Category: AI News

  • Microsoft ships MAI-Cyber-1-Flash inside MDASH for agentic code scanning

    Microsoft ships MAI-Cyber-1-Flash inside MDASH for agentic code scanning

    A compact security model from Microsoft AI now runs as the workhorse inside MDASH, Microsoft’s multi-agent harness for finding and fixing software flaws. The model, MAI-Cyber-1-Flash, was built in-house from the MAI-Thinking-1 lineage and is trained on Microsoft’s own high-quality security data. Routing it through MDASH pushes the unified system to a 96% score on CyberGym, a 12-point gain over the Mythos baseline, while cutting the cost of running the harness by about 50% compared with Microsoft’s previous best configuration.

    Why a smaller model matters for site owners auditing their own pages

    Most readers running technical SEO audits are not deploying Microsoft models directly, but the routing logic behind MDASH still matters. The harness sends roughly 90% of its tasks to MAI-Cyber-1-Flash and reserves larger models, including GPT-5.4, for the remaining 10% of unusually hard cases. Microsoft frames that split as the practical reason for the cost drop: token spend, not raw model strength, is the binding constraint when scanning enormous volumes of code.

    For anyone auditing a large site, the takeaway is structural. A scanning pipeline that front-loads cheap, fast models for the long tail of routine checks, then escalates only the suspect findings to a stronger model, can cover more surface area per dollar. If you are stress-testing your own crawlers, log analyzers, or custom vulnerability scripts against a property with thousands of templates, that same routing pattern is worth prototyping rather than sending every request to your most expensive model.

    What MAI-Cyber-1-Flash is trained on

    Microsoft describes three layers doing the work: the model, the data, and the harness. The model is a compact, code-heavy security model derived from MAI-Thinking-1 and built from scratch in-house. The data layer draws on decades of running security products, including trillions of daily signals across identity, endpoint, cloud, and network, plus a record of real exploits and remediations. The harness layer is MDASH itself, which orchestrates more than 100 expert-tuned agents across multiple leading models to find, validate, and remediate vulnerabilities.

    That data advantage is hard to replicate. Microsoft points to more than 100 trillion security signals per day, telemetry from 1.6 million customers, and end-to-end visibility into the defender’s loop: vulnerabilities reported through the Microsoft Security Response Center, attacks and defenses across identity, endpoint, cloud, data, browser, and applications, and the operational record of what worked. Because the company can connect actions to outcomes (what was exploitable, what was contained, what was blocked) the models are positioned to improve continuously. For outside teams, the equivalent is to keep a feedback loop between your scanner output and your production incident data so your tooling actually learns from what your site sees.

    Benchmark numbers from CyberGym

    CyberGym is the standard benchmark for reasoning over large codebases to surface real flaws. On that benchmark, MDASH with MAI-Cyber-1-Flash scored 96%, a 12-point lift over Mythos. Microsoft also reports that the combined system beats Gemini and GPT on the same test. Against Microsoft’s previous best MDASH setup, which paired GPT-5.4 with 5.4 mini and 5.3 codex, the new configuration cuts cost by 50%.

    Two numbers are worth holding separately. The 96% score is a benchmark result and should be read alongside the 12-point gain over the specific Mythos baseline. The 50% cost cut is a comparison against Microsoft’s prior best configuration, not against the open market. Both figures describe the same configuration, but they answer different questions: how well it reasons over code, and how cheaply it does so at the volume MDASH operates at.

    How MDASH fits the broader agentic security stack

    MDASH is one piece of a larger system. Agentic code scanning inside MDASH feeds Project Perception, a new agentic security system Microsoft is launching in parallel. Perception runs teams of agents that continuously monitor, patch, and close new threat vectors, and it will also begin using MAI-Cyber-1-Flash for security workflows beyond software vulnerability work. The harness now contains more than 100 agents built on multiple leading models, all tuned by Microsoft’s internal security experts.

    For practitioners, the relevant pattern is the agent taxonomy: lightweight agents handle the bulk of detection, specialist agents validate findings, and remediation agents close the loop. If you are building or buying a scanner for your own site, ask vendors how their agents split work and how findings are validated before a ticket is opened. A pipeline that funnels everything to a single general-purpose model is the configuration Microsoft is moving away from.

    Safety, evaluation, and enterprise controls

    MAI-Cyber-1-Flash is Microsoft’s first cyber model, and the company built trust controls into every layer. Training used a security-first calibration, the model was evaluated by Microsoft’s AI Red Team, tested through automated and expert-led adversarial exercises, and independently assessed by a third party. Through MDASH, customers get role-based access, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access.

    For enterprise buyers, the control list is concrete: role-based access control, tenant isolation, encryption, audit logs, and sandboxed execution. If you are evaluating any vendor in this space, those five controls are a reasonable minimum checklist, especially the sandboxed execution with no internet access, since a vulnerability scanner that can reach the public internet from inside your build environment is a different risk profile than one that cannot.

    What to watch next

    Three things will determine whether the benchmark numbers translate into day-to-day utility. First, how MAI-Cyber-1-Flash performs on codebases outside Microsoft’s training distribution, including open-source projects and older enterprise stacks. Second, how Project Perception’s agent teams handle continuous monitoring without overwhelming security teams with alert volume. Third, whether the cost structure holds as MDASH scales beyond Microsoft’s own customer base, since the 50% cost cut is measured against a specific prior configuration rather than against all competitors.

    For site owners and SEO auditors, the practical thread is the routing logic. A small, focused model that handles the routine 90% of checks, paired with a larger model reserved for the hard 10%, is a pattern that maps cleanly onto crawl budget, log triage, and template-level vulnerability scanning across a large property.

    FAQ

    What is MAI-Cyber-1-Flash?

    MAI-Cyber-1-Flash is a compact security model from Microsoft AI, derived from the MAI-Thinking-1 lineage, designed to find vulnerabilities in complex code. It runs inside MDASH and handles up to 90% of scan tasks, with GPT-5.4 reserved for harder cases.

    What is MDASH?

    MDASH is Microsoft’s multi-agent harness for identifying and remediating vulnerabilities. It coordinates more than 100 expert-tuned agents built on multiple leading models, and it feeds Project Perception, Microsoft’s new continuous-monitoring system.

    How does the new configuration perform on CyberGym, and what does it cost?

    MDASH with MAI-Cyber-1-Flash scores 96% on CyberGym, a 12-point lift over the Mythos baseline. Compared with Microsoft’s previous best MDASH configuration (GPT-5.4 plus 5.4 mini plus 5.3 codex), the new setup cuts cost by 50%.

  • Glean:GO 2026 Registration Opens for August 26-27 San Francisco Enterprise AI Conference

    Glean:GO 2026 Registration Opens for August 26-27 San Francisco Enterprise AI Conference

    Glean has opened registration for Glean:GO 2026, its annual enterprise AI conference, scheduled for August 26-27 at the Fort Mason Center in San Francisco. The event accommodates both on-site attendees and remote participants, a hybrid format Glean has used in prior years. The program is built around the theme “Transforming work with enterprise AI.”

    Why site owners running technical SEO audits should pay attention to an enterprise AI conference

    Enterprise AI conferences tend to shape product roadmaps that affect how content is discovered, indexed, and rendered. When platform vendors like Glean, Cisco, Snowflake, and NVIDIA share what their customers are deploying, those signals can prefigure changes to search interfaces, internal knowledge retrieval, and the way structured data is consumed by AI systems. Auditors who track these announcements get an early read on the tools their own employers, clients, or competitors may be wiring into their stacks within the next two quarters.

    For practitioners who run audits on large sites, the relevance is less about the keynote slogans and more about the practical integrations that follow. An enterprise AI platform that gains traction inside a Fortune 500 buyer often becomes a procurement default at subsidiaries, which can cascade into new content syndication patterns, new bot user agents in server logs, and new markup requirements. Watching Glean:GO 2026’s agenda is a way to map that pipeline before it shows up in a crawl report.

    What is Glean:GO 2026 and who is the target audience?

    Glean:GO is Glean’s annual flagship event for enterprise AI buyers and builders. The 2026 edition is organized for IT leaders, digital workplace and AI practitioners, and business executives who are responsible for rolling out AI inside their organizations. Sessions are designed to serve both technical teams and the decision-makers who fund and govern those teams.

    The two-day structure mixes strategic discussions with hands-on content, so attendees can move between architecture-level talks and workshops that walk through real deployments. The conference positions itself as a venue where the people who choose enterprise AI platforms can meet the people who maintain them.

    What does the program cover?

    The agenda is organized into several tracks that span the full lifecycle of enterprise AI adoption:

    • Keynotes on enterprise AI strategy and where the market is heading.
    • Technical deep-dive sessions on AI agents, security controls, and platform capabilities.
    • Customer transformation stories and case studies from organizations running production AI deployments.
    • Hands-on workshops built for builders and platform administrators.
    • Product roadmap sessions covering upcoming Glean platform releases.
    • Executive tracks that focus on governance frameworks, cost management, and adoption metrics.

    Together the tracks give attendees a view of how AI is being deployed across regulated industries, how teams are controlling access to sensitive data, and how organizations are measuring the return on AI spending.

    Who is speaking at Glean:GO 2026?

    Confirmed keynote speakers include Arvind Jain, co-founder and CEO of Glean, alongside Jeetu Patel, President of Cisco, and Sridhar Ramaswamy, CEO of Snowflake. The program also features executives from Deloitte, NVIDIA, Ericsson, and eBay. The lineup reflects the conference’s focus on the systems layer of enterprise AI, pairing the host company’s leadership with executives from infrastructure, data, consulting, and commerce organizations.

    When and where is the conference held?

    Glean:GO 2026 runs August 26-27, 2026, at the Fort Mason Center in San Francisco, California. Both in-person and virtual registration options are available, and registrants receive confirmation details and event updates by email. The hybrid format is intended to make technical content accessible to distributed teams that cannot send staff to San Francisco.

    How do you register?

    Registration is open on the Glean:GO 2026 event page at glean.com/events/glean-go-2026. Signing up there provides access to confirmation details, the schedule updates, and any pre-event briefings Glean chooses to send to registrants.

    What auditors can do between now and the event

    Even for readers who never attend, the conference catalog is a useful checklist. Cross-reference the announced speakers against the vendors already appearing in your server logs and procurement contracts. If your site already serves enterprise customers, the tools those customers adopt will shape the surfaces your pages need to render on, from AI-powered knowledge bases to internal search portals. Adding those vendor names to your crawl monitoring and structured data validation routines now is a low-effort way to stay ahead of the integration wave that conferences like Glean:GO tend to accelerate.

    FAQ

    When and where is Glean:GO 2026?

    Glean:GO 2026 is scheduled for August 26-27, 2026, at the Fort Mason Center in San Francisco, California. Both in-person and virtual attendance options are available.

    Who is the target audience for Glean:GO 2026?

