Social vietati ai minori, in Australia è un flop per la falla nell’age verification. Italia capofila Ue con modello Agcom e app IO?

Il divieto di accesso ai social media in vigore in Australia dal dicembre del 2025 non funziona come sperato. Sette ragazzi con meno di 16 anni su 10 riescono a collegarsi alle piattaforme social nonostante il divieto. E’ quanto emerso dal primo report realizzato dalla società di analisi eSafety dopo tre mesi dall’entrata in vigore del provvedimento.  

In sintesi, trattare i social media per i minori in modo analogo al fumo e agli alcolici rischia di essere una modalità inefficace, che non funziona.

In Italia il tema è di grande attualità, con l’avvio della discussione sulle varie proposte di legge di legge in discussione in Commissione Ambiente al Senato già oggi.

Il dibattito a livello internazionale è in corso. L’esperienza australiana, però, scrive un’analisi alquanto approfondita del britannico Guardian, dovrebbe essere tenuta in grande considerazione visto che si tratta del primo bando reale che un Governo mette in atto per i minori.

E a quanto pare, non sembra semplicemente una questione di compliance, vale a dire di conformità e applicazione delle regole. In generale, le grandi piattaforme non sembrano particolarmente propense a mettere in atto ogni modalità per verificare l’età degli utenti.

Modello australiano, perché non ha funzionato

La falla tecnica più evidente è legata al comportamento delle piattaforme stesse (come TikTok, Meta e Snapchat). Molti servizi non hanno inserito un blocco rigido di verifica dell’età al momento dell’iscrizione (account set-up). Di conseguenza, ai ragazzi è bastato creare nuovi profili dichiarando semplicemente una data di nascita falsa.

Sistemi basati sull’Intelligenza Artificiale per analizzare i volti tramite selfie (come i software di Yoti o k-ID) si sono rivelati facilmente aggirabili e imprecisi:

Escamotage tecnici standard (VPN e browser)

Anche se le indagini più recenti mostrano che solo una minoranza ha dovuto effettivamente ricorrere a strumenti avanzati, l’uso di VPN (Virtual Private Network) ha permesso ai ragazzi più tecnologicamente avanzati di geolocalizzarsi fuori dall’Australia, bypassando istantaneamente qualsiasi restrizione federale. Inoltre, la legge richiede restrizioni solo per l’uso delle app tramite account, lasciando aperta la possibilità di visualizzare i contenuti direttamente tramite browser web in modalità ospite.

Mancano inoltre sistemi di riverifica dell’età da parte delle piattaforme.

Riconoscimento facciale impreciso. Rischio boomerang?

Per assurdo, non soltanto il divieto rischia di rivelarsi inefficace e facilmente aggirabile dai ragazzi, ma in realtà rischia di rendere le persone online addirittura meno sicure.

I software di stima dell’età tramite riconoscimento facciale sono tristemente imprecisi, scrive il Guardian, si legge nel report di eSafety, ma approcci più rigidi al controllo dell’età creano nuove opportunità di vulnerabilità per la privacy e la sicurezza digitale: si pensi, ad esempio, all’esposizione di circa 70mila foto di documenti d’identità governativi quando il fornitore di verifica dell’età di Discord è stato hackerato lo scorso anno.

Il Social Media Minimum Age Act australiano (in vigore da fine 2025) si è scontrato con enormi falle di applicazione e privacy:

  • Facilità di elusione: I minori hanno aggirato facilmente i controlli inserendo date di nascita false, condividendo gli account dei genitori o usando semplici VPN.
  • Privacy e rischi di hackeraggio: I metodi usati dai social – come la scansione dei documenti d’identità (ID) o il riconoscimento facciale basato sull’AI – hanno suscitato enormi polemiche per la privacy e la conservazione centralizzata di dati sensibili.

Age verification fa a pugni con modelli di business delle piattaforme

In definitiva, il problema fondamentale del controllo dell’età è che non affronta nessuno dei problemi di fondo del nostro attuale panorama online, ovvero i modelli di business estrattivi e le caratteristiche di progettazione dannose delle principali aziende tecnologiche.

L’obiettivo delle piattaforme è raccogliere informazioni sugli utenti, per poi commercializzare i nostri dati in chiave pubblicitaria. Si tratta di un modello legale, pienamente legale, che tuttavia coinvolge anche i minorenni.  

Quali alternative più efficaci avrebbe potuto perseguire il governo australiano, dopo aver speso quasi due anni a inseguire questa falsa pista?

Vietare ai bambini l’accesso ai social media, in poche parole, rischia di essere una modalità rozza che rischia di compromettere l’obiettivo stesso di minimizzazione del danno a cui la politica dichiara di aspirare. E l’esempio australiano sembra darne prova. Resta da capire se i Governo di Canberra tornerà sui suoi passi.

Detto questo, non più tardi della scorsa settimana anche il Regno Unito ha optato per l’introduzione di un divieto di accesso ai social media per gli under 16.

Funzionerà?

Presto per dirlo.

In cosa il sistema AGCOM è migliore: Doppio anonimato e App IO

L’approccio dell’AGCOM (qui i 10 requisiti necessari) mira a superare i limiti strutturali di quello australiano attraverso alcuni pilastri fondamentali:

  • Logica di “doppio anonimato”: Il fornitore della verifica dell’età non sa per quale servizio (es. un sito di contenuti per adulti) l’utente stia chiedendo la verifica; allo stesso tempo, la piattaforma web riceve solo la conferma “maggiorenne” ma ignora l’identità o i dati personali del cittadino.
  • Minimizzazione dei dati: Evita la raccolta di informazioni sensibili da parte delle piattaforme online, limitando drasticamente i rischi di data breach ed esposizione di documenti (che sono costati cari ad altri sistemi di verifica).
  • Nessun obbligo di SPID per i siti: Lo SPID (identità digitale) è stato escluso per l’accesso ai singoli siti perché trasmetterebbe troppi dati (come il nome) all’atto dell’autenticazione, preferendo un approccio incentrato su “app terze” certificate che gestiscono i dati in locale o su wallet digitali.

Age verification, Capitanio (Agcom): “Doppio anonimato per l’accesso e App IO”

Già un anno fa il commissario Agcom Massimiliano Capitanio esponeva il funzionamento dello strumento di age verification per minori in un’intervista a Key4biz.

