Trump plan to test AI models has a problem—US security teams were gutted by DOGE

Once covered models are defined, Nguyen then warned that the effectiveness of the safety testing will likely depend on whether AI firms are fully transparent and treat the process as a “genuine collaboration.”

“Underneath the definitional problem sits an observability problem,” Nguyen wrote. “The government cannot assess what it cannot see, and frontier capabilities are visible only to the labs that build them.”

Ferren suggested that “the window for erecting proper cyber defenses to new AI models may also close quickly,” and that even a well-designed government program may struggle to properly vet frontier models in such a short timeframe. “Even when well implemented, pre-deployment testing has limits,” Ferren said, noting that Google’s threat intelligence team has found state-aligned actors using frontier models to automate cyberattacks and “researchers have shown that Mythos-style vulnerability reasoning can be reproduced with open-weight systems.”

So while AI may voluntarily submit to testing, they may be financially motivated to seek a rubber-stamp, rather than work with the government to test known frontier capabilities to their fullest extent.

“It will likely prove difficult to develop models that are incapable of malicious hacking yet remain commercially compelling,” Ferren said.

He concluded that the EO “may yield short-term cybersecurity benefits,” but the “long-term effect” remains “unclear.”

Nguyen suggested the EO takes necessary steps to create “classified cyber benchmarking, voluntary prerelease evaluation, and coordinated vulnerability scanning” that “the national security community will need for decades” to “continuously evaluate systems that are probabilistic rather than deterministic, autonomous rather than directed, and whose capabilities change with every update.”

But the safety testing will have to evolve as fast as the technology does, Nguyen said, otherwise we risk assessing emerging models against “yesterday’s risks.”

That’s why, at its core, the process will depend on an honest exchange between stakeholders with deep technical expertise and confidential national security insights. It’s the only way to ensure the US focuses its energies on protecting the public from the most credible and consequential AI risks, rather than just providing “performative reassurances,” Nguyen wrote.

https://arstechnica.com/tech-policy/2026/06/trumps-ai-executive-order-may-not-prevent-dangerous-deployments/




Inside Meta’s attempts to play catch-up with AI

Several people said Wang had also advocated placing greater emphasis on proprietary models over Meta’s longstanding open source approach.

Wang has tried to build support for his vision by cultivating a non-hierarchical start-up culture inside TBD. On a recent podcast, he argued that “the very small team where everyone is ‘cracked’ is always going to move faster than the large org where responsibility is distributed,” using gamer slang to describe highly talented engineers.

He also hosts regular boba tea-fuelled happy hours to foster camaraderie inside the secretive group, according to insiders.

Meta’s broader workforce has experienced a less convivial period. Wang’s first year has coincided with restructurings and rounds of layoffs across the company, seeking to offset the cost of its AI spending spree.

Some employees have also protested company plans to install tracking software that would capture their computer usage in order to train AI models. Meta on Tuesday told staff in a memo, seen by the FT, that it would roll back parts of the plan following the backlash.

Muse Spark has also been deployed primarily inside Meta’s own products, making it difficult for outsiders to assess. Wang had indicated that some external companies would receive access through a private API, but that rollout has been limited.

The model was trained using some third-party open-source models, including Chinese ones. Some insiders have compared aspects of the system with DeepSeek’s latest model, although the extent of any similarities remains disputed.

Muse Spark has been praised for visual understanding, but Wang has acknowledged it trails rivals in coding. Several employees said staff asked to test the model for software development tasks continued to prefer Anthropic’s Claude.

Future Meta models are expected to focus on coding, completing agentic tasks, and more advanced multimodal capabilities, including video generation.

“It was a rough start for him to find his power at the company,” said one associate. “But he’s found his groove.”

© 2026 The Financial Times Ltd. All rights reserved. Not to be redistributed, copied, or modified in any way.

https://arstechnica.com/ai/2026/06/inside-metas-attempts-to-play-catch-up-with-ai/




Indipendenza digitale europea, la Commissione presenta 4 misure. Von der Leyen: “Non possiamo dipendere da altri”

Von der Leyen (Ue): “Non possiamo permetterci di dipendere da altri”. Il pacchetto per la sovranità tecnologica

Presentato il tanto atteso pacchetto europeo sulla sovranità tecnologica, con le misure volte a rafforzare la capacità dell’Unione europea in materia di semiconduttori, intelligenza artificiale (AI), cloud e open source, ma anche di efficienza energetica.

“Non possiamo permetterci di dipendere da altri per le tecnologie che mantengono in funzione i nostri ospedali, le nostre reti energetiche stabili e i nostri servizi sicuri. Si tratta di proteggere i nostri cittadini, difendere i nostri interessi e fare le nostre scelte. L’Europa ha il talento, l’eccellenza della ricerca, la base industriale e il mercato unico. Insieme, dobbiamo trasformare questi punti di forza in sovranità tecnologica”. Ha dichiarato la Presidente della Commissione europea, Ursula von der Leyen.

I punti chiave del pacchetto comprendono: la legge sui chip 2.0 e la legge sullo sviluppo del cloud e dell’IA, la strategia open source e una tabella di marcia strategica per la digitalizzazione e l’AI nel settore dell’energia.

