AI Weekly: August 23–29, 2026 — Over 100 Companies Warned the Public That AI-Driven Cyberattacks Are Coming Within Months. The Same Week, Anthropic Gave Agents Control of Lab Robots, OpenAI's Own Code Revealed an Always-On Agent It Won't Confirm, and Nvidia Priced a $30B Stake in Perplexity Off a Record Quarter.

1. NVIDIA POSTED A RECORD $96.2 BILLION QUARTER THE SAME WEEK IT WAS PRICING A $30 BILLION STAKE IN PERPLEXITY

On August 23, The Information reported that Nvidia is in talks to invest in Perplexity as part of a funding round that would value the AI search company above $30 billion — more than 50% higher than the roughly $20 billion valuation Perplexity secured about a year earlier. The interest tracks Perplexity's own growth: its annualized revenue has climbed above $750 million, up from less than $250 million at the start of the year, helped by Perplexity Computer, a cloud-based agent that automates computer-based tasks for professional users. Three days later, on August 26, Nvidia reported fiscal second-quarter revenue of $96.2 billion, up 106% year over year, beating Wall Street's $92.37 billion estimate, and guided to $108 billion for the current quarter — a number itself above analyst consensus. CEO Jensen Huang told investors AI had "reached its inflection point." Read together, the two stories describe the same shift: Nvidia is no longer just the landlord renting out the compute other companies build on. A company running a record quarter off chip sales is now using that position to buy equity further up the stack, in the search and agent layer sitting directly on top of its own hardware.

2. SOFTBANK SOUGHT A SECOND $10 BILLION LOAN AGAINST ITS OPENAI STAKE — 22 DAYS AFTER THE FIRST ONE CLOSED

SoftBank's financing of its OpenAI position kept compounding this week. The company is already carrying a $40 billion bridge loan taken out earlier this year to help fund a planned $65 billion total commitment to OpenAI, paid in tranches through October, and on August 6 it secured a separate $10 billion, two-year margin loan — priced around 275 basis points over SOFR, arranged by Mizuho — collateralized by its OpenAI stake. On August 26, Bloomberg reported SoftBank is in discussions with banks to issue up to $20 billion in dollar- and euro-denominated bonds, as soon as September, specifically to refinance that $40 billion bridge loan. Then on August 28, Bloomberg reported SoftBank is seeking another $10 billion loan against the same OpenAI stake — 22 days after closing the first loan of identical size against the identical collateral. Each new facility is described as partly repaying the one before it, which means SoftBank is now financing debt with debt to hold a stake in a company that has not gone public and does not disclose profitability. None of the four facilities disclosed this year, on their own, resolves what the other three were meant to cover.

3. OVER 100 COMPANIES TOLD THE PUBLIC AI-DRIVEN CYBERATTACKS ARE COMING. NONE OF THEM PROPOSED SLOWING WHAT MAKES THAT POSSIBLE

On August 27, more than 100 companies — CNBC counted 116 signatories, other outlets counted as many as 118 — signed "A Call for Collective Action on Cyber Defense," a letter spanning AI and cloud providers (OpenAI, Anthropic, Google, Microsoft, Amazon Web Services), cybersecurity firms (CrowdStrike, Palo Alto Networks, Okta, Proofpoint), semiconductor makers, and financial institutions (Citi, Capital One, Mastercard, Visa, US Bank, Zurich). The letter states that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," and warns that hospitals, water treatment plants, and the infrastructure that powers the internet are at risk. What the letter asks for is coordination: shared threat intelligence, faster patching, better default security practices across the private and public sectors. What it does not ask for, from any of its own AI-lab signatories, is a pause or a slowdown in the model capability gains the letter itself names as the source of the coming escalation. The companies best positioned to know how fast that risk is growing are the same companies building the thing that grows it.

4. ANTHROPIC GAVE ITS MODELS DIRECT CONTROL OF MICROSCOPES, ROBOTIC ARMS, AND A QUANTUM LAB'S LASERS

On August 27, Anthropic opened a research preview of the Model Hardware Standard (MHS), a model-agnostic specification, compatible with the Model Context Protocol, that lets AI agents coordinate physical lab equipment — microscopes, liquid handlers, robotic arms — directly, cutting integration work Anthropic says used to take weeks or months down to hours. Genentech used MHS to automate a protein-assay procedure across a liquid handler, a robotic arm, and a plate reader. QuEra Computing, which builds quantum computers, used it to let an AI agent recover a laser's precise operating frequency without human intervention, succeeding 99.3% of the time. The preview is limited to a small group of research labs and manufacturers for now; Anthropic says it intends to make MHS public eventually but has not committed to a date. It is Anthropic's first real move from AI agents that act inside software into AI agents that act on physical instruments in someone else's lab — disclosed, this time, with the company's name attached and a stated intent to keep it limited until it's ready.

5. OPENAI'S OWN PUBLIC CODE SHOWED IT BUILDING AN ALWAYS-ON CODEX AGENT IT WON'T CONFIRM EXISTS

Wired reported on August 27 that a pull request merged into OpenAI's public Codex GitHub repository the day before, August 26, added a "persistent" option to the coding agent's reasoning-effort settings — letting Codex keep working on a task indefinitely, instead of stopping after each prompt, until a user manually puts it to sleep. A companion setting would let users dial down how much reasoning the agent performs during those extended sessions, to manage token cost. For now, the feature is only half-real: the persistent option is stored in local configuration on a user's machine, but the value the client actually sends to OpenAI's API is hardcoded to "disabled." OpenAI has not announced the feature, and a company representative told Wired it is "trying the capability out" with no near-term plan to release it. Unlike Anthropic's hardware preview the same week, this one has no name, no safety framing, and no acknowledgment beyond a spokesperson's comment prompted by outsiders reading the company's own commit history — the only reason the public knows OpenAI is testing a standing, self-directed version of its coding agent at all.

Run the week end to end and the direction is the same in every story, even though the disclosures aren't. Nvidia turned a record quarter into a bigger stake in the layer above its own chips. SoftBank turned one loan into a second loan and a bond sale, still short of resolving the first one. Anthropic told the public, on its own terms and in advance, that its models can now touch physical lab equipment; OpenAI's equivalent expansion — an agent built to keep running with nobody watching — surfaced only because someone outside the company went looking through its code. And in between, more than 100 of the companies making all of this possible spent August 27 warning everyone else that AI-driven attacks are coming, without once suggesting that the fastest way to slow that risk down might be to slow down what they were doing the rest of the week.