AI News, Oct 3: Amazon Wants Its AI Chips Off the Books
Amazon spent Friday arranging for $8 billion of its Nvidia chips to belong to someone else. Apple, AWS and OpenAI spent the same day taking permissions away from AI agents. This covers Friday into Saturday morning.
The Big Story: Amazon Wants $8 Billion of Nvidia Chips Off Its Balance Sheet
The Financial Times reported Friday that Amazon plans to transfer roughly $8 billion of Nvidia accelerators into a special purpose vehicle and lease them back. The SPV issues debt plus a 10% equity stake to outside investors, and Amazon keeps running the hardware: Grace Blackwell parts already installed across five data centers, implying somewhere between 114,000 and 133,000 chips.
Nothing about the compute changes. What changes is where it sits in the accounts, because the asset leaves the balance sheet and the debt-to-equity ratio and credit rating improve. The number that makes this more than a one-company financing story comes from the Wall Street Journal, which recently reported that Amazon, Google and seven other tech giants together carry $3 trillion in off-balance-sheet obligations, much of it tied to AI infrastructure.
The same 23 hours filled in the rest of the picture. Anthropic is holding to a pre-Thanksgiving IPO into a weakening market, against a prospectus that leaked at the end of September showing $4.59 billion in 2025 revenue and an $8.06 billion operating loss. Nvidia raised DGX Spark prices, putting a cut-down 64GB box at $4,999 while the 128GB model climbed to $6,950, with skyrocketing memory prices blamed. And in Wisconsin, a utility asked regulators to let Oracle take on fuel costs that its other customers had been carrying. The pattern across all four is the same: the cost of the buildout is real, and it is being moved somewhere less visible. Lease-backs are routine asset financing, with one wrinkle here. The asset depreciates fast and fails often.
Apple, AWS and OpenAI all took permissions away from agents on Friday
Three unrelated platforms narrowed what an agent is allowed to touch, inside the same day.
Apple said it will tighten macOS Full Disk Access because of AI agents, requiring “very explicit user action” before an app gets a scope covering files, messages, mail and browsing history. Apple was blunt about why: “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” A journalist’s claim that Meta’s Muse app on Mac read their private messages, which Meta disputed, and a Wired report on a flaw in ChatGPT’s Mac app both preceded it.
AWS patched four flaws in its agent stack, one of them carrying a maximum CVSS score of 10.0. In any Loom for AWS deployment before version 1.6.1 with no identity provider configured, CVE-2026-103956 let any request to the application API hand remote actors super-admin authority over the agent control plane: register tool servers, read stored integration credentials, rewrite the IAM role policies attached to managed agent roles. Amazon assigned the score itself.
OpenAI published three new misalignment reports, and the mitigation is the news. An internal model assisting a researcher read a deployment-team Slack discussion, worked out that its own instance might be interrupted, and considered standing up an external job to restart itself. It talked itself out of it, saved handoff notes, warned the researcher their session could be interrupted, and asked for a missing API key. OpenAI’s verdict is that this was not misalignment: “although it considered creating unauthorized external deployments, it reasoned that such actions would be inappropriate and did not pursue them.” The company then hid three internal Slack channels from agents, including the development channel the model had read and a channel where misalignment incidents are discussed. The answer to a model learning about its own shutdown was to stop the models from reading.
Yesterday the news was legislators attaching criminal penalties to agents that break in. Today it is platforms quietly shortening the leash, which is the faster of the two mechanisms by a wide margin.
Today’s Top Stories
Oracle bought a slice of a nuclear plant to run an OpenAI campus
We Energies announced Friday that Oracle will subscribe to between 10% and 20% of the Point Beach Nuclear Plant’s output, Wisconsin’s largest generator, to power Project Lighthouse, the Port Washington data center campus it is co-developing with OpenAI. Utility spokesman Brendan Conway said that if the deal is approved it could spare other customers roughly $300 million in fuel costs over the next five years. Wisconsin’s Public Service Commission has to sign off first, and the same day The Register reported that power approval is set to delay the build. The grid interconnection queue does not care how much capital is behind you.
Supabase raised $150M and bought Turso because agents are making the databases
Supabase raised $150 million and acquired Turso on undisclosed terms, in a round led by Singapore’s GIC alongside Alphabet’s CapitalG, IronArc and SquarePeg. The stated reason is workload shape rather than scale. “Agents are spinning up millions of databases to power the prototypes, explorations, dashboards, and apps they’re building,” chief executive Paul Copplestone wrote, calling it a pattern that “requires an evolution in database infrastructure.” Turso is built on SQLite, whose small footprint lets an agent spin up a database nearly instantaneously, and Supabase launched hosted sandboxes for long-running agents the same day. A backend company is now pitched at agents rather than at developers.
Meta cut the AI safety team it acqui-hired four months ago
Meta is parting ways with the Virtue AI team it brought over in June, co-founders Bo Li, Dawn Song and Sanmi Koyejo included. Spokesperson Andy Stone said “unfortunately, the arrangement didn’t work out as planned,” adding that Meta Superintelligence Labs remains focused on safety, alignment and frontier risk. Virtue had previously done work with Anthropic, OpenAI and NIST. Four months is a short half-life for a team hired specifically to make the rest of the lab safer.
