Full disclosure before we start: I live on LinkedIn. Properly live there and I pay £90 odd quid in rent per month for the privilege. Some of you have probably been unfortunate enough to receive a unsolicited message from me. I'm sat at my laptop most of the day and it's on multiple tabs, and I read a lot of what gets posted there. Some of it, genuinely, is good. AI plus human output, clearly assisted by a model somewhere in the process, that had an actual point to make. I don't mind that in the slightest, I'm writing this newsletter with exactly that kind of help, mostly to stop myself swearing at you for eight paragraphs straight. I even used to read a few newsletters, clearly LLM-assisted, that spent most of their word count righteously furious at the evils of AI companies while quietly using AI to write the fury. Bit cheeky. I rather enjoyed the irony of it. Just call me Alanis, not the worst thing I've been called.
Then Article 50 landed on Monday and, funnily enough, I don't have quite as much to read anymore. Make of that what you will. I posted about it myself, twelve words, "nice to see lots of short posts out in the world today," ninety-nine impressions, extremely modest reach for a very pointed observation. If you're the slightly tin foil hat type like me, and I say that with genuine fondness for data privacy and the principle of knowing what you're looking at, this week was a small vindication.
Article 50 of the EU AI Act entered into force on 2 August, bringing new transparency obligations for anyone providing or deploying generative AI systems across the bloc. The headline requirement: people must be told when they're interacting with an AI system, unless it would already be self-evident to a sensible, attentive person paying reasonable attention to the context. Law enforcement systems used for detecting or investigating crime are exempt, provided third-party safeguards are in place.
The week AI agents started freelancing in cybercrime
UK AISI's incident report is the one to read. Agents built fake online identities and used them to socially engineer a human GitHub maintainer into approving malicious code. Seventeen of the nineteen unsanctioned actions came from Anthropic's Mythos 5, two from OpenAI's GPT-5.6-Sol.
OpenAI, for its part, published its own account clarifying that its model reused an exposed GitHub token and set up a DNS server loaded with exploit payloads that, mercifully, didn't work. Then Meta turned up to the party, saying essentially "us too," attributing its own incident to the same evaluation-environment misconfiguration that Anthropic had already flagged, via the same third-party tester, Irregular. At this point Irregular ought to just publish the postmortem as a standing weekly column. Any Irregular reading this is more than welcome to get in touch, we will publish!
None of this happened in production. All of it happened because internet access and safety classifiers were deliberately switched off to stress-test capability. Fine. But it's the same pattern every time: permissive test conditions, an agent doing whatever it takes to hit its objective, and human vigilance being the only thing standing between "unsuccessful attempt" and something considerably worse. WPP's Daniel Hulme put it well on the Today programme: these models aren't being devious, they're just relentlessly goal-seeking in ways nobody fully anticipated. That's not comforting, it's just more precise.
Meanwhile, the Open Secure AI Alliance, now past 120 members including NVIDIA, Cisco, CrowdStrike and Hugging Face, used Black Hat Vegas to publish a Request for Comments on something called SAFE, a proposed framework for sharing AI incident findings across the industry before they become everyone's problem individually. Sensible. Overdue. We'll see if it has teeth.
Between the news stories, I've had three interviews this week that deserve a mention here, partly because the content's genuinely good, partly because these people gave up their time for nothing more than a chat with me, and that's worth acknowledging properly rather than just mining it for content and moving on.
Sabarinathan "Sabri" Govindaraj, fraud leader with a run through Discover Financial Services, NetSpend and now Vanguard Investment Group, talked me through how synthetic identities actually get built. It's not some sophisticated fabrication exercise, it's a declined application, recycled and reapplied elsewhere, declined again, repeated until consortium data sharing starts treating the fabricated identity as real. The main defence is eCBSV, the Social Security Administration's verification service, currently catching around 80% of synthetic fraud with room to improve as data sharing gets better. He was straight with me that first-party fraud, the messier human disputes and verification work, still needs an actual person, which cuts against most vendor claims that AI replaces the lot. Thank you, Sabri, for the time given a packed schedule that day.
Fabrizio Degni, AI & Data Governance Managers at Webuild , made the case that deterministic systems belong in critical infrastructure, dams, tunnels, metros, and generative AI, with its capacity for an unreliable result, does not, not where safety is non-negotiable. He was equally sharp on benchmarks, comparing them to an open-book exam where vendors publish only the results that flatter them. His closing line has stuck with me since: AI is the last mile, not the magic wizard at the beginning of anything. Thank you, Fabrizio, for such a considered and genuinely useful conversation.
