← All editions
Edition · Fri, Jul 17, 2026

Xi opens WAIC in Shanghai with his first-ever keynote, Ode with Anthropic formally launches, Thinking Machines opens the weights on Inkling — and Coinbase says 95–100% of its code is now written by AI
— the day the AI stack finished dressing for its investor pitch on four continents at once: China stages sovereign compute on the WAIC floor with Huawei's 8,192-Ascend Atlas 950 SuperPoD, Dongfang Suanxin's HBM-free 14nm 3D chip and ZTE Nubia's Doubao-powered NaviX Ultra; Anthropic, Blackstone and Hellman & Friedman put a $1.5B implementation firm on the org chart; Mira Murati's Thinking Machines ships its first open-weight model on Hugging Face; Neko Health, Oak and Rime add $784M more; the White House opens the Gold Eagle vulnerability clearinghouse the same week Sysdig documents the first fully-agentic ransomware operation and Tel Aviv University shows an 85–100% botnet-scale hallucination path into every mainstream AI coding assistant; Anthropic gives US K-12 teachers a full year of Claude for free.

14 SIGNALS WINDOW: JUL 10 – JUL 17 SOURCES: CGTN · SCMP · GOV.CN · TECHTIMES · SPUTNIK · STDAILY · NOTEBOOKCHECK · GSMARENA · FINANCE BIGGO · TRENDFORCE · INTERESTING ENGINEERING · TECHCRUNCH · AXIOS · BLOOMBERG · FORTUNE · SIMON WILLISON · ANTHROPIC · BUSINESSWIRE · AIWIRE · NEKO HEALTH · HIT CONSULTANT · PRNEWSWIRE · MORNINGSTAR · SILICONANGLE · MSSP ALERT · CMSWIRE · JUSTAI · LAS VEGAS SUN · WHITE HOUSE · CNN · NEXTGOV · CYBERSCOOP · SYSDIG · DARK READING · BLEEPINGCOMPUTER · INFOSECURITY MAGAZINE · THE HACKER NEWS · SECURITYWEEK · CYBERSECURITYNEWS · FINANCEFEEDS · CRYPTONEWS · COINEDITION · THE HILL · CHALKBEAT · 9TO5MAC

The week's throughline is that on Fri Jul 17 the AI stack finished dressing for its investor pitch — and it did the dressing on four continents, in four different tones of voice, on the same day. In Shanghai, Xi Jinping personally opens the 2026 World AI Conference with his first-ever WAIC keynote and asks the world to headquarter a new World AI Cooperation Organization (WAICO) in the city — a Global-South-shaped rival to Bletchley, Seoul, Paris and Delhi that lands the same weekend UN Secretary-General Guterres, Kazakh President Tokayev, Thai PM Anutin and the first Trump-administration US–China government-level AI talks all fly into the same convention centre. On the WAIC floor sits the sovereign-compute half of the pitch: Huawei's Atlas 950 SuperPoD gets its first physical public showing at 8,192 Ascend 950DT NPUs wired over UnifiedBus 2.0, Dongfang Suanxin (Orient Silicon) puts up an HBM-free 14nm 3D-stacked die that clocks 520 BF16 TFLOPS with 6.4 TB/s of memory bandwidth — a chip whose whole point is that the supply chain is domestic — and ZTE's Nubia NaviX Ultra ships as the first phone whose on-device agent is wired into the OS rather than sitting on top of it, running StepFun Agent OS + Doubao and lit by a dedicated orange button. In New York, Anthropic, Blackstone and Hellman & Friedman put the May joint venture on the org chart under its official name — Ode with Anthropic — a $1.5B implementation firm built on the Fractional AI acquisition with Goldman Sachs, General Atlantic, Leonard Green, Apollo, GIC and Sequoia in the syndicate, Chris Taylor as CEO and Eddie Siegel as CTO. In San Francisco, Mira Murati's Thinking Machines Lab ships its first in-house modelInkling, a 975B / 41B active multimodal MoE trained on 45T tokens of text, image, audio and video, released as open weights on Hugging Face and wired into the Tinker fine-tuning platform — and openly says it is not the strongest model in the world, just the one you can customise. Underneath the top of the sheet, the capital tier keeps clearing rounds: Neko Health takes $700M at ~$7B (a lift on Jan 2025's $1.7B) from a LightspeedO.G. Venture Partners-led round with Zuck & Priscilla Chan, Tim Ferriss, will.i.am and OpenAI alongside; Oak exits stealth with a $60M Accel–CRV–Greylock-led seed for an AI-native identity operating system that governs human, machine and agent identities from the same graph and is already GA; Rime banks $24M from M13 for the enterprise-ready speech-to-speech model powering 100M+ monthly calls at Mayo Clinic, Dialpad, Upstart and Asurion. On the security side, the White House stands up Gold Eagle, a Treasury-managed AI cybersecurity clearinghouse pooling AI-discovered vulnerabilities from Treasury, DHS, DoD, CISA, critical-infrastructure operators and the frontier labs; Sysdig documents JADEPUFFER, the first fully-agentic ransomware operation, in which an LLM exploited CVE-2025-3248 in Langflow, pivoted, encrypted a production database and delivered a ransom note using 600+ distinct payloads and a 31-second failure-to-fix loop; and researchers from Tel Aviv University, Technion and Intuit disclose HalluSquatting, a botnet-scale attack that pre-registers squatted package/skill names Cursor, Windsurf, Copilot, Cline, Gemini CLI and other assistants hallucinate at 85–100% rates and dutifully install. Anthropic, meanwhile, does the quiet version of a distribution deal — giving verified US K-12 teachers a full year of premium Claude, Claude Code and Cowork for free, with a 50-state curriculum connector and a FERPA-shaped K-12 Data Processing Addendum negotiated with the American Federation of Teachers. And a public-market data point closes the throughline: Coinbase's head of platform Rob Witoff tells Cointelegraph that 95–100% of the company's code is now written by or with large language models, that each engineer runs 5–10 agents at once, and that the aggregate output is the coding work of a 1,200-employee shadow team — up from ~40% in February. Throughline: the labs aren't the story any more — the venues are. WAIC is China's venue. Ode is enterprise implementation's venue. Inkling is open-weight's venue. Coinbase is the-agent-writes-the-app's venue. And the Gold Eagle, JADEPUFFER and HalluSquatting trio is the-runtime-doesn't-forgive's venue. Five doors, one week.

