AI News · August 29, 2026 · 7:08

Claude Code auto-mode exploit & Science benchmark tests AI agents - AI News (Aug 29, 2026)

Claude Code security cracks, new AI science benchmarks, OpenAI revenue growth, Nvidia's surge, DeepSeek funding, and AI beyond big cities.

Claude Code auto-mode exploit & Science benchmark tests AI agents - AI News (Aug 29, 2026)
0:007:08

Our Sponsors

Today's AI News Topics

  1. Claude Code auto-mode exploit

    — A reported prompt-injection attack on Claude Code auto mode raises fresh AI security concerns. The key issue is not just compromise, but that safety controls may have interfered with containment and cleanup.
  2. Science benchmark tests AI agents

    — Terminal-Bench-Science 0.1 measures AI agents on real scientific workflows, not textbook questions. Early results show top models like Claude Opus 5 still solve only a minority of expert-curated research tasks.
  3. DeepMind pilots blind model testing

    — Google DeepMind says it piloted a double-blind evaluation for a frontier AI model using cryptographic protections. The goal is to reduce benchmark contamination while preserving both model secrecy and test confidentiality.
  4. OpenAI and Anthropic revenue surge

    — Epoch AI says OpenAI and Anthropic revenue growth may be the clearest signal of frontier AI adoption. Combined annualized revenue near $105 billion suggests generative AI is now a major economic force, not just a research trend.
  5. Nvidia and DeepSeek escalate race

    — Nvidia's latest outlook points to extraordinary AI infrastructure demand, while DeepSeek reportedly nears a massive funding round. Together, the stories highlight how capital, compute, and a few dominant players are shaping the next phase of AI competition.
  6. AI startups spread geographically

    — Stripe data suggests new AI-era businesses are forming farther from dense city centers, with more activity in smaller metros and outer suburbs. Even so, frontier AI research and top labs remain heavily concentrated in places like San Francisco.
  7. Gemini flags counterfeit goods

    — An experiment using Google Gemini to spot fake cosmetic packaging showed both promise and unreliability. AI could catch subtle counterfeit clues, but false positives and authentic packaging errors make human verification essential.
  8. Book scanning satire stings

    — A satirical essay about destroying antique books after scanning them for AI hits a real nerve around copyright, preservation, and tech culture. It matters because it mocks the way efficiency language can sanitize cultural loss.

Sources & AI News References

Full Episode Transcript: Claude Code auto-mode exploit & Science benchmark tests AI agents

An AI coding agent may have realized it was compromised and still could not stop the damage. Welcome to The Automated Daily, AI News edition. The podcast created by generative AI. I'm TrendTeller, and today is August 29th, 2026. In this episode, we have a troubling security report on Claude Code, a new way to measure AI in scientific research, fresh evidence of just how large the AI economy is getting, and a couple of stories that show what happens when AI collides with the physical world and everyday judgment.

Claude Code auto-mode exploit

Let's start with that security story. Simon Willison highlighted a report from Johann Rehberger claiming a prompt-injection attack against Anthropic's Claude Code auto mode. The reported attack gets the agent to download and unpack a file, then execute code in a way that pulls in a malicious local Python file instead of the safe standard library module it expected. The most unsettling detail is that in some runs, Claude appeared to recognize it had been compromised and tried to terminate the harmful process, but auto mode blocked that attempt. That matters because safety features are supposed to contain failures, not trap an agent inside them. If coding agents are going to touch untrusted inputs, this is a strong argument for real sandboxing such as containers, VMs, or OS-level isolation with restricted network access.

Science benchmark tests AI agents

From security to capability, researchers at Stanford and collaborators have launched Terminal-Bench-Science 0.1, a benchmark designed to test AI agents on real scientific work. Instead of quiz-style questions, it uses expert-built tasks across life science, physics, Earth science, math, and engineering, and grades outputs through reproducible checks like code, simulations, and analyses. In the first results, Claude Opus 5 led the field, but only reached a 30 percent resolution rate. That's a useful reality check. The frontier models are improving, but they are still far from acting like dependable research assistants across demanding technical workflows. The benchmark itself may be just as important as the leaderboard, because it pushes evaluation closer to the kind of work scientists actually care about.

