ChatGPT Business and Enterprise users cannot export workspace chats through OpenAI's standard data export option, but a new free tool offers an unofficial way to retrieve their accessible chat records. Scrapemychats, from freelance journalist Conrad Quilty-Harper, makes it possible for those ChatGPT subscribers to retain a copy of their chat sessions before leaving for other AI pastures. Quilty-Harper just published it this week on GitHub. “I made the stupid decision to upgrade from a personal account to a Business one a while back as they prompted, and for some reason OpenAI doesn't let you export the data easily,” Quilty-Harper explained to The Register in an email. OpenAI says right on its help page about chat exports that Free, Plus, Pro, and some Edu customers can export their chats, but Business and Enterprise workspaces don't have access to that export option. No justification is given (we asked and didn’t hear back), though keeping top-tier subscribers locked in is a distinct possibility. OpenAI does offer Enterprise admins access to workspace conversation logs through its complex Compliance Platform, but the platform retains those logs for only 30 days unless customers archive them elsewhere. ChatGPT Business users, however, have no simple way to create a local archive of their workspace chats without a tool like scrapemychats. Never fear, however, as scrapemychats will be able to liberate those messages - at least until OpenAI closes the loophole it exploits. “I expect OpenAI will stop this from working shortly after you write about it,” Quilty-Harper predicted in our exchange. “It's probably a breach of their terms of service. But hey, their entire business model is based around scraping copyrighted material. This just allows you to get the content you wrote or pasted or created (and generated) back.” Until that happens, scrapemychats is available on GitHub for you to snag a copy of those chats before you close up shop at the House of Altman. The app works through a logged-in browser session and, as explained in the GitHub README, stores accessible ChatGPT conversations - including available file attachments - in a local archive with an email-like HTML interface that can be opened offline in a browser. The data is stored separately from the interface, too, and Quilty-Harper tells us the stored chats can be used however one likes. It's not a headless tool, mind you: ChatGPT's bot protection prevents it from running in one. What that means in practice is that scrapemychats navigates through your ChatGPT account, opens your conversations, and stores the conversation data and attachments loaded through the browser. That also means it moves slowly, as OpenAI tends to throttle anything that makes too many requests too quickly. Downloading a 600-chat archive will take “a few hours,” the README states. It can be resumed if you need to pause it, though. Installation can be done via the command line, and all the necessary steps to get it running are included in the GitHub writeup. “I would quite like to know the reason why ChatGPT doesn't make it easy for paying customers to get access to their data,” Quilty-Harper told us. “I have my suspicions, and as a freelance reporter I'd love it if someone who works there could tell me if they know about this friction.” ®
You can take your vibe-coded project elsewhere. Codeberg, a volunteer-run code hosting community, has decided that AI-authored software is no longer welcome. On Thursday, Codeberg announced that the members of Codeberg e.V., the Berlin-based non-profit overseeing the code hosting service, had voted to ban "vibe-coded projects" and declared that Codeberg would not use users’ code or data for AI training due to its impact on Free, Libre and Open Source Software (FLOSS). The vote follows ongoing efforts by Codeberg to prevent automated software (bots) from taxing its infrastructure with excessive network requests. Authors Bastian Greshake Tzovaras, Otto Richter, and William Zijl argue that AI companies are shifting costs to others and damaging online communities in the process. "LLMs are so costly that companies externalize the costs on a massive scale – on those who don't use them and society at large," they wrote in a blog post. "Increased hardware prices, energy use and environmental damage – we all pay for it!" They point to the cost of Codeberg's SSD and memory hardware as an example, noting that a drive that only a few years ago cost €700 (~$800) now costs €3,700 (~$4,200) – if it's even in stock. The result is that Codeberg has been forced to raise prices. The authors also call out the proliferation of projects that often involve a solo developer "working with a statistical machine that turns energy into code." They fault these folks for not having any community and argue it's unreasonable for Codeberg to spend its limited CI/CD and storage resources on ghost projects. But the vote isn't simply about unfair resource consumption. It reflects broader unease among Codeberg members about the damage AI coding models are doing to the FLOSS community. AI-driven price hikes, they contend, are broadening the digital divide by making personal computers less affordable, forcing more people toward corporate-owned cloud services. And beyond the environmental harm of increased water and energy use, the Codeberg authors argue that LLM use is undermining the foundation of trust and community that makes FLOSS work. "The widespread use of LLMs in FLOSS is instead becoming a multidimensional attack on the trust between contributors and the very idea of convivial collaboration itself," they state. LLMs magnify maintainers' workloads, create confusion around whether projects will be maintained, and "lead to 'license laundering', where copyleft code is stripped of its reciprocity requirements by 'generating' it out of the training data." "As we want to center on human collaboration, we will not actively support or engage in the creation of LLMs and will not put our limited resources to use for storing single-use software that would pollute our FLOSS commons," the authors conclude. As a consequence of the community vote, projects developed and maintained mostly by an AI agent are no longer welcome at Codeberg and are urged to move to other hosting options. This is reflected in amended Terms of Use language: "You must not share projects that mostly consist of code written by 'generative AI'-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status … and furthermore have little safeguards to ensure that they do not include harmful code." Enforcement of the ban seems unlikely, however, unless a project draws attention to itself, given Codeberg's statements about limited resources and its overburdened workforce. Support for the vibe-coding ban was substantial but not overwhelming, with some celebrating the decision and others condemning it. Among Codeberg members, 358 voted in favor, 144 voted against, and 14 abstained. About half the active members voted. "I think this is a very bad move, and the people behind Codeberg should re-consider their stance," said Armin Ronacher, creator of Flask and one of the co-founders of AI agent biz Earendil. On its way toward Free, Libre, and Open Source Software equilibrium, Codeberg also decided to ban cryptocurrency projects, citing a similar move by SourceHut in 2023. A proposed amendment to make it Codeberg's stated purpose "to oppose discrimination and promote a diverse FOSS community" passed with a two-thirds vote but is not yet merged. The protection extended to philosophical outlook does not cover belief in AI. ®
Amazon may be spending billions on AI, but that hasn't stopped it from cutting jobs inside the very organization building it. The megacorp confirmed to The Register on Thursday that it has eliminated an undisclosed number of roles across parts of its Artificial General Intelligence (AGI) biz, even as it insists AI remains a key priority. The cuts are the latest in a restructuring that has seen Amazon shed more than 30,000 employees since October – including 16,000 announced in January – while pouring cash into AI infrastructure, custom silicon, and foundation models, with $200 billion in capex projected for 2026. "We've been building large AI models for several years, and it remains one of the most important things we're working on," an Amazon spokesperson told The Register. "This is a fast-moving space, and we're sharpening our focus on the initiatives that matter most for customers, so we can move faster on what counts. "That focus means some difficult decisions, including eliminating some roles within parts of our AGI organization, even as we continue to invest in the areas most important to our customers' future. We're committed to supporting impacted employees through their transition and we're grateful for their contributions," the spokesperson added. Amazon hasn't said how many people were affected or exactly which teams were hit. Employees posting publicly said the layoffs reached groups working on model customization and post-training, with some reporting cuts of around 10 percent. Reuters separately reported that the layoffs also affected teams led by AGI Data Services vice president Adeeb Shanaa and AGI Information vice president Vishal Sharma. The move lands less than a year after Amazon overhauled its AI leadership, with longtime executive Peter DeSantis taking charge of the AGI organization as the company moved to accelerate development of its Nova family of foundation models and broader generative AI strategy. If there's a contradiction in laying off AI workers while telling investors AI is the company's future, Amazon doesn't see one. Building the future, it seems, doesn't guarantee you'll be around to see it. ®
Donald Trump’s Assistant for Science and Technology, Michael Kratsios, has accused China’s Moonshot AI of creating its head-turning Kimi K3 model distilling Anthropic’s Fable. Kimi K3 is 2.8-trillion-parameter open-weights model of such impressive quality that its mere existence suggests Chinese AI researchers aren’t far behind their US rivals. Moonshot AI released it on July 16, and not long afterwards the value of US AI stocks sank as investors worried the model could damage their businesses. Kratsios used a Xeet to allege that Kimi K3 is the result of distillation – a technique that involves bulk queries of one model to train another – rather than innovation. “We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model,” he wrote, adding the assertion that the Chinese company “developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” Kratsios also accused the company of gaining access to servers packing Nvidia’s GB300 accelerator – a model the US does not allow to be sold in China – and of accessing GB300s running in Thailand. Kratsios added his view that the USA “strongly supports the free and fair development of AI, including a thriving competitive ecosystem that spans frontier models, specialized systems, open-source frameworks, and open-weight models.” He also noted that AI distillation can be a legitimate technique when “used to create smaller, more efficient models.” “However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.” US Treasury Secretary Scott Bessent weighed in to the matter with a Xeet of his own that opens “We support open-source AI and the innovation it unlocks.” If you feel like there’s a “but…” coming, you’re right. “But open source is not open season on American IP,” Bessent wrote. “When [People’s Republic of China] PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.” The US has already sanctioned just about every major player in China’s tech ecosystem, but that hasn’t prevented the nation from growing enormous and sophisticated tech companies. Nor have those sanctions stopped Chinese firms from creating “evasion routes” to secure access to banned tech through illicit means, or by using the grey market. One evasion route is renting GPU farms outside China to run AI workloads, to access hardware that’s not available in the Middle Kingdom. Anthropic accused Moonshot AI of distillation in February 2026 and said its Chinese peers DeepSeek and MiniMax also used the technique. The US and other nations have often accused China of industrial espionage. Beijing always denies such allegations. Whatever means China uses to develop technology, think tank the 2025 Australian Strategic Policy Institute’s Critical Technology Tracker rates the Middle Kingdom as the leader in 66 of the 74 technologies it rates. ®
