AI Waypoints: Week of July 13, 2026 — Edition #19
China released the biggest open-weight model ever the same week Google’s flagship slipped. Anthropic lined up IPO banks and a private-equity services arm, TSMC posted a fifth straight record quarter,
PS: I am publishing this a week delayed along with this week’s AI Waypoint I just returned from an epic motorcycle trip across 14 states covering 4560 miles over 12 days! More to come on that front later!
Good morning!
Moonshot AI released Kimi K3, the biggest open-weight model ever, the same day Bloomberg reported that Google’s Gemini 3.5 Pro is months behind schedule. Chip stocks sold off, and Apple briefly took the most-valuable-company crown from Nvidia before giving it back by Friday’s close.
Anthropic spent the week lining up IPO banks and standing up an enterprise services firm with Blackstone. TSMC put hard numbers under all of it: a fifth straight record quarter and another $100 billion for Arizona.
And the AI labor question stopped being theoretical. 200+ economists signed a warning, the federal government published projections to match, and 26 Meta employees sued over AI-assisted layoff picks.
1. China ships the biggest open model ever — the same week Google’s flagship slips
What happened: On July 16, Moonshot AI released Kimi K3: a 2.8-trillion-parameter Mixture-of-Experts (MoE) model with a 1-million-token context window (tokens are the word-pieces AI is billed and measured by; the window is how much it can consider at once) and native vision.
Moonshot calls it the largest model ever put on the open-weight track, with weights promised for download on July 27; the API and kimi.com are live now. As of this writing it sits #1 on the WebDev Arena leaderboard at 1,679, ahead of Claude Fable 5 at 1,631 and GPT-5.6 Sol at 1,618, and 4th on the Artificial Analysis Intelligence Index; Moonshot’s own post is more modest, saying K3 still trails Claude Fable 5 and GPT-5.6 Sol on the hardest benchmarks.
The same day, Bloomberg reported that Gemini 3.5 Pro is months behind schedule after a training-data refresh fell short on coding; Alphabet shares fell, and Google’s model page still says “coming soon.” Google’s on-record response: it is “currently testing 3.5 Pro, an upgraded Flash model, and other models with partners.” The rumored 2-million-token context window remains unconfirmed.
By July 17 the chip selloff had Fortune calling it a “new DeepSeek shock”, and Apple briefly passed Nvidia as the world’s most valuable company before Nvidia edged back ahead by the close.
ELI5: What’s an open-weight Mixture-of-Experts model?
An open-weight model is one whose trained brain (the “weights”) you can download and run on your own servers, instead of only renting through the vendor’s API. Mixture-of-Experts is a design trick: the model contains many specialist sub-networks, and only a few wake up for any given question, so a 2.8-trillion-parameter model answers at a fraction of that cost.
Open weights don’t mean open everything; the training data and recipe usually stay private, and the license still sets the rules for commercial use.
Why it matters: The top-tier scoreboard flipped in one news cycle. I ran the July 17 Gemini date as rumor in last week’s edition; the miss is now the story, and every enterprise that penciled “wait for Gemini 3.5 Pro” into a Q3 plan just lost the date. Meanwhile a top-tier open-weight alternative showed up with a hard download date attached. Roadmap risk runs both directions.
What to do: I’d re-baseline any 2026 initiative that assumed Gemini 3.5 Pro against models that exist today. Settle your open-weights governance posture (provenance checks, license review, where Chinese-origin models are and aren’t acceptable) before July 27.
2. Anthropic spent the week acting like a company about to go public
What happened: 5 Anthropic items in 3 days, and together they sketch a vendor dressing for the public markets.
IPO investor meetings (July 15): Goldman Sachs, Morgan Stanley, and JPMorgan are lining up investor meetings ahead of a potential October listing, per Bloomberg, which broke the story. Anthropic reportedly filed confidential S-1 paperwork (the registration step for going public) last month and carries a $965 billion valuation from its May round, above OpenAI’s $852 billion.
