Three threads are converging this week: AI outputs are becoming traceable artefacts, AI toolchains are proving to be high-value attack surfaces, and the power needed to run AI at scale is forcing a generation of infrastructure bets that have no precedent in enterprise technology. The developments below each deserve attention on their own terms; together they describe an industry moving from experiment to infrastructure, with all the accountability that implies.

Every Claude response will now carry an invisible watermark

On 11 August, Anthropic announced it will embed invisible watermarks in all Claude-generated text and images, effective globally. The commitment goes further than the EU AI Act's Transparency Code technically requires: rather than marking only outputs served to EU users, Anthropic is applying the standard worldwide. Google, Meta, Microsoft, and OpenAI have made the same commitment.

For files, Anthropic is using the C2PA open standard, which encodes provenance metadata into documents in a way that survives most editing workflows. For text, the watermark is embedded at the generation layer and travels with copied and pasted content, so AI-generated text placed on a publisher's site or inside a client document carries an identifier that detection systems can read.

The framing Anthropic chose is legally significant: the watermark records that the model processed the text, not who commissioned or directed it. Deliberate removal or alteration is prohibited under Article 50 of the EU AI Act, with fines reaching €15 million or 3% of global annual turnover, whichever is higher.

For any operator whose product outputs Claude-generated text to clients, this changes the compliance picture immediately. A watermarked output is now a traceable artefact. That is useful for internal audit trails; it becomes a risk if clients have not been told that AI processed their documents, or if confidentiality assumptions were built around output that was not, until now, machine-identifiable.

Lovable raises $400 million at $13.3 billion: vibe-coding is now enterprise infrastructure

Stockholm-based Lovable announced a $400 million Series C on 12 August, led by Menlo Ventures and the Scaleup Europe Fund, a European Union investment vehicle managed by EQT. The round values the company at $13.3 billion, double its December 2025 valuation of $6.6 billion. Annual recurring revenue is tracking toward $600 million by the end of August, nearly triple the $200 million figure from earlier this year. Users have built more than 60 million projects on the platform; Lovable-hosted applications attract more than 900 million visits a month.

Co-investors include Balderton Capital, Carmignac, Tencent, Kaszek Ventures, and World Innovation Lab. The geographic spread — European, Latin American, and Asian capital alongside US lead — signals that this is not a local market bet.

Lovable competes in the segment often called vibe-coding: the user describes what they want, the model writes and deploys working software, and the human edits by prompting rather than writing code. At 900 million monthly visits, the platform has passed a scale threshold that most traditional SaaS companies never reached. For operators assessing competitive exposure: a non-technical founder or team can now ship production software at a pace that was not possible twelve months ago. The organisational moat that came from controlling a software development capability is narrowing faster than most strategy documents currently reflect.

LiteLLM supply chain breach: 2,500 enterprises and 434,000 CI/CD pipelines exposed

Security researchers at CloudSEK disclosed that a threat actor group known as Team PCP compromised LiteLLM PyPI package versions 1.82.7 and 1.82.8 in March 2026. The initial entry point was the Trivy security scanner used inside LiteLLM's own build pipeline, which remained compromised for approximately 20 days. The FBI issued a FLASH advisory in July 2026 warning that stolen credentials from the breach could still be weaponised in future attacks.

High-confidence organisations in the exposure dataset include NVIDIA, Amazon Web Services, Cisco, Salesforce, Siemens, X Corp, and Orange. The full exposure spans more than 2,500 companies and 434,000 CI/CD pipelines across technology, finance, telecommunications, manufacturing, and defence.

LiteLLM is one of the most widely deployed open-source libraries for routing requests across multiple AI model providers. Any team running it in a build pipeline should audit whether the compromised versions were present and rotate credentials immediately. The broader lesson is structural: as AI tooling becomes a standard layer in enterprise infrastructure, the supply chain around that tooling carries the same attack surface as any other critical dependency. The AI model itself is not the only thing that needs to be trusted.

Fermi names Lee McIntire CEO to steady its nuclear-AI data centre bet

Nuclear-AI startup Fermi appointed Lee McIntire as Chief Executive Officer, effective 11 August, four months after the board removed co-founder Toby Neugebauer. McIntire was already an independent director on Fermi's board; he previously served as chief executive of CH2M Hill and held senior roles at TerraPower, the nuclear venture founded by Bill Gates, and Bechtel.

Fermi is developing Project Matador in Amarillo, Texas: a large AI campus planned to be powered by small modular reactors. The company was co-founded with former U.S. Energy Secretary Rick Perry. The leadership crisis in April left it financially strained and the project timeline uncertain; promoting an experienced infrastructure executive already familiar with the company's books is the lowest-friction resolution available to the board.

The appointment is a chapter in a story this digest has tracked all week. The binding constraint on AI scaling is no longer model quality. It is power. From Nvidia's $500 billion infrastructure financing to Anthropic's 20-year compute lease with Riot Platforms, and now Fermi stabilising its nuclear programme, capital is accumulating along the energy vector. McIntire's appointment signals the board has not abandoned the long-dated bet; it has simply decided to run it with someone who has built large, complex physical infrastructure before.

IBM and Together AI sign a $240 million NVIDIA-powered open-source inference deal

On 11 August, IBM and Together AI announced a $240 million multi-year commercial agreement under which IBM will deploy an NVIDIA HGX B300 cluster on IBM Cloud to power Together AI's enterprise open-source inference service. The cluster uses NVIDIA Spectrum-X Ethernet interconnect and is scheduled to reach general availability in Q1 2027. Together AI currently serves more than one million developers and processes approximately 400 trillion tokens monthly on its platform.

Together AI runs inference across a broad roster of open-weight models, including Llama, Qwen, Mistral, and others, and serves enterprises that want frontier-class performance without the data-residency and pricing implications of a closed API. The NVIDIA HGX B300 is NVIDIA's current highest-throughput multi-GPU inference chassis.

For operators evaluating the build-versus-buy decision on AI inference, this deal sets a concrete reference point for what enterprise-managed open-source inference will look like nine months from now: NVIDIA's latest hardware, IBM's cloud operations and compliance infrastructure, and Together AI's model routing layer. The pricing premium of GPT-5.6 or Claude Opus 5 APIs becomes harder to justify at scale for commodity workloads that open-weight models can handle adequately.

The through-line this week: AI at scale requires trust at every layer, from the watermark on the output to the integrity of the build pipeline that assembled the model-serving library. Operators who have not yet mapped their AI supply chain with the same rigour they apply to financial or IT supply chains are operating with a blind spot that their regulators and adversaries have already noticed.