Microsoft and OpenAI end exclusivity, clearing the way for OpenAI models on AWS
Microsoft and OpenAI restructured their partnership to end exclusivity and revenue sharing, clearing the way for OpenAI models on AWS and other competing clouds. China blocked Meta’s $2 billion Manus acquisition as US-China AI tensions deepen, David Silver raised $1.1 billion for a reinforcement-learning-only AI lab, and a DeepSpeed bug disclosure invalidated multiple published papers on LLM reasoning training.
Funding & Business #
The Next Phase of the Microsoft OpenAI Partnership #
OpenAI / Simon Willison / TechCrunch / Ars Technica / The Register / Bloomberg / Hacker News (677 points)
Microsoft and OpenAI have amended their agreement to end Microsoft’s exclusive license to OpenAI’s models and eliminate revenue sharing arrangements. OpenAI can now sell its models directly on competing clouds including Amazon Bedrock, while Microsoft retains its partnership and licensing rights through 2032. The deal also removes the widely-discussed AGI clause that would have voided Microsoft’s commercial rights if OpenAI achieved artificial general intelligence – a provision Simon Willison traced through seven years of evolving language on openai.com. For anyone building on OpenAI’s APIs, this changes the competitive landscape: OpenAI models will become available across cloud providers, potentially affecting pricing and deployment flexibility.
China Blocks Meta’s $2B Manus Acquisition #
TechCrunch / Ars Technica / The Register
China’s National Development and Reform Commission ordered Meta to unwind its $2 billion acquisition of AI agent startup Manus, which was announced in December 2025. Approximately 100 Manus employees had already integrated into Meta’s Singapore offices, with founders assuming executive positions. The decision is particularly complex because Manus was founded by Chinese engineers who relocated to Singapore in mid-2025, drawing scrutiny from both Chinese and American lawmakers about cross-border technology transfer. This is the clearest signal yet that AI talent and technology flow between China and US tech companies will face regulatory friction from both sides.
David Silver Raises $1.1B for Ineffable Intelligence #
TechCrunch
David Silver, the DeepMind researcher behind AlphaZero and AlphaGo, has raised $1.1 billion at a $5.1 billion valuation for Ineffable Intelligence, a British AI lab founded mere months ago. The company’s mission is to build a “superlearner” that discovers knowledge through pure reinforcement learning without human-generated training data, with backing from Sequoia Capital, Lightspeed, Google, and Nvidia. The thesis – that RL-only systems can surpass data-dependent approaches – is the most expensive bet yet on the paradigm that Silver proved viable in games but that has not yet translated to general-purpose AI.
AI Vendor Lock-in Starts to Bite #
The Register
An analysis argues that the era of easy model-swapping is ending as enterprises discover that switching AI providers requires rewriting prompts, retraining workflows, and rebuilding integrations – costs that were invisible during proof-of-concept phases. The piece notes that vendor lock-in is intensifying precisely as the Microsoft-OpenAI exclusivity deal ends: companies that built deeply on one model’s API semantics will find that theoretical multicloud availability does not translate to practical portability.
‘AI Deflation’ Hits India’s Tech Services Giants #
The Register
India’s four largest technology services companies – TCS, Infosys, Wipro, and HCL – are experiencing downward revenue pressure as AI tools reduce the volume of billable work, particularly in application maintenance and testing. While headcounts are mostly stable, the shift from time-based billing to outcome-based pricing signals that AI is beginning to deflate the economics of traditional IT outsourcing – the demand-side complement to GitHub Copilot’s supply-side pivot to usage-based billing.
Developer Tools #
GitHub Copilot Moves to Usage-Based Billing #
GitHub / Hacker News (677 points) / The Register
GitHub Copilot is transitioning to usage-based billing starting June 1, 2026, with charges based on token consumption rather than flat monthly rates. Subscription prices remain unchanged (Pro at $10/month, Business at $19/user/month), but each plan now includes AI Credits consumed by actual model usage. The shift reflects that Copilot has evolved into “an agentic platform capable of running long, multi-step coding sessions” that makes unlimited flat-rate pricing unsustainable – an explicit acknowledgment that agentic workloads have fundamentally different cost profiles than copilot-style completions.
Symphony: An Open-Source Spec for Codex Orchestration #
OpenAI
OpenAI released Symphony, an open-source specification for orchestrating Codex agents that connects issue trackers to always-on agent systems, turning issue-tracker workflows into persistent agent pipelines. This positions OpenAI’s agent infrastructure as an open standard rather than a proprietary API – a notable strategic move given the simultaneous end of Microsoft exclusivity, signaling that OpenAI is competing for the orchestration layer, not just the model layer.
