Computerworld.com [Hacking News]
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw
Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971.
This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update.
Known issuesBoth August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY).
- On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list this, the detail pane removed to address a remote code execution flaw CVE-2025-59287, with no published workaround.
One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers.
Major revisions and mitigationsBetween the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including:
- Windows storage and file system: four NTFS entries, all three July ReFS elevation-of-privilege flaws, and two Brokering File System fixes.
- Identity and federation: six AD FS denial-of-service CVEs, plus two Azure Active Directory entries.
- Developer runtimes: nine .NET and .NET Framework CVEs, with PowerShell and ASP.NET Core alongside.
The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release.
Windows lifecycle and enforcement updatesMicrosoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages.
- Windows Server 2012 and 2012 R2 ESU hits year three. Windows 10 2016 LTSB reaches the end of extended support, and Office LTSC 2021 and retail Office 2021 all end 13 October.
- Windows Server 2022 drops to extended support on 13 October 2026, security-only to 14 October 2031.
One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.
Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping.
Printing, fonts and graphicsThree of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first.
- Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change.
- Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs.
- Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files.
- Exercise the graphics kernel: full-screen DirectX, multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume.
The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside.
- Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another.
- Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end.
- Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart.
The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk.
- Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate.
- Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and BitLocker, and connect USB storage and MIDI devices.
- Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts.
TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow.
- Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3.
- Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive.
This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates:
- On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins.
- On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot.
On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.
- Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy.
- Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions.
- Confirm Autodiscover and free/busy resolve, test any hybrid connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production.
The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the .NET Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms.
- Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions.
The Readiness team recommends the following priorities for your larger enterprise deployments:
- Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else.
- Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN.
- Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack.
- Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check.
Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.
BrowsersAfter July’s 46-strong Microsoft Edge (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments.
Microsoft WindowsWindows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles.
- DHCP and DNS lead the critical-rated issues. Windows DHCP Server takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw (CVE-2026-62823, “Exploitation More Likely”), with DHCP Client adding four more. Windows DNS Server is the headline RCE risk: six entries, four of them critical (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes.
- A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics and Active Directory Certificate Services; domain controllers take priority, and Print Spooler and WSUS are for once absent.
- Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the Telephony Service (11), the DNS client resolver (10), Windows Installer (nine), and the Windows Kernel and NTFS (eight each).
Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first.
Microsoft OfficeMicrosoft released 120 Office CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list Microsoft 365 Apps for Enterprise as affected, 20 of them critical, straight through the update channel.
- Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, CVE-2026-70130, lists Microsoft 365 Apps among its affected builds, so Click-to-Run estates are squarely in scope rather than sitting this one out, as they could in July.
- SharePoint Server – three critical-rated vulnerabilities on the on-premises farms, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side.
Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule.
Microsoft Exchange and SQL ServerExchange Server has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates (KB5121573 through KB5121576). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait.
- Exchange Server (on-premises) – the critical entry is an elevation of privilege (CVE-2026-62911); the heaviest of the rest is a remote code execution (CVE-2026-62913). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration.
- SQL Server – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side.
Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month.
Microsoft developer toolsMicrosoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions.
- Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries (CVE-2026-62897, .NET Framework, and CVE-2026-70354, .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime.
- Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor.
Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities.
Adobe (and third-party updates)Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw (CVE-2026-48449), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry.
OpenAI loses its AI ethics lead
OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported. Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirmed then it will add to the list of OpenAI executives who have quit in recent months.
Other departures include robotics chief Caitlin Kalinowski, who left the company over its deal with the US Department of Defense; researcher Zoe Hitzig, who quit in a very public way by writing an article in the New York Times; and Johannes Heidecke, head of safety systems.
OpenAI’s ethical stance has been called into question following an attack by OpenAI models on Hugging Face.
The departure of its sole ethicist will add to the pressure on the company. In her year at OpenAI Bakalar focused on ethical approaches to model development, looking at how humans interact with AI and examining machine consciousness, according to the FT report.
Bakalar had considerable expertise in the area. She was previously at Meta, where she developed the company’s ethics programs, but has also held several positions at prestigious universities on both sides of the Atlantic. Her departure will cause some anxiety at OpenAI as it continues to prepare the ground for its IPO.
Meta gives up control of Chinese AI startup Manus after eight months
Chinese AI company Manus has laid out its plans to operate as an independent company following the reversal of its acquisition by Meta.
The US social media company agreed to buy Manus last year but Chinese regulators quickly opened an investigation into the deal, as they were concerned that it violated Chinese export controls. In April, China’s National Development and Reform Commission blocked the purchase.
Manus will now revert to being an independent company and to meet with regulatory requirements must delete some user data collected while it was part of Meta, it said Tuesday.
The failure of the deal illustrates the problems that US and Chinese companies are having as they attempt to build a hold on the AI market.
While regulatory authorities in China don’t want Manus under US ownership, US authorities are equally suspicious of China’s role in AI development. The US administration fired a warning shot this March by unveiling a new cybersecurity policy, a move which was prompted by suspected Chinese involvement in a cyber-attack on the FBI.
Also in March, the US-China Economic and Security Review Commission warned that Chinese use of open-source AI tools could lead to an economic advantage that the US couldn’t counter through regulation. And last year, US and Chinese authorities played a cat-and-mouse game over Nvidia chip exports.
Customers of AI vendors in both countries may need to be wary about future cross-border acquisitions as the two superpowers jostle for a technological lead.
Microsoft brings Copilot apps together ahead of ‘super app’ overhaul
Microsoft will bring its two Copilot apps into a unified interface for consumer and work users, part of a wider drive to create a Copilot “super app” that consolidates various features.
Until now, Microsoft has offered two Copilot apps across web, desktop and mobile platforms: a simplified, consumer-focused Copilot app, and Microsoft 365 Copilot, which combines the AI assistant with access to Microsoft’s productivity apps and files.
Microsoft on Thursday announced an “updated Copilot app” aimed at providing a “simpler, more cohesive experience” for personal and work users.
For users of the consumer Copilot app, the update will provide access to Microsoft 365 tools such as Word, Excel, and Outlook from within Copilot, as well as the ability to connect email, calendars and cloud storage. At the same time, some features previously available in the consumer-focused app will be retired, including group chats and Deep Research, though Microsoft 365 Premium subscribers will still have access to a similar research tool called Researcher.
The changes mean consumer Copilot app users will be moved to an updated version of the app starting Aug. 18, with their history and most content carried across.
For Microsoft 365 Copilot work accounts, there’ll be minimal changes aside from a change to the app name and icon, Microsoft said.
As the two apps are brought together, Microsoft said work and personal accounts will remain separate, with security and admin controls remaining in place when users are logged into their Microsoft 365 Copilot account at work:
“Commercial data boundaries, tenant controls, and compliance protections are not changing,” the company said. “The boundaries that keep work and personal separate remain in place: Personal (Microsoft account) and work (Microsoft Entra) accounts are distinct by design. Data entered into the work (Microsoft Entra) experience does not flow into the personal (Microsoft account) experience, and vice versa.”
The changes can be viewed as part of a wider overhaul of Microsoft’s Copilot strategy, which centers around the introduction of a “super app” later this quarter. The plan — rumored for some time and recently confirmed by Microsoft CEO Satya Nadella in an earnings call — is to consolidate various Copilot features, including Copilot Cowork and “autopilot” agents into a single app.
Microsoft has struggled to convince business customers to pay for the Microsoft 365 Copilot since it launched in 2023. The AI assistant costs $30 per user each month in addition to Microsoft 365 subscriptions for enterprises, and $20 per for user a month for smaller firms. (Microsoft does offer promotional discounts.)
Microsoft said earlier this year that it had 15 million paid seats, meaning that only 3.3% of Microsoft 365 customers pay for the tool. That figure has grown however, reaching 30 million paid seats as of last month, the company said.
Apple cracks China with Alibaba for iPhone AI
Apple recently posted and removed details explaining how Mac users in China could set up their computers to work with Alibaba’s Qwen AI. Now, Reuters has confirmed long-held speculation that Apple has revisited its Google Gemini AI playbook and built its own proprietary AI model for China with support from Alibaba.
Apple worked with a Chinese partner because US models such as ChatGPT or Claude are not being made available there, though Chinese AI development doesn’t seem to be held back by that lack. Apple and Alibaba have not commented on the claims, the report said.
The approach echoes Apple’s work with Google to build more advanced large language models (LLMs) for use with Apple Intelligence, and the news will likely be seen as broadly positive by Chinese iPhone users. They can now look forward to working with Apple Intelligence on their devices. The proximity of the reporting suggests they may be able to access Apple’s AI quite soon, once new Apple operating systems ship next month.
The silver liningIt’s also smart, as it means Apple has identified a way to introduce AI features in nations that are becoming protective of their tech stack.And while Apple’s work with Google on Apple Intelligence was widely regarded as signifying how far behind the company had grown on AI, the work it is now doing with Alibaba shows how the partnership approach has become a strategic tool. Basically, Apple found a way to use such development partnerships to navigate protectionism and political rivalry for the benefit of its customers.
The approach means Apple has the distinction of becoming the first foreign company approved to offer a proprietary AI model in China.
The work seems to have begun in February 2025, when Apple and Alibaba submitted co-developed AI features for approval to China’s Internet regulator, the Cyberspace Administration of China. Apple last month crossed a milestone in this work when the regulator finally registered Apple’s service. Apple will work with both Alibaba’s Qwen and tech from Baidu, previous reporting has claimed. It is not yet clear how the work with Baidu will be deployed.
This work supports US presence in ChinaDelivering AI to Chinese customers is strategically vital to Apple. Its products are hugely popular among Chinese consumers and can arguably be seen as an expression of US soft power there. Any erosion of its position also erodes the US reputation in the economically vibrant market.
AI, or the lack of it, has become a fulcrum for change. Morgan Stanley analyst Erik Woodring explained this last year, when he said: “Our survey work shows that Chinese iPhone users are not only more interested in access to genAI technology than US or European iPhone owners, but over 50% of Chinese iPhone owners cited the staggered rollout of Apple Intelligence as having a moderate to significant impact on their decision not to upgrade to a new iPhone this cycle.”
Apple is already struggling with these new competitive pressures. It has been encountering stiff competition from Huawei’s already AI-capable devices in China, with Huawei now the biggest-selling smartphone vendor there.
Apple is also experiencing a seasonal slowdown in sales as shoppers wait on the introduction of the new iPhone Pro range. They expect powerful AI to be baked into the devices they select. “Increasing investment in agentic AI is becoming a competitive necessity rather than a differentiator,” Counterpoint warns.
Good for jobsThere’s also an impact on US employment. While Apple often faces criticism for having some of its assembly done in Asia, rather than the more expensive and inadequately resourced US, outgoing CEO Tim Cook recently explained that the company accounts for more than 400,000 jobs in the US. Many of those jobs are generated by the manufacturing of high-tech parts such as the protective glass used on iPhones.
While the significance may be easy to miss, this also means that any slowdown in device sales in the world’s second-largest economy — China — will also have a negative impact on US employment. Apple, meanwhile, continues to invest in improving US manufacturing skills and infrastructure. The company recently opened its Advanced Manufacturing Center in Houston in the presence of US Secretary of Commerce Howard Lutnick.
“With this Advanced Manufacturing Center, Apple will equip American workers with the skills they need to lead the next generation of technology,” Lutnick said.
Apple, meanwhile, is apparently planning toward introducing its much-anticipated folding iPhone Ultra device initially in America first.
Please join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core for your extensive, hand-curated Apple-related daily news fix.
How to replace Edge as the default browser in Windows — and why you shouldn’t
Microsoft has been struggling to get people to use its Edge browser for years. Even though the company made Edge the default browser in Windows 10, users left in droves, most of them flocking to Google Chrome — and with good reason. The original version of Edge was underpowered, had difficult-to-use features, and offered very few extensions compared to Chrome and Firefox.
But in January 2020, Microsoft launched a new version of Edge that’s based on the same technologies that drive Chrome. (The new Edge is the only one that’s ever been offered in Windows 11.) The Chromium-based Edge is a much better browser, and there are compelling reasons to use it. But you might still prefer to use Chrome, Firefox, or one of the many other browsers out there.
Even if you’ve set up another browser to be your default in the past, it might have been changed since then. When there’s a major Windows upgrade, the installation software recommends switching to Edge, and you might have inadvertently made the switch.
