Computerworld.com [Hacking News]

Syndikovat obsah
Making technology work for business
Aktualizace: 20 min 13 sek zpět

Anthropic’s new privacy policy offers US consumers a way around the Fable ban

16 Červen, 2026 - 11:34

Anthropic’s apparent inability to identify which of its users are foreign nationals has led to some collateral damage from a US export ban on its most powerful AI models — but there is a way around it, at least for some.

On Friday, the US government ordered Anthropic to suspend access to Fable and Mythos, the new AI models it had introduced just a few days earlier, to all foreign nationals, citing national security reasons.

[ See also: Anthropic Fable dispute suggests ‘export’ no longer means what it used to ]

While the drafters of the US order may have had sovereignty in mind, they ended up making it an identity management problem.

“The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance,” Anthropic said in a blog post commenting on the order, implying that it was unable to distinguish between foreign nationals and US citizens in its user base.

That’s likely the case today, but for its consumer customers, an update to its privacy policy, introduced last week and taking effect on July 8, gives it a new option: asking them for government ID.

The section of the policy on collection of personal data contains a new provision under the heading “Personal data you provide to us directly,” saying:

  • Verification Data: In certain circumstances, we may ask you to verify your age or identity. If you choose to do so, data we will collect includes, depending on the method: an image of your government-issued identity document and the information appearing on it (such as your ID number and date of birth); your image in photo or video form, facial geometry templates (which may be considered ‘biometric data’ in some jurisdictions); and the result of the verification (for example, whether your age meets the applicable threshold).

If the government ban on foreign access to Fable and Mythos continues, that would give Anthropic the option of opening access to users willing to submit a scan of their identity document, provided that it contained proof of their US citizenship. That would be the case for US passports — and also for citizens’ driving licenses issued by some US states along the country’s Northern border, which issue so-called enhanced driving licenses indicating the holders’ nationality.

Enterprise users most likely to benefit from the power of the new AI models, though, will have to hope Anthropic finds some other way out of the current impasse.

The article originally appeared on CIO.

Kategorie: Hacking & Security

Q&A: A look at forward-deployed engineers, AWS style

16 Červen, 2026 - 09:00

Hot AI companies can’t stop talking about forward-deployed engineers (FDEs), which are now very much in vogue. 

FDEs, in case you haven’t heard, are hired by companies looking (hoping?) to successfully deploy AI tools and services. It’s one of the hotter professions in a world still trying to understand the impact of AI on careers.

So, what exactly are FDEs — are they techy lone rangers like the ones OpenAI, Google and Microsoft are hiring? Turns out it’s not so much about individual engineers who swoop in to design and roll out AI deployments; it’s more about a team of engineers working together at customer sites.

At least, that’s the view at Amazon Web Services (AWS).

In fact, according to Taimur Rashid, managing director of the AWS Generative AI Innovation Center, the FDE concept pre-dates the current generative AI (genAI) gold rush. The same kinds of engineering teams were needed for the earlier machine-learning and cloud eras to help companies with deployments.

Taimur Rashid, managing director of the AWS Generative AI Innovation Center,

AWS

Rashid recently talked about how AWS sees FDEs as a profession in a conversation with Computerworld. And he weighed in on the desired job skills the company seeks in this increasingly AI-centric era.

What is an FDE? “We view it as a team. It’s a cross-functional team that has engineers, scientists, strategists, and folks that can piece technology and business together. In some cases, we do have to have security engineers in there, too. 

“I see them as anesthesiologists. They have to prep so many things, monitor things throughout. We see ourselves as a frontier deployment team helping customers adopt all forms of AI, whether it’s genAI, agentic AI, even emerging trends like physical AI. We’re helping these companies become frontier themselves.”

How does an FDE engagement begin, and how is it structured? “Where we see the forward deployed model is when customers come in — for example, we have our executive briefing center in Seattle and in Arlington, VA. When customers share what they’re trying to do, very quickly a customer’s like, “What’s the quickest way I can go and build something with you?” 

