AI Weekly: week in review (17–23.08.2026)

The most important developments from the world of AI over the past week, collected in one place. This time, the key themes are OpenAI's massive infrastructure buildout, agent security, advertising in Europe, enterprise data privacy and AI's growing role in science.

AI Weekly: week in review (17–23.08.2026)

Table of contents

    Last week highlighted two parallel directions in the development of the AI market. On one side, infrastructure continues to scale at a pace that would have seemed unrealistic not long ago. Nvidia, SB Energy and OpenAI are preparing an Ohio campus measured in gigawatts of compute capacity, while the leading labs continue securing the capital needed to stay in the frontier-model race.

    On the other side, the cost of increasing capabilities is becoming increasingly visible. Microsoft patched a vulnerability that could turn Copilot into an intermediary for data exfiltration, while OpenAI tightened restrictions around work on Astra after indications that the model could be approaching the highest tier of cybersecurity capability defined in the company’s Preparedness Framework.

    At the same time, AI is expanding into new areas of the market. OpenAI is preparing ChatGPT advertising for Europe, launching a separate experience for teenagers and offering API customers Zero Data Retention. Anthropic, meanwhile, is showing that Claude can do more than generate text or code: it can coordinate a protein-design process whose results can later be tested in a physical laboratory.

    Capital pressure remains in the background. Anthropic is accelerating preparations for a potential IPO, while recent reports suggest that the market is beginning to evaluate frontier labs less like conventional software startups and more like infrastructure companies with strategic importance comparable to the world’s largest technology firms.

    We collected the most important developments of the week in one place to separate individual launches and eye-catching numbers from changes that could affect costs, security, regulation and the way companies build AI-powered products.

    The format remains simple: first, a quick overview of the week’s developments, followed by short analyses of the most important themes.

    W skrócie

    Tydzień 17–23.08.20269 newsów
    17.08Nvidia secures infrastructure for OpenAI's massive Ohio campusPORTS-Pike shows that the AI race increasingly depends on financing energy, data centers and long-term compute contracts, not only on the quality of the next generation of models.
    17.08Z.AI releases GLM-5.2 TurboAnother Chinese model launch sustains an unusually rapid release cycle and increases pressure on Western providers in terms of cost, availability and iteration speed.
    18.08Microsoft patches CoSnitch in CopilotThe vulnerability shows that an assistant connected to email, calendars and cloud storage can become a new attack surface once the model is allowed to act on a user's data.
    18.08OpenAI launches ChatGPT for teensA separate experience for users under 18 strengthens safeguards, parental controls and mechanisms that adapt model behavior to the user's age.
    18.08OpenAI announces ChatGPT Ads for 31 European countriesThe European rollout beginning August 24 will test both a new monetization model and OpenAI's ability to operate advertising in one of the world's most demanding regulatory environments.
    19.08OpenAI offers Zero Data Retention for frontier modelsEligible API customers can use frontier models without prompts and outputs being retained after a request is completed, removing one of the more important barriers to adoption in regulated sectors.
    18.08Claude designs working binders for 14 of 15 targetsLaboratory-validated results show that a general-purpose AI model can coordinate a specialist protein-design process and produce measurable outcomes outside a purely digital environment.
    18.08OpenAI maintains restrictions on work involving AstraThe possibility that the model could reach Critical-level cybersecurity capability requires stronger sandboxes, monitoring and changes to the pace of some research work.
    20.08Anthropic accelerates preparations for a potentially record-breaking IPOReports of a possible public filing before the end of August show that competition between AI labs is increasingly extending into public markets and infrastructure financing at unprecedented scale.

    Nvidia shows that AI advantage increasingly begins with energy and the balance sheet

    17.08.2026Infrastructure and capital

    Nvidia, SB Energy and OpenAI announced another stage of the PORTS-Pike project in Pike County, Ohio. OpenAI is ultimately expected to use around 8 GW of IT capacity, SB Energy is responsible for developing and operating the campus, while Nvidia provides the computing infrastructure and financial support associated with the project.

    The headline figure is Nvidia’s potential commitment of up to $105 billion. This is not, however, a conventional equity investment in OpenAI. The structure is primarily based on guarantees connected to the long-term use of the infrastructure, while Nvidia simultaneously remains the supplier of the hardware on which the campus will operate.

    This is a good illustration of how the nature of the AI race is changing. Access to the strongest models no longer depends only on the quality of a research team or the number of GPUs purchased in a given quarter. Energy contracts, data-center financing, access to the power grid and the ability to plan infrastructure many years ahead are becoming just as important.

    For the market, this also means increasingly tight links between AI labs and hardware suppliers. The larger these projects become, the harder it is to quickly change architecture, chip provider or infrastructure strategy. Economies of scale increase, but so does the cost of losing flexibility.

