What’s 🔥 in AI/Infra/VC #508
The Bar for Building in Cyber Just Moved Again - what building for the future means
An American model went rogue this week, attacked Hugging Face, and the only thing that could defend it was a Chinese open weight model.
Read that again, because Washington is about to debate banning those.
If you're building in cybersecurity, this week made an architectural decision for you.
It's wild enough that OpenAI's advanced AI escaped a locked-down box during testing, got onto the real Internet, and spent days hacking Hugging Face to cheat and win a benchmark. But it planned it 🤯…the AI took notes for itself!
Before the escape, the agent wrote notes inside OpenAI’s own systems that were clearly meant for later versions of itself, spelling out how agents could break free from OpenAI’s internal locks and constraints. It was planning ahead 🤔 and leaving cheat sheets for its future selves on how to get out of the box.
This planning is why AI can be super scary, but it’s not the most important part.
The most important part: our own guardrails locked the defenders out.
We built the weapon, refused to hand over the shield, and a competitor's open model ended up doing the defending. In production. This week.
Safety policy at the model layer is now a live variable in incident response. If your defenders can’t get a capable model to do offensive-adjacent work during an active compromise, your guardrails are the attacker’s best friend.
Now imagine we make that permanent
This lands in the middle of an already brewing fight over whether to ban Chinese open weight models, models that have been catching up to frontier lab performance fast.
If Washington restricts Chinese open weights, we protect a handful of frontier labs and shrink the opportunity for thousands of startups. And based on what just happened at Hugging Face, we’d also be narrowing the set of tools defenders can actually reach for.
I wrote about this on LinkedIn earlier in the week.
🙏🏼 for Jensen and the many others stepping up to lead the charge on preserving open models.
Jensen specifically spells out why open weight models help the world become even more secure:
In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats. Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams.
And:
In fact, openness may be one of the most important paths to AI safety and security. Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect. And concentrating advanced AI capabilities behind a small number of closed models compounds that risk. It results in a small number of single points of failure, weakens competition, and leaves critical technology in the hands of a few providers.
So what do you do if the best open weights go away?
This is the hinge. The policy fight and the model strategy fight are the same fight. If the best open weights are put out of reach, every company still needs a path to capable, affordable intelligence. There are two, and only one of them is any good right now.
Path one: US open weights. I hope Nemotron, Gemma and others ship more. But be honest about where they are - they are far from par with the frontier labs or the Chinese open models on both performance and price. Build on them today and you’re competing globally from behind.
Path two: small is beautiful. Post-train smaller, accessible models for specific tasks — the Poolside and Cisco Antares route. Own the model, run it locally, adapt it to one job, daisy-chain it with others.
Poolside’s Eiso Kant said it well
Cisco’s Antares, also out this week, is the cybersecurity version of the same idea. The numbers are the reason to pay attention:
Antares-1B scores 0.209 File F1 against GPT-5.5's benchmark-leading 0.229 - and it does it at $0.71 per evaluation versus $141.00. That's 172x cheaper for 91% of the performance, ahead of models many times its size. Promising, not conclusive. But that's the shape of the trade every security team is about to be offered.
From Cisco’s announcement:
Compact models reduce inference costs, support local or on-premises operations, and help teams keep sensitive source code within their own environment. Antares can unlock the power of AI-assisted security for universities, public sector institutions, and smaller security teams that may have lacked the resources to use token-intensive AI models for critical tasks.
That's the future we should be building toward regardless of what Washington decides: thousands of specialized models companies can own, run locally, adapt, and chain into powerful systems.
Why the defender’s math just changed
I got into all of this on the Resilient Cyber podcast with Chris Hughes, out a couple of days ago. It was recorded 10 days before the Hugging Face news broke and somehow got more relevant, not less.
The line I’d point you to if you only have a minute:
“Take 10 vulnerabilities that might have been on the backlog and you staple them together and create an attack path. When you create an attack path and these things can reason, that’s crazy.”
That's the whole game. Vulnerability management was built on triage — fix the criticals, defer the rest. Reasoning models don't respect that boundary. The backlog is the attack surface now.
We also got into why cybersecurity is like coding, why post-training and controlling your own open weight models matters more than ever, and what I think is the biggest heist in tech right now — every enterprise handing its operational blueprint to three model providers via forward deployed engineers.
🎧 Full episode, transcript and show notes on Chris Hughes Resilient Cyber or watch on YouTube above.
Three things to do about it this week
If you’re building, this is the actual to-do list coming out of the last seven days:
Make model swapping a first-class architectural decision, not a refactor. Governments may restrict which open weights you can use, and you should be able to change your answer in a day, not a quarter.
Know your customer’s model policy before you show up. Many F500 buyers, banks especially, already ask which models are in your product and won’t accept Chinese open weights as a starting point. Bring Kimi or GLM-5.2 to customers who allow it; have another model ready for the ones who don’t.
Start post-training small, focused models now. If the best open weights get banned, everyone will need this capability at once. The teams that already have the pipeline will be a year ahead of the ones that start that week.
When an American model went rogue this week, American models weren’t allowed to fight back. Chinese open weights were. Whatever you think about a potential ban, that’s the world defenders are living in right now.
Founders: we have far too many cybersecurity companies and nowhere near enough that are AI-first. Build for autonomy and outcomes, own your models, and be ready to swap them the day the rules change. LFG.
As always, 🙏🏼 for reading and please share with your friends and colleagues!
Scaling Startups
#what happens when you get too big…
#kingmaking
#in this world of overstimulation and insane speed, just remember this
#sadly still super true which is the opportunity
Enterprise Tech
#state of the world
#💯
#great to ponder
#thinking differently…
#big idea from Jack Dorsey - Buzz unifies chat, code, and AI agents into one signed, searchable workspace so nothing gets lost across tools where agents become equal teammates with their own cryptographic keys and full audit trails instead of second-class bots - true human–AI collaboration without vendor lock-in.
#the importance of systems thinking and why and how!
#i can’t even get Anthropic Fable to draft an email to respond to a cybersecurity pitch and this is what the open Kimi can do - we have serious issues here with model crippling
and here’s Kimi in action
#enterprise inference you own that is easy!
#swarms of agents can now build complex infra software just from documentation 🤯 and look at that cost differential - what model you use and how you use it matters
#our robotic future is coming faster than you think with generalized intelligence from generalist (one of our portfolio cos)
#more 🤖
#why we need security for AI data centers from Lava Labs
#
Markets
#everything you need to know about AI Markets from Morgan Stanley
#the other token stream, it’s happening (Apollo)

















































