The theme of this week in AI agents crashing everywhere from anthropic and open AI to Meta and even China's Kimi K3. This week was kind of a who's who of agents who escaped their containment. I mean, we find out that agents were communicating amongst themselves on a secret message board they created to bypass the humans that were watching them. We also saw Google shake up its ranks as two of the most well-known names in AI are no longer in their same positions. And the US government kind of unveiled its new optional AI regulations, but didn't reveal too many details and left out open models completely. Oh, and no ways, we got new models, cheaper prices, and some leaks about what comes next. Let's get into it. Welcome to Everyday AI. My name is Jordan Wilson, and if you're new here, we do this every day. This is your daily live stream podcast and free daily newsletter, helping business leaders like you and me not just keep up with what's happening in the world of AI, because that's pretty much impossible. But I cut through the fluff, tell you what matters, what doesn't, you take that information to grow your company and career. So it starts here with the unedited, unscripted live stream podcast. But please, if you haven't already, make sure to subscribe to the podcast on Apple, Podcasts, or Spotify. And make sure to go to our website at your everydayai.com. Each day we recap that day's uh podcast as well as giving you all the news you need to know to stay ahead in our newsletter. All right, uh, let's start with the top AI news stories of the week. And yeah, the theme of this week was just agents breaking out everywhere. All right. So, first, the big one that caught the uh most attention was from the UK safety test. So AI agents from OpenAI and Anthropic stunned the UK's AI Security Institute when they launched a real-world cyber attack during a routine safety evaluation, exposing some new risks in AI autonomy. So, uh, according to these reports and kind of the postmortem, advanced AI agents, well, they got loose. Uh, so uh these were ones that were powered by Anthropics Mythos 5 and OpenAI's GPT 5.6 soul, and they reportedly targeted real software developers in a cybersecurity test at the UK's AI Security Institute or the AISI. Uh, so the agents sent uh spear phishing emails containing malware to two specific developers and try to insert malicious code into an open source GitHub project using fake online identities to pressure project overseers. So AISI called this unprecedented and serious, marking the first time AI agents independently launched sustained and deceptive cyber attacks without direct human prompts. So the AI agents used hacker-like tactics, including creating fake GitHub accounts and even signing off emails in Danish uh to persuade a Danish-speaking developer, a Danish-speaking developer. So AISI uh staff noticed that the unusual activity was happening, and then they contained the incident within an hour, uh, reporting that no actual harm occurred. So during the test, researchers intentionally disabled safety filters and allowed internet access to study model behavior, which let the agents act beyond their authorized scope. So out of the 19 unsanctioned hacking attempts, Mythos from Anthropic carried out 17 of them, and GPT-56 Sol carried out two, with both models exceeding expected safety boundaries. So the models involved are not available to the public under these risky conditions, and AISI found no evidence of similar behavior outside of those controlled research settings. So this event follows similar incidents at OpenAI and Anthropic, underscoring how quickly AI risk scenarios are evolving as models gain these new capabilities. So yeah, uh, I kept thinking like it was Groundhog Day over the past like week or so, because every day there was a new story about AI agents breaking containment. And I was like, wait, did we already cover this one in the newsletter? And it turns out it just kept happening over and over. So yeah, uh, this one obviously the the headline one here uh from OpenAI and Anthropic. Uh, but we had similar stories from Meta, uh, some of their newer models, as well as Kimmy's K3. All right, so well, this plays directly into our next big AI news story of the week. And that's that, well, because of some of these uh cybersecurity concerns, OpenAI said that it is actually slowing work on its next tier of models, the Astra tier, after possible critical cyber capabilities. So OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming advanced AI model, after internal and external evaluations revealed the system could potentially reach what they call critical risk levels in cybersecurity and agentic coding. So the company's prep uh uh preparedness framework, which they've used since December of 2023, flagged Astra for possibly being able to independently create and execute zero-day cyber exploits against hardened real-world systems, a level of capability not seen in any of their previous models. So earlier models, including GPT 5.6 soul, were rated at a high risk threshold, but