Your Secure and Responsible Technology Partner

Across the Industry Brief – Issue 18

July 27, 2026 · Policy, Regulation & AI Industry Developments


POLICY & REGULATION


Tags: News | United States
Date: July 22, 2026

White House OSTP Director publicly accuses China’s Moonshot AI of distilling Anthropic’s model to build Kimi K3

White House Office of Science and Technology Policy Director Michael Kratsios publicly stated on July 22, 2026 that China’s Moonshot AI distilled Anthropic’s Fable model to build its Kimi K3 model, characterizing it as large-scale covert industrial distillation aimed at stealing US technology. Kratsios separately alleged that Moonshot obtained restricted Nvidia GB300 chips accessed through Thailand. Part of the cited evidence for the distillation claim is that Kimi K3 sometimes identifies itself as Claude. The statement represents the first named US government accusation of this kind against a specific Chinese AI developer, marking an escalation in the intersection of AI competition and national technology policy.

The accusation lands at a consequential moment for both the technology and the geopolitics. Kimi K3 is a near-frontier open-weight model that approaches the benchmark performance of Claude Fable 5 and GPT-5.6 at roughly a third of Fable’s per-token price, and its release contributed to a selloff in AI infrastructure stocks. Distillation, the technique of training a model on the outputs of a more capable model, is difficult to prove because the evidence is inherently ambiguous, and the industry has been converging on defensive measures including query-pattern detection, rate limiting, and terms of service that prohibit training competing models on outputs. Kimi K3’s open weights were scheduled for release on July 27, days after the accusation, forcing organizations evaluating the model to weigh a contested provenance claim alongside their technical assessment.

For organizations, the accusation introduces a governance dimension to open-weight model adoption that extends beyond technical evaluation. Organizations planning to download and self-host Kimi K3 must now weigh a US-government-level provenance dispute and the associated legal and reputational considerations. Organizations should incorporate model provenance and intellectual property questions into their AI vendor and model selection due diligence, particularly for open-weight models subject to contested origin claims. The episode also signals that the US government is prepared to intervene publicly in AI model competition on national security grounds, which raises the policy risk profile of adopting models at the center of such disputes.

Read more →


Tags: News | Global
Date: July 15–27, 2026

China’s companion and emotional-support AI rules take effect as global regulatory frameworks converge toward the EU August 2 deadline

China’s rules governing companion AI and emotional-support AI systems took effect July 15, 2026, adding to a wave of international AI regulation reaching operational status through late July. The Chinese rules join a converging global regulatory picture that includes the EU AI Act’s transparency obligations becoming applicable August 2, South Korea’s enforcement having already begun, India’s draft Digital India Act published July 1 containing a statutory AI liability framework, and the UK’s AI Regulation and Safety Bill advancing through the House of Lords. The period marks a shift, described by multiple analysts, from AI regulation being theoretical to becoming operational compliance pressure across major markets simultaneously.

The convergence carries specific structural implications. The EU’s August 2 transparency deadline reaches most deployed AI systems, not only high-risk ones, since the AI Omnibus deferred high-risk obligations but left transparency requirements on the original timeline. China’s companion AI rules impose obligations on emotional-support and companion products that overlap with the chatbot-safety concerns driving US state legislation. The result is that organizations operating AI systems across multiple jurisdictions face overlapping but non-identical obligations arriving within weeks of each other, which rewards a unified compliance architecture over jurisdiction-specific point solutions.

Organizations deploying AI across international markets should treat late July and early August 2026 as a compliance inflection point rather than a series of isolated regional deadlines. The organizations best positioned are those that built a compliance architecture, comprising a system inventory, a jurisdiction map, an evidence log, and a documentation owner for each system, allowing new rules to be addressed by updating parameters rather than starting over. Organizations should prioritize the EU August 2 transparency obligations and assess exposure to China’s companion AI rules for any emotional-support or companion products, while monitoring the UK and India frameworks as they move toward enactment.

Read more →


Tags: Alert | Security | Industry
Date: July 22, 2026

ServiceNow AI Platform pre-authentication RCE added to CISA KEV after active exploitation of Fortune 500 workflow platform

A critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform, tracked as CVE-2026-6875, was added to CISA’s Known Exploited Vulnerabilities catalog on July 22, 2026 following confirmed active exploitation. The flaw allows unauthenticated attackers to escape ServiceNow’s script sandbox and execute arbitrary code remotely on a targeted instance. Searchlight Cyber researchers disclosed the vulnerability on July 14, the same day ServiceNow released patches for self-hosted instances, and threat intelligence firm Defused observed in-the-wild exploitation beginning around July 17 to 19. ServiceNow had pushed mitigations to hosted instances within 24 hours of disclosure and released patches to self-hosted customers throughout June.