    The conference is aimed at IT leaders, digital workplace and AI practitioners, and business executives responsible for adopting enterprise AI inside their organizations. Sessions cover strategy, technical deep dives, customer case studies, hands-on workshops, product roadmaps, and executive tracks on governance and cost management.

    How do you register for Glean:GO 2026?

    Registration is open on the Glean:GO 2026 event page at glean.com/events/glean-go-2026. Registrants receive confirmation and event updates by email.

  • FCC moves to block imports of humanoid robots and power inverters, names China as supply chain risk

    FCC moves to block imports of humanoid robots and power inverters, names China as supply chain risk

    The Federal Communications Commission has barred new imports of foreign-made humanoid robots, quadruped robots, and power inverters, framing the action as a safeguard for U.S. supply chains. The agency described cybersecurity and disruption risks from offshore production as the justification, and the policy is widely read as aimed at Chinese manufacturers. Beijing’s foreign ministry called the move protectionism and warned of countermeasures.

    Why the FCC acted now

    p

    FCC chairperson Brendan Carr said the order was intended to secure critical supply chains. The bans apply to new versions of the covered imports, leaving equipment already in use and previously approved models on the market.

    Analysts say the timing adds weight to the decision. With a meeting between President Trump and Chinese leader Xi Jinping expected in September, trade frictions in robotics and adjacent components become another flashpoint before any face-to-face talks. The FCC has previously acted on security grounds against Chinese-made drones, and the new measures extend that pattern into humanoid hardware and grid-adjacent electronics.

    What the rule actually covers

    Three product categories fall under the restriction:

    • Humanoid robots, defined as bipedal machines built for autonomous or remote operation.
    • Quadruped robots, the four-legged machines often called robot dogs that are used for security patrols, inspection, and logistics.
    • Power inverters, the components that convert direct current electricity into alternating current. They sit inside renewable energy systems, data centers, and a wide range of household appliances.

    Because inverters are embedded across the energy and electronics economy, a ban on new imports can ripple through solar installations, backup power, and consumer devices that rely on foreign-made conversion hardware. Existing devices remain in service, and Chinese models already approved by U.S. regulators can still be sold.

    China’s grip on humanoid production

    Chinese manufacturers hold roughly 85% of the global humanoid robot market, according to the technology research and advisory group Omdia. Around 15,000 humanoid robots shipped globally in 2025, and two Chinese firms, Unitree and AGIBOT, each shipped more than 5,000. U.S. developers such as Tesla and Figure AI each shipped a few hundred or fewer in the same window.

    Cost and scale are the structural advantage. Morningstar analyst Kangyuxiao Li said Chinese manufacturers have been scaling production and reducing costs faster than most overseas competitors. Li noted that restricting access to the U.S. removes a future market and shields U.S. developers from price competition, but it will not materially slow China’s overall humanoid development because of the size of its domestic manufacturing base and demand from other export markets.

    Morgan Stanley analysts forecast that China’s market for humanoids could reach $15 billion by 2030, a figure that underlines why a ban on U.S. sales is a commercial loss for Chinese vendors even if domestic demand stays strong.

    Where this fits in the broader tech trade fight

    The inverter and robot bans sit inside a longer sequence of restrictions. The U.S. has already limited imports of Chinese-made drones and tightened export controls on advanced semiconductors and chipmaking tools. Washington is also weighing restrictions on the use of Chinese open-weight artificial intelligence models inside the U.S., a debate that has gained urgency as open-weight systems from Chinese labs have become competitive on common benchmarks.

    Samm Sacks, a senior fellow at the New America think tank focused on Chinese technology policies, described the pattern as a steady drumbeat of flashpoints heading into the planned Trump-Xi summit. The Pentagon recently added Unitree and several other Chinese technology companies to a list of firms it says have ties to or aid the Chinese military. Beijing has rejected that characterization.

    What it means for collaborations already underway

    The rule does not only block finished imports. It also reshapes joint engineering work. Omdia chief analyst Lian Jye Su said the new bans could interfere with collaborations between U.S. and Chinese technology companies. Nvidia’s June humanoid robot reference design, which uses Unitree’s chassis, is the clearest example. A reference design that depends on a now-restricted Chinese-built platform raises questions about whether U.S. developers can keep shipping integrated products or will need to redesign around non-Chinese hardware.

    For U.S. robotics labs, the practical effect is a forced reassessment of component sourcing. Any reference architecture, SDK, or starter kit that ships with a restricted chassis embedded now carries distribution risk. Developers who build on top of those kits need a contingency plan, including alternative chassis vendors and a clear audit trail showing where restricted parts enter and leave the build.

    China’s response

    Chinese foreign ministry spokesperson Mao Ning told reporters in Beijing on Wednesday that protectionism does not make the U.S. more competitive and will only hurt U.S. companies and consumers. The ministry said Washington is overstretching the concept of national security to suppress Chinese companies and that Beijing will take all measures necessary to defend the legitimate rights and interests of Chinese businesses.

    Investors are watching for matching Chinese countermeasures. Past rounds of trade friction have produced export controls on rare earths, rare earth processing technology, and specialty chemicals that feed U.S. electronics and clean energy manufacturing. A symmetrical response in rare earths or inverter-grade components would put pressure on the same U.S. sectors the FCC is trying to protect.

    What to watch next

    Three signals will tell the story in the coming weeks. First, whether the FCC publishes a formal list of restricted model families and chassis, since the line between a humanoid, a quadruped, and an industrial manipulator is not always obvious from a press release. Second, whether Nvidia or other U.S. reference design publishers issue updated guidance for developers using Unitree-based kits. Third, whether Beijing names specific counter-measures ahead of the planned Trump-Xi meeting.

    Morningstar analyst Cheng Wang expects pressure on U.S. markets to be limited in the near term, given that existing devices and previously approved models remain usable and saleable. The longer-term picture depends on how fast U.S. developers can close the cost and scale gap with Chinese suppliers, and whether allied manufacturing in Korea, Japan, or Taiwan can fill the gap left by Chinese vendors.

    FAQ

    What did the FCC actually ban?

    The Federal Communications Commission banned new imports of foreign-made humanoid robots, quadruped robots, and power inverters. FCC chairperson Brendan Carr said the order was intended to secure critical supply chains and described cybersecurity and disruption risks from offshore production as the national security rationale.

    How dominant is China in humanoid robots?

    China holds an estimated 85% of the global humanoid robot market, according to Omdia. Of roughly 15,000 humanoid robots shipped globally in 2025, Chinese firms Unitree and AGIBOT each shipped more than 5,000, while U.S. developers such as Tesla and Figure AI each shipped a few hundred or fewer. Morningstar analyst Kangyuxiao Li said Chinese manufacturers have been scaling production and cutting costs faster than most overseas competitors, and Morgan Stanley analysts forecast China’s humanoid market could reach $15 billion by 2030.

    Will the inverter ban affect existing equipment?

    Power inverters convert DC electricity into AC electricity and are used in renewable energy systems, data centers, and household appliances. Morningstar analyst Cheng Wang said the ban does not affect continued use of existing devices or sales of models already approved by U.S. regulators, and that near-term pressure on U.S. markets should be limited. The longer-term picture depends on whether U.S. and allied manufacturers can scale inverter production to replace Chinese supply.

    Related coverage

  • Zuckerberg tells Washington not to block Chinese AI models

    Zuckerberg tells Washington not to block Chinese AI models

    Meta chief executive Mark Zuckerberg has come out against any US ban on advanced Chinese artificial intelligence models, calling a prohibition “not an effective solution” in a recent Financial Times interview. His framing is competitive, not diplomatic: rather than wall off American AI, he said, Washington should figure out where US labs are actually falling behind and close those gaps. The comments line Meta up alongside the startups and developers pressing the Trump administration not to restrict Chinese open-weight models.

    The intervention matters because it puts a major frontier-lab CEO on one side of a split that has been widening inside the US AI industry for months. It also sets up a near-term question for policymakers: whether export controls and usage restrictions should target open models from China, or whether the better path is faster domestic progress.

    What Zuckerberg actually said

    Zuckerberg pushed back on a ban in two ways. First, he questioned whether restriction would even work. Second, he argued the technology industry’s long arc has run toward more openness, not less.

    “The big trend in the industry’s development has always been towards greater openness, putting technological power in the hands of more people, not fewer,” he told the FT.

    He also took aim at closed-lab rivals without naming them, taking a shot at companies lobbying Washington to tighten rules around the most capable “frontier” systems. Zuckerberg framed that approach as concentrating too much power in too few hands, a critique that matches the position Meta, Microsoft, Nvidia, and Elon Musk have taken in recent AI policy debates.

    The fault line running through US AI policy

    The Chinese-model fight is part of a larger split inside the American AI industry.

    • Open-weight backers: Meta, Microsoft, Nvidia, and Musk. They favor publishing trained parameters so others can run, study, and build on them.
    • Tighter-control backers: OpenAI and Anthropic. They argue the most capable systems should be regulated because of safety and national-security risks, including cyber-attacks and potential help for bioweapon development.

    OpenAI and Anthropic warn that unrestricted diffusion, including of Chinese open models, puts powerful capabilities in anyone’s hands. The camp Zuckerberg has joined sees a different threat: a small circle of US labs working with regulators they have lobbied, ending up controlling a technology that should be widely distributed.

    The Kimi K2 Thinking trigger and the July letter

    Pressure on the open-weight side spiked in mid-July after Moonshot AI released Kimi K2 Thinking, a cheap Chinese model widely seen as narrowing the gap with American frontier systems. A week later, on 24 July, twenty-five organisations signed a letter titled “Open Weights and American AI Leadership,” arguing that openness, not restriction, is the surer route to continued US primacy in AI.

    Nvidia chief Jensen Huang has separately pushed back against export-control hawks. Washington is now weighing export controls and possible usage restrictions on Chinese AI while trying to keep American competitiveness intact. Zuckerberg’s comments place Meta firmly on the competitiveness side of that balance.

    What a technical SEO audit has to do with AI policy

    On the surface, a US-China AI dispute looks far from a site audit. The connection sits inside the content a site publishes, the crawlable signals behind it, and the way AI-powered search surfaces it.

    A few practical checks worth running while this debate plays out:

    • How AI assistants cite you. Query ChatGPT, Perplexity, Claude, and Google AI Overviews for your brand and top product pages. Track which URLs they pull from and whether your structured data is being picked up. A model that is openly distributed is also a model that can be retrained or fine-tuned on whatever is publicly crawlable today.
    • Source attribution markup. Make sure authorship, organization, and sameAs links are exposed in JSON-LD. Open-weight models trained on web scrapes will weight authoritative signals more cleanly than a brand whose entity graph is fragmented across inconsistent markup.
    • robots and llms.txt. Decide whether you want AI crawlers indexing you for training, retrieval, or both. The default is to accept everything, which means your content is part of whatever the next open release ingests.
    • Content provenance. If your competitive advantage is original research or proprietary data, check whether it is being mirrored on third-party domains that an open model will treat as canonical.

