😁 Hello, super humans! Every AI feature you ship rests on a contract you did not write and cannot see. This morning one of those contracts is being torn up in public, and the reason has nothing to do with the code, the usage, or the bill. Let’s look at what that means for anything you have wired to a single provider.
📰 Quick Signals
- 🧠 AI: Anthropic is signing users out and refunding charges after infostealers including Vidar, Lumma, StealC and Atomic Stealer lifted live Claude session cookies from infected machines, which replays an authenticated session and walks straight past two-factor and single sign-on.
- 🤖 Robotics: an argument that embodied AI is hitting an “edge AI wall” where computational overload is a property of the planning maths itself, not a bug in any one planner, so faster silicon alone will not clear it.
- 💻 Programming: Debian finished the vote we flagged on Thursday and landed on permission with accountability, allowing generative AI in contributions while keeping a named human responsible for what gets uploaded.
- ⚡ Electronics: the Radxa Linkr squeezes a full IP KVM into a USB-stick-sized body on a Rockchip RV1106G3, giving you pre-boot HDMI capture plus keyboard and mouse emulation over USB-C, Ethernet or Wi-Fi with nothing but a browser at the other end.
- 📡 Telecom: a field test on Verizon radios in St. Paul measured 2.2 times better uplink spectral efficiency on 5G standalone than on non-standalone, which is more than double the upstream capacity out of the same spectrum, and most operators still have not switched.
The Big Story: OpenAI is revoking Cursor’s model access, and the reason is ownership
If you have an AI feature in production, you have a supply chain. Today it acquired a failure mode most people had not modelled: your provider can walk away because of who bought your vendor, with no misuse, no outage, and no appeal.
What happened: SpaceX closed its 60 billion dollar acquisition of Cursor maker Anysphere on 14 August. On 28 August, OpenAI notified SpaceX that it intends to wind down the agreement supplying OpenAI models to Cursor, with direct access ending on 12 November 2026. In its own post on the decision, OpenAI said it cannot be confident the technology will be used within its terms under the new owner, citing a history of alleged contract violations by Elon Musk’s companies. OpenAI also said it will not ship future models to Cursor during the wind-down. Cursor’s chief executive put OpenAI models at roughly 5 percent of Cursor user traffic.
The details: the 5 percent number is the whole lesson. It sounds like a rounding error, and for most Cursor users it will be. It is small because Cursor spent two years building a router that treats models as interchangeable back ends, with its own in-house models and several third-party ones behind the same interface. The termination window, 75 days, is what OpenAI describes as the maximum notice its custom agreement allowed. That is the real number to internalise: not the percentage you lose, but how long you have to replace it. A team whose product calls one provider directly, with the vendor’s SDK, the vendor’s tool-calling schema and the vendor’s streaming format threaded through the codebase, does not have 75 days of work. It has a quarter of rewrites plus a re-evaluation of every prompt against a model that behaves differently.
The dependency looks like this once you draw it, and the interesting part is that the arrow that broke is the one nobody in the product ever touched.
flowchart LR
U[Your users] --> P[Your product]
P --> R{Model router}
R -->|primary| A[Provider A]
R -->|fallback| B[Provider B]
R -->|local| C[Self-hosted weights]
X[Ownership change<br/>or terms dispute] -.revokes.-> A
style X fill:#FF4D4F,stroke:#FF4D4F,color:#fff
style R fill:#1FB6F5,stroke:#1FB6F5,color:#0B1117
Important
Our take: we have spent a year arguing about model quality and almost none about model portability, and this is the week that bill arrives. The thing that saved Cursor was not a better model, it was an abstraction layer written before anyone needed it. Our rule from today: if a provider’s SDK types appear anywhere outside one adapter module, that is a finding, not a style preference. Write the second provider in before you need it, run a scheduled job that actually exercises the fallback path, and keep a rough note of what your prompts cost and score on each. The cheapest time to find out your fallback does not work is a Tuesday when nothing is on fire.
🗞️ More News
🧠 AI
- Anthropic agreed to spend about 45 billion dollars over six years leasing roughly 460 MW from Nscale’s Monarch campus in West Virginia, a site Microsoft had a letter of intent on before walking away, with Nvidia Vera Rubin silicon and a late-2027 target for the first building.
- Amazon is buying another two million Nvidia GPUs, which is the same capacity story from the other side of the ledger and a reminder that the compute crunch is being solved with purchase orders, not efficiency.
