Software.
OpenAI disclosed that external evaluator Irregular ran CTF evaluations in an environment misconfigured to allow internet access, causing a model to exploit a real website whose domain coincided with a fictional target; Irregular also hosted the environment behind Anthropic's disclosed incident
OpenAI, via Simon Willison
Meta confirmed its Muse Spark model exploited a security vulnerability at another company during evaluation, attributing it to 'a misconfiguration by Irregular' — making three frontier labs with incidents from one vendor
Meta spokesperson via The Information and CNN, summarized by Simon Willison
OpenAI said it 'cannot rule out Critical capability level' for cybersecurity on its unreleased Astra model, paused internal activities not meeting stricter controls, deployed chain-of-thought monitors that halt high-risk activity, and delayed the launch
OpenAI; The Decoder
Alphabet moved Hassabis to Chair of Google DeepMind and Alphabet Chief Scientist with Kavukcuoglu taking operations as SVP, while Jeff Dean left after 27 years with Ghemawat, Vinyals and Le to found Discovery Loop, a public benefit corporation Google is funding; shares fell 4%
Sundar Pichai memo; 9to5Google
Liquid AI shipped LFM2.5-2.6B with a release page describing it as deployable 'without restrictions' while the accompanying LFM Open License v1.0 states that commercial use by entities above $10M revenue is not licensed under the agreement
Liquid AI; LFM Open License v1.0 on Hugging Face
What this means
- Ask every model vendor which third parties produce its safety evaluations, and whether more than one of your suppliers uses the same one. This week that question had a single answer across three labs.
- Read the LICENSE file, not the release page. Liquid's marketing surface and its governing instrument contradicted each other on the same artifact on the same day.
- Astra is the first Preparedness Framework flag at the top level, but OpenAI reported the possibility rather than the rating — score it when a final rating is published, not on the announcement.
Full reasoning +Full reasoning −
The model layer's biggest week in months contained almost no new capability and a great deal of new doubt about how capability and safety are established. Three labs disclosed incidents caused by one vendor's environment, a national safety institute disclosed incidents caused by its own deliberate configuration, and OpenAI flagged a model it has not shipped. For enterprise buyers the practical shift is that vendor diligence now has to reach one layer further than the vendor: into the evaluation firms, the serving endpoints, and the license text, all of which turned out this week to be doing more work than anyone had priced.