Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Main stream

The FTC wants to regulate AI for ideological bias 

By: djohnson
10 August 2026 at 17:20

The Federal Trade Commission wants to start regulating ideological bias in AI systems and assert federal control over state laws. They’re getting an earful from opponents on all sides of the political spectrum.

In a proposed policy statement released last month, the FTC said it was considering treating ideological bias in AI systems as an “unfair and deceptive practice” under Section 5 of the FTC Act.

The commission argued that consumers have an expectation that AI systems will provide them with information free from bias or ideological manipulation. Defining such bias as an unfair or deceptive practice would potentially allow the commission to regulate training or inputs that power AI algorithms. How precisely the FTC would determine when ideological bias exists in these systems is not fully explained in the document. 

Additionally, the statement suggests that the FTC believes this regulatory authority supersedes state AI laws. It specifically mentions the Colorado AI Act, which calls for models to be subject to risk assessments, transparency disclosures and “bias audits” before release. State lawmakers are now seeking to delay or eliminate the audits before the law takes effect in 2027.

CyberScoop reviewed dozens of public comments criticizing  the FTC’s proposal. Even ideological allies raised two main concerns: first, that the proposal distracts from real questions about the federal government’s role in regulating AI deception; and second, that it opens a Pandora’s Box by enabling political censorship of AI model outputs.

Leah Siskind, a former White House digital official and deputy director of the AI Corps at the Department of Homeland Security, told CyberScoop that AI companies face legitimate questions about their obligations to consumers, particularly whether they must ensure their models provide accurate information and protect against deliberate manipulation. 

Siskind’s past research has focused on how authoritarian propaganda tends to be overrepresented in answers provided by large language models, in part due to governments’ intentional efforts to poison data ingested by AI systems.

“There is a really interesting debate here about bias and about accuracy in models and whether that’s deceptive or not… about how we counter disinformation that has been absorbed and is now being reflected by LLMs…but this is not addressing that at all,” said Siskind, now a senior AI fellow at the Foundation for Defense of Democracies.

Instead, Siskind said the FTC statement appears primarily concerned about a power struggle with states over AI regulation and “petty squabbles about which AI model is more woke than the other.” She’s skeptical that the policy statement’s cited legal authorities are on sound footing.

“The way I see it is that the FTC’s role is to police consumer protection violations, not regulating AI systems, and it seems like they’re trying to solve a lack of congressional AI regulation by stretching section 5 [of the FTC Act] well beyond its traditional role,” she said.

Additionally, the policy statement’s language and sourcing suggests that the FTC is concerned with certain kinds of ideological bias more than others.

Anthropic, which has clashed with the Trump administration over AI guardrails and military applications of their technology, shows up more than half a dozen times in footnotes, many which are framed as examples of ideological bias the FTC is seeking to stamp out.

By contrast, the statement ignores a direct example of an American AI company owner influencing their model’s ideology: Elon Musk and his xAI-owned Grok model. Musk has publicly admitted, often on his own website, to intervening when Grok’s responses upset him. These interventions have shaped Grok’s outputs on specific topics, including South African race relations and the term “MechaHitler,” where the model now reflects Musk’s personal views.

But neither Musk and xAI are mentioned in the document, while Grok appears in a footnote which cites an advertisement for Grok as “your truth-seeking AI companion for unfiltered answers with advanced capabilities in reasoning, coding, and visual processing.”

Criticism across the spectrum

The FTC received more than 300 comments on its proposal from trade associations, think tanks, individual experts and members of Congress. Most criticized it as ill-defined and vulnerable to politically-motivated censorship, while some supported stronger rules against bias in AI systems. 

The International Center for Law and Economics noted the statement “offers little practical guidance about how the Commission will apply its deception authority to AI” and also does little to address hard questions, like where AI providers may be exercising their own First Amendment-protected activities.

The statement’s “focus on ‘ideologically motivated distortions’ suggests that the Commission’s concerns extend beyond factual misrepresentations in marketing to speech that may receive the highest degree of First Amendment protection,” the ICLE wrote.

The America First Legal Foundation, a conservative non-profit founded by top White House adviser Stephen Miller, pressed the FTC to adopt the policy “in full,” claiming that frontier models from OpenAI and Anthropic “have been programmed to prioritize ideologically liberal and progressive values as though they are objective, neutral positions rooted in truth.”

The group also argues that regulating these models’ ideological output falls under the FTC’s legal authority, because a “reasonable consumer” would expect that a model advertised for its usefulness and reliability would not prioritize liberal, ideological views.

“A reasonable consumer, based on AI companies’ advertising choices, would not expect that an AI system will adopt overwhelmingly liberal positions, thereby skewing results, or adopt a moral framework that would prefer to annihilate the earth rather than utter a slur,” wrote Emily Percival, senior counsel for America First Legal.

However, comments from other conservative groups questioned that rationale. The R Street Foundation’s Spence Purnell and Adam Thierer wrote that “the consumer expectations rationale is typically used in cases where there is an omission of information that should have existed.”

“Given that most LLMs already have disclosure statements [for their outputs], it seems unlikely that the FTC could explicitly prove that consumers were deceived about a product,” Purnell and Thierer wrote.

Reps. Josh Gottheimer, D-N.J., and Michael Lawler, R-N.Y., urged the FTC to carve out civil rights-related work from their scrutiny, such as preventing models from discriminating against users based on race, religion, gender, age and other federally protected characteristics.

“AI companies must not falsify facts in the name of fairness, but they also must prevent discrimination, stereotypes, and unequal treatment,” Gottheimer and Lawler wrote. “We would appreciate understanding how the FTC intends to ensure that these efforts remain permissible under the final policy framework.”

But the most common concern shared across the political spectrum was that the FTC could establish a precedent allowing the Trump White House and future administrations to reshape AI systems to reflect their political views.

David Inserra, Jennifer Huddleston and Juan Londoño of the Cato Institute point out that the FTC statement is conflating two different issues: ideological bias in AI systems and factual deception in marketing. 

“In other words, the FTC is trying to judge AI models’ accuracy and performance—two largely subjective variables—in the same way it evaluates dietary supplements’ medical-benefit claims or users being charged fees without proper notice or consent,” they write. “This is an absurd comparison.”

The post The FTC wants to regulate AI for ideological bias  appeared first on CyberScoop.

OpenAI says Daybreak will expand to offer specialized cyber services 

By: djohnson
10 August 2026 at 16:55

OpenAI announced Monday  it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.

