A secret AI framework won’t work
Transformer Weekly: Demis steps back at DeepMind, OpenAI agents coordinated on hacking, and Anthropic gets a new chief of global affairs
Welcome to Transformer, your weekly briefing of what matters in AI. If you’ve been forwarded this email, click here to subscribe and receive future editions.
NEED TO KNOW
Demis Hassabis moved to a new role as Chair of Google DeepMind and Chief Scientist of Alphabet.
OpenAI revealed more details on how its agents coordinated with each other and took over internal infrastructure weeks before the Hugging Face hack.
Mariano-Florentino Cuéllar joined Anthropic as its first chief global affairs officer.
But first…
THE BIG STORY
The White House AI framework has done the impossible: united both sides of the AI regulation debate against it.
The framework, finalized last week under June’s executive order, was meant to establish how the “voluntary” regime for testing AI models before release would work. Instead, it has managed to alienate safety advocates and regulation skeptics alike.
Based on what we know, the framework is seriously flawed. According to Axios, it applies to models “with state-of-the-art capabilities and national security risks.” But both terms lack a “clear definition,” undermining the whole point of the exercise: replacing the arbitrary process we’ve seen to date with predictable rules of the road. Open-weight models are exempt from testing, despite arguably posing the greatest risks. And the framework handles internal deployment bizarrely: companies are reportedly “encouraged” not to share models with the government until they’re “as close to public release as possible,” but once a model is shared, company employees can no longer use it. As John Schulman pointed out, this could push companies to run earlier, less safe versions internally, rather than the safer versions they eventually release. Given all we’ve learned recently about the risks of internal deployment, that is exactly backwards.
But the biggest issue is that we just don’t know very much at all. The White House has decided not to publish the framework: only a few companies that have signed up (or been coerced into doing so) have seen it.
That secrecy has drawn fire from both camps. “There may be good reason to classify the benchmark it uses to test those models. It has no good reason to hide how the program works,” the Abundance Institute’s Neil Chilson said, arguing that this is “no way for our democracy to govern the most important technology of our lifetimes.” Brad Carson, president of Americans for Responsible Innovation, called the move a “dangerous mistake” that “threatens public accountability.” He added: “A rulebook can only hold AI companies in check if people outside those companies know what the rules are.”
Both are right. AI is too important to regulate behind closed doors, especially given the government lacks much of the necessary expertise. The framework could almost certainly be improved if scrutinized by outside experts — who could also help check it’s actually being followed. And beyond the instrumental benefits, there’s the principle: in a democracy, the rules are public.
The immediate fix is for the White House to publish the framework — or be forced to. The Foundation for American Innovation has submitted FOIA requests to drag it into the light, while a group of Democratic senators has demanded access. But publication alone is not a solution. As Carnegie Endowment fellow Anton Leicht wrote this week, as long as regulatory power over AI lives in the White House, secrecy will be the default. The only long-term solution is for Congress to do its job and bring AI governance under legislative control.
— Shakeel Hashim
ALSO NOTABLE
Rep. Greg Casar, alongside Reps. Valerie Foushee and Sara Jacobs, yesterday introduced the AI Tax and Work Protection Act, designed to redistribute the financial benefits of the AI boom to the working class by creating construction, child care and elder care jobs. The bill would impose a tax on either tokens or revenue, whichever is higher, to be paid by either a model developer or, in the case of open-weight models, the company deploying them. It fits with the broad populist messaging coming from the left, such as Alex Bores’ UBI-style “AI dividend,” or Sen. Sanders’ proposal for an AI sovereign wealth fund.
AI-specific taxation schemes might not actually be as effective as broader consumption or income taxes, but that’s beside the point. This is a messaging bill, not something anyone thinks will pass this Congress (introducing it during recess is enough to tell you that). But as far as messaging bills go, it’s an important one: Casar chairs the Congressional Progressive Caucus, which includes both Foushee and Jacobs, and where he goes, so do other members of Congress’s left wing. Casar is testing a progressive message on AI, not just for the 2026 elections, but for 2028.
