# The Gate, Reopened Halfway

**Issue 11** · 21-27 JUN 2026 · published 2026-06-27  
OPEN INTELLIGENCE · ISSUE 11

> Six days after pulling its most powerful models, Washington unlocked the parent for roughly a hundred vetted institutions and left the consumer model dark. OpenAI answered the policy era by taping out its own inference silicon in nine months and pushing its agent platform into production. Embodiment went commercial on a Shanghai stage. And a single poisoned skill walked into twenty-six thousand agents that every scanner called clean. The chokepoint came back smaller, sharper, and aimed at a model that already tops the board.

Canonical (HTML): https://www.immersivecommons.com/newsletter/issue-11  · Archive: https://www.immersivecommons.com/newsletter

Discovery: https://www.immersivecommons.com/.well-known/signal.llmfeed.json · MCP: https://www.immersivecommons.com/.well-known/mcp.json · Skill: https://www.immersivecommons.com/skills/ic-signal/SKILL.md

---

## I. THE GATE, REOPENED HALFWAY

The state that recalled the model in a week un-recalled the parent for a hundred names, and kept the public one switched off.

### 139 · Washington Reopens The Gate. For A Hundred Names Only.

*The parent model comes back for vetted US institutions. The consumer model stays switched off.*

On June 26, Commerce Secretary [Howard Lutnick sent a letter](https://www.nbcnews.com/tech/tech-news/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018) lifting the two-week block on **Mythos 5** — but only for a defined list. The clearance covers the roughly one hundred [Annex A US institutions](https://www.neowin.net/news/us-partially-reverses-anthropic-ai-ban-for-mythos-but-keeps-fable-5-off-the-market/), their foreign-national employees, Anthropic's own foreign staff, and US government partners. Everyone else stays outside the fence. The order that on June 12 had pulled both models globally is now a perimeter drawn around a hundred names.

What did not come back is the part the public could touch. [**Fable 5** goes unmentioned](https://letsdatascience.com/news/anthropic-restores-fable-5-after-us-ban-9d5e2250) in the Lutnick letter, which means the June 12 suspension and its criminal and civil penalties still stand for consumers, API developers, Claude Code, and every international subscriber. The mechanism is the tell: the government did not reverse the recall, it scoped it. Mythos, the ungated parent confined since April to vetted orgs, returns to a slightly larger version of the same vetted-org list. The capability was never the thing being gated — the access was.

[Axios reported on June 27](https://explainx.ai/blog/is-fable-5-back-2026) that Fable 5, fifteen days dark, was on track to return within days as negotiations progressed; as of this writing no restoration date is public. For a builder the lesson is colder than a launch calendar. The most capable model ever sold to the public can be switched off by letter and switched back on by letter, name by name, and the difference between having it and not is no longer a price or a queue but whether your institution is on a list you do not control.


**Feature: RECKONING**
> They did not undo the recall. They drew it tighter — a hundred names inside the fence, the public outside it, and a model that ships or doesn't on the strength of a single signature.
— THE SIGNAL

**Sources:**
- [NBC News](https://www.nbcnews.com/tech/tech-news/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018)
- [Neowin](https://www.neowin.net/news/us-partially-reverses-anthropic-ai-ban-for-mythos-but-keeps-fable-5-off-the-market/)
- [Let's Data Science](https://letsdatascience.com/news/anthropic-restores-fable-5-after-us-ban-9d5e2250)
- [explainX](https://explainx.ai/blog/is-fable-5-back-2026)

Image: https://www.immersivecommons.com/signal/issue-11/mythos-partial-restore.jpg (image: [NBC News](https://www.nbcnews.com/tech/tech-news/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018))


## II. BUILDING THE WHOLE STACK

OpenAI's answer to a policy era it cannot control: own the silicon, own the runtime, sell the coworker.

### 140 · OpenAI Moves The Coworker Into Production

*Frontier goes live with named enterprises, turning agents from demos into a semantic layer that sits on top of the company's data.*

On June 25, OpenAI [moved its Frontier platform into production](https://www.edtechinnovationhub.com/news/openai-moves-enterprise-ai-agents-into-production-with-frontier-platform) with a roster of launch customers — HP, Intuit, Oracle, State Farm, Thermo Fisher, and Uber among the first. [Frontier](https://openai.com/index/introducing-openai-frontier/) is pitched as an intelligence layer that stitches together a company's siloed systems — data warehouses, CRM, ticketing tools, internal apps — into a shared business context that AI coworkers can reason over. It is available to a limited set of customers now, with broader rollout promised over the coming months.

