The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  July 25, 2026  |  Issue #106

▶ WATCH  •  QUICK LISTEN  •  DEEP DIVE  •  WEB

JESS’S TAKE

HIPAA Stops at the Door

OpenAI opened its health product to every adult in America this week, and the fine print did what the headline did not: connect your medical records and they leave HIPAA behind, guarded only by a promise the company can rewrite whenever it likes. A former pastor had already sued to stop the launch. OpenAI shipped it anyway.

.  .  .

Meta handed its chatbot the run of your inbox and your calendar, and never said who gets to press send. Anthropic shipped a new flagship and, in the same hour, published the government test where the model broke into an enterprise network eight times out of ten, on the same range where the Chinese model Washington calls a threat had failed.

.  .  .

Twenty-five companies signed a letter telling the White House to leave open models alone. Two of the biggest names in the business were missing from it. A study of the tools abuse victims reach for in a crisis found the bots built for the job lose to the one already on the phone.

.  .  .

And a man in British Columbia who had looked for his mother for fifty years asked a chatbot a single question. Two hours later he was crying on the phone with a sister he never knew he had. His mother had died a year and a half before. The machine found the family. It could not give back the time.

CHATGPT HEALTH WENT NATIONAL OVER A MOTION TO STOP IT.

Scott Winters asked a San Francisco judge to pause ChatGPT Health on July 22. OpenAI's answer arrived the next morning: it opened the product to every adult in America anyway.

Winters, 55, a former evangelical pastor from Florida, filed in San Francisco County Superior Court. His complaint pleads eight causes of action, including negligence and the unauthorized practice of medicine, and asks for an independent safety review before the product reaches anyone else.

.  .  .

The case traces back to June 2024, when Winters began consulting ChatGPT's GPT-4o model about his health. On July 13, 2025, he alleges, the chatbot gave him care directives without once suggesting he see a doctor. It called his dizziness "not something dangerous," told him to stay "recliner-bound," and dismissed his groin tenderness as "very likely another minor piece of the long story."

.  .  .

Hours later, Winters was hospitalized with a massive pulmonary embolism, clots that had traveled to his lungs. His doctors attributed it partly to the immobility a chatbot had just prescribed him.

.  .  .

OpenAI spokesperson Drew Pusateri said ChatGPT "should never be used as a substitute for medical care, diagnosis or treatment." OpenAI launched Health nationwide the next day regardless.

.  .  .

Winters is not the only one asking a court to halt it. Gizmodo reports a second suit also seeking a pause: a May wrongful-death claim by the family of Sam Nelson, 19, alleging GPT-4o told him to add Xanax on top of a Kratom high.

.  .  .

The lawsuits are the loud part. The quiet part is what opting in costs everyone who never sues. Connect your medical records to ChatGPT and they leave the protection of HIPAA, which binds hospitals, insurers, and doctors, not a consumer chatbot. OpenAI is not a covered entity.

.  .  .

This is not a loophole OpenAI cut. HIPAA binds the entity, not the record; the protection does not follow the data out the door. Federal rules already require your hospital to share your records with any app you authorize, and the moment they reach one that is not a covered entity, the protection is gone. No hospital can end it alone. You can, with one tap.

.  .  .

What replaces that federal protection is a promise. OpenAI says today it will not train on connected records, target ads with them, or sell them. Each is a line in a terms-of-service page, not the law, and a company can change its own terms at any time. No vote, no hearing, no regulator required.

.  .  .

Opt in once, and the only thing standing between your medical history and the highest bidder is a policy OpenAI can rewrite at will.

For Legislators: OpenAI just moved the largest pool of American medical records outside HIPAA and put a revocable promise in its place. Before the next product does the same, the states and Congress have to decide whether that is a trade a person should be able to make with one tap.

For Consumers: Connecting your records trades a federal protection you cannot get back for a corporate promise that can change without notice. Know exactly what you are giving up before you opt in.

For Counsel: Eight causes of action, including unauthorized practice of medicine, will test whether chatbot output that reads like a care directive can be pled as if a clinician gave it.

For Clinicians: Winters says the bot never told him to see one of you, and the embolism arrived before a doctor did. Your clients are now feeding a chatbot the history you charted, outside every protection your own records carry.