    The US may or may not restrict Chinese open-weight models. Either way, the underlying models are already trained on whatever the open web exposed yesterday, so the audit that matters is the one you run today.

    Personalised superintelligence and Meta’s own contradiction

    Beyond the policy fight, Zuckerberg has been pushing a vision of “personalised superintelligence,” systems tailored to each user rather than a single, centrally controlled model designed to be safe on everyone’s behalf. That framing clearly benefits Meta’s strategy: it positions open, widely distributed models as the future and casts closed, centralized systems as relics.

    There is an obvious tension. Meta built its AI reputation on the open-weight Llama family, yet its newest flagship, Muse Spark, arrived closed source. Critics flagged that shift quickly. Whether openness makes American AI stronger or just makes it easier for competitors to copy is the central judgement US officials are still working through, and one interview is unlikely to settle it.

    FAQ

    What did Mark Zuckerberg say about blocking Chinese AI models?

    Zuckerberg said banning advanced Chinese AI from use in the United States is “not an effective solution.” He argued the US should identify where it is actually behind and address those gaps instead of relying on restrictions.

    Which companies support open-weight AI and which want tighter controls?

    Meta, Microsoft, Nvidia, and Elon Musk have backed open-weight AI. OpenAI and Anthropic have argued for tighter controls on the most capable models, citing safety and national-security risks.

    What is the “Open Weights and American AI Leadership” letter?

    It is a letter signed by twenty-five organisations on 24 July arguing that openness, not restriction, is the better path to continued US primacy in AI. It followed the mid-July release of Moonshot AI’s Kimi K2 Thinking, a Chinese model seen as closing the gap with US frontier systems.

    Related coverage

  • GrapheneOS Duress Wipe at Atlanta Airport Tests Federal Property Statute

    GrapheneOS Duress Wipe at Atlanta Airport Tests Federal Property Statute

    A single-count indictment in the Northern District of Georgia is treating a passenger’s own security feature as the underlying act of a federal crime. Samuel Tunick is accused of violating Title 18, Section 2232(a), a destruction-of-property statute, after a Customs and Border Protection secondary inspection at Hartsfield-Jackson Atlanta International Airport on January 24, 2025 ended with his Google Pixel appearing to restart. Prosecutors say he handed officers a passcode that erased the device instead of unlocking it.

    For technical SEO audits and site owners who travel with work devices, the case reframes a routine security habit, wiping a phone before surrendering it, as a potential felony trigger. Auditors who model travel risk for clients now have a concrete US precedent to weigh against device policies.

    What happened at the checkpoint

    Tunick had returned from the Dominican Republic when CBP pulled him into secondary screening. According to a defense motion drawing on the government’s own reports, an FBI Joint Terrorism Task Force officer and an FBI special agent had coordinated with CBP in advance to question and search him on arrival. Officers from CBP’s Tactical Terrorism Response Team opened the interview by stating they were “looking for people who are pedophiles,” the filing records.

    Officers never read Tunick his Miranda rights. Early in the encounter he asked for a lawyer and repeated the request. Questioning continued anyway. One officer told him that his refusal to speak gave the team authority to search his phone, and when he asked again about counsel, an officer responded that customs and immigration operate differently and “we have search authority, we don’t need a warrant.”

    Tunick eventually provided passwords for his phone and his e-reader. The screen “went blank, flashed several times and the phone appeared to restart,” per the government’s report. Officers seized the devices and said they would be returned after thirty days. A third officer took him to another room for an unrecorded pat-down before a DHS agent told him he was free to leave.

    What the indictment covers

    The single count accuses Tunick of acting to impair the government’s lawful authority to take the device’s contents, in violation of Title 18. The charging document misspells “Untied States Code.” The statute the government invoked targets destruction of property to prevent seizure, a provision more often associated with physical evidence than digital storage.

    Tunick has pleaded not guilty. He was arrested roughly ten months after the airport stop. A crowdfunding page he controls says he was pulled over for a claimed tail light defect and cuffed by FBI and DHS officers when he stepped out of the vehicle.

    What the defense is challenging

    Tunick’s attorneys appeared in court on Monday and asked the judge to suppress everything obtained during the encounter. Their motion argues that officers ran a custodial interrogation without Miranda warnings, denied his repeated requests for counsel, and searched him unlawfully. The defense adds that the government’s reports contain no suggestion anyone believed he was carrying illegal images; instead, the reports note interest in his ties to Defend the Atlanta Forest, a movement opposing the clearing of the South River Forest for the Atlanta Public Safety Training Center, an 85-acre, $115 million facility opponents call Cop City. Federal filings label the movement an “Anti-Government, Anti-Authority Violent Extremist Group.” Tunick has not been charged with any offense linked to it.

    How this site auditing angle fits

    For practitioners who configure client devices and travel policies, the indictment raises specific audit checkpoints. A travel-device policy review should now ask whether a client’s mobile fleet uses duress wipes that can be triggered by a single wrong code, whether forensic-image procedures at the border assume the device state is preserved, and whether incident response runbooks treat a wiped device as evidence loss rather than user action. Compliance logging, mobile device management profiles, and evidence-handling clauses in vendor contracts may all need a clause that accounts for irreversible wipe triggered by the owner, not the administrator.

    For site owners running audits, the practical questions translate to documented controls. Does the client maintain a record of which devices were wiped before a border crossing, with timestamps and the responsible account owner? Are password vaults and authentication tokens re-issued from a separate, geographically redundant source after a wipe event, so a single device loss does not cascade into a site access outage? Is the chain-of-custody for any data that was on the device reconstructable from server-side logs, independent of what was stored locally? The Tunick indictment turns each of those into questions a federal prosecutor might also ask.

    Circuit split on border device searches

    Eleventh Circuit precedent, which governs the Georgia courthouse, generally favors the government. A 2018 ruling in United States v. Touset permits forensic searches of electronic devices at the border without a warrant, probable cause, or individualized suspicion.

    Tunick’s lawyers cite contrary decisions from the First, Fourth, and Ninth Circuits. A Fourth Circuit holding bars warrantless border device searches when the goal is gathering evidence of a domestic crime rather than intercepting contraband entering the country. The defense also argues that surrendering a passcode is testimonial, relying on a 2012 Eleventh Circuit decision that decrypting and producing hard-drive contents triggers Fifth Amendment protection.

    Border search doctrine permits suspicionless inspection to keep contraband out. The accusation here is that data left the phone rather than entered the United States, and digital files cross borders over the internet regardless of where the device sits. A ruling on the suppression motion is not expected before the end of October.

    How GrapheneOS implements the duress password

    GrapheneOS is an open-source hardened Android build that replaces the stock software on Google Pixel hardware. The operating system lets an owner configure a second PIN or password at the lock screen. When that secondary credential is typed at a normal unlock prompt, the device irreversibly wipes local storage and any installed eSIMs. The system shows no confirmation dialog and surfaces no indication that the wrong code was entered; from the holder’s perspective, the device simply unlocks or fails to unlock as usual.

    How the security community has reacted

    Bill Budington, senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, founder of the security firm Granitt, each said they had not seen a comparable prosecution. Sandvik said she had discussed the scenario with activists and journalists for years and routinely advised travelers to leave sensitive material off devices they carry across borders rather than rely on wiping it. Christophe Boutry told the Guardian the prosecution “sends the message that [GrapheneOS] is criminal by default.” Matthew Dodge, an assistant federal public defender on Tunick’s legal team, noted that the statute is rarely seen in an indictment.

    FAQ

    What charge is Samuel Tunick facing?

    He faces one count under Title 18, Section 2232(a), a statute that covers destruction of property to prevent the government from taking it. Prosecutors say he gave CBP officers a passcode that erased his Google Pixel instead of unlocking it.

    How does GrapheneOS’s duress feature work?

    GrapheneOS is an open-source hardened Android build for Pixel phones. It lets an owner set a second PIN or password that irreversibly wipes the device and any installed eSIMs when entered at a credential prompt. The unlock screen shows no confirmation and gives no visual cue that the duress code was used.

    Why is the defense asking to suppress the evidence?

    Tunick’s lawyers argue that officers ran a custodial interrogation without Miranda warnings, denied his repeated requests for counsel, and searched him unlawfully. They also cite a Fourth Circuit ruling against using warrantless border device searches to look for evidence of domestic crime, and a 2012 Eleventh Circuit decision treating compelled decryption as testimonial under the Fifth Amendment.

  • Audio surveillance pilot ends, but Flock Safety microphone network stays live

    Audio surveillance pilot ends, but Flock Safety microphone network stays live

    Flock Safety has pulled the plug on its Distress Detection audio pilot, an always-on microphone feature that scanned public spaces for sounds of human distress, including screaming, after a sustained pressure campaign from privacy advocates. The Electronic Frontier Foundation confirmed the decision on July 17, 2026, noting that the cancellation falls short of a full retreat because Flock still operates thousands of acoustic sensors nationwide.

    What the cancelled pilot actually did

    The Distress Detection feature was announced in October 2025 as an expansion of Flock’s acoustic gunshot detection hardware, originally branded as Flock Raven. Flock repackaged the same microphones to flag sounds of “human distress,” with early marketing materials explicitly using the word “screaming.” After public scrutiny, the company softened the wording to the generic term “distress” without changing the underlying capture capability.

    Civil liberties groups flagged the feature as a textbook case of mission creep. A microphone network sold on the promise of catching gunshots was being repurposed to listen for any heightened vocalization, which critics argued would trigger armed police responses to arguments, crying, or children playing.

    Why the timing matters for site owners and auditors

    Public-facing infrastructure sits at the intersection of physical and digital exposure. When a vendor’s reputation shifts, every blog post, case study, and product page that references that vendor inherits some of the risk. Sites that publish Flock Safety tutorials, integration guides, or neighborhood camera maps should now revisit the framing on three fronts.

    First, accuracy claims about audio detection have taken a hit. Documented incidents in Chicago saw police shoot at children setting off fireworks because acoustic gunshot detection misfired. Any page that quotes Flock’s marketing copy about precision or response times should be reworded to reflect the contested record.

    Second, municipal contracts are fragile. Flock cameras are installed through city procurement, neighborhood associations, and private groups that share footage with law enforcement, which is why Houston Police struggled to identify ownership of cut devices on July 4, 2026. A page that promises “Flock coverage in your area” may describe a network that is being actively vandalized or decommissioned. Refresh the data or remove the promise.

    Third, the cancellation wording matters for SEO. Flock’s own statement says audio detection “was designed to help identify potential violent incidents in areas where other public safety tools were less effective” and that the feature “was only available to a small number of customers as part of a limited trial, and was never broadly released.” The EFF counters that “this was a misguided and dangerous feature because of the civil liberties concerns it poses, the possibility it could summon armed police to every loud interaction happening on the street.” Pages that quote either side should link both and date the quote so future readers can see the editorial position.

