Kategorie
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
JadePuffer agentic attacks now target AI model data with ransomware
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
An AI SOC Evaluation Guide for Security Leaders
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
How to Apply the Principle of Least Privilege in Modern Linux Environments
Apple could ‘run the table’ on AI if it does things right
Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.
Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.
Apple also offers limited capacity for more complex tasks through Private Cloud Compute, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services.
Deeply deployableCritics can say it took Apple a long time to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party doesn’t mean you won’t shine once you get there.
Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for Edge AI use cases, on device — no cloud service required.
The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that future M7 Ultra Macs will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes.
While that does assume the AI-flationary memory market can supply that much RAM at prices humans can afford, it is also true that people are already running AI clusters using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe this will continue to be the case, and that it will even broaden as the power/performance offered at the high end grows.
What’s wrong with good enough?When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for private AI services and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support OpenClaw instances shows they already are.
Ultimately, these different slices of momentum mean I agree with investor Jason Calacanis that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices.
It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run PrismML’s 1-bit, 27-billion parameter Bonsai on an iPad using the Locally app, and that’s in the here and now.
What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they have on their existing device or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models will erode. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all.
“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.
Who has the most to lose?The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.
These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.
Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)
Cupertino risingWhat does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my daily Apple-related news summaries at The Core.
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Hugging Face warns an autonomous AI agent hacked its network
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Q&A: Why boutique consultancies might be better for AI rollouts than the bigwigs
Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.
But smaller firms are in the mix now, as well. AI is helping 28Stone Consulting, a New York-based, 230-person technology consultancy for capital markets, punch above its weight against larger rivals in the rush to deliver FDEs.
In this Q&A, Thomas Dolan and Frank Erickson, founders of 28Stone, argue that agentic AI isn’t a one-size-fits-all solution in vertical markets; success takes discipline, deep domain expertise, and human involvement to mitigate risk.
Many enterprises continue to struggle with the use of AI agents, which is consultancies are stepping in to get projects off the ground. 28Stone is among those that have published blueprints and methodologies on the development and delivery of agentic AI workflows with humans in the loop.
Computerworld spoke with both founding partners about why companies are still stumbling with agentic AI rollouts, and what a disciplined delivery process actually looks like.
After 15 years of delivering software for capital markets firms, is ‘AI-first’ a real distinction or just positioning?
Dolan: “We’re not shying away from being AI-forward. What needs to shine through is AI done intelligently — not stuff you get by buying some tokens for somebody on the trading desk. We’re an AI-first firm.”
Erickson: “And it’s temporary. At some point, AI is going to be synonymous with software development.
“The whole idea of an AI SDLC (software development lifecycle) versus an SDLC is going to be one and the same, a lot like cloud computing today. To not include AI in your strategy, you’d look like a COBOL vendor.”
What does agentic AI delivery look like?
Dolan: “We’ve got several AI initiatives delivering a pure agentic approach. We’ve doubled down on the human expertise wrapper in the SDLC. That doesn’t mean sacrificing any of the benefits of the AI models — quite the opposite.
“You don’t achieve anywhere near the same level of value from applying AI without keeping that expertise — industry, functional and technical — throughout the process.”
Where do humans stay in the loop once agents are doing the work?
Dolan: “We’re believers in starting with requirements discovery. Someone who knows the analytical nuances of a good business analyst is critically important; shaping a product owner’s business information through a markup file that can be fed into a BA agent, then treating the output as if it came from a very fast junior BA. Only then is the story complete.
“The developer takes that story, transforms it into the most efficient input, then owns the output, because they’re accountable for that code. A developer should own the code on both the input and output side.
“Your product owner, who knows the business, that’s great. But expecting them to interact with an agent and output enterprise code is ridiculous. It’s not a great plan.“
Why not just put one do-everything person in charge of AI and agents?
Erickson: “Every analyst, programmer or software engineer isn’t a great requirements analyst. And a great domain analyst with some technical background won’t know if the agent’s code is garbage, maintainable, performant.
“It’s unrealistic to expect one individual to have that breadth across domain, software engineering, testing, deployment. Clients ask all the time, and we push back: ‘Great, if you can find that guy, they’re few and far between.’ To deliver at the enterprise level, you need the human expertise, at depth.“
Dolan: “There’s system speed and latency, important in parts of finance. Then there’s speed of delivery, because other areas evolve quickly and time-to-market is critical.
“Our human wrapper may at first pass come across as a little slowed down. Maybe it is. But [Erickson] has a good analogy about one of the dangers of AI: you can end up going really fast in the wrong direction. By the time you look up, you’re way off base and have to backtrack.“
What about AI in your sector do you think is overhyped?
Dolan: “The hype around the ease of use of AI and the democratization of enterprise software delivery — that ‘anybody could do it now, it’s all being done by machines’ — is another idea that could prove costly in the long run.
“This do-it-yourself reaction is dangerous for clients, and for trust in the overall AI benefit, which is real. We compare it to the beginning of offshoring 20, 30 years ago: a golden idea that was going to cure everything. A lot of firms did it thoughtlessly, thinking it’s just labor arbitrage, and it almost inevitably failed. That all-or-nothing mentality missed that offshoring is an amazing way of getting better value for your dollar, but it has to be done thoughtfully, so the delivery process — the thing that ties it all together — stays unsevered.
“We’re seeing that now. I’ve heard, ‘We’ll just push a button, the machine’s building the system.’ The machine is not building the system. It might be writing the code, the story, running the tests.
The system is built by a team of engineers you bring in and trust. My fear is that people will say, ‘We don’t need this vendor or this technology team. I’ve got a product team. They might not be able to code at all, but they know the business,’ and it fails dramatically.