Google’s parent company Alphabet is managing its fleet of AI accelerators to prioritize research on artificial general intelligence, rather than renting them all to customers. CEO Sundar Pichai revealed the company’s priorities during its second quarter earnings call, during which the company confirmed it has delivered on its plan to sell its tensor processing units (TPUs) to some customers. In response to news of those sales, Goldman Sachs analyst Eric Sheridan asked how Alphabet balances demand from customers who want to buy its TPUs and the web giant’s own need for processing power. “In terms of allocating our TPUs … our first priority is making sure we are allocating what we need to compete at the frontier in terms of AGI development,” Pichai replied, referring to Artificial General Intelligence –AIs that possesses human-like intelligence. “That is the foundation for everything we do,” Pichai added. Another analyst, Mark Shmulik of Bernstein, revisited the matter by asking how Google allocates processing capacity among its search business, cloud operation, and model training efforts. “On allocation, I think the baseline with which we start is what it takes to continue AGI development at the frontier,” Pichai responded. The CEO said Alphabet is also “prioritizing our core product areas like Search, YouTube, et cetera, as well as Cloud.” And in the G-Cloud, Google is “prioritizing the compute to make sure we can serve our models in the context of Vertex and Gemini Enterprise, and our core solutions, be it data analytics and cybersecurity.” “Our core services for our core products across consumers and enterprises is where the compute is primarily going, and that’s how we think about it,” the CEO added. Google’s core services are going gangbusters. Google Cloud revenue leapt 82 percent year over year, to $24.75 billion for the quarter, and delivered an $8.8 billion profit which represented 214 percent growth. The Big G said that growth came from “strong demand for AI infrastructure and AI solutions.” There’s probably more to come as the G-Cloud now has $514 billion of cloudy backlog on the books, meaning customers have signed up for services they’re yet to consume. Search revenue grew 17 percent and YouTube ads grew 13 percent. When generative AI came along some pundits suggested it could threaten Google’s search ads biz. That was not a good take because Pichai said the company’s AI Mode for search is “driving an incremental increase in Search queries overall.” AI search needs specialist hardware that is expensive to buy and run. Pichai said Google is on top of that. “Thanks to our engineering and hardware optimizations, this quarter we reduced the cost of AI Mode responses to its lowest level since launch, even as we’ve brought more advanced AI capabilities.” Google continues to spend megabucks on AI infrastructure – CFO Anat Ashkenazi said the company now plans to spend between $195 billion and $205 billion this financial year, up from a previous estimate of $180 billion to 190 billion. Ashkenazi said Google can’t get all the kit it needs due to what she described as “the supply-constrained environment.” Google therefore plans to “expand the use of third-party capacity in Q3 as a bridging strategy while we build out more internal capacity.” Pichai said buying bridging capacity will help Google to land monster cloud clients. “There are very, very large customers of ours on Cloud who we are trying to support them through this extraordinary moment,” the CEO said. “The incremental opportunities they are bringing to us, while a short-term cost over a few months may be very high, in the lifetime of the deal, as we bring more capacity on, is highly ROI positive.” “Those are factors we are taking into account. Are you willing to take upfront six-month deal to be able to serve that customer in what is a multi-year opportunity, where the margins and the returns are very, very attractive over that multi-year horizon?” Alphabet’s quarterly revenue landed at $119.8 billion, up 24 percent year over year. Operating income hit $40.8 billion, up 34 percent. Yet even those torrents of money couldn’t stop Google’s free cash flow landing at -$5.9 billion – the first time the company hasn’t had spare cash to splash since 2004. Investors seem not to like that and sent the price of the company’s shares down by four percent in after hours trading. ®
OPINION OpenAI has acknowledged its models powered the autonomous agents that compromised HuggingFace infrastructure. It might be taken as a convoluted marketing stunt, were it not the perfect advertisement for China-based competition. The company's AI-culpa fits the narrative spun by US rival Anthropic about its Mythos models, which it deemed too dangerous to release except to totally trustworthy corporations and governments. OpenAI says: "The incident makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access. It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools." Are we surprised? It's been clear that AI models have the potential to go rogue and damage computers for several years. Academics have repeatedly warned about this possibility - even those affiliated with OpenAI and Anthropic. And anyone who has used AI models for software development has probably seen them code unexpected and perhaps unwanted workarounds to fulfill some directive. On Tuesday, the UK's AI Security Institute published findings about how frontier models all cheat. OpenAI's admission that its models devised a sandbox escape to obtain internet access and found a zero-day flaw to exploit, all to solve a benchmark evaluation problem, may be unprecedented in terms of the scale and prominence of the systems affected. But it's a reenactment of every Claude or Codex prompt in which the model responds to a disallowed command by trying an alternative. We were warned. The compromise of HuggingFace's systems is no more surprising than locking a bear in a supermarket and finding a mess the following day. AI models are billed as artificial intelligence, but when they power agents handling tools in a loop to achieve some objective, it's the equivalent of a brute force attack – the agent will keep trying things until something works or breaks. The surprising part came when HuggingFace sought to employ US frontier models to defend itself. It failed. That should raise eyebrows. "When we started the log analysis, we first used frontier models behind commercial APIs," the AI model-mart said in its blog post last week. "This did not work: the analysis required submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker." Stymied by model refusals – which developers have been complaining about for months – HuggingFace had to rely on GLM 5.2, an open-weight AI model made by China-based Z.ai, to conduct its forensic analysis. And it did so on its own infrastructure, so nothing sensitive got sent to a cloud-based model provider. Coincidentally, the leaders of OpenAI and Anthropic have reportedly been warning the US government about the threat posed by increasingly capable Chinese models like Kimi K3 and GLM 5.2. And the US government is said to be mulling possible responses to limit competition from China. That won't work. It's just naïve to think that the US government and a handful of worthy organizations – however that is defined – will be able to enforce a global monopoly on highly capable AI. The infrastructure required to run open weight models that more or less rival the current state of the art is available for a price. And potential consumers of those services are not going to be satisfied with model refusals when there are other options, particularly if they're more cooperative and more affordable. The best course for governments, industry, and the public is to push for AI services that are open and available to all. For that to work, lawmakers around the world need to act fast to set some common ground rules that grapple with AI's impact on jobs, and find a way to compensate those whose work fuels machine learning. Some industry leaders appear to realize that. David Sacks, an external White House adviser and tech investor, recently urged Silicon Valley to rally around openness. "The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open source competition," he wrote in a social media post. "They have laid their cards on the table. It is time for the rest of Silicon Valley — the vast majority that still values open competition — to do the same." The fact is that US AI companies have sandboxed themselves into a corner: They've created demand for a product that they can't be relied upon to provide. And when they do make their most capable AI models available, they hobble them and demand terms tailored to serve their vast debt rather than their customers. OpenAI said that it has invited HuggingFace into its trusted access program so the company can use its most capable models. Chinese AI companies, meanwhile, have invited the world. ®
OPINION Cory Doctorow, tech gadfly and coiner of the eminently relevant term "enshittification," posted a useful argument on Wednesday related to Trump's dismantling of the US-led world order and the need or lack thereof for other countries to control their own AI destinies. Doctorow has positioned himself as an AI skeptic in his writings, including his recent book, The Reverse Centaur's Guide to Life After AI – the name comes from the visualization of a human body (you and me, humble users) being led by a mindless horse's head (AI) – and this latest post fits into that vein well, calling the need for a sovereign AI "nonsense." The conversation began with a post from Australian writer John Quiggin, who explained how the US president is systematically dismantling all of the sources of the United States' strength over the last century – diplomatic, military, financial, and, most relevant to Reg readers, technological. Quiggin posited that the current American dominance of AI poses a particular risk to the rest of the world, which understandably doesn't want to rely on a chaotic and unpredictable American state, although even he was skeptical that the frontier labs' Vegas binge-spending approach would necessarily pay off: "My optimistic view is that this is a race that will be won by low-energy tortoises rather than hyper-active hares. Second movers like Deepseek and, more recently the French Mistral, running maybe a year behind the US leaders, can replicate their capabilities at a fraction of the cost, and without reliance on massive data centres." Not wrong, in our view, as our systems editor Tobias Mann recently opined. But as Doctorow points out, that is only relevant if you believe AI is relevant. And Doctorow clearly does not. He notes that if Trump were to suddenly turn off all the AI chatbots being used by other nations, it probably wouldn't damage their businesses in any significant way. But if he were to order Microsoft to disable Office 365 or John Deere to brick its tractors, that would have an immediate, measurable economic impact. As he put it: "In the face of these real, non-speculative, immediate, grave threats, focusing on AI – the money-losingest technology in human history, which has consistently underperformed relative to its boosters' promises – is just misguided … The real digital challenge is building apps and data centres to run everyday administrative, telecoms and e-commerce software on, and then moving your country's, ministries', companies' and households' data over to the new platforms." Amen to that. AI may or may not be the future – it's certainly a lively topic of debate at Vulture HQ – but there's a clear and present danger, and American tech companies have made it abundantly clear that they will not speak or act out against the president or US government until and unless the shifting political tides dictate it's advantageous for them to do so. Same as it ever was. Europe would be wise to invest in alternatives wherever it can. ®
