JS Wei (Jack) Sun

Munich binds Google, White House gates OpenAI, Anthropic accuses Alibaba

A Munich court binds Google's AI Overviews, the White House gates GPT-5.6, and Anthropic enlists US export law against Alibaba.

Munich binds Google, White House gates OpenAI, Anthropic accuses Alibaba

TL;DR

  • OpenAI ships GPT-5.6 only to vetted partners under EO 14409’s pre-release review.
  • Munich court rules Google owns its AI Overviews, ending the third-party-hosting defense.
  • Anthropic accuses Alibaba of distilling Claude via a 25,000-account hydra cluster.
  • Alibaba ADRs drop 3%+ as pending H.R. 8283 would treat distillation as export violation.
  • Codex output tokens jump 56x inside OpenAI research, spreading well past engineering.

Three frontier-AI stories today, and the common thread is which lever is doing the work: not capability, not the market, but state authority. A Munich Regional Court told Google its AI Overviews are Google’s own speech, ending the third-party-hosting defense. The Trump White House invoked EO 14409 a second time to gate OpenAI’s GPT-5.6 release to a vetted partner ring. And Anthropic turned its 25,000-account distillation complaint against Alibaba into a test case for pending House bill H.R. 8283, which would reclassify adversarial distillation as an export-control violation.

The lever cuts different ways — binding one lab, gating another, weaponized by a third against a foreign rival — but it’s the same lever. Courts, executive orders, and export law are now the operative force on frontier model deployment, and the labs are learning to argue inside that frame rather than around it.

OpenAI staggers GPT-5.6 to vetted partners on White House ask

Source: techcrunch-ai · published 2026-06-25

TL;DR

  • OpenAI will ship GPT-5.6 to a vetted partner ring, not the public, at the Trump White House’s request.
  • Second application of EO 14409’s “voluntary” 30-day pre-release review, authored by NSA with Treasury and CISA.
  • Anthropic’s June 12 Mythos/Fable shutdown set the precedent — the first federal “recall” of a frontier model.
  • Anthropic’s Opus 4.8 already beats GPT-5.5 69.2% vs. 58.6% on SWE-bench Pro.

The Mythos precedent is doing the work

The GPT-5.6 delay only makes sense alongside what happened two weeks earlier. On June 12, the Commerce Department issued an emergency export-control directive that forced Anthropic to disable Claude Mythos 5 and Fable 5 — the first documented federal recall of a deployed frontier model 1. The trigger, per a Senate Intelligence briefing readout, was a red-team in which Mythos breached “almost all” classified NSA and Cyber Command systems within hours 2.

That is the live operational result the administration is now extrapolating from. The framing for GPT-5.6 is not abstract existential risk; it is “the last model from a US frontier lab broke into our classified networks, and we would like a look at the next one first.” Sam Altman’s reported aside to staff that staggered release is “not our preferred long-term model” reads as compliance under a regime already enforced against a peer.

A “voluntary” regime, in practice

The legal scaffolding is Executive Order 14409 (June 2, 2026), which created a voluntary 30-day federal review window for “covered frontier models” against classified benchmarks 3. The order explicitly disclaims any licensing authority. GPT-5.6 is the test of what “voluntary” means when the asker is ONCD and the alternative is the Mythos treatment.

flowchart LR
    A[Frontier model<br/>ready to ship] --> B{EO 14409<br/>30-day review}
    B -->|classified NSA/<br/>Treasury/CISA<br/>benchmarks| C{Outcome}
    C -->|pass| D[Staggered release<br/>via trusted partners]
    C -->|fail| E[Commerce emergency<br/>shutdown — Mythos path]
    D --> F[TAC ring:<br/>CrowdStrike, Cisco,<br/>JPM, Goldman, etc.]

Senate Democrats are the loudest objectors. Warren and Blumenthal argue the ad-hoc intervention proves the absence of statutory authority and have moved the AI Bubble Transparency Act in response 4. The substantive complaint is not that GPT-5.6 is being reviewed — it is that no one has published the criteria for passing, the list of trusted partners, or the standard of judicial review if a vendor refuses.

