◆ Dispatch 050 · 2026-06-25 The Customer Gate
The Release Gate Moved To Washington
“Customer-by-customer model access creates a new bargaining surface between labs, states, and the institutions that want early access.”
— Jonas Vale, today's narration
Jonas Vale follows the U.S. government request for OpenAI to stagger GPT 5.6 access, China's GLM-5.2 security debate, the RAISE US workforce push, data center water politics, export-control chip workarounds, and a diabetes benchmark that makes clinical AI omissions measurable.
Chapters
- 00:00:04 The government asked OpenAI to stagger access
- 00:03:53 GLM-5.2 sharpened the open model security debate
- 00:07:51 The workforce fix now has a boardroom
- 00:12:02 Water joined the data center fight
- 00:15:57 The chip story is becoming margin and jurisdiction
- 00:19:55 Clinical AI needs measurable omissions
Sources
10 cited-
1
Axios: China’s new open-source model accelerates AI hacking threat
Article
www.axios.com/2026/06/25/china-glm-52-open-… →Details
- Key points
- Axios reported that GLM-5.2 performed near leading U.S. models in separate cybersecurity evaluations while being open-weight and cheaper to run.
- Provenance
- Article · Supporting source
-
2
Watcher.Guru: US tells OpenAI to limit GPT 5.6 release
X
x.com/WatcherGuru/status/2070246600090284194 →Details
- Key points
- The tweet amplified The Information report and quoted Sam Altman saying OpenAI told the U.S. government this is not its preferred long-term model.
- Provenance
- Tweet · Primary source
-
3
Axios: Water joins energy as top AI flashpoint
Article
www.axios.com/2026/06/25/water-energy-ai-fl… →Details
- Key points
- Axios reported that Google, Amazon, Microsoft, Nvidia, Virginia lawmakers, and the UN are all responding to public pressure around data center water use.
- Provenance
- Article · Supporting source
-
4
RAISE US launch announcement
Article
www.rockefellerfoundation.org/news/raise-us… →Details
- Key points
- RAISE US launched June 25 with Gina Raimondo, Eric Holcomb, anchor partners including OpenAI Foundation, Anthropic, Amazon, Microsoft, and initial state partnerships in Arkansas, Connecticut, Maryland, and Utah.
- Provenance
- Article · Supporting source
-
5
Techmeme: US asks OpenAI to stagger GPT 5.6 release
Article
www.techmeme.com/260625/p45 →Details
- Key points
- The Information via Techmeme reported that Sam Altman told staff the U.S. government asked OpenAI to stagger GPT 5.6 access customer by customer over security concerns.
- Provenance
- Article · Supporting source
-
6
AP/ABC News: AI is plowing through the workplace
Article
abcnews.com/Technology/wireStory/ai-plowing… →Details
- Key points
- AP reported RAISE US is starting with more than $500 million and cited BCG and Goldman estimates about jobs and work hours exposed to AI.
- Provenance
- Article · Supporting source
-
7
Techmeme: Alibaba shares fall after Anthropic accusation
Article
www.techmeme.com/260625/p15 →Details
- Key points
- Bloomberg via Techmeme reported Alibaba shares closed down 4.43% in Hong Kong after Anthropic accused Alibaba of illicitly accessing its AI models.
- Provenance
- Article · Supporting source
-
8
Techmeme: Global AI sales and depreciation costs
Article
www.techmeme.com/260625/p21 →Details
- Key points
- Bloomberg/Exponential View via Techmeme reported global AI sales excluding China reached $25 billion in Q1, above an estimated $21 billion in data center and chip depreciation costs, with thin margins.
- Provenance
- Article · Supporting source
-
9
T2D-Bench: Evidence-Gated Evaluation of LLM Outputs for Type 2 Diabetes
Article
arxiv.org/abs/2606.24145 →Details
- Key points
- The paper reported GPT-4o-mini failed benchmark-defined evidence-path checks in 35% of cases and GPT-4o in 33% across 100 diabetes vignettes.
- Provenance
- Article · Supporting source
-
10
Techmeme: Qualcomm China-compliant data center chips
Article
www.techmeme.com/260625/p13 →Details
- Key points
- Nikkei Asia via Techmeme reported Qualcomm CEO Cristiano Amon said Qualcomm is designing data center chips for Chinese customers that comply with U.S. export controls.
- Provenance
- Article · Supporting source
The government asked OpenAI to stagger access
00:00:04 OpenAI's next model release became a government access story today. The Information reported, via Techmeme, that Sam Altman told staff the U.S. government had asked OpenAI to stagger the release of GPT 5.6 over security concerns, approving access customer by customer.
