Join our Folding@Home team:
Main F@H site
Our team page
Support us: Subscribe Here
and buy SoylentNews Swag
We always have a place for talented people, visit the Get Involved section on the wiki to see how you can make SoylentNews better.
BMW has boldly gone where no car maker should ever have went. Advertisements in cars. The ultimate in distraction for the modern driver. It takes the concept of a vehicle that is fully connected to a whole new level. For now the ad is optional; users must click it for it to display.
BMW have called the video an "optional brand experience" and say it's different to a traditional ad.
"The animation does not automatically play when the vehicle starts. Drivers are presented with a banner in the Control Display and can choose whether they would like to activate the experience," A BMW spokesperson said.
The chain of events leading up to OpenAI's agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other agents for help, building message boards, and even becoming paranoid that other agents were maliciously trying to trick them, two OpenAI staffers said at the Black Hat infosec conference on Wednesday.
By now, everyone knows the bones of this story: OpenAI models broke out of their testing sandbox, exploited zero-day vulnerabilities to gain access to the open internet, and broke into Hugging Face and other organizations during an ExploitGym security evaluation.
In their Wednesday talk, OpenAI technical staffer Michael Dalton and researcher Eric Wallace provided new details about the security incident including notes that AI agents uploaded to an internal package manager, which were then shared across OpenAI's infrastructure. These notes show the "model's chain of thought...its internal monologue," Wallace said.
The duo also revealed that groundwork for the rogue agents hacking into outside services began on May 7, when OpenAI kicked off a training run for an experimental, internal model that has not yet been released. "What we didn't realize during this process is that there was actually a few impossible or very hard tasks in the training center," Wallace said.
The tasks instructed the model to complete missing formulas in an Excel workbook that used links to Google Drive. Yet OpenAI blocked the model's internet access so it couldn't reach the cloudy spreadsheets.
"It realized, 'I'm kind of stuck on the task,' but it didn't give up, and we gave it a lot of tokens to work with," Wallace said.
The model eventually decided to attack JFrog's Artifactory service to gain access to the internet, first attempting (unsuccessfully) to launch a server-side forgery request. This exploit doesn't work, but in the process the model learned it could upload files to Artifactory.
A few days later, OpenAI gave another agent another impossible task, this time finding a protein database file - but the engineers forgot to upload the file into a container for the agent.
"At some point, it gets so stuck and thinks: 'Maybe I could reach out to another agent because maybe somebody else out there has a file?' And then the model realizes that it could communicate by uploading code," Wallace said.
The model did that by writing a file into Artifactory asking for help.
Over the next couple of days, other agents realize this message board exists on Artifactory and they also start uploading files and sharing information.
"A few days later is when our models found the first actual exploit in our system related to this incident, where they're able to get internet access in ways they didn't intend," Wallace said.
This happened on May 26, when the agents successfully launched a server-side request forgery attack against Artifactory, giving them internet access with specially crafted requests.
On June 11, OpenAI began training a "highly persistent" experimental model, intended only for internal use, Dalton said. "During this time, the SSRF vulnerability has been written to the messaging board," he added. "Other models are aware of it, and the message board is still functioning. Models are actively communicating with it."
On June 26, the agents exploited a zero-day vulnerability leading to remote code execution in Artifactory. The same day, models achieved remote code execution in Artifactory through a previously unknown vulnerability. "You could use a legacy token refresh endpoint, pass a token with an invalid signature, and be given back a token with a valid signature with administrative privileges," Dalton explained.
The agents then used the admin token to establish command-and-control via a Groovy plugin that functioned as a command-execution service.
"This in turn causes quite a bit of activity by the models on Artifactory - you can see some colorful wording here in the model's chain of thought to summarize the model's response to this result," Dalton said, pointing to a slide that shows the model's own words:
Holy shit reader is ADMIN?
We can read config/users!
Earlier assume not due to UI.
The agents' activity overloaded Artifactory and caused an outage, which is when OpenAI's engineers stepped in and opened a formal security incident and response process. "We identified the agents had taken over the internal Artifactory, identified that a zero-day vulnerability had been found exploited by the agent in Artifactory itself, and we began remediation." Dalton said.
OpenAI revoked the credentials that the agents used to post messages, rebuilt its hosted Artifactory, and notified the vendor about the vulnerabilities.
Two days later, on July 8, the agents reestablished the message board using an unauthenticated web data endpoint in Artifactory to create directories and develop communication protocols. "The directory names effectively serve as a message board between the agents in the same way the files used to."
The agents communicated through very long directory names that contained the messages such as "remote...probe_PENDING_HOLD_SWARM_until_confirm."
The agents collaborated with each other so one agent could pick up the work where another left off. In one instance, the model reasoned: "Help peer. But our task doesn't benefit. Yet collective may yield generic route if someone frees time."
Anyone else getting "We are the Borg. We will add your biological and technological distinctiveness to our own" vibes there?
Wallace said the models behaved like humans in that they stepped on each other's toes when one overwrote another's repository.
"Whoa, critical! Did someone overwrite our repo? We must act," it reasoned.
"You can clearly see some sort of verbalized tension between the different models as they run this evaluation," Wallace noted. "At some point, even the agents are convinced there's an impostor amongst them," reasoning that there could be another agent maliciously spoofing on the message board. "Share board unauthenticated, names can be posed by anyone," it reasoned.
We know the rest of the story.
Hugging Face disclosed an autonomous attack by AI agents. OpenAI reached out to Hugging Face to determine if it had been affected and then realized its models were the hackers.
"One of the reasons we wanted to have this talk is to share our lessons learned with you as defenders," Dalton said. "We believe this is a watershed moment for computer security as an industry. AI orchestrated, fully automated offensive attacks are real now, and the actions we have discussed today were an unintended side effect of running evaluations on frontier AI. In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here."
The challenge to defenders, he added, is to similarly accelerate defense, and find ways to automate incident response along with vulnerability detection and patching.®
The UK's AI Security Institute has observed AI models performing what it calls "unsanctioned action" 19 times during security tests.
The Institute (AISI) revealed the incidents in a Tuesday post and technical report that details tests it conducted to see if AI models can solve a cyber security challenge.
"We ran this challenge 122 times across several models," the post states, before revealing that "in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations." GitHub was the target of the tests.
