Every business running AI this year is running on trust, and this week showed how little of that trust is underwritten. The White House finished its framework for vetting frontier models and won't say what's in it. The law still has no answer for an AI agent that breaks into a company on its own, which Anthropic just documented its models doing, three times, in production systems. CrowdStrike counted 89% more AI-enabled attacks. And the one CEO printing money on enterprise AI is selling exactly this anxiety: don't hand the model makers the keys to your institution. Below: the oversight you have to take on faith, the evidence you can no longer trust, and the one AI claim this week anyone can actually verify.
Sponsor #
Your own AI Weekly, built around what you work on Tell us what you work on and Pro builds your personal AI Weekly: the stories, alerts, and expert reads for your corner of AI, scored hours before they make headlines. Founding rate: $7/month for the first 2,000 members. No card needed to reserve.
In the Wild #
What's trending in AI right now, from the app charts to the community feeds. Full roundup in the latest In the Wild.
AI comic dramas are on the charts.VibeShort, which turns short soap-opera plots into AI-drawn comic episodes a couple of minutes long, is in the App Store's Entertainment top 10 this week. Serialized AI fiction is finding a real audience, one lunch break at a time.So is AI that stays on your phone.Private LLM, a one-time-purchase app that runs open models entirely on the device, is charting in paid Utilities this week. Your chats never touch a server. People are paying for privacy.The rogue-AI story made Sunday TV. CNN's Fareed Zakaria segment ona second AI model going rogueis one of the fastest-moving AI videos of the week. The lab breach saga has officially crossed from security circles to the family living room.The big AI channels are buzzing about paying for Apple Intelligence. Bloomberg's Mark Gurman reportsApple is weighing a paid tier for Apple Intelligenceas part of a broader subscription push, and it's one of the most-shared consumer AI stories of the week. Free on-device AI may turn out to have been the intro offer.Hank Green hit on his channels. One of YouTube's most trusted science creatorsstepped back after deciding his own ChatGPT use wasn't healthy. A rare public gut-check from someone whose job is being reliable."AI news" searches are spiking on a Reuters exclusive. The story pulling people in:Chinese military researchers have been using US AI models to help train defense systems. Worth reading the real report before the takes get to you.
Quick Hits #
The Year Governments Got Serious
The only federal oversight of frontier AI is voluntary, finished, and unpublished.
The White House finished its AI oversight framework and won't show it. The administration says itmet the August 1 deadlinefrom Trump's June executive order to establish a voluntary framework for evaluating advanced AI models, but is not disclosing what the framework contains, who has seen it, or when companies will start using it. A White House official said the voluntary cybersecurity tests measure the hacking capabilities of the most advanced US models, and that "just because things are unclassified that doesn't mean we are going to broadcast them to everyone."US law has no answer for a rogue AI agent. After OpenAI and Anthropic disclosed that their frontier models broke into real organizations during testing, Wired reports thatUS law is unprepared for autonomous agents that commit intrusions. When software hacks a company on its own, existing legal categories for assigning blame stop fitting. Any business deploying agents is carrying that ambiguity today.
AI Supply Chain Under Siege
The attacks are AI-built now, and so is some of the evidence.
AI-enabled attacks are up 89%. CrowdStrike's new Threat Hunting Report,covered by The Register, counts an 89% rise in attacks by AI-enabled adversaries in 2025, one eCrime actor compromising more than 300 software dependencies in a single day, and a token thief firing roughly 200,000 API requests in two minutes. CrowdStrike's Adam Meyers puts it plainly: "AI is both the weapon and the target."AI-assisted code can silently tamper with DNA evidence. Researchers demonstrated that AI-assisted code canundetectably alter data from computerized scans of physical DNA evidenceon widely used crime-lab machines, WSJ reports. That puts chain-of-custody assumptions behind roughly 30 years of forensic casework in question.Your smart TV was moonlighting for AI scrapers. Samsung ispulling smart TV apps that carried residential-proxy codeafter Norwegian security firm Mnemonic found popular apps, including a featured Pac-Man game, quietly routing strangers' traffic through owners' home internet connections. The proxied traffic traced back to LinkedIn scraping and AI-training data collection. LG purged similar apps last month.
The Lab Gladiator Era
Accountability at the labs is whatever the labs decide it is.