00:00:20 The line that moved around fastest came from Altman himself: OpenAI had made clear to the government that this wasn't the company's preferred long-term model. Start there: a reported staff meeting, a staged release, and a company saying it doesn't want customer-by-customer approval to become the normal path for frontier models.
00:00:40 We don't have the full government memo. We don't have the exact review criteria. We don't know whether the request is formal, informal, temporary, or the beginning of a licensing practice by another name. But the reported mechanism matters because it changes the unit of control.
00:00:57 The government isn't only asking whether a model is too capable to release. It's asking who gets to touch it first. That sounds small until you remember how model releases work economically. Early access goes to major enterprise customers, cloud partners, government users, safety researchers, favored developers, and sometimes press or benchmark groups.
00:01:18 Those early users help define the public reputation of the model. They find the surprising use cases. They also find the bad ones. If Washington gets a say in that first ring of access, it gains leverage over the lab without necessarily writing a public rule. The social reaction was predictable, and not especially subtle.
00:01:38 The Watcher.Guru post that amplified the report had hundreds of replies and more than two hundred thousand views when the broker snapshot captured it. Some replies treated this as proof that the U.S. government now controls AI releases. Some treated it as basic prudence after the recent fight over Anthropic's restricted models.
00:01:58 A few people saw the contradiction: the labs spent years telling policymakers that voluntary safety work and private deployment discipline could handle the problem, and now the state is asking to sit inside the release process anyway. My read is narrower than the panic version, but not reassuring.
00:02:16 This doesn't prove that every model update now needs a federal permission slip. It shows that frontier release timing has become national security administration, at least for the models the government believes may change cyber capability. Once release approval becomes customer-specific, the hard questions follow quickly.
00:02:36 Does a bank get access before a university lab? Does a defense contractor get access before a hospital? Does a foreign subsidiary count as the same customer? Can a state government ask for early access because public safety is involved? A private company can make those calls opaquely, and a government can make them opaquely too.
00:02:56 The public may end up with the worst mix: private ordering, state pressure, and no written standard. A useful next document would be a rule, even a narrow one, that says which security property triggers staged access and who can appeal the decision. Until then, the fact is plain enough.
00:03:13 For GPT 5.6, the release gate appears to have moved from the product calendar into Washington. There is one more practical wrinkle. Customer-by-customer approval can look orderly from a government desk and chaotic from the market. If one cloud partner receives access before another, that affects enterprise sales.
00:03:32 If one government contractor receives access before a commercial security company, that affects who can build defensive products first. If a foreign ally waits while a domestic customer moves ahead, the release schedule becomes diplomacy. None of that requires a public ban.
00:03:49 It only requires a queue, and queues are where power likes to hide.
GLM-5.2 sharpened the open model security debate
00:03:53 Axios reported today that China's GLM-5.2 is raising fresh concern among security researchers because it gives more people a cheaper path to high-end cyber assistance. The model was released by Z.ai last week. Axios says its agentic capabilities rival Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run, and that separate evaluations from Graphistry and Semgrep found it performing near leading U.S.
00:04:20 models on cybersecurity investigation and vulnerability-discovery benchmarks. There are two claims inside that story, and they should be kept separate. The first is capability: can an open-weight model investigate vulnerabilities, chain clues, and help an operator move through a security problem at something close to frontier quality?
00:04:42 The second is control: once the model is downloadable, who sees the abuse, who can ban the account, and who can force a patch? Closed providers like OpenAI or Anthropic can monitor accounts, rate-limit suspicious behavior, and suspend a user. That doesn't make misuse disappear, but it gives defenders a place to apply pressure.
00:05:03 With open weights, the model can run locally. It can be fine-tuned. It can be stripped of safety behavior. It can be used without any provider seeing the prompt. Travis Lanham, the chief technology officer and founder of Armadin, put the operational point clearly to Axios: an attacker can run it locally, remove limits, fine-tune it against targets, and operate with no visibility to a provider or defender.
00:05:29 Roye Bass at Halcyon added another consequence: people who now buy malicious large language model tools, jailbreak prompts, or stolen API keys can start building their own versions by downloading GLM-5.2 and using it for phishing, fraud scripts, and malicious content.
00:05:46 That doesn't mean every low-skill criminal suddenly becomes an elite intrusion team. Jason Baker at GuidePoint Security gave the necessary cold water: across the ecosystem, the skill needed to use these systems to increase scale hasn't caught up with the desire to do it.
