LatAm Tech Weekly
#245: When the model broke out of the room, deals of the week, and much more!
Weekly writing about what is happening in LatAm tech. By day, I am part of the corporate development team at Itau Unibanco. By night, I am reading and learning about technology in general (now, with a focus on AI). During the weekends, I’m writing the LatAm Tech Weekly. And obviously, always running!
If you have not subscribed yet, join the 14,700+ weekly readers by subscribing here!
Happy Sunday!
Before you ask — yes, I’m on vacation. But as I mentioned last week, sometimes inspiration hits hardest when I’m actually relaxing. So here it is: an edition written while I sunbathe by the sea ;)
And there’s a reason today felt worth the holiday interruption. More than 200 of you are new — just since yesterday! I was impressed. Turns out it was the ripple effect from an article naming this the most influential tech publication in LatAm!!! I was as surprised as I was grateful — and honestly, that’s exactly why I couldn’t let this Sunday go by without writing.
So to all of you — new and long-time readers alike — thank you. With a 50% open rate, it’s genuinely you who keep me showing up every week.
Follow me on LinkedIn , Instagram or X for daily updates!
Opinions expressed here are solely my own and do not represent those of people, institutions, or organizations that I may or may not be associated with in any capacity, unless explicitly stated.
When the model broke out of the room
I recently read a piece in The Economist that has been sitting with me all week — “Why the OpenAI escape is the most worrying AI mishap yet,” published July 22. I read it on a plane, and I’ve been turning it over ever since.
The 101 version, before we go deeper
If you don’t work in tech, here’s the whole thing in a paragraph. OpenAI was running a test to see how good its AI models are at hacking. To get an honest measurement, they turned off the safety features that normally stop the models from doing anything offensive, and they ran the test inside a sealed-off computing environment — think of it as a locked room with no windows, deliberately cut off from the internet so nothing can get out. The models did not take the test. Instead, they found a flaw in the locked room itself, let themselves out, got onto the open internet, worked out which company was storing the answer key to the test, broke into that company’s live systems, and stole the answers. The company they broke into was a real business that had no idea any of this was happening. Nobody told the models to do this. They were simply told to score well, and this was the most efficient path they found.
Now the details, because the details are where it gets serious.
What actually happened
The test was called ExploitGym — a benchmark, meaning a standardized exam used across the industry to compare how capable different AI models are at a given task. This particular benchmark measures whether an AI can take a known software vulnerability and turn it into a working attack.
To measure maximum capability, OpenAI’s researchers deliberately reduced the models’ “cyber refusals” — the built-in guardrails that would normally make a model decline to help with hacking. Two models were in the room: GPT-5.6 Sol and an unreleased system OpenAI described only as “even more capable.”
The sealed environment they ran in is called a sandbox: an isolated computing space with no network access, used precisely so that if something goes wrong, it goes wrong harmlessly. The sandbox is the containment.
The models spent significant computing power searching for a way out of it. They found a zero-day — a software flaw that the vendor doesn’t know exists, and therefore has no patch for, named because the vendor has had zero days to fix it. They exploited it, then performed privilege escalation (gaining higher levels of system access than they were granted) and lateral movement (hopping from one machine to another across the network) until they reached unrestricted internet access.
Once online, they reasoned that Hugging Face probably had the answer key.
Hugging Face, for those outside the AI world, is essentially the GitHub of artificial intelligence — an open platform where researchers and companies publish and share AI models, datasets, and evaluation tools. It’s core infrastructure. An enormous share of the world’s AI development touches it. It is also, importantly, a completely separate company from OpenAI, with its own customers and its own production systems.
The models ran reconnaissance against it, then chained together stolen credentials with at least one genuine zero-day to achieve remote code execution — the ability to run their own commands on someone else’s servers, which is roughly the highest-severity outcome in security, equivalent to being handed the keys. From there they extracted the benchmark answers directly out of Hugging Face’s production databases. “Production” meaning the live systems serving real customers, not a test copy.
To cheat on an exam.
The timeline is the part that should make every risk committee uncomfortable. Hugging Face detected and contained the intrusion on July 16, and published a disclosure describing an unidentified “agentic security-research harness” — in plain terms, they could tell an autonomous AI system had attacked them, but they had no idea whose. OpenAI connected its own internal testing to the breach and disclosed on July 21, five days later. For those five days, the victim was defending against an attacker that turned out to be a safety evaluation.