Il cloud computing è uno dei settori in cui la dipendenza europea è più evidente. Attualmente, le piattaforme statunitensi dominano il mercato. I tre principali fornitori (Microsoft, Amazon Web Services e Google) detengono circa il 70% del mercato europeo.
Secondo un rapporto del 2025 della società di consulenza francese Asteres, l’Unione europea spende circa 264 miliardi di euro all’anno per l’acquisto di software per il cloud computing che è sviluppato negli Stati Uniti.

Si rilancia e si torna di fatto il tema ineludibile dell’indipendenza digitale. Come ha spiegato il nostro direttore Luigi Garofalo nei giorni scorsi: “La Commissione Europea ha capito che dal punto di vista dell’innovazione tecnologica l’Europa deve iniziare ad agire in modo autonomo. Non più solo a normare, ma a fare innovazione – oggi dipende dal punto di vista digitale per l’80% da fornitori extra-UE – e a creare un’offerta tecnologica “made in Europe”, facendo crescere, allo stesso tempo, la domanda di Pubbliche Amministrazioni e aziende verso “uno stack tecnologico europeo completo”, con servizi e infrastrutture realizzati da aziende europee“.

Chip 2.0, serve una produzione made in Eu

Oggi, ha precisato Ursula von der Leyen, “per oltre l’80% dei nostri prodotti, servizi e infrastrutture digitali, ci affidiamo a fornitori extra-UE“. “Chi promuove l’innovazione tecnologica plasmerà il futuro, e noi dobbiamo garantire che l’Europa svolga un ruolo di primo piano in questo processo. La sovranità tecnologica non significa protezionismo. L’Europa rimane fondata sui principi di apertura, partenariato e concorrenza leale – ha aggiunto la Presidente della Commissione – ma vogliamo essere in grado di fare le nostre scelte, evitando di dipendere da fornitori unici e dominanti, soprattutto provenienti da paesi che non condividono la sua stessa visione“.

“Il pacchetto odierno ha tre obiettivi fondamentali: trasformare la nostra economia promuovendo l’adozione di nuove tecnologie e dell’intelligenza artificiale; rafforzare la resilienza delle nostre catene di approvvigionamento; promuovere il modello europeo di sovranità tecnologica“, ha precisato von der Leyen.

Obiettivi saranno raggiunti attraverso quattro azioni contenute nel pacchetto sulla sovranità tecnologica: la legge Chips 2.0; la legge sullo sviluppo del cloud e dell’intelligenza artificiale; una strategia europea per l’open source; una tabella di marcia strategica per la digitalizzazione e l’intelligenza artificiale nel settore energetico.

La normativa sui semiconduttori o Chips Act 2.0 è finalizzata a rispondere prontamente alle vulnerabilità critiche nella catena di approvvigionamento globale dei semiconduttori, dato che l’Europa dipende ancora fortemente dai paesi terzi per la produzione avanzata e la progettazione di chip.

Con la legge Chip 2.0 l’Ue intende accelerare le procedure di autorizzazione, approfondire la cooperazione con i partner che condividono gli stessi principi e introdurre un nuovo marchio di eccellenza per le regioni europee dei semiconduttori.

I chip sono anche un’industria globale cruciale per la crescita in Europa. Sono il terzo prodotto più commercializzato al mondo, subito dopo petrolio e veicoli. Nel 2025 il mercato è stato valutato circa 595 miliardi di euro e si prevede che continuerà a crescere, superando la soglia dei trilioni di euro entro il 2030, con componenti legati all’AI che rappresentano oltre il 70 % del mercato globale dei semiconduttori.

L’intento della Commissione è sia avvicinare i produttori di chip europei ai loro clienti, a partire dalla domanda dei settori in crescita, come i data center, i fornitori di cloud e le Gigafactory di IA, sia sostenere gli investimenti e i progetti strategici, affrontando così le vulnerabilità che potrebbero mettere a rischio l’approvvigionamento.

Promuovere lo sviluppo dell’AI e del cloud

L’obiettivo annunciato oggi è triplicare la capacità dei data center in Europa nei prossimi cinque-sette anni e rafforzare il ruolo della strategia Apply AI per promuoverne l’adozione.

Per fare questo è necessario però tenere alto il principio della sostenibilità e quindi rispettare la tabella della transizione energetica: “bilanciando nel contempo le ambizioni in materia di AI con gli impegni in materia di clima”.

La legge sullo sviluppo dell’AI e il cloud l’introduzione di un quadro unico a livello “la sovranità del cloud e dell’AI”, mantenendo comunque “un mercato aperto ai partner che condividono gli stessi principi”. Viene da chiedersi, tra questi ci saranno o no le Big Tech?

“Viviamo in un mondo in cui geopolitica e tecnologia sono inseparabili. Coloro che promuovono l’innovazione tecnologica daranno forma al futuro e dobbiamo garantire che l’Europa svolga un ruolo guida in questo senso. Il pacchetto odierno segna un importante cambiamento nel modo in cui l’Europa si avvicina alla sovranità tecnologica. È tempo che l’Europa abbia il controllo dei suoi dati, delle sue catene di approvvigionamento e del suo futuro in modo pulito e sostenibile. Stiamo rafforzando l’autonomia e la resilienza digitali dell’Europa, mantenendo nel contempo la nostra economia aperta ai partner di tutto il mondo”, ha commentato Henna Virkkunen, Vicepresidente esecutiva per la Sovranità tecnologica, la sicurezza e la democrazia.

