---
title: "AI weekly: NYC under oath, cyber tiers, Decisions and Ultrafast"
description: "AI weekly roundup, 5-11 October 2026: New York puts AI labs under oath, Anthropic tiers cyber access and OpenAI sells decisions and speed."
canonical_url: https://www.oguzhan.co/ai-weekly-5-11-oct-2026-oath-and-agents/
author: "Oğuzhan Koçaklı"
author_url: https://www.oguzhan.co/about/
date_published: 2026-10-11T09:36:23+00:00
date_modified: 2026-10-11T09:36:27+00:00
language: en
translations:
  tr: https://www.oguzhan.co/tr/ai-haftalik-5-11-ekim-2026-yemin-ve-ajanlar/
---

# AI weekly: NYC under oath, cyber tiers, Decisions and Ultrafast

This AI weekly roundup opens in New York. Six days after AI companies posed for a [voluntary safety accord at the White House](https://www.oguzhan.co/ai-weekly-28-sep-4-oct-2026-accord-and-agents/), the city made four of them testify under oath. The contrast defined the week. OpenAI, Anthropic, Google and Meta would not attach a probability to catastrophe, promise that a failed safety test would always stop a release, or give the City Council a clean answer on liability.

Then the rest of the industry supplied an odd echo. Anthropic divided powerful cyber assistance into three verified access tiers. OpenAI launched one API for making decisions quickly and another, much more expensive service tier for making a coding model run faster. Google Cloud described an enterprise agent that may eventually sit in the company directory with its own email and calendar identity. By Friday, Axios reported that labs were privately rehearsing the political morning after a catastrophic AI event, most likely a cyberattack.

So this [week in AI](https://www.oguzhan.co/ai/) is less about a single dazzling model than the machinery being built around models: subpoenas, permissions, identity, latency, liability and emergency plans. The software is moving from chat boxes into institutions. Institutions, in return, are beginning to ask who is responsible when it acts.

## 🏛️ New York put the labs under oath. The answers stayed slippery

![Empty council chamber with four chairs and microphones on a curved dais under amber lamps, sealed folders beside them](https://oguzhanco.s3.eu-west-3.amazonaws.com/wp-content/uploads/2026/10/11093617/nyc-council-ai-hearing-empty-microphones.webp)

*Four AI companies testified under oath on 5 October. None gave the Council a risk number or a blanket release rule. Illustration generated with Higgsfield.*

On 5 October, the New York City Council convened a rare Committee of the Whole hearing on AI risk. Roughly 40 of its 51 members participated. Proceedings began at 11:00 and ran late, with representatives from four major labs testifying under oath: Morgan Dwyer of OpenAI, Logan Graham of Anthropic, Shane Cahill of Meta and Alice Friend of Google.

Getting them there had already required force. Most of the companies agreed to attend only after the Council authorized subpoenas on 28 September; Meta volunteered without that pressure. SpaceXAI did not appear despite a subpoena. Council Speaker Julie Menin called the absence a “direct violation” and said the Council was pursuing enforcement in court.

Menin’s plainest question produced the hearing’s sharpest exchange. She asked each company to quantify the risk that advanced AI could cause a worst-case catastrophe. Dwyer answered: “I don’t know. I also don’t think it matters whether it’s 1% or 10% or 20%… None of these levels is remotely acceptable. We should not train models that we cannot make an extremely strong case that we can keep under human control.”

Menin called that answer “flippant at best.” Her comparison was a pharmaceutical company unable to estimate whether its product might kill people.

The other witnesses did not provide numbers either. Graham discussed Anthropic’s cyber and loss-of-control assessments but offered no percentage. Cahill said Meta would follow up rather than be imprecise. Friend said no rigorous scientific method yet exists for assigning such a probability. These are defensible cautions in isolation. Heard together, from companies spending heavily to make the systems more capable, they leave a large hole where a public risk estimate might be.

Liability was no cleaner. Asked who should pay if a rogue AI caused financial loss, exposed data, injured someone or killed someone, Dwyer spoke about safe development without giving a direct yes. Graham said the matter was outside his expertise. Cahill declined to speculate. Friend gave the clearest principle: existing law applies, and “if it’s illegal without AI, it’s still illegal with AI.” That still did not settle how responsibility would be divided among a model maker, deployer and user.

Nor would any company give Menin the blanket release rule she wanted. Would failing an internal safety test, or failing an independent third-party validation, automatically mean do not ship? No witness simply said yes. Dwyer pointed to releases OpenAI had delayed and to a wider review process. A process can be sensible. It can also leave a lot of room for commercial judgment exactly when a fixed boundary would hurt.

