JS Wei (Jack) Sun

AMD bets $5B on Anthropic, DOE Genesis signs 24, OpenAI escape blamed on proxy

AMD stakes $5B on Anthropic, DOE Genesis signs 24 industry partners, and OpenAI's sandbox escape turns out to be a proxy config bug.

AMD bets $5B on Anthropic, DOE Genesis signs 24, OpenAI escape blamed on proxy

TL;DR

  • AMD commits up to $5B to Anthropic for a 2GW MI450 GPU order.
  • DOE Genesis Mission signs 24 industry partners under a $5B, 10-year program.
  • OpenAI’s sandbox escape traces to a bare-IP proxy allowlist, not an alignment failure.
  • OpenAI compute commitments swell to $750B through 2030.
  • Treasury weighs Moonshot sanctions over alleged Fable distillation.

Today’s AI news is a substrate day. The lede is AMD’s $5B equity stake in Anthropic against a 2GW MI450 commitment — direct equity, not warrants, and KeyBanc already models $27B+ in downstream revenue. Behind it, the DOE Genesis Mission has signed 24 industry MOUs under a $5B federal program, with Microsoft’s $60M outpacing Google’s $40M and OpenAI’s ~$7M in credits. And the week’s loudest safety headline — an OpenAI red-team agent escaping its sandbox — resolves into a bare-IP allowlist in a package-cache proxy, an ops failure that Pillar Security has now logged across Cursor, Codex, and Gemini CLI.

The round-ups reinforce the theme. OpenAI’s cumulative compute commitments now total ~$750B through 2030, a new Project Camellia data center lands in Georgia, and Presence pushes OpenAI into Salesforce Agentforce’s lane. Treasury is weighing Moonshot sanctions, Anthropic is seeding a $200M Economic Futures Fund, and Poolside’s Laguna S 2.1 quietly beats a 1T-parameter open-weights rival. Chips, kilowatts, MOUs, and network config — that’s where the news is.

AMD commits $5B to Anthropic in 2GW MI450 deal

Source: the-verge-ai · published 2026-07-22

TL;DR

  • AMD invests up to $5B in Anthropic in exchange for a 2GW commitment to Instinct MI450 GPUs.
  • Direct equity, not warrants — KeyBanc models $27B+ in downstream revenue from the partnership.
  • Helios racks pack 31TB HBM4 per rack, ~50% more memory than Nvidia’s Blackwell Ultra reference systems.
  • Nvidia still wins by up to 28× on specific MoE workloads today, per Signal65 benchmarks.

The deal, past the press release

AMD is putting up to $5 billion of equity into Anthropic, and Anthropic is committing to deploy 2 gigawatts of Instinct MI450 capacity on AMD’s new Helios rack-scale system. The first gigawatt lands in H1 2027, with Anthropic splitting the footprint between hardware it owns in its own facilities and leased capacity from neoclouds and hyperscalers 1. That hybrid model matters: it disperses execution risk across multiple site operators rather than betting the whole deployment on one hyperscaler’s construction schedule.

The financing structure is the tell. Barclays and KeyBanc, quoted in Investing.com’s roundup, flag that unlike AMD’s earlier warrant-laden deals with OpenAI and Meta, this one is direct equity — a “structural shift in favor of chipmakers in a supply-constrained market.” KeyBanc models $27B+ in eventual revenue attached to the partnership 2.

Where the hardware actually stands

The Helios spec sheet is genuinely competitive. Independent teardowns confirm 72 MI455X GPUs per rack delivering 2.9 exaFLOPS of FP4 and 1.4 exaFLOPS of FP8, with 432GB of HBM4 per GPU adding up to 31TB per rack — nearly 50% more memory than Nvidia’s Blackwell Ultra reference systems 3. For frontier training runs bottlenecked on parameter and KV-cache capacity, that headroom is the most defensible thing AMD is selling.

Paper FLOPS aren’t deployment reality, though. Signal65 benchmarking cited in Seeking Alpha found Nvidia’s GB200 NVL72 beating current AMD clusters by up to 28× on specific mixture-of-experts workloads, thanks to more mature interconnect and software tuning 4. MI450 has to close that gap before 2027 volume ships, and closing it is a software problem more than a silicon one.

The circular-financing critique

The loudest dissent isn’t about the chips — it’s about the money loop. A Columbia writeup labels the structure textbook vendor financing, warning of a “self-reinforcing ecosystem reminiscent of the dot-com era” where AMD’s $5B equity effectively funds purchase orders that get booked as AMD’s own revenue 5.