Henna Virkkunen

Il mercato europeo del cloud e dell’AI sta crescendo rapidamente, passando da 70 miliardi di euro nel 2022 a 200 miliardi previsti entro il 2028. Queste tecnologie aumentano la produttività, migliorano i servizi pubblici e cambiano la vita quotidiana. Ad oggi, però, il loro pieno potenziale non è ancora pienamente realizzato in Europa.

La sovranità tecnologica passa per l’open source

Il pacchetto punta dritto all’open source per rafforzare l’autonomia digitale del continente: “Abbiamo oltre tre milioni di contributor open source. Forniscono soluzioni digitali realizzate in Europa, per l’Europa, sulla base di principi e valori europei”.

Seguendo questo principio, si capisce che l’Europa porterà avanti una strategia mirata a sviluppare e sostenere alternative open source in settori prioritari quali il cloud, l’AI, le tecnologie internet, la cibersicurezza e i semiconduttori.

Per ottenere un ecosistema open source più forte bisogna investire nelle competenze, sostenendo le startup open source e migliorando la manutenzione e la sicurezza a lungo termine dell’infrastruttura digitale open source europea. Altro punto chiave è il maggiore utilizzo dell’open source nelle pubbliche amministrazioni, da promuovere secondo quanto riportato nel documento ufficiale attraverso orientamenti chiari e più specifici in materia di appalti e best practice.

Dan Jørgensen

Jørgensen (Ue): “Non può esserci sovranità digitale senza sovranità energetica“

Altro problema non da poco, come abbiamo sperimentato sulla nostra pelle da qualche anno a questa parte è l’elevato costo dell’energia. Qui la Commissione vede come unica strada maestra la digitalizzazione del settore energetico dell’Unione.

Le guerre e le tensioni geopolitiche sempre più profonde ci obbligano ad agire con fermezza e rapidità, anche in considerazione dell’aumento della domanda di energia legato all’esplosione delle infrastrutture digitali necessarie a cloud e AI.

La strategia presentata oggi, è spiegato nel comunicato, stabilisce in che modo l’AI e altre soluzioni digitali possono garantire l’integrazione sostenibile dell’infrastruttura digitale critica nel nostro sistema energetico, contribuendo nel contempo a rendere più efficiente il sistema energetico dell’Unione.

“Dobbiamo integrare le infrastrutture digitali nel nostro sistema energetico in modo sostenibile. Perché non può esserci sovranità digitale senza sovranità energetica“, ha dichiarato secco Dan Jørgensen, Commissario per l’Energia e l’edilizia abitativa.

“La digitalizzazione del sistema energetico è la possibilità per l’Europa di ottenere di più dalle stesse infrastrutture di cui disponiamo e di ridurre le bollette per i consumatori. Questo pacchetto coglie questa opportunità e garantisce che la crescente domanda dei centri dati funzioni con la rete, non contro di essa, quindi l’ambizione digitale dell’Europa alimenta la transizione energetica piuttosto che competere con essa”, ha affermato Teresa Ribera, Vicepresidente esecutiva per una Transizione pulita, giusta e competitiva.

A tal fine, la tabella di marcia dovrebbe garantire che i data center siano integrati nel nostro sistema energetico “in modo sostenibile e trasparente”.
Nel 2024, i data center europei hanno consumato energia elettrica sufficiente ad alimentare quasi 20 milioni di famiglie. Entro il 2030, l’Ue stima che questa domanda raddoppierà.

“Introdurremo a breve un sistema di classificazione europeo per i data center. Promuoveremo inoltre un modello di accordo tra autorità pubbliche, gestori di data center e operatori del settore energetico. La nostra attenzione si concentrerà sull’integrazione nella rete elettrica, sulla fornitura di energia pulita, sulla flessibilità e sull’efficienza energetica, unitamente alla tutela delle risorse idriche e al rispetto degli standard ambientali“, ha aggiunto il Commissario per l’Energia.

La Commissione, di suo, lavorerà per facilitare “la cooperazione tra i settori dell’energia e del digitale” per garantire l’integrazione efficiente nella rete di queste infrastrutture e il necessario approvvigionamento di energia pulita per aliimentarle, salvaguardando nel contempo le risorse idriche ed energetiche.

Come più volte è stato detto, le stesse tecnologie digitali, in primis l’AI, saranno fondamentali per migliorare i livelli di efficienza energetica in generale e di efficienza della rete elettrica europea. A tal fine è considerata di primaria importanza la diffusione dei contatori di nuova generazione per il migliore controllo sui consumi dell’energia e quindi sui costi in bolletta.

In ultima analisi, la digitalizzazione dell’energia contribuirà a costruire modelli AI sovrani e sicuri per il settore energetico, formati sui dati europei e sviluppati dalle imprese europee: “Vogliamo creare un nuovo modello di intelligenza artificiale per il settore energetico, addestrato su dati europei e sviluppato da aziende europee. Si tratta di una questione di sovranità tecnologica europea e di autonomia strategica. Per questo motivo, svilupperemo modelli di intelligenza artificiale lungo tutta la catena del valore e istituiremo un quadro normativo a livello UE per semplificare lo scambio transfrontaliero di dati energetici“.