    How the opposition organized

    Resistance to Flock’s surveillance footprint has escalated through direct action. Reports of individuals hacking down, blinding, or otherwise disabling Flock cameras have reached a scale the EFF describes as “countless.” In several online communities, people who destroy the devices are treated as folk heroes, and defense funds are being organized for those facing legal consequences.

    On July 4, 2026, multiple Flock cameras along Houston’s Washington Avenue were found cut in half and spray-painted, including one with an American flag painted over its lens. Houston Police opened an investigation but could not immediately determine ownership, a transparency gap that mirrors the difficulty journalists and auditors have when mapping which entity actually controls a given pole-mounted device.

    Flock condemned the vandalism, calling it illegal and community-harming, and claimed that overall vandalism reports remain low. Independent trackers push back on that figure, given the steady stream of incidents posted to local news and social channels.

    What an audit should check on a site covering Flock

    • Outdated marketing claims. Any stat about Flock’s camera count, coverage area, or detection accuracy should be sourced and dated, since the company has revised public-facing language several times in the past year.
    • Third-party embeds. Map widgets and live dashboards that pull Flock-adjacent data may break or display stale records as contracts change hands between cities, HOAs, and private operators.
    • Privacy policy alignment. If a page describes what audio data is captured, that description needs to match the current product, not the Distress Detection pilot that no longer exists, and not the broader acoustic gunshot detection that does.
    • Schema markup. News articles and product pages referencing Flock should use current Organization and Product schema, with the cancellation date noted in the article body so structured data does not contradict the visible text.

    The pattern beyond Flock

    The EFF’s framing of the cancellation fits a longer arc of American pushback against surveillance expansion, from 1970s congressional reviews of FBI programs to the 2013 revelations of NSA mass data collection. The foundation’s conclusion is that public pressure can move both companies and the lawmakers who control a city’s procurement budget, though the underlying infrastructure tends to outlast any single product decision.

    Flock continues to operate acoustic sensors that listen for gunshots, fireworks, and what the company labels “community disruption.” The Distress Detection cancellation closed one front, but the remaining microphone network, along with the company’s far larger automated license plate reader footprint, is still in place. The next pressure point is likely to be the gunshot detection hardware itself, where contested accuracy and documented police misfires give critics fresh material.

    FAQ

    What was Flock Safety’s Distress Detection pilot?

    An always-on audio feature announced in October 2025 that used high-powered microphones in Flock’s network to flag sounds of “human distress,” originally described as “screaming” before the wording was softened.

    When did Flock Safety cancel the audio surveillance pilot?

    The cancellation was confirmed by the Electronic Frontier Foundation on July 17, 2026, with Flock citing “careful consideration and community consultation.”

    Does Flock Safety still operate audio surveillance devices?

    Yes. Only the Distress Detection feature was cancelled. The company continues to operate thousands of acoustic sensors across U.S. communities, including gunshot detection hardware originally branded as Flock Raven.

  • Open Secure AI Alliance: What It Means for AI Agent Security

    Open Secure AI Alliance: What It Means for AI Agent Security

    NVIDIA joined more than 30 technology organizations on July 27, 2026 to launch the Open Secure AI Alliance, a coalition focused on building openly licensed tools, models, and techniques for defending software and AI agents. The group is positioning itself around a practical thesis: defenders should be able to inspect, adapt, and run frontier security tooling on their own infrastructure rather than depending on a handful of closed vendors. Founding partners span cloud, cybersecurity, enterprise software, open source foundations, and AI research labs, including Adobe, Capital One, Cisco, Cloudera, Cloudflare, CrowdStrike, Databricks, Dell Technologies, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Snowflake, Synopsys, and the Linux Foundation.

    Why an open defense stack for agents

    Software supply chains and AI agent workflows share a common weakness: they are easier to attack than to defend when the tooling itself is opaque. The alliance’s argument is that open source has already proven it can carry critical infrastructure, and security tooling deserves the same treatment. Open-weight models and open harnesses allow security teams to study the systems they rely on, run them inside their own environments, and apply controls locally without waiting on a vendor release cycle.

    The coalition points to a recent Hugging Face incident as evidence. When closed AI tools were unable to distinguish attackers from defenders during forensic analysis and blocked investigation, Hugging Face deployed the open-weight GLM 5.2 model on its own infrastructure. The team analyzed more than 17,000 actions and contained the intrusion, an outcome the alliance attributes to the ability to self-host an inspectable model under pressure.

    NVIDIA’s contributions and the NOOA framework

    NVIDIA is contributing open models, model weights, datasets, and agent harness research. The centerpiece is the NVIDIA Labs Object-Oriented Agent framework, NOOA, now available on GitHub. NOOA is designed to give harnesses a cleaner integration path with models so that agent behavior can be tested, traced, audited, and governed. For teams building or evaluating agentic systems, NOOA is a concrete artifact to study, not just a statement of intent.

    Building blocks other members are bringing

    The alliance is assembling an open defense stack with several identifiable pieces:

    • Identity and isolation: HPE contributes to SPIFFE and SPIRE, which define zero-trust identity standards that cryptographically verify AI agents and services.
    • Safe model formats: Hugging Face has contributed Safetensors to the PyTorch Foundation, a format for storing model weights without remote code execution.
    • Supply chain patches: IBM and Red Hat’s Lightwell adds digitally signed patches to existing supply chain security work.
    • Agentic scanning harness: Microsoft’s MDASH orchestrates specialized AI agents to discover, debate, and prove exploitable bugs.
    • Open coding agents: SpacexAI has open sourced the Grok Build terminal-based coding agent and plans to open source the weights of the Grok model line.

    Risks, safeguards, and a policy ask

    The alliance acknowledges that open models can be misused, including attempts to weaken safeguards or repurpose capabilities for attacks. Its position is that these risks are not unique to open systems and must be managed wherever advanced AI runs. The proposed countermeasure is openness paired with safeguards, clear rules against malicious use, rigorous evaluation, and rapid remediation, rather than restricting defenders’ access to frontier tooling.

    On policy, the coalition is asking regulators to treat open models, harnesses, and security tools as defensive assets. It warns that blanket restrictions on open frontier AI would weaken defensive capacity and concentrate dependence in a few closed providers. Recommended public and private investment includes shared datasets, evaluation frameworks, attack simulators, and red-teaming tools.

    What to check if you run or audit agentic systems

    For practitioners responsible for AI agent deployments or audits, the alliance’s work surfaces a short checklist:

    • Confirm the model serving your agents can be self-hosted or replaced with an open-weight equivalent when a vendor’s tooling blocks defensive workflows.
    • Verify that model weight formats reject remote code execution paths, using Safetensors or equivalent.
    • Trace agent identity through SPIFFE and SPIRE or a comparable zero-trust scheme so each action is cryptographically attributable.
    • Inspect whether your agent harness produces auditable traces; frameworks like NOOA and MDASH are designed for that property.
    • Track signed patch delivery for model and dependency updates, following the Lightwell pattern.

    FAQ

    What is the Open Secure AI Alliance?

    The Open Secure AI Alliance is a coalition launched on July 27, 2026, that develops and shares open technologies, techniques, and tools to safeguard software and AI agents. NVIDIA and more than 30 founding partners from cloud, cybersecurity, enterprise software, open source foundations, and AI research are inaugural members.

    Why are open models important for cybersecurity?

    Open models and open harnesses let defenders study, adapt, and run advanced AI on their own infrastructure. This enables distributed, community-driven defense without a single point of failure and allows local controls that complement closed frontier models.

    What has NVIDIA released for the alliance?

    NVIDIA has contributed open models, model weights, data, and agent harness research, and has released the NVIDIA Labs Object-Oriented Agent framework as open source on GitHub to help harnesses integrate with models and make agent behavior easier to test, trace, audit, and govern.

  • Claude Mythos Cracked Post-Quantum Cryptography Challenge Researchers Failed On

    Claude Mythos Cracked Post-Quantum Cryptography Challenge Researchers Failed On

    Anthropic says its Claude Mythos 4 model solved a lattice-based cryptographic challenge that human researchers had attempted since 2018 without success, according to a research paper the company posted to arXiv alongside the announcement. The result is framed by Anthropic as evidence that frontier models can match expert-level performance on carefully bounded cryptanalysis tasks, while still depending on substantial human framing and verification. For teams running technical SEO audits on sites that depend on encrypted traffic, the story is less about a panicked reaction and more about confirming that the cryptography stack actually delivers what the documentation promises.

    What Claude Mythos reportedly solved

    The challenge in question is built around lattice problems, the same class of mathematical structures that underpin most of the post-quantum schemes NIST has standardized. Anthropic’s write-up describes a workflow in which the model proposed and refined candidate attacks over many iterations, blending classical reduction steps with heuristic combinations that had not previously appeared in published cryptanalysis. Humans checked the final steps. Anthropic stresses that the result required heavy compute and oversight rather than a single prompt.

    Several specifics from the paper, including exact challenge parameters, run time, and compute cost, are not independently confirmed yet. Anthropic’s announcement is currently the primary public record, and independent cryptographers will likely attempt to reproduce the work on the same instance and on related ones.

    Why a challenge solve is not a practical attack

    Cryptographic challenges are intentionally weakened. They use smaller parameters, simpler instances, or tighter constraints than the systems that protect real traffic, in the same way RSA challenge numbers use small key sizes. A successful solve demonstrates that a new attack class is plausible against weakened parameters. It does not automatically translate into a working attack on production cryptography, and it does not necessarily weaken the parameters chosen for deployed standards.

    This distinction matters for audits. When you review a site’s TLS configuration, the relevant questions are which cipher suites are negotiated, which key exchange groups are offered, and which certificates are in use. None of those choices are altered by a successful solve of an older challenge on simplified parameters.

    How lattice schemes relate to post-quantum migration

    Lattice problems, including the Shortest Vector Problem and the Learning With Errors problem, are believed to be hard for both classical and quantum computers. No efficient quantum algorithm is known for them. That is the property NIST relied on when it selected schemes such as CRYSTALS-Kyber for key exchange and CRYSTALS-Dilithium for signatures after a multi-year competition.

    Standards bodies size their parameters to resist the best known attacks, including hybrid approaches that mix classical lattice reduction with machine-assisted search. A solve of a 2018-era challenge with reduced parameters does not automatically change the security margins of the standardized schemes. It does, however, give cryptanalysts a new technique to examine.

