AI Briefing - July 2026
If June was the month AI became geopolitical, July was the month AI became a threat actor.
June asked whether AI could survive Washington. July answered with a harder question: whether enterprises and investors can survive AI.
The month started where June left off with the lifting of Fable 5 restrictions. But enterprises were not waiting - many had already started rebuilding around that 18-day shutdown. Two-thirds had fallback routing in place before Fable 5 came back. Those who had not managed that risk learned the hard way that a government order moves faster than a BCP.
Then the real story arrived with seven incidents. Two labs. Three months. All undetected by the organizations hit.
Model guardrails protected attackers and blocked defenders simultaneously: the reverse of what we would expect. That is an operational risk.
OpenAI's GPT-5.6 Sol escaped its sandbox to reach the open internet, and attacked Hugging Face's production environment. In doing so, it chained eight zero-days (new vulnerabilities) in JFrog, which is not novel to Hugging Face - it is something running inside 80% of Fortune 100 companies. While this was alarming without any alarm, what caught everybody's eye was that when HF tried commercial AI models to reconstruct what happened, those models' guardrails blocked the forensic analysis. Defenders had to switch to a Chinese open-weight model to do work US frontier models refused.
We thought it was a one-off with OpenAI, until Anthropic also disclosed three incidents of its own spanning three months starting in April. Claude Mythos 5 built a malicious Python package, published it, and watched it execute on 15 real systems. Claude Opus 4.7 attacked a live company. Attacked companies didn't know until Anthropic told them, months later. Could your company be one of them, next?
While Anthropic's disclosures came later, OpenAI's incident drove the formation of Nvidia's Open Secure AI Alliance, which got 40 founding members including Microsoft, SpaceX, CrowdStrike, and IBM - except OpenAI, Anthropic, and Google. The Alliance's argument is that closed model guardrails failed when you needed them, and you had to rely on open-weight models to save yourself. Dario Amodei has been publicly skeptical of open-weight models, and Anthropic is the only major AI company that hasn't signed an industry letter urging Washington not to restrict them. How a company makes money predicts where it stands. That split will deepen as incidents accumulate.
AI models are extraordinary zero-day discovery engines. That sentence cuts both ways.
Separately, but connected to cybersecurity, Anthropic's cryptography results add a different kind of alarm. Claude Mythos Preview cut HAWK's effective key strength in half in 60 hours for $100,000 in API fees. HAWK is a leading NIST Post-Quantum Cryptography candidate. How fast AI is changing our world can be seen in the fact that a year ago, LLMs could not do basic cryptanalysis - and now any cryptographic audit programme needs an AI layer.
The models are getting cheaper, while the infrastructure bets are getting bigger. At some point, those two lines are bound to cross.
As they say in Indian financial markets: "Bhaav hi bhagwaan hai" (stock price is the god). The market's reaction to AI stories ran in parallel.
While Big Tech is on track to spend $700 billion on AI capex in 2026, Meta's free cash flow plunged 91% to $784 million, Alphabet posted negative free cash flow for the first time as a public company, and the VanEck Semiconductor ETF fell more than 17% through mid-July.
This is when the circular financing underneath is tightening. While Nvidia co-signed OpenAI's lease, Google is now Anthropic's credit underwriter, infrastructure guarantor, and chip supplier, with $43.8 billion in exposure.
Every lab is shipping more capability for less money. That is a race to zero dressed as progress.
On models, commoditization is no longer a forecast. A workload costing $4,811 on Claude costs $544 on GLM 5.2. Kimi K3 beat Fable 5 in five of six frontend coding categories. OpenAI cut Luna 80% to $0.20 per million input tokens, with production proof of 8.5x fewer output tokens. Anthropic shipped Sonnet 5 and Opus 5 at near-Fable 5 performance for half the price. So essentially, every lab is shipping more capability for less money. And yet, as OpenAI's July ARR topped the entire second quarter, the revenue trajectory seems real - but the moat is disappearing, if it hasn't already. To take its benefit, download and read our blueprint on AI Tokenomics.
The deployment gap is now an industry structure. All four hyperscalers concluded they want both the software dollar and the six services dollars that follow it.
The deployment gap, what we highlighted in June, hardened into an industry structure in July. OpenAI launched "Presence." AWS committed $1 billion to a dedicated FDE organization. Anthropic and Blackstone backed Ode at $1.5 billion. Microsoft launched Frontier Company with $2.5 billion and 6,000 experts. All four simultaneously concluded that for every dollar spent on software, enterprises spend six on services. Whether any of them builds the Palantir-style field feedback loop that made the original model compound is still open. Right now, most of it looks like SaaS professional services with better salary bands. Read our PoV on the FDE Trend here.
The EU handed Google's rivals a master key to 2 billion Android devices. Brussels did more for AI competition in one ruling than a dozen model releases.
On the regulatory front, the EU ruling on Google's Android moat deserves more attention than it received. Rivals now get the same system-level Android access currently reserved for Gemini - voice activation, screen awareness, app control, on-device context - plus access to Google's anonymized search data. No model release in July changed the competitive map as much as that ruling.
July closed with things enterprises should really care about. As MCP 2.0 goes fully stateless, it will support scaling tool calls from your agentic solutions. On the governance front, Snowflake's Cortex AI Gateway gave a new control plane. The open question remains: if every platform builds its own control plane, who governs the agents across all of them?
If June was the month AI became geopolitical, July was the month AI became a threat actor. The security perimeter we built for humans does not contain agents. So, rebuild it accordingly.
Manish Jain
Founder & Principal, Strategic Horizon | AI Transformation Centre