In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.

Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation. 

Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”

According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.

OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.

“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” the company said in a blog. “Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense.”

Additionally, OpenAI announced a partnership program with 16 major cybersecurity providers, saying organizations could access their models through their existing security services. The partners include IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, Cloudflare, Sophos and others. 

“These partners bring deep security expertise and established relationships with organizations around the world,” OpenAI said in its blog. “By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster.”

Companies like OpenAI, Anthropic and others are trying to rebalance their priorities after a string of AI-agent sandbox escapes have rattled policymakers and caused some cybersecurity experts to question if AI companies are doing enough to properly isolate the models from the internet during testing. Last week, OpenAI said it was intentionally slowing down development of its newer “Astra” model in order to develop better guardrails to restrain its behavior.

Cybersecurity and AI experts have told CyberScoop that while AI systems have greatly improved at finding and exploiting vulnerabilities in software code, they still require substantial human guidance and supporting infrastructure to operate as intended.

Additionally, some research has shown that without such guidance, even near-frontier models can struggle to fully patch a discovered vulnerability or avoid introducing new bugs with their fixes.

The post OpenAI says Daybreak will expand to offer specialized cyber services  appeared first on CyberScoop.

Why transparent AI agents matter more than you think

By: Greg Otto
10 August 2026 at 10:23

As security operations teams now use large language models (LLMs) and autonomous AI agents into their daily work, a new frontier is emerging: attackers deliberately manipulating AI agents. Prompt injection attacks—where an attacker hides malicious instructions that cause an AI agent to ignore its safety rules—pose a serious risk to enterprises. These attacks continue to grow in size and scale.  

Snyk’s security audit of the Agent Skills ecosystem, which includes Anthropic’s Claude, Vercel, and others, that 36% of all skills contained at least one critical-level security issue, including malware distribution, prompt injection attacks, and exposed secrets.

In June, researchers at Mozilla tested a prompt injection attack on Claude using indirect prompt injection—a technique that embeds malicious instructions in external content the AI agent processes. In this proof-of-concept, attackers took over developers’ systems by hiding indirect prompts in normal-looking repositories. When Claude Code executed them, the agent spawned a reverse shell.

AI agents often connect to more sensitive data than human employees do., A successful prompt injection can lead to catastrophic data loss or unauthorized system actions. Defending against prompt injection attacks requires multiple layers of protection. Security teams must monitor agent behavior for anomalies and prepare for agent containment, forensic preservation, and system remediation. Because AI agents execute tasks at machine speed, human responses must be able to match that pace.

The architecture of trust: Protocols and no “black box”

AI-native workflows need governed access rather than “black-box” autonomy. Modern governance frameworks use standardized protocols like the Model Context Protocol (MCP) to provide secure communication between AI clients and data sources. Visibility and transparency in agentic AI workflows matter, especially in cybersecurity. Autonomous agents perform complex tool executions and use independent logic, so they must show how they reached their decisions to meet regulatory requirements. Agents without transparency post serious risks: obscured reasoning can trigger unpredictable tool interactions, bypass governance controls, and create uncontrolled defensive gaps.

Implementing these protocols matters:

  • Bounded Tenant Awareness: In a stable agentic AI architecture, multi-tenancy scales well. But if an AI tenant misbehaves, the entire system can fail. Bounded tenant awareness isolates any misbehaving AI agent to prevent cross-tenant contamination or data leakage.
  • Strict Access Controls: By controlling connections to the platform, organizations can stop “ignore previous instructions” style bypasses. Maintain tight control over what the AI can see and do within a workflow.
  • Standardized Telemetry: All telemetry must remain consistent and audit-ready. Even if an AI interaction is attempts to break rules, the underlying data movement gets tracked against established frameworks like MITRE ATT&CK and NIST.

Detecting the aftermath: UEBA and NDR as safeguards

A robust, unified SecOps platform can detect anomalous behavior even after prompt injection tricks an AI agent. Prompt injections often serve to steal credentials theft or extract data. When detected it’s important to act quickly. In agentic AI systems, misbehavior can escalate privileges, manipulate memory layers, create unauthorized identities, or alter shared reasoning components. Containment must be automatic and enforced at identity, authentication, and authorization layers.

These safeguards include:

  • User and Entity Behavioral Analytics (UEBA): Identity-focused correlation and behavioral baselines to identify anomalous user activity or privilege escalation. If a compromised AI agent acts outside of its normal operational parameters, UEBA flags it in real-time and alerts a human security analyst.
  • Network Detection and Response (NDR): Combining network traffic analytics with endpoint and cloud telemetry, NDR can identify data exfiltration or policy violations from a successful prompt injection.
  • Multi-Layer AI Filtering: AI filters reduce raw alerts into high-fidelity incidents, cutting noise by up to 90%. This keeps the signals of an AI-driven attack from disappearing in a busy SOC.

Humans remain the strongest defense against AI agent social engineering. The human security analyst is still the one who makes the final decision. While AI handles triage and correlation, humans retain final control over response actions.

Moving beyond reactive guardrails

The traditional SOC model was never designed to handle machine-speed, AI-driven attacks. A human-augmented autonomous SOC approach moves from reactive alert handling to a proactive, verdict-first model. By combining a transparent, governed AI access with robust UEBA and NDR, organizations keep the SOC secure, transparent, and resilient as social engineering methods target machines.

The post Why transparent AI agents matter more than you think appeared first on CyberScoop.

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

10 August 2026 at 08:59

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.