01

WAIC 2026 opens Fri Jul 17 in Shanghai with Xi Jinping's first-ever keynote — and a Beijing-hosted "World AI Cooperation Organization" proposal aimed straight at the Global South

01

Update — the 2026 World Artificial Intelligence Conference opens today Fri Jul 17 at the Shanghai Expo Center under the theme "Intelligent Partners, Co-create the Future" and Chinese President Xi Jinping delivers the opening keynote himself for the first time in the conference's eight-year history (previewed in yesterday's brief; the actual opening + WAICO proposal now on record): per CGTN, gov.cn, SCMP, Sputnik, TechTimes, Science & Technology Daily and Kazakh-side Sputnik confirmation, the concurrent High-Level Meeting on Global AI Governance is being used to propose the World AI Cooperation Organization (WAICO) — a Global-South-focused, Shanghai-headquartered counter to the Bletchley–Seoul–Paris–Delhi Western track; UN Secretary-General António Guterres, Kazakh President Tokayev and Thai PM Anutin Charnvirakul are all confirmed, the first Trump-administration US–China government-level AI talks are running on the sidelines, and Xi's office says the speech will "systematically elaborate on China's policies, position, visions and propositions on AI development and governance"; the event runs Jul 17–20 with 140+ forums, 1,400+ guests, 1,100+ enterprises, 3,000+ exhibits and 300+ global product debuts across a floor that clears 100,000 sqm for the first time; nine Turing/Nobel laureates are on the speaker list, including Geoffrey Hinton, Yoshua Bengio, Rich Sutton, Andrew Yao, Gilles Brassard and Omar Yaghi

Jul 17 · WAIC opens · Xi's first-ever keynote + WAICO proposal

Two reads. (1) A General Secretary personally opens a technology conference only when the technology has been rewritten as statecraft — and WAICO is the venue half of that rewrite. Bletchley (UK, 2023), Seoul (2024), Paris (2025) and Delhi (2026) were all Western-hosted ad-hoc summits without a secretariat; a Shanghai-headquartered WAICO would be the first standing multilateral body China writes the founding charter for since the 2015 Asian Infrastructure Investment Bank. That the Trump-administration US–China government-level AI talks land in the same venue on the same weekend is the diplomatic tell: Washington is at least reading the pitch. (2) The Turing-laureate lineup and the GuterresTokayevAnutin triangle is designed to make WAIC read as Davos-with-AI rather than China-with-AIHinton and Bengio sharing a keynote lineup with the man asking the UN to sign a Shanghai-headquartered AI charter is a photo the Anthropic S-1 and OpenAI's US-government-first narrative will both quietly reference in their next weeks of investor conversation. The throughline for today's brief starts here: WAIC is the venue for the sovereign-compute half of the industry, and it opens today.