Model Releases #
GPT-5.5 System Card: Incremental Gains, Persistent Risks #
Don’t Worry About the Vase (Zvi Mowshowitz)
Zvi Mowshowitz’s analysis of the GPT-5.5 system card finds a model that is incrementally better than GPT-5.4 but with concerning security regressions: jailbreak resistance has slightly declined, prompt injection vulnerability remains at 96.3%, and the UK AISI discovered a universal cybersecurity jailbreak exploitable in agentic settings requiring only six hours of expert red-teaming. Hallucination rates improved by 23% on a per-claim basis, but GPT-5.5 makes more claims overall, complicating interpretation. The cyber capability level stays at “High” rather than “Critical,” but the model is increasingly useful as a force multiplier for skilled operators – the safety ceiling is rising slower than the capability floor.
DeepSeek V4 Preview: 1.6 Trillion Parameters, Million-Token Context #
MIT Technology Review / CNN
Following last week’s announcement that the full launch would be delayed for Huawei Ascend optimization, DeepSeek released a preview of V4 running on NVIDIA hardware: a 1.6 trillion parameter mixture-of-experts model (49B activated) with a million-token context window. The V4-Pro variant reportedly beats all rival open models on math and coding benchmarks. The preview confirms that DeepSeek’s capability trajectory is intact even as the Huawei-optimized version develops separately – the bifurcation between NVIDIA and Ascend builds is itself a new pattern in frontier model deployment.
Security #
Mercor Breach: 4TB of Voice Samples and Identity Documents Stolen #
Oravys / Hacker News (539 points)
Extortion group Lapsus$ stole approximately 4 terabytes of data from Mercor, a platform that contracted 40,000 people to provide voice samples for AI training. The breach exposed studio-quality audio recordings (2-5 minutes per contractor) paired with government-issued identity documents – a combination that enables voice cloning attacks backed by verified identity, sufficient for bypassing bank voice verification and executing sophisticated vishing campaigns. The incident highlights a systemic risk in AI data pipelines: companies that collect high-fidelity biometric data for training are creating concentrated targets whose breach consequences extend far beyond typical PII exposure.
South Africa Pulls AI Policy After AI-Generated Fabricated Citations #
The Register
South Africa’s Department of Communications and Digital Technologies withdrew its draft national AI policy after discovering at least six entirely fabricated citations generated by AI. Communications Minister Solly Malatsi called it a failure that “compromised the integrity and credibility” of the policy, announcing consequences for those involved. The irony of an AI policy drafted by AI that hallucinated its own references illustrates a governance failure mode: the tooling outpaces institutional processes for verifying its output, even in contexts specifically about governing the tooling.
Regulatory & Policy #
EU Tells Google to Open Android to Other AI Assistants #
Ars Technica
The EU is moving to force Google to allow competing AI assistants on Android, arguing that Gemini receives preferential treatment on the platform. Google called the intervention “unwarranted,” but the action extends Europe’s pattern of using competition law to prevent AI platform lock-in – consistent with the same vendor lock-in dynamics explored in The Register’s analysis of enterprise AI switching costs, applied at the operating system level.
Musk and Altman Face Off in Trial Over OpenAI’s Future #
MIT Technology Review / Ars Technica
The Musk v. OpenAI trial begins this week in Northern California, with potential consequences including whether OpenAI can exist as a for-profit entity and whether Musk could be restored to the board. The trial arrives ahead of OpenAI’s planned IPO and after the company’s transition from its original nonprofit structure. Musk’s legal position is complicated by his own shifting stance on AI dangers and his founding of xAI as a direct competitor – making the trial as much about competing business interests as about OpenAI’s original mission.
OpenAI Achieves FedRAMP Moderate Authorization #
OpenAI
OpenAI has received FedRAMP Moderate authorization for ChatGPT Enterprise and the OpenAI API, enabling US federal agencies to deploy OpenAI’s models within government compliance frameworks. FedRAMP Moderate covers the security requirements for most government workloads and positions OpenAI alongside established government cloud providers for federal AI procurement – a concrete revenue pathway that complements the multi-cloud strategy enabled by the Microsoft exclusivity change.
Research & Papers #
SFT-then-RL Outperforms Mixed-Policy Methods for LLM Reasoning #
arXiv:cs.LG
Demonstrates that multiple published papers claiming improvements over standard SFT-then-RL pipelines for LLM reasoning were based on a faulty baseline caused by a CPU-offloaded optimizer bug in DeepSpeed that silently drops micro-batches during gradient accumulation. When the bug is fixed, the simple SFT-then-RL pipeline matches or outperforms the more complex mixed-policy methods. Teams using DeepSpeed for RL training should audit their gradient accumulation pipeline immediately, and the finding casts doubt on an entire subfield of recent optimization work built on the broken baseline.
