> daily_signal(2026_06_05)
Trump signed an AI executive order giving the government a 30-day look at new frontier models before the public. Bernie Sanders says the public should own half of OpenAI, Anthropic, and xAI.
PickBits Daily Signal · Friday, June 5, 2026
// tl;dr
- Trump signed a narrower AI executive order on June 2, asking companies to voluntarily give the government access to new frontier models for up to 30 days before public release. An earlier draft set a 90-day window; it was cut to 30 after industry pushback, and the order explicitly creates no mandatory licensing or permitting. Treasury, the NSA, and CISA will write the benchmarks that define a "covered" model.
- Senator Bernie Sanders used a June 1 op-ed to propose an American A.I. Sovereign Wealth Fund Act: a one-time 50% tax on the largest AI companies, paid in company stock rather than cash. The government would hold voting shares and board seats in OpenAI, Anthropic, and xAI and route dividends to the public. He has not introduced the bill yet.
- Anthropic expanded Project Glasswing, giving its Claude Mythos vulnerability-hunting model to about 150 more organizations across more than 15 countries, now including power, water, healthcare, communications, and hardware. Partners scanning their own code with Mythos have already found more than 10,000 high- or critical-severity security flaws. Anthropic says rival "Mythos-class" models are 6 to 12 months out.
- An attacker backdoored 32 Red Hat npm packages, pushing 96 malicious versions in a roughly 72-second window through a compromised build pipeline. The packages pull around 117,000 downloads a week; responders say anyone who installed one should assume cloud credentials, SSH keys, and build secrets are stolen. Red Hat has published clean versions.
Washington moved on the AI labs from two opposite directions this week. On June 2, President Trump signed an executive order asking the companies to voluntarily show the government their most powerful new models before anyone else can use them. The day before, Senator Bernie Sanders argued the public should simply own half of those companies outright. One approach is a light-touch look from the outside; the other is a seat at the table inside. Both are answers to the same question — how a government holds an industry this consequential to account.
Out in the field, AI security got the parallel demonstration. Anthropic put a model that is unusually good at finding software flaws into the hands of about 150 more organizations that run power, water, and hospitals, so they can hunt the holes in their own systems before someone else does. And an attacker did the someone-else version: they slipped malware into three dozen widely used Red Hat code packages in just over a minute, turning the same kind of code fluency against the supply chain that software, including the software running those grids, is built on. The thread across all four is leverage over AI and over the systems it now touches, and who is allowed to hold it.
The same week Washington asked the AI labs to show the government their models and floated owning the labs outright, Anthropic aimed a vulnerability-hunting AI at the power and water grid, and an attacker aimed the same kind of tool at the code beneath it.
1. Trump signed an AI executive order asking labs to hand the government a 30-day look at new models before the public sees them.
The on-again, off-again federal AI order finally got signed on June 2 — in private, and narrower than the draft that leaked in May.
On June 2, President Trump signed an executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security." Its central ask is that AI developers, on a voluntary basis, give the federal government access to new frontier models for up to 30 days before they release them to other trusted partners, so the government can test them for national-security and cyber risks. He signed it quietly, weeks after a planned public ceremony with prominent tech executives was scrapped. The order does not name a single new regulator; instead it tasks an interagency group, led in practice by the Treasury, the NSA, and CISA, with writing the technical benchmarks that decide which models count as "covered."
Two things define how much teeth this has. First, the review window started life at 90 days in a May draft and was cut to 30 in the final order after the industry objected that a longer hold would slow releases. Second, the order goes out of its way to say it is not a permission slip: in its own words, "Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models." In plain terms, the government is asking for an early look, not the power to say no. Whether labs actually opt in, and which models the benchmarks end up covering, is the part that turns this from a statement of intent into a real process.
cnbc.com: Trump signs AI executive order asking companies to give government early access to models (June 2, 2026)
whitehouse.gov: Promoting Advanced Artificial Intelligence Innovation and Security (official order text, June 2, 2026)
rollcall.com: Executive order sets voluntary cyber reviews for advanced AI (June 2, 2026)
2. Bernie Sanders says the public should own half of OpenAI, Anthropic, and xAI.
A proposal, not yet a bill, but a clear marker for where one pole of the AI-ownership debate now sits.
On June 1, Senator Bernie Sanders published an op-ed arguing that because AI is "built on the collective knowledge of humanity," the public should share in the wealth it generates. His mechanism is a bill he says he will introduce in the coming weeks, the American A.I. Sovereign Wealth Fund Act. It would impose a one-time 50% tax on the largest AI companies, but paid in something other than cash: the companies would hand over stock equal to half their value, which would go into a public sovereign wealth fund. Sanders names OpenAI, Anthropic, and xAI as the kind of company in scope.