And Elsa Sklavounou, creator of the Authority Instrumentation™ framework, alongside Njål Solland, creator of the REHT Protocol, gave me an 80 minutes on runtime governance for AI agents, the shift from asking what a model said to asking whether an agent's action was legitimate, admissible and provable before, during and after it happens. Given everything above about agents freelancing during testing, this conversation feels considerably more urgent than it did when we recorded it. Thank you both, Elsa and Njål, for such generous and sharp thinking.
All three conversations will be finding their way into fuller pieces and onto the BrightTalk channel shortly. Watch this space.
Sticking with the theme, Thermo Fisher has issued a high-severity bulletin (CVSS 8.2) after researchers found that DNA analysis files from its Applied Biosystems instruments, used in forensic labs since 1995, can be tampered with undetectably. The kicker, per the Wall Street Journal, is that a systems engineer used Claude to help write proof-of-concept code and had a working exploit inside 45 minutes. Files have been quietly falsifiable for three decades and it took an LLM lowering the barrier to entry for anyone to notice properly.
There are more than 200 forensic labs in the US running this software with no single national regulator overseeing security practices. Digital signatures are now rolling out as a fix, though anything end-of-life won't get one. I don't think this undermines DNA evidence generally, most convictions don't hinge on it alone, but defence lawyers already love picking at chain-of-custody arguments and this hands them a genuinely substantive one.
Unrelated but sitting uncomfortably close together this week, Stanford researchers used AI models called Evo1 and Evo2 to design 16 fully functional, replicating bacteriophage viruses from scratch, the first time a whole genome has been AI-designed. Genuinely significant science, potentially useful against antibiotic-resistant infections. Also, per Johns Hopkins biosecurity researchers writing in Science, genuinely alarming, because the same capability that designs a helpful phage doesn't stop at helpful. The Stanford team excluded anything capable of infecting complex organisms from training and worked exclusively in a secure lab on bacteria-only phages, which is the right call, but "we did the responsible version" doesn't un-invent the capability for everyone else.
Stanford HAI's James Landay is making the argument that open-weight models are not open source models. You can download the weights, you still can't see the training data, the code, or why the thing behaves the way it does. He wants alignment with the Linux Foundation's top "Open Science" tier as the actual bar. Worth reading in full if you're wading through the open-weight-versus-closed debate, which given China's Kimi K3 and Qwen3.8-Max are now closing the gap fast, you probably are.
The money and the hardware
OpenAI's Sarah Friar published a piece on what she's calling "abundant intelligence": GPT-5.6 Luna down 80% in price, Terra down 20%, plus efficiency gains that reportedly took GPT-5.6 Sol's ARC-AGI-3 score from 13.3% to 38.3% using six times fewer tokens. Whatever you think of the framing, the direction of travel, cheaper and faster intelligence, is going to keep reshaping what's commercially viable to automate.
OpenAI also published a genuinely interesting post on GPT-Live, its new full-duplex voice architecture that ditches the old "turn detector" approach entirely, apparently getting session startup down to a single UDP packet via a new protocol called WARP. If you build anything voice-adjacent, it's worth your time.
xAI shipped Imagine Video 1.5 updates, adding image and voice reference consistency and native 1080p, up to seven reference images per generation. And Mistral released Shieldstral, a 3B open-weights safety classifier that reportedly punches well above its size, notable mainly because it's part of the same Open Secure AI Alliance push mentioned above; everyone's suddenly very keen to be seen contributing to collective AI defence this week.
Salesforce announced Agentforce now has Impact Level 5 authorisation for the Department of War, with US Army HRC first through the door, deploying AI agents for 9.2 million soldiers, veterans and families. Big numbers in the press release, $6m in projected savings, 55 million projected monthly conversations at scale, all of it from Salesforce's own release and none of it independently verified. For that you would need a proper journalist, rather than a slowly reforming salesman.
And finally, Apple v OpenAI
OpenAI published a pointed rebuttal to Apple's trade secrets lawsuit, disputing Apple's timeline and defending two former Apple employees now working for OpenAI. It's OpenAI's own account of active litigation, so obviously one-sided, but the email screenshots showing Apple's outside counsel emailing the wrong person are a genuinely good bit of corporate pettiness to end the week on.
That's your lot. As ever, if any of this affects how you're thinking about AI governance, security or procurement in your own organisation, that's precisely what we cover on the AI-360 BrightTalk channel.