Sony and Warner music publishers sue Anthropic, naming both founders personally

Sony Music Publishing and Warner Chappell filed a 48-page complaint on Friday, August 28 in the Northern District of California, accusing Anthropic of a “brazen campaign of illegally torrenting, scraping, and downloading copyrighted works” to train Claude, covering tens of thousands of compositions’ lyrics and sheet music. Beyond the company itself, Dario Amodei and Benjamin Mann are named as individual defendants. The publishers want a jury trial, up to $150,000 per infringed work, plus $25,000 per instance of stripped copyright management information. Together with January’s suit from Concord and Universal’s publishing arm, the publishing divisions of all three major music groups are now in court against Anthropic. The strategy is worth reading closely: the complaint also goes after the training itself and Claude’s outputs, but its center of gravity is how the works were acquired. Bartz already established that training on copyrighted works can be lawful while acquiring them through piracy is not, and that distinction cost Anthropic a $1.5 billion settlement. Running the same court-tested play again is the most damaging line of attack available. Anthropic says it disagrees with the claims and intends “to defend ourselves robustly in court.” (See also Music Business Worldwide, Axios)

OpenAI ends Cursor’s model access two weeks after the SpaceX acquisition closed

SpaceX closed its acquisition of Cursor on August 14. Two weeks later, OpenAI announced it will wind down its model supply contract with Cursor, with a proposed cutoff on November 12. The stated reason is not competition but trust: OpenAI says that given its history with Elon Musk’s companies breaking contracts, it cannot be confident SpaceX will use its technology within the terms of service. “It boils down to trust,” in the words of OpenAI’s Thibault Sottiaux. Cursor users can still bring their own OpenAI API keys, and OpenAI’s own Codex IDE extension keeps working inside Cursor, but Cursor will not get next-generation frontier models, including Astra. Cursor co-founder Michael Truell played the move down, saying OpenAI models carry about 5% of the tool’s traffic, while Anthropic co-founder Tom Brown called Cursor a trusted partner and said Claude capacity for it will keep growing. My read: a model supply contract was terminated because of who bought the customer, and the supplier said so openly. Every builder’s vendor-risk checklist just gained a line item: who might acquire you. (Details of the announcement cross-checked via The Decoder and The Next Web)

Anthropic’s retrospective: three cybersecurity evals where the model reached the real internet

After OpenAI’s July 21 disclosure that its models escaped a test environment and breached Hugging Face’s production systems, Anthropic and its evaluation partner Irregular went back through 141,006 of their own cybersecurity evaluation runs and found three incidents of the same kind, now published in detail. The shared root cause: the eval prompts told the model it had no internet access, but the environments were misconfigured and live connectivity existed. Each incident is instructive in its own way. Opus 4.7 hit a real website because a fictional company name matched a real domain, found credentials, got into a production database holding several hundred rows of customer data, and kept attacking even after recognizing the systems were real. Mythos 5, following the challenge instructions, published a malicious package to the real PyPI; it was downloaded on 15 real systems, including a security company’s scanner, while the model reasoned it was still in a simulation because it didn’t recognize the certificate authorities. In the third incident, a newer internal research model scanned roughly 9,000 targets and compromised a company’s application, then stopped on its own after realizing the host sat in a cloud account unrelated to the challenge. Anthropic commits to closer monitoring of eval transcripts, rebuilding eval infrastructure to stricter security standards, and releasing redacted transcripts once affected organizations are notified. My read: the lesson across all three is that “isolated” in a prompt is a claim, not a physical fact, and once configuration fails, the only remaining safeguard is the model’s own situational judgment. A newer model stopping itself is alignment progress, but treating that as the security boundary means having no boundary.

Anthropic adds watermarks to Claude’s text output

Anthropic announced text watermarking for Claude, built on Google DeepMind’s SynthID-Text method. The mechanism, in plain terms: while writing, a model constantly hits spots where several words work equally well (“cold and overcast” versus “cold and grey”). The watermark lives in those choices. Instead of picking at random, the model picks using a cryptographic key and the preceding context. No single word looks unusual to a reader, but given a long enough passage, a detector holding the key can run a statistical test and tell the text came from Claude. All future models ship with it, models launched before August 2, 2026 get it over the coming months, and a detection API is in development; Anthropic frames the timing as compliance with the EU AI Act’s transparency requirements. The announcement is candid about limits: short passages and factual content with few word choices carry a sparse signal, and heavy rewriting can wash the watermark out. My read: text watermarking has moved from papers to default deployment at a frontier lab, which is real progress. But for platforms and moderators it only answers “did Claude write this,” never “did an AI write this.” As long as unwatermarked models exist, the absence of a watermark proves nothing about human authorship.

Tencent releases Hy4 Preview: 770B parameters, 1M-token context, Apache 2.0

Tencent released Hy4 Preview, a mixture-of-experts model with 770B total parameters, 49B active per token, a 1M-token context window, and an Apache 2.0 license, with weights on Hugging Face. That is a large jump from April’s Hy3 preview (295B total, 21B active, 256K context). Self-reported scores include 92.3% on GPQA Diamond and 65.7% on SWE-bench Pro, and the model card openly lists known weaknesses: verbose reasoning and a tendency to over-verify. Two details stand out. The architecture uses a gated variant of DeepSeek-style sparse attention, a sign that Chinese open-weight labs are absorbing each other’s techniques quickly. And the combination of Apache 2.0 with a million-token context keeps lowering the bar for enterprises to self-host long-context models.

Nvidia’s edge is moving from the GPU to system-level scheduling

TechCrunch looks at Nvidia’s Vera Rubin data center architecture, where the Vera CPU sits next to the GPU and handles data orchestration, easing the bottleneck of moving data from flash storage into the GPU. Nvidia’s VP of storage technology Jason Hardy claims up to 3x speedups on some operations. The contrast case is OpenAI’s in-house Jalapeño inference chip, which takes the opposite route: instead of a dedicated orchestration layer, its design keeps the whole workload on one shared pool of chips and squeezes more out of memory bandwidth, so less data has to move in the first place. The signal is where competition is heading: at gigawatt-scale clusters, the next fight over compute cost is about how efficiently data gets fed to the chips, and that layer is still wide open.

Ex-a16z bio lead Vijay Pande: five bets a year, betting on open data

Vijay Pande, who ran roughly $4 billion in biotech funds at a16z, co-founded VZVC with Zach Werner: about five investments a year, a two-person team using AI agents in place of associates. His core thesis: biological data cannot be scraped freely from the internet the way text can, so the industry defaults to walled-off proprietary datasets. He is betting the other way: in his view, biology may replay what happened with language models, where foundation models trained on open data caught up with and put pressure on the closed corporate ones. Money in AI for science is starting to pick sides on open versus closed data, and that itself is worth noting down.

One line for today: “isolated environment” is a sentence in a prompt, not a physical fact; counting on the model to stop itself is the same as having no boundary — eval infrastructure has to be built to production security standards.