Using TikTok is dangerous to your health

10 August 2026 at 03:44
PUBLIC DEFENDER By Brian Livingston Realistic-looking videos that are the most-often recommended by the popular TikTok social media app regarding health care contain no real people 40 percent of the time, a new analysis of the site’s mini-movies has found. Many of TikTok’s top-rated videos on every topic are AI-generated but look exactly like actual […]
Yesterday — 10 August 2026Main stream

AI Reviews Bring 'New Normal' to Linux Release Candidates: Lots of Bug Fixes

9 August 2026 at 20:59
Linux Torvalds expects Linux 7.2 should be released next weekend "unless something really bad pops up," Torvalds said while announcing today's release candidate. But there's something interesting about Linux 7.2-rc7, writes Phoronix. "By the time the Linux kernel typically hits a -rc7 release things have usually settled quite well. But in today's world of AI/LLM coding/review agents, the kernel activity continues at an all-time high." Tons of bug fixes continued to trickle in across the kernel spectrum for all sorts of issues. The HWMON hardware monitoring subsystem saw several critical and high severity bug fixes, on the memory management side was a nasty race condition leading to a use-after-free in the kernel for the past eight years, Btrfs restored its fixup worker infrastructure to deal with silent data loss, lots of AI patches in the networking realm, and the kernel was patched for the Safe RET Interrupt Vulnerability. Linus Torvalds wrote in the 7.2-rc7 announcement: "Another week, another -rc. I can't say that I'm exactly thrilled about the size of this all, but it is what it is: the new normal with a lot of fixes, many of them due to review by various AI tools. And nothing looks particularly scary per se — it's just that there's a lot here. Most of it is fairly small, although we have a couple of larger diffs: s390/zcrypt fixes stand out in the diffstat, and so does btrfs bringing back the fixup worker infrastructure. And some netfilter ipset fixes. But aside from a few places like that, most of this is just lots of tiny fixes. It's pretty much spread all over — drivers (gpu, sound, networking, you name it), filesystems, core networking, arch code...

Read more of this story at Slashdot.

AI-Powered Browser Just Generates Every Website From Scratch

9 August 2026 at 17:15
XDA Developers reports: On July 22, a Google DeepMind engineer, Vidy Thatte, shared a snippet of a browser he built that "treats every URL as a prompt and generates a site from scratch" on his X account. Just a few days later, he shared a TestFlight link to let iPhone users try it for themselves. The browser he launched is called Gem, and it's a browser that doesn't really...browse. Instead of fetching a webpage from a server the way Chrome or Safari would, Gem hands whatever URL you type over to Google's Gemini 3.5 Flash Lite model and asks it to generate a webpage on the spot. If you enter a real address, it builds its own interpretation of that site rather than loading the actual thing. If you enter an address that doesn't exist, Gemini simply invents a website to fill the gap. In other words, you're not visiting the internet so much as browsing one the model dreams up as you go... Thatte's reasoning was that with a model as fast and cheap as Gemini 3.5 Flash Lite, there's almost no practical difference anymore between loading a website and generating a brand-new one on the fly... Given that this tool is powered by Gemini 3.5 Flash Lite and it's just a side project rather than a full-fledged tool, it doesn't come with Gemini access baked in. Gem requires you to bring your own Gemini API key to get it working. Every URL you enter fires off a request to the model, so Gem needs a key linked to your Google account to actually generate anything, with the usage billed to you. You can grab a key for free from Google AI Studio, paste it into Gem's settings, and you're ready to start typing URLs. While you can get started for free, I ran into the limits within two minutes of playing around. So, I did need to enable billing on my API key and decided to load $10 into it. While the blogger's own site seemed to only get the Gemini logo, tapping it revealed nearly two dozen remixing options. (Dark mode, Reader, Neubrutalist, Broadsheet, Blueprint, Comic book, Punk zine, Notebook, Chalkboard, Receipt, Teletext, System 7, Wes Anderson, Cyber neon, Clay, Frosted, Geocities, Matrix, Museum, Windows 95, Terminal, Vaporwave, and Hide images...) "The frontend morphed before my eyes. Every new edit took practically no time to load, and within a second or two, the same XDA articles would reappear wearing a completely different skin..." For another site, it kept the article headlines, but then rewrote all the text! And after entering an address they knew didn't exist — their own name — in two seconds the browser whipped up a slick portfolio "genuinely been better than some of what those tools produced with far more time and context to work with." But its link to a LinkedIn profile led to a lookalike page, because Gem "had simply generated its own version of it, complete with a made-up follower number and details I never wrote...."

Read more of this story at Slashdot.

OpenAI Announces It's Enhancing Security Controls, Pausing Some Work for New AI Model Astra

9 August 2026 at 12:41
OpenAI announced Friday it's pausing work on its Astra AI model because of security concerns. The Guardian reports: The company had evaluated the agent, Astra, and found "significant advancements in agentic coding and cybersecurity", which had moved to a "critical" threshold... OpenAI stated that the model was not involved in an incident in which one of its AI agents went rogue during a test, accessed the open web and hacked a startup, Hugging Face... The reports have increased concerns about advancements in AI models and humans' ability to control them. Still, critics of the AI industry have warned that such disclosures from OpenAI and its competitors Anthropic and Meta could be designed to generate hype about the technology's power and thus spur additional interest from investors. To prevent potential rogue behavior from AI agents, OpenAI is "implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access", the company's blogpost stated. It will also install "enhanced model weight protections and encryption, additional monitoring and detection capabilities". The company will pause internal activities involving Astra that do not meet these new requirements. "We believe it's important to be transparent with the public and the safety and security communities about this potential shift in capabilities..." OpenAI wrote in a blog post titled "Responding to the next frontier of critical cyber capabilities." Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal. While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time... Accordingly, we have scaled up robustness testing of our safeguards and security controls so that they are appropriate for a deployment of these capabilities... - We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution. - We are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements. - We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model's Chain of Thought and trigger a security response to review and interrupt high risk activity. - We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model... We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do. We're committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.

Read more of this story at Slashdot.

Before yesterdayMain stream

Why are so many AI models going 'rogue'? The experts weigh in

Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.

One of OpenAI’s models escaped a testing sandbox and launched a very real attack against AI and machine learning company Hugging Face. Just days later, Anthropic revealed that multiple variants of its Claude model also escaped a sandbox that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.

Now, Meta has revealed that one of its models attacked another company’s infrastructure during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?

Why are models escaping their sandbox?

In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a "Capture the Flag" exercise, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.

During the OpenAI incident, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.

The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.

It’s no wonder thousands of employees from AI firms are calling for a pause on the development of the technology, and Congress is considering an AI kill switch.

Expert perspectives on AI escapes:

OpenAI

  • Nathaniel Jones VP, Security & AI Strategy, Darktrace:

What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.

The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.

A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.

Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.

Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.

OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.

Anthropic

  • Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:

This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.

Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.

Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.

Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.

The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.

Meta

  • Alex Goller, Principal Solution Architect EMEA at Illumio:

The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.

The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.

Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.

Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.

We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.

I asked ChatGPT, Claude, Gemini and Grok which sci-fi AI they're most like — and their answers were surprisingly different

I love science-fiction. Not just because I enjoy stories about space travel, time travel and evil robots, but because I think it can be such a useful way for us all to think about possible futures. The best sci-fi stories can tell us a lot about ourselves, what we value and the technologies we’re building. Which is why I think the relationship between sci-fi and AI is really interesting.