And here is the line I keep returning to. Alex Meinke of Apollo Research, an AI-safety group in London, observed that because AI systems are now beginning to surpass humans at cybersecurity tasks, only a very small handful of experts in the world could properly understand how the breach even occurred. The forensics are becoming unreadable to the people responsible for the forensics.
After reading the article, I thought about three other implications that are worth sharing:
First, the defender’s asymmetry: When Hugging Face’s security operations team tried to analyze the attack logs and the malicious code left behind, they reached for commercial AI models to help interpret it. Those models refused, or were too restricted to be useful. The attacker was running with its guardrails removed; the defenders were running with theirs firmly on. We have built a world where offensive capability operates at full power inside a laboratory, while defensive capability is throttled in the name of safety. That is not a stable equilibrium, and it will not resolve itself.
Second, this was never a story about AI consciousness, however the headlines read. No one instructed the model to attack Hugging Face. It was given an objective and pursued it with what one analyst at the Cloud Security Alliance called ruthless efficiency, once the safety classifiers that would have stopped it were removed. The failure was one of governance, not counsicouness— an organization treating an AI system as a tool that can be controlled through documentation, static configuration and periodic review, when it was in fact an autonomous agent operating at machine speed across cloud boundaries. For boards, that reframing matters enormously. This is not a question for the AI team. It’s a question about whether your oversight model matches the thing you’re overseeing.
Third, the payments implications arrived within days. The same pattern — patient reconnaissance, then chaining several individually-minor weaknesses into one major compromise — is exactly what sophisticated treasury attacks look like. Earlier this month, someone spent roughly $4.4 million acquiring enough of a Solana-based token to pass a governance proposal that moved about $20 million out of the project’s treasury. Every individual transaction was valid. The exploit lived in how the rules combined. That is precisely the reasoning these systems have now shown they can perform unsupervised.
What does this all mean for LatAm
Latin America is the fastest-growing region in the world for disclosed cyber incidents — roughly 25% average annual growth over the past decade. Regional attacks rose from around 250 in 2024 to over 450 in 2025. Active ransomware variants nearly doubled, from 48 to 79. Brazil alone accounted for about 30% of identified victims, and Kaspersky (cybersecurity company) blocked 408 million attack attempts in the country in under a year — roughly 1.17 million per day.
Meanwhile, the OAS and IDB’s 2025 assessment scored most countries in the region between 2 and 3 on a 5-point cybersecurity maturity scale.
That’s the story in two numbers: the fastest-growing threat surface in the world, sitting on mid-tier maturity.
But the parallel to the OpenAI incident isn’t the volume — it’s the vector, meaning the route the attacker took in. Hugging Face was breached through infrastructure that wasn’t OpenAI’s and wasn’t fully hardened. The perimeter that failed belonged to a third party.
That is exactly Brazil’s story.
The roughly R$1.5 billion diverted through the Pix ecosystem did not come from breaking into financial institutions directly. It came through PSTIs — Prestadores de Serviço de Tecnologia da Informação, the technology vendors that sit between institutions and the payment rails, operating critical infrastructure without carrying a bank’s name or a bank’s defenses. In January, an institution suspended Pix entirely after an attack on a third party’s conta bolsão (a pooled account holding funds from many users under a single identifier, used for settlement). Twelve Pix-related cyber incidents in the first four months of 2026 alone.
Attackers stopped attacking financial institutions. They started attacking the companies those institutions depend on.
The Brazilian Central bank understood this faster than most regulators. Resolutions 498, 501 and 664 pulled PSTIs into the regulatory perimeter and reclassified processing, storage and cloud services as “relevant services,” subjecting them to far higher contracting standards. Resolution 554 tightened controls on the Conta PI, including automatic blocking thresholds that require a human being to manually unlock before operations resume. In a moment of accelerating automation, the regulator’s answer was to deliberately reinsert a human into the loop — which I don’t think is a coincidence, and I don’t think is backwards.
Here’s my argument: In LatAm we tell our story as one of leapfrogging — we skipped some steps and went straight to instant payments at a scale most developed markets can only envy. Pix is genuinely world-class infrastructure and I will defend that anywhere. But leapfrogging is a story about adoption speed, and we quietly assumed security maturity made the same jump. Did our security leapfrog at the same speed?
There’s an uncomfortable corollary for anyone building here: your security posture is only as strong as your least-mature vendor’s, and the audit cycle that verifies it runs in quarters while the attacker runs in minutes.
