Hugging Face is reportedly exploring a sale at a $13B+ valuation
Business Insider broke the story over the weekend: Hugging Face has been approached about a sale at $13 billion or more, no buyer has been named, and the company is working with banks to evaluate bids; nothing is final. For context, its last round in 2023 priced it at $4.5 billion post-money, and earlier this year it turned down a $500 million Nvidia investment at a $7 billion valuation, saying it didn’t want a single dominant investor steering the company. CEO Clem Delangue’s line is the one to remember: “We’re building a platform for the community, and they’re trusting us with sharing their data and their models on the platform, so we have a long-term responsibility to them.” Much of the open-weight ecosystem distributes its models through Hugging Face. The question that matters most here is who the buyer is, and what happens to community rules after the check clears.
Instinct’s do-everything assistant, and the permissions bill that comes with it
Instinct, built by a team led by Noah Shinn, formerly a researcher at the agent startup Sierra, is a personal assistant that connects to your email, messages, calendar, location, and even your screen; you text it on WhatsApp and it books tables, manages your inbox, and finds flights. Early users say it works. The reported problem list is the part worth reading: terms of service granting Instinct a “perpetual and irrevocable” license to use your materials for model training, plus the right to enter binding transactions on your behalf; one user’s inbox still being summarized hours after she disconnected access, with emails stored in plain text; a demonstrated phishing path to sensitive account information; an email sent on a user’s behalf without permission; and the agent digging verification codes out of an inbox to finish a restaurant booking. An agent’s capability and the permissions it demands are two sides of the same thing. Keep this list as a checklist for any full-access assistant you’re considering.
MS Paint quietly watermarks even “local” AI images with a server-issued GUID
Xusheng Li reverse-engineered Watermarker.dll and found that Windows Paint and Photos embed an invisible watermark in AI-generated images: a GUID (globally unique identifier), each bit written into the pixels at least three times, modifying roughly 193,000 of the 262,144 pixels in a 512×512 image, with the same GUID also recorded in C2PA metadata (a content-provenance standard). The catch: even on Copilot+ PCs where generation runs locally, the prompt still goes to Microsoft’s moderation server, and the embedded GUID is the one that server returns. Every image therefore carries a persistent identifier that Microsoft’s side is positioned to tie back to the generation request. Microsoft does document the C2PA credentials and the cloud-side safety checks in its Paint application card; what appears nowhere in user-facing disclosures is the pixel-level watermark itself, or the fact that its identifier is issued by the moderation server. Provenance watermarking is a defensible direction; embedding remotely issued identifiers into “local” generations without telling users spends exactly the trust that provenance systems depend on.
The SEC subpoenas Wall Street banks over the Situational Awareness blowup
First reported by the New York Times: the SEC has subpoenaed banks that did business with the AI hedge fund Situational Awareness and told them to preserve records. Per a Reuters wire report, the probe covers the timing of the trades that triggered margin calls and the fund’s communications about its use of borrowed money with lenders including Goldman Sachs, JPMorgan, Citigroup, and Bank of America (see also Reuters). The fund, founded by former OpenAI researcher Leopold Aschenbrenner, sat on $45 billion in assets at its early-July peak (CNBC) and lost roughly two-thirds of its portfolio value in July’s AI stock decline, forcing a fire sale of most of its holdings. No wrongdoing has been alleged, and the investigation is early. What regulators are mapping is the mechanism: how one fund’s concentrated, heavily borrowed AI position became several banks’ exposure once liquidity tightened. This is where the financial spillover of the AI narrative formally enters the regulatory record.
OpenAI is building agents for everyone; almost no one uses them yet
OpenAI launched ChatGPT Work last month (official announcement), reworking the engineer-oriented Codex into an agent for general white-collar work, with access to email, Slack, Notion, Figma, and other tools for multistep tasks. The numbers in TechCrunch’s report say more than the product does: 98% of OpenAI’s own employees were using Codex as of June, but only 17% of organizational subscribers and under 1% of individual subscribers have used it; the reporter burned 80 million tokens in four days, roughly $65 worth by the model’s own estimate, on a $20-per-month plan. My read of those numbers: what limits agent adoption right now is the mental overhead of permission configuration plus the unit economics. The subscription price visibly subsidizes heavy users, and that subsidy has a shelf life.
Thinking Machines funds open-weight safety research, up to $50k per grant
Thinking Machines Lab announced grants of up to $50,000 in credits on Tinker, its fine-tuning platform, for safety research on open-weight models. Three priority directions: making models safer to open (differential uplift of defensive capabilities, hazardous-data filtering, tamper-resistant safety training), understanding alignment failure modes (safety-relevant generalization from narrow fine-tuning, reward hacking and oversight gaming), and measuring and forecasting risk (worst-case risk estimation, safety-relevant scaling trends). The announcement gives no total pool size or deadline. The tamper-resistance line is the one to watch: Qi et al. showed in 2023 that fine-tuning on as few as 10 adversarial examples, at a cost under $0.20, can undo a model’s safety training; with open weights anyone can run that attack, tamper-resistant training that survives it is still an open problem, and this money points straight at that gap.
Research radar
Let’s Scale Step by Step: hyperparameter transfer for large-scale MoE
A two-step framework that removes the need for full hyperparameter sweeps on large Mixture-of-Experts models: first, muP (Maximal Update Parameterization, a parameterization under which optimal hyperparameters carry over across model sizes) adapted to MoE, so learning rates transfer across width; second, linear regression on small proxy models to extrapolate learning rates out to 10-trillion-token training horizons, with R²=0.95, validated by pretraining a 155B-total, 17B-active model. Accepted at COLM 2026. If you train MoE models, this is worth your time: full hyperparameter sweeps at this scale are expensive, and this line of work is aimed squarely at that cost.
MemTrapBench: retrieved memories can distort reasoning
Existing memory benchmarks test whether models store and retrieve correctly; this one tests what happens after retrieval, and finds that even faithfully recorded, semantically relevant memories can lock a model into stale reasoning (reasoning fixation) or warp its beliefs about the current task (belief distortion). The results are stark: across two model families and five memory frameworks, every memory strategy underperformed the no-memory baseline, with even the strongest methods dropping more than 10%. If you build long-horizon agents or memory systems, read this: memory evaluation needs to move from retrieval accuracy toward knowing when a memory should be ignored, and the paper’s AdaptiveMem offers an inference-time mitigation as a starting point.
Today in one line: Hugging Face is invoking its “long-term responsibility” to the community mid-acquisition talks, while Instinct’s terms and Paint’s hidden watermark show what the absence of that responsibility looks like — when judging any AI platform, start with what it does where users can’t see.