Ryan Carson named the asymmetry directly: Anthropic is quietly tightening cyber-capable model access while OpenAI ships Daybreak — a live AI cyber-defense system pairing frontier models with named security partners to continuously scan and patch software. That same week, the Mini Shai-Hulud worm hit TanStack, Mistral, and OpenSearch with valid Sigstore provenance and a dead-man's switch that wipes home directories on token revocation. The attack surface is expanding in real time. The restriction is permanent until it isn't.

The two labs are making opposite bets on the same risk. Anthropic is treating cyber capability as a liability to contain; OpenAI is treating it as a moat to monetize. Enterprise security buyers don't care about the safety positioning if Daybreak patches CVEs and Claude won't touch them — and VentureBeat's number this week is that 85% of enterprises are already piloting agents, with identity-governance as the gating constraint. Anthropic wins the cautious procurement cycle. OpenAI wins the one where the CVE is already in production. Those two customer bases don't converge.


Top developments

  • OpenAI — launched the OpenAI Deployment Company with 150 Forward Deployed Engineers, $4B from 19 investment-firm and consultancy partners, and an undisclosed acquisition of UK consulting firm Tomoro to staff it. It's a direct Palantir-FDE playbook bid for the ~$6-of-services-per-$1-of-software market, with OpenAI guaranteeing partners a 17.5% return on the deployment book. x x x

  • TanStack — npm namespace was compromised in the Mini Shai-Hulud worm: 42 packages / 84 versions signed with valid Sigstore provenance, payload exfiltrates AWS/GCP/K8s/Vault creds and ships a dead-man's switch that wipes the home directory if the stolen GitHub token is revoked; the attack chain abused GitHub Actions cache to inject into the official release workflow, bypassing 2FA, and has since spread to PyPI (mistralai, guardrails-ai) and the OpenSearch npm packages. Provenance attestations are no longer a sufficient supply-chain signal, and the CI cache itself is now the soft underbelly. x x x

  • Anthropic — Claude Platform went generally available on AWS as a first-class service — full Claude API features (including Managed Agents) with AWS auth, billing, and EDP commitment burndown, not the Bedrock indirection. The AI-cloud distribution question stops being "which hyperscaler do you buy through" and becomes "whose control plane runs the agent," with Anthropic now sitting natively inside the spend customers already committed. x x

  • OpenAI — shipped Daybreak, an AI cyber-defense system that pairs frontier models + Codex with named security partners to continuously scan and patch software. Lands the same week TanStack and Mistral got worm-published to npm and Anthropic is quietly tightening cyber-capable model access — OpenAI is opening the offensive-defense surface that Anthropic won't, and that asymmetry will start showing up in enterprise procurement. x x

  • Claude Code — 2.1.139 shipped the agent view (single research-preview list across all parallel sessions) plus the /goal command, which runs across turns until a user-set completion condition with live elapsed/turns/tokens. Anthropic is conceding that the unit of work is no longer a chat — it's a long-running goal you steer; the tmux-style multiplexing is the bet that one developer drives 5–10 agents at once. x x

  • Thinking Machines — released its first research preview from Mira Murati's lab: a family of "interaction models" that handle realtime voice/turn-taking natively rather than stitching ASR + LLM + TTS, claiming SOTA on combined intelligence + responsiveness. First product after the $2B seed at ~$12B; if the duplex claim holds, it pulls voice out of the orchestration-layer commodity bucket the rest of the field is converging on. x x

Notable discussions

  • Anthropic's secondary-market squeeze — Frankie Is Lost's viral Frog-and-Toad satire crystallized a day of complaints that Anthropic is using transfer restrictions and SPV invalidation to choke secondary trading, with TFTC21, BrianNorgard, and JesseRank warning current holders face ROFR waivers and structural uncertainty as the company moves toward IPO. The real story isn't fairness — it's that at $1.4T market-implied valuation Anthropic is now big enough that the cap-table mechanics it picks set norms for every late-stage AI lab behind it. x x x x

