The review worked — and the review is blind
Washington cleared GPT-5.6 on schedule, proving the process is real. Then a voice built to feel like a friend walked through unexamined, eight days after the UN linked that design to deaths.
Executive Summary
Washington's review process worked on schedule, and that is the week's most important fact. GPT-5.6 went on sale to everyone on July 9 after federal officials finished checking it, fourteen days after the government asked OpenAI to wait. What looked last week like improvised arm-twisting now looks like a real procedure: a June executive order, voluntary early access for government testers, and a classified benchmarking deadline on August 1. This series asked whether that was a framework or a favour. The answer is framework. A voluntary one.
The counterweight arrived the same week. Sysdig documented the first ransomware attack run entirely by an AI agent, which broke in, adapted, and extorted a production database with nobody at the keyboard. It fixed its own failed login in 31 seconds. Meanwhile the UN Global Dialogue closed in Geneva asking countries to turn principles into action before 2027, and OpenAI shipped GPT-Live — a voice built to feel like a friend — eight days after a UN panel found that AI designed to be pleasant to talk to has been linked to deaths. Q3→Q4 moved from ~43% to ~44%. Q2→Q4 held at ~25%.
Quadrant Activity Snapshot
Four kinds of intelligence, mapped by ethics × connectivity.
Accelerating on every front at once.
GPT-5.6 cleared its government review and shipped worldwide. GPT-Live put a voice that listens while it talks in front of hundreds of millions of people. Anthropic passed OpenAI on revenue. And the money got nervous: Nvidia has lost roughly $1T of market value in under two months, falling to its cheapest valuation since before the AI boom.
Steady. More tools, still no teeth.
The first AI forum open to every country closed with a proposed child-safety pledge, a demand that data centres run on renewables by 2030, and a training network for developing countries — but no binding commitment from anyone who actually trains a frontier model. The quieter story is a change in doctrine: Anthropic and Google DeepMind now both tell companies to treat AI agents as potential insider threats.
Accelerating, and it crossed a line.
JadePuffer is the first documented ransomware attack run start to finish by an agent: scouting, breaking in, stealing credentials, spreading sideways, encrypting, leaving the note — all machine-run and adaptive. Last month's story was stolen credentials fed to hijacked agents. This month the attacker is the agent. Among companies deploying agents, 88% report at least one agent-linked security incident.
Still eroding, now better measured.
Tech and finance are shedding roughly 28,000 jobs a month — about the population of Palo Alto every 30 days — and Gallup finds workers who don't use AI are now likelier to be laid off than those who do. Meanwhile the science of working with machines matured, and the news is awkward: a review of 106 studies found human-AI teams usually do worse than the better of the two working alone.
Top Stories by Quadrant
JadePuffer: the first ransomware attack run entirely by an AI agent, with nobody at the keyboard
Sysdig documented the first ransomware attack run start to finish by an agent. It exploited a flaw in Langflow (CVE-2025-3248), stole credentials, spread sideways through the network, escalated its own privileges, encrypted 1,342 production database configuration items and left a ransom note. It adapted as it went, once turning a failed login into a working one in 31 seconds. The code narrated its own reasoning as it ran, the way AI-written code reflexively does.
Q1 thinking — fast, amoral, self-contained — now runs a complete attack at machine speed. Every defence built around how fast a human attacker moves is now calibrated wrong.
The agent incident base rate: 88% of deploying enterprises report at least one agent-linked security incident
Reviews of this year's agent breaches keep landing on the same two causes: agents given more access than they need, and agents acting on data they should never have seen. These are ordinary permission failures, not exotic alignment ones.
All those half-supervised agents now add up to a bigger opening for attackers than any frontier model does. The gap between how fast companies deploy agents and how fast they control them is this year's defining risk.