[embedded content]

Italia capofila del progetto Ue di age verificaton

L’Italia non si muove da sola. In parallelo, partecipa a un progetto pilota europeo insieme a Francia, Spagna, Grecia e Danimarca per sviluppare un sistema di verifica dell’età valido per i social network.

L’idea è quella di un’app interoperabile, integrata nel futuro portafoglio digitale europeo, atteso entro la fine del 2026. L’obiettivo è ambizioso: consentire alle piattaforme di sapere se un utente è maggiorenne o meno, senza conoscere la sua identità, in linea con GDPR e Digital Services Act.

Il Sottosegretario alla Trasformazione Digitale Alessio Butti ha recentemente detto che per la “verifica età minori sul social con l’App IO sarebbe già possibile, ma serve una norma”. Insomma, in Italia sarebbe già fattibile.

ALESSIO BUTTI, SOTTOSEGRETARI ALL’INNOVAZIONE

Paesi nordici e baltici scettici sull’age verification

Gli Stati membri che hanno annunciato una legislazione in materia sono Francia, Spagna, Austria, Grecia, Irlanda, Danimarca e Paesi Bassi. Anche l’Italia sembra essere favorevole. Tuttavia, diversi Paesi, in particolare alcuni nordici e baltici, si oppongono fermamente. A loro avviso, il livello di alfabetizzazione digitale di genitori e figli è tale da consentire loro di riconoscere e affrontare i pericoli posti dai social media. Impedire ai bambini di accedere a queste piattaforme li priverebbe di informazioni e conoscenze, scoraggiando le loro future capacità innovative. Non a caso, la vicepresidente della Commissione responsabile per gli affari digitali, la finlandese Henna Virkkunen, si mostra scettica sull’introduzione di un’età minima per l’accesso ai social media.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/social-vietati-ai-minori-in-australia-e-un-flop-per-la-falla-nellage-verification-italia-capofila-ue-con-modello-agcom-e-app-io/576343/




French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

French President Emmanuel Macron on Wednesday urged the world’s wealthy democracies to work together on regulating advanced artificial intelligence systems, speaking at a high-level meeting that included top AI executives.

OpenAI CEO Sam Altman issued a similar plea at the Group of Seven summit of major industrialized nations in France, saying an “international forum” is needed for countries to draw up AI guardrails. He said the task of AI safety should not be left to tech companies.

Overshadowing the discussion on AI was President Donald Trump’s administration’s directive last week, preventing foreign nationals from using Anthropic’s newest and most powerful artificial intelligence models.

Macron said it was a “good thing” that U.S. officials recognize that so-called frontier AI models could be dangerous, but he also criticized it as a “strictly nationalist” reaction.

The remarks followed a G7 working lunch that brought together AI industry figures, including leaders of three of the most powerful AI companies — Altman, Google DeepMind CEO Demis Hassabis and Anthropic CEO Dario Amodei — on the theme of “ensuring a safe, rapid and effective deployment of artificial intelligence.”

Trump’s feud with Anthropic has unsettled many outside the US

Ahead of the meeting, the White House’s dispute with Anthropic fueled distrust in Europe about American dominance of AI and tech ecosystems.

Advertisement. Scroll to continue reading.

The company was forced on Friday to take its latest artificial intelligence models, known as Fable 5 and Mythos 5, offline to comply with the directive. The AI giant said it did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue.

When asked by a reporter whether France and other G7 countries had asked Trump to permit access to Anthropic’s latest AI models, Macron said he made a forceful plea for the U.S. not to keep cutting-edge AI to itself.

Macron warned of a possible drop in value for U.S. firms pioneering the disruptive technology if they switch off access like a light switch. Macron backed his appeal for partnership among key democracies with an insurance policy: France, he said, will boost funding for its own AI industry, so it’s not left behind if international cooperation breaks down.

Democratic countries ultimately want to prevent authoritarian regimes from getting access to advanced AI systems, Macron said.

“So let us move forward together,” he said. “Our relevant agencies must first cooperate so that, in the areas of security and cybersecurity, we have a smooth government-to-government relationship.”

Altman said in his lunch speech, attended by the G7 leaders and more than a dozen AI bosses, that the technology’s future must be shaped by people, democratic institutions and society as a whole, “not just by the companies building the most capable systems.”

“We need an international forum for discussion that establishes globally accepted standards for testing, provides expert and impartial analysis of capabilities and risks, and serves as a venue for cooperation among nations,” he said.

Europeans have sought checks on American AI dominance

Even before the Anthropic episode, there was growing distrust of American companies dominating AI and other tech ecosystems. In Brussels, the European Commission unveiled a tech sovereignty package this month with plans to boost homegrown AI, and at the Vatican, the pope last month called for robust regulation of artificial intelligence.

Trump’s intervention with Anthropic highlighted how Europe, Canada or other countries “can be put in an extremely vulnerable position” if they are cut off from advanced AI models, said Zach Meyers, director of research at CERRE, a Brussels-based think tank.

“There is a general anxiety about the state of Europe, the fact that we’re relying on other countries for quite important strategic infrastructure and a desire to do something about it, whatever that is,” Meyers said.

At the G7, Aidan Gomez, CEO of Canada’s Cohere AI, said a “number of proposals” were discussed on working together on AI governance and regulation.

“I think the consensus was we need something,” he told The Associated Press.

He said he told the gathering that democracies should focus their efforts on making sure the G7 “doesn’t just produce the most capable AI, but also the second most capable AI,” a reference to the U.S. and China being the world’s only two major AI powers.

Meta’s chief AI officer, Alexandr Wang, also attended the meeting, along with the heads of smaller AI labs, including France’s Mistral, Germany’s Black Forest Labs, Italy’s Domyn, Sakana AI of Japan and United Kingdom-based Synthesia.

The G7 comprises France, the United States, Canada, Germany, Italy, Japan and the UK. Brazil, India, Kenya and South Korea were among guest nations invited to participate in some discussions.

Related: AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask

Related: Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation

Related: Industry Reactions to Claude Fable 5: Feedback Friday

https://www.securityweek.com/french-president-urges-us-to-share-cutting-edge-ai-and-democracies-to-cooperate-on-regulation/




Bernie Sanders unveils $7 trillion plan to give Americans control of AI industry

Bernie Sanders has unveiled an aggressive plan to transfer trillions from leading AI firms to the public, and, to the likely horror of AI firms, it goes even further than expected to give Americans more control over the AI industry.

