Sponsor:
Win AI Search Without a Big Team
92% of VCs use AI to find companies. 58% of buyers start there, too. If you're not showing up in AI answers, you're invisible before the conversation even starts. Join HubSpot for Startups, Anthropic, and Marketing Against the Grain on July 30 (11 am ET) for a live AEO teardown. Real startup. Real recs. Register and unlock the free Startup Visibility Bundle.
iPrompt
THE AI NEWSLETTER THAT TURNS NEWS INTO ACTION
ISSUE #146 WEDNESDAY · 29 JULY 2026
THE HOOK
By Hugging Face’s account, its security team sat on 17,600 log entries with an AI agent still inside. They asked a frontier model to help read them. It refused — the guardrails couldn’t tell a defender from an attacker. So they pulled down a Chinese open-weight model, ran it on their own hardware, and used that to reconstruct the attack. The thing attacking them had no usage policy. They were working under somebody else’s.
AI NEWS ROUNDUP
This week in AI
1 Hugging Face published the full reconstruction of the OpenAI agent breach. Roughly 17,600 attacker actions between 9 and 13 July, entering through the dataset pipeline. Hugging Face caught and contained it themselves. Per Reuters, OpenAI didn’t work out the agent was its own until that disclosure went up — by which point the FBI had been called. CNBC →
2 Three names are missing from the industry’s new security alliance. Nvidia’s Open Secure AI Alliance launched Monday with 30-plus members — Microsoft, IBM, CrowdStrike, Red Hat, the Linux Foundation. OpenAI, Google and Anthropic aren’t among them. Days earlier 25 companies signed a letter warning Washington off restricting open weights; OpenAI signed once people noticed it hadn’t. Tom’s Hardware →
3 The frontier halved in price. Claude Opus 5 landed Friday at $5/$25 per million tokens, with a gold-medal 42/42 on this year’s IMO. Anthropic didn’t train it on cybersecurity tasks. Kimi K3’s 2.8-trillion-parameter weights went live at midnight UTC Monday. Which of those two is more use to a security team this week? Axios →
4 Someone has to sign for the $500 billion. OpenAI is valued at $852bn, unprofitable, and can’t get an investment-grade rating alone — so Nvidia is in talks to guarantee roughly $250bn of debt for a 10-gigawatt campus in southern Ohio, on a decommissioned uranium site. Chips are a separate conversation, up to $350bn more. TNW →
OUR ANGLE
🔭 The asymmetry is the product Last week I bet Washington’s framework grows an open-weights annex by Q1 2027. Five days later 25 companies wrote to stop exactly that. Then note who convened the security alliance the three closed labs skipped: Nvidia, also underwriting $250bn of OpenAI’s debt. So I had the wrong border. Not American weights against Chinese ones: who must ask permission and who needn’t. Hugging Face’s write-up names it: the attacker was bound by no usage policy, the defender by somebody else’s. Every guardrail is a capability the attacker gets free and the defender applies for. Opus 5 wasn’t trained on cybersecurity tasks — the frontier getting less useful to defenders by design. That’s the reporting. Here’s the bet — open to disagreement: by the end of Q4 2026, either OpenAI’s Daybreak or Anthropic’s Glasswing drops the invite-only gate for self-serve enrolment, with a published approval time. Wrong? Reply and tell me where. |
THE THREE SPECIALS
Do · Use · Understand
🎯 PROMPT OF THE WEEK The Refusal Pre-Mortem Most teams have never tested where their vendor stops helping, and assume the answer is nowhere that matters. Hugging Face found out at the worst possible moment there is. You get to find out cheaper — run this before you need it. You are a business continuity analyst. I'll describe workflows my Why it works: refusal risk clusters around content types rather than falling at random. Naming the trigger turns a vague worry into a testable list. And the 30-minute constraint is doing the real work: it blocks the model from answering ‘consider a multi-vendor strategy’ and forces something you could actually execute on a Tuesday. Run it once a quarter — the boundary moves every time a vendor ships. Where to be careful: models are unreliable narrators about their own refusals and will under-report. Verify by sending your two highest-risk prompts for real. A hedged answer that’s useless to you counts as a refusal for planning purposes. Works best on: Claude Opus 5, GPT-5.6 Sol. |
