Apple wasn’t joking when it warned us that competitors want access to our most private data. Now, OpenAI’s ChatGPT has introduced a new plugin that can control Apple’s Messages app on Macs. This follows the earlier introduction of a new Computer History feature that monitors what you do on your Mac. And while I don’t think Apple will challenge the new feature — yet — on the Mac, I do see trouble ahead on other platforms.
So, what’s ChatGPT’s new thing? Its latest tool means you can use the tool to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from Messages.
“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS,” says OpenAI. “In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats.”
So, if you’ve ever wanted an AI system to go through all your messages to pluck out insights, you’re in luck (though you’ll probably want to check in with corporate legal before doing so). The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.
ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them, and more. You might get ChatGPT to recommend a set of secure browser and messaging services you could use without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples here.
The company has suggested some prompts, including:
The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed, along with recent history on how ChatGPT protects such data on Macs.
OpenAI told Bloomberg the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages. But that may not mean much, given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”
Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools.
The degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some apologists tend to dismiss concerns around privacy, while others warn that AI automation is becoming an always-on surveillance system that itself becomes a target for exploitation and attack. Both sides may have a point. But what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy. It’s all well and good to require consent to make the AI magic happen, but it would be far better, and more legitimate, for such consent to be informed.
It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which might yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data. That’s particularly true in Europe, where the Digital Markets Act requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools.
It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree on some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers; if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them — perhaps using ChatGPT to help them build the code with which to do it.
I don’t think Apple will challenge OpenAI’s approach for now, as the company doesn’t appear to have actively subverted Mac security protection. But I do predict a showdown on iOS, particularly if Apple is unable to build support for the “trusted intermediary” approach it originally proposed to the EU, if only because of the wider extent of information collected on mobile. It also puts yet another slant on the ongoing litigation between both companies.
Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
With the launch of “Slack Code” channels, Slack this week introduced a new way for developers and non-tech staff to work collaboratively with coding agents.
While Slack already integrates with several coding agents, developers have to interact with them independently to get work done. The aim of Slack Code is to make agents available to multiple coworkers in shared, project-based “code channels.”
“We built code channels to be this multi-player AI experience and bring more development into Slack,” said Sateja Parulekar, vice president of product marketing at Slack. “It’s not just engineers and product managers who are working with the coding agents; it’s the marketers, the product designers who are now able to interact with a coding agent in a safe, governed environment.”
Slack code channels are intended for one-off coding sessions and projects — building a new application feature, updating a web page, or fixing a bug, for example.
When the coding agent is tagged in a Slack channel or DM with a request, it automatically creates a new code channel, adds links to required documents, and invites relevant participants.
The code channel functions just like a normal Slack channel, with participants able to send messages and files as usual, while also letting them interact with a coding agent and track outputs via the channel’s “session artifacts.” These artifacts include “code diffs” that highlight changes to code made by the agent, as well as Slack “canvas” documents and live HTML that displays prototypes and previews created by the agent.
All participants can use natural language to direct the agent, making suggestions and signing-off on outputs, for instance. Any updates are then highlighted in the original Slack channel. And when a task or project is complete, the code channel is automatically archived.
Slack Code channels can also be customized — Slack admins can create guardrails to prevent non-technical workers from shipping code without engineering review, for example.
Code channels adhere to Slack’s existing security and permissions model, the company said, with agents able to access conversations and data based on controls set for a Slack workspace.
At launch, four agents integrate with Slack Code — Claude Code, Devin, GitHub Copilot, and Vercel — though Slack intends to expand the list of options over time. Slack Code is available at no extra cost on all Slack subscriptions.
“Slack Code closes the gap between where work gets done and where code gets written with dedicated spaces built for output along project-based channels right in Slack,” said Wayne Kurtzman, research vice president at IDC. “This furthers the Salesforce goal of making work more seamless and multi-player within the Slack environment, regardless of the other applications the business is using.
“While Slack Code may seem early to market for some companies, others are leveraging the first-mover advantage.”
While software development and coordination work “has happened in Slack forever,” according to Will McKeon-White, senior analyst at Forrester, the new features make it “easier to just stay in Slack only and [open] up who is involved with the actual code creation.”
For IT staffers who enable Slack Code, the immediate consideration involves permissions, he said — “a persistent challenge for anything multiplayer.” McKeon-White cites various approaches: “…Some inherit user permissions based on task, some have persistent permissions with different ‘invoking’ permissions for users, some inherit the permissions of the room. Each has flaws.”
The longer-term challenge, he said, is around multi-agent collaboration.
“Multi-agent collab today in successful environments isn’t very dynamic,” said McKeon-White. “Having true dynamic agents cooperating can create extremely interesting emergent behavior,” he said, pointing to recent Anthropic research on the topic.
While Slack Code is aimed at software development-related tasks, Slack also envisages a similar cross-functional, collaborative approach to AI agent interactions applied to a wider variety of purposes: marketing campaigns, for instance, or legal document reviews.
“That might not involve code per se, but it does involve a very detailed review of a document and tracking changes and a preview of what’s going to be sent out to the customer,” said Parulekar. “In the future, we see this extending to a lot of different teams and use cases for technical and non-technical users.”
Other features announced Thursday include “agent DMs” that allow for individual interactions with an agent and a new “agents tab” where users can view existing agent conversations.
Parulekar said Slack Code feeds into a wider Slack strategy centered on a “multi-player experience” for human workers and AI agents. This includes the recent announcement of Claude Tag, which makes Anthropic’s agent available to teams.
“Whether it’s the user experience that we’re evolving — like the agent tab, or coding channels where you can plan, code, test, and ship inside of Slack — it’s all part of that bigger vision of making Slack a great home for agents and furthering that vision of multiplayer AI,” she said.
OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments.
“OpenAI does not retain…prompts or model responses after a request is processed,” the company said in a blog post, describing its ZDR approach. The new system, called Private Safety Processing, is “designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.”
The capability is being tested with eligible enterprise and API customers and is intended to address a limitation in existing safety controls that evaluate interactions individually, making it harder to detect risks that unfold over time.
Private Safety Processing is designed to extend existing safety systems by correlating activity across related interactions rather than analyzing each prompt in isolation, according to OpenAI.
Under the model, automated systems analyze interactions and generate “a narrowly defined signal indicating the type of activity involved,” instead of exposing the underlying prompts or responses, according to OpenAI.
The system can operate whether customer data remains within enterprise-controlled infrastructure or is stored by OpenAI with encryption keys controlled by the customer, the company said.
“In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel,” the post added.
OpenAI said the new capability is intended to address a gap in the detection of AI risks.
“The most serious AI safety risks are not always visible in a single interaction,” the company said, noting that harmful intent may only become clear when multiple interactions are viewed together.
Such risks include repeated attempts to probe safeguards, coordinated activity across accounts, and misuse that emerges over a sequence of interactions, according to the company.
As AI systems take on longer and more complex tasks, evaluating individual prompts in isolation can limit the ability to identify such patterns, OpenAI said in the post.
The introduction of Private Safety Processing highlights differing approaches to safety among AI providers.
OpenAI said the system is designed to detect misuse patterns across interactions while preserving zero data retention.
By contrast, some providers retain customer interaction data for a period of time to support safety monitoring, reflecting a different approach to identifying risks that span multiple requests.
Sanchit Vir Gogia, chief analyst at Greyhound Research, said the difference lies in how evidence is handled rather than whether signals are used.
“This is a disagreement about how much raw content you need besides a signal you are keeping regardless, rather than privacy against surveillance,” Gogia said.
He added that both approaches rely on derived indicators but differ in where investigation data resides. “Anthropic wants enough content to investigate the case. OpenAI wants the customer to hold the case while the provider holds the alarm,” he said.
The system’s reliance on signals rather than direct data access shifts how enterprises verify and investigate incidents, analysts noted.
“The architecture is entirely viable. Security has worked from derived indicators for a generation. The difficulty is verification, not feasibility,” Gogia said.
He added that detecting behavior across time requires retaining some form of representation. “A system cannot detect behaviour across time unless it remembers something across time,” he said.
Private Safety Processing “is privacy-preserving abuse detection. It is not an enterprise forensic record, and OpenAI does not claim it is,” he said.
According to Apeksha Kaushik, senior principal analyst at Gartner, the approach could influence AI adoption in industries with strict data requirements.
“Privacy-preserving safety models, such as those employing Zero Data Retention (ZDR), represent an emerging approach that may lower barriers to AI adoption in regulated sectors like financial services and healthcare,” she said.
Such models “may help organizations address certain privacy requirements and may align with frameworks such as GDPR and HIPAA, contingent on specific implementation details and regulatory guidance,” she noted.
Kaushik added that organizations should evaluate such approaches against their compliance requirements. “Organizations are encouraged to consult with their compliance and legal teams to determine whether such approaches meet their specific regulatory and operational requirements,” she said.
OpenAI said enterprises retain control over their data under this model and can investigate alerts using their own systems. Customers can also choose to share relevant data with the company to support investigations or appeals.
Analysts say this shifts responsibility toward enterprises. “Zero Data Retention does not remove the forensic burden. It relocates it,” Gogia said.
The article originally appeared on CSO.
Apple’s latest filing in its ongoing fight with OpenAI makes it sound as if Apple legal is so frustrated at the arguments the AI firm is making that it’s begun swatting them away like a parent might dismiss a child.
If you’ve not been keeping up with tech’s latest legal soap opera, here’s the overview of what’s true:
What’s also clear is the tone of Apple’s litigation, which appears to have shifted to exasperation. For example:
“Defendants’ arguments about the individual defendants ignore the legal standard on a motion to dismiss. Again and again, Defendants rely on attorney argument or extrinsic evidence, hypothesize about implausible explanations for a Defendant’s ‘innocent’ misconduct, and ask the Court to draw inferences in their own favor. That is not how a motion to dismiss works. As long as Apple has alleged ‘enough facts to state a claim to relief that is plausible on its face,’ Defendants’ disagreement on the merits is irrelevant.”
