A breach cleanup task, discount AI credits that aren't, and what an 'AI layoff' really means
If you have a Hugging Face account, rotate your tokens
The security incident we covered yesterday now has a cleanup step attached. Hugging Face's security incident disclosure says attackers reached a limited set of internal datasets and several service credentials, and asks users to rotate any access tokens and review recent account activity. The company says it found no evidence that public models, datasets, or Spaces were tampered with. Separately, Hugging Face's chief executive called for the research community to get the full record of what happened. Why it matters: most small businesses don't use Hugging Face directly — but a developer or contractor who has built something for you might. The five-minute version: ask whoever handles your technical work whether they have an account there, and if so, rotate the token. It's the same routine as changing a password after a service you use gets breached.
The cheap AI credits going around are a gray market
An investigation into the "relay" market, highlighted by a widely followed AI newsletter, describes a sizable business reselling access to major AI models at steep discounts — one listing offered the equivalent of thousands of dollars of official credit for a tiny fraction of the price. It works by pooling large numbers of accounts behind a proxy and reselling capacity, and the report ties parts of the supply chain to bulk-registered accounts and payment-card abuse. Why it matters: if someone offers your business AI access at a price that looks impossible, it probably is. Two practical risks: everything you send through a reseller passes through a middleman you have no agreement with, and the access can vanish the moment the pooled accounts are shut off. Buy AI capacity from the vendor or an official reseller you can name, and keep the invoice on file.
A software company cut a fifth of its staff — and said it wasn't about replacing people
The company behind the monday.com work platform disclosed in a filing on July 22 that it is eliminating roughly 630 roles, about 20% of its workforce, as it reorganizes around an AI-focused product strategy, with $45–55 million in restructuring charges. A co-founder told staff the decision was not made to cut costs or to replace people with AI. TechCrunch is keeping a running list of 2026 tech layoffs where employers cited AI, and notes an interesting wrinkle: by one analysis, companies announcing AI-linked layoffs have tended to underperform the market in the weeks afterward. Why it matters: "AI layoffs" is doing a lot of work as a phrase. Sometimes it means AI did the job now; often it means a company is reorganizing around a new product bet and AI is the headline. If you use a tool that's going through this, the thing to watch isn't the headcount — it's whether support response times and your renewal terms change.
Capable open-weight models are changing where AI can run
TechCrunch has a look at the reaction to recent open-weight model releases from Chinese labs, including Moonshot AI's Kimi, which have posted competitive benchmark results while being published in a form anyone can download and run. The piece walks through an active policy debate in the US about whether and how such models should be restricted. Why it matters: open-weight models are the reason "run the AI on our own server" is becoming a real option for ordinary businesses instead of a research project — relevant if you handle data you'd rather not send to an outside service. It's also worth knowing the rules here are unsettled: if you're planning around a specific model, it's fair to ask a vendor what happens to your setup if that model's availability changes.