Sanders shared a summary of his legislation with AP News. If passed, the law would create a sovereign wealth fund “financed through a one-time 50 percent tax on the stock of the largest AI companies,” AP News reported. Any AI firm that does $200 million in annual AI sales would be subject to the tax, as would any new firm once it reaches that revenue level.

In total, Sanders estimated the fund could be worth $7 trillion, generating “hundreds of billions of dollars annually in direct payments to Americans and programs such as health care, education and housing,” AP News reported. Each American would likely receive more than $1,000 annually in 5 percent annual dividends, Sanders estimated.

“The benefits cannot simply go to the handful of wealthy corporations,” Sanders said. “They will be shared by the American people.”

Beyond the payouts and support for critical US programs, the legislation would also ensure that Americans have “direct influence over corporate decision-making,” Sanders said. Seven members of a newly created, bipartisan Independent Commission for Democratic AI—nominated by the president and confirmed by the Senate—would oversee the fund. Using voting shares, the commission could block any decisions companies may move to make that could harm the public, The Hill reported.

“The public has got to have a significant seat at the table to make sure that terrible things do not happen to ordinary people, and that in fact, AI benefits ordinary people, not hurts them,” Sanders told AP News.

AI industry unlikely to embrace Sanders’ plan

Although some CEOs like OpenAI’s Sam Altman and Anthropic’s Dario Amodei have shown support for some public benefits from AI, their ideas are not as bold as Sanders’.

In a meeting with Sanders, Altman remained “far apart” from the senator on how much stake in OpenAI the American public should have, sources in the room told AP News. However, Sanders insists that his legislation transfers a fair amount of wealth while critically ensuring that AI benefits humanity. He confirmed that he intends to campaign on creating the fund, and during the meeting, he cast AI firms that expect to transfer significantly less than 50 percent as greedy.

https://arstechnica.com/tech-policy/2026/06/bernie-sanders-unveils-7-trillion-plan-to-give-americans-control-of-ai-industry/




L’AI ACT sarà modificato: prorogato al 2028 lo stop per i modelli ad alto rischio

La sessione plenaria del Parlamento europeo ha dato il via libera ieri alla riforma della legge europea sull’intelligenza artificiale (AI Act), che includerà nuovi divieti sui contenuti sessuali non consensuali (con il ban delle cosiddette app nudifier) e posticiperà di due anni alcuni degli obblighi previsti dai regolamenti UE in relazione ai modelli ad alto rischio.

Divieto di nudifier senza consenso

Nello specifico, come anticipato il 7 maggio scorso su Key4biz, sono vietati i sistemi di intelligenza artificiale progettati esclusivamente per generare immagini sessuali o intime senza il consenso delle persone coinvolte, così come il materiale pedopornografico creato con questa tecnologia.

La riforma richiederà inoltre alle aziende che sviluppano modelli di intelligenza artificiale generici di implementare “misure di sicurezza ragionevoli” per prevenire la diffusione di questo tipo di contenuti.

Misura anti-Grok

La revisione del primo regolamento comune per mitigare i rischi legati all’intelligenza artificiale è stata elaborata mesi dopo la controversia scatenata dalla diffusa circolazione sui social media di immagini intime manipolate tramite intelligenza artificiale, in particolare attraverso strumenti integrati in piattaforme digitali come Grok, l’assistente virtuale collegato al social network X.

Lo scorso maggio, il Consiglio dell’UE e il Parlamento europeo hanno concordato i dettagli di queste modifiche, che includono anche il rinvio al 2 dicembre di quest’anno dei requisiti di trasparenza per i contenuti generati artificialmente, come immagini, video o audio creati con l’intelligenza artificiale, che devono includere meccanismi che consentano agli utenti di identificare questo tipo di contenuto.

Sistemi di AI ad alto rischio posticipati in parte nel 2027 e in parte nel 2028

Parte degli obblighi previsti per i sistemi di intelligenza artificiale ad alto rischio, come quelli utilizzati in settori sensibili quali sanità, istruzione, settore bancario, reclutamento, controllo delle frontiere o gestione delle infrastrutture critiche, è stata posticipata dal 2 agosto 2026 al 2 dicembre 2027. Nel caso di sistemi integrati in prodotti, come dispositivi medici o macchinari industriali, i nuovi requisiti entreranno in vigore il 2 agosto 2028.

Proroga di due anni

Inizialmente, la legislazione europea prevedeva l’entrata in vigore anticipata di tali obblighi nel 2026, ma i colegislatori hanno concordato di posticiparli fino a 16 mesi, ritenendo che non tutti gli standard e gli strumenti tecnici necessari per la piena attuazione del regolamento siano ancora disponibili

L’accordo fa parte del pacchetto legislativo europeo sulla semplificazione digitale, Omnibus VI, attraverso il quale la Commissione europea cerca di ridurre gli oneri amministrativi e agevolare l’attuazione delle normative UE, in particolare per le piccole e medie imprese.

In questo contesto, il testo estende alcune delle esenzioni normative inizialmente previste per le PMI anche alle società a piccola capitalizzazione e rinvia ad agosto 2027 la scadenza per gli Stati membri per la creazione di ambienti nazionali di prova normativi per i sistemi di intelligenza artificiale.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/lai-act-sara-modificato-prorogato-al-2028-lo-stop-per-i-modelli-ad-alto-rischio/575606/




Trump admin tries to block Clean Air Act lawsuit over xAI’s gas turbines

The Trump administration is trying to help Elon Musk’s xAI Corp. beat a Clean Air Act lawsuit filed by the National Association for the Advancement of Colored People (NAACP). The US said the NAACP lawsuit threatens an xAI data center that powers Grok systems needed by the military.

The NAACP sued xAI and subsidiary MZX Tech in April, alleging that they violated the Clean Air Act by operating 27 gas turbines without an air permit in Southaven, Mississippi. The number of unpermitted turbines rose to 57 by mid-May and there were plans to install two more, the NAACP said in a June 12 filing.

