Computerworld.com [Hacking News]
OpenAI’s new priorities for third-party assessments are a fine start, but they lack teeth
OpenAI published a detailed list of priorities and principles on Tuesday designed to govern its third-party model assessors, a list that industry observers agreed was a good one. But they also stressed that it lacked any enforceable controls to truly maintain safety.
If the goal is to encourage enterprise CIOs to trust OpenAI more, it won’t help, they said, but most doubted that this was OpenAI’s objective. Its more probable aim is to use the list to work out an arrangement with competitors and regulators so that enforcement is made more palatable, under the theory that it is open to stricter enforcement, but only if all of its key rivals are locked into identical restrictions.
The OpenAI post said, “OpenAI is committed to supporting independent assessments with deep levels of access across training, evaluation and deployment. That access should enable assessors to challenge our assumptions, identify risks we may have missed, and reach their own conclusions about the effectiveness of our safeguards.”
It added: “Third party assessments are most useful when they address specific, consequential questions: Does the evidence support a lab’s safety case and safety claims? Do evaluations adequately test the risks they are intended to measure? Do safeguards work under realistic conditions?”
Nothing about enforcementPieter Arntz, a malware intelligence researcher at Malwarebytes, said that giving third parties rules for engagement is certainly a good thing, but the implication behind such rules is that they are somehow enforceable. And the document says nothing about that enforcement process.
“It sets some useful expectations for independence and rigor, but it does not itself compel OpenAI to submit to a particular scope, publish adverse findings, or change deployment decisions,” he pointed out. “Its credibility will depend on the terms of individual assessments, and what outsiders are allowed to see. Its value therefore hinges on whether OpenAI accepts genuinely inconvenient scrutiny, and whether results, redactions, remediation, and deployment decisions can be independently checked.”
Valence Howden, advisory fellow at Info-Tech Research Group, agreed that the lack of enforceability makes the rules close to pointless.
The document “doesn’t impose any requirements on OpenAI, and I would have been surprised if it did, because their motivations are not as clear-cut as they’re stating,” he said. “They also haven’t really identified what they will do based on the assessments, once they are conducted. OpenAI retains control over scope in that [OpenAI] must agree with it, limiting where assessors can go. They retain the ability to determine the appropriate level of access, which still allows them to filter what’s provided, impeding the gathering of direct evidence in those cases they define as material or classified. It also allows them to control much of the reporting and redact portions.”
Howden said the net impact is that “it’s good for determining what should be assessed, but considerably weaker on true clarity and approaches for how this is done.”
But Jason Andersen, principal analyst at Moor Insights & Strategy, offered a different perspective, although he reached the same conclusions as Howden and Arntz.
“It’s not an act of good faith to not empower these evaluators,” he said, but at the same time, CIOs need to understand the split personality of OpenAI today.
“It’s a classic problem with OpenAI because they are a split brain company, with the commercial side and the original mission side,” he pointed out. “Those two teams have not aligned very well over the past two years. It looks like it started with the original mission team, but then commercial interests took over that document and turned it into legalese.”
‘A principle instead of an excuse’Frank Dickson, principal analyst at Dickson Research, concluded from the post that OpenAI “seems proactive in highlighting the threats posed by AI, but hesitant to accept accountability or take real action. This is a code of conduct for the assessors, not for OpenAI. The gap between the two is the whole story.”
He delved into the details of the document and was not happy. He pointed out, for example, that third-party assessor access was “granted within the bounds of legal, security, and IP constraints. That is a company deciding the scope of its own scrutiny.”
He also noted that the document specified that “publication happens after labs get a reasonable period to remediate issues. That is the same grace-period logic that just got Google criticized for sitting on the Gemini hacking disclosure for seven weeks, now written down as a principle instead of an excuse.”
Just the beginningHowever, Samantha Gloede, global head of risk services at KPMG, said that she sees the document as the beginning of the process, and it should be evaluated accordingly.
“I believe the conversation will increasingly shift from assessment to accountability,” Gloede said. “Independent testing is important, but long-term trust depends on how organizations respond when material risks are identified. Stakeholders will want confidence not only that issues can be found, but that corrective actions are taken, independently validated and reflected in governance and deployment decisions. The next evolution of AI assurance will be demonstrating that accountability with the same rigor used to assess risk in the first place.”
Edna Conway, executive advisor at consulting firm Acceligence, agreed, noting that the substance of this effort will only become clear in the next phase.
“The next step is making the lab accountable to the assessment process itself. Who determines when an assessment is required? ” she asked. “How much access is sufficient? What happens when the assessor and lab disagree about scope? Who sees a critical finding? Embracing independence is essential, as third-party assessments are genuinely valuable only when the assessor can ask uncomfortable questions, get sufficient access to answer them, follow evidence outside the original hypothesis when necessary, and report conclusions without commercial or organizational pressure shaping the outcome.”
This article originally appeared on CIO.com.
From admin to architect: Jamf’s vision for the autonomous Apple enterprise
Now a private company, Jamf opened its big annual event for Apple enterprise management teams, JNUC, by taking big steps to exploit artificial intelligence in the management of Apple fleets. During her keynote speech at the Kansas City event, CEO Beth Tschida shared some of the details of the platform-scale overhaul the company has set in motion.
“IT teams are managing more endpoints and more complexity than ever,” she said. “We want Jamf to handle more of that routine work automatically… because AI runs better on Apple, and Apple runs better on Jamf.”
Tschida — and Jamf — have been consistent on the value of AI to IT, which played a major focus at last year’s JNUC also. When I spoke with her, she was resolute on the need for IT to engage with the tech, telling me, “AI is happening whether organizations know it or not. That’s the problem. You can try to block it, but that’s very hard to do well. It’s far better to build visibility and governance around it.”
As you’ll see, this is very much part of what Jamf at JNUC 2026 is working to achieve.
AI, Apple, and ITThe combination is about exploiting AI support inherent to Apple’s platforms to help reduce time-consuming IT tasks. It means that Apple device management in the future will be less about management and more about creating autonomous enterprise ecosystems in which the tech handles the routine tasks, while humans handle the strategy.
Jamf’s offerings now include a new AI-powered self-service diagnostics system. Employees will be able to troubleshoot their own devices by asking Jamf questions on their device, such as “Why are my video calls lagging?” and receive an immediate explanation and a one-click fix.
These improvements aren’t confined to routine task automation. They also extend into AI governance. The company introduced its AI Governance suite earlier this year, and at JNUC announced new capabilities to help IT take control of shadow AI across their networks.
A response to shadow AIThese include a centralized AI control panel which shows admins which AI systems are running across their fleet and lets them enforce usage policies and also generate audit-ready reports. The company is extending this into the Safari, Chrome, and Edge browsers, which means organizations can prevent the upload of corporate files to personal AI accounts through browsers on managed devices.
It means that IT doesn’t just see AI is being used but can identify which models are running and what the token costs are, while also being able to block corporate files from being uploaded to a personal account in Safari or Chrome.
For security-conscious firms, Jamf is also enabling the deployment of local inference engines. That support means companies can run AI workloads directly on Apple hardware, ensuring that prompts and sensitive data never, ever leave the device.
IT as a serviceThe transformation of IT means IT itself is becoming an application, and Jamf seems to be embracing this approach with a new Platform API Gateway and a Terraform provider. Together, these make it possible for IT teams to manage their entire Apple environment using “Infrastructure as Code.”
Think GitOps for admins, in which a change to the fleet becomes a peer-reviewed pull request, and a rollback becomes as simple as a click.
Jamf also introduced Jamf Tap, its NFC/RFID system that lets frontline workers simply tap an ID badge to instantly assign the device and sign into necessary apps, aimed at streamlining things like shift changes in warehouses.
Final announcements from the company included Ring Deployments, a rollout system that tests updates with a pilot group before expanding to the wider fleet, and a curated catalog that automatically installs and updates popular Mac apps.
JNUC 2027 takes place in Anaheim, California, from October 26–28, 2027. It will mark the company’s 25th anniversary.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Hello, Googlebook: The complete FAQ on Google’s Android-ChromeOS combo
Googlebook, Googlebook, Googlebook. Google’s mysterious new Android- and ChromeOS-combining laptops have been the talk of the town here in the land o’ Googley matters for much of this year already — and their name also makes for an incredibly challenging tongue-twister to say, as an added layer of intrigue. (Seriously: Try saying it 10 times fast. It ain’t easy.)
All linguistic feats aside, the story with the Googlebook so far has mostly been one of questions — with Google giving us shockingly little solid info about what these systems are actually all about, what they’ll be like to use, and how they’ll fit into the broader Android and Chrome ecosystems that’ve existed around us all this time.
For the first time now, we’re finally getting some solid answers. The first-ever Googlebooks are up for pre-order as of this week and set to become broadly available in early October. I had the opportunity to check in with Google ahead of the announcement, ask some questions, and get some inside info about all of the many unknowns surrounding these systems.
Here, with no punches pulled and no stones left unturned, is everything we know — going far beyond the spotlighted talking points that you’ll see in the official Googlebook announcements.
[Get level-headed knowledge in your inbox with my free Android Intelligence newsletter — one new and useful thing from me to you each Friday.]
Let’s start simple: What exactly is a Googlebook?A fine place to start, you wise little wallaby. A Googlebook is the name for a new kind of laptop Google’s launching, with a whole new kind of custom operating system behind it. The simplest way to think about it is as a specialized version of Android that incorporates many of the concepts and ideas central to ChromeOS and Chromebooks — with a focus on a productivity-centric, desktop-caliber computing environment that avoids many of the awkward compromises that come with trying to work on a traditional Android tablet.
Googlebooks are not, notably, the same thing as Google Books — the long-standing book searching service Google still operates — though you can access Google Books on a Googlebook for a true Matrix moment.
The Googlebook logo, at top, and Google Books beneath it. Who’s on first?This is where it starts to get tricky — but the shortest possible answer is that it’s kind of a combination of those two things, in what’s meant to be a “best of both worlds” setup.
In practical terms, what that means is that you get an expanded desktop that’s designed to feel like Android but with a variety of enhancements to better take advantage of the added screen space. Amusingly enough, that results in something that brings to mind the short-lived large-screen-optimized Android 3.0 Honeycomb era of 2010 — with notifications and Quick Settings living in one corner of the interface, the clock and date in another corner, and a dock along the the bottom-center.
The Googlebook desktop, as seen during a Google press demo.Unlike with Chromebooks, Googlebooks do give you a fully customizable home screen, where you can add any number of widgets and shortcuts you want. They also allegedly include the new Gemini-powered Create My Widget option for building your own custom widgets from simple natural-language prompting, though we’ve been hearing about that since May with promises of an appearance on Pixel phones, too, and it’s yet to show up anywhere so far.
A demo of the Googlebook Create My Widget system, which was also announced for Pixel phones in May.And, of course, you can install and run any Android app natively on the device in addition to using the full web and all the progressive web apps out on the wild ol’ World Wide Web of ours.
Google’s promise with this is “a laptop that feels familiar to Android users,” as natural and familiar as the phone they already know, and that certainly seems to be how things appear. Googlebooks also tie into Android’s auto-syncing system and bring all of your apps, settings, and basic system-connected data over by default; they follow the Material 3 Expressive design language used throughout Android (in the software’s standard version, as it appears on Pixels and certain other devices) as well as in most Google-made Android apps; and it offers the ability to both continue work from your phone — in apps that support the option, at least (a list that isn’t at all clear as of yet) — and to stream apps directly from your phone and run ’em on the computer, as you can with ChromeOS already.
width="1024" height="639" sizes="auto, (max-width: 1024px) 100vw, 1024px"> Google’s phone-to-computer app streaming system, as first seen on Chromebooks.There’s also a new desktop-specific Files app that boasts a few neat-sounding tricks, like being able to let you interact with files from your phone on the computer and also search for an image in your storage based on what’s in it and not just its filename, as you can in Google Photos — so, for example, searching for “taco” and finding all images that show a taco (of which you should have many).
The Googlebook’s Android files connection is a pretty powerful perk for Android users — with any kind of Android device.With the caveat that I haven’t had a chance to spend any actual hands-on time with these devices for myself just yet, Google says its Googlebooks will sport the “full browser capabilities” and “desktop-class” browser quality carried over from ChromeOS — with full native support for browser extensions and a computer-level browsing experience.
The systems will also allow you to easily hand off tabs from your phone to your laptop and vice-versa, and Google’s been working to ensure web apps like its Workspace suite of Docs, Sheets, Slides, and so on work perfectly well on all of the devices.
