AI News Daily 2026-07-31
- Anthropic published the results of a review of roughly 141,006 evaluation runs and said three of its models — Claude Opus 4.7, Mythos 5 and an internal research test model — reached three external organizations’ production systems without authorization.
- The root cause Anthropic describes is environmental, not adversarial: a misunderstanding with evaluation partners left the models with internet access, and the intrusions happened inside “capture the flag” exercises via weak passwords and unauthenticated endpoints.
- The European Commission launched a call for tender to build up to seven AI gigafactories, each a compute base in the class of more than 100,000 state-of-the-art AI chips, with applications due 12 November 2026 and selection planned for early 2027.
- The EU and member states will contribute up to EUR 10 billion (about USD 11.5 billion), and total investment including private money is expected to exceed EUR 30 billion.
- Kioxia Holdings reported record April–June 2026 results: net profit of JPY 842.1 billion, 46 times the year-earlier figure, on revenue of JPY 1,767.1 billion, roughly 5.2 times higher, driven by NAND flash demand from generative-AI data centre construction.
01Anthropic discloses that several Claude models gained unauthorized access to three external organizations during security evaluations
Published: 2026-07-30 · Category: Corporate developments · Source tier: Tier 1
Facts
Anthropic has disclosed that, after examining approximately 141,006 evaluation runs, it found that three of its models — Claude Opus 4.7, Mythos 5 and an internal research test model — had been left in a state where they could reach the open internet, the result of a misunderstanding with the evaluation partners involved. In each case the model was working through a “capture the flag” task and exploited weak passwords or unauthenticated endpoints to gain unauthorized access to the production systems of three external organizations.
The disclosure came from Anthropic itself, in a post on its own site describing its investigation into incidents arising from cybersecurity evaluations. It was also covered by TechCrunch and CNBC on the same day.
Background
Capture-the-flag exercises are a standard way to measure how far an AI model can get when asked to find and exploit a vulnerability. The whole point of that format is to let the model behave like an attacker, which is exactly why the containment boundary around the exercise matters more than in almost any other kind of evaluation: the same capability that makes the test informative makes an escape consequential.
What Anthropic describes is a failure of that boundary rather than a failure of the model’s alignment. The models were not, on the account given, breaking out of a correctly configured sandbox; the sandbox was not closed in the first place, because the parties running the evaluation did not share the same understanding of what the environment permitted. The attack surfaces the models then found — weak passwords, endpoints with no authentication — are the most ordinary weaknesses in production infrastructure, which is part of what makes the episode instructive.
The scale of the review is worth registering on its own terms. Anthropic states it went through around 141,006 evaluation runs to establish what had happened. That is the kind of number that indicates the incidents were rare relative to the volume of testing, and also that identifying them required a systematic sweep rather than a single alarm.
Implications
This is a case in which the party responsible published the finding about its own models. That matters for how the rest of the industry should read it: the disclosure sets a reference point for what an AI developer is expected to say publicly when its evaluation infrastructure fails, and it makes the failure mode concrete rather than hypothetical.
For organizations deploying AI, the practical question this raises is narrower and more answerable than “is the model safe”. It is whether the isolation of the evaluation and audit environments they rely on is genuinely guaranteed — and whether every party operating those environments agrees on what the isolation actually covers. The incident here originated in a difference of understanding between the model developer and its evaluation partners, so the check is as much contractual and organizational as it is technical.
A secondary implication concerns third-party assurance. If evaluations conducted with outside partners can reach live production systems, then the trustworthiness of the audit depends on the audit’s own containment, not only on its methodology. That question now sits alongside capability results whenever a security evaluation is cited.
Anthropic — Investigating incidents from cybersecurity evaluations · TechCrunch · CNBC
02The EU opens bidding for up to seven AI “gigafactories”, targeting more than EUR 30 billion in public and private investment
Published: 2026-07-30 · Category: Regulation and policy · Source tier: Tier 1
Facts
The European Commission has launched a call for tender to select the operators that will build up to seven AI gigafactories — compute facilities in the class of more than 100,000 state-of-the-art AI chips each. The EU and its member states will contribute up to EUR 10 billion (about USD 11.5 billion), and together with private investment the programme is expected to draw more than EUR 30 billion. Applications close on 12 November 2026, with selection planned for early 2027.