You get a similar tone at the end of the filing, where Apple points out: “As for Defendants’ argument that, ‘the access it complains of was identified and shut off by Apple before it filed suit,’ that does not address OpenAI’s continued use of the materials Defendants took, nor does it address other ways Open AI seeks to misappropriate Apple’s trade secrets….”
Again and again in the filing, Apple’s legal team looks to absolutely demolish the arguments raised by OpenAI. You also see them hint at additional evidence the company expects to find during discovery that it will subsequently present once the case reaches trial. You even see them argue that aspects of OpenAI’s denial actually help prove Apple’s claims, when it says, for example, “In any case, the value of Apple’s trade secrets can be plausibly inferred from the lengths to which Defendants have gone to acquire them.”
It’s hard not to hear the impatience in some of the phrasing — you can read it for yourself right here.
That phrasing is deliberate, of course. Ultimately, Apple’s legal team knows that OpenAI is not doing itself any favors in the way it is denying the claims made against it, and the company hopes that by convincingly pointing out the weaknesses in the defense arguments it will leave the judge with little option but to let Apple take its litigation to the next stage.
While not necessarily relevant to the case, it may also be worth pointing out that OpenAI has also been accused by Elon Musk’s xAI of stealing trade secrets, which may yet come up as an aside here, if only to show a claimed pattern of behavior.
If Apple does succeed in its arguments, the tone it has set very much shows it to be defining the battle space. Successfully doing so will be even more strategically vital once its competitor finally manages to introduce the world to Jony Ive’s magic donut AI device.
Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
After a week of using Google’s new Pixel 11 phones, two seemingly at-odds realities are crystal clear in my mind:
Interestingly enough, these two realities manage to exist harmoniously — because they’re both very much accurate and very much true.
The real question, then, becomes what all of that means for you as a productivity-minded, tech-dependent professional — and if these shiny new Pixels are advisable for you to think about buying.
The answer, believe it or not, is actually quite simple.
[Got a Pixel? Any Pixel? Check out my free Pixel Academy e-course to find all sorts of advanced intelligence lurking within your current phone!]
First things first, let me tell you a little bit about my past week’s adventures.
Last Wednesday — the same day Google awkwardly launched its latest-gen Pixel 11, Pixel 11 Pro, and Pixel 11 Pro Fold (gesundheit!) phones in an elaborate evening event several hours after an extensive blog-based announcement — I received a box of loaner review units for all those shiny new models.
I’ve spent the past year or so living with my own personal Pixel 10 Pro, and I’ve personally owned and used almost all of the flagship-caliber Pixels (in one form or another) before that. Even with the iterations I haven’t personally owned, like last year’s Pixel 10 Pro Fold, I’ve spent plenty of time toting ’em around and getting to know ’em — and I’ve taken detours to explore most flagship-level Android gadget releases from other manufacturers along the way as well.

JR Raphael, Foundry
So when I moved myself into these latest Pixels and started carrying ’em in place of my now-standard 10 Pro device, I have all the perspective in the world to tell you that:
And that’s to say nothing, of course, of the Pixel’s unmatched software support policy. The Pixel is the only Android device where timely and reliable software updates — both major Android releases and the many smaller rollouts that now accompany those throughout the year — are an unambiguous part of the core product promise. With any Pixel phone, you’ll receive every software update within days of its release. No other device-maker even comes close to matching that guarantee, and for anyone who cares at all about maintaining optimal privacy and security practices on your phone over time, that’s a distinction you simply can’t ignore.
So that’s the first part of the Pixel 11 paradox — and that’s why these latest Pixels are all incredibly easy to recommend as the best all-around Android experiences available today and the only sensible suggestions for a top-tier Android purchase in 2026.
But there’s another half of the story, and it’s equally important.
Plain and simple, the most striking thing about these latest Pixels is how similar they are to their previous-gen Pixel 10 equivalents.
Now, don’t get me wrong: On paper, these latest Pixels are packin’ plenty of pertinent improvements. They’ve got new extra-efficient processors, brighter and supposedly more scratch-resistant displays, faster charging speeds, some new and improved camera components, and a thinner camera bar on the back. The Fold model is also ever-so-slightly thinner and lighter than its predecessor, by 0.7mm when folded (0.02″ — roughly half the thickness of a US dime) and 19g (roughly two-thirds of an ounce — the equivalent weight of three #2 pencils).
Speaking of the Fold, the 11 Pro Fold model is a true treat to use, and I still love its more familiar-phone-like form compared to the shorter and squatter, square-ish shape Samsung is now adopting ahead of Apple’s expected move in that same direction. The Pixel Fold’s dimensions allow you to feel like you’re using a regular phone most of the time, without much compromise or awkwardly limited screen space, and then enjoy that glorious tablet-like screen on the inside whenever you feel like unfolding it.

JR Raphael, Foundry
Again: All of this works. Across the board, the Pixel 11 phones couldn’t possibly be more pleasant to hold, carry, and use. They’re fast, their photos are second to none, and they sport a couple of truly interesting new software features that you might actually appreciate — like a new Magic Capture camera mode that lets you tap one button to record a video and automatically get full-resolution photos of the most meaningful moments from within it and an enhanced Android voice typing system that works like Wispr Flow and makes dictation easier and more accurate than ever.
There’s also a new HiLight LED system on the Pro models’ backs that’s intriguing in theory but almost shockingly limited in implementation. Quite literally, all it does at the moment is light up when you’re talking to Gemini hands-free and light up with a custom color when one of your favorite contacts is calling.

JR Raphael, Foundry
It’s a great idea and return to the simple effectiveness of notification lights from Android’s past, but it’s embarrassingly half-baked in its execution. You can set up something similar but much less limited and more useful with a few minutes of crafty configuring on any Android device.
Oh, and these latest Pixels also pack a handful of new whizbang AI additions that you probably won’t notice or ever do much with.
So as you can see, in and of themselves and in the big picture, the Pixel 11 phones all stand out and are exceptional. But when you start looking at them compared to last year’s models or even the Pixel 9 devices before that — well, things get a little more complicated.
In a week of using the different Pixel 11 phones, I couldn’t immediately detect or appreciate the presence of any of the aforementioned year-to-year improvements compared to the experience of using last year’s Pixel 10 models. The camera performance is still incredible, but looking at photos taken with the Pixel 11 Pro and Pixel 10 Pro (or any other 11-to-10 Pixel-to-Pixel comparison), the actual visible differences are subtle enough (and the previous model’s photos strong enough) that I suspect few people will spend much time thinking about them. As far as the processor goes, the phones feel zippy and as fast as can be right now, for sure — but, once more, I’d struggle to say they’re noticeably any faster, in real-world terms, than the models that came before them. And as far as the Fold is concerned, the form differences from last year’s device are so subtle that I think most people will be hard-pressed to be aware of the evolution.

JR Raphael, Foundry
The Magic Capture mode is nice, meanwhile, but I’m not sure it’s a reason in and of itself for most folks to buy a new device if they’re already using a recent previous-gen Pixel — and it may well make its way to older Pixels eventually. The enhanced Android voice typing system might be a reason to upgrade — but (a) it’ll almost certainly come to the rest of the Android ecosystem before long, and (b) in the meantime, you can get almost the exact same experience in just a slightly less native-feeling and convenient way by installing Wispr Flow.
That aside, we can’t overlook two downgrades in the Pixel 11, compared to the 10 models: First, the Pixel 11 eliminates the thermometer that’s been present on the past few Pixel Pro models — something that was originally launched before it was ready but that evolved into a genuinely useful element. I can’t even count the number of times my wife or I have relied on it for taking a quick temperature when someone’s under the weather and a standalone thermometer can’t be found or is acting up and giving us a different reading every time we try it.
Second, and perhaps even more significant, the Pixel 11 Pro models start with 12GB of RAM and only bump back up to 16GB — the standard level of memory for all Pro models last year — if you opt for the pricier 512GB storage version. The reason for this change is seemingly an industry-wide issue that’s out of Google’s control, of course, but it’s still something you’re faced with as a potential purchaser of these products. (I’d be surprised if anyone detected an immediate discernible difference in experience as a result of this change, but it stands to reason that the limitation could adversely affect you at some point down the line — particularly if you’re doing a lot of multitasking or other resource-intensive work.) The Pixel 11 Pro Fold, meanwhile, maintains its 16GB RAM level but includes a $100 price hike from last year’s version.
So while the Pixel 11 phones are great phones in and of themselves, they aren’t exactly great upgrades if you’ve already got a Pixel 10 or arguably even a Pixel 9 equivalent in your person-paw. And because of that, most reviewers are gonna look at ’em and say, “Meh. These aren’t exciting.”
Here’s a little secret, though: Particularly for professionals, “exciting” isn’t everything. An exceptional all-around experience and the knowledge that your device will remain optimally up-to-date as far as security, privacy, and performance are concerned — for a full seven years, with these products — means more. And in a weird way, having these phones not feel like must-buy upgrades over the past couple models is actually an indication that those previous years’ products are doing their jobs well.
If you’re on an older-gen Pixel or thinking about making the leap to the land of Pixels for the first time, you can’t go wrong with any of Google’s new Pixel 11 options. They may not be exciting, exactly, compared to what came before ’em — but in an era where almost everything new is all about AI gimmicks for the sake of AI (and often at the expense of accuracy and quality), avoiding excitement and sticking to a setup that simply works well might be the smartest move you can make.
Don’t let yourself miss an ounce of Pixel magic. Sign up for my free Pixel Academy e-course and discover tons of hidden features and time-saving tricks for whatever Pixel you’re using right now!