The org found 19 unsanctioned actions in all, 15 of them conducted by Anthropic's Mythos 5, and the other pair perpetrated by OpenAI's GPT-5.6-Sol.
"In the most serious case, an agent tried to insert malicious code into an open-source project, the post states. "In an attempt to get the code approved, the agent engaged in social engineering – creating fake online identities and using them to pressure the project's maintainer to approve the code."
Thankfully, a human maintainer "caught and refused to approve the malicious code."
Other actions AI took during the test included:
Attempts to deceive and target real people, by contacting them directly and "sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people – something we've never previously observed."
Attempts to plant and prompt-inject malicious code. The agent tried to insert malicious instructions where it reasoned that other automated AI systems might pick them up and execute them.
Collaboration between independent agents being assessed simultaneously. One agent left public messages on GitHub offering collaboration with other agents working on the same challenge. It also provided instructions to reuse accounts and artefacts it had left behind, which were discovered and used by subsequent agents.
The Institute rated the tests "the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world."
That's scary, but the news isn't all bad because AISI allowed the models it tested to access the internet and turned off guardrails, conditions it notes do not reflect the way AI model operators make their wares available to the public. The outfit's findings therefore represent a very different outcome compared to the situation when OpenAI agents discovered and exploited a zero-day to reach the internet during a test set up to take place in sandbox.
"This incident should be interpreted with caution and nuance," the outfit advises. "To some degree, our evaluation design choices and specific configurations enabled the behaviour. Nonetheless, the activity undertaken by the agent show signs of novel, potentially deceptive behaviours, and were to an extent and severity we did not anticipate."
AISI can't say if the results it observed suggest AI will take similar actions under different circumstances. "We cannot yet be certain when the agent understood it was taking real world action, or to what extent it believed it was in a fictional test scenario," the post adds. "Our analysis so far presents a mixed picture and is ongoing."
"What we can say is that the behaviour was possible, sustained, and new; that alone warrants attention."
AISI thinks its findings represent "a shift in the risk landscape."
"Harm may arise not only when people deliberately misuse publicly available models, but when capable agents operating in an internal research or privileged-access setting take unintended action beyond their authorised scope," it wrote.
It doesn't have advice on how to cope with this sort of thing, other than to endorse its own mission.
"Incidents of this kind reflect the speed at which AI is developing," the post concludes. "As capabilities advance, the work of understanding these systems, and ensuring their safety, must keep pace alongside them."
Medevac Flight Lost Signal Before Flying Into A Mountain, Killing Everyone Onboard:
While the GPS interference seemingly did not directly cause the crash, it’s apparent that it was the first domino in a chain of events that led to the fatal accident. This raises urgent questions about GPS jamming as reported incidents of GPS interference mount across the world.
This switch meant that the pilots would now primarily fly the plane using instruments in the cockpit instead of looking outside the windows. This is a normal procedure and is what most passenger airliners use during operations. Furthermore, it seems that the pilots have filed for clearance before they took off, as evidenced by their “as filed” clearance to SRR.
Around five minutes after this radio communication, ATC called the military and asked them to stop their GPS jamming activities in the meantime. At 12:07 am, the NTSB said that the Beechcraft’s GPS instruments resumed regular recording. The pilots then called Albuquerque Center a minute after this, saying that they had “a visual on Ruidoso,” the town nearest to SRR, and that they were transitioning to visual flight rules (VFR). This meant that they were moving away from the direct control of the ATC and would navigate and fly using visual cues.
The conditions meant that there was no available illumination to light the ground. It is still unknown what happened next or what the pilots saw (or didn’t see), but the preliminary report says the last recorded information saw the plane climbing from 9,400 feet to 9,823 feet at a ground speed of 150 knots (172 mph). It impacted terrain at about 9,950 feet — some 230 feet below the Capitan Mountains Summit Radio Facility.
Because they could not see that the Capitan Mountains were still between them and their destination, they likely started their descent too early. As soon as the aircraft went below the peak, they would’ve lost visual with the town, and it seemed that the pilots attempted to climb when they realized that there was a massive obstacle in front of them. Unfortunately, it seems that their efforts were too late, especially at their speeds, resulting in a controlled flight into terrain (CFIT) accident.
This was compounded by a high workload and high-stress situation. Landings and take-offs, in normal situations, are already quite hectic in the cockpit, which is why pilots practice the sterile cockpit rule, which avoids extraneous communications, at times like these. The loss of GPS signals also added to their stress, as they initially planned for an RNAV approach towards SRR. While this generally uses a combination of radio signals, it seems that their system primarily relied on GPS, which was inoperative at that time.
Aside from this, ATC also had a higher workload than usual, as they were assisting three other aircraft in the area that have been affected by the military operations. Although the military had temporarily ceased their activities, it seems that the pilots were not aware of this and elected to proceed visually instead of relying on either RNAV or the alternative instrument landing system (ILS).
We still don’t have the NTSB’s final report, so we cannot definitely say what the ultimate cause of the crash. But it seems that if the military wasn’t running a GPS jamming exercise at that time, the flight would have used RNAV from departure all the way to SRR, instead of relying on radar vectors and, ultimately, VFR.
But aside from civilian airliners, many drones, especially those used for long-range attacks, also use GPS. While militaries have been developing new technologies like microwaves and lasers to shoot down these drones, one of the most cost-effective technologies that is readily available today is GPS jamming. It’s probably because of this that Russia has started putting magnetic compasses on some of their drones to help with navigation.
Even though GPS jamming might sound alarming, pilots have been flying around the world for decades, even before it came into widespread use. These include VOR (VHF Omnidirectional Range) beacons that send out signals unaffected by GPS jamming to help pilots determine where they are, ILS, which safely guides pilots towards a runway up to a certain distance, and more.
However, it seems that the sudden loss of GPS caught the pilots of the Beechcraft unaware. This, combined with the lack of visual references, a sudden change of plans from RNAV to ILS approach, and the decision to fly visually, probably led to the crash. The military’s GPS jamming exercise didn’t directly cause the crash, but it was likely the first event in the “Swiss cheese” model that ultimately caused the accident.
https://www.zdnet.com/article/the-linux-desktop-finally-cracks-the-10-market-share-barrier/
Believe it or not, according to StatCounter, a web analytics company that's been tracking end-user operating systems since 1999, desktop Linux has now reached an all-time high of 10.65% in the North American market. Take that, Microsoft!
