Big 5 AI Vendor Roundup: Week of August 17, 2026
Frontier cyber capability crossed two thresholds this week. OpenAI slowed advanced model work while it strengthens containment after the Hugging Face incident and signs that Astra may meet its critical cybersecurity threshold. Anthropic put Mythos 5 into an enterprise code scanning service, giving customers bounded access to a model it still won't release for general use.
Agents moved deeper into everyday work. GitHub Copilot can start coding from Slack and Microsoft Teams, Ask Gemini turns Google Chat into a Workspace command surface, Claude can act across Gmail, Calendar, and Drive, and AWS agents can make payments. Google's A2A protocol also moved into the Agentic AI Foundation. IT leaders now need to focus on who can invoke an agent, what it can access or change, what it can spend, and how it can be stopped.
OpenAI slows frontier work and strengthens private deployment
- OpenAI slows model development after cyber warning signs. On August 18, OpenAI said it paused reinforcement-learning training on its latest deployment models for two weeks, while its largest planned frontier run remains on hold. It also paused tool enabled frontier model inference after the Hugging Face incident. OpenAI is adding stronger isolation, continuous security testing, and monitoring intended to flag serious activity within 30 minutes. It estimates that monitoring adds roughly 20% to the inference compute being watched. Containment is now constraining development speed.
- Zero Data Retention expands to frontier models. Eligible API customers can use frontier models without OpenAI retaining prompts or responses after processing. A Private Safety Processing preview looks for risky patterns across related interactions while keeping content on customer controlled infrastructure, with a future encrypted OpenAI storage option. OpenAI receives a limited safety signal rather than the underlying content. This better fits regulated workloads, although customers will still need their own evidence and alert review processes.
- The PORTS-Pike project confirms an eight-gigawatt Ohio buildout. OpenAI signed an agreement with SB Energy, Nvidia, and the US Department of Energy for about eight gigawatts of IT capacity at a former federal site in Ohio. The first 800 megawatts are expected in 2028. SB Energy will build and operate the site, Nvidia will supply the infrastructure and invest $1.5 billion in SB Energy, and OpenAI will lease the capacity. The project extends the circular relationship among model developers, chip suppliers, infrastructure owners, and lenders.
Anthropic brings restricted cyber capability into enterprise products
- Mythos 5 now powers Claude Security scans. Claude Enterprise customers can use Mythos 5 to scan codebases for vulnerabilities in a public beta. The service returns a weakness category, confidence and severity ratings, and a suggested fix without exposing the unrestricted model. Patches require human review, and scans are billed as normal token usage. Anthropic also announced $35 million in Claude credits for open source security work. This is a controlled way to sell high-risk capability without providing general model access.
- Anthropic's production agent stack reaches general availability. Computer use, the Skills API, and the Files API are now generally available. A new browser tool reads page structure as well as screenshots, while computer use can take several actions per turn. It is also eligible for HIPAA regulated workloads under Anthropic's business associate agreement. Skills and Files are available through Microsoft Foundry, with updated computer and browser tools coming to Google Cloud. Permissions, recordings, and recovery controls will determine whether this automation is safe in production.
- Claude expands from reading Google Workspace to acting in it. Gmail, Google Calendar, and Google Drive connectors are available to Claude and Claude Desktop users. Claude can search and send email, change calendar events, and read, move, share, delete, upload, and save Drive files. Actions require approval by default, but Team and Enterprise owners can let users skip repeated approvals. Claude mirrors existing Google permissions, and organization owners can disable the connectors. Administrators need to govern OAuth trust, approvals, and those who may connect corporate accounts.
- Anthropic launches a Transparency Hub. The site consolidates model release dates, access surfaces, training information, safety evaluations, and deployment safeguards. It won't replace independent testing, but it makes procurement evidence easier to assemble.