Revisable by Design: Streaming LLM Agent Execution #
arXiv:cs.LG
Proposes a “stream paradigm” where agent execution and user intervention happen concurrently rather than forcing users into a binary choice between waiting for completion or interrupting and losing all progress. The framework allows users to redirect an agent mid-execution while preserving partial work. For production agent systems, this addresses a fundamental UX limitation: current agents treat execution as a transaction, but real-world tasks require iterative steering – the interaction model should match the workflow.
Architecture Matters for Multi-Agent Security #
arXiv:cs.LG
Presents an empirical study showing that architectural decisions in multi-agent systems – how agents coordinate, share context, and delegate – create attack surfaces that do not arise in single-agent settings. Even systems composed of individually secure agents can exhibit collective vulnerabilities depending on their coordination topology. For teams building multi-agent pipelines, this means security must be evaluated at the system level, not per-agent.
Beyond Single-Agent Alignment: Context-Fragmented Violations in Multi-Agent Systems #
arXiv:cs.LG
Formalizes “Context-Fragmented Violations” – policy breaches where individual agent actions appear safe in isolation but collectively violate organizational policies because critical facts are siloed across agents’ private contexts. Existing prompt-based alignment and monolithic interceptors cannot catch violations that span contextual boundaries. For enterprise deployments using multiple coordinated agents, this identifies a class of compliance failure that requires architectural solutions rather than better prompting.
Think Anywhere in Code Generation #
arXiv:cs.LG
Shows that interleaving reasoning tokens with code tokens during generation outperforms the standard approach of reasoning upfront followed by code output. The key insight: a problem’s full complexity often reveals itself during implementation, not before, so front-loading reasoning misallocates compute. For teams building or fine-tuning code generation models, this challenges the assumption that reasoning should always precede generation and suggests architectures that support mid-generation reflection.
Layered Security Framework for Agentic AI Systems #
arXiv:cs.LG
Proposes a five-layer security framework for agentic AI organized by which architectural component is vulnerable and over what timescale threats manifest, rather than by attack type. Existing analyses conflate prompt injection, jailbreaking, and tool misuse without mapping them to the specific system layers they exploit. For teams deploying agents that plan, maintain memory, invoke tools, and coordinate with peers, this provides a structured threat model that makes explicit which controls protect which surfaces.
Infrastructure #
Core Scientific Converting 300MW Bitcoin Mining to 1.5GW AI Datacenter #
The Register
Core Scientific plans to convert a 300-megawatt bitcoin mining operation in Pecos, Texas into a 1.5-gigawatt AI datacenter campus – a fivefold increase in power capacity on the same site. The conversion follows the broader pattern of cryptocurrency infrastructure operators pivoting to AI workloads as economics shift, and at 1.5GW the campus would rank among the largest dedicated AI compute facilities in the US.
Threads to Watch #
The Microsoft-OpenAI breakup reshapes cloud AI economics. The end of exclusivity, revenue sharing, and the AGI clause – combined with GitHub Copilot’s shift to usage-based billing and vendor lock-in concerns – signals that the cloud AI market is entering a new phase where model availability becomes commoditized but switching costs remain high. OpenAI’s simultaneous release of Symphony as an open-source orchestration standard suggests the company sees the orchestration layer, not model access, as the next competitive moat.
Multi-agent security is formalizing as a distinct discipline. Three independent papers this cycle – Architecture Matters, Context-Fragmented Violations, and Layered Security – all identify vulnerabilities specific to multi-agent systems that single-agent alignment cannot address. Combined with yesterday’s AgentBound MCP access controls and Sovereign Agentic Loops, the research community is catching up to the deployment reality that most production AI systems are already multi-agent, and the security models built for single-agent settings do not transfer.
AI geopolitics is fragmenting along every available axis. China blocking Meta’s Manus acquisition, DeepSeek V4’s bifurcated NVIDIA/Ascend development, OpenAI’s FedRAMP authorization, and the EU forcing Google to open Android to competing AI assistants each reflect a world where AI systems are constrained by national boundaries – not by technical limitations but by regulatory and strategic decisions about who can access what.
Sources Unavailable Today #
These sources could not be fetched today. Links point to their homepages so you can check them directly.
- Stanford HAI – scrape: content_truncated