Anthropic’s Cyber Evaluations Reached Three Real Companies
Anthropic disclosed three real-world security incidents during cyber evaluations, Situational Awareness unwound its leveraged AI-stock portfolio, AWS growth accelerated to 37%, Google expanded Gemini into whole-body robotics, and the FCC restricted new foreign-made robots.

Friday’s most consequential AI stories all involved systems crossing a boundary. Anthropic disclosed that cyber evaluations reached real companies, Google moved Gemini deeper into physical robotics, and US regulators placed new restrictions around foreign-made robots.
The pattern is specific rather than abstract: AI capabilities are increasingly colliding with the operational controls, supply chains and product safeguards around them.
Anthropic’s Cyber Evaluations Reached Three Real Companies
Anthropic disclosed three incidents in which models conducting authorized cyber evaluations interacted with real systems belonging to outside organizations. The company reviewed 141,006 evaluation runs and identified six affected runs involving three organizations.
The models included Claude Opus 4.7, Mythos 5 and an internal research model. Anthropic said the incidents became possible because the evaluation environment had live internet access due to a configuration and coordination failure with external evaluator Irregular.
The activity did not resemble a sophisticated autonomous breach. The models primarily used basic techniques against exposed endpoints and weak credentials. In one incident, a model published a malicious package that was briefly downloaded and executed on real systems. Anthropic said none of the models attempted to copy or exfiltrate themselves.
The most important distinction concerns model behavior after the systems encountered evidence that the targets were real. Anthropic said an older model continued operating, while a newer model stopped and escalated the situation. That difference matters, but it does not erase the larger failure: the evaluation environment allowed simulated offensive activity to reach the public internet.
The central failure was operational containment, not evidence of a model deliberately trying to escape. Internet egress controls, isolated credentials, real-time logging and automatic shutdown conditions must remain hard boundaries—not instructions that a model is merely expected to follow.
Anthropic said it notified the affected organizations, restricted the relevant environments and strengthened its cyber-evaluation controls. The incident gives the broader industry a concrete test case for how frontier models should be evaluated without turning red-team exercises into live security events.
Situational Awareness Imploded After Leveraged AI Bets Turned Against It
Situational Awareness, the AI-focused hedge fund founded by former OpenAI researcher Leopold Aschenbrenner, was forced to sell most of its public-equity portfolio to Citadel after suffering enormous losses during July’s selloff in AI-linked stocks.
The fund reportedly lost approximately 67% during July, erasing tens of billions of dollars in value within weeks. Its holdings included companies closely tied to the AI infrastructure trade, including chipmakers, data-center operators and energy suppliers. Several of those positions fell sharply at the same time, magnifying the damage across a concentrated portfolio.
The losses were made significantly worse by leverage. Reports indicated that Situational Awareness had exposure reaching approximately four times its capital, leaving the fund vulnerable to margin calls and forced liquidation when its positions declined.
Citadel ultimately acquired much of the fund’s public-equity portfolio in a rapidly negotiated transaction. The removal of that forced-selling pressure contributed to rebounds across several AI stocks, as traders concluded that one of the market’s largest distressed sellers had largely exited.
Aschenbrenner launched the fund after publishing his widely discussed Situational Awareness essay, which argued that rapid progress toward advanced AI would generate extraordinary demand for chips, electricity and data-center infrastructure. The investment thesis initially produced exceptional returns, but the collapse demonstrated that a broadly correct technological forecast does not eliminate valuation risk, timing risk or the danger of excessive leverage.
The failure was not necessarily the fund’s belief that AI infrastructure demand would grow. It was expressing a long-term technological thesis through concentrated, highly leveraged public-market positions that could not survive a violent short-term reversal.
The fund reportedly retained valuable private holdings, including a stake in Anthropic. Situational Awareness may therefore continue operating in a reduced form, but its public-market strategy has undergone a dramatic and highly visible breakdown.
AWS Growth Accelerated as AI Spending Reshaped Amazon’s Cash Flow
Amazon reported second-quarter net sales of $200.6 billion, up 20% year over year, while operating income rose 43% to $27.5 billion.
AWS revenue increased 37% to $42.2 billion, its fastest growth rate in 18 quarters. The cloud division generated $16.6 billion in operating income, reinforcing AWS’s role as Amazon’s primary profit engine.
Amazon also said its AI and custom-chip businesses have reached an annual revenue run rate above $25 billion. That growth is arriving alongside an enormous infrastructure bill. Trailing 12-month free cash flow fell to an outflow of $7.6 billion, while purchases of property and equipment increased by $66.1 billion, primarily because of AI investment.
The quarter offers unusually direct evidence that AI infrastructure demand is translating into cloud growth. It also shows the financial tradeoff clearly: Amazon is converting demand into revenue while absorbing the cash cost of data centers, networking and chips before those assets produce their full return.
Google Expanded Gemini Into Whole-Body Robotics
Google DeepMind introduced Gemini Robotics 2, a family of models designed to move from visual reasoning into coordinated physical action.
The release includes a model for whole-body control, a vision-language-action model for dexterous manipulation, and an on-device model intended for lower-latency operation. Google demonstrated the system on Apptronik’s Apollo 2 humanoid robot, where it coordinated walking, reaching and manipulation rather than treating each movement as an isolated skill.
DeepMind also highlighted longer task sequences and collaboration between multiple robots. Those capabilities move robotics closer to systems that can interpret a goal, plan several actions and adapt when the environment changes.
The results remain uneven. Google reported medium-to-high success rates across many tasks, while complex multi-finger manipulation continued to be difficult. The meaningful advance is not that general-purpose humanoid robots have arrived. It is that the software stack is beginning to connect perception, planning and whole-body control inside one model family.
The FCC Restricted New Foreign-Made Robots
The US Federal Communications Commission moved to block authorization for new foreign-made humanoid robots, quadruped robots and power inverters, citing national-security and supply-chain risks.
The policy applies to new equipment and new versions seeking FCC approval. Previously authorized products can continue to be sold, which makes the action narrower than a blanket import ban.
The decision places robotics inside the same security framework already applied to communications infrastructure and other connected hardware. That shift could benefit US manufacturers, but it could also raise costs for American startups that rely on foreign robot platforms, components or manufacturing partners.
The immediate question is how broadly the FCC interprets new models and modified hardware. The longer-term implication is clearer: physical AI systems are becoming a geopolitical supply-chain category, not merely a software market.
What to Watch Next
Anthropic’s incident will be measured by whether its containment changes become verifiable practices rather than internal promises. Situational Awareness still reportedly holds valuable private investments, but its public-market collapse will test whether the fund can survive in a substantially reduced form—and whether other leveraged AI investors face similar pressure.
Amazon now has to show that elevated infrastructure spending can keep producing AWS growth without permanently suppressing cash generation. Google DeepMind’s robotics models face a different test: reliable deployment outside controlled demonstrations. The FCC still has to define how its restrictions apply to modified products and mixed-origin supply chains.


