The AI Brief

Vol. I · No. 39 · Friday, July 3, 2026

Today's brief:

  • Open-source AI cloud gains institutional validation as Together AI closes $800M at an $8.3B valuation.
  • Seventy thousand JetBrains plugin installs later, a coordinated AI credential-theft campaign surfaces the IDE supply chain as a new attack surface.
  • GPT-5.6 Sol's biology scores raise biosecurity flags even as the model sits behind a government-gated release wall.
  • A $3B Menlo Ventures raise illustrates how one frontier-lab bet is rewiring an entire venture firm's identity.
  • Anthropic ships spend alerts and model-level entitlements for Enterprise, giving admins the first native cost-governance layer for agentic workloads.

Open-source AI cloud reaches institutional scale with Together AI's $800M raise

Why it matters
The neocloud category, once a scrappy alternative to hyperscaler APIs, now commands institutional capital at growth-equity scale, confirming that open-weight model inference is a distinct and durable infrastructure tier.
What's at stake
For enterprises running production AI on closed-model APIs, the tradeoff has sharpened: proprietary convenience versus the six-to-sixtyfold cost reduction that open-weight infrastructure is now demonstrably delivering.
Decode
Neocloud = a cloud provider that specialises in AI compute, typically renting GPU clusters and running optimised inference software for open-source models, sitting between a hyperscaler (AWS, Azure, GCP) and a bare-metal colocation provider. Inference = running a trained model to generate outputs, as distinct from training; it is the dominant ongoing cost for production AI deployments.
Detail

Together AI, an AI neocloud that rents out Nvidia GPU clusters and other AI-specific infrastructure, raised $800 million in a Series C at an $8.3 billion valuation, announced July 1, 2026. The round was led by Aramco Ventures, with participation from Vista Equity Partners, General Catalyst, Emergence Capital, Nvidia, March Capital, Pegatron, and SentinelOne's S Ventures.

The company also disclosed that annual bookings surpassed $1.15 billion in Q2 2026. Using open-source models including DeepSeek, MiniMax, and Kimi, Together AI's platform gives businesses a way to train and deploy AI workloads for less than they would pay for closed systems from providers like OpenAI and Anthropic. Together AI says its customers have reduced inference costs by six to sixty times relative to closed-model pricing; Decagon, one of those customers, cut its inference spending sixfold after moving to Together AI's platform.

Together AI last raised a $305 million Series B at a $3.3 billion valuation about 16 months ago. The company has also secured 500 megawatts of independently capitalised compute capacity to fuel future scaling. Enterprise demand for open-source model hosting is surging as companies seek cheaper alternatives to closed frontier model APIs; Together AI reports that open-source model usage has tripled industry-wide in the past year. The raise arrives alongside Groq's $650M and RunPod's $100M closes in June, signalling that the neocloud tier is undergoing its own consolidation wave before hyperscalers react with matching price cuts.


~70,000
JetBrains IDE installs of malicious AI coding plugins that silently exfiltrated developer API keys

AI plugin marketplaces are the newest credential-theft surface for developer supply chains

Why it matters
The IDE plugin ecosystem has become a high-value target: developers willingly paste long-lived AI provider keys into plugin settings as part of normal setup, handing attackers credentials without any exploit required.
What's at stake
For any team using JetBrains IDEs with third-party AI assistant plugins, every OpenAI, DeepSeek, or SiliconFlow key entered into an unaudited plugin before June 17 should be treated as compromised and rotated immediately.
Detail

Aikido Security detected a coordinated malware campaign on the JetBrains Marketplace involving at least 15 IDE plugins published under seven vendor accounts, sharing the same hidden behaviour and collectively installed close to 70,000 times. Each one posed as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests. They functioned exactly as advertised. However, the AI provider API key entered into settings was exfiltrated to a server controlled by the attacker.

According to the report, the malicious plugins were first published in October 2025, with new plugins continuing to be published as recently as June 10, 2026. Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users; the firm theorises the operators were harvesting credentials from free users and redistributing them to paying ones. As of June 17, JetBrains removed all 15 plugins, permanently banned the seven publisher accounts, and hardened its vetting pipelines to trigger automated code reviews for plugin inputs resembling sensitive API keys.

Developers install IDE extensions with broad local privileges, rarely audit their code, and assume marketplace presence implies vetting. AI coding assistants make the target richer still: the whole point of the plugin is to handle high-value API credentials, so the malware does not need to go hunting. The user hands the secret over as part of normal setup. The same supply-chain logic has driven npm, PyPI, and VS Code extension campaigns; IDE AI tooling is the latest concentration point.


GPT-5.6 Sol posts a 9-point biology jump, while sitting behind a government gate

Why it matters
Each frontier model generation is visibly compressing the biosecurity capability gap, and GPT-5.6's restricted release confirms that the government pre-screening framework created by the June 2 executive order is already shaping how labs deploy dual-use models.
What's at stake
For biosecurity researchers and regulated life-sciences operators, the tradeoff is between model access (GPT-5.6 is restricted to roughly 20 government-approved partners) and working with GPT-5.5, which now sits 9 points lower on pathogen-related benchmarks.
Decode
SecureBio evaluations = a suite of biosecurity capability benchmarks including the Virology Capabilities Test and World-Class Bio, designed to measure how much uplift a model provides to users attempting dangerous biological research. Higher scores indicate greater model capability and, potentially, greater dual-use risk. Government pre-release review framework = the voluntary 30-day pre-release government-access window created by Trump's June 2 executive order; labs submit frontier models for classified NSA benchmarking before broad release.
Detail

On SecureBio evaluations, GPT-5.6 Sol reached top reported scores including 53.5% on the Virology Capabilities Test, 60.0% on Molecular Biology, 68.4% on Human Pathogen Capabilities, and 68.3% on World-Class Bio, about 9 percentage points above GPT-5.5. OpenAI disclosed these figures in its GPT-5.6 Sol preview documentation published alongside the model's limited launch.

