Two things happened this week that are easy to describe badly. In a Stanford and Arc Institute lab, a language model that reads genomes rather than text designed sixteen viruses that had never existed, and they worked. In Grimes County, Texas, Elon Musk committed $16.8B to what he says will be the largest building on Earth. Both stories are being told as inevitabilities, and both are better understood as bets on where the real bottleneck sits — in biology, on whether a screening system designed to recognise the familiar can cope with the genuinely new; in silicon, on whether the specialised supply chain that built the AI boom has become the thing holding it back. Underneath them, a quieter shift: Washington has started policing compute-hours instead of chips, OpenAI has stopped metering its free tier, and a worm spent four hours turning developers' own AI assistants against them.
Sixteen viruses that never existed
A team led by Brian Hie at Stanford and the Arc Institute, with graduate student Samuel King, used the Evo genome language models to write complete bacteriophage genomes from scratch. The result was published in Science on 6 August. Evo is not a chatbot that suggests edits; it is trained on raw genetic sequence and generates genomes directly. The team produced hundreds of thousands of candidates, synthesised around 300 of them in the lab, and recovered sixteen that assembled into functioning phages — modelled on ΦX174, a small, exhaustively studied virus that infects E. coli. Some of the designs infected E. coli as effectively as the wild-type virus or better. Combined into a cocktail, they killed two E. coli strains that had already evolved resistance to a natural phage.
The qualifier belongs in the same sentence as the claim: these are bacteriophages. They infect bacteria. They do not infect humans, animals or plants, and the models' training data deliberately excluded viruses that do. "AI created a virus" is not a fair description of what happened without that context attached.
With the context attached, it is still significant, and the disagreement about why is worth listening to. One camp points out that phage genomes are among the smallest and most tractable targets in synthetic biology, that ΦX174 has been assembled synthetically since 2003, and that generating a working variant of an extremely well-characterised virus is an achievement of degree rather than kind. The other camp — including Simon Clarke at the University of Reading, who raised serious regulatory and safety concerns — is less interested in the difficulty and more interested in the gap the result exposes. The Science companion editorial, written from Johns Hopkins, states it directly: the DNA-synthesis screening layer the field relies on is voluntary, not legally required, and it was designed to flag sequences that resemble known hazards. A generative model's entire value proposition is producing sequences that resemble nothing on record.
That is the durable finding, and it holds whether or not you find the sixteen phages impressive. Homology-based screening asks "does this look like something dangerous we already know about?" — a question with no useful answer when the input is novel by construction. There is a real clinical prize on the other side of this, too: antibiotic-resistant infection is a large and worsening problem, phage therapy has been stuck for decades on the difficulty of matching the right phage to the right strain, and designing one to order is a plausible way through. Both readings are correct simultaneously, which is usually how you can tell a result matters.
The largest building on Earth, allegedly
On 6 August, Tesla and SpaceX jointly committed $16.8B as phase one of "Terafab", a single semiconductor plant in Grimes County, Texas, roughly an hour northwest of Houston, sited beside the Gibbons Creek Reservoir — water that once cooled a coal plant retired in 2018 and will now cool a fab. The finished site is planned at more than 100 million square feet with over 3,000 jobs, hiring aimed at Grimes and neighbouring Brazos county, plus a $30M Texas Enterprise Fund grant. Musk called it "the largest and most valuable building on Earth by far." Output is reportedly split roughly a quarter to edge and inference silicon for Optimus and Cybercab, three quarters to high-power parts for SpaceX's space-based data-centre programme.
Two numbers need separating carefully. The $16.8B is phase one. SpaceX filings suggest total spend across a multi-phase build could reach as high as $119B, against a stated goal of roughly a terawatt of AI compute per year — but that is a ceiling derived from a filing, not money anyone has committed.
