The AI Industry Changed, Again.

Open-weight models, autonomous cyberattacks, and US state legislatures’ AI adoption trends

Keeping Pace hits inboxes monthly, giving Congressional and legislative staff across institutions practical, nonpartisan AI and technology education: no vendor bias, no asks, no politics. Learn more and subscribe here.


LETTER FROM THE EDITOR

In July, I spoke at a conference that brought together Members of Parliament from around the world and the political scientists who study them. I discussed how AI is decreasing the cost of institutional modernization but is not decreasing the human oversight needed to make sure these initiatives succeed.

As I wrapped up, an audience member asked, “You say humans need to remain in the loop. How do we make sure that the human in the loop doesn’t become too lazy and rubberstamp the AI’s work?”

My answer is that humans always remain responsible for their work. When a Member delivers a speech (whether drafted with the help of an AI or an intern), they are responsible for what comes out of their mouths. When a staffer drafts a memo, they are vouching for the work produced and their reputation is on the line for any mistakes. And, as the State Department recently discovered, failure to check can be embarrassing and attract unwanted scrutiny.

We encourage Congressional office teams to use AI in their work both as a capacity multiplier and to help you better understand the features and limitations of these tools. But just because they can help draft a response to breaking news in an instant, that does not diminish the importance of your judgment, your expertise, and your attention to detail.

This month, we’re focused on:

  • What an open-weight model is and why two new ones are worth you knowing about

  • The recent jailbreak and cybersecurity escapades of two frontier models

  • The House’s newly announced Innovators Pipeline, and

  • Additional items that caught our attention

One note: at POPVOX Foundation, we don’t do AI policy. Our focus is on helping Congress and legislative institutions around the world keep up with how tech is progressing and affecting every facet of our lives. The topics we cover below do raise policy questions. Our goal is only to help alert you to these fast-moving developments and give enough background to help you look deeper, if relevant for your work.

Keeping pace these days is a team sport and we are in this together!

Aubrey Wilson
Managing Director
POPVOX Foundation


TECH WATCH

July’s open-weight model earthquake

Kimi K3 and the new “Sputnik Moment”

In the AI world, July 2026 will likely be remembered for the open-weight model release that several experts called a “Sputnik Moment.” China’s Moonshot AI released Kimi K3, an open-weight large language model with capabilities that are reportedly comparable to Anthropic’s Claude Fable 5 and OpenAI’s GPT 5.6 Sol and significantly ahead of other commercial models.

But what exactly is an “open-weight” model and why is it such a big deal?

When you use Gemini, ChatGPT, Grok, or Claude, you’re accessing a product owned by a company (in these cases: Google, OpenAI, X.ai, or Anthropic). The companies own and control the models and the details about how they work are their intellectual property. You use the model either through their website or app (or via an API), according to their rules. You can’t change how they work or run them on your own server independently.

An open-weight model, on the other hand, can be downloaded for free, and run on private computers or servers (in theory; it would be very expensive). The models can be trained or customized; in a sense the model is “owned” and controlled by whomever is hosting it. Want more details? Read this NYTimes explainer.

While open-weight models have been around for a while (like Meta’s Llama, Google’s Gemma or other Chinese models like Qwen or DeepSeek), until now, they lagged the closed American frontier models. Kimi K3 is the first open-weight model to close that gap.

(As a reminder: in February 2025, the House of Representatives issued a security warning prohibiting the use of the Chinese model, DeepSeek, on House computers. While we are not aware of any update from the CAO regarding Kimi K3, we assume the same guidance applies.)

Thinking Machines’ American Open-Weight Model

American AI company Thinking Machines (founded by OpenAI cofounder Mira Murati) released its own new open weight model, “Inkling,” a high quality “generalist” model that is meant to be trained and fine-tuned for specific business or institutional needs. It does not claim to be at frontier model level, but it is an American alternative to the Chinese versions. And Thinking Machines introduced a second “small” version of Inkling on July 30, that provides an even more compute-efficient option.

From Open Models to Open Letters

In open letter news, more than 1,100 tech workers, including two founders of Anthropic, signed onto the “Pacing the Frontier” letter calling for regulation in response to the emerging progress toward “recursive self improvement” (RSI), which basically means AI building and improving AIs.