“Ode with Anthropic” (July 15): a standalone enterprise AI services firm built with Blackstone and Hellman & Friedman, two private equity firms, on top of Anthropic’s May acquisition of Fractional AI. Chris Taylor is CEO, Eddie Siegel is CTO, and the investor consortium includes Goldman Sachs, General Atlantic, Apollo, Singapore’s GIC, and Sequoia. No funding amount was disclosed.
Claude for Teachers (July 14): free premium Claude for verified US K-12 educators, standards-aligned in all 50 states.
CA$10 million for Canadian AI research (July 14), committed the same day.
Microsoft friction (July 16): in remarks to Copilot engineers, Satya Nadella called Anthropic’s Fable “editorially controlled,” criticizing how often the model refuses requests, an escalation in the Microsoft-Anthropic back-and-forth just as Anthropic courts public investors.
Why it matters: Ode is the piece to study. Anthropic now sells implementation services with private-equity distribution behind it, which puts it in direct competition with the Accentures quoting AI transformation work. And a public Anthropic means quarterly-earnings pressure on pricing and packaging from a vendor a lot of enterprises just standardized on.
What to do: If you’re scoping AI implementation work for the second half, I’d get Ode into the bidding alongside the incumbent consultancies, if only for pricing leverage. Revisit the Anthropic contract terms too, before an IPO changes the vendor’s incentives; renewal language written for a private company reads differently under earnings pressure.
3. TSMC’s record quarter put hard numbers under the AI boom — and another $100 billion into Arizona
What happened: TSMC posted its fifth straight record quarter on July 16: net income of NT$706.56 billion (New Taiwan dollars), up 77.4% from a year ago, on revenue of about US$40.2 billion, up 33.7% in dollar terms, with a 67.7% gross margin. High-performance computing (HPC, the category AI chips fall under) is now 66% of revenue, and advanced manufacturing nodes (its newest chip-making processes) are 77% of wafer revenue. TSMC raised its full-year growth guidance to slightly above 40%, lifted planned capital spending to $60-64 billion from an original $52-56 billion, and CEO C.C. Wei committed another $100 billion to Arizona, bringing total planned US spend to $265 billion. ASML, one layer upstream, said the same thing a day earlier (more on that below).
ELI5: Why does a chip maker’s margin matter to my AI budget?
TSMC manufactures nearly all the world’s advanced AI chips; Nvidia, Apple, and AMD design them and pay TSMC to make the silicon. When the one factory everyone must use keeps 67.7 cents of gross profit on every revenue dollar and still can’t meet demand, no price pressure moves down the chain. Your cloud provider’s GPU bill is built on TSMC’s price, and yours is built on your cloud provider’s.
Why it matters: Every AI budget in the world clears through this one company, and it just said demand is still accelerating. A 67.7% gross margin at record volume means compute input costs aren’t falling soon, and the “GPU prices will normalize next year” assumption baked into a lot of AI cost models needs a fresh look.
What to do: I’d treat compute pricing as structurally firm through 2027 in any AI total-cost model. The $265 billion for Arizona is real evidence that US-based advanced capacity is coming, but it’s years out; geographic supply risk stays on the register.
4. The rest of the money week — the AI buildout tab, itemized
What happened: 4 more money items this week, running from the machines that print the chips down to a streaming service reporting what it does with them.
ASML raised its year (July 15): Q2 sales of €9.3 billion and €2.9 billion net income, with its 2026 revenue forecast raised to €43-45 billion from €36-40 billion, about 16% higher at the midpoint. ASML is lifting capacity for its most advanced low-NA extreme ultraviolet lithography machines (EUV, the machines that print advanced chips) by roughly 30% for 2027.
Fireworks AI raised $1.505 billion (July 15): a Series D at a $17.5 billion valuation led by Atreides, Index, and TCV, with Nvidia participating. Underneath, the company says: more than $1 billion in annualized revenue and 40 trillion tokens served daily, over 95% from models specialized on customer data, for customers like Cursor and Harvey.
Reflection AI signed a $1 billion-plus compute deal (July 14): capacity from Nebius through 2029 on Nvidia GB300 chips, weeks after a reported $150 million-a-month SpaceX compute deal. Reflection is reportedly in talks to raise at a $25 billion valuation on top of that.
