ai-powered-markdown-translatorArticle translated from fr to en with gpt-5.4-mini.
July 19, 2026 sees Alibaba announce Qwen3.8, a 2.4 trillion-parameter model on its way to open-weight, while OpenAI boosts Codex with a cybersecurity plugin powered by a record on a cyber range. Against this backdrop, the CEOs of Hugging Face and Together AI both go on the offensive the same day to defend open models against regulatory rumors, while developer tooling grows on the Copilot CLI side and Kimi K3, overwhelmed by demand, temporarily closes new registrations.
Qwen3.8: Alibaba announces a 2.4 trillion-parameter model, open-weight to come
July 19 — Qwen, Alibaba’s AI division, announced the upcoming launch of Qwen3.8, a new model with 2.4 trillion parameters whose weights will be released as open-weight in the coming weeks. According to the company, the model, still in continuous development, would rank among the most powerful available today — Alibaba even claims a level comparable to frontier market models, placing it just behind Fable 5, Anthropic’s model whose standard access on the Max and Team Premium plans, announced on July 18, takes effect on July 20. A comparison that remains the publisher’s own claim about its launch, not an independently verified third-party ranking.
Without waiting for the full availability of the weights, a preview version — Qwen3.8-Max-Preview — debuted that same day on Alibaba’s Token Plan as well as on the Qoder and QoderWork platforms, allowing early users to try it immediately.
The announcement sparked a strong reaction from the community (4.4 million views in a few hours), with many requests — notably from Unsloth AI — for smaller versions of the model to also be released in order to enable local execution.
| Feature | Reported detail |
|---|---|
| Number of parameters | 2.4 trillion |
| Open weights availability | Coming soon (“soon”, undated) |
| Preview version | Qwen3.8-Max-Preview, available immediately |
| Preview platforms | Alibaba Token Plan, Qoder, QoderWork |
OpenAI launches Codex Security, powered by a GPT-5.6 Sol cybersecurity record
July 18 — OpenAI launched Codex Security, a plugin for Codex (CLI and Desktop) dedicated to detecting, validating, and fixing vulnerabilities in real code. The announcement rests on a strong claim: GPT-5.6 Sol would set a new cybersecurity record on “The Last Ones,” a cyber range used by the AISI (AI Security Institute) to evaluate models’ offensive and defensive capabilities in a simulated enterprise network attack.
The course includes 32 steps grouped into nine milestones, from initial reconnaissance (M1) to full network takeover (M9), including browser credential theft and web app exploitation. In its best attempt, GPT-5.6 Sol reaches the top of the chart through milestone M9, ahead of Claude Mythos 5, GPT-5.5, Claude Opus 4.6, GLM-5.2, and Sonnet 4.5; DeepSeek-V4-Pro remains well behind.
Once installed, the plugin follows a near-identical guided flow on Desktop and CLI: install Codex, add the Codex Security plugin, start a chat with a ready-to-use analysis prompt, choose the project folder to inspect, then send the prompt. Codex Security then scans the codebase, identifies vulnerabilities, validates them to reduce false positives, and proposes fixes.
This announcement stands apart from GPT-Red (covered on July 15), which focused on internal red teaming of OpenAI’s own models: Codex Security puts that same offensive capability to work in an external defensive use case, on third-party codebases.
| Evaluated model (best attempt) | Position on the AISI cyber range |
|---|---|
| GPT-5.6 Sol | Top — milestone M9 (full network control) |
| Claude Mythos 5 | 2nd place, close to the top |
| GPT-5.5 / Claude Opus 4.6 | Upper middle |
| GLM-5.2 / Sonnet 4.5 | Lower middle |
| DeepSeek-V4-Pro | Well behind |
🔗 Announcement on X · Codex Security — official page
Open-weight labs push back against regulation
July 19 — On the same day, the CEOs of Hugging Face and Together AI separately posted statements on X defending open-weight AI — a signal of mobilization from the open-source ecosystem in the face of rumors of stricter regulation.
Clément Delangue (Hugging Face) calls for a gathering in San Francisco
Clément Delangue, cofounder and CEO of Hugging Face, responds to rumors of an upcoming clampdown on open-source AI: in his view, what is needed instead is more open AI, accessible to everyone. His argument boils down to three points: more control and transparency, cheaper and more adaptable AI, and the ability to compete with the big players rather than depend entirely on renting intelligence from them. On safety, he believes restricting open models would only hide risks and concentrate power in a few hands. To back up his position, a peaceful gathering is being organized in San Francisco the following Saturday, with registration via a Partiful link shared in the tweet.