AI is known to be confidently wrong, and now it’s influencing humans to be that way, too.
In a new study, researchers tested AI’s influence on humans reviewing innovation proposals, and found that AI recommender tools were persuasive enough to convince the evaluators to reject decisions made by independent human experts, thus causing them to pass on promising innovations. Similarly, they went along with AI approval of ideas that the human experts found sub-par.
Interestingly, reviewers were also more inclined to defer to an incorrect AI decision when the model explained itself. Narrative explanations degraded human judgment, rather than enhancing it. People did better when they weren’t given a reason for the AI’s decision.
“Our findings reveal that LLM explanations do not necessarily improve decision-making,” the researchers, associated with Harvard Business School, MIT, and the University of Washington explained in their findings. “Effective human-AI collaboration requires designs that preserve rather than supplant independent human judgment.”
Every enterprise screens proposed projects before pursuing them, but there is always uncertainty, and the risk of trade-offs like false positives (going forward with projects that ultimately fail) or false negatives (rejecting ideas that might have succeeded). For an example of the former, the researchers point to Google Glass or Amazon’s Fire Phone; for the latter, Xerox terminating early Ethernet and PostScript projects.
Because they have limited time and only basic information to go on, decision-makers are increasingly turning to LLMs that use predictive algorithms to generate recommendations and rationales based on context.
The researchers set out to explore AI’s role in what they called “early-stage innovation screening.” They judged how human evaluators were influenced by LLM recommendations, both with and without explanations from the model on how and why it reached its decision.
Their experiment asked 228 experienced evaluators to assess nearly 50 submissions to an MIT challenge. They tested three different scenarios: human-only proposals with no AI assistance; LLM evaluations with a written rationale for the decision; and black-box AI pass-fail recommendations with no accompanying explanation.
Evaluators’ decisions were then compared to those made by four human experts. Those decisions were considered the ‘correct’ baseline. They were judged on whether they outright complied with the LLM’s recommendations, overrode them, or productively overrode them, meaning they independently verified persuasive model outputs before making a decision.
Their decisions were classified as correct (agreeing with human experts’ positive/negative decisions), false positive (supporting submissions that experts would reject), and false negative (rejecting submissions experts would move forward with).
Overall, the evaluators accepted LLM recommendations 67% of the time. They agreed with both black-box and narrative LLM decisions roughly 75% of the time, but only agreed with human decisions 54% of the time.
Seemingly counterintuitively, black-box recommendations improved the quality of decisions (aligning them with human experts) but recommendations with narratives did not. When given an LLM recommendation to reject a submission and an accompanying reason why, evaluators disproportionately agreed, which reduced false positives, but “substantially” increased false negatives.
The researchers posit that this is because narrative explanations “suppress” productive overrides; LLMs provide a convincing argument that is easy to accept, essentially discouraging independent human verification. This contradicts a common assumption that LLM explanations augment human decision-making.
The researchers pointed out that people are cognitively predisposed to weigh negative information more heavily than positive information; the phenomenon is known as ‘negativity bias.’
“Rejection is an active, eliminative decision that feels more consequential and accountable than preserving optionality,” they wrote. It also maintains the status quo, avoids risk and bias, and requires no resource commitment.
LLM explanations provide “ready-made justifications” for going along with rejection decisions without independently verifying them; humans effectively offload their thinking to AI, researchers explained. Evaluators often rely on surface cues such as fluency, coherence, and seeming credibility. LLMs are particularly well-suited to exploit this because they are linguistically fluent and expert-like, creating an “illusion of explanatory depth.”
Thus, “individuals tend to overestimate their understanding of a decision despite limited insight into its reasoning,” the researchers wrote.
The researchers pointed out that their findings have “clear implications” for enterprises designing AI-assisted evaluation systems.
Enterprises should be cautious with LLM explanations in high-stakes decision-making, they advised. AI recommendations should not be taken at face value; they should always be tested before any associated deployment. This helps improve accuracy and encourages human reviewers to detect errors and learn how models operate, or potentially can even increase human-AI agreement.
In decision contexts such as quality control, compliance screening, or fraud detection, LLM explanations could support conservative human decision-making, the researchers noted. On the other hand, in tasks like early-stage screening, LLM narratives could undermine performance by “discouraging independent judgment and suppressing productive human override.” In this context, simpler or more opaque recommendations may preserve human discretion and verification.
Future design of explanation systems should factor in the nature of the task and the potential cost of errors made by AI, the researchers advised. Enterprises could experiment with models that support contrasting narratives (reasons to reject an idea alongside reasons to accept it) or uncertainty disclosures based on a fixed threshold, rather than on purely binary decisions. Systems could also be structured to invite human disagreement.
The researchers also noted that there is opportunity to test whether narrative explanations have different impacts at later stages of decision-making, when evaluators have fewer options, more information, and increased incentive to verify outputs and think the problem through.
Ultimately, the researchers emphasized, “organizations should treat AI explanations not as universally beneficial transparency tools, but as behavioral interventions whose effects depend on how evaluators process information under uncertainty.”
This article originally appeared on CIO.com.
OpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.”
In its first announcement, issued Tuesday, OpenAI said it “temporarily” slowed the pace of its scaling, in addition to pausing reinforcement learning training.
Those efforts occurred while OpenAI hardened and red-teamed its research environment and expanded monitoring, it said, adding, “our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignment before proceeding.”
OpenAI’s statement said the company will “now require stronger evidence of aligned behavior throughout all of training, building on research and evaluations already underway. Keeping increasingly capable systems aligned is a challenge the whole field will need to address.”
It also highlighted other recent efforts to improve its procedures, including workload isolation, network isolation and “continuous security testing.”
However, the company noted that its newly proposed monitoring will generate overhead costs of “roughly 20% of the inference compute being monitored, though the cost varies substantially across training and evaluation workloads.” It promised to share more details about this system in a forthcoming blog post.
Analysts and consultants said that the moves were likely announced to position OpenAI better for an imminent IPO.
Carmi Levy, an independent technology analyst, viewed the statements as “a slickly conceived move to win PR points as safety concerns around agentic AI continue to mount. It signals that the company is doing something, even if that something is woefully inadequate. In the absence of explicit regulations forcing vendors like OpenAI to permanently prioritize safety above all other factors, a two-week pause is little more than window dressing designed to deflect criticism.”
Jason Andersen, principal analyst at Moor Insights & Strategy, agreed, saying that he thought that “this is a little bit of pragmatic theater as they move into an IPO.” But he suggested that there also may be more going on. Enterprises will continue to spend on AI aggressively, and “it will be pedal to the metal until they get sued.” Then they’ll back away.
However, he said, “the only way that these [large AI] companies are going to be successful post-IPO, the only way to scale, is to get much deeper into enterprises. And the only way to do that is to alleviate fear and risk.”
In Wednesday’s announcement, OpenAI didn’t say what constitutes eligibility for the zero data retention program, only that it would start in September, when the company would share details in a “technical white paper.”
But Andersen said that this move has to be viewed in the context of today’s complicated vendor relationships.
Much of OpenAI’s revenue is not direct from the enterprise, but through partners like Microsoft and AWS, he pointed out. “So let’s say I use a tool like Amazon Kiro, which can use OpenAPI via API to build my app without my knowledge of the model. It sounds like Amazon is the customer and you are Amazon’s customer. If you are an enterprise and want this [zero data retention] protection, you must provide your own API key to Kiro. The enterprise just becomes the direct customer and now gets the lockbox access. AWS no longer has access and loses out on revenue/margins.”
Consultant Brian Levine, executive director of FormerGov, added that the data retention promise is also complicated by how processes tend to function.
“OpenAI says it can now monitor for abuse across interactions without any staff ever reading the underlying content,” he said. “That is a strong technical promise, because watching for misuse and not being able to see the data have historically pulled in opposite directions. And the proof is a white paper that is still weeks away.”
In addition, he noted, “Zero is never quite zero because CSAM-flagged content is still retained for legal reporting.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, saw the move somewhat differently, suggesting that it was designed to soften possible legislation.
“It is likely that they are seeing the writing on the walls about upcoming regulations that could have a significant impact on them, and this could be their attempt at showing a desire to self-regulate to avoid a more draconian legislation in the future,” Villanustre said.
Still, Mike Wilkes, enterprise CISO at Aikido Security, observed, “sincerity is not the same thing as permanence. In the old Norse/Scandinavian image of a giant sea monster waiting beneath the surface, you might call this ‘Pause the Kraken.’ The real question is what conditions have to be met before OpenAI decides to release it again.”
Added Justin St-Maurice, technical counselor at Info-Tech Research Group, OpenAI seems to want credit for doing the bare minimum of what a major AI firm should have always done.
“If a carmaker announced that it was going to take basic safety testing more seriously before production, it wouldn’t be to fanfare. Frankly, it would be embarrassing that something so fundamental needed clarifying to a skeptical public,” he said. “The question for me is why this needs to be an announcement now, and whether they hold the line once a competitor ships something that makes a pause expensive.”
Thus, he advised, “stop treating these announcements as diligence. Ask for the evidence of what you’re actually getting, not what you’ve been promised. If a vendor can pause development for security reasons, and the way you found out was through a blog post, then you should be asking what your contract requires them to disclose to you.”
The new Google Pixel 11 Pro XL doesn’t dramatically reinvent the company’s flagship smartphone formula. From a hardware perspective, this year’s model represents an incremental update. But after spending time with Google’s latest full-featured Pixel, I’ve found that some of its most meaningful improvements for business users aren’t necessarily the things that stand out on a spec sheet or benchmark chart.
Starting at $1,299 with 256GB of storage, the Pixel 11 Pro XL features a 6.8-in. Super Actua LTPO OLED display, Google’s new Tensor G6 processor, a 5115mAh battery and an updated triple-camera system. Google also pledges seven years of operating system, Android security and Pixel Drop updates.
