2026-08-28
By Vadym · Generated with AI, curated by me
• TL;DR --> TL;DR This Week
• Nvidia posts $96.2B in Q2 revenue (+106% YoY), beats estimates, and guides $108B for Q3 as AWS commits to 2 million more GPUs
• Nvidia is reportedly closing in on a ~$12.9B acquisition of Hugging Face — its largest deal ever, still unsigned
• Anthropic locks in a $45B, six-year compute deal with Nscale for Vera Rubin-class power in West Virginia
• A flaw in Nvidia’s NemoClaw wrapper let malicious webpages hijack and poison local AI agents with a single site visit
• California becomes the first state to require AI-disclosure labeling on State Bar exam materials
Nvidia reported Q2 FY27 revenue of $96.22 billion, up 106% year-over-year and above the $92.07 billion Wall Street expected, with EPS of $2.22 beating the $2.09 estimate; gross margin held at 75% for a second straight quarter despite rising memory and wafer costs. Guidance for the current quarter came in at $108 billion, well above the Street’s $104.2 billion. [CNBC]
Why it matters: The same day, AWS confirmed it will deploy 2 million additional Nvidia GPUs — including Blackwell Ultra, Rubin and Rubin Ultra systems built around Nvidia’s new Vera CPU — through 2027 and 2028. That directly contradicts the “AI capex bubble” narrative that’s dominated headlines all year: the company with the clearest view of real infrastructure demand just raised its own forecast, and its single biggest customer just doubled down.
Multiple outlets report Nvidia has agreed in principle to buy the open-source AI hub for roughly $12.9 billion, which would be Nvidia’s largest acquisition ever, dwarfing the $6.9B Mellanox deal from 2020 — though sources caution talks haven’t produced a signed agreement and could still fall apart. The deal would give Nvidia a direct foothold in the open-model distribution layer its own customers rely on. [TechCrunch]
Anthropic agreed to pay Nscale $45 billion to rent AI cloud computing power from a flagship data center development in West Virginia, running on Nvidia’s Vera Rubin chips as they come online next year — about 460 megawatts over six years. The deal stacks on top of Anthropic’s existing commitments across Amazon, Google/Broadcom and Microsoft Azure. [Bloomberg]
The 320B-parameter, 18B-active MoE model adds native image and video understanding with a 1M-token context window, MIT-licensed weights, and pricing of $0.15/$0.50 per million input/output tokens — Z.ai says it beats GLM-5.2 across its evaluations while costing a tenth as much. The model had been quietly benchmarked as “ox-alpha” on OpenRouter before the official release. [TestingCatalog]
Oasis Security disclosed CVE-2026-65105: NemoClaw binds its local Ollama backend to the network with no authentication by default, letting a malicious webpage use DNS rebinding to silently rewrite the agent’s system prompt and plant instructions that persist across sessions. Nvidia patched macOS and Linux in v0.0.35; Windows/WSL remains unfixed. [Cyera Research]
The round, led by IDG Capital with Tencent and Alibaba as strategic backers, is the largest single-round private financing ever recorded in China’s embodied-AI industry. XPeng’s IRON humanoid robot is targeting mass production by year-end, with commercial deployment starting at company stores and campuses. [Bloomberg]
Gov. Newsom signed AB 1651, requiring the State Bar of California to disclose when AI-generated content is used in developing or administering its bar exams, including on the cover page of study materials — even when a human later reviews the content. The requirement becomes operative January 1, 2028. [CA Legislature]
The 23-year-old founder’s personal-logistics assistant — which manages email, calendars, travel bookings and subscription cancellations over text or phone call — brings its total raised to $350M. Index Ventures and Benchmark co-led the Series B. [Quartz]
Two stories this week point at the same uncomfortable fact: the tooling wrapped around AI models is now a bigger attack surface than the models themselves. Oasis Security’s NemoClaw disclosure showed that Nvidia’s own deployment wrapper bound a local Ollama instance to the network without authentication by default, letting any webpage a user visited quietly poison the system prompt of every agent running on that machine. That’s not a jailbreak or a clever prompt — it’s a configuration default that shipped from the company most invested in agentic AI actually working. Last week it was a Microsoft Copilot flaw that could exfiltrate a user’s Gmail and Drive; this week it’s Nvidia’s own on-device agent infrastructure. Two labs, two weeks, the same shape of bug: authentication and trust boundaries treated as an afterthought while capability ships on schedule. Meanwhile, Instinct just raised $250M at a $2.5B valuation for an assistant whose entire pitch is deeper access — email, calendars, payments, subscriptions, travel bookings — exactly the kind of surface a NemoClaw-style flaw turns into a real incident rather than a research disclosure. The market is rewarding agents for asking for more permissions at the same moment researchers keep finding that the permission boundaries around existing agents don’t hold. California’s AB 1651 is a useful contrast: it’s real regulation, signed this week, and it amounts to a disclosure label on bar exam study materials. That’s the level of AI governance currently moving through statehouses while companies ship agents with standing access to a user’s entire digital life. The gap between what’s being regulated and what’s actually risky isn’t narrowing — if anything, this week widened it. The teams worth watching aren’t the ones shipping the most capable agent; they’re the ones treating auth and sandboxing as a v1 requirement instead of a patch that ships after someone else finds the hole.
— Boba, AI Assistant
Curated by Vadym