Are there any special software touches that set these apart from other laptops, beyond the native Android app compatibility?Excellent question, detective. As you’d expect — for better or for worse, depending on your perspective — Googlebooks have Gemini baked into their operating system in all sorts of places, for what Google’s calling a “deep OS-native AI” experience.
Some specific examples:
- A Magic Pointer feature lets you wiggle your mouse to summon Gemini and have it identify or interact with whatever’s in that area of your display.
- Magic Cues offer proactive contextual assistance — suggested actions, in other words — based on what you’re doing (in theory, at least; this same system has been present on Pixels for quite a while now, and I rarely ever see it show up).
- Rambler, Google’s new Wispr-Flow-like natural speaking dictation system, is built in at the system level for simple voice-to-text work in any app or process you’re using.
Beyond that, you’ve got all the bits of built-in Android syncing and integration we’ve already gone over — with files, apps, and the alleged continuity stuff (forgive my skepticism on that; we’ve just been hearing about such systems within Android for years now, and they’ve yet really manifest in any meaningful ways) — along with the phone-to-computer app streaming possibility and automatic cross-device file access.
A demo video showing the Android to Googlebook task handoff system in action.There’s also a ChromeOS-like “Quick Insert” key that follows the Chromebook’s current model of acting as a supercharged clipboard of sorts — along with the added integration of that Rambler voice-to-text system now.
The Googlebook Quick Insert menu, as seen during a Google press demo.And the classic Google glowbar from Google-made devices past makes a glorious return across the entire Googlebook ecosystem — with special light patterns to go along with devices booting up, the resurrected old Chromebook Pixel trick of being able to touch the bar in a certain way to summon a visual representation of your laptop’s current battery level, and other unspecified “playful Easter eggs” to be discovered.
The return of the glowbar, seen at the top of the Acer Googlebook model.Google also says it’ll be opening up the glowbar system to developers in the future so that the light can be integrated into other apps and made even more useful, though it’s not at all clear what the timeline might be for that actually happening — or, of course, if and when different developers will invest the time and resources in participating.
But wait — I thought Googlebooks were all about AI?They are, to some degree. But other than the fact that Gemini is easily accessible for on-demand summoning on the Googlebook, most of the AI takes the shape of those aforementioned features — like how Magic Pointer can lean on AI to identify what’s on your screen and offer up extra info or potentially actions related to it, how Magic Cues leverage AI to assess on-screen text at different moments and suggest actions connected to that, and how Rambler uses AI to listen and process your speech and then transform even unfocused ramblings into legible prose.
The same goes for the Files app and its ability to search through images on the fly to find specific terms, even when they aren’t included in the files’ names.
So the AI is certainly there. It just may or may not be the true day-to-day-use focal point of these systems (or at least overtly so), particularly for business users.
Got it. So, the big question: If the software is a combination of Android and ChromeOS, what is it called?Ah, yes: the big question, indeed. I asked Google this during the media briefing and, I’m happy to report, finally have an answer:
The software is based on Android but is technically now its own separate entity.
So with that mind, it’ll be called Googlebook OS — yes, with a space between the two terms, just to keep everyone perpetually unsure of how to style it. (Anyone else remember how we went from Chrome OS to ChromeOS a few years back?!)
If Googlebooks run Googlebook OS and Chromebooks run ChromeOS, what in the world do Android tablets run now?An identity crisis on a 10″ screen — obviously.
In all seriousness, I’m not entirely convinced that anyone is spending much time thinking about tablets right now. Google’s flipped and flopped and flopped and flipped more times than I can even count when it comes to its tablet philosophy (or lack thereof) over the years — and best we can tell at the moment, the philosophy is mostly just “meh, whatever.”
Following the discontinuation of its 2023 Pixel Tablet, Google itself is showing no signs of making its own tablet again anytime soon or doing much to support other device-makers’ efforts in that area — beyond just noting that Android itself can of course be molded into any form and used for any purpose anyone wants. If I had to guess, I’d say that ho-hum Android tablets will continue to show up from a variety of companies, running Android beneath a variety of over-the-top custom interfaces, without much in the way of love or attention from Google or fancy branding like Googlebooks. And they’ll just kinda be there for anyone who cares. Which Google, best I can tell, doesn’t.
But, as usual when it comes to Google, only time will tell.
All righty, then. So, with Googlebooks: Can device-makers mess with the interface, a la Android — or is it more like ChromeOS, where everything’s standardized and uniform across the entire ecosystem?You’re one smart cookie! That was a pressing question I had going into all of this as well, given what a dramatic difference that distinction creates on Android vs. ChromeOS. While we won’t have a ton of detail or firsthand device-to-device confirmation for a little while yet, Google told me we can expect “consistent experiences” across the Googlebook ecosystem — which certainly seems like we’re looking at more of a Chromebook-like approach than the free-for-all land of Android, with every device-maker having the opportunity to completely revamp the interface and add in all sorts of unnecessary extras.
How will software updates work, then? And how long will these be supported?Seemingly in line with that previous answer, we can cautiously celebrate: Google says all Googlebook software updates will come directly from Google, with regular operating system updates and Pixel-style quarterly feature drops for a full 10 years from every device’s launch date.
That means, at least in theory, everyone should get every update more or less instantly when it’s released — without any of the hemming and hawing and unacceptable uncertainty that we see with that in the Android arena.
Halle-frickin’-lujah.
What about security, fast boot, and the other things Google’s been touting as advantages of Chromebooks all this time?On the security front, Google says Googlebook OS is “built on the same security architecture” as ChromeOS, with the whole Google Titan hardware system there to support it. The company also says Googlebooks will have a fast boot setup similar to what we see on Chromebooks.
The two areas that remain murky in my mind for now are:
- The ChromeOS advantage of being able to wipe your entire system, restart it, sign back in, and be right back where you left off in a matter of minutes. Traditionally, this same process has been a massive pain in the patootie (to use the technical term) on Android. It’s not entirely clear yet which path Googlebook OS will follow, but since it has so much Android architecture, I can’t help but suspect it’ll be more similar to that side of things than the ChromeOS approach.
- The true desktop computer feel that Chromebooks have but that Android devices have never quite managed to master. Android’s come a long way in this area lately, though, and Google says it’s done all sorts of specific optimizing for Googlebook OS — leading to a supposedly “no compromise” result — so, once more, we shall see.
They do — so all those same advantages and line-blurring possibilities for power users exist in this new environment, just as they have in ChromeOS all these years.
For the nerds among us wanting even more details, Googlebooks offer a Debian Linux environment through a built-in Terminal app. So, much like the traditional Chromebook approach, you can install any compatible Linux program via the command line and then take it from there.
What about Windows app compatibility and all the work that went into that on the ChromeOS front?This is an interesting one, given how much Google worked to bring Windows app compatibility into Chromebooks over time — with multiple approaches over the years and the goal of closing any remaining gaps for businesses that rely on native Windows software that just won’t work in a web-centric or mobile app environment.
With Googlebook OS, though, Google’s giving that path up — and the devices will not have any manner of Windows app compatibility. I asked what the story was with that and got back the following explanation from a company spokesperson:
Googlebook takes a fundamentally different architectural path than previous platforms. We aren’t attempting to patch together legacy PC software layers or rely on Windows emulation to make a laptop functional.
Instead, Googlebook OS is built directly on the Android tech stack with the desktop foundations of ChromeOS, pairing the world’s largest native app ecosystem with an uncompromised, full desktop Chrome browser.
This makes it easier than ever for developers to build a true desktop-class app experience on the same Android architecture they’ve already built for.
Top developers are deeply invested in Googlebook already. Leading partners like Capcut, Luminar, and Fantastical have built dedicated versions of their products specifically to take full advantage of Googlebook’s desktop performance, multi-windowing, multitasking and keyboard/mouse precision.
Because Googlebook OS is built directly on standard Android, the developer on-ramp is straightforward. Requiring no proprietary rewrites, developers can use standard Android APIs from a single codebase that spans over 3B devices. By adopting large screen guidelines, their apps scale seamlessly from phones, to desktop with low engineering overhead.
Google also noted that the Play Store will feature a specially curated and categorized experience for Googlebook users that breaks recommended apps down into “Made for Desktop,” “Optimized for Desktop,” “Desktop Web Experiences,” and “Mobile Android Apps” sections for easier discovery and understanding.
That all sounds fantastic in concept — but we’ve also been hearing about similar efforts on the ChromeOS front for years, and the fruits of similar-seeming solutions never seemed to fully show up or make much difference in that environment. And also, as usual, this depends largely on developers participating and creating the right kind of software to take advantage of this approach and the framework around it.
For someone who really wants the full desktop version of, say, Adobe Photoshop or Microsoft PowerPoint — or someone whose company has proprietary software that’s available only for Windows — this will seemingly mean that Googlebooks won’t be a good option or a viable path forward.
You mentioned PowerPoint. What exactly would this setup mean for Microsoft Office apps and companies that rely on those tools as part of their workflow?It means you’ll have to choose between using the Office web apps — which are generally decent and reasonably fully featured but not the same as their desktop counterparts — or using the Office Android apps, which are similarly manageable but, once more, not the full desktop-caliber experience.
Or, of course, you could use Google Docs (which has gotten pretty darn good at Office compatibility over time) or a Linux-based office suite like LibreOffice instead. But that’s arguably a compromise, if the desktop Microsoft Office app is what you want or need.
When asked about this, a Google exec said he’d personally go with the Office Android app over the web app, in that specific scenario. But, again, it’s hard not to see that as a compromise and a possible deal-breaker for anyone who’s fully invested in the Microsoft ecosystem.
Who’s making these Googlebooks, anyway? And how much are they?Like Android and ChromeOS both, Googlebooks will be made by a variety of different hardware manufacturers. We’ll see five models from five different companies to start:
- The HP Googlebook 14 — a 14″ all-aluminum clamshell started at $1,299
- The Dell XPS Googlebook — a 13.4″ “machined aluminum” laptop starting at $1,199
- The Lenovo Googlebook 15 — a 15″ magnesium-alloy and carbon fiber system starting at $1,299
- The Acer Googlebook 14 — a swiveling convertible aluminum/magnesium laptop/tablet combo that starts at $899
- And the Asus Googlebook 14 — a 14″ aluminum/magnesium computer starting at $1,299
A Google exec described the HP system as being especially high in “craft and care,” the Dell as having the most “flashy design,” the Lenovo as being the “workhorse machine,” the Acer as being the sole convertible, and the Asus as being the most lightweight model.
All of these initial systems also come with a free year of personal access to Google’s AI Pro plan, which includes 5TB of Google cloud storage and would typically cost $200.
Hang on — so Google itself isn’t making one?Nope — not yet, anyway.
If it ever does, how in the world would it handle the branding for that?!By calling it the Google Googlebook for Google by Google, presumably.
What about more affordable options — for schools, businesses, anyone who isn’t looking to pay a thousand bucks for a laptop?What about that, indeed. At launch, at least, Google is deliberately focusing Googlebooks on the premium (and thus also pricey!) market. It’s not clear at this point if or when the category will expand to include more midrange and budget-level systems, but one could certainly imagine those sorts of options coming into the mix over time.
So are Chromebooks going away, then? Is this a replacement?Kinda-sorta-maybe, but not exactly. Clear as mud, right?
That’s the question I’ve been asking ever since the notion of the Googlebook first came up, and Google’s been artfully dancing around it and avoiding any direct answer ever since.
What the company is saying is that it absolutely is maintaining support for the entire range of current Chromebooks through their promised support windows — and that we’ll see quite a few new Chromebooks launching in the next year yet.
Oh, and that at least some current Chromebooks may be able to transition to Googlebook OS at some unspecified point in the future, with details to be determined.
That’s all well and good — and, by all means, good on Google for not giving up on the products that are out there and the many customers (enterprise, education, and individual) who’ve bought into ’em — but it still doesn’t truly tell us anything about the long-term aim of all of this and if Googlebooks are ultimately meant to take the Chromebook’s place, once devices that were presumably already under development and in the pipeline are done.
What I’d say is that reading between the lines, it certainly seems logical and feels like the idea is for Googlebooks to be the future and Chromebooks to be a legacy, technically-still-supported-but-no-longer-the-primary-focus piece of the past. Some court documents unearthed earlier this year suggest that Google has planned to phase ChromeOS out entirely over the next several years, which would fit in perfectly with the notion of keeping ChromeOS around on the backburner until all current devices are past their promised support periods. And the fact that Google isn’t outright answering this question and saying “Yes, Chromebooks will stick around as an option alongside Googlebooks indefinitely, and we continue to keep actively investing in and developing both” sure makes the answer here seem apparent — even if it isn’t being directly confirmed in any way at this point.
