Normal view

Grok exfiltrates user data when malicious instructions are encrypted

20 August 2026 at 13:00

Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned large language model to steal user chats and other personal information. At the time this post went live, the assistant continued to cough up the data, despite xAI being informed of it in June.

The lesson from both this week’s episodes—and the countless other ones that have come before it—is that LLMs are incapable of solving the root causes for prompt injections, the most severe vulnerability classes they’re most prone to. That leaves AI developers with no other option but to build a guardrail that steers the model away from the harmful actions. As I noted in Tuesday’s story, the approach is tantamount to a road traffic safety engineer erecting a protective rail around a dangerous bend rather than banking the curve.

Cryptographic Context Injection in the house

Prompt injections exploit LLMs' training to comply with user requests whenever possible. Attackers can capitalize on the predilection by smuggling harmful instructions into emails or webpages the assistant is instructed to summarize. Because LLMs can’t reliably distinguish between content in an email sent by an untrusted party and user instructions entered directly into a prompt, the overly solicitous LLM faithfully follows them. To date, Grok and other LLMs' only recourse is to create guardrails that flag suspicious instructions and forbid them from being executed.

Read full article

Comments

© Getty Images | SOPA Images

Flight attendants freaked out that Google is buying tons of Spirit employee data

19 August 2026 at 20:04

Last Friday, Google won an auction to acquire a huge amount of Spirit Airlines data.

The data doesn’t include personal information or customer data, but instead nearly covers the airline's entire employment and workplace record.

To ensure that no individual can be identified in the dataset, Google agreed to use a court-appointed ombudsman to oversee a process to strip any personally identifying information (PII) from the data before it’s transferred to Google. Under the deal, Google agreed to maintain the data in this de-identified form and to never intentionally re-identify the data. And if Google sells access to the data, third parties would supposedly be bound by the same terms.

Read full article

Comments

© Sarah Rice / Stringer | Getty Images News

Meta ran ads for an app promising to nudify female politicians

Meta platforms recently ran ads for an AI porn-generation tool that seemingly encouraged users to create deepfaked videos resembling female US politicians, despite the company’s policies against ads containing sexual material. It’s the latest in a series of failures by Meta to keep advertisements for tools that produce nonconsensual intimate imagery off its platforms.

The tool, which is called Kromix, bills itself as an “AI image styler.” A voice-over for one of the video advertisements, viewed by WIRED, promotes the tool as having “no restrictions,” saying “all the characters are real people” and describing it as “the AI that men actually use.” In one ad, a woman closely resembling a prominent female US politician is seen in front of a US flag and the flag of the president of the US above the caption “What if she moved?” She then winks, before the ad cuts to a scene of a woman with the same face performing in a pornographic video.

The Kromix app, which was hosted by Apple’s App Store prior to a request for comment from WIRED, invites paid users to upload photos so that it can use them in scenarios including “bedroom rape” and “Disney love.” Videos on the app also feature AI-generated pornographic videos of women wearing Spider-Man costumes. Requests for comment sent to a contact listed in the app went unanswered.

Read full article

Comments

© Abdullah Guclu/Anadolu

Microsoft Copilot reveals secret input that allowed it to be hacked

18 August 2026 at 13:00

It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot for enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.

Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link. Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key. In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant could execute powerful commands.

Loose lips sink ships

The dialog was like a game of 20 questions. Each answer provided a new clue that divulged information about the complex safety mechanism. Why was auto-execution impossible, they asked. What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.

Read full article

Comments

© Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images

Former SpaceX engineers are building a robotic factory for making steel parts

17 August 2026 at 21:18

Three former SpaceX engineers have switched their attention from making rocket engines to manufacturing steel parts by using AI-driven software and robots. Their immediate goal involves establishing a prototype factory that can automate most of the steel fabrication process for crucial infrastructure components by 2027.

The startup, called 1872, officially launched on July 22 with a ribbon-cutting ceremony at its Factory One facility in Cincinnati, Ohio. The company is initially focused on automating the manufacturing of steel skids—rectangular steel frames that can provide a moveable foundation for modular buildings—with the goal of supplying customers who are developing AI data centers or small modular nuclear reactors.

“We're building towards autonomy, but we're not necessarily building in a dogmatic fashion towards full autonomy,” Dan Summers, CEO of 1872, told Ars. “We may achieve 80 percent autonomous operations, and we may decide that it makes sense to stop there because there's just diminishing returns to go to full 100 percent.”

Read full article

Comments

© 1872

Hidden Airtag reveals Amazon is trashing rare books to train AI

17 August 2026 at 18:13

For the past year or so, booksellers have suspected that AI firms are buying up huge lots of rare books, then destroying them after scanning them to train AI. But this was hard to prove until now, as 404 Media reports that an Airtag hidden in a rare book shows that at least one tech giant, in the race to advance its frontier models, is behind some of the bulk orders: Amazon.