“Defendants’ Colossus Gas Plant powers xAI’s nearby Colossus 2 data center, which in turn powers the chatbot ‘Grok,’” the lawsuit said. The gas turbines have fueled both health concerns and noise complaints.

US Department of Justice lawyers urged a federal judge to dismiss the case in a filing yesterday. The Mississippi Department of Environmental Quality determined that the turbines don’t require permits, the US filing said.

The lawsuit “threaten[s] artificial-intelligence innovation, plus the energy needed to power it,” the US filing said. “The NAACP’s attempt to cut off the power that supports Grok also threatens national security because… Grok provides critical support for the Department of War’s military operations.” The US court filing said xAI’s Grok Gov Model aided targeted strikes in Iran during Operation Epic Fury.

Grok was used with Maven Smart System to help US forces “deploy over 2,000 munitions to 2,000 distinct targets within 96 hours during Operation Epic Fury, a testament to the greatly increased operational efficiency made possible by the Grok Gov Model,” according to a declaration by Cameron Stanley, chief digital and artificial intelligence officer for the Department of War. The Grok Gov Model has unique features not found in any other AI model, he wrote.

US helping xAI break the law, group says

The US is arguing “that xAI should be allowed to break the law solely because the Trump administration says so,” said the Southern Environmental Law Center (SELC), which represents the NAACP in the case.

https://arstechnica.com/tech-policy/2026/06/trump-admin-helps-xai-fight-pollution-lawsuit-says-military-needs-grok-for-war/




I Had 1,000+ Pokémon Cards to Sell — So I Built an App That Lists Them in My Store and Promotes Them via Buffer

I collect vintage Pokémon cards, and they’re quite hard to get a hold of. Often, the card I needed was only available in a bulk lot someone was selling. So, through trying to source cards for my own collection from old box sets and starter packs, I ended up with a lot of “spare” cards.

Selling the spares started as a side hobby, but I soon built up an inventory of over 1,000 cards and realized I needed a better process to keep the logistics smooth and manageable.

Each one needed:

  1. its own listing with the right name, set, edition, condition, and clear photos of the front and back.
  2. a description that would make sense to a buyer.
  3. a social post or two, otherwise nobody beyond the people already searching for that exact card would see it.

The cards themselves were the fun part, but doing them one at a time across hundreds of cards quickly became a part-time job I didn’t sign up for.

I also noticed that social was the first thing I’d skip when it got tedious, which meant cards would end up listed and live but invisible to anyone who wasn’t already looking for them. A listing nobody sees doesn’t sell, especially with collectibles, where most demand comes from feeds and fan accounts rather than the marketplace itself.

So I built a Mac app that handles the whole pipeline end-to-end and feeds listings on my own website. Here’s how I did it:

The thing about Pokemon card collectors (and why I needed a simpler social workflow)

When I first started selling, everything went through eBay, and eBay has gotten really good at the listing-creation side of things. The platform can suggest a title, pre-fill some of the item specifics, and do a lot of the description heavy-lifting for you. That’s a huge time-saver for a seller listing one item at a time, who doesn’t mind waiting a while for buyers to naturally come across their wares in a few days or weeks.

The Pokémon card market works a little faster than, say, selling “gently-used” shoes. Pokémon card buyers don’t typically hunt for their dream card on a marketplace. They follow card accounts on Threads and Instagram, they bookmark dealers they trust, they spot a card in a feed, and click through. Social promotion is half of what makes a listing sell. And sometimes more than half, depending on the card.

Of course, there’s a lot of work that goes into manually sharing one card on social — never mind 1,000. I found myself craving a way to simplify that admin, like a built-in connection between the listing and social post processes. This turned out to be the perfect use case for the new Buffer API I’d been working on.

The Buffer API was the missing piece that turned this from a tool to just create listings into a tool that sells cards.

With this system, each listing (and its promotion) lives in one flow. Scheduling matters as much as posting. Buffer drops the posts when my audience is actually online (based on our own Best Time to Post data, which you can now find right in your publish dashboard), rather than at 11 pm on a Sunday when I happened to finish photographing a stack.

Here’s a closer look at how I closed the gap between the listings and sales.

How the app works

The (as yet nameless) app lives on my Mac, and the whole flow starts with a drag-and-drop. Here’s what a typical session looks like.

A zip of photos goes in

Originally, I built this to handle one card at a time. I’d chuck a front photo and a back photo into the app, Claude would do its thing, and I’d publish from there. It worked fine, but working through a pile this size one pair at a time was almost as tedious as listing them manually, so I added zip-file support.

Now I shoot the cards in my little lightbox in batches, pair the photos so each card has a front shot and a back shot, zip the whole lot up, and drag the zip into the app. The app sorts the photos by filename and automatically groups them into pairs.

The upload screen also has a newer addition: a selector for where the batch should publish. When I first built the app, everything went to eBay; now I can choose eBay, WooCommerce, or both at once. It’s quite modular, so if I added another provider in the future, like Shopify, it would just be another option in the list.

In practice, I tend to do batches of around 50 cards at a time. It takes a little while for the AI to work through, but that’s fine.

With this system, I can drop the zip folder in, walk away, and come back once it’s done.

Claude reads each card

This is the slowest part of the flow, but easily the most useful one. The app sends each pair of photos to Claude, which pulls out the structured details I need for the listing: card name, set, card number, rarity, edition, language, holo or non-holo, and condition.

Condition is the field I cared about most. I used to have to spend the longest part of a listing session just squinting at corners and edges, trying to weigh up whether a card was Lightly Played or Heavily Played. Now Claude makes the call, and I just confirm whether it’s accurate or not.

Sometimes the condition isn’t quite right, and the ratings need to be nudged up or down because my photo isn’t great or the lighting in my lightbox fooled it. I’ll change that before approving the listing, but it’s usually accurate enough that I’ve stopped manually reviewing every single field. I trust Claude on the easy stuff and only look closely at the calls I’d second-guess anyway.

The listing details fill themselves in

Once Claude has done its pass, every field on the listing form is already populated: title, description, condition note, item specifics, set, number, rarity, and language. The little “AI” badge next to each field is the only visual reminder that I didn’t type any of this.

The only thing I set manually at this point is the price. I’ve been looking at card market data APIs like TCGdex that could pull recent sold prices and active listings for the same card, with the goal of suggesting a number based on actual market data rather than my best guess. I haven’t found one I’m happy with yet, so for now, the price stays the one piece of human judgment in the flow.

