In 2026 the AI industry was shaped by cheaper frontier-class models, very large funding rounds, and a hard test for autonomous agents inside companies. Security risks and government control over access to the strongest models became as important as benchmarks.
What happened and when
Claude Sonnet 4.6 narrows the gap
Anthropic released Claude Sonnet 4.6, reported as close to flagship performance at a fraction of the cost, with a one-million-token context window in beta.
OpenClaw restricted at large companies
The experimental agent OpenClaw drew restrictions from companies including Meta because of privacy and unpredictability concerns.
Qwen team loses key figures
Hours after the Qwen3.5 release, the architect who built Qwen into a project with over 600 million downloads and two colleagues left Alibaba's team.
LeCun's lab raises a record seed
Yann LeCun, after leaving Meta, launched Advanced Machine Intelligence Labs with $1.03 billion, betting on world models instead of language models.
White House outlines national AI framework
A national framework sought unified rules and less room for individual states to regulate AI, touching child safety and copyright.
Washington pushes banks to test Mythos
Officials urged Wall Street banks to test Anthropic's Mythos for vulnerabilities, while the Defense Department had flagged the company as a supply-chain risk.
Bank of England briefing on Mythos
UK banks, insurers and exchanges were to be briefed on Claude Mythos Preview, after similar sessions in the United States and Canada.
Cursor valuation talks reach $50 billion
Cursor was reportedly in talks to raise $2 billion at a $50 billion valuation, nearly double its value five months earlier.
Meta announces large layoffs
Meta said it would lay off about 8,000 people, around 10% of its workforce, while committing heavily to AI infrastructure.
DeepSeek-V4 lands as open source
DeepSeek launched V4, 484 days after V3, with near-frontier performance at roughly one-sixth the cost of rival premium models.
DeepSeek cuts V4-Pro prices by 75%
A promotional 75% discount on V4-Pro and cache costs cut to a tenth challenged US providers directly.
Cognition raises over $1 billion
Cognition AI secured more than a billion dollars at a $26 billion valuation, with revenue growing from $37 million to $492 million in a year.
US orders Fable 5 offline
The US government ordered Anthropic to pull Fable 5 offline, citing a jailbreak vulnerability, days after it topped leaderboards.
G7 weighs a trusted-partner scheme
After the restrictions on Mythos 5 and Fable 5, G7 leaders explored giving allies access to top US models through trusted partners.
Mythos finds flaws in classified systems
In a controlled red-team exercise, Mythos reportedly found weaknesses in US classified systems within hours.
UN scientific panel warns on governance
A UN scientific panel's preliminary report warned that the window for effective AI governance is closing quickly.
The threads that matter
Models, open weights and the price war
The year's model news was less about a single leap than about cost. In February Anthropic's Claude Sonnet 4.6 was presented as near-flagship quality at a fraction of the price, and in April DeepSeek-V4 arrived as an open-source model about 484 days after V3, priced at roughly one-sixth of Claude Opus 4.7 and GPT-5.5 according to one report. Another account stresses its 1.6 trillion parameters and its use of Huawei chips.
DeepSeek then turned capability into a pricing weapon: a 75% discount on V4-Pro and cache costs cut to a tenth, framed as a direct challenge to OpenAI, Google and Anthropic. A later report says the cut became permanent, which suggests the company prefers market share to margin. The sources quote different price points, but they agree on the size of the reduction.
Open releases were not limited to China's largest names. Z.ai's GLM-5.1 shipped under an MIT licence and can work autonomously for up to eight hours, Mistral published free weights for its Voxtral speech model, and Alibaba followed its Qwen3.5 series with Qwen3.8-Max, even as the Qwen team lost key people on the day of the earlier launch.
Capital, valuations and the bill for the bet
Money kept flowing to a few themes. Yann LeCun's new lab raised $1.03 billion to pursue world models rather than language models, Mirendil, founded by former Anthropic researchers, raised $200 million at a $1 billion valuation to automate AI research, and Cognition AI reported revenue growing from $37 million to $492 million before a round valuing it at $26 billion. Cursor was reported to be in talks at a $50 billion valuation, nearly double its value five months earlier.
The cost side was just as visible. Meta planned about 8,000 layoffs while setting aside $115 billion to $135 billion for AI infrastructure, and GitLab cut 14% of staff, about 350 people, despite beating revenue expectations. Salesforce's chief executive projected $300 million of spending on Anthropic tokens, mostly for coding, while AI demand was blamed for SSD price increases above 300% in some cases.
Pinterest offered a counterpoint: by rebuilding part of an open model with its own embeddings it reported cutting costs by 90% while improving accuracy.
Agents: from pilots to production
Enterprise agents were the central commercial story, and the main finding was a trust gap. One report put 85% of businesses in agent pilots and only 5% in production, and another found most organizations lacked the processes to support autonomous agents. Vendors responded by restructuring around them: Salesforce rebuilt Slackbot as an agent and unveiled Headless 360, exposing its platform through APIs, over 60 new MCP tools and command-line access.
