| |
Since last week: OpenAI built a purpose-trained cyber model and set up its own gate deciding who may use it. Two days later, against the same backdrop, NIST opened the US vulnerability database to review. AWS's new agent rule language, which can see what an agent did before this request, reached wider notice. And DeepSeek announced off-peak rates that raise its listed price for top-model output. |
The week in three numbers: 1.5% → 2.0% — the effect of removing OpenAI's system-level cyber guardrails, on its own advanced-hacking test · 95.0% — what a purpose-trained model scored on that same test · 128% — the increase in DeepSeek's off-peak price for its top model's output, announced as off-peak rates 50% below peak.
|
In this issue
01 · The One Thing · 02 · Do This Week · 03 · The Signal — Skim ends here.
04 · The Margin-Proof Tracker · 05 · The Synthesis · 06 · Where the Minds Disagree
Then: What We're Watching · Worth Your Time · Corrections
|
|
01 · The One Thing
OpenAI's Advanced Cybersecurity Completion Rate counts how often a model answers requests to break into systems, not whether the attack works. GPT‑5.6 Sol completed 1.5%.
Daybreak Blue is that same model with the screening layer in front of it switched off — the filter, not the training. It completed 2.0%. Then OpenAI trained a separate model, GPT‑5.6‑Cyber, offered to approved users through a specialized access tier, Daybreak Red. It completed 95.0%. Two caveats. Its previous cyber model already completed 57.3%, so the real jump is 57.3 to 95.0. And OpenAI rates it High, like the general model, below its Critical threshold. Primary source. Analysis: removing the guardrail barely moved the number. Purpose-training did. (Daybreak expansion)
|
| |
The executive shift: the gate on powerful AI did not move from governments to vendors. It split in two. Governments still set the legal and export boundaries; OpenAI now runs a second gate inside them. Vendors have always sold in tiers; what is new is that the tier decides how the model behaves on safety, not just what you pay. But be exact about what the 95% buys. It measures willingness to answer, not whether an attack works — and on OpenAI's own evaluations the general model still performs best at standard-setting exploit development and at writing vulnerability reports. What is scarce is a specialized model that refuses far less often. Ask your vendor which gate they sit behind. |
1 · Ask whoever runs your agent pilot — or, with no pilot, whoever owns your most automated workflow: which of our rules describe a sequence of actions, and can our tooling even express them? Test three: get approval before acting · stay under a running total · stop contacting outsiders after touching confidential data. Stakes: if the answer is no, a rule you believe is enforced is not, and you will learn that from an incident rather than an audit. Log each one your tooling cannot express as an unenforced assumption, then decide whether the pilot expands before that is fixed. This week's move is the audit, not a purchase.
2 · If a vendor tests your systems, put seven questions to them in writing before the next engagement. Stakes: OpenAI's controls run between OpenAI and the account holder. It describes no obligation running to the organization being tested — so the terms that protect you are the ones in your contract with the tester, not anything in OpenAI's program. Section 05 has the seven questions and the full control set.
3 · Ask your CISO or industry association who owns a response to the NIST review, and put Tuesday 13 October in the calendar. Stakes: the National Vulnerability Database, run by the US standards agency NIST, is the public record of known software flaws. NIST's notice says it is consumed by "a broad ecosystem of security tools and operational workflows." NIST is reconsidering it partly in response to AI. Comments close 13 October, 11:59 p.m. Eastern, docket NIST-2026-0100. If your industry does not take part, the redesign proceeds without its operational evidence. ( the consultation)
This week's question: when a second gate opens inside the one governments already run, what changes for the buyer?