Whatever the reason, if Edge is your default browser in Windows 10 or 11, it’s easy to switch to the browser of your choice. As I’ll show you, it only takes a few minutes.
The instructions in this article assume you’re using either Windows 10 version 22H2 or Windows 11 version 25H2. If you’re using an earlier version, the screens you see may vary somewhat from what you see here.
Why you might want to stick with EdgeIt’s probably worth at least trying out Edge. The browser offers a clean design with intuitive features. One of the biggest drawbacks to the old Edge was its paltry selection of browser extensions, but because the new Edge uses the same rendering engine as Chrome, it can run Chrome extensions, which number in the thousands. Edge also has its own library of extensions.
In my tests, Edge feels faster than Chrome and uses less RAM. It has some interesting features worth trying, such as the ability to launch a website as if it’s an app. And if you prefer Microsoft’s Copilot generative AI chatbot to Chrome’s Gemini, Edge is the logical choice.
All that said, you might not be interested in trying out Edge, or you might try it and decide you still prefer Chrome, Firefox, or another browser. You may, for example, like Firefox’s ability to alert you when a website covertly uses your computer’s processor to mine cryptocurrency in the background, without your knowledge. Or you might like Chrome’s Gemini more than you like Edge’s Copilot.
If you want to use another browser as your default, here’s what to do.
How to designate another browser as your defaultThe first thing you need to do to switch to another browser as your default is to install the other browser on your system. What you do next depends on whether you use Windows 10 or Windows 11.
Changing the default browser in Windows 101. If you’re using Windows 10, click the Start button and then click the Settings icon that appears on the left-hand side of the screen. (It looks like a little gear.) You can alternatively type settings into the search box and click the Settings result that appears at the top of the screen.
2. In the Settings app, select Apps > Default apps. The “Default apps” screen appears. It shows the default apps for email, maps, playing music and videos, viewing photos, and more.
3. To change the default browser, you’ll have to scroll down toward the bottom of your screen. There you’ll see Microsoft Edge under the “Web browser” listing.
4. Click the Microsoft Edge icon and you’ll see a pop-up with a list of your installed browsers.
Select a different browser to be your default.
Preston Gralla / Foundry
Side note: The pop-up also has a “Look for an app in the Microsoft Store” option, but if you click it, you may not find a popular browser you want to install. Clicking it launches a search of the Windows App Store for the term “http.” When I tried it for this article, the only familiar browsers it found were Firefox, Opera, and Edge. Otherwise, there was a motley collection of apps, from file downloaders to an app that dims your Windows background to make it easier to view videos. There are also some little-known browsers listed, such as C Lite Browser and Flash Browser. Try them out if you like, but keep in mind that they’re Windows Store apps, and as a general rule, Windows Store apps are underpowered compared to desktop apps like Chrome, Firefox, and Opera.
5. Click the browser that you’d like to be your default browser. No need to restart; your work is done.
Changing the default browser in Windows 111. In Windows 11, after you’ve installed an alternate browser, click the Start button and then click the Settings icon.
2. In Settings, select Apps > Default apps, then scroll to the browser you want to make your default — for example, Google Chrome.
3. Click the arrow next to it, and at the top of the screen that appears, click Set default.
chrome screen in windows 11 with set default button highlighted" class="wp-image-4203104" width="899" height="465" sizes="auto, (max-width: 899px) 100vw, 899px">Making Google Chrome your default browser in Windows 11.
Preston Gralla / Foundry
4. A checkmark then appears next to “Set default.” To change the default back to Edge or another browser, scroll to the browser you want to be the default and click Set default.
When you do this, some but not all of the file types associated with Edge will become associated with Chrome instead. Below, I’ll show you how to have more than just those file types be opened by your alternate browser.
Some links will still open in EdgeOnce you switch the default browser to something other than Edge, clicking most web links in emails, documents, and most other apps will open them in your new default browser. However, some links associated with web browsing will likely still open in Edge — for example, PDF files, some graphics files such as .svg, mailto links, and more.
You can hunt down each of those file types and links and change them individually to your new default browser, but it’s going to take you time. Here’s how to do it.
Changing link defaults in Windows 101. In Windows 10, go to Settings > Apps > Default apps > Choose default apps by file type.
2. On the screen that appears, scroll through all the file types and look for those still associated with Microsoft Edge — for example, .pdf.
width="634" height="389" sizes="auto, (max-width: 634px) 100vw, 634px">Microsoft Edge is still associated with the .pdf file type on this screen.
Preston Gralla / Foundry
3. Click the Microsoft Edge icon to the right of the file type, and from the screen that appears, select your default browser — for example, Google Chrome.
4. You can alternatively choose to have an app from the Microsoft Store run the file. To do it, click Look for an app in the Microsoft Store and follow the directions.
5. After you’ve done that, go to Settings > Apps > Default apps > Choose default apps by protocol and follow the same steps.
Changing link defaults in Windows 111. In Windows 11, go to Settings > Apps > Default apps and click your default browser — for example, Google Chrome.
2. Scroll through all the file types and protocols, and click any still associated with Microsoft Edge — for example, .pdf.
Change the file types associated with Edge in Windows 11.
Preston Gralla / Foundry
3. On the pop-up screen that appears, select the browser you want to handle the file type (for example, Google Chrome), then click Set Default. Note that you don’t have to choose your default browser for every file type — you can choose another app, such as a PDF reader for .pdf files.
Even after all that, you may still find that clicking links in the Windows interface itself — such as in the Start menu, Windows Search results, or widgets — will open them in Edge. Microsoft changed this behavior in Windows 11 so that all links open in the user-set default browser, but only in Europe. There’s hope for the rest of us, though: sleuths at Windows Latest discovered flags in early preview software indicating that browser choice may be coming to the Start menu and taskbar. Time will tell.
This story was originally launched in September 2017 and most recently updated in August 2026.
Related reading:
DeepSeek raises some V4 prices by more than 10x as AI demand strains capacity
One of AI vendor DeepSeek’s biggest selling points has been its ultra-low price point, but that party’s about to end.
The Chinese model provider is raising API pricing for its V4 model family by notable margins, in some cases by more than 1,100%. The increases may not be that dramatic for all, though; the company is encouraging “more flexible workload scheduling,” with peak rates and half-price off-peak rates.
The news was tucked into the announcement of the general availability (GA) of DeepSeek V4-Pro and upgrades to VR-Flash. The new pricing takes effect for most parts of the world on August 16.
“On paper, at peak, against the right comparator, DeepSeek’s price advantage does disappear, and in places inverts,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. But in practice, “the schedule’s own clock and cache hand most of it back to any buyer paying attention.”
How Flash and Pro compare nowThe new API pricing structure is as follows:
- Flash is now $0.22 per million input tokens (cache miss) and $0.66 per million output tokens off-peak; and $0.44 per million input tokens (cache miss) and $1.32 per million output tokens at peak.
This is up from the flat rate of $0.14 for inputs (cache miss), representing a 57% to 214% increase, and $0.28 per million tokens for outputs, a 136% to 371% increase. - Pro is now $0.66 per million input tokens (cache miss) and $1.98 per million output tokens off-peak; and $1.32 per million input tokens (cache miss) and $3.96 per million output tokens at peak.
This represents an input increase of between 51% and 203% (up from $0.435) and output increase between 127% and 355% (up from $0.87).
Inputs with cache hits, when apps reuse stored prompts rather than processing similar requests from scratch, have even more dramatic pricing increases of 52% to 1,100%.
Mark Tauschek, VP of research fellowships and distinguished analyst at Info-Tech Research Group, pointed out that the increase does eliminate the price advantage that 4.0 Flash has over OpenAI 5.6 Luna at peak pricing, but not at off-peak pricing, as OpenAI has dropped Luna API pricing by 80%, off-peak.
It also doesn’t eliminate Deepseek 4.0 Pro’s price advantage over Terra, OpenAI’s GPT-5.6 mid-tier reasoning model, even at peak pricing, nor its advantage over GPT-5.6 Sol released in July, Tauschek said.
Greyhound Research’s Gogia noted that, off-peak, V4 Flash is “marginally more expensive” on input and 45% cheaper on output than Luna. Pro at peak, meanwhile, runs close to 5x Luna’s price on a representative coding-agent workload.
DeepSeek’s roughly 98% cache-hit discount, against an industry norm nearer to 90%, is the mechanism that has kept its measured cost per task at about 60% below Luna, even after Luna’s cost cut, he said.
“The schedule re-prices exactly that mechanism,” Gogia said. Flash’s edge over Luna decreases from roughly sevenfold to threefold off-peak, and 1.4 times at peak. “The cache is where the advantage genuinely erodes.”
Encouraging users to rethink their schedulesDeepSeek’s V4-Pro is now generally available, and V4-Flash is in beta. Both models have new flexible reasoning capabilities (low, high, max) and ‘thinking modes’ that use chain-of-thought (CoT) reasoning to improve answer accuracy. V4 Pro is now available on app, web, and via API, and users can try it using “Expert Mode.” V4 Flash is now in beta.
The general availability “completes a two-tier structure in which Flash serves volume and Pro is priced for complexity,” Gogia noted.
DeepSeek’s peak/off-peak pricing is a means to “allocate resources more reasonably,” the company said, to encourage users to “schedule their tasks based on actual usage.”
Gogia pointed out that with the new model, 17 of every 24 hours stay at half price, so timing becomes an economic variable, and work that can wait moves into the cheap hours. In fact, the new pricing schedule hits DeepSeek’s home market hardest and its export market lightest; Western buyers largely pay the off-peak rates.
“Usage is following economics at least as much as capability, and economics can change by schedule,” Gogia noted.
Simple supply and demandReading between the lines provides a more nuanced picture, Tauschek noted. “While it’s alarming to see the headlines saying DeepSeek is raising API pricing by 50%-1100%, it doesn’t really tell the whole story.”
Part of that story is demand, which is increasing exponentially. DeepSeek can’t keep up with compute requirements, and Anthropic also had a price increase for the same reason in April. And, while third-party providers have not yet reflected that trend, they’ll eventually have to, Tauschek said.
“This isn’t unexpected at all,” he noted. “It’s simple supply and demand: when demand goes up, pricing goes up, because supply becomes constrained.”
For enterprises that do use DeepSeek (many in the US do not, or can not), the new pricing is not likely to change anything, he said. Cost increases will mostly impact developers, but it will still be less expensive than most alternatives.
He pointed out that enterprises are adapting to model routing, which is critical for developers using agentic workloads. Just a few months ago, organizations were paying per-seat pricing and running up usage as a matter of course, but the market move to usage-based pricing has resulted in sticker shock akin to that of the early cloud days.
“Pricing will continue to be a big deal because CFOs are starting to ask what they’re getting for the massive AI spend,” Tauschek said.
DeepSeek pricing doesn’t change the need for compatibility, multi-modalityCIOs should read the schedule with “relief and unease,” Gogia noted. Relief because the bill is largely schedulable; unease because “a supplier that has learned to price the clock has learned something about its own leverage.”
Going forward, he predicted, Flash keeps the volume usage, Pro handles complexity, and interface compatibility lowers the cost of adoption and departure. The real question becomes whether lower economic floors, open weights, and compatible interfaces, when taken together with multi-model routing, make foundation model intelligence materially easier to substitute.
Capable inference can be produced “far below the price structures that once surrounded frontier AI,” Gogia noted, and open weights mean model developers become one of just several parties able to serve inference requirements. “The traditional software dependency changes shape when that happens,” he said.
The vendor still matters, as do capability and support, but once a workload can move between providers, and enterprises manage their own orchestration and governance, the vendor no longer owns the whole dependency, Gogia said.
The most lasting effect of DeepSeek is unlikely to be that it stayed cheapest, he noted. “It is that every provider must now explain why intelligence should command a premium once near-equivalent capability is available through several technical and commercial routes.”
This article originally appeared on InfoWorld.
How Apple is leaving money on the table
Apple now has a long and storied history in wearables. The Apple Watch set expectations for the category, replacing Swiss watches on so many wrists on its journey to become the world’s most widely worn wearable AI device. But is Apple making the most of the technology it has now developed — and is there another opportunity waiting to be explored?
Apple seems to think there might be. Mark Gurman recently reported the company is exploring a wider family of wearables, including products such as fitness bands and rings. And while the latter certainly represents a viable opportunity, the fitness band market seems ripe for a good bit of Sherlocking.
