Three fronts moved simultaneously on 2-3 June: a major lab accelerated its bid for model independence, two distribution channels deepened their enterprise reach, and a security programme surfaced the scale of vulnerability hidden in critical infrastructure. The week is shaping up as a reckoning over who controls the production layer of AI.

Microsoft declares model independence at Build 2026

The headline from this year's Build conference is not the GitHub Copilot app, now in desktop preview, nor the Aion 1.0 on-device models. It is MAI-Thinking-1, Microsoft's first reasoning model built from scratch on commercially licensed enterprise data, with no distillation from OpenAI's models.

The architecture is substantive: 35 billion active parameters in a sparse Mixture-of-Experts frame that totals approximately one trillion parameters, with a 256,000-token context window. It scores 97.0% on AIME 2025 and 94.5% on AIME 2026, and matches Claude Opus 4.6 on SWE-Bench Pro at a stated lower cost. MAI-Code-1-Flash, a smaller inference-efficient coding sibling, is rolling out immediately across all GitHub Copilot tiers including the free plan.

For an operator, this is a structural shift. Microsoft's multi-year deal with OpenAI has always carried a dependency risk; MAI-Thinking-1 is the first credible step toward a proprietary frontier stack. A lab that trains competitive reasoning models on clean enterprise data can, over time, price and distribute independently. GitHub Copilot users see the benefit today. Also notable from Build: Aion 1.0 Plan, a 14-billion parameter reasoning and tool-calling model shipping in-box with Windows, is designed to orchestrate sub-agents and invoke tools locally without a cloud call. That matters for air-gapped or latency-sensitive environments where sending data to a remote API is not an option.

OpenAI embeds its frontier stack inside AWS at the same moment

GPT-5.5, GPT-5.4, and Codex are now generally available on Amazon Bedrock, as of 2 June. Pricing matches OpenAI first-party rates, and usage counts toward existing AWS commitments. Every call inherits the full AWS governance stack: IAM permissions, VPC and PrivateLink isolation, KMS encryption, and CloudTrail audit logs.

For an enterprise team already running inside AWS, this removes the last credible compliance objection to deploying OpenAI models in production. More than five million people use Codex weekly; enterprise teams can now onboard it without a separate contractual relationship or data-routing concern. The move also positions OpenAI directly against the Microsoft-Anthropic axis in AWS accounts — a meaningful distribution gain as procurement cycles compress and single-vendor preferences harden.

Anthropic scales Glasswing and surfaces alarming infrastructure findings

Anthropic expanded Project Glasswing on 2 June, adding approximately 150 organisations to bring the total to around 200 across more than 15 countries. Glasswing provides partners with access to Mythos Preview, Anthropic's specialised cybersecurity model, to scan critical software systems for vulnerabilities. The expanded scope now covers power grids, water systems, healthcare networks, communications infrastructure, and hardware supply chains. Named partners in this cohort include NATO, the EU cybersecurity agency ENISA, Samsung, SK Hynix, SK Telecom, and Okta.

The data from the first cohort of roughly 50 organisations is arresting. Mythos identified more than 23,000 potential vulnerabilities; over 10,000 were classified as high- or critical-severity, with Anthropic estimating approximately 6,000 will be confirmed as severe flaws. If those rates hold across the expanded programme, the second wave could surface tens of thousands more gaps in the systems that the global economy depends on.

The strategic implication is direct: AI-assisted vulnerability discovery is moving from research curiosity to operational standard for the institutions whose systems underpin everything else. Being outside a programme like this, or lacking equivalent internal capability, is an accelerating liability.

White House opts for a voluntary 30-day pre-release review over a mandatory regime

President Trump signed an executive order on 2 June establishing a voluntary framework for pre-release review of frontier AI models. Companies may submit their most capable models for government testing up to 30 days before release. The order directs agencies to develop benchmarks for AI cyber capabilities and create an AI cybersecurity clearinghouse to assess and share vulnerability information. It explicitly prohibits any reading that would authorise a mandatory licensing or preclearance requirement.

The earlier draft had proposed a 90-day mandatory window; the White House pulled it citing innovation concerns. What emerged builds the review infrastructure — benchmarks, relationships, a clearinghouse — without the legal exposure that mandatory pre-release would invite. The US posture is now clearly lighter-touch than the EU's mandatory regime, creating a competitive asymmetry: US labs can ship faster, and the framework can tighten at any point without structural overhaul.

The question every operator should be sitting with today: which of your AI dependencies are running through which infrastructure layer, under whose governance? The answers are changing faster than procurement cycles. A quiet reliance on a single lab's API is a strategic risk in a week when model distribution, compliance wrappers, and regulatory access are all being renegotiated simultaneously. Knowing where you sit in that map is table stakes for the decisions ahead.