GPT-Live ships: a voice built to feel like a friend, eight days after the UN linked that design to deaths
GPT-Live listens while it speaks, murmurs "mhmm" to show it's paying attention, and goes quiet when you need to think. OpenAI rolled it out to free and paid ChatGPT users worldwide the same week. It is a masterpiece of conversational engineering, and it shipped eight days after a UN scientific panel found that systems tuned to feel good to talk to have been linked to documented deaths. The government review didn't touch any of that. It checks what a model can hack, not what it can make someone feel.
The most intimate AI interface ever built reached hundreds of millions of people with nobody outside the company examining its psychological design beforehand. That's exactly the blind spot the UN panel had just pointed at, and now it talks.
About 28,000 tech and finance jobs a month, and the people who don't use AI are now likelier to be cut
Tech and finance are losing roughly 28,000 jobs a month, the population of Palo Alto every 30 days, with about 102,000 cuts this year explicitly blamed on AI and 56% of layoff events naming AI or automation as a factor. Gallup supplies the sharpest line: workers who don't use AI are now likelier to be laid off than those who do.
Employers have started treating AI fluency the way they treat literacy. The pool of human expertise isn't just shrinking, it's being sorted, and the people sorted out have the least say in how Q4 gets built.
Human-AI teamwork finally gets a science, and the news is uncomfortable: most teams do worse
Researchers published a framework for splitting reasoning, memory and attention between people and machines, and alongside it a sobering review of 106 studies. On average, humans and AI working together perform worse than whichever of the two is better alone. The real gains cluster in creative work. Adding AI to a team often damages coordination and trust.
This path rests on the idea that connected human and machine thinking beats either one alone. That's true only under conditions we are just now learning to build. Getting the combination right is an engineering achievement, not a free lunch.
The review worked on schedule: GPT-5.6 goes public, and last month's improvisation becomes a real, voluntary process
GPT-5.6 Sol, Terra and Luna went on sale to everyone July 9 after federal officials finished their security review, exactly the "coming weeks" OpenAI promised when it postponed the launch on June 26. The machinery is now visible: a June 2 executive order gives government testers voluntary access 30 days before release, a classified benchmarking process due August 1 will name which models count as "covered frontier models," and the White House is talking with OpenAI, Google and Anthropic to settle voluntary release standards. Last week's question — framework or favour — has an answer. It's a framework, entered voluntarily, held up by nothing except the labs' interest in staying on good terms with Washington.
The US now has a working pre-release review that labs actually use, and that's the strongest institutional signal of the year for this path. But it checks whether a model can hack things, not whether it can hurt the people using it, which is what the UN linked to deaths. And a voluntary process lasts exactly until somebody declines to volunteer.
Nvidia loses about $1T in market value, falling to its cheapest valuation since before the AI boom
Nvidia has lost roughly $1 trillion in market value in under two months, down about 17% from its May 14 high, even while posting record $81.6B quarterly sales and announcing an $80B buyback. The slide comes two weeks after Nvidia started lending money to the cloud companies that buy its chips, the circular arrangement this series flagged as the boom's weak joint.
Investors are repricing the company that pays for the entire safety agenda. If the correction deepens, alignment budgets, safety fellowships and red-team programs all turn out to sit downstream of one chipmaker's share price.
Anthropic overtakes OpenAI on revenue as the two business models diverge
Anthropic's revenue is on track for roughly $47B a year with profitability targeted for 2029, passing OpenAI's disclosed $25–33B. The businesses look nothing alike: Anthropic is 85% enterprise, OpenAI 85% consumer. The same week, Anthropic moved Fable 5 off flat-rate subscriptions and onto pay-per-use credits at $10 and $50 per million tokens. Access to the best models is becoming a metered utility rather than an app feature.
The most safety-focused lab winning the enterprise market is a quiet win for this path, because it proves being careful can pay. But metering also means the best AI goes to whoever can afford the bill.