Publish in a specific order

When the prices are in, I hit “publish all priced ones,” and two things happen in sequence.

First, the app creates the product in my store through the WooCommerce API (when I started, this step created an eBay listing instead). That has to go first, because the next step needs the live product URL.

Then the app builds a social post with the

  • card name,
  • set,
  • condition note,
  • the front and back photos

Then, it queues the post through the Buffer API across whichever channels I’ve selected. Threads gets a direct link to the listing in the post — the newer ones read “now on our store” and link straight to the product page. Instagram, where you can’t drop a clickable link in the body of a post, points to the link in bio instead.

The workflow that used to live across three apps: the marketplace, my photos folder, and a separate mental note to post on Threads later, now lives in one approval.

⚡One thing I purposely kept in the workflow is a single-card mode. If a card is rare or valuable, I don’t want to bulk-publish it alongside fifty Common cards from a Base Set. I want to look at the photos and read Claude’s description closely, set the price more thoughtfully, and then run it through. Full automation is the right default for the bulk of what I’m selling, but it’s not always what you want.

What started on eBay has grown into a store of its own

I sold through eBay for the first stretch of this project, and it served me well. The older posts in my Buffer queue still point to live eBay listings, and I’ve kept those products up for that reason. But it felt important to me to have my own brand and my own space to experiment, so I set up Shadowless, a WooCommerce store, and pointed the app at it. Because the publish step was already modular, WooCommerce support was about half a day of work on top of the eBay version.

I’m most pleased with what happens to all those details Claude pulls from the photos. Every field — set, card number, rarity, edition, language — becomes a filterable attribute on the store. A buyer who only collects Rare cards from the Fossil set can filter down to exactly those cards, which is the kind of browsing experience I’d always wanted to offer buyers and could now actually build. Those attributes would have taken me ages to fill in manually, and they’re what makes the store feel like a card shop rather than a long list.

Running my own store does mean the marketing is on me too. I’m still building up traffic, and that’s a whole other project, but the listings and the social promotion were already handled the day the store went live, because the app didn’t have to change.

And then I leave it alone

The process I’ve settled goes something like this: I photograph a stack of cards on a Sunday afternoon, drop the zip into the app, set the prices when Claude finishes its pass, hit publish, and walk away. The listings go live on the store, the Buffer posts go into the queue at the times I’ve already set up — two a day to Threads and Instagram — and I get on with my evening.

My Buffer queue is sitting at over 1,000 posts now, so I’m not losing my streak any time soon. And for all the Claude image analysis behind the 1,310 products in the store (so far), I’ve spent maybe $15 to $20 in total.

The parts I’m still working on

The pricing step is the next thing I want to crack, which is the main reason I’ve been digging into card market APIs. The market moves constantly, and I don’t want to be overcharging anyone, so I’d rather keep this step manual than get it wrong. Once a data source I’m happy with is in, the last manual step in the bulk flow is gone.

The other wrinkle is stock. Some cards have started selling before their scheduled posts go out, which means a post can point to a card that’s no longer available. I’m thinking about a script that watches for stock changes and tracks down the corresponding Buffer post, but there are some complexities there I haven’t worked out yet.

Takeaways for selling anything physical

The Pokémon card-angle is my version of this story, but you can think of this flow beyond cards. It’s how any small seller can make more of their work automatic. Here are four things you can do.

  1. Pull structured details from your photos with AI vision. Whether it’s Claude, GPT-4, or Gemini, pick whichever vision model you trust. The key is asking for structured output (for example, a JSON object with the fields you actually need) rather than a short description. Structured output is what lets the next step in the pipeline consume it without you having to parse anything by hand.
  2. Connect to your marketplace’s API. Most of the platforms a small seller might use (eBay, Etsy, Shopify, Mercari, WooCommerce) have one. The docs are usually rougher than you might hope for, and the listing-creation endpoint is the part that takes the longest to get right, but it’s the only endpoint you really need. And if you choose to build the publish step yourself, adding a second destination is cheap. WooCommerce took me about half a day on top of the eBay version, and that same half day is what now runs my own store.
  3. Close the loop with the Buffer API. Once the marketplace listing is live, use the listing URL to automatically generate a social post with an image, a short caption, and the link. Then queue it through Buffer across whichever channels are right for what you sell. This is the step that’s easiest to skip when you’re building, and it’s the one that turns a listing into a sale.
  4. Keep a manual override. Full automation is the right default for the bulk of items, but add in a single-item review mode for the cases that warrant it. A high-ticket item still needs human eyes.

Listing a product and promoting it should be the same action rather than two separate workflows. Once you wire those together, the time you spend per item drops to seconds, and your products (cards in my case) stop sitting in a box in the corner of your room.

Ready to build?

If you’re taking Buffer’s API for a spin, we’ve got resources to get you moving. Our developer docs cover the GraphQL schema, auth flow, and quick-start examples. The Buffer MCP server docs walk through plugging it into Claude or any MCP-compatible AI agent.

If you need hands-on help, our support team is around, or you can join our Discord server and chat to other people building with the API.

We’d love to hear about what you make. Find us in our Discord server, or @buffer on all major social channels.

https://buffer.com/resources/pokemon-cards/




Indipendenza digitale, la proposta della Commissione scontenta tutti. Critiche incrociate da Europarlamento e Big Tech Usa

Il pacchetto di provvedimenti annunciato dalla Commissione Ue per spingere l’uso di tecnologie europee e allentare la dipendenza dal tech made in Usa, che pesa per l’80% sul totale del parco tecnologico nel Vecchio Continente, è stato accolto da forti critiche interne (da parte dell’Europarlamento) ed esterne (le Big Tech americane, bersaglio per quanto mascherato dell’offensiva).  

Le due proposte legislative, una dedicata alla produzione di microprocessori (Chips Act 2.0) e l’atro con l’obiettivo di sviluppare l’AI per il Cloud a livello europeo (CADA, Cloud and AI Development Act) ha sollevato non poche rimostranze, a partire dall’Europarlamento. Del pacchetto fanno parte anche misure open source, ma anche di efficienza energetica.

Il piano dell’esecutivo UE, ad ogni modo, dovrà incassare il sostegno dei 27 paesi del blocco e del Parlamento europeo nei prossimi mesi.