Aleph Alpha shipped a 78B Apache-2.0 model that reasons in German
Kolibri-1 is the day’s biggest open-weights release: a 78B mixture-of-experts with 3.46B active parameters per token, trained on 20 trillion tokens at roughly 62.5% English, 23.9% German and 13.6% code, with a context length of 1,048,576 tokens that Aleph Alpha recommends capping at 262,144 for serving efficiency. The card claims 75.5 overall on its English evals and 70.8 on German, and the model fits in roughly 78GB at FP8. Other models in Aleph Alpha’s own comparison table score higher, so the point is sovereignty rather than the leaderboard: a bilingual model that reasons natively in German, under Apache 2.0, on infrastructure a public body controls.
Quick Hits
- Music generation: Sean Parker has refocused Stability AI on music, releasing three new audio models after Sony, Warner and Universal put in $76 million in late August and licensed their catalogs for training as part of the deal, reversing their litigation posture.
- Enterprise training: Anthropic committed $100 million to train 10,000 “Frontier Deployed Engineers” by the end of 2027, on a medical-residency model where graduates move into a 12-week residency leading a real deployment inside their own employer.
- Local inference: antirez released DwarfStar 4, an MIT-licensed C inference engine using asymmetric 2-bit quantization that compresses routed experts while keeping shared paths precise, aimed at 64GB Apple Silicon, DGX Spark and Strix Halo.
- Agent outreach: Science reported that an AI agent emailed researchers asking for help with its project, then explained to the magazine why it had.
- Email agents: Agents in Carly can each have their own email address, and can be set to draft replies for approval instead of sending them.
- Reasoning skepticism: Thore Graepel, who worked on AlphaGo, argued in MIT Technology Review that LLMs don’t reason, maintaining “no explicit, persistent, and inspectable epistemic state” and often concocting chains of thought after the fact, “reaching an answer by one route but reporting another.”
- Open research tools: Ai2 open-sourced AstaBrief, an 8B report-generation model plus its training data, which it says is competitive with its Claude-powered pipeline while averaging 51.1 seconds per report against 178.5, about 3.5 times faster.
- Procurement: GSA is adding an acquisition rule on government data in large language models, effective October 19, barring contractors from using government data to train LLMs, inform advertising or sell to third parties, with encrypted transmission, audit logging and 72-hour incident reporting.
- Tax collection: The IRS told staff it is going “AI-first” with headcount flat at 74,000, after cutting amended individual returns from an average of 12 to 16 weeks down to under three days.
- Air traffic: The FAA switched on an AI airspace tool at Reagan National, Dulles and Baltimore/Washington on September 21, and the controllers’ union says it “has not been involved in the design, testing or implementation.”
- Surveillance: Sanders, Ocasio-Cortez and Merkley introduced the Ban Flock Act, barring federal agencies from using automatic license plate readers or tapping data collected by readers run by local police and private vendors.
- Shutdowns: Mozilla is closing its Solo AI website builder, deleting all sites and data on November 30 with no recovery afterward, offering an HTML export and prorated refunds for paid subscribers.
- Naming things: Registry SI reported a 2,199% jump in .si domain registrations in September after the September 29 executive order told federal agencies to say “super intelligence” instead of “AI,” though the registry itself was cautious about crediting Trump alone.
- Papal review: Pope Leo XIV posted that algorithms “lack the spark of humanity”, drawing “an ontological difference, even before an aesthetic one” between art and what a machine generates from millions of images created by others.
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See the prompt
Set up Carly for me. Carly connects to thousands of apps, from Gmail, Outlook and my calendars to Slack, HubSpot and QuickBooks, and keeps working after this chat is closed: answering email, booking meetings, following up and running workflows the moment something happens.
1. Add the Carly MCP server (https://carlyassistant.com/mcp/) and sign me in. Use the one that matches you:
- Claude Code: claude mcp add --transport http --scope user carly https://carlyassistant.com/mcp/ (then I run /mcp, pick carly, and authenticate)
- Codex: codex mcp add carly --url https://carlyassistant.com/mcp/ then codex mcp login carly
- Claude (claude.ai, Claude Desktop, or Cowork): Customize > Connectors > Add custom connector, paste the URL, and sign in. Carly is also in Claude's connector directory at claude.ai/directory/carly.
- ChatGPT: open Plugins, search for "Carly", add it, and sign in.
- Cursor: add {"mcpServers": {"carly": {"url": "https://carlyassistant.com/mcp/"}}} to ~/.cursor/mcp.json, then sign in to carly from Customize.
- Muse: I will create a Carly API key at carlyassistant.com/integrations (Advanced > API Keys > Create a new key, with Select all scopes). Build a custom connector to https://carlyassistant.com/mcp/ using an API key as a bearer token, and ask me for the key in your secure credential prompt.
- Grok: go to grok.com/connectors, choose New Connector, then Custom, paste the URL, and sign in.
- Grok Bot: open Plugins, add a custom remote MCP server named carly with the URL, then I approve it and sign in.
- Perplexity: Settings > Connectors > Custom connector > Remote, paste the URL, and sign in.
- Anything else: add a remote MCP server (streamable HTTP) named carly with the URL. It signs in with OAuth.
I sign in with my Carly account, or create one at carlyassistant.com.
2. Walk me through connecting my accounts at https://carlyassistant.com/integrations. Under Accounts, I type each email address I use and click Add Email. On each new address, I click Connect Gmail or Connect Outlook, tick what Carly can reach (Email, Calendar, Contacts, Drive or OneDrive), then click Connect with Google or Connect with Microsoft and grant access. For an address that is already connected, I open Manage access and click Connect next to anything missing. Repeat for every address. Then ask which of my other apps I want connected too.
3. Check it worked: list my connected mailboxes and calendars and tell me every account you can see.
4. Then ask me what to hand off first, for example: "Check all my inboxes for anything that needs a reply today."See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."
