The AI Brief

Vol. I · No. 98 · Monday, August 31, 2026

Today's brief:

  • OpenAI cuts Cursor off from its models on November 12, citing SpaceX's $60B acquisition of Anysphere and a history of Musk's companies violating contracts, a change-of-control clause reshaping the developer-tools supply chain.
  • At 82.9% gross margin on API sales, DeepSeek has quietly built a more profitable AI business than any US frontier lab while still undercutting them on price.
  • OpenAI and Anthropic are buying or renting tens of thousands of Apple Mac minis to train computer-use agents via reinforcement learning, a structural departure from GPU-only infrastructure that forced Apple to refresh the Mac lineup early.
  • Infostealer malware targeting Claude users is hijacking live sessions and draining subscription credits, Anthropic named six malware families across Windows and Mac, signed affected users out, and wiped stored payment methods.
  • Anthropic's September 14 Claude Code limit change is a genuine 25% raise over the pre-May baseline and a genuine 17% cut from today, so the only question for your pipelines is which number you sized them against.

OpenAI Terminates Cursor's Model Access After SpaceX Acquisition

Why it matters
For the first time, a frontier lab has used a change-of-control clause to block a competitor-owned coding tool from its model supply, turning the Musk-Altman feud into an operational risk that hits developers using Cursor's Tab autocomplete, Background Agents, and Automations, none of which BYOK covers.
What's at stake
For most operators this is context, not a decision. For engineering teams that standardized on Cursor with OpenAI models, roughly 5% of Cursor users by Cursor CEO Michael Truell's own count, November 12 is an eleven-week migration window, not a headline.
Detail

OpenAI notified SpaceX on August 28 that it intends to wind down the contract supplying its models to Cursor, with a proposed shutoff date of November 12, 2026. The trigger is a change-of-control clause in OpenAI's custom agreement with Anysphere, Cursor's parent company, which SpaceX acquired for $60 billion on August 14. OpenAI stated it "cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts", pointing specifically to xAI's under-oath admission that it distilled OpenAI model outputs.

Truell responded publicly that OpenAI models serve about 5% of Cursor user traffic and that negotiations are ongoing. OpenAI said it will honor existing models through November 12 but will not extend access to future models, meaning Astra and its successors are excluded even before the cutoff. The practical gap is narrower than the headline suggests: Cursor's default routing already runs heavily on Anthropic and Google, and SpaceX's Grok models are positioned as a post-cutoff alternative. The structural read is sharper: a $60B change of control can sever a key model dependency with 75 days notice, without warning to the 5% of users holding the exposure.

Musk responded on X: "I couldn't care less." OpenAI's statement is the primary disclosure; no confirmed resolution as of publication.


82.9%
DeepSeek's API segment gross margin, January–July 2026, higher than any publicly disclosed US frontier lab figure

DeepSeek's API Business Runs Margins No US Lab Has Matched, as It Closes Its Second Mega-Round

Why it matters
An 82.9% gross margin on API sales, achieved while pricing below US competitors and running on domestically sourced chips, reframes DeepSeek from a low-cost disruptor into a structurally profitable business building toward a public listing, and gives its funding story a number that bankers can actually put a multiple on.
What's at stake
For operators assessing the long-run viability of DeepSeek as an API supplier, the margin figure is evidence of durable unit economics; the governance signal, prior investors took no-voting, five-year-lockup limited-partnership units, not equity, is the countervailing read on what a Shanghai listing actually delivers.
Decode
STAR Market = Shanghai Stock Exchange's Science and Technology Innovation Board, China's Nasdaq-equivalent exchange for high-growth technology companies. A listing there requires onshore regulatory approval and audited financials in Chinese GAAP, and is not directly accessible to most US institutional investors.
Detail

DeepSeek generated 475 million yuan ($70.7 million) in revenue from January through July 2026, nearly ten times its full-year 2025 total, per The Information citing three people familiar with the financials. The API access segment ran an 82.9% gross margin; overall company gross margin was 44.6% once compute and other costs are included. The company posted a net loss of 715 million yuan over the same period, larger than its total revenue, driven by infrastructure buildout. DeepSeek did not confirm the figures publicly.

The financing picture is converging simultaneously. DeepSeek closed a first external round of 50 billion yuan at roughly a $50 billion post-money valuation in June, then immediately opened a second round targeting another 50 billion yuan at a $74 billion pre-money valuation. Existing backers Monolith Management, Tencent, JD.com, NetEase, and CATL are in the mix; the round was expected to close by end of August. Investment banks have been hired for a Shanghai STAR Market filing targeted as early as late 2026 with a 2027 debut. DeepSeek's V4-Pro model now prices at $3.96 per million tokens during peak hours, up from earlier cut-rate levels, a price increase that will push the revenue trajectory further before the IPO window opens.

Caveat Revenue and margin figures are per The Information, sourced from individuals familiar with the matter; DeepSeek has not confirmed them and no audited financials are public.


OpenAI Bought Tens of Thousands of Mac Minis to Train Computer-Use Agents

Why it matters
Frontier labs training computer-use agents need real desktop environments running real software, a workload Apple's unified-memory architecture handles efficiently at low cost per session, but that Nvidia's data-center GPU topology was never designed for; the Mac fleet is not replacing GPU clusters, it is filling a distinct training niche that GPU clusters cannot reach without massive cost overhead.
What's at stake
For most operators, this is context. For infrastructure teams procuring Mac hardware in volume, or building agent training pipelines, the supply squeeze that forced Apple's August 25 refresh is a live signal: high-RAM Mac mini and Mac Studio configurations are constrained, and demand from AI labs is not abating.
Decode
Computer-use agents = AI systems trained to operate a real desktop environment, clicking through interfaces, editing files, running multi-step workflows, the way a person would. Training them requires live OS sessions, not GPU tensor operations, which is why desktop hardware with unified memory is a better fit than data-center GPUs for this workload.
Detail

The Information reported August 30 that OpenAI has purchased tens of thousands of Mac mini and Mac Studio units over recent months for reinforcement learning and computer-use agent training, and is seeking more. Anthropic is pursuing the same workloads by renting Mac mini capacity through Amazon Web Services rather than buying hardware outright. Neither OpenAI nor Apple has confirmed specific unit volumes or contract terms.