“We’ll forward deploy our people in, we’ll embed them in your business and we’ll go through these 45-day sprints that we typically design. Through those successive sprints, we’re building stuff together, we’re proving value, and then they can expand that to a much broader engagement.

Where do FDEs actually sit? Client side, internally, or in-between? “It’s mixed, and it largely depends on what the customer’s preference is. We’ve seen models where the customer has been very adamant that, ‘We want your teams with us in our business.’  In those cases, we forward deploy the majority of the teams on site. 

“We have models where customers are fine with you being wherever you’re based, as long as you’re still embedded virtually. And then there’s a hybrid. We deploy anywhere from five to seven people. Sometimes, the baseline is actually three.”

Will cost savings be the job of an FDE, or someone else on the team? “I expect these teams to be able to architect systems that have those cost requirements in mind, whether it’s use a different model for a different use case that doesn’t increase the per-token cost…or think about ways where you can use semantic caching. I personally think you may have a high spend in token consumption, but if you’re generating revenue, as long as the economics work out, then you’re at peace.”

What challenges have you gone through deploying FDEs in the real world? “One of the challenges worth highlighting is when customers get really excited about us forward deploying resources, what they end up realizing is [that] they’re not set up to absorb that right away. They realize they have to go through … process-related things, security access — all those operational things. 

“One very good example is the Commonwealth Bank of Australia. They said: “Prioritization’s a big thing, and if you forward deploy and you’re 100% dedicated, how do we ensure that our teams are also equally 100% dedicated?’ When you’re sitting in your office, you’re distracted by your day-to-day. So they said, ‘Why don’t we create a neutral ground in Seattle? You fly your people, we’ll fly our people. We’ll give them three weeks of dedicated time so they have no distractions.’”

Have you gone into projects where they want AI but have no security or governance ready? “I’ve been through this before, certainly. We do see customers that have security processes and capabilities, but it’s not as tight as it should be in the age of AI. Governance is the biggest area where customers right now have the biggest gap. I’m talking governance around agents. In the past two months, almost 100% of the conversation around agents is not about capability. It’s all about governance. 

“That is a big area right now where forward deploy teams are helping with governance education, and building the scaffolding for that.”

How does software engineering fit into the FDE model? “One of the greatest learnings is that as we forward deploy resources and get customers to take AI and integrate it into their systems, the knowledge of software engineering is so important. Today, a customer can use one of the Claude models and scan their code base and look at vulnerabilities. 

“The tough part is not assessing those vulnerabilities, it’s remediating [them]. Remediating [them] requires software engineering experience, because you have got to merge code, test it, deploy it. We largely see that the frontier software development teams are smaller and they’re managing agents that are doing various tasks across the software development lifecycle.”

AWS has many models at your scale, open source, closed — it’s more complex than what other AI vendors offer.  How do you nail down the talent? “It’s massive, and when you look at not only scale, it’s the complexity of the stack. We take an approach where we fundamentally do three important things: No. 1, we want to ensure people understand concepts; they have to understand pre-training, post-training, reinforcement, fine-tuning. 

“Secondly, we make sure that our teams are well versed in their first-party services. The third thing is that by design, AWS has always been about choice. We say, ‘Let’s do 80-20 here. What is 20% of those specialties that we need to have, which can cover 80% of what most customers are trying to do?’”

What skills should software developers learn to move into FDE work — the top three or four things? “We look at three categories. First category is entirely functional. Are they more engineering specific? Are they science specific? Are they security specific? Our litmus test is not only knowledge of the function, but the actual hands-on work that they can do with it. Secondly is around domain. I focus on what is their domain understanding across the whole AI lifecycle? The third thing is cultural. We are looking for folks that are okay at dealing with ambiguity, being good at stakeholder management, and having that startup mindset. 

“This AI transformation’s not for the faint of heart.”