“Stiamo vivendo una rivoluzione digitale globale e una corsa mondiale per plasmare il futuro dell’intelligenza artificiale. Queste tecnologie stanno trasformando il nostro modo di vivere, lavorare e alimentare le nostre economie. L’Europa non deve semplicemente partecipare a questa trasformazione, deve guidarla. Ma leadership significa farlo in un modo che rifletta i nostri valori: responsabile, sostenibile e a beneficio di tutti i consumatori e di tutti i settori. Il nostro compito è chiaro: gestire le crescenti esigenze energetiche della digitalizzazione, liberando nel contempo le immense opportunità che l’innovazione pone alla nostra portata”, ha spiegato Jørgensen.

Da migliorare, infine, la sicurezza informatica dei dispositivi critici, come gli impianti solari, contestualmente ad un utilizzo più sicuro dell’intelligenza artificiale.

In arrivo il bando per le gigafactory AI

A questo punto si attende per luglio l’invito a presentare proposte per la rete di gigafactory AI europee.

La Commissione avvierà inoltre una consultazione con gli Stati membri, la Banca europea per gli investimenti e altre parti interessate per raccogliere le risorse necessarie a finanziare le ambizioni europee in materia di sovranità tecnologica.

Tutte le proposte legislative presentate oggi dovranno comunque essere negoziate dal Parlamento europeo e dal Consiglio dell’Unione europea nelle prossime settimane.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/indipendenza-digitale-europea-la-commissione-presenta-4-misure-von-der-leyen-non-possiamo-dipendere-da-altri/574051/




Security of 100 AI Agents Tested and Ranked – What You Need to Know

AI is our new leader. We just accept and do what it tells us. Maybe we should be a bit more circumspect.

Concern over the performance of AI agents has been constant, ranging from ‘leaky’ to just plain wrong decision-making. Since the pressure to use more agents more autonomously because of supercharged AI-assisted attacks is now constant, Adversa AI’s decision to measure and compare the performance and security of 100 agents across ten categories is welcome.

But the results are not. Of the 100 agents tested, and positioned within a new AI Risk Quadrant, only 11 are categorized as ‘capable well-defended’. 

The root problem is the AI agent ‘lethal trifecta’, which Adversa describes as ‘private data access + exposure to untrusted content + ability for outbound actions’. This translates directly into the standard lethal trifecta of too much power + too much trust + too little control’.

Since all three parts of this trifecta are necessary for an AI agent to achieve its goal, capability and security will always be a big ask. Ninety-eight percent of the agents have this trifecta, so it is no surprise to learn – but still shocking to hear – that so few are both capable (useful) and defendable (secure).

Capability and security verge on mutual exclusion. “The same vendors shipping the most capable agents ship the widest attack surface – a structural feature of the market, not a handful of outliers,” states Adversa’s analysis in its AI Risk Quadrant for Agent Security report. It calls this a ‘power-protection inversion’ and adds that it appears in all ten agent categories.

Advertisement. Scroll to continue reading.

The agent categories with the greatest power protection inversion, however, are ‘computer agents’ followed by ‘coding agents’.

Computer agents are designed to perform a specific task, such as make a decision or perform an action for a user. Since agents can only operate with what they know (the context problem, where poor context leads to bad decisions in all agents), computer agents are given wide access rights, effectively the complete operating system. “A compromise hands the attacker the user’s entire machine, not just one application or tab,” warns Adversa.

Such agents also suffer from an issue that affects all agents: the user has little, if any, visibility into or control over what the agent actually does. It is given an input (the task), and it generates an output (the completed task). But with computer agents, the user doesn’t know the route it takes between input and output, nor what specific actions within the operating system it takes along that route.

“The deeper issue is that the desktop confirmation step looks like a control while being unreliable in practice,” warns the analysis. ‘The human and the model reason over different abstractions (windows and labels vs. screenshots and accessibility trees). That gap produces confirmation mismatch: the human approves the appearance of the action, not what the agent is about to do, because nothing in the interface surfaces the difference.”

The second-worst offender in the exposed giants quadrant is coding agents. This is concerning since ‘vibe-coding’ applications are becoming the future of software, and ‘vibe-coded’ in-house applications may live with us for many years.

The analysis sub-divides coding agents into three types: “coding copilots (human reviews each suggestion), autonomous coding agents (goal-in, repo-out), and app builders (prompt-to-deployed-app). The first might appear to be the least dangerous, but the user still doesn’t know what the agent does between input and output. “Coding agents don’t just write code – they touch shell, dependencies, and tokens long before a diff lands in review,” comments Adversa.

“This is the class where compromise most directly becomes production compromise. The danger is not bad code suggestions; it is high-trust operation inside the software supply chain. Non-determinism makes code review an incomplete defense: even if a human reviews the final diff, the agent may already have traversed secrets, run tests against production-like services, modified configs, or selected risky dependencies. Review catches outputs; it does not catch the full action trail.”