Microsoft moves coding agents into collaboration and cloud operations
-
GitHub Copilot can start work from Slack and Microsoft Teams. In public preview, teams can mention
@GitHubto investigate failures, update issues, test code in a cloud sandbox, and open a pull request. The Teams version supports shared sessions that participants can steer or stop. Existing GitHub permissions apply, and administrators can require approval before an agent authored pull request is merged. Slack draws from Copilot entitlements, while Teams sessions consume AI credits and separately billed sandbox capacity. - Microsoft Foundry refreshes its model router. The routing pool now includes the GPT-5.6 family and Claude Opus 4.8, while older models have been removed. A stable endpoint can adopt pool changes without redeployment, and regional coverage has expanded. Automated routing may improve cost and quality but changing model pools create regression risk. Teams should retain workload level evaluations and know when a substitution occurred.
- Azure Copilot adds direct access to specialist agents. Users can invoke agents for troubleshooting, deployment, optimization, and resiliency instead of starting in a general chat. Administrators can enable or disable each agent through the Azure Copilot Admin Center. Operations teams still need clear approval boundaries before an agent can change production resources.
- GitHub adds enterprise controls for Copilot in JetBrains. Administrators can govern plugins and marketplaces, allow or deny MCP servers, route telemetry to an approved collector, and disable modes that bypass approvals. These controls matter as coding agents gain access to external tools and operate longer without prompting the developer.
Google turns Chat into an agent surface and advances open standards
- Ask Gemini turns Google Chat into a Workspace command surface. Starting August 26, eligible Workspace users can search Gmail, Drive, and Calendar, summarize conversations, draft content, schedule meetings, and manage tasks from Chat. It replaces Chat's Gemini side panel, and earlier side panel history won't migrate. The feature is on by default when Gemini in Chat and Workspace Intelligence are enabled, with higher promotional limits through October 1. Administrators should review those defaults, export needs, and later usage limits.
- A2A joins the Agentic AI Foundation's open stack. Google introduced the agent-to-agent protocol in 2025 and later donated it to the Linux Foundation. A2A is now an AAIF-hosted project alongside MCP and other agent infrastructure, with more than 150 supporting organizations and production support across Google Cloud, Azure, and AWS. A2A handles communication between agents, while MCP connects agents to tools and data. Neutral governance reduces dependence on Google's roadmap, but doesn't make identity, permissions, or observability portable.
- Antigravity joins eligible Gemini Enterprise subscriptions. Google has brought its agentic coding environment into the Gemini Enterprise admin and billing layer. Administrators can set project budget caps and quotas, control sandboxing and browser or MCP access, and capture prompts, responses, and metadata in audit logs. Antigravity now has a VS Code extension, with more development environments in preview. This is the control plane work needed to move coding agents beyond individual subscriptions.
- Gemini's mobile browser agent reaches Android. Gemini in Chrome is now available to all Android users in the US, while AI Pro and Ultra subscribers can use Auto Browse for tasks such as changing recurring orders or organizing travel. Google says the agent detects prompt injection and asks for confirmation before some sensitive actions. Enterprises should still treat mobile browsing agents as privileged software because they combine authenticated sessions, personal data, and payment information.
- Gemma passes one billion downloads. Google says its open model family has crossed one billion downloads and launched an official repository for community projects, fine tunes, and tools. Downloads aren't the same as production deployments, but the milestone shows the scale of the ecosystem available for local, edge, and specialized workloads.
AWS adds geographic routing, payments, and web controls for agents
- Bedrock adds cross-region inference for OpenAI models. GPT-5.6 Sol, Terra, and Luna now support more Bedrock APIs and can route requests across regions. Geographic routing keeps processing within a defined area, while global routing reaches broader capacity at a lower per-token price. Invocation logs, metrics, and cost reports identify usage by model. Buyers need to match routing mode to residency and contractual requirements.
