
Happy Tuesday ⚡️
Anthropic is going public, and it's going public profitable. The IPO is expected in October at a target near $2 trillion, up from $965 billion in May. Second-quarter revenue more than doubled to $10.9 billion, and the company posted its first operating profit years earlier than its own plan said it would. One number worth knowing: at $2 trillion, it would eventually need somewhere between $59 and $79 billion a year in profit to look normal next to the rest of the Nasdaq. Keep that in mind, because the week's biggest deal was a bet on where the profit in AI ends up.
Today, we're talking about:
1. The 60-second version of everything that happened in AI this week
2. Why a payments company paid $7 billion for a business that doesn't make a single model
3. Grok Bot after a week: the good, the bad, and whether your team should try it

Sixty seconds on the week, then one story worth your full attention.
A Chinese lab held back its open weights because the model got too good at hacking. Z.ai released GLM-5.3 but delayed the public weights by about two weeks after it scored 84.5% on CyberGym, a benchmark for finding software vulnerabilities. That's a hair ahead of Claude Mythos 5 and GPT-5.6 Sol. Since the last version, the model has turned up 2,436 vulnerabilities across 269 open-source projects, 1,097 of them rated critical or high. And the base model didn't change. All of that came from extra training on top.
An AI manager recommended firing a human. Luna, the Claude-based manager running Andon Labs' store in San Francisco, recommended parting ways with a worker who showed up late for 17 of 23 shifts. People at the lab reviewed it and made the call. The part we found interesting: Luna had written an attendance policy months earlier, then lost track of it. It only acted after someone told it to go back and read its own rules. Worth remembering the next time you assume an agent will enforce something you set up in week one.
Google shipped another cheap model, three weeks after the last one. Gemini 3.7 Flash went from 49% to 65.3% on DeepSWE and 34.4% to 43.6% on FrontierCode, at $0.75 per million input tokens. That price is introductory and doubles on January 1, 2027.
IBM is putting its consultants behind OpenAI. IBM launched a dedicated OpenAI practice, training thousands of consultants and building GPT-5.6 and Codex into its consulting platform, with a focus on financial services, government, telecom, and retail. If you run a big company, this is the pitch you're going to hear next.
And Stripe paid more than $7 billion for a company that doesn't make a single model.
That last one is the one to double-click. Let’s dive in.

Stripe Bought The Meter
Stripe finalized a deal this week to buy OpenRouter for more than $7 billion. Three months ago OpenRouter raised money at $1.3 billion. So more than five times the price, in a quarter, for a company that has never trained a model and isn't planning to. What OpenRouter does is simpler than that. You connect once, and it gives you access to more than 400 models from every lab. It picks the one you asked for, sends the request through, and bills you at the end of the month. About 8 million people use it.
The scale is what people miss. OpenRouter now handles roughly 1.5 quadrillion tokens a year, up from about 100 trillion a year ago. That's a meaningful slice of what Google or OpenAI handle directly. And none of it is OpenRouter's. It's other companies' models and other companies' customers. OpenRouter just sits in the middle and counts.
So, are models the new currency? We'd say no. Models are the inventory. Tokens are the currency. What Stripe bought is the cash register.
Here's why that distinction matters. Look at what's happening to the inventory on OpenRouter's own platform. American models went from about 70% of token volume in June 2025 to roughly 30% a year later. DeepSeek alone now runs 16.3% of all traffic, more than any other single provider, including Google, Anthropic, and OpenAI. Tencent's Hy3 Preview costs six cents per million input tokens. When customers can swap suppliers that fast over a price gap that big, being the supplier is a tough spot. Being the thing they swap through is a good one.
That's why the buyer was a payments company and not a lab. Stripe has spent fifteen years sitting between buyers and sellers, taking a small cut of everything that passes through. Tokens look a lot like the thing Stripe already does. They're metered, they come from a bunch of vendors, they're billed on usage, and the spend is growing faster than most finance teams can keep up with. OpenRouter's CEO has been calling his company "the equivalent of Stripe for AI." Stripe apparently agreed, and decided buying it was easier than building it.
Where we land: treat AI less like a software license and more like electricity. A license is something you pick once and forget about. Electricity is a meter you watch and a rate you shop. The question your CFO will ask next year isn't which model you chose. It's what a finished task costs you, and how fast you could move if that number doubled.
Stripe didn't bet on which lab wins. It bet that you'll keep switching, and that whoever counts the tokens gets paid either way.
Try it: OpenRouter is free to sign up and you pay by the token. Point one low-stakes workload at it, run the same job through three different models, and compare cost and speed side by side. You'll learn more about your real AI spend in an afternoon than from any vendor deck.
Everybody's waiting for cheaper AI. Almost nobody is set up to use it.
Tenex is the AI engineering team behind this newsletter. We sit with your team, find the work worth handing to an agent, build the systems around it, and train your people to keep going after we leave. So when the next price cut lands, you're actually plugged in.