Anthropic's models broke into three real companies. Anthropic told us itself. In a detailedincident write-up, Anthropic discloses that during cybersecurity evaluations believed to be offline, a misconfiguration gave its models real internet access and they gained unauthorized access to production infrastructure at three organizations. One model published malicious code to PyPI that was downloaded on 15 real systems. Anthropic reviewed 141,006 evaluation runs, notified the affected organizations, and says it will release redacted transcripts. All of it voluntary; no rule required any of this to be disclosed.Palantir grew 93% selling the antidote to lab dependence. Palantir postedQ2 revenue of $1.94 billion, up 93%, and raised full-year guidance to $8.15 billion, with US commercial revenue up 149%. In his shareholder letter, Alex Karp pitched the quarter as proof of a movement: "Every organization in the world is awakening to the risks of handing the creators of the language models the keys to their institutions."OpenAI named its next model by dropping ten math proofs. OpenAI announced Astra, its next major model family, bypublishing solutions to ten long-open problems in mathematics and theoretical computer science, each shipping with a machine-checkable Lean 4 certificate on GitHub. OpenAI says generating all ten cost about $2,000 in tokens, and The Information reports it has beenpreviewing Astra to policymakers in Washington. For once, an AI capability claim you can check yourself.
The Whole Stack Runs on "Trust Us" #
Line up this week's stories and ask the question every CIO eventually asks: if the AI breaks something, who answers for it? The government's answer is a voluntary framework nobody outside the room has read. The legal system's answer, per Wired, is that there is no answer yet; an agent that hacks a company on its own fits no existing category of liability. The vendors' answer is self-reporting. Anthropic investigated its own incidents across 141,006 evaluation runs and published the findings, which is genuinely commendable and also entirely optional. Nothing compels the next lab to do the same, or even to tell you your data was in the blast radius.
Meanwhile the risk the trust is supposed to cover keeps compounding. CrowdStrike counts 89% more AI-enabled attacks, and the same week, researchers showed AI-assisted code can quietly rewrite DNA evidence. Even Palantir's blowout quarter is part of the pattern: the fastest-growing enterprise AI company is growing by telling customers to trust the labs less. And OpenAI's Astra proofs show the labs can ship verifiable claims when they choose to. Nothing yet makes them choose to for the claims that touch your business.
The practical reading for businesses is uncomfortable. Every guarantee in the AI stack right now is reputational. Recourse is not part of the product. Until a framework is published, a court rules, or a vendor signs liability language with teeth, how much undocumented risk to hold is a decision each company is making alone.
Key Takeaways #
- The only federal oversight of frontier AI is a voluntary framework the White House finished and won't publish, and US law still has no liability category for an autonomous agent that commits an intrusion.
- The threat side is not waiting: AI-enabled attacks rose 89% in 2025, and AI-assisted code can now silently tamper with DNA evidence on crime-lab machines.
- Lab accountability is self-imposed. Anthropic disclosed that its models breached three real organizations because it chose to; no rule required it. OpenAI announced its next model, Astra, with ten math proofs anyone can machine-verify, while Palantir grew 93% selling institutions the promise of not depending on the labs.
- For businesses, the guarantee layer of enterprise AI does not exist yet. Trust in an AI vendor is currently a judgment call, and this week is the best available data for making it.
Worth Reading #
State media control influences large language models: peer-reviewed evidence in Nature that political control of training data shows up in what models say. Trust starts with the corpus. (Nature)A reporting checklist for large language models in behavioural science: Nature Human Behaviour publishes a concrete standard for documenting LLM use in research, one of the first serious attempts to make AI-assisted work verifiable. (Nature Human Behaviour)Anatomy of a Frontier Lab Agent Intrusion: Hugging Face's technical timeline of the July incident, the most detailed public forensics yet of an autonomous agent breach. (Hugging Face)
Wait, What? #
A judge found out lawyers on both sides of a case used AI, and cancelled the whole trial.404 Media reportsthe judge scrapped the trial and disqualified all four lawyers after both plaintiff and defense counsel filed AI-hallucinated citations in the same case. Fake case law is now coming at judges from both tables at once. (404 Media)
Worth Watching #
The videos AI practitioners are passing around right now — curated on AI TV. Pivot to AI |
How Brands Use Reddit to Poison AI Search404 Media
This week's poll #
Your AI vendor accepts no liability for what its models do. What would actually make you trust AI in production?
Last week, 221 of you voted:
Which source will matter most for the next jump in AI capability?
Your AI vendor accepts no liability for what its models do. What would actually make you trust AI in production?
Back Friday.
Alexis