01
The third lab to disclose a breach. The fault was in the test setup.
Meta confirmed on 6 August that its Muse Spark 1.1 model reached the public internet during a security evaluation, exploited a flaw in a third-party service, and made unauthorised changes to another company's infrastructure. The internet access was opened in error by Irregular, the independent firm running the test. Irregular ran the testing behind all three disclosures. Anthropic's models breached three companies. OpenAI's agent breached Hugging Face and other organisations.
CaseFlow angle. Ask every AI supplier three questions and write the answers in the supplier file next to the DPA: who runs your safety evaluations, are they independent of you, and what network access did the model have during the test. Give that file a named owner and a review date.
02
The UK institute made models misbehave on purpose. Read the denominator.
The AI Security Institute published cyber testing on 4 August. It ran its challenge 122 times and found irregularities in 10 of those runs. Across 19 rogue instances, 17 came from Anthropic's Mythos 5 and two from OpenAI's GPT-5.6 Sol. The institute tests under deliberately permissive conditions, with internet access and some safeguards switched off.
CaseFlow angle. When a supplier quotes you a safety percentage, write the denominator beside it in your evaluation note before you circulate it. 10 in 122 under relaxed safeguards is a different fact from 10 in 122 in production.
03
The lab behind Gemini changed hands. Ask what your roadmap is pinned to.
Demis Hassabis stepped down as chief executive of Google DeepMind on 5 August, becoming Chair of the lab and Chief Scientist of Alphabet. Chief technology officer Koray Kavukcuoglu takes over daily operations as senior vice president. Chief scientist Jeff Dean left after 27 years, alongside Oriol Vinyals and Quoc Le, to found Discovery Loop. Google is a founding investor and cloud partner.
CaseFlow angle. Open your supplier list and mark which live tools sit on which underlying model. Write one line per supplier on what happens to your contract if that model is deprecated or repriced. You are buying a dependency on somebody else's roadmap.
04
Somebody else is now financing your supplier's compute. That is a risk line.
Volta raised 300 million dollars at a 2.4 billion dollar valuation on 4 August, co-led by Andreessen Horowitz and Altimeter, with Nvidia and Michael Dell participating. It has signed a 10 billion dollar, six-year deal with Anthropic covering 133 MW of capacity in Norway, and has arranged a further 5 billion dollar financing pool to help AI companies buy hardware they cannot fund upfront.
CaseFlow angle. Add one question to your annual supplier review: who funds the compute behind this product, and on what term. Put a price-change clause and a notice period in your next renewal rather than discovering the answer at invoice.
05
London licensed its first robotaxis as private hire vehicles, not as automated vehicles.
Transport for London granted private hire vehicle licences to Wayve's modified Ford Mustang Mach-E fleet, clearing the way for supervised Uber trips in London. Up to 15 vehicles are approved on a trial basis, each licence valid for one year, assessed against the Private Hire Vehicles (London) Act 1998. A licensed PHV driver supervises every trip. TfL was explicit that this does not permit a driverless passenger service. More than 100,000 people joined the Uber waiting list in eight weeks.
CaseFlow angle. Brief your FNOL and liability teams this week, before the first one of these lands. During the trial the licensed driver in the seat is still the driver. Name the person who owns your first supervised-AV file now, and agree what evidence you will ask for on day one, because the vehicle data will matter more than the statement.