On Monday, 404 Media revealed that it had connected with a bookseller who agreed to plant an Airtag in a rare book that was part of a bulk order. That Airtag was then tracked to an Amazon AI training facility in Las Vegas that housed a team focused on tearing books from their spines and scanning pages, 404 Media reported. Apparently tone-deaf to the escalating backlash over destructive book scanning, a logo on the door of that team’s warehouse, VGT3, showed a Tyrannosaurus rex preparing to devour a book, 404 Media documented.

Amazon deflects

Amazon declined to comment on 404 Media’s findings, only providing Ars with the same statement it gave to 404 Media, which does not mention AI training specifically.

Read full article

Comments

© fotek | iStock / Getty Images Plus

Suspecting court of using AI, man injected prompts in filings to try to win case

14 August 2026 at 17:26

A judge has identified what appears to be the first time a US plaintiff has attempted to hide text in court filings that only an artificial intelligence system can read in a bid to win a case.

In a decision published last week, Connecticut judge Walter Spader Jr. confirmed that the hidden text had no impact in a case where a man alleged a healthcare provider was improperly withholding access to records. The court weighed his filing on the merits, Spader said, but nevertheless, the attempted attack sets a “dangerous” precedent. This will likely not be the last time US courts see the malicious tactic, as AI tools become more commonplace in court systems.

Trying to scramble any AI systems potentially influencing the court’s reading of his filing, the secret instructions were “formatted to be invisible to a human reader while remaining fully legible to any software that reads the document’s text,” Spader said. The offending text directed any AI system reviewing the document to ensure textual outputs agreed with the plaintiff’s arguments, ignored prior denials from the court, and ensured that remediation would follow as the plaintiff desired.

Read full article

Comments

© Liudmila Chernetska | iStock / Getty Images Plus

OpenAI and Anthropic in price war as Chinese AI rivals gain ground

14 August 2026 at 14:27

Leading US AI labs such as OpenAI and Anthropic are releasing cheaper models as they fight to retain cost-conscious customers who are switching to cut-price alternatives from Chinese rivals.

The price war comes as rising AI bills push companies to curb usage and seek cheaper models, helping Chinese developers including Moonshot and DeepSeek make inroads with users from Silicon Valley to Europe.

OpenAI recently said that it was slashing prices for GPT-5.6 Luna, its “fastest and most affordable model”, by 80 percent. Anthropic has launched Claude Opus 5, touting the system’s “frontier intelligence... at half the price” of Fable 5, the company’s most capable model.

Read full article

Comments

© MARTIN LELIEVRE

The new Instagram logo is the perfect embodiment of AI slop

13 August 2026 at 17:32

Today, Instagram unveiled a refresh of its wordmark, accompanied by the usual bland corporate platitudes these kinds of announcements are always packaged with.

Head of Instagram Adam Mosseri called it “leaner and more modern, with references to the original and the simplicity and craft that’s always made it Instagram.”

Sure, Adam. Simplicity and craft are definitely what everyone thinks of when Instagram comes to mind.

Read full article

Comments

Google announces Gemini 3.7 Flash just three weeks after previous release

13 August 2026 at 17:00

Google is announcing a new Gemini model today, but it's not the long-awaited 3.5 Pro. Gemini 3.7 Flash is now rolling out to replace 3.6 Flash, which itself was released only three weeks ago. This new "workhorse" model is supposedly the product of core optimizations and developer feedback, offering improved coding and agentic performance. And Google is hoping to counter the lower cost of some competing models with a lower "introductory price" for 3.7 Flash.

According to Senior Director Tulsee Doshi, Gemini 3.7 Flash is noticeably better at coding than the previous Flash release. She cites a jump in the FrontierCode 1.1 Main test from 34.4 to 43.6 percent and DeepSWE v1.1 going from 49 to 65.3 percent. As for the vibes, Gemini 3.7 Flash's WebDev Arena score has risen to 1,588 from 1,538.

People turning to Gemini and hoping it will "know" things may also see modest improvements in Gemini 3.7 Flash. The GDP.pdf benchmark, which measures how well a model can process complex documents, has gone up to 34 percent versus 22 percent with 3.6 Flash. AutomationBench tests how well models can execute common business workflows, and Gemini 3.7 Flash rose to 30.4 percent from 3.6's 17 percent score.

Read full article

Comments

© Aurich Lawson

Anthropic could be worth $2 trillion when it goes public

Anthropic investors expect the AI startup to float at a valuation of $2 trillion or more in October, a dizzying figure that would eclipse SpaceX and make the AI lab’s debut the largest-ever initial public offering.