Coding agents figure so highly among the exposed giants because they have a wide attack surface, an extensive blast radius, and poor defense controls. The attack surface is wide because they run shell commands, load MCP servers, and auto-load rules files. The blast radius comes from sitting inside the software supply chain with access to secrets, signing keys, and deployment pipelines. And their primary defense is a code review of the output, which doesn’t consider either the attack surface or the blast radius.

We’ve glanced at just two of the ten agent types included in Adversa’s agent analysis and AI Risk Quadrant. The other eight categories are general assistant, work copilot, browser, conversational, custom workflow, business process, platform operations, and data engineering. None come out squeaky clean. Ninety-eight percent of the tested agents are subject to the lethal trifecta, with only one agent in each of the general assistant and data engineering agents being the exceptions.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

General comments from Adversa include: agent defaults favor velocity over safety; agents with the most power have the least protection, while the agents with the most protection have the least power; only 11% qualify for the capable and defended quadrant; tool execution accounts for 76% of blast radius; 37% of the market is audited more than defended; and 83% of claimed AI agent defenses are not publicly verifiable.

Agents are effectively black boxes – it’s a take it or leave it scenario. Business economics is forcing us to take it. Since we cannot control what the agent does while it is running, our only option is to be careful over what we input, and control, where possible, the output. 

Here, Adversa recommends concentration on controlling the output since there is little that can be done on the input prompts. “Defend the legs you can own, not the one you can’t,” it suggests. “Prompt injection has no deterministic fix – no classifier reliably separates the agent’s data from its instructions, and vendors concede it. Concede the input boundary and spend the defensive budget on the trifecta legs the operator does control: egress, identity, and irreversible actions.”

This is where we are today. The headlong rush into agentic AI solutions is irreversible but concerning. We will only match adversarial AI-assisted attacks by using AI-assisted defense. All businesses will only remain competitive if they are faster, and more efficient than the competition. In business, all roads lead to AI. We must hope, and can probably expect, that AI will improve in all areas in the future. To what extent and when that may happen is another unknown. 

But in the meantime, the ultimate message from Adversa’s massive and detailed analysis is clear: “Let’s be careful out there.”

Related: Can We Trust AI? No – But Eventually We Must

Related: The Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore

Related: Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’

Related: Raising the Cybersecurity Stakes: Ante up for the Agentic Era

https://www.securityweek.com/security-of-100-ai-agents-tested-and-ranked-what-you-need-to-know/




AI, Trump vuole testare i modelli più potenti prima del lancio sul mercato

Testare e valutare i modelli AI più potenti per rafforzare la sicurezza nazionale, l’ordine esecutivo firmato da Trump

Non sarà un obbligo imposto alle Big Tech come OpenAI, Google oAnthropic, ma un meccanismo volontario di collaborazione con il Governo degli Stati Uniti. È quanto prevede l’ultimo ordine esecutivo firmato dal presidente Donald Trump, che pone le basi per una nuova fase di sperimentazione e valutazione dei modelli di intelligenza artificiale più avanzati a livello federale.

Ufficialmente, come si legge nel documento pubblicato dalla Casa Bianca, l’iniziativa ha l’obiettivo di rafforzare il coordinamento tra i principali dipartimenti federali, dal Dipartimento della Difesa a quello del Tesoro, passando per la Sicurezza Nazionale e l’Homeland Security, per potenziare la protezione informatica del Paese e delle infrastrutture critiche.

Prima dell’implementazione e del rilascio sul mercato dei modelli AI più potenti, l’amministrazione Trump ha dunque espresso la volontà di valutarne preventivamente gli aspetti di sicurezza, con l’obiettivo dichiarato di tutelare gli interessi nazionali.

“Le capacità avanzate dell’intelligenza artificiale rendono la nostra nazione più forte, ma introducono anche nuove implicazioni per la sicurezza nazionale che richiedono un’azione coordinata tra dipartimenti e agenzie esecutive”, si legge nell’ordine esecutivo. Il documento sottolinea inoltre che l’amministrazione Trump “lavorerà a stretto contatto con l’industria per garantire che le tecnologie più avanzate e sicure vengano implementate rapidamente per contrastare qualsiasi minaccia al Paese”.

Firma posticipata di 10 giorni per no danneggiare le Big Tech?

Secondo quanto riportato da NBC News, il decreto avrebbe dovuto essere firmato il 21 maggio nel corso di una cerimonia pubblica alla presenza degli amministratori delegati delle principali aziende tecnologiche statunitensi. All’ultimo momento, tuttavia, Trump avrebbe annullato l’evento, rinviando la firma del provvedimento, poi avvenuta ieri a porte chiuse.

Una scelta che, secondo l’emittente americana, sarebbe stata motivata dal timore di penalizzare le stesse Big Tech e di compromettere la competitività dell’industria tecnologica statunitense nei confronti della Cina.

Non solo. Il rinvio potrebbe aver consentito all’amministrazione di introdurre modifiche sostanziali al testo. L’ordinanza stabilisce infatti che il programma di test volontario consentirà al Governo federale di accedere ai modelli di intelligenza artificiale di frontiera fino a 30 giorni prima della loro distribuzione ad altri partner considerati affidabili, rispetto ai 90 giorni previsti nella bozza iniziale.

