> daily_signal(2026_06_05)

Trump signed an AI executive order giving the government a 30-day look at new frontier models before the public. Bernie Sanders says the public should own half of OpenAI, Anthropic, and xAI.

PickBits Daily Signal · Friday, June 5, 2026

By Mark Pickering · 11 min read · June 5, 2026

// tl;dr

Washington moved on the AI labs from two opposite directions this week. On June 2, President Trump signed an executive order asking the companies to voluntarily show the government their most powerful new models before anyone else can use them. The day before, Senator Bernie Sanders argued the public should simply own half of those companies outright. One approach is a light-touch look from the outside; the other is a seat at the table inside. Both are answers to the same question — how a government holds an industry this consequential to account.

Out in the field, AI security got the parallel demonstration. Anthropic put a model that is unusually good at finding software flaws into the hands of about 150 more organizations that run power, water, and hospitals, so they can hunt the holes in their own systems before someone else does. And an attacker did the someone-else version: they slipped malware into three dozen widely used Red Hat code packages in just over a minute, turning the same kind of code fluency against the supply chain that software, including the software running those grids, is built on. The thread across all four is leverage over AI and over the systems it now touches, and who is allowed to hold it.

The same week Washington asked the AI labs to show the government their models and floated owning the labs outright, Anthropic aimed a vulnerability-hunting AI at the power and water grid, and an attacker aimed the same kind of tool at the code beneath it.

1. Trump signed an AI executive order asking labs to hand the government a 30-day look at new models before the public sees them.

The on-again, off-again federal AI order finally got signed on June 2 — in private, and narrower than the draft that leaked in May.

On June 2, President Trump signed an executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security." Its central ask is that AI developers, on a voluntary basis, give the federal government access to new frontier models for up to 30 days before they release them to other trusted partners, so the government can test them for national-security and cyber risks. He signed it quietly, weeks after a planned public ceremony with prominent tech executives was scrapped. The order does not name a single new regulator; instead it tasks an interagency group, led in practice by the Treasury, the NSA, and CISA, with writing the technical benchmarks that decide which models count as "covered."

Two things define how much teeth this has. First, the review window started life at 90 days in a May draft and was cut to 30 in the final order after the industry objected that a longer hold would slow releases. Second, the order goes out of its way to say it is not a permission slip: in its own words, "Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models." In plain terms, the government is asking for an early look, not the power to say no. Whether labs actually opt in, and which models the benchmarks end up covering, is the part that turns this from a statement of intent into a real process.

CNBC report June 2 2026 Trump signs AI executive order voluntary 30-day government early access to frontier models cut from 90 days no mandatory licensing Treasury NSA CISA
cnbc.com · June 2, 2026
Why this matters: If you use AI tools, the government just set up a channel to look at the most powerful new models for up to a month before you ever touch them, and it did it without giving itself the power to block a release. That sounds like oversight, and it is the start of one, but the word doing the work is "voluntary": a model only gets reviewed if its maker chooses to hand it over. The order also quietly sorts the AI world into "covered" and "not covered" models, and the people writing that line are at Treasury, the NSA, and CISA, not at a consumer-facing agency. Action this week: Read the order itself at whitehouse.gov ("Promoting Advanced Artificial Intelligence Innovation and Security") so you are working from the text, not a headline. If you plan AI rollouts at work, watch for which models get labeled "covered frontier models" once the benchmarks publish, and add the gap between a model's public release date and its government-review date to your risk notes before you commit to a multi-year deal on a model that has not gone through the window.

cnbc.com: Trump signs AI executive order asking companies to give government early access to models (June 2, 2026)
whitehouse.gov: Promoting Advanced Artificial Intelligence Innovation and Security (official order text, June 2, 2026)
rollcall.com: Executive order sets voluntary cyber reviews for advanced AI (June 2, 2026)

2. Bernie Sanders says the public should own half of OpenAI, Anthropic, and xAI.

A proposal, not yet a bill, but a clear marker for where one pole of the AI-ownership debate now sits.

