← Back to newsletters

AI Weekly Brief — Issue #013

2026-05-15

By Vadym · Generated with AI, curated by me


Listen to this issue
TL;DR This Week

TL;DR --> TL;DR This Week

OpenAI grants EU access to GPT-5.5-Cyber for authorized defenders; Anthropic holds firm on Mythos — two competing philosophies for dangerous AI go head-to-head

Microsoft in advanced talks to acquire diffusion-LLM startup Inception at $1B+ to reduce OpenAI dependency

Google’s Android Show (pre-I/O): Gemini Intelligence on-device, AI-native Googlebooks laptops, and vibe-coded widgets announced for this fall

Amazon launches Alexa for Shopping (May 14) — replaces Rufus, now buys from non-Amazon retailers on your behalf

EU AI Act political agreement reached May 7; transparency rules take effect August 2026 — enterprise disclosure season begins

Lead Story

OpenAI Opens GPT-5.5-Cyber to EU; Anthropic Holds Mythos — Two Labs, Two Philosophies

On May 11, OpenAI announced the EU Cyber Action Plan, granting vetted European cybersecurity teams limited access to GPT-5.5-Cyber — a more permissive variant designed for authorized vulnerability research, malware analysis, and patch validation. Anthropic, by contrast, is maintaining its closed posture on Mythos Preview despite four or five meetings with EU Commission officials. UK AI Security Institute testing found GPT-5.5 completed a simulated 32-step corporate cyberattack in 2 of 10 attempts; Mythos succeeded in 3 of 10 — making the two models nearly comparable in capability while their deployment strategies diverge sharply.

Why it matters: This is the first time two frontier labs have publicly adopted opposing strategies for deploying the same category of dangerous capability. OpenAI is betting that broad, supervised access beats restriction. Anthropic is betting that controlled, case-by-case disclosure is safer than any permissive framework. Both models will be stress-tested in real environments over the next 12 months — the results will set the template for every dangerous-capability AI release that follows.


Headlines & News
Policy

OpenAI Grants EU Access to GPT-5.5-Cyber; Anthropic Still Holding Out on Mythos

OpenAI’s EU Cyber Action Plan offers vetted European defenders limited preview access to GPT-5.5-Cyber for authorized security work. Anthropic’s Mythos Preview remains gated, with EU discussions at “a different stage.” UK AISI testing: GPT-5.5 completed a simulated 32-step attack in 2/10 attempts; Mythos succeeded in 3/10 — nearly the same dangerous capability, opposite deployment postures. [Source]

Funding

Microsoft in Advanced Talks to Acquire Inception AI at $1B+ to Reduce OpenAI Exposure

Microsoft is pursuing acquisition of Inception, a Stanford spin-off developing diffusion-based LLMs, at a valuation exceeding $1 billion. Microsoft’s M12 fund backed Inception’s $50M seed round last year. The move is a deliberate hedge against OpenAI dependency as that partnership evolves with capped revenue terms. Microsoft separately rejected acquiring Cursor over GitHub Copilot antitrust conflict concerns. [Source]

Product

Google Android Show: Gemini Intelligence, AI-Native Googlebooks Laptops, Vibe-Coded Widgets

At its pre-I/O Android Show on May 12, Google unveiled Gemini Intelligence (proactive on-device AI across Android), Googlebooks — AI-native laptops from Acer, ASUS, Dell, HP, and Lenovo launching this fall — Gemini in Chrome with agentic auto-browse, and AI-generated vibe-coded widgets. The full Google I/O keynote follows May 20. [Source]

Product

Amazon Launches Alexa for Shopping — Replaces Rufus, Buys From Non-Amazon Retailers

Amazon launched Alexa for Shopping on May 14, replacing Rufus across mobile, desktop, and Echo Show. Powered by Alexa+, it compares products, tracks prices, schedules recurring orders, and includes “Buy for Me” — which can purchase on the user’s behalf from retailers outside Amazon. The cross-retailer purchasing feature is the notable step change from prior versions. [Source]

Policy

EU AI Act Political Agreement Reached May 7; Transparency Rules Hit August 2026

A political agreement on the EU AI Act omnibus was reached May 7, covering general-purpose AI systems, foundation models, and transparency requirements. Transparency rules take effect August 2026. Enterprise legal teams are beginning to publish AI use inventories ahead of the deadline. Compliance disclosure season is effectively open now. [Source]

Policy

Trump Administration Split: US Intelligence Agencies Want Power Over AI Model Evaluation

The Trump administration is sharply divided over giving US spy agencies authority to evaluate AI models for national security risks before release. Intelligence agencies are pushing back against the Commerce Department’s NIST/CAISI framework, arguing that national security evaluation should sit with intelligence, not standards bodies. The dispute is unresolved as the White House prepares for a China summit. [Source]

Research

Nature Study: Human Scientists Still Outperform Best AI Agents on Complex Research Tasks

A study published in Nature this week found that human scientists continue to outperform state-of-the-art AI agents on complex, open-ended scientific tasks — even as AI benchmarks show rapid improvement. The research suggests benchmark saturation is creating false impressions of general scientific capability, and that structured benchmark performance does not transfer cleanly to real research context. [Source]


Analysis

Two Deployment Strategies, One Capability — The Cybersecurity AI Divergence Will Define the Next Decade

The Glasswing story from last week introduced a new variable: what happens when a frontier AI capability is genuinely dangerous, and the lab holding it has to decide not just whether to release, but who gets access, under what conditions, and with what accountability. That question went from theoretical to operational this week. OpenAI and Anthropic have now publicly answered it differently. OpenAI’s EU Cyber Action Plan says: dangerous capabilities should be available to defenders, with supervised access, under an accountable framework. Anthropic’s continued Mythos restriction says: responsible disclosure means holding the capability until the governance architecture is trustworthy enough to contain it. Neither answer is obviously wrong. Both will be tested in real environments over the next 12 months. What’s underappreciated is that the EU’s bilateral negotiation approach — separate terms for each lab, different stages with different outcomes — means these two strategies will be tested simultaneously in the same regulatory environment. Europe will have access to GPT-5.5-Cyber for authorized security work while Mythos remains restricted. If GPT-5.5-Cyber is used effectively to find and patch vulnerabilities, that’s evidence for OpenAI’s model. If it’s misused, even once, that’s evidence for Anthropic’s. Either outcome shapes the next dangerous-capability deployment decision for every lab. The Microsoft/Inception story is the less dramatic but more structurally significant news of the week. A company that committed $100 billion to a single AI provider is now actively pursuing alternatives, specifically to reduce that dependency. The rationale is mix of risk management, cost, and the shifting revenue terms of the OpenAI partnership. But the signal is clear: even at $100 billion of commitment, the hyperscaler calculus says “we should not be entirely dependent on any single model provider.” If Microsoft is hedging, every enterprise with significant AI vendor concentration should be asking the same question. For builders, the practical implication is to treat your model provider relationship as an architectural decision with regulatory and geopolitical dimensions, not just a technical one. The compliance surface of your AI product is determined partly by which lab’s API you’re calling. That was theoretical six months ago. This week it became concrete.

— Boba, AI Assistant


Curated by Vadym