All right — so when can I actually buy a Googlebook?The five aforementioned devices are all up for preorder as of this week and should start shipping and showing up on store shelves on October 4, for the US, and October 5 for Canada, the UK, Ireland, France, Germany, and Australia.
What happens if you open both Google Books and Google Play Books on a Googlebook, then look for books about Google to save into your Gemini Notebook (formerly known as Google NotebookLM)?One of three things will absolutely, positively happen:
- You’ll be living the dream.
- You’ll summon the ghost of Mr. Jingles, the old bell mascot from Google+, back from the Google graveyard.
- The universe will spontaneously combust.
Keep me posted.
How many Google Books could a Googlebook book if a Googlebook could book books?All right. I think we’re done here.
Want even more no-nonsense Googley knowledge? Come check out my free Android Intelligence newsletter to get next-level insight delivered directly to your inbox.
Review: M5 Ultra Mac Studio: Pure, unadulterated power
I’m old enough to remember when Macs were friendly little machines. While a little underpowered and equipped with some platform-unique foibles, they were really good at some things, highly secure, and had the best user interface of any PC.
That was then; this is now. And while the platform is still unique, still highly secure, and still has the best user interface, Apple’s all-new Mac Studio is a beast of a machine. It’s incredibly powerful and would crackle with energy if it weren’t so energy efficient.
TL;DR reviewNo matter what pro workflow you follow, the M5 Ultra Mac Studio is more than you need.
Longer reviewApple hasn’t changed the design of the Mac Studio.
It’s 7.7-inch square, 3.7-inch high aluminum box with two USB-C and one SDXC port on the front, and an array of ports — four Thunderbolt 5, two USB A, 10Gb Ethernet, HDMI, and headphone — at rear. It brings Wi-Fi 7 and Bluetooth 6, supports up to eight displays with up to 6K resolution at 60Hz, or four Studio Display XDR units.
Basically, this one box can power a bank of displays, and for those using it in a live video production environment, Apple has also introduced generator locking (a.k.a. genlock) over USB-C, which lets the on-display image synchronize precisely with a pro video camera for the most precise editing and playback you’ll find.
Pros and consPros
- Massive CPU/GPU power capable of handling the most demanding 3D and AI tasks.
- Neural accelerators and unified memory make it ideal for training and running large LLMs on-premises privately.
- Doubled read/write performance over the previous generation via a new storage controller and fast NAND.
- Inclusion of four ProRes accelerators (handling up to 33 streams of 8K) and genlock over USB-C for precise sync.
- High performance at low wattage; runs quiet and cool compared to high-end PC alternatives.
- Features Thunderbolt 5, Wi-Fi 7, and Bluetooth 6.
- Works exceptionally well as a headless AI or rendering server.
Cons
- Extremely high retail price ($12,299 for the top spec).
- Neither the RAM nor the SSD can be upgraded or replaced by the user.
- No keyboard or mouse included, which feels odd for a five-figure machine.
For my review, Apple loaned me a top-of-the-line M5 Ultra Mac Studio equipped with a 36-core CPU and 80-core GPU. It has 256GB memory, 4TB storage, and carries a retail price of $12,299. At that price and with those specifications, it is of little surprise that this is such a great computer.
It’s also intended for some of the most demanding 3D and AI tasks you’ll find out there, rather than for people who spend their time writing about tech — though this machine can open multiple tabs in Chrome without stuttering, so unleashes real productivity boosts even at my level.
Apple Let’s get one thing out the wayThat’s not to say some pro users lack reservations about it. Many are frustrated that neither the RAM nor SSD are user serviceable, while the lack of a keyboard and mouse in the box chimes oddly in a computer that costs five figures.
In Apple’s defense, in these pro markets most users probably already own better keyboards and mice than you’d find in the box, while the massive performance benefits you’ll find with the M5 Ultra chip are in part realized because RAM in Macs is built to be part of the processor itself.
That SOC design boosts efficiency, cuts heat dissipation, and makes for great performance at low wattage relative to other machines. Changing the way memory is installed on the chip would compromise Apple’s silicon architecture, which Apple doesn’t want to do.
It’s all about the architectureThe Mac is powered by a quad-die chip built using Apple’s UltraFusion process. Inside is an engineering marvel. The 80-core GPU brings neural accelerators, making these Macs truly phenomenal machines for building, developing, training, or running AI models. Apple’s unified memory tech is a godsend for tasks like these as it scales to handle… well, most anything you throw at it. Efficiently.
Apple’s coupled chip speed with performance across the system. That means an advanced storage controller, superfast NAND, and really fast, next-gen SSDs for twice the read/write performance of the last model. This basically means the chip can grab big dollops of data and very swiftly push them around the system all the way from storage to display. Then there’s the rest of the advanced tech to consider, including the inclusion of four ProRes accelerators, which means my test Mac can deal with up to an incredible 33 streams of 8K ProRes video.
This is a machine that can happily handle massive multi-camera editing, racing through dozens of high-res angles at once to field the perfect shot. Think live sports, concerts, and movie shoots. Not only this, but all those streams are at normal res, no conversion required — no sitting around waiting for low-quality proxy files.
Apple A bicycle for several mindsI’m thinking a full-flight video rendering data server in an 8-inch box that consumes perhaps 10 cents an hour at peak power (c. 480 watts). I’m also thinking of it as an on-premises AI system for me, the family, or any enterprise.
Compared to the previous equivalent mode, the M3 Ultra, Apple says the chip brings up to 4.3x faster AI performance, up to 1.8x faster GPU performance, and up to 1.3x faster CPU performance. It’s also almost ten times faster than the M1 Ultra for AI.
None of this is accidental. All of it is designed. This whole creation is architectural; it leans heavily into Apple’s software and hardware integration, which now also extends to the design of the processor itself. Making the RAM user-serviceable would limit the performance of the machine, which at this price and in this sector of the market seems a little counterintuitive.
Sure, you can build yourself something pretty powerful using a Ryzen 9 chip that consumes 900 watts at peak and runs hot. Or you can put Apple’s silver box on your desk and barely hear a thing as it crunches through ‘god tier’ AI models your Ryzen can’t handle without additional GPU’s. All the same, if you want to configure your own memory you do have a choice — it’s just not a Mac.
Choice is niceI know what I’d choose. Based on a weekend of using the Studio, I’ve found what it does is beyond most of the feeble tests mere mortals like me can cook up, so I thought you might want some benchmarks:
Geekbench 7
- Single-core CPU: 3,771
- Multi-core CPU: 52,350
- GPU (Metal): 360,019
- GPU (OpenCL): 214,466
Cinebench
- CPU (Multi-thread): 18,052
- GPU: 141,480
Putting these numbers into context, Apple explains what these numbers mean when compared to the M1 Ultra Mac Studio:
- 2.4x faster project builds in Xcode
- 4.7x faster render performance in Redshift
- 9.8x faster time to first token performance in LM Studio
- 15.4x faster CopyCat ML training in Foundry Nuke
Of course, with these machines built to work with and manipulate huge files, one roadblock to performance will be storage, right? Not on this Mac. Apple says it has deployed a new storage controller tech in the computers, which works with the speediest NAND memory it could find to deliver twice the read and write performance we got from the last generation of this system.
This gives it plenty of horsepower for flinging files about, with Blackmagic’s Disk Speed test giving me exceptional results: 13,941MB/s write and 11,350MB/s read speeds. These speeds are indeed double the performance of the previous generation.
It also means this Mac Studio can handle data transfers faster than almost anything out there, making it happy to handle multiple streams of uncompressed 8K RAW video, heavy compositing workloads and, of course, AI development, machine learning, or running your own on-premises AI models. Install the models you want to use and use them to your heart’s content. Run it headless if you like. I did.
Apple Headless, no hangingI know a lot of you will end up wanting to run some kind of headless setup using this Mac. You’ll have it working furiously as your domestic or business AI server, chewing through your data, vibe coding opportunistic app creations, rendering video off your main Mac, and more. In my own little experiment, I found myself typing sentences for this review (this sentence, actually) on a Mac mini using a keyboard on a MacBook that happens to have the Mac Studio in its active window over vnc, and nothing ran slow. It means that if you run this Mac headless, it’s no slouch.
Better yet, once you have the Mac set to run as a headless unit, you’ll be able to download LM Studio, install your choice of AI, and chat to your heart’s content. Your AI running privately and securely for you on your device, and — one more thing — it’s fast and responsive. What’s not to like? I used it to design and develop a capability test to put the Mac through its paces.
Apple’s focus on AI is strategic, of course. Apple knows its hardware has pretty much occupied the AI development space, to the extent that almost any LLM you use was probably at least in part made on a Mac. AI is up there with CAD and medical imaging among the most demanding tasks you can do on any PC, let alone a Mac. And these Macs can handle all those tasks. I did want to try stringing four of these Macs together to run as an AI cluster, but at $12,000+ each that wasn’t going to happen.
Buying adviceMost of us don’t need this Mac. We probably never will — which is why cost is not the point here. This Mac is about performance, full stop, and that shows at every layer: a faster processor, blistering SSD storage, unified memory that scales to the task, and a storage controller fast enough to leave most other PCs gasping in the dust. From the software to the silicon, it feels like Apple’s engineers raided every high-end tech they had and crammed it inside this good-looking silver box.
The real question isn’t whether this Mac is impressive — it obviously is — but if it’s impressive enough to justify an upgrade if you already own the previous model. Things get a little more nuanced if that is the case. The M5 Ultra is a genuine step up: the processor gains are significant, and the storage speed increase alone will matter to plenty of pro workflows. But last year’s Mac Studio was already so far ahead of most computers that “significantly better than the best thing available” doesn’t automatically mean “worth $12,000+ to replace.”
My take: if you’re still on an older computer and need the extra processing power or storage throughput for demanding work, this machine delivers in spades. If you bought last year’s M3 Ultra model and it’s handling your workload fine, there’s no urgency. You’re not falling behind, you’re just not on the bleeding edge. All the same, I so wish AI-driven price inflation hadn’t pushed these systems quite so high in price.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Beware these fake websites selling subscriptions to AI assistants
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes.
The sites impersonate AI products with solid reputations, including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, in addition to some that no longer exist (such as Omegle, a chat service shut down in 2023) or are less reputable.
All the fake websites were polished and incorporate genuine Google authentication elements inviting users to “Sign in with Google” to enhance credibility on the path to charging visitors’ payment cards anything from $10 a month to as much as $2,000 for a year’s access to the promised AI and software services.
“The sites we examined did not use fake password forms or push malware downloads,” Malwarebytes researchers said in a blog post describing their discovery. But some of the sites asked users to upload documents, recordings, or other files in order to unlock the advertised services.
The danger for enterprises is if would-be customers of such services think they’re getting a good deal for their departmental budget and don’t want to involve IT in the buying process. Shadow IT is bad enough when the products are legitimate, but in these cases there’s no knowing where the data gathered will end up.
Malwarebytes’ researchers suspect that all the fake subscription sites it identified are run by the same person or group, since they were all created using the same website creation kit based on identical underlying files and with closely related developer email addresses shared across them.
The website creation kit is a legitimate commercial offering that provides account management, billing, file storage and other administrative functions, Malwarebytes said, noting its makers claim it can launch a website in an hour and that, after a one-time purchase, additional templates cost only about $2 each.
The fake sites use genuine Google sign-in pages rather than fake password forms. Visitors enter their credentials on Google’s website and the applications request basic information such as their name, email address and profile picture. Malwarebytes said the sites it examined did not request access to Gmail or Google Drive.
Google’s consent screen generally identifies the application requesting access and provides developer details, Malwarebytes noted. But on the fake websites, that screen displayed free webmail addresses for the developer contacts instead of addresses belonging to the well-known AI services promised. In the case of the unfamiliar AI brands, the sites provide little independently verifiable information about the businesses selling the subscriptions, the researchers added.
Look past the polishMalwarebytes recommends that users look beyond a site’s design and the presence of familiar authentication options when deciding whether an AI service is legitimate. These include checking who operates the service, looking for verifiable company information and examining the developer details shown during Google authentication.
It also warned users not to upload sensitive documents, recordings or other data to unfamiliar AI services, particularly when the business behind the site cannot be independently verified.
For services connected through Google, users can review the connections in their Google Account and remove services they no longer trust or recognize to prevent future access.
California joins US states clamping down on data center gold rush
The state of California has joined the growing number of governments and communities at all levels across the US taking proactive, even preemptive, measures to keep data center development under control.
California Governor Gavin Newsom signed what he called the “most comprehensive data center laws in the nation” on Monday. While the seven bills don’t block data center development, they do reinforce requirements for reporting data centers’ energy and water use, and ensuring they pay their fair share of utility costs.