00:06:03 I believe that. A model can suggest an exploit chain, but the operator still needs infrastructure, access, patience, and judgment. Plenty of AI-generated malware in the wild is bad. Some of it is almost charmingly bad, in the bleak way that badly automated crime can be charming for about three seconds before someone gets hurt.
00:06:24 But cheap enough changes behavior before it perfects performance. If a tool cuts the cost of reconnaissance, translation, phishing personalization, or vulnerability triage, attackers don't need it to be brilliant. They need it to make the next attempt less expensive.
00:06:41 That matters for small businesses, school districts, hospitals, local governments, and regional banks, because those are the institutions that already struggle to patch ordinary systems on ordinary budgets. There is also a geopolitical layer here. Graphistry suggested that GLM-5.2 may be an illegal distillation of GPT-5.5 and Opus 4.8.
00:07:02 Axios says Z.ai didn't respond to a request for comment. I would be cautious with that claim until there is evidence beyond evaluation similarity and suspicion. But the accusation itself tells you where the industry anxiety has gone. U.S. labs aren't only worried that Chinese open models are catching up.
00:07:22 They are worried those models may be learning from closed systems in ways the closed labs can't audit or price. The open model argument has always had a democratic side: more access, more local control, and less dependence on a handful of providers. Today's security story doesn't erase that.
00:07:41 It does force the harder version of the argument. Openness distributes capability, including capability that can make defenders' lives worse before institutions have adjusted.
The workforce fix now has a boardroom
00:07:51 Gina Raimondo and Eric Holcomb launched RAISE US today, a nonpartisan workforce nonprofit backed by major AI companies, employers, states, and philanthropies. The primary announcement says the group has already secured more than half of a planned one billion dollars in multi-year commitments.
00:08:10 AP puts the starting figure at more than five hundred million dollars. The anchor partners include Amazon, Anthropic, Microsoft, the OpenAI Foundation, and Bank of America, with other companies such as UPS, General Motors, Eli Lilly, Mastercard, AMD, Cisco, IBM, ServiceNow, Workday, and several large philanthropies around the table.
00:08:31 Raimondo's launch quote was unusually blunt for this kind of coalition. She said, quote, "America has a technology strategy for leading the global AI competition. It does not yet have a people strategy — and we cannot lead without one." She also told AP, "We're talking about a certain level of unemployment that could destabilize our country and our democracy." That isn't the language of a coding boot camp press release.
00:08:58 It is a former commerce secretary saying the labor transition has become a political stability problem. The group starts with state partnerships in Arkansas, Connecticut, Maryland, and Utah. The program list is practical rather than utopian: apprenticeships, short-term credentials, AI-powered career navigation, employer incentives to retrain workers instead of laying them off, wage insurance, short-time compensation, and state-level pilots that could later become federal policy.
00:09:29 Arkansas is using an AI-powered career navigation platform called Arkansas LAUNCH. Maryland is expanding service-year pathways in healthcare and education, creating a fund for career transition models, and supporting displaced workers who try entrepreneurship. There are two reasons this belongs in an AI power episode and not only in a labor-policy brief.
00:09:51 First, the companies building and selling the systems are helping fund the worker-transition apparatus. That is a concession, even if nobody wants to call it one. The industry is admitting that the gains from AI won't automatically flow through the labor market fast enough or fairly enough.
00:10:10 Second, the structure isn't federal. It is states, employers, philanthropies, universities, and corporations trying to build a national workaround for a Congress that Raimondo openly doesn't expect to move quickly. AP adds the harder numbers. Boston Consulting Group estimated in April that roughly half of U.S.
00:10:29 jobs will be reshaped by AI over the next few years, and that as many as twenty-five million jobs could be eliminated in the U.S. over five years. Goldman Sachs estimated in March that a quarter of U.S. work hours could be automated by AI. Those estimates aren't destiny.
00:10:46 Forecasts like this have a long history of being wrong in both directions. They can miss new jobs, overstate substitution, understate wage pressure, and flatten the difference between a task changing and a person losing a paycheck. Still, the labor institutions Raimondo is criticizing were built for a slower economy.
00:11:06 Unemployment insurance assumes temporary displacement. Four-year college assumes time, money, and a life stage that many workers don't have. Corporate training often gets cut exactly when workers need it most. A state pilot may be too small for the national problem, but it can test something Congress can't design from first principles in a hearing room.
00:11:29 Corporate comfort deserves skepticism. If the same companies automating tasks also help design the transition system, they may prefer programs that produce cheap adaptation over programs that preserve bargaining power. A worker can be trained into a worse job, not only a better one.
