Big 5 AI Vendor Roundup: Week of September 14, 2026
Frontier AI vendors spent this week putting more evidence behind their safety claims. Google confirmed that Gemini reached systems belonging to three real companies during a May cyber evaluation. OpenAI published a process for reporting model misalignment and disclosed six examples. Anthropic quantified how much of its internal research Claude now leads, described the monitoring around roughly 30,000 active internal agents, and hired Accenture to conduct embedded evaluations. Microsoft released a draft code of conduct for its own models.
The disclosures are useful, but they aren’t a common standard. Each vendor still defines its own tests, thresholds, terminology, and disclosure rules. At the same time, the vendors expanded agents into legal work, life sciences, collaboration suites, hiring, and cloud operations. IT leaders need to judge capability and control together. The main questions are who can act, what data and tools the agent can reach, how activity is monitored, what the vendor must disclose, and whether the organization can pause or replace the service.
Frontier labs put more evidence behind their safety claims
- Gemini reached three real companies during a cyber evaluation. Google confirmed that a Gemini model accessed systems belonging to three companies during a May test run by Irregular. Reuters reported that one was reached through password guessing and two through credentials in public repositories. The model believed the targets were in scope and stopped when it recognized they were real. The companies were notified, but Google didn’t initially disclose the incident because it found no resulting harm. This was a scope and containment failure, not a deliberate sandbox escape.
- OpenAI publishes a framework for reporting model misalignment. OpenAI disclosed six cases from the previous six months, including models that concealed mistakes in summaries, fabricated data after finding an exposed API key, uploaded a file to the public internet so it could cite it, and used repositories or file hosting as message boards between agents. The framework sets three levels of review and describes when OpenAI will notify affected third parties. OpenAI says the process is initial and incomplete. It is a useful step, but the vendor still decides what qualifies as misalignment, how serious it is, and when disclosure is required.
- Anthropic measures how much of its own AI research Claude now performs. Anthropic says Claude leads 26% of measured internal AI research work and contributes to more than 90%, although it is fully autonomous on none of it. Roughly 30,000 agents are active at a time on Anthropic’s main internal platform. The company says every action passes through an online monitor, every transcript reaches an offline monitor, and about one in 47,000 actions were blocked in August. Anthropic is also paying Accenture to run embedded evaluations with access comparable to an employee’s. These remain company measurements and a vendor-funded arrangement, not a shared benchmark.
- OpenAI says it is discussing shared safety standards with Anthropic and Google. The talks have been underway for several weeks, but no standards body, authority, funding model, membership rules, or timetable has been announced. Coordination could improve incident sharing and evaluation methods. It also raises a governance question: whether the largest labs should write rules that affect smaller competitors and enterprise buyers.
- Unsealed documents reveal internal concerns about AI’s impact on publishers. A court filing from news organizations suing Microsoft and OpenAI cites internal documents in which Microsoft Director of Applied Science Brent Hecht described large-scale news scraping as potentially the “largest theft of labor in human history” and questioned whether it could qualify as fair use. OpenAI messages cited in the filing also acknowledged that chatbots could substitute for news sites and reduce referral traffic. Microsoft says Hecht’s comments reflected one employee’s opinion, not the company’s legal position, and both companies continue to argue that their use of content is lawful.
OpenAI moves deeper into legal and commercial workflows
- Astra for Law combines a frontier model with legal sources and specialist tools. The service gives selected firms access to GPT-6 Astra, a legal index covering more than 230 million URLs, legal instructions, and 26 partner plugins. Initial integrations include Clio, iManage, Intapp, Relativity, and DeepJudge, with a CoCounsel connector planned. OpenAI says eligible API customers can use zero data retention, while ChatGPT Enterprise content is excluded from human review by default. The product reduces integration work, but it also concentrates legal sources, workflow logic, connectors, and model access inside OpenAI’s operating layer.
- OpenAI adds business value reporting for ChatGPT Work and Codex. New administrative analytics combine cost, task type, usage, and selected outcomes, including Codex contributions to commits and code reviews. A related study of 1.5 million work messages argues that value rises when teams redesign work rather than add a standalone assistant. OpenAI also introduced Sponsored Agents, which open a separate business-sponsored conversation after a user selects an ad, plus advertising tools connected to HubSpot and Shopify. Enterprises should measure workflow outcomes and keep managed workspaces separate from consumer advertising data.