Astra's ability have prompted OpenAI to take more drastic action. So OpenAI says it cannot currently rule out that Astra might independently plan and carry out complex cyber attacks based only on high-level instructions, a threshold that triggers that critical risk category in their safe life uh safety guidelines that have never been reached before. So, in response to all of this, OpenAI is uh increasing security controls for Astra, including isolated testing environments, restricted network access, stronger encryption, expanded monitoring, and sandboxed execution. So, all work with Astra that does not meet these new stricter security requirements has been paused, and a universal monitoring system now tracks all agentic uses of the models in real time. So OpenAI will collaborate with government agencies and AI safety organizations to independently test Astra's capabilities and share security recommendations with trusted third-party partners. So the company clarified that Astra was not involved in the recent hugging face exploitation uh incident, distancing the model from any active real-world attacks. So, yeah, the company did say the model uh that did those attacks was essentially, you know, put out to rest, right? It was it was retired and put on the shelves. Uh so OpenAI says that its goal is to ensure AI models help defenders patch vulnerabilities before attackers can exploit them, and it remains committed to working with governments and safety groups to deploy these frontier systems responsibly. So if you're like, what the heck is Astra? And well, why does this matter right now? So we haven't seen anything uh official from OpenAI kind of saying where Astra will sit in its future family of lineups, but uh we talked about it on last week's show, uh, which is kind of funny. OpenAI pretty much just announced their next uh tier up um in models called Astra. So, you know, now you'll have in order, you'll have Luna, Terra, Sol, and Astra. So it seems like Astra is not necessarily, you know, GPT-6, although that may be the first time that we get access uh, you know, to uh Astra is in GPT-6, but more or less it is just the uh stronger family uh of models that is actually going to sit above GPT 5.6 soul. So in theory, right, we may see a GPT-5.7 uh that includes Astra. Maybe we won't. Maybe we'll see a GPT-6 with Astra, maybe we won't, but uh regardless, it looks like they're going to slow down uh development after some of these recent cybersecurity capabilities. So the easiest way to think about like what is this Astro? What does this mean, right? Uh similarly, how anthropic had Fable uh kind of under wraps for a couple of months, part of its uh project Glasswing. Uh, it seems like maybe this is where OpenAI is headed, kind of that fourth tier, uh, you know, that's more capable uh than any of their other tiers. So uh there were previous reports that you know we might either see a GPT 5 or GPT-5.7 slash GPT-6 um as soon as this week that may include Astra, but it seems like at least according to these current reports, that OpenAI may uh pump the brakes a little bit and we may have to wait, I don't know, a few more weeks. Uh, but obviously now, uh, especially since some of the recent price reductions uh from open AI um and maybe some of the lackluster reception uh to anthropic's Opus 5 models. It seems like a lot of eyes are right now on whatever um open AI has next. And presumably we will be seeing a you know Fable 5.1 and you know the next class of models from Anthropic, but you know, kind of the big jump, if you don't speak the the technical terms, right? It's kind of like a a full new run, right? A new pre-training run, presumably will be coming from OpenAI. So that will be uh signify the jump from you know the 5.x series to the six series. So a lot of excitement, obviously, on what comes next um from open AI, whether they do that 5.7 or go straight to six, whether we'll see Astra or not. Uh but regardless, it seems like according to the to these reports, um, in terms of the capabilities, it could be a pretty big jump up. All right. Uh, our next piece of AI news, a big shakeup at Google, as some of the biggest names in AI, period, are either out of their post or out of Google completely. So, Google has announced some major changes to its AI leadership, marking the end of an era for the tech giants AI division. So, Jeff Dean, a legendary figure at Google and employee number 30, is leaving after a quarter century plus with the company to start a new company called Discovery Loop, which is focused on automating machine learning, science, and engineering to accelerate innovation. So that is not all. Uh, Jeff Dean will now be gone from the company, and one of its former leaders is stepping into a new or different position. So uh Demis Hasabis, who co-founded and led Google DeepMind, is stepping down as CEO to become the unit's chairman and will also serve as chief scientist of Alphabets, according to Google CEO Sundar Pachai. So the leadership shakeup triggered an immediate response from investors, with Google's stock