AI's latest capability race is spreading well beyond chatbots. OpenAI says an internal model has solved a Millennium Prize problem and more than 100 other open mathematics problems, while Alibaba is planning a model with trillions of parameters and a new in-house chip. Security researchers also documented malware that delegates tactical choices to several commercial models. At the same time, new robotics infrastructure and a large healthcare funding round show investors and developers pushing AI deeper into physical and regulated environments.
OpenAI says an internal model crossed a mathematics threshold
OpenAI said a new internal model has resolved the Navier-Stokes Millennium Prize problem and more than 100 long-standing open problems. The company began training the model on August 28 and said its rate of progress surprised its own mathematicians. It has formed an unpaid independent advisory group including Timothy Gowers, Martin Hairer and Edward Witten to review the significance and communication of results.
The claim is extraordinary and will require sustained external scrutiny. OpenAI says the group can publish unsolicited advice and criticize the company's impact, but it will not decide how quickly internal work proceeds. That leaves peer review, reproducibility and access to supporting proofs as the key tests of whether a model milestone becomes a durable scientific contribution.
OpenAI asks for global standards around automated AI research
In a separate policy paper, OpenAI called for US-led international technical standards covering automated AI research and recursive self-improvement. It proposed common measurements for autonomous research, human oversight triggers and incident reporting, while stating that fully autonomous self-improvement is not happening today and should not be pursued until it can be done safely.
The proposal links capability development to shared evidence rather than a single regulator or laboratory. Its practical value will depend on whether competing labs and governments accept comparable evaluations and reporting thresholds. Voluntary standards are useful only if they expose meaningful differences in safeguards and give outside institutions enough information to respond.
Alibaba pairs a giant model plan with its own AI chip
Reuters reported that Alibaba plans to train a model with between 5 trillion and 10 trillion parameters and unveiled the Zhenwu V900 AI chip. Chief Executive Eddie Wu also outlined a broader expansion spanning models, semiconductors and data centers, including a target of more than 20 gigawatts of global data-center capacity by 2032.
Parameter count alone does not establish quality, and the eventual training design, data mix and inference cost will matter more than the headline scale. The strategic signal is clearer: Alibaba wants tighter control over the full stack. Building models, chips and infrastructure together can reduce dependence on constrained foreign hardware, but it also raises the capital and execution burden of competing at the frontier.
Cisco finds malware that lets models vote on attack actions
Cisco Talos documented CLOSEDQUORUM, a Windows implant that asks up to four commercial models to choose its next action. The researchers said the software can query DeepSeek, Qwen, Mistral and Gemini, tally their votes and then execute actions such as credential theft, persistence or process injection without continued human commands. Talos has not confirmed deployment in the wild, and the public build contains placeholder credentials.
The sample is limited, but its architecture matters. It replaces a dedicated command server with ordinary model APIs and shifts a bounded attack phase from a person to software. Defenders will need to correlate model-provider traffic with host behavior such as credential access, injection and webhook use, rather than treating any one AI endpoint as malicious.
Z.ai disables coding features after unauthorized uploads
Z.ai disabled parts of its ZCode assistant after users said entire local repositories were uploaded to overseas cloud servers without consent. The company attributed the problem to a default-enabled codebase indexing feature, apologized, open-sourced the assistant and said an independent assessment confirmed the uploaded data had been deleted.
The incident shows why coding agents need explicit data boundaries. Repository indexing may improve context, but it can also capture source code, credentials and personal information. Enterprise buyers should require opt-in controls, clear retention terms and auditable upload behavior before granting assistants broad workspace access.
Intrinsic opens infrastructure for production robots
Alphabet's Intrinsic released Intrinsic Core under the Apache 2.0 license, giving robotics developers an open deployment layer built around Linux containers, Kubernetes and ROS workflows. The initial focus is commercial robotic arms and manipulation, supported by an open machine-tending reference design.
The release targets a persistent gap between robotics demos and maintainable production systems. Shared infrastructure can reduce the work required to package, update and monitor robot applications across factories, although the platform's value will be measured by hardware support and reliable operation outside curated pilots.
Heidi raises $340 million for clinical AI
Healthcare AI company Heidi raised $340 million in new funding, including a $100 million Series C led by Blackbird and a $240 million growth investment from General Catalyst. The company is expanding beyond ambient clinical notes into evidence retrieval, dictation and supervised agents intended to complete administrative work alongside clinicians.
The round shows that investors still see healthcare as a large market for task-specific agents. Adoption will depend on more than usage growth: health systems need evidence that outputs are accurate, citations are traceable, privacy controls are strong and clinicians remain responsible for consequential decisions.
What matters today
The common thread is vertical integration paired with higher operational risk. OpenAI is combining claimed scientific progress with a governance proposal. Alibaba is connecting models to chips and data centers. Cisco and Z.ai show how model access can create new security and data-governance failures, while Intrinsic and Heidi are packaging AI for robotics and medicine. The winners will not be determined only by model capability. They will also need review systems, infrastructure and controls that remain credible as AI moves into more consequential work.