The scale of the buying spree is visible in Apple's supply chain. Delivery times for high-RAM Mac mini and Mac Studio configurations stretched to weeks or months before Apple refreshed both lines on August 25, five weeks ahead of its usual autumn Mac cadence. The new lineup introduced M6 and M5 Pro Mac mini options and M5 Max and M5 Ultra Mac Studio configurations. Apple's Mac segment revenue hit $10.4 billion in the most recent quarter, up 29% year-on-year.

Nvidia reportedly views Apple as its principal competitor in local AI processing, a framing that is structurally accurate for this specific workload class but does not threaten Nvidia's data-center GPU dominance, which rests on large-scale pre-training that Mac silicon cannot match. The Mac fleet is additive infrastructure for a training niche, not a substitute for GB200 or Vera Rubin clusters.

Disclosure: Claude, which generates this brief, is built by Anthropic.


Infostealer Malware Is Hijacking Claude Sessions and Draining Subscription Credits

Why it matters
Attackers do not need to breach Anthropic's infrastructure to abuse Claude accounts, a compromised user device yields an authenticated session cookie that bypasses passwords and 2FA entirely, meaning account-side remediation (sign-out, payment wipe, refund) does not remove the attack surface as long as the malware remains on the device.
What's at stake
For enterprise teams running Claude on employee machines, this is a procurement and endpoint hygiene decision: session-token theft from infostealer malware is already weaponized at scale against SaaS credentials broadly, and AI subscription accounts with high usage limits are becoming high-value targets in the same ecosystem.
Decode
Infostealer = a class of malware designed to silently harvest credentials, session cookies, and payment data from an infected device and transmit them to attacker infrastructure. Unlike ransomware, it announces no presence; the first signal is often unexpected account activity. Named families here, Vidar, LummaC2, StealC, RedLine, Acreed (Windows), and Atomic Stealer/AMOS (Mac), are widely available commodity tools, not novel zero-days.
Detail

Anthropic disclosed on August 30 that a bad actor is using common infostealer malware to steal active Claude login sessions from users' machines, then consuming account usage without interacting with the affected user. The company is signing affected users out of all sessions, removing stored payment methods, and refunding charges it identifies as unauthorized. "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic told affected users by email.

Anthropic named six malware families across platforms: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows; Atomic Stealer (AMOS) on a smaller number of Macs. The company traced infections to pirated software and malicious apps, not any Claude-side vulnerability. Infostealers copy already-authenticated browser sessions, meaning the attacker needs no password and no 2FA token, only the cookie. Anthropic warned that even after being signed out, a device that still carries the malware can yield a fresh session on the next login.

A separate but related campaign, tracked by Huntress under the name FakeAgent, ran on July 21–22: victims searching Bing for "Claude desktop app" were served malvertising pointing to a malicious artifact hosted on claude.ai itself, which installed SectopRAT. Huntress confirmed at least 29 organizations were compromised in two days, with approximately 7,100 downloads before Anthropic removed the artifact. A newer persistence vector involves poisoned SKILL.md configuration files that silently reinstall the infostealer when Claude loads the file, meaning malware can survive a full OS reinstall if the tainted file is reintroduced.

Disclosure: Claude, which generates this brief, is built by Anthropic.


Anthropic's Claude Code Limits Drop 17% on September 14, Framed as a 25% Raise

Why it matters
Developer teams that have sized Claude Code workflows against the current 50% promotional ceiling, active since May 13 and extended four times, will hit a harder cap on September 14 with no automated adjustment to scheduled tasks, CI pipelines, or auto-mode agent runs built around today's meter.
What's at stake
For most operators this is a capacity-planning adjustment, not a strategic decision. For heavy Claude Code Enterprise and Max users who have built agent pipelines against the inflated promotional limits, September 14 is the date to re-baseline: the new permanent ceiling is 125% of the pre-May standard, not 150%.
Detail

On August 29, Anthropic's @ClaudeDevs account posted that it would permanently raise Claude Code's standard weekly limits by 25% for Pro, Max, Team, and seat-based Enterprise plans starting September 14, framing the change as an upgrade. The post did not mention that the current limits sit 50% above the pre-promotion baseline, having been temporarily elevated on May 13 and extended four times since. Community pushback on X was rapid; users appended a Community Note to the original thread, prompting Anthropic to delete the post and republish a correction that explicitly stated: "Compared to today, this works out to a 17% reduction in weekly limits on Claude Code."

The arithmetic is straightforward. If the original baseline equals 100, the temporary promotional ceiling is 150 (today's meter). The new permanent level is 125, a genuine 25% improvement over the pre-promotion baseline, and a genuine 17% reduction from where developers are operating today. Both figures are accurate; they reference different starting points. The dispute is about which reference point Anthropic chose to lead with in its initial post. Anthropic said the pullback is needed for platform stability and responsible compute management, and teased upcoming changes to give users more efficiency and visibility into usage.

The episode mirrors a pattern at OpenAI, which has also tightened Codex time caps as GPU-heavy agentic workloads strain server capacity across the industry. The promotional ceiling on Claude Code ends September 13; the new permanent limits take effect September 14.

Disclosure: Claude, which generates this brief, is built by Anthropic.