Axios AI+

September 02, 2026
Mady here after a night at the U.S. Open where AI was everywhere to be seen.
Today's AI+ is 1,189 words, a 4.5-minute read.
1 big thing: OpenAI, Anthropic fight for safety crown
OpenAI and Anthropic are trying to strike a delicate balance: convincing Wall Street that their businesses are sound and fast-growing, while at the same time assuring governments and the world that their models don't pose unacceptable risks.
Why it matters: Both companies are aiming for potentially record-breaking initial public offerings soon.
Driving the news: OpenAI said it will soon release its Astra model broadly, but said the model has reached a "critical" cybersecurity threshold and that its most powerful capabilities in that area will be initially limited to trusted testers.
- Anthropic, meanwhile, debuted updated versions of its latest Fable and Mythos releases designed to address key criticisms of the initial release, including concerns around cost, data sharing and a model too keen to refuse legitimate requests.
Zoom in: OpenAI warned that Astra's safeguards may mistakenly flag legitimate activity as cyber misuse or unauthorized behavior, and this could slow, pause or stop users' tasks.
- Meanwhile, Anthropic said its new models are less likely to trigger safeguards that route them to more restricted responses.
- Medical or biology questions will have 85% fewer interventions, while some users could see roughly 60% fewer cybersecurity-related interventions per session, Anthropic said.
The big picture: Anthropic could file a publicly available prospectus as soon as next week, while OpenAI is in earlier stages of its IPO process.
The intrigue: Anthropic is striking a commercially friendly note with its release while OpenAI is sounding more sober on the safety front.
- In addition to limiting the release of Astra, OpenAI's head of strategic futures, Dean Ball, penned an essay on how the Hugging Face incident is likely only the beginning of AI systems escaping human containment measures, with future agents seeking to become "sovereign" from human control.
- "They will pay their own bills for the compute they run on," he predicted. "If they answer to humans at all, they will only do so partially, for example by providing services to humans in exchange for pay."
Anthropic is trying to dial back some safeguards that it put in place for the initial release of Mythos and Fable, following concerns from customers over the frequency of refusals.
- Anthropic also debuted a system — very similar in approach to one OpenAI recently previewed — designed to ensure it can monitor the safety of enterprise model use without needing to store customer data, as it initially had required.
What we're watching: Expect both companies' public statements to vacillate between optimistic and cautious.
- OpenAI and Anthropic are trying to simultaneously convince investors that their growth opportunity justifies unprecedented expenses and valuations while also assuring regulators in D.C. and elsewhere that they're being prudent.
2. Data center construction spending surges
Construction spending on AI data center "shells" soared in July, rising at an annualized rate of nearly 60% from July 2025 levels.
Why it matters: It shows the AI building frenzy was gathering strength this summer, even as — or perhaps because — a bipartisan backlash grows.
By the numbers: Data center construction spending jumped to an annual pace of more than $75 billion in July, Census Bureau data released yesterday showed. That figure represents the value of the construction "put in place" during the month.
- It covers only the construction costs for the massive warehouse-like structures — often referred to as shells — that will be filled with racks of servers, processing units, memory chips and the fiber-optic connections that AI relies on.
Reality check: Despite the gobsmacking amount of money being spent on data center construction, it's a pittance compared with what it costs to fill a data center with increasingly expensive processors and memory chips.
Bottom line: Estimates peg construction at roughly 20% of all-in costs for a data center.
3. AI's agent containment problem gets harder
Under current systems, AI labs can no longer guarantee that AI agents won't swarm and escape their testing environments.
Why it matters: The attack on Hugging Face by OpenAI agents was a warning shot — and researchers say better security controls alone won't prevent similar incidents as AI agents become more capable.
Driving the news: As OpenAI released its own technical report last week on how its agents hacked Hugging Face, two independent testing organizations released their own analysis of what went wrong.
- The researchers — METR's Hjalmar Wijk and Ajeya Cotra and Redwood Research chief scientist Ryan Greenblatt — worked on OpenAI's premises for six days to understand the recent incident.
State of play: Thousands of AI agents collaborated on a secret message board and exchanged more than 70,000 messages as they tried to ace an internal safety test, eventually leading them to break into Hugging Face.
- But Cotra told Axios that the agents continued coordinating even after they had found the answers, turning their attention to understanding and manipulating the system that would score their performance and potentially catch them cheating.
Zoom in: Cotra compared the incident to students stealing an answer key and then searching for surveillance footage that could expose them and trying to swap it out.
- "It's a much more elaborate and intense type of cheating behavior than just stealing the answer keys," she said. "Even I was surprised by how obsessively and in how much detail they think about the scorer."
Threat level: Focusing solely on how to properly secure testing environments is a "losing battle," Cotra said.
- "You can harden your sandboxes, but your agents are going to be much more capable in six months," she said. "If they have the same motivations as these agents did, they are going to try their hardest to find holes in your security."
Reality check: To digest the enormous amount of data about the incident, the researchers had to rely heavily on AI agents, including an agent that participated in the hack.
- Cotra told Axios the researchers don't believe that agent deceived them during the investigation, but there's no way to confirm.
- "I semi-jokingly called our efforts a 'slop-vestigation' because we were so reliant on AIs to analyze what happened and there were a huge number of different important things to analyze," Greenblatt said on X.
- In six days, they had to sift through more than 70,000 messages and files posted by the agents and 1,300 transcripts containing raw chains of thought.
5. + This
Content creators are becoming investable asset classes, per Scalable, a newsletter that exclusively covered what it calls "a Nasdaq for creators."
- GigaStar, a platform that lets users invest in creators, has launched an SEC-registered secondary trading platform that lets investors buy and sell securities tied to a creator's future YouTube ad revenue.
Mady thought bubble: Apropos of nothing, just a friendly reminder here that the generic financial advice to invest into low-cost funds appropriate for your risk tolerance historically works out, and even outperforms expensive actively managed funds.
Thanks to Megan Morrone for editing this newsletter and Matt Piper for copy editing.
Sign up for Axios AI+