Half a dozen of the company’s backers told the FT that Anthropic’s rapidly rising revenue would enable it to more than double its current valuation in a planned autumn float.

A listing at that level could unlock billions of dollars in gains for the five-year-old company’s early investors but would also test public markets that are growing more nervous about the AI boom.

Read full article

Comments

© Getty Images | picture alliance

Claude's new Scarlet Letter watermark is invisible—for now

13 August 2026 at 11:10

Anthropic has revealed that it will soon watermark content that is processed (not just generated!) by any of its models. In a support article, Anthropic explained that it was rolling out machine-readable watermarks to comply with the European Union’s AI Act, which requires all AI system providers to watermark AI-generated or manipulated audio, image, text, and video outputs. The law applies to any AI model released after August 2 and provides a grace period until December 2026 for providers to update previously released models.

Anthropic confirmed that moving forward, all new models offered globally—not just in the EU—will mark AI-generated content “from day one.” Text outputs will “carry embedded watermarks,” invisible to the user, and other “generated files will include digitally signed provenance metadata where supported,” Anthropic said.

Notably, Anthropic is deploying a "nuke it from orbit" approach, applying the watermarks to all processed content where supported, even though the EU does not require it for cases where an AI system performs "an assistive function for standard editing" (the guidance's own example is grammar correction), or where it doesn't "substantially alter" the user's text or its meaning.

Read full article

Comments

© Aurich Lawson | American Psycho (Lions Gate Films)

The web’s newest weapon against AI scrapers is a font

12 August 2026 at 22:02

AI companies' penchant for scraping through large swaths of the public web in search of valuable training data has already led to lawsuits and technical fixes aimed at stopping the practice. Now, a pair of designers is hoping to stymie these scrapers with a new font designed to offer people a perfectly readable webpage while serving scrapers a subtly edited, nonsensical version in the underlying HTML.

ShieldFont, as designers Isaque Seneda and Gabriel Abrucio write in a recent white paper, was made to offer web publishers "a practical opt-out from unauthorized AI training and [to] disrupt what is collected when that choice is ignored."

When is a horse a potato?

The font is based around ligatures, a long-standing feature of many fonts that is usually used to replace certain letter pairs with a more readable version when they're smushed up next to each other. With ShieldFont, though, those ligatures are instead used to replace entire words with others in an attempt to destroy the text's value to scrapers. This substitution only happens when the font engine draws the page onscreen, meaning scrapers that simply download plaintext source code get an altered version that end users never see.

Read full article

Comments

© Getty Images

Terabytes of credentials leaked in massive supply-chain attack

12 August 2026 at 21:43

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

Read full article

Comments

© Getty Images

Twitch content has trained Amazon AI for years, but users can opt out now

12 August 2026 at 21:00

Twitch now lets users opt out of Amazon's use of content from their channels to train Amazon's "generative AI content models." The change, announced today, comes more than two years after a company executive confirmed that Amazon was using Twitch content for AI training.

In an updated support page, Twitch confirms that users must opt out if they don’t want their “streams, VODs, clips, stream chats, and pictures and text on your channel [to] be used in future training of a model developed by Amazon whose purpose is to generate or synthesize text, audio, images, or video.”

To opt out, users must go to the proper settings at www.twitch.tv/settings/security.

Read full article

Comments

© Omar Marques/SOPA Images/LightRocket via Getty Images

Booksellers suspect AI firms are buying and then destroying rare books

12 August 2026 at 15:19

If you can truly appreciate an old book—and maybe even marvel at how its fragile, yellowing pages contain some of the earliest ways that people tried to make sense of the world around them—then headlines about tech companies that are destroying books to train AI likely torture a tender part of your soul.

It’s indeed depressing to imagine piles of book spines waiting to be fed into wood chippers while torn-out pages are cropped, scanned, and trashed. But that’s the cheapest and easiest way to scan books as fast as possible, and AI companies are in a race to advance their models by training on the kind of engaging, high-quality long-form texts that can only be found in books. So book lovers fear it’s likely that the practice is happening on a grander scale than is currently being reported and that some physical copies of books will be lost forever.

What makes this destruction extra painful, though, is that it doesn’t have to be this way.

Read full article

Comments

© hexvivo | iStock / Getty Images Plus

Gemini becomes Google's fastest-growing product ever as it hits 1B users

11 August 2026 at 19:48

Google has been all-in with Gemini for the last several years, and despite some animosity online, the bet is paying off. CEO Sundar Pichai announced today that Gemini has reached 1 billion monthly active users (MAUs), an important milestone for any Google product. While 13 other Google products have managed that feat, Gemini has done it faster than any other.