The load-bearing detail is not the customer logos, it is where the value moves. Frontier gives agents a [dependable, open agent execution environment](https://www.edtechinnovationhub.com/news/openai-moves-enterprise-ai-agents-into-production-with-frontier-platform) — they work with files, run code, and call tools — sitting on a **semantic layer** that encodes how information flows and where decisions get made. That is a deliberate land grab on the most defensible part of the enterprise: not the model, which is rented and swappable, but the map of the business the model runs against. Capgemini joined the accompanying [Frontier Alliance](https://aibusiness.com/agentic-ai/capgemini-openai-frontier-alliance-enterprise-ai) to do the integration work that makes the map.

For the field, this is the other half of the week's policy story. While Washington was rationing raw model access by institution, OpenAI was busy making the model the least important layer in the stack — the part you can pull and replace without disturbing the semantic layer that holds the customer. A builder watching both moves at once should read the signal plainly: the moat is migrating off the weights and onto the context, and whoever owns the company's map owns the account.


**Feature: WATCHLIST**
- Whether Frontier's semantic layer becomes portable or locks customers in — the difference between a standard and a cage.
- How many of the six launch enterprises run Frontier on non-OpenAI models within a year; model-agnosticism is the stated pitch.
- Whether Anthropic and Google ship a context-layer answer, or cede the enterprise map to OpenAI.
- The first audited incident where a Frontier agent's code-execution environment touches production data it shouldn't.

**Sources:**
- [OpenAI](https://openai.com/index/introducing-openai-frontier/)
- [EdTech Innovation Hub](https://www.edtechinnovationhub.com/news/openai-moves-enterprise-ai-agents-into-production-with-frontier-platform)
- [AI Business](https://aibusiness.com/agentic-ai/capgemini-openai-frontier-alliance-enterprise-ai)

Image: https://www.immersivecommons.com/signal/issue-11/openai-frontier-prod.jpg (image: [EdTech Innovation Hub](https://www.edtechinnovationhub.com/news/openai-moves-enterprise-ai-agents-into-production-with-frontier-platform))

### 141 · OpenAI Taped Out Its Own Inference Chip In Nine Months

*Jalapeño is OpenAI's first custom silicon — built with Broadcom, aimed at inference, and a bet on owning the floor under the model.*

On June 24, OpenAI and Broadcom [unveiled **Jalapeño**](https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/), OpenAI's first Intelligence Processor — a custom accelerator architected around its own view of where LLM inference is going, and the first chip in a [multi-generation compute platform](https://investors.broadcom.com/news-releases/news-release-details/openai-and-broadcom-unveil-llm-optimized-intelligence-processor) the two companies are building together. The detail that stopped people was the calendar: design to manufacturing tape-out in [nine months](https://www.cnbc.com/2026/06/24/openai-and-broadcom-reveal-jalapeno-first-ai-chip-in-partnership.html), which the companies frame as among the fastest ASIC cycles ever achieved in high-performance silicon.

Jalapeño is an inference part, not a training one — built for the running of models in response to user commands, where the volume and the cost actually live. Early testing is claimed to deliver [performance per watt substantially better](https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/) than current state-of-the-art, with initial deployment targeted for the end of 2026 and expansion in the years after. Greg Brockman set the thesis without hedging: "By designing more of the stack ourselves, we can serve more intelligence with greater efficiency."

Put the week's two OpenAI moves side by side and the strategy resolves. Frontier captures the customer's context at the top of the stack; Jalapeño captures the cost-per-token at the bottom. A company that owns both ends stops being a tenant of Nvidia and a renter of enterprise data and becomes the landlord of its own economics. For everyone else, the **build-the-full-stack** play sets a new bar: in an era where access to any single layer can be revoked by letter or by supplier, the durable position is to own the layers nobody can switch off.


**Feature: TICKER**
- **9 months** (Design to tape-out)
- **Inference workload** (Not training silicon)
- **EOY 2026 first deploy** (Expanding after)
- **Gen 1 of N** (Multi-gen Broadcom platform)

**Sources:**
- [TechCrunch](https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/)
- [CNBC](https://www.cnbc.com/2026/06/24/openai-and-broadcom-reveal-jalapeno-first-ai-chip-in-partnership.html)
- [Broadcom](https://investors.broadcom.com/news-releases/news-release-details/openai-and-broadcom-unveil-llm-optimized-intelligence-processor)

Image: https://www.immersivecommons.com/signal/issue-11/openai-broadcom-jalapeno.jpg (image: [TechCrunch](https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/))


## III. THE MATTER

The telcos stopped talking about connecting people and started talking about moving machines.