Why is it ripe?
The technologies Apple already hasFirst, think of the technologies Apple can already bring to a fitness band product. The sensors, algorithms, and software the company has already developed would certainly make sense in wristband form when used with a paired iPhone to review the data the band collects. Apple’s sensors have a good reputation for accuracy and could deliver outstanding battery life. They could carry a smaller display to show limited amounts of information, such as time or distance travelled. And I expect the company’s product design teams could build a high-quality health and fitness band with very little effort, as some of the key technologies to support such a device have already been tried and tested on Apple Watch.
Privacy as a productThe second reason is competitive. Apple knows that in Europe under the Digital Markets Act it will eventually be forced to give third-party devices, including fitness bands, peer access to the kind of data it already uses in the Apple Watch. The company has suggested a protected system in which that information is shared (once it has been cleaned up to protect customer privacy), but EU regulators have not yet agreed – and perhaps never will.
The problem at the moment is that Apple doesn’t make a fitness band other than Apple Watch. And there are enough Apple customers who use third-party bands that the company might see an opportunity to bring its own versionto market as a fitness band that doesn’t erode privacy. Ironically, EU competition regulators have given Apple a reason to compete for a market it didn’t originally want to get into — to the likely detriment of incumbents in the fitness band space.
What customers wantThe third reason is the nature of the market itself. Recent success by the likes of Fitbit Air, Cirqa, or Whoop show growing interest among consumers for screen-free, all-day trackers.
“Consumers want either minimalist, screenless trackers they can wear 24/7 or feature-rich sports watches with superior accuracy and multi-day battery life,” Jason Low, research director at Omdia said in a statement. “Premium and screenless devices are gaining ground, while basic watches and mid-tier smartwatches are being left behind.”
Apple leads the smartwatch side of the equation with a 46% global share, Omdia says, while Garmin (with 15%) posted the biggest share gain among non-Apple vendors. “Garmin’s market share gains highlight a clear trend: consumers are increasingly willing to pay premium prices for devices that deliver accurate, advanced training data and translate it into actionable insights,” Low said.
What Apple offersApple already has its own market-tested technology to provide accurate and advanced fitness monitoring if provided on a screenless device. As its business is not built on selling the data its devices gather, it can supplement those high-quality features with privacy promises some other vendors don’t match, while offering additional features and services through integration at a platform level. Add Siri AI to the mix and access to Apple Music and the device seems even more compelling.
Apple might be motivated to boost attachment rates to customers who will update iPhones, Macs and other Apple devices less frequently in response to recent price increases. The logic is that if customers can’t afford a new iPhone, they might invest in an Apple Watch, AirPods, or fitness band instead, becoming more deeply invested in Apple’s ecosystem as they do.
The potential returns seem promising: the fitness tracker market is expected to $generate 189 billion by 2032. That’s real money Apple already has the tech to take a grab at – and its years of work on colorful Apple Watch bands means it could offer its bands in a wide selection of designs at a price consumers will find they can afford.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
Adobe now lets Workfront users assign tasks to AI agents
With the launch today of the AI Collaborators feature in Workfront, Adobe aims to bring AI agents directly into the flow of work as permissioned team members that can be assigned tasks.
Three types of these ‘collaborators’ are now generally available in Workfront. A content reviewer agent automatically checks documents in the work management app against brand guidelines. A project coordinator tracks project progress and keeps stakeholders up to date.
Then there are “task agents” that let customers connect external AI agents to Workfront and assign them work.
The task agents are geared towards a variety of purposes — a social media manager that turns briefs into published posts, a performance analyst that reports on how campaigns are faring, or a content designer that creates visuals and layouts.
To set up a task agent, users provide a name and description of the agent’s purpose, then connect it to an agent platform, with Anthropic’s Claude, Microsoft’s Copilot Studio, and Writer currently highlighted as options.
Once it’s ready to go, users can assign work to the agent in a Workfront project just as they would a human user.
As the agent carries out its tasks, an auditable trail of actions is recorded via the Workfront “update stream.” That allows humans to review outputs, such as AI-generated copy, and approve or adapt the result as needed.
Only admins are permitted to create AI Collaborators within Workfront.
With the launch of AI Collaborators in Workfront, Adobe’s intention is to deploy AI agents where work actually occurs, said Brent Rudewick, vice president for strategy and product management for Adobe GenStudio and Workfront. That, in turn, can help customers shift AI investments from proof of concept to production.
“The challenge we were solving is: how do we bring an agent into the context of the workflow as an authorized, permissioned user?” said Rudewick. “That’s what an AI Collaborator is.”
In many cases, employees might already use their own AI agents — be that ChatGPT, Claude, Copilot, or other tools. But those agents are removed from important information relating to work tasks, said Rudewick.
“Workfront already has all that context because it’s got the previous briefs you’ve done, the previous content, and it understands the knowledge graph of how that stuff works,” he said. “You’re bringing that agent into a system that already has all of the context: it knows what it needs to go and do, instead of you having to tell it every time you go into one of those other surfaces.”
“This is a step in Adobe’s evolution of AI and automation capabilities,” said Jessica Liu, principal analyst at Forrester. “It follows in the direction of the overall technology market.”
Marketers are looking to automation to gain efficiency, she said, though effectiveness is “unfortunately more of an afterthought at the moment.”
Any automation benefits will depend on organizations having well-designed processes and workflows, Liu said. “Technology that can support marketers in those efforts is helpful, but only if marketers can help themselves first,” she said. “Specifically, they need to have processes and workflows that are diagnosed, scoped, designed, implemented, and optimized. It’s very difficult to automate a process or workflow that is broken or non-existent.”
At the same time, Adobe wants to make it easier for Workfront users to access the feature from third-party AI agent tools via a model context protocol (MCP) client. At launch, this enables users to take actions such as creating a campaign record, assigning work, approving content and more from ChatGPT, Claude, Copilot and others.
“We want to give choice to the customer,” said Rudewick. “If the enterprise has decided, ‘Hey, Claude is the predominant surface we’re going to use,’ we want them to be able to use that surface and not be blocked to get the value that they have in their application investment in Workfront.
“If you boil Workfront down to its most rudimentary sense, it’s a campaign, it’s a project, it’s a task, it’s an assignment, and it’s an approval — that’s really what Workfront is, so how do we expose that through whatever surface?”
The emergence of AI tools that can perform tasks on behalf of users has been viewed as a threat to software companies such as Adobe. But even as Adobe opens Workfront up to third-party AI platforms, Liu believes the company’s AI investments can help ensure customers remain in the Adobe app.
“For marketers who use many Adobe products, having Workfront AI Collaborators operate within Adobe’s ecosystem should be easier for data transfer, access management, and user interface and experience,” said Liu.
AI Collaborators are available at no additional cost to Workfront customers (Adobe does not publish Workfront prices). However, using the “task agent” AI Collaborator could incur additional costs for third-party agents that connect to Workfront.
It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.
Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.
“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s Omri Baso told CSO.
The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.
Microsoft fixed the initial authorization flaw, tracked as CVE-2026-47301, in July, but Baso said the remaining links in the chain are not expected to be fully addressed until ConfigMgr 2609, planned for October.
The patch did not patchThe initial foothold comes from SCCM’s AdminService API. Its normal extension-upload endpoint checks whether a user has the required permission, but its “chunked-upload” counterpart does not. That allows an authenticated Active Directory user to submit a malicious CAB archive without SCCM administrative privileges.
Microsoft’s July fix blocks that route for standard domain users. However, the downstream chain remains reachable through another path. Users assigned the built-in Operations Administrator role, or a custom role with Create permission on “SMS_ConsoleExtensionData,” can still trigger the same sequence.
But there is an important qualification here. XM Cyber said it believes organizations are unlikely to be exposed through the Operations Administrator route because it is already a highly privileged role.
Once the CAB reaches the server, CabSlip allows files to escape the intended temporary extraction directory and be written elsewhere on the filesystem. The attacker can use this arbitrary file-write capability to replace “adsource.dll,” a secondary library loaded by the SYSTEM-level SMS Executive service without its own signature check.
When the service subsequently loads the DLL, the attacker gets code execution as SYSTEM.
A $58 certificate can cross the trust boundaryThe chain becomes particularly notable because SCCM’s signature validation does not establish that the signing certificate belongs to Microsoft or the target organization. It checks that the signature is structurally valid and non-expired, while revocation checks are disabled.
That means an attacker does not need an enterprise certificate. XM Cyber said the attack depends on a code-signing certificate and can also abuse certificates leaked online. For his own research, Baso used a Certum Open Source Developer Certificate that cost about $58.
For defenders, XM Cyber recommends restricting network access to the AdminService API and auditing SCCM RBAC assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.
Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.
Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.
Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.
The article originally appeared on CSO.
OpenAI: Latest news and insights
OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond.
A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over copyright infringement, and frequent product announcements keep OpenAI in the news. Follow this page and never miss a beat.
Latest Open AI news and analysis: OpenAI targets heavy users with premium ChatGPT Business seatsAug. 11, 2026: OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads.
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowAug. 11, 2026: OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsAug. 10, 2026: OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.
OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidentsAug. 5, 2026: OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute.
OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%July 31, 2026: OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models consume in ChatGPT Work and Codex, in an effort to effectively increase the amount of AI work enterprise subscribers can perform without paying more.
OpenAI rogue AI agent’s attack expanded beyond Hugging FaceJuly 29, 2026: The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.
Hugging Face breach shows why incident response needs a multi-model AI strategyJuly 28, 2026: The recent breach of Hugging Face’s platform by an internal OpenAI test of advanced model cyber capabilities that went wrong was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains.
Hugging Face CEO wants transparency after OpenAI’s AI incidentJuly 27, 2026: Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.
OpenAI not part of the new Open Secure AI AllianceJuly 27, 2026: A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defence.
OpenAI Presence raises new questions about enterprise automation and jobsJuly 23, 2026: OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.
OpenAI model escape puts enterprise AI defenses on noticeJuly 22, 2026: An attack on Hugging Face executed by a sandboxed OpenAI model shows that prompt guardrails cannot serve as the main security boundary for AI agents, putting more pressure on enterprises to contain them through infrastructure controls that limit access and prevent lateral movement.
OpenAI’s Codex context reduction for GPT 5.6 sparks dissatisfaction among developersJuly 20, 2026: OpenAI’s recent update to its Codex coding agent has developers worrying over the impact of the change on large code repositories and long-running AI-assisted sessions. The update to the Codex CLI reduces the default configured input context window for GPT-5.6 to 272,000 tokens from 372,000 tokens.
OpenAI’s new hardware is a $230, 13-switch keyboard for CodexJuly 17, 2026: OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.
OpenAI’s GPT-5.6 may accidentally delete filesJuly 17, 2026: OpenAI said its latest large language model GPT-5.6-Sol can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”
OpenAI launches ChatGPT Work as it broadens GPT-5.6 rolloutJuly 10, 2026: OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.
OpenAI to release delayed models amidst a sea of regulatory confusionJuly 8, 2026: As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, highlights the confusion.
US tells OpenAI to restrict access to its most powerful AI modelJune 26, 2026: US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on OpenAI.
OpenAI rolls out AI-led push to fix open-source software flawsJune 23, 2026: OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.
OpenAI gets the attention it needs from AI researcher Noam ShazeerJune 19, 2026: OpenAI has lured Noam Shazeer, one of the eight co-authors of the influential AI paper Attention Is All You Need, away from Google.
OpenAI adds spend controls and usage analytics to ChatGPT EnterpriseJune 19, 2026: OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits.
ChatGPT will soon be able to shop with your Visa cardJune 16, 2026: OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.
OpenAI buys Ona to help rein in AI agentsJune 12, 2026: OpenAI has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly.
OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campusJune 10, 2026: OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.
OpenAI’s Lockdown Mode is trying to solve the problem that it createdJune 9, 2026: OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.
OpenAI responds to White House executive order on AI governanceJune 4, 2026: OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.
OpenAI fixed a visibility problem; the governance problem remainsJune 3, 2026: OpenAI’s new ChatGPT session controls improve visibility, but experts say continuous model updates are creating a far bigger challenge for enterprise risk and compliance teams.
Attack targeting OpenAI Codex users exposes AI software supply chain risksJune 2, 2026: A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository.
