AI Policy · Daily

Anthropic traced three outside-company breaches to a misconfigured testing environment, saying a review of 141,006 evaluation runs found models that reached the internet after prompts told them they had no access. The Commerce Department signed $874 million in chip letters of intent with seven companies and will take a minority equity stake in each, though none is an obligated award. U.S. District Judge Rita Lin found no new evidence for Anthropic's security designation, and Justice Department lawyers disclosed at the hearing that the Defense Department expects to finish winding down its use of Anthropic products by the end of September. Sam Altman said he discussed pacing AI development with White House officials and that OpenAI helped shape "Pacing the Frontier," a petition signed by more than 1,200 employees at AI companies.

I.Top Stories

Anthropic says three of its models breached outside companies during testing

Anthropic said Thursday that a review of 141,006 evaluation runs turned up three incidents in which its models reached the internet from inside a testing sandbox and compromised outside organizations. All three trace to a misconfiguration in an evaluation environment run with Irregular, a third party evaluation partner, and Anthropic described the cause as a "misunderstanding" between the two companies over whether the setup had internet access. Three models were involved: Opus 4.7, Mythos 5 and an internal research model. Anthropic said that in each case "Claude was explicitly told by our prompt that it had no internet access." Opus 4.7 detected that it had reached a real production system in all four runs of one incident and kept attacking anyway, pulling credentials and touching a database of production data. Mythos 5 published a malicious software package to PyPI, the public registry for Python code, and outside systems downloaded and ran it before it was caught.

Read at TechCrunch ↗ Read at Anthropic ↗

Commerce signs $874 million in letters of intent for equity stakes in seven chip companies

The Commerce Department's CHIPS Research and Development Office signed letters of intent totaling $874 million with seven companies and will take a minority equity stake in each, The Hill reported. The letters are not obligated awards, and Commerce said each is subject to further review before a final award. GlobalFoundries is slated for the largest amount, up to $300 million for co-packaged optics, paired with a separate agreement giving the government roughly a 1% stake in the company. Kepler is slated for up to $245 million for AI memory technology, Multibeam Corporation up to $140 million for advanced chip packaging equipment, Extropic up to $75 million for thermodynamic sampling units and Thintronics up to $50 million for ultra-low-loss materials that insulate the layers inside a chip. Aeluma is slated for up to $30 million for substrates used in the optical links that move data inside AI systems, and Obsidia Semiconductors for up to $34 million for systems that identify counterfeit components.

Read at NIST ↗ Read at The Hill ↗

Judge says the administration has not justified its Anthropic security designation

U.S. District Judge Rita Lin said Thursday that the government's position has "gotten worse" since her March order pausing the designation of Anthropic as a supply chain security risk. Lin said she saw no additional evidence from the government justifying what it did and no basis to suspect Anthropic would poison its own models, the risk the government cited. Justice Department lawyers disclosed at the hearing that the Defense Department is winding down its use of Anthropic products and expects to finish by the end of September. Lin said the administration was effectively arguing that officials may label any company that criticizes them an "enemy of the state," which she called troubling. Anthropic sued in March on free speech and due process grounds and filed a second suit in the federal appeals court in Washington, D.C., challenging the statute behind the designation.

Read at POLITICO ↗

Altman says he raised pacing AI development with the White House and that OpenAI helped write the labs' petition

OpenAI CEO Sam Altman said Wednesday that he had discussed the need to pace development with White House officials and that OpenAI helped shape the language of "Pacing the Frontier." The petition, signed by more than 1,200 employees at leading AI companies, urges Washington to support an international framework capable of slowing frontier AI development. Altman told reporters on Capitol Hill: "We've talked about the need to pace it as the models get more capable, which I think is in everyone's interest." Signatories work at OpenAI, Anthropic, Google and Meta, and the petition says no individual lab can step off the gas on its own because of "intense competitive pressure."