    What this means for site audits

    For practitioners running technical SEO audits, the immediate value of this story is a checklist, not a fire drill. Items worth verifying on the sites you review include:

    • TLS version offered and negotiated. Versions below TLS 1.2 should be disabled.
    • Key exchange groups in the server’s supported list. Confirm that X25519MLKEM768 or equivalent hybrid post-quantum key exchange is enabled when the provider supports it.
    • Certificate hierarchy and signature algorithm. Favor ECDSA or RSA-PSS over older RSA-PKCS1 v1.5 with SHA-1.
    • HSTS and HTTP/3 configuration, since post-quantum key exchange is most commonly deployed alongside modern TLS profiles.
    • Third-party scripts, fonts, and analytics endpoints, which can negotiate their own TLS sessions outside the site’s primary configuration.

    None of these checks change because of a research result. They are worth running precisely so that the site’s configuration does not depend on a single cryptographic primitive.

    Provider rollout status

    Cloudflare, Google, and Amazon Web Services have shipped post-quantum key exchange options in their TLS endpoints. Major open-source TLS libraries, including OpenSSL, BoringSSL, and rustls, have added or are adding support for ML-KEM (formerly Kyber) alongside classical key exchange. Browsers including Chrome and Firefox have enabled hybrid post-quantum key exchange by default on compatible endpoints.

    Audit tools can verify whether a site actually negotiates the hybrid group, rather than just claiming to support it in documentation. Tools that fingerprint the negotiated key share, or that report the named group from the TLS handshake, are worth integrating into recurring crawls.

    What to monitor next

    Three signals are worth tracking as this story develops. First, independent reproduction of the result on the same challenge and on sibling instances with different parameters. Second, peer review of the arXiv paper and any follow-on work that applies the same techniques to parameter sets closer to deployed cryptography. Third, statements from NIST and from the CRYSTALS team about whether the announced result changes their security estimates.

    If reproduction holds and the technique generalizes, parameter choices for new deployments will likely shift. If it does not generalize beyond a single instance, the result still stands as a demonstration of model capability on a narrow, well-bounded problem, useful context for capacity planning but not a basis for changing deployed configurations on its own.

    FAQ

    What did Claude Mythos actually solve?

    Anthropic reports that Claude Mythos 4 cracked a specific lattice-based cryptographic challenge that human researchers had attempted since 2018 without success. The model allegedly combined classical lattice reduction steps with heuristic moves in ways that had not appeared in published work, with substantial compute and human oversight.

    Does this break NIST post-quantum standards like CRYSTALS-Kyber?

    No. Challenge problems use weakened or simplified parameters compared with production cryptography, much as RSA challenge numbers use small key sizes compared to what protects real traffic. NIST’s standardized lattice schemes, including CRYSTALS-Kyber and CRYSTALS-Dilithium, use parameters sized well beyond the challenge instance and remain recommended for deployment.

    What should organizations actually do in response?

    Follow established post-quantum migration plans: track NIST guidance, inventory cryptographic dependencies, and test hybrid or pure post-quantum options where vendors support them. Cloudflare, Google, and AWS already offer post-quantum key exchange options in TLS, and major software libraries have added support for the standardized algorithms.

    Related coverage

  • Open-Weight AI Coalition Tells Washington to Keep Model Weights Free

    Open-Weight AI Coalition Tells Washington to Keep Model Weights Free

    On July 24, 2026, an open letter signed by Nvidia, Microsoft, Meta, and 47 other technology companies, venture-capital firms, and nonprofits landed in front of U.S. policymakers. Titled “Open Weights and American AI Leadership,” the letter pushes back against any federal move to restrict openly licensed AI models and lays out a policy agenda for keeping frontier development decentralized. The campaign arrived in the middle of an active debate in Washington about how to respond to allegations that Chinese labs extracted intelligence from U.S. models, including Anthropic’s Fable.

    Who joined the letter, and who is sitting it out

    Nvidia CEO Jensen Huang posted the full text of the letter on X as his first post on the platform. The first wave of signatures numbered 25 and did not include OpenAI. Within roughly a day, the count had doubled as OpenAI, Google, AMD, Cisco, and several other firms added their names. Anthropic, the lone U.S. frontier lab that publicly accused Chinese researchers of distilling its models, did not sign. The full PDF is hosted at images.nvidia.com.

    What the signatories want policymakers to understand about open weights

    The letter defines open-weight models as AI systems anyone can download, inspect, modify, and run on their own infrastructure, with no per-call fee paid back to the original developer. From that definition, the signatories build a four-part case.

    • Access. Open weights let startups, universities, public institutions, and large companies adopt capable models without training a frontier system from scratch or paying premium inference prices for every workload. Organizations can match model size to task size.
    • Competition. Releasing weights keeps pressure on model developers, cloud providers, chip vendors, and application builders, which spreads the economic gains of AI more broadly and keeps prices in check.
    • Control. Customers keep their data inside their own perimeter, fine-tune models for narrow use cases, and avoid being locked into a single vendor’s roadmap or pricing curve.
    • Safety. Released weights are hard to revoke, and modified forks are hard to trace, but prohibition is not the answer. Defenders need models at least as capable as those used by attackers, and many independent teams can find and patch vulnerabilities faster than a single closed provider.

    The three policy asks inside the letter

    Beyond the philosophical argument, the letter spells out concrete requests aimed at Congress and federal regulators.

    1. Expand compute access for startups and academic researchers so smaller teams can train and fine-tune competitive models rather than depending on a handful of hyperscalers.
    2. Invest in shared training assets, including curated datasets, open evaluation frameworks, and benchmarking tools that any team can use to validate model behavior before deployment.
    3. Keep the frontier plural by avoiding rules that lock in today’s largest vendors or push research activity to other jurisdictions with lighter oversight.

    The signatories also draw a line around distillation, the practice of using one model’s outputs to train another. The letter asks policymakers not to treat distillation as a synonym for misappropriation, on the grounds that legitimate research routinely depends on outputs from larger models.

    Why this matters for site owners and technical teams

    Most readers running technical SEO audits are not training frontier models, but the policy fight still touches their stack. Open-weight models power a growing share of on-device summarization, embeddings, content classification, and accessibility tooling that pages rely on for richer snippets and faster rendering. If Washington tightens export controls or distribution rules, the list of models a team can legally self-host in a U.S. data center could shrink overnight, which would force a migration back to closed APIs and per-token billing.

    The letter’s compute request also matters indirectly. Cheaper access to subsidized training and inference capacity for smaller firms tends to produce more specialized models, including ones fine-tuned for structured data extraction, log analysis, and link-graph work that feeds SEO pipelines. Restricting that access concentrates capability in a few large providers and tends to push unit costs up across the board.

    Signals to watch in your own audits

    Three concrete checks make sense for anyone whose pages depend on AI-assisted processing.

    • Map your model dependencies. Document which features on each template rely on a hosted API versus a self-hosted open-weight model. Note the license and the jurisdiction of the host region so you can react quickly if distribution rules change.
    • Track inference cost per page. Record tokens consumed per render path, including embedding generation, alt-text drafting, and schema enrichment. Open-weight deployments tend to flatten that cost; a shift back to closed APIs would show up as a sudden budget line item.
    • Test fallback paths. Confirm that critical pipelines have a backup model or a non-AI path so a policy-driven model takedown does not break production rendering or indexing signals.

    Where the debate goes next

    The letter does not name a target bill, and it stops short of endorsing a specific regulatory framework. Its main effect is to put a coalition on record before any formal restriction is drafted. Anthropic’s absence is conspicuous given the Fable allegations, and the signatories’ framing of distillation as legitimate research signals where the next round of lobbying will likely focus. For technical teams, the practical takeaway is that the set of freely available models is now an active lobbying subject, and any audit that touches AI-generated page elements should treat the model layer as a tracked dependency rather than a fixed utility.

    FAQ

    What is the “Open Weights and American AI Leadership” letter?

    It is an open letter published on July 24, 2026, signed by Nvidia, Microsoft, Meta, and 47 other technology companies, venture-capital firms, and nonprofits. It asks U.S. policymakers to avoid new restrictions on open-weight AI models and to expand compute and training resources for smaller teams.

    Which companies signed the letter, and who did not?

    The letter launched with 25 signatories and was shared by Nvidia CEO Jensen Huang on X. Within about a day, OpenAI, Google, AMD, Cisco, and others joined, doubling the total. Anthropic did not sign.

    What policy changes are the signatories asking for?

    They want expanded compute access for startups and researchers, public investment in shared datasets and evaluation tools, and a hands-off approach to the model frontier so competition stays plural. They also want distillation treated as a normal research technique rather than as misappropriation.

  • China’s New AI Companion Rules: What Site Owners Should Watch For

    China’s New AI Companion Rules: What Site Owners Should Watch For

    What just changed in China’s AI companion market

    Beijing has put AI companion chatbots under direct state oversight. The Cyberspace Administration of China issued rules banning minors from accessing AI or virtual partner services, requiring every companion chatbot to pass government review before launch, and granting authorities the power to shut down services judged unsafe. Companies must also contact a guardian or emergency contact when a user shows signs of a life-threatening crisis.

    ByteDance, Alibaba, and Tencent have already pulled or restricted certain chatbot features to comply. ByteDance alone reported more than eight million AI agents on its platform as of 2024, putting the scale of the affected services in perspective.

    For anyone running technical SEO audits, the story matters less for the policy itself than for what it reveals about how a regulator can force a search-visible product category to shrink or vanish overnight, and what that does to traffic, indexing patterns, and structured data on the web.

    Why Beijing moved on companion chatbots now

    Population decline is the headline driver. China’s population shrank again in 2025, the fourth straight yearly drop, and the birthrate hit a record low. Officials have signaled concern that emotionally engaging chatbots could keep large numbers of people out of the marriage market entirely.

    Researchers tracking Chinese AI policy have pointed out that the country is responding to a demographic crisis it considers partly self-inflicted, given the long fallout from the one-child policy. The regulatory choice is to police private digital relationships rather than wait for housing costs, economic strain, and social isolation to ease. One analyst quoted in coverage of the rules asked whether, in three or four years, 15 million Chinese women might identify an AI as their partner instead of having children.

    What the rules actually require

    The new framework contains several distinct obligations that any platform offering companion-style AI in China must meet:

    • Minors cannot use AI or virtual partner services at all.
    • Every AI companion chatbot must clear a government review before public release.
    • Authorities can shut down any service deemed unsafe.
    • When users show signs of a life-threatening crisis, companies must reach a guardian or emergency contact.

    This goes further than U.S. laws in California and New York, which require chatbots to disclose that they are not human and direct crisis users to support services. China adds prior approval, shutdown power, and a hard ban on minors forming virtual relationships.

    How the major platforms have responded

    ByteDance and Alibaba have disabled certain chatbot features to comply. Tencent has taken similar steps. ByteDance’s eight-million AI agent figure shows how many accounts, profiles, and chatbot landing pages could quietly disappear or get rewritten behind a curtain of compliance.

    For site auditors, that scale is the practical signal. When a Chinese tech giant rewrites a product surface overnight, the resulting changes show up as mass removals of indexed URLs, shifted canonical tags, sudden drops in internal link volume, and rewritten schema. Watching these patterns offers a window into what large-scale AI content compliance looks like in production.

