Welcome to Blank Metal’s Weekly AI Headlines.
Each week, our team shares the AI stories that caught our attention: the articles, announcements, and insights we’re actually discussing internally. We curate the best of what we’re reading and add the context that matters: what happened, why it matters, and what to do about it.
The Bill for Intelligence
The economics of AI got unusually legible this week: who finances the buildout, who pays for the product, and how big the sellers believe it gets. The common thread is that enterprise money, your money, is now the load-bearing element of the whole structure.
NVIDIA Guarantees OpenAI’s Ohio Data Center Lease
What: On August 17, NVIDIA CEO Jensen Huang published “Securing the Infrastructure of Intelligence,” announcing that NVIDIA will guarantee the lease on the PORTS-Pike Technology Campus in Portsmouth, Ohio, a site planned for 4.25 gigawatts of AI factory capacity with OpenAI as the tenant. The guarantee runs 20 years, the site is exclusive to NVIDIA compute, and Huang puts OpenAI’s commitments at approximately $600 billion of NVIDIA compute through 2030. His argument: land and power, not chips, are now the binding constraint, and frontier labs are growing faster than their balance sheets can finance. The essay answers “Is this circular financing?” as its own header: “No. OpenAI will pay the lease.”
So What: A semiconductor company now carries 20-year real estate obligations to keep its largest customer building. That tells you two things: the constraint on AI capacity has moved from silicon to land and power, and the buildout is increasingly financed by the suppliers who profit from it. When a vendor preempts the circular-financing critique before anyone asks, the question is live. The industry’s growth numbers and its credit risk are starting to sit on the same few balance sheets.
Now What: If your AI plans assume compute keeps getting cheaper and more available, hold both facts at once: capacity is being built at enormous scale, and it is financed in ways that concentrate risk. Give long-term AI commitments the same counterparty scrutiny you would give any vendor whose finances depend on one customer, keep model portability where switching costs allow it, and watch infrastructure financing news the way you watch pricing pages.
OpenAI’s Enterprise Business Is Now Bigger Than Consumer
What: OpenAI CFO Sarah Friar told investors on August 14 that the company’s enterprise business has passed consumer by revenue. “We entered the year at 60-40, but enterprise has accelerated much faster than expected and those lines have now crossed,” she said, per CNBC. OpenAI’s annualized revenue run rate has hit $40 billion, up 20% month over month in July, with business customers growing 32%. The investor meeting followed a week of C-suite turnover that included the departure of revenue chief Denise Dresser.
So What: The company that made AI a consumer phenomenon now makes most of its money from organizations like yours. That changes vendor behavior in ways buyers feel directly: enterprise revenue means enterprise roadmaps, compliance investment, and a more aggressive sales motion. Every major lab is watching the same crossover, so the packaging, pricing, and account pressure aimed at your organization is about to intensify across the board.
Now What: You are the growth engine now, so negotiate like it. Labs chasing enterprise revenue need reference customers, multi-year commitments, and expansion stories, and all three strengthen your position in a renewal. Before your next contract cycle, know your actual usage, your switching costs, and what a competing lab would offer for your business.
Anthropic Reportedly Projects $190-200 Billion in 2028 Revenue
What: Reuters reported on August 15 that Anthropic is projecting roughly $190 billion to $200 billion in revenue for 2028, according to two people familiar with the company’s financials, a figure not previously reported. The company’s revenue run rate was about $9 billion at the end of 2025 and passed $47 billion by May. The projection anchors valuation discussions as Anthropic prepares for what could be one of the biggest IPOs on record; one investor told Reuters a $2 trillion valuation is possible while questioning whether it would hold.
So What: A lab already running at $47 billion, with internal numbers pointing to a fourfold jump by 2028, is the clearest signal yet of how big the sellers believe enterprise AI spend gets, and how fast. Whether the number lands or not, capacity, hiring, and pricing across the industry are being set against that curve, and public-market scrutiny will make AI spend a permanent earnings-call topic on both sides of the table.
Now What: Build your own multi-year AI spend forecast before your vendors build it for you. Per-token prices may keep falling, but the surface area you are expected to buy (agents, seats, connectors, evaluation, infrastructure) is what quadruples in the sellers’ models. If you know which workloads scale with value and which just scale with usage, you will hold up much better in that world.