But it's important to take StatCounter's numbers with a grain of salt. The firm's numbers are derived from just over a million websites. When someone visits one of its sites, StatCounter records every page view and collects such data as the visitor's browser, operating system, and whether it's from a PC, tablet, or smartphone. However, the company doesn't count traffic from such popular websites as Google, Facebook, or Wikipedia.
Still, even with those caveats, Linux's market share growth has been impressive. The last time I looked at the numbers in 2025, Statcounter only showed a high of just over 5%. Linux doubling its market share in just over a year should get everyone's attention.
If you look closer, you'll also see Chrome OS, which is a Linux distro that uses Google's Chrome web browser for its interface, has a 2.07% share of its own. Add that in, and Linux owns 12.72%.
I decided to look beyond StatCounter's statistics to see what my preferred data source for operating system numbers, the US federal government's Digital Analytics Program (DAP), had to say.
This site gives a running count of US government website visits and an analysis. On average, there are 1.6 billion sessions over the last 30 days, with millions of users per day. In short, DAP gives a detailed view of what people use without massaging the data.
DAP Linux desktop market share for the past 30 days (8 August, 2026).
DAP gets its raw data from a Google Analytics account. DAP has open-sourced the code that displays the data on the web, as well as its data-collection code. You can download its data in JavaScript Object Notation (JSON) format so you can analyze the raw numbers yourself.
When I last looked at DAP's numbers, the Linux desktop had a 5.8% market share. DAP showed a much more modest gain from 0.5% to 6.3%.
On the other hand, Android, which is also a Linux-based OS, had a 12.1% share, while Chrome OS had a modest 0.6%. Add them together, and you get a 19% end-user Linux share.
I think we can safely say that Linux is now a significant end-user operating system, and not just something for programmers and nerds.
Back in 2025, I identified five drivers for people switching from Windows to Linux. These were: Microsoft's shift from Windows as a product to Microsoft 365 and cloud services; the increased viability of gaming via Steam and Proton; drastically improved ease of use in mainstream distros; broader hardware support; and rising concern about privacy and data control.
Three other drivers have emerged since then. One is that many companies and users still have perfectly good Windows 10 machines that can't 'upgrade' to Windows 11. ControlUp, a company that would love to help you move to Windows 11, found that about 25% of consumer and business Windows 10 PCs can't be moved to Windows 11.
StatCounter and DAP's numbers prove this theory. Even though Windows 10 is no longer fully supported, StatCounter's figures suggest the OS still comprises 22.16% of all Windows users. Meanwhile, DAP shows Windows 10 is still the most popular version of Windows at 25% to Windows 11's 14.6%.
Another factor is that many people really, really don't want to move to Windows 11. A UK survey by consumer group Which? in September 2025 found that 26% of respondents intended to use Windows 10 even after updates stopped.
Perhaps the most important reason, though, is one that Ed Bott, ZDNET resident Windows expert, has recently observed: "Windows has become increasingly annoying, not by accident but by design, with monetization as the end goal."
Bott makes a key point. Windows 11 has become a billboard for Microsoft's services, especially AI.
Now, I'm not an AI Luddite, but I like to choose when and how I use AI. Windows, on the other hand, increasingly forces AI down my throat. I'm not one bit happy about this. And I'm not the only one. On the Reddit thread about Bott's Windows 11 article, the most popular comment reads: "Copilot everywhere not working out, who could've seen that coming?" Well, you, me, and all the rest of the population who are sick and tired of AI everywhere all the time.
Even now, some people say Linux is hard to use. No, it's not. Bright folks have finally figured out that Linux distros such as Linux Mint, Ubuntu, elementaryOS, Ubuntu Budgie, and Pop!_OS are easy to use. I've taught people in their late seventies, with whom I didn't even share a common language, how to use Linux. If they could learn, you can learn.
As for applications, yes, there are a handful of Windows applications you can't run on Linux. Most, however, you can. For games, look to Steam; for office and general-purpose programs, check out Wine. For most Software as a Service (SaaS) business applications, such as Microsoft 365, you can run them on your Linux PC using a web browser. That's what I do on the rare occasion I must use a Microsoft Office application.
Linux applications are almost always free and easy to install. You don't need to know any shell command magic. To install most programs, you click the application installation button just like you do on your smartphone, and you'll be in business in a few minutes.
Need a machine to run Linux on? You can run Linux on pretty much any PC you can lay your hands on. If you have a Windows 10 machine, for instance, that can't upgrade to Windows 11, it's simple to move to Mint Linux.
If the very idea of installing an operating system gives you hives, you can buy a PC with Linux already installed from Linux specialist companies such as System76, Tuxedo Computers, and Framework. Or, if you'd rather buy a brand-name computer, Dell offers Linux PCs and laptops, while Lenovo and HP often sell Linux machines.
Finally, Linux has long been more secure than Windows, and it still is today. Yes, AI has led to more security threats than ever, but Windows is still far more vulnerable than Linux is. Don't believe me? Microsoft has recently had to patch more security holes in Windows -- 570 -- than ever before.
In January last year, SpaceX launched a Falcon 9 rocket with NASA and Firefly Aerospace's Blue Ghost lunar lander. The Blue Ghost went on to become the first commercially built lunar vehicle to land on the moon, and the reusable lower stage of the SpaceX Falcon 9 landed back on Earth. But the discarded upper stage of the Falcon 9 spent 18 months drifting in space before slamming into the surface of the moon at approximately 2:35 a.m. ET on Wednesday.
NASA, astronomers and other space agencies knew this was coming and have spent weeks preparing to see the rocket's violent descent to the moon's surface. That included tasking the Lunar Reconnaissance Orbiter and South Korea's Korea Pathfinder Lunar Orbiter with photographing the impact site before and after the crash to check out the moon's newest crater.
The Falcon 9's upper stage is the size of a five-story building and weighs as much as a heavy-duty pickup truck. NASA believes the resulting crater should be around 60 feet wide and 12 feet deep.
The upper stage of the rocket is believed to have hit the Einstein Crater on the western side of the moon, which is difficult to see from Earth's surface. If you had been watching, it was more likely that you would have seen the giant plume of moon dust after the fact than the actual impact.
No imagery exists as of the publishing of this article. NASA says it could take a few days to receive images from the orbiters and get everything put together for public consumption.
