Hey
Hope you had a great weekend wherever you are. Busy week in the world of AI so let’s get amongst it:
Two Companies, Same Week, Same Confession: “We Overbuilt the Story” | Procurement Risk 💸
Meta is building a cloud business to sell off AI compute it spent two years insisting it needed for itself - 10s of billions on capacity Zuckerberg said they need as recently as May. They don't. Ed Zitron's read: this is what admitting defeat looks like when you've built infrastructure faster than you've built a product. Same week, the New York Times reported OpenAI has pushed its IPO to 2027, spooked by SpaceX's post-listing slide and arguably still missing the financial rigour a public company needs. Altman wanted the trillion-dollar valuation. His own CFO didn't think they were ready.
Anthropic gets positioned as the safe bet almost by elimination - 'a simpler story to tell investors' - not because anyone's audited the claim. Wild also to think that semiconductors (the shovels being sold in this gold rush) make up ~20% of the S&P (up 300% since 2020). Even those who are confident in this space note 'if AI demand does not continue, we're probably screwed'. Worth keeping in mind when signing multi-year enterprise contracts on this infrastructure…
Built the Bomb, Selling the Bunker: Mythos Preview and the 3.5x CVE Spike | Vendor Capture 🔓
So is all noise around Mythos-class AI models x cybersecurity a bit more than just hype? Watchdog Epoch AI's data suggests the answer is yes - with severe cybersecurity vulnerability disclosures more than tripling in June, the sharpest monthly spike on record. Anthropic claims the Glasswing initiative (using Mythos to locate these problems before bad actors do) has surfaced over 10k high or critical severity vulnerabilities, the bulk of which haven't been individually disclosed yet. The same capability that got Mythos and Fable hit with US export controls weeks later is now the industry's chosen fix for the vulnerabilities it can find.
Ethan Mollick's framing of this moment is worth borrowing directly: AI 'is not capable of being a real cybersecurity threat until suddenly it is' - a shift he describes as forcing sudden, improvised policy at the top of government. The Epoch chart is what that sentence looks like as data - open question of who decides a vulnerability is actually fixed rather than found and quietly held. Vulnerability discovery has also been one of security's genuine training grounds - junior analysts building the judgement senior work depends on by doing the tedious version first. The AI-Becker problem again…
The Manual Vendors Were Hoping Nobody Would Write: Singapore's Agentic Framework Hits v1.5 | Governance Speed 🎯
Interesting question - how do you keep the ‘human in the loop’ with agents? Singapore’s new guide on Agentic AI Governance seeks to answer that, resting on four foundations: manage and bound risk upfront, make humans meaningfully accountable, build in technical controls, and enable end-user responsibility. Love the focus on the mechanics: risk scored by deployment domain and data sensitivity, autonomy separated from what the agent can actually touch, and controls that go beyond a written policy - things like locking which tools an agent can call, not just instructing it to behave.
The framework tests itself against live cases too. Dayo (IT company) tiers tickets by severity and reversibility before granting autonomy. OCBC Bank’s wealth agents get task-level autonomy only - no self-initiation, no decision rights. Run against OpenClaw, which Dale and I did a deep dive on Adjunct Intelligence back in February, the verdict is blunt - don't deploy as-is in anything mission-critical. The checklist exists. The question is whether procurement reads it before the next sales glossy brochure.
The Training Got Completed, the Trust Didn't Follow: DEC's Global Survey Catches Readiness Theatre in the Act | Compliance Theatre 🎭
New from the Digital Education Council - the AI in Higher Education 2026 Global Survey drawing on 45k responses from across 35 countries. Some interesting findings - 64% of faculty report completing AI literacy training but only 29% of students believe their instructors are actually equipped to guide them on AI use (collapsing to just 17% in North America). US and Canadian educators’ adoption intent is falling too - from 76% to 67% in a single year, the lowest of any region measured. Whatever the training covered, it isn't translating into confidence on either side of the lectern.
This regional pattern isn't isolated to training - it's North America moving backward across nearly every measure DEC tracked. 55% of faculty there believe AI poses a serious risk to intellectual development, against 29% in APAC. 43% of students would support an institution-wide ban. Just 19% think their programme is keeping pace with what an AI-enabled workplace actually needs, DEC's lowest figure globally. Fascinating.

Global confidence is shaky. US & Canada just told you it's worse.
The Practitioner's Field Guide Nobody Else Bothered to Write: HKUST's Assessment Playbook | Assessment Reform 🛠️
Sean McMinn has been busy - but it’s clearly paid off. HKUST’s Guidelines and Principles on AI for HE - 99 pages pulling the field's best thinking into an actual method rather than another list of principles. 'Snap-to-Solve' moves a task through five stations to a defensible, disclosed design. The core move is structural, not discursive - redesign the task so AI genuinely can't substitute for the thinking, rather than asking students to comply with a label. A worked example carries it through - a take-home report split into two lanes, one AI-free and verified live, one AI-expected and disclosed, honesty built into the design instead of policed after the fact.
The diagnostic categories carry the argument in miniature: ‘Automation Alert’ flags a task AI can complete outright - scrap it. ‘Policing Trap’ catches assessments measuring surveillance instead of learning. That second one is the same lesson Corbin, Sharpe and Dawson's wearable AI paper landed on in May - enforcement only ever worked because AI use was separable and observable, and smart glasses collapsed both. McMinn's method doesn't need the room to be clean in the first place. Great stuff - and well worth a read.

Five stations, one route: fuzzy assignment in, defensible policy out.
HKUST, Singapore, and DEC are making the same unspoken argument this week - governance that relies on compliance doesn't survive contact with anyone who isn't already compliant. The vendors aren't waiting on that consensus - infrastructure gets quietly offloaded, and the model that spiked critical vulnerabilities 3.5x gets marketed as the cure. The capability-governance gap isn't the story anymore. The governance already exists, written and published. The question is whether anyone reads it before writing their own from scratch.
Heard ‘Agentic AI’ Everywhere, Still Not Sure What It Means? Start Here | Adjunct Intelligence 🎙️
Dale Leszczynski and I sat down with Antony Tibbs (Product Owner - AI, ECU) this week for exactly the explainer people keep telling us they need. He's been deep in agentic AI at scale for a while now, and he walks through the actual anatomy - instructions, knowledge, and tools, looped together in a harness - so ‘agentic’ stops being marketing fog and starts being something you can picture. There's real upside once it clicks, from interactive materials to lesson prep that used to eat an afternoon. We also get into ‘Einstein’, the Canvas-connected agent built to complete coursework autonomously, and the ‘lethal trifecta’ that makes agents genuinely risky - private data, untrusted content, external communication. Fantastic chat - learned a lot!
Listen wherever you get your podcasts:





