So, What Actually Happened?
Tuesday morning, second coffee, and I keep circling one detail from a Washington briefing: the framework is not being published. The administration walked the major labs through how it will test frontier models and then kept the test itself classified. We scanned 190,000 articles this week so you don't have to. Inside the same 24 hours, OpenAI opened a cyber-specific model tier to vetted defenders only, and a young Israeli startup raised $60 million with Sequoia leading, on the pitch that defenders are losing. I filed those as three separate stories. Policy, product, funding. Then I noticed each one is somebody deciding who is allowed to hold a capability, and in none of the three is that somebody you.
The Bottom Line: Three new gatekeepers appeared in a single day, and every one of them sits upstream of something your team already has in the budget.
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
The Tracks That Matter
1. OpenAI Now Decides Which Defenders Get The Cyber Model
OpenAI split its Daybreak program into two tiers and put a purpose-trained security model behind the gate: GPT-5.6-Cyber clears 95.0% of advanced cybersecurity requests against 1.5% for the general-purpose model, and it found a high-severity flaw in the V8 engine that runs Chrome's JavaScript. Read the tiers again. Blue is frontier access with defensive safeguards. Red is exploit validation and vulnerability research, for approved partners only, and Sophos is already inside that arrangement. So one company ships the capability, runs the vetting on who may point it at a live system, and publishes the benchmark that proves how big the gap is. The safeguards look sensible. The concentration is the story.
Here's what works: Ask your security vendor which AI access tier they hold and who grants it. If the answer is a marketing page, you have a hope, not a supply chain.
2. Sequoia Bet $60M That Defenders Are Already Behind
Corma came out of quiet with $60 million in seed funding, which is a lot of money for a company whose thesis fits in one line: attackers have a structural speed advantage and human teams cannot close it. Founder Alon Pluda is building a defensive model from scratch rather than wrapping a general one, and Sequoia's Shaun Maguire backed exactly that distinction. Whether or not the thesis holds, the market is now pricing it as true, and you can see the same assumption in the unglamorous work below it: identity-based controls for AI browsers are being specified right now because nobody wants to hand an autonomous agent a session cookie and hope. The security line item is quietly turning into a model line item.
Here's what works: Before buying a defensive AI, ask what it does when your own agents are the anomaly. Most tooling still assumes the intruder is a human.
3. Washington Wrote The AI Rulebook And Classified It
The administration briefed the labs on a framework for testing ”covered frontier models” and then declined to make the framework public. Neil Chilson, who sat in the briefing, said the power to decide who gets powerful models and who does not should not be exercised behind closed doors by one branch of government. Samuel Hammond made the narrower legal point: final agency decisions are textbook public records. Set that next to Ottawa, which put its national AI strategy out in the open for anyone to pick apart. Both approaches decide who gets to build what. Only one of them lets your legal team read the rule before it starts applying to you.
Here's what works: If anything you deploy could fall under frontier rules, have counsel request the framework now. Waiting for it to be published is not a compliance plan.
Quick hits:
- The AI factory round got another zero. Firmus raised $2 billion at a valuation above $10.5 billion to build out more capacity. So-what: compute is still being financed years ahead of the demand curve that justifies it.
- One endpoint became a single point of failure. A sharp architecture argument makes the case that hardcoding one model provider stopped being an acceptable availability strategy this year. So-what: your resilience review needs a model row, not just a cloud row.
- Your competitors are now scoring your AI. Fortune's AIQ ranking partly grades companies on how rivals rate their AI use, from a final sample of 165 technology leaders. So-what: your AI reputation is being set by peer opinion on a sample smaller than most usability tests.
Signal vs. Noise
🟢 Signal: agentic AI as a threat model. It gained real ground on Monday, and the anchors are concrete: a purpose-trained cyber model shipped behind an approval gate, and $60 million of seed money placed on the claim that autonomous attackers move faster than any human team. Most coverage still files agentic AI under productivity, which is why the security budget keeps getting surprised by it.
🔴 Noise: ”AI governance” as a phrase. It is still one of the loudest labels in circulation and it is steadily losing its hold on what actually gets decided. The real choices moved to named things: who approves model access, which jurisdiction holds the weights, which provider you can drop without an outage. When a label stays loud and stops carrying weight, the work has moved to a more specific name.
Wake Up Smarter About AI.
The president of OpenAI. The CEO of Google. The founder of LinkedIn. We talk to the people building AI. Every morning, we put what they told us in your inbox.
What they're actually worried about. What they're betting on. What's coming next. Delivered in five minutes, before your first meeting.
With one email, and only five minutes, you can stay ahead of 99% of the world.
From the 190K
We scanned 190,000 articles this week. Here's what no one's talking about:
A model vendor started deciding which defenders get the cyber tier, a government classified the test that decides which models count as frontier, and the architecture advice of the day was to stop depending on any single provider.
Three desks, three stories, no overlap. The security press covers the model tiering. The policy press covers the withheld framework. The engineering blogs cover multi-provider design. Read them on the same morning and they are one story: access to AI capability is being rationed by allowlist, in three separate places at once, and none of those allowlists runs through your procurement process. The vendor decides your tier. The regulator decides the category, in private. The architecture decides whether losing either one takes your workflow down with it.