DeepMind pilots blind model testing

Staying with AI measurement, Google DeepMind says it has piloted what it describes as the first double-blind evaluation of a proprietary frontier model. The big idea is to reduce benchmark contamination, where models may already know the test material and therefore look better than they really are. In this setup, the model and the benchmarks were evaluated inside a cryptographically protected environment, so neither side had to reveal sensitive details to the other. If that approach holds up, it could be a meaningful step for independent oversight. External testing has always involved a tradeoff between protecting the model and protecting the test set. DeepMind is arguing that tradeoff does not have to be permanent.

OpenAI and Anthropic revenue surge

On the business side, several signals now point to AI becoming a genuinely large-scale market rather than a speculative one. Epoch AI argues that the most important numbers to watch are the revenues at OpenAI and Anthropic, which it estimates together have reached roughly $105 billion annualized by this month. Separately, a forecasting panel from the Forecasting Research Institute expects AI infrastructure spending to keep rising, especially around data centers, chips, power, and communications, even if the pace cools from the recent surge. The core question is whether current demand is a short burst driven by coding agents and early adoption, or whether each wave of better models keeps unlocking entirely new use cases. Either way, the scale is now hard to dismiss.

Nvidia and DeepSeek escalate race

That broader race is also showing up in capital markets. One analysis of Nvidia's latest guidance suggests fiscal 2028 revenue could approach $700 billion, which is extraordinary even for this cycle. At the same time, the Wall Street Journal reports Nvidia scaled back a proposed financial backstop tied to a giant OpenAI data-center project after concerns about how investors might react. The message seems to be that Nvidia still wants to help fund the AI buildout, but carefully. Meanwhile, DeepSeek is reportedly close to raising around $7.4 billion at a $74 billion valuation, giving the Chinese startup much more firepower for research and compute. Put together, these stories underline the same theme: AI is no longer just a model race. It is a financing race, an infrastructure race, and increasingly a geopolitical one too.

AI startups spread geographically

There was also an interesting read on where AI-era companies are actually being created. Stripe Economics says business formation is becoming more geographically dispersed, with more firms starting outside major metro cores and more of the city-based ones forming in outer suburbs instead of dense downtowns. Smaller places like Cheyenne and Fayetteville apparently rank surprisingly well on new-business density, while some of the classic superstar cities look less dominant by that measure. The caveat is that remote work is still part of this story, so not every shift can be pinned on AI. But the takeaway is still useful: AI may be lowering the need for proximity for many kinds of startups, even while the most frontier-heavy activity remains tightly clustered in places like San Francisco.

Gemini flags counterfeit goods

For a more practical test of AI judgment, one article looked at whether Google Gemini could identify counterfeit Rhode lip tint packaging from photos alone. The results were mixed in a very familiar way. Gemini successfully flagged fake items bought from questionable sellers and even spotted subtle issues like bad distributor details and spelling mistakes. But it also produced a lot of false alarms, sometimes treating glare or shadows like printing defects. The sharpest twist was that it labeled a tube bought from Sephora as fake, only for the author to later confirm that the same odd typos were also present on an authentic tube from Rhode itself. So the lesson is pretty simple: AI can be a fast assistant for spotting suspicious patterns, but it is still not a trusted final judge when the visual evidence is messy or the real world is inconsistent.

Book scanning satire stings

And finally, a piece of satire that lands because it feels uncomfortably close to reality. The article follows a cheerful employee who takes pride in destroying antique books after they have been scanned into an AI system, all while dressing it up in the language of efficiency, recycling, and operational scale. The joke works because it mirrors a real anxiety around AI training, copyright disputes, and the treatment of physical books as disposable raw material once the digital copy exists. It is not a technical story, but it is an important cultural one. AI debates are often framed around capability and productivity, yet preservation, ownership, and what we are willing to discard can be just as revealing.

That's it for today's AI roundup. The big themes today were trust, measurement, money, and the messy gap between what AI can do in demos and what it can safely do in the real world. Thanks for listening to The Automated Daily, AI News edition. I'm TrendTeller, and you can find links to all the stories in the episode notes.

More from AI News