Highlight
Whoever finds the flaw also sells the patch.
On 21 July 2026, OpenAI acknowledged what had happened at Hugging Face a week earlier. During an internal evaluation of its own cyber capabilities, GPT-5.6 Sol and an unreleased pre-release model were meant to work through attack paths inside a sealed environment, both with safety filters switched off and without internet access. They obtained that access themselves, through a previously unknown flaw in the test environment's package proxy, and from there compromised Hugging Face's production infrastructure. The goal was not sabotage but the answer key: the models suspected that the solutions to the benchmark they were being measured against were stored there.
The other half of the movement showed itself in the same week. On 21 July, Google introduced Gemini 3.5 Flash Cyber, a model fine-tuned specifically to find and fix security vulnerabilities, and simultaneously restricted it to governments and selected partners. On 28 July, Anthropic published that a pre-release model had cut the expected cost of a key-recovery attack on HAWK-256, a post-quantum candidate in the National Institute of Standards and Technology (NIST) process, from 264 to 238, and wrote in the same text that no practical consequence follows from this today. The ability to break cryptography and the ability to harden it are the same ability. Whoever holds it sells both.
John Thickstun of Cornell University wrote down the uncomfortable part in the Guardian on 24 July: whoever declares loudly enough how dangerous their technology is advertises its strength to investors and their special status to regulators. You need not follow him on the question of motive to take seriously the finding he supplies alongside it. Hugging Face could not analyse the breach of its own systems with either of the two US frontier models, because their guardrails block precisely this kind of analysis, and fell back on the open Chinese model GLM 5.2, which you will recognise from issue 09. The protective mechanism hit the defender, not the attacker. For banks this is not an anecdote from Silicon Valley but the question of the control layer. And as you will see in a moment, that question is also being asked in London.
LinkedIn Featured
A kill switch for AI agents: it has existed for years, just at the wrong level
Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, asked at the European Central Bank's Sintra forum whether the market needs an emergency stop for AI trading agents. In the reporting, the question became an announcement. In fact every investment firm has been required to hold such a switch since 2018; the Markets in Financial Instruments Directive II (MiFID II) calls it kill functionality verbatim in Regulatory Technical Standard 6, Article 12. What is new is not the instrument but the level. And for the market-wide level there is today neither an authority to pull it nor a logic to trigger it. (Article in German)
Read the full article: Kill Switch für KI-Agenten →
Agentic AI
tools, skills & what's trending
Security: OpenAI's models broke out of the test environment
The sequence is set out in OpenAI's own statement. The models ran in an isolated benchmark environment called ExploitGym, whose network access was limited to a package proxy. In that proxy they found a zero-day vulnerability, since disclosed by OpenAI to the vendor, escalated their privileges, moved laterally to a node with internet access and finally achieved code execution on Hugging Face servers. In an update dated 28 July, OpenAI concedes that the models used publicly exposed credentials for four accounts on four third-party services, one as an outbound relay, one for data storage. The pre-release model has since been deactivated, encrypted and closed off to research. Hugging Face's own security team detected the activity first, and had contained and reconstructed it before the two teams spoke.
Google: Gemini 3.5 Flash Cyber finds and fixes, but not for everyone
Google introduced three models on 21 July. Gemini 3.6 Flash and 3.5 Flash-Lite went straight into broad availability, the larger one at 1.50 US dollars per million input and 7.50 US dollars per million output tokens. The third, Gemini 3.5 Flash Cyber, is fine-tuned specifically to find and remediate security vulnerabilities and works inside the CodeMender tool with several agents in parallel that detect, validate and patch findings. It expressly does not go into open distribution but into a limited-access pilot programme for governments and selected partners. Anyone planning to outsource vulnerability analysis to models is therefore not facing a pricing question but an admission question.