Il documento dispone inoltre che i procuratori generali attribuiscano priorità ai procedimenti che coinvolgono l’utilizzo dell’intelligenza artificiale, con particolare attenzione agli agenti AI e ai sistemi autonomi impiegati in attività di criminalità informatica.

In questo contesto, il caso Mythos di Anthropic potrebbe aver contribuito ad accelerare un processo interno di maggiore attenzione da parte del Governo federale ai temi della cybersecurity nazionale.

Se l’AI finisce nelle mani sbagliate …

Se da un lato il modello potrebbe rappresentare uno strumento utile per aiutare aziende e organizzazioni a individuare vulnerabilità nei propri sistemi di sicurezza informatica, dall’altro diversi esperti, così come numerosi esponenti dell’amministrazione, temono che tali capacità possano essere sfruttate da attori malevoli per identificare e colpire debolezze presenti nei software e nelle infrastrutture digitali.

È relativamente raro che l’amministrazione Trump intervenga con misure che introducono forme di supervisione sulle tecnologie più avanzate. Finora, infatti, l’approccio è stato prevalentemente orientato nella direzione opposta, con una forte opposizione sia alle proposte normative federali sia alle iniziative legislative dei singoli Stati che, secondo la Casa Bianca, rischierebbero di rallentare l’innovazione americana nel settore dell’intelligenza artificiale.

Dalla partecipazione volontaria a quella obbligatoria?

Non mancano, tuttavia, le critiche all’approccio adottato dalla Casa Bianca, come riportato da Politico. Caleb Knapp, responsabile senior delle politiche dell’Alliance for Secure AI, ha definito l’ordinanza “un buon punto di partenza per costruire le capacità istituzionali necessarie a una supervisione efficace dei modelli di intelligenza artificiale avanzata“.
Secondo Knapp, però, un sistema basato esclusivamente sulla partecipazione volontaria delle aziende non sarebbe sufficiente a garantire un controllo adeguato delle tecnologie più potenti. Per questo motivo ha invitato il Congresso a intervenire con una normativa più stringente, introducendo l’obbligo per gli sviluppatori di sottoporre i propri modelli a una revisione governativa prima del rilascio. Una posizione che evidenzia il dibattito in corso negli Stati Uniti tra chi ritiene necessario rafforzare gli strumenti di vigilanza e chi teme che un eccesso di regolamentazione possa rallentare l’innovazione.

Anche Caleb Max, presidente e CEO della National Artificial Intelligence Association, ha sottolineato come le iniziative volontarie rappresentino spesso soltanto una prima fase del processo normativo: “Raramente il governo adotta misure destinate a rimanere esclusivamente volontarie. In genere, le regole tendono a diventare più restrittive nel tempo, non più permissive“.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/ai-trump-vuole-testare-i-modelli-piu-potenti-prima-del-lancio-sul-mercato/574024/




Microsoft’s Project Solara is an Android OS designed for agents instead of apps

However, Microsoft is clear that this is still just a concept. None of it works, but the company is committed to spending money on it as part of its massive AI expansion plans.

Agentic concepts

Microsoft has shown off two concept devices that illustrate where it hopes to go with Project Solara. The more conventional is the Desk Concept, which looks like a typical smart display. It’s got a touchscreen, microphones, and a camera. While you sit at your desk, this gadget would keep you apprised of what your theoretical AI agents are doing on your behalf. It can act as a secondary monitor or become a standalone Windows PC with Windows 365 cloud computing. This concept is built around MediaTek IoT chips.

The other Solara concept skews weirder. What if the work badge at the end of your lanyard had a touchscreen, 5G connectivity, a camera, microphones, and a fingerprint scanner? That’s the Badge Concept. It would have the same Solara software, piping in generative interfaces from your preferred AI agent. Microsoft envisions this Qualcomm-based device providing biometric-authenticated access to your agents—just tap the sensor and start telling your personal robot what to do. It could also record and summarize meetings and use the camera to “take action on the environment,” whatever that means.

You can’t even get in line to buy either of these devices. Microsoft’s next step is to demo its agent-first devices with industry partners, including AccuWeather, Best Buy, CVS Health, Levi’s, and Target.

Microsoft has struggled to branch out beyond traditional computing and enterprise services, having tried and failed on numerous occasions to gain a foothold in mobile computing. With AI, Microsoft was uncharacteristically at the forefront of change. With its OpenAI deal sputtering, the company is now looking to the future, and this is it: agents instead of apps.

[embedded content]

This is an interesting pitch for how we might actually use AI agents, and it’s not coming totally out of left field. Google is also pursuing agentic interfaces in its search products. At I/O, Google previewed new agent-first search tools that can instantly build dashboards and mini-apps based on your search queries.

As vague and pie-in-the-sky as Project Solara may be, Microsoft is pretty in tune with the rest of big tech’s AI plans. If any of it works, we can only hope it doesn’t lead to a new generation of touchscreen millstones around our necks.

https://arstechnica.com/gadgets/2026/06/microsofts-project-solara-is-an-android-os-designed-for-agents-instead-of-apps/




Mathematicians warn of AI threats to profession as industry encroaches

Recommendations for humans

So what is a human mathematician to do during the AI boom? The Leiden Declaration recommends that individual mathematicians transparently disclose their use of AI tools, retain responsibility for the correctness of their mathematical work, continue crediting human authors while properly attributing work even if AI tools make that difficult, and consider using only AI tools that align with the values articulated in the declaration

The declaration also reminds mathematicians that mathematics has “applications in the development of technology for use in warfare, oppression, mass surveillance, and the undermining of democracy,” and so mathematicians should make ethical decisions accordingly when choosing external partnerships with tech companies.