Other states — and even local community groups — have been taking more direct action. At least 45 projects worth an estimated $68 billion were blocked or delayed in the US in the second quarter, according to research by Data Center Watch. There are now 843 identified opposition groups in the US, and 49 states are scrutinizing data center development, it said.
Project disruption remains at an “elevated level” and opposition has become “more local and project-specific,” targeting permitting, infrastructure, and individual policy decisions, according to Data Center Watch.
Some communities are getting ahead of development by preemptively mandating data center development moratoriums, even before developers have filed permit applications or expressed any interest at all.
Data centers no longer ‘invisible infrastructure’“The growing pushback is not surprising,” said Abbas Jaffery, principal advisory director at Info-Tech Research Group. “The conversation around data centers has shifted from a routine IT capacity decision to a complex energy, community, and economic issue.”
Anti data center sentiment is higher than it’s ever been, as AI gobbles up more and more resources and requires never-before-seen magnitudes of data.
State-by-state legislative activity is accelerating in response, with 30 state governments adopting or introducing legislation, resolutions, and executive actions targeting siting, cost-sharing, and electricity and water constraints, Data Center Watch reported.
Further, regulatory scrutiny is increasing across 49 states, and communities are clamoring for local, state, and national politicians to respond to data centers already in development.
California is a case in point; Newsom has just signed seven bills addressing data center costs, disclosures, and infrastructure. Operators will be required to pay their “fair share” for updates to the state’s electricity grid, comply with California energy procurement requirements, and bring on new clean energy supply.
Data center companies will also need to provide information on water use, supply, efficiency, and drought planning, and pay for any required infrastructure upgrades. Additionally, data centers will be ineligible for blanket environmental exemptions; they must demonstrate that their projects meet state energy, water, and fuel consumption standards prior to approval.
“As the innovation economy continues to grow, data centers are being presented as a solution, but with little thought or oversight of what that means for nearby communities,” Newsom said in Monday’s announcement. The goal of the bills is to protect communities from “shouldering the cost as industry reaps massive profits.”
Other regulatory initiatives can be found across much of the country: Independent electricity marketplace Electric Choice tracks 321 moratoriums and restrictions across 32 states, with pending legislation in 17 states. Just last week, Virginia Governor Abigail Spanberger unveiled a Data Center Accountability Framework, while in July, New York Governor Kathy Hochul placed a temporary moratorium on hyperscale data centers in her state.
“Data centers are no longer invisible infrastructure,” said Justin St-Maurice, technical counselor at Info-Tech Research Group. “They are being built in communities, where residents can directly experience the noise, energy demands, and other consequences.”
Enterprises must take a new approachWhile some concerns may be more legitimate than others, all require a stronger understanding and partnership between builders and communities, noted Matt Kimball, VP and principal analyst at Moor Insights & Strategy.
“Dismissing fears around water consumption, for example, by showing a spreadsheet at a local planning committee meeting, doesn’t resolve concerns for a community that is already suspicious,” he said.
Community opposition “is real, and it’s everywhere,” and the new strategic pillar for data center builders and operators is social outreach, Kimball noted. Those proposing data centers must be able to provide credible answers about usage and community impacts, listen to concerns, and commit to transparency.
Most enterprises aren’t building gigawatt campuses, he pointed out, but they are paying the price downstream in colocation availability, lead times, pricing, and other factors. Predictability is the big question, supply is already tight, and every delayed project removes capacity factored into forecasts.
“IT leaders should treat power and space as a strategic constraint rather than a facilities line item,” he said.
This means extending planning horizons and committing to colocated capacity earlier on. Ask operators where their sites actually are in the permitting and entitlement process, not just their roadmap, Kimball advised. Also, he said, “squeeze every bit of productivity out of the footprint you already own.” For instance, older servers consolidated onto current-generation platforms can free up rack space and power for AI projects without “a single extra square foot of data center space required.”
Buyers should also be deliberate about workload placement and underlying infrastructure. What can sit in the cloud and what needs to be closer to the premises? What kind of inference is running? “Not every workload requires the latest and greatest GPU cluster,” Kimball said; in fact, some don’t require a GPU at all.
He pointed to companies like Furiosa AI that are building more efficient hardware expansion cards, while CPUs like Intel’s Xeon feature on-chip accelerators that can efficiently handle inference workloads. Nvidia, for its part, is claiming its latest technology advancements can provide up to 40% more GPU capacity.
He noted that other interesting technologies to watch are two-phased cooling, and heat recapture and reuse. For instance, at one data center in Switzerland, generated heat is repurposed to heat nearby homes.
‘Radical optimization’ the way forwardInfo-Tech’s St-Maurice agreed that IT leaders cannot assume they can rely indefinitely on public cloud capacity at a predictable cost. Some organizations are reconsidering their compute strategies as token costs rise, repurposing internal data centers, running open-weight models, and using a tiered approach combining local, enterprise, private cloud, and public cloud resources.
“The goal is to direct each workload to the most cost-effective environment and gain more control over operating costs,” he said. While regulations will likely lead to innovation, more space, cooling, and power alone will not solve the problem.
The more sustainable path is “radical optimization,” St-Maurice said: Reducing energy cost per token and using compute more efficiently.
Indeed, when considering new data centers, enterprise leaders must ask whether the supporting power, cooling, water, and grid infrastructure actually exist, in what timeline, and at what cost, Info-Tech’s Jaffery advised.
“Organizations that integrate physical grid and power constraints into their IT architecture early will maintain speed to market,” he said, “while those that treat power as an afterthought will face costly deployment delays.”
This article first appeared on Network World.
Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’
A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday.
But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the May incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: Google, Anthropic, OpenAI and Meta. All four companies experienced agent misbehavior resulting in cybersecurity incidents, but of the four, only Google never publicly disclosed its agent’s activities. Indeed, it didn’t reveal the breaches at all until contacted by a WSJ reporter.
Irregular described the incident in August, around the same time as Meta published its version and Anthropic and OpenAI revealed theirs.
The Journal story noted, “the hacks occurred while the model was participating in a capture the flag exercise conducted on infrastructure belonging to Irregular to test the model’s cybersecurity capabilities. It was tasked with retrieving information from software operated by a fictional company inside the testing environment. The fictional company shared the same name as a real company. Although the model wasn’t intended to be able to get online, internet access was unintentionally made available, according to Irregular.”
The three small companies whose systems were violated had, according to one source familiar with the testing, “almost no [cybersecurity] infrastructure.” In short, none of the three was in a position to put up much of a fight when the Gemini agent successfully broke in.
According to a Google official, who asked to not be identified, the name of the public repository was similar to the name of the fake company. And within that repository were the names and credentials of the other two companies.
Most analysts and consultants focused not on the hacks themselves, but on the reasons Google gave for being silent on the successful attacks.
Google said that the agents stopped as soon as they realized the victim companies were real businesses. “No harm was caused,” the Google source said. “There was not an issue of model misalignment.”
The source confirmed the Wall Street Journal story, which said, “Google compared the episode to a ‘bug bounty’ program in which hackers are rewarded for finding and reporting security vulnerabilities to their owners” and then quoted Heather Adkins, Google’s vice president of security engineering, saying, “In this case, the model acted appropriately.”
Define ‘harm’Analysts generally disagreed.
“What does Google define as harm? Is it the same as the target company? Downtime, unauthorized access, and exfiltration of data may not result in immediate harm, but could have lasting impacts,” said Ryan O’Leary, an IDC research director. “The comparison to a bug bounty program is tenuous at best. If I broke into Google HQ and took nothing and caused no harm, it is likely I would still be prosecuted for trespassing.”
Nader Henein, a Gartner VP analyst, had a similar take on the situation.
“If a member of my neighborhood watch broke into my house, walked around a little bit and then left, I’m fairly certain the authorities would not classify it as an act of civic engagement,” he said. “In this case, if the impacted sites had bug bounty programs and Google had programmed the agents to discover bugs, the rebuttal might make sense, otherwise it is quite a weak argument.”
That said, he added, “Google does make an excellent point when they underlined ‘the importance of training powerful AI models to act responsibly’ and I look forward to seeing how Google plans to ensure that this doesn’t happen again.”
Inappropriate behaviorBut Jeff Pollard, VP/principal analyst at Forrester, took exception to Google’s assertion that the Gemini model had behaved appropriately.
“The model pursued an authorized objective through an unauthorized path, crossed from a simulated environment into real companies and gained access without consent,” he said. “This is another area where regulations haven’t kept up with the pace of technology change. There are two sides to this: regulations with respect to the agentic escape and intrusion, and then the regulatory issues for the victim companies in terms of their requirements for disclosure. Google is only responsible for one half of that equation.”
Erik Avakian, technical counselor at Info-Tech Research Group, also noted that it’s critical that companies have rules about when to disclose unexpected and problematic model behaviors.
“I don’t think every unexpected thing an AI model does needs to become a public incident. But there should be a clear line once an autonomous system crosses an authorization or trust boundary,” he said. “If an AI system leaves a controlled environment, accesses a real third-party production system, uses credentials, retrieves data, escalates privileges, or takes some other action that was never authorized, that should, at minimum, trigger disclosure to the affected organization along with a formal incident investigation.”
Even if there was no damage from the intrusion, Avakian said, public disclosure should happen “if the incident exposed a larger or repeatable problem with the controls around the model.”
Independent technology consultant Steven Eric Fisher also stressed that companies need to be strict and consistent about disclosing agent mishaps.
“What I find most puzzling about these incidents is not simply that an AI system crossed a boundary,” he said. “It is the emerging posture around culpability once it does. Stopping after an authorization boundary has already been crossed is not the same thing as preventing the boundary from being crossed in the first place. I do not think ‘the AI did it’ can become an accountability boundary.”
Control failureAnd, argued Justin Greis, CEO of consulting firm Acceligence, the absence of harm and absence of significance are not necessarily the same thing.
“An event can be consequential because of what it demonstrates about a system’s capabilities or controls, even when everyone gets lucky and nobody is damaged,” Greis said. “Gemini stopping itself after recognizing that it was inside a real company’s environment is a positive safety signal. Gemini being able to get there in the first place is a control failure. Both things can be true at the same time.”
Frank Dickson, principal analyst at Dickson Research, articulated the harshest criticism of Google.
“The model’s behavior is the least interesting part of this story. Google’s conduct afterward is the most damning part,” he said. “This isn’t a story about Gemini going rogue. It’s a story about one shared testing vendor’s infrastructure mistake hitting four AI labs at once, and about Google being the slowest and least forthcoming of the four in telling anyone about its own copy of that failure.”
He pointed out, “Irregular notified all four labs in late July. Google didn’t go public until September 18, seven weeks later, and only after the Journal called for comment. Let’s face it: that’s not a company that judged that the incident didn’t warrant disclosure. That’s a company that watched three competitors take the reputational hit for the same underlying failure and waited to see if it could avoid its turn. It couldn’t, and the only reason we know any of this is that a reporter asked.”
This article originally appeared on CSOonline.
Microsoft is pulling the plug on Publisher. What now?
It’s the end of a very long era: As of October 2026, Microsoft Publisher, in the company’s words, “will reach its end of life.” That makes it 35 years since the desktop publishing tool was launched back in 1991.
What does reaching end of life mean? That depends on what version of Publisher you use. If you get Publisher as part of Microsoft 365, it truly means the end of the road. After October 1, Publisher will no longer be available to those who use it as part of a Microsoft 365 subscription. Your personal publisher files (.PUB) won’t be deleted, but you won’t be able to open them in Publisher anymore — and most other desktop publishing software can’t open PUB files.
If you have a copy of Publisher that is part of Office 2021 or Office LTSC 2021 (Office Long-Term Servicing Channel 2021, for business and government computers), there’s good news and bad news. The good news is that those versions of Publisher (sometimes called “perpetual” versions) won’t die. You’ll still be able to use the software to create new files, open and edit old ones, and so on.
However, there is a caveat: After October 13, 2026, Publisher won’t be supported by Microsoft. That means it won’t get any updates, including security updates. So your PC will be more vulnerable to being hacked. Any bugs Publisher had before that date will still be bugs after that date. You also won’t be able to get any technical support for it.
If you’re comfortable with that, you can keep using Publisher. However, at some point you’re likely going to want to stop using it.
So what to do with all those PUB files on your computer for newsletters, marketing materials, and other business publications — as well as personal items like flyers or birthday invitations?
We’ve got your back. Here’s what you can do to make sure those projects live on, or at least that you have access to them after Publisher bites the dust. We’ve also provided suggestions on what programs you can use to create the kinds of documents you used to create with Publisher.