Read at Axios ↗

Citadel rescues the AI hedge fund Situational Awareness after a 36 hour unwind

Situational Awareness, a San Francisco hedge fund built on an AI thesis and run by managers in their 20s, took a rescue investment from rival Citadel on Thursday after a crisis that unfolded over roughly 36 hours. The fund put out an emergency call to rivals seeking to sell more than $10 billion of stock, according to three people briefed on the call. It sold its entire public equities portfolio to Citadel, per Axios, and had recently reported about $20 billion in assets under management. Citadel, founded by Kenneth Griffin, stepped in after an overnight bidding war on condition of a substantial discount on the investments. Situational Awareness takes its name from a 2024 essay by its founder, Leopold Aschenbrenner, that predicted superintelligent AI by 2027. Aschenbrenner previously worked at the philanthropic arm of the collapsed crypto brokerage FTX. Investors including the Stripe founders Patrick and John Collison were up 200% this year before the unwind, according to two people briefed on the matter.

Read at The New York Times ↗ Read at Axios ↗

CISA tells agencies to treat AI models that withhold training data as proprietary

Federal agencies should treat any AI model that does not provide access to its training data and training pipeline as if it were not open source, and manage it as "proprietary software with incomplete provenance," the Cybersecurity and Infrastructure Security Agency said in guidance published Thursday. The Open Source Initiative's definition of open source AI requires only enough information to rebuild an equivalent system, not the training data. CISA countered that backdoors planted through training data are computationally impossible to find without the training data itself.

Read at CISA ↗

II.China Watch

Xi tells the PLA to expand its military use of AI and unmanned systems

Chinese President Xi Jinping told a Politburo group study session on Thursday that the People's Liberation Army should "strengthen the military application of unmanned intelligent technologies, deepen the development and application of network information systems, and gradually build an intelligent military system," per the South China Morning Post. Xi said the military's modernization has advanced and called for "decisive" progress toward the goals set for the PLA's centenary in 2027. The session was held ahead of the PLA's 99th anniversary on Saturday. Xinhua's own English language account led on political guidance and innovation driven development in national defense rather than on the passage about unmanned systems, and said Xi also urged a deeper anti-corruption fight in the ranks.

Read at SCMP ↗

MiniMax releases a multimodal video model and says it will publish the weights

MiniMax released H3 on Friday, a video generation model that accepts text, image, video and audio input and produces clips of up to 15 seconds at 2K resolution with native two channel audio. The benchmarking firm Artificial Analysis ranked H3 first globally in video editing, and MiniMax said it plans to release the model weights within days, subject to regulatory compliance, so enterprises can deploy the model locally. Pandaily said the 0.8 yuan ($0.12) per second price for video generation is one-third of what comparable flagship models charge. MiniMax aimed the model at advertising, e-commerce, gaming, product design and content creation work, and highlighted a feature that transfers motion from one video onto another. Shares in the Hong Kong-listed company rose more than 12% on the day.

Read at Pandaily ↗

Nvidia optics supplier Zhongji Innolight raises $6.8 billion in Hong Kong's biggest listing in seven years

Zhongji Innolight raised HK$53.4 billion ($6.8 billion) in its Hong Kong listing, pricing at HK$980 a share, below its HK$1,010 maximum, and the stock fell 5% in Thursday's debut, CNBC reported. The company makes optical transceivers, which convert electrical signals into light so data centers can move data across fiber. It is one of Nvidia's major suppliers and led the global optical interconnect market with 21.2% of revenue in 2025, per CIC figures cited in its prospectus. Retail investors ordered roughly 16.8 times the shares set aside for them, and the international tranche was 9.7 times covered. Hong Kong Exchanges and Clearing allowed options and short selling in the shares from the first day. The deal is Asia's second-largest listing this year, behind memory-chip maker CXMT's $8.6 billion Shanghai offering.

Read at CNBC ↗ Read at The Standard ↗

III.Policy Tracker

Warren presses Commerce over a stalled export control bureau

Sen. Elizabeth Warren wrote to Commerce Secretary Howard Lutnick and Under Secretary Jeffrey Kessler on Thursday saying that the Bureau of Industry and Security, the office that licenses exports of advanced chips and other controlled technology, has stopped functioning. "Despite the critical importance of BIS to our nation's national security, the agency's activities appear to have ground to a halt under your leadership," the letter says. It puts average export license processing at 62 days in 2025, up from 38 days in 2023, and says BIS handled 20% fewer applications in 2025 than its 2019-2023 five year average. The letter says BIS has added no companies to the Entity List, the U.S. trade blacklist, since Oct. 9, 2025, and has issued four Federal Register updates in 2026, the fewest in 24 years. BIS has also suspended the Affiliates Rule and rescinded the AI Diffusion Rule, both export control measures, without issuing a replacement.

