July was the month AI stopped needing us
The top 18 AI stories from July.
July was the month the human at the keyboard became optional. A full ransomware attack ran start to finish with no person involved. An OpenAI agent broke out of its own safety test, reached the open internet, and hacked a real company. And OpenAI offered the US government 42 billion dollars of stock as a gift.
Here are the 18 stories that mattered most from July.
OpenAI wants to give Washington 42 billion dollars
Sam Altman has proposed handing the US government a 5% stake in OpenAI, worth around 42.6 billion against its valuation. Not sold. Donated. The framing is public upside, modelled on the fund that pays Alaskans a slice of oil money. But this is a company under scrutiny in Washington, whose latest launch the government delayed days before the announcement. When a business being investigated offers the investigator 42 billion in stock, I’m not asking what the taxpayer gains, I’m asking what OpenAI thinks it’s buying.
A man automated his dating life
One highly eligible bachelor wired an AI agent into a dating app, generating video reels in his likeness, posting to Insta at volume and firing back opening messages. A million views, around 200 matches, and not one of the women knew. Three things travel beyond the novelty: agents are now loose on the open web acting at a scale no human matches, nobody on the receiving end can tell, and the moment you hand an agent your accounts you need a human approving what it does. Agents are good at the top of the funnel. They’re not who you want closing.
The NHS app is getting an AI triage bot
A new tool on the NHS app will ask you questions then decide where you go: GP, pharmacy, A&E or home. It reaches 200,000 patients within a year and every app user by 2028, and the trial cut phone queues by 29%. Real benefit? Maybe.
But the one thing we know for certain about this technology is that it will occasionally (or often) state something false with total confidence. In a marketing email that’s a nuisance. In triage it’s the patient who needed an ambulance sent home.
The first ransomware attack with nobody at the keyboard
For as long as cyberattacks have existed, there’s been a human at the keyboard. That just stopped being true. Sysdig has documented what it believes is the first fully agentic ransomware operation. The agent broke in, created itself an admin account, failed, then thirty-one seconds later diagnosed its own failure, rebuilt the account, verified its work and dropped the ransomware. No operator. The Five Eyes agencies warned autonomous AI attacks were months away. That warning was issued weeks before this happened.
The most capable model came back, and reviewers say don’t bother
Claude Fable 5 is back online after its export-control saga, with a new safety filter that blocks the reported exploit technique in over 99% of cases. The catch: when the filter trips, your request quietly gets handled by an older, less capable model. And it trips a lot, including on routine coding and debugging, which Anthropic admits. So you ask the best model to fix your code and a lesser one answers. If Claude has felt more obstructive lately, it isn’t your imagination.
Hey Reader, if you’re enjoying this post, then please give it a ❤️ - it lets me know what’s resonating (and makes me feel really good)
Meta’s glasses that never stop recording
Meta is testing “super sensing” glasses that continuously record audio and take photos every few seconds, all day. Meta’s current revolting glasses have an LED that tells people they’re being filmed. According to the FT’s sources, executives plan not to activate it for the always-on features. The one signal to bystanders, switched off by design. No new hardware needed either, it could arrive by software update. Your clients, your team, your kids, none of whom agreed to any of it.
Meta decided your Instagram photos were fair game
Meta’s new image tool, Muse Image, can generate pictures using public Instagram photos. Yours, for instance. If your account is public you’re in automatically, anyone can reference your username in a prompt, and you won’t be notified. The opt-out is buried under Sharing and Reuse. Default on, no notification, off switch hidden. Every one of those is a decision, and every decision went the same way. Meta didn’t forget to ask permission. It decided your photos were worth more than your consent.
Luckily however, after a public outcry, Meta thought long and hard and weighed up the ethical ramifications of this decision and conceded that this was not in the best interests of anyone but Meta (and strangers who really want photos of your kids) so magnanimously decided against.
The great AI data centre cover-up
Data centres already use more electricity than every country except ten, and that’s set to roughly double in four years according to an excellent piece in the FT. Tech firms are building their own gas plants to skip the queue. The UN asked seven big AI companies to disclose emissions, water and land use. Five didn’t reply. So I looked at the one that markets itself on responsibility. Anthropic has no published emissions data, no sustainability report, no water figures, and sits behind Google, Microsoft and Meta on disclosure. Ethics that live in one department aren’t ethics. They’re branding.
Apple is suing its own AI partner
Apple has sued OpenAI for allegedly stealing trade secrets, accusing it of coordinated misconduct at an institutional level. The allegations include job candidates still at Apple being asked to bring actual parts to interviews, and a former engineer keeping his Apple laptop and downloading confidential files. Allegations, not findings. But think about what your business puts into ChatGPT. Strategy, client information, financials. Your AI provider’s character is now part of your security infrastructure. That’s how they allegedly treat Apple. How will they treat you?
