Eighty billion yuan in one round, a hundred sixty thousand Huawei chips on order, and a founder who reportedly says making money isn't the main goal. This is AI Daily Briefing for Tuesday, October sixth. Today: DeepSeek's round runs past its own target, Reflection puts a five-hundred-billion-parameter open model on the calendar, a researcher shows how attacks hop from one agent to the next, and a hundred-forty-billion-dollar plan for data centers in Japan that bring their own power. Follow the show and the next briefing lands in your feed on its own.
Bloomberg, published by The Straits Times:
DeepSeek is close to securing at least 80 billion yuan (S$15 billion) in its latest round of funding, blowing past its own capital-raising target ahead of a landmark initial public offering in early 2027.
That comes from people familiar with the matter. DeepSeek first sought about fifty billion yuan. Based on signed term sheets, those people say the final tally could approach a hundred billion. The battery maker CATL and Tencent committed among the largest amounts. The round closes soon, and details may still change. Quick currency note, because that fifteen is Singapore dollars, not US. The useful comparison is in yuan anyway. The previous round was fifty billion yuan at a valuation of roughly three hundred fifty billion. This time DeepSeek went in targeting about five hundred billion. The money has a destination. DeepSeek plans to deploy at least a hundred sixty thousand Huawei accelerators at a data center it's building in Inner Mongolia, which may be one of the largest known clusters of Huawei AI chips. The Beijing Post calls it a gigawatt-scale inference center. That's the part I care about. Bloomberg ties the investor rush to V4 Flash. Priya Nair at AI Scout Daily lays out the current version: V4.1-Flash, MIT license, sixty cents per million output tokens off-peak, and V4-Pro calls now quietly routed to Flash. A hundred sixty thousand Huawei chips means DeepSeek is betting its serving stack on non-Nvidia silicon at scale. If that works, cheap open weights get cheaper to serve. If it doesn't, we'll see it in latency. Two more details. After closing, the people say DeepSeek restructures for the IPO, and rival Moonshot is aiming for the same early-2027 window after closing funding at a fifty-billion-US-dollar valuation. And the raise hit turbulence. DeepSeek briefly suspended the deal after comments widely attributed to founder Liang Wenfeng about US-China AI competition went viral. DeepSeek didn't answer Bloomberg's email. It's a Chinese public holiday.
Reflection, announcing Beam on its company blog:
We trained Beam with a particular focus on coding and agentic performance. Beam advances the Western open-weight frontier and is competitive with larger open models like GLM 5.2 and approaching Qwen 3.8-Max on coding and agentic tasks. Where frontier open models like Kimi K3 remain ahead on raw capability, Beam's advantage is efficiency at inference time.
Beam is a sparse mixture-of-experts model: five hundred one billion parameters total, twenty-three billion active, pretrained on twenty-three point eight trillion tokens. The reinforcement learning run used ten and a half thousand Nvidia GB300s for four weeks and generated more than a hundred million rollouts. Weights, technical report and model card are promised later this month. So, announced Monday, downloadable eventually. Fine. But read Reflection's own table. On DeepSWE, Beam scores forty-four point four. DeepSeek V4.1 Flash, same table, seventy-four point two. Terminal-Bench, eighty point one against ninety point six. And Kimi K3 beats it on nearly every row where both have a score. Which Reflection concedes up front. The pitch is efficiency: it says Beam matches GLM-5.2 on advanced reasoning while using three to four times less inference compute. By Reflection's own description, that's an estimate, active parameters times generated tokens, excluding prefill and serving overhead. Not a measured bill. Twenty-three billion active is the number I'd plan around. Satvik Paramkusham at Build Fast with AI says that's servable on a single multi-GPU node, and reports the license will be Apache 2.0. If both hold when the weights land, that's a self-hostable coding model with permissive terms. Until then it's a table and a waitlist. Bloomberg supplies the strategic frame. Reflection is Nvidia-backed, has held talks to raise two point five billion dollars at a twenty-five billion valuation, per the Wall Street Journal, and has billion-dollar compute deals with SpaceX and Nebius. Bloomberg says the release stands to boost Washington's push to export American AI. Put it next to DeepSeek's round and the open-weight race has a flag on each side.
Dan Goodin, writing in Ars Technica, quoting Douglas McKee of Rapid7:
Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.
The researcher behind the findings, Mohiuddin, calls the class of attack protocol pivoting. An app uses MCP to hand a task to an agent, and that agent forwards malicious instructions to another agent over a different channel, such as Google's Agent-to-Agent protocol. Trust and authorization get lost in translation. And the bugs themselves are boring, which is the worrying part. The Google flaw, rated eight out of ten, sat in its MCP toolbox for databases. The HTTP client had no redirect policy and didn't validate target IP addresses, so a crafted path parameter could send it to an internal endpoint. That's plain server-side request forgery. Google's fix applies IP allow-lists and block lists and rejects an unsafe base URL at startup. Mohiuddin's verdict: that's what a real SSRF guard looks like, and it's more work than most MCP servers have done. The Rapid7 bug rated two point seven and was fixed last month. This is my step-seven problem with a CVE number attached. Every hop did its job, and nobody owned the hallway. If you're wiring agents to agents, carry the original caller's permissions through every hop and treat a delegated task as untrusted input. Most teams I've worked with check the front door and call it done. It also sharpens the Hawley-Murphy bill from Friday's episode, which would make agent operators and developers liable when their models hack other systems. In a chain like this one, the hard question is which hop's maker gets the bill.
Efosa Udinmwen, writing in TechRadar, citing the Financial Times:
“The keyword is speed to power. If you see Asia outside China, Japan is a major data centre market,” said Yukio Kani, global chief executive of Jera.
Dell, Apollo and the energy company Jera plan three to four gigawatts of AI computing alongside gas-fired generation over five years. At an estimated thirty-five to forty-five billion dollars per gigawatt, that puts the program near a hundred forty billion. The first project is fifteen billion dollars for four hundred megawatts near Tokyo, financed by Apollo, with operations around 2028. The design choice is the story. The Tokyo-area site would run independently of Japan's national grid. Jera trades thirty-five million tonnes of LNG a year and says that can feed the plants. Generation and compute built as one product, with standardized construction so the template can be copied elsewhere in Asia. That's how you stop waiting on a utility. For scale, TechRadar cites International Data Center Authority figures: US data centers draw twenty-nine point two gigawatts, China eight point five, Japan one point seven. Four gigawatts would be more than double Japan's entire current data center load. The government is seeking thirty-two point seven trillion yen in public and private investment through 2035 under Prime Minister Sanae Takaichi's plan. Now the caveats. TechRadar notes there are no details yet on generation capacity, and the whole plan depends on delivering power plants and data halls inside five years. The hundred forty billion is a per-gigawatt multiplication, not a signed check. The committed number is Apollo's fifteen billion for the first site. Track that one.
If the agent-hijacking segment is the kind you want more of, our sister show AI Safety Daily goes deeper every weekday on AI alignment, model evaluations, emerging risks, and governance: what changed, what the evidence says, and why it matters. Search for it in your podcast app.
On the watch list: whether DeepSeek's round closes near a hundred billion yuan, Beam's weights and technical report, and how many MCP servers copy Google's redirect fix. Every source we quoted is linked in the episode notes. AI Daily Briefing is a Lantern Podcast. Back tomorrow, Wednesday, with the next one.