There’s a rush for FDEs from OpenAI, Google, and others. What’s different about what you look for? “I don’t know entirely what the others are looking for, but I’ll tell you what we have been looking for in the past. When we hired solution architects, it was about systems level understanding. But what I see more and more is hands-on experience, cultural mindset, all these things are very important. If I had to pick one thing that is going to be very important in the talent that we either upskill or future talent that we hire, it has to be the application of AI towards software engineering and system integration tasks.

You’re upskilling AWS talent as well? “We do. You will see some publications coming out in the next couple of weeks around how do we do this across our software teams and how does that translate to customer-facing roles.”

Kategorie: Hacking & Security

Why Europe’s demands on Apple AI put your data at risk

15 Červen, 2026 - 17:21

Europe’s evangelistic approach to insisting Apple open up personal data to competing AI services is hurting Apple users in the region. More than that, it also places its entire business sector at risk, and a newly-published Jamf survey suggests why.

Announced at WWDC 2026, Apple Intelligence/Siri AI relies on personal, contextual data to run. Europe wants that same information to be made available to third-party services for competing apps, but has not worked with Apple to protect user confidentiality. It’s an approach that places your data at risk of exfiltration using those apps because Europe is insisting Apple share personal information with the developers of other apps.

The desire to protect that data is why Apple won’t distribute Siri AI in the EU for a while.

Jamf survey exposes the IT risks of AI

It’s not as if Europe doesn’t understand the risk of data leaks in an era of AI. Just look at the bloc’s focus on things that do matter, such as sovereign AI or managed AI services like Orange Live Intelligence. These locally-produced AI services, alongside Europe’s attitude toward them, tell me the confederation understands the risks.

How real are these risks? Very. Jamf on Monday published survey results confirming the scale of that risk, telling us that one-in-five IT and security leaders in the enterprise sector has already experienced an AI-related incident involving unexpected costs, a security issue, or both.  The survey also found that:

  • 72.9% of organizations have already deployed AI in some form.
  • 59.7% see an AI-related incident as a near-term risk.
  • Organizations with deeply integrated AI are 40% more likely to report an AI-related incident than organizations still in the exploratory stage. 

The implication is that AI governance is becoming an operational requirement and — as Apple has told us umpteen times in the past — the best way to maintain operational confidentiality is not to collect or share any data at all. That’s the whole point of its approach: the data doesn’t need to be shared, it just needs to be turned into another signal that promotes utility while protecting confidentiality. 

Crafting trust in a crowded market

There’s another challenge to emerge. There are now multiple brands of AI, with more coming on stream all the time. That’s great in terms of finding a model that suits your needs, but challenging when it comes to ensuring all the services you or your employees use of are equally secure. You don’t want your business to become deeply reliant on any service only for that vendor to subsequently get bought out and/or shut down, nor do you want a service to be hacked or otherwise exploited to your detriment.

“AI isn’t arriving as a single application that IT can approve and move on from,” said Jamf CEO Beth Tschida. “It’s showing up in developer tools, productivity apps, autonomous agents, and other software they already run. The challenge is maintaining visibility and control as that footprint expands.” 

The survey described the challenges IT faces with AI deployment: shadow IT, vendor sprawl, and the need to grapple with highly unpredictable use-based pricing models. And that’s even before considering the governance challenges of agentic and developer AI.

AI and the emerging governance nightmare

“What our survey shows is that governance must keep pace with adoption,” Tschida said. “For organizations built on Apple, the foundation is already an advantage. Apple’s privacy model and the management controls built into the platform give IT teams a strong foundation to build on and … that advantage depends on using tools built for Apple from the start.”

That’s the point of the curated, private and secured service offered by Siri AI, of course. It’s also part of what Apple is building toward with its wider ambitions toward AI on its platform. Bloomberg’s Mark Gurman discussed elements of this in his weekend newsletter, in which he suggested Apple might introduce some subscription services using AI, and that it is building an App Store for Siri Extensions, which would allow third-party chatbots to work with Siri

There is a need for curation and management in AI

What makes that model work is the curation with which Apple surrounds it, and its determination to extend Private Cloud Compute so it can protect your data even when using third-party servers (in this case, Google’s server clusters). It makes sense to think Apple intends to use that system to protect all approved third-parry AI interactions provided across its platforms by its own routes. That’s true, even if users access services free of those safeguards using a web browser, which they currently can.

