Four unrelated stories this week, one thread: what happens when nobody’s left to check the machine’s decision.

Start with the malware. Cisco Talos published research on CLOSEDQUORUM, a Windows implant Talos calls the first documented case of malware outsourcing its own command-and-control to AI. Instead of phoning home to an attacker’s server, the implant polls up to four commercial models — DeepSeek, Qwen, Mistral, and Gemini — and lets them vote on its next move: harvest a credential, hunt a crypto wallet, move laterally. Talos hasn’t seen it deployed in the wild, and there’s no evidence a four-model committee out-thinks a human operator. But it doesn’t need to out-think anyone. It just needs to run without one, and that’s the detail worth sitting with.

Then the story with actual stakes. Pentagon investigators concluded that a February missile strike on a school in Minab, Iran, which killed more than 120 children, was shaped in part by “overreliance” on Palantir’s Maven Smart System, the military’s AI targeting-assistance platform. But the sharper failure, by the investigators’ own account, wasn’t the algorithm — it was who was left to catch its mistakes. Civilian-harm review staffing at U.S. Central Command had fallen by roughly 90 percent, down to a single person, and nobody on that team reviewed the target before the missiles launched. An AI tool didn’t fire the weapon. It filled a gap that used to be a person’s job, and the person was never replaced.

Against that backdrop, the industry’s response this week reads almost modest: build better harnesses. JetBrains Air, unveiled Tuesday, bets that the next phase of software development isn’t a smarter autocomplete but the coordination layer around a fleet of agents — Claude, Codex, Gemini CLI, JetBrains’ own Junie — with enough governance, auditability, and cost tracking that a team can trust what actually shipped. CEO Kirill Skrygan called it the most significant step in the company’s 26-year history, a big claim that mostly amounts to admitting agentic work needs adult supervision built into the tooling, not bolted on afterward.

The model race, meanwhile, didn’t pause to reflect on any of this. Xiaomi open-sourced MiMo V2.6, a trillion-parameter, natively omnimodal model that now tops Artificial Analysis’s open-weights leaderboard — reportedly trained for around $3.5 million, a rounding error next to what a comparable Western lab spends. MIT-licensed, million-token context, ungated on Hugging Face. It’s a genuinely impressive efficiency result, and also a reminder that the loop keeps getting more capable regardless of who’s minding it.

These four stories don’t share an event. Put side by side, though, they describe the same year: autonomy is shipping faster than the infrastructure built to supervise it — in code, in the field, and in the review process meant to catch both.

Elsewhere, Alibaba teased a four-tier Qwen 4 lineup with no benchmarks attached yet, a crowdsourced math effort combining amateurs, professionals, and AI search finally closed out a 25,000-case Galois symmetry problem, and Salesforce leaned further into “AI replaces the UI” with AIforce. Full rundown below — along with a robot that broke a world sprint record and immediately ran into a wall.