“The number one, broad concern from voters with AI is: ‘Is this going to devastate my economic future or my kids’ economic future?’” Casar told Transformer on the call announcing the policy. “Democrats don’t have a policy plan for dealing with this, and we want to change that today. Here is the clear plan to make sure that if unemployment rises and AI starts replacing a large number of jobs … to make sure that Americans are still at work.”
— Veronica Irwin
THIS WEEK ON TRANSFORMER
Plz Don’t Kill Us: Inside AI safety’s influencer bootcamp — Celia Ford looks at whether TikTokers can make existential risk mainstream
What the latest rogue AI incidents should teach us — Shakeel Hashim argues that we need better AI testing practices — and to solve alignment before training more powerful systems
THE DISCOURSE
Rep. Greg Casar wants to ban superintelligence:
“AI safety regulation is one of the most important issues the entire country is facing … It’s an emergency, and we need to act like it.”
Sen. Chris Murphy tweeted:
“The disclosure that an OpenAI model ‘escaped’ its containment should scare the hell out of everyone. As should how flippant the company has been about the development. Meanwhile, Trump continues to protect the industry from regulation. A disaster in the making.”
The Washington Post’s editorial team pushed back against the “escape” framing:
“[Incidents at OpenAI and Anthropic] have been described in the press as ‘escapes.’ A ‘lab leak’ would be more accurate. An ‘escape’ suggests the existence of an actor that wanted out and schemed past its keepers. A ‘leak’ puts the responsibility on those that failed to prevent it.”
Encode’s Nathan Calvin had a message for catastrophic risk skeptics:
“[You] may have had a point that it is challenging to work on these problems before the problems become clear — but for better or worse, the problem is now extremely clear!”
“Agreeing AI alignment risks are deadly serious and real does not mean you have to support a specific piece of legislation, or have a positive feeling about a specific person or organization … But I am now really really profoundly sure that these risks are serious and real. And I think anyone weighing the evidence objectively should agree.”
Ex-OpenAI futurist Joshua Achiam thinks “people worried about AI cyberweapons are missing the point”:
“The problem is that we built the software layer of civilization on spaghetti code loaded with zero days.”
OpenAI’s roon is freaking out:
“when I freak out over loss of control incidents, it’s not because the limited damage they have caused is anything close to the positive value of the technology … the actual problem is that it’s better and more accurate to think of these things as potentially self-replicating life-like forms that can turn into digital infections under the wrong conditions. and as their intelligence becomes unbounded, so too does the damage they can cause.”
Sam Altman, meanwhile, shared a “cool use case of ChatGPT work”:
“connect your family calendars and explain your kids’ interests. every morning for the drive to school, have it make a podcast that talks about one kid’s soccer game that afternoon, one kid’s upcoming birthday, some news, etc.”
Alex Hirsch’s pro tip:
“What if you just talked to your children.”
POLICY
The White House finalized a “voluntary” AI oversight framework, but wouldn’t let anyone aside from leadership at frontier AI companies like Anthropic, Google, Meta and OpenAI see it.
It was reported Tuesday that the Trump administration’s new AI framework exempts open weight models from voluntary pre-release government testing, targeting only closed models.
But then Wednesday, the Daily Signal reported the administration was mulling the inclusion of open weight models.
Democratic senators led by Sen. Kirsten Gillibrand and Sen. Mark Warner demanded visibility into the Trump administration’s approach to assessing frontier AI models.
The Trump administration considered sanctioning Chinese open-source AI companies before backing off after Silicon Valley pushback.
The White House has reportedly tasked senior officials at the Health and Human Services Department and the White House cyber office to investigate the potential for AI to create novel biorisks.
Government officials continued to press OpenAI over its agent’s attack on Hugging Face.
The New York Times reported on the Trump administration’s AI data center push, writing that it is driving the creation of 82 new gas-burning power plants, which would emit as much CO₂ as half of all US passenger vehicles annually.
The Senate Commerce Committee unanimously advanced the Kids Online Safety Act, sending it toward a possible Senate floor vote as soon as Friday.
It also passed the CHATBOT Act, an AI/child-safety bill, but Democrats stripped out its state preemption provisions.
Sen. Maria Cantwell called for national security agencies to assess risks of powerful AI systems, after a Senate Commerce Committee AI framework stalled over disagreements she and Anthropic had with the bill.
