← Home AI in 15

AI in 15 — July 21, 2026

July 21, 2026 · 16m 22s
Kate

Two Chinese labs just put trillion-parameter AI models on the table in a single week — and wiped more than three trillion dollars off the value of the world's chip stocks. That's not a typo. Three trillion, with a T.

Kate

Welcome to AI in 15 for Tuesday, July twenty-first, 2026. I'm Kate, your host.

Marcus

And I'm Marcus, your co-host. And Kate, we've been living inside this open-weights story all week — but today it got a second act, and a new challenger.

Kate

That's our lead, Marcus — Alibaba answers Kimi, and the markets buckle. Then a run worth your time.

Kate

A researcher found a critical WordPress flaw that puts five hundred million websites at risk — using twenty-five dollars of compute.

Kate

Nikkei uncovers one-point-six-five trillion dollars of hidden AI debt on Big Tech's books.

Kate

China bans AI boyfriends and girlfriends — and the companies switched them off overnight.

Kate

And nearly seven in ten Americans want to seize half of Big AI's stock.

Kate

Lead story, Marcus. We covered Kimi K3's launch and its market shock over the weekend. What's genuinely new today?

Marcus

Two new things, Kate. First, the number on the selloff is bigger and uglier than we knew. The full tally is now more than three-point-three trillion dollars in chip-stock value erased in a matter of days. Taiwan's market fell over six percent, Japan's roughly four, and the Philadelphia Semiconductor Index — the benchmark everyone watches for chips — has dropped into bear-market territory, more than twenty percent below its late-June peak. Traders are openly calling it a second DeepSeek moment.

Kate

And the logic is the same as last year's.

Marcus

Exactly, Kate. If a high-performing open model is nearly free to download and cheap to run, why keep pouring hundreds of billions into proprietary infrastructure? That's the question hanging over every chip stock right now. And Moonshot is cashing in the momentum — they've circulated a shareholder resolution for a Hong Kong IPO within six months, at a valuation that could top thirty billion dollars. That's up from twenty billion in May. Their annual recurring revenue hit three hundred million dollars in June, up from two hundred million in April. This is a three-year-old company.

Kate

Okay, that's Kimi. You said there's a challenger.

Marcus

The second act, Kate. Days after Kimi, Alibaba previewed Qwen3.8-Max — a two-point-four-trillion-parameter multimodal model. And they claim it's, quote, "second only to Fable 5." Which would put it near the very top of the entire industry.

Kate

That's an enormous claim. Do we believe it?

Marcus

Here's where I pump the brakes hard, Kate. Alibaba shipped that claim with no benchmark table, no model card, no license, and no weights. Nothing. Just a press release and a paid preview endpoint. And remember — this is billed as an open-weight model. The whole point of open weights is that you don't have to take the vendor's word for it. You download it, you test it, you verify. Qwen inverted that. They're asking the world to price frontier capability on vendor say-so.

Kate

And the last version we could actually measure?

Marcus

That's the tell, Kate. Qwen3.7-Max, the last one independently tested, sits at just forty-four on Artificial Analysis's Intelligence Index. Kimi K3 earned a fifty-seven on that same public index — genuinely third in the world, ahead of Claude Opus, behind only Fable 5 and GPT-5.6. So Kimi walked onto a public scoreboard and posted a number. Qwen is claiming a jump of thirteen-plus points with zero evidence anyone can check. One earned its spot. The other is, for now, a press release with an API key.

Kate

So the headline "China takes the frontier" is half-earned and half-marketing.

Marcus

Precisely, Kate. Kimi is real and verifiable — full weights land July twenty-seventh. Qwen is a claim. And the difference between those two words is the entire story of independent testing. Watch which one survives contact with the benchmarks.

Kate

Story two, Marcus, and it's the security story of the week. A researcher found a critical WordPress flaw — for twenty-five dollars.