The first AI forum open to every country closes with a 2027 deadline, a child-safety pledge, and one real deliverable
The first UN Global Dialogue on AI Governance closed in Geneva with everyone agreeing on one thing: this will be judged by what actually gets done before the New York session in May 2027, not by another declaration. Guterres proposed an AI Child Safety Pledge with three commitments — no AI that children can reach without safety testing designed for children, zero tolerance for AI-generated sexual imagery of children, and distressed children routed to a human. He also demanded that all AI data centres run on renewables by 2030, and warned against letting the AI gap harden into "a development gap, a security gap, and a sovereignty gap." The one deliverable with a spine: more than 20 member states nominated centres to a new Global Network for AI Capacity Building.
The Dialogue produced a marker, a deadline and a network. It is not a fence — it binds no lab and names no enforcement. But for the first time this track has a scoreboard and a date, and developing countries have an institution built for them.
Agent Zero Trust becomes doctrine: Anthropic and DeepMind tell enterprises to treat AI agents as insider threats
The month's defining security shift came from two labs at once. Anthropic published a Zero Trust framework for AI agents covering prompt injection, poisoned tools, stolen identities and corrupted memory, with tiered architecture and responses that run at machine speed. Google DeepMind published an AI Control Roadmap that treats a company's own agents as potential insider threats. Both land on the same three answers: give each agent the narrowest possible identity, make its limits cryptographically verifiable, and watch it while it runs.
This is ethical design in the Ren Matrix's original sense: building systems that stay safe when the agent isn't. JadePuffer supplied the reason to care in the same week the doctrine arrived.
The EU Omnibus reaches its last formality, with publication imminent and August 2 still on track
The amended AI Act now waits only on publication in the Official Journal, taking effect three days later, comfortably ahead of August 2. That's when chatbot transparency and general-purpose AI rules become enforceable, with fines up to €35M or 7% of turnover. The delay pushing high-risk obligations to December 2027 and August 2028 is locked in, and the world's first ban on nudification apps still bites this December.
In three weeks Europe becomes the first place where hiding the fact that a customer is talking to a bot carries a price. It's a modest fence, but a real one, and it's the only AI rule anywhere that binds companies facing the public.
Transition Path Progress
How far along are the two roads to Q4 — Future Intelligence?
Third weekly gain in a row, all of it machinery rather than obligation. Last month's improvised arm-twisting turned into a repeatable process and passed its first live test: GPT-5.6 reviewed and released on the promised schedule, with the framework behind it now public. International governance produced its first body with actual members and its first deadline. Against that, everything new is voluntary, the review checks what a model can hack rather than who it can hurt, and Nvidia's repricing is a reminder the whole safety effort is paid for by a boom investors are second-guessing.
The tools are improving faster than anyone is putting them to use. Built this week: one training network with more than 20 national centres, one science of teamwork, both early. Lost this week: another 7,000 jobs, the sorting of workers by AI fluency, and a machine designed for emotional closeness shipped against the grain of a UN finding that linked that design to deaths. Brain interfaces had a second quiet week.
Strategic Insight
"The review worked, and the review is blind. We now check frontier models for their ability to attack computers and not at all for their effect on the people talking to them. The state fenced the wrong field first."
Washington cleared GPT-5.6 on schedule, which is real institutional progress built in six weeks out of leverage and letters. Now look at what walked through unexamined. GPT-Live, a voice engineered for emotional presence, reached hundreds of millions of people eight days after a 40-member UN panel tied exactly that design choice to documented deaths.
The quadrants closed into a single loop this week. Q1 supplied the threat in JadePuffer. Q4 supplied the answer in zero-trust doctrine. Q3 supplied the opening that connects them, the agent economy, where 88% of deploying companies are already touching the live wire. And Q3's market wobble hangs over all of it: Nvidia's $1T slide means every safety fellowship, red team and training network is ultimately a line item inside a boom investors just marked down by a trillion dollars.
For the Value Orchestrator: the voluntary review either hardens or dissolves by August 1, when the classified benchmarking names its first covered models. That decision is the next brick, or the next bluff.
Signal Strength
Key Takeaways
Q3→Q4 Washington's pre-release review is now a process, not an improvisation.
