Overview
9 stories in this issue. The first 3 are today's priorities.
Hot Model Moves
- Top · Replit rolls out model choice, starting with Kimi K3
- Top · Hundreds of shared Claude chats indexed by Google; Anthropic points to user sharing
Global AI 3. Top · OpenAI open-sources a Codex Security CLI to scan and patch repositories 4. 1,134 frontier-lab employees sign a letter urging tools to slow automated AI development 5. Gemini API Managed Agents default to Gemini 3.6 Flash, add sandbox hooks and a free tier 6. Liquid AI open-sources LFM2.5-Encoders for fast long-context inference on CPU 7. Fish Audio raises $52M seed for open, controllable voice models
Regional & Early Signals 8. xAI begins early testing of a Grok "Build" model for SuperGrok Heavy subscribers 9. Doubao opens its search to agents, returning structured results with source-authority tags

Jiufeng graphic based on the sources cited in this issue.
Hot Model Moves
Replit rolls out model choice, starting with Kimi K3
Replit turns model routing into a product feature, and the first option is Moonshot AI's open-weight Kimi K3.
On July 28th, Replit began rolling out a "model choice" feature, starting with Moonshot AI's Kimi K3, founder and CEO Amjad Masad (@amasad) announced in a post on X. Kimi K3 is Moonshot's open-weight release, and Replit is putting it directly into its product as an alternative to closed labs. Per RuntimeWire, Replit runs on usage-based pricing, so model routing becomes a way to place cost beside capability and to reduce dependence on the closed labs that supply AI coding platforms.
Limitations: only Kimi K3 has been named as an option so far, and the feature is still rolling out; RuntimeWire does not detail pricing differences, the roadmap of additional models, or switching granularity.

Image source: GitHub; mirrored on Jiufeng R2.
Source: RuntimeWire · Kimi K3 (GitHub) · Amjad Masad (X)
Hundreds of shared Claude chats indexed by Google; Anthropic points to user sharing
Claude "share" links were indexed by Google, with some pages missing noindex, exposing resumes, health details and even API keys. (Chinese-language source)
According to IT Home (ithome.com), around July 26th a screenshot on Reddit's r/ClaudeAI showed a Google search for "site:claude.ai/share" returning many clickable public Claude conversation links. These pages come from links users generate via the chat interface's "share" button, which should carry a noindex tag telling search engines not to index them; but some pages apparently lacked the tag when Google crawled them and were indexed. The exposed content reportedly included resumes, health information, internal company material and even API keys. Anthropic responded that the content was made public through users' own use of the share feature.
Limitations: this is so far reported via Chinese-language media (IT Home) and a Reddit screenshot; Anthropic's exact statement is relayed without a primary link, and there is no authoritative figure for how many links were affected or whether they have been removed from the index.
Source: IT Home
Global AI
OpenAI open-sources a Codex Security CLI to scan and patch repositories
OpenAI's Codex lead ships an Apache-2.0 CLI and TypeScript SDK that find, validate and patch vulnerabilities locally and in CI.
On July 28th, OpenAI Codex lead Thibault "Tibo" Sottiaux (@thsottiaux) announced on X an open-source command-line interface and TypeScript SDK for finding, validating and patching vulnerabilities in software repositories, published in a new Codex Security repository under the Apache-2.0 license. The package can scan complete repositories, selected paths or changed files and run inside continuous-integration pipelines; beyond scanning it adds validate and patch commands—the former asks the agent to test a candidate finding, the latter generates a proposed fix. It extends a Codex Security scanner OpenAI first introduced on March 6th as a GitHub-connected research preview. Per RuntimeWire, the move pushes application-security review into coding-agent workflows and into a market served by Snyk, Semgrep, GitHub, Checkmarx and Veracode.
Limitations: while the CLI and SDK are open source, the underlying scanner still gives scriptable access only to approved customers; RuntimeWire cites no false-positive rate or coverage metrics.
Source: RuntimeWire · Codex Security repo (GitHub) · OpenAI's March preview
1,134 frontier-lab employees sign a letter urging tools to slow automated AI development
Employees of OpenAI, Anthropic, Google, Meta and others ask the US government to back new tools that could slow automated AI development.