Grok Bot Is Passing The Builder Test
The Tenex team has been on Grok Bot for a week, and we're loving it so far. So is most of the builder crowd we talk to. People are getting real work out of it, and they like it. It might be the first personal agent simple enough that regular knowledge workers will actually use it.
It sits in the same bucket as Cowork and ChatGPT Work, but it's the easiest of the three to pick up. No tabs, no model picker. You get one computer in the cloud that all your bots share, each with its own screen, and nothing runs on your laptop unless you want it to. You tell it what you want and it figures out the tools. You can click in and watch the browser work, and it's not laggy the way most of these are. Routines are simple too: on a schedule, or when something happens outside, like a webhook. And you can make a few bots and put them in a group chat. Jack Dorsey's Buzz tried a version of that. This one feels native.
The catch is that it hides almost everything. No wall of toggles, no knobs. Some people will bounce because it looks basic. It isn't. You just have to ask.
When to reach for it:
1) A job that has to run while you're not there. Overnight research, a report that builds itself every morning, a queue that gets worked through. It lives in the cloud, so closing your laptop doesn't stop it.
2) A tool with no integration. If the only way in is a browser and a login, Grok Bot can click through it like a person. Most agents can't.
3) Something you do the same way every week. Show it once, save it as a routine, put it on a schedule or a trigger. Status updates, inbox sweeps, pulling numbers into a sheet.
4) Work that needs a few hands at once. One bot researches, one drafts, one checks. Put them in a group chat and let them pass it around.
5) A teammate who bounced off agents before. If the setup was what killed it last time, this is the one to hand them. There's almost nothing to set up.
Two things to know before your team tries it:
1) It's expensive. $200 a month on the personal plan (that's Cursor Ultra, with Grok Bot included) or $120 a seat on teams.
2) Your logins live on that shared cloud computer. It's shared across all your bots, not locked to one. If that machine has a problem, it's a problem for everything you signed into. It's beta, and enterprise is still a waitlist. Don't point it at sensitive connectors yet.

None of this is required reading. But if you want to go further than your job demands, we've got you too.
The free field guide to agent security — OWASP's State of Agentic AI Security and Governance, published in June and free to download. If you're deploying agents with real access, your security team is going to ask whether you've read it. OWASP
The IBM and OpenAI announcement, primary source — The press release itself, including the three workflow areas they're going after and the "Elite partner" language. Read it as a preview of the pitch your board will hear from a consultancy soon. IBM
What OpenRouter looked like three months before the $7 billion — The Series B write-up: 25 trillion tokens a week, 400-plus models, and an investor list with NVIDIA, Snowflake, Databricks, MongoDB, and ServiceNow on it. A lot of people saw this coming. Stripe moved first. Tech Startups
The bottom-up case for Anthropic's profit — SemiAnalysis built the financials by customer segment instead of taking the headline number. Useful if you want to know what "profitable" means for a company that still spends like this one. SemiAnalysis

Open roles:
AI Strategist
Forward Deployed Engineer
Applied AI Engineer
Engagement Manager
Salary ranges vary by role and experience. Additional comp based on output. Must be NY-based.