On June 1, Senator Bernie Sanders published an op-ed arguing that because AI is "built on the collective knowledge of humanity," the public should share in the wealth it generates. His mechanism is a bill he says he will introduce in the coming weeks, the American A.I. Sovereign Wealth Fund Act. It would impose a one-time 50% tax on the largest AI companies, but paid in something other than cash: the companies would hand over stock equal to half their value, which would go into a public sovereign wealth fund. Sanders names OpenAI, Anthropic, and xAI as the kind of company in scope.

The fund would not be a passive shareholder. Sanders writes that the federal government would have the power, "through its voting shares and an equal representation on each company's board, to block decisions that hurt our citizens." Dividends from the stake would initially pay out as a direct dividend to the public and later fund things like health care, education, and housing. It is worth being precise about the status: this is an op-ed previewing a bill, not a bill that has been introduced or voted on, and it is 50% of equity, not of profits. But set next to the executive order from the day before, it draws the outer edge of the debate. One Washington answer to the AI labs this week was a polite request to see the models early; the other was a claim that the public already owns half of what built them.

Bernie Sanders op-ed June 1 2026 the public should own half of the big AI companies American AI Sovereign Wealth Fund Act one-time 50 percent tax paid in stock OpenAI Anthropic xAI
sanders.senate.gov · June 1, 2026
Why this matters: If you have ever typed a question into ChatGPT or Claude, Sanders' argument is that you and everyone like you are part of what trained these systems, and so the public should hold a stake in the companies built on that. You do not have to agree with the plan to see why it matters: it is the most concrete version yet of "the people who generated the data should share the upside," and it puts a hard number, 50%, on a debate that has mostly been about vibes. It is also a useful reality check on the executive order. The same week the government asked the labs nicely for an early look, a sitting senator argued the government should simply own them. Action this week: Read Sanders' op-ed ("The public should own half of the big A.I. companies") at sanders.senate.gov so you can argue the actual proposal rather than the meme version of it. If you follow tech policy for work, file this as a position marker, not law, and watch for whether the bill is actually introduced and whether any other senator co-sponsors it, which is what would tell you it is more than a press cycle.

sanders.senate.gov: The public should own half of the big A.I. companies (op-ed, June 1, 2026)
foxbusiness.com: Sanders unveils plan to take 50% stake in AI companies for a government wealth fund (June 1, 2026)
commondreams.org: Sanders proposes AI sovereign wealth fund

PickBits Daily Signal is free. If this lands in your inbox every day and it is worth something to you, the best way to support it is to share it with someone who would read it. Subscribe at pickbitsai.substack.com.

3. Anthropic put its vulnerability-hunting AI into the hands of the people who run power, water, and hospitals in 15-plus countries.

The constructive case of the week, with the warning built right into it.

On June 2, Anthropic expanded a program it calls Project Glasswing, giving about 150 more organizations across more than 15 countries access to Claude Mythos, an unreleased model whose coding ability makes it unusually good at finding software vulnerabilities. The point of the program is defensive: an organization runs Mythos against its own code to find the security holes before an attacker does. The newly added members are in sectors that were thin in the first cohort, specifically power, water, healthcare, communications, and hardware, which are exactly the systems whose failure is felt directly by ordinary people rather than by a company's shareholders.

The early results are real and large: partners scanning their own codebases with Mythos have "so far found more than 10,000 high- or critical-severity security flaws." Anthropic paired the number with a blunt warning — it expects that "within 6 to 12 months, many other AI companies will have Mythos-class models," and that "cheap, fast AI models with powerful cyber capabilities are around the corner." The same capability that lets a hospital network find its own weak points will soon be cheap enough for whoever wants to find someone else's. This edition has the proof of that on both sides, because the very next story is what happens when the attacker gets there first.

