China launches WIKO as open models narrow cyber gap

China launches a 29-member AI group as Anthropic cuts Claude limits and AISI reports a 4-7-month open-model cyber gap.

Top Stories

China forms WIKO with 29 founding members

Twenty-nine nations formally established the World Artificial Intelligence Cooperation Organization, or WIKO, with its headquarters in Shanghai. The organization was first proposed in 2025. The countries named in the report include Russia, Brazil, South Africa, Pakistan, and Indonesia, and no Western country signed on. The Decoder has the details.

At the World AI Conference in Shanghai, Xi Jinping announced 5,000 AI training slots for Global South countries over the next five years. The same report says Xi called for AI to remain under human control and pushed back against overly broad national-security justifications in AI policy. The Decoder describes WIKO as China’s clearest bid yet for a parallel AI governance structure outside Western influence. Read the full report.

Anthropic cuts Claude Fable 5 subscription limits

Anthropic plans to end its bonus-usage phase on July 20. The regular limits will fall by 33 percent, while Claude Fable 5 will remain in the Max and Team Premium plans at 50 percent limits, according to The Decoder’s report.

Pro and Team Standard subscribers will receive usage credits and a one-time $100 credit. The report says Anthropic described demand for Fable 5 as hard to manage, said it was investing in more capacity, and reversed an earlier plan to remove the model from subscription plans. The subscription changes are detailed here.

The Decoder links the reversal to competition from OpenAI’s GPT-5.6 Sol and pricing pressure from China. That is the publication’s explanation for the change, not a statement that Anthropic has confirmed those causes. See the reported context.

Open models narrow the cyber gap to four to seven months

The UK AI Security Institute says recent open-weight models lag frontier closed models on cyber capabilities by four to seven months. That is narrower than the six-to-10-month gap it measured internally through most of 2025. AISI’s report says the comparison is about cyber capability only, not a general ranking of models. This lines up with our earlier look at how open-weight models are sitting ducks for multi-turn jailbreaks - the same weights defenders run are the weights adversaries fine-tune.

On a 70-task narrow cyber suite, AISI found GLM-5.2 comparable to Opus 4.6 and GPT-5.3-Codex, while DeepSeek V4-Pro was comparable to Opus 4.5. In its longer cyber range, called The Last Ones, GLM-5.2 reached the level of Opus 4.5, while DeepSeek V4-Pro fell below Sonnet 4.5. The Decoder’s summary includes the benchmark context.

The cost gap was large in AISI’s comparison of a 100-million-token cyber-range run: about $85 for Opus 4.5 and Opus 4.6, $46 for GLM-5.2, and $1.19 for DeepSeek V4-Pro. AISI cautions that it did not use first-party providers for the open-weight models, so real compute costs may vary. It also says safeguards were largely ineffective in the tests and that deployment-time controls cannot be universally applied once weights are public. Read AISI’s caveats.

NadMesh scans exposed AI services for credentials

QiAnXin XLab describes NadMesh as a long-term botnet that probes 30 ports and uses more than 20 exploitation vectors. Its target list includes ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio, MCP services, Redis, Docker API, Kubernetes, Jenkins, SSH, and Telnet. XLab’s analysis says the malware harvests AWS credentials, Kubernetes service-account tokens, model information, and exploitable MCP tools. We have flagged this default-open MCP posture before when 8,000 MCP servers were found sitting wide open on the public internet.

The Hacker News reports that the botnet’s operator dashboard claimed 3,811 unique AWS keys. XLab separates those dashboard figures from its own observations and notes that panel metrics are controlled by the operator. The Hacker News account also reports that the botnet refreshes scan targets through Shodan.

For self-hosters, the lesson is basic but urgent: services such as Ollama, ComfyUI, and Open WebUI should not be left reachable from the public internet without authentication and network controls. NadMesh is aimed at what an exposed machine can access, not only at the machine’s compute. XLab’s report explains the targeting model.

Acting Secretary of the Navy Hung Cao signed a new AI strategy that took effect immediately, according to The Decoder’s account. The strategy uses a five-stage “Bits2Effects Cycle” from data collection to battlefield action and tracks progress with a metric called Mean Time to Effect. Its core tradeoff is blunt: the document says the risks of moving too slowly outweigh the risks of imperfect alignment.

The strategy called for many measures to be in place by the first quarter of fiscal year 2027 and for the number of qualified data engineers, data scientists, and AI/ML engineers to double by the end of fiscal year 2029. GenAI.mil reached 1.5 million daily users in June 2026, up from 80,000 at its launch in December 2025. The report lays out the targets and figures.

The article also reports that a Navy AI program cut a submarine-planning task from 160 hours to 10 minutes. Those numbers are presented as an example of the speed case for deployment, while the strategy’s alignment tradeoff sets the policy direction for the department. Read the source report.

Meta and Anthropic discuss a possible compute deal

Meta is reportedly in talks with Anthropic to rent compute capacity from Meta’s data centers. The possible deal could be worth up to $10 billion over two years, but Anthropic pitched the arrangement in June, Meta is still reviewing it, and either side could walk away. The Decoder reports.

The same report says Meta plans to spend up to $145 billion this year, mostly on AI, while Anthropic needs more capacity as demand for Claude Code has surged. Anthropic has also signed a $45 billion deal with SpaceXAI and wants to build its own data centers. Those details provide context, but they do not turn the proposed Meta deal into a completed contract. See the reported terms and status.

Claude Code moves to Bun’s Rust port

Simon Willison reports that Claude Code version 2.1.181 and later use the Rust port of Bun. The version was released June 17. The Bun runtime embedded in the macOS arm64 binary identified itself as version 1.4.0, while Bun’s latest public GitHub release was version 1.3.14 when Willison checked. His technical notes include the inspection details.

The change comes from Bun’s Rust rewrite. Willison quotes Bun creator Jarred Sumner saying startup became 10 percent faster on Linux while otherwise barely changing, and writes that the Rust port is running in production across millions of devices. This is an implementation change inside the distributed CLI, not a new model release. Read the technical breakdown.

Kimi K3 turns an open model release into a policy fight

Moonshot AI’s Kimi K3 is an open-source model that TechCrunch says trails the most powerful proprietary models, Claude Fable 5 and GPT-5.6 Sol. Moonshot’s own evaluation claim is more favorable: it says K3 showed frontier-level performance across its evaluation suite and consistently beat the other models it tested. TechCrunch reports both positions.

The article uses K3 to map a disagreement over open weights, model distillation, and regulation. David Sacks and Travis Kalanick argue for a more aggressive response to China’s open models, while OpenAI’s Dean Ball warns that an open-weight-dominated world could make AI a public good provided as digital infrastructure. Transformer editor Shakeel Hashim argues that the concern may be overstated because K3 likely lacks dangerous cyber capabilities. Read the competing arguments.

Quick Hits

Worth Watching

  • AISI plans to test Kimi K3 as it tracks whether the open-weight cyber gap continues to shrink. The institute’s next-step note is the clearest follow-up signal.
  • Anthropic’s July 20 subscription changes will show whether the reduced Fable 5 limits ease access pressure or push more usage toward the API. The Decoder has the reported plan.
  • The Meta-Anthropic compute talks remain unsettled. The report says either side could walk away, so the next meaningful update is a signed agreement or a public cancellation. Track the reported status.