This was the week two frontier labs shipped at once. OpenAI put GPT-6 Astra into the world and called it its first Critical-cyber model. Anthropic answered with Claude Fable 5.1 and Mythos 5.1, the same weights under two safeguard stacks, and a 75% cut on Fable cache reads. Google added a third lane with Gemini 3.8 Flash and a Cyber twin built to hunt vulnerabilities.
Around that: Nvidia is in talks to buy Hugging Face for $12.9 billion, Tim Cook sent his last CEO memo at Apple, a Langflow remote-code flaw is already being exploited, and Nvidia put $3.5 billion into custom silicon with MediaTek.
The highlights
- OpenAI: GPT-6 Astra saturates ARC-AGI-3 and hits Critical cyber
- Anthropic: Fable 5.1 and Mythos 5.1, 75% cheaper cache reads
- Google: Gemini 3.8 Flash for agents, Cyber for vulns
- Nvidia: In talks to buy Hugging Face for $12.9 billion
- Apple: Tim Cook’s final CEO message
- Security: Langflow CVE-2026-0768 exploited in the wild
- Nvidia: $3.5B MediaTek deal for custom AI silicon
GPT-6 Astra saturates ARC-AGI-3 and hits Critical cyber
OpenAI did not claim Astra broke every benchmark, but the launch numbers are the story: 99.9% on ARC-AGI-3, 98% on FrontierMath Tier 4, a perfect ExploitBench score, and what the company calls state-of-the-art computer use, coding, and science. It is also the first model OpenAI rates Critical for cybersecurity under its Preparedness Framework — with the right tools, it can find previously unknown flaws and develop exploits without a person at every step. Rollout is gated to Plus, Pro, Business, and Enterprise, plus the API, Azure, and Bedrock.
The first day was messy. Paying users expecting access were locked out long enough that Sam Altman publicly apologized. Advanced cyber capabilities stay limited, not on by default. Read our September 4 pulse and OpenAI’s Astra announcement.
Claude Fable 5.1 and Mythos 5.1
Anthropic’s September 1 launch is one model, two products. Fable 5.1 is the generally available Mythos-class model for coding and knowledge work. Mythos 5.1 is the same weights with lighter cyber and biology safeguards, still behind trusted-access programs. Cache reads on Fable drop 75%, and Anthropic says typical token-billed workloads run about 25% cheaper than Fable 5.
Fable 5.1 can now be used to find software vulnerabilities in source code — not to write exploits. Full write-up: Claude Fable 5.1 and Mythos 5.1.
Gemini 3.8 Flash, plus a Cyber twin
Google shipped two Gemini 3.8 Flash variants. The standard Flash is a workhorse for agentic tasks, software development, and multi-step reasoning. Flash Cyber is tuned for vulnerability detection and mitigation. That is the same split Anthropic is making with Fable vs Mythos, and OpenAI is making with Astra’s gated cyber tier: one model for builders, a harder variant for defenders.
Read the Gemini 3.8 Flash analysis.
In talks to buy Hugging Face for $12.9 billion
Nvidia is in advanced talks to acquire Hugging Face for $12.9 billion. That would put the main open-source model hub — weights, datasets, Spaces, the default place developers pull checkpoints — under the same company that sells the GPUs those models run on. It is still talks, not a closed deal, but it is the largest open-source AI acquisition on the table this year.
Tim Cook’s last CEO memo
Tim Cook sent a final message to Apple employees confirming the step-down and framing a handoff to product-builder leadership after 15 years as CEO. The operational story of his tenure — supply chain, custom silicon, services — is now the starting brief for whoever runs Apple next, including the unfinished Siri and on-device AI work.
Langflow CVE-2026-0768 is being exploited
SecurityWeek reports unauthenticated remote Python execution against Langflow, tracked as CVE-2026-0768, already in the wild. If you run Langflow on a reachable network, patch first and assume the instance was probed. The same week also brought a 12-year-old PostgreSQL issue (PostGREShell / CVE-2026-6471) that turns replication access into code execution, plus VMware Workstation/Fusion host-escape patches.
$3.5B MediaTek deal for custom AI silicon
Separately from the Hugging Face talks, Nvidia is putting $3.5 billion alongside MediaTek to co-develop custom AI processors and automotive SoCs. This is edge and vehicle compute, not another data-center GPU SKU — a hedge as cloud customers design their own accelerators.
Also this week
GitHub changed Copilot model access on Team plans when a user holds seats in more than one organization, so billing and governance stay in sync. And EU regulators named ChatGPT and Reddit Very Large Online Platforms under the Digital Services Act, which triggers systemic-risk audits and a heavier transparency load.
Tools from Tech Bytes
CareerPilot matches a resume to live Ashby, Greenhouse, and Lever openings, with fit scores and rewrite suggestions.
Past Forward turns a photo into a decade-accurate vintage portrait. Free to try.
AI Lab Watch
Anthropic
- Introducing Claude Fable 5.1 and Claude Mythos 5.1 — same model, two safeguard levels.
- Enterprise Frontier Safeguards — safety as a customer control surface.
- Improving alignment and security efforts — staffing the work around the Fable launch.
- Claude Code self-hosted environments — official path to run it on your own infra.
OpenAI
- GPT-6 Astra — the launch post.
- Safety overview — Critical cyber, jailbreak robustness, alignment evals.
- Path to Astra — why the most advanced cyber capabilities stay gated.
- Astra system card — the evals behind the marketing.
Weekday pulses for Aug 31–Sep 6 live on Tech Pulse Daily. Next weekly lands Sunday.
Until next week,
TechBytes Weekly