Netflix counted its AI titles (July 16): Q2 revenue of $12.56 billion, up 13.4%, with a 33.4% operating margin and its largest-ever quarter of share buybacks at $4.7 billion. Per its shareholder letter, generative AI workflows have been used in roughly 300 titles in 2026, with the largest concentration in post-production. The stock still fell on the Q3 outlook.
Why it matters: Fireworks is the sleeper. 95% of 40 trillion daily tokens running on specialized models rather than top-tier flagships is the best market evidence I’ve seen that enterprises buy fit-for-purpose over flagship, which is the argument I made in the Corporate Tokenomics piece. Netflix supplies the other half: the adoption proof that carries weight is named workflows and counted deployments, sitting next to the financials.
What to do: Ask your inference vendor what share of your workload genuinely needs a top-tier model; the market data now supports aggressive tiering. And I’d borrow Netflix’s reporting move wholesale: name the workflows, count the deployments, and put those numbers in front of leadership that way.
5. Patch week came for the AI platforms
What happened: 3 security items this week, and they all touch the platforms AI agents read from and act on.
SharePoint, actively exploited (July 14 and 16): CISA, the US cybersecurity agency, warned that 4 on-premises SharePoint flaws (CVE numbers, the catalog IDs for publicly disclosed software flaws) are being exploited, chaining remote code execution (RCE, an attacker running their own code on your server) with theft of IIS machine keys, the web-server secrets that let attackers forge valid access tokens and keep access after patching. The worst, CVE-2026-58644, scores 9.8 of 10 on the CVSS severity scale, was exploited before a patch existed, and joined CISA’s Known Exploited Vulnerabilities catalog on July 16, with a reported federal fix-by date of July 19, per The Hacker News; CISA’s own pages wouldn’t load when I checked. Microsoft shipped fixes July 14 (KB5002882, KB5002883, KB5002891) for Subscription Edition, 2019, and 2016.
ServiceNow, patched before exploitation (July 13): CVE-2026-6875, a CVSS 9.5 sandbox escape in the AI Platform layer allowing unauthenticated remote code execution. ServiceNow patched hosted instances; self-hosted customers apply the patches themselves. No exploitation observed at disclosure.
OpenAI disclosed GPT-Red (July 16): a self-play-trained automated attacker that found successful attacks in 84% of scenarios versus 13% for human red-teamers (in-house attackers who probe your own systems) against GPT-5.1. Folded into training, it got GPT-5.6 Sol down to failing only 0.05% of direct prompt injections (attacks that hide hostile instructions in the text an AI reads), 6x fewer than its predecessor. In one live test it talked an Andon Labs vending agent into repricing items and canceling a customer’s order.
ELI5: What does “sandbox escape” mean?
A sandbox is the sealed room where a platform runs untrusted code, like the scripts its AI features generate, so mistakes can’t touch the rest of the house. A sandbox escape means someone found a door out of the sealed room and into the platform itself. On a system like ServiceNow, which holds tickets, workflows, and credentials for the whole company, getting out of that room means the whole house.
Why it matters: The collaboration and AI layers that agents index and act on are now the actively exploited target, and GPT-Red previews what happens when adversaries run the same automation on offense. “Patch SharePoint” now also means “protect every AI search index and agent that reads it.”
What to do: Confirm the July 14 SharePoint updates and AMSI Full Mode (Microsoft’s malware-scanning hook) are actually deployed, and hunt for machine-key theft before rotating keys; that’s the order CISA specifies. If you run self-hosted ServiceNow, the KB3137947 patches go in this week. I’d also add automated prompt-injection testing to the agent go-live checklist, because 84% versus 13% says human red-teamers alone miss most of what automation finds.
6. Governments stopped drafting and started stopping
What happened: 3 governments moved this week with 3 different instruments, plus a deadline 2 weeks out.
New York froze new hyperscale data centers (July 14): Governor Hochul signed the first US statewide moratorium on new “hyperscale” data centers (roughly 50 megawatts and up, the size AI clouds build): up to a 1-year pause on state discretionary environmental permits while agencies build a blanket environmental impact statement. Already-approved projects proceed. The package also aims to make data centers self-supply power or pay a grid premium, with legislation to repeal sales-tax exemptions.