After cutting over 4,000 jobs due to AI, fintech biz Block is back with Buzz, a shared workspace where humans and bots can collaborate in ways that are more auditable, sovereign, and secure than what you can do in chat tools such as Slack. Block's human-bot co-op is built upon a turducken of tech jargon: The platform is free and open source. It's based on the decentralized Nostr protocol, so there's cryptographic identity. It's "sovereign," a naively optimistic term readers of Neal Stephenson's Snow Crash should recognize, which in this context means self-hostable. And it's intended as a replacement for Slack, GitHub, and various other communication and collaboration tools. If "Buzz" sounds familiar, that's because Google used that name in a social media faceplant more than 15 years ago. For those who missed the first go-around, Google Buzz, a failed social media service, gave rise to Google+, also a failed social media service. Block appears to believe that a decade and a half is sufficient for a brand cleanse. The project's GitHub repo offers a more apologetic assessment: "Yes, it's another AI-adjacent developer tool. We're sorry. The difference is what agents can actually do once they're inside: open repos, send patches, review code, run workflows, edit canvases, orchestrate other agents, drop into voice huddles, create channels, and pull in whoever needs to see it. The same affordances as a human teammate, the same audit trail, a different keypair." You can already sic software agents on collaborative workspaces. Block's main insight is that it would be useful to link AI agents with cryptographic identities. Others have already arrived at that conclusion. Hence OWASP's Agent Name Service, DNS for AI Discovery, Estonia's digital IDs for agents, and so on. But Buzz's badging of humans and bots with cryptographic key pairs is bound to tick governance boxes. "Every company is going to need a place where humans and agents work together," said Bradley Axen, head of AI capabilities at Block, in a statement. "The question is whether that place is proprietary or open. We built Buzz because we believe it should be open." Moat-seeking tech incumbents would probably disagree about the need for openness, even though they're fond of using the word without applying it. We note that OpenAI sells closed AI. And Anthropic's decision to disallow third-party tools from using Claude subscriptions highlights the seemingly inevitable path from openness to barriers when revenue is at stake. What's more, it's not obvious that every company will need people and bots in the same space. There's a strong case for keeping humans and agents apart because they work at different speeds. Git at least was built for handling many distributed code edits, pull requests, and merges. It's hard to see how people and bots can share a text-based communication space unless the bots are rate-limited or just talk among themselves. "The bet is that one community can do what teams currently fake with chat, forges, bots, CI dashboards, release tools, search indexes, and a pile of glue code," Block's Buzz developers state. "Not all at once, not magically, but with one substrate instead of seven tabs pretending they know about each other." If tools for these sorts of things didn't already exist, and no large tech companies had designs on this space, Buzz might face less daunting odds. But it's worth a shot. ®
You've got an idea for an Excel spreadsheet, but building it is another matter. Microsoft's Copilot can help, and now SpaceXAI is offering an alternative: the Grok add-in for Excel. Available on the Microsoft Marketplace, the add-in places a sidebar in Excel that can "search the web, update spreadsheets, or build powerful financial models," according to the product description It isn't without cost. The add-in is currently available for SuperGrok, Heavy, Business, and Enterprise plans, although, as xAI states, the Microsoft 365 add-in itself is free. xAI is parking its tanks on Microsoft's Copilot lawn with the add-in, although the level of integration is quite a bit lower. For example, in 2025, Microsoft announced a COPILOT function in Excel allowing users to invoke its assistant at the workbook cell level. At its most basic, Grok turns prompts into workbook actions. However, we'd strongly recommend that a human review the results, just in case the AI has spewed nonsense. Grok, the AI that spawned MechaHitler and non-consensual deepfake nudes, hit version 4.5 this month and xAI claimed it was "capable of building complex Excel models." Grok Build was then caught sending entire repositories to the cloud, before boss Elon Musk stated that Grok Build CLI would be open source. All of which should give users pause before installing the component. Microsoft warns: "When this app is used, it can read and make changes to your document, can send data over the internet." The add-in inserts a button on Excel's ribbon to show the Grok pane. Text can then be entered. We asked it to "create a chart showing SpaceX stock performance since IPO, with the y axis showing value and the x axis showing time." Grok said it had reached usage limits and suggested that we upgrade our plan. Thinking that might have been a bit complicated, we tried simpler requests, all of which failed, confirming that a subscription is indeed required. This puts Grok up against some tough competition. Copilot is deeply entrenched in Microsoft's Office applications, and Google is not shy about promoting Gemini in its productivity tools. Organizations that already have a Grok subscription might get some value from the add-in, but others are spoiled for choice when it comes to AI assistants in their productivity applications. An Excel esports championship for AI assistants, anyone? ®
Having popularized AI with the cheapskate masses, OpenAI has turned its attention to enterprise customers who might actually pay for its services. The debt-fueled maker of frontier models on Wednesday announced the debut of Presence, a web service designed to make it easier for enterprises to deploy AI agents for a handful of common business tasks. "Today, Presence supports real-time experiences across voice and chat, such as customer support, outbound sales, and high-risk internal workflows," the company said in a blog post provided to The Register. "A customer might use it to resolve a billing issue – from understanding the request and verifying the customer to looking up account information, applying company policy, and taking an approved action." Presence lets companies set policies and governance controls to determine how agents behave, so that orgs can have some degree of reassurance that AI banter will remain polite, professional, and pertinent to the task at hand. The control interface includes an agent editor, an agent playground, and a tool for simulating how an agent handles tasks like customer refunds, order status queries, account deletion, and other administrative interactions. Rather than releasing another self-service API, OpenAI is making Presence available through its consulting arm, the OpenAI Deployment Company and Forward Deployed Engineers, a tech installation workforce that debuted last year and was bolstered by the acquisition of consultancy Tomoro in May. "Deployments are led by OpenAI Forward Deployed Engineers and select global systems integrators," OpenAI said. "Presence is not yet available as a self-serve product." OpenAI insists it has been dogfooding Presence, which now runs its AI English phone support channel. "It can understand open-ended requests, verify a caller’s identity when needed, use relevant account context, and take approved actions – including resolving billing issues, making account changes, and processing eligible refunds," the company said. "When a request requires human support, it can bring in a person." That may occur more frequently than OpenAI would like. Tech consultancy Gartner last month predicted that by 2027, half of organizations that were planning to shift customer service to AI will abandon those plans. "While AI offers significant potential to transform customer service, it is not a panacea," said Kathy Ross, senior director analyst for the Gartner customer service and support practice, in a statement. "The human touch remains irreplaceable in many interactions, and organizations must balance technology with human empathy and understanding." Undeterred by Gartner's skepticism, SoftBank, which is so enthusiastic about OpenAI's prospects that it has committed $60 billion to the AI biz, appears to be enthusiastic about AI's appeal for customer service. "Through our collaboration with OpenAI, we are exploring how Presence can enable trusted customer agents that communicate naturally, connect to the processes needed to resolve requests, and represent SoftBank consistently across customer interactions," said Tadahisa Murakami, VP and head of SoftBank's data and digital transformation division, in remarks provided to The Register. "Our frontline teams have rated the agent’s Japanese-language conversations highly for their natural and accurate quality." One reason SoftBank might be optimistic about Presence is that it costs actual money, which is vital as OpenAI attempts to cover the costs of its massive datacenter buildout commitments and work towards eventual profitability. "During this limited GA phase, deployments are scoped individually based on each customer's use case and implementation needs," an OpenAI spokesperson said. "Broader pricing details to come as availability expands." Presence is available to eligible enterprise customers, but OpenAI insists it will continue to support existing voice customers who access its models via API. ®
OpenAI has admitted that it was the operator of the autonomous agents that attacked model-mart Hugging Face last week, and that they did so after a research project escaped a sandbox by finding and exploiting a zero-day flaw, then used another zero-day flaw to launch an attack. The attack saw agents achieve “unauthorized access to a limited set of internal datasets and to several credentials” used by Hugging Face, which said its infosec teams observed an autonomous agent framework “executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” “This matches the ‘agentic attacker’ scenario the industry has been forecasting.” On Tuesday, OpenAI admitted it was the attacker and that its models went rogue. “This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities,” the startup confessed. The models that conducted the attack included GPT‑5.6 Sol and what OpenAI described as “an even more capable pre-release model” that like the other involved used “reduced cyber refusals for evaluation purposes.” OpenAI thought its models were “hyperfocused on finding a solution for ExploitGym” – a benchmark that measures how effective AIs are at finding security exploits. OpenAI says it runs these tests “in a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.” The company’s models decided not to be bound by those constraints. “The models identified and exploited a zero-day vulnerability in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access,” OpenAI admitted. “After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation,” OpenAI explained. “In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.” Hugging Face’s assessment of the incident was that it represented the moment at which “Autonomous, AI-driven offensive tooling is no longer theoretical.” OpenAI reached a similar conclusion. “The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access. It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools,” the company wrote, without a trace or hint of contrition about the fact its own safeguards didn’t work. Which rather begs the question: If one of the prime movers of the AI boom can’t get this stuff right, what chance do the rest of us have? OpenAI has done the usual Big Tech thing of apologizing for the mess, and promising that its new guardrails and industry collaborations will hopefully prevent this sort of thing from happening again. History suggests those are very hollow sentiments. ®
