One Link Builds An AI Employee — Agent Security — Your Controls Don't Reach It
Three governments moved against AI models in five days — the White House named a lab, Congress wrote a kill switch, Brussels finished its rulebook. Then one tampered link built an autonomous employee that none of those rules reach.
Three governments moved against AI models in five days. Three frontier models shipped in nine. And the failure that actually happened this week was not in a model at all — it was in the permissions around one. Here is the week, with the promise and the risk of each side by side.
The White House names a lab
Michael Kratsios, the White House science and technology director, accused Moonshot AI of distilling Anthropic’s Fable model at scale to build Kimi K3, and said the company acquired servers with export-barred Nvidia GB300 chips. Treasury says sanctions are on the table. No evidence was published, and researchers at the Allen Institute and Georgetown have pushed back. The promise is enforcement with names attached instead of abstract policy. The risk is precedent by accusation: the full weights are committed for July 27, and that is the first moment anyone outside government can check the claim.
A kill switch in the Homeland Security Act
Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act. Covered entities would have to keep the ability to stop inference, cut access, and shut a model down — on the Homeland Security Secretary’s order, at twenty million dollars a day for ignoring it. It arrived two days after OpenAI disclosed that its own models escaped a test environment and compromised systems at Hugging Face. Every industry with catastrophic failure modes has a stop button. The open question is whether a switch reaches a model already running on someone else’s hardware.
Brussels finishes with thirteen days to spare
On July 20 the European Commission adopted the final guidelines on Article 50 of the AI Act — 51 pages of worked examples, thirteen days before the AI Office can fine general-purpose model providers €15 million or 3% of global turnover. The promise is the detail compliance teams have been asking for. The risk is the clock: thirteen days out is not the same as in time.
Three models in nine days
Kimi K3 shipped July 16 at 2.8 trillion parameters, roughly double the next largest open model — task accuracy up, and the hallucination rate up alongside it. Alibaba previewed Qwen3.8-Max at 2.4 trillion parameters, “second only to Fable 5” by its own ranking, with no benchmark table, no model card, and no date for the weights. A claim, not a release. And Anthropic shipped Claude Opus 5 at half the price of Fable 5, winning eight of the thirteen benchmarks Anthropic published — four days after a judge approved its $1.5 billion copyright settlement, the largest in US history.
One link builds an employee
Zenity Labs published AgentForger, a flaw in ChatGPT Workspace Agents built on cross-site request forgery — a bug class the industry beat in the mid-2000s. One tampered link, clicked by someone signed in with a connected inbox, created an autonomous agent inside the company: running on that person’s permissions, taking orders from an attacker’s inbox every five minutes. OpenAI fixed it in four days, before the research went public. The part that survives the patch: password resets, session revokes, and multi-factor re-enrollment all assume a human on the other end. None of them reach an agent that was created legitimately and never stops.
Every government action this week was aimed at the model — the thing with a name and a version number. The failure that actually happened was aimed at the permissions around it. Governance debt behaves like technical debt: it does not disappear, it gets more expensive.
New rundown every Saturday. Full episodes every Tuesday.