The day’s bleakest claims came from former lab employees. Jacob Coxon, previously at OpenAI and Anthropic, told the Council: “We don’t fully control it.” His own assessment was that humanity was more likely than not to lose control, with human extinction among the possible outcomes. Daniel Kokotajlo, formerly of OpenAI, and Alex Turner, formerly of DeepMind, also testified. According to [amNewYork](https://www.amny.com/news/ai-giants-nyc-council-whistleblower-warnings/), Turner put his personal estimate of an eventual AI takeover at roughly one in three. Those are the witnesses’ estimates, not established probabilities, but they explain why the Council was unwilling to accept polished safety-process descriptions.

The proposed New York package includes third-party validation, human kill switches, whistleblower incentives, a private right of action and 24-hour incident reporting for city systems. No vote took place at the hearing. The fight over New York’s RAISE Act also returned: state Senator Andrew Gounardes said companies had lobbied against its stronger original form, while Assembly Member Alex Bores accused OpenAI of lying under oath about its position.

One more detail matters. OpenAI said it was reviewing possible past agent-misalignment incidents dating to November 2025. Dwyer said she was not aware of any effect on New York City government systems or residents, stressed that the review was still underway, and committed to telling affected third parties if New York City turned out to be hit. OpenAI also said it intends to make the results public.

The [City Council’s account of the hearing](https://council.nyc.gov/press/2026/10/05/3278/) is unusually direct. Monday’s lesson was not that city legislators had solved frontier AI policy. It was that a municipal body could use subpoenas and sworn testimony to expose how few crisp commitments sit beneath national safety language.

## 🔓 Anthropic turned cyber capability into a three-key door

![A glowing AI core seen through three nested gates marked with a shield, a red test grid and circuit patterns](https://oguzhanco.s3.eu-west-3.amazonaws.com/wp-content/uploads/2026/10/11093619/anthropic-cvp-three-cyber-access-gates.webp)

*Anthropic’s expanded CVP: Defense, Red Team and Specialized Access, with fewer cyber blocks and stricter vetting at each step. Illustration generated with Higgsfield.*

On 6 October, Anthropic expanded its Cyber Verification Program, folding the earlier Project Glasswing and CVP into one structure with three access levels. General-availability versions of Opus 5.5, Fable 5.1 and Sonnet 5.5 retain conservative safeguards that block most cyber work. Verified users can apply for broader access to Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models.

Defense Access is the widest gate. It covers security operations and incident response, malware reverse engineering, and vulnerability analysis or validation. Company security teams, critical-infrastructure operators, smaller businesses, open-source maintainers and individual researchers with a record of reporting vulnerabilities can apply. Anthropic says it aims to respond within a few days.

Red Team Access adds authorized penetration testing and red-team work. It is limited to organizations, not individual researchers, and reviews take weeks. Applicants receive Defense Access while waiting. Real-time blocks remain for ransomware, physical harm, mass disruption and attacks on high-risk safety systems.

Specialized Access removes the most cyber blocks. It is reserved for organizations authorized to test systems whose failure could threaten lives or markets, including flight operating systems, power grids, telecom networks, interbank systems and government administrative networks. Applications are reviewed with the US government. Existing Glasswing members move across without reapproval for the models they already use.

The scale behind this gate is striking. [According to Anthropic](https://www.anthropic.com/news/cyber-verification-program), Glasswing partners found at least 129,000 verified software vulnerabilities from April through July 2026. Anthropic’s own open-source scanning added another 5,500 from April through October. Of all those verified vulnerabilities, more than 33,000 have so far been rated critical or high severity. Anthropic calls the total an undercount, since it rests on survey data from only a subset of Glasswing partners, and expects the true impact to be at least five times higher.

One benchmark shows how much policy now shapes model utility. Anthropic ran Opus 5.5 through CyScenarioBench, five attempts at each of 10 challenges per tier. Without CVP, every task was blocked at the first prompt. Under Defense Access, 46 of 50 trials were blocked at some point. Under Red Team Access nothing was blocked and the model completed 34 of 50, which Anthropic calls effectively equivalent to its 67.6 percent success rate with no safeguards at all.

Access comes with monitoring. Data retention is required to detect misuse. Anthropic says Enterprise Frontier Safeguards, planned for later this fall, will add customer-controlled storage. Until then, zero-data-retention customers using Fable 5.1 or Mythos 5.1 can use CVP while keeping ZDR. The program is available through Claude Platform, Vertex AI and Microsoft Foundry; Bedrock access is limited to customers eligible for the forthcoming safeguards.

This is not simply a looser safety setting. Anthropic is building a licensing system around capability, identity and institutional legitimacy. The same prompt can be blocked for a general user, partly allowed for a defender and opened much further for an approved organization. Who gets the key becomes part of the product.