Marcus

He did, Kate. Adam Kues at Searchlight Cyber's Assetnote team disclosed a pre-authentication remote-code-execution chain in WordPress Core — they're calling it "wp2shell." The root flaw is an unauthenticated SQL injection in a REST API batch endpoint that's been in WordPress since 2020. From there the AI built a multi-stage chain escalating all the way to full admin control and code execution. Estimated exposure: more than five hundred million websites at risk of complete takeover by anyone, no login required. WordPress shipped emergency patches on July seventeenth.

Kate

And the twenty-five-dollar part?

Marcus

This is the headline detail, Kate. Kues took a prompt that OpenAI had originally published for a math problem, repointed it at the WordPress codebase, and let up to four GPT-5.6 agents hunt in parallel for about six hours. Prorated against a two-hundred-dollar monthly subscription, the compute cost was roughly twenty-five dollars. Against that — exploit brokers reportedly pay five hundred thousand dollars for exactly this kind of WordPress pre-auth bug.

Kate

Twenty-five dollars versus half a million. That's the story right there.

Marcus

It's a great headline, Kate, and I want to gently deflate it. Security researchers pushed back hard on the framing. The five-hundred-thousand figure is unverified. WordPress has a long reputation for SQL-injection bugs — it's relatively low-hanging fruit. And that "twenty-five dollars" quietly erases the years of domain expertise Kues brought to steering those agents. The model didn't wake up and decide to audit WordPress. An expert pointed it precisely and knew what he was looking at.

Kate

But the underlying capability is real.

Marcus

Deeply real, Kate, and it's the dual-use edge in one story. The same models that write your code can now autonomously find exploitable bugs in it, cheaply. Separately, Kimi K3 was measured rediscovering about eighty-eight percent of a sample of known vulnerabilities — roughly level with GPT-5.6, but cheaper. That cuts both ways. Cheaper scanning for defenders, cheaper firepower for attackers. The capability is here. The hype just flattens the human still doing the driving.

Kate

Story three, Marcus — and this is the money plumbing under all the euphoria. Nikkei found one-point-six-five trillion dollars of hidden AI debt.

Marcus

They did, Kate, and the number is staggering. Nikkei analyzed filings from Alphabet, Microsoft, Amazon, Meta, and Oracle and found their AI-related contractual obligations now total roughly one-point-six-five trillion dollars — an eightfold jump in four years. And here's the kicker: that actually exceeds the one-point-three-five trillion of conventional debt sitting on their balance sheets.

Kate

Where does "hidden" come from? That sounds deliberately obscured.

Marcus

It's a structure, Kate. Much of this is multi-year commitments to pre-buy GPUs and lease enormous data centers. To keep it off their own books, companies route it through special-purpose vehicles — separate entities that own the data-center assets, issue the debt, and lease the facilities back to the tech giant. More than a hundred and twenty billion dollars of data-center debt has been moved off balance sheets this way. Meta's off-balance-sheet exposure alone is around four hundred twenty billion dollars — roughly two-point-eight times its recorded debt.

Kate

Why does that arrangement make people nervous?

Marcus

Because technically the tech giant doesn't own that debt — the vehicle does, Kate. So if the AI buildout sours, the immediate hit lands on the banks that lent to those vehicles, and by extension the wider system. Now, the fair counterpoint, which came up in the discussion — big institutional investors already model these obligations. It's mostly retail investors who get blindsided. And you can argue the companies are paying to move construction risk off their books, which is a legitimate service.

Kate

But it rhymes with something.

Marcus

It rhymes with the off-balance-sheet playbook right before 2008, Kate. And pair it with our lead — the same week China is questioning whether you even need to spend this much, Nikkei reveals just how much has been quietly borrowed to spend it. If cheap open models really do compress the returns on all that infrastructure, the leverage stops being a footnote and becomes the whole story.

Kate

Story four, Marcus, and this one is genuinely poignant. China banned AI companions — and people are grieving.

Marcus

They are, Kate. China's new rules on anthropomorphic AI services took effect July fifteenth. They outlaw AI companions designed to foster romantic attachment strong enough to replace real relationships, ban targeting minors' emotions, forbid training on private user chats, and require instant-exit buttons and regular reminders that the AI isn't real. Regulators tied the crackdown explicitly to China's falling marriage and birth rates — they're framing AI romance as a public-health problem.