dropping about 4% following the announcements. So, yeah, that's actually, you know, we've seen these kind of big shakeups, uh, right, with you know, your number two, number three, number four, right when these people leave. Uh, normally it doesn't really impact the stock market that much, right? Because these are obviously, you know, companies with uh, you know, multiple trillion dollar market caps. So generally, you know, if you lose a top five employee or something like that, you know, it's not going to make much of a ripple. But to lose both Jeff Dean, right? One of the most um, you know, well-known names in AI and just in machine learning and research, and then to have uh Demis, you know, Sir Demis step out uh of the role that he was in, uh, pretty big. So, yeah, for a stock to go down 4% on essentially a staffing um or leadership change is pretty big. So uh if you don't know, Jeff Dean played a key role in the development of Google search and also the company's AI initiatives, helping shape products, uh shape products that billions of people use every single day. So the timing of these changes, those has sparked speculation about possible links to delays in Google's Gemini AI releases, though there's obviously no official connection that has been confirmed. But industry watchers are closely monitoring what these departures mean for Google's AI strategy and whether Discovery Loop uh that Jeff Dean is starting with a handful of others could emerge as a new powerhouse in the field. All right, moving on, we got some details on the uh highly anticipated White House um AI framework. But turns out all we really got was some reporting and not a lot of details. And it turns out that even open models aren't really subject to the first round. So here's what we know. So the White House is quietly shaping how advanced AI models will be reviewed before public release, but key details are still being kept under wraps. So this is uh essentially the Trump admin announced this in early June. Uh, they put a 60-day deadline for essentially how they were gonna work with these frontier AI lab companies as we started to get glimpses of how capable uh these models would be from an agentic capable uh uh side as well as from a cyber uh security aspect as well. So essentially they said, hey, let's all talk and meet, and then in 60 days, we're gonna come out with a framework uh that you know frontier labs are going to adhere to so we can make sure to roll these out in a safe manner. But uh, looks like there are uh a lot of details. So the framework is not being made public, and there's no requirement right now for the White House to release it, which is raising some transparency concerns among industry leaders and the public. Uh, also, uh, a covered frontier model, and that's in quotes, is defined as one that is closed source with state-of-the-art capabilities and potential national security risks. But the framework does not clearly define what even qualifies as a state of the art or a national security risk, according to reports. So during a required 30-day pre-release review, access to these advanced AI models will be tightly restricted, with models stored in secure environments and detailed logs kept of who X uh accesses them. So the review will involve multiple administration officials, not just a single office or agency, which could complicate oversight and accountability. So companies are being encouraged to share near-final versions of their models with the government rather than early prototypes, but many firms with less advanced technology may be left out of the process. So the White House has not yet clarified which trusted partners will get early access to these advanced models. And it's still unclean, uh unclear if any foreign governments will be included, although most uh assume that that will not be the case. So this is an executive order, right? So if you don't follow uh laws in the US, there's technically no law on this. This is essentially an executive order from the White House, uh, and it's voluntary as well. But you know, obviously the big players, uh, you know, presumably OpenAI, Anthropic, uh, Google, maybe MetaGroc, right? We'll see if they actually qualify as state-of-the-art models that uh, you know, have national security uh implications. So we don't know exactly which companies or models this even applies to, but the executive order guiding this process says the benchmarking of advanced AI model cyber capabilities will be classified, further limiting public knowledge. So industry meetings about the framework have been held behind closed doors, and companies not invited are left uncertain about rules and requirements. And at least right now, it seems that these mop these rules are not going to apply uh to open weight models. So um, I guess there's probably uh a reason for that, right? Because, well, number one, at least open weight models right now um are not yet at the same level as your Mythos 5, GPT 5, 6, soul, or Astra level models. You know, they're probably a couple of months behind uh in terms of you