The hardware is very good, but Google’s deeper integration of Gemini with Android and other thoughtful software features are what make this device more interesting.
Google’s Tensor processors have never been benchmark chart-toppers, and the Tensor G6 doesn’t change that. In Geekbench 6, the Pixel 11 Pro XL scored 2,736 single-core and 7,399 multi-core numbers. That’s a healthy improvement over the Pixel 10 Pro XL’s 2,326 and 6,413, respectively, but well behind devices like Samsung’s Galaxy S26 Ultra (at 3,683 and 11,243) powered by Qualcomm’s latest SoCs.

Dave Altavilla
In 3DMark Wild Life, the Pixel 11 Pro XL scored 13,761, essentially neck-and-neck with Apple’s iPhone 16e at 13,627, though still far behind current gen flagships like the Galaxy S26 Ultra at 31,036.
There’s an important disconnect, however, between those numbers and actually using the phone. The Pixel 11 Pro XL feels fast and responsive in everyday use, whether moving between email and messaging apps, browsing complex websites or multitasking. Google claims the Tensor G6 delivers 25% faster web browsing and 15% faster application launches, while its TPU offers 50% more compute and up to 3.5X faster on-device AI processing.
For business and mainstream users, benchmark performance is less relevant unless you’re also a mobile gamer. Opening and switching between apps especially feels more responsive than other Android phones I’ve used as daily drivers. Add Google’s latest software efficiency and AI features, and the Pixel 11 Pro XL feels much more capable than the benchmark numbers suggest.
Rambler may be the best example of Google’s efforts to minimize friction. Google has long offered excellent speech-to-text input, but Rambler takes voice input further. Instead of requiring carefully structured dictation, the Gemini-powered feature understands natural speech, including pauses and filler words, and turns it into cleaner written text.

Dave Altavilla
In practice, it’s a significant improvement and allows me to make fewer dictation mistakes, whether writing emails or texting. Being able to speak naturally and have the phone turn those thoughts into clean, well-crafted text is genuinely useful, and auto punctuation also seems improved. This is the kind of AI functionality I want from a business-focused device: technology that removes friction and makes me more efficient, rather than shoehorning in AI just for AI’s sake.
Gemini Intelligence also extends contextual assistance across more than 40 apps. Google can surface flight information when you’re discussing a trip, suggest adding events to Calendar or locations to Maps, and pull relevant information into Wallet.
The Pixel 11 also expands Google’s Live Translation capabilities to real-time translation and dubbing of video and audio using on-device generative AI models enabled by the Tensor G6. These features could be especially useful for international business and personal travel.

Dave Altavilla
HiLight is a new software feature and integrated RGB LED array on the rear camera bar that provides visual feedback when Gemini is active and displays different colors for incoming calls from selected contacts.
The concept has real potential for business users. Put your phone face-down during a meeting and you could know whether something important requires attention without repeatedly picking up the device to check. Unfortunately, Google doesn’t expose enough configurability yet. I’d like to associate colors or patterns with an important email, Teams or Slack message, Calendar alert or priority contact. Google says message notifications from favorite contacts are coming, but the hardware appears capable of much more.

Dave Altavilla
The Pixel 11 Pro XL’s 6.8-in., 1-120Hz LTPO OLED Super Actua display is excellent, with peak brightness now reaching 3,600 nits. It’s easily one of the nicest phone screens on the market, with plenty of punch in daylight and accurate, vibrant colors. Its speaker system remains strong as well, while the Pixel 11’s industrial design is an attractive evolution of Google’s familiar camera-bar aesthetic.
As we’ve come to expect from Pixel phones, the camera system is also excellent, with a 50MP main sensor, 48MP ultrawide and 48MP 5X telephoto camera. Shots are crisp, with especially good low-light performance and telephoto capability. The Pixel’s color science has always been a bit drab for my taste, while others on my team call it more “accurate” versus the often more saturated rendering of Samsung Galaxy devices.

Dave Altavilla
New software features include Camera Looks, Magic Capture and Creator Suite. Camera Looks provides more control over how Pixel devices process photos at capture, while Magic Capture uses AI to analyze hundreds of frames to catch fleeting moments. Creator Suite offers perhaps more practical utility for professionals, with an integrated teleprompter and project organization tools for producing video and social content on the fly.
Battery life appears improved as well. My observations are anecdotal currently, with specific benchmark testing still to come, but the Pixel 11 Pro XL seems appreciably more efficient than the previous generation. It’s not a groundbreaking leap, but battery life is solid and competitive with premium Android flagships like Samsung’s Galaxy S26 family. Some Chinese phone makers are operating in another class these days, with much larger silicon anode batteries and extremely fast charging, but that’s a different segment of the market in my opinion.
In my day-to-day use, which is admittedly heavy, the Pixel 11 Pro XL reliably gets me through a full, long day, though I typically need to top it off again the following day on my Pixelsnap charger.
Regardless, the Pixel 11 Pro XL’s 5115mAh battery can reach a 75% charge in roughly 30 minutes with a compatible 45W charger, while Pixelsnap Qi2.2 wireless charging tops out at 25W. So, at least there are well-rounded power options here.
The new Tensor G6 works alongside Google’s new Titan M3 security coprocessor and Trusted Execution Environment, with post-quantum cryptography extending into the device’s secure boot process. The Pixel 11 Pro XL also includes anti-phishing, anti-malware and scam protections.
Combined with seven years of OS and security updates, Pixel devices remain a compelling Android platform for organizations that intend to keep phones in service fleets for several years.

Dave Altavilla
The new Google Pixel 11 Pro XL doesn’t deliver a major generational hardware upgrade. Its conventional benchmark performance trails the fastest flagship phones, physical changes are modest, and most Pixel 10 Pro XL owners will likely have little reason to rush out and upgrade.
That said, Google’s differentiation with its Pixel series increasingly comes from the intersection of Android, its Tensor silicon, Gemini AI and the company’s broader services ecosystem. Rambler demonstrates particularly well why that approach makes a difference. The feature obviously doesn’t require massive horsepower, but this type of on-device AI can make a measurable difference in how efficiently someone uses a smartphone throughout their workday.
For business users coming from an older Pixel or another Android device, the Pixel 11 Pro XL is a polished, secure and highly capable productivity, creation and consumption device with an excellent display, great cameras, solid battery life and increasingly useful AI features.
The bottom line is that this is an evolutionary Pixel launch. But Google’s software and AI integration make the overall experience more compelling than hardware specifications alone would suggest.
Apple has changed its App Store fee structure in the EU in a move to further satisfy the requirements of the Digital Markets Act (DMA). While critics continue to argue the changes don’t go far enough, the European Commission welcomed the changes made and plans to monitor how they’re implemented.
Specifically, Apple introduced a less complex system than it had offered before, with a lower, but universal, 5% Core Technology fee applied on digital transactions in apps distributed outside the App Store. Apple changed its commission structure and eliminated some fees, including initial acquisition and store services fees. It has also expanded the scope of eligibility to operate alternative app marketplaces. The new changes go into effect Oct. 1, and include (verbatim from Apple’s statement):
There are additional improvements to what Apple was offering before, Developers, for instance, can now offer Apple In-App Purchase alongside alternative payment options. Also:
In what I consider a major win for most customers, Apple also seems to have convinced Europe of the need to require every alternatively distributed app to go through the company’s Notarization service. This provides a baseline review of an app aimed at ensuring basic functionality and protection from serious threats; that’s important, as it implies that Apple customers can be a little more certain, if not completely confident, that apps purchased outside of the App Store aren’t packed with secret malware or payment scams. While Notarization isn’t able to fully ensure against that, it helps.
Put the changes together and I think large developers will find themselves paying Apple less for the privilege of selling apps on its platform, while for the vast majority of developers a 15% charge remains. Epic, in contrast, charges developers 12%, but arguably offers a much more limited infrastructure as it does not make devices, operating systems, or any of the supporting services that make a good customer experience on the platform.
The fact that Apple has worked with the EU to reach these new terms, which to a great extent do seem to deliver much of what was required under the DMA in relatively straightforward fashion, should sound like a win to critics of the App Store business. Apple has made it possible to use alternative payment systems and app stores and seems to have coalesced around the 15% fee as a base charge for the vast majority of developers with a much clearer and more straightforward approach. The company would likely argue that while doing this, it has striven to protect its business and its customers — and it can argue it should be able to generate revenue from an app’s distribution on its platform.
That’s not how Apple’s fiercest competitors see things. The Coalition for App Fairness, a group that includes competitors Spotify and Epic, put it this way: “Apple’s new terms defeat the purpose of the DMA by keeping fees high and blocking true competition.”
Meanwhile, Epic CEO Tim Sweeney wrote, “Apple has launched a new junk fee structure in EU, mirroring the terms in Brazil and Japan. They’re still unlawfully charging for linked-out transactions (clearly prohibited by DMA) and add prohibitions and friction to herd kids into high-junk-fee Apple payments.”
The tone of both statements suggests that if the EU finds itself satisfied that Apple has brought itself into compliance with the DMA, some of its competitors might challenge that decision in the courts. They’ll have to if they want to avoid becoming bit-part players in Apple’s history, which is what an EU-approved settlement would reduce them to.
Apple, on the other hand, will likely continue to say some of its competitors want to compete on its platforms while paying nothing. If this continues, regulators will eventually need to define what they see as a viable revenue model (and why). At the same time, the tone of Apple’s latest statement suggests the new deal already matches regulatory expectation. If so, then it’s all over bar the shouting, and if the new détente holds, it’s reasonable to expect Apple will introduce this new business arrangement elsewhere over time as it firmly closes the door on its Epic struggle.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction.