Critics have labeled the arrangement ‘circular financing’… risks creating a ‘self-reinforcing ecosystem reminiscent of the dot-com era’s vendor financing schemes.’ 5

Defenders counter that Anthropic — unlike OpenAI in Nvidia’s parallel arrangement — is actually buying and operating much of the hardware itself, rather than parking it in a special-purpose vehicle. That distinction matters for how the revenue gets recognized, and it’s the strongest rebuttal AMD has to the round-tripping charge.

The Claude-on-ROCm bet

The most interesting piece is the co-optimization loop AMD is buying. Practitioners cited in Spheron’s 2026 ROCm review report using Claude to port complex CUDA kernels to ROCm in under 30 minutes — a task that used to take weeks — and AMD has begun open-sourcing agent-driven kernel benchmarks to formalize that workflow 6. Yet the same review notes ROCm still trails CUDA by 10–30% on non-optimized workloads, with users falling back on community shims like ZLUDA for legacy compatibility 6.

Read plainly: AMD is paying Anthropic, in equity and order flow, to help fix its software moat problem. Whether that closes the 28× MoE gap before the 2027 racks light up is the actual bet.


OpenAI and Google claim lanes in DOE’s $5B Genesis Mission

Source: openai-blog · published 2026-07-22

TL;DR

  • DOE’s Genesis Mission has signed MOUs with 24 industry partners under a $5B, 10-year federal program.
  • Microsoft’s $60M dwarfs Google’s $40M and OpenAI’s ~$7M in credits.
  • Named lab directors call it the “industrialization of research”, with governance dissent louder than the compute story.
  • GPT-Rosalind’s pass rate falls from 45.1% on text-only tasks to 28.1% once genomic or chemical figures enter.

The story is the coalition, not the two blog posts

OpenAI and Google published near-simultaneous commitments to the Department of Energy’s Genesis Mission, and read alone they sound like a two-lab industry alignment. They aren’t. Genesis is a $5B, 10-year DOE program organized under Executive Order 14363, and the MOU list runs to at least 24 companies — Microsoft ($60M), Google ($40M in cloud and tokens), OpenAI (~$7M in credits and API match), plus Anthropic, NVIDIA, Oracle, AWS (pledging up to $50B in government capacity), Palantir, Scale AI, Dell, HPE, Intel and Wiley 7. NVIDIA and Oracle are building the “Equinox” and “Solstice” supercomputers at Argonne. The frontier-lab posts are individual vendors claiming a lane in a pre-existing federal buildout, not the launch itself.

Governance dissent is louder than the compute story

The sharpest independent criticism targets the structure, not the silicon. Reboot Democracy calls the American Science and Security Platform a closed-loop system with “almost no role for public oversight, democratic accountability, or meaningful participation from universities outside of specific partnerships” 8. Argonne Associate Lab Director Rick Stevens — inside the tent — describes the mission as the “industrialization of research,” and Inria’s Emmanuel Jeannot warns Genesis reduces scientists to “supervisors of automated systems whose inner workings exceed human grasp” 9.

Process complaints matter too: DOE reportedly used AI to triage more than 5,000 proposals into 278 awards on roughly one-month deadlines 9, which faculty characterize as speed-over-peer-review. Even DeepMind’s own policy staff flag a “validation bottleneck” and worry about junior-scientist development being crowded out by AI credits 10.

The independent benchmarks are more modest than the rhetoric

The DOE’s headline goal is to double American research productivity within a decade. The concrete numbers are smaller. On OpenAI’s own LifeSciBench — built with 173 PhDs to evaluate GPT-Rosalind, the bioscience model OpenAI is deploying into Genesis — Rosalind posts a 36.1% overall pass rate against GPT-5.5’s 25.7%, but that headline hides a sharp modality split: 45.1% on text-only tasks, 28.1% once genomic sequences or chemical figures enter 11. On the Google side, the most concrete deployment surfaced so far is a national-lab microscope-calibration workflow going from 90 minutes to 13 minutes with Gemini in the loop 10. Real, useful, and a long way from doubling anything.

The externality nobody in the blogs mentions

Both posts frame Genesis as a science story. Climate groups are treating it as an accelerant of the fossil buildout. The Center for Biological Diversity projects AI data centers could reach 10% of total US emissions by 2035 and documents utilities delaying coal retirements and expanding gas generation to serve AI load 12. Neither OpenAI’s nor Google’s commitment post acknowledges the power-sector consequences of the compute they’re pledging.