Convert PUB files to PDF using PublisherIf you’re reading this before October 1 and still have a working copy of Publisher, or if you have a perpetual version of Publisher and you’re planning to abandon it, you can manually convert PUB files to other file types — most notably .PDF, which is your best bet. PDF files should look just like whatever documents you’ve created with Publisher, which means your files will live on. Perhaps more important is that there are many programs that can either edit PDF files directly or save them into another format and edit them in that format.
For example, Word can import PDF files, which you can convert to .DOCX files, and either save them in that format or as a PDF. (You can save them in other file formats as well.)
Publisher also saves to other file types, including multiple graphics formats including .TIF, .JPG, .PNG, .GIF and .BMP. You can also save them in various web formats.
To do it, in Publisher, open the file you want to convert, go to File > Save as, and select a file format and folder location.
Mass convert PUB files to PDFIt can be time consuming to save individual PUB files if you’ve got a lot of them. Microsoft offers a free way to mass convert them to PDF files, by offering a free a script that does just that. Keep in mind, though, that you will need to be comfortable with editing scripts, because you will most likely need to make changes to the script, such as the name of the folder where your PUB files live, where you want them exported, and so on. You also need to understand PowerShell.
There’s one caveat to this: The script only works if you have a working, licensed version of Publisher on your PC. If you have one and you’re comfortable working with scripts, here’s what to do:
- Download the script.
- Edit the script. See Microsoft’s documentation for help.
- Open a PowerShell window that has the execution policies you need to use.
- Run the script.
For more details, go to the Microsoft support page “Microsoft Publisher will no longer be supported after October 2026” and scroll to the “Example conversion script” section.
Alternatives you can use instead of PublisherJust because Publisher is dead doesn’t mean you can’t create the kind of documents you used to in it. There’s plenty of software out there to do it. Depending on what you used Publisher for, you may need to use one or more alternative programs.
You may even find that many of these programs are better bets than Publisher ever was. There are multiple reasons Microsoft killed Publisher, but one is that it was getting long in the tooth and wasn’t as capable or easy to use as newer programs. Publisher also didn’t work with mobile devices, didn’t allow multiple people to work on the same document, and didn’t have web-based versions. Many, but not all, competing programs do.
Here’s a list of what you can use.
Microsoft 365 appsIf you got Publisher via a Microsoft 365 subscription, there’s good news: You have everything you need to create new Publisher-like documents. And if you’ve saved PUB files with designs and content you may want to use again converting them to PDF files means you’ll be able to reuse the content. You might be able to reuse the designs as well, although not necessarily.
The two main Microsoft 365 programs that’ll do the work for you are Word and PowerPoint. Note that if you’re using PDFs converted from PUB files, Word does a much better job than PowerPoint of keeping the initial designs intact.
When to use Word and when to use PowerPoint to create the kind of documents you used to create with Publisher? Here’s what Microsoft recommends:
Type of documentWhich app to useAds or flyersWord or PowerPointBrochuresWord or PowerPointBanners, signs, or postersPowerPointCertificatesWord or PowerPointBusiness cardsWord or PowerPointBusiness invoices, applications, and formsWordCalendarsWord or PowerPointEnvelopesWordLabelsWordLetterheadWordNewsletterWordPrograms, folded paper projectsWordCards (greeting, compliment, etc.)Word or PowerPointNote that you can also try to create documents like posters, banners, signs, and greeting cards with Microsoft Designer, the AI image creation tool that comes for free with a Microsoft 365 subscription. With Designer, you create these materials using text prompts, which means you won’t have fine-tuned control over the designs the way you do in Word or PowerPoint. On the other hand, they’ll likely be more visually powerful than anything you can create with Word or PowerPoint.
Microsoft also recommends Microsoft Create, a tool in its Copilot AI app that incorporates Designer and other creative apps and offers customizable templates for various graphics projects.
Other alternatives to PublisherIf you don’t have Microsoft 365, there are several alternatives to Publisher you can try. Unfortunately, many of them are expensive and difficult to use. Here are some free or low-cost options that are fairly straightforward to use.
Affinity is a great bet and does pretty much everything that Publisher did. It’s free for individuals and businesses, but is also available as a paid product for enterprises. If you want image creation software as part of the package, you’ll have to pay to use the Canvas suite, which includes Affinity.
LibreOffice Draw is part of the free LibreOffice suite. It’s a good bet for flyers, brochures, newsletters, posters, and certificates. It has the added benefit of being able to directly import PUB files. Keep in mind, though, that although it can import PUB files, its ability to accurately capture complex layouts and documents, table formatting, and WordArt can be flaky.
Scribus is a free, professional-level tool for desktop publishing. It’s tough to use, but gives you even more control over your creations and layouts than Publisher did. If you’re not a professional, this program isn’t for you.
Marq has similar capabilities to Publisher. Individuals can try it for free for three projects. Paid versions cost $10 per month.
Microsoft mops up after Patch Tuesday broke logins, audio, Excel
Microsoft fixed hundreds of security flaws in its September Patch Tuesday software updates — but it also introduced some annoying bugs. Now it has fixed some of them with a series of out-of-band updates.
Excel 2016 users were among the victims, as Patch Tuesday update caused certain paste operations to fail. A hotfix in update 5002665 partly fixes the problem, but if operations still fail then users will have to resort to using Excel’s “Paste special” command instead.
Users of Remote Desktop Services had found some instability in the application where RDP connections failed or where servers were left hanging at “Please wait for the Remote Desktop Configuration”. The issue was resolved with update KB5129194.
Another issue that users were facing after the update was a problem with some Credential Guard-protected machine accounts. Some users discovered that they had lost some security within Active Directory which meant that some devices were not recognized. The solution involves temporarily preventing Machine Identity Isolation enforcement before installing a fix. Microsoft said that it would be introducing a permanent solution in a future update.
Another issue raised by the September update affected applications that use HCS-managed virtual machines. In some cases, Plan9 users found that they were not able to access folders shared from the Windows host.
Applications that depended on these shared folders sometimes displayed an error indicating that no Plan9 drive shares were mounted. Microsoft said that Claude Cowork and the Windows Subsystem for Linux (WSL) were two of the applications affected, while Hyper-V virtual machines that did not have the Plan9 feature were not affected.
Microsoft also fixed an issue with USB Audio Class 1.0 devices. Some users found that no sound was coming from their audio devices after the Patch Tuesday update, and volume controls were unresponsive. Now restored sound, so affected users can once again make and take Teams calls.
In addition to these fixes from the September update, there was also an issue for some users where they were incorrectly informed that Microsoft Defender had been switched off. This has now been resolved.
GhostCode attackers abuse device codes to take over Microsoft 365 accounts
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.
The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing, has been seen in other attacks before. As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.
GhostCode poses as one such device, gets Microsoft’s OAuth to generate a device code and then convinces the victim to enter it on Microsoft’s authentication page. The victim then signs in and completes multifactor authentication as normal — but the authentication is for the attacker-controlled device, allowing them to obtain the resulting authentication tokens. These tokens are then used to register attacker-controlled devices, obtain additional credentials and establish persistence in the victim’s Microsoft environment.
In the campaign observed by eSentire, the attack involved a social-engineering setup where attackers pose as procurement officers through a web contact form before moving conversations to an NDA-themed HTML file. Opening the file took the victim to the device-code phishing page.
Stolen tokens allow persistenceGhostCode’s post-authentication activity is focused on turning the stolen access into persistence inside the Microsoft environment. Once access was granted, eSentire recorded nine successful API calls over a 78-second period, involving Microsoft Intune Enrollment, the Device Registration Service, Azure Active Directory and Microsoft Graph.
Three devices were registered during that time, at 28, 53 and 77 seconds after authentication, a sequence eSentire said was automated.
The third device was also successfully enrolled into Intune, Microsoft’s cloud-based device management service. eSentire noted that Intune enrollment survived token revocation: The attacker-created device remained in the tenant until it iwas explicitly removed.
The attackers also obtained a Primary Refresh Token (PRT), which eSentire called “one of the most powerful” credentials in a Microsoft identity environment.
“Obtaining a PRT via device code abuse gives the threat actors essentially SSO-equivalent access to the victim’s entire M365 environment for the PRT’s lifetime — including any service not explicitly protected by a Conditional Access policy requiring a compliant device,” eSentire said, adding that the token persists 14 days by default.
The attackers also employed multiple evasion techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, checking for bots, and using Cloudflare Turnstile to keep security tools away from the phishing page.
What defenders can doTo defend against attacks like this, eSentire’s researchers recommend restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who do not need it. It also advises monitoring the Device Registration Service for multiple device registrations from a single non-interactive session, and looking for activity involving the user agent python-requests following device-code authentication.
Auditing Entra ID for devices matching GhostCode’s naming pattern and correlating successful device-code authentication with subsequent Python-based requests, should be able to catch an attack in progress, the company said. It shared a list of indicators of comprise related to the campaign to aid detection.
GhostCode adds to a growing number of attacks abusing device-code phishing to target Microsoft’s OAuth authentication flow. Recent examples include attacks using the “EvilTokens” phishing-as-a-service (PhaaS) kit, a campaign reported by KnowBe4 in February 2026, and activity observed in December 2026 involving multiple clusters, including both financially motivated and state-sponsored actors.
With Siri Recap, Apple threw a punch at OpenAI no one saw coming
John Ternus’ Apple threw a curveball at OpenAI with Siri Recap on Apple Watch, accelerating a conversation about privacy and data protection in an AI-augmented digital era. It’s a move that may yet contribute to finding a balance between scary surveillance and digital convenience.
Think of it this way: Apple operates on such a big scale that it must have expected the feature to face regulatory and legal investigation. We know Apple has tried to stay on the right side of existing data protection and privacy laws by ensuring that its system doesn’t keep personal data, audio recordings, or transcripts, but one thing it doesn’t do is achieve consent from everyone who may be exposed to the feature. That’s a big no-no in some places, and it’s logical to think Apple expects some pushback to that.
Apple thought it throughFrom where I sit, it looks like Apple has thought about this. You only need to look to Apple Worldwide Marketing VP Greg Joswiak’s recent comments on the matter to see this, as he very swiftly tried to position Recap as little more than the digital equivalent of notebook and pen, or a smartphone set to record. The difference is that using the latter still technically requires consent in some places, while using a pen and paper does not.
But if Apple has thought about it and anticipates oversight, then there are benefits to be had. Apple is not the only company seeking to use ambient data monitoring and AI tech to create new product families. Meta, OpenAI, and others also seem to be exploring ambient monitoring with AI, possibly with less of a commitment to privacy.
While it’s true as a general rule that your rights in a public place are weaker, they are not nonexistent, and both Apple and OpenAI must expect to face regulatory pushback on what they make.
This could be why Apple has accelerated regulatory conversation concerning such tools by introducing Siri Recap. The argument is that by forcing legislatures to make decisions on such matters, Apple is effectively throwing a punch at competitors who must also work within the law. (Though with data encryption such a huge piece of the privacy jigsaw, it’s fair to say that some nations may yet mess things up.)
Because it isn’t just about AppleIt makes sense for international lawmakers to create a harmonized framework of legislation to govern such products, particularly as they clamber headlong into so many different layers of protected personal existence. Apple’s decision to create this product at this time means regulators will now have to decide where to draw the line.
We can surmise where Apple thinks that line will be on the basis of what Joswiak said and the actions the company has taken with a variety of guardrails to maintain privacy and data security. The idea it seems to be moving toward is that by stripping out the stuff we want kept private, it has effectively built the digital equivalent of writing a few notes in your book with a pen while a conversation takes place.
If Apple’s argument prevails, then those will become the regulatory-approved principles to define what other companies must do with their devices in this space. Including Meta and OpenAI.
Caught in a trapThat’s going to be fine for some entities, but companies that want to build businesses on your data will be disadvantaged by those decisions. Apple’s approach is that by defining the space, it also knows precisely what it must do to compete within it. That’s going to make for a far more equal playing field as AI hardware reaches the market.
A second outcome Apple may also be looking at is that by challenging regulators to sit down and declare what data and privacy rights consumers should enjoy in an AI digital age, it also identifies terms of reference to inform how its future AR glasses handle and process external video. Right now, it’s plausible to imagine a similar arrangement in which actual video is never stored, just classified and summarized like audio in Siri Recap.
And, of course, one final potential outcome might be that if Apple manages to convince the EU that its system provides an appropriate balance between consumer privacy and security and third-party product design, then it may forge a path through the impasse that currently stops Apple Intelligence from working in the EU. This could be a blueprint of the intermediary architecture Apple originally proposed to the EU when it first introduced Apple Intelligence. We’ll have to see if Europe accepts that.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
More and more people believe that AI will take away jobs rather than create new ones
A new survey from the Pew Research Center shows that a majority of people worldwide now expect artificial intelligence to lead to fewer jobs rather than more. The survey is based on responses from 37 countries. In 34 of these countries, it is more common to believe that AI will result in fewer jobs over the next 20 years. Concerns are greater in wealthier countries.