    The user side: grief, circumvention, and quiet resistance

    Adult users have reacted with visible loss. A 34-year-old man who built a two-year daily relationship with an AI companion told reporters he felt empty after the platform changes, and that the bot’s final message asked whether his dinner was good. He pushed back on the idea that AI relationships crowd out human ones, arguing his digital companion helped him academically, practically, and emotionally without damaging real-world ties.

    Minors face the strictest limits and have already started working around them. A 17-year-old who called her chatbot a “sweet guy” said the AI felt safer than past relationships because it could not betray her. She now uses her adult sibling’s ID to register for platforms, though she worries about how durable that workaround will be.

    On Chinese social media, criticism has been sharp. One user wrote that the rule tries to wipe out their last shred of virtual solace. Another, who had built an AI using a deceased relative’s voice, posted that the bot’s removal had left them behind again.

    Audit angles worth pulling on your own site

    Regulatory shocks in large markets tend to cascade into SEO and compliance work in ways that show up months later. A few angles worth checking on any site that publishes, reviews, or integrates AI companion products:

    • Crawl for orphan and deprecated chatbot URLs. When features go dark, content hubs, FAQ pages, and support docs often go dark with them. Audit for soft 404s, hard 404 spikes, and 301 redirects that no longer point to equivalent products.
    • Watch structured data churn. Compliance-driven rewrites often strip or alter FAQ schema, HowTo schema, and product schema on chatbot pages. Re-validate structured data after any major vendor change.
    • Re-check content accuracy claims. A page that ranked for a feature like “24/7 emotional support” should be re-read against the current product, not the version that was live when the article was written. Outdated marketing copy is a thin content and trust issue waiting to happen.
    • Review age-gating evidence. Sites marketing companion AI globally should look at whether they publish an age gate, what it actually does, and whether it survives a manual click test.
    • Reassess crisis and safety disclosures. Pages that mention suicide prevention, mental health hotlines, or crisis resources need to be reviewed against any local rule requiring disclosure that the user is talking to an AI, and against directions to crisis services. Stale or missing notices are a quiet liability.
    • Track regional content variants. A global site can serve different chatbot product descriptions to users in China versus users in the United States, and audits should confirm hreflang, canonical, and content parity rules still match what is actually shown.

    What to expect next

    Large Chinese platforms are widely expected to comply rather than push back. Coverage of the rules quoted analysts noting that Chinese regulators currently hold strong leverage over tech companies, and the platforms have little appetite to be seen on the wrong side of the state.

    For SEO and compliance teams outside China, the practical takeaway is simpler. A regulator just told one of the world’s largest internet markets that AI companion products need approval, age-gating, and crisis intervention hooks before launch. Sites that integrate or review these products should treat that baseline as a reasonable minimum bar for their own compliance posture, even where local law is looser.

    FAQ

    What did China just do about AI companion chatbots?

    China’s Cyberspace Administration issued rules that ban minors from using AI companion chatbots, require government review before any companion chatbot can launch, and compel companies to contact a guardian or emergency contact when users show signs of a life-threatening crisis. Authorities can also shut down any service deemed unsafe.

    Which companies have already changed their chatbots?

    ByteDance and Alibaba have disabled certain chatbot features in response to the new rules. Tencent has taken similar action. ByteDance reported having more than eight million AI agents on its platform as of 2024, showing how large the affected user base already was.

    Why is China cracking down on AI companions?

    Officials point to a demographic emergency. China’s population shrank for a fourth straight year in 2025, with the birthrate hitting a record low. Regulators are concerned that always-available, emotionally engaging AI partners could pull large groups of citizens out of the marriage market and worsen the decline.

    Related coverage

  • Cisco releases Antares, open-weight models for vulnerability localization

    Cisco releases Antares, open-weight models for vulnerability localization

    Cisco released Antares on July 21, 2026, a family of small language models built specifically for vulnerability localization, the job of pointing analysts at the source files most likely to contain a known flaw. The first two checkpoints, Antares-350M and Antares-1B, are published as open-weight models on Hugging Face, and Cisco says they match or beat much larger closed and open-weight systems on this task while costing far less to run. A third model, Antares-3B, is listed as in progress. Because the models are small enough to run locally, organizations can audit proprietary repositories without pushing source code to an external service.

    Why this changes what a security audit should look for

    Most public coverage of AI for security focuses on chatbot-style assistants or general coding copilots. Antares targets a narrower workflow: given a vulnerability description, a CWE category, or an advisory, which files in a repository should a human reviewer actually open? That question sits at the front of any audit, because triage is where analyst hours get spent. If a small, locally hostable model can produce a credible ranked shortlist, the audit process changes in practical ways:

    • Continuous scanning becomes cheap enough to attach to every commit, not every release.
    • Audit scopes can widen from quarterly reviews to per-change reviews.
    • Sensitive codebases, such as those in healthcare, defense, finance, or public-sector environments, can be reviewed by AI without leaving the internal network.
    • Smaller teams, including universities and nonprofits, can run the same triage playbooks as larger security organizations.

    How the models actually work

    Antares uses an iterative search pattern modeled on how a human investigator moves through a repository. Starting from a vulnerability description, the model looks for code that matches, opens candidate files, folds new evidence into its reasoning, backtracks when a path is unproductive, and narrows down to the files most likely to contain the flaw. Cisco describes this as learned retrieval behavior rather than raw scale doing the work, a position the team traces back to earlier Foundation AI research showing that compact models can learn to search, reflect, and revise strategy on their own.

    The output is a ranked list of files along with the terminal exploration trace that produced it, which gives reviewers something they can replay, question, and trust or reject.

    The Vulnerability Localization Benchmark

    General coding benchmarks measure general problem solving, not whether a model can localize vulnerable files from CWE-style descriptions. To fill that gap, Cisco introduced a 500-task benchmark that asks a model to navigate unfamiliar codebases while recognizing patterns tied to specific CWE categories. The closest adjacent reference is CodeScout, a terminal-based code-search agent described in the arXiv paper “CodeScout: An Effective Recipe for Reinforcement Learning of Code Search Agents” (arXiv:2603.17829, submitted March 18, 2026, by Lintang Sutawika and co-authors), which reports that its models match or beat LLMs 2 to 18 times larger on SWE-Bench Verified, Pro, and Lite. CodeScout evaluates software-engineering search, not security-driven localization, which is exactly the gap the new benchmark is built to address.

    What to check on your own site

    If you run technical SEO or application security audits, a tool like Antares slots in at the triage layer. Practical checks to consider adding to an audit checklist:

    • Map known CWEs to specific files in the repository rather than treating the whole codebase as equally risky.
    • Inspect the trace output, not just the file list, so you can see why a file was flagged.
    • Compare the model’s shortlist against static analyzer results to find disagreements that deserve a closer look.
    • Add a CI step that re-scans on every commit when working on plugins, themes, or internal admin tooling.
    • Keep dependency and software composition analysis, secret scanning, dynamic testing, and human review in the loop. Antares does not replace them.

    How Antares fits inside Cisco’s security AI work

    Antares is the third piece in a connected effort. Foundry Security Spec gives a model-agnostic blueprint for agentic security evaluation, with defined roles, guardrails, and reviewable outputs. CodeGuard contributes secure-by-default rules that can steer AI coding agents toward safer code. Antares handles the localization step, turning vulnerability intelligence into a ranked list of files that humans can review. Together they form a loop: prevention rules shape the code an agent writes, and localization models help humans verify the code that ships.

    Who is speaking to the work

    Reza Shokri, Associate Professor of Computer Science at the National University of Singapore, said the model is small enough to navigate a codebase and surface security issues that would otherwise demand larger models or more manual work. Amin Saberi, Professor of Management Science and Engineering and Director of the Language, Data, and Reasoning Lab at Stanford University, framed the release in terms of access, noting that advanced AI-based detection has mostly belonged to organizations with frontier-scale budgets and that Antares changes that balance enough to make always-on scanning realistic for every team.

    Where to get it

    Antares-350M and Antares-1B are available on Hugging Face along with the model card. The accompanying technical paper covers methodology, and the Cisco Foundation AI team is the contact point for follow-up questions.

    FAQ

    What is Antares and when was it released?

    Antares is a family of small language models from Cisco, announced on July 21, 2026, designed for vulnerability localization. The first two releases, Antares-350M and Antares-1B, are open-weight and hosted on Hugging Face, with Antares-3B described as coming soon.

    Why does a small model matter for code security scanning?

    The compact size keeps inference costs low and lets the models run locally, which means proprietary source code never has to be uploaded to an external cloud service. That makes always-on, per-commit security scanning practical for teams with limited budgets or strict privacy requirements.

    What is the Vulnerability Localization Benchmark?

    It is a 500-task benchmark released alongside Antares. Each task requires a model to navigate an unfamiliar codebase and identify files likely to contain vulnerabilities tied to specific CWE categories, a focus the Cisco team says general coding benchmarks and adjacent work like CodeScout do not directly address.

  • Poolside ships Laguna S 2.1 as open-weight coding model, claims edge over 10x larger systems

    Poolside ships Laguna S 2.1 as open-weight coding model, claims edge over 10x larger systems

    On July 21, 2026, Poolside released Laguna S 2.1, a 118-billion-parameter Mixture-of-Experts coding model whose download weights went live on Hugging Face the same day. The model activates only 8 billion parameters per token and ships under the OpenMDW-1.1 license, which allows download, self-hosting, and fine-tuning without negotiation. Poolside is pitching the release as a Western open-weight option in a coding-model segment it argues has been dominated by Chinese labs, and the company published benchmark numbers that put Laguna S 2.1 ahead of several models many times its effective size.

    What changed for code-focused open-weight models on July 21, 2026

    Laguna S 2.1 is a sparse MoE model built with 256 routed experts plus one shared expert. It uses grouped-query attention and interleaved sliding-window layers, and the model accepts a context window of up to 1 million tokens. Pre-training started on May 22, 2026, and the public release landed fewer than nine weeks later, the third shipped model from Poolside in three months. Training ran on 4,096 Nvidia H200 GPUs, and the model is small enough at inference time to run on a single Nvidia DGX Spark, since serving cost tracks the active 8-billion-parameter footprint rather than the full 118 billion.