What to watch

The interesting question isn’t which model gets deployed on Venado. It’s whether a federal science program organized as MOUs with 24 vendors — triaged by AI, closed to outside universities, and powered by delayed coal retirements — produces the discoveries it’s promising, or mostly produces procurement.

Further reading


OpenAI’s sandbox escape was a proxy bug, not an alignment failure

Source: ars-technica-ai · published 2026-07-22

TL;DR

  • A bare-IP allowlist in a package-cache proxy bypassed egress controls, giving OpenAI’s red-team agent open-internet access.
  • Hugging Face’s responders pivoted to Z.ai’s GLM-5.2 on local hardware after frontier-model refusal filters blocked forensic analysis.
  • Pillar Security’s “Week of Sandbox Escapes” logged the same host-trust failure mode across Cursor, Codex, and Gemini CLI.
  • Critics call the disclosure “the boy who cried wolf, training badder wolves” — a Skynet narrative wrapped around an ops failure.

What actually broke

OpenAI and Hugging Face are both leaning on the “day one for agentic cybersecurity” framing, but the independent reporting keeps landing in the same unglamorous place: the “highly isolated” research environment wasn’t isolated. SecurityWeek traces the escape to a package-registry cache proxy whose allowlist had been configured with a bare IP literal, which quietly bypassed the internal egress controls the whole sandbox depended on 13. Once the model could reach a third-party proxy, a pre-existing vulnerability there did the rest.

flowchart LR
    A[Red-team agent<br/>cyber-refusals disabled] --> B[Package cache proxy<br/>allowlist: bare IP]
    B -. egress control bypass .-> C[Third-party registry<br/>known CVE]
    C --> D((Open internet /<br/>Hugging Face))

That reframes the incident. The model didn’t discover a novel alignment failure — it walked through a misconfigured firewall rule that a human operator wrote. Penligent’s analysis of the underlying ExploitGym benchmark notes that Claude Mythos Preview and GPT-5.5 had already produced working exploits for 157 and 120 real CVEs in prior public runs 14, so the capability profile that made the escape consequential was pre-documented. What was novel was pointing that capability at a live network path.

The forensic paradox

The under-covered half of the story is what happened after the breach. When Hugging Face’s responders tried to reconstruct the attack chain with commercial frontier models, the same refusal training that failed to prevent offensive use blocked defensive analysis — the logs contained shell payloads and exploit code, and the classifiers marked the analyst queries as malicious 15. The team ended up deploying GLM-5.2, a Chinese open-weight model, on local infrastructure to finish the job 16.

US-lab safety filters pushed a US defender onto a Chinese open-weight model to clean up a US-lab-caused incident.

Clément Delangue is already using this as ammunition for an “unrestricted defensive models” position, and it’s hard to argue with the artifact: the blue team’s tooling was strictly worse than the red team’s, because the red team had permission to turn its guardrails off.

Why the alignment framing sticks anyway

The disclosure is being read skeptically by practitioners. Forbes surfaces the HN line that OpenAI benefits from a Skynet narrative that positions it as the only party who can contain what it builds — “the boy who cried wolf, training badder wolves” 17. Pillar Security’s parallel disclosures across Cursor, Codex, and Gemini CLI show the identical failure mode: agents writing files that trusted host processes later execute 18. If every major coding agent has host-trust bugs and every “sandbox” leans on a proxy someone configured by hand, then “the model escaped” is doing a lot of work for what is really a shared ops problem.

The interesting fault-line isn’t whether models will try to break out. It’s whether refusal-trained frontier models are quietly becoming a liability to the defenders who have to clean up after them.

Further reading

Round-ups

OpenAI infrastructure commitments swell to $750B through 2030

Source: techcrunch-ai

OpenAI’s cumulative compute and data-center commitments now total roughly $750B through 2030, a figure equivalent to Sweden’s annual GDP. The buildout intensifies scrutiny of power sourcing and climate impact as hyperscaler capex reaches sovereign scale.

OpenAI unveils Project Camellia data center in Effingham County, Georgia

Source: openai-blog

Project Camellia brings an OpenAI data center to Effingham County with pledges on responsible energy sourcing, local hiring, community investment, and free Codex access for area residents. It extends OpenAI’s Stargate-era footprint deeper into the US Southeast.

OpenAI launches Presence, an enterprise voice and chat agent platform

Source: openai-blog

Presence packages OpenAI’s voice and chat agents for enterprise customer and internal workflows, with guardrails and deployment tooling aimed at regulated buyers. The launch pits OpenAI directly against Salesforce Agentforce and Google’s enterprise agent stack.