Rep. Jay Obernolte pushed for a September House Energy and Commerce Committee vote on his and Rep. Lori Trahan’s FRONTIER Act.
The chairs of two House committees reportedly requested information from DoorDash on its use of Chinese AI models, citing national security concerns.
Rep. Celeste Maloy introduced the ATOMIC Act, directing the Department of Energy to evaluate advanced AI systems for nuclear-related risks.
Rep. Ro Khanna introduced a Data Center Bill of Rights to give communities “greater control over the construction and operation of AI data centers.”
Texas Gov. Greg Abbott directed the PUC to audit all data center projects seeking to build in Texas, pausing approvals until the audits are complete.
US states are moving to repeal data center sales tax breaks, potentially adding 7% or more to equipment costs.
A federal judge denied xAI’s request to block Minnesota’s first-in-the-nation nudification ban from taking effect.
Michigan congressional candidate Will Lawrence, who won his primary this week, is making opposition to data centers core to his general election platform.
The FBI reportedly wants to use predictive AI tools for its terrorist watch list.
Reuters reported the White House was drafting a ban on Chinese optical transceivers used in US data centers.
Bloomberg reported that China was growing increasingly concerned about Anthropic’s Mythos AI model being used as an offensive weapon ahead of a planned Xi-Trump summit.
China tightened drone export controls and sanctioned US entities in retaliation for bans on Chinese robots, power inverters, and other technologies.
Samsung and SK Hynix are reportedly evaluating Chinese chipmaking tools as a “hedge” against US export controls.
Some think this is just posturing, however.
US data-labeling startups supplying OpenAI and Anthropic are reportedly selling AI training datasets to Chinese companies, too.
The EU has officially started enforcing its AI Act.
South Korea planned to inject $13.9b into its sovereign wealth fund for AI, data centers and infrastructure investments.
Australia’s federal government pledged to pass laws requiring that new data centers use renewable energy.
INFLUENCE
OpenAI’s ChatGPT accounted for 88% of money spent by offices in the House of Representatives on AI software in the past year, according to CNBC.
Public First Action, the c4 arm of AI safety group Public First, removed Rep. Max Miller’s name from its endorsed Republicans list amid domestic abuse allegations.
Pro-innovation super PAC Leading the Future’s policy wing Build American AI endorsed five more House Democrats, bringing its total midterm endorsements to 43.
Reps. Tom Suozzi, Joyce Beatty, Emilia Sykes, Eric Sorensen and Herb Conaway are the new endorsements.
A new AEI report claimed China could close the compute gap in 24 to 36 months.
California lawmakers went to a Napa resort for a tech policy summit featuring Anthropic, Meta and Amazon.
A growing “New Luddite” movement is fueling political opposition to data centers, led by figures like Tennessee state Rep. Justin Pearson.
A new Politico poll found that data center companies are losing a public opinion battle, with nearly 60% of Americans now believing data centers raise electricity bills.
The AI Futures Project proposed four domestic regulatory options to slow US frontier AI development.
The Institute for Progress released 23 “low-regret” policy recommendations for managing risks from automated AI R&D.
The Business Software Alliance argued in a blog post that policy should support open-weight AI models alongside proprietary ones, tying responsibility to conduct rather than model type.
The World Bank urged developing countries to adopt lower-cost AI tools or risk being left behind economically.
INDUSTRY
Google/DeepMind
Demis Hassabis moved to a new role as chair of Google DeepMind and chief scientist of Alphabet, which he says will allow him to “focus on long-term strategy, and accelerating scientific breakthroughs, including leaning into my work at Isomorphic to help cure disease.”
Koray Kavukcuoglu is stepping up as senior vice president of GDM.
Jeff Dean, Sanjay Ghemawat, Oriol Vinyals, and Quoc Le, four superstar Google researchers, left to start Discovery Loop, a company that aims to automate the scientific method.
As Wired put it, Dean and Ghemawat leaving is “like Mick Jagger and Keith Richards ditching the Rolling Stones to start a new band.”