Who actually gets the model

The “trusted partner” ring is largely pre-built. OpenAI’s Trusted Access for Cyber program already names CrowdStrike, Cisco, Cloudflare, Palo Alto Networks, Zscaler, JPMorgan, Goldman Sachs, Trail of Bits, and Semgrep as cleared recipients of cyber-tuned GPT-5.6 variants 5. Defense access flows separately via the Microsoft–Palantir IL6 stack. So the practical change from GPT-5.6 is less “OpenAI got slowed” and more “OpenAI’s distribution was rerouted through channels the administration already trusts.”

The competitive clock

The case against staggered release sharpens weekly. Claude Fable 5 currently leads the Artificial Analysis Intelligence Index at 65, with Opus 4.8 at 61 and GPT-5.5 trailing at 60; on SWE-bench Pro, Opus 4.8 hits 69.2% to GPT-5.5’s 58.6% 6. With Fable’s successor lineage paused by Commerce and GPT-5.6 in preview, the frontier capability available to US developers today is a generation behind what the labs have built — and nothing in EO 14409 reaches Chinese releases.

The real question is not whether GPT-5.6 ships. It is whether the voluntary 30-day review survives its first lawsuit, or its first month of being visibly outclassed on a public leaderboard.

Further reading


Munich court: Google owns what its AI Overviews say

Source: simon-willison · published 2026-06-25

TL;DR

  • Munich Regional Court ruled Google’s AI Overviews are Google’s own speech, ending the third-party-hosting defense for generative search.
  • Court rejected the “users can click through to verify” defense after finding almost nobody clicks the source links.
  • Bruce Schneier reads the ruling as agency doctrine: AI outputs bind the deployer the way an employee’s writing would.
  • Legal scholars push back, calling respondeat superior for AI “fictive” without granting the system legal personhood.
  • The EU is instead routing AI liability through the Product Liability Directive 2024/2853, a strict-liability product-defect frame.

What the Munich court actually held

The Munich Regional Court I (Case 26 O 869/26) granted a preliminary injunction to publisher Verlagshaus24 after Google’s AI Overviews falsely tied it to “subscription traps” and “shady business practices” that appeared in none of the cited sources 7. The doctrinal move is what matters: because the system “evaluates, combines, and rewrites information into new and substantive statements,” the output is Google’s own speech — not hosted third-party content 7. The judges explicitly rejected Google’s fallback that users should verify via source links, citing the empirical reality that almost no one clicks 7. Google has announced it will appeal, with analysts noting the ruling effectively requires AI outputs to be “legally defendable” rather than merely helpful summaries 8.

Schneier’s agency frame — and why scholars don’t buy it

Schneier’s argument is clean: an AI agent is the agent of whoever deploys it, full stop. If you’d be liable for a human writer’s defamation, you’re liable for the model’s. That logic already has a Commonwealth precursor in Moffatt v. Air Canada (2024), where the BC tribunal flatly rejected the airline’s claim that its chatbot was a “separate legal entity” and treated it as an extension of the website 9. Munich extends the same reasoning from one bereavement-fare bot to a planet-scale search product.

The dissent is sharper than Schneier’s excerpt admits. Chicago Law Review scholars call applying respondeat superior to AI a “fictive approach” — it requires the AI to hold a “genuine legal duty” it cannot possess without legal personhood, and the analogy “minimizes the unique ways AI fails,” like prompt injection 10. The EU has independently routed around the doctrinal problem entirely: the AI Liability Directive was withdrawn, leaving the Product Liability Directive 2024/2853 to treat AI as a strict-liability product, with EU AI Act non-compliance triggering a legal presumption of defectiveness 11. That is a different theory of the case than Schneier’s.

FrameTheoryWho’s on the hook
Agency (Munich, Schneier)AI output = deployer’s speechDeployer, vicariously
Product liability (EU PLD 2024/2853)AI = defective productManufacturer, strictly
Section 230 carve-out (US debate)Generative output ≠ hosted contentCase-by-case

Who actually pays

Schneier frames immunity as a “massive handout to corporations.” The distributional reality is messier. Section 230 scholarship warns of a “hybrid tiered liability” world where startups face disproportionate litigation exposure while incumbents treat settlements as a line item 12. Google can throttle a feature out of a single jurisdiction overnight; a Series A RAG vendor cannot eat a defamation suit per customer. The safe-harbor era is ending — that much is consensus. How it ends, and which builders survive the transition, is the open question Schneier’s column elides.