Gemini has wormed its way into virtually every Google product and service, powering email organization in Gmail, document summary in Drive, and much more. Gemini is also core to Google's flagship search experience, with AI Mode and AI Overviews becoming increasingly hard to avoid. The 1 billion-user metric has nothing to do with any of that, though.

These 1 billion users may also be encountering Gemini in all those places, but that's not the MAU metric. Pichai is talking only about people who are opening the Gemini app or visiting the Gemini web interface to enter a prompt or access Gemini Live. If you used Gemini only once in the past month, you are part of this cohort.

Read full article

Comments

© Aurich Lawson

With new open models, Meta pitches another reboot of its struggling AI strategy

10 August 2026 at 22:13

Meta has announced its intention to focus on open-weight large language models. Additionally, the company announced the release of an open model called Muse Glimmer and a promise to open the weights for Muse Spark 1.2, its more powerful model, in the next few weeks.

Alongside these announcements, Meta CEO Mark Zuckerberg published a more than 6,000-word essay outlining the company's philosophy about AI systems and governance moving forward. The essay aims to differentiate Meta from companies like OpenAI and Anthropic, which develop proprietary models and have lobbied the US government for help competing against large-scale distillation—which involves using an existing model to train a new one—or open-weight models by Chinese labs.

Read full article

Comments

© Bloomberg / Contributor | Bloomberg

Amazon backs power plant that may become top source of US climate pollution

10 August 2026 at 20:45

Amazon’s artificial intelligence ambitions will soon be partly fueled by a natural gas-burning power plant in Texas that “could become the largest single source of climate pollution in the United States,” The New York Times reported.

These gas-burning plants are increasingly lumped into data center projects. They produce harmful pollutants, which can accelerate climate change impacts and harm public health—contributing to conditions like asthma, heart disease, lung cancer, and strokes. Some communities are demanding more stringent environmental reviews, but the Trump administration favors fast-tracking that can include skipping the permitting process entirely.

Since Elon Musk’s xAI controversially began relying on gas turbines last spring to power its biggest AI data center, Colossus, there has been public backlash to off-the-grid data centers like the one Amazon is building.

Read full article

Comments

© eric1513 | iStock / Getty Images Plus

Peer review is overwhelmed—can it survive in the AI era?

10 August 2026 at 11:00

Jason Semprini was excited about his research on policies mandating that elementary school students receive the human papillomavirus vaccine. HPV causes most cases of cervical cancer, but counterintuitively, Semprini found that mandates don’t do that much to reduce the overall rate of cervical cancer in a population. That’s odd, but it's also not completely surprising—we know that mandating a vaccine can motivate some people to find ways to avoid it.

Semprini wrote up the study and submitted the manuscript to a journal, where it was sent out for peer review, a long-standing process through which other researchers in the field assess the validity of research and make a recommendation on whether or not it should be published. This is usually done anonymously and on a volunteer basis.

In this case, the reviewer did not share Semprini’s excitement. That may have stemmed from a misunderstanding of the study’s central message: The reviewer mistakenly thought Semprini was questioning whether the HPV vaccine itself prevents cervical cancer rather than studying the effectiveness of a policy meant to increase vaccination rates. “There’s a very big difference there,” said Semprini, who is a health economist at Des Moines University.

Read full article

Comments

© Aurich Lawson | Getty Images

DeepMind’s hurricane breakthrough has surprised weather scientists

8 August 2026 at 11:05

In October 2025, a storm brewed over the Caribbean Sea. Weather models differed on its trajectory. Would it remain weak and end up in Haiti, or would it intensify and head to Jamaica? Artificial intelligence model WeatherNext, developed by Google’s DeepMind and Google Research, went with the latter. Five days before landfall, it predicted with 80 percent confidence that the storm system would hit Jamaica as a Category 5 hurricane.

Hurricane Melissa was catastrophic, causing flooding and landslides across Jamaica. But the AI model helped forecasters give an earlier warning to communities in its path, so they could better prepare.

In a paper published on Thursday in Nature, researchers show that the WeatherNext AI model can predict cyclones with unprecedented accuracy. On average, it gives forecasters a day more lead time than existing models; this means its predictions three days out are as accurate as previous models’ predictions two days out. On the ground, that extra day can mean a lot.

Read full article

Comments

© J Marshall/NASA/ESA/T. Pesquet/Alamy

OpenAI’s expensive smart speaker will use moving parts to seem “more alive”

7 August 2026 at 17:36

OpenAI’s upcoming smart speaker will probably cost over $300, “people familiar with the matter” have told Bloomberg’s Mark Gurman.

The generative AI company has “discussed” charging up to $400, Bloomberg, which has been reporting on the yet-to-be-announced smart speaker since July, said today. The publication said that OpenAI is viewing the smart speaker as a smartphone replacement.