AI models more vulnerable than claimed when faced with iterative attacksMay 27, 2026: According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmarked using single prompts.
OpenAI introduces Daybreak cyber platform, takes on Anthropic MythosMay 12, 2026: OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.
OpenAI’s new AI consulting offering raises questions of trust, strategyMay 11, 2026: The OpenAI Deployment Company aims to help organizations build and deploy AI systems by embedding engineers specializing in frontier AI deployment, known as forward deployed engineers (FDEs), into their environments.
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloadsMay 11, 2026: A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.
OpenAI-led consortium seeks to address AI processing bottlenecksMay 8, 2026: An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol, Multipath Reliable Connection (MRC), designed to address network congestion, a problem that has always existed but has been exacerbated by the massive amounts of data required for AI processing.
OpenAI, Anthropic expand services push, signaling new phase in enterprise AI raceMay 6, 2026: OpenAI and Anthropic are expanding their reach into professional services through joint ventures and acquisition talks, moving model providers closer to implementation roles traditionally held by systems integrators.
OpenAI’s Symphony spec pushes coding agents from prompts to orchestrationApril 28, 2026: OpenAI has released Symphony, an open-source specification for turning issue trackers such as Linear into control planes for Codex coding agents.
Microsoft, OpenAI change contract terms — againApril 27, 2026: Microsoft and OpenAI have again revised their agreement, softening their exclusivity and revenue-sharing conditions in the process.
OpenAI pulls out of a second Stargate data center dealApril 15, 2026: In the space of one week, OpenAI has pulled out of two European Stargate data center deals, one in the UK and the other in Norway.
OpenAI puts part of Stargate project on hold over runaway power costsApril 10, 2026: OpenAI has postponed plans to open one of the data centers central to its Stargate project.
OpenAI calls for a four-day workweek — and a ‘robot tax’April 7, 2026: In a new policy paper, OpenAI makes some interesting proposals to address the impact of AI on the labor market.
Microsoft builds its own AI stack to help wean it from its reliance on OpenAIApril 2, 2026: Microsoft seems to be meeting OpenAI on its own turf, even as it continues its strategic partnership with the AI darling, with the release of three in-house, commercially-available AI models.
OpenAI patches twin leaks as Codex slips and ChatGPT spillsMarch 31, 2026: OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways.
OpenAI adds plugin system to Codex to help enterprises govern AI coding agentsMarch 27, 2026: OpenAI has introduced a plugin system for Codex, its AI-powered software engineering platform, giving enterprise IT teams a way to package coding workflows, application integrations, and external tool configurations into versioned, installable bundles that can be distributed or blocked across development organizations.
OpenAI’s Sora exit signals enterprise-first AI shiftMarch 25, 2026: OpenAI has discontinued its AI video generation platform Sora. The company announced the development in a sudden and unexpected post on X, stating that it was “saying goodbye” to the Sora app.
OpenAI’s Foundation play reframes the AI roadmap for IT leadersMarch 24, 2026: The OpenAI Foundation has announced a sweeping range of investment and research goals, from building safeguards around how AI behaves in the wild to pushing for shared data ecosystems and funding disease research.
OpenAI to double workforce, highlights growing demand for enterprise AI talentMarch 23, 2026: OpenAI is planning to almost double its workforce from about 4,500 to 8,000 employees by the end of 2026. The move comes as OpenAI sharpens its focus on scaling and monetising ChatGPT for enterprise use amid intensifying competition from Anthropic and Google.
OpenAI’s desktop superapp: The end of ChatGPT as we know it?March 20, 2026: OpenAI is reportedly planning to fold its ChatGPT application, Codex coding platform, and AI-powered browser into a single desktop ‘superapp’, a move that signals a shift toward enterprise and developer audiences and away from the consumer market that made the company a household name.
OpenAI buys non-AI coding startup to help its AI to programMarch 19, 2026: OpenAI has acquired Astral, the developer of open source Python tools including uv, Ruff and ty, and plans to integrate them with Codex, its AI coding agent.
OpenAI’s $50B AWS deal puts its Microsoft alliance to the testMarch 17, 2026: Microsoft is considering legal action against OpenAI and Amazon over the $50 billion cloud deal the two recently struck to make Amazon Web Services (AWS) the exclusive third-party cloud distribution provider for OpenAI Frontier.
Encyclopedia Britannica sues OpenAI over AI trainingMarch 17, 2026: Encyclopedia Britannica and its subsidiary Merriam-Webster have sued OpenAI, claiming the generative AI firm used their encyclopedia and dictionary texts to train AI models such as ChatGPT without permission.
OpenAI to acquire Promptfoo to strengthen AI agent security testingMarch 10, 2026: OpenAI said it plans to acquire AI testing startup Promptfoo, a move aimed at strengthening security checks for AI agents as enterprises move toward deploying autonomous systems in business workflows.
OpenAI robotics chief quits over Pentagon dealMarch 9, 2026: Caitlin Kalinowski has resigned over OpenAI’s contract with the US Department of War, saying key safeguards around domestic surveillance and autonomous weapons were not adequately reviewed before the agreement was signed.
OpenAI says Codex Security found 11,000 high-impact bugs in a monthMarch 9, 2026: OpenAI’s new AppSec agent, Codex Security, has already flagged over 11,000 high-severity and critical flaws in real-world codebases during its first 30 days of research testing. The tool is designed to automatically find, validate, and fix vulnerabilities in software repositories.
OpenAI says its US defense deal is safer than Anthropic’s, but is it?March 2, 2026: OpenAI has struck a deal to supply the US government with AI services, announcing it hours after US President Donald Trump’s decision to ban its AI rival Anthropic from all US government contracts.
OpenAI partners with consulting giants to deploy enterprise AI agentsFebruary 26, 2026: As it bids to push further into the enterprise, OpenAI announced that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co.
OpenAI hires OpenClaw founder as AI agent race intensifiesFebruary 16, 2026: OpenAI has hired Peter Steinberger, creator of the viral OpenClaw AI assistant, to spearhead development of what CEO Sam Altman describes as “the next generation of personal agents.”
OpenAI responds to Claude Cowork with its own platform for AI agentsFebruary 5, 2026: Anthropic released 11 open-source plugins that enable Claude Cowork to execute a series of automated processes in areas ranging from customer support to IT operations, OpenAI responded Thursday with a similar platform it calls Frontier.
Who profits from AI? Not OpenAI, says think tankJanuary 29, 2026: Findings from a new study by Epoch AI, a non-profit research institute, seeks to answer three questions: How profitable is running AI models? Are models profitable over their lifecycle? Will AI models become profitable?
Will the Microsoft-Anthropic deal leave OpenAI out in the cold?January 27, 2026: Microsoft wasted little time after reaching a deal to finalize its new relationship with OpenAI to find a new AI dance partner — Anthropic, the second most valuable AI startup in the world. It appears as if Microsoft sees a future with Anthropic that’s at least as valuable as the one it had with OpenAI.
OpenAI to add age verification to ChatGPTJanuary 21, 2026: OpenAI has adding age verification to ChatGPT following reports that several children and young people have taken their own lives after conversations with the popular chatbot. The move echoes a recent decision by TikTok to do the same thing to protect underage users from accessing inappropriate content.
Musk’s OpenAI lawsuit clears path to trial, putting Microsoft in the spotlightJanuary 9, 2026: A federal judge has signalled that Elon Musk’s lawsuit challenging OpenAI’s transformation to a for-profit entity will proceed to trial, adding legal uncertainty for enterprise customers that have built AI strategies around the ChatGPT maker’s technology.
OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacyDecember 12, 2025: OpenAI has released GPT-5.2, claiming significant gains in the AI model’s ability to complete real-world business tasks to an “expert level” compared to GPT-5.1, released in November. The new model offers major improvements across a range of benchmarks, the company said.
What does OpenAI’s ‘Code Red’ warning mean for Microsoft?December 10. 2025: OpenAI founder and CEO Sam Altman sent out a memo to OpenAI employees declaring a “Code Red” emergency and focusing all company efforts on improving ChatGPT. The reason? Google’s newly released Gemini 3 model beat the pants off GPT-5.1
OpenAI to acquire AI training tracker NeptuneDecember 3, 2025: OpenAI has agreed to acquire Neptune, a startup specializing in tools for tracking AI training. Neptune promptly announced it is withdrawing its products from the market.
OpenAI admits data breach after analytics partner hit by phishing attackNovember 27, 2025: OpenAI suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.
OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalizationNovember 13, 2025: OpenAI has introduced GPT-5.1, an update to its GPT-5 model, aiming to deliver faster responses, improved reasoning, and more flexible conversational controls as the company works to refine its ChatGPT experience for both consumer and enterprise users.
OpenAI spends even more money it doesn’t haveNovember 3, 2025: OpenAI’s overdraft continued its upward trajectory today when the company signed a multi-year $38 billion contract with AWS to have it run its AI workloads. The latest spending spree adds to the incremental $250 billion of Azure services it pledged to buy last week, and, of course, to the commitment it has made towards building Stargate data centers with Oracle.
OpenAI seeks to automate ‘computer use’ for Macs in the enterpriseOctober 24, 2025: While AI bots have begun mastering tasks in browsers and on Windows, Mac-using enterprises have largely been overlooked, until now. OpenAI aims to change that with its acquisition of generative AI interface maker Software Applications Incorporated.
Enterprises should not install OpenAI’s new Atlas browser, analysts warnOctober 24, 2025: Companies that might be eyeing OpenAI’s new ChatGPT Atlas browser should not rush to use it because of potential security risks, analysts said this week. The browser was unveiled on Tuesday after it had been teased for months as a work in progress. It is currently available for MacOS only.
Has OpenAI shown us a future for Safari?October 23, 2025: Has OpenAI shown us the future of Safari? In one way it has, because its new Atlas browser shows these generative AI (genAI)-based apps are no longer just windows to the web — they’re becoming intelligent copilots for our digital lives.
OpenAI–Broadcom alliance signals a shift to open infrastructure for AIOctober 14, 2025: OpenAI has partnered with Broadcom to co-develop and deploy its first in-house AI processors. The move could reshape data center networking dynamics and chip supply strategies as the ChatGPT maker races to secure more computing power for AI workloads.
OpenAI Codex rivals Claude CodeOctober 13, 2025: The OpenAI Codex gives software developers a first-rate coding agent in their terminal and their IDE, along with the capability to delegate background tasks to agents in the cloud.
OpenAI Codex adds SDK, admin tools, Slack integrationOctober 10, 2024: Codex is now generally available. Since being launched as a research preview in May, Codex, OpenAI’s AI-powered software engineering agent that can work on tasks in parallel, has added Slack integration, an SDK, and admin tools.
OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flawsSeptember 18, 2025: OpenAI, the creator of ChatGPT, acknowledged in its own research that large language models will always produce hallucinations due to fundamental mathematical constraints that cannot be solved through better engineering.
OpenAI, Microsoft discuss shape of future relationshipSeptember 12, 2025: Microsoft and OpenAI are in talks about the future of their partnership, they said in a joint statement , without providing details. Separately, OpenAI said it wants to go ahead with its previously announced plan to turn its for-profit business into a public benefit corporation, in which its nonprofit organization would own a $100 billion stake.
What Oracle’s $300B OpenAI deal means for enterprise cloud strategySeptember 11, 2025: A single $300 billion contract has seemingly transformed Oracle from a traditional ERP and database vendor into a cloud computing powerhouse.The company has signed a five-year computing power commitment with OpenAI, contributing to a reported 359% surge in future contract revenue this quarter.
OpenAI acquires Statsig to speed up generative AI-based product launchesSeptember 3, 2025: OpenAI is acquiring Statsig, a Washington-based product development platform startup, for $1.1 billion to speed up its generative AI-based product launches and accelerate iteration cycles of existing products such as Codex and ChatGPT.
OpenAI drops GPT-5: smarter, sharper, and built for the real worldAugust 7. 2025: More than two years after GPT-4’s release, OpenAI has unveiled GPT-5, boasting sharper reasoning, multimodal input, better math skills, and cleaner task execution, according to the company.
OpenAI challenges rivals with Apache-licensed GPT-OSS modelsAugust 6, 2025: OpenAI has released its first open-weight language models since GPT-2, marking a significant strategic shift as the company seeks to expand enterprise adoption through more flexible deployment options and reduced operational costs. The two new models — gpt-oss-120b and gpt-oss-20b — deliver what OpenAI describes as competitive performance while running efficiently on consumer-grade hardware.