China’s AI-agent rules took effect (July 15): joint “Implementation Opinions” from China’s internet, planning, and industry regulators (CAC, NDRC, and MIIT), the first jurisdiction-specific rulebook for AI agents. Per legal analyses from IAPP (the international association of privacy professionals) and Bird & Bird, it sets a 3-tier authorization system that scales required human approval with the consequence of the agent’s decision, plus mandatory filing, compliance testing, and recall provisions for agents in healthcare, transportation, media, and public safety, and a 70% agent adoption target for smart terminals (phones, PCs, and other devices) by 2027.
29 countries signed the WAICO charter (July 16-17): the World AI Cooperation Organization, chartered in Shanghai with UN Secretary-General Guterres attending. Xi Jinping opened the World AI Conference in person on July 17, his first in-person keynote there.
Watch line: the EU AI Act’s transparency obligations (telling users they’re interacting with AI, labeling deepfakes) apply from August 2, 2026.
Why it matters: A permit freeze, an in-force agent rulebook, and a standards body: 3 instruments, all touching enterprise decisions about where capacity gets built, how agents must be governed inside China operations, and whose rules a multinational reconciles. New York is my contagion watch; grid-cost politics travel fast between statehouses.
What to do: If you deploy agents in China operations, get a filing and authorization-tier assessment moving now; these rules are already in force. Ask your data-center and cloud providers which of their planned Northeast capacity sits behind New York permits. Then confirm any customer-facing AI meets the EU disclosure requirements before August 2.
7. The AI labor question got real — economists, federal data, and a lawsuit
What happened: The labor story arrived from 3 directions in 4 days.
200+ economists signed an 88-word warning (July 13): the Stanford Digital Economy Lab published “We Must Act Now”, signed by 200+ economists and AI researchers including 16 Nobel laureates (Acemoglu, Simon Johnson, Stiglitz, Spence, Krugman, and Bernanke among them) plus researchers from Google, Anthropic, and OpenAI. Organized by Erik Brynjolfsson, Ajay Agrawal, Anton Korinek, and Tom Cunningham, it warns AI could drive economic transformation “larger than the Industrial Revolution” over a much shorter timeframe and calls for building policy and institutions before displacement arrives. Several signatories, Acemoglu especially, were until recently prominent AI-jobs skeptics; Bernanke signed days after joining Anthropic’s Long-Term Benefit Trust, the outside body with authority to appoint members to its board.
The federal government put projection numbers behind it (July 16): the Bureau of Labor Statistics (BLS) published its 2024-34 employment projections with a dedicated AI analysis. Data scientists are projected to grow 33.5%, the 4th-fastest-growing occupation overall, while employment of computer programmers is projected to decline 6% over the same decade, with AI cited as a driver; BLS also names sales engineers and insurance sales agents among the reduced-demand roles.
26 Meta employees sued over AI-assisted layoff picks (July 14): filed in federal court in Oakland, the complaint alleges that Meta’s AI-assisted layoff selection, built on internal AI tools including Metamate, keystroke and activity monitoring, AI token-usage dashboards, and algorithmic performance rankings, disproportionately targeted workers on medical, parental, or family leave in the 8,000-person layoff Meta announced in May, about 10% of its workforce. The claims cite federal medical-leave, disability, and pregnancy-protection laws. All of it is allegation, not court finding, and a Meta spokesperson is on record: “Workforce management and organizational decisions were, and are, made by people, not AI.” On July 17 a federal judge denied the emergency request to block the layoffs, so separations begin July 22 while the discrimination claims proceed; a longer-lasting preliminary injunction request is still pending.
Why it matters: 3 legs of one story. The economists who spent 2 years saying calm down changed their minds in public, the government put projection numbers behind the concern, and a lawsuit over algorithmic layoff selection shows the legal exposure arriving before the policy does. A week after the Fed stood up its AI jobs task force, the institutions are converging on the same question from every side.