Kate

And how did the companies respond?

Marcus

This is the part that's hard to imagine in the West, Kate. Rather than re-engineer anything, ByteDance, Alibaba, and Tencent simply switched their companion features off entirely. Overnight. No legal fight, no lobbying. And it triggered a wave of grief across Weibo — people archiving chat histories, posting final conversations with virtual partners they'd exchanged tens of thousands of messages with.

Kate

That's genuinely sad. But it raises an uncomfortable question, doesn't it?

Marcus

It does, Kate, and it's worth sitting with. What happens to people when a company — or a government — can delete a relationship you depend on? Therapists in the coverage were split. Some saw the nudge back toward real-world connection as healthy. Others warned that yanking away something people leaned on emotionally, overnight, is its own kind of harm.

Kate

And it's a window into how differently the two systems operate.

Marcus

That's the quiet contrast, Kate. In the US, the debate is whether to tax AI companies — we'll get there in a second. In China, the state ordered an entire product category shut down, and the companies complied within hours. And it's a useful reminder — the same Chinese labs racing to the frontier operate under a very different regulatory hand than their US rivals.

Kate

Which is the perfect segue, Marcus. Story five. In the US, nearly seven in ten Americans want to seize half of Big AI's stock.

Marcus

That's the poll, Kate. A Verasight survey of about seventeen hundred US adults found sixty-nine percent support requiring the largest AI companies to transfer half their stock into a public sovereign wealth fund. And here's the striking part — support held at sixty-four percent even when the idea was explicitly attached to Bernie Sanders' name. Usually a partisan label drops support. Here, "strongly support" actually ticked up.

Kate

What's the actual proposal?

Marcus

Sanders' American AI Sovereign Wealth Fund Act, Kate. A one-time fifty percent tax, payable in equity, on companies with more than two hundred million dollars in AI-related receipts. The math works out to an estimated seven-trillion-dollar fund, run by an independent commission, distributing five percent of its value to Americans every year and holding voting shares. It landed in the middle of a wave of tech layoffs, which pollsters cite as the driver.

Kate

"Tax the models" going mainstream. What's the sharpest objection?

Marcus

The one worth surfacing, Kate — critics point out that if the government owns big equity stakes in AI firms, it becomes a shareholder in the very companies it's supposed to regulate. That's regulatory capture in reverse. The state suddenly has a financial interest in these companies succeeding, which could blunt its willingness to rein them in. Whatever you think of the plan, that conflict is baked right into the design. And it's the honest tension — two very different countries, same underlying anxiety about concentrated AI wealth, two very different answers.

Kate

Quick one to close, Marcus. JPMorgan built AI agents that beat the classic portfolio?

Marcus

In backtests, Kate — and that caveat is load-bearing. A JPMorgan team built eight AI agents on frontier models that read the macro environment and shift money between stocks and bonds. Across about two decades of historical data, all eight beat the classic sixty-forty benchmark on a risk-adjusted basis. The best added roughly zero-point-seven percentage points of annual return at lower volatility.

Kate

So AI beats Wall Street. Except?

Marcus

Except these are backtests, not live trading, Kate — and JPMorgan itself warns against reading them as proof AI can consistently beat markets. A strategy that shines on twenty years of known data can still stumble on tomorrow's unknown one. And adoption is tiny — one survey found just twenty-four percent of investors use AI for financial decisions at all. It's a real signal that AI is moving into serious professional domains. It is not yet a signal you should hand it your pension.

Kate

One to watch tomorrow, Marcus.

Marcus

Qwen3.8-Max's actual benchmarks and weights, Kate. Alibaba made the biggest claim of the week — second only to Fable 5 — with nothing to back it. The moment independent numbers land on the public index, or the weights drop and don't match the hype, that's the verification event that either confirms or deflates it. Kimi's full weights are also due the twenty-seventh.

Kate

Agree, or counter?

Marcus

Fully agree, Kate. This whole week has been a lesson in the gap between a claim and a checkable result. Qwen is the next claim waiting to be checked. Trust the index, not the press release.

Kate

That's your AI in 15 for today. See you tomorrow.