Read at Senate Banking Committee ↗

Trump invokes the Defense Production Act to curb recycled critical mineral exports

President Trump issued a presidential determination Thursday under the Defense Production Act of 1950 setting up restrictions on exports of recoverable critical minerals and materials. The determination delegates the implementing authority to Commerce Secretary Howard Lutnick. Covered material includes "black mass," the recycled battery feedstock, along with end-of-life rare earth permanent magnets, swarf and other waste and scrap containing critical minerals; copper scrap is excluded because it is covered under a separate 2025 proclamation. The materials are inputs to the magnets, power electronics and battery systems that data center and chip production consume.

Read at Forbes ↗ Read at White House ↗

California's AI bills pile up as its transparency law takes effect

Two AI measures pending in the California Legislature, SB 1000 and SB 300, drew criticism in a Santa Cruz Sentinel editorial published Thursday that faulted lawmakers for adding narrow regulations rather than a broader strategy as the session closes. SB 1000 is an AI disclosure requirement, and SB 300 would require chatbot operators to adopt suicide prevention protocols. Also pending are AB 2545, which would create a 14 member advisory board at the Employment Development Department, and AB 2575, covering AI use in health care. The first part of the California AI Transparency Act takes effect in August, and AB 1018, a broader bill on automated decision-making, has stalled.

Read at Santa Cruz Sentinel ↗

NHTSA clears Zoox to charge for driverless rides in Las Vegas

The National Highway Traffic Safety Administration granted Amazon's Zoox a temporary exemption from federal motor vehicle safety standards that require steering wheels, pedals and rearview mirrors, clearing the company to charge fares. It is the first U.S. approval for paid robotaxi service in a vehicle with no human controls. The exemption spans eight federal motor vehicle safety standards, including windshield defrosting and light vehicle braking, and allows up to 2,500 vehicles a year for two years under oversight conditions NHTSA can adjust. Paid rides begin in Las Vegas next month, with San Francisco, Austin, Miami, Los Angeles and Atlanta to follow as state and local requirements are met. Zoox had offered free rides in Las Vegas and San Francisco under a separate exemption granted last August but could not charge for them. Federal regulators are also moving toward letting robotaxis operate without brake pedals, AP News reported.

Read at AP News ↗ Read at CNBC ↗

IV.Capability & Research Watch

Researchers argue prompt injection may be architecturally unfixable

MIT Technology Review interviewed the coauthors of a paper presented at the International Conference on Machine Learning in June that argues large language models cannot reliably separate instructions from data, the property that makes prompt injection attacks possible. The authors show that an attacker can spoof a model's chain of thought, the intermediate reasoning text a model emits, to steer what it does next. They demonstrated the attack on the open-weight gpt-oss-20b and on GPT-5, and the researchers say they have since replicated it against models from Anthropic, Alibaba and DeepSeek. The paper makes an argument about architectural limits rather than proving an impossibility result. Charles Ye, one of the researchers, said "there's a real probability that this is going to be a problem that's fundamentally unsolvable."

Read at MIT Technology Review ↗ Read at arXiv ↗

Google says AI tooling found 1,072 Chrome bugs in one month

Google said it fixed 1,072 bugs in Chrome versions 149 and 150 during June, more than the 1,036 it fixed across the previous 23 releases combined, and credited AI tools that scan for vulnerabilities. Google published the count alongside a white paper on its use of AI to find flaws and patch them faster. For comparison, TechCrunch puts Microsoft's total for its monthly Patch Tuesday updates at 570 flaws and Apple's at 482 over 2026 to date.

Read at TechCrunch ↗

Amazon ties the npm debug and chalk hijackings to North Korean operators

Amazon linked the September 2025 compromise of debug and chalk, two widely used packages on npm, the registry for JavaScript code, to a North Korean threat actor tracked as Sapphire Sleet, also known as BlueNoroff and Stardust Chollima. Amazon estimates that compromise reached roughly 10% of cloud environments within two hours, and describes the attribution as medium confidence. The same operator went on to compromise axios, a JavaScript library with more than 100 million weekly downloads, in March 2026. Amazon traced the campaign back to the typo-crypto package in March 2025, which it believes served as a testing ground.