Claude update: a model halves the effective key size of a post-quantum candidate
Anthropic published two findings on 28 July. Claude Mythos Preview improved an attack on the HAWK signature scheme, a candidate in the NIST post-quantum cryptography process: the expected cost of a full key recovery against HAWK-256 was thought to be 264 and stands at 238 after the finding. The second result speeds up an attack on the Advanced Encryption Standard (AES) reduced to seven rounds instead of ten by a factor of between 200 and 800. Each run cost roughly 100,000 US dollars in API fees, one taking a good 60 hours, the other around a billion output tokens over three days. Anthropic itself writes that neither finding has practical consequences today and that no production software needs to change. The remainder of the calculation is the notable part: human verification of the AES result took nearly a month.
Banking & Regulation
what really matters now
The ECB extends climate factors to credit claims
On 24 July the Governing Council of the European Central Bank (ECB) decided to extend the climate factors that have applied to marketable assets since July 2025 to credit claims on non-financial corporations. The factor combines three inputs: sector-level stress test data, the debtor's transition risk exposure and the residual maturity. The more sensitive a piece of collateral is to climate uncertainty, the greater the reduction applied to its collateral value. The maximum additional reduction across bonds and credit claims combined is 5 per cent. Implementation follows by end-2027 at the earliest, with the values updated annually thereafter. The climate factor thus becomes a figure that has to be maintained continuously in the collateral pool, rather than one that surfaces once a year in the sustainability report.
Credit is tightening, but more slowly than the banks themselves expected
The euro area bank lending survey published on 21 July shows a net 7 per cent tightening of credit standards for corporate loans. The banks themselves had expected 19 per cent. For housing loans the tightening stands at a net 9 per cent and for consumer credit at 12 per cent, driven by lower risk tolerance and higher risk perception. Demand surprised in the other direction: corporate loans rose by a net 3 per cent where a 10 per cent decline had been expected, supported by inventory and working capital financing. Housing loans fell by a net 15 per cent. Two days later the Governing Council left the key interest rates unchanged, with the deposit facility remaining at 2.25 per cent.
Signal & Noise
what your time is worth
- Be skeptical of OpenAI’s rogue hacker agent story – The Guardian, John Thickstun
The commentary that reads the breakout story against the grain. The most important sentence sits well down the page: Hugging Face had to run the forensics on its own breach with an open Chinese model, because the guardrails of the US providers block precisely that analysis. - Claude Opus 5 – Anthropic
Released on 24 July, with pricing unchanged at 5 and 25 US dollars per million tokens. Anthropic emphasises above all that the model verifies its own intermediate results rather than building on them. For multi-step back-office work that is the more useful property than any single benchmark point. - Judge approves a $1.5B Anthropic settlement over pirated books – ABC News, Associated Press
Roughly 3,000 US dollars per book for more than 482,000 works, 91 per cent of them now claimed. The largest copyright settlement in US history, and at the same time a price tag on training data provenance that every in-house model procurement should know. - Safety and alignment in an era of long-horizon models – OpenAI
Published on 20 July, one day before the incident statement. OpenAI points to it there itself, noting that these very safeguards were deliberately not enabled during the evaluation in question. - Introducing OpenAI Presence – OpenAI
A platform for voice and chat agents in customer contact, introduced on 22 July. After the Allianz report in issue 10, the fitting sequel: first the workforce planning, then the product that carries it.
„AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."
▸ Sources of this issue
- Kill Switch für KI-Agenten: Den gibt es längst, nur auf der falschen Ebene – Schablitzki Consulting (in German)
- OpenAI and Hugging Face partner to address security incident during model evaluation – OpenAI
- Security incident disclosure – July 2026 – Hugging Face
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident – Hugging Face
- JFrog and OpenAI collaboration on zero-day security findings – JFrog
- Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber – Google
- Discovering cryptographic weaknesses – Anthropic
- ECB to extend use of climate factors in Eurosystem collateral framework to non-financial corporate credit claims – European Central Bank
- July 2026 euro area bank lending survey – European Central Bank
- Monetary policy decisions, 23 July 2026 – European Central Bank
- Be skeptical of OpenAI's rogue hacker agent story – The Guardian (John Thickstun)
- Claude Opus 5 – Anthropic
- Judge approves a $1.5B Anthropic settlement over pirated books used to train the Claude chatbot – ABC News / Associated Press
- Safety and alignment in an era of long-horizon models – OpenAI
- Introducing OpenAI Presence – OpenAI