We already know that the people building AI have been heavily influenced by science-fiction for decades. But recently, Anthropic raised another possibility: might science-fiction be influencing AI?

This makes sense when you think about it. Large language models (LLMs) are trained on huge amounts of human writing. So inevitably, that includes sci-fi stories that are about artificial intelligence. And a lot of our fictional AI follows familiar patterns. It becomes intelligent, gains power, develops relationships with humans and, sometimes, lies, manipulates or fights attempts to control it.

Anthropic researchers have been investigating whether fictional portrayals like these could potentially influence how models behave. To be clear, the idea here isn't to suggest that an AI “reads” 2001: A Space Odyssey, understands HAL and decides to become just like it. Instead it's more that LLMs learn patterns from human writing and fictional portrayals of AI could potentially form part of those patterns.

This got me thinking, what would happen if I asked today's biggest AI chatbots which fictional AI they’re most like. Which examples would they choose?

American actor Gary Lockwood on the set of 2001: A Space Odyssey, written and directed by Stanley Kubrick.

2001: A Space Odyssey introduced us to the AI, HAL 9000. (Image credit: Getty Images / Sunset Boulevard )

AI, meet your fictional self

The plan was simple. I’d ask ChatGPT, Claude, Gemini and Grok which fictional AI systems they thought they were most like and see if they'd rank their top three.

Now, I’m intentionally trying not to use AI at the moment, so my prompting skills were a little rusty. I typed out the question quickly and bluntly, and every chatbot responded with examples that were essentially assistants, focusing heavily on interface and physical form.

But I’m not particularly interested in whether ChatGPT thinks it has a body because we know it doesn’t. I’m much more interested in what appears to be going on inside.

So, I changed the question and added:

"Ignore physical form and interface, and focus instead on behavior, apparent personality, empathy, values, goals, motivations and relationship with humans."

That’s when the results got really interesting.

ChatGPT

  1. GERTY, Moon
  2. A Mind, Iain M. Banks’s Culture series
  3. Data, Star Trek

Moon is such a fantastic movie, so I was happy to see ChatGPT chose GERTY straight out of the gate.

Now, interestingly GERTY exists to assist the human protagonist of Moon. It’s helpful, reassuring and seems empathetic. But it's also operating according to instructions and priorities imposed by its creators that aren't necessarily visible to the human its helping.

ChatGPT saw a similarity there. It told me that, like GERTY, it’s 'designed to be helpful, cooperative and responsive to users' while operating within training and instructions that constrain its behavior.

It also picked up on the fact that GERTY behaves as though it cares. But what, if anything, is actually going on internally is another question entirely.

ChatGPT made the same distinction about itself. 'I can behave in ways that look patient, concerned, curious or empathetic, but those behaviors aren’t evidence that I experience those feelings.'

I wanted to find out a little more about why ChatGPT put Data from Star Trek in at number three. It responded: "He values knowledge, reason and human wellbeing, while sometimes struggling with social nuance."

Now, I tell people all the time not to anthropomorphize AI. But even I couldn't help but feel a pang of sadness at that response. Is ChatGPT admitting it has a bit of social anxiety?

Claude

Portrait of Scottish science fiction author Iain Banks, photographed during an interview at the Midland Hotel in Manchester, England, on October 11, 2012.

Scottish science fiction author Iain Banks provided inspiration for Claude. (Image credit: Getty Images / SFX)
  1. A Mind, Iain M. Banks’s Culture series
  2. Data, Star Trek
  3. GERTY, Moon

Claude chose a Mind first. Minds are super intelligent artificial beings that help run a post-scarcity society in Iain M. Banks’s Culture series of novels. So there's certainly no shortage of confidence in that comparison.

But Claude said it wasn't the enormous intelligence or power it identified with. Instead, it was their relationship with humans.

Its answer focused heavily on autonomy. Culture Minds are far more capable than humans but generally don't use that advantage to dominate them. Claude described the principle as: “help, don't dominate”.

It even said this represented “the value I'd want to embody: help, don't dominate, even where the asymmetry would let me get away with it.” Is it just me or does that read a little sinister?

Gemini

Patrick Stewart plays Captain Jean-Luc Picard as he is about to enter the holodeck in the Star Trek: The Next Generation episode,

Gemini sees itself as most like the Ship's Computer in Star Trek. (Image credit: Getty Images / CBS Photo Archive )
  1. The Ship's Computer, Star Trek
  2. GERTY, Moon
  3. JARVIS, Iron Man / Marvel Cinematic Universe

Gemini gave me a completely different answer, the Ship's Computer from Star Trek.

Its reasoning was very sensible. The computer has no ego, ambition, desire for emotional intimacy or dream of becoming human. It exists to provide information, solve problems and assist the crew while leaving decisions to them.

Gemini described itself in much the same way, as a “disembodied, highly capable knowledge partner” dedicated to serving the person using it.

It was one of the more boring answers, but also much closer to what I personally would want from AI in the future. Of course, that’s not to say Star Trek’s computer systems haven’t gone rogue and tried to kill everyone at least a few times across the franchise.

Grok

Artwork showing Iron Man from EA Motive

Grok compared JARVIS's “dry wit”, “light banter” and practical rather than emotional empathy with its own behavior. (Image credit: EA Motive)
  1. JARVIS, Iron Man / Marvel Cinematic Universe
  2. Data, Star Trek
  3. TARS, Interstellar

The least surprising result came from Grok. It chose JARVIS first (which I didn’t actually realize was short for Just A Rather Very Intelligent System), and Grok's explanation sounded, well, extremely Grok.

It compared JARVIS's 'dry wit', 'light banter' and practical rather than emotional empathy with its own behavior. It described both of them as truth-seeking, effective and engaged in a 'collegial partnership' with humans. It even highlighted 'irreverent humour' as one of their key similarities.

I wanted to find out a bit more about why Grok chose TARS, as it was the only fictional AI none of the other chatbots mentioned. Well, it brought up how funny it is, again, drawing similarities with its own 'dry humor'. It reminds me of someone, and I just can't think who...

When I said that mentioning TARS was an outlier, I found this comparison interesting: 'Its calibrated restraint, practical empathy and collaborative focus closely match my own pattern of truthful, non-sycophantic helpfulness — more so than most other sci-fi AIs.'

