AI Frontier · May 26, 2026
Product and model developments from OpenAI / Anthropic / Google. Security-related items are marked 🛡 and additionally archived under
intel/ai-frontier/security/.
OpenAI
Products & Models
-
OpenAI × Folha de S.Paulo / Grupo UOL (first Brazilian media partnership, 5/25)
ChatGPT's 900 million weekly active users worldwide begin seeing news summaries from Folha de S.Paulo / UOL inside ChatGPT. OpenAI's Latin American content footprint formally opens.
OpenAI announcement -
Codex on Mac — apps can keep running with the screen locked / off (5/22–5/24 updates)
Codex's macOS desktop agent, after three upgrades in the past six weeks (4/16, 4/20, 5/14), now reaches this point: with the Mac's display off and locked, Codex can still execute app tasks remotely, triggered by the iPhone / Android ChatGPT app pushing a session to the paired Mac. Security features shipped alongside: short-lived authorization windows, screen masking, immediate re-lock on detecting local input, and a manual unlock fallback.
MacRumors · Macworld · TechTimes -
Confidential IPO filing in preparation (reported by Reuters / CNBC, 5/20)
Working with Goldman Sachs and Morgan Stanley to prepare an S-1 draft, possibly filed within days to weeks.
CNBC
Security-related
-
GPT-5.5-Cyber continues to widen (Trusted Access for Cyber, since 5/7)
The most "permissive" cybersecurity-oriented model — open only to vetted critical-infrastructure defenders, paired with strong account controls and verification. The UK AISI has published an independent evaluation of its capabilities.
OpenAI · Help Net Security · AISI evaluation
→ Archived:intel/ai-frontier/security/2026-05-26-openai-gpt55cyber-rollout.md -
OpenAI caught up in the TanStack/Mini Shai-Hulud supply chain incident
OpenAI self-reported that the 5/11 npm worm wave compromised 2 employee devices and that internal code repositories were accessed; it has rotated its iOS / macOS / Windows code signing certificates as a defensive measure.
Phoenix Security write-up
→ Archived:intel/ai-frontier/security/2026-05-26-openai-shaihulud-impact.md
Anthropic
Products & Models
-
Code with Claude series (London 5/19–5/21 concluded; Tokyo 6/5–6/6)
The developer conference series continues: new Managed Agents capabilities (dreaming, multi-agent orchestration, outcomes, webhooks) and higher Claude Code / Opus API limits. MIT Tech Review reported from the floor that this is the future of software development, "whether you like it or not."
MIT Technology Review · Anthropic Events -
Brief Opus 4.7 elevated error rate incident (5/25)
Claude Opus 4.7 saw a period of elevated error rates, resolved the same day.
Claude status page -
Reaffirmed commitment to no advertising in Claude
Anthropic restated its position: advertising incentives are incompatible with a trustworthy AI assistant; growth will come by non-advertising means.
Security-related — the day's major item
- Project Glasswing formal monthly update (5/22) + partner expansion on 5/26
Anthropic published the first formal Glasswing monthly update on 5/22 (the 5/23 preview finalized as this month's official version), and on 5/26 further expanded the partner roster. Cumulative data for Claude Mythos Previewover the past 30 days:- ~50 partners have collectively found 10,000+ high/critical vulnerability candidates
- Cloudflare: identified 2,000 bugs in core systems, 400 of them high/critical; a false-positive rate "lower than human testing"
- Mozilla: identified and fixed 271 vulnerabilitiesduring the Firefox 150 test period, distinctly better results than the earlier Opus 4.6 trial run
- wolfSSL: found a certificate forgery vulnerability (CVE-2026-5194) and built a working exploit — one that would let an attacker stand up fake bank/email TLS sites that look perfectly legitimate. Now fixed.
- The bottleneck is no longer discovery but fix speed — high/critical vulnerabilities take two weeks on average to remediate, and some OSS maintainers have asked Anthropic to slow disclosure
- The public release of Mythos remains paused — Anthropic states bluntly: "no company, including us, has built safeguards reliable enough to prevent misuse of a Mythos-class model"
Glasswing monthly update· Help Net Security· Benzinga (partner expansion)· Dataconomy· gHacks
Google DeepMind / AI
Products & Models
-
Google I/O 2026 follow-through — the Gemini 3.5 family keeps rolling out
Ongoing topics this week: Gemini 3.5 Flash GA, 3.5 Pro in internal use (broad rollout next month), Gemini Spark at the consumer tier; the Ultra subscription drops from $250 to $200/month, with a new $100/month Developer tier. Gemini MAU at 900 million (2x year over year).
Tom's Guide live coverage · explainx.ai recap -
Project Zero — full Pixel 10 0-click root chain published (5/13)
Seth Jenkins / Jann Horn published the complete chain: CVE-2025-54957 (Dolby UDC decoder, triggered automatically along the Google Messages transcription path) + a mmap handler vulnerability in the new Pixel 10/dev/vpudriver = arbitrary kernel read/write within a day.
Project Zero · CyberSecurityNews
Security-related — the day's major item
-
Big Sleep's counter-discovery blocked an attempted mass exploitation with an AI-generated 0-day (GTIG disclosure, 5/11)
Google Threat Intelligence Group (GTIG) disclosed that it identified an attacker holding a suspected AI-developed 0-day aimed at a mass exploitation event; Big Sleep (the AI vulnerability discovery agent from DeepMind / Project Zero) may have prevented it from landing by finding the flaw proactively in advance. This is the first real-world case on public record combining "AI-generated exploit × planned mass exploitation × defender-side AI discovering it first."
Google blog · CNBC
→ Archived:intel/ai-frontier/security/2026-05-26-google-bigsleep-counter-discovery.md -
GTIG — report on AI vulnerability exploitation
The first comprehensive vendor-perspective report on "AI-augmented exploit development + agentic operations + initial access." Together with PROMPTFLUX/PROMPTSTEAL from Mandiant M-Trends 2026, it forms a complete picture.
Google Cloud — AI vulnerability exploitation
→ Archived:intel/ai-frontier/security/2026-05-26-google-ai-vuln-exploitation-report.md
🛡 = security-related. Items archived under
intel/ai-frontier/security/are folded into the weekly security roundup each Monday.