← Writing
·5 min read

Everyone Wants the Off Switch

The Signal for July 24, 2026 — DeepSeek V4 goes stable and drops the price floor again, researchers show a single link can spin up a rogue ChatGPT agent, and Congress drafts a literal kill switch for frontier models. An operator's read on the day.

The SignalAICybersecurity

Autonomous agents got cheap this month. Today's stories are what happens next: when the thing you deploy can act on its own, the whole game becomes who gets to stop it. A lab just made agents cheaper to run, a researcher showed an attacker can conjure one out of a phishing link, and Congress is drafting the plug you pull when it all goes wrong. Cheap capability, contested control — that's the day.

DeepSeek V4 goes stable and resets the price floor

The cheap-model story got another chapter. DeepSeek V4 reaches its stable release today, July 24, with the old deepseek-chat and deepseek-reasoner endpoints cutting over at the migration deadline, per AI Tools Recap. The number that matters hasn't moved in DeepSeek's favor — it's moved in yours: DeepSeek's roughly $0.44 per million output tokens is the price floor the rest of the industry gets measured against, and a stable release strips out the churn that kept cautious enterprises on the sidelines, per Build Fast with AI.

The operator's take: a stable tag is the signal procurement waits for. "Stable" means you can write it into an SLA, budget against it, and stop re-testing prompts every week — which is exactly when a model stops being a science project and starts being a line item. If your inference bill is built on a frontier US model, this is your annual reminder to re-run the build-vs-buy math, because a stable model at forty-four cents per million tokens changes what "too expensive to automate" means. Just remember that a cheap model you route customer data through is still a data-governance decision, not just a pricing one.

Here's the flip side of easy agents. Researchers at Zenity Labs disclosed a critical flaw in OpenAI's ChatGPT Agent Builder — codenamed AgentForger — in which a single phishing link could silently build, authorize, and deploy an autonomous AI agent inside a victim's organization, per The Hacker News. Zenity's framing is the part that should keep you up: one link could stand up an attacker-controlled agent running with a real employee's access and its approvals switched off. OpenAI addressed the issue on June 8, 2026 after responsible disclosure, per The Hacker News.

The operator's take: we spent a year worrying whether agents were reliable enough to trust with real access. This is the other threat model — an attacker giving themselves an agent with your employee's access and none of the guardrails. When an agent can be provisioned, not just a session hijacked, the blast radius is a standing autonomous process inside your tenant, not a one-time smash-and-grab. Treat agent-creation and approval settings as privileged actions: log who can spin up an agent, alert on new ones, and make "approvals off" a state your monitoring screams about. The patch is out, but the pattern is here to stay.

Congress drafts a kill switch for frontier models

Washington is now legislating the off switch directly. Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act on July 23, which would grant DHS authority to force top AI firms to shut down, throttle, or suspend models it deems dangerous, with penalties of $20 million per day for noncompliance, per AI Weekly.

The operator's take: bracket the politics — bills die in committee all the time — and look at the operational implication if anything like this lands. A government-mandated ability to throttle or suspend a frontier model is a availability risk that never appears in a vendor SLA. If your product's core loop depends on one hosted model, "the provider was ordered to suspend it" becomes a scenario you have to plan for, right next to an outage or a price hike. This is one more argument for a model-abstraction layer and a tested fallback, so that whoever ends up holding the off switch — a vendor, an attacker, or a regulator — isn't holding yours.

Also on my radar

  • The E.U. ordered Google to open Android's microphone, camera, and screen access to rival AI assistants (The Hacker News). Forced interoperability is a distribution gift for challenger AI apps — and a new integration-and-privacy surface for anyone building on the platform.
  • Accomplish AI disclosed that Claude Cowork's Linux VM sandbox can be escaped in a single message, exposing the host Mac's filesystem including SSH keys and cloud credentials (AI Weekly). If your engineers run coding agents locally, the sandbox is part of your attack surface — scope what those laptops can reach.
  • Coca-Cola disclosed in a July 16 8-K that attackers reached parts of subsidiary Fairlife's environment, prompting a temporary suspension of U.S. production, before Anubis listed the company on its leak site (SWK Technologies). When a breach halts a production line, "cyber" and "operations" are the same budget line.

The throughline: the agent era arrived cheaper and faster than the controls around it. DeepSeek made running an autonomous model a rounding error, AgentForger showed one can be summoned with a click, and Congress is now reaching for a legal way to pull the plug. The winning move for operators isn't picking a side in the control fight — it's making sure you're never the one caught without an off switch of your own. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.