There have been rumors that open-source AI could soon be limited and regulated. I believe the opposite is what’s needed: we need more open-source AI, not less, for everyone, from all over the world, at the frontier and everywhere! — @ClementDelangue on X
Vipul Ved Prakash (Together AI) defends the commoditization of open models
Vipul Ved Prakash, cofounder and CEO of Together AI, lays out the same day an economic argument in response to a thread by Dean W. Ball on Kimi’s model performance. His thesis: the commoditization of AI models is already underway, and it looks more like major commodity markets — oil, wheat, steel, electricity, memory — than a planned economy. He also argues that open weights do not curb capital expenditure but shift it toward inference, data, and tools, much like Linux, unfavorable to Sun Microsystems but beneficial to almost the rest of the industry. He concludes by denouncing what he calls “security theater” around AI’s existential risks, which he считает unsupported by evidence.
It has been clear to many of us, and now it’s becoming clear more tangibly, that AI models will commoditize to various degrees. This is of course a difficult business reality if your core business depends on exclusivity on intelligence. But commodity markets are not communism. They are the largest markets on earth. Oil, grain, steel, electricity, memory: trillions clear through them every year, priced by competition among thousands of suppliers. — @vipulved on X
GitHub Copilot CLI now shows issues, pull requests, and gists in the terminal
July 19 — GitHub announced that Copilot CLI now lets users view their current session, issues, pull requests, and gists directly from the command-line tool, without switching to the browser or the GitHub app. The feature is available starting with version v1.0.58.
This addition fits with Copilot CLI’s direction since launch: reduce back-and-forth between the terminal and the web interface during an agent-assisted work session. It is more of an ergonomic improvement than a new agentic capability, but the CLI remains Copilot’s number-one coverage priority, alongside Workspace.
Kimi K3: Moonshot AI temporarily suspends new subscriptions
July 19 — Three days after the launch of Kimi K3 (2.8 trillion parameters, announced on July 16), Moonshot AI says demand has exceeded its GPU capacity forecasts. Over the past 48 hours, demand has come close to the limits of the available infrastructure: the company is therefore temporarily suspending new subscriptions to preserve the experience of existing subscribers — they are not affected by the pause.
Moonshot AI says it is working on adding additional capacity and plans to reopen registrations in batches. The company also announces an upcoming restructuring of its offering, now split into two plans: Kimi Membership (Web, app, Work) and Kimi Code Membership (code-related workflows).
Kimi K3 has received far more love than we expected, and our GPUs are feeling it. Over the past 48 hours, demand has pushed close to the limits of our current capacity. — @Kimi_Moonshot on X
Briefs
- Claude Code CLI v2.1.215 — Claude no longer automatically triggers skills
/verifyand/code-reviewduring a session; they must now be invoked explicitly. 🔗 Changelog - HeyGen on World Cup TV coverage — Telemundo Deportes uses a HeyGen avatar of presenter Pablo Mariño for its FIFA World Cup 2026 coverage segments. 🔗 Source
- Kling AI releases “BACK SHADOW” — an AI-generated mockumentary about the human backstage of a football match, in the context of the FIFA World Cup 2026. 🔗 Source
What this means
The race for open frontier models is already saturating available infrastructure. Qwen3.8 claims 2.4 trillion parameters with an openly stated position very near the top of the market, while Kimi K3 — announced just three days earlier — has to suspend new subscriptions for lack of sufficient GPU capacity. The success of an open model is therefore measured no longer only by benchmarks, but by the publisher’s ability to absorb the demand it creates: an infrastructure problem as much as a research one.
Cybersecurity is emerging as a new direct battleground between models. The record claimed by GPT-5.6 Sol on the “The Last Ones” cyber range, immediately turned into a defensive product (Codex Security) rather than kept as a mere marketing argument, illustrates a broader trend: offensive capabilities developed internally to harden a model become, almost at the same time, a product sold to development teams to protect their own code.
The tension between open AI and regulation is taking on a more political tone. The statements by Clément Delangue and Vipul Ved Prakash, published on the same day without any apparent coordination, show that leaders in the open-weight ecosystem are no longer content to publish models: they are also organizing the public defense of the business model behind them, using different registers — civic mobilization on one side, commodity-market economic theory on the other.
Developer tooling continues to densify in the terminal rather than in the browser. The issues, pull requests, and gists joining Copilot CLI, just like the tighter user control over /verify and /code-review in Claude Code, point in the same direction: consolidate as much context and control as possible directly in the command line, as close to the code as possible, rather than forcing back-and-forth to separate web interfaces.
Sources
- Qwen3.8 — announcement on X
- OpenAI Codex Security — announcement on X
- OpenAI Codex Security — official page
- Clément Delangue on X
- Vipul Ved Prakash on X
- GitHub Copilot CLI — announcement on X
- Kimi K3 — announcement on X
- Claude Code CLI v2.1.215 — changelog
- HeyGen × Telemundo Deportes on X
- Kling AI — BACK SHADOW on X