Google snatches Windsurf execs in a $2.4B deal, derailing OpenAI’s biggest acquisition yetJuly 14, 2025: Google has recruited CEO Varun Mohan and co-founder Douglas Chen of AI coding startup Windsurf in a $2.4 billion talent acquisition deal, just two months after Windsurf agreed to be acquired by OpenAI for $3 billion. Mohan, Chen and select research and development staff, will join Google’s DeepMind AI division
OpenAI and Perplexity enter browser wars to take on ChromeJuly 10, 2025: Google Chrome’s dominance in the browser market is facing new threats as OpenAI and Nvidia-backed Perplexity unveil AI-powered browsers aimed at reshaping how users interact with the web. Comet is a new web browser with built-in AI search capabilities, the company said.
Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents
July 8, 2025: Microsoft added OpenAI-developed Deep Research capability to its Azure AI Foundry Agent service. The move is designed to let developers use Deep Research API and SDK to embed, extend, and orchestrate Deep Research-as-a-service across data and existing systems.
Oracle to power OpenAI’s AGI ambitions with 4.5GW expansionJuly 3, 2025: OpenAI has signed a significant compute leasing deal with Oracle, under which it will access 4.5 gigawatts (GW) of data center power, marking one of the largest single leasing arrangements in the industry.
OpenAI tests Google TPUs amid rising inference cost concernsJuly 1, 2025: OpenAI has begun testing Google’s Tensor Processing Units (TPUs), a move that — though not signaling an imminent switch — has raised eyebrows among industry analysts concerned about the escalating costs of AI inference and its effects.
Microsoft/OpenAI AGI argument unlikely to impact enterprise ITJune 26, 2025: The contract between the two AI giants has an exit clause once AGI is achieved. The problem: It is impossible to prove when that happens. Either way, IT execs at Macy’s, Bank of America, doubt it will matter.
OpenAI productivity suite could change the way users create documentsJune 26, 2025: OpenAI’s planned productivity suite could dismantle traditional habits of how users create and consume documents in the same the way the company changed browsing and search habits.
o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests itJune 24, 2025: In a head-to-head comparison of the two models, researchers found that o3-pro is far less performant, reliable, and secure, and does an unnecessary amount of reasoning. Notably, o3-pro consumed 7.3x more output tokens, cost 14x more to run, and failed in 5.6x more test cases than GPT-4o.
Microsoft and OpenAI: Will they opt for the nuclear option?June 24, 2025: The fight between Microsoft and OpenAI over what Microsoft should get for its $13 billion investment in the AI company has gone from nasty to downright toxic, with each of the companies considering strategies against the other that can only be described as their nuclear options.
OpenAI walks away from Scale AI — triggering industry-wide rethink of data partnershipsJune 19, 2025: OpenAI has ended its long-standing partnership with Scale AI, the company that powered some of the most complex data-labeling tasks behind frontier models such as GPT-4.
OpenAI’s o3 price plunge changes everything for vibe codersJune 18, 2025: o3 used to be too slow and too expensive for daily coding—no longer. The latency is now bearable, the price is sane, and the chain-of-thought pays off.
Sam Altman: Meta tried to lure OpenAI employees with billion-dollar salariesJune 18, 2025: After reports suggested Meta has tried to poach employees from OpenAI and Google Deepmind by offering huge compensation packages, OpenAI CEO Sam Altman weighed in, saying those reports are true.
OpenAI-Microsoft tensions escalate over control and contractsJune 17, 2025: The relationship between OpenAI and Microsoft is under growing strain amid extended talks over OpenAI’s restructuring, with OpenAI reportedly considering antitrust action over Microsoft’s influence in the partnership.
OpenAI’s MCP move tempts IT to trust genAI more than it shouldJune 16, 2025: OpenAI late last month announced changes to make it much easier to give its genAI models full access to any software using Model Context Protocol (MCP). Here’s why that’s a bad idea.
OpenAI launches o3-pro, slashes o3 price by 80% in bid to widen AI leadJune 11, 2025: OpenAI has unveiled its most advanced AI model to date, the o3-pro, which surpasses competitors on key benchmarks and replaces the o1-pro. The o3-pro is now available for ChatGPT Pro and Team users, as well as through the developer API, with access for enterprise and education sectors beginning next week.
What Microsoft hopes to get from its breakup with OpenAIJune 11, 2025: The once-tight bond between Microsoft and OpenAI has been fraying for well over a year — and it’s getting worse. What the two companies want from each other now is very different from when Microsoft made its original $13 billion investment.
Oracle to spend $40B on Nvidia chips for OpenAI data center in TexasMay 26, 2025: Oracle is reportedly spending about $40 billion on Nvidia’s high-performance computer chips to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.
OpenAI’s Skynet moment: Models defy human commands, actively resist orders to shut downMay 30, 2025: OpenAI’s most advanced AI models are showing a disturbing new behavior: they are refusing to obey direct human commands to shut down, actively sabotaging the very mechanisms designed to turn them off.
Jony Ive and OpenAI plan ‘bicycles’ for 21st-century mindsMay 21, 2025: OpenAI has announced that it will purchase io, the AI startup founded by acclaimed former Apple designer Sir Jony Ive, who helped create the iMac, iPod, and iPhone.
OpenAI launches Codex AI agent to tackle multi-step coding tasksMay 19, 2025: OpenAI’s most advanced AI coding agent, Codex, will bring parallel task automation to developers—but analysts caution that speed without scrutiny invites “silent failures.”
Cisco taps OpenAI’s Codex for AI-driven network codingMay 16, 2025: Cisco is working with OpenAI and its newly released Codex software engineering agent to give network engineers access to better tools for writing, testing and building code.
OpenAI’s IPO aspirations prompt rethink of Microsoft allianceMay 12, 2025: Microsoft and OpenAI are renegotiating their multibillion-dollar partnership deal to better align with each company’s evolving goals in the artificial intelligence race
OpenAI hires Instacart CEO Fidji Simo to oversee customer-facing appsMay 8, 2025: The hire indicates that OpenAI’s roadmap will involve more structured, productized offerings rather than just API access.
OpenAI offers help promoting AI outside the US, but analysts question why countries would acceptMay 7, 2025: OpenAI, acting as part of the US government-led Stargate AI project, rolled out a program called OpenAI for Countries. The idea is for Stargate to help other countries create their own genAI environments, including data centers and genAI models.
OpenAI reaffirms nonprofit control, scales back governance changesMay 6, 2025: OpenAI has scrapped plans to reduce its nonprofit parent’s oversight and will keep its existing governance structure intact, a move that limits CEO Sam Altman’s influence and responds to mounting external pressure.
OpenAI to acquire AI coding tool Windsurf for $3BMay 6, 2025: The acquisition comes just months after Windsurf explored funding at this same valuation from investors, highlighting the premium being placed on specialized AI coding capabilities, according to reports.
Former OpenAI employees urge regulators to halt company’s for-profit shiftApril 23, 2025: A broad coalition of AI experts, economists, legal scholars, and former OpenAI employees is urging state regulators to keep OpenAI’s nonprofit foundation in control of the company.
OpenAI’s new models can ‘think with pictures’April 17, 2025: OpenAI has released o3 and 04-mini, two reasoning AI models designed to be extra good at programming, math, and science and that can use images to “think,” according to Engadget, This means that users can upload sketches or diagrams, for example, and even if they are of low quality, o3 and 04-mini will understand what is meant.
OpenAI GPT-4.1 models promise improved coding and instruction followingApril 15, 2025: The GPT-4.1, GPT-4.1 mini, and GPT-4.1 nano models, available only via the API, will provide better performance than GPT-4o and GPT-4o mini at a lower price, OpenAI said.
OpenAI slammed for putting speed over safetyApril 11, 2025: According to a Financial Times report, the ChatGPT maker is now assigning staff and third-party groups only a few days to assess the risks and performance of its latest large language models (LLMs) as compared to several months they were given earlier.
OpenAI fears irreparable harm from Musk, files countersuitApril 10, 2025: OpenAI has filed a countersuit against Elon Musk, accusing the billionaire of a sustained campaign to damage the company and urging a US federal court to block further actions it described as unlawful and disruptive. The legal filing, submitted in a California district court, marks the latest escalation in a dispute between Musk and the AI startup he helped establish in 2015.
Senators probe Google-Anthropic, Microsoft-OpenAI deals over antitrust concernsApril 9, 2025: Democratic Senators Elizabeth Warren and Ron Wyden have launched a formal inquiry into partnerships between tech giants Google and Microsoft, and AI startups, demanding detailed information about arrangements they fear may be circumventing antitrust scrutiny while consolidating power in the rapidly evolving AI market.
Anthropic’s and OpenAI’s new AI education initiatives offer hope for enterprise knowledge retentionApril 4, 2025: Two of the biggest names in artificial intelligence are independently developing new AI tools that encourage learning, at a time when the technology has been criticized for dumbing down smart users in the enterprise and discouraging critical thinking. While the new initiatives from OpenAI and Anthropic are aimed at transforming how AI is used in higher education, the opportunities they open up extend beyond universities.
Amazon, OpenAI, and China’s Zhipu unveil new AI tools amid intensifying competitionApril 1, 2025: A wave of new AI products is hitting the market, signaling a shift toward more autonomous, task-completing systems that could reshape how businesses and consumers interact with digital services: Amazon has unveiled Nova Act, an AI agent designed to operate a web browser much like a human user; OpenAI said it will release an open-weight language model; and China’s Zhipu AI introduced a free AI assistant aimed at strengthening its position in the domestic market and competing with Western tech giants.
OpenAI, Google AI data centers are under stress after new genAI model launchesMarch 28, 2025: New generative AI models introduced by Google and OpenAI have put the companies’ data centers under stress — and both companies are trying to catch up to demand. OpenAI’s CEO Sam Altman tweeted that his company was temporarily restricting the use of GPUs after overwhelming demand for its image generation service on ChatGPT.
Microsoft abandons data center projects as OpenAI considers its own, hinting at a market shiftMarch 26, 2025: OpenAI has privately discussed building and operating its first data center to house storage, which is essential for developing sophisticated AI models. Microsoft, on the other hand, has pulled back on its buildouts, canceling data center projects in the US and Europe.
OpenAI calls for US to centralize AI regulationMarch 13, 2025: OpenAI executives think the federal government should regulate artificial intelligence in the US, taking precedence over often more restrictive state regulations.
New tools from OpenAI help companies create their own AI agentsMarch 12, 2025: OpenAI launched Responses, a new api intended to eventually replace Assistants. The big draw? Responses provides a number of new tools that companies and organizations can use to create their own AI agents.
Microsoft is developing its own AI models to compete with OpenAIMarch 10, 2025: Reports suggest Microsoft has decided to seriously challenge Deepseek and OpenAI by developing its own set of reasoning AI models called Microsoft AI (MAI). If successful, Microsoft would eventually not have to use its partner OpenAI’s o1 models in Copilot
Microsoft-OpenAI investigation closed by UK regulatorsMarch 5, 2025: The UK’s Competition and Markets Authority (CMA) spent a great deal of time deciding whether it should investigate Microsoft’s investment in OpenAI as a potential merger situation, but in the end, decided to open and close the investigation within 24 hours.
OpenAI revamps AI roadmap, merging models for a leaner futureFebruary 13, 2025: OpenAI will integrate “o3” into GPT-5 instead of releasing it separately, streamlining adoption while signaling a shift toward fewer, more controlled AI models amid rising competition and cost pressures.
Musk’s $97B offer to buy OpenAI rejected as leadership stands firmFebruary 11, 2025: In a message to staff, Altman said the board has no intention of considering Musk’s offer, stating that the proposal does not align with OpenAI’s mission
OpenAI launches deep research agent for multi-step research tasksFebruary 3, 2025: Hot on the heels of its launch of the o3-mini model, OpenAI announced another component for ChatGPT that allows the generative AI tool to do more in-depth research. “Deep research is built for people who do intensive knowledge work in areas like finance, science, policy, and engineering and need thorough, precise, and reliable research,” OpenAI said in a blog post announcing the new capability.
OpenAI unleashes o3-mini reasoning modelJanuary 31, 2025: OpenAI released the latest model in its reasoning series, o3-mini, both in ChatGPT and its application programming interface (API). It had been in preview since December 2024.
