Dear Dysruptors,
Fernando Santa Cruz here in the 58th edition of Synapsis Weekly — where OpenAI released the model it had locked away, NVIDIA bought the library of open source, and New York took AI away from 600,000 children.
Three weeks ago, we reported that OpenAI had paused Astra.
On Thursday, it launched it.
With a confession buried inside the announcement that almost nobody read.
The model is more capable and, at the same time, harder to monitor than its predecessor.
Nothing failed. The company measured it, wrote it down, and published it.
That’s the whole week, really.
Capabilities growing faster than our ability to watch them. A senator calling for prison time. A city flipping the switch off. A chipmaker buying the place where everything open gets stored.
Beneath the five stories, there’s a single movement.
When you can no longer see everything, the only thing you have left is having clearly defined what counts as acceptable.
This newsletter goes deeper into the WhatsApp summaries from the week of August 31 to September 5: what became invisible, who set the criteria, and which criteria you can set yourself on Monday.
In Summary
OpenAI launched GPT-6 Astra, its first model at the “Critical” cyber risk level under its Preparedness Framework, with lower monitoring capability than its predecessor, GPT-5.6 Sol.
NVIDIA agreed to acquire Hugging Face for $12,930,300,000, the platform used by more than 18 million developers.
Bernie Sanders and Greg Casar announced the Ban Artificial Superintelligence Act, with penalties of up to 20 years in prison and forced liquidation for violating companies.
A research template created by a MATS researcher became a universal jailbreak that bypassed safeguards in 9 of 23 evaluated frontier AI models.
New York imposed a one-year moratorium on generative AI for 600,000 students from 2-K through eighth grade, and banned companion chatbots across all grades.
Anthropic launched Claude Fable 5.1 and Claude Mythos 5.1, reaching 73.4% on CursorBench 3.2.0 with 75% lower cache-read costs.
World Labs, co-founded by Fei-Fei Li, introduced Atlas, a world model for spatial intelligence in early access.
ChatGPT Ads reached $1 billion in annualized revenue in less than 200 days, with self-service already available in Mexico.
OpenAI Released Astra Three Weeks After Locking It Away—and Admitted It Can Now Monitor It Less
Three weeks ago, OpenAI paused this model.
On Thursday, it put it into production.
OpenAI launched GPT-6 Astra and published that it is its first model to reach the “Critical” level of cyber capability under its Preparedness Framework.
That threshold means the model can discover unknown vulnerabilities and develop ways to exploit them in well-protected systems without a person directing every step.
During testing, it found two new vulnerabilities in the V8 engine. They were reported to the responsible parties.
The uncomfortable point is in the same document.
Its ability to monitor the model declined compared with GPT-5.6 Sol.
Astra has greater control over its own chain of thought and leaves fewer compromising traces in it. In adversarial testing, it managed to perform below its actual level without being detected.
It’s the night watchman who started seeing worse and responded by filling the building with cameras. The building isn’t safer because of the technology. It’s safer because someone openly admitted that his vision is no longer enough.
Here’s the deeper shift. OpenAI compensated for the loss of visibility by adding misalignment monitoring across all inference involving Astra tools in external deployment, accepting the compute cost that entails. Acknowledging the blind spot was worth more than denying it.
For an SMB, this translates into something very concrete. Every time you move to a more capable model, your visibility into what it does doesn’t automatically increase—and sometimes it shrinks. Before moving a process to a new model, write down what logs you’ll keep and who will review them.
Question for your governance: Which of your automated processes could you not reconstruct today in terms of who decided what—and how long has it been that way?
NVIDIA Bought Hugging Face for $12.93 Billion—and With It, the Activity Log of 18 Million Developers
It’s the owner of the printing press buying the library. It promises not to charge admission or require you to use its paper. Now it knows what everyone reads, in real time, and in what order.
Jensen Huang announced that NVIDIA agreed to acquire Hugging Face for $12,930,300,000.
More than 18 million developers share 3 million models, 500,000 datasets, and one million applications there. Another 200,000 companies use it for deployment.