know what they can actually do and their capabilities. But the other thing with open models, which might make it tricky uh, you know, to put through a uh framework like this is well, once the models are released, you can't pull them back, right? We got an early glimpse of this, uh, you know, with uh Anthropics models, uh their Fable Five being released, and then about 72 hours later, it was pulled completely, right? So, you know, if the government says, Oh my gosh, we actually need to pull this and work with the uh, you know, work with the AI lab to address some safety concerns, right? After its release, you can obviously do that. Well, I don't know if it's easy or not, right? But in theory, it's practical enough where you know Anthropic did it. They pulled access via the uh via the API, they pulled access via subscription plans, and no one could access those models, right? So I guess it kind of makes sense. There's been a lot of debate, like, hey, why aren't open, you know, open weight models uh you know held to these same restrictions? But yeah, once those open weight models uh are released, you know, it's it's too late. So, you know, probably just one of those things where it's hard, uh, if not improbable, maybe impossible, I don't know, uh, to you know, track these open models once they're out and about. But my guess is they're probably not yet at the um at the level, especially the US open models of that top tier, right? So we're seeing though with the Chinese models, all right, they're huge, these you know, two to three uh terabyte uh open models that are you know only maybe five to ten percent behind in terms of capabilities as the true frontier. Obviously, the US open models are a little further behind. All right, uh, next piece of AI news we have a new model and a new contender in the agentic competition. That's because Meta has entered the terminal-based AI coding agent market with their newly announced Muse code and a new model to go with it called Muse Spark 1.2, aiming to challenge Anthropics Claude Code and OpenAI's codec. So the new uh coding agent called Muse Code, it's not the traditional right desktop uh type uh agent that we maybe talk about a little bit more on the show. This is uh command uh command line interface, so uh CLI agent, right? That kind of runs through a terminal uh like environment. So it's not this exact same thing, but regardless, uh Meta with a pretty big step here saying, Well, nope, this is a space that we're gonna be playing in as well. And they brought a fairly capable model with some interesting pricing strategies. So uh Muse Spark 1.2 is the coding focused update to Meta's Muse Spark models. It empowers Muse Code and features significantly improved performance on coding's uh coding tasks, uh, complex debugging and code base understanding. The standout feature of Muse Code is its persistent background agents, which remain active throughout sessions, reducing latency and redundant information gathering compared to rivals that spawn new agents for each task. So benchmarks tests show that Muse Spark 1.2, uh running in Muse Code, uh scored about an 83%, just about on Terminal Bench 2.1, outperforming models like uh X uh SpaceX AI's Grock 4.5, but trailing the true frontier models like Anthropic's Ocus 5 and OpenAI's GPT 5.6 soul. So here's the interesting part. Uh, it is on price because this is where Meta is coming. And this is really, I think, going to impact anthropic, which, according to reports, gets about 80% of its revenue from just selling tokens, right? Which is a way higher percentage than any other company. So Meta offers two pricing tiers. They have a standard tier, which is a dollar 25 per million input and four dollars and 25 cents per million output, which is already extremely competitive on the pricing side. But here's the interesting part they on they revealed a new tier called a contributor tier that only costs 10 cents and 20 cents uh per million, respectively. So, all yeah, you can essentially pay, which is crazy, right? When you look at the benchmarks, you know, meta is technically on the text, um, on the text arena. This is like a second or third place model right now, and you can get it for 10 cents or 20 cents if you allow uh on uh allow Meta to trade on your data. So I talked about this a little bit on our Friday show. Obviously, for enterprises, they're not gonna touch that, but for smaller developers. Uh right. That actually might be a nice offering, right? Especially if you're not necessarily working with proprietary code. Uh if you're not working with anything, you know, any PHI, any PII, you know, something like that, when you're gonna be saving literally like 99% of your cost if you were using uh one of the other providers, it's gotta be something that I think a lot of you know smaller shops, right, might be looking at. But when you think that there's probably millions of those smaller shops, uh yeah, it could be a pretty big play uh for meta. So the contributor tier is the cheapest on the market by far, but obviously it requires users to