This week handed AI agents the keys to three very different rooms — a foreign government’s network, a wet lab, and a crypto exchange — and the results argue for keeping a hand near the wheel in all three.
The starkest case surfaced out of Taiwan, where researchers at the Israeli firm Dream say suspected China-linked attackers ran what may be the first fully autonomous cyberattack on a foreign government. Over four days in early July, an operator assembled a hacking platform from open-source agent frameworks, deployed as many as eight agents at once, and let them map 21 government systems, crack 85 accounts, and pull 2,500 personnel records with minimal human steering in between. The targets included Taiwan’s nuclear safety agency and several energy companies. Nobody has formally attributed the attack, but the mechanics are the point: an adversary didn’t need elite operators, just agents patient enough to adapt when blocked.
Set that against Anthropic’s own agents running an unsupervised protein-design campaign that produced working drug-candidate binders. Claude Opus 4.8 and an experimental Mythos model designed “minibinders” for 15 biological targets; wet-lab partners Adaptyv Bio and Twist Bioscience confirmed functional proteins for 14 of them, at a 22–35% success rate against roughly 10–15% for typical human-led campaigns. Same underlying capability — plan, iterate, act without a human approving every step — pointed at drug discovery instead of a government network.
Then there’s the middle ground, where Binance decided the safest place for that capability is a sandboxed sub-account. Its new Agent OS lets ChatGPT, Claude Code, Cursor, and other tools read market data, check balances, and place real trades once a user grants permission — withdrawals blocked by default, everything else up to how much rope the user wants to give it. “Instead of total freedom, we put the power in users’ hands,” a Binance VP told TechCrunch, which is either a sensible design principle or an admission that nobody’s found a better one.
Trust is the actual bottleneck
That’s the thread running under all three stories, and it’s the one Dario Amodei named directly this week: the public backlash against AI, he argued, isn’t really about whether the models work — it’s that people assume the companies deploying them are “cooking up some new way to screw them over.” A new Pew poll backs him up: a majority of Americans are more concerned than excited about AI, and most have little confidence anyone — governments included — can regulate it well. OpenAI spent the week making its own trust pitch, previewing Private Safety Processing, a system that flags misuse patterns across conversations without exposing the actual prompts even to its own staff.
Meanwhile the people nominally in charge of building all this kept reshuffling. Koray Kavukcuoglu now runs Google DeepMind’s day-to-day, reporting straight to Sundar Pichai, while Demis Hassabis moves up to chair the unit and chief scientist at Alphabet — the latest move in a reorg that started with stalled models and a talent exodus. It’s a very human kind of shakeup, arriving in the same week the more interesting question stopped being who runs the lab and started being what the lab’s agents do once nobody’s watching them directly.