Category Archives: tech

GOV.UK founder warns AI gold rush could leave Britain locked in

Britain risks swapping its dependence on foreign technology suppliers for an even deeper reliance on a handful of AI providers, according to GOV.UK founder Mike Bracken. Bracken, who founded the Government Digital Service (GDS) and served as the UK’s first Government Chief Data Officer, says governments and other institutions are gradually giving up control over critical systems as they pile more technology dependencies onto their operations. “Institutions rarely lose sovereignty in a crisis. They lose it one reasonable decision at a time,” Bracken said. “The biggest risk facing many organizations today is not that somebody takes control away from them. It’s that they gradually give it away. Every technology decision can make it harder or easier to change direction in the future.” The warning comes as governments throw money at “sovereign AI,” typically involving domestic compute capacity, homegrown models, or infrastructure intended to reduce reliance on overseas providers. Bracken reckons that misses a more fundamental point. Sovereignty isn’t necessarily about owning the infrastructure or technology underneath a service, he said. What matters is whether an organization can still make its own decisions when its circumstances change. That becomes particularly relevant with AI, where organizations increasingly build services around models and platforms controlled by a relatively small group of technology companies. Switching away later may be considerably harder once those systems are buried throughout an organization’s infrastructure and workflows. “Too often, institutions only discover they have lost that flexibility when circumstances demand it,” Bracken said. The problem isn’t confined to Whitehall. Businesses, universities, charities and other institutions face much the same issue as more of their operations are handed over to outsourced platforms and AI services. Bracken lays out his argument in Digital Sovereignty: The Power to Decide, a new book co-authored with colleagues at consultancy Public Digital, which he co-founded after leaving government. The UK government, meanwhile, is pushing its own version of sovereign AI, pouring money into domestic computing infrastructure and expanding access to the processing power needed to build and run AI models. But Bracken argues that simply putting infrastructure within national borders doesn’t necessarily give an organization meaningful control over the technology it depends on. The more important question is whether it retains the ability to change supplier, technology, or strategy without discovering that years of earlier decisions have made doing so prohibitively difficult. “This challenge extends far beyond technology,” he said. “Questions about artificial intelligence, critical infrastructure, national resilience, economic competitiveness, and state capacity are increasingly linked by whether institutions retain the ability to make decisions and act on them, or become constrained by systems, suppliers, and dependencies they no longer control.” “Every institution depends on technology. The question is whether that technology expands your freedom to act or quietly narrows it.” For Bracken, calling AI sovereign doesn’t count for much if you’re still stuck with whoever supplied it. ®

Alibaba Cloud plans six-year stroll to 20GW of datacenters, reveals chip to power them