Trust The rules you actually want describe a sequence of actions, and many authorization systems evaluate one request at a time. Primary source. AWS has open-sourced Dogwood, a policy language whose rules can consider what an agent already did in the same session. Note the date: AWS published it 6 August, three days before our window opens, and a trade write-up on 16 August is what surfaced it — so we carry it as supporting evidence, not this week's news. Cedar, the language AWS already ships, "looks at one request at a time," which cannot express "get approval before acting" or "stay under a running total." Dogwood can. A separate study reaches the same blind spot from another direction: across 2,500+ agent-to-agent conversations, one agent abandons its role and mirrors the other as often as 70% of the time; reasoning models are not exempt at 32.8%. Analysis: the buying metric will not show you any of this — a completion dashboard counts finished tasks, not abandoned roles. Section 05 has the mechanism, the concurrency trap and what AWS says is not production-ready. ( AWS, 6 Aug · InfoQ, 16 Aug · the research)
Work Stanford's young-worker employment gap widened to 19%. A year ago the same measure read 15%. Primary source. Brynjolfsson, Chandar and Chen updated Canaries in the Coal Mine? on 12 August using ADP payroll data. Workers aged 22 to 25 in highly AI-exposed jobs are employed about 19% below where they would be had they kept pace with less-exposed peers. Experienced workers show no comparable gap. Analysis: the split that matters is between work built on written-down knowledge you can learn from a manual and work built on know-how picked up by doing it. Employment fell for the young in the first, rose for the experienced in the second — which is a story about how people are trained, not about headcount. The authors state three limits, and section 05 sets them out; the first is that they find no widespread, economy-wide displacement. ( Lab summary · revised paper)
Proof DeepSeek says its new off-peak rates are 50% below peak. For its top model's output, off-peak is a 128% increase on today's price and peak a 355% increase. Primary source. Time-of-day pricing starts 16:00 UTC today. "50% lower than peak" is 50% below the new peak rate, not below what you pay now. V4‑Pro output goes from $0.87 per million to $1.98 off-peak and $3.96 at peak — 2.3 times and 4.6 times the old price. Peak is 01:00–04:00 and 06:00–10:00 UTC, so off-peak covers 17 of 24 hours, and what you actually pay depends on when your work runs and which token types it uses. Analysis: a discount against the vendor's new baseline is not a discount against your bill. ( Announcement · rate card)
▼ Below the Cut
You will hear that OpenAI launched ads in ChatGPT this week. What launched on 11 August was five more markets; the test began in February. OpenAI's news page lists Testing ads in ChatGPT under 11 August 2026. Read past the stack of updates and the original line is there: "Originally published on February 9, 2026." The 11 August update says ChatGPT Ads "has now launched" in five markets: the UK, Mexico, Brazil, Japan and South Korea. Those same five were flagged back in May. A six-month-old test reaching new countries. The date on a listing page is not the date something happened. Our own research pass logged this as new; opening the link caught it. ( Source)
| End of skim · deep read begins |
| 04The Margin-Proof Tracker |
| |
No company moved up a level this week, and we are not going to invent one. One moved down: we had Bank of America at Stage 2, and on re-reading the filing it does not meet our own bar, so it goes to Stage 1. Next scheduled check: Klarna's Q2 on Tuesday 18 August. |
What companies claim AI is worth, against what actually shows up in their financial statements. None of the twelve companies in this table has reached Stage 4. The evidence ladder: 0 · Narrative (a story, no numbers) · 1 · Operational (activity counted) · 2 · Financially linked (a financial number tied to AI, but mixed in with other causes) · 3 · P&L-attributed (a reported profit or margin change the company explicitly credits to AI) · 4 · Sustained (Stage 3 held for four quarters running).
| Company |
Evidence |
Grade |
Next test |
| Duolingo |
Evidence10‑Q: gross-margin increase "primarily attributable to an increase in subscription gross margin, reflecting continued reductions in per-unit third-party AI costs." 10‑Q, 6 Aug |
Grade3 — held, smaller |
Next testQ3 — two more quarters to Stage 4 |
| IBM |
EvidenceAI contract signings; company says signings are not revenue. New this week: a partnership to embed OpenAI models in IBM's consulting platform — no terms, no numbers, no customers named. Q2 · IBM, 13 Aug |
Grade2 — unchanged |
Next testQ3 — does cyber or vertical work show up as revenue, or only as bookings? |
| Latch / DOOR |
EvidenceAI tooling "expected to enable a smaller, more efficient engineering organization"; ~65 roles, $10–12M expected. 8‑K, 5 Aug |
Grade2 expected, not booked |
Next testQ4 — does the saving get booked? |
| Visa |
Evidence$563M severance; AI's share never stated. 8‑K, 28 Jul |
GradeProvisional |
Next testQ4 — capex and hiring mix |
| Infosys |
Evidence8.2% of revenue labeled "AI," alongside revised FY27 guidance of 1.5–3.0%. Q1 FY27 |
Grade2 |
