← Back to all news

Regulators on Three Continents Just Told AI Companies What They Can’t Do Anymore

A financial regulator called frontier AI a “severe” systemic risk, China forced two platforms to kill their AI companion features, and Apple sued OpenAI over stolen hardware secrets — all while Google finished rewriting search and two new frontier models shipped anyway.

Sam Altman and Tim Cook at a dinner event, amid Apple's trade-secret lawsuit against OpenAI
Image via Getty Images / TechCrunch

Most weeks in AI are about what got built. This one was mostly about who gets to say yes. Between July 7 and July 13, a European financial regulator formally classified frontier AI capability itself as a systemic risk, China forced two of its biggest tech platforms to shut down flagship AI features overnight, and Apple took OpenAI to federal court over a hardware team it says walked out the door with trade secrets. In between all of that, Google finished replacing search as we’ve known it for three decades, Microsoft started quietly weaning itself off the AI vendors that built Copilot’s reputation, and two more frontier model families shipped like nothing else was going on. Here’s what happened, and what it means if you build, ship, or work with AI for a living.

A European Regulator Called Frontier AI a “Severe” Risk to the Financial System

On July 7, the European Systemic Risk Board published a formal warning that frontier AI models can now discover vulnerabilities, write working exploits, and run full-scale cyberattacks on their own, faster and at greater scale than earlier AI generations. The board raised its systemic-cyber-risk assessment for the EU financial system from “elevated” in March to “severe” in June, and the European Central Bank simultaneously ordered major euro-area banks to submit AI-cyber-risk action plans by October 31.

It’s the first time a major financial regulator has treated frontier-model capability itself — not just how someone might misuse it — as its own systemic risk category. Anyone working in AI security, red-teaming, or compliance tooling should expect this kind of regulator-driven demand to keep growing.

Microsoft Started Quietly Routing Copilot Away From OpenAI and Anthropic

The same week, Microsoft began routing a meaningful share of Copilot requests inside Excel and Outlook — summarizing threads, drafting replies, formatting spreadsheets — to its own in-house MAI models instead of OpenAI or Anthropic, with tens of thousands of prompts a week now handled internally, according to trade reporting. AI chief Mustafa Suleyman said the goal is to reduce, and eventually eliminate, what Microsoft pays Anthropic; OpenAI’s frontier models still handle the harder tasks.

The largest enterprise-AI distribution channel in the world is starting to disintermediate the model vendors it built its own product on — a preview of how commoditized, everyday tasks get routed to cheaper in-house models while only the hard work stays with frontier labs.

Anthropic Can Now Ask Claude Users for a Government ID and a Face Scan

A day later, Anthropic’s revised consumer privacy policy took effect, allowing the company to require Claude Free, Pro, and Max users to submit a government-issued photo ID, a live selfie, and a facial-geometry scan through third-party vendor Persona Identities to gain or keep access. The new “Verification Data” category the policy creates, by its own language, may qualify as biometric data in some jurisdictions. API, Team, and Enterprise tiers are exempt, reporting on the change noted.

Anthropic is the first major consumer AI lab to formally write biometric ID collection into its terms of service — a precedent for age and identity verification that other consumer AI products, and anyone building on top of them, should expect to be asked to match.

xAI, Now Part of SpaceX, Shipped Grok 4.5 — Trained in Part on Cursor’s Coding Sessions

Also on July 8, SpaceXAI — xAI’s new identity following its February 2026 merger into SpaceX — publicly released Grok 4.5, a mixture-of-experts model Elon Musk called “Opus-class,” trained in part on trillions of tokens of real coding sessions supplied by coding-tool partner Cursor, where it went live the same day. Independent benchmark tracker Artificial Analysis ranked it fourth on its Intelligence Index, behind Claude, GPT-5.5, and Claude Opus 4.8.

A frontier lab training on a partner’s live usage data, not just buying its compute, is a distribution-plus-data deal pattern worth watching as more IDE and agent-tool vendors strike similar arrangements.

OpenAI’s New Model Family Had to Clear a Government Review Before It Shipped

On July 9, OpenAI publicly launched its GPT-5.6 family — Sol (flagship), Terra (mid-tier), and Luna (budget) — across ChatGPT, its API, and Codex, after a partner-only preview running since June 26 tied to a government early-access review window under a June 2026 White House AI-cybersecurity executive order. OpenAI says Sol sets new state-of-the-art results on coding, knowledge work, cybersecurity, and science benchmarks at lower token cost than GPT-5.5, per coverage of the launch.