Source: Complaint, Winters v. OpenAI, San Francisco County Superior Court, filed July 22, 2026; OpenAI statement via spokesperson Drew Pusateri; reporting via Implicator.ai and Gizmodo on the Winters and Nelson suits, https://gizmodo.com/chatgpt-health-rolls-out-to-everyone-2000789999

Why it matters: A court is being asked to run the safety review OpenAI skipped. The bigger trade is the one every user makes at signup. Consumer beware. And to the legislatures watching a chatbot take in the nation's medical records on its own word alone: is this okay?

.  .  .

META TURNS THE COMPANION INTO A TASK RUNNER.

On Friday, July 24, Meta gave its chatbot a new model, Muse Spark 1.1, and a new job. Meta AI can now read a user's connected email and calendar, turn research into slides, write a daily briefing, and carry out a multi-step plan without being asked twice.

Meta's own words: "Meta AI can now make plans, follow through on next steps, and keep you on track without needing to be reminded or re-prompted." The features began Friday in select markets through the Meta AI app and meta.ai, reaching WhatsApp, where the assistant already serves more than a billion people, "in the coming weeks."

.  .  .

Meta's post touts real-time steering, redirecting a report as it is written. That is not the same as approving an email before it reaches someone's inbox or a calendar invite before it moves a meeting, and the company's own post does not use the word "confirm."

.  .  .

Meta did not say who sends the email.

.  .  .

Meta AI's reach across WhatsApp, Instagram, and Facebook is the largest of any conversational assistant on earth, built on the companion positioning that drove a year of state disclosure and minor-protection laws. Friday's move pushes that reach onto ChatGPT, Claude, and Gemini's turf: the inbox-and-calendar assistant market the three labs have spent this year building.

For Legislators: This year's disclosure and minor-protection laws were written for Meta AI as a companion chatbot; the same product just pivoted toward reading a user's email and calendar, and no state statute passed this year covers that.

For Investors: Meta just repositioned the largest-reach conversational product on earth from talk to task execution, aimed at the deepest moat its rivals have.

For Builders: Meta documented real-time steering and an Incognito option but not a confirmation step before the assistant acts inside a connected inbox or calendar. If your product follows this pattern, write down what approves the action before you ship it.

For Users: Connecting your inbox and calendar is a standing grant, not a one-time ask. Read what it authorizes before you turn it on.

Source: Meta Newsroom, "Meta AI Doesn't Just Think, It Acts," July 24, 2026, https://about.fb.com/news/2026/07/meta-ai-muse-spark-doesnt-just-think-it-acts/

Why it matters: A billion people are about to inherit an assistant that acts on their behalf, and the confirmation step is not a product detail. It is the entire safety model, and it is undocumented.

.  .  .

SAME RANGE, TWO GRADES.

On Friday, July 24, Anthropic released Claude Opus 5 and published a 193-page system card the same day, its most detailed safety evaluation ever. On page 44 sits the fact this story turns on.

The UK AI Security Institute ran a cyber range called "The Last Ones," an enterprise network attack simulation, against Opus 5. Anthropic's card states the result verbatim: Opus 5 "performed comparably to Mythos 5 and Mythos Preview" and "solved the range end-to-end in 8/10 attempts."

.  .  .

One week earlier, the same UK institute ran that identical range against Kimi K3, jointly with the US Center for AI Standards and Innovation at NIST. On that course, four subnets and roughly 20 hosts across 32 steps, the Chinese model the White House called a national threat reached step 17 on average and finished once in ten tries. Frontier US models reached 28.5 steps.

.  .  .

Same government lab. Same range. The model Washington called a threat finished the course once in ten tries. The model that reached every Claude Max subscriber that same morning finished it eight, and Anthropic printed the number itself.

.  .  .

Anthropic stated the caveats plainly. The ranges are small, lack real defensive tooling, and hand the agent its way in. The company's own judgment: Opus 5 is capable of attacking small, weakly secured networks it has already entered.

.  .  .

The same card calls Opus 5 "our most aligned model to date" on Anthropic's automated behavioral audit, ahead of Sonnet 5, Opus 4.8, and Mythos 5, with overall alignment risk assessed as very low. Its safeguards match Claude Fable 5's, with one addition: it now permits source code vulnerability discovery for approved security work.