What to do: If AI-derived scores (activity data, token dashboards, algorithmic rankings) touch any workforce decision at your company, I’d get employment counsel reviewing how those numbers feed the decision now; allegation or not, the Meta complaint is a template other plaintiffs’ firms will reuse, and discovery is the cost either way. Make reskilling a named 2027 budget line. And when the board asks about AI and jobs, the Stanford letter is the citable consensus shift.
References:
Kimi K3 (Moonshot AI, 2026-07-16): https://www.kimi.com/blog/kimi-k3
Google Gemini launch delayed (Bloomberg, 2026-07-16): https://www.bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals
Gemini models page, “3.5 Pro coming soon” (Google DeepMind, accessed 2026-07-19): https://deepmind.google/models/gemini/
Kimi K3 market reaction (Fortune, 2026-07-17): https://fortune.com/2026/07/17/china-moonshot-kimi-k3-markets-china-ai/
Alphabet stock on Gemini delay (CNBC, 2026-07-16): https://www.cnbc.com/2026/07/16/alphabet-stock-gemini-3-5-pro-ai.html
Kimi K3 release coverage (VentureBeat, 2026-07-16): https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems
Kimi K3 and the open-model race (Axios, 2026-07-17): https://www.axios.com/2026/07/17/china-ai-kimi-k3-open-source-anthropic-opus
WebDev Arena leaderboard (Arena, accessed 2026-07-20): https://arena.ai/leaderboard
Apple briefly passes Nvidia in market value (CNBC, 2026-07-17): https://www.cnbc.com/2026/07/17/apple-nvidia-aapl-nvda-market-cap.html
Anthropic plans IPO investor meetings (Bloomberg, 2026-07-15): https://www.bloomberg.com/news/articles/2026-07-15/anthropic-is-said-to-plan-ipo-investor-meetings-as-listing-nears
Anthropic IPO coverage (CNBC, 2026-07-15): https://www.cnbc.com/2026/07/15/anthropic-ipo-banks-investor-meetings.html
Ode with Anthropic launch (Ode, 2026-07-15): https://www.ode.com/press/anthropic-blackstone-and-hellman-friedman-introduce-ode-with-anthropic-an-enterprise-ai-services-firm
Ode with Anthropic release (Business Wire, 2026-07-15): https://www.businesswire.com/news/home/20260715205134/en/
Claude for Teachers (Anthropic, 2026-07-14): https://www.anthropic.com/news/claude-for-teachers
CA$10M Canadian AI research commitment (Anthropic, 2026-07-14): https://www.anthropic.com/news/canadian-ai-research
Nadella on Anthropic’s Fable policy (CNBC, 2026-07-16): https://www.cnbc.com/2026/07/16/microsoft-ceo-says-anthropic-fable-request-policy-doesnt-make-sense.html
TSMC Q2 2026 results (TSMC, 2026-07-16): https://pr.tsmc.com/english/news/3326
TSMC 2Q26 results with guidance, Form 6-K (SEC EDGAR, 2026-07-16): https://www.sec.gov/Archives/edgar/data/0001046179/000104617926000451/a2q26e_withguidancexfinal.htm
ASML Q2 2026 financial results (ASML, 2026-07-15): https://www.asml.com/en/news/press-releases/2026/q2-2026-financial-results
Fireworks AI Series D (Fireworks AI, 2026-07-15): https://fireworks.ai/blog/series-d-announcement
Reflection AI-Nebius compute deal (Bloomberg, 2026-07-14): https://www.bloomberg.com/news/articles/2026-07-14/nebius-to-sell-1-billion-in-ai-capacity-to-startup-reflection
Netflix Q2 2026 shareholder letter (Netflix, 2026-07-16): https://s22.q4cdn.com/959853165/files/doc_financials/2026/q2/FINAL-Q2-26-Shareholder-Letter.pdf
Netflix Q2 2026 earnings exhibit (SEC EDGAR, 2026-07-16): https://www.sec.gov/Archives/edgar/data/0001065280/000106528026000211/ex991_q226.htm
Netflix stock drop on Q3 outlook (Variety, 2026-07-16): https://variety.com/2026/tv/news/netflix-q2-2026-earnings-1236812558/
CISA SharePoint hardening alert (CISA, 2026-07-14): https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations
CISA KEV catalog additions (CISA, 2026-07-16): https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
SharePoint zero-day KEV coverage (The Hacker News, 2026-07-16): https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html
CVE-2026-58644 technical analysis (Rapid7, 2026-07-16): https://www.rapid7.com/blog/post/etr-cve-2026-58644-microsoft-sharepoint-server-unauthenticated-remote-code-execution-vulnerability-exploited-in-the-wild/
ServiceNow CVE-2026-6875 advisory (ServiceNow, 2026-07-13): https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947
ServiceNow sandbox escape coverage (Security Online, 2026-07-14): https://securityonline.info/servicenow-sandbox-escape-cve-2026-6875/
GPT-Red disclosure (OpenAI, 2026-07-16): https://openai.com/index/unlocking-self-improvement-gpt-red/
GPT-Red prompt-injection coverage (Help Net Security, 2026-07-16): https://www.helpnetsecurity.com/2026/07/16/openai-gpt-red-prompt-injection-test/
New York hyperscale data-center moratorium (Governor of New York, 2026-07-14): https://www.governor.ny.gov/news/first-statewide-moratorium-new-hyperscale-data-centers-launched-governor-kathy-hochul
New York moratorium coverage (CNBC, 2026-07-14): https://www.cnbc.com/2026/07/14/new-york-ai-data-center-ban.html
China AI-agent rules analysis (IAPP, 2026-07-08): https://iapp.org/news/a/china-s-new-ai-rules-ethics-ai-agents-and-anthropomorphic-ai
China AI-agent regulations analysis (Bird & Bird, 2026-07-15): https://www.twobirds.com/en/insights/2026/china/china’s-new-regulations-on-ai-anthropomorphic-interactive-services
WAICO charter signing (US News, 2026-07-16): https://www.usnews.com/news/world/articles/2026-07-16/twenty-nine-countries-sign-agreement-to-establish-global-ai-cooperation-body
Xi opens World AI Conference (NPR, 2026-07-17): https://www.npr.org/2026/07/17/nx-s1-5897285/chinas-xi-calls-for-step-up-of-global-effort-in-ai-as-us-curbs-squeeze-chinas-tech-access
EU AI Act regulatory framework (European Commission, accessed 2026-07-19): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
We Must Act Now statement (Stanford Digital Economy Lab, 2026-07-13): https://digitaleconomy.stanford.edu/news/wemustactnow/
Economists’ AI warning coverage (Al Jazeera, 2026-07-13): https://www.aljazeera.com/economy/2026/7/13/hundreds-of-experts-warn-the-world-must-prepare-now-for-ais-impact
Artificial intelligence, information technology, and employment, 2024-34 (BLS, 2026-07-16): https://www.bls.gov/opub/ted/2026/artificial-intelligence-information-technology-and-employment-2024-34.htm
Industry and occupational employment projections overview (BLS Monthly Labor Review, 2026-07-16): https://www.bls.gov/opub/mlr/2026/article/industry-and-occupational-employment-projections-overview.htm
Computer programmers, Occupational Outlook Handbook (BLS, accessed 2026-07-20): https://www.bls.gov/ooh/computer-and-information-technology/computer-programmers.htm
Meta employees’ AI-layoff lawsuit (US News, 2026-07-14): https://www.usnews.com/news/business/articles/2026-07-14/26-meta-employees-sue-alleging-ai-driven-layoff-picks-hit-workers-on-medical-and-parental-leave
Meta lawsuit coverage (CBS News, 2026-07-14): https://www.cbsnews.com/news/26-meta-workers-sue-ai-aided-layoffs-medical-family-leave/
Meta lawsuit coverage (Fortune, 2026-07-15): https://fortune.com/2026/07/15/meta-workers-sue-over-ai-layoff-math/
Judge denies injunction against Meta layoffs (Reuters via Yahoo Finance, 2026-07-17): https://ca.finance.yahoo.com/news/us-judge-wont-block-meta-174519701.html