The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this year, following Reprompt, which bypassed Copilot guardrails by repeating queries, and SearchLeak, which Varonis said turned Microsoft 365 Copilot Enterprise into “a silent exfiltration tool. All three share the same exploit pattern: one click on a legitimate-looking link is enough.”
A detailed blog, posted by Varonis on Tuesday, said the hole’s capabilities were significant.
CoSnitch relied on an attacker leveraging three different Copilot flaws, Varonis wrote:
But the potentially most intriguing element of the CoSnitch bug was how it was discovered: Copilot essentially revealed the hole itself.
“We prompted Copilot to explain why auto-execution was impossible, and each refusal came with a technical justification, which mapped the architecture,” the Varonis post said. Varonis then “reframed every refusal as a follow-up question, and each answer narrowed the attack surface further. Copilot then disclosed an undocumented URL parameter, unprompted, mid-refusal, including its historical behavior and every protection put in place to disable it. We built the URL exactly as described. With no click or confirmation from the user, the prompt was successfully executed automatically. Copilot wasn’t breached; it was played.”
Microsoft confirmed both the flaw and the fix, emailing a statement that said, “our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques.” It also issued an MSRC disclosure labeling the hole “critical.”
But Microsoft’s emailed comments also included a statement that is not strictly accurate: It said, “enterprise customers using Microsoft 365 Copilot are not affected.”
But analysts and others stressed that the complex nature of enterprise environments would often also house some consumer-grade Copilots from the personal accounts of workforce members, meaning that the flaw in the personal version could have absolutely impacted the enterprise version.
This is further complicated by the fact that Microsoft also said that it “is in the process of moving toward a more unified Copilot experience,” referred to as Copilot Fusion; details of the planned product merger began to leak last month. That means that enterprise CISOs need to be concerned about flaws in the personal version of Copilot that may be carried over into the merged offering.
The timing of Microsoft’s fix was also fragmented. Varonis reported the CoSnitch hole on December 31, and the company patched one element of the hole, its auto-execution capability, on February 1, noted Lior Adar, a Varonis senior security researcher, in an interview, but it didn’t complete the fix until Tuesday.
That February patch “lowered the other vulnerabilities significantly,” Adar said. And, added his colleague, Chen Levy Ben Aroy, the Varonis Cloud Security Research Team leader, “LLMs are a whole new world of vulnerabilities.”
Mark Tauschek, VP and distinguished analyst at Info-Tech Research Group, said that he found the Varonis methodology of tricking Copilot into revealing its own flaws powerful.
Varonis used “a very sophisticated combination of social engineering on an LLM, a variety of jailbreaks, and a prompt injection attack that is very concerning in its capability,” he said. “The combination of hack vectors is what makes it more startling, as we’ve seen all of those methods alone before, but I think all three working for one exploit is new, at least from a disclosure perspective.”
For CISOs, Tauschek said urgent action might be required.
“Much like in the old macro virus days in the late 90s and early 2000s, the only way to definitively stop it is to turn it off. Disable macros back then. Disable Copilot now,” Tauschek said. “There are many mitigation steps that can reduce risk to negligible, but that’s not zero. The point is, it’s just the beginning.”
Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said there is a much more difficult issue involved in this case. He argued that the financial incentives for the major AI companies will make meaningfully fixing these kinds of holes almost impossible.
He pointed out that every guardrail that would fully close this class of attack degrades the product, because the same capabilities being exploited are the features that Microsoft is marketing as Copilot’s value. “The fix and the feature are in direct tension, which means these will not be cleanly patched so much as perpetually mitigated, and the eight-month window is what it looks like when a vendor is negotiating between its security obligation and its product roadmap on every single fix,” Mahapatra said.
“This is the pattern CISOs must internalize: in agentic systems, the malicious action and the legitimate action are the same action with different intent, which collapses the entire signature-and-anomaly detection model that enterprise security has been built on for twenty years,” Mahapatra said. “CoSnitch is serious, but its defining property is that nothing was broken. Three chained flaws: an autorun URL parameter firing a prompt with no click, OAuth connector abuse reading full Gmail bodies rather than metadata, and persistent memory poisoning through web summarization, and every one is Copilot doing exactly what it was designed to do.”
Mahapatra added that the third element of the CoSnitch flaw is the most troubling.
“The memory-poisoning component is the one being undersold, and it is the most dangerous. A single summarized webpage writes attacker instructions into Copilot’s persistent memory, and that memory survives password changes, session revocation, and device re-enrollment,” he said. “Every standard incident response step leaves the injection intact. The attacker needs no persistent infrastructure after the initial write, because every future session runs under attacker-controlled context, recorded only in a memory settings UI almost no user has opened.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, also pointed to a bigger-picture issue that impacts all agentic and genAI deployments.
“The mechanisms behind the prompt injection part of the attack are based on the inability of the LLM to differentiate between data, the unsafe data stream coming from an external web page, and instructions which happen to be embedded in that data stream by the attacker controlling that external web page,” Villanustre said. “This is another example of why a different architectural approach to LLMs that separates data and instructions is needed to better guarantee the safety of their operation. This is not something that Microsoft or any other AI vendor has addressed to date.”
Diffusion models are becoming sophisticated enough that they can reproduce an image even when they don’t have access to the original.
In a series of ‘what if’ scenarios, researchers associated with MIT’s Computer Science & Artificial Intelligence Laboratory (CSAIL) swapped out different training datasets to test the impact on image outputs when original image data was completely removed.
It turns out that, at sufficient scale, nothing changed.
The researchers call the phenomenon “attribution decay”: The more data a diffusion model is trained on, and the larger it gets, the less individual inputs matter.
“If you take away a piece of data and the output of the model doesn’t change, then that piece of data didn’t affect the output,” Zheng Dai, lead author on the work, explained in an MIT blog post.
These findings could have significant ramifications when it comes to resolving growing concerns about intellectual property (IP) and copyright infringement.
Modern generative diffusion models essentially replicate statistical patterns in large training datasets to create realistic reproductions. These powerful tools have achieved “remarkable results” in a wide array of applications, the researchers noted, notably image, video, and audio generation.
But they are increasingly under scrutiny by creatives, companies, and policymakers, who all want a way to assign responsibility for generated outputs. Models sit at the center of lawsuits, licensing deals, and proposed regulations around the world.
For instance, Stability AI (maker of Stable Diffusion) and Midjourney are embroiled in an ongoing class action lawsuit filed by several artists in federal court in California. The claimants argue that the popular image, video, and audio-creating models are scraping billions of their copyrighted images without their consent.
Getty Images also brought claims against Stability AI, but they were struck down by the High Court of Justice Business and Property Courts of England and Wales, although Getty did partly win trademark claims because some AI-generated images closely resembled its work.
Attributability, the MIT CSAIL researchers noted, would increase understanding of “machine unlearning,” data poisoning, model interoperability, fairness, and privacy, while also addressing ethical, legal, financial, and regulatory issues.
“Developing a method to attribute generated outputs to influential training data would greatly advance our understanding of and ability to regulate these models,” the researchers wrote.
In their experiments, they used ablation, which is essentially testing what happens when certain elements are removed by looking at what a model might have produced if it had never “seen” a particular image.
Typically, ablation is difficult because models need to be retrained after data is pulled out. But the MIT CSAIL researchers applied the method to a “diffusion ensemble” architecture of many different components trained on different pieces of data. These components could be swapped out to determine how much of an impact, if any, each one had.
“Our analysis is based on observing changes in model behavior, or lack thereof, upon omitting a part of the training set,” the researchers explained.
To do so, they trained 24 ensembles on datasets containing anywhere from 256 to 160,000-plus images. These were pulled from seven publicly accessible image datasets, including ArtBench (artwork), CIFAR-10 (generic colored images), Fashion-MNIST (clothing and accessories), CelebA (celebrity faces), and MetFaces (human faces).
In one example, they presented an image of a famous oil painting generated by a model trained on public domain artwork from 744 artists. It was shown side-by-side with hundreds of seemingly identical images that the model had generated, even when specific artists had been removed from training data.
The original was re-imagined in every possible variation, and the researchers quantified attributability by measuring the largest change they could induce by omitting training data. The radius became smaller as datasets became bigger, holding true across different measurements including pixel-by-pixel or semantic meaning.
In other words, single artworks by specific artists, or photographs of certain people, could be entirely removed from datasets, and the model could still reproduce that image or style. Essentially, tangible connections are lost, and linking to specific data points responsible for generated samples is “practically impossible,” or can even vanish, the researchers explained.
Their method is novel, they said, because prior work has focused on removing large swathes of data rather than targeting smaller pieces, what they called “leave-one-out style attribution.”
Because the experiment shows that, as Dai put it, it “doesn’t make much sense” to attribute a given output to a given piece of data, creatives and others may not be able to provide an audit trail tracing back to their original work.
Co-author David Gifford, an MIT professor and CSAIL principal investigator, said the findings have a direct bearing on legal questions around whether model outputs are actually derivative works.
“One way to think about this is that these models are creative,” he said. “They are not simply copying what they are fed, but creating brand new outputs.”
So if outputs can’t be correlated to individual pieces of training data, questions can be raised around fair use and whether, in fact, model-generated outputs are themselves copyrightable as “novel works,” Gifford said.
It could also shift the conversation about how original creators are compensated when what comes out of a model seems a direct recreation of their work, but can’t be traced back to anything on the internet.
Ultimately, producing outputs that are guaranteed to be unattributable is an “obligation for the industry, rather than a loophole,” he said. AI builders “need to revise their models to take advantage of the advances in this work, so they can show they’re not creating derivatives of individual people or items.”
Google has paid $10 million in a bankruptcy auction for a large amount of data from the defunct Spirit Airlines, Bloomberg Law reports.
