Valliance Logo in White
Valliance Logo in White

ISSUE NO.

ISSUE.

02

·

ISSUE NO.

02

·

The Week in AI

Our weekly read on the AI stories that matter to the people building the future enterprise.

ISSUE NO.

ISSUE.

02

·

ISSUE NO.

02

·

The Week in AI

Our weekly read on the AI stories that matter to the people building the future enterprise.

OpenAI's newest model, Astra, changes the architecture underneath the capability. Earlier models wrote their reasoning out as a working step, which meant their plans were visible in system logs. Astra uses a technique OpenAI calls opaque recurrence, reasoning internally without that step, so the record of why it did something no longer exists as a by-product of the work. OpenAI's own chief scientist concedes that 'as model capabilities are increasing, monitorability is getting more challenging'.

Spotted on

TechCrunch

Why it matters for you

If your AI system cannot show its reasoning, you cannot base assurance on reading it. Asking the model why it did something and trusting the answer isn’t governance. The control point moves out to the boundary, and the better the model gets, the more important the containment architecture becomes. Do most enterprises need Astra yet? In short, no. They need a small number of controlled agents doing bounded jobs, deterministic logic around them, and clean access to internal data. There is still a decade of operational debt between today's enterprise and the point where frontier model capability becomes the limiting factor.

Six national cybersecurity agencies across five nations that form the Five Eyes intelligence alliance have published guidance for governing AI agents in the enterprise. It names five risk domains, privilege, design and configuration, behaviour, structural and accountability, catalogues 23 risks over 100 associated best practices, and tells organisations to manage them inside their existing cyber security programme rather than as a separate AI discipline.

Why it matters for you

Least-privilege access, short-lived credentials and human approval on high-impact actions. Your security team has been arguing for all three. They now carry the backing of six national security agencies. Brussels pushed Annex III high-risk obligations from August 2026 to December 2027, so for the next fifteen months  the standard your agents will actually be judged against is this document and whatever your customers write into contracts. Note what the agencies will not claim: prompt injection is the most persistent and difficult-to-fix threat they identify, and no single control is sufficient against it.

Mutli-player AI, the new buzzword of the week. Nearly all AI adoption today is one person working with one assistant in one private session. A podcast argument that resonated hard with us this week names the next opportunity multiplayer AI, agents that serve a team rather than an individual, visible to everyone, steerable by anyone with standing to steer.

Why it matters for you

Today's agents, as we’ve all experienced, seem wired to please one person. An agent, or multi-player AI sitting inside a team's shared context behaves differently. It knows the team's goals, who owns what and how decisions get made, so its output serves the plan rather than whoever happened to type the request. Everyone sees the same work, so effort stops being duplicated in private sessions and knowledge stops dying in one person's chat history.The useful future looks like co-presence, humans watching, steering and correcting an AI worker together. The gains will go to the organisations who redesign how their teams work around shared agents.

Mistral has raised €3bn. The interesting part is what the money is backing. Mistral has left the frontier race to others. Its product is control, open-weight models, European jurisdiction and transparent deployment. Capital from all over the world, from Asia, America and Europe, just priced that story at €21bn.

Spotted on

Mistral

Why it matters for you

Sovereignty has levels, and each one costs more than the last. Choosing a European provider, using a hosted model that retains none of your data, and running everything on your own hardware are three different commitments at three very different prices. What the raise really means for an enterprise is that the doubt about whether a European provider will still be here in three years just got smaller. Mistral belongs on the shortlist for any workload where jurisdiction, residency or control is a requirement. Its general models are not at the same level as those of other frontier providers, though its specialist models are. For the level of sovereignty most clients need, it is a credible option today.

ISSUE NO.

01

_More of our latest thinking
_More of our latest thinking
_More of our latest thinking
_More of our latest thinking

ISSUE NO.

ISSUE.

02

·

ISSUE NO.

02

·

The Week in AI

Our weekly read on the AI stories that matter to the people building the future enterprise.

ISSUE NO.

ISSUE.

02

·

ISSUE NO.

02

·

The Week in AI

Our weekly read on the AI stories that matter to the people building the future enterprise.

OpenAI's newest model, Astra, changes the architecture underneath the capability. Earlier models wrote their reasoning out as a working step, which meant their plans were visible in system logs. Astra uses a technique OpenAI calls opaque recurrence, reasoning internally without that step, so the record of why it did something no longer exists as a by-product of the work. OpenAI's own chief scientist concedes that 'as model capabilities are increasing, monitorability is getting more challenging'.

Spotted on

TechCrunch

Why it matters for you

If your AI system cannot show its reasoning, you cannot base assurance on reading it. Asking the model why it did something and trusting the answer isn’t governance. The control point moves out to the boundary, and the better the model gets, the more important the containment architecture becomes. Do most enterprises need Astra yet? In short, no. They need a small number of controlled agents doing bounded jobs, deterministic logic around them, and clean access to internal data. There is still a decade of operational debt between today's enterprise and the point where frontier model capability becomes the limiting factor.

Six national cybersecurity agencies across five nations that form the Five Eyes intelligence alliance have published guidance for governing AI agents in the enterprise. It names five risk domains, privilege, design and configuration, behaviour, structural and accountability, catalogues 23 risks over 100 associated best practices, and tells organisations to manage them inside their existing cyber security programme rather than as a separate AI discipline.

Why it matters for you

Least-privilege access, short-lived credentials and human approval on high-impact actions. Your security team has been arguing for all three. They now carry the backing of six national security agencies. Brussels pushed Annex III high-risk obligations from August 2026 to December 2027, so for the next fifteen months  the standard your agents will actually be judged against is this document and whatever your customers write into contracts. Note what the agencies will not claim: prompt injection is the most persistent and difficult-to-fix threat they identify, and no single control is sufficient against it.

Mutli-player AI, the new buzzword of the week. Nearly all AI adoption today is one person working with one assistant in one private session. A podcast argument that resonated hard with us this week names the next opportunity multiplayer AI, agents that serve a team rather than an individual, visible to everyone, steerable by anyone with standing to steer.

Why it matters for you

Today's agents, as we’ve all experienced, seem wired to please one person. An agent, or multi-player AI sitting inside a team's shared context behaves differently. It knows the team's goals, who owns what and how decisions get made, so its output serves the plan rather than whoever happened to type the request. Everyone sees the same work, so effort stops being duplicated in private sessions and knowledge stops dying in one person's chat history.The useful future looks like co-presence, humans watching, steering and correcting an AI worker together. The gains will go to the organisations who redesign how their teams work around shared agents.

Mistral has raised €3bn. The interesting part is what the money is backing. Mistral has left the frontier race to others. Its product is control, open-weight models, European jurisdiction and transparent deployment. Capital from all over the world, from Asia, America and Europe, just priced that story at €21bn.

Spotted on

Mistral

Why it matters for you

Sovereignty has levels, and each one costs more than the last. Choosing a European provider, using a hosted model that retains none of your data, and running everything on your own hardware are three different commitments at three very different prices. What the raise really means for an enterprise is that the doubt about whether a European provider will still be here in three years just got smaller. Mistral belongs on the shortlist for any workload where jurisdiction, residency or control is a requirement. Its general models are not at the same level as those of other frontier providers, though its specialist models are. For the level of sovereignty most clients need, it is a credible option today.

ISSUE NO.

01

_More of our latest thinking
_More of our latest thinking
_More of our latest thinking
_More of our latest thinking