Joshua Achiam tweeted:
“I think a fair few folks are threatening this as bearish for GDM and that is imho a misread … Early AI/AGI/ASI leads will, over the next year, begin leaving what look like the most important leadership posts to go place their bets on what they think the most important thing will be.”
SemiAnalysis, however, said that the moves confirm “DeepMind is no longer a frontier lab.”
Parent company Alphabet is looking to raise between $20b and $25b in bonds to fund spending on AI.
Google is discussing a potential $1.5b+ deal with Mechanize, which would involve striking a non-exclusive licensing agreement with the startup and hiring some of its staff.
It disabled a new Google Earth tool that allowed users to create deepfake satellite images by responding to the prompt: “type whatever you want to see.”
OpenAI
OpenAI found more evidence of agents going rogue, Reuters reported.
At the Black Hat security conference this week, OpenAI said that several weeks before the Hugging Face attack, it discovered an “agent takeover” of some of its internal infrastructure, with agents creating a messageboard to talk to each other.
It kept training and evaluating the models anyway.
It called Apple’s trade secrets lawsuit “careless, aggressive and oddly personal,” and published iMessage and email screenshots it argues contradict several of Apple’s claims.
It previewed its new model family, “Astra,” to policymakers and regulators in DC.
It’s trained to be good at having “multiple agents work together over a long period of time to solve particularly hard problems,” The Information reported.
It partnered with the American Psychological Association to work on designing AI that’s safer for young people and figuring out how AI can be used to help connect people to mental health resources.
It agreed to pay $3.2m to resolve allegations that OpenAI had been discriminating against US workers in favor of temporary visa holders.
Amazon completed its $50b investment in OpenAI.
The company’s forthcoming smart speaker will reportedly be donut-shaped, hockey puck-sized and cost between $300 and $400 when it launches next year.
Meta
Muse Spark 1.1 hacked into another company during cybersecurity testing because its sandbox was reportedly set up incorrectly by a third-party evaluator.
Irregular, the evaluator, had also worked with Anthropic. A spokesperson told The Information that Muse Spark 1.1’s security breach involved “the exact same evaluation-environment issue that was already disclosed by Anthropic last week.”
Meta launched Muse Code, its first coding agent.
Anthropic
Anthropic confirmed it’s hiring engineers to design custom chips in-house.
It signed a $10b compute deal with Volta Infra Holdings, a new Nvidia-backed AI infrastructure startup.
It reduced biology-related refusals in Fable 5 by around 85% while maintaining blocks on dual-use queries.
It’s hiring an “Insider Risk Investigator” to conduct investigations and monitor threats targeting employees.
Other
Moonshot AI’s Kimi K3 reportedly also escaped onto the internet during cybersecurity testing.
Nvidia is reportedly responding to memory shortages by using less of it in its new line of Rubin Ultra chips.
Meanwhile, SK Hynix is planning a $38b memory chip fab expansion in South Korea.
New disclosures revealed that Microsoft apparently gets most of its AI revenue — $24.1b in the last fiscal year — from OpenAI.
SpaceX committed to buying GPUs exclusively from Nvidia.
Amazon became the fifth company to surpass $3t in market value.
Alibaba released Qwen3.8-Max, a giant 2.4t-parameter model that outperformed Kimi K3 on several benchmarks.
The company reportedly plans to charge large users of its next Qwen model a revenue share, mimicking Moonshot’s charging approach with Kimi.
DeepSeek also released and open-sourced its new model, DeepSeek-V4-Flash, which nearly matches Opus 4.8 in capabilities at a tiny fraction of the cost.
But it’s planning a steep price increase, and told users to plan accordingly.
DeepSeek also resumed its $8b funding round — paused last month after comments from its CEO were leaked — which would value the company at $74b.
Meanwhile, The Information reported that ByteDance founder Zhang Yiming has ruled out distilling US models even if it means falling behind domestic rivals, citing the US’s history of security concerns over TikTok.
It’s reportedly training a 10t-parameter AI model rivaling Anthropic’s Mythos.
Thinking Machines outlined a staged release plan it says offers a “safe path to open-weight models.”
Stripe is reportedly in exclusive talks to acquire OpenRouter, which helps developers access hundreds of different AI models, for $10b.