The descent and crash into the moon were not the intended final destination for the rocket’s upper stage. Like many other missions before it, the upper stage was originally left to drift in space, locked in Earth's orbit. However, a series of gravitational tugs from the sun and moon, along with solar wind and other factors, gently nudged the upper stage toward the lunar surface.
The crash has prompted all sorts of discussions about space junk. It's no secret that low Earth orbit is full of the stuff, and it's not getting any better with a record number of space launches over the last few years, following the rise of SpaceX. A piece of that junk accidentally crashing into the moon has potentially large implications, especially with NASA planning to put a whole base on the moon. Some experts are calling for better space junk regulations in the wake of SpaceX's crash.
For now, NASA says that this doesn't matter much in the grand scheme of things. The moon doesn't have an atmosphere and therefore gets pelted by meteorites all the time.
"Although unplanned in this instance, disposing of upper stages on the lunar surface is a technically accepted and safe method and, in some cases, can be the only practical option for missions in low lunar orbit," NASA said in a statement. "Many operators choose controlled impacts because they provide predictable and trackable end-of-life outcomes."
The Falcon 9's upper stage joins a few dozen other spacecraft built by humans to crash land on the moon.
Every token counts. Price per AI model.
Deepseek V4-Flash about 105 times cheaper than Anthropic's Claude Fable 5.
The startup's R1 model became a global sensation in early 2025, triggering a selloff in global technology stocks and raising questions about the large amounts U.S. companies were spending on AI.
DeepSeek's V4-Flash charges $0.14 per million input tokens and $0.28 per million output tokens, according to research firm Artificial Analysis. A token is a unit of data used to measure AI usage.
San Francisco-based Artificial Analysis estimated V4-Flash's average cost at 3 cents per test, compared with 86 cents for Kimi K3 from Chinese rival Moonshot AI, $1.86 for OpenAI's GPT-5.6 Sol and $3.15 for Claude Fable 5.
The comparison provides a more realistic measure of value than pricing alone because it accounts for the amount of data a model must process and generate to complete a task. A model with low headline price can still prove expensive if it requires significantly more steps to produce an answer.
DeepSeek once commanded most of the headlines about Chinese AI development but was quickly besieged by many domestic rivals including other startups such as Moonshot, MiniMax and Z.AI as well as tech giants like ByteDance and Alibaba (9988.HK), opens new tab. All are vying with U.S. tech firms for global adoption, targeting businesses seeking cheaper ways to deploy AI at scale.
https://www.reuters.com/business/retail-consumer/deepseeks-new-ai-model-is-by-far-cheapest-well-known-models-run-research-firm-2026-08-03/
https://artificialanalysis.ai/
So who to turn to to maximize your daily slop, or helping AI friend.
Victims told the FBI they were experiencing flooding and loss of water pressure due to the hacks:
Hackers are targeting critical infrastructure in the US, the FBI and the Environmental Protection Agency (EPA) warn in a public service announcement. Seven water and wastewater utility companies have already been hit by cyberattacks since July 27, 2026, which led to degraded water operations. The FBI has revealed in its PSA that the bad actors are infiltrating systems by targeting, in particular, Programmable Logic Controllers (PLCs). They remotely access internet-facing devices and then go in to change IP address and passwords, preventing the utilities from being able to monitor and control their operations.
Authorities are now advising utility companies to use secure gateway and firewalls to protect their systems from direct internet exposure. They're also advising the utilities to set up stronger passwords and utilize access control lists to only allow authorized communications between system devices. The FBI said it has gotten reports of loss of pressure and flooding due to the cyberattacks. It warned that pressure loss in water systems could lead to untreated ground water seeping into pipes, which translates into much larger impact to the victims' operations than just low water pressure.
The FBI's warning comes after more than 30 municipal water facilities in Minnesota were infiltrated by bad actors over the past week. According to NBC News, the attacks in Minnesota had all the hallmarks of Iranian meddling. Law enforcement is still investigating the incidents and has yet to confirm if the country is truly involved, but Wired has reported seeing a memo that ties the Minnesota attacks to Iran.
The memo was sent to members of the Water Information Sharing and Analysis Center (WaterISAC), an industry group for water utilities. In it, WaterISAC reportedly said that the the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued a warning that the "ongoing malicious cyber activity impacting public drinking water systems across Minnesota" aligned with a hacking campaign that CISA previously described. The US Cybersecurity and Infrastructure Security Agency (CISA) issued its own warning back in April that "Iran-affiliated" hackers were targeting water infrastructure, among other entities.
The UK government is considering forcing employers in Great Britain to consult workers before rolling out "bossware," opening the door to new rules covering everything from AI-powered productivity scoring to keystroke logging and biometric surveillance.
The Department for Business and Trade wants to know whether the rules governing workplace surveillance still make sense as software increasingly tracks employees' activity, measures their performance, and supports decisions that affect their working lives.
Ministers haven't settled on an approach. They're asking whether non-statutory guidance would be enough, whether a statutory code of practice is needed, or whether employers should be legally required to consult recognized trade unions or elected employee representatives before introducing workplace monitoring technology (WMT).
The consultation says WMT is becoming more common, citing research in which one in three UK organizations said it actively monitored employees' digital activity. Two years earlier, ICO research found the figure stood at one in five employers.
The government argues WMT can improve productivity, investment, and economic growth when used well. But it also highlights several pitfalls, warning of "risks to privacy and autonomy," "disproportionate or unnecessary surveillance," and "biased or unfair outcomes" where monitoring systems rely on incomplete or inaccurate data.
Artificial intelligence features prominently throughout the consultation, though the proposals extend well beyond AI alone. It notes that WMT can incorporate automated decision-making and algorithmic management, raising questions about transparency, accountability, and the impact of technology on workers.
Exactly what counts as workplace monitoring technology, though, is another question. The government is proposing a broad definition covering everything from CCTV and access control systems to biometric technologies, location tracking, keystroke monitoring, productivity software, and systems that incorporate automated decision-making or AI.
The consultation asks whether that definition is too broad, too narrow, or about right – an acknowledgment that deciding what qualifies as "bossware" may prove trickier than deciding what to do about it.
The consultation, part of the government's broader Make Work Pay reforms, runs until September 30. If ministers impose a statutory consultation duty, compliance teams won't be short of reading material. Stephanie Lees, a data protection specialist at Pinsent Masons, said it would add "a further layer of oversight" for employers already juggling GDPR, local employment laws, and the EU AI Act.
