Sidekick Orchestration
// The Sidekick Skim · July 10 - 17, 2026

AI This Week: Stop Waiting on Roadmaps and Check Your Browser Agents

Google's next Gemini is reportedly delayed, researchers found a live exposure in Claude for Chrome, and a cheaper model narrowed the price gap. Here is what changed, who it affects, and what was worth doing during the week covered.

In this edition
Read this if you read nothing else
What changed

A promised model slipped without a new date, a browser agent could be triggered by another extension, and a lower-cost model made premium pricing easier to challenge.

What it means

Model roadmaps are not operating plans. The larger near-term risk is not model intelligence but the software and permissions wrapped around it.

This week's decision

Build on tools available now, verify autonomous browser settings, and compare model costs only where usage is high enough to matter.

Safe to ignore

Do not start a compliance project because of this week's AI-and-jobs statement. It was advocacy, not a rule or deadline.

Only where it applies
  1. If a project was waiting for Gemini 3.515 minutes

    Unpark the decision

    Choose from models you can test and buy now. Treat a future Gemini release as a possible upgrade, not a dependency in the plan.

    Limit: If your current tool already meets the need, there is no reason to migrate simply because another model shipped.
  2. If anyone uses Claude for Chrome10 minutes

    Check autonomous actions

    Ask the tool owner whether act-without-asking was enabled. At publication, the reported issue was still unpatched, so the safe setting was per-task approval.

    Limit: If the extension was not installed or autonomous actions were disabled, no change was required. Verify the current patch status before acting on this archived advice.
  3. If model usage is a material monthly cost30 minutes

    Run one price comparison

    Compare the model you use with one lower-cost option on the same real task, including quality and rework rather than list price alone.

    Limit: For low-volume use, the savings may be too small to justify another vendor or workflow.
01

Model roadmaps are not commitments

Operator lens: Relevant if a project or purchase was waiting for a promised release.

DelayReported; testing confirmedGemini 3.5 Pro is reportedly on hold after a disappointing coding updateIn simple terms: Bloomberg reported that a coding-focused training update underperformed and the release was held back. Google confirmed only that testing continued, with no new launch date.Applies to: Teams delaying a project, purchase, or model choice for Gemini 3.5

Google's own statement, relayed through 9to5Google, is that it is currently testing 3.5 Pro, an upgraded Flash model, and other models with partners. It did not confirm the delay or the reason for it, both of which come from Bloomberg's reporting. No revised launch window has been given publicly.

Your decision

If a project was parked for Gemini's next jump, unpark it and test available alternatives. This does not mean abandoning Google; it means refusing to make an unconfirmed release date load-bearing in the plan.

Sources: 9to5Google

02

The wrapper can be riskier than the model

Operator lens: Relevant if a browser agent can reach company email, documents, or calendars.

Live riskSecurity research; vendor unconfirmedA browser extension can trigger Claude for Chrome without anyone clickingIn simple terms: Researchers found that another Chrome extension could fake the click Claude expected from a person, then trigger actions in connected services such as Gmail, Docs, and Calendar.Applies to: Teams using Claude for Chrome on machines with business data

The technical cause is that the extension does not check whether a click event genuinely came from a person. Severity was rated high in normal use and critical when the act-without-asking mode is turned on. The July 7 release still carried the vulnerable code according to the research.

Your decision

At publication, autonomous browser actions should have been opt-in per task on any machine with company email. Before applying that archived advice now, verify whether Anthropic has shipped a fix; the durable rule is that standing permissions deserve a named owner and a review date.

Sources: The Hacker News, Manifold Security

03

Cheaper models now belong in the cost conversation

Operator lens: Relevant when model usage is frequent enough to appear as a meaningful monthly cost.

Cost signalVendor pricing; mixed independent testsKimi K3 listed output at $15 per million tokens, against $50 for Fable 5In simple terms: A lower-cost model did not need to beat the premium models on every task to change the decision. It only needed to be good enough on repeatable, high-volume work.Applies to: Teams paying usage-based AI costs or designing high-volume automations

Moonshot listed K3 at $3 per million non-cached input tokens and $15 per million output tokens. Its own benchmarks placed the model behind Fable 5 and GPT-5.6 Sol, while two independent evaluations available at publication disagreed about how close it was. That uncertainty is exactly why price alone is insufficient: the useful comparison is cost per acceptable result on your own work.

Databricks' CEO described the broader shift as moving from tokenmaxxing to valuemaxxing. In plain language: stop paying for the smartest model on every task and start matching model cost to the value and risk of the output.

Your decision

If model usage is material, run the same real task through a cheaper and a premium option, then include review time and rework in the comparison. Keep premium models on customer-facing, legally sensitive, or genuinely difficult work; a small monthly bill is not worth adding operational complexity to optimize.

Sources: Tom's Hardware, Simon Willison, Databricks

Evidence note: Evidence status at publication: the Gemini 3.5 Pro delay and its cause were Bloomberg's reporting, not Google's statement; Google confirmed only that testing continued. Kimi K3's pricing and performance figures were vendor claims, the two available independent evaluations disagreed, and full weights were still a promise. The Claude for Chrome flaw came from Manifold Security and Anthropic had neither confirmed the account nor announced a patch. This is an archived edition: verify current release, patch, pricing, and licence status before acting.

// Never miss an edition

Get The Skim every week.

One email, every week, on where AI is heading and what it means for operators.

// One of these decisions applies to you?

Bring one decision. Leave with a next step.

Use the 30-minute call to work through that specific model, workflow, or risk choice.