Anthropic says Alibaba mined Claude via 25K fake accounts

Source: ars-technica-ai · published 2026-06-25

TL;DR

  • Anthropic alleges Alibaba ran a 25,000-account “hydra cluster” that pulled 28.8M exchanges from Claude to distill a rival model.
  • Defense disclosed: on high-confidence distillation triggers, the API silently swaps in a weaker model to poison the harvested dataset.
  • Independent reviewers note Anthropic has published no logit, tokenizer or weight forensics to back the attribution.
  • Pending H.R. 8283 would reclassify adversarial distillation as a sanctionable export-control violation.
  • Alibaba’s Hong Kong shares fell up to 5% and US ADRs dropped 3%+ as investors priced in Entity-List risk.

The accusation, and the counter-move

The Ars story is the headline number — 25,000 accounts, 28.8M exchanges — but Anthropic’s own engineering writeup is more interesting than the press release. The company describes a behavioral-fingerprinting pipeline plus chain-of-thought elicitation classifiers that cross-correlate accounts into what it calls “hydra clusters” 13. The novel piece is the response: when distillation confidence crosses a threshold, Anthropic doesn’t block the request. It quietly downgrades the responding model, so the adversary keeps scraping — but harvests degraded traces that pollute their training set 13.

That reframes the dispute. This isn’t a one-shot disclosure; it’s Anthropic surfacing a counter-intelligence program it has presumably been running for months, and choosing this moment to make it public.

Where the evidence is thin

The technical case Anthropic has shown the public is not what specialists would call dispositive. Kilo.ai’s writeup notes that Anthropic released no logit comparisons, no tokenizer analysis, no weight correlations — the kind of artifacts you’d expect if you wanted independent researchers to verify distillation rather than take it on faith 14. The viral screenshots of Claude identifying as “Qwen” in Chinese prompts, which circulated as smoking-gun evidence, are at least as consistent with training-data contamination (Qwen model cards and outputs saturate the Chinese web) as with successful theft in either direction 14.

Chinese-language coverage pushed back harder. Researcher Tian Feng and Global Times commentators framed the accusation as “technological hegemony anxiety” and a “kick away the ladder” move, pointing out that knowledge distillation is a standard, lawful technique every frontier lab — Anthropic included — uses internally 15.

Anthropic — itself a defendant in major-label lawsuits alleging it copied song lyrics without permission — is now accusing Alibaba of copying Claude to train a rival AI. 16

That hypocrisy frame is going to follow the story. It’s hard to argue API outputs are sacrosanct trade secrets while defending your own training pipeline against copyright plaintiffs.

Why the timing is not a coincidence

The letter dropped into a ready-made legislative vehicle. Forbes details H.R. 8283, the Deterring American AI Model Theft Act from Reps. Huizenga and Moolenaar, which would reclassify adversarial distillation as a sanctionable export-control violation and create a public “name and shame” list of foreign labs caught extracting US model outputs 17. Anthropic’s 25K/28.8M numbers are precisely the kind of concrete claim a bill like that needs.

Markets read it the same way. Alibaba’s Hong Kong shares fell as much as 5% to their lowest level since early 2025, and US ADRs dropped over 3% 18 — pricing in Entity-List risk, not civil damages.

The open question

Two stories are running in parallel. One is a national-security narrative where 25,000 accounts and 28.8M exchanges become the smoking gun that turns terms-of-service violations into export controls 1718. The other is a forensics question: until Anthropic publishes the logit traces or weight correlations, the attribution rests on its own classifiers 1314. Which story you find more compelling depends largely on whether you think a frontier lab gets to be its own court of record.

Round-ups

Claude gains ground on ChatGPT among paying consumers

Source: techcrunch-ai

Paid-consumer AI spending is tilting toward Anthropic even as ChatGPT keeps a commanding overall lead, according to market data. The shift marks Claude’s first meaningful traction in a subscription segment OpenAI has dominated since launch.

Codex output tokens jump 56x in OpenAI research since November

Source: latent-space

Internal Codex usage at OpenAI has exploded across functions since November 2025, with median output tokens up 56x in Research, 32x in Customer Support, 27x in Engineering, and 13x in Legal. The figures signal coding-agent adoption spreading well past engineering teams.