That is not a conspiracy, it is just what happens when a capability gets valuable enough to control. The uncomfortable part is that the standard enterprise answer, buy from the leader and standardise, is now the exact behaviour that hands all three switches to other people.
What changes for you this week is small and specific: for the two AI capabilities your business actually depends on, write down who can revoke your access, on what notice, and what you would run instead by Friday. If that page is blank, you are not managing a vendor, you are a guest.
By The Numbers
- GPT-5.6-Cyber completes 95.0% of advanced cybersecurity requests, against 1.5% for the general model — the capability gap between gated and open access is now measurable, and it is enormous.
- Corma raised $60 million in seed funding led by Sequoia — that is late-stage money at seed stage, for a bet that current defensive tooling is structurally too slow.
- Firmus raised $2 billion at a valuation above $10.5 billion — capacity keeps getting funded on conviction, well ahead of contracted demand.
- Fortune's AIQ ranking rests on a final sample of 165 respondents — the number quoted in your next board deck about AI leadership is thinner than it sounds.
- Nike projected $2 billion of savings over five years from its digital supply chain — the pre-AI version of the same business case, and the shape has not changed: big number, long horizon, quiet dependencies.
- See what's rising across AI and data this week →
Deep Dive: Who's On The Guest List
Every club I ever played had two doors. The public one with the queue, and the side one with a clipboard. I learned early that the clipboard was the real venue. You could be the better DJ and still not get in the booth, because access was never about the music, it was about who knew you.
The clipboard moved into the stack
That is Monday's shape. A vetted tier for cyber models, a classified test for frontier models, an approval list for exploit research. None of it is hidden, all of it is discretionary. The capability exists, and somebody else decides whether it exists for you.
Standardising is the thing that costs you
The advice enterprises have followed for three years is pick the leader and go deep. It made sense when the risk was fragmentation. It stops making sense when one provider's policy change can shut down a workflow you sell to customers. Depth is a virtue right up to the moment it becomes a dependency you cannot price.
A second name is cheaper than a second outage
You do not need a full parallel stack. You need one workload proven on a second provider, one contract that names a notice period, one owner who can answer what happens if access ends on Friday.
What Actually Works
- Name the revoker: for each AI capability in production, write down who can turn it off and how much notice you would get. Evolution, not revolution, start with the two that matter.
- Prove one fallback: run a single real workload against a second provider this quarter. Not a demo, a workload, with numbers.
- Put access terms in the contract: tiers, approval criteria and notice periods belong in writing, not in a vendor blog post.
- Ask for the rule before it applies: if a regulator is testing your category in private, have counsel request it now rather than reading about it after enforcement.
Play the room you are actually in. Just make sure you know who is holding the clipboard, and what it costs you the night they stop writing your name down.
Build a digital marketing strategy that drives better results.
HubSpot Academy's Digital Marketing Certification covers SEO, email, paid ads, social, and AI — in just over 3 hours, at zero cost. Join 200,000+ professionals who have advanced their career with HubSpot Academy. Get started today.
What's Coming
Access Tiers Become A Procurement Question
Now that defensive AI ships in approved tiers, the next security RFP will ask which tier a vendor holds and who granted it. Expect that line to appear in questionnaires within a quarter, and expect a lot of vendors to answer badly the first time.
The Classified Rulebook Meets A Records Fight
A framework that decides which models count as frontier, withheld from publication, is a public-records request waiting to happen. Someone will file, and the response will tell you more about how this administration intends to regulate AI than the framework itself would.
Multi-Provider Stops Being A Preference
The argument that one provider endpoint is a single point of failure is moving from blog posts into audit findings. Regulated industries will be asked to show a tested fallback, and ”we use the market leader” will not survive the question.
For Your Team
Wednesday's meeting prompt: ”Pick our two most important AI capabilities. Who can revoke our access to each one, how much notice would we get, and what runs instead? If nobody in this room knows, we are not a customer, we are a guest.”
Share-worthy stat: A gated cybersecurity model completes 95% of advanced security requests where the general-purpose version manages 1.5%. The gap between having access and not having it is no longer a matter of degree.
Go deeper: Track how AI access, security spend and policy are moving in real time →
The Track of the Day
”That type of ability to choose who gets to have powerful models and who doesn't, I just think that's not appropriate to be done behind closed doors by a single branch of the government.”
Neil Chilson, on the framework Washington briefed but would not publish
Every venue has a guest list. The trouble starts when you find out you were never on it, on the night you needed to play.
We scanned 190,000 articles this week so you don't have to. Data Pains → Business Gains.
Published: 2026-08-11 | Curated by Yves Mulkers @ Ins7ghts
1,300+ articles scanned. 7 stories selected. Our AI distills the noise into signal—in seconds. Get early access →
Know someone who'd find this useful? Share your unique referral link →
Want Your Own AI Intelligence Briefing?
Our platform analyzes 1,000+ sources daily and delivers personalized insights in seconds.
Join the Waitlist →Founding members: Lifetime discount • Priority access • Shape the product