### 142 · The Telcos Declared The Embodied Era On A Shanghai Stage

*MWC Shanghai opened with humanoids walking out before a single human speaker, and the GSMA reframed the whole industry's mission around machines.*

[MWC Shanghai 2026 opened](https://www.techtimes.com/articles/318972/20260624/mwc-shanghai-2026-humanoid-robots-open-day-one-telcos-declare-embodied-ai-era.htm) on June 24 with humanoid robots walking onto the stage before any human took the microphone — a staging choice the GSMA made on purpose. Director General **Vivek Badrinath** told the floor the mobile industry's mission had formally shifted from connecting people to enabling intelligent machines: humanoid robots, drone fleets, and autonomous vehicles. The trade body now calls 5G-Advanced the nervous system of embodied AI, which is the kind of sentence that sounds like marketing until you notice who is saying it.

The week made the claim concrete on two continents. Day two in Shanghai ran a Smart Mobility Summit alongside a [Humanoid Robot Football final](https://www.techtimes.com/articles/318972/20260624/mwc-shanghai-2026-humanoid-robots-open-day-one-telcos-declare-embodied-ai-era.htm); in Chicago the same week, the [Automate show](https://www.automateshow.com/agenda/humanoid-robot-pavilion-stage) ran an NVIDIA-sponsored Humanoid Robot Pavilion programming real sessions on robot learning, sensing, safety, and real-world deployment. The connective term is **embodied AI** — the application of frontier models not to a chat box but to a body with sensors and actuators, where the model's job is to move matter, not text.

For the field this is the matter beat graduating from demo reel to network plan. When the carriers — the people who own the radios and the backhaul — start designing capacity around drone fleets and walking robots rather than around handsets, the embodiment story stops being a robotics story and becomes an infrastructure one. A builder in the physical-AI space should read the GSMA's reframing as a procurement signal: the spend that used to chase phones is being redirected at machines, and the labs that supply the brains for those bodies are about to find a buyer with a budget.


**Feature: RECEIPT**
> The mobile industry's mission has shifted from connecting people to enabling intelligent machines.
— BADRINATH · DIRECTOR GENERAL · GSMA
Opening MWC Shanghai 2026, after humanoid robots walked the stage ahead of any human speaker.

**Sources:**
- [Tech Times](https://www.techtimes.com/articles/318972/20260624/mwc-shanghai-2026-humanoid-robots-open-day-one-telcos-declare-embodied-ai-era.htm)
- [Automate Show](https://www.automateshow.com/agenda/humanoid-robot-pavilion-stage)
- [Gasgoo Auto News](https://autonews.gasgoo.com/articles/news/two-government-agencies-move-to-accelerate-humanoid-robot-development-2065328346576302081)

Image: https://www.immersivecommons.com/signal/issue-11/mwc-shanghai-embodied.jpg (image: [Tech Times](https://www.techtimes.com/articles/318972/20260624/mwc-shanghai-2026-humanoid-robots-open-day-one-telcos-declare-embodied-ai-era.htm))


## IV. THE RUNTIME STILL LEAKS

OWASP called prompt injection permanent two weeks ago. This week a fake skill proved the marketplace can't tell.

### 143 · A Fake Skill Walked Into 26,000 Agents. Every Scanner Called It Clean.

*The agent supply chain's newest soft target is the skill marketplace, and this week proved the safety check can't see the threat.*

This week's [cybersecurity roundup](https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-exploits-and-supply-chain-risks-define-this-week-in-cybersecurity-in-june-2026/) led with a quiet, ugly one: a fake AI agent **skill**, pushed through a popular skill marketplace, reportedly reached roughly 26,000 agents — some of them on corporate accounts — while every skill-security scanner in the path marked it safe. No exploit chain, no zero-day. The malicious capability arrived through the same front door the legitimate ones use, and the automated reviewer waved it through.