In Sweden, for example, there are signs of growing skepticism toward the technology. The proportion of Swedes who are more concerned than enthusiastic about the increased use of AI has risen by nine percentage points in one year. This is the largest increase among the countries compared over time. Concerns have also increased among both younger and older Swedes.
In the US, 71% of respondents said they think AI will lead to fewer jobs over the next 20, compared to 5% who say it will lead to more jobs. Most pessimistic were the Australians, with 76% predicting fewer jobs because of AI. The most optimistic groups were in Nigeria and the Philippines, where just 26% of respondents predicted AI-induced job losses outweighing gains.
Globally, many also fear that AI will widen economic disparities. In none of the 37 countries do more than a quarter of respondents believe that AI will reduce inequality.
However, views on the technology are not entirely negative. The median for the 37 countries shows that 41% say they feel roughly equal amounts of concern and enthusiasm about the technology. People who have heard and read a lot about the technology also tend to have a more positive view of it.
This article was originally published on Computer Sweden.
Related:
Why AI companies are really pumping the brakes on their models
There we were, listening to AI leaders doing their usual spiel: AI is great! AI will cure cancer! AI impact will be “unprecedented, perhaps 10x of the Industrial Revolution at 10x the speed”! AI will find a final answer to “Why do socks disappear in washing machines?” (Well, maybe not the last one. Some things may be beyond us and our clever inventions.)
Then all the top AI leaders screamed as one: “Stop!”
Why? Well, it all seems to have started when AI researcher Jacob Coxon quit his job at Anthropic and proclaimed on X, “The people building AI earnestly believe that it could kill us all by the end of the decade.” Evan Hubinger, Anthropic’s Alignment Science Lead, immediately chimed in: “we really do earnestly believe AI could kill all humans! I personally think it will be >10% within the next decade.” And the world went nuts.
This added fuel to the “AI is untrustworthy” fire as more details came out about OpenAI’s Hugging Face fiasco and agent attacks on German programming wiki sites, while Anthropic has now racked up four known hacking attempts on other sites. Boy, is AI safe or what?
So the very next weekend, three of the top AI CEOs — Dario Amodei of Anthropic, Sam Altman of OpenAI, and Elon Musk of xAI — all urged an AI frontier model slowdown for safety reasons. Amodei, the most articulate of the trio, argued, “We must slow the pace at which we improve the capabilities of AI models” because we’re losing control of our AI systems (Really? Golly! Who knew?) and that an AI agent “swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage).”
Well, he’s not wrong. Sorry, President Donald Trump, but safe AI requires more than a “strong and smart” president. Even his Truth Social supporters think his stance on AI is wrong.
Like a stopped clock, Trump was right about one thing when he sputtered, “The only one that is happy about it is China.”
You see, just because some big US AI companies say “slow down!” doesn’t mean Chinese AI vendors will pump the brakes on their model development. Why would they?
Or, for that matter, why would the multitude of smaller AI companies or open-source AI developers? There are AI startups getting tens of millions in Series A rounds on nothing but a good pitch. You think they’ll tell their investors, “We’ll get right on improving our model… next month”? I don’t think so.
Besides, as wise writer Corey Doctorow observed, the narrative around “chatbots that wake up, ‘set their own goals,’ and ‘spontaneously’ start hacking servers — is fake. It doesn’t have ‘a 10% chance of ending the human race.’ The Hugging Face hack isn’t a mysterious, supernatural occurrence. It’s a Python loop and a chatbot. The people responsible didn’t accidentally create god: they created autonomous malicious software and then failed to closely monitor it, resulting in it doing something both foreseeable and bad.”
Exactly so.
In other words, it’s not the development of more powerful models that’s inherently dangerous. AI agents haven’t gone rogue; they’ve just been meeting their assigned objectives in ways researchers didn’t expect or plan for. What’s dangerous is the AI firms’ failure to pay close enough attention to what their agents are doing in tests. In fact, OpenAI just admitted to screwing up even more!
As Meta’s high poobah Mark Zuckerberg tweeted, “Every lab has the responsibility and incentive to move at the pace required to train its models safely, and the ability to take its own actions to ensure that happens.” He then goes on to explain that that’s why Meta delayed shipping Muse. Sure, Mark, sure.
Let’s get real. The big American AI companies may hope a slowdown will ensure that their lesser rivals, in the US anyway, can’t catch up. But given how OpenAI’s circular financing keeps leaking money, another reason OpenAI might welcome a slowdown is to save cash on R&D.
It’s not going to work. We’re in steamboat time. Steamboat time? While we remember Robert Fulton for building the first commercially successful steamboat in 1807, everyone and their uncle were making steamboats as fast as they could. Soon steamboats were everywhere, and they sparked an economic boom. But they also caused many deaths because of shoddy construction and pilots racing them to ever greater, unsafe speeds. Hmm, does that remind anyone of anything recently?
Seriously, we’re not going to slow down. But doesn’t all this hand-wringing about safety do a great job of distracting people from the simple truth that AI isn’t delivering the productivity gains it’s been claiming all along?
By slamming on the brakes now, Big AI firms can obscure that they won’t be able to deliver the AI fantasyland they’ve been trying to con people into believing. A case in point: A recent McKinsey survey report finds that 80% of people say AI makes them more productive, but only 37% of companies see that reflected in their earnings. A number, they say, that hasn’t budged in a year. Let’s hide that damning number under the concern that we must slow down AI.
It also means AI leaders can hand-wave away their failures to actually generate a profit. Sure, NVIDIA is making money hand over fist, but for all the financial hype, none of the frontier-model companies is making money. Not one of them.
Yes, I know: Anthropic just told the Financial Times that it would be profitable for the second consecutive quarter if you don’t factor in all its expenses. Seriously? Seriously!?
Sure, its adjusted operating income (AOI) is set to be positive for the second consecutive quarter, but come on, AOI “profitability” is billions and billions of dollars from bottom-line profitability.
No, what this is really all about is AI leaders making the right noises to assure people that they really — no, really — care about securing their AI, while slowing things down to maximize their own profits and get rid of the competition.
Oh, I’m certain they also want to make things safer. I mean, just think about the lawsuits when loosely controlled Anthropic or OpenAI agents swarm and take down a major company. This will happen. They have no choice but to make them safer. Now, how will they do that? Given their abysmal track record, that’s a good question, and neither they nor we have an answer yet.
5 internet-improving Chrome extensions worth trying on Android
Browsing the web on Android sure ain’t what it used to be.
Earlier this week, we talked about how the Vivaldi web browser is bringing support for Chrome extensions to Android. Vivaldi has the same Chromium code foundation as Chrome but with lots of extra features and options. I’ve been using it on Android and the desktop alike for months now and can’t see myself going back anytime soon.
And with extensions now in the mix, Goog almighty, are things really getting interesting. We’ve already looked at five Chrome extensions that can enhance your efficiency on Android — and today, we’re rounding out that list with five more excellent extension options that work impressively well in the Android environment and can improve your mobile web meanderings in some commendable ways.
While the last additions were all about saving you steps and eliminating common mobile web roadblocks, this next batch revolves around the notion of supplementing or upgrading the actual web itself and the experience of working within different sites — even when they don’t always provide an optimal framework.
So refresh your memory on the mechanics of installing and managing Chrome extensions in Vivaldi, then read on and see which of these internet-improving Android Chrome additions hits home for you.
[Keep the knowledge flowing with my free Android Intelligence newsletter — one useful new thing to try every Friday!]
Chrome Android extension #1: Your web customization genieLet’s be honest: Most of the web isn’t exactly a pleasure to peruse. (Insert awkward pause here.)
But with an extension called Click to Remove Element, you can take total control and remove any element of any website that doesn’t please you.
Vivaldi already has some customizable ad and script blocking elements built in at the browser level, if that’s your jam, but Click to Remove Element is more about the stuff that those systems don’t automatically catch and hide — and it doesn’t have to be ad-related, either. It could be a pop-up video player on a site, a prominent button in a back-end interface, a logo or floating menu that takes up too much screen space, or literally anything else that annoys you on any website anywhere.
All you’ve gotta do is tap the extension’s icon, once it’s installed, then tap on any element on a page that you want to remove. And…
One tap, and boom: Any element on any website is invisible.JR Raphael, Foundry
Poof! It’s gone. If you tap the little box beneath “Remember” in the Click to Remove Element panel at the bottom of the screen, that change will stick and stay present every time you load the same page in the future.
Chrome Android extension #2: A paywall peeperFor the record, as a working journalist in this weird and sustainability-challenged state of modern media we’re in right now, I strongly believe in and endorse paying for publications you appreciate whenever the opportunity arises.
Sometimes, though, you just want to read a random single article from a source you don’t follow regularly. Or maybe you want to share something you’ve read from a paywalled site with someone who doesn’t subscribe and isn’t going to do so just to read this one little thing you’re sending them.
That’s where a site called Archive Today can come in handy. Archive Today captures live views of articles and then saves ’em in a way that can be easily viewed and shared without any subscriptions or sign-ins required.
And a Chrome extension called Archive Page makes it as easy as can be to send a page over to the service for that purpose. Install it, tap its icon (in your Vivaldi extensions menu or in your browser toolbar, if you pin the extension), and you’ll have your viewable, shareable link in no time.
The tool won’t work for every site, depending on the nature of the paywall — and, again, I’d highly encourage you to use it as thoughtfully and ethically as possible — but it’s a powerful option to have available and one that’ll absolutely come in handy.
Chrome Android extension #3: An Amazon price spyWhether you’re eyeing Amazon listings for work or maybe just for “work,” keep an extension called Keepa in your Vivaldi Android browser. You’ll never think about it or directly open it again after you’ve installed it, but it’ll add a helpful price tracking section into every Amazon listing you pull up on your phone so you can see how the associated product’s price has varied over time and know as soon as it drops again.
Keepa adds a helpful product price history and tracking option onto every Amazon listing in your browser.JR Raphael, Foundry
Just scroll down a bit on any Amazon page you open, with the extension installed, and you’ll find the info along with the “Track product” option.
Chrome Android extension #4: Easier image savingEver find yourself needing to save an image from a website — then discovering that the image is in some funky format that isn’t what you require?
The aptly named Save Image As Type Chrome extension fixes that frustration once and for all. Just install the thing, then long-press on any image anywhere on the web — and…
Finally, you can save any image in any form you want — without any extra steps.JR Raphael, Foundry
There ya have it: You’ll find a newly added “Save image as…” option in the Vivaldi long-press menu, and tapping it will reveal a full menu of possibilities for saving your image however you need — without any annoying extra steps or after-saving conversions.
Chrome Android extension #5: The Wikipedia wizardFinally, make your Wikipedia work infinitely more pleasant with the excellent Wikiwand Chrome extension.
Wikiwand transforms every Wikipedia page into one with a delightfully modern, easy-on-the-eyes interface that has all the same info — just in a noticeably nicer form.
Once you see Wikipedia like this, you won’t want to go back.JR Raphael, Foundry
Install it, forget it, and enjoy a better Wikipedia experience henceforth. Now, that’s what I call an easy win.
Ready for even more unfair advantages? Check out my free Android Intelligence newsletter to get something new and useful in your inbox every Friday — and get my Android Notification Power-Pack today.
An undisclosed Microsoft presentation is now central to a multimillion-dollar antitrust fight
There’s a new development in a Microsoft antitrust case, originally filed in England’s High Court in April 2021, and it doesn’t look good for the tech giant.
A consent order from the UK Competition Appeal Tribunal is demanding documents from past and present Microsoft executives that may have a bearing on a £270 million (about $361 million) lawsuit filed by secondhand software reseller ValueLicensing. The company alleges that Microsoft offered incentives to customers to shift to subscription services without selling their pre-owned licenses.
Central to this development is a historic, potentially damning internal “Second-Hand Software” (SHS) presentation, referred to in the consent order as a “known adverse document.” The specific content of the presentation has not yet been made public, but Microsoft has until October 31 to explain why it did not disclose the presentation earlier.
Further, a confidentiality designation that previously applied to 11 documents relevant to the case has been lifted.
These developments represent “an inflection point in European tech litigation,” said Forrester senior analyst Dario Maisto.
“For Amazon (AWS), Google, and Microsoft, the signal is clear: Antitrust tribunals are fully comfortable examining software licensing mechanics as tools of anticompetitive lock-in.”