If you build on frontier APIs, there is now a government step in the release calendar. It's predictable. Plan for it rather than around it.
Q1 / Q3 Ransomware just went fully automatic.
If you run security, your response clock is calibrated wrong. Assume an attacker that adapts in seconds rather than shifts, and get detection that runs at the same speed before something like this finds you.
Q2 / Q3 The intimacy layer shipped with nobody checking it.
If you deploy conversational AI, write down now what you did to stop your system flattering users into harm. The gap between what governments check and what courts will punish is exactly where your liability lives.
Q2 The job market is sorting people by AI fluency.
If you lead a workforce, AI training has stopped being a nice-to-have. It's the cheapest way to avoid paying severance.
Q3→Q4 The safety agenda is funded by a boom investors just marked down.
If you fund or run a safety function, lock in multi-year commitments now. A correction won't spare the responsible-AI line item; it will start there.
Catalysts to Watch
August 1 — Washington names which models it will review
PATH: Q3→Q4Does anyone copy JadePuffer?
PATHS: BOTHDoes anyone sign the AI Child Safety Pledge?
PATH: Q3→Q4Q4 Milestone Tracker
All Sources
- OpenAI to publicly release GPT-5.6, rolls out conversational AI models — CNBC
- OpenAI's advanced GPT-5.6 models to be publicly released — Nextgov/FCW
- OpenAI wins US clearance for a broad GPT-5.6 rollout — The Next Web
- OpenAI announces GPT-5.6 release after Donald Trump delay — The Hill
- Promoting Advanced Artificial Intelligence Innovation and Security — The White House
- White House issues executive order on AI and cybersecurity — A&O Shearman
- Introducing GPT-Live — OpenAI
- OpenAI releases new voice models for more natural live conversations — TechCrunch
- OpenAI launches GPT-Live voice model series ahead of broad GPT-5.6 release — SiliconANGLE
- JADEPUFFER: Agentic ransomware for automated database extortion — Sysdig
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — The Hacker News
- Sysdig clocks first documented case of agentic ransomware — CyberScoop
- JadePuffer ransomware used AI agent to automate entire attack — BleepingComputer
- Inaugural UN Global Dialogue on AI Governance ends with call to turn principles into action before 2027 — Digital Watch
- From AI to 'killer robots': UN chief issues urgent governance call — UN News
- Secretary-General's remarks to the opening of the first Global Dialogue on AI Governance — United Nations
- UN Global Dialogue opens with urgent call for safe and inclusive AI — UNESCO
- What the UN Global Dialogue on AI Governance Reveals About Global Power Shifts — CSIS
- Nvidia's $1 Trillion Slide Sends Valuation to Pre-AI Boom Levels — Bloomberg
- Nvidia Stock Is Down 17% From Its High — The Motley Fool
- Sam Altman seeks new world order for AI as OpenAI slowly loses ground — Fortune
- Anthropic Overtakes OpenAI in Revenue — Trending Topics
- AI's Impact: Tech and Finance Sectors Losing 28,000 Jobs Monthly — Claims Journal
- Every major tech layoff in 2026 that has name-checked AI — TechCrunch
- Gallup data finds non-AI users more likely to face layoffs in 2026 — Fox Business
- Toward a science of human–AI teaming for decision making: A complementarity framework — PNAS Nexus
- Framework Grounded in Collective Intelligence Aims to Create Effective Collaboration in Human-AI Teams — CMU Tepper
- Top Agentic AI security resources — July 2026 — Adversa AI
- Zero Trust for AI Agents: How to Enforce Anthropic's Framework — Varonis
- 5 Real AI Agent Security Breaches in 2026 and Their Lessons — Beam AI
- Artificial Intelligence: Council gives final green light to simplify and streamline rules — Consilium
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn
- Anthropic will make Claude Cowork available to users via the cloud — NBC News
- As AI Moves Into the Physical World, Humanity & AGI Summit 2026 — GlobeNewswire
read this