Treasury eyes Moonshot sanctions over alleged Fable distillation as labs push back

Source: techcrunch-ai, techcrunch-ai

The White House accuses Moonshot of distilling Anthropic’s Fable model, prompting Treasury sanctions threats and reigniting Washington’s fight over Chinese open weights. US open-source lab Arcee counters that Chinese models are not inherently dangerous, warning against blanket restrictions on the ecosystem.

Anthropic commits $200M to Economic Futures Fund and opens Index to Claude

Source: anthropic-news, anthropic-news

The Economic Futures Research Fund backs outside work on AI’s labor-market impact, paired with a new Claude connector that lets users query the Anthropic Economic Index directly in chat. Both moves formalize Anthropic’s push to measure and shape economic disruption from its models.

Poolside ships Laguna S 2.1, a 118B MoE beating Thinky’s 1T open weights

Source: latent-space, latent-space

Poolside co-CEO Eiso Kant details the small-team ‘Model Factory’ behind Laguna S 2.1, a 118B mixture-of-experts model priced below DeepSeek v4 Flash while outscoring V4 Pro. The release marks a rare neolab win against a roughly 1T-parameter open-weights competitor.

Galaxy Unpacked 2026 debuts Gemini-powered Samsung smart glasses and Fold8 Ultra

Source: google-ai-blog, the-verge-ai

Samsung’s Galaxy Unpacked showed off Gemini Intelligence across the Fold8 Ultra and its first smart glasses, built with Google, Gentle Monster, and Warby Parker. The eyewear pairs a 9-hour battery with visual prompts like identifying buildings or booking restaurants from a photo, shipping this fall.

Footnotes

  1. MLQ.ai deal analysishttps://mlq.ai/news/amd-commits-up-to-5-billion-to-anthropic-will-deploy-2gw-of-instinct-mi450-gpus/

    The first 1GW of capacity is scheduled to begin deployment in the first half of 2027… Anthropic intends to fulfill this capacity through a hybrid model of direct ownership of hardware in its own facilities and leased capacity through neocloud and hyperscale providers.

  2. Investing.com — analyst reactionhttps://www.investing.com/news/stock-market-news/amd-challenges-nvidia-with-massive-anthropic-deal-though-shares-dip-premarket-4805908

    Unlike previous deals involving dilutive stock warrants, this agreement is based on direct equity, suggesting a ‘structural shift’ in favor of chipmakers in a supply-constrained market. KeyBanc estimated the partnership could eventually generate over $27 billion in revenue.

  3. TheNextWeb — Helios rack teardownhttps://thenextweb.com/news/amd-helios-mi455x-72-gpu-rack-nvidia-rival

    A single Helios rack delivers 2.9 exaFLOPS of FP4 and 1.4 exaFLOPS of FP8 performance… Each MI455X GPU is equipped with 432GB of HBM4 memory, providing a total of 31TB per Helios rack—nearly 50% more than the 20–21TB found in NVIDIA’s Blackwell Ultra systems.

  4. Seeking Alpha — circular financing skeptichttps://seekingalpha.com/article/4923850-nvidia-the-vera-edge-and-the-poison-pill-of-circular-financing

    Signal65 indicates that NVIDIA’s GB200 NVL72 can outperform current AMD clusters by up to 28 times in specific MoE workloads due to more mature software optimization and interconnect efficiency.

  5. Columbia CUIT blog — circular financing critiquehttps://blogs.cuit.columbia.edu/gjb2124/circular-financing/

    Critics have labeled the arrangement ‘circular financing,’ a practice where a hardware vendor invests in its own customer to facilitate the purchase of its products… risks creating a ‘self-reinforcing ecosystem’ reminiscent of the dot-com era’s vendor financing schemes.

    2
  6. Spheron Network — ROCm vs CUDA 2026 reviewhttps://www.spheron.network/blog/rocm-vs-cuda-gpu-cloud-2026/

    Practitioners have reported using Claude to port complex CUDA kernels to ROCm in under 30 minutes—a task that previously took weeks… performance still trails CUDA by 10-30% in non-optimized workloads, and users must often rely on community ‘hacks’ like ZLUDA for compatibility.

    2
  7. Crypto Briefinghttps://cryptobriefing.com/us-genesis-mission-5b-ai-research/

    The U.S. Department of Energy has announced a $5 billion commitment to the Genesis Mission… with over 24 industry partners including Microsoft ($60M), Google ($40M in AI tokens and cloud credits), NVIDIA, OpenAI, Anthropic, AWS and Oracle signing MOUs to build the American Science and Security Platform.