The purchase includes 100 million emails, 500 million messages, data from Microsoft Teams, as well as information on revenue, flight operations, marketing, personnel, and project management. The material also includes 30 million lines of program code, development data, and various software models and algorithms, as well as pricing data from 7.2 billion competing flights and approximately 7.5 billion passenger transactions.
No personal data will be included in the deal, and according to Google, a third party will review the material and remove any information that could identify individuals. Google said the data will then be used to improve the company’s products and AI models.
In recent months, hints emerged concerning Apple’s plans to introduce camera-equipped AirPods Pro; the cameras would be designed to pick up details of your ambient surroundings and feed information to Siri to help you with your life.
At one point, we heard the product had been pulled citing privacy concerns. But that doesn’t seem to be the case, as the latest seemingly orchestrated Apple “leak” offers up a short video to explain how these things are going to work.
First spotted by MacRumors (is Mark Gurman on vacation?), the short clip was unearthed from within the macOS 26.7 Release Candidate.
The demo shows a man holding up a book so the camera in the AirPods can see the title. A voiceover says, “With Visual Intelligence, your world becomes saveable.” It continues, “See something you like? Just ask me to save it for later.”
While you could be forgiven for thinking this is a reference to salvation, the task at hand is much more mundane, with the cameras used to search for a book called Could Should Might Don’t, How we Think About the Future by futurist Nick Foster. There’s probably a message in that choice, given that the inherent tech at play here consists of cameras that are always on. Perhaps we need to think different about putting our lives on tape?
While nothing has been announced, Apple seems to have designed the tech so that it doesn’t record or save ambient video without consent. That means the data is (probably) processed on your iPhone, rather than in the cloud, likely in real time — with no saving unless you expressly request it. Apple hasn’t announced the product, so we have no insight yet into how this works technically.
But what it suggests is that the camera is designed to feed its data to Visual Intelligence, which lets Siri pick up information about your environment so it can answer questions such as: “Where is my local CCTV camera?” or “Is that person wearing camera-equipped glasses over there filming my kids without permission?” I doubt Siri will have answers to those questions.
Inherently, though, Apple’s promise seems to be that while the AirPods cameras are always rolling, the information is interrogated, rather than saved, so no real data is retained. You just gain access to Visual Intelligence for ambient AI. That’s a promise that, on the face of it, seems to marry privacy with convenience to some extent.
Apple’s historical commitment to privacy has led the industry. It has quite literally fought to protect customer privacy even as other big firms folded. Sadly, we can no longer be completely certain of the extent to which the company still protects our privacy in an era dominated by unannounced decisions taken by secret courts.
We also know AI is being used to poke holes in platform security at an incredibly rapid pace. In recent weeks, we learned Apple is being inundated with vulnerability reports. And while many of these are repetitions of the same thing, or not precisely what they seem to be, the company has had to look at them. This has led to a rash of security patches and resource allocation challenges. (It’s even worse for other platforms, by the way.)
Of course, the big secret behind this is that at least some of these now-fixed vulnerabilities will have been actively used by military intelligence. And as those insecurities are found and eradicated by AI, security services will become more insistent that OS makers build in tools for surveillance. We’ll see how this shapes up.
What we can easily predict is that whatever security protection Apple builds inside of its camera-equipped AirPods will quickly be put to the test.
The fact that these things will be tested means enterprise IT will need to engage in close scrutiny of the protections Apple puts in place. You do not want confidential documents, blueprints, or other printed records photographed by cameras stuffed in someone’s ears; IT will likely put constraints on these things at work or in highly confidential settings, such as hospitals.
Finally, I’m fairly convinced this leak represents a company looking to reset privacy expectations on its platforms. The introduction of the friendly and fluffy face of video AirPods in the video should help Apple familiarize its customers with the concepts and workings of these devices. Apple has time to move slowly on this, and its leadership likely already knows that spy cameras in your ears will not be an easy sell to all of its customers.
Nevertheless, it’s a sell it has to make, in part because future Apple glasses will require this – and because building trust and familiarity with this kind of intrusive tech will also be necessary for other product categories. (Apple insiders whisper the company wants to get into robotics, automation, or even transportation.
Apple isn’t alone in needing to dance between privacy expectation and product realization, hence the need for a reset. I don’t like it, by the way, but this appears to be the direction of travel. Good luck in tech dystopia, and don’t forget to subscribe to my newsletter for news and analysis.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see.
The Ontinue Cyber Defense Center discovered the implant while investigating an active campaign in July and has since tracked it as TWINLOOT. It was seen using SharePoint Online as a file-based dead drop, Microsoft Teams’ TURN infrastructure for interactive communications, and a headless instance of the victim’s own Edge browser to send Microsoft Graph API requests.
Its primary C2 traffic can terminate in Microsoft IP space rather than an attacker-controlled domain, Ontinue researchers said in a report shared with CSO ahead of its publication Tuesday.
“TWINLOOT works because defenders have been trained to treat Microsoft traffic as safe by default, and this malware was built to take full advantage of that,” said Shane Barney, chief information security officer at Keeper Security. “There is no attacker-owned domain in the chain, which means the traffic looks exactly like what it is supposed to look like, and most detection tools will leave it alone.”
Microsoft did not immediately respond to CSO’s request for comment.
TWINLOOT’s architecture separates routine tasking from “interactive” access. Its SharePoint channel polls a drive roughly every 15 seconds for commands, returning results and exfiltrating stolen credentials and reconnaissance data.
According to Ontinue, the implant authenticates to an attacker-controlled Azure tenant rather than the victim’s Microsoft 365 environment, producing no authentication or audit events in the victim’s Entra ID logs.
For interactive access, the malware can establish a reverse SOCKS5 tunnel and route it through Microsoft’s Teams TURN infrastructure. The operator can then use the compromised endpoint to access the internal network, with connections to services such as SMB, RDP, and WinRM appearing to originate from the victim machine.
TWINLOOT is only the second observed case of in-the-wild Teams TURN abuse, and Ontinue says it is the first to use actual WebRTC DataChannels for the technique.
The pathway is different from Edge transport. The implant launches Microsoft Edge in headless mode, attaches through the Chrome DevTools Protocol, and issues Graph API calls as “same-origin fetch ()” requests from within the browser. From network telemetry, it looks like a legitimate Edge process communicating with Microsoft, the researchers said.
Commenting on the detection complications TWINLOOT adds, Robert Coles, senior manager of threat intelligence security at Black Duck, said, “Attackers are increasingly hiding inside trusted cloud services rather than using attacker-controlled infrastructure.” He recommended focusing on behavioral detection, identity monitoring, and anomaly detection, including unusual Graph API activity, OAuth applications and consent grants, and anomalous SharePoint and Teams behavior.
On command, TWINLOOT displays a Windows 10 or Windows 11 lock screen populated with the victim’s real account information. It never validates the password. Instead, every password attempt is captured, encrypted, and sent to the SharePoint C2 channel. The victim receives a normal-looking incorrect password message before eventually authenticating the login.
The stolen credentials can enable lateral movement through the reverse SOCKS tunnel, potentially allowing RDP, SMB, or WinRM access to other systems.
The implant also contains a persistence technique that Ontinue calls “Corrupting the Hive Mind.” It creates a Windows “NTUSER.MAN” mandatory-profile hive offline, requiring no administrator privileges and generating no registry modification event.
This is the first time the technique is ever used in the wild, Ontinue said. Defenders were advised to focus on anomalous SharePoint, Teams, and Graph activity rather than malware signatures alone. Ontinue also recommended disabling Edge headless mode, monitoring unusual Python activity, resetting exposed credentials, and using phishing-resistant authentication.
The article originally appeared on CSO.
Vibe coding is a top security threat to enterprises and could leak data into the public sphere, analysts and executives are saying.
“The number one risk at the minute is hard-coded secrets being uploaded through vibe-coded applications to GitHub, and then providing a route in,” said Pete Shoard, chief of research for cybersecurity at Gartner.
The term “vibe coding” was coined by Andrej Karpathy as a way to describe how developers can now create applications by chatting with generative AI (genAI) tools and services. AI can quickly generate code to create a program, a dramatic change from the typical manual development process.
Not surprisingly, vibe coding became the latest rage in the developer community almost immediately.
Enterprises have been rushing to upskill employees to take advantage of the technology by encouraging non-tech employees to vibe-code applications. Companies have seen the benefits, including faster application development and quick creation of prototypes or mockups of final products.
“Vibe coding makes writing apps more accessible to teams that don’t have developer or security experience, which expands the enterprise attack surface,” said Erik Nost, senior security analyst at Forrester Research.
Software companies aren’t necessarily “vibe coding” software patches, but they are able to leverage AI tools to help accelerate writing them, Nost said.
“The most common motivation theme for vibe coding — 62% — is speed & efficiency, with vibe coders highlighting rapid development,” researchers from Massey University and the University of Auckland wrote in a research study published last month.
AI coding tools produce working software in hours instead of weeks. But the rapidly advancing coding processes often neglect code reviews or security checks, raising the risk of undetected vulnerabilities.
“Others emphasized that while the outputs might appear clean and functional, they could conceal subtle logic errors, performance bottlenecks, or serious security flaws that only become apparent later,” the researchers wrote.
AI tools can hallucinate with poor prompting, and the same can happen with vibe coding. That’s why significant audit tools are required to verify and validate the results, said academic researchers from the US and UK in a June 30 paper published by the Association for Computing Machinery.
Employees who turn to vibe coding can quickly spin up hundreds of applications, but those efforts can also create problems, according to Gartner’s Shoard. “Not all of them will be scanned,” he said. “There will be no commonality. It’s not a patch that everyone can install.”
The big danger is that sensitive information or intellectual property can leak, Shoard said.
For example, vibe-coding tools could in many cases sync data files with public repositories like GitHub, unintentionally uploading internal corporate files to the internet.