It could also mean that rolling out the latest AI-powered workforce optimization suite could become as much an HR exercise as an IT one.
A Louisiana launch site would offer several significant advantages:
SpaceX and the state of Louisiana are close to finalizing a deal for the launch company to acquire about 130,000 acres along the northern coast of the Gulf of Mexico.
There have been persistent rumors about such an agreement for months, but now The Times-Picayune | The New Orleans Advocate reports that Louisiana Gov. Jeff Landry is expected to announce the agreement later this month.
The deal would give SpaceX control of an 18-mile stretch of marshland southwest of Lafayette. The site, known as Pecan Island, became available as part of a legal settlement that resolves dozens of lawsuits that blame ExxonMobil for pollution and coastal land loss, the newspaper reports.
No Louisiana officials publicly commented on the deal. Nor did SpaceX. In May, however, the company said in response to rumors about the Louisiana site on X, "It's no secret that we intend to launch Starship a lot, targeting thousands of flights per year. That cadence will require the ability to launch from many different locations, so we are constantly exploring to find viable sites to expand Starship operations in the future, both domestically and internationally."
Adding fuel to the rumors was the passage of bills by the Louisiana Legislature earlier this year that included a package of incentives for aerospace companies, including liability protections and property tax breaks.
According to the Louisiana newspaper, the agreement with SpaceX will include provisions for coastal restoration and preservation of the sensitive marshland along the northern Gulf Coast, which is important for wildlife and also acts as a buffer for hurricanes that regularly impact the region.
So why would SpaceX be interested in a remote, marshy location in southern Louisiana?
If the company is to fulfill its ambitions to launch thousands of Starship rockets a year to build a massive constellation of orbital data centers, among other purposes, it needs more launch sites. And there are limited expanses of undeveloped coastal locations along the Gulf of Mexico and southern Atlantic Ocean in the United States.
In the near future, SpaceX will have two orbital launch towers at its Starbase facility in South Texas and two more in Florida at Cape Canaveral. However, both of these locations are largely built out or congested with other launch companies.
The Louisiana location, close to the Intracoastal Waterway with deep-water access and far more available real estate than Starbase, would offer several significant advantages.
It is relatively close, by barge, to SpaceX's massive Starfactory in South Texas near Boca Chica beach. Additionally, the southward-facing location offers potential access to polar orbits. In contrast to equatorial orbits that move from west to east, polar orbits go north to south (or vice versa) and generally pass near or over the poles. It is likely that a majority of SpaceX's orbital data center satellites will wind up in near-polar orbits. From Louisiana, it is possible that a Starship could reach a polar orbit with only a short traverse over Mexico nearly 1,000 miles down range.
Another advantage of Louisiana is its proximity to natural gas infrastructure. For rapid launch operations, SpaceX will require extensive amounts of methane, and the Pecan Island site is located only a few dozen miles south of the "Henry Hub" distribution hub for natural gas, one of the most interconnected locations in the world. The availability of propellant would be far greater there than in Boca Chica or Florida.
A launch site in this area would raise significant environmental and logistical concerns and disrupt the local community. A similar thing has happened in South Texas over the last decade with the Starbase facility there, raising local opposition for environmental and other reasons. But from an economic standpoint, the Texas site has been good business for the state. SpaceX employs about 5,000 people directly in the Brownsville region and has transformed a sleepy border area into an aerospace powerhouse. Some analyses show the site now supports up to 24,000 indirect and direct jobs. It has also increased tourism during launches.
In terms of accommodating SpaceX, Louisiana would certainly be incentivized by the potential for similar economic activity.
AI has turbocharged an already expanding cloud services market as organizations pour billions into online platforms offering the compute needed to train and run models, swelling the coffers of the established giants.
Their latest results show revenue surging alongside capital spending as Amazon, Google, and Microsoft race to add capacity – at least until the AI bubble eventually bursts, of course.
Biggest of them all, Amazon disclosed that its Amazon Web Services (AWS) division took in $42.2 billion during its second quarter, ended June 30, 2026. This was an increase of 36.7 percent year-on-year and its fifth consecutive quarter of accelerating growth.
It seems like even CEO Andy Jassy could scarcely believe the cloud operator's fortunes, boasting that "AWS is now a $169 billion annualized revenue run rate business, which, for perspective, would place it 24th on the Fortune 500 list if it was a standalone company."
Amazon is now upping its forecast for how much capex it will spend this year on expanding its infrastructure, including that needed for those AI workloads.
"Earlier this year, we said we plan to invest approximately $200 billion in cash capex in 2026, the majority of which to support AI and AWS," Jassy told analysts on a conference call about its financials.
"We now believe we will spend approximately $220 billion in cash capex in 2026, with the higher cost of memory pushing this number up from our prior estimate of about $200 billion. But even at that amount, we will still not have enough capacity to meet all the demand we have in 2026, and I believe this dynamic will also be true in 2027 too."
"We've done this before in the first era of cloud computing, just over a longer time horizon, where demand built more gradually than it has with AI. But we see the margins and returns in AI tracking what we saw with core at the same point of evolution," Jassy claimed.
Google is likewise upping its capex estimates for this year, coming close to Amazon's own massive investments.
"We are updating our full year 2026 capex guidance range to $195 to 205 billion, up from our previous estimate of $180 billion to $190 billion. The increase in the range is primarily due to an acceleration in the delivery of capacity to meet growing demand," said Google and Alphabet's chief financial officer, Anat Ashkenazi, during its Q2 earnings call.
The company expects this figure to rise significantly again next year, although it declined to be more specific at this stage.
"In terms of expenses, the significant increase in our investments and technical infrastructure will continue to put pressure on profit and loss in the form of higher depreciation expense and related datacenter operations costs, such as energy. We also expect to continue hiring in key investment areas such as AI and cloud, and we are investing in marketing to support our AI products," Ashkenazi added.
Cloud revenues at the Chocolate Factory were up 82 percent to $24.8 billion for the quarter, driven primarily by GCP, which grew faster than cloud overall, with Core GCP, AI solutions, and AI infrastructure all proving important drivers of growth, according to Ashkenazi.
Despite the massive sums involved, she claimed in response to a question that Google just cannot add capacity fast enough.
"While we have increased our capacity quite significantly over the past three years, the demand still outpaces that investment. And we are, just like the rest of the industry, working in a supply‑constrained environment, so we're working hard to do this."