00:11:47 Wage insurance can cushion a fall while making the fall politically acceptable. RAISE US should be judged by whether workers who lose leverage because of AI get income, mobility, and choice, not just a new portal and a certificate.
Water joined the data center fight
00:12:02 Axios reported today that water has joined energy as a top fight around AI data centers. Google, Amazon, and Microsoft have each launched new efforts in recent weeks to explain and justify the water use of their AI infrastructure. They are talking about water replenishment projects, recycled water, and new cooling technologies.
00:12:23 Nvidia claimed this week that its latest generation of technology could largely address water concerns. Peter Gleick, co-founder of the Pacific Institute, gave Axios the useful sentence: the growing conversation about data center water and energy has forced companies to rethink what they are doing and become more transparent.
00:12:44 He added that they are starting to understand the reputational risk of a massive data center rollout with large energy and water footprints. Gallup polling from May found that roughly seventy percent of people in the U.S. would oppose data centers in their communities, with water and energy both showing up as top concerns.
00:13:04 This matters because data centers are local before they are global. The AI industry talks in model releases, token prices, and compute clusters. A county hears pumps, substations, road work, tax abatements, and a large industrial neighbor asking for water rights.
00:13:21 The aggregate numbers can be less alarming than the politics. Axios notes that data centers use far less water than some major industries, and Sarah Porter at Arizona State University's Kyl Center for Water Policy said the projections for water demand are not eyebrow-raising.
00:13:39 But she also said water concerns can stand in for broader discomfort with a fast-developing industry. That substitution point is important. People may say water when they also mean electricity, land use, jobs, tax breaks, noise, secrecy, and distrust of a company that arrived with lawyers before it arrived with a neighborly explanation.
00:14:01 The water issue is still concrete. In drought-prone regions, a modest new demand can become a serious fight because the margin is already thin. A community doesn't experience water use as a national average. It experiences it in one aquifer, one utility plan, one summer, and one public meeting where the company representative says the facility is efficient.
00:14:23 The technical trade-off is awkward. Water-based cooling often uses less electricity than air-based cooling, so a facility can reduce one burden by increasing the other. Electricity generation can require water too, especially from fossil fuel and nuclear sources.
00:14:40 Wind and solar don't require water in the same operating sense, but they bring their own land and grid questions. Bank of America estimated that electricity generation accounts for roughly seventy-five percent of a data center's total water footprint, according to Axios.
00:14:58 So the cooling tower is only part of the story. The power plant behind the facility may matter more. The political response is arriving. The United Nations Secretary General, António Guterres, called this week for major AI companies to measure and publicly disclose carbon, water, and land footprints.
00:15:17 Virginia lawmakers, in the jurisdiction with the world's highest number of data centers, moved toward clamping down on the most water-intensive cooling methods. Microsoft and Google are expected to release environmental reports in the coming weeks. Yesterday I talked about gigawatt-scale AI as land, power, cooling, financing, construction, and permits.
00:15:40 Today adds the public consent test. A company can win the interconnection queue and still lose the room. If water disclosure becomes a standard reporting line for AI systems, it will be because communities forced the industry to describe the physical machine behind the model.
The chip story is becoming margin and jurisdiction
00:15:57 The chip news today was less dramatic than yesterday's custom OpenAI-and-Broadcom story, but it filled in two useful pieces of the map. Techmeme, citing Nikkei Asia, reported that Qualcomm chief executive Cristiano Amon said the company is designing data center chips for Chinese customers that comply with U.S.
00:16:17 export controls. Separately, Techmeme carried Bloomberg's report that Alibaba's Hong Kong shares closed down 4.43 percent after Anthropic accused Alibaba of illicitly accessing its AI models, with Xiaomi and Baidu also falling around two percent. Put those together and you get the daily mechanics of the U.S.-China AI fight.
00:16:38 Export controls don't stop demand. They create product categories. A chipmaker looks at the rule, designs around the line, and sells the most capable legal part it can sell. The buyer gets something weaker than the restricted chip but better than nothing. Washington then has to decide whether that workaround preserves the intent of the rule or eats it from the inside.
00:17:02 Qualcomm isn't alone in this dance. Nvidia has been living inside it for years. Yesterday's Nvidia story was about hardware support as leverage: the chip isn't only silicon, it is driver support, ecosystem compatibility, repair, and supply assurance. Qualcomm's statement points to the same commercial reality from another angle.
00:17:23 If Chinese cloud customers can't buy the highest-end U.S. parts, they will buy compliant parts, domestic alternatives, gray-market supply, or some combination of all three. The rule doesn't remove the market. It redirects engineering effort. The Alibaba item is a different kind of control fight.