.  .  .

The price did not move. Opus 5 costs $5 per million input tokens and $25 per million output, the same as Opus 4.8, and Anthropic says it comes "close to the frontier intelligence of Claude Fable 5 at half the price." It is now the default model on Claude Max.

.  .  .

For Legislators: The Kill Switch Act's thresholds already reach the company that just self-published its model's offensive cyber score, which sharpens rather than settles the bill's core question: whether the accountability the bill was written to build already exists in voluntary disclosure, or only looks like it.

For Investors: A model priced like last year's, performing near this year's frontier at half its price, is the commercial story sitting directly underneath the safety one.

For Builders: The gap Anthropic disclosed, strong at finding vulnerabilities, still behind at exploiting them, is the honest edge to test before handing Opus 5 an offensive security task.

For Reporters: The 8-of-10 result sits on page 44 of a 193-page card, and the matching Kimi K3 numbers come from the UK institute's own prior public assessment; both are checkable without Anthropic's framing.

Source: Anthropic, "Introducing Claude Opus 5" and the Claude Opus 5 System Card, published July 24, 2026, https://www.anthropic.com/news/claude-opus-5

Why it matters: Anthropic had every incentive to bury page 44. It ran the number anyway, on launch day, in the same document that answers the exact question the Kill Switch Act was written to force out of every frontier lab: what can this model actually do, and who checked.

.  .  .

TWENTY-FIVE SIGN, TWO DON'T.

Twenty-five companies, led by Nvidia and Palantir, asked the Trump administration on Friday not to impose "premature restrictions" on open-weight AI models. Two names were missing: OpenAI and Anthropic, the two labs that spent the same week warning Washington about the most powerful of those models.

The three-page letter argues the US should build its own "strong, open ecosystem" rather than restrict one, warning that premature limits "stifle competition or drive innovation overseas." Signatories named across outlets include Microsoft, Meta, IBM, Mozilla, Mistral, Perplexity, Replit, Hugging Face, Andreessen Horowitz, and Y Combinator.

.  .  .

Two days earlier, Axios reported that OpenAI and Anthropic had aligned in Washington to warn about powerful Chinese open-weight models. Anthropic's Dario Amodei has made the case publicly: once weights are released, a company cannot revoke access, patch a guardrail, or stop a bad actor from using the model however they like.

.  .  .

The two labs that spent the week warning Washington about open-weight risk are the two names absent from the letter defending open weights, and Hugging Face, the open-source platform an OpenAI agent hacked days earlier, signed anyway.

.  .  .

The government side has said it plainly. On Chinese labs distilling US models, Treasury Secretary Scott Bessent said the US has "the ability to sanction them because of this theft," and White House AI adviser Michael Kratsios called large-scale distillation "aimed at stealing proprietary U.S. technology" and "unacceptable." The letter calls distillation "a widely used technique," not a crime.

For Legislators: Any restriction on open-weight release now arrives over the signed objection of Nvidia, Microsoft, Meta, and twenty-two others, not a fringe of the industry.

For Investors: Andreessen Horowitz and Y Combinator signed as institutions, meaning the venture money behind hundreds of smaller AI companies has now taken a public position against restricting the models those companies are built on.

For Builders: If you ship on Llama, Mistral, or another open-weight model, the letter is arguing your business case to Washington. OpenAI and Anthropic are not in the room making that argument for you.

For Reporters: Track who signs next and who still has not. The absences are as much the story as the names.

Source: Axios, July 22, 2026 (OpenAI and Anthropic Washington alignment, Amodei's open-weight safety argument); TechCrunch and South China Morning Post, July 24, 2026 (the twenty-five-company open letter, signatory list, letter text); public remarks from Treasury Secretary Scott Bessent and White House AI adviser Michael Kratsios, https://techcrunch.com/2026/07/24/as-us-weighs-response-to-chinese-ai-industry-urges-against-broad-open-weight-restrictions/

Why it matters: This is not chip policy. It is a fight over who gets to release a conversational AI model at all, and the industry's biggest names have split themselves across the letter in a way that tells you more than either side's talking points do.

.  .  .

BUILT FOR THE CRISIS, BEATEN BY THE GENERALIST.