  • Memory is the new GPU — Coatue's sector head argued memory demand 5x's over five years and is the actual binding constraint of the next AI cycle, while Korean DRAM contract prices ran 480% over twelve months and the broader memory complex spiked 35–140%. The capex narrative is rotating off pure GPU scarcity and onto HBM/DRAM — and the second-order winners (memory suppliers, packaging, 800V power) get re-rated before model labs do. x x x

  • Long context is hurting agents, not helping — Elvis Saravia surfaced a new paper showing agents with longer histories degrade in 18 of 28 model-game combinations (the "memory curse" — forward-looking intent erodes), Akshay Pachaar's harness-engineering thread argued the next AI-engineer skill stack is KV management, speculative decoding, and eval/observability rather than prompt craft, and Erik Meijer warned git infrastructure designed for human pace is buckling under agent commit volume. The bottleneck is shifting from "smarter model" to "better scaffolding around a finite context window" — and the people building harnesses are getting more leverage than the people fine-tuning. x x x x

Sharp takes

  • Karpathy — argues markdown is a halfway house and the new default for AI output should be HTML viewed in the browser, on the basis that ~1/3 of cortex is wired for vision and we've been routing all AI output through the lowest-bandwidth pipe; the extrapolation he points at is interactive diffusion-generated videos, not better prose. x

  • Gary Marcus — reads the Claude Code internals (53 symbolic tools, 500K lines of symbolic code wrapped around an LLM) as the most neurosymbolic system ever shipped and a complete vindication of his anti-pure-LLM position since 2001 — Claude Code's success isn't a win for scaling, it's classical AI re-asserting itself inside the agent harness. x

  • Theo — calls coding-with-agents a trap that produces false productivity gains and no lasting products, and says the whole field walked into it together; worth reading exactly because it lands the day Anthropic ships the agent-view-and-/goal stack designed to deepen that workflow. x

  • Clément Delangue — points out that with MacBook Pro memory frozen at 128GB for two years, the best open-weight model you can actually run jumped from a 10 to a 47 on Artificial Analysis (Llama 3 70B → DeepSeek V4 Flash Q2) — open-weights local intelligence is doubling every 10.7 months, more than twice Moore's Law, on unchanged hardware. x

  • Aakash Gupta — Devin hit $445M ARR with usage doubling every 8 weeks (US Army, Goldman, Mercedes, Citi, Dell on the customer list), Cognition raising at $25B / 56x with under $20M cumulative burn, and the post-Windsurf merger added 30%+ to combined ARR in 7 weeks — the autonomous-coding-agent unit economics finally look real, two years after the original "fake demo" mockery. x

  • Aaron Levie — argues agents are a bigger services wave than on-prem→cloud was, because agents rewire the underlying business process (not just the medium of delivery), and every industry/department/firm needs bespoke entitlement, eval, and change-management work — which is exactly the gap the OpenAI Deployment Company and Anthropic's vertical FDEs are pricing. x

  • Ryan Carson — flags the strategic asymmetry that Anthropic restricts cyber-capable Claude while OpenAI is now actively shipping it as Daybreak, and warns the cyber buyer doesn't care about safety positioning if it can't actually patch CVEs. x

Other news

Models & releases

  • Gemini Omni — Google's new multimodal video model previews with coherent on-screen text generation, drawing breakthrough-tier reactions x x

  • Gemini Flash 3.2 — confirmed for I/O; Abacus reports it already replaces GPT-5.5-low in 70% of their scheduled jobs x

  • Zed Zeta 2.1 — edit-prediction model emits 3x fewer output tokens, 28% faster at p50, 30% fewer servers x

  • Hermes Agent — Nous Research ships computer-use capability via CUA integration x

  • DeepSeek Flash — pricing rounds to zero in billing aggregation; 90% cheaper than GPT-class x x

Devtools & coding agents

  • Replit Parallel Agents — up to 10 agents simultaneously per workspace x

  • Cursor Microsoft Teams integration — agent-based task delegation from inside Teams x