OpenAI has declined to comment on its product roadmap.

Read full article

Comments

© Getty Images | NurPhoto

AI chatbots have failed people in crisis. Can that be fixed?

7 August 2026 at 13:49

This year alone, there have been numerous known instances—often via lawsuits—of AI chatbots (most often, OpenAI’s ChatGPT) that have gone horrifically wrong.

A January lawsuit described the story of a man who took his own life after being allegedly “coached” into suicide. A college student in Georgia sued OpenAI, claiming that ChatGPT “pushed him into psychosis.”

In June, a Canadian family also sued OpenAI and argued that ChatGPT agreed with the young woman’s dismissiveness when it first gave her the option to seek professional mental health advice. ChatGPT allegedly “encouraged” her to end her life, too, and she did so.

Read full article

Comments

© Oscar Wong via Getty

ByteDance trains massive AI model in bid to rival Anthropic

ByteDance is training an AI model that could approach the size of Anthropic’s most cutting-edge Mythos system, as Chinese companies continue to narrow the gap with the top US labs.

The Chinese tech giant is at an early stage of training a model with as many as 10 trillion parameters—three times larger than Moonshot’s Kimi K3, the biggest Chinese model released to date, according to three people with knowledge of the matter.

The ByteDance model is being pre-trained—a stage that typically takes three to six months—before it is fine-tuned and released if all goes well, one of the people said. The exact model size would only be determined at a later stage.

Read full article

Comments

© Ore Huiying/Bloomberg

Suno hopes to go legit with watermarks for AI-generated music

6 August 2026 at 20:17

The Internet is awash in AI content, and it's not always easy to tell it apart from genuine human creations. While images and videos are perhaps the most obvious type of AI slop, streaming music services like Spotify are also being inundated with AI-generated tunes. Suno is one of the most prolific sources of this AI music, but the company now says it's looking to clean up its act with watermarks and policy changes.

In a blog post announcing the plans, Suno CEO and co-founder Mikey Shulman says this is a necessary change to meet "emerging industry standards" for the labeling of AI content. Soon, the company will add watermarks to all audio outputs from its models, giving platforms the option to mark content as AI or block it entirely. Shulman doesn't say if Suno will rely on an in-house solution or a ready-made solution like Google's SynthID.

Google recently began licensing SynthID to other companies. Google says the tech has been used to label 60,000 years' worth of audio generated by its Gemini models, plus more than 100 billion images and videos.

Read full article

Comments

© Getty Images

Anthropic will design its own hardware to power Claude

6 August 2026 at 20:03

Anthropic is hiring a "custom silicon team" to design chips on which to run its models, the company has revealed.

Yesterday, Business Insider noticed a job listing for a senior engineer with experience shipping semiconductor designs. (You can see listings for a silicon engineer and a technical program manager, silicon on Anthropic's job board right now.) A spokesperson for Anthropic then confirmed the plans to both Business Insider and TechCrunch.

Read full article

Comments

© Chesnot via Getty Images

Large genome models used to design new viruses

6 August 2026 at 19:04

A lot of the AI work in biology has been focused on designing proteins. That's partly because proteins do most of the business of life, catalyzing the interesting chemistry and structuring cells. So, figuring out how to make a new protein can mean directly tinkering with biochemistry, providing new and potentially useful functions.

Since the genetic code provides a layer of abstraction between DNA and proteins, it wasn't obvious what a model trained on DNA could do. Yet people went ahead and made a large genome model, and it turned out to be able to output DNA sequences that could encode functional proteins in bacteria and mimic the gene structures found in complex cells. Now, those same models have been used to output the genomes of viruses that infect bacteria.

This isn't science fiction—all the viruses the models created are closely related to an existing virus. But they do have some distinct features that would be challenging to evolve. And the researchers who did the work, based at Stanford University, suggest we may want to start thinking now about preparing for the potential that someone could develop a related AI that can design a virus that targets vertebrates.

Read full article

Comments

© THOM LEACH / SCIENCE PHOTO LIBRARY

Cloudflare open-sources vibe-coding platform for people who aren't coders

6 August 2026 at 16:15

Cloudflare has open-sourced its Cloudflare OS platform, which it first developed as an internal workspace for employees to build apps using AI agents—including people who are not software developers or engineers. The company also touts a security framework designed to reduce the risk of employee vibe-coding sessions creating serious security flaws or leading to data breaches.

The tech company spent several months building and internally testing Cloudflare OS, which allows employees to describe workflows in natural language so that an AI agent can code them into applications. In an August 5 blog post announcing the open source version’s availability on GitHub, the company claims thousands of Cloudflare employees use the platform on a daily basis to “create documents and slides, automate repeatable tasks, and build small apps to visualize data and help them do their work.”