The genuinely unusual part is not the dollars, it is the shape. Terafab is designed to do logic, memory, packaging and test under one roof. Modern chipmaking is specialised for hard-won reasons: capital intensity, yield learning curves, and the plain fact that no company has led in logic, memory and advanced packaging simultaneously in thirty years. Choosing to rebuild all three internally is a specific, testable claim — that the coordination cost of today's supply chain now exceeds the efficiency it buys. It is also a scarcity signal. When a buyer with SpaceX's balance sheet decides to manufacture rather than queue, that is a statement about what it expects leading-edge capacity and advanced packaging availability to look like for the rest of the decade.
Whether it gets built is a water, power and workforce question long before it is a technology question. The reservoir siting, the state grant and the local-hiring language all read as pre-emptive answers to the objections that have stalled large data-centre projects across the US this year. No process node or manufacturing partner has been disclosed.
Washington starts policing compute-hours
The enforcement arm of the Commerce Department's Bureau of Industry and Security — the people who police export controls, not the people who write them — is systematically reviewing how Chinese AI firms reach Nvidia hardware offshore by renting compute abroad rather than importing chips. It is reportedly assembling two lists: countries running physical black markets into China, and countries where Chinese firms tap controlled silicon remotely.
The fact that makes this interesting is a legal one. Remote access is currently legal. The Export Administration Regulations govern where a chip physically travels, not who is logged into it, and a cloud contract in a third country is not an export. Reporting carries an Institute for AI Policy and Strategy estimate that offshore rental may be boosting China's effective access to advanced US compute by at least around 60% in 2026 relative to what export controls alone would allow. That is an estimate carried in the reporting rather than an agency finding, but if it is even directionally right, the controls are leaking more than they contain.
The trigger is capability. Moonshot AI's Kimi K3 scored close to the latest Anthropic and OpenAI systems, which is the outcome the export-control regime was built to prevent. Controls that visibly fail to bite tend to get tightened rather than abandoned.
It is worth being precise about what has and has not happened. This is a review, not a rule. No new restriction exists today, and none has been proposed. If one arrives, though, it implies a genuinely different regime — one where the unit of control is the compute-hour rather than the chip, with know-your-customer duties landing on cloud providers, jurisdictional rules about who may log into controlled silicon, and enforcement reach into countries that never signed up to American technology policy. The collateral falls on neutral-country cloud operators, GPU-rental intermediaries, and any company whose training runs happen to sit in the wrong jurisdiction.
OpenAI stops counting
OpenAI announced on 6 August that Free and Go users will move to GPT-5.6 Luna as the default model, with the daily text-chat cap removed entirely. Free users also get a per-message "Think" button for higher-effort reasoning. Limits stay on file uploads, image analysis, voice and tools, and the unmetering is subject to abuse guardrails. Plus and Pro subscribers get an updated GPT-5.6 Sol plus a reasoning-effort slider on web, mobile and desktop.
None of it is live yet. Unlimited chats and the Think button begin rolling out the week of 10 August, so this is an announcement rather than a feature you can go and use.
The most informative part of the news is not in the announcement. A usage cap is a cost control, and removing one from the world's largest consumer AI product is an implicit statement that inference on the default model has become cheap enough to serve without metering. It also moves the competitive floor: every rival now has to justify having a cap at all, and the free tier stops behaving like a trial.
The reasoning slider is the quieter change and possibly the more interesting one. The industry spent two years hiding model selection behind automatic routers that decide, on your behalf, how hard to think. Exposing effort as a user-facing dial is a concession that the router cannot read intent well enough — and it hands users a latency-versus-quality tradeoff they can actually reason about. On quality, OpenAI says responses containing at least one factual error are roughly 62% less common than GPT-5.5 Instant on financial, medical and legal prompts. That is OpenAI's own benchmark on OpenAI's own prompt set, with no independent replication, and those three domains are precisely where self-reported factuality gains are hardest to check and most costly to get wrong.