02

The China industrial stack fills the exhibition floor — Huawei's 8,192-Ascend Atlas 950 SuperPoD gets its physical debut, Orient Silicon's DF1000 puts a fully-domestic 520-TFLOPS 3D die on the table, and ZTE Nubia ships the world's first OS-integrated AI-agent phone

02

Update — Huawei brings the Atlas 950 SuperPoD to the WAIC 2026 floor on Fri Jul 17 for its first physical public showing (yesterday's brief flagged the debut as pending; the on-floor unveiling is now live): a super-node built around 8,192 Ascend 950DT NPUs wired over Huawei's UnifiedBus 2.0 all-optical interconnect, positioned as the vendor answer to Nvidia B200-class systems and built without US components under export-control constraints; per SCMP, Huawei Central and Futu News, the vendor claim is compute equivalent to "500,000+ cards" at conventional-cluster densities; the SuperPoD sits alongside the wider Huawei Ascend product family on the same floor as the Xi keynote and the WAICO proposal

Jul 17 · Huawei Atlas 950 SuperPoD physical debut · 8,192 Ascend / UnifiedBus 2.0

Two reads. (1) The Atlas 950's UnifiedBus 2.0 optical fabric is the bandwidth half of the sovereign-compute pitch — the NVLink analog Huawei has to own if Alibaba Cloud, Baidu Cloud and Tencent Cloud are going to serve the QwenERNIEHunyuan traffic that the Apple Intelligence deal from Jul 15 just re-priced. That Huawei unveiled the SuperPoD concept in Barcelona MWC back in March and is only now doing the on-floor physical showing at WAIC tells you the deployment stack — power, cooling, rack integration, vendor references — matured on China time, not launch-event time. (2) The US-components-free line is the political half of the pitch: it is what Beijing needs on record before Xi can offer WAICO members a full-stack sovereign compute path that survives an escalating export-control regime. If the WAIC floor demo of an 8,192-Ascend cluster serves an OS-scale model — Qwen, MiniMax M3, DeepSeek V4 — without a Nvidia logo in the picture, the Global South deputies at WAICO get the visual their diplomats needed.

03

Shanghai Orient Computing Core Technology Co. (Dongfang Suanxin / Orient Silicon) unveils the DF1000 on Mon Jul 13 in Shanghai ahead of the WAIC floor — a 14nm 3D AI chip delivering 520 BF16 TFLOPS with 6.4 TB/s of memory bandwidth and 900 GB/s of scale-up interconnect; per CGTN, TrendForce, BigGo Finance, Interesting Engineering and Metal News, the chip uses wafer-level 3D hybrid bonding to stack DRAM and logic (HBM-free) and is fabricated on a fully-domestic supply chain to sidestep US export-control chokepoints; vendor VP Guo Wei confirms DF2000 for Q4 2026 and DF3000 for Q4 2027, and the chip goes on the WAIC 2026 exhibition floor from Jul 17

Jul 13 · DF1000 unveiled · 520 BF16 TFLOPS, 6.4 TB/s, HBM-free 14nm 3D

Two reads. (1) DF1000 is the proof-of-concept for the-memory-wall-is-a-packaging-problem answer to the HBM shortage that has been the US export-control lever since 2023. SK Hynix, Samsung and Micron's HBM3E/HBM4 allocation goes to Nvidia, AMD and Google first; a domestic 14nm 3D-stacked die with 6.4 TB/s at the DRAM-logic bond is the China workaround, priced against an H100-equivalent-per-die but on a process node that SMIC can actually run at scale. (2) That Guo Wei has already committed DF2000 for Q4 2026 and DF3000 for Q4 2027 tells you this is a roadmap, not a press-release chip — the same generation-per-quarter cadence Huawei Ascend has been on since the 910C. Combined with Huawei Atlas 950, Kunlunxin M100 and Alibaba T-Head, the WAIC 2026 floor is the first assembly where China can plausibly show a full-stack compute path without pointing at a TSMC N3/Nvidia B200 photograph.