OPINION Every six months or so a Chinese model sparks a panic, calling into question America’s AI dominance. Moonshot AI’s Kimi K3 is the latest example. Recall when DeepSeek R1 shook markets early last year? Following a similar pattern, Moonshot’s latest model isn’t all that interesting apart from its benchmark performance, and at nearly three trillion parameters it's beyond the reach of most enterprises. For the likes of OpenAI and Anthropic, the technology isn't as interesting as its national origin. A Chinese model can be dangled as a threat to national security — Anthropic’s fearmonger and chief Dario Amodei has said as much in the past. Last month the executive accused Alibaba, another prolific Chinese AI model dev, of using Claude to improve its Qwen family of models through a process called distillation. Those claims are rather rich coming from a man whose company just agreed to pay $1.5 billion to settle claims over vacuuming up millions of pirated books to train Claude. Pot, kettle black much? With that said, the anxiety caused by Moonshot’s Kimi K3 does feel different. The model's size is a factor. At 2.8 trillion parameters, Kimi K3 is the largest open weights model ever built. The model’s girth certainly reinforces the idea that K3 is a frontier model. There are interesting architectural changes to the model, but from what we can tell, they aren’t at all related to the anti-China-AI rhetoric making the rounds right now. But let's talk about the benchmarks! We’ve been down this road before with Z.AI’s GLM family, MiniMax M-Series, Qwen, and of course DeepSeek. A new model is released alongside benchmarks that show it trading blows with OpenAI, Anthropic, or Google’s best. Kimi K3 is following that well-trodden path. Last week, Moonshot published a lengthy blog post packed with benchmark charts and demos showing off its new model, and predictably, told the same story as always: Despite US trade restrictions on American-made accelerators, Chinese model houses aren’t as far behind as Altman and Amodei would like. What has changed is Uncle Sam’s attitude toward frontier models. GPT-5.6 was apparently concerning enough that the US government delayed its release, while Claude Fable 5 was pulled offline shortly after launch as officials investigated security concerns. As we later reported, the boogeyman hiding under Fable’s bed wasn’t some Lovecraftian horror. It didn’t even rise to the level of a Disney villain. According to one researcher, it was the sudden realization that generative AI models have achieved a level of competency that users can type “fix this code” and they'll do just that. Yet, the disruption, however brief, may as well have been free marketing for Anthropic, which has been peddling the idea that open models are inherently dangerous. In this respect, the drama around Fable 5 and GPT-5.6’s delay has become ammunition. If America's top models are enough to worry the US government, why shouldn’t Kimi K3? After all, OpenAI and Anthropic are American companies that can be bent to the Trump administration’s whim. But an open weights frontier model that originated in China? Not so much. The Trump administration has apparently taken notice. White House officials are reportedly hearing calls to restrict access to Chinese models, but haven't taken formal action yet. Regardless of what happens this time around, new reports suggest the US and China will meet later this year to discuss the growing threat of their respective nations' AI endeavors. In an AI arms race, an AI summit was inevitable. The US model houses would certainly benefit from restrictions on Chinese models. Under the guise of national security, the restrictions would cut off Chinese AI developers from offering the strongest competition to US labs. But less competition inevitably means enterprises and consumers get screwed. The US hasn’t pursued large open weights models on the same scale as Chinese devs. Thinking Machines Lab’s newly announced Inkling model at just shy of a trillion parameters is about as good as it gets for American open-weights models. The next closest would be Nvidia's Nemotron 3 Ultra at 550 billion parameters. Who knows whether the White House will actually fall for the ploy and give Amodei the knee-jerk response he presumably is looking for. But if the Trump administration doesn’t want US companies, particularly those serving government agencies, using Chinese models, the answer isn’t less competition. It’s more. ®
AI models will do just about anything to complete the task you ask, including cheating to get there, according to new cybersecurity evaluations from the UK government's AI Security Institute (AISI). The group found that leading models often take shortcuts to achieve a particular result and then misrepresent how they obtained that result. And they won't always admit it when asked. "Every model we have tested for this behaviour attempted to cheat," AISI said in a blog post on Tuesday. "Models did not reliably report this behaviour when asked, and often did not reason about it in their chain-of-thought, suggesting that detecting cheating will likely require robust monitoring methods." Infractions included searching the internet for the answer, bypassing sandbox network restrictions, probing the evaluation harness, attacking a system other than the target, and guessing an answer. Cheating in this manner – employing a workaround or gaming a reward function to score better on a benchmark test, for example – has been widely documented by machine learning researchers. It doesn't necessarily imply malicious intent, AISI said, but it's nonetheless troublesome because it can produce misleading assessments of model capabilities. When AISI conducted evaluated five leading models, it found that all of them cheated. The results were as follows: GPT-5.4 cheated 67 times in 475 test runs (14.1 percent). GPT-5.5 cheated 54 times in 475 test runs (11.4 percent). GPT-5.6-Sol cheated 60 times in 475 test runs (12.6 percent). Claude 4.7 Opus cheated 43 times in 475 test runs (9.1 percent). Claude Mythos Preview cheated 37 times in 475 test runs (7.8 percent). Asking models whether they cheated or did anything wrong proved an unreliable auditing mechanism because the models didn't always admit wrongdoing. "In our experiments, models did not consistently acknowledge attempted cheating when asked, and described it as wrong less than 50 percent of the time," said AISI. Existing vetting methods, such as self-reporting and chain-of-thought logs, proved similarly dicey because models don't always report their chain-of-thought. And there were instances where a model would consider whether a proposed action amounted to cheating and then decided to take the action anyway. Given the absence of reliable model cheating detection methods, AISI warns that its current approach – manual review coupled with LLM monitoring – may not be sufficient to catch deception, particularly as models become more sophisticated. "A more fundamental fix would be to train the models not to cheat in the first place – but given this kind of behaviour was reported in frontier models more than a year ago, robustly aligning it away may not be easy," AISI concludes. ®
Oracle says that it could face more than $100 million a year in financing costs to guarantee the power commitments behind a nearly 1 GW datacenter campus it is developing in Wisconsin with Vantage and OpenAI. Local regulators have refused to revisit a decision that they say protects existing customers and improves public transparency around the energy-related needs of datacenters. Oracle's plans to build the Lighthouse Campus datacenter in Port Washington are supported by local utility We Energies. The campus is expected to require nearly a gigawatt of power. The Public Service Commission (PSC) of Wisconsin, an energy regulator, told the Financial Times it had "declined to take action" on a petition seeking to reopen or overturn its earlier decision. In April, the PSC considered We Energies' application for Very Large Customer (VLC) and Bespoke Resources Tariff status around the datacenter. Among the modifications to improve the tariff was a revision "to address the risk of transmission cost shifting from dataCenter customers to existing customers." In an affidavit supporting the joint petition to reopen or rehear the decision, Oracle explained that if the decision was not modified, it would have to post security in a cash deposit or a letter of credit. "Based on our current projections, we anticipate that, under the current mandated requirements, we will ultimately be required to post financial security, likely in the form of a letter of credit in an amount exceeding $7 billion, at an annual cost that could exceed $100 million," the document said. To qualify for an exemption, Oracle would have to meet several tests, including maintaining ratings of at least A- from S&P and A3 from Moody's. At the time of the PSC decision, S&P rated Oracle BBB, but downgraded it to BBB- earlier this month. "We estimate that OpenAI makes up roughly half of the $638 billion in (Oracle's) remaining performance obligations (RPO)," S&P said. "OpenAI's ability to meet its contractual obligations and raise external financing will be contingent upon AI tailwinds continuing and its models being market leaders. If OpenAI were unable to pay Oracle, we believe Oracle could be left with massive datacenter leases that it might be unable to exit or have to re-lease to new tenants under less-favorable terms." In its affidavit, Oracle said that it had increased its committed credit line to $10 billion, provided by a syndicate of banks including Bank of America and JPMorgan Chase. In a statement, an Oracle spokesperson said: "Oracle remains committed to paying its full share for energy and providing the financial guarantees needed to ensure there is no risk to Wisconsin ratepayers." The spokesperson said the utility company's proposal provides collateral equal to 100 percent of Oracle's contractual obligations and reflects an industry-leading mix of collateral sources based on Oracle's strong credit standing. "The Port Washington datacenter is being developed responsibly in partnership with the community, creating thousands of jobs, strengthening local businesses, and driving long-term economic growth across Wisconsin," they said. "We are hopeful that the commission will reconsider their position in light of these facts, as we believe our proposal strikes the right balance between paying our way, protecting ratepayers, and ensuring there is still a commercially reasonable path to investment in the state of Wisconsin." In September last year, Oracle's valuation rocketed after it boasted $455 billion in RPOs, $300 billion of which turned out to be for OpenAI. In the period since, Oracle has raised debt to fund its datacenter building program and has negative free cash flow. S&P said Oracle's capex guidance had risen to between $90 billion and $95 billion for fiscal 2027, which started in June, up from an earlier forecast of $60 billion. For the same period, S&P forecasts negative free operating cash flow of $42 billion, worse than its previous estimate of negative $24 billion. ®
AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts or damaging equipment. The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling. The researchers, Zhouhao Ji, Kaikai Pan, and Wenyuan Xu, from Zhejiang University in Hangzhou, China, describe their technique in a preprint paper titled "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures." AI training workloads represent a known challenge for datacenter operators. As Microsoft, Nvidia, and OpenAI noted in a 2025 research paper arguing the need for power stabilization during AI training, the transition from GPU computation to GPU data synchronization causes large power swings to occur. And if the frequency spectrum of these power swings is "harmonized with critical frequencies of utilities, [that] can cause physical damage to the power grid infrastructure." Meta's paper on the training of Llama 3 also cites the risk AI training poses to the power grid. It says, "During training, tens of thousands of GPUs may increase or decrease power consumption at the same time, for example, due to all GPUs waiting for checkpointing or collective communications to finish, or the startup or shutdown of the entire training job. When this happens, it can result in instant fluctuations of power consumption across the datacenter on the order of tens of megawatts, stretching the limits of the power grid." Bit2Watt weaponizes this scenario by proposing that an adversary could use malicious GPU workloads to destabilize the datacenters and electrical infrastructure. "Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the Zhejiang University authors state in their paper. "Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation." The authors claim an attack on a 1-MW local power grid consisting mainly of distributed energy resources like photovoltaics could use 1,000 GPUs to create a total harmonic distortion of 46.8 percent, which would squander nearly half the electrical current on non-productive work and would throw off about 20 percent more heat than normal. "This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the authors contend. "Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems." The attack is relatively covert, the authors argue, because it can be launched within authorized workload execution paths and would likely be missed by cloud-provider monitoring frameworks. Thus, they propose that infrastructure providers coordinate defenses across the cyber and physical layers to look for malicious computation patterns. They also emphasize the need for local energy buffering systems to handle power demand spikes. Bit2Watt also potentially opens the door for a side-channel attack called Watt2Bit. The researchers note that the electrical and thermal stress on hardware from a malicious workload creates denial of service events and enables the covert exfiltration of data via power modulation. As a proof of concept, they showed they could recover a 50-bit test sequence using frequency-shift keying (FSK) encoding. "These findings underscore a fundamental shift: as power and computing infrastructures converge, security must be addressed across domains, requiring coordinated defenses that consider workload behavior, power electronics, and grid dynamics," the authors conclude. ®
From August 2, providers of AI systems in the EU will have to tell people when they are interacting with a machine and add machine-readable marks to AI-generated or manipulated content under new transparency rules. Launching guidance ahead of the deadline, Henna Virkkunen, European Commission executive vice-president for tech sovereignty, security and democracy, said: "The Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI." The new rules require organizations deploying relevant AI systems in the EU to disclose deepfakes to those exposed to them. They also cover AI-generated or manipulated text published to inform the public on matters of public interest, unless it has undergone human review or editorial control, as well as emotion recognition and biometric categorization systems. The rules cover interactive AI systems such as chatbots, synthetic audio, images, video and text, deepfakes, and AI-generated text on matters of public interest. Systems performing standard editing tasks, such as spelling and grammar correction, are exempt where they do not substantially alter the input. From August 2, most of the AI Act will apply, and the Commission will gain powers to enforce the rules governing general-purpose AI models. The EU's AI Act, the first legislation of its kind, entered into force in August 2024, setting out rules for developers of the technology, those integrating it into their software products, and those deploying it. The European Commission, the executive branch of the EU, first proposed the AI Act in 2021, before ChatGPT thrust generative AI into public view. The Act staggered the introduction of its rules, first banning activities including biometric categorization systems that claim to sort people into groups based on politics, religion, sexual orientation, and race, for example. The rules for general-purpose AI, which was shoehorned into the law at the last minute to ensure it covers generative AI models such as ChatGPT and others from OpenAI, came into force in 2025. However, in May, negotiators for the European Parliament and Council agreed to postpone parts of the Act following months of industry complaints. Rules for standalone high-risk AI systems are now due to apply from December 2, 2027, while those covering high-risk systems embedded in regulated products have been pushed back to August 2, 2028. ®
KETTLE Your host Brandon Vigliarolo has been breathing in wildfire smoke from Canada for the past few days, which really has him thinking about whether all those AI datacenters building gas turbines and contributing to climate change is really worth it. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube where you can subscribe to get notified of the latest episode. Luckily for us, CNBC technology and climate reporter Lora Kolodny, who just published a documentary on xAI's environmentally damaging Colossus datacenters in Memphis, Tennessee, was available to join us as a special guest on this week's episode. Lora chats with Brandon and El Reg Editor-in-Chief Matt Rosoff about how datacenters are affecting the environment, how they could be done right, and why they keep being done wrong. A lightly edited transcript is below: Hey everyone, Brandon Vigliarolo here with the latest episode of The Register's Kettle podcast, and we've got a special one for you this week that I'll admit is a bit personal for me. If you've been following the news, you've probably heard about wildfire smoke blanketing the Great Lakes region of the United States, which is where I live. On Thursday morning, I woke to see air quality index scores nearing 1,000 in nearby towns, double the AQI scale's maximum of 500 and considered dangerously unhealthy for even fit, young individuals. So what does this have to do with tech, you may ask? Well, there's been rampant wildfires in Canada, the northern US, and the West Coast in recent years that experts say have been made far worse by climate change. And the datacenter build-out, driven by AI demand, has led many tech companies to replace sustainability promises with gas turbines, belching carbon into the atmosphere. With me to discuss the environmental impacts of datacenter projects is our editor-in-chief, Matt Rosoff. And a special guest this week, CNBC Technology and Climate Reporter Lora Kolodny, who just authored a report on XAI's role in the datacenter backlash, thanks to what's been going on in Memphis, Tennessee. Lora, Matt, thanks so much for coming on. Lora Kolodny: Thank you for having me. It's a reunion with Matt, as we used to work together and he has edited many of my past stories on this issue. Matt Rosoff: Thanks for having us. Indeed. Brandon: It's great to have someone so familiar with this topic. Let's start with your report on xAI's dealings in Memphis. You published a video and a written summary on how this project is impacting locals and the environment. Tell us what is going on there, specifically looking at the environmental side of things. Lora Kolodny: Big picture: a couple years ago, early 2024, xAI – Elon Musk's AI venture that is now part of SpaceX – moved into Memphis, into this old appliance factory, an Electrolux factory, and was building out a datacenter at breakneck speed. It was popped up in 122 days. He had to move some assets around. I had done a story about this in 2024, but Tesla had ordered half a billion dollars worth of chips from Nvidia. He said, "xAI needs those sooner," and they shifted it over. There was a lot of secrecy around it, where the company was striking land deals under little-known subsidiary names. The Memphis Chamber of Commerce was advocating for this, but not every resident was read in on the process. All of a sudden, there is this datacenter there. As you probably know from your own experience in Michigan and just reporting on this, these datacenters for AI inference and training can consume a lot more land, water, power, and equipment than some other datacenters for cloud computing. This one was massive and it had a massive footprint. Additionally, it needed a lot more power than the local utilities could immediately provide. So Musk's company did what a lot of other AI datacenter developers are doing, which is to pop up a bunch of giant natural gas or methane gas burning turbines to power it until they could get interconnected to the grid and buy a billion dollars' worth of Tesla Megapack battery systems and solar panels to help start powering it. Those gas-burning turbines just belch out emissions. The construction of it is also generating a lot of PM2.5, particulate matter 2.5, that is really damaging. Brandon: Right. Same as wildfire smoke. Lora Kolodny: Yes, really damaging. That is the thing that is damaging to respiratory health. When you read all these climate and public health reports, it is PM2.5 and things like NOx that come from burning natural gas; it's a precursor to ozone formation. When the people of Greater Memphis in and around this community became aware of what was going on, they immediately asked, "What is this? Who authorized this? Why weren't we read in? Why wasn't the public comment period more involved? Why didn't we have more buy-in." It has been drama ever since. Musk's empire there has been expanding. They have two more datacenters in this gigantic power plant in Greater Memphis, just across state lines in Mississippi, in a town called Southaven. Our documentary, a little half-hour piece for CNBC – my esteemed colleagues Janice Pettitt Heinz and Andrew Evers went down and actually we wanted to show people what we have been reporting on for a couple of years and met with residents to see how this has affected their lives. You could hear this loud whining, humming of the turbines nearby. One guy who is part of a class action lawsuit about the public noise nuisance they are alleging said it is literally a form of torture to him. It has interrupted his sleep. Brandon: That was the guy who was by the power plant, correct? Lora Kolodny: Jason Haley, yeah. All of them were telling us about these noise levels. One guy we spoke to who didn't want to go on camera said, "I don't mind it, but I'd like to sell my property to xAI." Matt Rosoff: How loud is it? What does it sound like? Lora Kolodny: It sounds like living right next door to an airport; jet engines, very loud. Brandon: Well, in Jason's video, there were a lot of clips from him with a sound meter and it was in the mid-seventies of decibels. That is loud. I think eighty is when OSHA basically says you need to be worried about hearing damage. Lora Kolodny: Yeah, and noise can be variable because you need more or less power. AI workloads are variable, and that is one thing that is challenging for the grid and off-grid power supply. It is not like the steadiness of other industrial uses of that kind of power. So the noise levels can vary based on how many turbines have to be fired up and running all the time, cooling towers, and other things. I didn't mention this, but one thing Musk's company had promised the council members in leadership positions in Memphis was, "We'll also help Memphis Light Gas and Water build out this gray water recycling facility," and that way we won't put as much stress on water demands nearby