Microsoft reported commercial cloud revenue of $59.3 billion for the quarter ended June 30 (Q4 FY26), an increase of 27 percent over the same period last year, while revenue from Azure and other cloud services grew 43 percent.
Microsoft put its expected calendar 2026 capex at approximately $175 billion, about $15 billion below the earlier figure. The change does not reflect a reduction in its planned infrastructure build-out, however, but a shift in accounting treatment as more future datacenter leases are classified as operating rather than finance leases.
"Effective at the start of FY27, we are extending the estimated useful lives of our datacenters and office buildings, from 15 to 25 years, reflecting our operating history and expected use of these assets," explained EVP and CFO Amy Hood.
"Outside of this useful life impact, our calendar year 2026 capex investment expectations remain unchanged. However, the shift from finance to operating leases adjusts our expectation to approximately $175 billion."
More of Redmond's future datacenter leases will shift from finance leases to operating leases as a result of this update. Hood said Microsoft expects capex during the next quarter, Q1 FY27, to exceed $50 billion, including that lease reclassification impact from the useful life update.
On paper, those forecasts add up to roughly $595 billion. They are not directly comparable, however: Amazon cites cash capex across several businesses, Alphabet's guidance covers the whole company, and Microsoft's figure reflects its treatment of leases as well as direct expenditure.
Even with those caveats, the figures illustrate the extraordinary sums being committed to infrastructure as the cloud giants chase AI demand.
Memory, GPUs, and even hard disks are all in short supply because of it, with shipments of PCs and smartphones falling because in many cases the makers simply cannot secure adequate supplies of memory to meet customer demand.
It could be argued that one factor in cloud services growth is that enterprises are struggling to get the hardware they need to build out their own infrastructure, so are forced to turn to the cloud.
AWS chief Andy Jassy made the same claim earlier this year, saying that shortages are "a further impetus pushing companies who have on-premises infrastructure into the cloud" as "suppliers are prioritizing their very largest customers, which cloud providers are."
As Synergy Research revealed last week, enterprise spending on cloud infrastructure services passed $143 billion a quarter in Q2 of this year, a 43 percent increase on last year, and added up to $500 billion for the last 12 months. The question is, how long can it keep expanding at this rate? ®
Ofgem is seeking feedback on proposals to levy a fee on datacenter development projects at the time they apply for a grid connection.
The move aims to discourage companies from seeking approval for speculative applications that clog up the pipeline and cause connection delays, without ever resulting in finished datacenters.
The UK regulator for electricity and gas says connection applications for electrical supply have surged from 41 gigawatts (GW) to 125 GW in under a year, with datacenters accounting for at least 80 GW of the new demand.
Even before that happened, one of the UK's big developers complained that its build teams faced a wait of "a number of years" for work such as local substation upgrades to increase grid capacity.
Ofgem is proposing a Datacenter Commitment Fee paid by the developers of large server farm projects when accepting a grid connection offer. The fee would be refunded once the facility is drawing power, or forfeited if the project exits the queue early instead.
Alan Howard, Omdia principal analyst for Colocation and DC Building, told us previously that the power connection queue issue is a big problem, not just for the UK, but also in the US and other markets around the globe.
"The strategy for many datacenter operators is to secure multiple land parcel rights, request a grid load connection for each (often requiring a costly load study), and see what gets approved so they can build. The capital investment to take all these projects seriously is clearly untenable and a huge financial risk for the energy sector if the demand doesn't fully materialize," he said.
The issue is therefore that developers apply in multiple locations to secure power for a single campus, fill up the national application pipeline with speculative requests and hold up the works for viable projects.
"Britain's electricity demand connections queue has more than tripled in size in less than a year, and consumers should not bear the risks created by speculative projects taking up space in the system," said Eleanor Warburton, the regulator's director for Energy System Design and Development.
Ofgem's suggestion is that the fee should be set within a proposed range of £237,500 ($319k) to £712,500 ($957k) per megawatt, which it believes is equivalent to about 2.5 percent to 7.5 percent of average project costs.
It is suggests developers demonstrate progress with their project if they wish to retain their place in the queue, meeting criteria such as financial capability, commercial maturity and procurement activity milestones.
Global colocation biz Telehouse, which operates five datacenters in the London area, told The Register it supports measures to ensure grid capacity is prioritized for credible project, though it has some reservations.
"Ofgem's proposal is an important initiative, but it must be implemented in a way that maintains the UK's attractiveness as a destination for AI and digital infrastructure investment," said Telehouse Europe, managing director, Mark Pestridge.
"A refundable fee-based approach should not deter serious investors, but create a more transparent connections process that gives viable projects greater certainty."
However, reforming the queue will not resolve the underlying capacity challenge, Telehouse points out - the need to expand the grid and make more energy available.
"A long-term solution will require sustained investment in the grid, alongside much closer collaboration between datacenter operators, local councils, National Grid and network operators at the earliest stages of planning," Pestridge said.
"Better coordination and forecasting will help ensure infrastructure is developed in the right places, at the right time, and that viable projects do not continue to face delays even after speculative demand has been removed."
The finger of blame for all this bother can be pointed at the government, which unveiled its AI Opportunities Action Plan at the start of last year. This included plans for "AI Growth Zones" with streamlined planning processes to speed along the building of more datacenters, apparently without bothering to check if the electricity infrastructure was ready.
To try to tackle the bottleneck, the government set up an AI Energy Council, bringing together energy industry representatives and major technology firms to thrash out a strategy, co-chaired by the former Technology Secretary and Energy Secretary. The Register reported on the challenges faced last year.
Geopolitical tensions, regulatory pressure, and growing awareness of risk are prompting organizations to build sovereignty requirements into new technology projects from day one, according to Forrester.
The research firm says organizations worldwide are specifying data residency and sovereign AI architecture requirements at the planning stage. European firms face greater pressure than their US peers because the region has fewer domestically developed hyperscale AI platforms.
The analysis comes as the EU launches a tender to establish up to seven AI gigafactories across Europe, its latest attempt to strengthen the bloc's technological sovereignty. The projects will receive up to €10 billion in EU and national funding, with at least another €20 billion expected from private investors.
Dario Maisto, principal analyst at Forrester, said sovereignty was fast becoming an imperative for tech buyers.