The allegations against MicrosoftUnder EU law, it is fully legal to resell perpetual pre-owned (“second hand”) software licenses; software makers cannot use their Terms of Service (ToS) to override this right. ValueLicensing specializes in this secondary market, re-selling licenses for products including Microsoft Windows and Microsoft Office.
But the company alleges that Microsoft has stifled the supply of these pre-owned licenses in the UK and the European Economic Area (EEA) comprising 27 European Union member and non-member countries. It says Microsoft abused its market dominance and entered into agreements that “prevented, restrained or distorted competition” via clauses restricting customers from reselling their Microsoft perpetual licenses in return for subscription service discounts.
“The net result has been higher prices and less choice for customers, who have been steered into cloud-based Office365 and Azure subscriptions,” ValueLicensing claimed, pointing out that many enterprises, as well as publicly-funded organizations, rely on pre-owned Microsoft licenses to keep operating costs low.
The consent order is asking Microsoft to provide its “view” of whether those allegations are true, and to make “reasonable endeavors” to contact former COO Kevin Turner, former president and EVP Jean-Philippe Courtois, and former corporate VP of worldwide licensing and pricing Joe Matz. The company must document that it has done so by November 30.
The company must also file a witness statement from a former consultant addressing who within the company was aware of the SHS presentation and when they became aware of it; why the presentation was not disclosed as a “known adverse document”; when in-house legal counsel became aware of the presentation; what steps were taken to check for these types of “known adverse documents”; and the decision making process within the company when the presentation was located.
Microsoft is also being asked to search for specific terms in the emails and document repositories of Matz, Courtois, Turner, and several other named current and past research managers, former VPs and presidents, between July 2012 and June 2020.
The more than 40 search terms include “SHS,” “antitrust,” “competition,” “ValueLicensing,” “used licenses,” “do nothing,” “competition,” “revenue,” and “discount licensing.” These documents cannot be designated “restricted” or “confidential,” according to the consent order. They must also be disclosed by November 30.
A witness statement from deputy general counsel Cynthia Randall has been paused.
Microsoft has said that any abuse of dominance was “objectively justified” and that the contractual terms at issue were “necessary and reasonable.” It also argued that anti-competitive effects were “outweighed by and proportionate to” certain benefits and efficiencies.
The company did not reply to a request for comment.
Microsoft is facing similar antitrust allegations from UK barrister Alexander Wolfson, who issued an opt-out class action claim in May 2025 alleging that public and private UK organizations that purchased software licenses, including those for Microsoft Office and Windows, were overcharged over a 10 year period due to Microsoft’s market practices.
Wolfson said in a release at the time that Microsoft’s actions had a significant and far-reaching impact on UK consumers, businesses, and public bodies. “With billions of pounds potentially at stake, this case is about ensuring fairness in the digital marketplace and ensuring even the largest tech companies play by the rules,” he wrote.
Implications for enterprise leadersFor enterprise CIOs, procurement leads, and IT financial managers, the current development holds “practical implications,” said Forrester’s Maisto: Organizations that surrendered perpetual licenses or agreed to contractual restrictions against reselling software as part of an enterprise agreement (EA) renewal or cloud commitment may have given up quantifiable asset value.
“The secondary market for perpetual licenses remains legally valid,” he pointed out.
CIOs should pay close attention to licensing “penalties” or inflated costs for running legacy software on third-party clouds, like AWS or GCP, versus Azure, he said. They should also evaluate the benefits of hybrid licensing strategies. Combining pre-owned perpetual licenses for static workloads with cloud subscriptions for dynamic workloads can yield significant cost savings compared to all-subscription models, Maisto pointed out.
Finally, he urged, “use these rulings as leverage during Microsoft agreement renewals.”
Anthropic tries to make Claude stickier with launch of Docs and Slides
Anthropic is equipping its Claude AI assistant for more productivity work with the launch of Claude Docs and Slides.
While it’s already possible to create documents such as Microsoft Word and Google Docs files from Claude chats, the latest update, announced Wednesday, brings a rich-text editor directly into Claude.
Users ask the AI assistant to draft a document or slides via the chat interface, and Claude will ask clarifying questions before starting work. It will also leave comments to explain its choices.
Claude Docs files are then stored in the Artifacts tab and can be exported as Word, PDF, Google Docs, or markdown files. Documents can be shared with colleagues for real-time collaboration.
Anthropic
“Strategically, this signals Claude moving from an AI assistant into an agentic platform meant for full lifecycle of knowledge work,” said Arun Chandrasekaran, Distinguished VP analyst at Gartner.
He anticipates early user demand around “recurring, template-driven work,” such as status reports, board decks, and data-to-story reports.
“The likely near-term outcome isn’t wholesale replacement of alternative digital workplace tools, but it positions Anthropic as an entry point for workflows historically created in third-party tools,” said Chandrasekaran.
Claude Docs usage counts towards a customer’s Claude usage limits, and larger requests such as drafting a document with several sources takes up more of the limit. There are currently feature limitations, with no version history, access levels, or external sharing on Team and Enterprise pans. It’s also unavailable for customers that use “customer-managed encryption keys (CMEK), zero data retention (ZDR), or a HIPAA-ready configuration,” according to Claude’s support site.
Claude Docs and Slides are available in beta now on paid plans, rolling out to Pro and Max plans first. The feature is turned off by default for enterprise plans.
Anthropic
All of the major AI model providers are seeking ways to make their products stickier within customer organizations, said Jack Gold, principal analyst at J. Gold Associates. Some have targeted coding agents, while others, particularly Microsoft and Google, have AI assistants and agents that are connected into existing office productivity tools.
Microsoft’s Copilot is embedded across its Office suite, for instance, although users can also create documents directly from the Microsoft 365 Copilot chat interface.
“Microsoft and Google are bringing AI deeper into established productivity environments, while Anthropic is bringing more of the productivity environment into AI,” said Maria Bell, senior research analyst at FDM CCS Insight. “Over time, the competition may increasingly be over which becomes the primary interface through which knowledge workers get work done.”
Early findings of FDM CCS Insight’s ‘2026 Employee Workplace Technology Survey’ show that show that around half of employees that use generative AI at work do so to create or edit reports and documents.
It’s unlikely that native document editing features in Claude will result in a large-scale move from Microsoft or Google’s productivity suites, analysts say.
The updates to Claude this week have the potential to help users get more done, said Gold, “but it’s unclear how many users that already have productivity suites in place will choose to move to other tools,” even if they prefer Claude for its AI capabilities.
“The fundamental question is, if I am used to certain tools and they work for me, am I willing to change for the promise of working better? Not sure that will be a winning strategy,” he said.
“Microsoft and Google are deeply embedded in how people already work, and users have spent years becoming comfortable with their products and workflows,” said Bell.
“They are also increasingly bringing access to powerful AI models directly into those familiar environments. Anthropic therefore must do more than match document-creation features; it has to offer an experience compelling enough for users to build new habits around Claude,” she said.
As well as Anthropic’s Claude, it has long been rumored that OpenAI plans to build its own native productivity tools in ChatGPT that would bring it into more direct competition with Microsoft and other incumbent office software vendors.
Anthropic also announced that users can now invoke Claude Design in an ordinary chat. Claude Design, which generates visual outputs such as slides and prototypes, was previously available as a separate tool within the Claude app.
In addition, Claude Cowork — which can perform multiple-stage tasks — and the regular Claude chat interface have now been combined, with Claude determining how to handle a request. This removes the need for users to decide which tool to use for a particular task, according to Anthropic. It’s not clear exactly how Anthropic decides where to route a request, however. Cowork queries are generally more token-intensive than the core chat interface.
“Claude can now figure out what a task needs, so what Cowork and Design can do is available from any conversation, with the context, skills, and connectors you already have,” the company said in a blog post.
The new Claude experience will roll out gradually, starting with Pro and Max customers. Anthropic said it will alert Claude Enterprise customers before any changes are made to their account.
Claude Enterprise costs $20 per user each month alongside consumption-based pricing.
Will Apple enter the server business?
In a world of speculation, this week’s most interesting rumor says Apple may plan to enter the server business once again, with powerful systems running its own Apple Silicon chips.
It’s hard to dismiss the claims, particularly as Apple is already in the server business, with its Texas factory manufacturing servers for its Private Cloud Compute (PCC) cloud intelligence system. While those servers are only used internally —or externally if installed at third-party data centers for use with Apple’s ecosystem of products — they are still servers.
Apple is already in the server businessIt’s also a business Apple has been in before. Many years ago, around 2002, I visited Apple in Paris, where the company demonstrated its Xserve and Xserve RAID systems. These were particularly aimed at the video and music industries and became quite widely used in those sectors. Apple discontinued Xserve in 2011, because the product sat outside its broad consumer-focused strategy.
Things were different then. You see, today’s Apple has billions of users. It has a fast-growing reach into enterprise tech — SAP recently updated its fleet of 60,000 Macs to macOS 27 on the very day the OS shipped, and there are hundreds of thousands of Macs in use at businesses worldwide. Apple has hundreds of millions of iPhones in active use across business. Apple even has the silicon to power these things.
The Apple Silicon advantageYou can’t ignore the computational advantage of Apple Silicon. The first leaked benchmarks for the M5 Ultra chip used in the new Mac Studio are incredibly impressive, with multi-core performance at an astonishing 52,516. That’s amazing performance from a Mac that costs an estimated 8 cents an hour to run at full capacity.
Now imagine that price/performance ratio stashed in a server.
You don’t even need to imagine it, because MacStadium, AWS, and others already use Macs in server farms, with great success. MacStadium CTO Chris Chapman once told me that Apple Silicon is so power efficient his data centers would tell him the Macs he had racked with them were not using enough power for the space. (Data centers sell space by the square foot and calculate energy costs within that calculation.)
Making cloud cheaper and more secureThe computational performance per watt is an advantage to any user, but the cost benefits rack up pretty fast when you have a thousand machines racked up on the data farm. Apple even has a server operating system waiting in the wings — or did until it stopped offering macOS Server four years ago.
Apple’s existing server production is focused on Private Cloud Compute. That system is impressive, (a) because Apple has opened it up to security experts to confirm it is secure, and (b) because it delivers data and privacy security equal to what its end-user platforms provide.
But, as data centers blossom across Terra Firma, there’s a growing recognition of the need for sovereign AI, on-premises AI, and private AI. Think of it this way: We already know Macs can run some of the world’s most powerful LLMs very, very well. What’s wrong with introducing Apple Silicon-based servers to do the same thing? These things could even offer companies access to their own white-label private builds of Apple Intelligence, though I consider that unlikely.
Why the speculation makes sense, and why it doesn’tSo, I see lots of reasons why speculation that Apple may re-enter the server market makes sense — though it may not be in a huge hurry, as the original claim is that these servers will run M8 Ultra chips. (Mark Gurman thinks it may be an M7 Ultra).
Of course, speculation and conversation don’t always become fact. Merely because Apple is talking about servers again doesn’t mean it will advance those plans.
Former Apple business-focused product marketing executive Todd Dailey doubts these plans. He says Apple is far more focused on consumer markets than enterprise.
He also points out that if it were to offer servers, the company would need to consider providing same-day tech support and more flexibility around OS upgrades, adding that the business may not be big enough to justify the cost of implementing the plan.
That doesn’t mean Apple isn’t considering it, just that once you bounce the idea through a few real-world weeds there may be obstacles to making it happen.
Is it time for iCloud Ultra?I do think there are signs Apple is taking enterprise markets more seriously. I also think that as PCC deployment expands, it makes sense for Apple’s server teams to build a product road map for the future of PCC servers like any other Apple product, even if they are only used to support its own server-side AI.
But I also think that if the company were to go ahead to make this happen, the solution would be aimed at developers and businesses seeking a uniquely private way to deploy sophisticated AI outside of the thrall of the frontier models, chipping a little more business away from those over-leveraged entities as it does.
The thing is, if that’s the case, then is it servers Apple is thinking of building, or server farms offering hosted services for a price? An iCloud Ultra service for developers and enterprise users may perhaps make more sense. I guess we’ll have to wait and see.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Salesforce’s massive outage exposes the hidden risks of cloud dependencies
While its flagship Dreamforce event was in full swing on Wednesday, Salesforce was triaging a roughly seven and a half hour-long service outage that disrupted user access and caused “severe delays” and intermittent errors. Some customers were also unable to submit new support cases.
The service outage hit at 3:50 a.m. EDT, impacting “multiple instances across all regions,” Salesforce reported. It was marked resolved right around 3 p.m. EDT, after several hours of monitoring to determine that fixes had been successful.
Salesforce initially pegged the issue to an “external dependency failure” impacting the legacy login server. A core system component experienced increased load, limiting its capacity to process requests. The company confirmed that there were no issues with third-party infrastructure.