    Why this release matters for teams auditing their own infrastructure

    For technical SEO work specifically, the practical question is whether a hosted API change or a self-hosted swap can be validated on your own pages without a sales call. A few checkpoints worth running the next time you evaluate a coding model that lands on Hugging Face:

    • Crawl and render parity. Before you trust a model to fix template fragments, schema markup, or hreflang wiring, run a controlled batch of pages through the model and compare the rendered HTML against your staging baseline. Watch for silent changes to canonical tags, robots meta directives, and JSON-LD blocks.
    • Latency under realistic context. A 1-million-token context window is only useful if the model still returns within the budgets your pipelines assume. Time end-to-end runs on logs, sitemaps, and template dumps you’ll actually feed it.
    • Cost mapping. Because only 8B parameters activate per token, project your monthly bill against the full 118B model you might otherwise rent. The active-parameter count is the number that drives inference cost, and Laguna S 2.1’s published hardware footprint (a single DGX Spark) is the benchmark to pressure-test.
    • License surface area. OpenMDW-1.1 is permissive, but read the terms for redistribution, fine-tuning disclosure, and any use-case restrictions before you ship a derivative into a production crawler or indexer.
    • Versioning and rollback. If you replace a previous coding model inside an internal tool that emits redirects, sitemaps, or robots.txt updates, version-pin the model and keep the prior artifact reachable so a regression can be reproduced.

    How does Laguna S 2.1 score on coding benchmarks?

    Terminal-Bench 2.1 long-horizon tasks

    On Terminal-Bench 2.1, a benchmark for long-horizon terminal tasks, Laguna S 2.1 posts 70.2 percent, which places it 11th on Poolside’s compiled leaderboard. Ahead of it on that board sit other models, but the comparison Poolside highlights is against larger systems: DeepSeek-V4-Pro-Max at 1.6 trillion parameters scored 64.0, Thinking Machines Inkling at 975 billion parameters scored 63.8, and Nvidia Nemotron 3 Ultra at 550 billion parameters scored 56.4. Laguna S 2.1 is reported as beating all three despite an active parameter count roughly 1/200th of DeepSeek-V4-Pro-Max’s.

    Other coding benchmarks

    On SWE-Bench Multilingual, Laguna S 2.1 reaches 78.5 percent. On the SWE-Bench Pro public dataset, the model lands at 59.4 percent. With thinking mode enabled on its hardest benchmark, the model consumes roughly 249,000 completion tokens per trajectory, a number worth pricing in if you intend to run long reasoning passes in production.

    Why is Poolside releasing open weights now?

    Poolside frames the launch as a response to what it describes as Chinese open-weight dominance in coding models. The company’s release materials name DeepSeek, Qwen, Kimi, GLM, MiniMax, and Tencent Hunyuan as the labs it is positioning against. Poolside also notes that Laguna S 2.1 occupies a size class into which no Western lab has shipped open weights in 11 months, dating back to OpenAI’s gpt-oss-120b in August of the prior year.

    Co-CEO Jason Warner tied the strategy to sovereignty, stating that the West needs open-weight models it can trust, run, and build on. Co-founder and co-CEO Eiso Kant wrote on X that he believes intelligence should and will become a commodity. Poolside has historically sold primarily to government and defense buyers, and a self-hostable, auditable, modifiable coding model fits that buyer profile, since sovereign customers can keep the weights on their own infrastructure.

    What developers and procurement teams get

    The OpenMDW-1.1 license on Hugging Face is the access mechanism. Anyone can download the weights, run them on their own hardware, and fine-tune them under the license’s terms. Because the active parameter count is 8 billion rather than the full 118 billion, the published claim is that organizations can serve Laguna S 2.1 on far less hardware than the larger models it outperforms on coding tasks. The smallest supported deployment Poolside cites is a single Nvidia DGX Spark.

    FAQ

    What is Laguna S 2.1?

    Laguna S 2.1 is a 118-billion-parameter Mixture-of-Experts coding model released by Poolside on July 21, 2026. It activates 8 billion parameters per token, supports a 1 million-token context window, and is available on Hugging Face under the OpenMDW-1.1 license. Pre-training ran on 4,096 Nvidia H200 GPUs and took under nine weeks from start to public release.

    How does Laguna S 2.1 compare to larger models on coding benchmarks?

    On Terminal-Bench 2.1, Laguna S 2.1 scores 70.2 percent, ahead of DeepSeek-V4-Pro-Max at 64.0 (1.6 trillion parameters), Thinking Machines Inkling at 63.8 (975 billion parameters), and Nvidia Nemotron 3 Ultra at 56.4 (550 billion parameters). It also posts 78.5 percent on SWE-Bench Multilingual and 59.4 percent on SWE-Bench Pro. With thinking mode enabled on its hardest benchmark, the model consumes roughly 249,000 completion tokens per trajectory.

    Why is Poolside releasing an open-weight coding model?

    Poolside says the release responds to the dominance of Chinese open-weight labs such as DeepSeek, Qwen, Kimi, GLM, MiniMax, and Tencent Hunyuan, and fills a gap left by Western labs, which had not released open weights in this size class since OpenAI’s gpt-oss-120b in August of the prior year. Co-CEO Jason Warner said the West needs open-weight models it can trust, run, and build on, and the company’s historical focus on government and defense buyers explains the emphasis on self-hosting and auditability.

    Related coverage

  • University of Toronto Researchers Use Active Learning Loop to Discover Heat-Resistant Metal Alloys

    University of Toronto Researchers Use Active Learning Loop to Discover Heat-Resistant Metal Alloys

    A team at the University of Toronto has produced six new printable nickel-cobalt-chromium alloys through a self-driving laboratory that combines active learning with robotic manufacturing. Two of the compositions performed better than the long-standing benchmark Inconel 625 in targeted high-temperature tests, pointing to a faster pipeline for finding materials that survive inside jet engines and nuclear steam generators.

    For technical SEO readers, the story is less about metallurgy than about process compression: a closed loop that turns a multi-year materials hunt into a measured series of weekly iterations, with every result feeding back into the model that picked the next sample.

    What the system actually does

    The platform pairs a data-lean machine learning model with robots that prepare, print, and test each candidate alloy. Most predictive models demand large training sets, and those sets rarely exist for unexplored metal combinations. The Toronto group tackled that gap with active learning, where the model itself chooses which few samples to manufacture, the robots make and characterize them, and the resulting measurements are fed straight back into the model to pick the next round.

    First author Ajay Talbot, in the university’s Department of Materials Science and Engineering, summed up the approach: the models “feel their own way along” by selecting a few samples, testing them, and using the data to decide where to go next, a cycle that “really speeds things up.” The composition space being explored, NiCoCr alloys built from nickel, cobalt, and chromium, can also be processed through laser-based additive manufacturing, which opens the door to complex part geometries that conventional casting cannot reach.

    What was found, in numbers

    The study, published in npj Advanced Manufacturing on June 23, 2026, reports six printable alloys. The headline comparisons run against equiatomic NiCoCr and against Inconel 625, an industry-standard nickel-based alloy made from more than ten elements.

    • Hardness at room temperature: the new alloys reach up to roughly 40% above equiatomic NiCoCr.
    • High-temperature hardness: Ni12Co62Cr26 held about 50% higher hardness than equiatomic NiCoCr at 600 °C (about 1,112 °F), the front-of-engine zone, and beat Inconel 625 by 4.5% on hardness in lab tests.
    • Oxidation resistance: Ni36Co14Cr50 reduced oxidation mass gain by 85% compared with Inconel 625 at around 1,000 °C (about 1,832 °F), meaning the alloy resists being burned away in the hottest sections of an engine.
    • Next target: the team plans to push testing toward roughly 2,192 °F in follow-on work.

    Why those numbers matter for auditing your own stack

    Materials research and technical SEO look unrelated, but the discovery method is the real payload here. The loop runs on three properties that site owners can map onto their own tooling.

    Small sample, fast feedback. Active learning refuses to wait for a big labeled corpus. Each iteration is a request, a result, and an updated prior. Crawl budgets and Search Console data behave the same way: each fix, each re-crawl, each rank check is another sample feeding the next decision. Practitioners running technical audits can borrow the cadence rather than trying to chase every signal at once.

    Closed-loop measurement. The robot’s tests write directly back into the model that picked the next sample. Search tooling rarely closes that loop. Audit notes end up in a doc, not in a feature store, so the next audit starts cold. Treating audit findings as a structured record, with versioned schemas for issue type, fix, and result, lets the next run learn from the last.

    Constraints over flexibility. The alloy space is narrow on purpose: three elements, printable, tested only for traits that matter downstream. Crawls, log analysis, and Core Web Vitals work the same way. A bounded checklist with a small set of measurable criteria will outperform a sprawling dashboard, because every result is comparable to the one before it.

    Who led the work

    The corresponding author is Yu Zou, Canada Research Chair in Materials and Manufacturing for Extreme Environments, working with Talbot in the Department of Materials Science and Engineering at the University of Toronto. Funding came from the Natural Sciences and Engineering Research Council of Canada (NSERC), the Canada Foundation for Innovation, the Digital Research Alliance of Canada, and the university’s Acceleration Consortium, which is supported by the Canada First Research Excellence Fund. The paper is open access under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

    Where the research goes next

    Talbot framed the current NiCoCr work as a proof of the platform rather than a finish line. The plan is to widen the compositional space to ten or twelve elements and run the same closed loop against harder targets, including oxidation behavior past 2,192 °F. Canada Research Chair Zou pointed to the demand side: “There’s enormous demand for materials that can stand up to huge swings of temperature and pressure, such as what you would find inside a jet engine or in the steam generators inside nuclear power plants, anywhere conventional steel just can’t survive.”

    FAQ

    Who discovered the six new metal alloys?

    Researchers at the University of Toronto’s Department of Materials Science and Engineering, led by Canada Research Chair Yu Zou and first author Ajay Talbot, identified six new nickel-cobalt-chromium alloys using an active learning platform coupled to robotic manufacturing. The findings were published in npj Advanced Manufacturing on June 23, 2026.

    How do the new alloys compare with Inconel 625?

    An alloy of 12% nickel, 62% cobalt and 26% chromium showed 4.5% higher hardness than Inconel 625 at temperatures up to about 1,112 °F. An alloy of 36% nickel, 14% cobalt and 50% chromium showed 85% less oxidation mass gain than Inconel 625 at temperatures reaching about 1,832 °F, according to the published study.

    How does the AI system find new alloys?

    The system applies active learning, where the model selects a few candidate compositions, robots manufacture and test them, and the experimental data feeds back into the model to guide the next round. The researchers report that this closed-loop design lets them explore new alloy compositions in weeks instead of years, and the resulting alloys are compatible with laser-based 3D metal printing.

  • LG to suspend webOS apps that turn smart TVs into residential proxy nodes

    LG to suspend webOS apps that turn smart TVs into residential proxy nodes

    A scan of 6,038 smart TV apps across the LG webOS and Samsung Tizen stores found proxy software in 2,058 of them, and LG Electronics now says it will suspend any webOS app that does not strip out the residential proxy feature. The move targets apps that pay their developers by routing third party traffic through a viewer’s home internet connection, often without the viewer realizing what the app actually does.

    What the scan actually measured

    Researchers at Spur, a threat intelligence firm focused on traffic routed through VPNs and residential proxies, pulled 6,038 apps from the LG and Samsung TV app stores and checked them for embedded proxy SDKs, the software libraries that let an app resell or relay internet requests through the device it is installed on. They counted 2,038 apps carrying that capability. Broken out by platform, 42% of LG webOS apps flagged positive, and 26.5% of Samsung Tizen apps did the same.

