OpenAI confidentially filed its IPO prospectus on May 22, with Goldman Sachs and Morgan Stanley leading, targeting a valuation of $852 billion to $1 trillion for a Q4 2026 debut. The company lost $1.22 for every dollar of revenue in Q1 2026 — a number that would be fatal in most industries but reads as table stakes here.

Three days earlier, Anthropic told investors something different: $10.9 billion in Q2 revenue and its first quarterly operating profit of $559 million are both on track. The same week, SpaceX’s IPO filing disclosed that Anthropic pays $1.25 billion per month for access to xAI’s Colossus GPU cluster in Memphis through May 2029 — $15 billion a year flowing from one AI lab to another’s datacenter, via a rocket company’s books. The compute arms race has produced financial interdependencies that would have looked like fiction two years ago.

Google’s bid for the agentic web

At I/O on May 19, Google made a credible bid to own the infrastructure layer for the next phase of the web. AI Mode in Search crossed one billion monthly users one year after debut; Gemini 3.5 Flash is now the global default. Gemini Omni arrived for video generation — text, image, audio, and existing video as inputs, conversational editing rather than re-prompting, 10 seconds per generation, SynthID-watermarked.

The more durable announcement may be WebMCP: a proposed open standard that lets websites expose structured JavaScript functions to browser AI agents, with an experimental origin trial starting in Chrome 149. Booking.com, Shopify, Instacart, and Intuit have already committed to implement it. If WebMCP achieves broad adoption, a meaningful fraction of the commercial web becomes natively navigable by AI agents — no scraping, no fragile DOM parsing. Google is seeding that shift early and naming it.

The toolchain is the target

On May 18, a threat actor published a backdoored version of the Nx Console VS Code extension — 2.2 million installs, verified publisher status. It was live on the Marketplace for 11 to 18 minutes before removal. That was enough: TeamPCP extracted 3,800 GitHub internal repositories, plus credentials from OpenAI and Mistral installations. The payload swept cloud provider keys, CI/CD tokens, SSH private keys, and credentials from AI coding assistants.

The same week, 700-plus versions of Laravel-Lang PHP packages were backdoored via GitHub tag injection, with a 5,900-line credential stealer loading automatically through Composer’s autoloader. Both attacks share the same logic: the development toolchain is now a high-value target, and the attack surface for organizations relying on off-the-shelf extensions is enormous.

Policy, shelved

The White House postponed a planned AI executive order hours before the signing ceremony, after direct pushback from David Sacks, Elon Musk, and Mark Zuckerberg. The draft would have established a voluntary 90-day pre-launch review for frontier models, with classified benchmarking by NSA and CISA. Opponents wanted a 14-day window and less intelligence-community involvement. The EU moved differently: on May 7, the Council and Parliament agreed to defer high-risk AI compliance to December 2027 — a 16-month extension — while adding new prohibitions on AI-generated non-consensual intimate material.