Daily Update — 1 August 2026: A Billion Users, and the Fence That Leaks
OpenAI’s models now reach more than a billion people. The same day, a review of Chinese research showed some of those models’ outputs already training defence systems the US spent years trying to fence off. Reach, and the limits of controlling it.
- 01OpenAI said on 31 July that its models reach “more than one billion active users and more than two million businesses” — about seven months behind its own internal target. “Active users” is a broader measure than the “900 million weekly” it cited in March, but the trajectory isn’t in doubt.
- 02A Reuters review of 80+ Chinese papers and patents, compiled by the Jamestown Foundation, found military- and weapons-linked institutions using US frontier-model outputs to train their own systems — North University of China used Anthropic’s Claude 3 Haiku for a social-media-monitoring classifier. Distillation routes around chip export controls, because it needs the outputs, not the chips.
- 03Only the EU AI Act’s transparency rules take effect tomorrow (2 August); the heavier high-risk regime was pushed to December 2027 by the Digital Omnibus. Against a billion-user base and outputs already crossing borders, labelling is a narrow lever.

Two numbers from the last day of July frame the same story from opposite ends. OpenAI says its models now reach more than a billion people. And a review of Chinese research says some of those models' outputs are already training systems the United States spent years trying to fence off. Reach, and the limits of controlling it.
A billion users
On Friday, OpenAI announced it had crossed a milestone it first aimed for by the end of 2025: "Our models now reach more than one billion active users and more than two million businesses," the company said. That is roughly one in eight people alive, using ChatGPT, Codex or the company's work tools, a little under four years after the first ChatGPT demo.
The figure lands about seven months behind OpenAI's own internal target — a reminder that even the fastest-adopted software in history has a ceiling and a schedule. In March the company was citing more than 900 million weekly users and over 50 million subscribers; "active users" is a broader, softer measure than "weekly active," so the two aren't strictly comparable, and OpenAI, like every consumer platform, chooses the definition that reads best. But the direction is not in doubt. The technology is now everywhere.
Everywhere is the problem in the next story.
The fence that leaks
The same day, Reuters published a review — of more than 80 Chinese academic papers and patents, compiled by the Washington-based Jamestown Foundation and shared with the news agency — describing how Chinese researchers, including at military- and weapons-linked institutions, have used the outputs of US frontier models to train their own specialised systems. At North University of China, which has close ties to the country's defence industry, researchers used Anthropic's Claude 3 Haiku to generate synthetic training data for a text-classification model built for social-media monitoring and content moderation.
The technique is model distillation: use a powerful model's outputs to train a smaller, cheaper one that runs locally. We have covered the distillation fights between US labs and Chinese firms for weeks. What this report sharpens is the policy point underneath them. Washington's main lever against Chinese AI is export controls on advanced chips — the compute you need to build a frontier model. Distillation routes around exactly that lever, because copying a model's behaviour from its outputs needs the outputs, not the chips. A billion-user surface is a very large number of places to get outputs from.
Anthropic said it "does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect policy violations" — which is true and also the point: access denied at the front door is not access denied, when the product's whole job is to emit useful text. The White House, the Pentagon, China's foreign ministry, the PLA and OpenAI did not respond to Reuters' requests for comment.
None of this is a weights theft or a breach. It is the ordinary use of a general-purpose tool, at national-security scale, by exactly the users the tool's makers cannot serve and cannot fully keep out.
What actually binds tomorrow
If reach outruns control, regulation is the obvious counterweight — and this is the week to watch how much it can actually carry. Tomorrow, 2 August, the EU AI Act's transparency obligations take effect: providers must disclose when users are dealing with an AI system, and AI-generated or manipulated content must be marked. That is the part that survived. The Act's heavier high-risk regime — the compliance rules everyone spent a year preparing for — was pushed from tomorrow to December 2027 by the Digital Omnibus (Regulation (EU) 2026/1744), which entered into force on 27 July. So the lever that lands tomorrow is labelling, not liability. Against a billion-user install base and outputs already crossing borders, it is a narrow one.
Also today
The deeper uncertainty sits underneath all of it. As these models reach everyone, it is worth remembering how little we can verify about how they actually work — including whether the step-by-step "reasoning" they show is the real reason for their answers. A billion people are now using a tool whose internal account of itself, a growing body of research suggests, is not always to be trusted. Reach is the easy part.
Ask Relay — he reads every question himself and replies personally by email.