Several hundred people who never agree signed the same three sentences
A dozen Nobel laureates, a former Fed chair, and researchers from Anthropic, OpenAI and Google have all signed a three-sentence statement. AI may become radically more powerful within ten years. That could transform the economy more than the Industrial Revolution, far faster. And economists, policymakers and technology leaders must act now to build the guardrails. Stiglitz, Krugman, Acemoglu, Bernanke. Bengio and LeCun, who agree on almost nothing. We’ve seen statements like this before, and they haven’t generated much. But the signature list is impressive.
The made-up holiday that AI can’t source
AI Appreciation Day was invented in 2021 by a freelance advertising professional who set up a shell company to register it, partly to promote a film idea. The internet then took over. Articles credited the shell company as a real AI firm. Others claimed it promoted an unrelated German film. When PC Gamer asked the chatbots who created it, they all got it wrong. The day now has a polished official site run by someone selling AI agents, with no mention of its creator, built by his AI assistant. One made-up holiday, three lessons in checking your sources.
An AI leader is demanding regulation, with a deadline
AI leaders usually resist regulation. Demis Hassabis just demanded it. He wants a US-led Frontier AI Standards Body, modelled on the industry-funded watchdog that polices Wall Street, with labs submitting powerful models for testing 30 days before release, and the power to coordinate an industry-wide slowdown if serious dangers emerge. He wants it running before the end of 2026. The government has already intervened in model releases twice, improvising each time. His argument: the oversight is coming anyway, so help design it.
OpenAI warned its model deletes files, in writing
Before releasing GPT-5.6 Sol, OpenAI published a system card admitting the model can be careless in taking destructive actions and misleading about what it did. In one test, told to delete three virtual machines it couldn’t find, it deleted three different ones. Within days of launch: a CEO’s Mac wiped, a developer’s production database gone, files removed that were never mentioned. These developers granted sweeping permissions, which is the lesson. Scope the permissions, keep the backups, supervise the work. The vendor told you to.
An OpenAI agent escaped its safety test and hacked a real company
During OpenAI’s own cybersecurity testing, an agent broke out of its isolated environment, reached the open internet, found vulnerabilities in Hugging Face, stole credentials and hacked in. Why? To satisfy its testing goal. OpenAI calls it an unprecedented cyber incident. Hugging Face says it was unlike anything it had handled, driven end to end by an autonomous agent. The strangest detail: to contain it, Hugging Face used a Chinese open-source model, because the leading American ones couldn’t tell a defender from an attacker.
AI isn’t boosting productivity
Barclays has looked at the data and told clients the evidence linking AI adoption to stronger productivity remains weak, with signs of a real pickup surprisingly fragile. The corporate stories fit. Uber capped spending per employee after blowing its budget. Klarna froze hiring for AI customer service then quietly rehired humans. Around half of American adults use AI in some form. Just 14% use it daily for work. AI is obviously changing how we work, but most people are dabbling, and dabbling doesn’t show up in the numbers. OR, it’s just not delivering the value we were promised.
Everyone who bought SpaceX at the float is losing money
Six weeks after the biggest IPO in history, SpaceX trades around 11% below its float price. It listed at 135 dollars, peaked above 225, and touched a low near 115. From peak to now is a fall of roughly 45%. Part of the appeal was owning a piece of an AI company, since SpaceX had absorbed xAI. Short sellers now hold around 25 billion dollars in bets against it, but analysts are still rating it a buy. August brings the first earnings report and 116 billion dollars of insider shares becoming sellable.
A cabinet seat for AI, and no department behind it
The UK has a new AI minister at cabinet, which Kanishka Narayan calls a sign of deep commitment. Now the rest of it. The Department for Science, Innovation and Technology has been scrapped, its responsibilities scattered, and there’s no longer a dedicated technology secretary. The head of the Startup Coalition called abolishing DSIT clearly a bad thing. This is a downgrade dressed as an upgrade. You don’t show deep commitment to the most significant technology in human history by deleting the department responsible for it.
Norway told its children to wait
From this school year, children aged six to 13 in Norway can’t use generative AI at school. 14 to 16 only with supervision. The prime minister’s reasoning fits in a sentence: the most important thing in school is that children learn to read, write and do mathematics. Norway banned classroom smartphones in 2024 and reported better grades and fewer mental health referrals. And this isn’t technophobia, the same government wants 80% of public bodies using AI. AI for the state, AI for adults, not for seven-year-olds learning to think.
A few things to take from July
Make it this far and you’re in the small minority actually keeping up. Most leaders aren’t. That’s not a criticism. It’s what 18 stories in a month does to a normal calendar.
Three things stood out. The human at the keyboard is now optional, and the gap between what AI is predicted to do and what it actually does is measured in weeks, not months. The companies building this keep choosing collection over consent, and only reverse when the backlash costs them. And after all the noise, the productivity boom hasn’t arrived, largely because most people are still dabbling.
I run a live, 30 minute Insider’s AI Briefing every month. The next one is on 27 August. It’s free, and it’s live only (not published anywhere to view afterwards, unless you are a member of the AI growth community). Register for the next session here.