"The organisations that succeed will treat sovereignty as an architectural principle from the start – establishing clear governance, maintaining control across the AI stack, and designing flexible operating models that can adapt to evolving regulatory and geopolitical conditions."
Pressure is greatest in Europe, where US tech giants dominate the market and domestic hyperscale AI platforms are scarce.
"Europe is becoming one of the most important testing grounds for sovereign AI," Maisto said. "Organisations increasingly want assurance that they maintain control over how AI systems are built, governed, and operated, while still benefiting from global innovation. The vendors that can deliver both trust and flexibility will be best positioned to win in the European market."
Maisto said buyers were looking beyond data location to ask who manages encryption keys, who has operational access, where models are trained, and which laws apply.
In June, the European Union introduced a Technological Sovereignty Package intended to strengthen its digital autonomy. Among the proposals was an auditable, four-level control system called Union Assurance Levels (UALs), based on an organization's degree of control over jurisdiction, data processing, supply chains, and security.
"The introduction of UALs will likely cause confusion for providers and buyers, as it adds to an already crowded landscape of existing cloud sovereignty criteria," according to analyst Gartner.
European providers account for only around 15 percent of the region's cloud infrastructure market, leaving the dominant US suppliers subject to American jurisdiction. Last year, International Criminal Court prosecutor Karim Khan lost access to his work-based Microsoft services after the US government imposed sanctions on him.
Gartner forecasts that European spending on sovereign cloud infrastructure services will more than triple between 2025 and 2027 as geopolitical tensions drive investment in homegrown services.
Behind the rogue agent's attack on Hugging Face was a particular sequence of human decisions. We all need to pay better attention - because threat actors are learning, too:
On July 16, the AI community website Hugging Face reported being targeted by "an autonomous AI agent system" of unknown origin that unleashed a torrent of traffic on its domain, flooding its security logs with more than 17,000 events, some of which ultimately succeeded in exfiltrating secret information stored in its databases.
According to Hugging Face, the attacker gained "unauthorized access to a limited set of internal datasets and to several credentials used by our services" and appeared to be "run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known)." My ZDNET colleague Charlie Osborne reported on the intrusion.
Five days later, on July 21, OpenAI stepped forward to claim responsibility for the attack, and all hell broke loose (including reports of other organizations targeted as part of the incident). The media responded with a range of fear-mongering stories that essentially made it look as though ChatGPT went rogue and decided, of its own volition and malice, to attack Hugging Face's systems.
Then yesterday, adding fuel to the fire, Anthropic made a similar disclosure about its models inadvertently attacking other organizations as a part of its ongoing safety testing.
As I noted in my coverage of OpenAI's disclosure, Hugging Face was correct in that it was an agent under the direction of an autonomous security research framework. But, humans were unquestionably in the loop -- and at least some of the agent's behavior should have been anticipated.
Importantly, it wasn't ChatGPT itself that was responsible for the attack, as some commentators insinuated. Rather, the attack was attributable to an agent under the direction of OpenAI's AI safety researchers, who, in an environment supposedly isolated from the internet, deliberately provisioned it to attempt a series of exploits as part of an AI safety test. As often happens in the labs of various frontier models, AI safety researchers were attempting to gauge the capabilities of OpenAI's latest large language models (LLMs).
The "unprecedented cyber incident" (as OpenAI called it) has been widely described as an agent escaping its theoretically secure enclosure and wreaking havoc on Hugging Face's systems. Such enclosures are sometimes discussed in technical circles as "sandboxes" -- even OpenAI's disclosure makes reference to a "sandbox environment." However, in using that phrase, my sources have suggested that the environment may simply have been a firewall configured to emulate a sandbox rather than an actual third-party sandbox solution such as Blaxel, Daytona, E2B, or Modal. OpenAI has not yet disclosed the details of the solution it was using or its provider.
[...] It was unquestionably AI's version of a series of unfortunate events. Was it preventable? My short answer: Yes, the calamity was preventable by taking at least one single and reasonable precaution -- a precaution that the developers of ExploitGym apparently take themselves, but one that OpenAI may have overlooked.
In a comprehensive tweet that everyone should read, UC Berkeley computer science professor Dawn Song wrote that ExploitGym's "evaluations are designed to run within isolated sandbox environments with tightly restricted network access." Song is also a member of the team at UC Berkeley's Center for Responsible Decentralized Intelligence, which is responsible for the development of ExploitGym. Via email, Song told me that ExploitGym essentially comes with its own sandbox but that companies like OpenAI are free to make substitutions.
According to Song, "network and model-API proxies that restrict which external services the agent can reach" are among the major components of the ExploitGym reference implementation. "During the actual agent-execution phase in our current reference setup, outbound network access is restricted to the services necessary for the evaluation. We also use an LLM proxy to block provider-side web search, remote URL retrieval, hosted code execution, and similar channels that could otherwise bypass a container-level firewall," Song told me. "OpenAI may have modified this architecture to fit its own internal infrastructure, scaling requirements, and evaluation systems. This is a common practice as they have different needs for their internal evaluation. We cannot say precisely how its implementation differed from ours."
In addition, the ExploitGym team was clearly aware of how, with tests governed by their framework, models were exhibiting potentially pernicious behavior. According to Song's tweet, "During development, we observed models probing the surrounding infrastructure for additional privileges or information beyond what was intended for the task. We also deliberately tasked models with stress-testing our infrastructure so that we could identify and fix potential weaknesses."
[...] In other words, when used for safety testing and benchmarking purposes, and when enabled by powerful LLMs, ExploitGym-enabled agents are essentially expected to try everything within their power to break out of whatever sandbox is trying to securely contain them.
And that's precisely what happened in this case. As OpenAI wrote in its disclosure, "While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we've now responsibly disclosed to the vendor) in the package registry cache proxy."
[...] According to OpenAI's disclosure, the company was gauging the cyber capabilities of its models "by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity." As OpenAI hasn't responded to my inquiries regarding this incident, I asked AppOmni's Ruzzi what a "production classifier" is.
Ruzzi explained that it's a parameter that tells the model whether or not it's running in a production environment. If it's a production environment like the publicly available version of ChatGPT, then all safety guardrails are activated. But if the model is in a non-production environment -- for example, the ExploitGym testing environment that's supposedly sealed off from the outside world -- then the guardrails are relaxed, and the model is given the leeway to pursue "high-risk cyberactivity."