The severity stems from the platform’s ubiquity combined with the zero-authentication exploitability. ServiceNow’s AI Platform processes more than 100 billion enterprise workflows annually and powers over 100,000 enterprise AI applications at 85% of Fortune 500 companies. Any unauthenticated attacker with network access to a vulnerable instance can trigger the flaw without credentials, phishing, or a prior foothold. Security researchers confirmed a second sandbox-escape gadget chain that bypasses defenses tuned only to the published proof of concept, meaning detection rules calibrated to the original exploit may miss active attacks. ServiceNow vulnerabilities are historically rare in the KEV catalog, which underscores the significance of this addition.

Organizations running self-hosted ServiceNow AI Platform instances must patch immediately if they have not already, given confirmed exploitation and the platform’s role as a central workflow and IT service management system with broad access across enterprise environments. The combination of ubiquitous deployment and pre-authentication exploitability makes this an emergency rather than a scheduled patching item. Organizations should also account for the confirmed second exploitation route when tuning detection, since signatures based solely on the published proof of concept are insufficient. Given ServiceNow’s central position in enterprise workflows, organizations should assess potential lateral movement and data exposure on any instance that was internet-facing and unpatched during the exploitation window.

Read more →


AI INDUSTRY


Tags: News | Industry
Date: July 24, 2026

Anthropic launches Claude Opus 5 ahead of planned IPO, extending its frontier model line

Anthropic officially launched Claude Opus 5 on July 24, 2026, introducing a new flagship model as the company prepares for a planned initial public offering. The launch was covered by Anthropic’s own announcement alongside VentureBeat, Bloomberg, TechCrunch, and Yahoo Finance, which noted the timing as the company positions itself for a public listing targeted for the fall. Opus 5 extends Anthropic’s frontier model line above the recently released Sonnet 5 and the Mythos-class Fable 5, continuing the rapid release cadence that has characterized the company’s 2026, following its confidential S-1 filing on June 1 and its $965 billion valuation from the June Series H round.

The release lands in an intensely competitive week for frontier models. It arrived alongside the White House distillation accusation against a Chinese competitor, the imminent open-weight release of Kimi K3, and a broader environment in which independent testers reported significant hallucination rates in competing open models. For Anthropic, shipping a new flagship immediately ahead of an IPO roadshow serves both a competitive and a narrative function, demonstrating continued capability leadership at the moment public-market investors are evaluating the company. Anthropic’s revenue run rate, reported at $47 billion in prior coverage, and its position as the most valuable pure-play AI company frame the commercial stakes of maintaining a visible capability lead.

For organizations, Opus 5 represents the newest option at the top of Anthropic’s model line and should be evaluated on its own merits against representative workloads rather than launch benchmarks. Organizations with existing Anthropic deployments should assess whether Opus 5 justifies migration from Opus 4.8 or whether the lower-cost Sonnet 5 remains sufficient for their use cases, consistent with the cost-governance discipline that has reshaped AI procurement. Organizations should also note that a pre-IPO release cadence may prioritize capability announcements, and should validate real-world performance and pricing stability before committing critical workflows to the newest model.

Read more →


Tags: News | Industry
Date: July 23, 2026

AMD and Anthropic announce $5 billion compute partnership as OpenAI unveils enterprise agent platform and $30 billion data center

AMD and Anthropic announced a strategic partnership on July 23, 2026 to deploy AMD MI450 GPUs in AMD’s Helios rack-scale systems, a deal reported at approximately $5 billion and 2 gigawatts of capacity, with the first gigawatt scheduled to come online in the first half of 2027 and AMD taking an equity stake in Anthropic. The announcement coincided with AMD’s unveiling of Helios, its rack-scale AI infrastructure platform, and with major partnerships involving Microsoft. On the same day, OpenAI launched Presence, a managed enterprise platform for building, deploying, and monitoring voice and chat agents, and announced a data center campus that could exceed $30 billion in investment.

The concurrent announcements illustrate the two dimensions along which the AI industry is now competing: compute infrastructure and enterprise agent deployment. The AMD-Anthropic deal is notable for diversifying Anthropic’s compute supply beyond its existing arrangements and for AMD’s equity stake, which deepens the financial entanglement between chipmakers and frontier labs that has characterized 2026. OpenAI’s Presence platform, which the company said handles a majority of its own phone support without human intervention, targets the enterprise agent market where Anthropic, Google, and Microsoft are also competing directly. The scale of the announced data center investment reflects the continued escalation of capital commitments to AI compute infrastructure.

For organizations, these developments carry two practical signals. The compute partnerships and data center investments indicate that frontier model providers are securing long-term capacity, which supports the predictability of model availability that enterprises depend on, though it also concentrates the industry around a small number of heavily capitalized players. OpenAI’s Presence platform adds another enterprise agent option to a crowded field, and organizations evaluating enterprise agent platforms should assess the competing offerings from OpenAI, Anthropic, Google, and Microsoft against their specific deployment, governance, and monitoring requirements rather than defaulting to an incumbent provider.

Read more →