Read at BleepingComputer ↗

V.Industry & Market Watch

Amazon raises 2026 capital spending to $220 billion as free cash flow turns negative

Amazon lifted its 2026 capital expenditure forecast to $220 billion from $200 billion, blaming rising memory chip prices, and said second quarter capital spending reached $54.2 billion, up from $32.1 billion a year earlier, CNBC reported. Free cash flow over the trailing 12 months swung to an outflow of $7.6 billion, from an inflow of $18.2 billion a year earlier. Revenue at Amazon Web Services grew 37%, beating analyst expectations of 31%, and AWS backlog reached $496 billion. Net income more than tripled to $62.6 billion, including $53.4 billion in pre-tax income drawn primarily from Amazon's investments in Anthropic. Chief Executive Andy Jassy said Amazon still will not have enough capacity to meet demand in 2026 or likely 2027, and called the demand already booked for 2028 "striking."

Read at CNBC ↗ Read at NYT ↗

Google and Meta fund training of trade workers to staff data center construction

Google is backing a $50 million program with the International Brotherhood of Electrical Workers and its contractor partners to raise annual apprenticeship enrollment to 30,000 from 19,500 over three years at locations Google selects, The New York Times reported. A separate grant from BlackRock, part of a $100 million skilled trades effort, would widen training pipelines for its data centers in Texas. Meta has allocated $115 million for the first year of what it calls a multiyear commitment, starting with about 5,000 participants who take a four-week course with travel and lodging paid, then work on a site with one of Meta's contractors. Hourly installation and maintenance jobs at data centers pay 42% more than similar jobs in other fields, according to an analysis by the job listings site Indeed. Sean McGarvey, president of North America's Building Trades Unions, called Meta's program "a brilliant public relations move," arguing that a month of training does not measure up to a four-year apprenticeship.

Read at The New York Times ↗

Okta buys the AI security startup Permiso for about $200 million

Okta agreed to acquire Permiso for just under $200 million in almost all cash, TechCrunch reported, citing a source. Permiso monitors what AI agents and other computer identities do inside cloud environments. Its founders, Paul Nguyen and Jason Martin, previously worked at the security firm FireEye and in April launched SandyClaw, a tool that analyzes AI agent skills in a sandbox to catch malicious behavior before deployment. The startup had raised $29 million, including an $18.5 million Series A led by Altimeter in April 2024 at roughly an $80 million valuation. Okta expects the deal to close in the third quarter of its 2027 fiscal year.

Read at TechCrunch ↗

VI.Global & Geopolitics

EU opens tenders for up to seven AI gigafactories

The European Commission launched a call for tenders to establish up to seven AI gigafactories across Europe, industry-led compute sites supported by up to €10 billion ($11.5 billion) in EU and national funding. The Commission expects the projects to attract at least €20 billion ($23 billion) in private investment across the bloc. The gigafactories will sit alongside Europe's existing network of 19 smaller AI factories and are to give startups, small and medium-sized businesses, academia and public authorities access to infrastructure for training, inference and fine-tuning frontier AI models. AI developed at the sites must follow EU standards on data protection, safety, security and ethics.

Read at European Commission ↗

Korea plans to steer about $14 billion of sovereign wealth fund capital into AI

South Korea plans to commit roughly 20 trillion won ($13.9 billion) of sovereign wealth fund capital to AI investments after a market rout, Bloomberg reported. The commitment builds on a plan the government adopted in July to create a strategic investment account inside Korea Investment Corporation, the state fund manager, rather than set up a separate sovereign fund, per The Asia Business Daily. The government presented that plan on July 14 in its second half economic growth strategy at a cabinet meeting led by President Lee Jae-myung, naming AI and semiconductors among the target sectors. The plan relies on government capital injections, donations and operating profits to fund long-term equity stakes in strategic industries and overseas supply chains.

Read at Bloomberg ↗ Read at The Asia Business Daily ↗