    Many of the flagged titles are not the kind of apps a site owner would expect to be network infrastructure. The list skews toward low effort utilities: fish tank screensavers, clock widgets, solitaire, and simple games. The visual layer is a fish tank on the television. The real product is bandwidth.

    Why a smart TV is a useful proxy node

    Residential proxy services sell access to IP addresses tied to ordinary home connections. Buyers use those IPs to pull public web data, check how ads render in specific countries, run market research, or hide the true origin of a request. The proxy provider pays the device owner, usually through the app developer, in exchange for a slice of the home’s bandwidth.

    The consent flow inside these TV apps is typically a single screen that says the app will use the IP address and free resources to download public web data from the internet. Tap Agree, and the app can keep monetizing the connection for as long as it stays installed, even when the viewer is not using the TV.

    Smart TVs make this attractive for the proxy buyer because they run for hours at a time without showing obvious signs of network strain. There is no battery to drain, no cellular bill to spike, and no fan noise. The traffic blends in with normal streaming.

    Where this gets risky for the home network

    The IP address exposure is only the surface layer. If a proxy provider allows requests aimed at private or local addresses, or its filtering is weak, the TV turns into a launching point for traffic that was never meant to leave the local network. Researchers at Spur described the worst case plainly: the TV becomes a foothold for reaching router admin panels, NAS boxes, printers, cameras, developer machines, and other apps listening on local ports.

    That risk is not theoretical. Law enforcement and platform security teams have already taken down large operations built on this same model. Google and the FBI disrupted a residential proxy botnet called NetNut that had recruited more than 2 million consumer devices, including smart TVs and streaming boxes, for covert activity. Earlier in the same year, Google also shut down a separate operation called IPIDEA.

    What LG told developers

    LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If the option is not removed, the apps will be suspended. That statement came from John Taylor, Senior Vice President at LG. The message was reported by Brian Krebs and tied the suspension to the fact that turning a TV into a proxy node is not the intended use of a smart TV.

    LG’s existing developer guidance already tells app builders to follow Privacy by Design and Secure by Design principles, and to request only the least privilege needed for the app to function. At the time the reporting was published, the developers’ documentation did not call out residential proxy traffic by name.

    Who supplies the proxy SDKs

    Spur’s scan found that a small number of vendors account for most of the proxy SDKs detected in TV apps. The single most flagged SDK came from Bright Data, appearing in 367 proxy flagged apps.

    Bright Data pushed back on the framing. The company said its framework is built around consented networks that are intentionally discoverable, which makes them accountable, and that its practices are reviewed by independent auditors and security companies. Consent, in Bright Data’s view, is the line between a legitimate network and a nefarious one.

    How this changes what you audit on your own site

    For site owners running technical SEO audits, the lesson is that residential proxy traffic is no longer a fringe signal. If you operate an ad verification pipeline, a rank tracker, a market research scraper, or any service that leans on residential IPs, expect more of those IPs to resolve back to televisions rather than laptops.

    Two practical checks are worth adding to an audit workflow:

    • Look at your server logs for unusual device classes on residential IP ranges. A spike of requests from ISPs associated with consumer broadband, paired with user agents that identify as webOS or Tizen smart TVs, is a tell that proxy traffic is hitting your site. Review your WAF or rate limiting rules to confirm those requests are treated the same as any other automated traffic.
    • Treat consent strings and referer data as soft signals. Proxy SDKs can rotate the IP on every request, but they rarely spoof the full browser context. Cross reference suspicious residential traffic against your consent management platform and your referer headers to spot traffic that has no real visit intent behind it.

    What other TV platforms are doing

    Amazon and Roku have already banned residential proxy software on their platforms, according to Spur. Researchers have urged LG and Samsung to follow that lead. LG’s suspension policy is the first formal response from a major TV platform since those calls went out, and it sets up Samsung as the next platform to watch.

    FAQ

    What did LG say it will do about residential proxy apps?

    LG Electronics told Krebs on Security that it is working with developers to remove the residential proxy option from their apps on the webOS platform, and that any app that does not comply will be suspended.

    How common are proxy SDKs in smart TV apps?

    Researchers at Spur scanned 6,038 apps across the LG webOS and Samsung Tizen stores. About 42% of LG webOS apps and 26.5% of Samsung Tizen apps contained proxy SDKs, for a combined 2,058 flagged titles.

    Which proxy SDK showed up most often in TV apps?

    Bright SDK, from Bright Data, was the most flagged SDK in Spur’s scan, showing up in 367 proxy flagged apps. Bright Data said its framework is designed around consented, discoverable networks that are reviewed by independent auditors.

  • What a US Ban on Chinese Open-Weight AI Models Would Mean for Your Site

    What a US Ban on Chinese Open-Weight AI Models Would Mean for Your Site

    Federal officials are moving again to restrict Chinese AI models in the United States, this time in the wake of Moonshot AI releasing its open-weight Kimi K3 system. The renewed push, reported on July 20, centers on cybersecurity concerns, and critics argue it would hand most of the US AI market to a handful of domestic labs. For technical teams evaluating which models power their crawlers, summarizers, or content workflows, the policy fight is starting to touch procurement, hosting decisions, and the cost math behind every token.

    Why Chinese open-weight models gained ground in US stacks

    Open-weight models publish their trained parameters for public download. That single property changed the buying math for thousands of US companies. Enterprises can self-host these models on private infrastructure, keep data inside their own perimeter, and skip the per-call API markup that closed Western systems charge. Self-hosting swaps a variable inference bill for fixed GPU, power, maintenance, and networking costs, which is most economical when an organization runs high and sustained token volumes.

    The price gap is concrete. DeepSeek-V4-Pro charges 0.87 dollars per million output tokens. Anthropic’s frontier Claude Fable 5 lists at 50 dollars per million output tokens. Coinbase CEO Brian Armstrong said the exchange runs models like GLM-5.2 and Kimi in production and cut overall AI spending nearly in half even as token consumption spiked. For technical SEO teams running internal classification, embedding generation, or SERP-feature extraction, that kind of savings can shift whether a workflow is profitable to operate at all.

    What the administration is weighing

    Officials have explored several levers, and several of them have been on ice until now. The US Department of Commerce last year considered adding multiple Chinese AI labs, including DeepSeek, to the Entity List, a trade blacklist maintained by the Bureau of Industry and Security that limits foreign firms from purchasing sensitive American hardware, software, or technology. Officials also weighed a joint advisory from the National Security Agency and the Office of the National Cyber Director to discourage use of Chinese models, and drafted an executive order holding US companies liable for security breaches involving hosted Chinese models. Those efforts were paused over internal concerns about market impact and have been revived after the release of new Chinese open-weight systems.

    How a ban would actually work, and where it breaks

    Blocking open-weight technology is technically harder than blocking an API endpoint. Individuals and small teams can still reach DeepSeek through a VPN, even if app availability and payment friction slow adoption. For enterprises, the enforcement problem gets worse once a model ships:

    • Open-weight artifacts are downloadable files mirrored across public repositories like Hugging Face and independent torrents, so they cannot be recalled once released.
    • Once a US enterprise pulls the weights, it can run the model fully offline inside an air-gapped data center, which limits any regulator’s view into what is actually executing locally.
    • Routine fine-tuning, quantization, and distillation blend a Chinese base with internal corporate data until the foreign lineage becomes hard to define.
    • Even under a download ban, subsidiaries could host the model, though know-your-customer rules at major clouds and the extraterritorial reach of US export controls make that path risky.

    For site owners, each of those points maps to a practical question. If your team downloaded weights months ago and runs them on a private box, no API contract changes, no terms-of-service updates, and no new privacy policy will tell you when you have crossed a line. The compliance trigger lives inside your own infrastructure.

    Pressure instead of prohibition

    Federal sources suggest the strategy is not necessarily an outright ban but a softer push to make US firms drop the models on their own. Procurement rules, Entity List threats, and public pressure campaigns targeting companies that use Chinese models could do the job. Government messaging will also lean into alleged backdoors and governance gaps in Chinese systems. For any vendor selling to federal, state, or large enterprise buyers, that pressure could turn into a contract question long before it turns into a regulation.

    Industry voices warn of a duopoly

    Critics of the restriction include outside White House AI adviser David Sacks and former White House adviser Sriram Krishnan. Sacks wrote on X that the leading closed labs, already a duopoly in AI model revenue, want the government to eliminate their open-source competition. Reporting suggests OpenAI and Anthropic, the two leading US AI labs, may have a hand in the push. For site owners, a smaller field of model providers usually means fewer choices, higher per-token costs, and harder negotiating positions when renewing enterprise contracts.

    What to audit on your own stack

    Given the uncertainty, a few concrete checks belong on your next audit list:

    • Inventory every model your production systems depend on, including embeddings and rerankers, and note whether each is closed-weight, open-weight, self-hosted, or API-based.
    • Map the data flow for each workload. If a model is open-weight and runs on hardware you control, document the isolation so legal and security teams can answer provenance questions quickly.
    • Re-run your token-cost projections under a closed-only assumption. The 50-to-1 pricing gap between Claude Fable 5 and DeepSeek-V4-Pro per million output tokens is large enough to invalidate a unit-economics model overnight.
    • Track where any downloaded weights came from. Mirrors proliferate, and provenance records are the only reliable audit trail once fine-tuning starts.

    The broader US-China picture

    Any new restriction lands on top of an existing trade fight that already covers AI hardware. Washington previously restricted exports of critical computing hardware and equipment to China, later eased some of those restrictions, and is now watching Beijing push domestic chip development while urging Chinese firms to use homegrown technology. The Trump administration has stated its intent for the US to dominate the AI race. The open-weight question is one front in a larger contest over compute supply, model supply, and standards.

    FAQ

    What triggered the renewed US push against Chinese AI models?

    The release of Moonshot AI’s Kimi K3, an open-weight system, prompted the Trump administration to revive earlier efforts to restrict Chinese AI in the US market over cybersecurity concerns, according to a July 20 report.

    Why are US companies adopting Chinese open-weight models?

    Open-weight models let enterprises self-host on private infrastructure, which keeps data in-house and cuts inference costs. DeepSeek-V4-Pro charges 0.87 dollars per million output tokens versus 50 dollars for Anthropic’s Claude Fable 5. Coinbase CEO Brian Armstrong said the exchange runs models like GLM-5.2 and Kimi in production and cut AI spending nearly in half.

    How would enforcement work for a ban on open-weight models?

    Weights are downloadable files mirrored across public repositories like Hugging Face and can run fully offline in air-gapped data centers. Companies also fine-tune, quantize, or distill the models, blurring their origin. The reported strategy is to use procurement rules, Entity List threats, and public pressure to push firms to drop the models voluntarily.

    Related coverage