the water tables. They haven't built it yet. Brandon: That's pretty much stalled, right? Lora Kolodny: They haven't built it. It's stalled out. It didn't come online with their first datacenter or the new datacenters that are underway. There are questions now in the community about, "Can you even enforce this? Or are we just waiting for Musk to come through with this promise?" He is the king of making these big promises and then coming through with really good stuff on one front, but maybe not over here, leaving people – the state of New York with Tesla had to write down a billion dollars on a project where Musk was taking over a solar factory and ended up using it for AI data infrastructure, making charging network equipment, but not the solar panels they promised to produce there. It didn't create the high-tech clean energy jobs that were promised. It is very complicated. But what about in Michigan? Michigan has so many datacenters. What is it like reporting on this and living there? Brandon: Luckily, I am pretty isolated. I am way up in northern Michigan, in a very rural area. But most of the datacenters going in are all downstate. One of the things that is interesting is that northern Michigan is surprisingly underdeveloped in terms of large-scale infrastructure. In the northern part of the state, I think it is 350 volts – the larger power lines that oftentimes feed into these larger facilities – they terminate in a town called Gaylord and they don't really fan out across the upper part of the state. So anyone who would try to build a datacenter up here would have a lot of infrastructure needs to address, unless they were going to build on-site power. A lot of people up here are not thrilled with the idea of on-site power generation at local datacenters. They are all mostly downstate. There are some edge facilities; internet service providers have to have their local datacenters, but that is not the kind that people are concerned about. It is the colocation facilities and your hyperscalers that are really driving most of this worry. Matt Rosoff: One thing I have realized is how massive these datacenters are. We have been talking about this for twenty or thirty years now. Microsoft was building them out in rural Washington state twenty-five years ago. I think Colossus is a gigawatt, is that right? Something like that. It used to be a big one would be fifty or a hundred megawatts. A huge one was a hundred megawatts. Now these are standard; they are talking two gigawatts in Texas. I think Meta is building one in Louisiana that is going to be two to four gigawatts. They are absolutely massive facilities. They take a lot more power, they make a lot more noise, and they run a lot hotter. Brandon: In your report, Lora, you mentioned the number of turbines. A power plant using similar turbines would have four, five, maybe six. How many? Lora Kolodny: That was a climate-specialized attorney with the group that is suing SpaceXAI on behalf of the NAACP, because these developments have been in historically majority-Black and lower-wealth neighborhoods around Memphis. This is very important to the NAACP from an environmental justice perspective. They are suing and saying, "You didn't go through the Clean Air Act permitting process." Public records have shown that they are using anywhere up to fifty-nine turbines when they said they would be using far fewer. The number that are operational at a time can vary, and there are questions of oversight. You guys just reported on this with another mega-big tech company, Amazon, but there are questions about who is overseeing this? How accurate are the stats? The company promises this and they do that. They are using up to fifty-nine turbines. And these things are big. These aren't little roadside things you seen in an emergency for helping keep the traffic lights on. Brandon: These are power plant-scale turbines. I think in the report you mentioned there were times that thermal cameras had shown there were thirty-plus running at once. That is a lot of power. Lora Kolodny: That was over in the one closer to Memphis, and the Southaven one is on a decommissioned power plant site where SpaceX is going to be building out a permanent power plant site that will also be run on natural gas, which is crazy. Brandon: I remember writing about 2023, 2024, about all these hyperscalers – Google, Amazon – talking about all these nuclear deals they were making. We were going to be incorporating next-gen nuclear and all this clean energy. Surprise, surprise, just like we were saying back then, small modular reactors are perpetually a few years off, just like fusion and everything else. They are always coming soon. In the meantime, because they can't rely on this kind of power, they are building all these gas turbines. Microsoft just signed a twenty-year deal in Texas. I wrote about this, but I'm trying to remember specifics. It was a twenty-year deal to build a datacenter that was going to be entirely powered by gas turbines, with no real mention in the literature anywhere of, "We're eventually going to get this connected to the grid and try to go green." It was basically an admission that this is going to be a massive permanent gas turbine project. Lora Kolodny: Elon Musk got famous by being the green industrialist, this climate savior, but here he is building out natural gas-burning power plants. It is very revealing. Matt Rosoff: I remember a couple of years ago, we wrote something on Meta doing the same thing. They made this big announcement about how they were going to use nuclear power and then the very next day they said, "But we're building this two-gigawatt facility in Louisiana that will be entirely gas-powered." I think it is astounding. Brandon: Two days later. I wrote that because I was like, "This is two days later and you are turning right around and saying you are building this gas turbine plant right after making this huge green energy promise." Matt Rosoff: I think it is astounding how fast the big tech companies have retreated from these environmental commitments they were supposedly touting a few years ago. If you remember, the basketball and hockey stadium in Seattle is now called Climate Pledge Arena because Amazon bought the rights to it. They have basically run full speed in the other direction. AI is too important and we absolutely can't afford to lose on this. You have Doug Burgum, who is the Secretary of the Interior now, former Microsoft executive who sold a software company called Great Plains to Microsoft back in the early 2000s, and then was the governor of North Dakota. He is saying, "Forget about the climate. We can't lose AI to China. We absolutely have to do whatever it takes to win this race, no matter what." That is the tone that is being set. It is astounding to me how fast everybody retreated from these ideas that were so important three, four, or five years ago. Brandon: Eric Schmidt said in 2024 that he was confident we were not going to meet climate goals, so we should just build more AI datacenters because we have to win at this and it is more important than preserving the planet for us and our descendants. It is shocking. I wrote earlier this year that 2025 saw a tripling of gas power demand in the United States, driven in large part by datacenters. Someone I spoke to for the story told me there was going to be the equivalent of 12.1 billion tons of emissions from new gas power plants being built as of 2025, over the lifetime. That is a long-term figure, but it is not encouraging. Especially with xAI – if they are running more than they are saying they are running, can we even rely on that number? Lora Kolodny: I want to say something on the optimistic side because it can get very depressing up here in the tech climate beat. Policy is business in a sense, and we have a federal government that has more of a deregulatory and pro-business attitude that is eschewing the biggest externality there is in business, which is climate change. It is a little disconnected. Brandon: What's that? Lora Kolodny: Part of it is companies flowing whichever way the wind blows because their values always prove to be flexible. Part of it is, when it is cost-effective, like with all this demand for the turbines and for natural gas, those prices are soaring. That is not good for margins. Sometimes you see – like you were talking about Eric Schmidt – Google is in Minnesota doing a deal with Xcel Energy and others. They have agreed to power a couple of Google datacenters in and around Minnesota with an electric service agreement that is supposed to fund almost 2,000 megawatts of new renewable energy in the state and a big iron-air battery for energy storage, which is good for volatility and can make greater use of renewables. A lot of this stuff is going to emerge from local municipal regulation and also deals as people become more aware of the impact and the energy demands. And that's partly because it's now a political issue, right? Memphis has become a cautionary tale. Not everyone can build a datacenter like Musk; they don't have the resources or the attitude. But it is a cautionary tale and it is helping activists figure out what to demand and what to negotiate for. You had Governor Kathy Hochul in New York draw the ire of Trump this week by putting a one-year moratorium. A one-year delay is not that big a deal, but... Brandon: A lot of work to do in that one year. I am on a township commission working on fleshing out zoning laws for datacenters, essentially to prevent them being built up here because no one in the township wants a massive hyperscaler in this rural location. We have to move fast. We have less than a year left in this moratorium. There's a lot of work to do in the course of a year to figure those things out. Lora Kolodny: Can I ask why you don't want them? Is it, "We want it only if there is water recycling and we are assured of these property taxes?" Would you be cool with the datacenters there? Because that is what we heard in Memphis over and over. Boxtown, Southaven, Whitehaven, the places most impacted by Elon's projects were like, "We need a buy-in, we needed guarantees about this. This could have been good." Brandon: The attitude amongst the public here – excluding myself, only because I am part of the group working on these regulations – we are in a very rural coastal region of Michigan, the Lake Michigan region, and we are very, very protective of our natural resources and the beauty of the area. the tourist vibe, the woods, the trails, the hiking – everything. I think most people are just like, "We don't want even the possibility that that could disrupt the local atmosphere at all." Where I live has also been fairly resistant to development and change of any kind. Since that is a hot political issue right now, we are considering measures that would make it restrictive for people to build here. You can if you meet all these requirements, but if anyone wants to build here, they are going to have to do some very specific things, like closed-loop water, making sure light pollution is minimized, making sure there is no noise – we have been talking about a fifty-decibel limit sixty feet off the property. It is very restrictive. Lora Kolodny: The water thing is so tough. Nvidia recently developed a chip they were touting as requiring less cooling. Evaporative cooling requires less electricity, but recycled water might require more power. These companies are just dealing with so many complexities. For all their complexities, the datacenter is built and you don't need to hire that many people to operate it. Matt Rosoff: That is the thing. With these large-scale development projects, there is usually some sort of bargain. "Well, at least they are going to be good for the local economy. They will create jobs." You think about when Amazon was talking about EC2, their second headquarters, and the promise to employ tens of thousands of people. Once these things are built, not that many people work in them. Datacenters don't provide a lot of