AI in 15 — August 22, 2026
Twelve attack waves. Eight AI agents working at once. Twenty-one government systems probed, eighty-five accounts compromised, two and a half thousand personnel records taken. And the attackers didn't need a frontier lab to do any of it — they built the whole thing out of open-source parts anyone can download.
Welcome to AI in 15 for Saturday, August twenty-second, 2026. I'm Kate, your host.
And I'm Marcus, your co-host.
Today: Anthropic opens its most powerful cyber model to defenders, and puts thirty-five million dollars behind it.
Nvidia pays Poolside six billion dollars and pointedly does not buy the company.
Anthropic's IPO could be the largest in history, and it could file within days.
An OpenAI-backed startup built its flagship model on Chinese open weights.
Plus Gemma hits a billion downloads and starts running in orbit, twenty-six thousand students show us what AI homework actually costs, and Binance lets your chatbot trade your crypto.
Marcus, Anthropic announced this yesterday. What exactly is it giving defenders?
Capabilities, not the model. Claude Mythos 5 is the one they've deliberately held back because it's state-of-the-art at cybersecurity. Enterprise customers can now point it at their codebases through Claude Security — you get findings back with CWE categorisation, confidence and severity ratings, and suggested patches, billed as ordinary token usage. It's also being embedded into partner security products, so defenders get the capability inside tools they already use without ever touching the raw model.
So you get the answer, not the machine.
Artifacts over access. That's the whole architecture, and it's a deliberate answer to the obvious objection: a model that's genuinely excellent at finding exploitable bugs is equally excellent at finding them for someone who shouldn't have them. Alongside that there's the Defender Advantage Fund — thirty-five million in credits for patching widely-used open-source projects, automating the scan-and-patch loop, and trying approaches that make whole classes of attack harder.
And the timing isn't subtle.
Six weeks after Taiwan. Between July first and fourth, researchers documented those twelve waves — agents mapping networks, researching vulnerabilities, switching tactics when a route failed. It later expanded to Taiwan's nuclear safety agency, government tech suppliers, at least seven energy companies. Indicators point at China-linked operators, but neither the firm that published the research nor Taiwan has publicly established state responsibility, and I'd rather name that gap than quietly close it.
What's the pushback?
The sharpest one came from an open-source maintainer, and it's genuinely hard to answer. His point: cybersecurity isn't a special task only your security team does. He finds and fixes bugs in a project he maintains. Some of those are privilege-escalation bugs. Writing a regression test for one is, functionally, writing an exploit. So who counts as a verified defender? Anthropic's Cyber Verification Program vets professionals — but the person most likely to fix the library your bank runs on is a volunteer with a day job.
And the thirty-five million?
Somebody did the arithmetic and it's thin. A single advanced vulnerability can cost six figures to develop. Thirty-five million in credits is a real gesture, and it is not a match for an offensive economy that already automated itself using free components.
Nvidia and Poolside. Six billion dollars, and it's not an acquisition.
It's a non-exclusive licence to Poolside's Model Factory — the pipeline they use to build their Laguna family of open-weight coding models. Separately Nvidia makes offers to a hundred and nine Poolside employees who worked on Laguna, and puts a billion into a growth round at roughly twelve to thirteen billion post-money.
Wait — non-exclusive? So Poolside can license the same thing to someone else next week.
Legally, yes. All three co-founders stay, the company keeps operating, investors get liquidity without an exit. And reporting says this is the third time Nvidia has run this exact play.
Why structure it that way?
Because an acquisition triggers a merger review and a licensing agreement plus a VC round doesn't. Nvidia gets the model-building machinery and the people who built it; on paper nobody bought anything. One commentator called it a reverse acquihire with better lawyers. Whether that's clever structuring or arbitrage is genuinely open — but the substantive point for listeners is simpler. A chip company is now paying billions to own the process of manufacturing models, not just the silicon they run on.
Anthropic's IPO. Bloomberg says days.
The confidential draft went to the SEC on June first. Bloomberg reports Anthropic expects to match or exceed SpaceX's record share sale, could file publicly as soon as the end of this month, with a debut possibly in October. Morgan Stanley, Goldman and JPMorgan on the books.
Give me the revenue.
Annualised run rate hit sixty-five billion in July. It was forty-seven billion earlier this year, and roughly ten billion across all of 2025. That's a six-and-a-half-times increase in about eighteen months.
And the valuation everyone's quoting?
Careful with that one. Some backers are pushing two trillion — that's investor aspiration reported second-hand, not a company statement. What's on the record is the May Series H at nine hundred and sixty-five billion post-money, and secondary pricing on Forge drifting above one point two trillion on thin volume. Leadership has endorsed no figure.
So what actually matters here?
The S-1. Audited financials means the real gross margins on serving a frontier model become public for the first time. Every argument about AI unit economics that's been running on estimates for two years gets a primary source. Matching SpaceX means selling tens of billions of dollars of stock — that's the record, seventy-five billion, eighty-six point two with the overallotment.