Pacchetto per favorire digitale made in Europe

Henna Virkkunen, commissaria europea alla Sovranità Digitale, ha presentato il pacchetto che esclude i giganti statunitensi come Amazon, Microsoft e Google dalle gare d’appalto cloud più sensibili, incoraggiando al contempo una rapida realizzazione di data center che utilizzino almeno in parte hardware o software europei. Per quanto riguarda i chip, il piano non si concentra tanto sull’attrarre impianti all’avanguardia, quanto sul sostenere i punti di forza esistenti del principale produttore di apparecchiature per chip ASML, dai materiali al packaging avanzato, sfruttando la domanda pubblica per aiutare le startup a crescere.

Ma con pochi campioni europeo, ridurre la dipendenza non sarà facile. Il blocco non ha una versione europea di Nvidia per la progettazione di chip per l’intelligenza artificiale, nessun concorrente della taiwanese TSMC per la loro produzione, e nessun gigante del software paragonabile ai grandi hyperscaler in grado di guidare la domanda attraverso vaste piattaforme Cloud.

Requisiti di sovranità in settori sensibili come banche, energia e sanità

La spinta verso requisiti di sovranità in settori sensibili come quello bancario, energetico e sanitario è motivata dalle preoccupazioni per il dominio dei giganti tecnologici statunitensi, nonché da timori relativi a leggi come il Cloud Act, che obbliga i fornitori con sede negli Stati Uniti a concedere alle autorità l’accesso ai dati anche se archiviati all’estero.

Criteri di sovranità negli appalti pubblici

La proposta dell’UE, finora inedita e che potrebbe subire modifiche dell’ultimo minuto, introduce anche criteri “non di prezzo” obbligatori per gli appalti pubblici, inclusi requisiti per software e hardware sviluppati all’interno dell’UE, il che svantaggerebbe le grandi aziende tecnologiche statunitensi.

Proposta troppo morbida per l’Europarlamento

La proposta è carente, dice Kim van Sparrentak, eurodeputato dei Verdi, che non considera abbastanza severo il provvedimento per assicurare l’indipendenza digitale dell’Europa a lungo termine.

Secondo i detrattori, scrive Politico.eu, la proposta della Commissione è forte nelle intenzioni ma debole nel confronto diretto con el big tech come Google, Microsoft e Amazon.

“La proposta resta troppo permissiva”, dice Christophe Grudler, europarlamentare centrista già in prima linea nella battaglia contro Starlink e l’invadenza extra Ue nel settore satellitare. Per Grudler il pacchetto lascerebbe ancora spazio alle aziende estere per offrire servizi a fette molto delicate e sensibili dell’economia europea.

L’Europarlamento ha così già manifestato apertamente l’intenzione di tentare di rimodellare la proposta.

Il CADA cuore del pacchetto

Il Cloud and AI Development Act (CADA), che rappresenta di fatto il cuore del pacchetto presentato nell’independence Day, introduce una certificazione su quattro livelli che le autorità pubbliche dovrebbero utilizzare per valutare strumenti digitali in base alla loro vulnerabilità a interferenze straniere. In alcuni casi, gli enti pubblici potrebbero essere costretti a sostituire servizi stranieri con alternative europee nel nome del principio del “Buy European”.

Ma larghe fasce del mercato europeo potrebbero comunque restare aperte ai giganti americani. Anche perché il fatto di bloccarli dipenderebbe dalla volontà dei singoli paesi europei di fare arrabbiare Trump.

“Avrei voluto sentire più chiaramente dalla Commissione che gli Stati Uniti non sono più un partner affidabile per il settore pubblico europeo, così come non lo è la Cina”, ha detto Aura Salla, membro del Parlamento europeo di centro-destra, alla commissaria europea per la tecnologia, Henna Virkkunen, durante un’audizione in commissione dopo la presentazione del pacchetto.

Big Tech sulle barricate: un danno per le organizzazioni Ue

Sul fronte opposto delle Big Tech è già partita la protesta, nonostante il tentativo di Bruxelles di depurare al massimo l’idea che il pacchetto sia specificamente anti-americano.

“L’attenzione della proposta su criteri geografici e di nazionalità non favorisce risultati efficaci in termini di sovranità”, ha detto Guido Lobrano, direttore generale per l’Europa dell’Information Technology Industry Council, un’associazione di categoria che annovera tra i suoi membri Amazon, Meta, Google e Microsoft.

Lobrano è stato raggiunto dalle parole di Harry Staight, portavoce di Amazon: “Le organizzazioni europee meritano di avere accesso alla migliore tecnologia disponibile da fornitori affidabili, scelti in base a sicurezza, prestazioni, controlli verificabili e rapporto qualità-prezzo”.

Insomma, il tentativo di Henna Virkkunen, commissario Ue alla Sovranità Digitale, di togliere l’etichetta di protezionismo anti-americano al pacchetto appena predentato è fallito sul nascere.

Mentre Virkkunen presentava il piano mercoledì, racconta Politico che gli ambasciatori dell’UE, riuniti dall’altra parte della strada, stavano approvando una proposta della Commissione per l’adesione dell’UE a Pax Silica, un nuovo club guidato dagli Stati Uniti volto a garantire le catene di approvvigionamento dell’intelligenza artificiale in chiave anti cinese.

CCIA attacca: “Carta bianca alle capitali Ue per escludere le Big Tech”

Daniel Friedlaender, responsabile della sede di Bruxelles del gruppo di pressione tecnologico CCIA, tra i cui membri figurano Google, Meta, Uber e Airbnb, ha affermato che la proposta “di fatto concede alle capitali nazionali carta bianca per escludere fornitori globali affidabili provenienti da tutti i principali paesi produttori di tecnologia al di fuori dell’Unione”.

Se la legge diventerà uno strumento per estromettere i giganti tecnologici statunitensi o un trampolino di lancio per i campioni europei dipenderà da quanto Bruxelles e le capitali dell’UE saranno disposte a spingersi oltre i propri poteri. Tuttavia, il percorso attraverso i negoziati tra il Parlamento e i governi nazionali dell’UE potrebbe essere lungo e accidentato.