But the key thing is that if Apple can get this right, offering up a managed, curated, and controllable ecosystem for AI agents and services, it will be going a long way toward building the kind of managed AI ecosystem the Jamf survey shows our modern digital enterprises increasingly need. 

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Nextcloud CEO: Open source moves from ‘a nerdy audience’ to the geopolitical stage

15 Červen, 2026 - 09:00

MUNICH — Amid trans-Atlantic political and trade tensions, digital sovereignty — once a relatively niche concern — has jumped to the top of the agenda for European organizations wary of their reliance on US technology suppliers.

For many, including European Union policy makers, increased use of open source software is a key part of the answer, offering an alternative to proprietary platforms from a handful of large US vendors.

That’s the view of Frank Karlitschek, CEO of Nextcloud, the German software vendor that bills itself as an open-source alternative to software suites from the likes of Microsoft and Google. 

Nextcloud CEO Frank Karlitschek speaking at the German software company’s Nextcloud Summit 2026.

Nextcloud

Karlitschek founded the company in 2016, forking OwnCloud’s open-source file-sharing software. Since then, Nextcloud has expanded its products to include a range of productivity and collaboration tools that organizations can install and run on their own servers or access via cloud providers

More recently, Nextcloud helped develop the Euro-Office application suite, which launched last week as an open source alternative to Microsoft Office and others, and continues to build out its Nextcloud Hub with AI assistant and agent features. The company now says revenues are growing at between 50% to 100% year over year.

Computerworld spoke to Karlitschek at Nextcloud Summit about momentum around digital sovereignty, the European Commission’s Tech Sovereignty Package proposals, and how Nextcloud hopes to evolve in the coming years.

The following interview was edited for length and clarity.

When Nextcloud launched, there was a big push in Europe away from on-premise software towards US cloud providers. How have attitudes towards open source and awareness of alternatives providers changed since then? “I’ve been doing open source since the ‘90s; at the time it was mostly for a nerdy audience — a very small group of people who really care about software and being in control. The sovereignty part was always there. It’s the core idea behind open source that you can understand what the software is doing, you can deploy it wherever you want, you can study it and change it, and so on. 

“At the time, it was very niche, and since then it’s really growing and growing. There are certain points in time that really accelerated the growth; something like the Snowden revelations, for example, or the whole discussion about GDPR and certain legislation. And then, of course, the current geopolitical situation.  

“I personally find it interesting that it grew from something that is just interesting for software developers, and now it’s on the geopolitical stage. I have meetings with big politicians who really care about it now, and I personally find it interesting that it’s increasingly understood by — I wouldn’t say the mainstream, but more and more people.

“At the beginning of Nextcloud, we mostly talked with IT managers looking for a solution; they care about how it works, the price and other things. But now we are also talking with the C-level people. It’s part of an overall strategy of a company, to say, ‘Hey, we need to look into the dependencies, we want to have a solution that fits into the strategy of the company.’

“In the past, it was like a commodity – it’s just some software, who cares? Now, it’s really part of the company strategy. That’s really interesting.”

There’s been a lot of interest around digital sovereignty over the past couple of years. To what degree is this translating into action, with organizations migrating away from US cloud providers? “The interest is gigantic. Everybody’s talking about it, we have so many contacts and people coming to us. Not everybody is doing it — a lot of people are just exploring and seeing what the options are. 

“Obviously, we hope that this will translate into actions in a few months. At the moment, it’s a lot of talking and exploring the options. As a company, we are also growing a lot in customer base.  But the interest in this space is even bigger; we see it as the beginning of a funnel.

‘In defense we see a lot of interest, then also everything around education is very important for us, then other regulated markets like the healthcare, for example. Finance is an interesting one.”