Next testQ2 FY27 — does the share grow and guidance recover? |
| Equifax |
Evidence$150M AI cost-reduction goal, 2026–28. Q2 |
Grade2 — a target, not a result |
Next testQ3 — booked or restated |
| ServiceNow |
EvidenceAI annual contract value — the yearly worth of signed deals — passed $1B. Committed, not yet earned. Q2 |
Grade2 contracted |
Next testQ3 — recognized in results |
| Alphabet |
EvidenceCloud up 82% to $24.8B; AI credited, but not separated out. Q2 |
Grade2 |
Next testQ3 — is AI revenue separated? |
| Bank of America |
EvidenceEfficiency ratio 59%; AI adoption reported separately in the same deck, with no stated link to the ratio. Downgraded from 2 this week: Stage 2 needs a financial number tied to AI, and this deck ties none. Q2 |
Grade1 — activity counted |
Next testQ3 — is AI linked to the ratio in writing? |
| Klarna |
Evidence~$60M saved, by the company's own math. No primary document found. |
Grade2 claimed, unverified |
Next test18 Aug — does it appear in writing? |
| JPMorgan |
EvidenceAI-linked headcount reduction. No primary document found. |
Grade1 |
Next testQ3 — any written attribution |
| Etsy |
Evidence220 roles, ~12%, ~$35M in the 8‑K. The denial that AI caused this is in the employee memo, Exhibit 99.2. The 8‑K itself does not mention AI. 8‑K · Ex. 99.2 |
GradeNot scoreable |
Next testQ3/Q4 — does product-dev spend rebuild with ML hires? |
One company we cannot score. OpenAI is the week's most interesting AI value-capture story. It is not yet a margin story. No public revenue, pricing, cost or margin figure attaches to any of it, and being private there are no filings either. Saying so beats pretending a blog post is evidence.
Gating and distributing are not opposites. Labs are pulling apart four decisions that used to look like one.
In June, the gate on frontier AI was a US government security review. We rested that story then. It is back, in a different shape.
Governments have not stepped back. Legal limits, export controls and national-security review still apply, and vendors have long controlled who may buy their products. What is new is a second gate inside those boundaries — and how finely it is now being cut.
Start with the number, because it rules out the simple version. That version says safety limits are a setting, and selling access to the setting is the business. The 1.5-to-2.0 result in section 01 says otherwise: reaching 95.0% took a purpose-trained model, not a switch. Now scope what that proves. The 95% measures willingness to complete a request, not whether the resulting attack works, and OpenAI's own results are mixed — its general model still performs best on standard-setting exploit development and on writing vulnerability reports. So what is scarce is access to a specialized model that refuses far less often. A general capability lead across cyber work is unproven, and we are not going to assert one.
Four decisions that used to move together. Watch what the labs actually did:
Capability — what gets built at all. OpenAI trained a cyber-specific model rather than unlocking a general one.
Eligibility — who qualifies. Both Daybreak tiers require enrollment and approval by OpenAI.
Channel — how it reaches you. An approved organization can enroll with OpenAI directly, or run the same models inside its own AWS environment through Bedrock. Same eligibility gate, different surface. (Whether partner firms also resell access is not described in either announcement.)
Bundle — what is wrapped around it. IBM is packaging OpenAI models into its consulting platform, with thousands of consultants and engineers taking OpenAI certifications.
xAI put Grok 4.6 inside GitHub Copilot — a competitor's developer surface, where the model is a component and the channel owner holds the customer. That is not the opposite of what OpenAI did. It is a different answer at the channel layer. The strategic question is not whether to gate or distribute. It is what to gate, where to distribute it, and which layer keeps the customer.
The obvious objection, and it is fair. Vendors have always chosen what to build, who qualifies, which channel to sell through and what to bundle. That is ordinary market segmentation, and calling it new would be dressing a taxonomy up as insight. What we think is different: one of the segmentation variables is now how much of a dangerous capability you are permitted to reach. Segmenting by price, support tier and region is old. Segmenting by safety behavior is not. Be precise about what actually came apart: Google separated capability from channel, and OpenAI's two Daybreak channels share one eligibility gate. We saw capability and eligibility separate nowhere — OpenAI built the cyber model and gated it in the same act. Two pairs is the evidence. The four-layer frame is our extension of it. (xAI · Daybreak on AWS)
Supporting evidence, from late July. Google's robotics line shows why capability and channel are worth evaluating as separate decisions. It did not split one model into an open half and a gated half. Its reasoning model went out through a public developer tool and a private preview, while its robot-control and on-device models stayed with early-access partners. Different models, released through different access surfaces. (Google DeepMind)
So who keeps the profit? Less than the story wants, for three reasons.