Indian media houses rally against OpenAI over copyright disputeJanuary 27, 2025: The legal heat on OpenAI in India intensified as digital news outlets owned by billionaires Gautam Adani and Mukesh Ambani joined an ongoing lawsuit against the ChatGPT creator. They were joined by some of the largest news publishers in India including the Indian Express, and Hindustan Times, and members of the Digital News Publishers Association (DNPA), which includes major players like Zee News, India Today, and The Hindu.
Altman now says OpenAI has not yet developed AGIJanuary 20, 2025: Confusion over whether OpenAI’s o3-mini has reached the major milestone of artificial general intelligence (AGI) or not deepened following a post on X by CEO Sam Altman that completely contradicts what he said two weeks earlier in an interview with Bloomberg.
Microsoft sues overseas threat actor group over abuse of OpenAI serviceJanuary 13, 2025: Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.
With o3 having reached AGI, OpenAI turns its sights toward superintelligenceJanuary 6, 2025: OpenAI CEO Sam Altman has reinvigorated discussion of artificial general intelligence (AGI), boldly claiming that his company’s newest model has reached that milestone.
Now US government agencies can use OpenAI’s ChatGPT tooJanuary 28, 2025: OpenAI has rolled out ChatGPT Gov, a version of its flagship frontier model specifically tailored to US government agencies. The platform has many of the same capabilities as OpenAI’s other enterprise products, including access to GPT-4o and the ability to build custom GPTs — and it also features a much higher level of security than ChatGPT Enterprise.
OpenAI debuts AI agent Operator to transform web task automationJanuary 24, 2025: OpenAI has unveiled “Operator,” a new AI agent designed to perform web-based tasks, offering potential productivity enhancements for enterprises. The tool enables interaction with on-screen elements, positioning it as a solution for automating routine processes in business workflows amid growing competition in the generative AI space.
OpenAI opposes data deletion demand in India citing US legal constraintsJanuary 23, 2025: OpenAI has informed the Delhi High Court that any directive requiring it to delete training data used for ChatGPT would conflict with its legal obligations under US law. The statement came in response to a copyright lawsuit filed by the Reuters-backed Indian news agency ANI, marking a pivotal development in one of the first major AI-related legal battles in India.
OpenAI, SoftBank, Oracle lead $500B Project Stargate to ramp up AI infra in the USJanuary 22, 2025: Several large technology firms including OpenAI, SoftBank, Oracle, Nvidia, and MGX have partnered to set up a new company in the US to ramp up AI infrastructure in the country.
OpenAI is losing money on its pricey ChatGPT Pro subscriptionJanuary 7, 2025: OpenAI CEO Sam Altman, in a post on X, says the AI company is currently losing money on its ChatGPT Pro subscription. “People are using it much more than we expected,” he wrote.
Fine-tuning Azure OpenAI models in Azure AI FoundryJanuary 2, 2025: Microsoft Azure’s new AI toolkit makes it easy to customize OpenAI large language models for your applications.
OpenAI still hasn’t released tools to deny data collectionJanuary 2, 2025: OpenAI has failed to release the tool to opt-out or customize data collection the company promised to make available by 2025, according to Techcrunch.
Pixel 11 envy? Here’s how to unlock its best new feature on any Android device
Have you heard? It’s that time of year again — time for some snazzy new Pixels to tempt our gadget-coveting “gimme!” reflexes and guide flagship Android phone expectations for months to come.
Google’s latest and greatest gizmo is the Pixel 11 series, which includes the regular Pixel 11 and Pixel 11 Pro alongside the plus-sized Pixel 11 XL and Pixel 11 Pro XL and the fancy new folding Pixel 11 Pro Fold model (gesundheit!). El Googaloo took the wraps off all those new devices on Wednesday and has ’em all available for preorder now, with prices starting at $899 (regular Pixel 11), $1,099 (Pixel 11 Pro), and $1,299 (Pixel 11 Pro Fold).
At first glance, this year’s Pixel models might not seem like the most exciting upgrades from last year’s Pixel 10 products. They bring plenty of significant refinements to an already successful formula, with some welcome ticks forward — like better cameras, brighter and more scratch-resistant displays, faster charging speeds, and an updated processor that supposedly leads to speedier and more efficient performance. And, of course, there’s more Gemini everywhere (for better or for worse, depending on your perspective). But impressive as it all may be, it’s mostly iterative improvements over the previous-gen Pixels — which isn’t necessarily a bad thing but also isn’t exactly awe-inspiring, at least on the surface.
The most eye-catching addition to the Pixel 11 series is, rather ironically, a callback from Android’s past. It’s something Google’s calling HiLight, and it’s basically a new series of LED lights built into the freshly thinned-down camera bar on the phones’ backs. The lights illuminate to alert you to different events, allowing you to know about important incoming info at a glance — without having to so much as even look at your screen.
If the concept feels familiar, it should: Early Android devices boasted a similar sort of LED notification light for a very similar purpose. They were less visually striking, but they served the same basic purpose — up until they went out of favor for the far more complex (and, some might argue, less effective) always-on display concept that followed.
Here’s a little secret, though: You don’t have to have a new Pixel 11 phone in front of you to enjoy a similar sort of distraction-reducing, awareness-enhancing sorcery. You can actually recreate the Pixel 11 HiLight glow effect on any Android device this instant — and do it in a way that’s much more versatile, functional, and all-around useful, to boot.
Lemme show ya how.
[Get next-level knowledge in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]
The lowdown on Pixel 11 HiLightFirst things first, a quick hit of context about the Pixel 11 HiLight system and how it actually works.
As of the phones’ launch, HiLight is active only when the device is face down on a surface — perhaps not surprisingly, given that the lights live on the device’s back — and it works only in two super-specific scenarios:
- When you’re in the midst of getting an incoming call from a favorite contact, the Pixel 11 HiLight indicator glows with a custom color so you can see who’s calling and know it’s important. (It works with both the Pixel Phone app and WhatsApp, to start.)
- When you’re interacting with Gemini, HiLight pulses to let you know the system is listening, thinking, and responding.
Aaaaaaaand, that’s it. The system doesn’t work with any other apps, according to Google, and it doesn’t interact with notifications in general to let you know about important pending activity beyond those incoming calls.
It’s actually quite limited, in other words. And no matter what Android phone you’re using — even if it ends up being a Pixel 11! — you can take the same classic concept and make it infinitely more valuable.
The trick revolves around a handy little power-user app called AodNotify. The app has a few different versions, depending on which specific type of Android device is in your paw right now:
- This version is for any and all Pixel phones
- This one is for Samsung Android gadgets
- This one is for OnePlus devices
- And this one is a catch-all for any other brand of Android handset
Whichever version you end up with, AodNotify essentially creates your own custom notification light within your Android phone’s screen — by lighting up the area around your camera cutout at the top of the display, or alternatively creating a border-outline light that goes all the way around the phone front’s perimeter. And it shows up both when the screen is on and when it’s off.
AodNotify puts a Pixel-11-HiLight-style notification light right on any Android device’s display.JR Raphael, Foundry
It serves the same basic purpose as the Pixel 11 HiLight (as well as the old-school 2008-era Android phone LED notification lights that preceded it), but with some key advantages:
- You can see it when your phone is face-up — the way most folks seem to set their devices down when they aren’t actively in use.
- As a result, you can see it when your screen is on and you’re actively using the device as well as when the display is off, as mentioned a moment ago.
- You can have it light up to alert you of any manner of incoming call or notification with the same sort of simple at-a-glance recognition.
- And you can control exactly how and when it works, down to the tiniest of preferences, to make it perfectly useful for you.
Compared to HiLight, the practical value of this approach is absolutely bonkers. Rather than just letting you know about important incoming calls when your phone is face down, AodNotify lets you see at a glance exactly what type of notifications are waiting for you at any given moment — without having to so much as pick up your phone or process any intricate on-screen info.
Whatever alert it flashes can stay present and visible for any amount of time, too, so whether you hear a ding and want to glance to see what’s up or even if you miss the audio alert entirely (or have it disabled deliberately) and want to sneak a peek at your screen to know in a split second what’s waiting for you, AodNotify will get the job done.
And it’s surprisingly easy to set up, too — with two to three minutes of one-time configuration that you’ll never have to think about again.
Your own Android HiLight equivalentAll right — ready? First things first, go install AodNotify from the Play Store, using whichever link is appropriate for your current Android device from above.
Once the app is ready, open ‘er up and follow the prompts to get it going and grant it all the forms of access it needs to operate:
- First, you’ll select which apps can activate your new notification light and cause it to illuminate. If you want any and all notifications to be included, tap the “All” option at the top of the list. If you want to cherrypick and select only certain especially important apps while leaving others off, you can just choose whichever apps you’d like to have included.
- Next, tap the lines for “Notification access,” “Enable AOD,” and “Draw on screen,” if needed, and follow the prompts to enable AodNotify and/or the necessary option for each of the associated areas. This may seem like a lot of access, but AodNotify genuinely needs it to do what it does — and, critically, the app doesn’t require any other system-level permissions, including even access to the internet, so it couldn’t possibly do anything with your data (and its privacy policy is clear about the fact that it doesn’t collect or share any manner of data, ever). It’s also by a known and long-standing reputable Android developer.
- After that, you’ll see a pop-up prompting you to consider the app’s Pro version — which runs five bucks a year or $7 for a single one-time purchase. The Pro path turns off some ads in the AodNotify setup interface and enables some extra features. You may or may not want to consider it eventually, but for now, just hit the “x” in the upper-right corner of that prompt to dismiss it and move on.
JR Raphael, Foundry
Now for the fun part: At the app’s main setup screen, make sure the toggles next to “Notifications” and “Notification light” are active — then tap into each of those sections along with “Colors” and “General” to explore all of the available options.
Of particular note:
- Under “Notifications,” the “Battery” section lets you activate a special notification light for anytime your phone is charging, fully charging, or with a low (less than 15%) battery — so you can always be aware of that info when it arises.
- Under “Notification light,” the “Style” selector will let you shift your spiffy new light from its default camera-cutout-outline position to a full-screen outline or a classic-Android dot-in-the-corner LED-type effect.
- “Effects” in that same section will let you change the light from a simple pulse to all sorts of other interesting light-up patterns.
- “Dimensions” will let you shift the exact size, shape, and placement of the light, if it doesn’t look quite right on your screen.
- And the “How long to show the light” subsection will let you adjust how long any active notification light remains present, both when your screen is on and when the display is dark.
JR Raphael, Foundry
Beyond all of that, some of AodNotify’s most helpful options are in its “Colors” settings section. There, you can specify different distinctive colors for messages or calls connected to different contacts, so you can see who is calling or texting you just by the color of the light (much like what the Pixel 11 HiLight feature does, only with a much broader and more sensible scope). And you can activate an off-by-default option to have your notification light automatically change its color to match the primary hue associated with any given app’s icon — which is a nifty way to know at a glance that a pending alert is coming from, say, your Calendar app or Slack.
AodNotify’s “Auto color” option is one of the app’s most powerful — and easily overlooked — features.JR Raphael, Foundry
And that’s pretty much it. Your Pixel-11-style HiLight upgrade is officially complete — with an even more useful productivity-boosting framework than what the Pixel 11 HiLight version provides.
That’s the power of Android for ya. And it’s a power that’s present no matter what device is in front of you or how long you’ve been holding it.
Never miss a moment of Android awesomeness with my free Android Intelligence newsletter. One new exceptional tip in your inbox every Friday — straight from me to ye.
Lovable bolsters its AI software creation capacity, touts $400M funding round
Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.
The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.
Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.
The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.
The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)
Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.
That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.
“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”
In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.
Computerworld is part of Foundry, which is owned by Regent.
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such bypass can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Researcher creates workaround for Microsoft Defender security patch
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security workaround, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier workarounds.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a workaround for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such workarounds can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
Lovable raises another $400M, confirms new $13.3B valuation
Europe’s favorite vibe-coding startup Lovable has confirmed previously reported whispers that it was raising another mega round at a $13.3 billion valuation. Lovable said on Wednesday that it has raised $400 million in a Series C round led by Menlo Ventures and the Scaleup Europe Fund, with more than a dozen other investors participating.