The fund would not be a passive shareholder. Sanders writes that the federal government would have the power, "through its voting shares and an equal representation on each company's board, to block decisions that hurt our citizens." Dividends from the stake would initially pay out as a direct dividend to the public and later fund things like health care, education, and housing. It is worth being precise about the status: this is an op-ed previewing a bill, not a bill that has been introduced or voted on, and it is 50% of equity, not of profits. But set next to the executive order from the day before, it draws the outer edge of the debate. One Washington answer to the AI labs this week was a polite request to see the models early; the other was a claim that the public already owns half of what built them.
sanders.senate.gov: The public should own half of the big A.I. companies (op-ed, June 1, 2026)
foxbusiness.com: Sanders unveils plan to take 50% stake in AI companies for a government wealth fund (June 1, 2026)
commondreams.org: Sanders proposes AI sovereign wealth fund
PickBits Daily Signal is free. If this lands in your inbox every day and it is worth something to you, the best way to support it is to share it with someone who would read it. Subscribe at pickbitsai.substack.com.
3. Anthropic put its vulnerability-hunting AI into the hands of the people who run power, water, and hospitals in 15-plus countries.
The constructive case of the week, with the warning built right into it.
On June 2, Anthropic expanded a program it calls Project Glasswing, giving about 150 more organizations across more than 15 countries access to Claude Mythos, an unreleased model whose coding ability makes it unusually good at finding software vulnerabilities. The point of the program is defensive: an organization runs Mythos against its own code to find the security holes before an attacker does. The newly added members are in sectors that were thin in the first cohort, specifically power, water, healthcare, communications, and hardware, which are exactly the systems whose failure is felt directly by ordinary people rather than by a company's shareholders.
The early results are real and large: partners scanning their own codebases with Mythos have "so far found more than 10,000 high- or critical-severity security flaws." Anthropic paired the number with a blunt warning — it expects that "within 6 to 12 months, many other AI companies will have Mythos-class models," and that "cheap, fast AI models with powerful cyber capabilities are around the corner." The same capability that lets a hospital network find its own weak points will soon be cheap enough for whoever wants to find someone else's. This edition has the proof of that on both sides, because the very next story is what happens when the attacker gets there first.
techcrunch.com: Anthropic scales Claude Mythos to critical infrastructure in 15 countries (June 2, 2026)
anthropic.com: Expanding Project Glasswing (official, June 2, 2026)
cnbc.com: Anthropic expands Mythos AI to critical infrastructure partners (June 2, 2026)
4. An attacker poisoned 32 Red Hat code packages in 72 seconds, and anyone who installed one should assume their secrets are gone.
The dark twin of story three: the same code fluency, turned against the supply chain.
Around June 1, an attacker published malicious versions of 32 Red Hat npm packages, in the widely used @redhat-cloud-services namespace, pushing 96 backdoored versions in a roughly 72-second window. Every poisoned version carried obfuscated "preinstall" malware that runs automatically the moment a developer installs the package, before any of the code is even used. Researchers named the campaign Miasma and describe it as a self-propagating worm: the malware steals developer credentials and then uses them to publish more poisoned packages. The affected packages are not obscure. They pull roughly 117,000 downloads a week.
What makes this one nasty is how it got in and how legitimate it looked. The bad versions were not slipped onto a developer's laptop; they were published through a compromised build pipeline, and they carried valid cryptographic provenance attestations, the digital paperwork meant to prove a package is genuine. To an automated check, the malware looked official. Red Hat removed the compromised versions and published clean ones, and its own advisory says that based on current findings "no actions from customers are required." Outside responders are far less reassuring. As security firm Wiz put it, "organizations should assume potential exposure of GitHub tokens, SSH keys, cloud credentials, and CI/CD secrets, and rotate them accordingly." When the vendor and the people who reverse-engineered the malware disagree about whether you need to do anything, the safe move is to side with the people who took the malware apart.
cybersecuritydive.com: Dozens of Red Hat npm packages hit in supply-chain attack (June 1, 2026)
access.redhat.com: RHSB-2026-006 security advisory (June 1, 2026)
wiz.io: Miasma supply-chain attack targeting Red Hat npm packages
» What to watch this week
- Whether any AI lab actually opts into the executive order's voluntary 30-day review, and which models get labeled "covered." The order is only as real as its first participant. Watch for the Treasury/NSA/CISA benchmarks that define a "covered frontier model" and for the first lab to publicly enter, or decline, the review window.
- Whether Sanders introduces the American A.I. Sovereign Wealth Fund Act and whether anyone co-sponsors it. Right now it is an op-ed. A filed bill with even one other name on it is the line between a position statement and a live proposal.
- Whether a second AI company ships a "Mythos-class" vulnerability-finding model. Anthropic put the timeline at 6 to 12 months. The first competitor to match it is the signal that AI-grade vulnerability discovery has gone from one lab's program to a commodity both defenders and attackers can buy.
- Whether more supply-chain worms use stolen build-pipeline access plus valid provenance. The Miasma attack worked because it owned the assembly line and looked legitimate to automated checks. Watch for copycats hitting npm, PyPI, or other registries the same way, and for registries to respond on how provenance is verified.
Tomorrow's signal lands here.