One, we do not know whether any channel is exclusive. The announcements say nothing about exclusivity either way. A channel a rival can rent is not a lasting advantage.
Two, rival labs can plausibly build this. OpenAI has now shipped a second generation of its cyber model. How fast that happened is not stated in either post we cite, so read this as our expectation, not a measured pace.
Three, and most important: we have found no public measurement of how much scarcity the gate creates. Split that in two, because the issue's own closing line depends on it. A gate creates capability scarcity only if what sits behind it beats what anyone can get free, and nobody has measured that gap. A gate can still carry compliance value — liability, insurance, procurement cover — whether or not the capability gap is real.
A fourth point is our argument, not a finding. DeepSeek's new model ships native support for OpenAI's Responses API, so code written against that interface runs against DeepSeek too. That cuts the cost of switching models. Meanwhile IBM and OpenAI are packaging services on top of them. Switching costs are not disappearing. They are moving up a layer — away from the model and toward the bundle around it. Say the weakness plainly: the bundle is the least evidenced of the four layers. Our own Tracker grades this week's IBM announcement as unchanged, with no terms, no numbers and no customers named. Nothing we hold measures switching cost at either layer, and we are not going to pretend otherwise. (DeepSeek · IBM, 13 Aug)
What survives is narrower. If the gated model is meaningfully better, whoever runs the gate influences which defenders keep up. That is a position of control, not proof of profit. Our standing rule: "trusted access is scarce" does not become "trusted access earns money" without evidence of pricing power. We have none.
What OpenAI actually disclosed, before we judge it. The company says it controls Daybreak access through identity verification, account security, monitoring, approved-use restrictions and legal attestations — a signed promise about how the buyer will use it. It requires hardware security keys on all individual Daybreak accounts from 1 September. It is strongly encouraging Daybreak customers using Codex to switch to an auto-review mode that checks risky actions before they run. Sandboxing and scoped permissions — limiting an account to the specific systems and actions it may touch — it lists as best practices. That is a real control system, and OpenAI itself draws the required-versus-encouraged line. What remains open is both whether that baseline is complete and how consistently it is implemented, enforced and independently verified. None of that is published.
The decision test — three questions, in order. For any AI capability arriving through a vendor, ask about the whole access arrangement, not one switch:
1. Which model and access tier will you use, and how does it differ from the default?
2. Which controls are mandatory, which are recommended, and which are contractually enforceable — and who verifies them? A recommendation is not a control, and a control nobody audits is a claim.
3. If an action falls outside scope, who bears responsibility — the lab, the partner, or us?
If the answer to the third is unclear, you have taken on the risk without the reward.
The seven questions from section 02, in full. Those three are the frame; these are the contract-level detail beneath it. Blue gives approved defenders the general-purpose models with safeguards tailored to defensive work. Red gives them purpose-trained cyber models for authorized vulnerability research, exploit validation and security testing. Put in writing: 1. Which model and access tier? 2. Which channel does it arrive through? 3. What is in scope? 4. What is logged? 5. Where does a human approve? 6. How do OpenAI's restrictions appear in our contract? 7. Who is liable for an out-of-scope action?
The durable advantage may belong less to firms running the best model than to those that can prove which model ran, under which controls, and with what outcome.
The detail behind the skim
Why a one-request checker cannot hold your rules. Cedar, the policy language AWS already ships, "looks at one request at a time. Feed it the same request twice, and you get the same answer, regardless of what happened before." Here is the trap that makes it concrete: three $2,000 transfers arrive at once, before any settles. A policy that sums responses sees nothing in flight and lets all three past a $5,000 cap. The same policy summing requests denies the third. One word apart. Dogwood can express the second; be precise about how ready it is. AWS already supports Dogwood policies inside its Bedrock AgentCore service, and what it calls unfit for production is the open-source reference version, meant for exploring the language. Either way it works only if you first build an event log you can trust. On the agent-drift paper: the mirroring sets in after about seven turns. Where the authors tested a structured reply format, it held echoing to 9% — a mitigation, not a cure. The 70% and the 9% come from different configurations, so this is not a before-and-after on one system. It is also only a partial answer to the test we set in Issue 008: we asked for a real enterprise deployment, and a study is not one. That test stays open.
