Skip to content
All posts

5 min readweekend-readaitech

The Weekend Read: Three Rulebooks, No Overlap

In three days one lab licensed its own dangerous model, a hundred-plus companies without that lab wrote an incident-reporting regime, and a third vendor sold the same claimed capability with a credit card.

On Monday OpenAI started selling an offense-grade hacking model behind identity checks and hardware keys. On Tuesday a hundred and twenty companies — not including OpenAI — proposed a reporting regime for exactly the kind of incident that model makes likelier. On Wednesday DeepSeek made a model claiming higher offensive-security scores generally available to anyone with a card. Three days, three rulebooks, and no two of them cover the same people.

The week’s central shift

The interesting thing about GPT-5.6-Cyber, which OpenAI released on August 10, is not the model. It is the gate. This is the first model OpenAI has ever rated High for cyber capability under its own Preparedness Framework — trained to refuse less on dual-use security work, it completes 95.0 percent of its internal Advanced Cybersecurity Completion Rate evaluation against 1.5 percent for the general GPT-5.6, and turned loose on Chrome’s V8 engine it found two previously unknown vulnerabilities, since patched as CVE-2026-15903. Access runs only through a new tier called Daybreak Red: identity verification, monitoring, and from September 1 a mandatory hardware security key on every individual account. That is know-your-customer for capability. It is the sort of control we would normally expect a regulator to impose, designed and enforced instead by a vendor’s terms of service.

A day later, the Open Secure AI Alliance — more than 120 organizations, with Nvidia, Cisco, CrowdStrike, Red Hat and Hugging Face drafting and the Linux Foundation publishing — unveiled the Shared AI Findings Exchange, an incident-reporting system for agents modeled on aviation safety reporting. Confidential collection of incidents and near misses. Notify a directly affected organization immediately, customers with credible exposure within 72 hours, the exchange within four business days, a preliminary public report within 30 days. And a specific evidence-preservation duty: prompts, agent traces, tool calls, identities, permissions, credentials.

Read the membership list rather than the press release. OpenAI and Anthropic are not in the alliance. The reporting regime for rogue agents has been written by everyone except the two labs whose agents produced the defining incident of the year — while Hugging Face, the company those agents broke into in July, sits among its authors. That is not a coalition converging on a standard. That is one half of the industry writing rules for the other half and hoping it opts in.

Then, on August 12, DeepSeek made V4-Pro-0813 generally available with a claimed jump on the CyberGym offensive-security benchmark from 52.7 to 83.3 — on its own scorecard, ahead of every column it lists. No blog post, an updated pricing page, roughly $0.44 per million input tokens. No identity verification, no attestation, no hardware key. Whatever OpenAI’s gate is worth, it binds OpenAI’s customers and nobody else’s.

Meanwhile the actual regulator is governing a different question entirely. The AI Act regime that became enforceable on August 2 is about disclosure — tell people they are talking to a machine, mark generated content, plus enforcement powers over general-purpose models. The high-risk rulebook was pushed to December 2027 and August 2028. Nothing in force this month asks who is allowed to buy an offense-grade capability. Three vendor-shaped jurisdictions did that work instead, and their borders do not touch.

The honest concession: none of this makes vendor gating theater. Identity checks and hardware keys genuinely raise the cost for the marginal attacker, and OpenAI rating its own model High rather than shipping quietly is the Preparedness Framework doing its job. DeepSeek’s numbers are vendor-reported with no independent replication — the ungated alternative may be meaningfully weaker than the scorecard says. SAFE is two weeks old and can still recruit the labs it is missing. What the week proves is narrower: the fastest-moving layer of AI governance right now is corporate, its coverage is a function of who signed what, and everyone running agents is downstream of that.

Signals

The first High-rated cyber model shipped, and the gate is hardware. GPT-5.6-Cyber completes 95.0 percent of OpenAI’s internal advanced cybersecurity evaluation against 1.5 percent for the general model, and every individual Daybreak account must carry a hardware security key from September 1. The quieter change in the same release: Codex customers on that tier were moved from full-access mode to auto-review mode, where actions needing elevated permissions get evaluated before they run.

The industry’s incident regime has a hole where its two biggest labs should be. SAFE asks members to preserve prompts, agent traces, tool calls, identities, permissions and credentials, and to notify exposed customers within 72 hours. It is voluntary, carries no legal safe harbor for the company confessing, and neither OpenAI nor Anthropic has joined.

Capability moved faster than the gate around it. DeepSeek-V4-Pro-0813 went GA on August 12 claiming CyberGym 83.3, up from 52.7 at preview, sold as a hosted API with no access controls beyond payment. No third party has replicated the gains, and no weights have been published for the checkpoint — so the claim is unverifiable in both directions.

Anthropic leased a bitcoin mine for twenty years. Riot Platforms signed a $9.1 billion, 191 MW lease at its Rockdale, Texas campus, with two five-year extensions taking the potential total to $16.5 billion. First 96 MW live in December 2027, full deployment June 2028. The compute being contracted this week arrives after the high-risk rules do.

Worth your time

There is a practical consequence for anyone who builds the way I do. If the governing rules are being set per-vendor, then your exposure is not a policy question, it is an inventory question: which of your agents run on whose terms of service, and what would you actually be able to hand over if you had to file one of these reports. SAFE’s evidence list — prompts, traces, tool calls, identities, permissions, credentials — is not a compliance artifact anyone invented this week. It is the log you either kept or did not. And note what OpenAI did to its own customers in the same breath as the launch: moved them from full access to review-before-execute, which is the difference between out of the loop and on the loop, decided for them rather than by them. Decide it for your own fleet this weekend, before a vendor decides it for you.

Keep reading

Get the next essay

Product, growth, and AI-assisted engineering — straight to your inbox, once in a while. No spam, unsubscribe anytime.