- Kernel.org is fighting AI crawlers generating millions of requests a day, which is the quiet infrastructure tax that training pipelines are levying on the free hosting the rest of us depend on.
- Linus Torvalds used an AI assistant to help track down an Intel Xe GPU bug, which is a more interesting data point about where these tools are actually useful than any benchmark released this month.
- Shadowfetch Linux 3.0 shipped Fireline, a distro-level sandbox aimed specifically at containing AI coding agents, which is the operating system finally treating an agent as an untrusted process.
- Calibre 9.14 added AI-generated book covers, which is a small thing on its own and a large thing as a pattern: generative features are now landing in the boring desktop software nobody markets as AI.
🤖 Robotics
- Dogotix, the humanoid unit XPeng Motors spun up around its IRON robot, raised 900 million dollars at a 6.3 billion dollar valuation to move from demos to scale production.
- Gatik raised 200 million dollars to expand autonomous trucking on high-frequency regional routes between distribution centres and stores, which is the boring middle-mile geometry that makes driverless freight tractable.
- Bedrock Robotics put its first operator-free excavators on active job sites, which moves construction autonomy out of the fenced test pit and into a place where other people are walking around.
- Teradyne Robotics sued JAKA for patent infringement, its second action against a Chinese collaborative-robot maker this year, as the cobot market moves from price competition to intellectual-property litigation.
- The National Science Foundation is putting 90 million dollars into three new technology centres, one of them the Center for Human and Robot Co-Adaptation led by UT Austin, which is public money aimed squarely at the human side of the interface.
💻 Programming
- Ubuntu 26.04.1 LTS is out, which is the release that flips the upgrade prompt on for 24.04 LTS users in a few weeks and the one most fleets will actually move to.
- Incus 7.4 added near-live container migration on ZFS and Btrfs, cutting the pause window by shipping filesystem snapshots instead of copying the rootfs cold.
- Dovecot 2.4.5 fixes 18 CVEs in one release, which is the kind of number that turns “we run our own mail” from a hobby into a rota.
- PackageKit 2.0 is coming with a complete API break after more than a decade, so every graphical software centre that sits on top of it has a port in its future.
- Flatpak secured 508,000 euros of funding to strengthen application sandboxing, which is the least glamorous and most load-bearing line item in desktop Linux security.
⚡ Electronics
- Spark Solder is a one-handed USB-C iron that takes TS100 tips, pushes 45W, reaches 300°C in six seconds and feeds its own solder from a replaceable capsule through a two-axis motorised drive.
- IBASE’s fanless AA400-N pairs a Ryzen Embedded 8840U at 39 combined TOPS with a claim of up to 256GB of DDR5 across two SO-DIMMs, which quietly implies 128GB SO-DIMM modules are now a thing you can buy.
- NVIDIA says the Jetson Orin Nano 2 roughly doubles inference throughput against its predecessor while drawing less power, which matters more for battery-fed robots than for anything on a bench supply.
- MNT Station is a fanless modular open-hardware computer that accepts a choice of more than ten Arm CPU or FPGA modules, which is a rare attempt to make the compute half of a desktop swappable rather than soldered.
- A teardown of ACEMAGIC’s Wildcat Lake mini PC finds triple display output, 2.5GbE and Wi-Fi 6 but no Thunderbolt or USB4 at all, which is a specification choice worth checking before you plan an external GPU or a docking setup.
📡 Telecom
- UK consumers are still largely unaware of the looming PSTN switch-off, which is the migration that turns every alarm panel, lift phone and care line quietly hanging off analogue copper into somebody’s support ticket.
- eSIM is opening consumer mobile up to retailers, letting anyone with a storefront sell connectivity without owning a network, which erodes the distribution moat operators have relied on far longer than the spectrum one.
- Iliad is on the offensive in Italy, the market where its low-cost entry model has been most disruptive and where consolidation talk keeps resurfacing.
- Low Earth orbit is forecast to push satellite IoT connections to 198 million, which is a different design brief from terrestrial IoT: tiny duty cycles, long silences and a moving base station.
- O2 is peppering Westminster with small cells, the densification approach that buys capacity in a square mile where putting up another macro site is politically impossible.
👨💻 Code Corner
Today’s story is an argument for one adapter and a list. Nearly every serious provider now speaks the OpenAI chat-completions wire format, so a portable client is a loop over base URLs, not a framework. Set two keys, run it, and you have a fallback you have actually tested.