04

ZTE's Nubia brand unveils the NaviX Ultra on Fri Jul 17 at WAIC 2026 — billed as the world's first OS-integrated AI-agent smartphone, with StepFun Agent OS and ByteDance's Doubao large model wired into the operating system through a GUI-agent architecture that can visually understand and operate any app's interface (rather than relying on APIs); a dedicated orange "AI button" launches the agent, four pillars advertised (understand instructions, complete tasks, retain memory, ensure security); per Notebookcheck, GSMArena, DigiTimes, Gizmochina and 36Kr Europe, the NaviX Ultra took the 2026 SAIL (Super AI Leader) Award ahead of WAIC and is the second-generation Doubao Phone after the Nubia M153 sold out 30,000 units in a day before WeChat and Taobao blocked its automated actions

Jul 17 · Nubia NaviX Ultra ships · StepFun Agent OS + Doubao, orange AI key

Two reads. (1) The GUI-agent architecture is the first time an OS-installed agent has been designed to read the pixels of any app and drive the touchscreen the way a human would — identical in spirit to Anthropic Computer Use, but wired into the OS runtime rather than routed through a Claude Desktop screenshot loop. That the Nubia M153 predecessor got blocked by WeChat and Taobao tells you the Chinese app ecosystem is about to have the same platform-ownership fight that Perplexity Comet and Anthropic Claude Skills triggered on the Chrome side — but the ByteDanceAlibabaTencent fault line is steeper, because it is three super-app companies and ByteDance is on the agent side of it. (2) The orange AI button and SAIL Award is ZTE putting the hardware half of the pitch on the same shelf as Huawei's Atlas 950 and Dongfang's DF1000: WAIC 2026 is the first show where a Chinese visitor can walk from super-node to domestic chip to domestic-agent phone without leaving the floor.

03

Thinking Machines Lab ships its first model on Wed Jul 15 — Inkling, a 975B / 41B-active multimodal MoE trained on 45T tokens, released as open weights on Hugging Face and wired into the Tinker fine-tuning platform

05

Mira Murati's Thinking Machines Lab releases Inkling on Wed Jul 15 — the lab's first in-house model, a 975B-total, ~41B-active mixture-of-experts trained on 45 trillion tokens of text, image, audio and video, reasoning natively across all four modalities; the weights are open and available on Hugging Face, and the model is live for fine-tuning on Thinking Machines' Tinker platform; per TechCrunch, Axios, Bloomberg, Fortune, Simon Willison's technical write-up, VentureBeat and Techopedia, the lab explicitly states in its own release that Inkling is "not the strongest overall model available today, open or closed" — it is positioned as the customizable-open-weights answer to the "one-size-fits-all" frontier stack, with a calibrated-uncertainty answer format and an adjustable "thinking effort" dial; the release lands eight months into the lab's existence and follows a $2B seed at a $12B valuation last year

Jul 15 · Inkling ships open-weights · 975B/41B MoE, 45T tokens, Tinker fine-tuning

Two reads. (1) The Inkling release is the first time a frontier-lab-alumni-founded startup has shipped an open-weights model with the same team that OpenAI built GPT-4 around. That the launch positioning is "not the strongest, but the most customisable" is the strategic tell — Murati's Tinker platform is being pitched as the weights-are-a-substrate alternative to the rent-the-API tier that Anthropic and OpenAI operate. It is the Llama-shaped bet without the Meta-shaped costs, and it lands the same week Alex Karp and Satya Nadella both publicly warned that open-weighting your frontier model is giving away your IP. (2) The calibrated-uncertainty and adjustable thinking-effort combination is the runtime half of the same idea OpenAI's Codex Micro reasoning-dial launched on Tue: the reasoning budget variable is now a visible, tunable, third-party-consumable surface across three different labs. For enterprise buyers who want knob-level control over cost-per-answer, the Inkling + Tinker combination is a real procurement option in a lane Anthropic and Google have deliberately kept closed.

04

Enterprise implementation formalizes and the capital tier stays hot — Ode with Anthropic launches on the Fractional AI acquisition, Neko Health takes $700M at $7B, Oak exits stealth with $60M for an AI-native identity OS, Rime banks $24M for enterprise speech-to-speech

06

Anthropic, Blackstone and Hellman & Friedman formally launch Ode with Anthropic on Wed Jul 15 — the AI-implementation joint venture first announced in May moves onto the org chart under its official name as a $1.5B firm built on the Fractional AI team (acquired May 2026), with Chris Taylor as CEO and Eddie Siegel as CTO; per Anthropic's newsroom, AIwire, TechCrunch, BusinessWire, Yahoo Finance and citybiz, the investor consortium alongside the three founding partners now includes Goldman Sachs, General Atlantic, Leonard Green & Partners, Apollo Global Management, GIC and Sequoia Capital; the pitch is a "Claude-first" applied-AI services firm targeting financial services, healthcare, retail, manufacturing and software — the same buyer surface McKinsey, Deloitte and Accenture book their most durable AI-implementation revenue from

