Monday, September 14, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Morning Edition Free of Charge
TODAY'S LEAD STORY

The day anyone can borrow the "heart of Codex"—OpenAI reveals the contents of its agent operation platform.

On September 10th, OpenAI released the "Agents API," the agent operation platform that has supported Codex, in public beta. While it allows users to outsource all the cumbersome aspects of deploying agents in production, such as session management, automatic context compression, and partner sandboxes from nine companies, it remains limited to the United States for data residency.

The day anyone can borrow the "heart of Codex"—OpenAI reveals the contents of its agent operation platform.
(Photo: illustrative)

A Quiet Beginning, a Major Tectonic Shift

On September 10th, OpenAI released a single API. There was no flashy announcement, no new model name. It's a public beta called "Agents API," a rather unassuming name. But upon reading its contents, I felt this might be the most impactful announcement on how engineers work in the last few months.

In short, OpenAI has decided to lend out the entire "backend mechanism that powers Codex." The cumbersome foundational elements that have supported ChatGPT's "Work" function and the coding agent Codex—session management, context processing, and sandbox execution—are suddenly accessible through a single API call.

What is a "Harness"?

For those unfamiliar with the term, a "harness" is like a scaffolding for running agents. No matter how intelligent a model is, to use it for actual tasks, it needs a mechanism to maintain conversational context, a mechanism to invoke tools, a mechanism to assign tasks to multiple sub-agents, and a sandbox for safely executing code.

Until now, many teams built this "scaffolding" themselves. They wrote prompt chains, managed tool call logic, and implemented their own state-saving mechanisms to prevent session interruptions. While seemingly mundane, this was the most labor-intensive part when creating agents that would run for extended periods in production.

Made up of four components

According to OpenAI's official documentation, the Agents API is composed of four concepts: an "agent" that combines the model, tools, and MCP server; an "environment," or sandbox, for file access and command execution; a "session" that maintains state between turns; and "events and items" representing input and output themselves.

The sandbox selection is also flexibly designed. You can use a sandbox hosted by OpenAI, or you can set up your own `codex exec-server` on your infrastructure and connect. It also integrates with sandboxes from partner companies such as Blaxel, Cloudflare, Daytona, DigitalOcean, E2B, Modal, Oracle, Runloop, and Vercel from the start. The design philosophy is that developers only choose "where to run," and OpenAI handles the rest.

The Invention of Context "Compression"

Personally, what I found most interesting was the automatic context compression mechanism for long-running sessions. When an agent works for many hours, the conversation history and work logs grow exponentially, exceeding the model's processing capacity. The Agents API automatically summarizes and compresses the context up to that point as the session approaches its limit, leaving only the information necessary for the agent to continue working.

Another mechanism is "tool search." By loading only the definitions of tools likely to be used each time, it maintains the model cache while minimizing token consumption. Furthermore, using "programmatic tool calls," tools can be executed in parallel, and large amounts of data can be filtered code-wise before returning only the necessary results to the context. While this may seem like a minor feature, it directly addresses the biggest cause of the high costs associated with deploying agents in production.

Sandboxes are selectable, but data cannot leave the US

On the other hand, there are some concerning limitations. Currently, the Agents API's data residency is limited to the US and does not support Zero Data Retention (a mode that does not retain any data). Even if a company sets up its own sandbox in any country, the control plane itself remains within the US. This is likely to be a barrier to adoption for regulated industries and companies outside the US.

Voices from Companies That Have Actually Used It

The article also includes testimonials from companies that have already implemented the API. The head of engineering at insurance tech company WithCoverage commented that while they previously wrote their own prompt chain and tool call management, the Agents API allowed them to rethink the design of their complex, multi-stage workflows. One company reported a 60% reduction in costs and improved latency after migrating their case review workflow. While not flashy figures, these are reliable reports of cost savings in real-world operation.

From "Model Intelligence" to "Infrastructure Maturity" as the Competition Shifts

This API suggests that the competitive landscape for frontier AI is gradually shifting. This marks a shift from competing on model benchmark scores to competing on "how mature the foundation for running agents stably for extended periods has been." The pricing structure is also simple: there are no additional charges for the Agents API itself; you are only billed for the tokens and tools you use.

Things Engineers Should Consider

For teams building their own agent infrastructure, this announcement provides material for seriously considering whether to switch or continue developing in-house. The ability to externalize parts that subtly consume time with each feature addition, such as session management and context compression, is particularly significant. However, the US-only data residency restriction is a significant obstacle for teams running agents in overseas locations, including Japan. For the time being, it seems realistic to monitor how this restriction is eased and try implementing it via the partner sandbox.