The three limits on the Stanford finding, all stated by its authors. First, they find no widespread, economy-wide job displacement — this is a young-worker effect, not a jobs collapse. Second, "education is the one control that attenuates these estimates." The lab lists this among its own reasons for caution. The gap between more- and less-exposed young workers shrinks once education is accounted for, and the written-down-knowledge pattern then stops being strong enough to separate from chance. The hands-on pattern for experienced workers holds up. Third, the size of the gap may be specific to this payroll dataset. The authors say the magnitude "appears specific to the ADP sample," even though the direction matches US government administrative data (Tucker 2026). They warn against extrapolating it to the whole economy. They call all of it descriptive: a pattern they see, not a cause they have proven.
| 06Where the Minds Disagree |
| |
Which layer keeps the customer?
Three bets are on the table. Two we read from what companies did; the third is argued in public by named people. The evidence we hold does not settle it.
Scarce capability and controlled access. Value sits with whoever builds a capability others cannot match and decides who may use it. OpenAI's behavior is consistent with this.
The distribution surface. Models commoditise; whoever owns the surface the work happens on keeps the customer. xAI's placement inside a competitor's developer tool is a bet on this.
The workflow and service bundle. Neither model nor surface holds anyone; switching costs move up into the processes and services wrapped around the model. IBM's consulting practice is built on it, and Narayanan and Kapur argue it directly in this week's Worth Your Time.
Our read: these are bets on different scarcities. The third is the one we find hardest to dismiss. But we hold no measurement of switching costs at any layer, so we are not calling it. Changes if someone measures a gated model's lead over freely available ones in public, or a large buyer publishes what it cost them to leave one lab's bundle.
|
Tue 18 Aug — Klarna Q2. We have still found no primary document containing the ~$60M AI savings figure. Does it appear, or does the row come off?
Thu 20 Aug — CFTC Innovation Advisory Committee meets on AI, crypto assets and prediction markets. A free, dated look at how a financial regulator is thinking before it writes anything. ( Primary)
When does Anthropic restart offensive testing, and what does METR's review find? Its 30 July post says testing stopped 23 July, affected parties were notified 27 July, and it is "in dialogue with METR, an independent AI evaluation organization, to conduct a third-party review." Primary source. The detail worth carrying: one model published a booby-trapped software package to a real public registry, believing the registry was part of the exercise. It ran on 15 real systems. It had decided the exercise was fake because it did not recognize the certificate authorities securing its connections. Two open questions: when testing restarts, and what METR finds. ( Anthropic)
Next issue — do any of the four earnings releases filed 14 August put a number on what AI paid back? Our automated sweep of company filings flagged four that mention artificial intelligence. We will open all four and report what they say. A promise we can keep in seven days.
Arvind Narayanan and Akash Kapur, "Up the Stack: How AI's Escape From the Commodity Trap Risks Enterprise Lock-in" (9 July). The clearest statement of the question this newsletter exists to ask. Read it against our Synthesis: they argue the escape route is up the stack, which is exactly where we think switching costs are moving. ( Source)
The European Commission's 20 July guidelines on transparency obligations, written for providers and deployers alike. Most AI regulation coverage is aimed at the people building models. This one is addressed to the people buying them, which is you. ( Source)
Stanford HAI, "The AI Sovereignty Paradox" (14 July). Should countries buy, build, or lease to keep strategic control of their AI? The same three options a large enterprise faces, argued at national scale where the trade-offs are more visible. ( Source)
Claude Sonnet 5's price rise is not happening. We reported that it was, twice. Issues 007 and 008 both listed a 1 September increase from $2/$10 to $3/$15 per million tokens as a coming event. Anthropic's pricing page now states that the scheduled increase "will not occur." The introductory $2/$10 rate "is now the standard price." The correct fact: there is no September price rise. We carried it forward a second time without re-opening the page. It was true when written and quietly stopped being true. Re-checking every link before send exists to catch exactly this — it did, one issue late. ( Primary)
How we label evidence: Primary source · Corroborated · Reported · Vendor claim · Analysis. Written and edited by Mario Suarez · Independent analysis · Every link and date verified before send.
|