Week in Review — 2026-05-04

The Week’s Story

Three storylines collided this week to redraw the commercial and security topology of frontier AI. On Monday, OpenAI and Microsoft tore up the Azure-exclusivity clause that had defined cloud AI for half a decade; within 24 hours OpenAI’s GPT, Codex, and Managed Agents went live on AWS Bedrock. By Thursday the renegotiation had widened into what The Verge called a “divorce notepad,” with compute, IP, and product roadmaps all back on the table. Running in parallel, the Musk-Altman trial in Oakland turned the founding myth of OpenAI inside out: Musk took the stand to “save humanity,” his finance fixer Birchall hurt the case in a jury-out exchange, and on Friday Musk testified that xAI had trained Grok on OpenAI models — making “distillation” a live legal flashpoint.

The second narrative was the arrival of broadly proliferating offensive cyber capability. Anthropic’s Claude Mythos Preview, which last week could autonomously find and weaponize software vulnerabilities, surfaced 271 zero-days in Firefox by Wednesday. By Friday, the UK AI Security Institute confirmed that OpenAI’s GPT-5.5 had become the second model to autonomously execute a full network takeover. Anthropic packaged the same capability set for defenders as Claude Security; OpenAI restricted GPT-5.5 Cyber to “critical defenders.” The patch-and-protect window that defenders have relied on for two decades is visibly closing — a thesis Schneier laid out on Tuesday and that the rest of the week reinforced. AI also found a 9-year-old kernel privilege-escalation bug in Linux (“CopyFail”) that left major distros scrambling, alongside 38 flaws in OpenEMR and a CVSS-10 RCE inside Google’s own Gemini CLI.

The third thread was the U.S. government hardening its posture. The week opened with Google taking a classified Pentagon contract Anthropic had refused, despite 600+ Google employees protesting. Mid-week the White House moved to restore Anthropic access — then on Thursday reversed course and blocked wider Mythos distribution citing compute limits. By Friday, the Pentagon had signed eight vendors (OpenAI, Google, Microsoft, AWS, Nvidia, xAI, Reflection, and one more) to deploy AI on classified networks, with Anthropic conspicuously excluded after rejecting a usage clause and being flagged as a security risk. Underneath all of this, big tech’s combined AI capex hit $725B for next year, Anthropic was reportedly closing a round at over $900B valuation in a 48-hour window, and Samsung warned the memory shortage will worsen through 2027. Compute, not models, is now the binding constraint.

Continuing Stories

Musk v. Altman trial: Opened Tuesday in Oakland with bitter testimony — Musk arguing he is trying to “save humanity,” jurors arriving with “pre-existing strong opinions.” Wednesday saw founding-era emails, photos, and corporate documents enter the record. Friday brought Musk’s admission that xAI trained Grok on OpenAI models, turning model distillation into a legal flashpoint. The week closed with Birchall’s jury-out exchange potentially damaging Musk’s case. The trial has become both the discovery process for OpenAI’s origin story and a stress test for whether OpenAI can complete its for-profit conversion ahead of the IPO.

OpenAI–Microsoft restructuring: The Azure-exclusivity unwind announced Monday played out faster than anyone expected. By Tuesday, AWS had three OpenAI offerings on Bedrock including a jointly built agent service; by Thursday, The Verge was reporting the deal had widened from a renegotiation into a full restructuring of compute, IP, and product roadmap commitments. The frame shifted from “Microsoft loses exclusivity” to “the OpenAI–Microsoft monopoly era ends.” OpenAI also said it hit its 10-GW compute goal years ahead of schedule.

Anthropic’s Mythos and the cyber-capability proliferation: Tuesday’s Schneier piece framed Mythos as the end of patch-and-protect; Wednesday’s 271-Firefox-zero-days result demonstrated the magnitude. Thursday saw the White House block wider Mythos access on compute-supply grounds, OpenAI mirror that move with GPT-5.5 Cyber, and Anthropic launch Claude Security in public beta. Friday’s UK AISI verification that GPT-5.5 matches Mythos on full network takeover confirmed this is now an industry-wide capability, not a single-model anomaly.

Anthropic vs. the Pentagon: Started Tuesday with Anthropic refusing the classified DoD work Google then accepted. Wednesday’s draft White House guidance hinted at a thaw. Thursday’s compute-limit block reversed it. Friday’s eight-vendor Pentagon announcement excluded Anthropic outright — flagging it as a “security risk” after it rejected a usage clause. The week converted Anthropic’s “responsible scaling” stance from a marketing posture into a procurement liability.

AI infrastructure as attack surface: From Tuesday’s CVSS-9.3 unauthenticated RCE in Hugging Face LeRobot, exploited LiteLLM SQLi, and Microsoft Entra ID role flaw aimed at AI agents — through Wednesday’s DPRK-authored npm supply-chain attack via Claude Opus and AI-found GitHub RCE — to Thursday’s PyTorch Lightning, intercom-client, and SAP npm compromises plus the Gemini-CLI CVSS-10. The AI tooling stack itself is now the perimeter, and the attackers reached it before the defenders.

Anthropic’s $900B valuation round: Surfaced Thursday as Anthropic reviewing investor offers, escalated Friday to reports the round could close in a 48-hour window. Coincides with Q1 reports that OpenAI is missing revenue targets while Anthropic and Google close in.

The goblin incident: Started Thursday as a curiosity (OpenAI explaining why Codex/GPT-5 kept saying “goblin”), escalated Friday to a ban list including gremlins and raccoons, and was framed by Saturday as a cautionary case study — a faulty reward signal in an “otaku” persona that points to deeper training-incentive fragility.

Research Highlights

Safety

Agents

Benchmarks

Reasoning

Applied AI

Key Themes

What to Watch