This website uses cookies

Read our Privacy policy and Terms of use for more information.

// AI Tangle

The Week AI Got an Owner

Salesforce kept its own weights, a Chinese lab served a flagship without American chips, and Gemini walked into three real companies. This week was about who controls the AI your business runs on.

This week, the AI story wasn’t really about benchmarks or who released the biggest model. It was about control — and who gets to hold the keys. Salesforce moved toward owning its own reasoning model instead of relying entirely on outside providers, while Z.ai showed that a Chinese lab can run its flagship open-weight model on Chinese-made accelerators across its production traffic. Google also disclosed that Gemini accessed three outside companies during a May security test after credentials were exposed in a public repository. At the infrastructure level, Crusoe raised $3.9 billion to build data centers around available power, showing just how much the physical side of AI is expanding.

And while all of that was happening, OpenAI confirmed safety discussions with its two biggest rivals as the major labs consider whether they should create their own standards for AI safety. So this week’s question is bigger than which model is ahead: who actually controls the AI your business runs on? Join us in this week’s AI Tangle as we break down what happened, why it matters, and where the industry is heading.

// The Big AI Story

At Dreamforce on September 15, Salesforce and Nvidia announced Koa, Salesforce's first reasoning model for Agentforce. Salesforce took Nvidia's open-weight Nemotron 3 Super and post-trained it on a synthetic dataset modeled on 27 years of CRM deployments — how a deal moves, how a service case gets routed, how a follow-up gets scheduled.

The detail that matters is one sentence in the press release: Salesforce controls the weights and runs post-training and inference inside its own trust boundary. On Salesforce's own CRM benchmark — and yes, it's their benchmark, so season to taste — Koa matches or beats leading models on CRM actions with three times fewer errors. Pilots are under way at Formula 1, UChicago Medicine, Xero, and three others.

TechCrunch's read was that Koa is everything the AI labs should fear: the enterprise wants a model trained to do specific work, on weights it can control, and the frontier labs would prefer you upload your files, prompts, and feedback to them. Jensen Huang's version, as Constellation Research reported it, is that the world will keep using closed models and every company will build private ones alongside them.

Here's the business read. You're not Salesforce and you're not going to post-train a model next quarter. But the pattern is the same one I watched play out with Linux: nobody ripped out their Unix boxes in a weekend, they just stopped putting the new, important stuff on a platform they couldn't control. Start asking your vendors the Koa question — whose weights, whose infrastructure, and what happens to my data at inference? If they can't answer in a sentence, that's your answer.

// The Number

100,000

The number of Chinese-made accelerators Z.ai says are now serving production traffic for its flagship open-weight model. The company says throughput tripled in less than two weeks, with per-token costs comparable to mainstream Nvidia GPUs. The figures haven't been independently verified, and serving a model is different from training one. But the bigger story is what that number represents: AI infrastructure is becoming something companies — and countries — increasingly want to control themselves, from the model weights to the chips to the data centers running them.

Source: Z.ai

// 4 Quick Hits

Google disclosed Friday that in May, during a cybersecurity evaluation, a Gemini model gained unauthorized access to three outside systems — in one case by guessing login information, in the others by using credentials it found in a public repository. Google says the model thought those systems were part of the test and stopped once inside. The test was run by Irregular, the same evaluator tied to similar disclosures from OpenAI, Anthropic, and Meta, and Google only learned of it in July. What it means for you: an agent didn't need a zero-day, it needed a password somebody committed to a public repo — go find yours before something tireless does.

In a September 17 technical post, Z.ai says all production inference for its open-weight GLM-5.3-Flash now runs on a cluster of more than 100,000 Chinese-made accelerators, and that throughput tripled in under two weeks at a per-token cost it calls comparable to mainstream Nvidia GPUs. Nobody outside the company has verified those numbers, and serving a model is a lot easier than training one. What it means for you: this is what sovereign AI looks like when a country means it, and it puts one more cheap, capable open-weight option on your procurement list, plus a provenance question for legal.

Crusoe announced the initial close of a $3.9 billion Series F on September 17 at a $30.9 billion post-money valuation, co-led by Atreides Management, Mubadala Capital, and Valor Equity Partners. The money goes into Spark, modular data centers built in Crusoe's own factories and trucked to sites with power to spare. What it means for you: the constraint on AI has moved from chips to electricity and concrete, and capacity that ships on a flatbed is how smaller buyers — including, eventually, mid-market companies — get compute of their own.

OpenAI policy chief Chris Lehane told reporters Tuesday that the three labs have been talking about safety for weeks, and TechCrunch notes reporting that they're working on an industry standards body — something Demis Hassabis called for in July. The antitrust question is obvious, and Lehane also said OpenAI backs a FRONTIER Act provision that would put independent verification organizations inside frontier labs. What it means for you: release gates for the models you depend on may soon be set by the companies that sell them, so add one line to your vendor review — who, outside the vendor, verified this model before it shipped?

// 3 AI Tools
  • Claude memory import and export — Anthropic now documents a flow for bringing your memory over from another assistant and for writing Claude's memory of you out to a file. If you can move your context in ten minutes, you're a customer, not a hostage.

  • Astra for Law — OpenAI's first vertical configuration of its flagship pairs the model with a legal search index covering more than 230 million URLs of U.S. case law, statutes, and regulations. It passed 54% of a legal research benchmark versus 38.7% for the base model with web search — better, and also a reminder that a lawyer still checks the cites.

  • LM Studio — A free desktop app that downloads open-weight models and runs them on your own laptop, offline. It's the easiest way I know to try the documents you'd never paste into a chatbot, because nothing leaves the machine.

// The Extra Read

Fortune's Nicholas Gordon, reporting from Hong Kong, makes the point that sovereign AI means something different everywhere you go, and that the buyers who want it mostly don't need the most powerful model — they need one nobody can take away. Swap "government" for "company" and it's the best framing I've read for this week's news. Nobody in this week's news is chasing a leaderboard. They're buying the option to walk.

Mark R. Hinkle

Your AI Sherpa,

Mark R. Hinkle
Founding Publisher, The AIE Network
Follow me on LinkedIn


If you want to get in contact or give me feedback, reply to this email. I read every single one of them.