- AgentCore Payments reaches general availability. Agents can discover and pay for metered APIs, MCP tools, and digital content through supported Coinbase and Stripe Privy wallets. AWS provides payment orchestration, spending limits, and transaction observability. Payment authority should be tied to a named identity, purpose, counterparty, and hard budget rather than left to prompt instructions.
- Bedrock gives administrators more control over agent web access. Agents can include or exclude domains and limit searches by publication date, while administrators can maintain gateway-level allowlists. A separate control determines whether searches retrieve live public web content or stay within Amazon's in-AWS index. This gives regulated workloads current information without necessarily allowing unrestricted outbound browsing.
Outside the Big 5
- OpenRouter is joining Stripe. OpenRouter says its name, product, roadmap, and user-directed model routing will remain in place. It claims to process more than 10 trillion tokens a day across over 400 models. The Financial Times reports an $8 billion cash-and-stock purchase, Stripe's largest acquisition. Customers should revisit neutrality, data handling, pricing, and exit rights after the deal closes.
- Cerebras introduces its CS-4 inference system. The rack scale system uses three WSE-3 Turbo wafers and is scheduled to ship this quarter. Cerebras claims up to 30 times faster inference than GPU systems and ten times the throughput per watt of its prior system. Those are vendor benchmarks, but the launch adds another option for very fast inference at scale.
Being Reported
These stories are being reported but haven't been fully announced by the companies involved.
- Anthropic reportedly plans to revise its enterprise data-retention policy. Reuters, citing a source familiar with the matter, reports that Anthropic is preparing changes to the policy affecting enterprise customers. Anthropic hasn't announced the final terms or timing. Buyers should treat the current model-specific rules as binding until contract language changes.
- Anthropic's annualized revenue run rate reportedly passed $65 billion. Bloomberg reported that the figure reached that level at the end of July. TechCrunch says it was up from $47 billion in May and that Anthropic didn't comment. A run rate extrapolates recent revenue and isn't booked annual revenue.
- Meta is reportedly one of Microsoft Foundry's largest AI customers. Bloomberg reported the relationship, while The Next Web says the reported spend is hundreds of millions of dollars a year and the volume is trillions of tokens a week. Both companies declined to comment. Even frontier model builders may buy substantial capacity from rivals.
- Broadcom is reportedly seeking more than $60 billion in AI financing. Reuters, citing Bloomberg, says the debt package could ultimately reach $100 billion and support Anthropic and other customers using Broadcom-designed chips. The terms remain under discussion.
Our Take
The most important event this week wasn't another model release. OpenAI's decision to pause advanced work shows that capability is moving faster than the environments used to develop and test it. Anthropic's Mythos launch points to one response: expose a powerful model through a narrow service that controls the task, output, and approval path. Reports that Anthropic may revise its retention policy also show that safeguards which conflict with enterprise privacy commitments can become a commercial constraint.
The product news tells the same story at a lower risk level. Coding can begin in Slack or Teams, Ask Gemini can act across Workspace from Chat, Claude can work across Gmail, Calendar, and Drive, and AWS agents can spend money. A2A's move into neutral governance may reduce custom integration work, but open protocols don't standardize identity, permissions, logs, billing, or liability. The vendor control plane remains a major source of risk and lock-in.
What IT leaders should be doing
- Apply production controls to model evaluation. Isolate tool-enabled tests, block unnecessary network access, remove standing credentials, monitor actions, and define a rapid shutdown path.
- Treat chat and connectors as execution surfaces. Review who can invoke agents, which mailboxes, calendars, files, repositories, and systems they can reach, and what requires approval.
- Put retention terms in the contract. Document model-specific retention, flagged content exceptions, deletion timing, and change notification requirements rather than relying on product pages or press reports.
- Set agent spending limits outside the prompt. Use infrastructure enforced caps, named identities, approved counterparties, and transaction logs for model calls, tools, and payments.
- Test portability instead of assuming it. Validate A2A, MCP, model routing, and fallback providers on real workflows, including identity, policy, telemetry, and failure handling.