AI news roundup September 11 2026: Google ADK CVE, Nvidia Groq DOJ probe, Mistral, Positron, Harvey
the shed // AI NEWS ROUNDUP

A CVSS 10.0 hole in Google’s agent framework, the DOJ digging into Nvidia’s Groq deal, a safety hawk on OpenAI’s board, and three funding rounds that say where the money thinks inference and vertical AI are going.

This week’s AI news splits cleanly into two piles: things that can break your production environment today, and things that will shape what you get hired to build next year. We lead with the first pile. Six stories, all from the last 72 hours, each with a source link and a note on why it matters if you work in DevOps, security, or AI engineering.




ai-news/2026-09-11

[2026-09-09 security] CVE-2026-79696 :: Google ADK for Python :: CVSS 10.0

An unauthenticated remote attacker can execute arbitrary code against adk web in Google’s Agent Development Kit for Python 2.0.0 through 2.6.0 using a crafted test-session replay, wherever pytest is installed. That covers OSS, Cloud Run, and GKE deployments.

Why it matters: the dev UI is exactly the kind of thing that gets left exposed on an internal cluster. If you build on ADK, patch past 2.6.0 today and confirm adk web is not reachable from anything you don’t control. CVE Brief

[2026-09-10 regulation] DOJ opens antitrust probe into Nvidia-Groq license

The Justice Department is investigating whether Nvidia structured its December “non-exclusive license” with inference-chip startup Groq (reported at 17 to 20 billion dollars, plus the hiring of Groq’s CEO and COO) to dodge merger review. Nvidia has received a formal information demand.

Why it matters: license-plus-acquihire has been the AI industry’s favorite way to buy a company without calling it an acquisition. If DOJ fines this one, expect the pattern to slow, and expect inference silicon to stay a more competitive market than it would have otherwise. Axios

[2026-09-09 governance] Paul Christiano joins OpenAI Foundation board

OpenAI added alignment researcher Paul Christiano, currently a senior technical adviser at the Commerce Department’s Center for AI Standards and Innovation, to its nonprofit board and its safety and security committee.

Why it matters: a week after cyber-evaluation agents made headlines for escaping their sandboxes, the most-cited “catastrophic risk” researcher is now inside the governance of the biggest lab. Whether that changes shipping decisions is the thing to watch. TechCrunch

[2026-09-08 funding] Mistral closes 3B euro Series D at 21B euro valuation

Samsung led the largest equity round ever raised by a private European tech company, with EQT’s Scaleup Europe Fund and PSG Equity co-leading. Mistral says the money goes to compute, data centers, and international expansion.

Why it matters: sovereign, open-weight AI now has a war chest. For teams in regulated industries that need EU-hosted models with published weights, the credible option list just got longer. TechCrunch

[2026-09-10 hardware] Positron raises 875M at 5B for memory-first inference chips

Positron AI closed a 375 million Series C plus up to 500 million in a C-1, co-led by NEA, Atreides, Valor, Andra, SemiAnalysis Capital, and Jim Clark. Its Asimov chip pairs compute with 288 GB to 2.3 TB of commodity LPDDR5X per chip, sidestepping the HBM shortage. Tapeout on TSMC N3P is planned for late 2026.

Why it matters: inference is becoming its own hardware category, and the bottleneck is memory, not FLOPs. If you run model serving, the next two years of cost curves will be set by chips like this. PR Newswire

[2026-09-09 funding] Harvey hits 15.5B valuation with 550M round

Legal AI company Harvey raised 550 million led by Diffusion and Lightspeed, days after shipping Tenet, its first in-house model: a fine-tune of the open-weight Kimi K3 with a custom harness built for legal work.

Why it matters: the vertical-AI playbook is now explicit. Open weights plus domain data plus a proprietary harness. That is a stack a platform team can build for its own domain, and the market is paying for it. TechCrunch

1. Google's Agent Development Kit ships a CVSS 10.0

What happened: CVE-2026-79696, disclosed September 9, is a code-injection flaw in the adk web developer UI of Google Cloud's Agent Development Kit for Python, versions 2.0.0 through 2.6.0. An unauthenticated remote attacker can run arbitrary code by feeding the server a crafted test-session replay, on any host where pytest is installed. The affected environments include self-hosted OSS, Cloud Run, and GKE.