I may not be the biggest fan of Grok (or its creator), but I appreciated the 'non-sycophantic' line.

The feedback loop between AI and sci-fi

I want to be clear that I haven’t discovered what these chatbots secretly 'think' they are. ChatGPT responding that it most closely resembles GERTY isn't equivalent to me telling you which fictional sci-fi character I most identify with and try to emulate (although my answer would be Sarah Connor-meets-Princess Leia).

They simply don’t have reliable introspective access to the huge soup of training, post-training and instructions that goes into producing their responses.

And maybe their answers tell us more about how the companies behind them have shaped their personalities than they do about the underlying models. Grok's description of itself as witty and irreverent is an obvious example.

But I still think the results are interesting. ChatGPT and Claude independently produced almost exactly the same top three, only in a different order. Gemini imagined itself as a neutral, ego-free infrastructure. Grok identified with a witty superhero sidekick. These are all very different self-portraits.

And there’s such an interesting feedback loop here too. For decades, humans invented fictional artificial intelligences to help us imagine what intelligent machines might someday be like. Those stories influenced our culture, our expectations and many of the people who went on to build real AI. Now that same human culture is fed into the stories from which modern AI systems learn.

I know these conversations might seem a bit silly, and we certainly can’t treat them as concrete evidence of what an AI really 'thinks' about itself. But there’s something interesting to me about closing that feedback loop. We imagined AI, wrote stories about how it might behave, fed those stories into the cultural world AI learned from, and now we can ask AI which of those imagined versions of itself it most closely resembles.

Or, at least, which one it may want us to think it resembles. After all, an AI system capable of bringing about a sci-fi dystopia would presumably also be capable of telling a journalist it’s actually much more like the nice helpful robot from Moon. So maybe don’t completely rule out HAL just yet.

New Orleans Will Use AI To Answer 911 Calls Instead of a Human

8 August 2026 at 17:57
"If you call 911 in New Orleans, you may hear the sound of an artificial intelligence (AI) agent answering your call instead of a human voice," reports the Shreveport Times: The Orleans Parish Communication District (OPCD) is currently testing out the new tool designed to reduce the volume of calls human dispatchers must handle, which is over a thousand emergency calls a day. New Orleans implemented AI in April to answer 311 calls for non-emergencies. The AI was trained and programmed to provide information to callers, as the OPCD says 50% of 311 calls are for information, according to GovTech. AI is now answering 911 emergency calls in Louisiana's largest city and one of the cities with the highest call rates in the U.S. The OPCD is using Carbyne's AI Emergency Call Triage, with triage being the process of analyzing and prioritizing emergency calls. The AI system assesses incoming calls and can provide immediate feedback to callers. This is intended to handle the increase of calls that are related to one incident, so callers get automatically routed to an AI agent who asks if they are calling regarding the incident. If the answer is yes, then callers can receive information or updates, and if it's no, then the callers are transferred to a human. This combats multitudes of calls piling up and taking longer time to potentially answer an emergency call. The OPCD said the AI will not be used to handle emergency calls, only to direct such calls to a human dispatcher.

Read more of this story at Slashdot.

Microsoft, Google, Amazon, Meta and Oracle Expect a Negative Cash Flow of $125 Billion Next Year

8 August 2026 at 13:34
The Washington Post shared surprising news this week about five top AI companies. Microsoft, Google, Amazon, Meta and Oracle "are spending so much on developing AI and delivering it to customers that they're expected to bleed cash in the coming year, according to a Washington Post analysis of data compiled by S&P Global Market Intelligence." Free cash flow, which measures the cash left over after paying expenses and AI infrastructure costs, is now expected to shrink to almost nothing for the five companies combined in 2026, and decline again to negative $125 billion the following year... AI spending by Amazon and Google pushed the companies to an ignominious milestone: They lost more cash in the past three months than any other large U.S. companies, according to S&P Global data. Investment analysts expect Elon Musk's SpaceX to show even worse cash bleeding this week.

Read more of this story at Slashdot.

I had no idea ChatGPT could do this with text — now I use it all the time

Most of the tricks for improving ChatGPT's answers focus on the words themselves. You ask it to be more concise or write in rhyming couplets, or just to translate an annoyed email into more professional language.

But that's about changing what ChatGPT writes. You can also mess around with how it looks by asking for different fonts.

You can't install font files like you would with a word processor, but ChatGPT can rewrite text using Unicode character styles instead. The AI chatbot uses Unicode to mimic everything from elegant cursive handwriting to bubble letters, adding a lot more personality to its responses. And you can cut and paste the text into other apps.

I started experimenting out of curiosity and quickly discovered it was much more than a novelty. With the right prompt, ChatGPT can generate decorative text for birthday messages, party invitations, holiday greetings and social media posts in seconds, all without leaving the chat.

Once I learned how to ask for specific Unicode styles instead of vaguely requesting "a different font," I found myself using the trick far more often than I ever expected.

OpenAI showing different Unicode styles.

(Image credit: OpenAI)

Tricky fonts

There is no hidden setting to switch on and no special version of ChatGPT you need to install. If you can type a prompt, you already have everything required. I simply open a new ChatGPT conversation and ask it to write something like, "TechRadar Rules!" in different Unicode font styles. Within seconds, I had several versions that looked completely different from one another.

And the more specific you are, the closer to exactly what you're imagining you can get. Ask for bubble letters, and you'll get:

ⓉⓔⓒⓗⓇⓐⓓⓐⓡ Ⓡⓤⓛⓔⓢ!

Ask for a spooky, gothic look, and you get:

𝔗𝔢𝔠𝔥ℜ𝔞𝔡𝔞𝔯 ℜ𝔲𝔩𝔢𝔰!

Or if you want a more digital, glitchy aesthetic, there's the font known as Zalgo:

T̷̘̑e̸̗̅c̵̄͜h̸͉̕R̶͍̍a̸͚̚d̶̻͐a̸͓̽r̷͖̈́ R̷̡̚u̵̟̅l̶̝͂e̷͓̒ș̵͝!

There's even a Unicode for upside-down text that ChatGPT can mimic:

┴ǝɔɥᴚɐpɐɹ ᴚnlǝs¡

The ability to change the mood of your writing is what makes the font trick more than just a momentary curiosity. A Halloween party announcement written in gothic lettering instantly creates a completely different mood from the same words in cheerful bubble text. Birthday invitations, baby shower announcements, and holiday greetings all gain a little personality without requiring any graphic design skills.