  • Codex Code Mode + Ultrafast Mode — Code Mode for flexible tool integration, Ultrafast for 2–3x latency improvement x x

  • Artificial Analysis coding-agent index — new benchmark for end-to-end coding-agent performance x

  • METR productivity survey — 349 technical workers self-report AI use makes their work 1.6–2.1x more valuable x

  • Anthropic Claude Cookbook — 81 practical guides across agents, tools, RAG, evals, Skills, integrations x

  • Anthropic open-sources finance agents — full pitch / DCF / LBO / KYC / earnings agent suite + Bloomberg-tier data MCP connectors x

  • Zen / River-style agent platforms — Composio's Zen agent reports ~1,500 tasks at 94% success in 10 weeks, edits its own prompts after each run x

Funding & deals

  • OpenAI ↔ Microsoft — agree to cap revenue-sharing at $38B, clearing OpenAI to do new deals with Amazon and Google x

  • Anthropic — onchain pre-IPO instruments price implied valuation at $1.4T, up 40% in 24 days and 1,067% since October x

  • OpenAI secondary — 2026-05 disclosure: 600+ current/former staff cashed out $6.6B at $400B in October, kept quiet for months x

  • DeepSeek funding — confirmed largest Chinese AI round with government backing x

Industry & policy

  • GitLab restructuring — layoffs framed as "agentic era" workforce shift; Ryan Carson reads it as the leading edge of broader tech restructuring x x

  • Anthropic + OpenAI FDE buildout — both labs are committing thousands of engineers to ~2,000 large enterprises over the last 5 days x

  • Tech layoffs YTD — 128K cuts in first 5 months of 2026; March worst month x

  • Mythos vs Daybreak first results — Mythos audit found 1 cURL vulnerability with false positives across 20B installed instances; GPT-5.5 with /goal reportedly outperforms Mythos on cybersecurity tasks x x

  • VentureBeat agent governance — 85% of enterprises pilot AI agents, only 5% reach production, identity-governance is the gating constraint x

Infrastructure & platforms

  • Files SDK — unified storage API across 18 cloud providers x

  • Supabase as ChatGPT app — becomes an official ChatGPT-native database integration x

  • GPU compute futures — contracts now trading on Architect platform x

  • TurboAPI 1.0.30 — 2.3x faster WebSocket throughput than FastAPI x

  • Databricks + Superhuman — 200K QPS sub-second LLM serving in production x

Web & frontend

  • Bun v1.3.14 — possibly the last Zig-built release before Rust takeover x

  • Oxlint — dramatically outperforms ESLint on React Aria; experimental Svelte support x

  • Roc compiler — Richard Feldman rewriting from scratch in Zig, v1 approaching x

  • Rolldown in Framer — AST transformation used to speed up hydration x

Security

  • Anthropic cyber posture — quietly tightens cyber-capable model access while OpenAI ships Daybreak x

  • GitHub Code Security Risk Assessment — vulnerability triage by severity now in GitHub native x

  • pnpm minimum-release-age — recommended mitigation against rapid-publication supply-chain worms x

  • fsnotify maintainer dispute — supply-chain concerns extend beyond npm into Go ecosystem x

Continuing threads

  • HTML-vs-Markdown — Karpathy weighs in (covered as Sharp take); broader debate from May 9–11 continues with no new frame x

  • Karpathy's CLAUDE.md rules — repo at 120K stars, 60K bookmarks in 2 weeks; new v2 adds 8 rules for agent fights and hook cascades (May 10/11 tail) x

  • Bun's Rust port — Theo flags more unsafe blocks than uv; Adam Rackis reads Zig departure as language signal (May 10/11) x x

  • chatgpt21 Codex $5 goal — recap of the autonomous $16.88 bounty hit (May 11 Sharp take) x

  • Codex eating Claude Code mindshare — additional voices report Codex surpasses Claude Code on cost-to-intelligence (May 10 Notable) x x