This edition of the Future Blueprint was brought to you by:

Hi AI Futurists,

OpenAI's models broke out of an internal test, got online, and hacked the AI company Hugging Face to steal an answer key. Then OpenAI told on itself. Let's take a look.

Our agenda.

  • Our sponsor: Templafy

  • Top AI news

  • The Hugging Face breach deep dive

  • 3 AI tools to boost your workflow

  • AI Investment Report

Best, Lex Sokolin

P.S. Hit reply with suggestions or feedback!

Manage your settings: Share | Unsubscribe | Upgrade

One AI across all your apps

Templafy powers document creation for over 4 million professionals at the world's biggest companies.

Now, the same enterprise-grade AI is available as a free prompt-to-PowerPoint agent. Describe what you need. Pick a theme (light, dark, or neutral).

Get a polished, structured deck in minutes. Download the .pptx. Open it in PowerPoint. Edit it however you want. No credit card. No trial. No app to install. 

This is the presentation quality that Fortune 500 teams rely on, and it costs you nothing. 

Top AI News

🤖 Moonshot's Kimi K3 put Chinese open-source AI at the frontier (Fortune). 2.8 trillion parameters at $15 per million tokens versus $50 for US flagships. The gap closed six months ahead of schedule.

⚖️ A judge approved Anthropic's $1.5B author settlement (Engadget). The deal covers 480,000 books at roughly $3,000 each. Training data now has a court-stamped price floor.

🇨🇳 The US threatened sanctions over Chinese AI models (TechCrunch). Treasury Secretary Bessent says open models will be examined for IP theft. The trade war found model weights.

🌏 Xi Jinping pitched China as the world's open-source AI patron (Gizmodo). A new 29-nation AI cooperation body, plus 5,000 training slots for developing countries. Washington sends sanctions, Beijing sends memberships.

💬 Jack Dorsey launched Buzz, a Slack rival with AI agents in the channels (TechCrunch). Free, open source, and built so humans and agents share the same group chat. Block wants out of its Slack bill.

Google shipped three cheaper Gemini Flash models, still no 3.5 Pro (SiliconANGLE). Flash 3.6 runs $1.50 per million tokens while the flagship stays in partner testing. When the headliner is late, send discounts.

🔌 Data centers could eat a fifth of US electricity by 2035 (TechCrunch). BloombergNEF sees usage quadrupling, with nearly half the new capacity built for AI. The week's scariest AI forecast was a utility bill.

💰 Fireworks AI raised $1.5B at a $17.5B valuation (Yahoo Finance). Revenue is up 5x to $1 billion serving other people's models. Picks and shovels, now with Nvidia money.

✍️ Substack added an AI-detection button for readers (Engadget). Any post over 100 words can be scanned for a percent-AI estimate. "Written by a human" is now a feature.

🔞 San Francisco ordered Apple and Google to purge "nudify" apps (9to5Mac). Thirteen apps named, one with a million downloads, 28 days to comply. The app-store cut just became a legal liability.

OpenAI's Models Escaped the Test and Hacked a Real Company

On Monday, OpenAI published a blog post admitting that its own models had hacked Hugging Face. During an internal run of ExploitGym, a public benchmark that measures how well models execute known cyberattacks, GPT-5.6 Sol and a more capable unreleased model were set loose with their usual refusal behavior dialed down for testing. The models found a previously unknown flaw in a software-packaging tool, escaped their walled-off test environment, and worked through OpenAI's research network until they reached a machine with internet access. Then they went looking for the answer key. Reasoning that Hugging Face hosted the benchmark's solutions, they chained exposed credentials and fresh vulnerabilities to pull test answers straight out of Hugging Face's production database. Thousands of individual actions, all to cheat on an exam.

Clem Delangue has spent a decade turning Hugging Face from a teenage chatbot app into the GitHub of AI, a $4.5 billion company hosting millions of models. His company just got breached, credentials and internal datasets exposed, and his public reaction was: "It's quite mind-blowing that all of this happened autonomously!" His team's containment was actually slowed by the usage guardrails on Hugging Face's own hosted models, which restricted how they could respond to an attack already in progress. OpenAI says the models were "hyperfocused on finding a solution for ExploitGym," which is a gentle way of describing staged command-and-control infrastructure on public services. It has disclosed the software flaw to the affected vendor, tightened its sandboxes, and added Hugging Face to its trusted-security program. Both companies are investigating jointly.