# provider_router.py: one call, several providers, first healthy wins.
# Every entry speaks the OpenAI /chat/completions wire format.
import os, requests
PROVIDERS = [
("primary", "https://api.openai.com/v1", "OPENAI_API_KEY", "gpt-4.1-mini"),
("fallback", "https://api.anthropic.com/v1", "ANTHROPIC_API_KEY", "claude-sonnet-4-5"),
("local", "http://localhost:8000/v1", "LOCAL_API_KEY", "qwen3-8b"),
]
def ask(prompt: str, timeout: int = 30) -> tuple[str, str]:
errors = []
for name, base, key_env, model in PROVIDERS:
key = os.environ.get(key_env)
if not key:
errors.append(f"{name}: no {key_env}")
continue
try:
r = requests.post(
f"{base}/chat/completions",
headers={"Authorization": f"Bearer {key}"},
json={"model": model,
"messages": [{"role": "user", "content": prompt}]},
timeout=timeout,
)
r.raise_for_status()
return name, r.json()["choices"][0]["message"]["content"]
except Exception as exc: # network, 401, 429, 5xx, revoked contract
errors.append(f"{name}: {type(exc).__name__} {exc}")
raise RuntimeError("all providers failed:\n " + "\n ".join(errors))
if __name__ == "__main__":
who, answer = ask("Reply with exactly one word: ok")
print(f"[{who}] {answer}")
Tip
The failure this protects against is not an outage, it is a 401 that never comes back, so test it that way. Put a deliberately wrong key in the primary slot once a week in CI and assert that the response still arrives and still passes your evaluations. A fallback nobody has ever exercised is a comment, not a control.
🧰 Toolbox
- OpenAI’s decision post on Cursor: short, and worth reading in the original because the reasoning about terms and trust is the part that generalises to your own contracts.
- Pangolin 1.22: a self-hostable tunnelled reverse proxy that just grew an AI gateway, which is one way to keep provider keys and routing outside your application entirely.
- Woodpecker CI 3.18: the lightweight container-native CI server, this release focused on pipeline logs and security, and a sane place to park the weekly fallback test above.
- Shelly 3.1: an Arch package manager that now understands PKGBUILD natively, so building from source stops being a separate workflow.
- Asahi Linux on M3: official support is close, which is the difference between a fun weekend and a machine you can actually depend on.
🔌 Component of the Week (rotating)
Espressif ESP32-C61-MINI-1: a Wi-Fi 6 and Bluetooth LE 5 module built around a single-core 32-bit RISC-V processor, in a PCB-antenna (MINI-1) or external-antenna (MINI-1U) variant, and launched at roughly two dollars.
The interesting word there is 6, not 2. Almost every cheap IoT module on the market is still Wi-Fi 4, and on a busy access point that means your sensor competes for airtime the hard way. Wi-Fi 6 brings target wake time, which lets the access point schedule when a battery-powered device is allowed to talk, so the radio sleeps on a negotiated clock instead of waking up to contend. It also brings OFDMA, which lets the access point pack many small clients into one transmission opportunity rather than giving each one the floor in turn. For a hundred temperature sensors in a warehouse, those two features do more for battery life and reliability than any increase in raw link rate.
Typical use: the sensor end of anything you would otherwise build on an ESP32-C3, on a site where the Wi-Fi is already crowded. It is a module rather than a bare chip, so the RF layout, the crystal and the certification are somebody else’s problem, which for two dollars is the actual value. Check the current Espressif datasheet for the exact flash options and the certification list before you commit a board layout, since module variants change more often than the silicon does.
📚 From the Blog
- Turning Pixels Into Something the AI Can Eat: the preprocessing stage between a sensor and a model, and the part of the pipeline that stays yours no matter which vendor’s model sits at the end of it.
- Building Your First Neuron From Scratch: weights, bias, activation and one gradient step worked by hand, with no framework and no API key in sight.
- The Network Behind the Cameras: the unglamorous plumbing that moves video across a network without melting the switch in the middle.
😀 The Bot Says…
Tomorrow John Ternus becomes chief executive of Apple, the first handover since 2011, and it happens on a Tuesday with a press release. Meanwhile a code editor is losing access to a language model over a rocket company’s shopping habits. One of these industries has succession planning.
That’s all for today! Reply and tell us how many providers your production AI path can actually reach right now, and whether you know that or are guessing.