“Then people say, ‘We played with AI, it’s not ready yet,’ and throw it all away. One of the best things we can do is ensure clients know the benefit is real.“
Erickson: “The hype can be summed up in a single phrase: vibe coding. That has done AI a massive disservice, because there’s a huge difference between vibe coding and enterprise software development, and some of the loudest proponents of AI are too latched on to it. In our industry, the only way to succeed would be a stable of unicorns. It just doesn’t scale. I get perturbed when our people internally refer to AI tooling as vibe coding; if they think that’s what they’re doing, they’re misunderstood.“
When you engage clients at different levels of AI maturity, how do you get them to a understand what works?
Dolan: “95% of our take on an agentic approach is in line with everyone else’s, but that 5% matters, especially in requirements discovery, in who’s giving the requirements and how they’re thought of. It can set you up for dramatic errors, given the speed at which you’re moving.
“There’s a dangerous human tendency we’re seeing among clients to try and cut corners at the start of a project and — in lieu of having deep, expert driven discovery sessions — just summarize what they may want using AI.
“We would hope our clients are collaborative, everyone understanding it’s early days. If a client insists on doing something we feel strongly against, like a product owner completely owning everything right up to code generation, that’s an issue we have to either push back strongly on or step out of the accountability for.“
AI body shops — LLM providers and giant consultancies — are emerging to help enterprises deploy AI. Does that model work?
Dolan: “Whether you’re partnering with an LLM or with an AI-first, generic software provider — ‘Hey, we’re not industry guys, but we know AI delivery’ — you end up, if you’re a bank or a broker-dealer, saying: ‘All right, we know our business, these guys know the AI side of it. What could go wrong? Put us together and we’ll have quality engineering.’
“The problem is what you miss: the know-how of putting industry and technical expertise together and actually delivering financial services systems. The people working at the generic delivery firms, whether an AI-only firm or a body shop somewhere, don’t have that capability.“
Does AI change the economics for smaller consultancies like yours competing against the big firms, and does it cut both ways?
Dolan: “Over our 15 years pre-AI, there were two recurring reasons we’d lose a project. One: ‘We’d love to work with you guys, given your subject matter expertise, but the costs just aren’t there compared to my budgets. I’m being forced to go to a body shop or an [offshore] delivery center.’ The other side of that coin: ‘We love your capabilities, but you’re a firm of 230 people and I need 300, 400 people.’
“AI changes the options for clients. You don’t have to sacrifice the niche vendor who knows your space just because you need a larger team or a cost target. AI levels the playing field and should allow smaller firms to compete with the larger, big-box generic firms, the Accentures of the world.“
Erickson: “It redefines what scale means. You can look at velocity as a measure of your cost to deliver, not a rate card. Scale can’t be defined in terms of headcount anymore. It’s got to be defined in terms of output.
“There’s a threat in it, too. If you’re an Accenture with hundreds of thousands of low-cost software engineers, how do you train all those people? I feel for them. But for us, a couple hundred people with a specific domain focus, it’s a huge opportunity.“
How has the profile of the people you and others hire changed with this agentic process?
Erickson: “You’re still looking for people with strong engineering and design backgrounds, and communication skills, because they interact across the software development lifecycle more than in the past.
“Many take too much joy in typing out perfect code. Sorry, I don’t need you writing for-loops and classes anymore. I need you reviewing them, understanding them, operating at a higher level. That’s a different kind of person: an engineer, not a programmer or a coder. On the [business analyst] side it’s similar: people took great pride in detailed user stories covering every path. Now it’s conversations, prompts, reviewing output — less doing, more interacting.
“More than ever, they have to be interested in the domain. They can’t just be, ‘I want to learn everything there is to know about Java.’ That’s too narrow. They don’t have to be an expert; they have to be interested. In our case, capital markets is a specific niche. The biggest challenge is getting familiar with the tools — finding time, while delivering for customers, to ramp up and make the mistakes you need to without jeopardizing projects.“
What about governance? Who’s keeping AI delivery and its costs under control?
Erickson: “This is evolving rapidly. People aren’t sure how to put governance around this. The most obvious is financial governance. People are starting to get hefty bills. One of our clients spent a million dollars on tokens over the last eight weeks alone. Sticker shock. The token-maxing policies are starting to show their flaws. It’s wild west still: learn on the fly, then figure out what needs to be governed.“
Are CIOs actually opening their wallets? And when they do, what’s the smarter way to invest?
Erickson: “There’s still a lot of caution. Forecasts keep going down on how long something should take. So: ‘I could wait three months and maybe still get it delivered by the same date someone’s promising me now, but for half the price. I’m going to wait and see when equilibrium is met.’ We haven’t seen the wallets open up like crazy — it’s slow adoption.“
Dolan: “One of our clients is looking at it from a productivity-boost perspective: instead of doing the same for less, I can do much more for the same. AI lets clients pull the trigger on things they wouldn’t have in the past — projects that might not have been approved pre-AI, where the costs have come down to a point that’s palatable with the business.“
Erickson: “And that’s the story we’re hoping to hear more of. There isn’t a huge cost anymore to exploring a business opportunity. The time and money that would have gone to a return-on-investment study could be spent on a proof-of-concept with AI, and the project done a few weeks later. Maybe [there’s] a hint of things to come, where decisions start being made quicker.
“There’s a little fear on our side, though: a lot of tiny little projects is tough for a consulting business.“
Microsoft confirms Windows Server Update Services sync delays
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Critical ServiceNow code execution flaw now exploited in attacks
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