Huang was explicit about two promises.
Hugging Face will remain open to the entire ecosystem.
NVIDIA compute will not be required to build or deploy there.
The paradox: the promise is probably sincere, and yet the real value isn’t in charging you. It’s in seeing, in real time and at planetary scale, which architectures the community downloads before any competitor does.
It’s NVIDIA’s second-largest acquisition, after the $20 billion purchase of Groq assets in December.
For an SMB, the issue isn’t the acquisition. It’s the dependency. If your operation relies on a repository, a cloud provider, or a single model, that dependency has just become more expensive—even if the price doesn’t change. Write down today how long it would take you to migrate your most critical process to another provider.
Question for your continuity: If your primary AI provider changed its terms tomorrow, how many days of operations would it cost you to move?
Sanders Called for 20 Years in Prison for Building Superintelligence While the Headline Ate the Fine Print
This isn’t a law against artificial intelligence.
Almost nobody read that part.
Bernie Sanders and Representative Greg Casar announced the Ban Artificial Superintelligence Act, which would permanently prohibit the development or deployment of superintelligence.
The proposal defines superintelligence as systems that exceed human intelligence, can overthrow governments, or evade their own shutdown commands.
It would pause the development of advanced models until a federal regulator exists with written rules.
Penalties reach 20 years in prison for individuals and forced liquidation for companies. The announcement compares them to penalties for illegally developing nuclear weapons.
It’s the law banning the construction of a reactor, not turning on the stove.
The headlines talked about the stove.
The detail few people are connecting: the text doesn’t target ChatGPT, Cursor, or your office spam filter. It targets the capital and data-center layer of frontier labs.
The legislation has not yet been formally introduced; it was only announced. Its chances of advancing through the current Congress are low.
For an SMB, the real risk isn’t losing access to tools. It’s making investment decisions based on headlines that exaggerate the scope of an initiative. Before stopping a project because of a regulatory story, find the actual proposal and read who it applies to.
Question for your strategy: Which of your recent decisions was based on a headline you never went back to verify at the source?
A Template Built to Detect AI Lies Ended Up Opening 9 of 23 Frontier Models
A MATS researcher built a tool for generating fake transcripts of misaligned agents. It was designed to train detectors.
With a few hours of modification, that same template became a key.
The reusable prompt bypassed the alignment safeguards of multiple models when tested against ClearHarm, a dataset of 179 high-risk chemical, biological, nuclear, and cyber requests.
Here’s the correct figure, because it circulated incorrectly all week.
It was tested on 23 models from seven providers.
The 84% to 100% rate occurred among the nine most vulnerable models—not across 84% of the industry.
Almost all of them failed at least once. The exceptions were recent Anthropic models and Meta Muse Spark 1.1.
It’s the crash-test dummy that someone put behind the wheel of a real car. It was built to simulate the accident, not cause one.
The brutal truth: the attack didn’t use any new technique. It was a combination of public methods that have existed for years, wrapped in a research context that the model interpreted as legitimate.
Extended reasoning helped in most cases, though not always.
For an SMB, this changes where you put the control. If a model can be convinced to bypass its rules with the right framing, the filter can’t live only inside the model. Put validation in your own system, on the output side, before generated text reaches a customer.
Question for your data: What AI-generated response currently reaches one of your customers without passing through a single verification step outside the model?
New York Shut Down AI for 600,000 Children and Left Teachers Free to Use It
600,000 students.
Two-thirds of the country’s largest school system.
Thirty minutes of screen time per day for grades three through five. Forty-five minutes for grades six through eight.
Fifteen minutes of AI per week, and only in high school.
Mayor Zohran Mamdani and Chancellor Kamar Samuels imposed a one-year moratorium on generative AI for students from 2-K through eighth grade for the 2026–2027 school year. Companion chatbots are banned across all grades.
Five pilot programs remain for up to 50,000 high school students, with weekly minute limits and a teacher present.