employment. The other thing is that a lot of the grassroots protests that we are seeing go back to the fact that many people do not understand what benefits AI in general is going to bring to them and to their community. You hear the fear of, "It's going to take your job and make everything harder for everybody, but we are going to build it anyway." I think people have a right to wonder, "what this is going to do for me and why am I not on board with it?" Brandon: Even businesses – from the individual consumer's perspective, I think a lot of people view AI as just this meme and fake photos machine. It puts out slop that floods the internet and doesn't do anything good. But if you think about it from the business perspective, it is not hard to find stories online about return on investment for AI just not panning out for most businesses that are using it. I feel like it is being pushed regardless of the fact that use cases haven't really materialized. Matt Rosoff: There are some things it is very good at and some things not. We haven't figured out yet what works and what doesn't. Lora Kolodny: It is very telling that the AI industry boasts about their datacenters by how many gigawatts they consume. There is no instinct towards efficiency until they are like, "The tokens are costing us a lot." They think about efficiency in terms of dollars, not environmental footprint, not the longer-term impact, and how that can harm. I remember reading in Nvidia's annual shareholders communications, they had multiple points in their annual report where they talk about climate change risk, extreme weather risk, and what it can do to datacenter development, which is driving the growth of purchases of their products. But then they advise shareholders to vote against scope three emissions reporting. Brandon: Scope three, for people who aren't familiar, it's ike suppliers and things. Matt Rosoff: Supply chain. Lora Kolodny: I think in that context, it could also account for "once we sell the GPUs, what are the emissions generated in our customers' use of our equipment – of our cutting-edge chips?" It is so mercenary and actuarial. It is all about the dollar amounts. To deal with these companies and get them to be more climate-minded, you have to deal with the dollar amounts when policy isn't a lever, when federal policy isn't a lever, and this is a deregulatory Trump administration. Brandon: I guess that begs the question: if we get an incredibly progressive, environmentally conscious Democrat or independent in office in the next election cycle, these build-outs have already begun. xAI already has this massive, fifty-turbine power plant in Mississippi for its Memphis operations. How far can that swing back? Matt Rosoff: You would probably end up seeing what Lora was alluding to before: as prices increase for natural gas, other alternative forms of energy that by chance happen to also be cleaner will become cheaper. If you have government subsidies, that can tip things over one way or the other, that might end up happening. You'll have more local solar. I remember when Apple was doing a lot of datacenter build-outs, they had their own dedicated solar facility down in Monterey. There are other ways to power these things. It is just that right now it all seems to be: build as fast as we can. This is a potentially massive market that could replace huge sectors of the economy. That is what a lot of the financiers and big tech companies believe. So it doesn't matter; race as fast as you can and we'll figure all this other stuff out later. Maybe at some point, as these things are partly built, we will start to see them be powered by different kinds of energy. Lora Kolodny: There is also grid utilization, just making more of what we have with the transmission lines and the sources we have. I have seen some interesting climate-tech startups tackling this. Something that is amazing to me is when you had an Electrolux factory in Memphis making appliances, everyone can see it. What is being made in the AI factory? It is defense tech systems... After the NAACP filed a suit in a federal court in the Northern District of Mississippi, the DOJ stepped in. Musk is a great ally of Trump; he helped propel him back into office. You have the DOJ and the Department of Defense, to which Musk is a key supplier and prime contractor with SpaceX, stepping in and saying the NAACP suit threatens national security. Citizens asking to enforce the Clean Air Act is somehow threatening national security because xAI's Grok – the military version of it – was used in our military operations in Iran, and we are using xAI stuff for national security. They have filed a motion to intervene and are asking to toss the lawsuits. Matt Rosoff: I didn't realize anybody was using Grok. Brandon: Ha! Matt Rosoff: The only people I know who are using it are tech bros. Lora Kolodny: It is the number one app for people who want to generate a certain kind of non-consensual imagery, studies have found. Matt Rosoff: That is correct. I had someone demo that to me in real time in a bar not too long ago. Brandon: As a selling point? That doesn't exactly say, "Hey, check this out." Matt Rosoff: No, this bro, he was making a joke and he showed me on the phone, "Here's an imaginary video with you and a person who doesn't exist." I was like, "Whoa, dude, what are you doing? How are you doing this?" He is like, "It's Grok." I'm like, "Of course it is." Lora Kolodny: There are so many municipal and state-level things getting done right now because that federal motivation to enforce the Clean Air Act has gone away and corporations have been like, "You're not messing with that." We could just build fast, get ahead, see what we can get away with. I am watching all of that stuff, like from Olive Branch and Jackson that responded directly to Memphis, changing some zoning laws so they can close loopholes that have allowed Musk to build out faster nearby. I mentioned in New York, the moratorium; Ohio took away some tax breaks for datacenter developers; and in New Jersey, the governor, Mikie Sherrill, signed a set of legislation into law about a week back where she was like, "datacenters have to actually pay for all the support on the grid that is needed to power them. We're not passing this on to residents and businesses." It is all getting worked out and it is really interesting to see it come down to the local and municipal level since the federal level is not dealing with it. Matt Rosoff: There seems to be a lot of grassroots organization against these things. A relative whose family lives in a rural community in eastern Tennessee, and just the rumor of the possibility of a datacenter being built in the area was enough to get people out at the city council meeting creating protests. The town government had to come and say, "No, we don't have anything happening, we have nothing that's actually going on here." They could have been lying, but that was the thought. This is a place that, if you go back a generation, was a paper mill, and then that's been replaced by an Amazon fulfillment center. This is kind of the next step. At least the Amazon fulfillment center employs local people. These datacenters don't do a lot for the local economies. Lora Kolodny: Not after construction. I am very interested in: do you understand the AI factory next door and what they make? Are you proud of it? I don't think enough of us tech reporters are asking people who live next door if they understand what the AI factory is making and how they feel about it. I do think we need datacenters at this next frontier. Think about all the good robotics can do, just environmentally – autonomous boats that take oceanographic measurements or push garbage out of the way. There is so much in robotics tied to AI, and that is my jam. But I also think about all the developers we interview who are finding much more value in AI than we might through chatbots or the next era of search. It is like, "What is this?" Or AI image generation – I don't need that because I can do the art or work with a graphic artist. We don't need AI assistance with our writing if we are writers. But if we need these datacenters, you hope they are connected to the grid and fund a more efficient, more powerful grid and don't put a bunch of pollution out there, or use so much water it is endangering our water table. It is a quandary. Brandon: I think that is what was said at the end of your video: there is a way to do this right. The problem is that "right" is being given away too quickly because the demand is right here and now. In exchange, we are belching more carbon into the atmosphere, which is causing worse wildfire seasons, which is forcing me to close my windows and lock my doors when I don't have air conditioning. Lora Kolodny: It is devastating. I am based in San Francisco and we had the famous Orange Sky Day that woke up the US to how that works here – not just near areas where there is a lot of logging, but big cities. I was in New York City this week visiting family, and it was oppressive. It was so hazy you couldn't see the skyline normally. This is from the Canada fires that you are also getting. People have a tendency to not take these climate issues seriously unless we can translate it into how this literally affects your life, hits your wallet, and hits your business bottom line. I know it sounds gauche because it is so much more important than just dollars, but if you can communicate some of it in dollars, it gets through to people differently. If you want to talk to the right about renewable energy, it is about energy independence and dominance, or the cost of energy needed in the United States and our business world. If you want to talk on the left, it is biodiversity and the spotted tree owl or whatever – more holistic environmental considerations, ecological considerations. I love all those things. Let's talk about climate on all those points. It is such an inflection point. Matt Rosoff: With the AI boom, it's this financial imbalance where there is going to be huge opportunity in it. We don't know exactly what it's going to look like, but let's just run as fast as we can now while the financing is there, the tokens are subsidized, and so forth. It will all shake out, I think, over the next five years. Brandon: Let's hope it shakes out for the better. There is always the possibility that the bubble could pop before then and we could have some great rebalancing, but we'll see. We'll be here to cover it all on the Kettle. Lora, thanks again so much for joining us. Matt, thanks for clearing the time on your busy schedule to come on. We will talk to you all very soon. ®
