· artificial intelligence · 3 min read

AI and cloud briefing: new frontier models, and a shift in cloud identity risk

A short, factual round-up for July 2026: a new wave of frontier AI models, strong open-weight releases, and why non-human identities are becoming the biggest cloud security question.

A short, factual round-up for July 2026: a new wave of frontier AI models, strong open-weight releases, and why non-human identities are becoming the biggest cloud security question.

A lot has happened in AI and cloud over the past few weeks. Here is a short, factual briefing on the items we think matter most for UK businesses, with links so you can read further.

A new wave of frontier models

The frontier AI race has moved quickly this summer. Anthropic released Claude Fable 5, the first model in its new Mythos-class tier, positioned above Claude Opus in capability. It ships alongside Claude Mythos 5, the same underlying model offered in limited release to approved organisations. Anthropic also released Claude Sonnet 5 at the end of June.

OpenAI has been rolling out its GPT-5.6 line, and xAI released Grok 4.5 in early July. Trackers such as LLM Stats and AI Release Tracker list the full timeline.

What this means in practice: capability keeps rising, but so does choice. If you locked into a single model a year ago, it is worth re-testing your workloads against the current generation.

Open-weight models keep closing the gap

It is not only the closed labs. Moonshot AI released Kimi K3 in mid-July, and Thinking Machines, the lab founded by Mira Murati, released Inkling, an open-weight general-purpose model aimed at reasoning and coding. Models such as DeepSeek V4 and Qwen 3.6 continue to offer strong reasoning and long context under permissive licences.

For businesses with data residency or cost constraints, open-weight models are now a serious option for many workloads, not just experiments.

Cloud security: machines now outnumber people 100 to 1

The most important structural story is identity. Security researchers report that service principals, API keys, and autonomous AI agents now outnumber human users by roughly 100 to 1 in many cloud environments (Dark Reading).

Non-human identities outnumber human users by roughly 100 to 1

Two recent items show why this matters:

  • Researchers found that attackers can spoof OAuth client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments (Infosecurity Magazine).
  • A new phishing-as-a-service operation called Forg365 targets Microsoft 365 accounts using device code phishing, adversary-in-the-middle tactics, and AI-assisted lures (The Hacker News).

Our advice is simple: inventory your non-human identities. Most organisations know their user list but cannot list their service accounts, API keys, and agent credentials. Start there.

Cloud spend: FinOps now covers AI

The FinOps Foundation has broadened its mission beyond cloud cost management to cover the full value of technology spend, including AI and SaaS. One driver: GPU-intensive workloads now account for roughly 18% of total cloud spend at AI-forward companies. If AI spend is growing in your business, it needs the same cost discipline as the rest of your cloud bill.

The takeaway

Three things to act on this month: re-test your AI workloads against the newest models, audit your non-human cloud identities, and bring AI spend under your FinOps process. If you would like help with any of these, get in touch.

Back to Blog