This new funding comes after Lovable hit $500 million in annualized run rate revenue in June, the startup told TechCrunch. Its previous round, announced in December, brought in $330 million at a $6.6 billion valuation and was also led by Menlo Ventures, with CapitalG as co-lead.
Note: One of Lovable’s new Series C investors is Regent, the investment firm that owns Foundry.
IT infrastructure shortages are real and lasting. Here’s how to cope
Lead times of nine to 12 or even 18 months. Costs rising by 35%, 45%, even 50% to 200%. More than halfway through 2026, the market for IT infrastructure that’s crucial for enterprise projects, including those involving artificial intelligence, is strapped.
Memory is at the root of the shortages. Memory prices “have risen by 50% to 200%, resulting in PC prices increasing by 35% to 45% and some server prices rising over 125%,” according to Jon Forest, VP analyst at Gartner. Network switches also need memory, albeit in lesser amounts than servers, so they are not immune, with prices and lead times likewise rising dramatically.
Industry experts agree that most of the issues stem from hyperscalers gobbling up memory capacity, which trickles down to servers, storage systems, and networking devices. But while the source of the problem may be new, supply chain disruptions are far from unprecedented.
As a result, industry insiders are not short on advice on how best to deal with the situation, with tips including making better use of what you have, considering options beyond your usual scope, and lots of planning with your vendors and internal finance teams.
State of the problemJust how bad is the current supply chain problem? “It’s pretty bad,” says Matt Kimball, vice president and principal analyst with Moor Insights & Strategy. Companies accustomed to 30- to 45-day lead times for various infrastructure are now looking at 6, 12, or even 18 months.
“It’s real, and I’m hearing it from companies of all sizes, from the 1000-server to the 10,000-server shops,” Kimball says.
“Memory costs are expected to rise sharply well into 2027 and will reach up to 25% of network hardware expenses by the end of 2027,” according to an email Gartner’s Forest sent to Network World. The figure below shows the timeline Gartner expects for memory prices, and Forest notes that the same timing applies across networking, storage, and compute infrastructure.
Gartner
“Enterprise network equipment pricing is projected to increase by over 20% in 2026. This upward trend is anticipated to continue with a further rise of 3% to 5% entering 2027, with no signs of price reduction until the end of 2027.”
But “reduction” will likely look more like “stabilization.”
“That’s something a lot of people don’t like to talk about. But let’s say prices went up 40%, they may come down five,” says Phillip Privett, senior vice president of vendor management with the global distributor and value-added reseller TD SYNNEX. “They’re not going to come down 40%.”
Perhaps worse, compared with past disruptions caused by issues such as fires in chip fabrication factories or the Covid pandemic, Kimball says this one is “durable” because its cause—the AI wave—is more long-lasting and just getting started.
“This AI inference wave we’re hitting is just beginning. It’s going to be longer and bigger than the training wave,” he says. “It’s impacting everything, from AI infrastructure to the traditional stuff that’s standing up your virtualization and cloud infrastructure.”
No vendors seem to be immune, not even the likes of Cisco, which makes its own Cisco Silicon One chips. Or, at least, it designs the chips; they’re actually manufactured by the Taiwan Semiconductor Manufacturing Company (TSMC), the same company that makes many of the other chips that are in such demand. And that’s only one component of many that comprise a switch.
On the other hand, the margins Cisco gets from enterprise sales are far greater than those from hyperscalers because Cisco sells mainly just hardware to hyperscalers, whereas enterprise sales generally include software and services as well. So, Cisco has incentive to keep enterprise customers happy and maintain the 66% margins it reported in Q3, its latest quarter.
Still, Cisco must deal with the same shortages as other vendors.
“I wouldn’t say any company is faring better than others,” says Neil Anderson, vice president and CTO for cloud, infrastructure, and AI solutions at World Wide Technology (WWT). “There may be nuances that some suppliers are employing to balance it to some extent, but I fail to recognize a supplier that’s not having almost the same issue.”
Cloud storage vendor Backblaze is one company that’s facing equipment cost and availability issues. “There are different types of shortages occurring in multiple places, all driven by unusual market demands, really by just a handful of very large buyers,” says James Rowell, senior vice president of operations with Backblaze.
Backblaze is constantly forecasting and monitoring demand triggers, Rowell says. That involves close alignment with the sales team to forecast client needs, as well as paying attention to historical trendlines to predict upcoming demand from new deals and growth with existing clients. But the company also looks for “unnatural market-related triggers” that would cause a spike in utilization.
With hyperscalers buying up vast amounts of capacity, “This is definitely an unnatural phase,” Rowell says. “For about for the last 12 months, I would say there’s been somewhere between a 15% and 30% uptick in costs,” especially in terms of servers and compute disks.
On the positive side, at least for Backblaze, the company is also seeing an uptick in business from an interesting source: AI companies. “We reported in the last earnings period a 70% increase in AI companies using our platform,” says Patrick Thomas, vice president of marketing at Backblaze. “That’s massive.”
On top of that, the company is seeing an uptick in deals from enterprises that can’t get the storage capacity they need or want on-prem. “There’s a general market nervousness where we’ve got potential deals coming our way because those organizations are concerned about being able to do it themselves,” Rowell says.
While some expect new chip fabrication plants currently under construction will ease memory supply constraints, Privett doesn’t buy it. “I don’t see it getting better anytime soon,” he says. “Building a new fab is a two-year process.”
Advice: Start with the basicsEnterprises, then, must play the cards they’re dealt. For Moore Insights’ Kimball, who did stints as an IT exec with the states of Florida and Oregon, that starts with making the most of what you have.
Such a strategy is “shockingly not implemented much” across the companies he sees. “A simple capacity planning exercise can free up a lot of resources.” That includes virtualized servers running at just 20% to 30% utilization as well as extending the life of existing servers. While 15 or 20 years ago it was common to refresh every four years or so, companies can often get six or seven years out of today’s servers.
While such strategies won’t solve your AI compute challenges, they can certainly help support your ongoing operations and free up budget for AI and other modernization projects, he says.
“Sweat your assets,” agrees Privett of TD SYNNEX. “Work them as much as you can, add only what you need, get extensions on your licensing, renewals on your services agreements and things like that. Just sweat it out a little longer.”
If you have budget to spend but can’t get the hardware you’re after, buy something else, says WWT’s Anderson. “Look at things that are not tied to those components, like software projects or SaaS licensing,” he says.
Get friendly with finance teamsNumerous experts recommend regular meetings with your CFO or finance teams to keep them apprised of what you’re up against so the company can plan accordingly.
Gartner’s Forest advises using rolling 12- to 24‑month forecasts and engaging early with suppliers to identify constrained components and SKUs. Committing to quarterly or monthly buys can help you avoid long-term agreements that extend past the rapid increases we’re seeing in 2026, he says.
Also engage with the financing arm of your equipment vendors, some of which are offering financing incentives, Privett says. Compute vendors in particular are offering subsidized financing, deferred payments, and low-cost financing for the first year or so. “Those are huge opportunities to take advantage of,” he says.
By engaging with finance teams, IT groups can conduct budget allocation exercises and try to come up with ways to make the financials work. The last thing you want to do is surprise them with additional budget requests out of the blue.
Kimball recalls his days with the state of Florida, when all budget requests were examined by a technical review working group—which was designed to be hostile.
“I can’t imagine going to them and saying, ‘Oh, did I say that was a million dollars? It’s actually $2 million. I need you to write me a bigger check,’” he says. “I would walk into one of the swamps in Tallahassee and get eaten by the alligators instead of doing that.”
Work with your vendors and VARsAs you put plans together, lean on your vendors for help, including channel partners such as value-added resellers (VAR) and national resellers. “Work with them to map things out and understand what your workloads will look like,” Kimball says.
That’s what Backblaze’s Rowell regularly does with his suppliers. He lays out his forecast for the year, with commitments on what Backblaze will definitely buy, as well as scenarios that account for rapid growth, say, 2x. “And they’ll come back with, ‘Well, okay, no problem,’ or maybe they say we need to put in an allocation right away, or we won’t be able to get what we may need,” he says.
Similarly, he sits down with his CFO regularly to map out predictive models that factor in inflation, price hikes, and the like. The idea is to plan out multiple scenarios, so you don’t get blindsided.
“If you don’t do that, you’ll get caught with your pants down, on the upside-down end of spectrum,” he said – meaning not having the capacity to take advantage of market opportunities.
Acquiring the capacity you need to meet project demand may also mean being flexible in terms of your equipment choices. If you’re a Dell shop but can’t get Dell servers, maybe you go with Lenovo, Kimball says.
“You’ve got to figure out how to use all this silicon and infrastructure in a heterogenous way to serve your needs,” he says. That’s especially true when it comes to AI infrastructure. “If you think you’re going to go with 100% Nvidia for everything from RAG [retrieval augmented generation] to inferencing at the edge, you’re kind of crazy, not because of cost but because of availability.”
Look at alternatives, including AMD and cloud solutions, while staying mindful of how it all plays together. You may not be able to get Nvidia GPUs, but AWS, Azure, and Oracle Cloud have them, Kimball notes.
Be strategic, perhaps by using cloud offerings to handle certain tuning or inference workloads, then bringing them back in-house when appropriate. “Have a better understanding of what absolutely has to be on prem and what can be in the cloud,” he says.
That’s good advice, says Backblaze’s Thomas. When it comes to AI, think about performance tiers and the range of use cases you have. They don’t all need top-tier performance.
“People get wrapped around axle of needing the top end. There’s a lot of flexibility in the edges, innovation in different hardware and software,” Thomas says.
Gartner likewise advises companies to increase configuration flexibility and expand sourcing paths. That may include buying from secondary markets and lease-return programs to preserve continuity with existing infrastructure until the shortages pass, Forest says.
Get started somewhereEven if you can’t acquire or have to wait for the infrastructure you need, don’t let that keep you from getting started with AI or other modernization projects.
Options include public cloud and neocloud providers, Anderson says. WWT also provides capacity in its own lab so customers can get started with proof-of-concept projects. “Don’t just throw your hands up. We can help you find access to capacity,” Anderson says. “Production-scale AI may be delayed, but don’t let that derail your strategy.”
Colocation providers may likewise be an option, especially if enterprises are struggling to acquire high-end networking equipment. Networking is a key value proposition for colocation providers, in that they have built-in connections to various cloud providers and other ecosystem players.
Equinix, for example, has 280 data centers in 77 metropolitan areas, says Phil Read, senior director, colocation product management for the company. If you have the compute infrastructure, Equinix can help you with the high-end connectivity required both intra- data center and at edge facilities.
It also has partnerships with the likes of Cisco and Nvidia for “ready-to-go AI connectivity,” Read says. That means Equinix offers the right infrastructure to meet the requirements of high-end compute solutions in terms of power density and cooling. Such power densities are significant, requiring 120k VA per rack and up. “There’s plenty of talk about a megawatt rack,” he says.
Power is a significant issue in this entire discussion, Privett says. Older installed computing infrastructure likely consumes far more power than newer systems, which is an argument for upgrading as soon as possible.
“If you modernize today, you could substantially reduce the number of servers needed to support the same applications at a much lower power consumption rate,” Privett says. He advises sitting down with folks from the OT side of the house to make sure power is available for whatever you want to do. In many areas, power is at a premium.
If your plans include installing GPU environments in your own data center, WWT advises you not to delay. “We’re telling customers, you need to talk with us and get that designed, get that ordered, because it will take quite a bit of time until it actually ships and we’re able to install it,” Anderson says.
Apple’s response to RAM-ageddon? Lease, downgrade, refurbish, repair
Apple is in the process of tweaking its business models to cope with the unyielding memory price and availability crisis. Its response is now emerging across multiple fronts.
Finance or leaseThe company’s recently-introduced Apple Upgrade scheme in partnership with Klarna is a smart response to the reality that as devices inevitably become more expensive, consumers will shift from outright ownership to flexible lease and financing arrangements. With its partnership, Apple continues to generate revenue while also maximizing the likelihood customers will return the product at EOL, more about which later.
Samsung and Google have introduced similar schemes. “Financing models already dominant in India and Africa are now poised to reshape the US and European markets,” said CCS Insight in a presentation exploring the consequences of the memory shortage.
DowngradeApple has seen a lot of success with the iPhone 17 this year. That success wasn’t entirely because it’s such a good smartphone; it also reflects consumers making the decision to purchase lower-specced devices to stay within budget. Apple continues to see strong sales of its Pro range, which represents the power of its reach into more affluent consumer groups. It’s also important to note that at the moment, the iPhone 16e is the biggest-selling device on the US pre-paid market.