A lot of the conversations around digital sovereignty are tied to the current geopolitical situation and even the US administration. Do you see demand for sovereign technology as a structural change or are some organizations holding back to see how the situation improves in the future? “I see it as a long-term trend. If you look at the IT budgets and projects in the ‘90s, it was some something unimportant. It was, of course, important that the printer works and the fax machine works, but it was not definitely not strategic for the company. 

“And then in 2000, the whole cloud trend came up, and there was the big hope that this will save money. It was always the narrative with cloud computing that you can just outsource it and save money and it’s great. 

“Nowadays, people realize that it’s not something that you can just ignore. I wouldn’t say that everything comes back on premise, but people care about it now. They understand it’s not just a commodity, like water, or electricity that comes out of the wall and you don’t care what’s behind it. People realize that it’s something that has an impact on the future of an organization, from a vendor lock-in perspective, from a cost perspective, from an industry espionage perspective, and competitiveness. With open source, you’re more flexible. So, I think the trend that this is all more strategic and important for the future, this will go on.”

The European Commission recently published its Tech Sovereignty Package, including its open source strategy. Are these proposals sufficient to address the concern around digital sovereignty and support the open source ecosystem in Europe?

It’s great, I really like it. I was actually surprised they listened so well. But now the real challenge is to actually do it; this still needs to happen. The description of the problem and a possible solution, this is all very good. I’m surprised, I’m happy about it, but to put this into actually binding law, this still needs happen.”

Would you like to see any changes to the current proposals before they’re gets passed into legislation? “At the moment, they have these four different risk levels, and the most critical one — No. 4 — is one where they accept only open source and European solutions. This is the highest risk level, but this is only for 1% of the market. I hope that it’s better understood that more than 1% should care about this more.

“If you have something which is completely not critical, maybe doesn’t possess any personal data at all — sure, it’s totally fine [to use non-EU suppliers]. But if you have GDPR requirements, espionage protection, no vendor lock-in, and so on, then there should be more of that [the highest requirement level].”

US firms have attempted to address European customers’ concerns in different ways, with sovereign marketed cloud services and joint ventures with European providers. Microsoft 365 Local is designed to run on premise. Where do you draw the line between what’s actually a sovereign solution and what some call ‘sovereignty washing? “Sovereignty has different dimensions, of course. But if you look at the problem of the CLOUD Act alone, which gives foreign agencies full access to the data here, then the whole idea that it’s enough to have European data centers — that’s not enough. It’s clearly written in the CLOUD Act, that even with [European] data centers, or subsidiaries, it still applies.  

“Microsoft tries to find a solution there with its Delos idea; a company that is owned by SAP — a German company — and Microsoft delivers only the software. But even then, you have this dependency, because software needs updates and software security updates. And if they’re not available, or if someone puts a backdoor into the software, which is possible, then you still have a problem. 

“So, they’re trying really, really hard to find a way around the problem, but it’s not easy for them.”

To look ahead a bit in terms of the product strategy, there were announcements for Nextcloud Hub this week around AI agents, and the program to work with independent software vendors. What do these say about Nextcloud’s future? “The overall product strategy will not change so much; it’s about having state-of-the-art collaboration software — but with a lot more control, security and safety — that’s open source and independent where you host it. So this will always stay, but of course, there’s some additional factors that come into play now, like the AI impact that we see and want to leverage with our agent strategy. 

“We’ve had this for one and a half years already, but we are expanding that. In the future, you might still use an interface in a classic way that you open documents and type in text and so on. But there are also a lot of operations that can be automated in the future with AI. And this is something we really invest a lot into. 

“Another aspect of AI is how easy it is to build custom software around it. The coding models are getting better all the time, which means there will be more and more custom business software. This is what we want to capture with our ISV program. Software development will become easier, but you don’t want to deploy just random software in your company, you want to have something that is tested, certified and secured, and that somebody’s accountable for it. This can be something we can provide at Nextcloud.”

Editor’s note: NextCloud paid for Matthew Finnegan’s travel and hotel costs for NextCloud Summit 2026, but had no editorial role in the creation of this story.

Kategorie: Hacking & Security