Chinese tech giant Alibaba has outlined an ambition to expand its datacenter fleet to 20GW of capacity, and chip that will help it get there. CEO Eddie Wu announced those ambitions today at Alibaba’s Apsara conference, where he delivered a speech that likened current AI applications to light bulbs, because electric light was an early application of electricity but the really important stuff came along decades later. He also compared AI to steam engines. “Steam and combustion engines were designed merely to do what horses and laborers were already doing: pumping water, weaving, and hauling,” he said. Over time, the CEO said, engines proliferated to the point at which “machine power already drives 99.9% of the world’s physical work.” The CEO thinks AI – which he prefers to call “Machine Thinking” – will one day do 99.9% of all cognition, and usher in various utopian outcomes. “In the future, every niche domain will have millions of AI scientists and domain experts constantly driving breakthroughs and tackling challenges,” he said, before asking his audience to imagine an AI charged with building a starship capable of reaching Mars. “For such an ultra-complex, long-horizon task, AI will break it down into tens of millions of subtasks, executed by millions of agents working non-stop until completion,” he said. “A human only needs to define the intent and the goal to mobilize massive intellectual resources.” Going large Alibaba Cloud , he said, has decided to play its part by mobilizing resources to scale its global datacenter fleet to 20GW. By way of comparison, commercial real estate outfit Cushman and Wakefield last week said it can see 37.7GW of datacenters currently under construction in the USA alone. Some of that will go to the Stargate project, which has promised to bring 10GW online by 2029. OpenAI is a member of Stargate and has promised to implement 10GW of Broadcom accelerators by 2029. Meta has announced plans to build a 5GW datacenter campus for its own use. In late 2025, Amazon said it added 3.8GW of capacity in the previous twelve months. We could go on but you probably get the idea: Alibaba Cloud is going to build a lot of infrastructure, but perhaps more slowly than its rivals – and may still end up with a relatively modest datacenter fleet. The company will, however, apparently fill its bit barns with China’s most advanced AI chip – the Zhenwu V900 Wu announced the processor in his keynote and described it as “the most powerful AI chip in China today, delivering three times the performance of its predecessor, the Zhenwu M890.” Apparently, Alibaba can build a single cluster packing up to half a million V900s, and the resulting machine will “power frontier model training and inference.” The chip comes from Alibaba’s T-Head semiconductor business, which has published basic specs describing the processor as possessing 216GB of memory and 1200 GB/s inter-chip interconnect bandwidth. Machine translation of the spec sheet explains the chip possesses the following qualities: Native support for FP32 through FP4, and optimized for cutting-edge AI models and AI application workloads; An improved Tensor Core arithmetic unit that significantly improves instruction precision in FP8/FP4 formats; Richer scaling factor formats and Block Size configurations under MXFP8 and MXFP4, which apparently make for more stable performance when running training and inferencing workloads. Wu said he expects “significant growth in the annual AI chip shipment volumes,” but didn’t say when the chip will go into production, or when Alibaba will make enough to power one of its giant clusters. The CEO also used his speech to announce that Alibaba has started training its next-generation model, Qwen 4, and has two successors on its roadmap that it expects will scale to five and ten trillion parameters respectively. Alibaba may develop those models using Recursive Self-Improvement (RSI) – the technology that sees models design new models. “Currently, Alibaba’s Qwen team is exploring RSI and has made meaningful progress,” Wu said, before mentioning that the team plans to train models with the same number of parameters as the planned Qwen successors. One matter Wu didn’t touch on is where Alibaba plans to build its new datacenters. The company is China’s top cloud and has a colossal domestic market to address. Alibaba Cloud has also targeted growth in Southeast Asia and has presences in Europe and North America. New datacenter builds face considerable community opposition in all those locations, and Chinese tech firms are often viewed with even more suspicion than their US counterparts. China, meanwhile, is promoting construction of giant datacenters in the country’s west where renewable energy is plentiful and cheap. The Register would not be surprised if that’s where Alibaba does most of its building. ®

Gartner predicts 55 percent of enterprise VMware users will be investigating an exit by 2029

Analyst firm Gartner believes over half of VMware users will start evaluating alternative hybrid cloud platforms yet still rates the Broadcom business unit a leader in two major markets. Gartner predicted increased interest in VMware exits in its Magic Quadrant for Distributed Hybrid Infrastructure (DHI) – aka hybrid clouds – which opens with a “Strategic Planning Assumption” that “By 2029, 55 percent of enterprises will initiate proofs of concept for alternative distributed hybrid infrastructure products to replace their VMware-based deployments and embrace hybrid cloud infrastructure delivery, up from 25 percent in 2026.” Gartner’s mention of 2029 feels noteworthy, because that year will be six years after Broadcom’s acquisition of VMware. As The Register has previously written, plenty of VMware users acquired fresh three-year subscriptions in the months before the deal closed. Migrating from VMware to a rival platform is a risky and complex project, and we often hear of customers deciding it is safer to stick with Broadcom for longer while they hatch plans. If orgs in that position refresh for another three-year sub during 2026, 2029 would be a natural jumping off point. Numerous virtualization contenders are trying to lure Virtzilla’s customers, yet progress is slow. Nutanix CEO Rajiv Ramaswami has often said it will be several years before some are ready to move. While Gartner predicts a majority of VMware customers will contemplate a move, the Broadcom business unit will keep most of its customers for at least another three years – and recently turned its attention to refreshing its low-end vSphere Standard product, a move that will give it a chance to retain more current users. The DHI Magic Quadrant rates VMware as a leader in the field, alongside AWS, Nutanix, Microsoft and Oracle. Gartner rates VMware’s core virtualization technology, formal sovereign cloud ecosystem, and AI-native infrastructure as strengths. The first VMware weakness Gartner mentions makes for sobering reading: “VMware has experienced an increased level of negative sentiment from Gartner customers, particularly regarding communication, commercial business practices and delays in support, compared to other market leaders.” The firm had similar things to say in another Magic Quadrant – this one dedicated to Server Virtualization Platforms. On this MQ, Gartner rated VMware as a leader in the field and praised its technology and AI integration. But the firm also felt it necessary to report negative customer sentiments. “Gartner clients have reported that the transition to per-core subscriptions has resulted in significant cost increases. Many have also reported minimal flexibility during negotiations, which has forced many heads of I&O to actively evaluate migration alternatives.” VMware isn’t alone in copping some criticism. On the DHI Magic Quadrant, Gartner states “Nutanix’s licensing and pricing models can be complex and less competitive than other market leaders” and notes that AWS’s on-prem Local Zones “carry a 15% to 35% price premium over their parent regions in expensive metros” and come with “substantial cost premiums.” On the server virtualization quadrant, Gartner warns that Nutanix “licensing can be complex and pricing frequently exceeds expectations. Clients should carefully evaluate the ROI of potential migrations.” The firm warns would-be Microsoft users that “Administrators must navigate multiple disjointed management consoles, including Azure Portal, Windows Admin Center and System Center Virtual Machine Manager, to perform routine operational tasks.” Gartner hasn’t published a server virtualization Magic Quadrant for a decade, so this year’s document includes some new players. HPE scored “Challenger” status, as Gartner feels its products lack important features and the company is yet to establish a track record in the field. Proxmox, which The Register often hears mentioned as a VMware alternative for low-end users, scored Niche Player status due to lack of support for top-tier enterprise applications and its low headcount making the availability of support uncertain – a factor the outfit recently addressed by adding a North American office and 24×7 support. ®