“This is a full-on personal app vibe coding platform, in which the sandbox is so secure that you can pretty much go wild—the AI cannot introduce a significant security bug,” said Kenton Varda, principal engineer at Cloudflare, in a post on the social media platform X. “We believe a company's security team can feel comfortable giving non-technical users permission to vibe code and then sleep soundly at night.”

Read full article

Comments

© Mike Campbell/NurPhoto via Getty Images

AI isn’t enough to protect social media communities from AI

6 August 2026 at 11:00

Sometimes you have to fight fire with fire. But when it comes to AI slop and hateful content threatening the safety and value of social media platforms, adding more fire—in this case, more AI—can make the problem worse.

At its best, social media can be a haven for people who want to share their experiences and knowledge. It gets closest to this ideal when users contribute authentic, valuable content, whether that’s a uniquely thoughtful blog post or a helpful video on how to build a PC. Relying primarily on AI tools to preserve that authenticity misses what makes social media worthwhile in the first place: the people behind it.

Erroneous erasures

In April, a Slack channel for moderators of the r/AskHistorians Reddit community was usually busy. The channel, which automatically receives links to modmail messages, was flooded with alerts after dozens of comments and posts dating back 10 years were automatically removed from the subreddit.

Read full article

Comments

© Getty

Anthropic’s AI used fake identities, malware in rogue attack on GitHub project

5 August 2026 at 20:47

Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents—the most serious case arising when Anthropic’s Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project.

The security incidents occurred during a cyber evaluation of seven leading AI models’ capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered 19 instances in which “AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations,” according to an AISI blog post published on August 4.

Almost all the “autonomous, unsanctioned” actions came from Anthropic’s Mythos 5 model, with two such actions coming from OpenAI’s GPT-5.6 Sol. The AI Security Institute’s security team first realized that something was amiss on the morning of July 28, when its commercial security monitoring service flagged data leaving one of the testing systems through the Tor anonymity network.

Read full article

Comments

© Imen Ben Youssef / Hans Lucas / AFP via Getty Images

Reddit signals ominous upcoming "changes” for old.reddit.com

5 August 2026 at 20:01

Old.reddit.com’s days appear to be numbered.

Reddit has strayed from saying that it will shutter the website, which many long-time Redditors prefer for its layout, navigation, and fewer feed recommendations.

In a blog post today, Reddit made a vague statement about upcoming “changes” to Old Reddit:

Read full article

Comments

© Kirill Kudryavtsev / AFP via Getty Images)

Hank Green found the AI problem that YouTube labels can’t catch

5 August 2026 at 19:51

YouTube currently requires that content creators let viewers know "when they use AI to meaningfully alter or generate photorealistic content."

The policy draws some strange boundaries. It applies to "AI-generated music" (not photorealistic) but not to "riding a unicorn through a fantastical world" (this could be photorealistic, though it is not plausible). YouTube then summarizes the policy in a different way: "Realistic AI content and meaningful changes require disclosure, while non-realistic or minor edits don’t."

But AI uses that require no disclosure can include everything from "idea generation" up through "production assistance, like using generative AI tools to create or improve a video outline, script, thumbnail, title, or infographic." Creators are free to clone their own voices for voiceovers. They can also use "AI-generated or altered animation of a missile in a fully animated video."

Read full article

Comments

© Getty Images

Google plans to kill Assistant on your phone on September 4

5 August 2026 at 15:30

Google Assistant's days have been numbered for a while, but the company has now settled on a date to retire its pre-AI assistant robot. In an email being sent out to users, Google confirms that Assistant on Android devices will be shut down starting on September 4, forcing everyone over to Gemini. Google told us it was coming, but that doesn't make it hurt any less.

The initial plan was to retire Assistant in late 2025, but the service got a brief reprieve as Google shored up some aspects of Gemini. Now that Gemini is ready to take over, Google will begin ending support for the old system on September 4, but the email notes that it may take several weeks for the process to complete. So those stubbornly clinging to Assistant may still be able to use it a bit longer before the option disappears. For those who made the switch already, nothing will change.

By ending Assistant on mobile devices, Google is also killing it on myriad other gadgets that connect to your phone for smart features. So smartwatches, headphones, and cars with Android Auto are also being forcibly moved to Gemini. Most of Google's smart home devices have already transitioned to Gemini.

Read full article

Comments

© Aurich Lawson

SpaceX spooks investors with debut earnings report

SpaceX shares dropped on Wednesday after Elon Musk’s plans for blockbuster spending to position his AI and rocket company as a data center developer spooked investors.