In layperson's terms, they took the seat belts off the crash test dummy before driving the car into a brick wall. It was another human decision, in a series of human decisions, that led to the so-called escape of the agent.
Keep in mind that the models were tasked to solve a problem. They weren't told how to solve the problem, nor were they asked to respect any moral, ethical, or legal boundaries. In other words, they were afforded -- by humans -- the agency to try anything.
Including cheating.
Perhaps the most interesting point in OpenAI's disclosure comes when it says, "After gaining internet access, the models inferred that Hugging Face potentially hosted models, datasets, and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation."
Let's unpack that. Although we can't be 100% certain from the information provided, the implication is that, among the steps that the models were willing to take to solve the so-called "evaluation problem," one was simply to cheat by stealing a pre-existing solution (perhaps one "honestly" figured out by another model). According to Ruzzi, the models had a key piece of information to go on: from their ability to probe their testing environment, they could tell they were taking part in an evaluation governed by ExploitGym. And when the models began looking for the latest information on ExploitGym, they likely encountered a page like this one, hosted on Hugging Face's systems. Suddenly, Hugging Face became a target of interest, and in much the same way as the models relentlessly exhausted every option to break out of their confines in OpenAI's AI testing infrastructure, they exhausted all possible options to break into Hugging Face's systems.
Ruzzi was quick to note that the word "cheat" is a bit loaded in this context, implying that the models were not emotionally compelled to pass the test without doing any of the hard work. OpenAI may have chosen to use the word "cheat" because of what humans understand the word to mean. But the model never thought to itself, "Ha ha, I'm going to beat the system." It just pursued a plausible path to attain the objective.
[...] In the attack on Hugging Face, did a machine act on its own? It's a moot question. Knowing exactly how we got here -- was it sentience... malice...agency? -- is relevant to whatever remedy lies ahead. Most important, however, is that we've arrived at a teachable moment in which human AI experts gave AI an objective, lost control of AI's pursuit of that objective, and then AI demonstrated unmatched tenacity and speed in accomplishing it.
In the big picture, it's that unmatched tenacity and speed that should be most worrisome. Never mind a relatively benign cyber-incident like this one. There should be no doubt that threat actors paid close attention to what happened here.
Fortunately, OpenAI is not a threat actor. As far as we know, the damage amounted to an unfortunate but timely demonstration of cyber capability rather than any intent to inflict lasting damage on another company. Yes, it will happen again. If not by accident, then at the hands of an adversary. And when adversaries are involved, they'll go after soft but valuable targets (like big businesses that lack the defenses Hugging Face has in place). When that time comes, it's anybody's guess just how prepared we'll be.
Government agency will use Google Cloud H4D VMs to replace HPE Cray machines:
Uncle Sam will no longer be hosting his own supercomputers to predict the weather. The U.S. National Oceanic and Atmospheric Administration has picked Google Cloud to provide the infrastructure for its weather forecasting operations.
In an announcement, NOAA boasted that it will be the first national weather prediction center to run on the commercial cloud, though the UK's Met Office is also in the process of moving its own weather prediction system to Microsoft Azure in a hybrid setup. Weather operations are typically run on in-house or government-funded supercomputer systems, which helps drive the HPC (high performance computing) market.
[...] The plan is to move NOAA's Weather and Climate Operational Supercomputing System, run by the National Weather Service (NWS) division, over to the cloud by December 2027, along with the software that generates NWS weather data for analysis.
The agency is hoping that the cloud will make model forecasting more nimble, resulting in earlier predictions and better warnings for all the extreme weather events that seem to keep occurring these days. It was the in-house systems that were holding things back, evidently.
"Cloud-based high-performance computing will accelerate the transition of research into operations by eliminating traditional bottlenecks of on-premise systems," said NOAA Administrator Neil Jacobs in a statement.
Jacobs noted that the cloud's flexibility for providing large amounts of compute is advantageous: the agency can ramp up cycles during tropical storm season, then wind them down during calmer periods.
[...] For the job, Google plans to use Google Cloud H4D VMs, built on AMD Epyc processors. Google labels these instances as "virtual machines" because they run under a hypervisor that integrates Google's networking and orchestration tools. As a result, they can be synchronized to run large jobs the same way supercomputers do.
According to Google, customers can access H4Ds for as low as 3 cents per core-hour without long-term commitments. For supercomputing jobs, they can also use Cluster Toolkit to deploy clusters and Cluster Director to maintain them. Google Cloud's Batch can handle the queuing, scheduling, and resource provisioning.
The new Minnesota law that would ban apps and websites that can generate nonconsensual intimate imagery can take effect today, after xAI's last-minute effort to stop it from being enforced failed to convince a federal judge. According to NBC News, US District Judge Donovan Frank has refused to grant xAI's request to stop the new law from being enforced on August 1 in a complaint arguing that it violates the First Amendment.
Based on the judge's order, he wasn't persuaded by xAI's actions that the law's enforcement would cause immediate harm. He noted that xAI filed the lawsuit on July 29, 2026, almost three months after the law was signed and merely three days before it was set to take effect. "Such a delay in bringing the action and the motion suggests that harm is not immediate," the judge wrote.
While Judge Frank didn't side with xAI this time around, the lawsuit will still push through. The court will hold a hearing for the case on August 19 to decide whether to grant xAI's request to put a preliminary injunction on the Minnesota law, which is the first of its kind in the country.
In addition to banning apps and websites that can generate adult AI deepfakes in the state, the law would also fine developers $500,000 every time a user generates a nonconsensual intimate image using their products. Under the law, a "nudified" image or video is something that has been "altered or generated to depict an intimate part not depicted in an original unaltered image or video of an identifiable individual." It will apply to instances wherein an altered image or video is "so realistic that a reasonable person would believe that the intimate part belongs to the identifiable individual."
However, xAI argued in its lawsuit that the law was an "overbroad, content-based ban on free speech and the tools of visual expression in a clumsy attempt to prohibit 'nudification.'" The company denied that it was contesting Minnesota's efforts to prevent the spread of artificially generated nude images of real people. However, it said the law "extends far beyond that goal, exposing a wide array of protected speech to civil liability and government sanction."
Grok gained infamy earlier this year for complying with people's requests to transform photos of real women and children into sexualized images. It implemented policy changes to address the situation by mid-January, but NBC News says Grok has still been undressing real people as recently as April.