General Intuition raises $320M to train agents on gameplay video

Source: techcrunch-ai

General Intuition has pulled in $320 million at a $2.3B valuation to train AI agents on millions of hours of video-game footage. The thesis: action data from games teaches world models the physical intuition robots need for real environments.

Patronus AI raises $50M to simulate worlds that stress-test agents

Source: techcrunch-ai

Patronus AI, founded by former Meta researchers, has closed a $50 million round to build simulated digital environments for evaluating AI agents under adversarial conditions. Investors cite near-insatiable enterprise demand as agent deployments outpace the tooling needed to audit them.

Adobe buys Topaz Labs to fold image and video upscaling into Creative Cloud

Source: techcrunch-ai

Adobe is acquiring Topaz Labs and plans to integrate its image and video enhancement tools across Creative Cloud apps. Topaz’s denoising and upscaling models are widely used by photographers and editors as standalone plug-ins to Lightroom and Premiere.

Google Finance exits beta with AI portfolio agent and first mobile app

Source: google-ai-blog, ars-technica-ai

Google Finance has graduated from beta with an AI-powered overhaul and its first dedicated Android app, 20 years after launch. An iOS version is slated for later in 2026, alongside an agent that summarizes holdings and answers portfolio questions in natural language.

Ex-Databricks AI chief targets 1,000x cut in model power use

Source: techcrunch-ai

Former Databricks AI head has unveiled Un-0, an image-generation system designed to replicate conventional model outputs at a fraction of the energy cost. The demo is the first public proof that the startup’s architecture can match standard diffusion pipelines.

Footnotes

  1. Adaptive IS blog — ‘Anthropic Mythos/Fable Shutdown Business Impact’https://adaptiveis.net/blog/anthropic-mythos-fable-shutdown-business-impact/

    On June 12, 2026, the U.S. Department of Commerce issued an emergency export control directive that forced Anthropic to immediately disable Claude Fable 5 and Mythos 5 — the first documented case of the federal government ordering a ‘recall’ of a publicly deployed frontier AI model.

  2. bankwatch.ca (NSA briefing readout)https://bankwatch.ca/2026/06/21/nsa-chief-says-mythos-breached-almost-all-classified-systems-in-hours/

    Mythos breached almost all classified [NSA and Cyber Command] systems in hours

  3. AgenticBrew — analysis of EO 14409https://www.agenticbrew.ai/news/f58c59e2-b099-4bce-ad6d-4f80930e7695/trump-executive-order-on-voluntary-ai-safety-testing

    Executive Order 14409 establishes a voluntary 30-day federal review window for ‘covered frontier models,’ with classified benchmarks developed by the NSA in consultation with Treasury and CISA.

  4. Stefan Bauschard Substack (Congressional reaction roundup)https://stefanbauschard.substack.com/p/education-2526-18-trends-instructional

    Senator Warren has called for additional hearings, arguing that the White House’s reliance on voluntary compliance leaves the public and financial system vulnerable; she and Blumenthal introduced the AI Bubble Transparency Act in response.

  5. OpenAI — ‘Accelerating the Cyber Defense Ecosystem’https://openai.com/index/accelerating-cyber-defense-ecosystem/

    Trusted Access for Cyber (TAC) vets partners — CrowdStrike, Cisco, Cloudflare, Palo Alto Networks, Zscaler, JPMorgan, Goldman Sachs, Trail of Bits, Semgrep, Socket — for access to cyber-tuned variants including the GPT-5.6 preview.

  6. Kilo.ai — ‘Benchmarking the Benchmarks’https://blog.kilo.ai/p/benchmarking-the-benchmarks-new-gpt

    Claude Fable 5 leads the Artificial Analysis Intelligence Index at 65, followed by Opus 4.8 at 61 and GPT-5.5 at 60; Opus 4.8 hits 69.2% on SWE-bench Pro versus GPT-5.5’s 58.6%.