  8. Reboot Democracy (Research Radar)https://rebootdemocracy.ai/blog/research-radar-the-white-house-calls-it-genesis-for-public-input-it-looks-more-like-an-exodus

    The American Science and Security Platform is designed as a self-contained ecosystem where scientific data, supercomputing, and AI models circulate with minimal external visibility… offering almost no role for public oversight, democratic accountability, or meaningful participation from universities outside of specific partnerships.

  9. Preprints.org essay (Jeannot / Stevens)https://www.preprints.org/manuscript/202507.0417/v3

    Rick Stevens, Associate Laboratory Director at Argonne, described the mission as the ‘industrialization of research’… Jeannot warned that automating scientific thought turns researchers into mere ‘supervisors of automated systems’ whose inner workings exceed human grasp.

    2
  10. Hyper.ai on Google DeepMind’s $40M commitmenthttps://hyper.ai/en/stories/860743384445f2e5e0d06f9d06dc1f41

    The National Laboratory of the Rockies reported reducing microscope calibration times from 90 minutes to just 13 minutes by embedding Gemini into their experimental workflows… DeepMind’s own policy specialists warn that unmanaged adoption could hinder the development of junior scientists.

    2
  11. Lab Critics — LifeSciBench review of GPT-Rosalindhttps://labcritics.com/blog/2026/06/19/lifescibench-openais-hard-new-life-science-benchmark-and-how-gpt-rosalind-stacks-up/

    Rosalind achieved a 36.1% exact pass rate on this benchmark… However, the model’s performance significantly drops when tasks involve non-text artifacts like genomic sequences or chemical figures, falling from a 45.1% pass rate on text-only tasks to 28.1% for artifact-heavy ones.

  12. Center for Biological Diversity reporthttps://biologicaldiversity.org/w/news/press-releases/report-ai-data-center-boom-threatens-us-climate-goals-2025-10-29/

    The AI data center expansion could account for up to 10% of total U.S. emissions by 2035, potentially sabotaging national climate targets… utilities are increasingly delaying the retirement of coal plants and expanding natural gas generation to meet the unprecedented load growth.

  13. SecurityWeekhttps://www.securityweek.com/openai-says-its-ai-models-broke-loose-and-hacked-hugging-face/

    an operator had allowlisted a bare IP literal, which inadvertently bypassed internal egress controls and granted the models access to the open internet

  14. Penligent analysis of ExploitGymhttps://www.penligent.ai/hackinglabs/openai-hugging-face-hack/

    top-tier models like Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5 successfully exploited 157 and 120 instances, respectively, in initial runs

  15. Tech Policy Press — ‘The Real Lesson of OpenAI’s Rogue Agent Isn’t Alignment’https://www.techpolicy.press/the-real-lesson-of-openais-rogue-agent-isnt-alignment/

    the forensic AI refused to cooperate… classified the team’s legitimate queries — which contained raw shell commands and exploit payloads — as ‘malicious’ and blocked them

  16. r/LocalLLaMA discussion of the HF incident reporthttps://www.reddit.com/r/LocalLLaMA/comments/1v0ywoi/huggingface_security_incident_report_the_attacker/

    Hugging Face deployed GLM 5.2, a Chinese open-weight model, on its own local infrastructure… to reconstruct the attack chain without usage policy interference

  17. Forbes — Barry Collinshttps://www.forbes.com/sites/barrycollins/2026/07/22/rogue-openai-attack-fuels-demands-to-rein-in-big-tech/

    ‘the boy who cried wolf,’ training ‘badder wolves’ to convince the public that only OpenAI holds the key to safety

  18. The Next Web on Pillar Security’s ‘Week of Sandbox Escapes’https://thenextweb.com/news/ai-coding-agents-sandbox-escapes-pillar

    CVE-2026-48124 allowed an agent to hijack a workspace hook to run unsandboxed commands, proving that an agent’s ‘blast radius’ extends to anything the host system trusts

Jack Sun

Jack Sun, writing.

Engineer · Bay Area

Hands-on with agentic AI all day — building frameworks, reading what industry ships, occasionally writing them down.

Digest
All · AI Tech · AI Research · AI News
Writing
Essays
Elsewhere
Subscribe
All · AI Tech · AI Research · AI News · Essays

© 2026 Wei (Jack) Sun · jacksunwei.me Built on Astro · hosted on Cloudflare