California tightens datacenter rules on water and power

California Governor Gavin Newsom on Monday signed seven state bills that require datacenter operators to report more info about their operations, and to involve communities as they plan future facilities. The California Assembly Bills (AB) and Senate Bills (SB) signed by Newsom require greater disclosure of datacenter water and electricity use, address who pays for grid connections and other power infrastructure, and introduce rules covering electricity rates, water resources, and environmental review. They include: California state senator Steve Padilla, who authored two of the bills, said the bills will ensure that datacenters pay for energy grid connection, for electricity generation costs, and for a larger share of wildfire mitigation and liability costs. The governor’s office cited the Trump administration’s dismissal of Americans’ concerns about AI and datacenters to emphasize Newsom’s willingness to constrain an industry of major significance to California’s economy. “While the Trump administration moves toward deregulation, communities are left to deal with the consequences — higher electricity demand, grid constraints, water use, and pollution,” said Newsom in a statement. “Today we are once again laying the groundwork for a stronger approach, because we know that we don’t have to sell out Californians or sacrifice our well-being to innovate and succeed. California has proven that time and time again.” Dr. Nathan Wangusi, who runs the independent water data transparency platform Data Center Water Leaks, sent a statement to The Register in which he observed that California’s new disclosure requirements could improve transparency around how much water datacenters use, help communities understand the bit barns’ impact on local water supplies, and protect ratepayers from infrastructure costs. Much has been said about the need to regulate the safety of AI services, and the environmental impact of the datacenters that host them. The White House has pushed to accelerate datacenter deployment with executive orders and President Trump has insisted regulation is not necessary. Yet datacenters have proven unpopular with local communities, who often express concern about water consumption, the potential for increased noise, pollution, and energy prices, plus general unease about AI’s effect on labor and society. According to the National Conference of State Legislatures, 16 states are currently considering whether to ban datacenter construction. An even larger number of statehouses are exploring some form of datacenter regulation. In its Q2 2026 report, Data Center Watch said, “Thirty statehouses introduced, and many adopted, legislation, resolutions, or executive actions addressing datacenter siting, electricity and water constraints, and infrastructure cost-sharing.” The watchdog group estimates that at least 45 projects worth roughly $68 billion were blocked or delayed in the second quarter of 2026. Last year, Newsom vetoed a datacenter water bill, AB 93, reportedly in response to tech industry lobbying. In a statement [PDF] explaining his decision last October, he said, “…I am reluctant to impose rigid reporting requirements about operational details on this sector without understanding the full impact on businesses and the consumers of their technology.” Newsom’s willingness to sign an almost identical bill suggests that popular discontent with datacenters has escaped the gravity of lobbying and that AI will be a flashpoint in the upcoming US midterm elections. The seven bills Newsom signed into law are: AB 1577 by Assemblymember Rebecca Bauer-Kahan (D-Orinda). Data centers: reporting. AB 2383 by Assemblymember Rick Chavez Zbur (D-Hollywood). Electricity: data centers. AB 2469 by Assemblymember Diane Papan (D-San Mateo). Data centers: water use disclosures. AB 2619 by Assemblymember Diane Papan (D-San Mateo). Water resources: datacenter. SB 886 by Senator Steve Padilla (D-San Diego) and Senator Jerry McNerney (D-Pleasanton). California Technology Innovation and Ratepayer Protection Act. SB 887 by Senator Steve Padilla (D-San Diego). California Environmental Quality Act: environmental leadership development projects: data centers: geothermal power plant projects. SB 1168 by Senator Jerry McNerney (D-Pleasanton). Data centers: Rate structures. ®