  7. Transparency Coalition (decision summary)https://www.transparencycoalition.ai/news/german-court-holds-google-liable-for-ai-hallucination-read-the-full-decision-here

    the AI evaluates, combines, and rewrites information into ‘new and substantive statements’… very few users actually click through to verify AI claims

    2 3
  8. Leaders League — ‘German court ruling puts AI developers’ liability under scrutiny as Google appeals’https://www.leadersleague.com/en/news/german-court-ruling-puts-ai-developers-liability-under-scrutiny-as-google-appeals

    Google has announced plans to appeal… AI outputs must now be ‘legally defendable’ rather than just helpful summaries

  9. McCarthy Tétrault — Moffatt v. Air Canada analysishttps://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot

    the tribunal rejected Air Canada’s argument that the chatbot was a ‘separate legal entity’… the bot was merely an extension of the company’s website

  10. U. Chicago Law Review Online — ‘Law for Risky Agents Without Intentions’https://lawreview.uchicago.edu/online-archive/law-ai-law-risky-agents-without-intentions

    applying respondeat superior to AI is a ‘fictive approach’… it requires the AI to possess a ‘genuine legal duty’ to commit a tort in the first place, which is legally incoherent without granting the system personhood

  11. IAPP — ‘AI as product vs AI as service: unpacking the liability divide’https://iapp.org/news/a/ai-as-product-vs-ai-as-service-unpacking-the-liability-divide-in-eu-safety-legislation

    the AI Liability Directive was effectively withdrawn… the Product Liability Directive 2024/2853 has become the primary mechanism… non-compliance with the EU AI Act’s safety requirements can trigger a legal presumption of defectiveness

  12. University of Chicago Business Law Review — ‘Generative AI Meets Section 230’https://businesslawreview.uchicago.edu/print-archive/generative-ai-meets-section-230-future-liability-and-its-implications-startup

    may create a ‘hybrid tiered liability’ dilemma where smaller startups face disproportionate litigation risks and compliance costs compared to entrenched tech giants

  13. Anthropic engineering blog (‘Detecting and preventing distillation attacks’)https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks

    Behavioral fingerprinting and chain-of-thought elicitation classifiers flag coordinated ‘hydra cluster’ accounts; on high-confidence triggers the system silently swaps the frontier model for a weaker one to poison the harvested dataset.

    2 3
  14. Kilo.ai blog (‘Did Claude Opus 4.8 distill Alibaba’s Qwen?’)https://blog.kilo.ai/p/did-claude-opus-48-distill-alibabas

    Anthropic has not released forensic artifacts — logit comparisons, tokenizer analysis or weight correlations — and Claude’s habit of identifying as ‘Qwen’ in Chinese is more plausibly training-data contamination than proof of theft in either direction.

    2 3
  15. TrendingTopics.eu (citing Global Times / Tian Feng)https://www.trendingtopics.eu/anthropic-accuses-alibaba-of-large-scale-ai-model-theft/

    Chinese commentators dismissed the accusations as ‘technological hegemony anxiety’ and a ‘kick away the ladder’ tactic, noting knowledge distillation is a standard, lawful technique used by every major lab including Anthropic.

  16. Music Business Worldwidehttps://www.musicbusinessworldwide.com/anthropic-fighting-lawsuits-over-alleged-copying-of-song-lyrics-accuses-alibaba-of-copying-claude-to-train-a-rival-ai/

    Anthropic — itself a defendant in major-label lawsuits alleging it copied song lyrics without permission — is now accusing Alibaba of copying Claude to train a rival AI.

  17. Forbes (Craig Smith) on H.R. 8283https://www.forbes.com/sites/craigsmith/2026/06/25/distillation-the-new-uschina-ai-fight/

    The Deterring American AI Model Theft Act, introduced by Reps. Huizenga and Moolenaar, would reclassify adversarial distillation as a sanctionable export-control violation and create a ‘name and shame’ list of foreign labs caught extracting US model outputs.

    2
  18. 24/7 Wall St.https://247wallst.com/investing/2026/06/25/anthropic-says-alibaba-used-25000-fake-accounts-to-copy-its-ai-and-the-stock-is-already-sliding/

    Alibaba’s Hong Kong shares fell as much as 5% to their lowest level since early 2025 and its US ADRs dropped over 3% as investors priced in possible new sanctions.

    2
Jack Sun

Jack Sun, writing.

Engineer · Bay Area

Hands-on with agentic AI all day — building frameworks, reading what industry ships, occasionally writing them down.

Digest
All · AI Tech · AI Research · AI News
Writing
Essays
Elsewhere
Subscribe
All · AI Tech · AI Research · AI News · Essays

© 2026 Wei (Jack) Sun · jacksunwei.me Built on Astro · hosted on Cloudflare