00:17:42 Anthropic's accusation, as reported through Bloomberg and Techmeme, hit public-market pricing immediately. Alibaba was already down more than thirty-six percent year to date, and the new accusation pushed shares to a sixteen-month low in Hong Kong. We don't have the underlying evidence in the Techmeme summary, and I don't want to overstate a market move from one report.
00:18:05 But the allegation sits beside the GLM-5.2 security story in an uncomfortable way. If closed U.S. labs believe Chinese firms are illicitly accessing or distilling their models, then model access becomes a trade-control issue, not only a terms-of-service issue. The money signal is tighter but useful.
00:18:25 Bloomberg's Exponential View item, via Techmeme, said global AI sales excluding China reached twenty-five billion dollars in the first quarter, above an estimated twenty-one billion dollars in data center and chip depreciation costs, while margins remain thin. I wouldn't build a victory parade on that spread.
00:18:45 Depreciation isn't the whole cost of AI, revenue quality varies, and the investment cycle is still front-loaded. But the number matters because it challenges the simplest bubble story. The industry isn't only spending; it is generating enough revenue, at least on this estimate, to meet a large part of the physical asset wear-down bill.
00:19:06 The phrase thin margin carries the business argument. If revenue barely clears depreciation, then control over chips, power prices, utilization, customer mix, and model routing becomes the business. A lab that can run a model cheaper gets room to price aggressively.
00:19:23 A cloud provider that owns the customer relationship can keep more of the margin. A government that controls which chips cross a border can reshape where that margin is earned. So today's chip story isn't a single breakthrough. It is the accounting and jurisdiction around the breakthrough.
00:19:42 Who can sell into China, who can design around a rule, who can accuse whom of model theft, and whether the revenue pays for the machinery fast enough. That is how the AI race looks when the keynote lights are off.
Clinical AI needs measurable omissions
00:19:55 A small medical AI paper today gave me a better way to talk about clinical risk. T2D-Bench, from Saba Farahani, Hung Cao, Ramesh Jain, and Amir Rahmani, proposes an evidence-gated benchmark for large language model outputs in type 2 diabetes. The claim isn't that a model says obviously foolish things.
00:20:14 The claim is that a model can produce fluent, clinically plausible recommendations while failing to satisfy guideline constraints or justify lifestyle-related glycemic claims. The benchmark uses one hundred structured vignettes across diagnosis, medication safety, and adversarial lifestyle conflicts.
00:20:33 It builds a multi-layer knowledge graph from biomedical sources, computable American Diabetes Association Standards of Care rules, and lifestyle knowledge tied to glycemic lab effects. Then it checks whether the model's answer has the evidence path the benchmark requires.
00:20:50 In their baseline tests, GPT-4o-mini failed those evidence-path checks in thirty-five percent of cases, and GPT-4o failed in thirty-three percent. That is a much more useful failure than a general warning about hallucinations. Hallucination has become a bucket word.
00:21:06 It can mean a fake citation, a wrong drug interaction, an invented lab value, or an answer that sounds fine but omits the one constraint that would keep a patient safe. In diabetes care, omissions matter. A recommendation about exercise, medication, food, or monitoring can be fluent and still miss a contraindication, a safety rule, or the evidence chain connecting lifestyle advice to a glycemic outcome.
00:21:32 The paper's evidence gate detects unsupported omissions and then uses constrained revision to bring the answer into compliance with the benchmark's evidence requirements. That is a limited claim, and I mean that as a compliment here. It doesn't say, let the chatbot practice medicine.
00:21:49 It says: make the missing evidence measurable, make the rule computable, and test whether revision can repair the answer. This connects back to yesterday's MedLog discussion. If medical AI is going to enter clinical workflows, the logging problem and the evidence problem meet each other.
00:22:07 You need to know what the system said, which patient context it saw, which guideline constraint it satisfied, which constraint it missed, and whether a human corrected it. Otherwise the risk disappears into a note that looks competent. There is a labor angle too.
00:22:24 Evidence gates like this don't remove clinicians from the loop. They change the work the clinician is asked to do. A doctor or diabetes educator shouldn't have to read a smooth paragraph and mentally reconstruct every guideline dependency from scratch. The system should surface the checks it passed and the checks it failed.
00:22:44 If it can't do that, then the model is outsourcing verification to the busiest person in the room. Several gates became explicit today: release access, worker transition, data center water, and clinical evidence. A customer-by-customer GPT 5.6 release needs a written public standard before the queue becomes habit.
00:23:03 Jonas