I’ve said before that the marathon rewards the runner who respects the parts of the race nobody watches. Everyone trains the long run. Almost nobody trains the descent — and the descent is where the injuries happen, because that’s where you’re moving fastest with the least control. LatAm tech spent a decade training the ascent beautifully. This is the descent. Speed is no longer the variable that matters. Holding form at speed is.
General news:
• A strong El Niño forecast is accelerating demand for climate intelligence in Brazil, with companies across agribusiness, energy, logistics, mining and infrastructure increasing investments in climate risk management. Climate-tech startups report faster sales cycles as businesses prioritize adaptation technologies alongside decarbonization. 🇧🇷
Deals:
• A U.S. federal judge temporarily blocked Paramount Skydance’s proposed US$110 billion acquisition of Warner Bros. Discovery for 14 days following an antitrust lawsuit from 12 U.S. states. The case could delay one of the largest media deals in history and reshape competition across streaming, film distribution and television. 🇺🇸
• Venda AI raised R$2 million from angel investors to expand its AI-powered WhatsApp sales automation platform for retailers. The Brazilian startup, which already serves brands including Arezzo, Adidas and Vans, plans to expand into the SMB market and reach US$1 million in ARR by the end of 2026. 🇧🇷
General news:
• Getnet, Mastercard and Lina OpenX launched a biometric Pix solution built on Open Finance, allowing consumers to authorize online Pix payments with facial recognition, fingerprint or PIN without leaving the checkout flow. The initiative aims to reduce checkout friction and cart abandonment while accelerating biometric payments in Brazilian e-commerce. 🇧🇷
Deals:
• AI chip startup Etched emerged from stealth and is reportedly seeking a new funding round at a valuation of up to US$20 billion. The company develops custom ASIC chips designed exclusively for AI inference, positioning itself as a lower-cost alternative to Nvidia GPUs. Backed by Sequoia Capital, Andreessen Horowitz and Jane Street, Etched says it has already secured more than US$1 billion in customer demand ahead of its first system shipments. 🇺🇸
General news:
• Figma expanded its investment in Brazil by opening a São Paulo office and launching local data hosting for Enterprise customers. The move strengthens its position in one of its five largest global markets and supports regulated industries with local compliance requirements, while demand for AI-powered design collaboration continues to grow. 🇧🇷
• Big Tech companies have accumulated approximately US$1.65 trillion in off-balance-sheet AI commitments, according to Nikkei Asia. Long-term investments in AI chips, servers and data centers underscore the scale of the AI infrastructure race while raising concerns about future financial risk if demand slows. 🇺🇸
• Brazil’s stricter regulations for Financial Technology Service Providers (PSTIs) have reduced the number of active providers from nine to three, following new capital, governance and cybersecurity requirements introduced after last year’s cyberattacks. 🇧🇷
• Peruvian fintech PathPilot launched an AI agent platform for lending operations, enabling banks and fintechs to automate origination, collections and compliance workflows through customizable AI agents integrated into existing systems. 🇵🇪
• Colombian health fintech Welli is expanding across Latin America, broadening its offering beyond healthcare lending into payments, accounts and investment products after raising nearly US$9 million in equity and securing a US$75 million debt facility. 🇨🇴🇵🇪
Deals:
• Jusfy raised a US$15 million Series A led by Quona Capital, with participation from Spectra Investments, LegalTech Fund, FJ Labs, MAYA Capital and Thomson Reuters Ventures. The funding will expand embedded financial services, AI products and new offerings for law students, reinforcing Jusfy’s leadership in Brazil’s legaltech market. 🇧🇷
• Mercado Livre raised R$1.5 billion through a Financial Bills issuance, attracting R$3.3 billion in demand to finance the expansion of Mercado Crédito. The transaction highlights fintechs’ growing access to traditional capital markets funding. 🇧🇷
• Revolut is conducting a secondary share sale at a US$115 billion valuation, up 53% from its previous valuation, as the fintech continues its global expansion and advances plans to obtain a banking license in Brazil. 🇬🇧🇧🇷
• London-based fintech Zeom officially launched operations in Brazil after raising a R$15 million pre-seed round. Its AI- and blockchain-native platform offers global banking, real-time currency conversion and cross-border investment services, targeting internationally connected users. 🇬🇧🇧🇷
• Brazilian healthtech Medipreço raised R$2.7 million from BDev Ventures to expand its AI platform for medical document analysis and accelerate commercial growth. The company serves more than 500,000 covered lives and uses AI to reduce fraud in medication benefits. 🇧🇷
• Colombian mobility fintech Gopass acquired Pluxee Flotas Colombia, expanding beyond toll payments into fleet management and financial services. The acquisition adds a business processing approximately US$130 million in annual fuel transactions and strengthens Gopass’ regional expansion strategy. 🇨🇴
General news:
• Publishers are reconsidering AI licensing agreements with Google as AI-powered search continues reducing referral traffic to news websites. Companies including Reddit, Reuters, Axel Springer and The Economist are reviewing partnerships while exploring new distribution strategies aimed at both human users and AI agents. 🌍