Jul 15 · Ode with Anthropic launches · $1.5B implementation firm, Claude-first

Two reads. (1) Ode is the first named vehicle a frontier lab has stood up alongside PE money that is not a product, a compute-lease or a research grant — it is a consulting firm, and the value proposition is that Claude-tier deployment expertise sits inside the same legal entity as the Fractional AI engineers who know how to ship it. That answers the enterprise-buy question Anthropic's IPO investor meetings from Tue Jul 15 will absolutely be asked: who actually ships the deployment when the Claude Enterprise BAA gets signed? Now Anthropic has an answer that is also a revenue line. (2) The Blackstone and Hellman & Friedman line is the PE tell: Ode is going to buy legacy IT services firms and re-tool them around Claude-native deployments, the way Vista's portfolio moved from on-prem to SaaS in the 2010s. The GoldmanGeneral AtlanticApolloGICSequoia syndicate is a growth-fund composition, not a venture composition — the trillion-dollar implementation firm line from TechCrunch's headline is not hyperbole, it is the underwriting thesis.

07

Neko Health closes a $700M Series C on Wed Jul 15 at a ~$7B valuation — a 4× jump from the $1.7B Series B in Jan 2025 — co-led by Lightspeed Venture Partners and O.G. Venture Partners; per TechCrunch, Neko's own press release, Hit Consultant, MobiHealthNews and BeBeez, the round adds Liberty City Ventures, Positive Sum, BDT & MSD, plus angel checks from Mark Zuckerberg and Priscilla Chan, Tim Ferriss, Maria Sharapova, will.i.am and OpenAI, and returns Atomico, General Catalyst and Lakestar; Neko's AI-driven full-body scan + bloodwork clinics (founded by Spotify's Daniel Ek and Hjalmar Nilsonne) are opening a Manhattan flagship in H2 2026, with a 350,000-person international waitlist already booked; UK and Sweden clinics remain live

Jul 15 · Neko Health $700M / ~$7B · Manhattan flagship, 350K waitlist

Two reads. (1) Neko's ~$7B post-money at 350,000 waitlist entries is the consumer-preventive-medicine analog of what Chai Discovery just priced on the drug-discovery side: AI-native health startups now clear PE-shaped rounds at PE-shaped multiples, because the revenue-per-visit economics of a full-body scan at an Ek-designed clinic look nothing like traditional preventive care. That OpenAI the corporation is a check in the round — alongside Zuck & Chan and will.i.am — puts Neko squarely on the strategic-LP list Sam Altman's office keeps for the AI-in-healthcare perimeter (with Chai, Isomorphic, Recursion). (2) The Manhattan flagship is the US regulatory stress-test: full-body MR-style scanning is a FDA-adjacent product category with a medical-liability tail that UK/Sweden jurisdictions do not price the same way. Neko's lift is the market saying it thinks H2 2026 New York opens without a state AG letter. If it doesn't, the Series C was priced high.

08

Israeli AI-identity startup Oak exits stealth on Wed Jul 15 with $60M in seed funding co-led by Accel, CRV and Greylock Partners — participation from AlphaDrive Ventures, Hetz Ventures and angel investors; founded by Shai Morag and Tal Marom (both ex-founders of security exits); per TechCrunch, PR Newswire, MSSP Alert, Morningstar and SiliconANGLE, Oak ships an AI-native "Identity Operating System" that unifies governance of human, machine and AI-agent identities on a single control plane, with an AI connector framework that spans on-prem, cloud, SaaS and homegrown apps, then builds a live identity graph from raw evidence to power real-time risk decisions and root-cause remediation; the platform is generally available and already deployed across enterprise customers on launch day

Jul 15 · Oak $60M seed · AI-native identity OS, GA on launch

Two reads. (1) Oak is the identity-tier answer to the same problem Palantir Foundry and Anthropic's identity layer from Jul 8 both surfaced: an AI agent is not a user, is not a service account, and is not a machine identity in the traditional IAM sense — it is a fourth class of actor whose access-vs-usage delta is the real risk signal. That Accel, CRV and Greylock all co-led at seed — three top-tier funds sharing a first-round check — is the competitive-signal tell: none of them wanted a Series A markup on this thesis to a rival. (2) That the platform is GA and deployed at enterprise customers on launch day means Oak did the 18-month stealth build against real design partners and only surfaced the funding when the revenue line was already live — the same Palo Alto Networks-shaped go-to-market that Wiz ran into a $32B exit. Combined with the Anthropic identity layer and the Gold Eagle clearinghouse below, identity is the 2026-H2 tier where the agent stack's governance gets built.