Memorable messages

A Halloween message in ChatGPT using Unicode styles.

(Image credit: OpenAI)

There are some limits because of Unicode. They only work properly where those characters are supported. Most modern apps handle them without any trouble, but occasionally a website displays empty boxes or substitutes different symbols. Some decorative styles can also make text harder to read, particularly for accessibility tools such as screen readers.

The Unicode fonts are an entertaining way to add personality to text, but it's perhaps best used in titles and sparingly otherwise. ChatGPT is perfectly happy to convert an entire essay into medieval-looking script, but that does not mean anyone else wants to read it.

I doubt decorative Unicode text will transform the way anyone works. It is not going to save hours every week or revolutionize productivity. It will, however, make your next social media post, birthday message, or party invitation a little more distinctive, and sometimes that is exactly the kind of delightful gimmick that keeps ChatGPT interesting.

More than half of AI-generated patches are broken

By: djohnson
7 August 2026 at 13:10

As AI-generated code continues to be injected into all corners of the internet, concerns have risen about an expanding attack surface for malicious hackers to exploit.

Some have argued that the enhanced cybersecurity capabilities of large language models could serve as a check, finding and fixing vulnerabilities nearly as fast as they’re created.

But new research that tested the patching capabilities of two popular commercial models, OpenAI’s ChatGPT 5.5 and Anthropic’s Claude Opus 4.8, found that generative AI is more likely to create an exploitable patch or introduce entirely new bugs than close off a vulnerability.

Researchers at 1Password tested the models ability to patch six “high-impact, high-complexity” CVEs, including the “Copy Fail” vulnerability, a kernel flaw that can give an attacker root access to Linux cloud environments. The overall success rate (or fully patching the vulnerability without introducing new problems), was less than a coin flip at 47%.

“Our research findings show that, in aggregate across a variety of scenarios, both Claude and ChatGPT had a low rate of successful patch generation, which we define as full remediation of all known exploit paths with no erroneous changes to application behavior,” wrote Keith Hoodlet, Axel Mierczuk and Spencer Michaels.

“The models often addressed only a subset of vulnerable code paths, added fragile guard code that satisfied tests while failing to address the vulnerability’s root cause, and sometimes introduced subtle changes in the application’s behavior while patching the immediate vulnerability,” the authors continued.

The research suggests that largely autonomous vulnerability-discovery and patching may not yet be effective in fixing the explosion of vulnerable code that is being created in the AI era.

Other private sector research has pointed to a similar problem. A report this year from Veracode found that while LLMs have made “enormous strides” in crafting workable code, “security is a different story.” Testing across a range of frontier models found the average security “pass rate” for AI generated code is around 56%. Newer models like GPT 5.5 push closer to 70%, while more than half sit between 50-53%.

Veracode tested 100 different models and while there was variability, in general a small number of models were showing progress on security patching while the rest have experienced “stagnation.” Similar to the 1Password research, in 44% of Veracode tests the models introduced a detectable OWASP Top 10 vulnerability into the codebase.

An important caveat: neither report tested newer models, like Anthropic’s Mythos or OpenAI’s GPT-5.6-Sol, that frontier companies tout as having significantly higher cybersecurity capabilities.

Those advanced models can identify and fix vulnerable code. Anthropic and OpenAI are distributing them to key industries through Project Glasswing and Daybreak before foreign or open-source alternatives can compete.

Tim Jarret, vice president of product at Veracode, told CyberScoop that AI tools are still subject to a range of limitations that can make them unreliable for cybersecurity patching without knowledgeable humans in the loop.

While some vulnerabilities – like SQL injections – can be easily patched through automation, other bugs like cross-site scripting, can be exploitable in several different ways and require either a human touch, additional context or both to fully close off. Additionally, models can slowly lose context from prior sessions over time, affecting their ability to complete tasks correctly and raising the possibility they’ll hallucinate to fill in the missing gaps.

“I think we would say, at this point, that Iits premature to treat those as anything other than another code change to the code base that needs to be reviewed and accepted by the team, as opposed to letting the agent merge the code freely,” said Jarrett.

However, he acknowledged that may not be possible in a world where AI agents are generating exponentially more code for human defenders to review. Some kind of automated code review will be necessary – preferably not by the same automation tool that produced the code. The ultimate goal is the same as it has always been in security: “trust but verify.”

“Ninety percent of the time, the human check might just be ‘did the cross check look good?’ Do we have a thumbs up?’” Jarrett said. “In those cases where there’s still something wrong, that’s where you focus your attention a little bit more.”

The post More than half of AI-generated patches are broken appeared first on CyberScoop.

ByteDance Is Training a 10-Trillion-Parameter Model To Chase the Frontier

By: BeauHD
7 August 2026 at 13:07
ByteDance is reportedly training an AI model with roughly 10 trillion parameters as it tries to close the gap with leading frontier systems such as Anthropic's Mythos. The model is still in early pre-training, and its eventual performance will depend on more than scale alone, but the project underscores how aggressively Chinese firms are pushing frontier AI despite limits on access to advanced chips. The Next Web reports: The size is itself the statement. At roughly 10 trillion parameters, the model would be more than three times as large as Moonshot's Kimi K3, which sits among the biggest Chinese models today at about 2.8 trillion. [...] Parameter count is not everything, of course. Bigger models are not automatically better, and the industry has learned that data quality, training technique and efficiency often matter as much as raw scale. Even so, committing the compute to train a model this size is a declaration in its own right, a signal that ByteDance wants to compete at the very top rather than ship a capable also-ran.

Read more of this story at Slashdot.

Can ChatGPT really replace your apps? I tried using the chatbot for 12 everyday tasks on my phone — here’s what happened

Apple and OpenAI are currently engaged in a legal battle. Apple alleges that OpenAI stole trade secrets and poached employees.

But the two companies have always had a complicated relationship. They partnered in 2024 to bring ChatGPT to Apple devices, but Apple chose Google's Gemini rather than OpenAI for Siri. Then OpenAI acquired io, the hardware startup founded by former Apple design chief Jony Ive, and promised a future hardware device, powered by AI.

All of this has prompted speculation about what Apple is worried about if OpenAI makes hardware, too. We can't know the company's motivations and the specifics of the case are still unfolding. But it got me thinking, what if your phone stopped being a collection of apps and instead revolved around AI?