Why it matters: agent frameworks are now attack surface in their own right. The dev UI is the piece most likely to be left listening on an internal network "just for the demo." Patch to the fixed release, confirm adk web is not exposed beyond localhost, and add ADK to whatever SBOM scanner you already trust. If you run agents on GKE, this is also a good week to check that your agent pods cannot reach the metadata server. Source: CVE Brief

2. DOJ probes whether Nvidia's Groq deal dodged merger review

What happened: The New York Times, then Axios and Bloomberg, reported that the Justice Department is investigating whether Nvidia's December "non-exclusive license" with Groq, valued in the 17 to 20 billion dollar range and paired with hiring Groq's founder and COO, was structured to avoid Hart-Scott-Rodino review. DOJ has sent Nvidia a formal demand for information. A fine is possible; unwinding the deal reportedly is not.

Why it matters: license-and-acquihire deals have let the biggest AI companies absorb competitors without a merger filing. If this one draws a penalty, the pattern gets more expensive, which is good news for anyone hoping the inference-chip market stays plural. It also means the exit math for chip and model startups just changed. Source: Axios

3. OpenAI puts Paul Christiano on its Foundation board

What happened: On September 9, OpenAI named Paul Christiano, a senior technical adviser at the US Center for AI Standards and Innovation and founder of the Alignment Research Center, to the board of its nonprofit foundation. He joins the safety and security committee chaired by Zico Kolter.

Why it matters: this lands after a stretch where frontier labs' own cyber evaluations spilled into real systems and lawmakers started drafting agent-security bills. Christiano has publicly put double-digit odds on catastrophic outcomes, and now he has a governance seat. For practitioners, the practical read is that "safety case" documentation, sandbox containment for evals, and independent review are about to become table stakes, not differentiators. Source: TechCrunch

4. Mistral raises 3 billion euros at a 21 billion valuation

What happened: On September 8, Mistral confirmed a Series D led by Samsung Electronics, co-led by the EQT-managed Scaleup Europe Fund and PSG Equity, at a 21 billion euro valuation. It is the largest equity round ever completed by a private European technology company. The stated use of funds: compute capacity, data-center infrastructure, and international growth.

Why it matters: if you work somewhere with data-residency rules (finance, healthcare, public sector), an EU-based lab with open weights and its own data centers is the option you keep getting asked about. That option now has the capital to keep up. It also means more open-weight models to run on your own hardware, which is worth revisiting in our courses on local model ops. Source: TechCrunch

5. Positron raises 875 million for memory-first inference silicon

What happened: Positron AI announced September 10 that it raised a 375 million Series C and a C-1 of up to 500 million, reaching a 5 billion post-money valuation, up from about 1 billion in February. Its upcoming Asimov chip pairs its compute architecture with up to 2.3 TB of commodity LPDDR5X per chip, avoiding the high-bandwidth-memory crunch that is currently raising accelerator prices worldwide. Tapeout on TSMC N3P is scheduled for late 2026, production in the second half of 2027.

Why it matters: serving models is where most of the money now goes, and serving is memory-bound. A credible non-Nvidia inference chip that sidesteps the HBM shortage changes the cost forecast for anyone running LLM endpoints at scale. Worth tracking alongside your capacity plans. Source: PR Newswire

6. Harvey hits a 15.5 billion valuation, with its own model

What happened: Harvey raised 550 million led by Diffusion and Lightspeed on September 9, roughly doubling its valuation since March. The round follows the launch of Tenet, Harvey's first in-house model, built by post-training the open-weight Kimi K3 on legal documents and wrapping it in a custom harness of prompts and tooling.

Why it matters: the recipe is public now: open weights, domain data, proprietary harness, strict document control. That is a stack a platform or security team can replicate for its own domain (runbooks, IaC, incident history) without waiting on a vendor. Vertical AI is where the valuations are, and the barrier is data discipline more than model access. Source: TechCrunch

The thread this week

Agent frameworks are getting the same critical CVEs that web frameworks got fifteen years ago, regulators are finally treating "license plus hire" as what it is, and capital is moving to the layers below the model: inference silicon, sovereign infrastructure, and domain-tuned open weights. If your job touches production, the two actions for today are patching ADK and checking which of your agent tools are listening on an interface they should not be. If you want the fundamentals to do that with confidence, the DevOps Boot Camp is where we teach it.