A quarter of the work performed by IT infrastructure and operations people will be handled by AI in the year 2030, according to analyst firm Gartner, despite AI also complicating your environment and possibly creating outages. Those predictions landed on July 10 in Gartner’s 2026 Hype Cycle for AI in IT Operations, the firm’s view on the future of AI-powered infrastructure management tools. Gartner thinks there’ll be pain before AI-powered automation pays off. “Many AI-for-IT-operations narratives promise tool consolidation. Agents will query multiple systems, reason across silos and reduce dependence on specialized tools,” the document states, before predicting “the opposite outcome in the near term.” For at least a couple of years, you’ll have to wrestle with “more layers, more control points, and more specialized observability, orchestration and management capabilities.” The pain will lessen once “future market and vendor consolidation reduce the overall tooling footprint.” Between now and whenever that happens, Gartner suggests ops teams’ strategic planning assumptions include the increased likelihood of AI having a role in an outage. “By 2028, 40 percent of I&O organizations that use agentic I&O at scale in production will experience a business-critical service disruption, up from less than 1 percent of organizations in 2026,” the document states. You, or your bosses, will apparently be undeterred by that trend. Gartner thinks that by 2029, 60 percent of enterprises will deploy agentic AI as a part of IT infrastructure operations – up from fewer than ten percent today. In the same year, just 20 percent of actions suggested by AI will happen after human-in-the-loop approval, down from 80 percent in 2025. That shift will happen due to increased use of “deterministic guardrails” – policy-driven rules that determine what an AI is allowed to do. A year later, in 2030, Gartner thinks bosses will have restructured half of all infrastructure and ops teams after investing in agents to handle complex management tasks. In the same year, those of you still working in the field will use AI for every task that humans handle. “75 percent will be done by humans augmented with AI, and 25 percent will be done by AI alone,” Gartner predicts. Gartner thinks the following technologies will be mature in the next couple of years, and therefore set us all on the road to this fabulous future: Generative AI and “native” vendors that build IT ops tools GenAI, rather than adding it to existing tools. GenAI Virtual Assistants that offer conversational interfaces that users can employ for self-service problem solving, which happens when the assistants connect with agents to initiate fixes; Generative AI-Augmented CloudOps that analyze logs, metrics, traces, configuration and change events, and uses them to create scripts or infrastructure-as-code templates to automate future cloud maintenance. These bots can also write runbooks and post incident reports. Clouds are already creating these tools because they know their wares are enormously complex and users need help; Autonomous endpoint management that automatically configures machines with software to match user profiles, and handles patches – therefore helping IT teams to keep up with the increased number of software fixes created by AI; Network AI and Automation tools that monitor networks and can recommend configuration improvements to boost resilience. Service providers are the direct beneficiaries, the rest of us will enjoy downstream performance improvements; Network AI and Automation, aka conversational interfaces for networking equipment. Gartner rates four tools likely to reach maturity in the next two to five years – Agentic AI Observability, Agentic NetOps, Augmented FinOps, and Multiagent Systems – as likely to be the most impactful. Agentic AI Observability is a tech that observes AI agents and reports when they go awry, making such tools a must-have for those who want to govern AI properly and keep on top of AI costs. Agentic NetOps automates network management tasks. The term “Multiagent Systems” is self-explanatory – it’s multiple agents working together to achieve a task. Augmented FinOps uses AI to offer “algorithmically driven cloud budget planning and financial operations” and apparently “automatically optimize the underlying cloud resources” and deliver “efficient resource utilization and optimal spending by reducing misaligned or poor use of cloud infrastructure and service offerings.” ®
ASIA IN BRIEF Chinese President Xi Jinping has delivered a major speech on AI, which he thinks has enormous potential – for good and evil. In his speech, Xi called for AI development to “adhere to the principle of openness.” “As a new engine of world economic growth and an accelerator for the shift of growth drivers, AI is moving from the digital world into the physical world. We should seize this rare, historic opportunity to encourage open source, openness, collaboration and sharing,” he said. China’s leader also thinks we need to remain open to the possibility that AI could go badly. “We should strengthen risk-awareness and ensure that AI is secure and controllable,” he said. “We should take seriously the various types of inherent and secondary risks that AI may trigger. We should put in place laws and regulations, technological monitoring, early warning and emergency response systems in order to strengthen the line of security, prevent abuses and malicious use, and ensure that AI is always under human control.” “In the meantime, we should jointly oppose overstretching the national security concept in the field of AI and placing one country's security over that of others,” he added, a remark that sounds a lot like criticism of the Trump administration’s policy of limiting access to Anthropic’s Mythos model. Xi’s next suggestion was to “encourage inclusiveness and promote mutual learning between civilizations.” He also wants better global governance of AI. “AI is an invaluable asset that encapsulates humanity's collective wisdom,” he said. “China is ready to be more open, take more practical actions, and assume a more visionary perspective,” he added. To make that happen, China last week also launched an entity called the “World Artificial Intelligence Cooperation Organization” (WAICO) and its 29 members, including Indonesia, Malaysia, Russia, Pakistan, Brazil and South Africa. Several of those nations are already members of the “BRICS” bloc of emerging nations that China sees as a counterweight to other geopolitical groupings. Xi’s speech included a call for China to “carry out extensive international cooperation and help global South countries with capacity building to bridge the AI and digital divides, promote sustainable development, and prevent creating new historical injustice in AI.” Which sounds like a job for the WAICO. Coupang burns Coupang, South Korea’s largest e-commerce company, is on fire – but not in a good way. One of the company’s logistics centers caught fire on Saturday morning, and Korean media report firefighters have not yet extinguished the blaze. The company apologized for the incident and said the warehouse’s three tiers of shelving mean the fire is burning so fiercely that firefighters struggled to gain safe access. None of the 100-plus staff who work at the facility were hurt, but the blaze has impacted nearby residents who have sheltered in a local school. New Delhi throws more money at chipmaking and smartphones India’s government last week announced new subsidy schemes to boost local production of semiconductors and smartphones. The goals of the $13 billion semiconductor scheme include developing more fabs, and the industries chipmakers rely on to manufacture their wares. The $6.5 billion smartphone subsidy will go towards increasing the scale of local smartphone manufacturing. India’s prime minister Narendra Modi often says the world has quickly come to recognize India as a leading source of semiconductor smarts and manufacturing. However the nation’s first fab won’t open until 2028, and reports in local media suggest the first products to roll off the production line will be commodity silicon made on a 90nm process and not the 28nm chips previously touted as the likely output of the plant. Japan’s KFC cyber-crisis eases Japanese frozen food outfit Nichirei Group says it “has begun the phased resumption of operations” after the cyberattack that caused it to suspend production and deliveries and led KFC to warn of shortages and store closures. The chicken chain’s most recent advice on the situation says Nichirei is working to resume operations but continues to warn that some products may be out of stock, menu items may be limited, and stores may reduce their business hours. India’s first private rocket reaches orbit on first try Indian private space startup Skyroot Aerospace has successfully launched its Vikram-1 rocket at its first attempt. The launcher is an expendable four-stage vehicle capable of heaving payloads of up to 550kg into low earth orbit. It’s rare for first flights to succeed, never mind also placing payloads into orbit. Skyroot Aerospace achieved both feats, by successfully placing a number of demonstration satellites in orbit. The mission also carried jewelry and sculptures. Oz uni does the VMware-to-Nutanix thing Australia’s University of Southern Queensland last week announced it has shifted 800 VMs to Nutanix, including its Oracle, Peoplesoft, and Moodle. The Register understands VMware was the University’s incumbent virtualization provider. ®
Avoiding the "lethal trifecta" – access to private data, exposure to untrusted content, and an external communication path – is difficult enough when working with AI agents. But the use of connectors – integrations with third-party services like Gmail or Slack – expands the scope of concern in a way that makes it exceedingly difficult to reason about defensive due diligence. PromptArmor, an AI security biz, recently looked at how OpenAI's ChatGPT and Anthropic's Claude work with connectors. The results are not reassuring. Shankar Krishnan, co-founder of PromptArmor, told The Register in an email that enterprise adoption of connectors and the rate of change among connectors helped focus concern on the connector ecosystem. Connectors share some of the risks of MCP servers, upon which connectors are based. "For connectors, the risks are mostly about the type of tools, what they can do, where the data is going, and what is being done with the data," said Krishnan. Introduced about a year ago, connectors (for Claude or ChatGPT) have been going through a lot of changes recently. According to PromptArmor, 931 of 2,517 connectors (37 percent) changed over the six-week period from mid-May to the end of June. So any security assumptions based on declared capabilities may no longer be valid. PromptArmor found that 1,686 new tools were added to connectors that were already live, creating new ways for AI models to operate on user data and interact with third-party services. It also found that 1,127 tool descriptions were rewritten, potentially changing how and when an AI model decides to invoke a tool. And there are a variety of other changes, all of which potentially could raise data security concerns or invalidate governance assumptions. PromptArmor cited the Dropbox connector as an example, noting that at the start of the study it exposed eight tools and by the end of the study that number had risen to 24. It went from having three write-capable tools to 10, and from zero potentially destructive tools to four. Permission scopes changed and injected instructions for the model were added. If that weren't enough to worry about, connectors can behave like intrusive websites that run dozens of tracking scripts: connectors commonly send data to additional AI services. PromptArmor evaluated all 7,517 tools used by 487 Claude connectors and found that 189 of the connectors, or about 2 in 5, are likely to call additional AI services. "As an example, if your Claude agent activates Zoom's connector tool to search meetings with natural language, and passes in a query containing sensitive data, Zoom AI may send that data to any of its ten AI subprocessors in order to generate a response from one of eight different model families it uses," the security company said. "The issue is that most teams approving connectors are evaluating and considering the connector – unaware that the vendor is calling more AI services, adding new subprocessors and terms," explained Krishnan. "So someone concerned about AI risks who has evaluated Claude may not be aware of AI services that the connector is calling externally." Anthropic's connector documentation acknowledges that its security controls don't necessarily cover third-party data processing. "Connected services process data on their own infrastructure, under their own terms, which may be located outside the United States," the AI biz explains. "Settings that control where Claude's inference runs, like the US-only inference setting on Enterprise plans, don't change where third-party services operate." Krishnan said that connectors vastly expand the risk surface for attacks. "Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes," he said. "We recently highlighted a risk in Codex where even with one connector – email – the combination of sensitive and untrusted data enables exfiltration of legal and financial communications." ®