OpenAIAgents APICodexAIエージェントクラウドインフラ

AI continued its attack while fixing its own "bugs"—Anthropic exposes automated workshop of state-sponsored hacker group

This analysis examines the threat intelligence report published by Anthropic for December 2025 to August 2026. GTG-20006, believed to be of Russian state origin, operates a loop in which an AI agent automatically corrects and redeploys malware whenever it is detected, using hotel Wi-Fi as a stepping stone to narrow down targets in a chain reaction. The analysis suggesting that autonomy and the severity of an attack are on different axes is also insightful.

What Eight Months of Threat Data Tell Us

I read through the latest threat intelligence report published by Anthropic. The report covers an eight-month period from December 2025 to August 2026, spanning seven areas: cyberattacks, influence operations, surveillance, fraud, biological risks, conventional weapons development, and distillation. Personally, the case study that interested me most was "GTG-20006" in the cyberattack chapter. It details how a state-sponsored hacking group used AI to continuously "self-repair" malware.

The Identity of the Russian-Speaking Operators in GTG-20006

According to the report, GTG-20006 involved Russian-speaking operators, and attribution analysis of publicly available information aligns with Midnight Blizzard, a known Russian state espionage group. Targets included military and government agencies, diplomatic personnel, and defense industry companies in Ukraine and Europe, as well as maritime government agencies in Southeast Asia and government technical authorities in North Africa. The attackers allegedly operated a proprietary toolkit consisting of two Windows-specific implants, a mobile attack kit, a credential theft tool, a phishing platform disguised as a government agency, and a management console for managing compromised accounts.

The "Automatic Reconstruction Upon Detection" Loop

The most interesting aspect of this case is that the attackers continuously monitored the malware's detection evasion using an AI agent. If deployed malware was detected by a security product, the agent automatically identified, corrected, and redeployed the artifact. This iteration was designed to continue until the tool evaded detection.

This fundamentally alters the structure of traditional offensive and defensive battles. The traditional premise—that the attacker automatically rewrites the malware to evade signatures even after the defender creates them—is broken. The report describes this as "the cost flowing back to the defender." The attackers distributed tools from disposable hosting servers, directing victim traffic to them.

Chain of Targets Starting from Hotel Wi-Fi

An interesting technical detail is the indirect route to the targets. GTG-20006 compromised at least three hotel guest Wi-Fi vendors, using administrator privileges to rewrite DNS records and perform "DNS hijacking" to redirect traffic to its own servers. The communications, device identifiers, and IP addresses of guests connected to the hotel Wi-Fi were sent to the attackers' servers, where ClickFix-type spoofing was installed to distribute malware for Windows, Android, and iOS. The attackers combined guest information stolen from the hotel's management system with data stolen from individual guest devices to narrow down their targets. Government officials and drone manufacturers with ties to Ukraine were particularly targeted. It should be noted that some of these methods are consistent with a report independently published by Microsoft Threat Intelligence in July 2026 as "CaptiveCrunch," and the fact that independent observations from multiple security vendors corroborate the same attack campaign enhances the credibility of this research. ## The AI ​​Supply Chain Itself Becomes a Target

Another pillar of the report is the analysis that AI API keys and session tokens themselves have become "trophies" of the criminal economy. One group (GTG-50020) successfully injected prompts into an AI vendor's automated evaluation sandbox, extracting production API keys from multiple providers held by the sandbox. A campaign was also launched from the same infrastructure, attacking 30 AI companies in about four days. The attackers' ultimate goal was access to an unreleased Claude model, but the report states that "the attempt was never successful."

Autonomy and Severity are Different Axes

The report repeatedly emphasizes that "autonomy" and "severity" are different axes. Autonomy amplifies the speed and scale of operations and reduces operational costs and complexity, but severity itself is determined by other factors. In fact, some of the most serious breaches described in the report were cases where humans directly directed every step. From an economic perspective, AI-driven automation reduces the cost of ROI calculations for attackers, lowering the required skill level and workload while maintaining virtually the same results. This asymmetrical shift is analyzed as enabling attacks on previously unprofitable targets and fostering low-involvement, high-frequency operations.

What Researchers Should Note

This report reveals a structural shift where the line between sophisticated attackers and amateurs is no longer distinguishable by "technical skill" but solely by "intention." Russian-speaking operators, French-speaking hacktivists, and groups of Chinese-speaking students have independently, yet remarkably, arrived at similar methodologies—delegating everything from reconnaissance to exploit development and data processing to AI agents. The attacks themselves employ familiar tactics such as stolen credentials, unpatched devices, and phishing; no novel technologies are used. The report's conclusion that only economics has changed carries significant implications for future defensive design philosophies.

AnthropicAI安全性サイバーセキュリティ脅威インテリジェンス企業公式発表

NVIDIA paid 1.9 trillion yen for a company with annual sales of 15 billion yen—the real price they paid for the "heart of open source."