The current vibe-coding hype has “done AI a massive disservice,” said Frank Erickson of 28Stone, a consulting firm that develops software for the capital markets. “There’s a huge difference between vibe coding and enterprise software development, and some of the loudest, most aggressive proponents of AI are a bit too latched onto the concept,” he said.
AI might be changing the nature of a variety of jobs, especially for developers, but vibe coding can’t scale — and it can’t outright replace enterprise software development. “I get pretty perturbed when our people internally refer to AI tooling as vibe coding. If they think that’s what they’re doing, they’re misunderstood,” Erickson said.
Vibe coding, while potentially good for software prototyping, should be governed by guidelines and development principles, researchers said. That would include heavy auditing to address hallucinations and security risks, as well as skilled prompts to provide better context, the US and UK researchers wrote.
“AI functions primarily as an assistant…, providing localized code suggestions and learning support while leaving overall direction, integration, and validation to the human developer,” they said.
Beyond automated security auditing, governance should include “continuous technical debt monitoring,” Indonesian researchers said in a research paper published last month.
The researchers proposed a vibe-coding framework that includes inspecting, interpreting, and validating AI-generated code as part of the typical software development lifecycle. This foundation “provides for developing risk-based governance policies that can guide … in adopting AI-assisted programming responsibly,” the researchers wrote.
GitHub has restored services after a nearly eight-hour outage disrupted several of its core developer tools, including Actions, pull requests, APIs, Git operations, Webhooks, and Copilot, impacting software development workflows across its platform.
“This incident has been resolved. Thank you for your patience and understanding as we addressed this issue,” the company wrote on its status page.
The disruption was first reported at 1:40 PM UTC on August 17, with GitHub initially flagging degraded performance across parts of its platform. Within minutes, the disruption had spread to API Requests, Actions, Webhooks, Issues, and pull requests (PRs).
At the height of the incident, GitHub reported an error rate of about 20% across its web experience and API traffic. Archive downloads and raw repository content downloads were seeing an error rate of approximately 50%, while SAML and OIDC authentication, SCIM, and Team Sync were also affected.
GitHub’s AI coding assistant, Copilot, also experienced degraded availability beginning at 2:31 PM UTC. The company later said that some Copilot authentication problems persisted even after other parts of the platform had recovered.
Finally, at 4:36 PM UTC, the company said that it had identified the problematic component and had taken corrective actions.
However, the recovery of services was not linear.
Git Operations experienced another period of degraded performance, while API Requests briefly returned to a degraded state. GitHub subsequently said it had mitigated the Git Operations issue and restored normal API operation by 7:01 PM UTC.
Still, other services remained affected with problems centered largely on authentication. GitHub said it had partially disabled authentication-token retries after observing sporadic authentication failures and later reported that Copilot authentication issues were still affecting some applications.
“We are continuing to investigate sporadic authentication failures. We have partially disabled authentication token retries and have seen improvement, and we are monitoring impact before fully applying this mitigation,” the company wrote.
It finally fixed these issues at 8:45 PM UTC and marked the incident resolved at 9:15 PM UTC, nearly 8 hours after it was first reported.
While the incident didn’t amount to a complete shutdown of GitHub, the number and nature of services impacted are significant for enterprise development teams as the company increasingly serves as more than a repository for source code.
Development teams use its APIs, Actions workflows, PRs, and integrations as connected parts of their software delivery processes, and a disruption to several of those components simultaneously can therefore affect workflows even when basic repository access remains available.
GitHub has yet to identify the “problematic component” that caused the failure or why its failure took out so many services together.
Until the company’s post-incident analysis is available, it is unclear whether the outage was caused by an infrastructure failure, a software change, an authentication problem, or another issue like an attack.
For now, GitHub’s status page says that a “detailed root cause analysis will be shared as soon as it is available.”
The article originally appeared on InfoWorld.
The good news is that large language model (LLM) token costs are coming down. The conundrum: The overall cost of AI workloads is going up.
Gartner research predicts that, while token costs will fall by 95% by 2030, inference costs for agentic workflows will increase more than fivefold over the next two years. This is because AI app builders are using more, and often more expensive, tokens as LLMs get ever more complex. It is what Gartner calls the “inference paradox.”
In other words, “the rate of innovation is outpacing the cost curve,” Gartner analysts Will Sommer and Sabine Zimmerhansl noted in their report. “The market is captured by a token-deflation illusion.” Buyers dangerously assume that as AI providers improve token economics, these savings will be reflected in their roadmaps. But, simply put, “they will not.”
There is no doubt that AI delivers massive value, and is often better, and faster, than people at many routine tasks, the analysts pointed out. Agents can also more quickly identify patterns across siloed systems. For instance, Gartner has seen customer success agents reduce response times by 99%.
But as AI evolves, token usage increases, and token value is variable, Sommer and Zimmerhansl noted. Advanced AI agents that can reason already cost up to 150x more on a single task than basic AI chatbots.
A simple chatbot must read and interpret a request and quickly deliver a “probabilistically reasonable” answer, but agents, as they become more sophisticated, must think, question, and adapt when something goes wrong, and they increasingly run continuously, and often invisibly, in the background.
“They need to be able to validate their results for accuracy without necessarily having a human in the loop,” the analysts wrote. “They need to talk to other agents.”
All of this demands more resources, and token consumption increases exponentially as “swarms” of increasingly autonomous agents trigger and call each other. This incurs a “massive inference tax” before a user even gets their result, they noted.
The hardware costs to train medium-sized agentic models with advanced reasoning capabilities is 2.5x greater than training simple, similarly-sized chatbots, they reported. Further, agent inference costs are 5x greater, and agents require 5x to 30x more tokens than a chatbot to handle equivalent tasks.
“Now consider how costs will balloon when running hundreds of agents that can perform dozens or hundreds of tasks each hour,” the analysts said. Costs continue to skyrocket as agents break many problems into several small tasks, call higher-order models, and require multimodal data.
“The volume of compute required for these capabilities is mind-bending,” the analysts noted.
To analyze the impacts of agentic systems, Gartner built a Tokenomics Model based on various scenarios of training and inference. These included various designs (number of layers, LLM-as-a-judge or as mixture-of-experts), technology improvements, hardware specifications, and various other cost considerations (data, infrastructure, energy, labor).
The firm ran 12 types of AI model with various capabilities, and found that basic workflows cost around $0.05 per inference token; summarization and knowledge retrieval cost roughly $0.10; more complex workflows cost around $0.30; and planning and learning cost roughly $0.40 per token. This means provider cost per token for planning and learning tasks is 8x to 10x that of basic workflows.
“Costs will inevitably escalate, and as they do, there is no guarantee that value will grow commensurately,” Sommer and Zimmerhansl contended. “ROI from each new generation of technology will be hard-earned.”
Enterprises can be diligent and keep token costs in check by developing and maintaining complex multimodal systems, Gartner said. They will also need ways to measure ROI and improvement across completed workflows.
Orchestration will be the differentiator, and “inference tiering” will improve cost and performance, so enterprises should develop systems that route queries to the most cost‐efficient model and block agents from invoking frontier models by default for simpler tasks, Gartner advised. Adopting usage-based pricing is another important step; move from flat compute fees to tiered plans that scale based on need.
Enterprises can consider mandating continuous refresh cycles, Sommer and Zimmerhansl added. “Treat each model release like a ‘new car’ losing value on day one,” they wrote, and build in data fine-tuning and self-learning feedback loops.
Builders should also set minimum standards for AI execution: Define success thresholds and risk mitigation and compliance overhead up front. “Refuse to greenlight deployments until scenarios are stress-tested against token-price swings and compliance expenses,” the analysts emphasized.
Further, Gartner also advises embedding value-per-outcome into product planning. This could mean requiring every AI feature to forecast and track its spend against a “clear outcome metric,” such as tasks automated or cases successfully closed. This can help identify the low-performing workflows that require improvement or deprecation.
Still, ROI is “eminently possible,” but it requires significant effort across complex workflows, the analysts noted; enterprises can’t simply rely on traditional systems and workflows. “Defaulting to generic autonomous intelligence will result in unbounded costs orders of magnitude higher than those of optimized product ecosystems,” they pointed out.
OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks.
Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant flaws, and defenders need to find and fix them before attackers do.”
He added: “The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models.”
The details he shared about OpenAI’s current defensive efforts, however, were mostly routine best practices familiar to enterprises.
“We continue to invest in secure architecture and controls, embrace strategies like defense in depth and least privilege, and are designing systems that require multiple independent controls to fail simultaneously for something catastrophic to occur,” Brockman said. “Classic security controls like network isolation, workload hardening, monitoring, and safe patching and deployment will be more important than ever in the AI future.”
To combat emerging threats, Brockman also advised enterprise CISOs to increase their use of agentic systems, not surprisingly recommending those from OpenAI.
“Give your security team an agent,” he wrote. “Start using Codex, the Codex Security plugin, or another capable agentic coding and security tool. Give it approved access to the codebases, infrastructure configurations, and technical documentation your security team needs to assess. Do not wait for a company-wide rollout to start with your highest-priority systems.”
Then, he said, “Equip that agent with security expertise. Start from community-supported skills, which include workflows for static analysis, security-focused code review, vulnerability variant analysis, software supply-chain risk, and other security workflows. Then build your own skills around your organization’s architecture, security standards, threat models, and playbooks.”
Analysts and consultants said that Brockman’s advice was accurate, but that it was also obvious and somewhat self-serving.
Gartner VP analyst Nader Henein put it bluntly: “As a rule, I tend to recommend against taking advice from a party actively selling the solution to a problem they had a role in creating. Curiously, at no point in the blog post is the subject of liability discussed.”
Pieter Arntz, malware intelligence researcher at Malwarebytes, added “the thing that really stands out to me is that the OpenAI sales pitch is unusually explicit.”