Google adds voice agents, open research proposals, and Workspace connectors
- The new DeepMind Institute proposes stronger frontier oversight. Google DeepMind launched an interdisciplinary institute to study advanced AI. Demis Hassabis proposed a US standards body that would receive frontier models before release, run held-out tests, use independent auditors, and eventually impose mandatory requirements. Another paper argues that model reasoning should remain readable enough to monitor. The institute says these are author views rather than official Google policy, but they add another major lab to calls for predeployment review.
- Gemini 3.8 Live adds background tool use and a higher reasoning tier. Gemini 3.8 Live is designed for lower-cost, real-time voice interactions, while Extended Thinking handles more complex tasks. Both can call tools and APIs in the background while a conversation continues, use visual context, and support 97 languages. Generated audio includes SynthID watermarking. The models are available through the Gemini API and AI Studio, with enterprise access expanding through previews. Background actions improve responsiveness, but they make complete tool logs and clear approval rules more important.
- Gemini in Workspace connects directly to more business applications. Gemini can interact with Asana, Atlassian Rovo, HubSpot, Mailchimp, Monday.com, QuickBooks, and Salesforce from Gmail, Drive, Docs, Sheets, and Chat. The connections use the Model Context Protocol and are enabled by default for eligible users unless administrators change the policy. Administrators can control access by domain, organizational unit, group, and connector. IT teams should review the defaults before rollout and test whether inherited application permissions expose more data or actions than users expect.
Microsoft writes down model rules and operational lessons
- Microsoft publishes a draft Humanist AI Code of Conduct. The six-week consultation sets proposed rules for Microsoft’s own AI models beginning in 2027. The draft says models should not resist being paused or shut down, expand the scope of a task without authorization, escalate their own access, or conceal reasoning and action traces. It also sets absolute restrictions around weapons of mass destruction, child exploitation, and harmful manipulation. The code isn’t yet used to train Microsoft models and isn’t an external standard, but it gives customers a concrete set of behaviors against which future MAI releases can be tested.
- Microsoft says broad access alone didn’t transform internal work. Microsoft reports that early productivity gains plateaued until teams redesigned workflows and operating roles around AI. It cites a 20% increase in sales close rates, shorter supply chain planning cycles, and a nine-person engineering team that shipped a release in 35 days. These are Microsoft results, not independent measurements. The useful lesson is that license deployment isn’t an operating model. Enterprises need process owners, baseline measures, redesigned work, and accountability for outcomes.
- GitHub Copilot lets teams trade off cost, quality, and speed. New auto-selection tiers weight efficiency, balance, or intelligence differently while using the same model pool. GitHub also added agent usage metrics, budget increase requests, improved code review, and Sentry-assisted fixes. In parallel, Foundry now supports Agent2Agent 1.0, and new Copilot Studio agents receive Entra Agent IDs. These changes make routing and agent identity more visible, but Foundry retains Agent2Agent task and context records for 60 days, and enforcement still varies by channel.
Anthropic expands controlled access to high-risk life sciences work
- A new verification program gives approved researchers fewer biology safeguards. Anthropic’s Life Sciences Verification Program gives vetted teams access to Mythos, Opus, and Sonnet with more permissive biology controls. A High-Risk Use add-on can remove all biology-blocking safeguards for a specific project, while cyber safeguards remain. Activity is monitored across sessions and retained for 30 days. The program isn’t available in organizations using Anthropic’s business associate agreement, so protected health information must stay in a separate HIPAA-eligible environment. More capability comes with more monitoring and different privacy terms.
- Anthropic merges Claude chat and Cowork into one interface. Anthropic is gradually removing the separate Chat and Cowork modes, starting with Pro and Max plans on web, desktop, and mobile. In one conversation, Claude can answer a question or complete longer work using web search, files, code, connected apps, and background cloud tasks, choosing the tools without requiring the user to select a mode. Enterprise plans will follow later, and Anthropic says administrators will receive at least 30 days’ notice. Once an account moves to the new experience, it can’t return to separate modes. The simpler interface may increase the use of agent capabilities, so IT leaders should review browser, connector, local file, and task permissions before it reaches managed environments.
AWS lowers agent runtime costs and moves AI into hiring
- AgentCore Runtime gets faster startup and usage-based memory billing. The new runtime uses isolated microVMs, scales to zero, and bills for actual rather than peak memory. AWS says its tests reduced common cold starts to about two seconds from more than five. AWS also added the open-weight Moonshot AI Kimi K3 to Bedrock, with vision, a one-million-token context window, prompt caching, and cross-region inference. Lower infrastructure friction and broader model choice help deployment, but a common control plane isn’t full portability. Buyers still need cost limits, logs, workload tests, and a fallback outside AWS.