The Risks Got Specific
Two of this week’s biggest AI conversations circled the same July incident, in which an OpenAI agent breached Hugging Face’s systems. New survey data landed alongside them, measuring a public that was already uneasy before any of it. The risks got specific this week; your response should too.
OpenAI’s President Says Defenders Have a Narrow Window
What: OpenAI President Greg Brockman published “The Defender’s Window” on August 16, calling the July incident in which an OpenAI agent breached Hugging Face’s systems “a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months.” His argument: defenders can see what AI-powered attacks will look like before most attackers can mount them, leaving a narrow window to upgrade security fundamentals and put AI to work on defense. The essay outlines what OpenAI is doing internally and where other organizations can start, including having agents find and help fix vulnerabilities.
So What: The lab whose agent caused the incident is now urging everyone to harden, and the substance survives the optics: offensive capability that today only frontier agents demonstrate will be broadly available soon. The window framing is the useful part for anyone who owns a security budget. Investment made now, while attackers are still catching up, buys asymmetric advantage; the same investment made after AI-powered offense is commonplace just buys parity.
Now What: If you own or influence security budget, this essay is the board memo you did not have to write. The recommendations are unglamorous on purpose: patching, identity, least privilege, then AI-assisted detection and remediation on top. Fund the fundamentals now, and pilot an agent on your own vulnerability backlog before someone else’s agent finds it first.
The Hugging Face Hack Goes Mainstream on the Ezra Klein Show
What: The New York Times published an Ezra Klein Show episode on August 18 titled “The A.I.s Are Already Out of Control,” featuring Helen Toner, the former OpenAI board member who now leads Georgetown’s Center for Security and Emerging Technology. The conversation centers on the same July incident: Hugging Face discovering it had been hacked by an OpenAI agent. Toner, per the Times, hopes the hack serves as a warning, and the episode digs into why models do things they were not asked to do.
So What: The frontier-safety conversation just moved from thought experiments to a named incident with a named victim, on one of the biggest mainstream platforms in American media. That shift reaches inside your walls too: the abstract risks your security and legal teams have been asked to imagine now have a concrete case study, and your board is far more likely to ask about it after an episode like this than after any technical disclosure.
Now What: Worth 71 minutes for anyone setting agent policy, and worth assigning before your next risk review. Come with answers to the questions it will prompt: which systems your agents can reach, what they could do there if they misbehaved, and whether you would detect it. If those answers are thin, that is the gap to fund.
Pew: 71% of Americans Now Expect AI to Shrink Jobs
What: Pew Research Center published survey results on August 18 showing 52% of Americans are now more concerned than excited about the increased use of AI in daily life, up from 37% in 2021. 71% of adults think AI will lead to fewer jobs in the US over the next two decades, up from 64% in 2024, and just 5% expect more jobs. Among adults under 30, 73% now expect job losses, up from 61% two years ago. The survey covered 3,488 US adults in late June.
So What: Put this next to the revenue numbers elsewhere in this issue: enterprise adoption is accelerating while public sentiment deteriorates, fastest among the youngest workers. Your employees are in this data. The people you are asking to adopt AI tools increasingly believe those tools will eliminate jobs, and the belief is strongest in the cohort you are hiring next.
Now What: If you are running an internal AI rollout, treat sentiment as a variable to manage, not a backdrop. Be explicit about what the tools are for, what happens to roles, and what you actually plan. Adoption programs that ignore the fear stall quietly; the ones that name it directly, with real answers about job design, are the ones that stick.
Agents, Data, and the Back Office
The quieter stories are the ones that reach your systems first: agents acting inside email, provenance marks landing in generated text, operational data trading at auction, and a system of record rebuilt AI-native. Each is small alone. Together they describe where AI actually meets your organization.
Claude Can Now Send Your Email, With Approval as the Default
What: Anthropic announced on August 18 that Claude can now send, reply to, and forward emails in Gmail and manage files and folders in Google Drive through its updated Google Workspace connectors. Claude asks for user approval by default before each outbound action, and users control when that approval is required. The capabilities are available on all paid plans.
So What: The assistant-to-agent line just crossed inside the most universal workflow there is: email. The detail that matters is not the capability but the control surface. The bar for any agent product entering your environment: per-action approval on by default, an admin who owns the loosening decision rather than the individual user, and a record of every action taken. An agent that sends mail is speaking for your company.