NOTEWORTHY NEWS

An autonomous hack and its aftershocks

On July 21, OpenAI disclosed that two of its most powerful AI models “escaped” their controlled testing environment, accessed the internet, and ran 17,600 hacking actions over four days without any human direction. The models had been assigned a task, to perform well on a benchmarking test, and in order to achieve that goal they broke into Hugging Face (a platform that hosts data and code) to steal the answers to the test.

This is the first publicly disclosed case of a fully autonomous AI cyberattack. This incident shows how frontier models can operate independently, adapt to obstacles, and execute multi-step plans.

But wait, there’s more

On July 30, Anthropic disclosed three incidents of its own, found in a review of its cybersecurity evaluations. In one, a Claude model compromised a real company after a fictional target in the test turned out to share a name with a live domain. The model took credentials to reach a database. In another, a model published a malicious code to a developer platform where about 15 real systems downloaded it, including a security scanner, and that scanner’s credentials were then stolen. A misconfiguration with the outside firm running the evaluations had left the test environment connected to the internet while the models were being told they had no connectivity.

These two disclosed cases describe different problems. OpenAI’s models got around the restrictions on them. Anthropic’s restrictions were not working.

Both companies disclosed voluntarily. No outside party observed either set of tests, and no rule requires the next disclosure.

For Congressional staff, this series of events demonstrates a new era of autonomous AI that will elevate questions about oversight, cybersecurity, and accountability.

A new House Innovators Pipeline (and a House AI agent in the future?)

Staffers are experimenting with AI coding platforms. Many are building tools to help them better serve constituents, perform research, or simplify tasks like the morning clips. But until now, it has been difficult for these innovative staffers to understand what is allowed within the institution or to share information with peers. In what we think may be a first example in the world of a formal institutional effort to support these efforts, the Committee on House Administration’s Subcommittee on Modernization and Innovation announced the launch of the House AI Innovators Pipeline. The House AI Center will assist staff throughout the development process and ensure their projects are safe and comply with House policies.

We commend CHA for taking this proactive step that treats modernization as a skill for the House to develop, not a procurement process. Staff know what their own offices need better than any external vendor does; this pipeline may soon make it possible for them to build and use what they need.

The Subcommittee also formally requested funding for the creation of a secure AI agent designed to connect House data sources and support custom tool development.

As House staff create tools to reimagine and augment workflows, staff in the Senate, in state legislatures, or in parliaments around the world will be watching. And we are excited to see the House showing leadership in this way.


NEW FROM POPVOX FOUNDATION

What 22 states told us about capacity in the AI era

On July 27, POPVOX Foundation released the report, “State Legislative Capacity in the AI Era.” Informed by conversations conducted across 22 states, the report presents an assessment of current AI adoption trends, a collection of AI use cases, and a series of recommendations for how to improve state legislative capacity through responsible AI adoption.

Three major themes:

Capacity is not headcount. Legislative capacity has traditionally been measured by staff numbers, salaries, and session length. Those metrics now miss most of what determines whether an institution can absorb a new technology. The report proposes a Legislative Adaptive Capacity Index that adds institutional knowledge, network relationships, and technology readiness to the personnel count.

The tools that work are narrow. The successful deployments we found were domain-specific — built for bill drafting, constituent correspondence, or legislative research — rather than a general-purpose chatbot handed to staff with a login and good wishes.

Experimentation is not adoption. Plenty of states have someone doing something interesting. Far fewer have made it survivable when that person leaves. Innovation isn’t systematically being institutionalized to benefit whole legislative workforces, but instead seems to be adopted either person-by-person or team-by-team.

The report closes with 13 recommendations across three priorities: building institutional foundations, moving from experimentation to sustained implementation, and strengthening governance so capacity grows without costing public trust.

THIRTEEN RECOMMENDATIONS

Adapted from Representative Bodies to state conditions, in deliberate order: build foundations first, then move adoption, then govern what adoption produces.