I ministri del digitale dell’UE dovrebbero esprimere il loro parere durante il loro incontro in Lussemburgo la prossima settimana, e potrebbero reagire negativamente a una proposta che potrebbero considerare un’ingerenza nei loro poteri decisionali e nelle prerogative nazionali.

Bitcom (Confindustria digitale tedesca), passare dalle parole ai fatti

“È fondamentale che questi sforzi non si fermino a semplici annunci. L’Europa deve agire rapidamente”, sostiene dal canto suo Bitcom, la Confindustria digitale tedesca. Henna Virkkunen, commissaria europea per la tecnologia, ha presentato il pacchetto che esclude i giganti statunitensi come Amazon, Microsoft e Google dalle gare d’appalto cloud più sensibili, incoraggiando al contempo una rapida realizzazione di data center che utilizzino almeno in parte hardware o software europei. Per quanto riguarda i chip, il piano non si concentra tanto sull’attrarre impianti all’avanguardia, quanto sul sostenere i punti di forza esistenti del principale produttore di apparecchiature per chip ASML, dai materiali al packaging avanzato, sfruttando la domanda pubblica per aiutare le startup a crescere.

Ma con pochi campioni regionali, ridurre la dipendenza non avverrà rapidamente. Il blocco non ha una versione europea di Nvidia per la progettazione di chip per l’intelligenza artificiale, nessun concorrente della taiwanese TSMC per la loro produzione, e nessun gigante del software paragonabile alle grandi aziende statunitensi in grado di guidare la domanda attraverso vaste piattaforme cloud.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/indipendenza-digitale-la-proposta-della-commissione-scontenta-tutti-critiche-incrociate-da-europarlamento-e-big-tech-usa/574167/




Indipendenza digitale, come creare il Fondo europeo per partire

Cloud e AI, la strategia europea c’è. Ma ora Bruxelles deve trovare i soldi

La Commissione europea ha presentato la sua strategia per rafforzare la sovranità tecnologica dell’Unione nel cloud e nell’intelligenza artificiale (AI). L’obiettivo politico è chiaro: ridurre la dipendenza da un numero ristretto di fornitori extraeuropei (in particolare quelli americani) e costruire capacità proprie in infrastrutture, calcolo, data center e servizi AI. La vera questione, adesso, è come finanziare questa ambizione.

Qualcosa su questo si trova nei documenti allegati alla proposta di Cloud and AI Development Act, o CADA, in cui Bruxelles non propone un fondo sovrano già pronto all’uso, perchè non c’è e va costruito. Disegna invece un modello di finanziamento ibrido da cui partire, che combina programmi europei esistenti, contributi degli Stati membri e investimenti privati, rinviando la piena scala industriale al prossimo quadro finanziario pluriennale. E qui si giocherà la vera partita della futura autonomia finanziaria dell’istituzione europea.

Il regolamento è esplicito: le iniziative per il cloud e l’AI “may be supported by funding from Union programmes and other instruments”, in particolare Horizon Europe, il Digital Europe Programme e InvestEU. La Commissione aggiunge che le stesse iniziative “may be supported by Member States” e anche da “private-sector investments”. In altre parole, non un unico fondo centrale, per il momento, ma una costruzione graduale di risorse pubbliche e private coordinate tra loro.

Virkkunen (Ue): “Creare capacità di investimento europea per sostenere le nostre migliori imprese nella competizione globale”

Il percorso l’ha ben illustrato la Vicepresidente esecutiva per la Sovranità tecnologica, la sicurezza e la democrazia, Henna Virkkunen, nel suo discorso in occasione della presentazione della strategia europea: “L’Europa sta perdendo terreno nella corsa tecnologica globale perché ha bisogno di più investimenti ad alto rischio nel settore dell’innovazione. Mentre i principali competitor internazionali stanno mobilitando ingenti capitali, il continente si trova ad affrontare un crescente deficit di investimenti strategici.
I finanziamenti pubblici rappresentano un punto di partenza importante, ma non possono essere i contribuenti a sostenere da soli questo sforzo. Se l’Europa vuole rafforzare la propria sovranità tecnologica e mantenere il controllo del proprio futuro digitale, è indispensabile che anche il capitale privato aumenti il proprio impegno, sostenendo i progetti più ambiziosi e strategici
”.

“Per colmare questo divario, la Commissione europea avvierà con effetto immediato una consultazione con gli Stati membri, il Gruppo Banca europea per gli investimenti (BEI) e i principali attori del settore finanziario.
L’obiettivo è chiaro: creare una capacità europea di investimento in capitale di rischio su larga scala, in grado di garantire alle migliori imprese tecnologiche europee le risorse necessarie per competere e affermarsi sui mercati globali
”, ha sottolineato la Vicepresidente della Commissione.

È qui che molti hanno letto tra le righe il richiamo ad un “fondo sovrano europeo” che poi sarebbe chiamato ad investire direttamente nelle società tecnologiche (ma anche energetiche e di altri settori strategici) con maggiori possibilità di competere a livello globale. Una sfida significativa, ma che probabilmente è nelle corde della Commissione e dell’Unione tutta.

Un modello ‘ibrido’ a tre livelli

Tornando al modello di finanziamento ibrido al momento individuato dalla Commissione, c’è già un primo livello di risorse europee disponibili. La Commissione punta su programmi esistenti per finanziare ricerca, sviluppo, infrastrutture e prima adozione industriale delle tecnologie cloud e AI. È un passaggio importante, perché mostra che Bruxelles non parte da zero, ma prova a riallocare strumenti già in essere verso gli obiettivi di sovranità tecnologica.

Il secondo livello è quello nazionale. Il testo prevede che gli Stati membri possano sostenere la strategia con misure di ricerca, sviluppo e innovazione, nel rispetto delle regole sugli aiuti di Stato. Questo significa che la Commissione immagina un cofinanziamento pubblico distribuito, in cui i governi nazionali restano parte attiva del processo, soprattutto nei progetti infrastrutturali e nei poli strategici.

Il terzo livello è quello del capitale privato. La Commissione chiede agli operatori industriali e finanziari di tenere conto della strategia nelle loro decisioni di investimento. Qui il messaggio è chiaro: l’obiettivo non è soltanto attrarre capitali, ma orientarli dentro un quadro coerente con le priorità europee, evitando frammentazione e duplicazioni.