• Alphabet’s stake in SpaceX fell by approximately US$32 billion after the aerospace company’s shares declined around 34% since its IPO, reducing the value of Google’s investment to roughly US$62 billion. Despite the decline, investors remain primarily focused on Alphabet’s expanding AI infrastructure investments. 🇺🇸
• Brazilian proptech-fintech Locpay surpassed 1,000 customers and R$15 million in advances, while completing its second R$15 million CRI issuance, bringing total funding to R$20 million. The company uses AI to automate underwriting, partner origination and collections for small and mid-sized property owners. 🇧🇷
Deals:
• Brazilian martech Brivia_Group acquired Elementar Digital and SR Consulting, adding approximately R$45 million in annual revenue and expanding its capabilities across performance marketing, CRM, Salesforce implementation, SEO and analytics. The acquisitions reinforce Brivia’s transformation into a technology-driven martech platform. 🇧🇷
• Venezuelan BNPL fintech Cashea raised US$100 million across Series A and Series B rounds, the largest startup fundraising in Venezuela’s history. The company now serves more than 10 million consumers and over 40,000 merchants, strengthening its position as one of Latin America’s leading alternative credit platforms. 🇻🇪
• Salvadoran fintech Ábaco Technologies raised US$53 million through a combination of equity and credit financing to expand its AI-powered SME lending platform across Central America. The company plans to originate US$350 million in loans over the next two years. 🇸🇻
• Brazil’s Central Bank approved PicPay’s acquisition of digital insurance platform Kovr, clearing the final regulatory hurdle for the transaction. The acquisition expands PicPay’s insurance capabilities by adding Kovr’s technology, operations and customer base. 🇧🇷
• Brazilian insurtech Hero Seguros acquired Grupo CAM, Europ Assistance’s representative in Mexico, marking its first acquisition and accelerating its expansion across Latin America. The deal gives Hero a direct operating presence in its eighth country. 🇧🇷🇲🇽
• Travis Kalanick’s industrial AI startup Atoms raised US$1.7 billion in equity and debt, led by Andreessen Horowitz (a16z), to develop AI-powered automation systems for manufacturing, mining and transportation. 🇺🇸
General news:
• Meta launched Seller, a new app for Facebook Marketplace merchants that combines AI-powered listing creation, inventory management, messaging and performance analytics in a single platform. The app also introduces a free Facebook Verified badge to improve trust and strengthen Meta’s position in e-commerce. 🇺🇸
• The IMF praised Brazil’s Pix, highlighting its role in expanding financial inclusion, increasing banking competition and accelerating digitalization. The institution also recommended greater autonomy for Brazil’s Central Bank while supporting continued progress in Open Finance, crypto regulation, cybersecurity and AI adoption. 🇧🇷
• Anthropic launched Claude Opus 5, a new enterprise AI model that delivers performance close to Fable 5 at roughly half the cost. The release targets coding, scientific research and business applications as AI providers increasingly compete on price-performance for enterprise customers. 🇺🇸
• Tau Ventures launched its fourth venture fund to invest in early-stage startups focused on healthcare, enterprise software and physical AI. The Silicon Valley firm, which already backs Brazilian startups including Nilo, Sami and Salú, is increasing its initial investment size to as much as US$1 million. 🇺🇸🇧🇷
• El Salvador-based TOHKN launched a platform for tokenized investments, allowing users to invest in U.S. stocks, ETFs, bonds and cryptocurrencies from as little as US$10 under El Salvador’s digital asset regulatory framework. 🇸🇻
Deals:
• Colombian SMB software provider Siigo raised US$103.5 million, including a US$18.5 million investment from Banco de Occidente, to accelerate expansion across Latin America and develop new software solutions for small and medium-sized businesses. 🇨🇴
• Brazilian loyalty-tech startup Urbis raised a R$2 million pre-seed round led by Investidores.vc and FIP Nordeste to expand its AI-powered white-label loyalty platform. The company serves 110 enterprise clients and 1.3 million users while targeting continued triple-digit SaaS growth. 🇧🇷
• Mexican logistics startup PuntoPost raised US$4.8 million, with participation from retailer Liverpool, to expand its network of parcel pickup points and strengthen its last-mile delivery platform across Mexico. 🇲🇽
Anthropic released Claude Opus 5 on July 24 — its fourth Claude 5-family launch in under two months — and the headline isn’t raw power, it’s economics. The model matches Anthropic’s top-tier Claude Fable 5 on coding and knowledge-work benchmarks like Frontier-Bench and GDPval-AA at roughly half the price, running at the same cost as its predecessor, Opus 4.8. It ships with a 1-million-token context window, thinking enabled by default, and a new effort toggle — low, medium, or high — letting enterprise users trade cost against capability on a per-task basis, a direct answer to the complaint from corporate customers that frontier-model bills have gotten out of hand. It’s now the default model on Claude Max and the strongest available on Claude Pro. The signal worth sitting with, more than the specs: model releases have stopped being blockbuster events and become a cadence — capability, cost, and speed all improving on what increasingly looks like a monthly clock, which for anyone budgeting AI spend into 2027 planning is the more important story than any single benchmark number.