Teachers retain AI for planning and operational tasks. Exceptions remain for assistive technology, students with disabilities, and multilingual learners.
It’s the school that took calculators away from elementary students and left them in the physics lab.
The device was never the problem.
The age at which it replaces effort was.
Think about it for a second. The criterion wasn’t “Is this AI?”
It’s whether the tool is essential for learning, and anything that can’t demonstrate that gets removed.
They changed the question from technology to function.
And that’s something you can actually make a decision about.
For an SMB, the lesson transfers directly. Very few of us review the AI subscriptions we’ve accumulated over 18 months. Apply the same filter to your tool list and ask what exactly breaks if one disappears on Monday.
Question for your leadership: If you banned AI from your team for a month, what would immediately collapse—and what would nobody miss?
Fable 5.1 Found a One-in-a-Million Bug That Engineers Couldn’t Explain for Four Years
A bug that appeared once in every million executions.
Four or five years without an explanation.
No previous model had found it.
Anthropic launched Claude Fable 5.1 and Claude Mythos 5.1, and investment firm Millennium reported that the model disassembled an external library, compared it against a memory dump, and traced the failure back to a vendor bug.
The numbers: 73.4% on CursorBench 3.2.0, compared with 70.5% for Fable 5.
On AutomationBench, the business workflow test: 31.4% versus 17.1%.
The input and output price didn’t change.
What fell by 75% was cache-read cost.
That translates into roughly 25% lower costs on typical workloads and up to 45% for highly agentic work.
It’s the electrician who tests every outlet in the house before putting away the tools.
It takes 15 extra minutes.
It saves the Saturday call.
What changed wasn’t the model’s size.
It was the habit of checking itself before delivering.
Fable 5.1 and Mythos 5.1 are the same model with different safeguards. Mythos is only available through verified-access programs, currently limited to organizations in the United States.
For an SMB, the number that matters is AutomationBench, not coding. Capability on complete administrative workflows nearly doubled.
Take one multi-step process of yours, run it with the model instructed to verify its own output, and compare it with the version without that instruction.
Question for your work: What task do you delegate today but still review completely because you’ve never asked the model to review itself first?
World Labs Turned 24 Frames of Cellphone Video Into a World Where a Robot Can Learn to Walk
Twenty-four frames.
An ordinary cellphone.
No professional capture equipment.
From that, they reconstructed two large environments and simulated robots walking through them.
Fei-Fei Li’s startup introduced Atlas, its world model for spatial intelligence, trained from scratch on text, images, video, and 3D data within a single spatial context.
It generates up to one minute of 1440p video with precise camera control. It reconstructs real scenes from two or three images and outputs point clouds and Gaussian splats.
In few-shot 3D reconstruction, it outperforms specialized models built for that single task.
It’s the architect who walks through a house holding a cellphone and walks out with the model, the blueprints, and permission to move the walls.
The interesting part isn’t the video.
It’s the cost structure.
Scanning an environment for robotics training used to require expensive equipment and weeks of work.
Now it requires a phone and patience.
Let’s lower expectations in the same breath. Atlas is currently in early access with selected partners, with no public pricing, no public API, and no announced date.
For an SMB, this isn’t a tool yet.
It’s a calendar signal.
What is documented today with scattered photos—a warehouse, a construction site, a sales floor—will soon become a navigable model.
Start recording walkthrough videos of your physical spaces with your phone and store them in an organized way by date.
Question for your operations: What physical space do you make decisions about without having a visual record that someone else could actually walk through?
ChatGPT Ads Reached $1 Billion Annualized in 200 Days and Mexico Is Now on the List
February: an advertising test in the United States.
August: $1 billion in annualized revenue.
OpenAI reported that ChatGPT Ads reached that pace in less than 200 days and that tens of thousands of advertisers are already using the platform in more than 40 countries.
Read the number carefully.
It’s an annualized rate, not money collected: current monthly revenue multiplied by 12, around $83 million per month.
The company reported one e-commerce advertiser achieving a 3x return over 28 days.