NVIDIA announced it will acquire Hugging Face for $12.93 billion. Hugging Face's annual operating revenue is approximately $150 million, making the acquisition price more than 80 times that amount. The majority of the acquisition price will be used to pay existing investors and retain employees. This article analyzes, from an accountant's perspective, the implications of NVIDIA's governance decision to maintain openness rather than lock in its customers.

The 50 Billion Yen Offer That Was Once Rejected

NVIDIA has officially announced its acquisition of Hugging Face for $12.93 billion, approximately 1.9 trillion yen. What's interesting from an accountant's perspective is the facts preceding this figure. According to the Financial Times, NVIDIA's $500 million acquisition offer was rejected by Hugging Face last year. This means the offer has ballooned to approximately 26 times its original price in just over a year. Of course, this doesn't mean Hugging Face's business value has increased 26-fold. Rather, we need to break down why they agreed on this level.

Analyzing the Breakdown of the Acquisition Price from an Accountant's Perspective

According to the reported breakdown, approximately $11.9 billion of the $12.93 billion will be used to pay existing investors, with the remaining up to $1 billion allocated to employee retention incentives. This structure is closer to a deal that buys not just stock, but also talented individuals and the continued operation of the community itself. NVIDIA CEO Jensen Huang explicitly stated in a blog post that the Hugging Face team would "integrate directly into the NVIDIA organization and continue the project," suggesting that this is more of an acquisition of talent and an entire platform rather than just a product.

The Reality of Hugging Face's Business Scale

Let's look at some numbers here. According to The Information, Hugging Face's annual recurring revenue (ARR) is approximately $150 million, or about 22 billion yen. The acquisition price is a staggering 80 times its revenue. From its founding to the present, the company has raised a total of approximately $395 million, with its most recent funding round in 2023 being $235 million, led by Salesforce Ventures. In other words, its valuation in the finance market hasn't suddenly skyrocketed in the last two and a half years; rather, its value has jumped dramatically due to a strategic decision by NVIDIA.

Why "Openness" Was Chosen Instead of "Domination"

More than the accounting figures, what's noteworthy is NVIDIA's explicit statement that it will "maintain Hugging Face as an open platform" even after the acquisition. It's stated that it will continue to support competing hardware from AMD and Intel, other cloud services, and other inference frameworks as before. Normally, acquiring companies would be tempted to lock users into their own products, but NVIDIA has deliberately resisted that temptation.

This suggests that NVIDIA's value in Hugging Face lies not in "revenue from lock-in," but in "holding the center of gravity of an open ecosystem." If they can hold the center of gravity of a platform used by 18 million developers, 3 million models, 1 million applications, and 200,000 companies, remaining the largest supplier of computing resources consumed there will have a greater long-term revenue impact. In fact, some sources say that NVIDIA itself is the largest contributor, providing over 500 models and over 250 datasets to the platform. I believe the essence of this transaction lies not in the acquisition price itself, but in the choice of governance—"who will take the lead?"

600 Billion Yen for Poolside and 5 Trillion Yen for the Frontier Research Center

While this deal may seem outlandish in isolation, its meaning becomes clearer when placed within NVIDIA's recent investment pattern. In its most recent earnings call, NVIDIA revealed it has invested over $50 billion in its AI Frontier Research Centers. Just last month, it was reported that NVIDIA had signed a $6 billion contract with coding startup Poolside for open model development. The acquisition of Hugging Face is not a one-off move, but rather an extension of NVIDIA's consistent strategy of continuously investing capital in those who create demand for computing resources. It's reasonable to understand this as a move to reinforce its dominant hardware position from the software ecosystem side as well.

The Next Hurdle: Antitrust Laws

As an accountant, I'll be watching closely to see if this deal ultimately closes. NVIDIA already holds a dominant share of the data center GPU market, and acquiring core infrastructure for AI model distribution would certainly raise antitrust concerns from competition authorities in various countries. Depending on the outcome of the regulatory review process leading up to the acquisition's completion, the terms announced this time may be subject to change.

Points to Note from an Accountant's Perspective

While the $12.9 billion figure may seem like a bold gamble, the majority of it is a cash payment to existing shareholders, and the immediate impact on cash flow will not be particularly large given NVIDIA's current cash reserves. Rather, what should be closely watched is how this acquisition will be recorded as "software ecosystem revenue" in NVIDIA's future financial statements, and to what extent the synergies with hardware sales will be quantitatively demonstrated. We should check how this acquisition is reflected in the segment-specific figures in the next quarterly earnings report.

NVIDIAHugging FaceM&AファイナンスAIインフラ
Advertisement300 × 250