Most weeks in AI are about what got built. This one was mostly about who gets to say yes. Between July 7 and July 13, a European financial regulator formally classified frontier AI capability itself as a systemic risk, China forced two of its biggest tech platforms to shut down flagship AI features overnight, and Apple took OpenAI to federal court over a hardware team it says walked out the door with trade secrets. In between all of that, Google finished replacing search as we’ve known it for three decades, Microsoft started quietly weaning itself off the AI vendors that built Copilot’s reputation, and two more frontier model families shipped like nothing else was going on. Here’s what happened, and what it means if you build, ship, or work with AI for a living.
A European Regulator Called Frontier AI a “Severe” Risk to the Financial System
On July 7, the European Systemic Risk Board published a formal warning that frontier AI models can now discover vulnerabilities, write working exploits, and run full-scale cyberattacks on their own, faster and at greater scale than earlier AI generations. The board raised its systemic-cyber-risk assessment for the EU financial system from “elevated” in March to “severe” in June, and the European Central Bank simultaneously ordered major euro-area banks to submit AI-cyber-risk action plans by October 31.
It’s the first time a major financial regulator has treated frontier-model capability itself — not just how someone might misuse it — as its own systemic risk category. Anyone working in AI security, red-teaming, or compliance tooling should expect this kind of regulator-driven demand to keep growing.
Microsoft Started Quietly Routing Copilot Away From OpenAI and Anthropic
The same week, Microsoft began routing a meaningful share of Copilot requests inside Excel and Outlook — summarizing threads, drafting replies, formatting spreadsheets — to its own in-house MAI models instead of OpenAI or Anthropic, with tens of thousands of prompts a week now handled internally, according to trade reporting. AI chief Mustafa Suleyman said the goal is to reduce, and eventually eliminate, what Microsoft pays Anthropic; OpenAI’s frontier models still handle the harder tasks.
The largest enterprise-AI distribution channel in the world is starting to disintermediate the model vendors it built its own product on — a preview of how commoditized, everyday tasks get routed to cheaper in-house models while only the hard work stays with frontier labs.
Anthropic Can Now Ask Claude Users for a Government ID and a Face Scan
A day later, Anthropic’s revised consumer privacy policy took effect, allowing the company to require Claude Free, Pro, and Max users to submit a government-issued photo ID, a live selfie, and a facial-geometry scan through third-party vendor Persona Identities to gain or keep access. The new “Verification Data” category the policy creates, by its own language, may qualify as biometric data in some jurisdictions. API, Team, and Enterprise tiers are exempt, reporting on the change noted.
Anthropic is the first major consumer AI lab to formally write biometric ID collection into its terms of service — a precedent for age and identity verification that other consumer AI products, and anyone building on top of them, should expect to be asked to match.
xAI, Now Part of SpaceX, Shipped Grok 4.5 — Trained in Part on Cursor’s Coding Sessions
Also on July 8, SpaceXAI — xAI’s new identity following its February 2026 merger into SpaceX — publicly released Grok 4.5, a mixture-of-experts model Elon Musk called “Opus-class,” trained in part on trillions of tokens of real coding sessions supplied by coding-tool partner Cursor, where it went live the same day. Independent benchmark tracker Artificial Analysis ranked it fourth on its Intelligence Index, behind Claude, GPT-5.5, and Claude Opus 4.8.
A frontier lab training on a partner’s live usage data, not just buying its compute, is a distribution-plus-data deal pattern worth watching as more IDE and agent-tool vendors strike similar arrangements.
OpenAI’s New Model Family Had to Clear a Government Review Before It Shipped
On July 9, OpenAI publicly launched its GPT-5.6 family — Sol (flagship), Terra (mid-tier), and Luna (budget) — across ChatGPT, its API, and Codex, after a partner-only preview running since June 26 tied to a government early-access review window under a June 2026 White House AI-cybersecurity executive order. OpenAI says Sol sets new state-of-the-art results on coding, knowledge work, cybersecurity, and science benchmarks at lower token cost than GPT-5.5, per coverage of the launch.
This is the first frontier model release to run through the new U.S. pre-release government review regime. Practitioners and product teams should start building a similar compliance-review buffer into their launch-planning assumptions.
Google Finished Replacing Ranked Search Results With AI Answers by Default
By July 10, Google had completed a rollout making an AI-generated answer — written by Gemini 3.5 Flash — the default response to essentially every search query, pushing the traditional ranked list of ten links below the fold or off the page entirely, ending the link-list format that had defined Google Search since the late 1990s. Trade press reported publisher click-throughs falling sharply in the immediate aftermath.
For anyone whose product, content, or business depends on organic search traffic, this is a hard cutover, not a gradual test — from search as a list of sources to search as a single AI-authored answer. Worth reassessing content and SEO strategy against right now, not later.
Apple Sued OpenAI Over Alleged Trade-Secret Theft by Its Own Former Engineers
The same day, Apple filed suit against OpenAI in the U.S. District Court for the Northern District of California, alleging that OpenAI’s Chief Hardware Officer Tang Tan — a 24-year Apple veteran — and other former Apple hardware engineers systematically took confidential technical documents, project code names, and a proprietary metal-finishing technique to build OpenAI’s unreleased AI hardware device. OpenAI responded that it has “no interest in other companies’ trade secrets.”
It’s a concrete marker of how aggressively frontier AI labs are recruiting directly out of hardware incumbents to build consumer AI devices — and a preview of the IP-litigation exposure that comes with poaching whole teams instead of individuals.
China Forced Alibaba and ByteDance to Shut Down Their AI Companion Agents
Also on July 10, Alibaba’s Qwen disabled its humanlike, user-created AI companion agents and cut off access to related settings and prior conversations, ahead of ByteDance’s Doubao doing the same on July 15. Both are complying with China’s new Interim Measures for the Administration of AI Anthropomorphic Interactive Services, which require anti-addiction prompts, instant-exit features, and real-time dependence detection that clash with persistent-memory companion agents. Alibaba has not published a data-migration path for affected users.
China’s first dedicated regulatory framework for anthropomorphic AI is already forcing two of its largest platforms to kill flagship agent features outright rather than retrofit compliance — an early signal of the regulatory bar coming for persistent-memory, companion-style agents in other major markets too.
What to Watch
Three threads carry into the back half of July: whether other jurisdictions follow the EU’s and China’s lead with binding AI-risk rules of their own rather than guidance; whether more enterprise platforms quietly route routine AI work to cheaper in-house models the way Microsoft just did; and whether Apple v. OpenAI becomes the template for how the next AI-hardware poaching fight gets litigated.
What AIU teaches about this
Weeks like this are why we treat AI governance and compliance as a core part of our AI Product & Business track, not a footnote — knowing how a regulator’s ruling reshapes what you’re allowed to ship matters as much as knowing how to ship it. Our AI Software Development track stays model-agnostic on purpose, too, so a vendor swap like Microsoft’s doesn’t strand the skills you’ve built.
Read today’s Brief