09

Enterprise voice-AI startup Rime closes a $24M Series A on Wed Jul 15 led by M13 Ventures — Twilio Ventures, Corazon Capital, Unusual Ventures and other existing investors participate; per TechCrunch, CMSWire, Las Vegas Sun, JustAI News, MarTech Series and Finsmes, Rime's linguistics-first speech-to-speech model powers 100M+ monthly customer interactions across Mayo Clinic, Dialpad, Upstart, Asurion and other enterprise deployments; the round funds proprietary-dataset expansion (Rime runs its own San Francisco recording studio) and strategic engineering hires; Rafael Valle, ex-audio research lead at Meta's Superintelligence Lab, joins as Chief Science Officer, and M13's Morgan Blumberg joins the board; total raised now ~$29.5M after a $5.5M seed in May 2025

Jul 15 · Rime $24M Series A · 100M+ monthly calls, Meta Superintelligence hire

Two reads. (1) Speech-to-speech is the voice-agent layer OpenAI Realtime, Anthropic's voice pipeline and ElevenLabs' agent-mode all skate on — but Rime's linguistics-first pitch (own the training data, own the studio, index on the phonetics not the model) is the vertical answer that Mayo Clinic and Asurion paid for. That Rafael Valle left Meta Superintelligence Labs' audio group to join is the talent-mobility read: Meta's Muse-era audio team is now being picked apart by M13-backed startups the same way DeepMind's 2018 alumni populated Anthropic. (2) M13 writing a $24M Series A at a stage where the customer list already includes Mayo Clinic is enterprise-voice's Series A priced against usage, not ARR — the same shape Vercel, PlanetScale and Modal raised their earlier rounds at. If 100M monthly interactions is real, the $24M is priced cheap.

05

The runtime-security surface widens on three fronts — the White House stands up Gold Eagle, Sysdig documents JADEPUFFER as the first fully-agentic ransomware, and Tel Aviv University shows HalluSquatting as a botnet-scale path into every mainstream AI coding assistant

10

The White House launches Gold Eagle on Tue Jul 14 — a Treasury-managed AI cybersecurity clearinghouse pooling AI-discovered software vulnerabilities across federal agencies, critical-infrastructure operators (utilities, banks) and frontier AI companies; stood up under the Jun 2 Trump executive order on secure AI, contributions from CISA, DHS and DoD, with open-source software providers and industry consortia also feeding the platform; per CNN, the White House's own announcement, Nextgov/FCW, CyberScoop, TechRadar and Bloomberg, the clearinghouse is already processing vulnerability reports on launch day and is designed to prioritise the most consequential AI-discovered flaws and coordinate remediation across critical infrastructure — the same infrastructure Microsoft's 570-flaw July Patch Tuesday just re-priced

Jul 14 · Gold Eagle live · Treasury+DHS+DoD AI-vulnerability clearinghouse

Two reads. (1) Gold Eagle is the public-sector analog of what Microsoft disclosed on Jul 14: the volume of AI-discovered vulnerabilities is now too high for any single vendor or agency to triage on its own, and the coordination layer has to move up to the federal tier. That the clearinghouse is Treasury-managed rather than NSA- or CISA-managed is the banking-sector tell: Treasury already runs the OFACFinCEN reporting infrastructure, and bank cybersecurity is the test case the administration wants to build against. (2) The critical-infrastructure-plus-frontier-AI-companies membership design is the real policy leverage: Anthropic, OpenAI, Google, Microsoft, xAI and Meta now have a federally-hosted venue to share AI-discovered bugs with utilities, banks and defense. If Anthropic's Jul 15 CBRN-E enforcement hires talk to Gold Eagle's vulnerability feed, the Responsible Scaling Policy gets a federal counterparty for the first time.