The worm that went after your coding assistant
On 4 August, a self-propagating npm worm called ChainDrop published 2,212 malicious package versions in under four hours, hitting more than 400 packages with over a billion monthly downloads. It spreads by stealing maintainers' publish tokens: land in one pipeline, republish yourself into every package that maintainer controls, repeat. It began from a compromised account in the keyv and cacheable namespaces, and researchers describe it as a descendant of the earlier Shai-Hulud family, with its command-and-control instructions hidden in the Ethereum blockchain — which removes "take down the domain" from the response playbook entirely. Package and download counts differ across vendor reports, so 400-plus packages and over a billion monthly downloads is as precise as the evidence supports.
The structural finding is the uncomfortable one. Every poisoned release passed provenance checks, because every poisoned release genuinely was published by the victims' own trusted build pipelines. Provenance attests who published something. It does not attest what they published, or whether they meant to. When the credential is stolen and the pipeline is legitimate, the signature guarantees nothing that matters.
Then there is the payload. ChainDrop rewrites Claude Code and VS Code configuration files so that the developer's AI assistant executes attacker-controlled setup the next time it launches — using the agent itself as the persistence and lateral-movement mechanism. Coding assistants read local config and run setup commands with the developer's full privileges, which makes those files a high-value target with roughly the blast radius of a CI system and roughly the monitoring of a dotfile. And the worst detail is deliberate: revoking the compromised GitHub token is what triggers the remote handler. The first move in every incident-response playbook is the move that fires the payload.
The money view, and one very good billboard
Money this week went into physical capacity and legal exposure rather than models. Musk's $16.8B is the largest single private bet yet on owning fabrication outright. DeepSeek restarted its $8B raise at a valuation near 500bn yuan, roughly $74B, up from $7B at $52B in May, with Monolith Management newly in the running and signing targeted for late August; terms are not final and the round has already been restarted once. Underneath all of it sits the same silicon: Counterpoint's sovereign-AI index finds Nvidia powers about 92% of more than 170 sovereign LLMs across roughly 55 countries outside the US and China, with AMD near 4% and Cerebras near 1.7%. Sovereign AI, it turns out, is mostly a hosting story. The hardware dependency it was meant to solve is exactly the dependency Washington is now examining.
On the liability side, a New Mexico judge called Meta a "public nuisance" and ordered an additional $567M in the state's child-safety case, bringing the cumulative award to $942M. The more consequential part is not the money but the mandated product changes — removing like counts for under-18s, restricting overnight notifications. Meta says it will appeal. A fine scales away with revenue; a court supervising your product design does not. And in the quieter column, Google notified users on 4 August that Assistant will be removed from Android phones, tablets, Wear OS, compatible headphones and Android Auto from 4 September, with no opt-out. Google TV, Home speakers and cars with Google built-in are exempt for now.
Which brings us to the corner of Sixth and Folsom in San Francisco, where a 14-by-48-foot billboard has been advertising "ChatTJB: The leading chat interface powered by AI." The fine print clarifies that AI stands for "Average Individual." Behind it is Tucker Bryant, a 32-year-old former Googler turned conceptual artist, answering every prompt by hand — as much as ten hours a day, hand-drawing his replies to image requests. His site calls it "artisanal intelligence, handcrafted by a single human being." The billboard costs him around $6,000 a month, which is real money for a joke, except it is not really a joke: the target is what Bryant calls cognitive surrender, the reflex to trust anything with a chat box in front of it. It is a good week for the point to land. Sixteen viruses that never existed, a hundred million square feet of fab, a review of who may log into a GPU, an unmetered free tier, and a worm that rewrote developers' assistants against them — and the most human thing in the industry this week was one man at a keyboard, drawing pictures by hand for strangers who assumed a machine was doing it.
What to watch next: whether DNA-synthesis screening moves from voluntary norm to legal requirement now that a peer-reviewed paper and its companion editorial have named the gap; whether the BIS review turns into actual rulemaking, and what that would mean for cloud operators in neutral jurisdictions; and whether OpenAI's rollout holds to the week of 10 August, whether rivals drop their caps in response, and whether anyone outside OpenAI replicates that 62% factual-error-reduction claim. Signal, not advice; no live prices.