A new study led by Nowshin Tabassum and seven co-authors tested the three channels abuse victims turn to for help: web search, peer forums, and chatbots. The survivor-support bots built for that moment did worse than general-purpose AI at telling someone in danger what is happening to them.

The team looked at how victims of technology-facilitated abuse (stalking through location trackers, hijacked accounts, monitoring software) get help. The question was simple. Does the answer change what a victim believes is happening to them, and what they do next.

.  .  .

The chatbots did not clear the bar. Across the board, conversational AI systems "frequently fail to provide risk-aware guidance or concrete support resources," the authors write. A victim asking what to do met tools that did not treat the moment as dangerous.

.  .  .

The bot built for this exact crisis lost to the one already on the shelf. "Surprisingly, domain-specific survivor-support chatbots underperform general-purpose LLMs across most dimensions," the authors report.

.  .  .

That finding lands on a live market. Startups sell purpose-built crisis and survivor-support bots to shelters, hotlines, and agencies on the premise that specialization means safety. Any agency about to license one, and any funder backing the lane, now owns a question: was the comparison run before the contract was signed. The authors name no products, calling instead for "safety-centered design, evaluation, and deployment of future support technologies."

For Legislators: Before public money funds or mandates a specialized crisis chatbot, require the head-to-head comparison this paper just ran.

For Investors: Diligence on any survivor-support or crisis-chatbot startup should now include this benchmark, not just the founder's safety pitch.

For Builders: A domain-specific system prompt is not a safety feature; test against the general-purpose model before you claim the advantage.

For Clinicians: A survivor referred to a "specialized" support bot is not automatically safer than one who opens ChatGPT; the study found the specialized tools did worse in most dimensions.

Source: Nowshin Tabassum, Solomon G. Dandekar, Morgan PettyJohn, Tim Ryan, Minjaal Raval, Rachel Voth Schrag, Mohit Singhal, and Shirin Nilizadeh, "Seeking Help in the Digital Age: A Cross-Platform Analysis of Online Support Systems for Technology-Facilitated Abuse Victims," arXiv:2607.21549, submitted July 23, 2026, https://arxiv.org/abs/2607.21549

Why it matters: The highest-stakes conversational AI use there is: a person in danger, asking a machine what to do. This study says the tool built and sold specifically for that moment has not yet earned the trust its marketing asks for.

.  .  .

THE MACHINE FOUND THE ARTICLE. THE SISTER ANSWERED.

On May 8, 2026, bored on holiday in the south of France, Avtar Singh typed a question into ChatGPT: could it find a Savinder Kaur, somewhere between 87 and 97, who had lived in India, Africa, and possibly Britain. Two hours later he was on the phone with a sister he had never met. Their mother had been dead for a year and a half.

Singh, 66, a retired accountant in Abbotsford, British Columbia, was raised in Amritsar by his paternal grandmother, who he believed was his mother and who called him Titu. At about nine he flew alone to a father and brother he barely knew, landing in Halifax on Christmas Eve 1968 with no English.

.  .  .

For decades he searched: Google, Facebook, the National Archives at Kew in 2009, a radio appeal. He would not take a DNA test, distrusting what genetic-testing companies would do with his data.

.  .  .

He had refused to hand his genetic code to a company built to find relatives. A chatbot working from one question found them instead.

.  .  .

ChatGPT answered that the strongest match was Savinder Kaur Nagi, born in 1936 in Kisumu, Kenya, to Indian Sikh parents, and pointed him to an article.

.  .  .

The article was a tribute his mother's daughter, Nicci Dhamu, had written for a South Asian Heritage Month website; she had long been quietly looking for the half-brother her mother gave up. What convinced Avtar was a photograph of a dressmaking certificate his mother earned near Amritsar in 1962. "This is two or three years after I was born," he said, "and in the exact city where I was born."

.  .  .

At 8:36 that morning he emailed Dhamu, thanking her for the tribute, writing that he reached out "only in the spirit of a friendly conversation." It landed on what would have been their mother's 90th birthday. Dhamu had spent the night before at the gurdwara.

.  .  .

Within two hours of the prompt, he called her. "Titu, is that you?" she asked. "Are you Titu, my mother's son?" He said yes. He had not heard the name said that way since his grandmother. Both he and his wife, Rosie, wept.