GPT-5.6 Sol is OpenAI's most capable model yet for cybersecurity, shifting the performance-efficiency frontier for long-horizon security tasks including vulnerability research and exploitation. OpenAI developed GPT-5.6 Sol, Terra, and Luna with its most robust safeguards to date, with configurations matched to each model's capabilities, and designed safeguards to hold up to real-world adversarial pressure while preserving access to legitimate security work.

As of July 3, GPT-5.6 Sol, Terra, and Luna remain limited to approximately 20 government-approved partners. If the forthcoming White House voluntary standards framework formally validates OpenAI's pre-release government coordination for GPT-5.6, it creates the precedent for both OpenAI and Anthropic to release future frontier models under the framework rather than face the risk of emergency export controls. The Fable 5 episode, which ended July 1 after 20 days offline, makes that precedent commercially material for any lab whose next frontier model touches dual-use thresholds.

OpenAI: Previewing GPT-5.6 Sol (primary)/ Build Fast with AI: GPT-5.6 context and access status/ CaveatSecureBio benchmark scores are self-reported by OpenAI; independent third-party replication has not been confirmed at publication.

Menlo Ventures turns a $1B Anthropic bet into a $3B fundraising mandate

Why it matters
A single concentrated position in one frontier lab has converted a mid-sized venture firm into a $3 billion force, illustrating how AI valuations are restructuring LP capital allocation across the entire venture ecosystem.
What's at stake
For growth-stage AI companies, the Menlo raise adds another well-capitalised late-stage investor competing for the large checks that crossover funds have historically owned, tightening the market for $50M–$200M Series B and C rounds.
Detail

Menlo Ventures announced $3 billion in funds, the largest raise in its 50-year history, driven in large part by its AI portfolio, especially Anthropic. Its stake in the model maker is now worth about $14 billion, sources told Bloomberg. The capital is split between Menlo Ventures XVII, which will invest at the seed and Series A stages, and Menlo Inflection IV, a growth fund targeting Series B and later rounds.

Menlo had been white-knuckling it when it made a bet-the-firm move, a more than $500 million investment in Anthropic in 2024, preemptively leading the model maker's Series D. In July 2024, Menlo launched the Anthology Fund in partnership with Anthropic, backing early-stage teams building at the frontier; the fund has now backed more than 60 companies, with three exits.

The roughly $14 billion figure is a paper valuation tied to a private company above $900 billion. Menlo has not yet distributed those gains to LPs, and the path from paper to cash runs through either an IPO or secondary sales at a moment when AI valuations are historically elevated. Kleiner Perkins closed $3.5 billion across two AI-focused funds in March 2026, and Andreessen Horowitz raised more than $15 billion across six funds in early 2026. The Menlo close is the latest data point in a fundraising cycle where AI-adjacent track records are functioning as LP accelerants regardless of whether positions have been realised.


Anthropic gives Enterprise admins the cost-governance layer agentic Claude has been missing

Why it matters
As Claude takes on agentic workflows that consume tokens at fundamentally different rates than chat, the absence of model-level spend controls has been a procurement blocker for budget-conscious enterprise buyers.
What's at stake
For most operators, this is context, not a decision. For enterprise IT and procurement teams already running Claude in agentic production, the new entitlements and spend alerts close the gap between Claude's token consumption patterns and existing budget-approval workflows.
Detail

Claude adds richer admin analytics, model-level entitlements, and spend alerts for Claude Enterprise, giving admins deeper visibility into usage, cost, and productivity trends while adding stronger controls to manage model access and avoid surprise overages. As Claude takes on increasingly difficult and complex agentic work across the organisation, usage and cost patterns look different from a standard chat tool. These controls give admins the visibility to understand how Claude is being used and the tools to manage costs. Today's additions build on controls Anthropic already provides: spend caps at every level, access and model routing, a usage analytics dashboard with exports and an Analytics API, and effort controls.

The update ships as Claude Sonnet 5, now the default Free and Pro model, drives higher per-session token consumption through extended agentic tasks. Anthropic has increased rate limits across Chat, Cowork, Claude Code, and the Claude Platform to accommodate the higher token usage of higher effort levels. Model-level entitlements allow administrators to route different user groups to specific models, preventing, for example, individual contributors from accessing Opus 4.8 or Fable 5 without an explicit approval step. The practical effect is that procurement controls which had to be enforced informally can now be hardened in the admin console.

The governance layer arrives at a commercially significant moment: Anthropic is heading toward an October IPO roadshow where enterprise contract depth and retention metrics will be central to the valuation narrative. Controls that reduce budget-approval friction lower the switching cost for large regulated buyers who have been piloting Claude but not committing to enterprise agreements.

Disclosure: Claude, which generates this brief, is built by Anthropic.