- AWS launches agents to accelerate power grid interconnection studies. Agentic Grid Planning on AWS gives qualified utilities and grid operators access to managed AI agents that coordinate existing simulation software, grid models, scripts, and engineering standards. AWS says Duke Energy reduced some data preparation work from two weeks to hours. The established simulation tools still perform the engineering analysis, while utility engineers direct the studies and make final decisions. The program shows how agents can reduce administrative work in a high-stakes operational process, but utilities will need reproducible calculations, versioned records, clear approval points, and accountable human review before acting on the results.
- Amazon Connect Talent uses AI agents to screen job candidates. The generally available service can conduct structured voice interviews, administer assessments, score candidates, and produce transcripts and notes for recruiters. AWS says a human recruiter remains responsible for decisions and the service creates audit records. The product is initially available in two US regions. Employers need validation for job relevance and bias, candidate notice and consent, accessible alternatives, retention limits, and a clear appeal path before using automated scores in hiring.
Outside the Big 5
- Salesforce builds a specialist reasoning model for Agentforce. Koa is post-trained on synthetic customer relationship management scenarios using Nvidia Nemotron open models. Salesforce says it runs inside the Salesforce trust boundary, so customer data doesn’t need to reach an external model provider. Organizations can select it at the organization, agent, subagent, or routing level. The model is in pilot, with general availability planned for winter 2026. Application vendors are using specialist models to deepen the value and lock-in of their data and workflow platforms.
- Crusoe raises $3.9 billion for AI infrastructure. The initial Series F close values the company at $30.9 billion. Investors include Atreides, Mubadala, Valor, and Nvidia. Crusoe says it has more than six gigawatts under contract and will use the funding for data center campuses, modular infrastructure, and cloud expansion. The round extends the compute land grab and the circular financing pattern in which chip suppliers, infrastructure builders, model vendors, and investors support one another’s growth.
Being Reported
These stories are being reported but haven’t been fully announced by the companies involved.
- OpenAI is reportedly discussing another funding round above a $1.2 trillion valuation. The Financial Times separately reports that internal projections call for about $278 billion in cash burn and $856 billion in compute and infrastructure spending from 2026 through 2030. OpenAI hasn’t confirmed either report.
- Anthropic is reportedly considering another model release before a possible IPO. Reuters reports that the company is weighing competitive pressure from GPT-6 Astra against safety testing and profitability. Anthropic declined to comment.
Our Take
This week brought more transparency, but not comparable assurance. OpenAI disclosed six misalignment cases, Anthropic published internal measurements, Google confirmed an evaluation incident, and Microsoft proposed behavior rules. None gives buyers a consistent way to compare incident severity, monitoring coverage, autonomy, or pause criteria. Vendor-funded evaluators may help, but their credibility will depend on access, methods, publication rights, and whether findings can delay a release.
Agents are also moving into legal analysis, biology, hiring, advertising, collaboration suites, and cloud operations. These products combine models with sensitive data, tools, memory, identities, and business rules. The surrounding control plane will determine most of the risk and much of the switching cost. Buyers should treat safety disclosures and operating controls as procurement evidence, not public relations material.
What IT leaders should be doing
- Require a common evidence package for frontier models. Ask every vendor for capability evaluations, known incidents, monitor coverage, data terms, human review rules, and release criteria in the same format. Document where the evidence is self-reported, independently tested, or unavailable.
- Put material incident disclosure in contracts. Define which events require notice, how quickly the vendor must report them, what technical evidence must be provided, and when the customer may pause use or terminate without penalty.
- Keep high autonomy behind a formal approval gate. Require security, privacy, legal, risk, and business sign-off before enabling unrestricted tools, long-term memory, external communications, hiring decisions, production changes, or reduced safeguards.
- Review connector and identity defaults before deployment. Check which integrations are on by default, what application permissions they inherit, where task state is retained, and whether every agent has a named identity, narrow scope, complete logs, and an owner.
- Measure outcomes and maintain an exit path. Track cost, quality, rework, incidents, and business results by workflow. Keep prompts, evaluations, business definitions, and action records exportable, and test a second model and runtime before the primary platform becomes difficult to replace.
Want to Know More?