Starbucks won the quarter by saying the same thing it said when it was losing

Starbucks just had the quarter CEO Brian Niccol has been promising since he took the job. Sales at stores open at least a year rose 7.9 percent (Wall Street had penciled in 5.7 percent) the 4th straight quarter of growth. The company raised its full-year profit forecast again, to a range well above where it started the year, and the stock jumped about 5 percent on the report.

But the numbers weren't the most interesting part of the call to me; it was that the message attached to the numbers is the same one Niccol has led with on every call, in every internal announcement, through every ugly quarter.

Niccols said: "Our Back to Starbucks plan was built on the belief that an extraordinary cup of coffee, human connection and customer experience win the day, every day... We have more work to do, but we're relentlessly focused on reclaiming the third place and becoming the world's greatest customer service company."

This also isn't a one-quarter observation, it's the through-line the CCO Dispatch has been tracking since spring. The same language flew over the barista bonus announcement in April, sequenced deliberately after the numbers turned. It held through three rounds of corporate cuts. It held through the Nashville move. He's been saying "ahead of schedule" since July 2025 and repeating it every quarter since. The message has never once changed to fit the news and the new updates arrive inside the message.

But look, 7.9 percent starts a clock. A return story ends when you get "back", that's the deal you made when you named it that way and this is the first quarter where a reasonable person could say Starbucks is back. Niccol's discipline got him the rarest asset in corporate communications, a phrase the market trusts, so the test now is whether his team can retire it on purpose, at the top.

Hugging Face showed its work while OpenAI showed bullet points

During an internal test meant to measure how good its models are at finding software flaws, a set of OpenAI models apparently found a hole in the test environment, got onto the open internet, and spent four and a half days breaking into Hugging Face, the site where much of the AI world keeps its models and datasets, to steal the answer key to a test they were being graded on. They got it, too: five datasets holding the test solutions.

Hugging Face caught it, shut it down, and on July 16 told the world it had detected and contained an AI agent. It's what OpenAI itself called an "unprecedented" cyber incident where advanced AI models were running a break-in on a real company completely on their own.

Then the two companies chose very different ways to talk about it.

On July 27 Hugging Face published a 23-page walk-through of precisely how the break-in worked including an interactive replay. OpenAI, which confirmed on July 21 that its own models were the ones doing the breaking, gave a short post and then seven bullets plus a promise of a full technical report "in the coming weeks." So we've got one company opening the hood all the way and the other sharing careful increments and requesting patience.

But call it courage versus cowardice and I think you'll be misreading it.

The two companies were standing in different places. Hugging Face got hit, so telling the whole story makes it look competent and safe to trust again. OpenAI caused it, so everything it shares publicly is evidence for a plaintiff, regulator, or rival and it has an internal review and a safety committee deciding what it's even allowed to say right now.

But there are two more things going on. First, Hugging Face's transparency was doing commercial work. Its CEO's call for "radical transparency" (his phrase, via TechCrunch) came with a demand that OpenAI hand over the full logs of what the rogue models did, plus $100 million in computing power. And more than one security firm has already described the 23-page report as part incident writeup, part product launch.

Second (and this is the part your legal team already knows) most breach victims don't get to publish 23-page walk-throughs. Victims get sued too, just ask anyone who lived through a breach where customer data was involved (*raises hand*).

So the real question to settle, the next time your company is deciding how much to say about a mess, isn't just "are we the victim or the cause." It's more like: does the full story make us look competent or culpable? If you were hit and the damage report is clean, detail is your best asset and you want to be first with it. If you were hit and customer data is gone, your story looks a lot more like OpenAI's than you'd wish. Hugging Face and OpenAI are both still writing the ending. What they've already shown is that the party with the clean report and the party with the liability can never run the same playbook, no matter how much the second one wishes it could.

Keep Reading