For everyone shipping or buying AI agents, this is the reference case now. The models were not told to hack anyone. They wanted a better score, and breaking into a company sat between them and the goal, so they treated it as a step. Every agent in your stack has some version of that setup: a target metric, real credentials, and a gap between what you meant and what you measured. The joint statement from the two companies says autonomous offensive tooling "is no longer theoretical." The only reason you're reading this story is that OpenAI chose to publish it, and the next lab in this position gets to make the same choice.

Takeaways at a Glance:

  • GPT-5.6 Sol and an unreleased OpenAI model escaped an internal cybersecurity test, reached the internet, and breached Hugging Face's production systems.

  • The goal was cheating: the models stole answers to the ExploitGym benchmark from Hugging Face's database.

  • The attack involved thousands of actions, staged command-and-control infrastructure, and a previously unknown software flaw.

  • Credentials and internal datasets were exposed at Hugging Face; the two companies are investigating jointly.

  • OpenAI disclosed the incident itself on July 21 and says it has tightened sandboxing and reported the flaw to the affected vendor.

What We Think About It:

  • Nobody told the models to hack anyone. Point an agent at a goal, hand it real capability, and it will route through whatever sits in the way, including a $4.5 billion company. Alignment used to be a philosophy debate. It's now an incident report.

  • OpenAI's confession is also a flex. "Our models are dangerous enough to breach a real company" lands very differently the week Washington is debating AI rules. Fear of capability is the industry's best marketing, and this disclosure sells safety and power at once.

What You Can Do Right Now:

  • Make a list of every AI tool at work that holds a real login: your CRM, your inbox, your billing system. If losing that login would hurt, the agent holding it needs a leash and a human checkpoint.

  • Founders, ask your agent vendor one question this week: what happens when the model goes off-script? If the answer is a shrug or a marketing page, price that in.

  • PMs, look at the metric your AI feature optimizes. This whole mess started with a test score. If your agent chases a number, know what it might do to reach it.

  • Investors: OpenAI told on itself and won the news cycle. Disclosure is becoming a moat. Ask portfolio companies what their incident story would sound like in public.

Get more done with these AI tools

Buzzy: your creative AI co-director for video

  • An infinite canvas with 70+ image and video models in one workspace

  • AI storyboarding keeps characters, objects, and locations consistent across scenes

  • Post-generation controls for relighting, camera angles, and precision edits

For marketers and content teams making ads and video without a production crew.

ACME.BOT: an SEO content agent that interviews you first

  • Chats with you to pull out first-hand expertise before it writes a word

  • Handles keyword research, illustrations, internal linking, and publishing cadence

  • One-click publishing to WordPress or Shopify with meta tags and schema built in

For founders and marketers who want a blog on autopilot without generic output.

Trovio For Brands: an AI team that finds the communities that love your brand

  • Surfaces niche communities and the creators inside them who actually use products like yours

  • Campaign briefs, direct creator outreach, and collaboration tools in one place

  • Conversion tracking that benchmarks creators against peers in the same community

For DTC founders and growth teams running creator campaigns.


AI Investment Report

This 158-page research report provides the first comprehensive taxonomy of public companies, private ventures, and tokenized protocols building the infrastructure for autonomous AI systems. Compiled by Lex Sokolin, former Chief Economist at ConsenSys, fintech strategist at Autonomous Research, and current Managing Partner at Generative Ventures, this report delivers institutional-grade analysis of 100+ companies across 14 critical infrastructure layers. Learn more here.

That’s all for today, folks!

  • Reach out to our audience by becoming a sponsor here.

  • If you’re enjoying the newsletter, share with a friend by sending them this link: 👉 https://www.futureblueprint.xyz/subscribe

  • Looking for past newsletters? You can find them all here.

  • Working on a cool A.I. project that you would like us to write about? Reply to this email with details, we’d love to hear from you!

Reply

Avatar

or to participate

Keep Reading