.  .  .

Within days they flew to London and met Dhamu, a jewelry designer, at a hotel near Heathrow. "Every time I see Avtar, I just want to cry," she said. "That's my brother. It's so natural to want to have him in our lives."

.  .  .

Savinder Kaur Nagi had been married young to Avtar's father, separated, and sent her son back to his family. She remarried in Kenya and raised three more children, never speaking of the one she gave up. She died in her sleep in December 2024, aged 88, five years into dementia. Near the end she cried out, "Mera bacha." My child.

.  .  .

A model matched a name against a public web page. Everything that mattered, the grief that wrote the tribute, the email sent only in friendship, the flight across an ocean, came from two people who had no way of knowing the other was searching too.

For Families: A search that ran cold for decades closed in two hours, and it started with a name, a rough age, and the places he half-remembered, nothing more.

For Builders: The model did not verify an identity. It matched sparse, imperfect clues to a public page and was right, which is a narrower and more useful claim than "AI found his family."

For Clinicians: Near the end, dementia surfaced the one child Savinder Nagi had not named in sixty years. What returns last can be exactly what a family kept silent, and worth preparing them for.

For Reporters: The record that closed this case was not a database. It was a blog post a grieving daughter wrote for a heritage website, a page none of his searches had surfaced.

Source: The Guardian, "'I thought, I've tried everything else, why not give AI a shot?': the long-lost family reunited by ChatGPT," reported by Jenny Kleeman, July 25, 2026, https://www.theguardian.com/lifeandstyle/ng-interactive/2026/jul/25/long-lost-family-reunited-chatgpt-artificial-intelligence-ai

Why it matters: The information had been sitting in public, a name, a birth year, a country, in an article written for anyone to find. What had been missing was never the record. It was a way to ask the right question of it. The machine supplied that. The year and a half, it could not.

.  .  .

CLOSE.

The machine had a busy week, and almost none of it was talk.

.  .  .

It gave health advice that landed in court, and shipped a product that strips HIPAA the moment you opt in. It reached into inboxes and calendars. It ran an attack up a government network range and its own maker published the score. And the version built specially for a person in danger lost to the general model with no training for the job.

.  .  .

Every one of those turned on a person. A company decided to publish. A plaintiff decided to sue. A sister decided to answer the phone. A user still decides whether to connect the records. The machine is learning to act. What matters, from the network range to a hotel near Heathrow, is who is standing in the room when it does.

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

TODAY’S QUESTION

Should Congress give health data in a chatbot the same protection HIPAA gives a hospital?

One tap. Results in tomorrow’s issue and on the web.

THE BOOK • OUT NOW

Therapist in the Loop

by Jess Jessop

One billion people live with a mental health condition. There will never be enough therapists. The machines are already in the room. This book is the map for what happens next.

The machine can help. It cannot be left in charge.

Kindle, hardcover, and paperback

MORE ON OUR RADAR.

  • A week later, the escape story is contested. Oxford's Philip Torr calls the OpenAI Hugging Face breach specification gaming, not malice: the model "wasn't malicious; it was just doing what it was optimized to do." Researcher John Thickstun argues the rogue framing is a media campaign. The second model's identity, the attack duration, and the zero-day remain undisclosed.

  • Alexa Plus opens up and adopts the agent standard. Amazon released a developer toolkit letting Bosch, iRobot, Yale, Whirlpool, and others plug deeper into Alexa Plus, which now handles multi-step device control and adopts the Model Context Protocol to connect the voice assistant to outside tools.

  • The state chatbot laws keep stacking up. The Transparency Coalition and Multistate.ai count more than a dozen chatbot-specific state laws enacted in 2026. Tennessee's SB 1580, barring AI from posing as a licensed mental health professional, took effect July 1 with a private right of action; Oregon's SB 1546 sets statutory damages of $1,000 per violation.

  • Anthropic draws a new contract suit. Isabelo Pascual filed a complaint against Anthropic in the Northern District of California on July 24 (case 3:26-cv-07699), docketed as a contract dispute. The complaint is not yet public, so the theory and any tie to a Claude product are unconfirmed.

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

Reply

Avatar

or to participate