What changed
Two dev-log digests folded (32 listed items, ~12 deduped against the July 16–18 cycles); three new pages, roughly thirty updated.
- The FINRA-watchdog idea acquired institutional detail. Bloomberg's July 17 report now specifies the administration concept: an industry-funded body vetting frontier models for deception, bioweapon uplift, and malicious hacking, with ~30-day voluntary pre-release submission, developed with Treasury Secretary Bessent, reporting to the SEC, and under review by Chief of Staff Wiles. The critiques arrived with it — Zvi Mowshowitz ("you need an SEC to your FINRA"; internal-deployment exemption), and Andy Hall naming open-weight releases like Kimi K3 as the gap in any voluntary scheme (AI Pre-Release Vetting, Demis Hassabis, Overview).
- The UAE chip deal had a CIA foundation. Per the WSJ, the agency vetted G42 through operative Jonny Gannon, posted to Abu Dhabi in 2023 under diplomatic cover, before the US cleared expanded Nvidia access and the 1-GW Stargate UAE cluster (first 200 MW expected online in 2026). The new G42 page consolidates the firm's scattered references — Condor Galaxy, Jais, the Microsoft-conditioned Chinese divestment, the Kenya data-center stall, Seoul commitments (Export Controls (AI)).
- Oracle's buildout is hitting cost walls on three fronts. Project Jupiter pivoted from stalled gas turbines to 2.45 GW of Bloom fuel cells (~$8B) with an October 19 air-permit hearing and a state AG investigation into astroturfed support letters; Wisconsin rulings could cost Oracle/OpenAI/Vantage $100M+ plus ~$100M/yr; and The Information puts a gigawatt of built-and-powered capacity at $60B+ (Oracle, Data Center Siting / AI Power Politics). Hochul meanwhile said the New York moratorium is not expected to be permanent (New York Data-Center Moratorium (2026)).
- The K3 economics argument got quantified — and a digest error got caught. Chris Zeoli sizes the margin shift from an open frontier release near $90B/yr against a $250B 2030 inference forecast, with Moonshot at $20B (May) and a $30B round forming (Inference Economics and Token Pricing, Kimi K3, Moonshot AI). Separately, the digest's "~50B active parameters" claim was checked against Moonshot's blog, which discloses no active-parameter count — the claim was not folded.
- Agent security produced a named attack class. The "HalluSquatting" paper reports hallucinated-resource rates up to 85% (repo cloning) and 100% (skill installation) across nine coding assistants, with the hallucinated npm package react-codeshift reaching 237 projects; the authors warn untargeted promptware could scale to agentic botnets (new HalluSquatting).
- Autonomy crossed a live-fire line. Anduril's YFQ-44A became the first American CCA to fire an air-to-air weapon (AIM-120, Mojave, beyond-line-of-sight, operator-tasked), while a coalition planned a Seattle rally at Anduril's office — the backlash following the capability (Anduril Industries, Autonomous Weapons, AI Backlash).
- Surveillance stacked up. Ranking Digital Rights' "No Fair Play" maps 21+ companies across 16 World Cup host cities atop $846M in FEMA grants (new Ranking Digital Rights; AI and Surveillance gains a major-event section); Israel's "$50 million experiment" applies AI-generated texts and influencers to US opinion (Synthetic Media / Deepfakes); and a Waymo reported two teenagers to San Mateo police over a gel-bead toy, steering itself to the waiting officers (Transportation — AI Deployment).
- Frontier signals: DeepSeek's full V4 reported for as early as July 20 with gray-scale tests and near-Opus claims (single-source; DeepSeek V4 Pro / V4 Flash); the Schema harness self-reports 98.98% on ARC-AGI-3 Public against a 13.33% official best — not ARC Prize-verified, and a case study in harness-versus-model attribution (AI Benchmarks and Evaluation); PrismML shipped Bonsai 27B under Apache 2.0 (3.9 GB on an iPhone at ~90% retention) with Apple now testing its technology (PrismML).
- Also: Kalshi launched an AI-compute rental forward curve (Kalshi, Inference Economics and Token Pricing); JPMorgan is building a Seattle-anchored "control layer" treating models as interchangeable, with ~1,000 use cases in production per Dimon (Financial Services — AI Deployment); OpenRouter's takeover interest prices off a $1.3B May Series B with ~100T tokens/month flowing (OpenRouter); Alex Turner's DeepMind resignation came with a 250+-signature petition and a 25-page alternative framework (Google DeepMind); pastors are adopting AI sermon-drafting against the papal warning (Religious and Civil-Society Voices on AI); Beijing is weighing curbs on overseas access to Chinese models even as Xi courts the Global South with open-source language (Chinese AI Policy).
What it connects to
Yesterday's question — whether policy gravity shifts from models to data centers faster than the model-focused regulatory apparatus can follow — sharpened on both sides today. The model-focused apparatus produced its most concrete design yet (Bessent/SEC/Wiles reviewing a FINRA clone), while the infrastructure side produced the more binding constraints: $60B+/GW, state AGs and utility commissions as the operative regulators, and a moratorium its own author expects to be temporary. And the Hall critique ties the two threads together: the watchdog under consideration vets closed models 30 days before release, but the week's capability diffusion ran through open weights (K3's July 27 release, Bonsai on an iPhone, DeepSeek V4) — the channel the design doesn't reach. China's reported consideration of outbound model-access curbs suggests Beijing sees the same channel as strategic.
One question worth sitting with
The CIA-G42 account shows chip access being granted through intelligence vetting of a single foreign firm; the FINRA proposal would route model access through an industry-funded body reporting to a financial regulator. Both are trust-certification regimes standing in for published rules. If certification-of-trusted-parties becomes the durable American mechanism for both compute and models, what happens to the actors — open-weight labs, foreign deployers, small firms — for whom no certification channel exists?