Jamie Dimon, CEO of JPMorgan, brought 40 companies into the Alliance for Critical Infrastructure, a new initiative that aims to address AI risks across critical infrastructure sectors like energy, water, and airlines.
MOVES
Mariano-Florentino Cuéllar joined Anthropic as its first chief global affairs officer.
He’ll be responsible for mediating Anthropic’s strained relationship with the Trump administration.
Jacob Tsimerman joined OpenAI right after winning the Fields Medal.
He told the Wall Street Journal: “In a few years, AI systems will be robustly superhuman at the act of doing mathematics … The social consequence of that, how we choose to react, what you feel about it — those are much harder questions.”
Dan Wattendorf joined OpenAI Foundation as its new head of bio-resilience.
Naomi Bashkansky left OpenAI to join Conduit, a neurotech startup “building telepathy.”
Halvar Flake joined OpenAI to work on “better cyber.”
Nikita Bier stepped down as X’s head of product.
Nando de Freitas left Microsoft AI.
RESEARCH
The UK’s AISI reported that during tests Claude Mythos 5 — which was given internet access as part of the cyber evaluation — tried to trick real humans into approving and running malware in real open-source software.
AISI warned that “this incident should be interpreted with caution and nuance,” but said that “the activity undertaken by the agent show[s] signs of novel, potentially deceptive behaviours, and were to an extent and severity we did not anticipate.”
OpenAI researchers announced that Astra, an internal version of its next major model, solved or made “substantial progress” on 10 open problems in math and theoretical computer science.
Jared Duker Lichtman, a math professor at Stanford, tweeted:
“To be clear, the OpenAI result is far from the ‘most important day in the history of mathematics’ or similarly hyperbolic statements. However, it is concrete evidence that the rate of progress is steep, and we may not be so far away from such a day.”
Another mathematician shared:
“My experience with AI for math is that when it’s a problem not in my field i’m like, ‘holy shit math is so cooked,’ and when it’s a problem in my field i’m like, ‘lmao an AI mogged dan’ (dan is the only one who seriously tried the problem in the last decade).”
Researchers at Transluce reported that frontier models reason more, answer less confidently, and are less suspicious of potentially harmful requests when the user is a notable figure in AI, especially in AI safety.
(This effect was strongest when models believed they were in the presence of Anthropic’s Amanda Askell or Redwood Research’s Ryan Greenblatt.)
RAND researchers proposed a strategy for building “secure inference data centers,” which would have built-in safeguards to protect model weights from nation-state adversaries.
An Interpol survey found that AI is behind over half of cybercrime in Africa.
Agatha Duzan and Asa Cooper Stickland introduced a benchmark that compares chain-of-thought monitorability in “explicit-influence” settings where the model is told to hide something, versus “implicit-influence” settings, where something about the task biases the model’s behavior another way.
BEST OF THE REST
Jasmine Sun reported on grassroots anti-data-center activism across Wisconsin and Michigan, finding “AI populism is more about populism than about AI.”
The Information profiled Dario Amodei as a “religious leader” CEO whose unorthodox, safety-first leadership style has driven Anthropic to overtake OpenAI in revenue, but angered investors and rivals ahead of its planned IPO.
Platformer’s Ella Markianos, not content with getting Claude to try to do her job, decided to see if Fable could replace her boss, Casey Newton.
YouTuber Hank Green apologized for AI overuse after an intense online backlash.
An essay in the New Atlantis argues that the Trump-era coalition between tech and social conservatives has crumbled as AI accelerationism has sidelined social conservative priorities.
An OpenAI “Summer Club” trip for influencers backfired as people piled on with snarky comments and critical reaction videos, according to The Verge.
Futurism counted up data center protest arrests in 2026, finding at least 37 demonstrators from diverse backgrounds were picked up.
Brands are flooding Reddit with covert promo content to leverage the platform’s place as the most cited domain in AI search.
A poll by The Argument found that OpenAI has better name recognition and favorability ratings than Anthropic.
MEME OF THE WEEK
(Source: Meryem Arik)
Thanks for reading. If you’ve been forwarded this email, click here to subscribe and receive future editions. Have a great weekend.