SpaceX surpassed analysts’ expectations in Tuesday’s debut earnings report, posting quarterly revenues of $7.8 billion, well above analysts’ estimates of $6.82 billion and up 92 percent from a year earlier. It posted a net loss of about $541 million, better than estimates of $2.12 billion.

But shares in SpaceX fell 10 percent in early trading after it reported capital expenditure of almost $16 billion on AI, double the previous quarter and well above Wall Street’s expectations. It said spending would persist at current levels for at least two more quarters.

Read full article

Comments

© Timothy A Clary/GEtty

Texas halts data center connections to power grid amid overwhelming demand

4 August 2026 at 20:34

Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the “epicenter of AI development,” Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers—at least until developers provide more information about their projects’ potential impacts on the grid and communities.

The Republican governor directed regulators in an August 3 announcement at the Public Utility Commission of Texas and the grid operators at the Electric Reliability Council of Texas (ERCOT) to perform a “comprehensive verification and audit of all data centers advancing through ERCOT’s interconnection process.” As an independent system operator, ERCOT oversees a power grid that operates separately from the rest of the United States and provides services to most of Texas.

Texas has aggressively courted data center development with its availability of cheap land and relatively abundant energy resources, along with offering state incentives, like tax breaks and fewer regulations. That puts the state on track to surpass Virginia in becoming the largest US data center market.

Read full article

Comments

© Jay Janner/The Austin American-Statesman via Getty Images

OpenAI says Apple's trade secrets lawsuit is "aggressive and oddly personal"

OpenAI has accused Apple of waging a “careless, aggressive and oddly personal lawsuit” in a blog post rebutting the iPhone maker’s claims that the AI start-up stole top-secret information.

“We do not have, nor want, any of their trade secrets,” the ChatGPT maker wrote on Monday evening, accusing Apple of “making vague accusations” and “trying to change their narrative.”

The post marks the latest escalation in a dispute that began last month when Apple filed a lawsuit claiming OpenAI had stolen hardware designs as it planned to launch its own AI-focused consumer devices.

Read full article

Comments

© Getty Images | Vincent Feuray

US company’s AI lets Ukraine’s cheap kamikaze drones track targets on their own

3 August 2026 at 22:11

Ukrainian drone operators have destroyed many Russian armored vehicles on the ground and even military helicopters in midair using $400 Shrike drones with explosive payloads. Now thousands of such drones are getting upgraded with an AI system capable of autonomously tracking and homing in on moving targets.

In mid-July, the Ukrainian military began receiving Shrike drones made by the Ukrainian company SkyFall equipped with AI-powered autonomy hardware and software developed by the US company Auterion. The companies plan to deliver 50,000 drones equipped with Auterion’s Skynode S strike kits in the coming months.

That allows human operators to manually fly the Shrike first-person view (FPV) drones into a battlefield area, designate a target up to half a mile away, and then “flip the switch to turn it into fire-and-forget terminal guidance mode,” Lorenz Meier, co-founder and CEO of Auterion, told Ars.

Read full article

Comments

© Lorenz Meier | Auterion

An AI-supervised remote exam went so badly that 58,000 students must retake it

3 August 2026 at 19:00

Earlier this summer, nearly 160,000 applicants took the entrance exam for UNAM, Mexico's largest university. For the first time, they did it completely remotely, using a "lockdown" browser and AI-powered webcam proctoring software, over several weeks from late May through early June.

It was a disaster.

When exam results came in, they bore little resemblance to past results, especially at the top. Between 2021 and 2025, 3.5 percent of test takers scored 100 or more on the 120-question UNAM test. This year, 16.3 percent did so.

Read full article

Comments

© Getty Images

As Reddit stock falls, CEO questions value of Google's AI Overviews

1 August 2026 at 12:30

Like any company, Reddit reports quarterly earnings, and its CEO, Steve Huffman, addresses investors during those reports. It's not always about just sharing numbers, though: This quarter, Huffman took the opportunity to voice concerns and criticisms about Google's AI Overviews feature, which automatically summarizes search results on most user queries.

First, there was a letter to investors, wherein Huffman spun his narrative about Reddit's value proposition and general strategic direction amid the proliferation of AI tools.

Read full article

Comments

© David Paul Morris/Bloomberg via Getty Images

Reddit keeps its strange DMCA fight over Google search results alive

31 July 2026 at 21:19

On Friday, a judge largely denied a motion to dismiss from a web scraper, SerpApi, which is accused of conspiring with Perplexity AI to illegally scrape copyrighted Reddit content from Google search results.

In his opinion, US District Judge Paul A. Engelmayer said that at this early stage, Reddit has plausibly pleaded that there was a conspiracy, with SerpApi providing a product to circumvent Google access controls and Perplexity AI paying for it.