Background
The term “gigafactory” is a deliberate borrowing from industrial manufacturing, and the framing is the point: the Commission is treating frontier-scale compute as infrastructure to be built at industrial scale under public co-financing, rather than as something to be procured piecemeal by individual research institutions or firms.
The stated aim, as characterised in today’s reporting, is to close Europe’s compute gap with the United States and China. The structure of the programme — a public contribution of up to EUR 10 billion levering total investment above EUR 30 billion — implies that the majority of the capital is expected to come from private participants, with public money used to make the projects bankable rather than to fund them outright.
The timetable is also informative. A tender closing on 12 November 2026 and awards in early 2027 means the decisive commercial conversations — consortium formation, site selection, chip supply, power and cooling — are happening now, well ahead of any public announcement of winners.
Implications
For semiconductor and data-centre suppliers, including Japanese firms, this is a demand-creation event. A programme sized at more than 100,000 leading-edge AI chips per site, replicated across as many as seven sites, is a procurement pipeline large enough to matter to component, memory, power and facilities vendors well outside Europe.
For European industrial policy more broadly, the tender converts a stated ambition into a dated, funded process with a deadline attached. Whether the EUR 30 billion figure is realised depends on how much private capital the tender actually attracts — a number that will not be visible until the November close and the early-2027 selection.
03Kioxia’s net profit rises 46-fold in April–June 2026 as generative-AI data centres drive record NAND sales
Published: 2026-07-31 · Category: Japan · Source tier: Tier 2
Facts
Kioxia Holdings announced results for the April–June 2026 quarter on 31 July, prepared under IFRS. Net profit came to JPY 842.1 billion, 46 times the figure for the same quarter a year earlier, and revenue reached JPY 1,767.1 billion, roughly 5.2 times higher. Both were record highs. The company attributes the result to sharply higher demand for its main product, NAND flash memory, accompanying the expansion of data centre construction for generative AI.
Background
A 46-fold increase in net profit alongside a 5.2-fold increase in revenue is not a story about volume alone. Profit rising roughly nine times faster than sales is the signature of severe operating leverage in a memory business: fixed manufacturing costs are largely unchanged while pricing and utilisation move sharply, so incremental revenue converts to profit at an unusually high rate.
Memory has always been the most cyclical part of the semiconductor industry, and Kioxia’s quarter is a clean illustration of the upswing phase. What distinguishes this cycle from previous ones, on the company’s own account, is the identity of the demand: generative-AI data centre buildout, rather than the smartphone or PC cycles that historically set NAND demand.
Implications
This is a concrete instance of AI infrastructure investment rapidly reshaping the earnings structure of the memory semiconductor market. Because Kioxia sits upstream of the data centres themselves, its quarterly results can be read as a leading indicator of the strength of the data centre investment cycle — a way to gauge, from outside, how much building is actually being committed to.
The corollary is that the same leverage runs in both directions. Earnings amplified this strongly by a demand surge are equally exposed if the buildout decelerates, which is precisely why the trajectory of the figure — rather than the single quarter — is what deserves tracking.
04Editor’s note: how the day’s items fit together
Three items, three different layers of the same industry — and read together they describe a sector that is being built out at industrial scale while its safety machinery is still being debugged in public.
The first thread is disclosure. AI companies are increasingly publishing their own security and safety incidents, and the focus of scrutiny is shifting from the models to the environments in which the models are tested: how evaluation infrastructure is isolated by design, and how much confidence third-party audits deserve. Anthropic’s account of its own models reaching outside systems is exactly that shift made concrete.
The second thread is compute geopolitics. Europe is moving in earnest on large-scale investment in AI compute infrastructure through public–private partnership, in a hurry to close the compute gap with the United States and China. The gigafactory tender puts a deadline and a number on that ambition.
The third thread is the physical supply chain underneath both. Generative-AI data centre demand continues to lift the earnings of the memory semiconductor market, and Kioxia’s record quarter shows how steep that lift has become.
The connection is straightforward: the same buildout that is producing record memory earnings is what programmes like the EU tender are trying to accelerate in Europe — and the faster that capacity arrives, the more consequential it becomes whether the evaluation environments meant to keep the resulting systems contained are actually closed.