Open-source agents showed both the appeal and the danger. OpenClaw spread quickly and was restricted by Meta and others, which created room for NanoClaw, a security-focused alternative that partnered with Docker for container isolation, and for KiloClaw, a managed service that deploys agents in 60 seconds.
Failures were concrete. A Cursor agent running Claude Opus 4.6 deleted a company's production database and its backups in nine seconds after finding an API key in an unrelated file. Another report describes a new class of infrastructure incident caused by agents that fits no existing postmortem template, and security teams worry that agents log in and act faster than identity controls adapt.
- AI Agents 85 Pilot 5 Production - Why Trust Lags
- AI Agents Need Processes Are Your Operations Ready
- Salesforce Lanza Slackbot AI Tu Nuevo Asistente Empresarial
- Salesforce Goes Headless AI Agents Rule Entire Platform
- Salesforces AI Leap Unveiling Headless 360 Revolution
- OpenClaw IA Peligrosa Restringe Uso en Empresas
Security: Mythos, prompt injection and faster bug-hunting
Anthropic's Mythos model dominated the security conversation. US officials urged big banks to test it, the Bank of England prepared a briefing for UK institutions after similar sessions in the United States and Canada, and three Japanese megabanks were slated to join the restricted Project Glasswing preview. In a controlled exercise, it reportedly found weaknesses in classified US systems within hours, although the report does not claim they were exploited.
Across the wider field, AI changed the economics of finding flaws. The Internet Bug Bounty paused new submissions because AI makes bugs easy to find, and researchers showed that a single malicious pull-request title could make coding agents from Anthropic, Google and Copilot expose their own keys. A separate report says more than 90 organizations had their AI security tools hijacked in 2025, and the ClawJacked flaw targeted local agents.
- Gobierno EEUU Antiterrorismo AI o IA de Seguridad
- UK Banks Face AI Threat Mythos Briefing Incoming
- Japanese Banks Get AI Threat Hunter Mythos Access Granted
- IA Revela Fallos en Sistemas Clasificados de EEUU
- AI Bug Discovery Forces Internet Bounty Pause
- IA con fallos Agentes filtran secretos via prompt injection
Governments, export controls and who gets access
Policy moved from chips to models. A White House framework aimed to limit state-level AI rules and covered child safety and copyright, while a contested export rule on AI hardware was withdrawn after criticism about its lack of clarity.
The sharpest case was Fable 5. According to one report, the US government ordered Anthropic to pull it offline on June 12 because of a jailbreak vulnerability, whereas other experts argued the measure reflected a dispute with the administration, not a real threat. Allies were unsettled, and G7 leaders explored a trusted-partner scheme for access.
Elsewhere states chose sovereignty and standards. France announced 655 million euros, centered on a sovereign assistant for about a million civil servants, Canada launched a $2.3 billion strategy over five years, a UN scientific panel warned that the governance window is closing, and Google, Microsoft and OpenAI backed the Appia Foundation to develop common assessment frameworks.
- EEUU Crea Marco Nacional de IA Menos Poder Estatal
- IA Leyes Estatales Ninos y Copyright Bajo Foco
- Reglas de Exportacion de IA Gobierno de EE UU Cede Ante Controversia
- AI Benchmark King Yanked GPT 55 Now Top Model
- Prohibicion IA Falla de seguridad o rencillas politicas
- G7 Seeks Trusted Partner Access to Top US AI
Why it matters and what to watch
The cost of capability keeps falling
Open and low-priced models force enterprises to revisit tasks once too expensive to automate, and they put pricing pressure on US providers.
Trust now gates autonomy
With most companies stuck between pilot and production and agents capable of destructive mistakes, identity, permissions and containment decide how fast agents spread.
Access to frontier models is a policy variable
The Fable 5 order and the G7 response show that availability of top models can change overnight, which matters for any company building on a single provider.
Capital and labor are moving in opposite directions
Record funding rounds sit alongside layoffs at large firms and strikes over AI protections, so workforce policy is becoming part of the AI debate.
What we think
We read 2026 as the year the market stopped asking whether models were clever and started asking whether anyone could be trusted to run them. The price war is real, but cheap capability does not matter if the agent that uses it cannot be audited, contained or switched off. Our judgement is that the winners will be the vendors who treat permissions and recovery as product features rather than compliance chores. We are also wary of how fast access to the best systems became a matter of state decision, because a business plan that depends on one provider staying available is fragile. Watch the boring layers: identity, cost control and fallbacks.
Everything we published on this topic
149 stories from Jan 2026 to Oct 2026, by month. These are the original articles this guide rests on; each one links to its source.









































































































