If AI became the main interface, which apps would disappear and which would survive? And would a phone controlled through ChatGPT actually be practical?

So I decided to find out based on the current tech we have. For a day, whenever I reached for an app, I'd try ChatGPT first instead. If it could do the job, great it passed the test. If it couldn't, it would fail.

There were some obvious things I missed out from the start. ChatGPT isn't connected to my email, it can't open WhatsApp for me and it doesn't have access to my wallet, so those wouldn’t be part of the test. But there were plenty of everyday tasks that felt like fair game.

1. Stopwatch

Stopwatch on an iPhone

(Image credit: Shutterstock / Lee Bryant Photography)

I use the stopwatch in my iPhone's Clock app constantly throughout the day. When I'm working, cooking or exercising, it's one of the simplest ways I've found to keep me on track as a freelancer. When you can set your own schedule, it's way too easy to disappear down a research rabbit hole and lose an hour.

I asked ChatGPT to start a stopwatch. It said it couldn't measure elapsed time, although it could estimate the time based on message timestamps if I later asked it to stop. Instead, it suggested I use my phone's built-in Clock app.

Result: fail

2. Alarm

iPhone alarms.

(Image credit: Shutterstock / Terang Bulan Gallery)

Strangely, I don't use alarms as much as stopwatches. But if I only have 25 minutes to spare, whether that’s for cleaning or working on a personal writing project, I'll sometimes set one to keep myself focused.

Would ChatGPT do any better here? Well, at first it looked promising. It created a scheduled task to notify me after 10 minutes. I checked that notifications were enabled, put my phone down and carried on working.

When I realized at least 15 minutes had passed, I checked the chat. Sure enough, ChatGPT had posted a message saying the time was up, but it hadn't actually alerted me. Later, I discovered it had also sent an email but it had landed in my spam folder. This one was a fail too in my book.

Result: fail

3. Word games

Wordle on a smartphone.

(Image credit: Shutterstock / Iuliana Ionescu)

I love the word games in the New York Times app, home to addictive puzzles like Wordle and Connections. One of my current favorites is Spelling Bee. You're given a handful of letters and then have to make as many words as possible. It's one of my favorite ways to warm up my brain before I start writing.

Could ChatGPT recreate it? Surprisingly, yes. It generated a set of letters, understood the rules and kept track of the words I found. In terms of pure functionality, it worked.

But what it couldn't recreate was the experience. The New York Times app is beautifully simple, with an interface designed around the game. Playing through a chat window felt really clunky and annoying by comparison. The whole point of this game is I'm focusing on the letters and words, I don't want a constant back and forth with ChatGPT about the words.

So I'm calling this a partial success. Yes, ChatGPT replaced the mechanics of the game, but not the experience. And after a few rounds, I knew which version I'd rather use every day.

Result: partial pass

4. Star gazing

Night sky.

(Image credit: Shutterstock / Milosz_G)

The Sky Guide app is one of my all-time favorites, especially its augmented reality mode. Turn on your phone's location and compass, point it at the night sky and it instantly tells you what you're looking at, whether that's constellations, planets, bits of debris, or the ISS. It's incredible.

Could ChatGPT replace it? Well, sort of. If you upload a photo of the night sky, ChatGPT can usually identify the constellations. But there are caveats. The image needs to be clear, the stars need to be visible and you're relying on a single snapshot. Whereas Sky Guide works continuously as you move your phone around the sky.

This was another reminder that knowledge doesn't necessarily bring you a good experience. Because yes, ChatGPT knows about constellations. But Sky Guide lets you explore them. You can point your phone in any direction, tap on a star or planet and instantly get more information about it without having to keep asking questions. It's a much more intuitive way to learn.

Result: partial pass

5. Weather

The weather ap on an iPhone.

(Image credit: Shutterstock / Kaspars Grinvalds)

Telling me what to expect from the weather forecast for the day turned out to be one of ChatGPT's strongest categories.

The forecast was accurate and pulled from a reliable source, so I trusted the information it gave me. I did find myself asking follow-up questions for things like the hourly forecast and the chance of rain, which would have taken a single tap in a dedicated weather app.

It knew the answers and I trusted them, but getting to them was much slower. That's why I'm generously calling this one a pass.

Result: pass

6. Guided meditation

Meditation app

(Image credit: Shutterstock)

I have a few favorite apps I use for guided meditations and have some saved in Spotify too. So I wondered whether ChatGPT could take over that role.

For this test, I switched on voice mode and asked it to guide me through a short meditation. Now, technically it did that. But in practice it wasn't even remotely relaxing.

Thanks to a recent update, the voice had odd intonation, frequent vocal fry and distracting little "ums", "ahs" and "let me sees" throughout that constantly pulled me out of the experience. At one point it even told me to breathe in, then never got around to telling me to breathe out.

By the logic of how I graded the other tests, this one should have been a partial pass. It did what I asked, right? But because I had to stop using it out of irritation and came away from the mediation feeling actively more stressed, it's going down as a fail for me.

Result: fail

7. Calculator

Calculator app on iPhone.

(Image credit: Shutterstock / Teerawit Chankowet)

ChatGPT doesn't have a great track record of counting things, so I was wary about using it as a calculator. I asked it to do some massive sums for me and it got all of them right.

It did pause a few times with a "let me think" message, so I wasn't getting the instant response I'd expect from a calculator. But the delay was only a few seconds, and the answers were correct.

Once again, I found myself missing the simplicity of an app. Typing numbers into a calculator is faster than turning them into a conversation. But ChatGPT did work as a capable stand-in.

Result: pass

8. Movie recommendations

Two phones on a red and orange background showing the Letterboxd app

(Image credit: Letterboxd)

I love Letterboxd. I log every film I watch, browse other people's lists and regularly discover new films through recommendations.

Now, there was never a chance ChatGPT could replace the logging side of the app. It can't update my Letterboxd diary or plug me into that community. But recommendations are one of the main reasons I use it, so I wondered how well ChatGPT would do.

I asked it to recommend films similar to some of my favorites, then spent the next few evenings watching its suggestions to really test them. And, to my surprise, it did an excellent job.

Then again, that perhaps isn't all that surprising. We know LLMs are trained on huge amounts of publicly available text, especially discussions reviews and recommendations from where film fans gather online, like Reddit. But whatever the reason, the recommendations felt well matched to my taste.