🛠️ TOOL OF THE WEEK ‘It’s Spotify for models you own.’ LM Studio ★★★★☆ 4 / 5 Hugging Face’s stated lesson from the breach was blunt: have a capable model you can run on your own hardware, vetted, before the incident. This is the least painful way to have one. — Free desktop app, macOS/Windows/Linux, currently 0.4.13. — Browse and download open-weight models, run them locally. — OpenAI-compatible local server — existing code points at it by changing a base URL. — MCP support since 0.4.12, so local models use tools, not just chat. 16GB RAM minimum, 32GB before it’s pleasant. You are not running Kimi K3’s 1.4 terabytes on a laptop — you’re running something in the 8–30B range that keeps working when your vendor doesn’t. A floor, not a ceiling. The floor is the point. LM Studio → |
💡 TIP OF THE WEEK Your best prompts are now costing you money This won’t apply to the prompt you wrote yesterday. It applies to the one from eight months ago you never reopened. Opus 5 shipped Friday with a prompting guide almost nobody read. Half the advice is deletion. ‘Include a final verification step.’ ‘Double-check before responding.’ Lines written to stop a weaker model being sloppy now cause over-verification, per Anthropic’s own guide — more tokens, no quality gain. It cut over 80% of Claude Code’s system prompt for Claude 5 with no measurable loss. 1. Search every prompt, CLAUDE.md, custom instruction and agent config for verify, double-check, re-check. Custom agents are the usual hiding place. 2. Delete, don’t rewrite. Then run your five most common tasks and compare. 3. Audit defensive rules too. Name a session where this model did what your rule forbids. Can’t? It’s a fossil. Every instruction was patching a gap in a specific model. Training closes the gap; the patch stays and starts billing you. Scope, format and tone instructions are different — those still earn their keep. It’s the verification scaffolding that has gone stale. Anthropic’s guide → |
YOUR MOVE
Pick one. Reply by Friday.
You just learned:
— The defender’s problem isn’t capability, it’s permission. Hugging Face had to self-host a Chinese model to read its own logs.
— Nvidia runs a 30-company security alliance the three biggest labs aren’t in — and a $250bn guarantee keeping the largest of them building.
— Your old prompts are a tax. Opus 5 charges you for instructions it stopped needing.
Pick one before Friday. Run the Refusal Pre-Mortem, install LM Studio and point one real task at a local model, or spend twenty minutes grepping your prompts for verify.
⚠ PRODUCTION NOTE — DELETE BEFORE SEND Issue #145 promised readers the split of their replies would be published here, and that the most-requested workload would get a purpose-built prompt in #147. Drop the real numbers into the paragraph below, then delete this box. Example: ‘Last week’s split: 41% Workload Audit, 34% the OpenRouter test, 25% the detector decision. Winner — the migration question. #147 gets a prompt built for it.’ |
Then reply with the one you picked. One line is enough. I read every response, and last week’s replies are why this issue exists in the shape it does.
—
R. Lauritsen
EDITOR · iPROMPT
P.S. Reply first — one line is enough. If you want the longer argument afterwards, the deep dive has the full breach timeline and the permission map behind it. Read it →
iPrompt
PUBLISHED BY FRONTWAVE MEDIA LTD · LIMASSOL, CYPRUS
Own AI deployment, grow your career
Making AI actually work day to day is becoming its own job. Hear from three people doing it: Simone Santiago Broad (Yoco), Yelva Espinoza (Zumba Fitness), and Fin's Dave Lynch. They share what the role really looks like, how it came to exist, the skills worth hiring for, and the challenges they're tackling right now. Watch the full conversation on demand.


