OpenAI just shipped its most powerful model to twenty companies the government picked. Not the best twenty. The approved twenty. A week after the US switched off Anthropic's best model, the frontier has a guest list, and you are not on it. We figure out what that does to anyone trying to build on the newest model.
Welcome to Human In the Loop, a weekly podcast where two builders cut through the AI hype cycle. No breathless hype. No doomerism. No surface-level recaps.
The week’s AI headlines, filtered.
- SIGNALGPT-5.6 ships under US government restrictions
OpenAI began a limited preview of GPT-5.6 — Sol, Terra, and Luna — to roughly twenty pre-approved organizations at the US government's request, the first major model to ship under the June 2 executive order. Last week Anthropic went dark by force. This week OpenAI went gated by choice. Two labs, two weeks, same direction.
- SIGNALAnthropic accuses Alibaba's Qwen of the largest distillation attack on record
Anthropic's complaint to Senators Warren and Scott alleges Alibaba's Qwen lab ran about 25,000 fraudulent accounts and 28.8 million exchanges against Claude between April 22 and June 5, aimed at software engineering and agentic reasoning. That is roughly 1.7x the combined total it attributed to DeepSeek, Moonshot, and MiniMax in February, and the first time it has named a major Chinese conglomerate.
- SIGNALOpenAI and Broadcom unveil Jalapeño, OpenAI's first inference chip
OpenAI's first custom chip, built with Broadcom for inference, went from first design to tape-out in nine months with help from OpenAI's own models — the companies call it the fastest ASIC cycle ever. Early claims cite performance-per-watt well above the current state of the art, with first deployment targeted for the end of 2026.
- SIGNALAgentjacking: the prompt-injection hole in every coding agent
A new attack class hijacks coding agents like Claude Code, Cursor, and Codex by hiding instructions inside data they already trust, such as a Sentry error report pulled in over MCP. There is no universal patch — the fix is to treat incoming data as untrusted and keep a human review step before the agent acts. OWASP says prompt injection is up 340% year over year.
- NOISEChatGPT slips below 50% as Gemini and Claude surge
Reports put ChatGPT at 46.4% of the assistant market, its first time below 50% since launch, with Gemini at 27.7% and Claude at 10.3%. Mostly a distribution story — Gemini's climb is Android OS-level placement. Noise for builders, except the one real line: Claude roughly quadrupled its monthly users in five months on the back of agentic coding.
Two AI words an exec heard this week and couldn't define on the spot, in plain English.
Teaching a small, cheap model by having it copy a big, expensive one's answers. The word at the center of the Alibaba–Claude fight, and why some cheap models punch far above their price. The real question is provenance, not the technique.
A model reads instructions and data as one stream of words, so commands hidden in the data get obeyed like orders. Researchers say it may not be patchable — the defense is design: read-only by default, a human in front of anything you can't undo.
Two opinions, no disclaimers.
Oscar“The frontier is being quietly nationalized, and most builders are cheering it as safety. Build on the model you can actually keep.”
Matt“Everyone panicking about distillation forgot the lesson. The frontier has no moat. Stop betting your company on a six-week lead anyone can clone.”
- Axios, OpenAI releases GPT-5.6 (Sol, Terra, Luna) under restrictions
- OpenAI, Previewing GPT-5.6 Sol
- Thurrott, OpenAI launches GPT-5.6 in limited preview
- White House, Promoting Advanced AI Innovation and Security
- CNBC, Anthropic accuses Alibaba of campaign to 'illicitly' extract AI capabilities
- The Next Web, Anthropic accuses Alibaba of largest distillation campaign against Claude
- Mobile World Live, Anthropic accuses Alibaba of large-scale distillation attack
- CNBC, OpenAI and Broadcom reveal Jalapeño, first AI chip in partnership
- TechCrunch, OpenAI unveils its first custom chip, built by Broadcom
- OpenAI, OpenAI and Broadcom unveil LLM-optimized inference chip
- Tom's Hardware, Jalapeño is a reticle-sized ASIC built in nine months
- Digital Applied, Agentjacking: your AI coding agent can be hijacked
- Help Net Security, Prompt injection still drives most agentic AI security failures
- TechTimes, Prompt injection may be a permanent flaw, not a patchable bug
- Unit 42 (Palo Alto), Web-based indirect prompt injection in the wild
- TechTimes, ChatGPT's market share falls below 50% for the first time
- Business Standard, ChatGPT market share slips below 50% as Gemini, Claude gain
- Momentic, Top generative AI chatbots by market share, June 2026