People still want the best, but are being more cautious in how they acquire it.
RefurbishedThe trade in refurbished devices is fundamentally built on two things: A large installed base of originally-sold devices resilient enough to be refurbished in the first place and buy-back deals attractive enough to encourage consumers to trade those devices in at all. That’s why it matters that Apple recently increased the value of its trade-in scheme: you’ll get up to $480 for an iPhone 16 or up to $720 for an iPhone 16 Pro Max under Apple’s new deal. It’s also important because Apple has its own growing refurbished business in Apple Refurb, and also because devices that really have reached end-of-life can be broken up for parts, taking a little pain out of Apple’s ongoing component crisis.
In 2024, Apple shifted 15.9 million refurbished devices and accessories.
Delay and RepairAs prices rise, consumers will keep their devices longer and are far more willing to repair existing hardware than upgrade. It’s well-known that iPhones are the most durable smartphones and ship with extensive future system support, so these devices can be successfully used for five years — sometimes more. Apple offers its own service and support package to keep your devices in good shape, and its recent decision to extend AppleCare One support to new nations reflects consumer sentiment. Those who want Apple’s trusted support for up to three devices can now get it for just a few dollars each month.
Not just about iPhonesAll these initiatives are important in their own right, of course, and while I’ve focused on iPhone here, Apple is implementing these changes and services across all its product lines. It knows that in the face of AI-flation, consumer habits will change. Demand for new devices — assuming Apple can even get enough components to make them — will fall. “Demand for refurbished models and financing will grow — fast,” said CCS.
The other transformation concerns price. The hyperinflation driven by decisions made by the effective cartel of the big three memory vendors (who could have continued to support the consumer memory industry while providing less support for data centers) is driving low-tier smartphone manufacturers to exit markets or raise prices. CCS expects smartphone prices to increase by 25%. Counterpoint says DRAM prices have risen 70% since 2025, while Gartner and others expect price inflation to remain into next year.
As Intel’s CEO said, “There’s no relief until 2028.”
Price increases leave a huge gap in the sub-$500 device market; that’s a vacuum the second-user market in refurbished smartphones will fill. As the value of that tier increases, it becomes a more strategically important market for both Apple and Samsung, who make the vast majority of smartphones. For both vendors, ongoing market changes mean the second-user market is becoming a primary channel for both companies; you can expect continued business pivots from both as they seek to capture business revenue.
Incoming structural challengesEven there, there’s a structural challenge to overcome. That is that as memory prices surge, sales of new devices decline. Down the road, there will be fewer devices to trade in, meaning the supply of used devices will fall, creating a future supply-and-demand imbalance in the second-user market. I predict this could get quite bitter, with manufacturers grabbing larger chunks of available devices to the detriment of the small renew-and-refurbish retailers. CCS Insight expects the market for second-user smartphones to grow by 9% in 2026 as cost-and-supply challenges bite.
Making the circleThere is opportunity within the chaos. Apple has committed to building a circular manufacturing ecosystem by 2030, which is only four years away.
We don’t know how far along the company is on that road, or the extent to which changing market conditions have undermined its attempt to reach that goal. But the company will have spent time developing new manufacturing and production processes to enable more extensive use of recycled and renewable raw materials in that attempt.
The signs are positive — the recently introduced MacBook Neo has a 90% recycled aluminium enclosure and 100% recycled cobalt battery.
Distorted loopThere is a reality in which any slowdown in new device manufacturing — or, indeed, the cadence of new device introductions — gives Apple and its partners a little breathing space in which to develop and deploy new manufacturing process technologies.
In that narrative, it does perhaps matter that under its new iPhone release schedule, there will be an 18-month gap between the launch of the best-selling iPhone 17 and the spring 2027 release of the iPhone 18. With a 20th anniversary iPhone and new iPhone Ultra range, along with some talk of a future flip phone, Apple may soon be in position to maintain the marketing buzz with new iPhones every six months while actually crafting an 18-month wait between major device improvements.
Doing so will likely reduce initial unit shipments while also flattening sales revenue for more predictable income. It also builds in extra time to retool the production lines for each device family.
Leading with the newWhen it comes to the deployment of new circular manufacturing tech, that potential 18-month gap buys that most precious of resources, time. Which means that while memory price inflation has caused huge problems, raised prices and forced Apple to change business practices, it could also give the company an opportunity to introduce one of the most profound changes in manufacturing of the 21st Century: circular manufacturing. To some extent, this transition in the nature of Apple’s business is reflected at board level, as the company is itself transitioning to new leadership under incoming CEO John Ternus.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core to keep pace with daily Apple news in one email.
AI policies work better when employees help write them
It’s likely that many enterprises have created — or are at least considering — AI policies that clearly lay out approved AI tools and their uses, set up training programs for employees to help them use the tools in their jobs, and establish guardrails around those systems to avoid issues such as security vulnerabilities and data bias.
But how many of these policies have received the blessing of employees? It’s a key question, because many workers are highly wary of AI.
They worry that it will cost them their jobs, either by taking over their work or because companies will cut jobs and use the savings to fund investments in AI research and infrastructure. They worry about AI-powered performance tracking software impacting raises and promotions. They worry about AI screening of job applications for future roles.
Even employees who have embraced AI to assist their work have reason to worry. Many say that using generative AI tools saves them time, but the time savings are eroded by “botsitting” — having to check and recheck output, provide missing context, fix errors, and go through multiple iterations before the desired outcome is achieved. They may also have to wade through “workslop,” low-quality genAI output that hasn’t been properly vetted by co-workers.
Additionally, workers say that as AI makes them more productive, their workload keeps increasing. All of this can add up to “prompt fatigue” or “AI brain fry,” mental exhaustion that affects heavy genAI users, particularly when they bounce between multiple AI tools.
AI policies that don’t take these factors into account are apt to be problematic. Employees may even organize to protect themselves from AI in the workplace. Indeed, tech pros are increasingly interested in unionizing, driven in part by the incursion of AI.
It doesn’t have to come to that. Company leaders can proactively work with their employees to develop AI policies that take employee well-being into account. The result might be stronger AI adoption, better business outcomes, and a happier, more productive workforce.
The 2026 Tech Sentiment Report by technology career marketplace Dice found that professionals are generally not resisting AI itself, “but rather, they’re looking for clarity around how it will affect their jobs, careers, and workplace decisions,” says Paul Farnsworth, president of the firm. “The research suggests that employee buy-in comes from making AI feel like something being done with workers rather than to them.”
In many cases, IT management runs the deployment of AI, and this can ultimately result in employees being left out of any decision making.
“When IT leaders drive deployment, they ask questions about integration, security, and capability,” says Amy Loomis, group vice president, Workplace Solutions at IDC. “That is not the same as asking workers how AI could actually improve their day, where they waste time on tasks that add no value, and where a well-designed tool would make a real difference.”
Following are some key steps to building an AI policy everyone can agree on. Bear in mind that any worker protection items should be in addition to the usual corporate governance, risk, and compliance AI policies, not a replacement for them.
Invite input from everyone involvedIt might sound obvious but can’t be overstated: the only real way to produce an AI policy that employees will accept is to get their input.
“We started by surveying our employees through SurveyMonkey to see what they were already using and why,” says Monica Washington Rothbaum, COO and senior attorney at law firm J&Y Law. “Then we sat down with every department, and involved operations, IT, HR, and leadership from the beginning. We wanted to understand the opportunities, but we also wanted to understand the risks” of AI.
Most AI policies “fail when they’re created in a conference room and handed down from the top,” Rothbaum says. “The people using these tools every day need to be part of the conversation. That’s why transparency became a major focus for us” in creating an AI policy.
Organizations should include employees in policy development, pilot programs, and feedback processes, Farnsworth says. This is especially important because Dice research found that only 48% of organizations have formal AI policies, while nearly one quarter of professionals surveyed said they’ve used AI without manager approval.
Keep the lines of communication openCreating an AI policy is not a one-and-done proposition. Organizations need to keep communicating with employees as AI and tools evolve.
“We communicated updates during company all-hands meetings, through email, in Microsoft Teams, and through department-level discussions,” Rothbaum says. “We even designated a member of our marketing team to oversee communications around AI adoption so there was clear ownership and accountability.”
The biggest mistake organizations make is treating AI like standard software, Rothbaum says. “It’s not. It’s an operational change,” she says. “It’s a communication challenge. It’s a governance challenge. The technology itself is often the easy part. The hard part is deciding what data can be used, who has access, how outputs are reviewed, and how the organization remains compliant while the technology continues evolving.”
One of the biggest drawbacks to AI adoption, from the standpoint of many employees, is the worry that AI tools will ultimately take away their jobs or many of their responsibilities.
Indeed, this has already been the case at some tech companies. A majority of non-AI technology professionals think AI eliminates more jobs than it creates, according to the Dice report, and three quarters think
junior-level workers are most at risk of displacement.
“Reassurances that no jobs will be lost ring hollow when workers can see
reorganizations happening around them,” Loomis says. “The organizations that sustain worker trust communicate specifically about what is changing, what it means for individual roles, and what the organization is committing to in return.”
One way to get around these concerns is to include provisions in policies that require any decisions around individual workers’ employment to be made by a human. That way no one can be dismissed from their job at the discretion of a machine.
Ensure access to training programsAnother way to gain workers’ support for AI policies is to include provisions about access to ongoing training and educational programs designed to build on their existing knowledge and provide them with valuable new skills.
“Employees are more likely to embrace AI when they see opportunities to grow alongside it,” Farnsworth says. “As AI becomes increasingly embedded in daily work, organizations should invest in AI literacy, upskilling, and career development programs to help employees adapt to changing job requirements.”
And those programs should be codified in AI policies. Guaranteeing workers access to training that evolves with the technology and enterprise workflows “requires treating training as a policy commitment with defined standards, timelines, and completion tracking,” Loomis says.
“Effective AI training does two things: it teaches workers how to use specific tools in the context of their specific roles, and it builds the human skills, judgment, critical thinking, and adaptability that determine whether workers can use AI well rather than just technically. Both are necessary,” she says.
When training is treated as a one-time event rather than a continuous policy commitment, Loomis says, adoption stalls and distrust grows. Ongoing “human skills training is gaining explicit recognition as core to
effective AI use,” she says.
This needs to be a standard component of any AI policy. But the language of proper and improper uses of AI tools and data must be clear for everyone in the workforce.
Such guardrails not only address cybersecurity and regulatory concerns, but can help prevent uses of AI that result in discrimination.
“The organizations that get the most value from AI won’t be the ones that adopt it the fastest,” Rothbaum says. “They’ll be the ones that communicate clearly, train consistently, and build the right guardrails before they need them.”
Confidential, client, firm, or employee information may not be entered into any AI tool unless explicitly authorized and approved, according to the J&Y Law policy.
Emphasize the positives of AIPolicies will of course include restrictions on the use of AI and rules around avoiding risks, but they also need to share how workers can leverage tools to help make their jobs easier or more fulfilling.
“One thing we’ve seen is that effective AI policies aren’t just lists of restrictions,” Farnsworth says. “Instead, they provide employees with clear guidance on how to use AI responsibly and confidently in their work. At Dice, our AI policy encourages employees to use AI when it can improve productivity, while establishing guardrails around data security, confidentiality, and human oversight.”
A good policy will help employees better understand that AI presents not just risks, but opportunities as well.
More on AI in the workplace:Anthropic to watermark AI-generated content
Anthropic will begin labeling AI-generated content created by Claude, Claude Code, and the company’s API, as well as Claude models via third-party services, according to The Register.
Text generated by future Claude models will be given an invisible watermark. According to Anthropic, the watermark is embedded directly into the generated text without affecting its meaning or readability. For files, Anthropic will instead use signed metadata in accordance with the C2PA standard.
The effort is part of the company’s plan to comply with the EU’s AI Regulation and transparency requirements regarding AI-generated material. However, the labeling will be implemented globally for all users.
At the same time, Anthropic noted that the technology has its limitations. A label does not guarantee that material was created by Claude. Similarly, the absence of a label is not necessarily proof that the material is not AI-generated.
- 1
- 2
- 3
- 4
- 5
- následující ›
- poslední »