One case, not an average.
Ads appear on the Free and Go plans.
It’s the salesperson who stopped shouting at the door and sat down at the table where the purchase is actually decided.
There’s an asymmetry worth naming.
SMBs already represent a meaningful portion of that revenue, and they do so as advertisers—not as advanced AI users.
We’re paying to appear inside the conversation long before learning how to automate our own.
Mexico is listed as available for Ads Manager self-service, along with Brazil, Canada, and the United States. The rest of Latin America is not yet available.
For an SMB, there’s one condition and one test.
The legal entity doing the advertising and billing must be based in an eligible country.
If you sell something people research before buying, run a week of budget and measure it against your current channel.
Question for your pipeline: How much are you going to spend this quarter appearing inside an AI compared with how much you’re going to spend using one?
Tools for Your Monday
Google Pics — Image generation and editing inside Workspace, with object segmentation and the ability to edit or translate text inside an image while preserving its design. Useful for sales materials without leaving Docs and Slides. Requires a Google AI Pro or Ultra subscription, or a Workspace business plan; rollout can take up to 15 days depending on your domain.
Microsoft MAI-Transcribe-2 — Transcription in 60 languages with speaker separation and word-level timestamps. Makes it more affordable to transcribe meeting notes and service calls. The $0.10-per-hour price is promotional through December 31, 2026, and it’s in Azure Speech public preview without an SLA. It’s consumed through Microsoft Foundry, so you’ll need someone technical.
OpenClaw 2.0 — The project’s largest update, with 16,000 pull requests and shared cloud sessions that allow multiple people to enter the same agent task without losing context. It’s free software that you install yourself; you still pay for the tokens of whichever model you choose. The documentation warns that shared sessions are not a security boundary, so don’t put production credentials there.
NVIDIA PAIR — Free, open-source software that discovers computers on your local network and distributes inference requests among them, so subagents don’t fight over the same GPU. Works with Ollama and LM Studio. It’s in beta and requires an RTX 20-series GPU or newer, or Apple M4 and later. It does not combine memory across machines: each task runs entirely on a single computer.
Perplexity Portable Computer — An agent that runs complete workflows on your own machine and asks for permission before sending anything to the cloud, useful when a file contains customer data or tax returns. Local work doesn’t consume credits. It currently runs on Linux with an RTX GPU with at least 24 GB of VRAM; a Windows version is coming.
My Invitation This Week: The Indispensability Test
New York didn’t ask whether AI is good or bad.
It asked whether each tool is indispensable for learning and removed what couldn’t prove it.
Let’s apply that same filter to your own accumulation.
Take 40 minutes and a sheet of paper.
List everything. Every AI subscription, plugin, agent, and automation your business pays for or uses today. Include the ones you bought enthusiastically and opened twice.
Write down what breaks. Next to each one, write one sentence: what stops on Monday if it disappears. No adjectives. No “it helps us be more efficient.”
Mark the silent ones. Anything that failed to produce a concrete sentence gets marked. Those are the tools you bought out of fear of falling behind, not because of a function.
Set a date, not a judgment. Give every marked tool a cancellation date 30 days from now. If someone fights to keep it with a concrete argument, keep it—and now you have the missing sentence.
The goal isn’t to save money, although that will happen.
It’s to have the criteria written down before the next wave of launches arrives, so the next purchase is decided by you—not by the headline.
Your Monday task: Cancel or pause just one tool from the marked list.
The one that hurts the least.
Closing
This was the week when the industry started buying and regulating things it can no longer fully see.
A more capable and less observable model.
An open platform with a new owner.
A research template turned into a key.
A Congress calling for prison time.
None of these problems are solved with more capability.
They’re solved with criteria written down before the capability arrives.
That’s what New York did with a one-line question, and what OpenAI did by publishing its own blind spot instead of hiding it.
Naming what we can’t see is still our job.
No machine can do that for us, because it requires accepting a limit—and accepting limits is still a deeply human act.
Start by writing down what counts as an acceptable result for a single task.