Q2 ’26 AI Briefing: Why the Model Is No Longer the Advantage

Last quarter, I argued that AI had stopped being a capability question: the models were already strong enough, and the differentiator was everything built around them.
Q2 reinforced that point.
This quarter brought another wave of exceptional models, tighter government scrutiny, open-weight cyber capabilities, record capital bets on AI infrastructure, and real-world examples of AI reshaping high-stakes decisions.
For insurers, the takeaway is simple: a model, however strong, cannot be your AI strategy. The harness is.
Here is what happened in Q2 and what it means for how insurers will compete.
Story 1: The Government Now Sits Between the Lab and the User
One of the most consequential AI stories of Q2 was a model restriction.
Anthropic’s Mythos and Fable model family drew significant attention across technology, cybersecurity, and policy circles. The most sensitive issue was cybersecurity. The models were reported to be unusually strong at identifying and reasoning through software vulnerabilities, including those in legacy systems.
Anthropic restricted the most capable version, Mythos, to a narrow set of trusted cybersecurity partners under Project Glasswing. A safeguarded public version, Fable 5, was released on June 9.
The situation escalated when the U.S. government intervened, citing national security concerns around misuse, jailbreak risk, and foreign-national access. Anthropic disabled access globally, restoring it 19 days later after working with the U.S. government on safeguards and validation.
OpenAI faced a similar dynamic with its latest model release, GPT-5.6, which was initially rolled out to a government-approved group of partners before broader release.
Taken together, the two labs tell the same story. Both shipped their strongest models yet this quarter, but the decisions around deployment are no longer made only in San Francisco. They now also go through Washington.
What this means for insurance
Set aside the politics and focus on the operational fact: a production AI model that businesses had begun building workflows around was switched off worldwide, with limited notice, for more than two weeks.
For insurers, the priority is resilience. AI needs to be designed so underwriting work remains reliable even when the underlying model or infrastructure changes. This is where the harness comes in. It is everything around the model: the layer that connects it to your data and workflows, enforces your rules, and corrects course when something fails.
The lesson from Q2 is not simply that models are volatile. It is that AI is becoming part of critical operating infrastructure. Insurers that depend on AI need a harness built to absorb volatility wherever it comes from and ensure decisions remain consistent, controlled, and accountable.
Story 2: A $2 Trillion Bet on Infinite Demand
On June 12, the same day Fable 5 went dark, SpaceX completed the largest IPO in history, raising roughly $75 billion at a valuation that crossed $2 trillion in its first trading session. The previous record, Saudi Aramco’s 2019 listing, was beaten nearly threefold. Anthropic and OpenAI have both filed confidentially to follow.
What interests me is not the size. It is the assumption underneath it.
SpaceX’s prospectus describes a total addressable market of $28.5 trillion, roughly the size of the U.S. economy, and attributes much of that opportunity to future AI enterprise applications, anchored by plans for “orbital AI compute infrastructure”: data centers in space.
Reasonable people can disagree on whether that is vision or froth. Either way, the signal is clear: public capital markets are beginning to price AI compute demand as if it were effectively unbounded.
What this means for insurance
Technology markets are directing extraordinary amounts of capital toward capacity: more compute, more infrastructure, more power, more scale.
Insurance currently operates under the opposite logic: a constrained capital regime. Reinsurance remains costly, and available capacity is allocated with growing scrutiny. The market is not rejecting growth, but it is rejecting undisciplined growth. That discipline is not a limitation the industry endures. It is what insurers are good at. Separating the wheat from the chaff is the job.
The same mindset should apply to AI. Don’t spend more because capital markets are excited about compute. Evaluate AI the way you evaluate risk: look for evidence, know the downside, and back what earns its keep. AI only matters if it helps you use scarce capital more precisely and be rewarded appropriately.
Story 3: Cyber Offense Just Got Easier to Access
While Washington and Anthropic were arguing over whether Fable 5 was too dangerous to release broadly, something more consequential happened quietly.
Security researchers found that an AI model from Chinese company Z.ai now matches some of America’s most restricted AI systems at finding security flaws in software, the core skill behind both cyber defense and cyberattack.
It still trails the best American models at many other tasks. But for the specific job of finding exploitable weaknesses in code, the gap has narrowed sharply.
Here is the part that should reframe the conversation: the Chinese model is open-weight. Anyone can download it, copy it, and run it on their own computers. There is no subscription, no required vendor relationship, and, importantly, no central switch that a government or provider can turn off.
The irony is hard to miss. The U.S. government pulled Fable 5 off the market over cybersecurity concerns in the same month that comparable cyber-relevant capability became freely available to a much broader population.
Whatever you think of either development, the practical outcome is fixed: the ability to find weaknesses in software is becoming less scarce, less expensive, and harder to control.
What this means for insurance
Cyber underwriting has long rested on an unstated assumption: sophisticated attacks require sophisticated attackers.
Capability was the bottleneck. Frequency assumptions, pricing, and accumulation scenarios all quietly lean on that idea.
That assumption is now weakening.
When expert-level tools for finding software weaknesses can be downloaded freely and run on inexpensive computing power, the number of people capable of mounting a serious attack expands.
Now hold that against market conditions: cyber remains a highly competitive market, with abundant capacity and continued pressure on pricing. Attacker capability is becoming more accessible at the precise moment underwriting discipline is hardest to maintain.
I am not predicting a cyber catastrophe. However, cyber insurers with lax underwriting standards are likely to face increasing financial pressure.
Story 4: And Now, F̶o̶o̶t̶b̶a̶l̶l̶ Soccer
As the world watches the World Cup, a practical example of AI changing high-stakes decisions is playing out in front of 5 billion viewers.
The 2026 tournament is one of the largest AI deployments in sport. Every team has access to Football AI Pro, an assistant built by FIFA and Lenovo that turns vast amounts of match data into plain-language answers for coaches. It is not making live tactical decisions, but it is changing the work around the game: how teams prepare, how they study opponents, and how quickly analysis becomes usable.
The applications are already broad. England’s Football Association reportedly cut its penalty-kick preparation from five days to five hours. Curaçao used global population data to assemble a squad in which only one player was born on the island.
That shift is also visible on the pitch. Players underwent a one-second body scan so that AI-generated replicas of them could settle offside calls with millimeter precision, decisions previously left to the human eye.
This changes how the game is played, and there will be strong opinions on both sides. But once this kind of capability exists, teams adopt it because the alternative is competing with less information, less precision, and less speed.
The One Thing to Take Into Your Next Board Meeting
Q2 proved that models will keep getting stronger. It also proved that the model is no longer where the advantage lives. The same model, placed in a different harness, produces meaningfully different results. The harness is now the asset.
For insurers, the board-level question is not which model is best today. That answer will keep changing, and each change will matter less. The question is whether the business has a harness that reliably turns AI progress into better underwriting outcomes: one that grounds AI in your own data and decisions, connects it to your workflows, enforces appetite, authority, and underwriting rules, preserves auditability, and adjusts to prevent disruption to the underwriting floor.
A model is a powerful base layer, with broad reasoning ability and broad knowledge. But underwriting does not run on broad intelligence alone. It runs on the specific: appetite, guidelines, submissions, loss history, broker context, portfolio strategy, relationships, and the human judgment of risk. The same model will perform differently and fail differently depending on the harness surrounding it.
That is the board-level takeaway from Q2. The models will keep improving, and the regulatory environment will keep changing. Neither is in your control. But the harness is.













.png)





.png)