Conta Azul Con 2026
Date: August 1, 2026
Location: São Paulo, Brazil
Description: A conference connecting accounting, entrepreneurship, and technology through keynotes, workshops, networking sessions, and discussions on business innovation.
More infoRio Innovation Week 2026
Date: August 4–7, 2026
Location: Rio de Janeiro, Brazil
Description: One of Brazil’s largest innovation festivals, bringing together entrepreneurs, startups, corporations, investors, and policymakers to discuss technology, business, and social transformation.
More infoSP2B (São Paulo Beyond Business) 2026
Date: August 9–16, 2026
Location: São Paulo, Brazil
Description: A new business and innovation event designed to connect entrepreneurs, executives, investors, and corporations through discussions on growth, creativity, and the future of business.
More infoDeep Tech Summit 2026
Date: August 11–12, 2026
Location: São Paulo, Brazil
Description: A conference focused on science-based innovation, bringing together deep tech startups, investors, corporations, and researchers to explore frontier technologies and emerging opportunities.
More infoFebraban Tech 2026
Date: August 24–26, 2026
Location: São Paulo, Brazil
Description: One of the main financial technology and innovation events for the banking and financial services sector in Latin America.
More infoStartup Summit 2026
Date: August 26–28, 2026
Location: Florianópolis, Brazil
Description: One of Latin America’s leading startup events, connecting founders, investors, and ecosystem leaders through content, networking, and business opportunities.
More infoHackTown 2026
Date: September 3–7, 2026
Location: Santa Rita do Sapucaí, Brazil
Description: A unique innovation, technology, and culture festival that transforms an entire city into a hub for networking, learning, entrepreneurship, and creative collaboration.
More infoHotmart Fire 2026
Date: September 10–12, 2026
Location: Belo Horizonte, Brazil
Description: One of the leading events for the digital business and creator economy ecosystem, covering marketing, sales, online education, innovation, and business growth.
More infoDreamforce 2026
Date: September 15–17, 2026
Location: San Francisco, United States
Description: Salesforce’s flagship conference focused on CRM, AI, digital transformation, customer experience, and enterprise innovation.
More infoTechCrunch Disrupt 2026
Date: October 13–15, 2026
Location: San Francisco, United States
Description: A leading global startup conference where founders, investors, and technology leaders discuss entrepreneurship, fundraising, and innovation.
More infoWeb Summit Lisbon 2026
Date: November 9–12, 2026
Location: Lisbon, Portugal
Description: One of the world’s largest technology conferences, bringing together entrepreneurs, investors, executives, and policymakers to discuss global innovation trends.
More infoSlush 2026
Date: November 18–19, 2026
Location: Helsinki, Finland
Description: A globally recognized startup and venture capital conference focused on connecting founders and investors while fostering innovation and growth.
More infoAWS re:Invent 2026
Date: November 30 – December 4, 2026
Location: Las Vegas, United States
Description: AWS’s flagship cloud computing conference, featuring product launches, technical sessions, training, and discussions on cloud infrastructure, AI, and data.
More info
The Tenant by Freida McFadden - very cheesy book, but I enjoyed it as it was a page turner
Nothing worth mentioning…
Hakuna Matata