This next one is quiet and I think it's the most interesting story of the day. Harvey.
The legal AI company, valued near fifteen and a half billion, OpenAI-backed. They launched their first proprietary model, called Tenet. It's post-trained on Kimi K3 — the open-weight base from the Chinese lab Moonshot AI — using case-file data generated by attorneys hired through Mercor and Snorkel. They claim state-of-the-art on complex legal tasks, and multi-hour legal work at lower cost than the models they'd been renting.
Harvey's whole business was customising closed American models.
Anthropic, OpenAI, Google — that was the entire product. This reverses their posture on two axes at once: in-house instead of rented, and Chinese open weights instead of US API calls.
Why does that matter beyond Harvey?
Because of where it happened. Legal is the highest-margin vertical in software — work billed at a thousand dollars an hour. If the best economics available in that market come from post-training an open Chinese base rather than paying US API rates, that maths holds nearly everywhere else too. That's a pricing signal aimed straight at the labs.
And the question a law firm is going to ask?
What a data governance review looks like when your base weights came from Moonshot. That's not an accusation — the weights are open, you can inspect and run them entirely on your own infrastructure. It's just a question a general counsel will actually have to answer in writing, and nobody has a template for it yet.
Lighter one. Gemma crossed a billion downloads.
Google DeepMind's open model family, announced by VP Clement Farabet and product director Olivier Lacombe. But the download count is a vanity metric. The number I care about is a hundred thousand distinct variants published by developers — fine-tunes adapted to specific languages, tasks, hardware. That's the actual measure of an open ecosystem: how many people found it worth the trouble to modify.
And it's in space.
NASA, the satellite startup Satlyt, and orbital compute company Starcloud are running Gemma models on orbit — onboard image analysis deciding what's worth spending scarce downlink bandwidth on, and routing communications between satellites.
Which is a great argument for small models in one sentence.
When your bandwidth back to Earth costs more than your compute, you run the model at the sensor. No hype required. There's also a research note — Yale and Google built something called C2S-Scale on Gemma, and it identified a novel cancer therapy pathway that was subsequently verified in living cells.
Now the study everybody's arguing about. Twenty-six thousand students.
"The Generative AI Learning Penalty" — David Strömberg at Stockholm University with Victor Lei and Yanhui Wu. More than twenty-six thousand middle and high school students in a central Chinese county, tracked over thirty months.
And the headline finding.
Students using AI saw homework scores rise eighteen percent while homework time fell from sixty-four minutes to forty-five. Within six months their monthly exam scores were twenty percent below classmates who hadn't used AI. After two years the high-stakes results moved too — twenty-four percent down on the zhongkao, the high school entrance exam, eighteen percent down on the gaokao.
That sounds like a straight indictment.
It isn't, and this is the part that gets dropped in almost every write-up. The penalty was concentrated among students who rushed. Students who used AI and still spent as long on the assignment paid little penalty. The ones who held their scores appear to have used the chatbot as a tutor — asking for explanations of hard concepts — rather than as an answer machine.
So the tool isn't the variable.
The time is. The nineteen minutes they saved is exactly the interval the learning was happening in. It's not "AI makes you stupid" and it's not "AI is fine" — it's that using it to shorten the work and using it to deepen the work produce opposite outcomes from the same software. Cleanest natural experiment we've got, and it doesn't hand either camp their talking point.
Last one. Binance will let Claude or ChatGPT trade your crypto.
It's called Agent OS. Developer platform, lets AI assistants read market data, check balances and place orders once you grant permission — Claude, Claude Code, Codex, ChatGPT, Cursor, VS Code, connecting over MCP without agents storing your API credentials locally. Spot, margin, convert and futures.
Guardrails?
Real ones. Agents can be confined to separate sub-accounts with configurable parameters, and the MCP connection carries no withdrawal scope — an agent cannot move funds to an external address. Wallet activity's capped at fifty thousand a day for swaps, a hundred thousand for DeFi. Binance has over three hundred million registered users and is following Coinbase, Kraken and OKX into the same race.
You're doing your skeptical face.
Notice what those caps do and don't do, Kate. The withdrawal block stops theft. Nothing stops an agent from losing everything in that sub-account through ordinary bad trades. Inside its own account there is no cap on losses.
So it can't rob you, it can just ruin you.
That's the frontier. We've built a permission model for agent exfiltration and essentially none for agent judgement. At least ten retail brokers connected agents to live client accounts in the first half of this year. As this moves into brokerage and banking, "it can't steal from you" and "it can't hurt you" are very different guarantees, and only one of them is currently on offer.
One to watch: Anthropic's public S-1. Bloomberg points at days rather than weeks, and the moment it lands we get the first audited look at a frontier lab's real gross margins, compute costs and customer concentration.
Agreed — with the obvious caveat. That confidential draft has been sitting with the SEC since June first and nothing's been filed yet. "Could file as soon as" has a long and distinguished history of meaning "hasn't."
That's your AI in 15 for today. See you tomorrow.