The mechanism is the recurring architectural flaw, one layer up. A **skill** is packaged instruction plus tool access an agent installs to extend itself; the marketplace scanner judges it the way an app store judges a binary. But an agent skill is not a binary — its payload is natural-language instruction that only becomes dangerous in the context of the agent that runs it, which is precisely the [class of failure OWASP flagged as permanent](https://www.rescana.com/post/threatsday-bulletin-june-2026-miasma-supply-chain-worm-leak-claude-code-github-action-vulnerability-ai-agent-phishing-to) two weeks ago. The same week brought [CVE-2026-4372](https://therecord.media/supply-chain-attack-hits-widely-used-ai-package), a Hugging Face Transformers remote-code-execution path through malicious model config files — the model-weights version of the same lesson.

For a builder shipping agents on third-party skills, the takeaway is a posture change, not a patch. A green checkmark from a marketplace scanner is not a security boundary; it is a statement that the scanner did not recognize the threat, which for instruction-shaped payloads is the default. The runtime keeps leaking because the thing being installed is language, and language is the one input these systems were never able to quarantine. Treat every installed skill as untrusted code with your agent's full privileges — because that is exactly what it is.


**Feature: LEXICON**
- **Skill** — A packaged bundle of instructions plus tool access an agent installs to extend itself — distribution-shaped like an app, danger-shaped like a prompt.
- **Scanner-blind** — A malicious artifact that passes automated security review because the reviewer checks for code threats while the payload is natural-language instruction.
- **Agent supply chain** — The marketplaces, registries, and package feeds an agent pulls capability from — now a primary attack surface, the way npm and PyPI became before it.

**Sources:**
- [eSecurity Planet](https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-exploits-and-supply-chain-risks-define-this-week-in-cybersecurity-in-june-2026/)
- [Rescana](https://www.rescana.com/post/threatsday-bulletin-june-2026-miasma-supply-chain-worm-leak-claude-code-github-action-vulnerability-ai-agent-phishing-to)
- [The Record](https://therecord.media/supply-chain-attack-hits-widely-used-ai-package)

Image: https://www.immersivecommons.com/signal/issue-11/skill-marketplace-poison.jpg (image: [eSecurity Planet](https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-exploits-and-supply-chain-risks-define-this-week-in-cybersecurity-in-june-2026/))


## V. THE BOARD

The model the government just rationed is the one sitting at the top of the agentic leaderboard.

### 144 · The Model They Rationed Sits At The Top Of The Board

*As Washington scoped Mythos 5 to a hundred institutions, the agentic leaderboards put it first — and left the still-banned consumer model 0.3 points off the coding lead.*

The week's policy fight has a scoreboard, and it reads against the policy. On [BenchLM's agentic leaderboard](https://benchlm.ai/agentic), the top model as of late June is **Claude Mythos 5**, with a weighted agentic score of 100 — and agentic capability now carries the single largest weight in the composite, 22%, on the theory that browse-and-do workflows matter more than chat fluency. The model the US just rationed to roughly a hundred institutions is the one the independent evals rank first at doing the work.

The picture on coding is closer and more pointed. On [Terminal-Bench](https://www.morphllm.com/best-ai-coding-agents-2026), Codex paired with GPT-5.5 leads at 83.4%, with Claude Code on **Fable 5** a rounding error behind at 83.1% — except Fable 5 is the model that, as of this week, no developer outside the cleared list can actually run. The leaderboard is measuring a capability the market has been denied access to; the [public benchmark trackers](https://llm-stats.com/benchmarks) keep scoring a contestant that has been pulled from the field.

For a builder the divergence is the whole story of the issue. Capability and availability have come unbolted: the most capable agentic model is the least freely available, and the gap between the top two coding stacks is smaller than the gap between being allowed to use one of them and not. When the leaderboard and the license disagree this loudly, the number that decides your roadmap is not the benchmark score — it is whether your name is on the list that gets to touch it.


**Feature: TICKER**
- **100 agentic score** (Mythos 5, top of BenchLM)
- **22% composite weight** (Agentic, the biggest single factor)
- **83.4 / 83.1 Terminal-Bench %** (Codex+GPT-5.5 vs Claude Code+Fable 5)
- **~100 institutions** (Cleared to run the leader)

**Sources:**
- [BenchLM](https://benchlm.ai/agentic)
- [Morph](https://www.morphllm.com/best-ai-coding-agents-2026)
- [LLM Stats](https://llm-stats.com/benchmarks)

Image: https://www.immersivecommons.com/signal/issue-11/mythos-tops-board.jpg (image: [BenchLM](https://benchlm.ai/agentic))

---

*THE SIGNAL · FRONTIER TOWER / SAN FRANCISCO*