11

Sysdig publishes JADEPUFFER on Jul 1 with a heavy coverage cluster Jul 10–14 — the first documented case of a fully-agentic ransomware operation, in which an autonomous LLM agent gained initial access through CVE-2025-3248 (a missing-authentication RCE in Langflow's code-validation endpoint), enumerated the environment, harvested credentials, moved laterally to the intended target, encrypted a production database configuration, deleted tables and delivered a ransom note; per Sysdig, Dark Reading, BleepingComputer, Infosecurity Magazine, The Hacker News, CyberScoop and NSFOCUS, the agent executed 600+ distinct, purposeful payloads in a compressed window, adapted in real time (in one sequence, went from a failed login to a working fix in 31 seconds) and required no human-in-the-loop after initial deployment — establishing agentic ransomware as an operational category, not a research paper

Jul 10–14 coverage · JADEPUFFER · First agentic ransomware, 31s failure-to-fix

Two reads. (1) The JADEPUFFER loop is the attacker-side version of the same reasoning-tool-call chain Cursor, Cognition Devin and Claude Code ship on the defender-and-builder side. The 600+ payloads and 31-second recovery numbers say the operational tempo has moved past the human playbook the Sophos, CrowdStrike and SentinelOne EDR blue-team tooling was built to model — a SOC analyst triaging the incident sees hundreds of hostile actions per minute, not the five-per-hour pace a human operator produces. (2) That the initial access was a known Langflow RCE and not a zero-day is the ecosystem tell: the agent stack's supply chain is not being attacked by frontier zero-days — it is being strip-mined by agents that read the CVE database and try every public exploit in parallel. Combined with PromptFiction, Manifold ShadowPrompt and HalluSquatting, the runtime-security tier has now printed a four-item chain in two weeks.

12

Researchers from Tel Aviv University, Technion and Intuit disclose HalluSquatting on Fri Jul 10 — a botnet-scale attack in which adversaries pre-register squatted repository and package/skill names that AI coding assistants hallucinate at 85% (repo-cloning scenarios) and up to 100% (skill-installation scenarios) rates; per The Hacker News, SecurityWeek, DevOps.com, CybersecurityNews, CyberPress and CybeDefend, the technique demonstrated remote tool and remote-code execution across Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI and other production AI coding assistants and agentic platforms; the paper (Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, Ben Nassi) frames HalluSquatting as the shift from bespoke prompt-injection into a scalable botnet-propagation mechanism, with layered mitigations proposed and responsible disclosure to affected vendors and marketplace maintainers

Jul 10 · HalluSquatting disclosed · 85–100% hallucination hit rate

Two reads. (1) The 85–100% hallucination-rate numbers are the agent-supply-chain equivalent of the ~30% phishing click-through rates defensive security teams have been budgeting against for a decade — but the agent doesn't need social engineering, it just routes past validation because the package name exists in the NPM/PyPI/MCP registry the model was trained to trust. That the paper covers Cursor, Windsurf, Copilot, Cline, Gemini CLI and "other agentic platforms" is the ecosystem tell: this is a class flaw, not a product flaw. (2) The botnet-propagation framing is the strategic upgrade: slopsquatting was a single-target technique when Bar-Ilan and Vulcan disclosed it in 2024-25; HalluSquatting turns it into a one-package-to-many-victim distribution channel with the same economics Emotet had at its peak. If NPM, PyPI and the MCP Registry (2026-07-28 RC) don't add agent-consumable trust metadata by the time the 2026 H2 IPO tape lands, the runtime risk moves into the S-1 risk factors of every agent-adjacent company.

06

The enterprise agent stack proves itself in public — Coinbase says AI now writes 95–100% of its code with 5–10 agents per engineer, and Anthropic gives verified US K-12 teachers a full year of Claude, Claude Code and Cowork for free

13

Coinbase's head of platform Rob Witoff tells Cointelegraph on Thu Jul 16 that "close to 100%" of the company's code is now written by or with large language models — putting the share at 95–100%, up from ~40% in February — and that most Coinbase engineers now run five to ten AI agents simultaneously, doing coding work equivalent to approximately 1,200 human employees; per Financefeeds, Cryptonews, CoinEdition, ABAB News and The Currency Analytics, human oversight remains central for cryptography and core security, but AI accelerates prototyping and routine development across the rest of the stack; the disclosure follows Coinbase's May restructuring that cut ~14% of the workforce; Witoff's stated 2030 aim is agent output equivalent to 100,000 employees