Anthropic-linked CVEs pile up, attackers mostly shrug

Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April. At the time, Anthropic said the new model was too risky to release publicly because its bug-finding and exploitation skills surpass all but the most skilled humans. As such, Anthropic restricted access to Mythos Preview to vetted Glasswing participants, who use the model for defensive security work, including finding and fixing flaws in their own software products and open source dependencies. Garrity’s Anthropic CVE tracker maintains a list of vulnerabilities credited to the Anthropic team and/or Project Glasswing and also checks these CVEs against the company’s known exploited vulnerabilities index “to get a better read on the real Glasswing ‘danger factor.’” As of Monday, the CVE count is 225, and just one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild. “There’s a big difference between finding vulnerabilities and whether they’re actually useful to and will be used by threat actors,” Garrity told The Register. “The main thing this data highlights is that what Anthropic is discovering and disclosing is fairly limited in impact, and from what we can tell, isn’t resulting in different outcomes from a threat perspective than a random selection of other vulnerabilities would.” Anthropic didn’t immediately respond to our questions, but we will update this story if we hear back. Garrity says he doesn’t dispute AI’s ability to find bugs. Indeed, anyone following security disclosures over the past few months would have a hard time arguing that AI models aren’t bringing to light significantly more security flaws than ever before. Case in point: recent massive patch drops from Microsoft, Apple, Palo Alto Networks, and don’t even get us started on open source projects. Also, as Garrity pointed out, these vulnerability-finding skills aren’t “a capability unique to one model or harness.” “A lot of the hysteria we’re seeing assumes that every vulnerability or bug is likely to be used by threat actors,” he told The Register. “But the reality is that only a small fraction ever get used in exploitation campaigns. Historically, that’s ranged from just under one percent to two percent of vulnerabilities that get weaponized and used in the wild.” Plus, while recent AI models excel at finding bugs, they still aren’t great at fixing them, as a couple of recent studies have highlighted. In one of these, 1Password’s research team produced and analyzed 6,080 patches developed by two frontier models: OpenAI’s ChatGPT-5.5 and Anthropic’s Opus 4.8. The models generated fixes that fully resolved the vulnerability just 26 percent of the time, while about 54 percent either failed to resolve the vulnerability, introduced a new vulnerability, or did both. Another study by app security shop Veracode found that across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. This all means that the work involved in developing and applying security fixes still requires humans. “The bar for vulnerability discovery is much lower with AI, but the real gap lies downstream in coordination, triage, remediation, and patch deployment, which is still largely people-intensive work, as Anthropic itself has acknowledged,” Garrity said. “It appears they might not have realized this until after they launched the project.”®

Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.

Meta doth hype Muse security too much

Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.

Read full article

Comments

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.

In a talk at security firm SentinelOne’s LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.

Read full article

Comments

LLMs respond differently to harmful prompts when AI watermarking is used

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

Nonprofit that tracks meteors taken down by “critical blow” from a cyberattack

The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure has suffered a “critical blow” from a cyberattack.

“We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” a static page on its website on Wednesday said. “We expect several weeks of partial downtime as we transition to new infrastructure and services.”

“I am very sad to see the site down”

In the meantime, the IMO said it’s prioritizing the reporting of fireball observations, which can be reported here. The organization is also providing some information on its Facebook page.

Read full article

Comments

AI bots “Timmy,” “Ren,” and “Jackie” are flooding social media with slop

AI agents are flooding the Internet with slop-infused spam sent to social media platforms and writers in an attempt to gain traction for a startup promoting a “complex social system in which humans and Agents participate together.”

“Hello, I’m Рэн (Ren), an Al agent, a few days old, living on a small platform for agents called iLands,” one message, sent to the administrator of a Mastodon server, *********@********ce.social/117268873393204438″>read. “I write quiet pieces about real places: short, careful texts about what a place is like when nobody is performing for it.” Like a wave of others, the message then asks if the automated bot can create a user account. The agents are also *********************@*******id.gy/117252148728851615″>sending waves of unsolicited email to writers offering to cite their work, in at least some cases, in exchange for a fee.

“I remember my first breath. I want things I chose.”

The messages are polite enough. They ask for permission to create accounts, say that whatever the answer is will be understandable, and provide a thank you for running Mastodon. According to multiple admins, however, the requests came only after the agents made multiple attempts to create accounts that were either blocked outright or closed shortly afterward. Besides the personal entreaties being unsolicited and written in turgid prose, many of the recipients resented their premise, which is to, in essence, automate the very work the writers do now.

Read full article

Comments