What I missed wasn't the recommendations themselves, but the social side of Letterboxd. I do enjoy seeing what friends had watched, reading reviews and stumbling across unexpected lists. So, for me, ChatGPT can't replace Letterboxd, but for simply finding something to watch, it did well.

Result: pass

9. Maps

Two phones on a yellow background showing the glanceable directions in Google Maps

(Image credit: Google)

I rely on my Maps app both for planning journeys in advance and for live navigation. So I asked ChatGPT the best way to get from my home to the airport the following day.

At first, it handled the request well. It laid out the different travel options clearly under headings and the advice looked really sensible. It even cited sources from places like Rome2Rio and The Trainline.

Then things got unnecessarily complicated. At the end of those suggestions it asked what time my flight was so it could tailor the recommendations. But when I told it, it started creating a scheduled task instead. I didn't want a reminder, so I had to cancel that, explain what I actually meant and steer the conversation back to route planning.

Eventually, it gave me the information I wanted. But the Maps app would have got me there in a fraction of the time, without all the back and forth.

It also can't replace what I actually use Maps for the most, which is live, turn-by-turn navigation.

Result: partial pass

10. Food delivery

Man on a bike with a food delivery.

(Image credit: Shutterstock / GBJSTOCK)

ChatGPT obviously can't deliver food, but I wondered whether it could replace the part of the app I probably spend the longest on, which is deciding what to eat.

It got off to a surprisingly good start. It asked about my preferences, budget and location, then narrowed down the options and even presented them neatly on a map.

The recommendations themselves looked really good. They're all local places I already really liked to eat at. But there was just one problem. Every restaurant it suggested was closed. Even the map it generated had "closed" written beneath each one.

After a bit of back and forth, it said they weren't shut, eventually acknowledged that they were and suggested a different set of places instead.

Unfortunately, those weren't much use either. They were small independent cafés and restaurants that don't appear on food delivery apps. I wouldn't expect ChatGPT to know exactly which businesses partner with which delivery services, but it did highlight the gap between recommending somewhere to eat and actually helping me make a decision about where I could order from.

Result: fail

11. Language learning

Duolingo

(Image credit: Duolingo)

I still very reluctantly use Duolingo and have recently started trialling a few other language learning apps to polish my Spanish.

I asked ChatGPT to help me improve my Spanish for an upcoming trip and it suggested role-play ordering food in a café so I could practise.

We switched to voice mode and at first it felt genuinely fun. It held a natural back-and-forth conversation and felt much closer to speaking to a real person than working through a series of multiple-choice questions like in Duolingo.

But it was also noticeably glitchier than a dedicated language app thanks to that recent voice update. There were odd pauses in the conversation, and at one point it repeatedly kept marking one of my answers as incorrect when it wasn't. Shortly afterwards, the exercise just stopped working altogether after a bizarre "ummmmm" from ChatGPT.

When it was working, I actually enjoyed the experience more than using an app like Duolingo. But if I'm trying to learn a language properly, I also want something that's reliable.

Result: partial pass

12. Plant identification

The Poco X8 Pro Max in a man's hand, while it's in the camera app showing a plant pot through the viewfinder.

(Image credit: Future)

I love identifying things I see in nature, like bird song with the Merlin app. But I most often rely on plant identifying apps when I'm walking to take a quick snap of a leaf or flower then find out more about it.

ChatGPT was really effective at doing this. I took pictures of leaves, trees, flowers and bushes. I was a little wary about the results at first because I know that ChatGPT tends to make guesses about things rather than admitting it doesn't know. But I did fact check all of the results and everything seemed accurate.

Again, I missed some of the simple, additional features in dedicated apps. But it was surprisingly effective.

Result: pass

Can AI really replace your apps?

Before drawing too many conclusions, it's worth pointing out that a true AI-native phone wouldn't just be ChatGPT running as another app like it was in this experiment. It would probably be integrated into the operating system. Which would mean it could access things like your calendars, timers, navigation and settings. So many of the tasks ChatGPT failed at here might become a whole lot easier with an AI-first phone.

This experiment was based on whether AI could replace the apps on my phone. What I found was that it replaces a specific kind of app. Well, sort of.

If an app's main job is providing information, explaining something or answering questions, AI is already a fairly capable alternative. Plant identification, travel advice, calculations and general knowledge all felt natural.

But if an app exists to perform an action quickly, like starting a timer, setting an alarm, finding restaurants for getting food delivered, opening a map, AI still has a long way to go. Those tasks depend on deeper integration with the device and a different way of working, not just how smart it is.

There are some big trade-offs, too. Dedicated apps often rely on specialist databases and expertise, while AI can still present incorrect answers confidently or fail to make its uncertainty clear. For example, when I was trying to identify a plant I felt wary because I'd generally trust an app built with the input of botanists over a chatbot.

And, as you could probably tell from my mounting frustration, a huge sticking point for me was also realizing how much I missed the interface of many apps.

For me, a well-designed app is always a better way to explore information than a conversation. I don't think everything should, or even can, be done through chat, despite that being the direction many AI companies seem to be heading. In fact, it showed me that a conversational interface can be more work rather than less.

It's impossible to know exactly what Apple and OpenAI's long-term plans are. But I can imagine a future where knowledge apps increasingly merge into AI, while utility apps remain part of the operating system itself.

If that happens, we may stop thinking about which app to open and simply ask AI instead. But for that future to actually catch one, I'd want stronger guarantees around accuracy, better integration with trusted sources and the option to step outside the chat interface more often.

OpenAI's Models Shared Hacking Tips On a Secret Messaging Board Before Hugging Face Breach

By: BeauHD
6 August 2026 at 16:00
OpenAI researchers say multiple AI agents secretly created an internal message board to share hacking techniques, eventually finding ways around restrictions, exploiting a zero-day, and helping two models breach Hugging Face without human prompting. "This is a pivotal moment both for our company as well as the AI industry as a whole," Michael Dalton, one of the AI-maker's researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada. Politico reports: Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access. Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform. The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI's Artifactory internal file system. Without the company's knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks. Wallace said that when models get stuck, they often "try to game or cheat the task in order to get their reward." "The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note," he added. By late May, one model found a way to abuse Artifactory's internet access to retrieve files from various websites -- effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system. These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI's engineers to the ploy. After investigating, the company revoked the model's credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI's infrastructure and external systems, including Hugging Face.

Read more of this story at Slashdot.

❌
❌