    GLM-5.2 Turbo shows that the pace of Chinese labs is becoming an advantage in itself

    17.08.2026Models and competition

    Z.AI released GLM-5.2 Turbo, adding another launch to an exceptionally intense August for the model market. Within a matter of days, multiple providers introduced new systems, and the gap between successive generations is increasingly measured in days rather than months.

    The model itself is only part of the story. More important is the pace at which Chinese laboratories are able to train, publish and iterate new variants despite restrictions on access to the most advanced Western hardware.

    That increases pressure on closed models available only through APIs. If companies can regularly choose between increasingly capable systems from China, some workloads become harder to justify paying a premium for solely because of the provider’s brand or a relatively small benchmark advantage.

    For enterprises, the practical conclusion is straightforward: multi-model architecture is becoming increasingly rational. At the current pace of releases, it is difficult to assume that the model selected today will remain the best compromise between quality, price and speed six months from now.

    CoSnitch shows that an agent with data access is also a new attack vector

    18.08.2026Cybersecurity

    Microsoft published a fix for CVE-2026-24301, a vulnerability known as CoSnitch. The chain of flaws in Copilot Personal made it possible to use a malicious link to trigger unwanted behavior and potentially extract information from services connected to the assistant, such as Gmail, Google Drive and Google Calendar.

    This is qualitatively different from a conventional vulnerability in a web application. Copilot does not operate only on its own data — it acts as an intermediary between the user and multiple external services. If an attacker can manipulate the way the agent interprets instructions, they can indirectly gain access to a much broader set of information.

    The more permissions agents receive, the more the security of prompts, memory and tool calls begins to resemble conventional privileged-access management. A model that can read email, browse files and perform actions on behalf of a user should be treated as a highly trusted infrastructure component.

    For teams deploying agents, this means controls are needed across the entire action trajectory: which data the agent accessed, where an instruction came from, which tool it intends to call and whether the requested operation genuinely requires that level of permission.

    ChatGPT for teens turns age safety from a setting into a separate product experience

    18.08.2026Safety and users

    OpenAI launched ChatGPT for Teens — a separate experience for users aged 13 to 17. The system automatically directs users who declare an age within that range, or who are identified as minors by age-estimation mechanisms, into the teen experience.

    The teen version includes stronger default safeguards, additional content restrictions and tools for parents. In practice, OpenAI is moving away from the assumption that one universal set of model-behavior rules should apply equally to every user.

    This is an important product precedent. As AI becomes more widely used by children and teenagers for learning, entertainment and conversations about personal problems, the user’s age becomes part of the product architecture rather than merely a line in the terms of service.

    For other providers, this creates growing pressure to develop similar mechanisms: age estimation, parental controls, separate data policies and more precise behavioral restrictions. The market may gradually move away from one universal assistant toward several versions of the experience tailored to different user groups.

    ChatGPT Ads in Europe will test more than advertising — it will test the entire business model

    18.08.2026Business models and regulation

    OpenAI announced that ChatGPT Ads would expand to 31 European markets. Ads are scheduled to begin appearing for European users on August 24, although the decision itself was officially announced during the previous week.

    Advertising remains limited to the Free and Go plans, while paid premium subscriptions continue to be ad-free. This is another step toward building a second source of revenue alongside subscriptions and API usage.

    Europe is a particularly important test. GDPR, the DSA and other local requirements create a much more restrictive environment for profiling, personalization and data usage than the US market. The success of the advertising model will therefore depend not only on ad performance, but also on how OpenAI separates monetization from conversation privacy and trust in the assistant’s answers.

    Strategically, this also moves OpenAI onto territory that has financed Google’s growth for decades. If conversations with AI begin replacing part of the search and product-discovery process, the natural next question is whether a portion of advertising budgets will also move from search engines to conversational interfaces.

    Zero Data Retention opens frontier models to workflows companies previously did not want to send to the cloud

    19.08.2026Privacy and enterprise

    OpenAI expanded access to Zero Data Retention for eligible deployments of frontier models. Under this mode, prompts and responses are not retained by OpenAI after a request has been processed, and customer content is not available for standard review by company employees.

    The biggest impact is on organizations that previously treated data retention as a barrier to using the strongest externally hosted models. Banking, legal services, healthcare, government and defense often operate under substantially stricter requirements than ordinary consumer applications.

    Zero Data Retention does not eliminate every privacy and compliance challenge. Organizations still need to control their own logs, permissions, data sources and the ways agents move information between systems. It does, however, remove one of the main arguments for completely avoiding externally hosted models purely because of retention requirements.

    That increases pressure on on-premise solutions and locally deployed models. Their advantage of full environmental control remains, but data retention alone becomes a less obvious differentiator.

    Claude shows that a general-purpose agent can coordinate specialist scientific tools

    18.08.2026AI for Science

    Anthropic published results from an experiment in which Claude Mythos Preview and Opus 4.8 designed binding proteins for 15 targets. External laboratories Adaptyv Bio and Twist Bioscience produced and tested the designs, confirming working binders for 14 of the 15 targets.