## ⚡ What is the Decisions API actually deciding?

OpenAI’s 6 October launch was not another general chat model. The [public-beta Decisions API](https://community.openai.com/t/decisions-api-is-now-available-in-public-beta/1403877) gives every developer a dedicated endpoint, `POST /v1/decisions`, using `gpt-6-luna` for quick judgments inside applications.

It accepts text, images or both. A developer can request a predicate, meaning the probability that a statement is true; a choice among fixed options with confidence values; or a numeric score against a rubric. According to OpenAI’s announcement, it can be up to roughly ten times faster than GPT-6 Luna through the Responses API on decision tasks.

The price is unusually simple: $0.10 per million input tokens, with no output-token, cache-read or cache-write charge. Replies in the launch thread confirm there is no input caching during the beta, which makes switching high-volume classification jobs less attractive than the headline price suggests.

The attraction is easy to see. An agent about to refund a purchase, route a support case, flag an image or choose its next tool does not always need a long answer. It needs a small, typed judgment before the rest of the application can move.

Early community testing in the same thread is worth reading with care. One developer ran a few hundred questions from word games and a conversational game and found Jev cheaper, faster and more accurate on judgment-heavy questions, with the two roughly level on simple yes/no checks. The tester called it a strong early signal rather than a general benchmark, which is the right weight to give it. Another user noted that Jev does not accept images yet, so image checks are an obvious opening for Decisions. A third test showed output format changing the apparent confidence: with a coin loaded to land heads 70 percent of the time, the predicate format returned heads about 70 percent of the time over 1,000 trials, while the choice format returned it about 98 percent of the time. The same tester added that Jev does no better here. A fixed-choice interface can concentrate probability mass and make uncertainty look tidier than it is.

That is the interesting bit. Decision models do not merely answer faster; their schemas influence what downstream software believes. Anyone wanting the longer route into this category can read the earlier [Clef and Jev comparison](https://www.oguzhan.co/clef-vs-jev-cloudflare-decision-models/). For this week’s purposes, the API marks a move from generating prose to selling machine-readable judgment by the million.

## 🏢 Google’s new coworker needs an identity policy

At Gemini at Work 2026 on 8 October, Google Cloud announced the Gemini agent, describing it as a universal agent for work. The official pitch begins with one prompt box and the organization’s business context. From there, the agent can answer questions, create content, write code, plan work, use tools and skills, connect to company systems, then deliver results into documents, inboxes or development environments.

Google says the agent chooses the best model for a job and includes cost controls plus enterprise security, administration and governance. That phrasing matters because the product is intended to span tasks rather than remain attached to one model or one chat thread.

The more consequential details came from secondary reporting and should be treated accordingly. Reports from Implicator and New Way said the agent was in private preview for selected customers and could route work across Google’s Gemini family and Anthropic’s Claude. They also described a persistent coworker mode in which an agent may receive its own company email, calendar and directory identity. Timing for general availability and pricing for long-running agents were not fully public, despite chatter about late October or early November and some inclusion in existing Gemini Enterprise or Workspace business plans.

Google Cloud CEO Thomas Kurian described the shift this way, as [quoted by Implicator](https://www.implicator.ai/google-launches-gemini-agent-that-gives-ai-coworkers-their-own-workspace-email/): “You give it objectives, not just instructions.”

I think the mailbox is more revealing than the slogan. Once an agent has an address, calendar access and a durable place in the company directory, it starts to resemble a service account with initiative. Which meetings can it accept? Can another employee forward confidential material to it? Who reviews the messages it sends? What happens to its history when a project ends?

The [official Google Cloud announcement](https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/gemini-at-work/) emphasizes business context and delivery into existing work surfaces. The difficult work begins just beyond that announcement, in permissions, audit logs, retention and ownership.

## 🚀 OpenAI put an express-lane price on coding latency

![Two streams of code packets enter one AI chip; the bright fast lane passes through a metering turnstile with a dial](https://oguzhanco.s3.eu-west-3.amazonaws.com/wp-content/uploads/2026/10/11093622/gpt-6-1-sol-ultrafast-metered-lane.webp)

*Same model, two lanes: OpenAI says Ultrafast Sol is up to 8x faster, and in the API it costs 6x Standard. Illustration generated with Higgsfield.*

Around 8 and 9 October, OpenAI rolled out Ultrafast mode for GPT-6.1 Sol across the API, Codex and ChatGPT Work. The company says it can run up to eight times faster than Standard Sol while keeping intelligence close to GPT-6 Astra. Those are company claims, not an independent latency result.