This is the first frontier model release to run through the new U.S. pre-release government review regime. Practitioners and product teams should start building a similar compliance-review buffer into their launch-planning assumptions.

Google Finished Replacing Ranked Search Results With AI Answers by Default

By July 10, Google had completed a rollout making an AI-generated answer — written by Gemini 3.5 Flash — the default response to essentially every search query, pushing the traditional ranked list of ten links below the fold or off the page entirely, ending the link-list format that had defined Google Search since the late 1990s. Trade press reported publisher click-throughs falling sharply in the immediate aftermath.

For anyone whose product, content, or business depends on organic search traffic, this is a hard cutover, not a gradual test — from search as a list of sources to search as a single AI-authored answer. Worth reassessing content and SEO strategy against right now, not later.

Apple Sued OpenAI Over Alleged Trade-Secret Theft by Its Own Former Engineers

The same day, Apple filed suit against OpenAI in the U.S. District Court for the Northern District of California, alleging that OpenAI’s Chief Hardware Officer Tang Tan — a 24-year Apple veteran — and other former Apple hardware engineers systematically took confidential technical documents, project code names, and a proprietary metal-finishing technique to build OpenAI’s unreleased AI hardware device. OpenAI responded that it has “no interest in other companies’ trade secrets.”

It’s a concrete marker of how aggressively frontier AI labs are recruiting directly out of hardware incumbents to build consumer AI devices — and a preview of the IP-litigation exposure that comes with poaching whole teams instead of individuals.

China Forced Alibaba and ByteDance to Shut Down Their AI Companion Agents

Also on July 10, Alibaba’s Qwen disabled its humanlike, user-created AI companion agents and cut off access to related settings and prior conversations, ahead of ByteDance’s Doubao doing the same on July 15. Both are complying with China’s new Interim Measures for the Administration of AI Anthropomorphic Interactive Services, which require anti-addiction prompts, instant-exit features, and real-time dependence detection that clash with persistent-memory companion agents. Alibaba has not published a data-migration path for affected users.

China’s first dedicated regulatory framework for anthropomorphic AI is already forcing two of its largest platforms to kill flagship agent features outright rather than retrofit compliance — an early signal of the regulatory bar coming for persistent-memory, companion-style agents in other major markets too.

What to Watch

Three threads carry into the back half of July: whether other jurisdictions follow the EU’s and China’s lead with binding AI-risk rules of their own rather than guidance; whether more enterprise platforms quietly route routine AI work to cheaper in-house models the way Microsoft just did; and whether Apple v. OpenAI becomes the template for how the next AI-hardware poaching fight gets litigated.

What AIU teaches about this

Weeks like this are why we treat AI governance and compliance as a core part of our AI Product & Business track, not a footnote — knowing how a regulator’s ruling reshapes what you’re allowed to ship matters as much as knowing how to ship it. Our AI Software Development track stays model-agnostic on purpose, too, so a vendor swap like Microsoft’s doesn’t strand the skills you’ve built.

Read today’s Brief

Sources

  1. Frontier AI Models Could Strain Cyber Resilience in the Financial System, ESRB Warns — European Systemic Risk Board
  2. The ESAs Support ESRB Warning on Systemic Cyber Risks From Frontier AI Models — European Banking Authority
  3. Microsoft Replaces OpenAI, Anthropic Models With Its Own AI — American Bazaar
  4. Microsoft Quietly Swaps Cores: Excel, Outlook Gradually Ditch OpenAI, Adopt In-House MAI Models — BigGo Finance
  5. Updates to Our Privacy Policy — Anthropic Privacy Center
  6. Anthropic’s New Privacy Policy Lets Claude Ask Users for Government ID, Face Scans — Yahoo Tech
  7. SpaceXAI Releases Grok 4.5, Which Elon Describes as an ‘Opus-Class Model’ — TechCrunch
  8. Grok (Chatbot) — Wikipedia
  9. GPT-5.6 — OpenAI
  10. OpenAI Launches Its New Family of Models With GPT-5.6 — TechCrunch
  11. Google Search Ends 25-Year Era of ‘Blue Links’ With AI Summaries — BigGo Finance
  12. Google Ends 10 Blue Links Era With AI Search Overhaul — Media Copilot
  13. Apple Sues OpenAI Over Alleged Trade Secret Theft — TechCrunch
  14. Apple Sues OpenAI Alleging Trade Secret Theft — CNBC
  15. ByteDance and Alibaba to Disable Humanlike AI Custom Agents as New Rules Loom — South China Morning Post
  16. ByteDance’s Doubao and Alibaba’s Qwen to Shut Down AI Agent Features on July 15 — TechNode