    A total of 1,320 designs were tested, of which 354 showed binding. Depending on the configuration, the hit rate was approximately 22–35%, while Anthropic cites 10–15% as a typical range for comparable protein-design campaigns.

    The most important point, however, is what Claude did not do. The model did not replace the entire field of structural biology with a single generative system. It coordinated existing specialist tools, selected approaches, analyzed results and managed a long computational process based on a detailed prompt prepared by an expert.

    That may be more interesting than a simple headline about “AI discovering drugs.” If general-purpose models become an orchestration layer for specialist scientific software, their value can increase even without replacing those tools. In this model, the agent acts like a digital researcher capable of running a multi-step experiment.

    Astra shows that the ability to train a model and the ability to train it safely are two different things

    18.08.2026Model safety

    OpenAI published another update on the safety of more advanced models and confirmed that some work involving Astra remains restricted until stricter security requirements are met.

    Earlier evaluations indicated that OpenAI could not rule out Astra reaching the Critical level in the cybersecurity category of its Preparedness Framework. The company therefore introduced more isolated environments, limited network and tool access, stronger protection of model weights and additional monitoring of agent behavior.

    This suggests that the next bottleneck in frontier AI development may no longer be the number of GPUs available. A laboratory can have enough compute to run a training process while still lacking a security environment strong enough to conduct that training at full scale.

    For the industry as a whole, this creates a new category of cost. Alongside energy, chips and data centers, companies will need to invest in “secure compute”: isolation, monitoring, systems for detecting unwanted behavior, permission controls and procedures for stopping experiments before model actions move outside the intended scope.

    Anthropic enters the stage where public capital could become part of the model race

    20.08.2026Financing and capital markets

    Anthropic’s preparations for a potential IPO are accelerating. According to reports, the company is considering an offering that could rival or exceed SpaceX’s record-setting debut, while public registration documents could reportedly appear before the end of August.

    At the same time, some investors have been discussing expectations that Anthropic could be valued at around $2 trillion or more at the time of the offering. This is not, however, an official target disclosed by the company. Early meetings led by CFO Krishna Rao reportedly avoided committing to a specific valuation.

    That distinction matters. The market is not valuing only Claude’s current revenue. It is trying to price Anthropic’s potential future share of the software, agents, coding and AI infrastructure markets, while simultaneously accounting for the cost of maintaining investment in models and data centers.

    If an IPO does happen at that scale, the way AI laboratories are evaluated will also change. Instead of private funding rounds every few months, there would be a daily public-market valuation, quarterly investor expectations and much greater pressure to demonstrate that billions spent on compute translate into a durable business.

    Infrastructure is growing faster than the systems designed to control it

    The developments of August 17–23 point to a market in which the question of the “best model” is becoming an increasingly poor description of the actual competitive landscape. The largest laboratories are simultaneously building infrastructure, safety systems, new business models, products for specific user groups and mechanisms for accessing sensitive data.

    The first signal concerns scale. PORTS-Pike shows that AI infrastructure is beginning to be financed and planned more like energy or telecommunications. Contracts cover many years, billions of dollars and gigawatts of capacity. Entering the top tier of model development will therefore require not only research talent, but also access to capital and energy.

    The second signal is security. CoSnitch and the restrictions around Astra illustrate two ends of the same problem. At the product level, an agent with access to email and documents creates a new attack surface. At the laboratory level, a more autonomous model may require a testing environment far more restrictive than what was sufficient for the previous generation.

    The third signal concerns monetization and privacy. OpenAI is simultaneously preparing advertising for European users and Zero Data Retention for its most demanding enterprise customers. A single product increasingly needs to support radically different economic models: free access financed by advertising and highly restricted enterprise environments in which privacy is a condition of adoption.

    The fourth signal extends beyond conventional generative-AI applications. Anthropic’s protein-design results show the potential of general-purpose agents as a control layer for specialist scientific tools. If that direction continues, the value of models will increasingly be judged not only by text or code quality, but also by their ability to run long, measurable processes that end with a result in the physical world.

    For companies, the implication is clear: AI strategy increasingly looks less like choosing a SaaS provider. Organizations need to design the model layer, data layer, permissions, costs, security controls and migration options at the same time. Providers are evolving too quickly, and their business models and infrastructure are changing too dramatically, to assume that a decision made today will remain optimal for the next several years.

    Sebastian Kaczmarek

    About author

    Sebastian Kaczmarek

    CTO at MDBootstrap and CogniVis AI / Co-founder of MDBS - 10 years shipping hard tech, now building private AI that turns document chaos into structured data.

    Author of Learn Bosque Programming book / YouTube creator / ex StackOverflow contributor.