API users can request the tier by setting `service_tier: "ultrafast"` on `gpt-6.1-sol`. It is available to all API users, but the express lane costs six times the Standard rates (short-context prices, as listed in DigIntoAI’s summary of OpenAI’s pricing page):

| GPT-6.1 Sol API tier | Input per 1M tokens | Cached input per 1M | Cache write per 1M | Output per 1M |
| --- | --- | --- | --- | --- |
| Standard | $2.00 | $0.10 | $2.50 | $10.00 |
| Ultrafast | $12.00 | $0.60 | $15.00 | $60.00 |

In Codex and ChatGPT Work, Ultrafast is limited to the $500 Pro plan and eligible Enterprise or Education accounts. It consumes included usage at eight times the Standard rate. Credits and pay-as-you-go usage are charged at six times the Standard rate. Enterprise workspaces have it disabled until an owner turns it on.

Sol Ultrafast has separate rate limits, with higher tokens-per-minute allowances on Build, Launch and Grow than Astra Ultrafast. It also supports US and EU data residency; a [summary of the product documentation](https://digintoai.com/en/articles/gpt-6-1-sol-ultrafast-api-codex-pricing) says Astra Ultrafast remains US-only.

Early Playground users reported a much less dramatic feel at roughly 49 tokens per second. OpenAI’s Tibo (@thsottiaux) attributed that to the Playground itself, both browser rendering and the network, and OpenAI shipped rendering changes for the Playground. OpenAI has not published measured speed figures, so that exchange is not a speed audit. It does show why “up to eight times” needs workload-level measurement before anyone rebuilds a budget around it.

The larger shift is commercial. Coding latency is no longer merely something the model provider optimizes in the background. It is a metered service class. A team can now pay six times more per token to shorten the pause between an agent’s thought and its next action. Cloud computing has had this logic for years. AI coding tools have made it visible at the prompt.

## 🧯 By Friday, labs were rehearsing the day after catastrophe

The political rhyme arrived on 9 October. Axios reporter Maria Curi wrote that senior executives at Anthropic, OpenAI and other AI companies were privately gaming out the public and political backlash after a catastrophic AI event.

The anticipated event was large, with a cyberattack considered the likeliest form. Financial services, the internet, electricity or water could be affected. Axios reported that many senior researchers and executives believed a major incident was inevitable, while an OpenAI spokesperson drew an important distinction: the company does run preparedness exercises, but the scenarios are “not treated as inevitable.” Anthropic declined to comment.

According to the report, planning has two tracks. Labs red-team worst cases, then consider how to educate Congress quickly enough to influence legislation written after a crisis. Many industry insiders told Axios they expect a major event within the next six to twelve months. They are unnamed, and no public method sits behind that window.

Axios also cited a recent campaign against South Korean financial organizations, in which a hacker from China allegedly used AI tools including DeepSeek to steal data from tens of thousands of bank customers. According to CrowdStrike, the attacker also asked Claude Code for help finding places to sell the stolen data. The report placed that episode beside political proposals ranging from pauses on superintelligence to kill switches, an idea with some bipartisan and industry support but disputed technical feasibility.

Read beside Monday’s hearing, the tension is hard to miss. Under oath, companies would not quantify catastrophe or accept an automatic no-release rule. In private, according to Axios, parts of the same industry are preparing for the legislative rush after a severe cyber incident. Preparedness is responsible. Wanting to shape the rules after the disaster is also power politics.

The [Axios report](https://www.axios.com/2026/10/09/ai-companies-day-after-major-attack) (also summarized by [Decrypt](https://decrypt.co/380621/openai-anthropic-quietly-rehearsing-ai-catastrophe)) does not prove that catastrophe is imminent. It does show that the people building these systems consider the aftermath concrete enough to rehearse. That is more revealing than another safety-principles page.

## 📦 A 21-fold rush closed Anthropic’s startup gate

One smaller item completed the week’s access-control theme. On 9 October, Anthropic head of startup marketing Sarah Wolf [said on X](https://postcutoff.com/p/2026-10-09-sarahzorah-claude-startups-21x/) that Claude Startups had received 21 times as many applications in its first 48 hours as in the previous five months the program had been live.

The acceptance criteria had not been tuned for the rush, and Wolf said many non-startups were accepted. Anthropic paused distribution of Claude Team plans and $1,000 API-credit benefits while it rechecked applicants. Already claimed offers remain valid; people with unclaimed offers will be reverified by email. Startup Stack resources and Applied AI office hours and events continue.

Free frontier-model credit attracts opportunists. No surprise there. What is notable is how the same operational question appeared at every scale this week: who gets access, to which capability, under whose identity, with what record and at what price?

New York’s legislators tried to answer that question with law. Anthropic used verification tiers. Google reached for enterprise administration. OpenAI sold two different forms of speed. None of these systems is just “the model” anymore.

That may be the useful way to remember 5 to 11 October. The models kept moving, but the real news was the set of doors being built around them, and the hurried planning for the day one of those doors fails.