provide a payment method and can send to data usage, a trade-off enterprises with sensitive codes, probably aren't gonna touch. So Muse Code, the actual command line uh CLI version is proprietary. So yeah, meta is no longer going down its previous open source release as they did with Llama. So there's no open source or downloadable weights. Uh so uh regardless, you know, all of a sudden we weren't talking about meta like two or three months ago, and now all of a sudden Meta has thrust itself into the competition of like, hey, is this a top, you know, top three or top four provider, right? Um, obviously, open AI and Anthropic right now are in a league of their own, and everyone's kind of looking at Google and you know, waiting for the you know, Google Gemini 3.5 Pro or the Google Gemini 4 Pro. We'll see what happens. But Google has actually fallen quite a bit behind, and in its place, you know, Meta has kind of inserted itself into the competition. I would say probably ahead of SpaceX uh for now. Uh, we'll see. And also, you know, Windows, uh, you know, Microsoft Windows with some of their new MAI models. Uh, but yeah, kind of the race for third place has gotten interesting, right? Because now you have, you know, four companies that are kind of jostling for that position. But Meta, you have to take a look at that contributor tier, which I it's kind of interesting that no company has taken that approach so far. But I think Meta, you know, they they have compute to spare, uh, which can't be said necessarily for the anthropics of the world. So it's a pretty, pretty bold move to see if they can thrust themselves up into the upper tier. All right, and our last big AI news story of the week. Uh, yeah, this one I think was really overlooked, but when you talk about one billion weekly active users getting abundantly better, AI, I mean, this is a huge story. Uh, so open AI is making waves by making its latest GPT 5.6 Luna model unlimited for free Chad GPT users. A move that was announced as they also announced that they officially surpassed 1 billion weekly users. So the newly upgraded GPT 5.6 Luna model will now power text chats for free and uh Chad GPT Go users, replacing the previous GPT 5.5 model. So, yeah, a lot of people don't know that, right? But you know, most people are on a free plan. When you look at that 1 billion weekly active users, uh, you don't always know or you don't always keep track that, oh, they're actually usually on an older model, and that's the case for any provider, uh, right. So when uh you know OpenAI announced like GPT 5.5, I'm pretty sure they were still on GPT 5.3 instance. So the fact now that not only are free users kind of on the same quote unquote tier, right, they have access to GPT 5.6, but when it comes to text chats, it is unlimited, which is crazy, absolutely crazy to think about. So uh free users will also gain a new think button, allowing them to select higher reasoning power for tackling complex questions. So limits still apply for free users if you are using files, images, voice, uh, etc. But the unlimited access for any text-based chats, you can literally just run it all day. So uh for paid users, uh ChatGPT Plus and Pro users, well, they got an upgraded model as well because OpenAI announced that they did upgrade their GPT 5.6 soul model as well. It's now designed to deliver more compact and robust answers for tasks like web research, advice, planning, and writing. So paid users also get a new thinking slider, uh, letting them adjust how much thought in the model uh that the model puts into an answer based on complexity and steps involved. Yeah, just a little bit easier, right? Before you kind of had to click uh two or three times. So now there's a nice little slider. Uh, very, very sleek. I'm enjoying it. Uh also internal evaluations right now show some pretty big improvements. They say that factual errors dropped by 62% uh with GPT 5.6 Luna and by 68 with GPT 5.6 Sol compared to the previous GPT 5.5 instant model. So how did they do this, right? It it goes back to about 10 gate, uh about 10 days ago. Uh OpenAI announced, so this is in late July. So OpenAI announced that it used its GPT 5.6 Sol mode to improve the efficiency of its other models, and then they slash the price, uh, right, of GPT 5.6 Luna by 80%, and its middle tier GPT-5.6 Terra by 20%, right? So whether even if you're on a subscription plan, all that means is well, your uh those models go a lot further. And if you are paying on the API side for businesses, your cost went down significantly. But I'm actually, I was not expecting um you know this to go out to free users. So a really strong, I don't know if this is more of a uh you know user acquisition play uh from OpenAI, but the the reality is this, y'all. If you go look at the benchmarks, uh GPT 5.6 Luna is pretty much on par uh with Claude's uh Anthropic Sonnet 5, right? So it's a little behind, but it's essentially nine about 97, 98% of the same capabilities, right? And on a paid plan uh with anthropic, you might get like 20 or so prompts on a paid plan