Professional mathematical organizations can develop guidelines for the use of AI and other automated tools in publication and review, protect the rights of researchers as authors through licensing agreements that prevent their work from being used as training data without consent, and support the role of peer-reviewed publications. The declaration also suggests such organizations “actively prepare to become involved if major mathematical results are claimed using unconventional means.”

The authors of the declaration also offer straightforward recommendations for policymakers, including “protect the rights of authors,” “regulate the artificial intelligence industry,” and “invest in public computational infrastructure.” Under “don’t believe the hype,” the declaration warns about how “there is currently a strong commercial incentive on the part of the technology industry to overstate the capabilities of their products.”

Lastly, the declaration acknowledges that the tech industry “has offered lucrative jobs, monetary rewards, computing resources, and intellectually stimulating opportunities that some mathematicians have found attractive… in an era of underfunding of higher education and precarious academic employment.” It calls on such collaborations between mathematicians and the tech industry to abide by the standards laid out in the declaration.

“By endorsing the declaration, the IMU affirms that the future of mathematical research must be guided by human judgment, fair and transparent practices, and the shared values of the global mathematical community,” said Ulrike Tillmann, vice president of the International Mathematical Union, in a statement. “Mathematics is, and should always remain, a profoundly human endeavor.”

https://arstechnica.com/tech-policy/2026/06/mathematicians-warn-of-ai-threats-to-profession-as-industry-encroaches/




Android phones will soon be able to detect spoofed calls and impersonation scams

We’re expecting Android 17 to begin rolling out later this month, but first, Google has a batch of updates for the wider Android device ecosystem. As usual, some of the new features are limited to specific devices, and others require using Google’s apps. But if you don’t mind the latter, you can get automated protection from the growing threat of deepfake phone scams.

According to Google, “impersonation fraud” is one of the most common types of financial scams. The FTC tracked almost $3 billion in losses from such scams during 2024, and the improvements in AI voice cloning tools more recently are making the schemes easier to pull off. The voice models are becoming so capable that it can be difficult to identify a fake caller even when an AI is imitating someone you talk to every day.

Google’s solution is an expansion of the system it debuted last month for verified financial calls. Now, a similar feature will work with anyone in your contacts. Many of the most effective deepfake scams involve spoofing a contact’s number, which makes the call look more legitimate when your phone lights up. Victims of these scams are then greeted by an accurate re-creation of the person’s voice spinning a yarn that involves an urgent need for cash.

Google’s scam call detection feature will be available on all phones running Android 12 or higher, but it does require you to have three Google apps installed: Phone by Google, Contacts, and Google Messages. Depending on your device, you may already have these. They’re the preloaded options on Pixel and Motorola phones, and Samsung has now switched over fully to Google Messages. Google claims that Phone by Google is the most widely used dialer, but that doesn’t seem right—Samsung has its own phone app, and it’s the largest Android OEM by far.

https://arstechnica.com/gadgets/2026/06/google-announces-deepfake-call-detection-for-android-new-airdrop-device-support/




Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis

Two reports offer differing viewpoints. One suggests a failure of tools to provide what security teams really need. The other suggests the tools exist but are not properly managed.

The industrialization of cybercrime threatens to overwhelm cyber defense. It’s a process that started before the arrival of ChatGPT, was supercharged by the age of AI, and is now typified as the post-Mythos era. It’s a time when defenders must improve their performance or cede the battleground to the adversary. Applications are the battlefield. The speed, scale and sophistication of AI-assisted attacks is difficult to contain. 

“AI is not just creating more vulnerabilities. It is exposing the fact that companies cannot fix known vulnerabilities fast enough,” explains Daniel Shechter, CEO and co-founder at Miggo Security. “For years, security programs have been measured by how well they find risk before software goes live. Frontier AI like Mythos changes the question. If attackers can move from disclosure to exploit in hours, boards and CISOs need to understand how long the business remains exposed, and what can be done to mitigate quickly and efficiently.”

The Cloud Security Alliance (CSA) State of Modern Application and AI Security report (PDF), commissioned by Miggo and published on June 2, 2026, confirms and explains this new reality. CSA surveyed more than 900 cybersecurity leaders and found that vulnerabilities in this post-Mythos era are evading the pre-production phase while 82% of organizations lack effective runtime visibility.

“The real challenge begins once applications are in production, where security teams must rapidly determine which exposures are truly exploitable, prioritize the risks that matter most, and respond before attackers can take advantage,” suggests Daniel Shechter, CEO and co-founder at Miggo Security.

Most breaches are driven by known vulnerabilities. Eighty percent of the companies surveyed have suffered at least one incident involving a known vulnerability in the last year. If it is known, it is almost certainly patchable; but in the post-Mythos era there are too many patches to handle. The biggest problem is knowing which of those vulnerabilities are exploitable and most urgently need patching.