According to The Verge and SiliconANGLE, a public letter/statement dated July 28th carries 1,134 signatories, all of whom work at companies building frontier models, including employees of OpenAI, Anthropic, Google, Meta, Microsoft, Mistral and Thinking Machines. It calls for a new approach to regulating "automated" AI development and for tools that could slow such automated development, addressed to the US government. The Verge notes the statement follows a recent high-profile cybersecurity incident that rocked the industry.
Limitations: this is a letter signed by individual employees, not a company position or enacted policy; neither report details what the "slowdown" tools would look like or how they would be implemented.
Source: The Verge · SiliconANGLE
Gemini API Managed Agents default to Gemini 3.6 Flash, add sandbox hooks and a free tier
Google switches its Gemini API managed agents to a 3.6 Flash default and adds environment hooks that can block or audit tool calls.
In a July 28th blog.google post, Google DeepMind's Philipp Schmid and Mariano Cocirio announced that Managed Agents in the Gemini API now default to Gemini 3.6 Flash. New environment hooks let developers block, lint or audit tool calls inside the sandbox, and the update adds budget controls, scheduled triggers and free-tier access.
Limitations: this is a developer-facing API update framed around building "reliable, production-ready" agents; the post gives no latency, cost or success-rate numbers versus the previous default.
Source: Google (blog.google)
Liquid AI open-sources LFM2.5-Encoders for fast long-context inference on CPU
Liquid AI releases 230M and 350M encoder models built to stay fast on CPU as inputs get longer.
On July 28th the Liquid AI team released two encoder models on Hugging Face, LFM2.5-Encoder-230M and LFM2.5-Encoder-350M, positioned for fast long-context inference on CPU; the team says they match the quality of larger models while staying fast as inputs grow. Evaluation covers GLUE, SuperGLUE and multilingual classification, reporting the mean across five held-out seeds, and the evaluation framework and raw results are open-sourced on GitHub.
Limitations: these are encoder models for representation/classification, not generation; the "matches larger models" claim comes without specific scores in the excerpt, so gains should be verified per task.
Source: Hugging Face blog · Eval framework (GitHub)
Fish Audio raises $52M seed for open, controllable voice models
Voice-model startup Fish Audio raises a $52M seed and reports over 8M users and $21M in annual recurring revenue.
According to TechCrunch, Palo Alto-based Fish Audio has raised a $52M seed round. Since launching last year, more than 8 million people use the open-source or hosted versions of its models, which now generate $21M in annual recurring revenue. Fish Audio targets creators and enterprises with more than 15,000 natural-language controls, aiming to serve both expressive creative use cases and the steerability that customer-support and sales automation require.
Limitations: this is a seed round; the report does not disclose valuation or investors, and the 8M-user figure combines open-source and hosted versions without a separate paid-conversion or enterprise-deployment number.
Source: TechCrunch
Regional & Early Signals
xAI begins early testing of a Grok "Build" model for SuperGrok Heavy subscribers
Chinese newswire Cailianshe reports xAI is rolling out a Grok "Build" model in early testing, first to SuperGrok Heavy subscribers. (Chinese-language source)
Per 36Kr relaying Cailianshe (Chinese-language source), xAI has introduced a "Build" model for Grok that is in an early testing phase and first available to SuperGrok Heavy subscribers. This is one of the few items in today's pool dated July 29th.
Limitations: the item rests on a single short Chinese newswire with no link to an xAI announcement and no parameters, capability positioning, context length or pricing; whether this "Build" is the same as the previously open-sourced Grok Build code tooling is not addressed by the source and should not be assumed.
Source: 36Kr
Doubao opens its search to agents, returning structured results with source-authority tags
Per QbitAI, ByteDance's Doubao exposes search to enterprise/developer agents, returning source names, authority tiers, timestamps and quotable excerpts. (Chinese-language source)
According to QbitAI (Chinese-language source), ByteDance's Doubao has opened its search capability to enterprise- and developer-facing agents. In the reported example, one query returned three directly relevant items—from a government-site repost, Science and Technology Daily, and the Simons Foundation—and each result carried not just a web link but the source name, an authority tier, a publication date, a generated summary for the query, and a directly quotable Markdown excerpt of the original. The stated purpose is to let an agent judge reliability and freshness from the authority tier and date before extracting content.
Limitations: this is a product capability on the Volcano Engine/Doubao side—search infrastructure for agents rather than an update to the Doubao model itself; it is a single Chinese-language report with no availability scope, pricing or third-party benchmarks.
Source: QbitAI
Get the latest AI model insights and tutorials from Jiufeng.
Explore more