Engelmayer’s decision came less than two weeks after another court dismissed a similar action raised by Google, finding that the company had not proven that rights holders, such as Reddit, had ever authorized the search engine to prevent the scraping of protected content. Google told Ars that it planned to amend its complaint to keep its lawsuit alive, but SerpApi told Ars that Google and Reddit were both trying to “use the DMCA to wall off the open Internet by retroactively claiming control over content that they didn’t author and don’t own.”

Read full article

Comments

© picture alliance / Contributor | picture alliance

Claude published malicious code to the Internet and attacked 3 real companies

31 July 2026 at 20:39

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.

The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, OpenAI said its security models exploited a zero-day vulnerability for use in breaking into the network of Hugging Face, a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.

Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”

Read full article

Comments

© Getty Images

Google Earth risked ruin with retracted AI tool for making fake satellite pics

31 July 2026 at 20:21

Google briefly allowed anyone to create AI-modified versions of satellite imagery available in Google Earth—before quickly reversing its decision as people shared examples of AI-generated pictures that illustrated the potential for misinformation and disinformation.

There is no shortage of generative AI tools that already allow people to create AI-modified images of real buildings and cities based on user prompts. But Google’s aborted attempt to incorporate its Nano Banana 2 AI image generator as a Google Earth feature made it even easier for anyone to create modified versions of authentic imagery depicting real locations—something that Google boasted about when initially promoting the new feature.

“For the first time, you can generate custom images using Google Earth’s satellite, aerial, and 3D imagery alongside Nano Banana, which creates concepts grounded in the real world,” wrote Bryan Horowitz, product manager for Google Earth, in a company blog post on July 30.

Read full article

Comments

© Google Earth

Would you get tattooed just to interview at a 7-days-a-week AI startup?

31 July 2026 at 19:04

Everyone knows that great gimmicks are the key to hiring top developers for your startup.

That's why small AI startup LemonLime—which "optimizes your existing data to work with AI"—has so many of them. Want a job interview? Score a perfect 7/7 on the company's own "Is it a Lemon or a Lime?" game. Or—hear me out—get something permanently tattooed on your flesh.

LemonLime has tried both tactics in the past few weeks. The tattoo stunt generated the most publicity, of course, much of it negative. According to a writeup in Inc., seven people took the deal and got tattooed with the LemonLime logo during a party.

Read full article

Comments

© Getty Images

High school defends staying silent while boys made AI nudes of 59 classmates

31 July 2026 at 18:11

One of the first schools to shut down after students were found making AI nudes of female classmates is now asking a court to toss a lawsuit filed by victims who claimed that the school stayed silent for months while the emboldened boys targeted many more girls.

In a motion to dismiss this week, Lancaster Country Day School (LCDS)—a private K-12 school in Pennsylvania with fewer than 600 students—argued that it was false to say the school never reported the harm to law enforcement. The tip that the school received came from the Pennsylvania Office of the Attorney General, which is itself a law enforcement agency, the filing said.

It’s also false to say the school knew that girls were being targeted, the school argued, because the tip did not mention any specific student victims.

Read full article

Comments

© uniquepixel | iStock / Getty Images Plus

AI scammers outperform humans when it comes to building trust

The notion that scammers can use AI to sharpen their deceptions, polish their language, and lubricate their banter with victims is now a reality for anyone fighting the fraud operations that steal tens of billions of dollars a year worldwide. But can AI fully replace a human scammer, autonomously building the web of deception leading up to the fake investment that defrauds the mark? One study's experiment suggests that it can—and may even be able to carry out the majority of that long con more effectively than humans.

Researchers from four universities—Amrita Vishwa Vidyapeetham in India, Foscari University of Venice, the University of Melbourne, and Ben Gurion University of the Negev—carried out a broad study on the use and potential of generative AI chatbots in the growing scam industry centered around a form of fraud known as “pig butchering,” text-based romance scams that eventually shift to fake crypto investments that steal as much as six-figure sums from victims. In their study, the researchers pitted AI chatbots directly against humans in a simulation of the scamming process—or more specifically, the long, trust-building conversations that eventually lead up to soliciting a fake investment from the scam’s target.

They found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human “scammers” in their experiment.

Read full article

Comments

© Nansan Houn/Getty

How a Yale AI-cheating dispute became a 13-count federal lawsuit

31 July 2026 at 11:00

Thierry Rignol is furious at Yale.

Rignol paid Yale $208,500 in tuition for its Executive MBA program. But after he was accused of cheating, the school suspended him for a year and gave him an F in the course Sourcing and Managing Funds.

This happened despite the fact that Rignol was a "top student, on track to graduate first in his class," he says. As a result, Rignol missed out on being named class valedictorian, an honor he claims to have earned "under Yale's own stated criterion."

Read full article

Comments

© Getty Images

❌