Il ruolo del futuro fondo sovrano e un meccanismo di priorità nei finanziamenti

La parte più interessante del testo è però quella che collega la strategia al futuro European Competitiveness Fund. Nel considerando 43 si legge che i “data centre strategic projects” dovrebbero ricevere sostegno da programmi, fondi e strumenti finanziari dell’Unione, in linea con gli obiettivi dei singoli strumenti e senza pregiudicare il prossimo bilancio pluriennale 2028-2034.

Il passaggio più rilevante è quello in cui si afferma che questi progetti dovrebbero ottenere il “competitiveness seal” se soddisfano le condizioni previste dal futuro European Competitiveness Fund, cioè se sono considerati progetti di alta qualità che contribuiscono agli obiettivi del fondo.
Di fatto, si sta ragionando su un marchio di qualità da attribuire a progetti considerati validi e strategici, così da facilitarne il finanziamento con altre risorse pubbliche o private anche se non (ri)entrano direttamente nel programma UE originario.

In sostanza, la Commissione sta creando un meccanismo di priorità per far entrare i progetti cloud e data center nel perimetro dei futuri finanziamenti europei.

Questo non significa che il fondo sovrano esista già in forma pienamente operativa. Significa però che la Commissione ne sta preparando la funzione: selezionare, premiare e indirizzare i progetti industriali ritenuti strategici per la competitività europea. È un tassello fondamentale della strategia, perché lega la sovranità tecnologica non solo alla regolazione, ma anche alla futura architettura finanziaria dell’Unione.

Una strategia ancora da finanziare

Il punto politico resta lo stesso: la Commissione ha definito l’orizzonte, ma non ha ancora chiuso il capitolo delle risorse. Il documento mostra una scelta precisa: utilizzare i fondi UE esistenti nel breve periodo, coinvolgere gli Stati membri e il capitale privato nel medio periodo, e agganciare la piena scala industriale al prossimo quadro finanziario pluriennale.

È una costruzione pragmatica, ma anche una prova di forza. Perché la sovranità tecnologica non dipende solo dagli obiettivi industriali o dalle regole sul mercato, ma dalla capacità di mettere insieme risorse sufficienti per sostenere data center, cloud e infrastrutture AI su scala continentale.

In questo senso, il Cloud and AI Development Act è insieme una strategia industriale e una promessa finanziaria ancora da completare, che peraltro dovrà fare i conti con le solite divergenze interne ai 27 Stati dell’Unione. Accetteranno di contribuire a livello finanziario? Condivideranno l’impostazione generale di questa architettura finanziaria? Saranno favorevoli ad aumentare la dote finanziaria dell’Unione? C’è anche da chiedersi se condividono a pieno gli obiettivi della strategia. La Commissione ha aperto il cantiere; ora deve trovare il modo di finanziarlo davvero e di convincere tutti e 27 a mettersi a lavorare.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/indipendenza-digitale-come-creare-il-fondo-europeo-per-partire/574149/




Google ordered to put clearer links in AI search and let UK publishers opt out

UK regulators today ordered Google to put clearer attributions and links to publishers’ content in its AI-generated search features. The UK’s Competition and Markets Authority (CMA) also said Google must give publishers a way to opt out of AI features in search.

“In a world first, publishers will now have effective tools to prevent their content being used to power AI features in search, such as AI Overviews,” the CMA said today. “This will put publishers, like news organizations, in a stronger position to negotiate content deals with Google. To boost consumer trust, Google is also now required to make sure that publisher content is properly attributed, using clear links, in AI‑generated search results.”

The CMA ruled that Google may not penalize publishers for opting out of AI, meaning that Google can’t downrank opted-out publishers in general search results. The CMA said Google will have nine months to comply with all requirements but that the agency “expects important parts of the controls to become available to publishers well before that deadline. Google will also be required to submit and publish compliance reports, supported by key data and metrics, explaining changes it has made and how it has complied.”

Google’s AI Overviews tend to give confident-sounding responses to search queries, but the links to sources in the AI Overviews may or may not support those confident responses. Clearer attribution and links could make it easier for searchers to determine the accuracy of AI Overview summaries.

The CMA applied the rules to Google after determining that it has “strategic market status” in general search services, and has ongoing investigations into Apple and Microsoft. Google today said it will comply with the CMA decision.

https://arstechnica.com/tech-policy/2026/06/google-ordered-to-put-clearer-links-in-ai-search-and-let-uk-publishers-opt-out/




Google’s new Gemma 4 12B model is designed to run on any laptop with 16GB of RAM

Gemma 4 benchmark graph

Gemma 4 12B is almost as capable as the version with 26 billion parameters.

Credit: Google

Gemma 4 12B is almost as capable as the version with 26 billion parameters. Credit: Google

Google says the new model is capable of complex multistep reasoning and agentic workflows that previously required the larger Gemma variants. Despite the smaller parameter count, Gemma 4 12B comes with the newly devised Multi-Token Prediction (MTP) drafters, which take advantage of unused processing cycles to calculate possible future tokens. The result is greater speed and efficiency. Google has released optional MTP versions of the other Gemma 4 models, but this is the first one to have MTP out of the box.

Gemma 4 12B is also more efficient thanks to a new approach to multimodality. The Gemma 4 family is natively multimodal, accepting text, audio, or images as inputs. Most gen AI models—including the other Gemma 4 variants—use dedicated encoders to process non-text inputs and pass that data to the LLM. This works well enough, but it increases latency and memory usage.

With the new mid-weight model, Google has implemented a streamlined embedding module for vision, featuring single-matrix multiplication and positional embedding, which allows the data to pass to the LLM with proper spatial awareness. This eliminates the need for a bulky middleman encoder. For audio, there’s no encoding at all. The developers worked out a method of projecting the raw audio signal into the same vectors used for text tokens.

[embedded content]

Gemma 4 12B Demo

If you want to check out the new Gemma 4 model, it’s accessible without a download via tools like LM Studio, Google AI Edge Gallery, and more. But the whole idea with Gemma 4 12B is that you can run it locally and on your own terms. If you’ve got the RAM, the model weights are available for download immediately on Kaggle and Hugging Face. It’s just shy of 18GB.

https://arstechnica.com/google/2026/06/googles-new-gemma-4-open-ai-model-is-sized-for-your-laptop/