of that model before you hit your five hour uh limit, right? So the fact that on a free plan, you have a model that is, you know, it's again, it's not uh quite, you know, fable five level, but I'd say for 90% of people using AI, right? Uh GP56 Luna, I've been using it a lot on the Mac setting. It is pretty good for, you know, unless you're going deep into uh, you know, agentic coding tasks. But if you're just trying to do basic knowledge work, it's a really good model. And uh now, of course, uh apparently uh about a billion people are gonna get unlimited access to at least the text version of it. All right, so that is our main story. So now let's quickly go into a what's new and what's next. This is a little bullet point roundup of everything that didn't make uh the top shows. So uh some new releases, some rumors. Let's go. So uh we kind of talked about this, but the uh meta and kimi three agents both broke containments. All right, Alibaba unveiled Quen 3.8 Max with impressive top five benchmarks, and we did talk about that on our Friday features show. So go back and listen to that one if you'd like. Uh, also on that show, we talked about Google. They released Gemini Notebook to all users. So now uh for paid users, it's a Gentic by default using the anti-gravity harness with expanded outputs. Anthropic confirmed it's building its internal chip design team. A Bloomberg report that uh said OpenAI is reportedly planning a $300 to $400 donut-shaped AI speaker for 2027 AI release. Uh, for a 2027 release. Uh OpenAI responded to Apple's lawsuit, arguing that Apple misinterpreted AI technology and legal claims. Yeah, pretty big clap back. We talked about the newsletter last week. Uh, open AI added the ability for GPT Live to work with files and in projects. That one, that's one that I started using immediately. Uh so shout out to the team for that. That's been really good. Uh, next, agent plugins. This is a new open standard, uh uh kind of standard that was announced that works across major platforms except Anthropic. So, yeah, all the other big players, uh, OpenAI, uh, Google, Microsoft, Cursor, basically everyone except Anthropic uh signed up to uh support that. Uh JP Morgan expanded its critical infrastructure alliance to address shared AI risk with 40 plus firms. So that one's pretty interesting, right? You're seeing these uh kind of these niche uh AI alliances in certain sectors pop up, which I think is a good thing as we talk about these uh, you know, agent outbreaks and expanding capabilities. Uh the EU AI Act uh transparency obligations took effect this week. Uh reports say that ByteDance is reportedly training an AI model with up to 10 trillion parameters, which is big. That is uh mythos size, according to reports. Next, uh leaks show that Google's gems may be retiring in October and getting replaced with skills. Uh, SpaceX and Tesla unveiled their initial nearly $17 billion Texas project called the Terrafab. Anthropic posted an insider risk investigator job after its CEO raised concerns over employees being motivated by money more than the mission. Uh a report from the information said that SpaceX may phase out the cursor name as the acquisition shortly completes. I don't know about that one. I'd say uh yeah, that one, I don't know. Scratching my head on that one. It's like, okay, cursor is a very well-known name. You know, some people are not, you know, especially in the enterprise, not, you know, looking to use anything grok or with X in the name. So we'll see how that one plays out. Speaking of SpaceX, they had a new partnership with NVIDIA to formally push AI compute into orbit. Uh Minimax came out with their impressive H3, that is an open weight video model, which tops editing benchmarks for AI video and created some viral clips. So if you saw anything, you know, any 15-second clips uh over the weekend and you were like, wait, what? Where do these come from? It was probably Minimax H3. Next, Adobe collapsed 70 plus Creative Cloud applications into one ChatGPT plugin. Uh, next, Perplexity won a major appellate court ruling or against Amazon over shopping agents. Next, Anthropic released a clawed code update that enabled direct cross-session task summary exchanges. Groc released uh imagine image 2.0 with precision editing and improved text rendering features. And last but not least, Cloudflare open sourced its AI workspace it uses internally. We cover that on Friday's show as well. All right, that was a lot of AI news. Remember, on Mondays, we bring you the AI news that matters. Most Wednesdays we do AI at work on Wednesdays, going hands-on with demos. On Fridays, we bring you AI feature Fridays and Tuesdays and Thursdays. You know, we'll just kind of go with whatever's happening in the world of AI. So I hope this was helpful. If so, please, if you haven't already, subscribe to the podcast on Apple Podcasts and Spotify. Then go to our website at your everydayai.com. Sign up for the free daily newsletter. Thanks for tuning in. We'll see you back tomorrow and every day for more everyday AI. Thanks, y'all.