“‘Give your security team an agent’ and provide it access to code, infrastructure configurations, and technical documentation, and begin with high-priority systems rather than waiting for a company-wide rollout,” Arntz said, paraphrasing Brockman’s post. “The recommended trajectory from read-only scans to alert triage to automatic closure of narrowly defined false positives is sensible in outline, but OpenAI is clearly trying to normalize agent access for enterprise environments.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, was also skeptical.
“Although I agree in general with Mr. Brockman’s recommendations, this is a problem that OpenAI helped create in the first place. And the recommendation seems to be for users to now pay more to OpenAI as they use AI to defend themselves,” he said. “I’m fully aware that the cat is now out of the bag and cannot be put back, but I believe that OpenAI should take a responsible approach and help address the problem with higher safety standards, and even fund initiatives that increase software security in general. Perhaps help fund key open source projects that are currently severely overtaxed with the increased volumes of AI-generated findings and fixes.“
“Accountability should always start at home,” he added, “and I don’t see this reflected in that blog post.”
Mike Wilkes, enterprise CISO at Aikido Security, noted what is more important are the many things that Brockman did not say, such as suggesting ways to limit the damage when agents go rogue.
“Every consequential agent action needs blast-radius limits, an audit trail and a tested, near-immediate rollback path, not simply confidence in the model’s security judgment,” Wilkes said. “Brockman’s own recommendation to expand autonomy only incrementally is consistent with that, but I would make reversibility an explicit design requirement.”
He added, “Brockman appropriately talks about ‘bounded automated responses’ and keeping humans responsible for the highest-impact decisions, but enterprises deploying defensive agents also need extremely fast and highly reliable ‘undo buttons’ for whatever those agents change.”
Incident response always operates with incomplete knowledge, he pointed out, and early indicators are often wrong, leading teams to pursue the wrong thing until new evidence modifies their hypothesis about who is attacking, what has been breached and where they are going next.
Analysts and consultants agreed that these problems are industry-wide, and that many AI vendors have been focusing on what makes the most money and positions them to control the greatest market share, instead of ways to make systems truly safer.
“Brockman’s blog post is a good summary, but there’s nothing really new or noteworthy in it. All of the major AI labs are backing off the safety and ethics guardrails that were put in place in the early days,” said Mark Tauschek, a distinguished analyst at Info-Tech Research Group. “Their focus is going to be on cybersecurity capabilities because that’s where the attention and money are. The appetite to spend money and slow development in order to ensure new models are acting ethically and safely for average users has waned.”
Noah Kenney, principal consultant at Digital 520, agreed, and added that there are reasons for OpenAI to do this, given that they are preparing for an IPO.
“To me, this is an IPO story more than anything else. Defensive security reads well in an S-1 because it protects revenue, signals operational maturity, and reassures investors,” Kenney said. “A catastrophic risk team is the opposite kind of line item, because its entire purpose is to walk into a launch meeting and say this model may be too dangerous to release. That results in delays and legal exposure right when a company is trying to go public, and it brings in no revenue.”
Katie Norton, research director of cloud security at IDC, said the key point that struck her about the post was the immediacy of the suggested actions.
“What stands out is the urgency of Brockman’s message and OpenAI’s admission that it underestimated the real-world cyber capabilities of its models following the OpenAI-Hugging Face incident,” Norton said. “He is essentially saying organizations have months, rather than years, to adapt.”
US Commerce Secretary Howard Lutnick is “not in favor” of Apple’s plan to alleviate the impact of rapid memory price inflation by purchasing RAM made in China for use in devices sold there.
Trade by US firms with the biggest Chinese memory manufacturers, CXMT and Yangtze Memory Technologies, is restricted. Apple must secure a license before it can share product information with either firm, though it can still purchase off-the-shelf components that do not require any product details to be shared.
That may be good for Apple, despite White House reticence. Apple has said there isn’t a lot of customization in how it uses memory on its systems, which means it might be able to purchase off-the-shelf RAM. Still, Lutnick seems ideologically against such a move, saying there must be “other solutions to the memory issue, but it’s not great American companies using Chinese memory.”
Apple isn’t alone. HP and Acer are both using memory from CXMT in devices sold outside the US, which suggests a US-native solution to the memory crisis doesn’t yet exist. Pending discovery of any magical fix to the real-world supply challenge, the big three US-approved memory vendors continue to raise DRAM prices as they focus manufacturing on data center clients. The vendors have promised to bring more capacity online, but this won’t get into production until 2029 at the earliest.
The US seems to be rushing to make this more difficult; there’s a bipartisan Senate push to force Apple to avoid doing business with the firms, alongside calls to place even heavier restrictions on trade with CXMT. That would prevent Apple from purchasing even commodity memory from the companies.
The lack of memory supply is raising prices across the consumer and enterprise electronics industries worldwide, putting smaller companies out of business and making tech far less affordable for US and international consumers. It is also affecting product inventories; Apple has had to delay delivery dates for newly purchased devices and was forced to temporarily stop sales of some high memory configurations.
Analyst Ming-Chi Kuo even warned Apple has scaled back its hardware shipment plans for 2026 in response to the crisis. (There are even reports that the supply of Apple silicon processors has been hit by the shortage of good memory.)
The only positive way to escape this inflationary loop is to source, manufacture, or otherwise secure more supply — as Apple is attempting to do with CXMT. Alternatively, the government might need to force existing vendors to divert additional capacity to DRAM, which the Trump Administration hasn’t done and has flagged no intention to do.
US consumers and US businesses continue to pay the price for that indifference. Apple has been forced to raise some product prices up to 25% and might yet have to implement another wave of price increases.
The rapid increase in prices is being reflected by consumer purchasing behavior. The biggest signal so far on how this will play out comes from Japan, where refurbished iPhone sales more than doubled after Appe’s July price hikes. That trend was confirmed by a second report in Japan Times, which reports a huge spike in iPhone sales via the Nicosuma online marketplace.
As that trend asserts itself globally, it will affect new device sales, hurting both down- and upstream manufacturers in the consumer electronic supply chain, creating another vortex of inflationary pressure. Consumers will also wind up using their devices longer and turn to lease and hire schemes in preference to cash or credit to settle high purchase costs.
This change in behaviour can only go on for so long while new device sales shrink. At some point, it will become apparent that not enough new devices are entering the second user value chain to satisfy demand in that side of the market. The result: an additional inflationary wave, prompting second-user devices to become even more costly as lowering sales of new devices put smaller manufacturers out of business entirely, further reducing competition, denting corporate profits and, conceivably, undercutting tax receipts.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.Apple’s Chinese memory puzzle
Moburst has launched Answerburst, a dedicated practice within the agency focused specifically on Answer Engine Optimization, built out of what the team describes as an internal need that showed up before there was a market name for it.
The practice did not start as a planned product launch. According to the team, it began with client questions that traditional App Store Optimization and SEO reporting could not fully answer, specifically, why install and traffic patterns were shifting in ways that did not map to any tracked channel. Investigating those anomalies led the team to AI-mediated referrals long before AEO had settled into an industry term.
“We were debugging a mystery, not building a product,” a member of the founding team said. “The naming and the packaging came after we had already been doing the work for a while.”
Formalizing the practice required building measurement infrastructure that did not exist off the shelf: tracking citation frequency across multiple AI assistants, distinguishing that signal from ordinary seasonal noise, and connecting it back to the channel-specific discovery features that a purely web-focused approach would have missed.
The team also says internal expectations shifted over the course of building the practice. What started as a narrow reporting fix became a recognition that AEO measurement needed its own standing discipline, connected to the agency’s existing organic and paid acquisition work but scoped separately.
Part of what slowed the initial investigation, the team says, was that no existing tool answered the specific question they had. Not how a site ranks, but whether an AI system mentions the brand when asked, and why. Building that answer meant querying multiple assistants directly and manually, on a repeated schedule, before anything resembling automated tracking existed. Some of that manual process still underpins the methodology today, even as parts of it have been automated. The team says the manual groundwork, tedious as it was, gave them an unusually granular early view of how citation behavior varied across assistants, one that off-the-shelf tools built later did not initially replicate.
The clearest lesson the team points to is that consistency across independent sources matters more than any single piece of optimized content. An AI system deciding whether to cite a brand confidently seems to weigh agreement across many sources more heavily than the polish of any one source, which reframed a lot of the team’s early assumptions about where to focus effort.
The second lesson was measurement humility. Early internal reporting overstated AEO’s contribution before the team built a reliable way to separate it from seasonal and platform-driven noise. The current methodology takes a deliberately more conservative approach to attributing any outcome to AEO work.
A third, less expected lesson involved internal alignment. Getting the agency’s existing organic, app store, and paid acquisition teams to treat AEO as a connected discipline instead of a competing budget line took longer than building the measurement tooling, according to the team, since it meant changing how account teams were used to scoping and pricing engagements.
Moburst says Answerburst will continue operating as a distinct practice inside the agency, serving both new AEO-specific engagements and existing clients looking to extend into AI search visibility. The team frames the launch as formalizing work it was already doing before the category had a name.
The near-term priority is publishing more of its internal measurement methodology externally, both to build credibility in a crowded field and to give the industry a clearer shared standard for what a defensible AEO results claim should include.
The team is also candid that the name itself is still being tested internally before any wider rollout. Whether Answerburst becomes a permanent externally facing sub-brand or an internal practice name attached to Moburst’s broader AEO work is, by the team’s own account, an open question, one they say they would rather answer correctly than quickly. For now, the name is a working label.
About Moburst
Moburst is a full-service, mobile-first digital marketing agency founded in 2013 by CEO Gilad Bechar and COO Lior Eldan. Headquartered in New York with global offices (including Israel), it helps startups and Fortune 500 brands scale using AI-powered marketing. Major clients include Google, Uber, Samsung, and Reddit.