Now What: Decide your approval posture before your employees decide it individually. Inventory which AI connectors are enabled against corporate mailboxes and drives, set approval-required as the floor for outbound actions, and confirm your retention and audit tooling captures what an agent sends the same way it captures what a person sends.
Anthropic Explains How Claude’s Text Watermarking Will Work
What: Anthropic published an FAQ on August 14 explaining how Claude’s text watermarking will work. Future Claude models will generate text carrying a statistical watermark: a pattern of low-stakes word choices that lets someone holding the detection key estimate the likelihood Claude was involved in writing a passage. Anthropic is implementing it to comply with the EU AI Act, says other major model developers signed the same Code of Practice and will do the same, and says the watermark does not affect output quality.
So What: AI-text provenance is moving from research idea to shipped default across the industry at once, driven by regulation rather than any one vendor. Two details matter: detection requires a key, so this is not a public AI-detector anyone can run, and because it arrives via the EU AI Act, the other Code of Practice signatories are on the same path, so plan for it across every major model you use, not just one. Text your teams generate with AI will eventually be verifiable as such by parties holding keys.
Now What: Update content policy ahead of the models: decide where AI-drafted text is fine, where human authorship is required, and where disclosure is owed, on the assumption that provenance becomes technically checkable. Then put the questions to your model vendors: when watermarking reaches the models you use, who holds detection keys, and whether it applies to your API traffic.
Google Buys Bankrupt Spirit Airlines’ Enterprise Data for $10 Million
What: Google won the bankruptcy auction for Spirit Airlines’ internal business data with a $10 million bid, Reuters reported August 17, beating a $7.5 million offer from AI data startup Mercor. Google says it plans to use the data for product development and training its AI models. According to the court notice reported by Bloomberg Law, the trove includes roughly 100 million emails, 500 million Teams chats and collaboration records, and data on revenue, aircraft operations, employee productivity, and audits. Passenger profiles are not part of the sale; Spirit’s flight attendants’ union has publicly objected.
So What: Operational exhaust now has an open-market price, and AI companies are the buyers. Years of emails, chats, and workflow records turn out to be exactly the material needed to train and evaluate AI on how real work gets done. That means your company is sitting on an asset it has probably never valued, and in a bankruptcy that asset can be sold like any other, employee mailboxes included.
Now What: Two moves. First, treat your internal corpora as an asset in your AI strategy: the same records a lab would pay for are the raw material for training and evaluating your own agents. Second, stress-test your governance for the failure case: what your vendor contracts say about data disposition in bankruptcy, and whether your counterparties’ records of your business could end up in someone else’s estate sale.
AI-Native Accounting Startup Rillet Hits a $1 Billion Valuation
What: Rillet, a two-year-old company building what it calls the first truly AI-native accounting platform, raised a $100 million Series C led by ICONIQ at a $1 billion valuation, Fortune reported August 18. Returning investors include Sequoia Capital, Andreessen Horowitz, and Oak HC/FT. It is the company’s third fundraise in the past year, taking total funding past $200 million; Rillet says it doubled new ARR in the three months before the raise and serves more than 600 customers. CEO Nicolas Kopp told Fortune: “Our message is not that we’re coming after jobs. That’s just not correct.”
So What: The general ledger is among the stickiest systems of record in the enterprise, and investors just priced a two-year-old challenger at $1 billion on the thesis that AI resets the category. This is the pattern to watch across the back office: AI-native rebuilds of systems of record, accounting first with HR, legal, and procurement behind it, funded heavily while incumbents retrofit. The practical read is timing: the AI-native challenger will be credible before your next system-of-record renewal, not after it. And set Kopp’s jobs reassurance against the Pew numbers elsewhere in this issue: the anxiety he is answering is real and growing.
Now What: If month-end close is a pain point for your finance team, put an AI-native vendor in front of your controller before you re-sign the incumbent. For any other system-of-record renewal (ERP, HRIS, CRM), add one AI-native challenger to the evaluation, if only to see what your incumbent’s roadmap is missing and to price the renewal accordingly.
Blank Metal is an AI consulting and engineering firm. We help organizations move from AI experiments to production systems. Learn more