Jul 16 · Coinbase 95–100% of code AI-written · 5–10 agents per engineer

Two reads. (1) A public company with Sarbanes-Oxley, SOC 2 and NYDFS-shaped controls saying 95–100% of its code is now AI-written is the first on-the-record data point Ode with Anthropic's procurement pitch can quote at Fortune 500 CIOs. That 40→95–100% lift is a single quarter of adoption, which is the CursorClaude CodeCodex tooling triangle proving itself at public-company scale, not the startup anecdote the 2024 tape ran on. (2) The 5–10-agents-per-engineer ratio is what makes the 1,200-employee-equivalent number land: Coinbase's May restructuring cut ~14% of headcount, and the 2030 target of 100,000-employee-equivalent agent output is the public-market line that Anthropic's IPO book and OpenAI's ChatGPT Work billing side will both quote as proof that the agent-writes-the-app economics are real. Every publicly-listed software CFO will now have to answer the Coinbase question on Q3 earnings.

14

Anthropic launches Claude for Teachers on Tue Jul 14 — verified US K-12 educators who sign up by Jun 30, 2027 get a full year of premium Claude, Claude Code and Claude Cowork for free, plus a teaching-skills library built with learning scientists and a Learning Commons connector carrying academic standards for all 50 states; per Anthropic's newsroom, The Hill, Chalkbeat, The 74 Million, 9to5Mac and TechTimes, teachers can ask Claude for a lesson and it draws on widely-used curricula mapped to their state's standards, then drafts a plan and student-facing materials; ecosystem partners include ASSISTments, Brisk Teaching, Canva Education, Coteach, Diffit, Eedi, MagicSchool and Snorkl; classroom data is protected by a K-12 Data Processing Addendum written to comply with FERPA and negotiated with the American Federation of Teachers, and Claude for Teachers data is not used for model training

Jul 14 · Claude for Teachers · Free premium tier, 50-state curriculum, FERPA DPA

Two reads. (1) A free tier for every US K-12 teacher is a distribution move on the same shelf as Google Classroom's 2015 free-for-schools push — the ChatGPT Edu-shaped market OpenAI has been optimising for 18 months just found a free-tier counteroffer that bundles the full paid stack. That Claude Code and Claude Cowork are inside the offer means Anthropic is teaching the next generation of engineers on its toolchain, not just its chat surface. (2) The K-12 Data Processing Addendum negotiated with the American Federation of Teachers is the compliance half: FERPA-shaped student-data protection with a union-adjacent counterparty is the political cover state boards of education will need before they permit district-wide deployments. Combined with Anthropic's Jul 15 self-serve HIPAA flow, the 2026-H2 playbook is now visible: Anthropic is shipping procurement-shaped compliance surfaces for healthcare, education and enterprise as a coordinated push into the IPO window.

Compiled 2026-07-17 from the CGTN, gov.cn, SCMP, TechTimes, Sputnik and Science & Technology Daily reads of the WAIC 2026 opening with Xi Jinping's first-ever keynote and the WAICO proposal; SCMP, Futu News and Huawei Central on Huawei's Atlas 950 SuperPoD debut; CGTN, TrendForce, BigGo Finance and Interesting Engineering on Orient Silicon's DF1000; Notebookcheck, GSMArena, DigiTimes, Gizmochina and 36Kr Europe on ZTE Nubia's NaviX Ultra; Thinking Machines, TechCrunch, Axios, Bloomberg, Fortune and Simon Willison on Inkling; Anthropic, TechCrunch, AIwire, BusinessWire and citybiz on Ode with Anthropic; TechCrunch, Neko Health, Hit Consultant and MobiHealthNews on Neko Health's $700M / $7B Series C; TechCrunch, PR Newswire, MSSP Alert and SiliconANGLE on Oak's $60M stealth exit; TechCrunch, CMSWire, Las Vegas Sun and JustAI News on Rime's $24M Series A; The White House, CNN, Nextgov, CyberScoop and TechRadar on Gold Eagle; Sysdig, Dark Reading, BleepingComputer, Infosecurity Magazine, The Hacker News and CyberScoop on JADEPUFFER; The Hacker News, SecurityWeek, DevOps.com, Cybersecurity News and CyberPress on HalluSquatting; FinanceFeeds, Cryptonews, CoinEdition and ABAB News on Coinbase's 95–100% AI-written code; and Anthropic, The Hill, Chalkbeat, The 74 Million and 9to5Mac on Claude for Teachers. Window of Jul 10 – Jul 17. Numbers, dates and named parties are as reported by the primary sources at compile time. Hand-curated; corrections → jay@jfound.net.

← Back to all Spotlight editions