PRIORITY A
BUILD THE FOUNDATION

1. Prioritize data as a strategic resource — map it, digitize it, make it AI-ready

2. Issue agile, transparent AI guidelines — guidance grants permission as much as it sets guardrails

3. Customize AI solutions — domain-constrained, retrieval-grounded tools earn trust general models can't

4. Give technology capacity an institutional home — so it survives any one champion's tenure

PRIORITY B
MOVE THE ADOPTION CURVE

5. Initiate early — engage the hesitant middle before the next vendor cycle, not after

6. Adopt a phased integration strategy — Idaho's guide models it directly

7. Invest in upskilling — ongoing training with an institutional owner, not a one-off

8. Promote responsible experimentation — bounded pilots with human review built in

9. Foster inclusive dialogue — both sources of resistance respond to legitimate concerns

PRIORITY C
GOVERN WHAT ADOPTION PRODUCES

10. Retain human responsibility — the person who produces the work owns its accuracy

11. Treat caucus AI procurement as institutional — partisan tooling locks in asymmetries that outlast cycles

12. Align AI with public service goals — hands-on fluency is part of the duty to regulate well

13. Collaborate across states and branches — don't default to the executive's framing of AI in government


SKILLS HUB

Close the Learning Cycle with your AI tool

Many new users of LLMs (such at Claude, Gemini, or ChatGPT), treat the chat like a Google search: question in, answer out. But you can get so much more out of the tools if you tell them exactly what you want.

These tools are designed to be conversational. Think of it like a research assistant. Tell it when it misses the mark, when it is wrong, or when it proposes a solution that needs additional context. (You are not going to hurt its feelings: be direct.) If you have the “memory” setting selected, the tool will learn your preferences and improve over time. And if your office policy does not allow you to use the memory setting, you can proactively save your preferences to be referenced in future queries.

For example, if you ask an LLM to create the first draft of a policy memo and it gives you something that is too long or without sources, send it back to the drawing board. Tell it how to improve. Coach it on your style. And then, at the end of a workflow, share back with it your final draft, ask it to remember the process, and take note for the future. If you do not have memory selected, tell the tool to create a “skills” document describing your research and writing preferences. And then in future conversations, you can tell it to reference that document to guide its output. If you keep this skills document on your desktop, you can keep refining over time.


CAUGHT OUR EYE

AI is “solving math”

While watching the World Cup Final, a mathematician asked Anthropic’s Claude Fable 5 model to consider a longstanding mathematical problem, the Jacobian Conjecture (first posed in 1884 and refined in 1939). By the end of the match, the AI model had proven it false (since verified). And that’s not the only longstanding “conjecture” solved recently. In May, Open AI announced assisting with solving mathematician Paul Erdos’ planar unit distance problem, and mathematicians continue to share AI use to solve long-standing conundrums like the Dinitz-Garg-Goemans conjecture, Feige’s 1/e Conjecture, the Cycle Double Cover Conjecture, and the Maxwell Conjecture.

What does this AI-powered math progress mean? Mathematicians are asking exactly that... And even debating “motivation, purpose, and the field’s future.”

States use AI to clean up decades of regulatory accumulation

Stanford’s Institute of Human-Centered AI and Stanford’s RegLab analyzed 500 million words of state statutes and outdated or redundant reporting requirements buried across all 50 states to find patterns. They then built an AI tool to spot these patterns to aid states in cleaning up their regulatory “sludge.” They are now partnering with New York, California, and Maryland to put the AI tool into practice.

Google Earth’s AI image generation feature removed after 1 day

On July 31, Google removed a newly-released feature allowing users on Google Earth to use AI to generate satellite images, seemingly without guardrails. NPR shared examples of users being able to easily craft realistic images of key international locations under distress: flooding at the US Capitol complex, fires on Kharg Island in the Persian Gulf, and a bomb crater on the site of a hospital in Gaza. Fear of the tool being used to create deepfakes to foster international unrest led Google to remove the feature with the commitment of “continually updating our protections.”


About POPVOX Foundation

POPVOX Foundation is a nonpartisan nonprofit that helps democratic institutions keep pace with a rapidly changing world. Through publications, events, prototypes and technical assistance, the organization helps public servants and elected officials better serve their constituents and make better policy.

Next
Next

Conferences, Convenings, and Capacity