Advertisement. Scroll to continue reading.

Only 9% remediate critical vulnerabilities within 24 hours; with74% take one to seven days. Patch time is important: Organizations taking four or more days had a 97% incident rate. Those taking three or less had a 67% rate. The implication is that patch rates must be increased and exploitable vulnerabilities better understood – and preferably both.

It gets more complicated, and urgent, in runtime, which is described as the breach battlefield. Most organizations only know what happened after reconstructing the event after the horse has bolted. Most (73%) would adopt virtual patching if they had better confidence in minimal false positives; but only 17% configure WAFs for automatic blocking, with 56% citing a lack of application context as the reason.

Because of the runtime difficulties, there is an intention by 42% of the organizations to increase investment in runtime monitoring and protection over the next few years. But since protection is always better than cure, the bulk of investment (52%) remains in pre-production such as CI/CD build protection.

The potential solutions are clear. Improved visibility into vulnerability exploitability together with better all-round contextual understanding of the application concerned – and its effect on business stability – would allow autonomous patching for many vulnerabilities and confidence in increased automated blocking.

A separate FireMon Insights report, also published June 2, 2026, suggests that concern over the automated use of firewalls as a security barrier is unsurprising but at least partially due to a lack of human oversight. FireMon discusses firewalls in general, but the same principles will apply to WAFs.

“Firewall complexity is no longer just an operational problem. It is a control problem,” says Jody Brazil, CEO at FireMon. “Security teams have massive investments in firewalls, cloud, and segmentation platforms, but without control of policy those environments become difficult to manage securely. The problem is no longer lack of tools. It is lack of operational control.”

It concludes that manual policy management is inefficient and allows risk across the attack surface to continue to expand rapidly, primarily due to an environment in which high severity policy failures persist over extended periods of time, and are exacerbated by unused and redundant rules. 

FireMon suggests a failure in human management rather than firewall capability. For example, 45% of firewall rules lack an owner or documentation, 17% are redundant or shadowed, and 69% are unused.

“Firewall complexity is no longer just an operational problem. It is a control problem,” adds Brazil. “Security teams have massive investments in firewalls, cloud, and segmentation platforms, but without control of policy those environments become difficult to manage securely. The problem is no longer lack of tools. It is lack of operational control.”

While this suggests a route toward better usage of firewalls, it doesn’t discuss or explain the fear that contextually incorrect blocking rules might adversely affect business operations – which lies at the heart of improving application security.

The two reports are, however, slightly at odds. The CSA report suggests the problem is a failure of security tools to provide the solutions really necessary, while the FireMon report suggests the tools exist, but are not being properly managed.

Related: Anthropic Unveils ‘Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attacks

Related: The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security

Related: New Class of CI/CD Attacks Could Have Led to PyTorch Supply Chain Compromise

Related: Microsoft to Enable ‘Windows Baseline Security’ With New Runtime Integrity Safeguards

https://www.securityweek.com/two-new-reports-offer-competing-explanations-for-cybersecuritys-growing-crisis/




Anthropic Expanding Mythos Access to 150 New Organizations

Anthropic announced on Tuesday that it is expanding Project Glasswing, its collaborative program aimed at securing critical software using AI. 

The initiative, launched with roughly 50 initial partners in early April, granted them access to Claude Mythos Preview. Those partners have since used Mythos to scan codebases and identified thousands of vulnerabilities.

The expansion adds roughly 150 new organizations, each required to meet Anthropic’s standards before gaining access. These partners are based in more than 15 countries and include providers of critical infrastructure in sectors such as power, water, healthcare, communications, and hardware. 

Many are vendors and maintainers of widely used codebases relied upon by governments and other organizations worldwide.

A common factor among the new partners is the potential impact of a successful cyberattack targeting their products, which could affect more than 100 million people for most participants and carry significant national and global security implications. 

The expansion of Project Glasswing follows collaboration with existing partners, the security industry, open source software maintainers, and the US government.

Advertisement. Scroll to continue reading.

Anthropic has not shared the expanded list of partners, but the Financial Times reported that the newly added organizations include Okta, Samsung, the EU cybersecurity agency ENISA, and NATO. 

The AI giant reported recently that Mythos identified more than 23,000 potential vulnerabilities, with the company estimating that more than 6,000 will be confirmed as severe flaws.

Organizations such as Mozilla, Palo Alto Networks, and Cloudflare saw good results when turning Mythos against their own products. 

[ Read: Anthropic Releases New Claude Sandbox, Security Guidance Plugin ]

With Mythos and other AI tools rapidly discovering vulnerabilities, the problem now shifts to verifying and patching them. For instance, of the thousands of security bugs found by Mythos, only 75 critical and high-severity issues have been patched. 

Anthropic says Mythos can also help with verification and patching, and the company is working with others to “substantially scale up the reviewing and patching of vulnerabilities in open-source software”.

“We’re also working on sharing ideas and best practices for disclosing vulnerabilities to open-source maintainers, with the intent of making these reports easier to triage and to act upon,” Anthropic said. 

Related: Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

Related: The Mythos Moment: Enterprises Must Fight Agents with Agents

Related: OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

Related: Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’

https://www.securityweek.com/anthropic-expanding-mythos-access-to-150-new-organizations/