TechCrunch report June 2 2026 Anthropic scales Claude Mythos to critical infrastructure in 15 countries Project Glasswing power water healthcare 10000 high critical security flaws found
techcrunch.com · June 2, 2026
Why this matters: If you get electricity, drink tap water, or have ever been treated at a hospital, the software running those systems is now being scanned by an AI built to find the holes attackers would use, and this week that defensive tool reached a lot more of the organizations that run them. That is genuinely good news, and it is the rare AI story where the win lands on the side of the people who use the system rather than the people who sell it. The catch is Anthropic's own warning: the same capability is months away from being cheap and everywhere, which means the attackers get it too. Action this week: For most people the takeaway is to keep your own basics current, because the defenders are racing the clock now: turn on automatic security updates on your phone and computer so the patches these scans produce actually reach you. If you run security or IT, read Anthropic's "Expanding Project Glasswing" post and its defenders' guidance, and treat the 6-to-12-month "Mythos-class models everywhere" timeline as your planning horizon for assuming attackers have AI-grade vulnerability discovery, not a someday.

techcrunch.com: Anthropic scales Claude Mythos to critical infrastructure in 15 countries (June 2, 2026)
anthropic.com: Expanding Project Glasswing (official, June 2, 2026)
cnbc.com: Anthropic expands Mythos AI to critical infrastructure partners (June 2, 2026)

4. An attacker poisoned 32 Red Hat code packages in 72 seconds, and anyone who installed one should assume their secrets are gone.

The dark twin of story three: the same code fluency, turned against the supply chain.

Around June 1, an attacker published malicious versions of 32 Red Hat npm packages, in the widely used @redhat-cloud-services namespace, pushing 96 backdoored versions in a roughly 72-second window. Every poisoned version carried obfuscated "preinstall" malware that runs automatically the moment a developer installs the package, before any of the code is even used. Researchers named the campaign Miasma and describe it as a self-propagating worm: the malware steals developer credentials and then uses them to publish more poisoned packages. The affected packages are not obscure. They pull roughly 117,000 downloads a week.

What makes this one nasty is how it got in and how legitimate it looked. The bad versions were not slipped onto a developer's laptop; they were published through a compromised build pipeline, and they carried valid cryptographic provenance attestations, the digital paperwork meant to prove a package is genuine. To an automated check, the malware looked official. Red Hat removed the compromised versions and published clean ones, and its own advisory says that based on current findings "no actions from customers are required." Outside responders are far less reassuring. As security firm Wiz put it, "organizations should assume potential exposure of GitHub tokens, SSH keys, cloud credentials, and CI/CD secrets, and rotate them accordingly." When the vendor and the people who reverse-engineered the malware disagree about whether you need to do anything, the safe move is to side with the people who took the malware apart.

Cybersecurity Dive report June 1 2026 dozens of Red Hat npm packages compromised in supply-chain attack 32 packages 96 versions 72 seconds Miasma worm preinstall malware rotate credentials
cybersecuritydive.com · June 1, 2026
Why this matters: If you or anyone on your team installs open-source code, and almost every app, website, and internal tool is built on it, then this week a package that looked completely official was actually malware that grabbed credentials the instant it landed. You do not have to be a developer to feel this: the secrets these worms steal are the keys to the cloud accounts and systems that hold other people's data, including yours. The unsettling part is that the usual "is this package legit?" checks passed, because the attacker had the keys to the assembly line, not just a fake label. Action this week: If you or your team installed anything from the @redhat-cloud-services npm scope on or after about June 1, treat that machine and build environment as compromised and rotate your cloud credentials, SSH keys, npm tokens, and API keys today, then update to Red Hat's clean package versions. As a standing habit, pin your dependencies to known-good versions and turn off automatic install scripts where you can, so a 72-second poisoning window cannot reach your laptop before anyone notices.

cybersecuritydive.com: Dozens of Red Hat npm packages hit in supply-chain attack (June 1, 2026)
access.redhat.com: RHSB-2026-006 security advisory (June 1, 2026)
wiz.io: Miasma supply-chain attack targeting Red Hat npm packages

» What to watch this week

Tomorrow's signal lands here.