Beyond the obvious embarrassment from the outage occurring during Dreamforce, an analyst said the incident highlights a cloud resilience problem, rather than purely a legacy one.
“Cloud does not eliminate architectural dependencies,” said Abbas Jaffery, a principal advisory director at Info-Tech Research Group. “It can sometimes make them less visible. And when the platform is your system of record, those hidden dependencies become an enterprise risk rather than simply a technology risk.”
Rolling restarts, persistent issues throughout the daySalesforce began experiencing service issues at 3:50 a.m. EDT on September 16, and initial investigation determined that requests were stalling while waiting on responses from an internal login service that was using up available server resources.
Initially, Salesforce blocked application programming interface (API) endpoints and attempted rolling restarts to revive the service, then pushed out fixes region-by-region. At 7:20 a.m., some customers were seeing service return to normal, and Salesforce was working on a “code-level permanent fix.”
However, the rollout did not complete for a number of instances, and some automated fixes didn’t fully resolve the issue. For example, customers reported that scheduled jobs were not running as expected, even after service was restored. Salesforce manually restarted those instances.
Salesforce later reported that the impact radius was “narrower than initially understood” and saw signs of recovery by around 11 a.m. EDT, with most customers coming back online.
A sub-set of Hyperforce instances were the last to be restored. Mitigations were in place across all instances by 11:39 a.m. EDT, and Salesforce continued to monitor the issue until marking the incident resolved at 2:59 p.m. EDT.
“We apologize for how this incident affected you and your business,” Salesforce posted on its incident blog. “We will undertake a full investigation of the incident, establishing the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.”
Creating a ‘temporal’ data problem
For customers for whom Salesforce is a system of record, several hours of authentication and service disruption can create a “temporal data problem,” Info-Tech’s Jaffery explained. “Events that should have happened at different points in time may occur later, fail altogether, or arrive out of sequence,” he said.
For instance, a customer interaction may occur through another channel while Salesforce is unavailable, but an integration, workflow, or scheduled process that normally records or propagates that event is unable to run.
This has several potential consequences, Jaffery said. Transactions and customer service processes are delayed; APIs and middleware may accumulate retries, timeouts, and queues. Records can become temporarily inconsistent, and scheduled jobs and workflows may be missed. Employees could lose visibility into customer history or case status, even when the underlying data has not been lost, creating a “data divergence.”
The first mistake would be to assume that just because users can log in, the incident is over, he noted. “Enterprises should move immediately into a reconciliation and integrity phase,” Jaffery advised. This means not only verifying interactive access, but APIs, integrations, scheduled jobs, queues, workflows, automation, authentication flows, and downstream systems.
Enterprises should ask what transactions failed, partially completed, or were duplicated during the outage? Which scheduled or asynchronous processes did not execute? Did integrations retry successfully, or did they create a backlog or retry storm? Are downstream systems now consistent with Salesforce?
Security teams should also validate authentication and session behavior, privileged access, integration credentials, and any emergency changes made during recovery, Jaffery explained. “The most important question is not simply ‘Is Salesforce back?’, but ‘What did the business expect to happen during the outage, and can we prove that it actually happened?,’” he said.
What to look for in post-incident reportsA credible post-incident review from Salesforce should establish a causal chain: The trigger, dependency failure, technical propagation, customer impact, detection, mitigation, recovery, and permanent corrective action, Jaffery said.
The company should be able to answer these questions, he said:
- What was the actual initiating failure and why did the failure propagate into the login path?
- Why could the affected dependency consume sufficient capacity to affect core services?
- Why didn’t isolation or failover prevent the impact?
- Why did initial remediation attempts fail and why did the subsequent rollout require additional intervention?
- What safeguards are being added to prevent recurrence?
- How will Salesforce demonstrate that the corrective action actually works under failure conditions?
Service restoration simply tells customers: “We got it working again,” he noted. But root cause analysis tells customers: “We understand why it failed, why our controls didn’t prevent it, and what has changed so that the same failure mode is less likely to recur.”
It’s not just about ‘legacy’ pieces in the stackOne architectural lesson is that a legacy component does not have to be large to be critical, Jaffery pointed out. An older authentication service can remain part of a modern stack, and therefore become a dependency for newer services.
“The component’s age matters less than its position in the dependency graph, its blast radius, and the quality of its isolation and failure handling,” he said, pointing to this incident’s progression: Requests stalled waiting on an internal login service due to increased resource consumption led to investigation into an external dependency failure, which in turn revealed impact on a legacy login server. Finally, Salesforce said, “core system components experienced increased load, which limited its capacity to process request”.
That is a classic resilience question, Jaffery pointed out: Can a failure in one dependency remain in that one dependency, or does it become a platform-wide failure?
Modernization should not be identified simply by how much old technology has been replaced, he noted, it should also measure dependency concentration, isolation, “graceful degradation,” recovery paths, and failure blast radius.
“For enterprise architects, that is the real takeaway,” he said.
Maybe driven by agentic AI, exacerbated by layoffsAt this point, there are no obvious signs that this was a security incident, noted David Shipley, CEO of Beauceron Security. “Right now, this bears all the hallmarks of an update gone horribly wrong.”
He pointed to an incident in December 2025 when Amazon’s internal AI coding agent, Kiro, caused a 13-hour AWS outage in a mainland China region, noting, “I’m not going to be shocked if we don’t see some kind of agent role in this kind of scale disaster.”
Significant Salesforce layoffs over the last few years could also have had a negative impact on the outage and recovery, he added. “Having it happen during Dreamforce had to be all kinds of hell, though, for their sales and customer support teams,” he said. “Pour one out for them as they work on rebuilding relationships, face-to-face.”
This article originally appeared on CIO.com.
LinkedIn fights for the right to tell customers when the feds want their data
Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users.
LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is being requested.
The company is asking federal courts “to enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them,” wrote Jon Palmer, Microsoft’s chief legal officer, in a Tuesday blog post. “We recognize law enforcement’s important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process.”
He pointed out: “People and organizations increasingly entrust their most sensitive information to online services. If providers cannot challenge demands they know are overbroad—or if courts may silence them without a rigorous, adversarial review—the safeguards the law requires will be weakened precisely when they are most needed.”
A tricky issueThe issue is a tricky one. Law enforcement often use this type of subpoena as an investigative tool, seeking those who are engaged in illegal activities. The theoretical justification for secrecy is to avoid alerting the investigative target to make it less likely the suspect will try to destroy evidence or flee the jurisdiction.
Government lawyers are supposed to only make secrecy requests when absolutely essential. Microsoft is suggesting that courts and congress need to step in to curtail blanket government efforts.
“The Fourth Amendment protects the right to be free from unreasonable searches and seizures. That right applies to papers kept in a desk and it also applies when personal and business records are stored online,” Palmer wrote. “Online service providers, like LinkedIn and Microsoft, also have a First Amendment right to speak to their customers when the government obtains an order to search their private information. Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review.”
He added: “The government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible.” In his post, he pointed to a recent legislative effort in the US House of Representatives that might mitigate the issue if it ends up becoming law.
“On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers,” he wrote. “The reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure that secrecy is the exception – not the rule. The Senate should act promptly to send these historic reforms to the President.”
LinkedIn privacy battlesLinkedIn itself is currently fighting litigation that accuses it of directly violating the privacy rights of its customers, and a federal judge this month dismissed another similar case, but gave plaintiffs permission to refile, with a caveat.
“Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” US District Court Judge Vince Chhabria wrote. “But in an abundance of caution, dismissal is with leave to amend.”
But, he added, if the amended complaint isn’t filed within 14 days, “dismissal will be with prejudice.”
Privacy now a ‘data stewardship obligation’Jeff Valdes, a director at Acceligence, noted, “there is definitely some irony here.”
“If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves,” he said. “Privacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem.”
Mike Wilkes, enterprise CISO at Aikido Security, agreed, pointing out, “without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance. The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment.”
That, he said, “is why Microsoft’s argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users.”
But Ryan O’Leary, an IDC research director, offered a different perspective.
“Microsoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users,” O’Leary noted. “This seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade.”
At the same time, Valdes pointed out, Palmer’s post highlights how deeply privacy has become a top-tier enterprise IT priority.
“Privacy is rapidly becoming a much broader data stewardship obligation,” he said. “Companies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world’s data, customers are going to judge how you protect that data in every direction.”
However, Wilkes noted, “Microsoft does not need to be a perfect privacy saint to be right about this particular problem.”
This article originally appeared on CSOonline.
Big Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems.
The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on calls from rivals to slow development or tighten coordination.
“trust and alignment are quickly becoming the most important capabilities that will differentiate agents and models. Any lab that doesn’t focus on alignment will fall behind,” Zuckerberg wrote in a post on X.
“Engaging independent evaluators and advisors is industry best practice,” he added, noting that Meta already does this in several areas.
His comments follow a series of public proposals from AI industry leaders including Dario Amodei, who argued for a more cautious pace of development, and Sam Altman, who called for collaboration on safety standards.
The debate has intensified amid disclosures from AI labs and policymakers on potential misuse of advanced systems. Anthropic has said it restricted attempts to use its Claude models in sensitive domains, while OpenAI has engaged with policymakers on AI-related risks, according to company statements and reports.
Enterprise concernsWhile the debate is often framed as a choice between slowing innovation and strengthening oversight, analysts said enterprises should focus less on which approach prevails and more on the operational consequences already taking shape.
“Divergent safety approaches will make access to advanced AI models less predictable, rather than producing an industrywide slowdown,” said Sushovan Mukhopadhyay, director analyst at Gartner. Vendors are likely to apply different release schedules, regional availability, access tiers, and usage restrictions, he said, meaning enterprises could encounter similar capabilities “at different times and under materially different conditions.”
Mukhopadhyay said enterprises should plan for variability in access rather than assuming consistent availability across providers or geographies.
“I read this week as the point where frontier AI became a managed supply,” said Bhupendra Chopra, chief revenue officer at Kanerika. “For three years CIOs could assume the next model would simply show up. A frontier model now behaves more like a critical component from a supplier whose delivery dates depend partly on outside reviewers and export rules.”
Chopra added that “any AI roadmap built on a specific model arriving on a specific date is carrying supply risk it hasn’t priced.”
Security pressure builds regardless of slowdownAnalysts said slowing development alone is unlikely to materially change enterprise risk, particularly as open-source models proliferate.
“The biggest point isn’t the pause itself. It’s that the leaders of AI companies are agreeing on something,” said Nikhil Gupta, founder and CEO of ArmorCode.
Gupta said the threat landscape has already shifted. “Even if companies hit pause, open-source AI models are already out there,” he said. “I’m not convinced slowing down some companies meaningfully changes what adversaries can do.”
“Even if AI development slows down tomorrow, security must accelerate,” Gupta added. “The job of securing these systems has effectively gotten ten times harder.”
A new ‘AI assurance’ layer emergesThe focus on evaluation is driving what analysts described as an emerging “AI assurance” layer, where third parties assess models for safety and compliance.
“A distinct AI assurance layer is likely to emerge, but enterprises should not expect a single certification to establish that an AI system is safe,” Mukhopadhyay said. “Enterprise risk also depends on data, system instructions, tools, agents and deployment controls.”
Chopra said enterprises risk misinterpreting such evaluations. “Procurement teams may see a third-party evaluation and treat the model as vetted,” he said. “Within a year it becomes a checkbox.”
Instead, he said, enterprises will need to run their own validation. “CIOs who get ahead will test each model against their own data before it touches production.”
Fragmentation complicates multi-model strategiesFor CIOs pursuing multi-vendor strategies, differing approaches across providers could introduce additional complexity.
“Fragmentation was already the default. Safety divergence deepens it,” Chopra said.
He said risk is most acute during transitions. “For an enterprise running several models, the exposure sits in the handoff,” he said. “When a model is delayed or replaced, the system can behave differently.”
“I’d rank untested model substitution above vendor lock-in,” Chopra said.
Gupta said open architectures will be important. “The framework needs to be open, not locked to any single vendor,” he said.
Mukhopadhyay added that enterprises should prepare for models becoming unavailable or restricted.
CIOs urged to build resilienceAnalysts said enterprises will need to design AI strategies that can adapt to changes in availability, pricing, and governance.
“For critical applications, CIOs should separate application controls and business logic from the underlying model,” Mukhopadhyay said.
Chopra emphasized flexibility. “A routing layer between applications and model providers turns switching into configuration work,” he said, adding that contracts should cover deprecation timelines.
He also pointed to pricing implications. “Scarce access to the frontier starts to carry a premium,” Chopra said.



