Category: Being in Business

  • Digital Omnibus reality check: 83.5% of access requests not properly answered

    noyb

    Read original article →

    Concatena says

    Our Take: This analysis from noyb (who may have a particular point to make) shows companies – not data subjects – are the real problem: 83.5% of access requests tied to noyb cases were either incomplete or unanswered, including many from big tech, who one would have imagined would have sophisticated enough systems to automate such a process. Noyb suggest this indicates that proposals in the Digital Omnibus to restrict access rights are misdirected.

    Your Takeaway: it’s true that data subject access requests can be misused, but they are a vital check and balance for data protection. If responding to a subject access request is hard, you may wish to consider whether that shows some weakness in your overall data governance practices. Give us a call – we can help!

    Most companies do not properly answer requests for access to personal data, with 83.5% of such requests ignored or incomplete. Big tech firms often fail to provide full replies, making it hard for people to check their data use. The European Commission wants to limit these access rights, but experts warn this would harm people’s privacy protections.

    Highlights

    **Access Requests not a relevant workload.** At the same time, a recently published *noyb* survey made clear that the majority (over 70%) of Data Protection Officers (DPOs) working in companies think that data subject rights – and the Right of Access in particular – don’t create a significant workload, while being a useful tool for protecting people’s rights.

    **Real-life data: 83.5% of access requests not properly answered.** In practice, however, the primary problem concerning the right of access is not “abusive” complaints, but the huge amount of requests that don’t receive a proper answer. This also explains why a significant number of complaints before authorities concern the lack of a full reply to access requests. To gain more insight into how companies deal with the right of access, *noyb* analysed 121 access requests that have been filed in relation to *noyb* cases since 2018*. The results are clear: only 16.5% of those requests received a satisfying reply, while 53.7% were incomplete – and almost 30% were not answered at all. Overall, 83.5% of requests were not responses in line with the law.

    **The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new** **analysis of** ***noyb*** **cases shows: Only 16.5% of all access requests** ***noyb*** **has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30% were not answered at all. In other words: while companies are lobbying Brussels to limit people’s right of access because of an alleged “abuse”, the real problem is non-compliance by these exact companies.**

  • Usage-based pricing killing your vibe – here’s how to roll your own local AI coding agents

    Tobias Mann and Thomas Claburn

    Read original article →

    Concatena says

    Our Take: I’m not necessarily encouraging you to rolll your own here, but it is worth being aware of this business model change – and the fact that from the get-go the definition of a token as a metric has been less than clear and open.

    Your Takeaway: If you’re reliant on third party LLMs, remember to account for the risk of them changing their measurement metrics and charging – it’s been on the cards for a while.

    Usage-based pricing for AI coding tools is becoming expensive and restrictive. This article shows how to run local AI coding agents like Claude Code, Pi Coding Agent, and Cline to avoid those costs. Local models work well for small projects but may need human approval to avoid mistakes.

    Highlights

    Over the past few weeks, we’ve seen Anthropic toy with dropping Claude Code from its most affordable plans while Microsoft has skipped testing the waters and moved GitHub Copilot to a purely usage-based model. The whole debacle got us thinking. Do we even need Anthropic or OpenAI’s top models, or can we get away with a smaller local model? Sure, it might be slower, less capable, and a little more frustrating to work with, but you can’t beat the price of free… Well, assuming you’ve already got the hardware that is.

  • Does Your AI Agent Need a VPN? The Company Behind Norton and Avast Thinks So

    Ajay Kumar

    Read original article →

    Concatena says

    Our Take: Some are looking to ban VPNs, whilst others are giving them to AI Agents… Back to whack-a-mole for services who are trying to stop AI agents from clogging up their processes.

    Your Takeaway: If your service distinguishes between human and agent, will VPN use affect that process? Or could your agent benefit from its own VPN?

    You might use a VPN yourself, but have you considered giving one to your AI agent? It might be more important than you think.

    Highlights

    "Perhaps most importantly, your ISP can’t distinguish between your own internet traffic and that of your autonomous AI agent," said Tomaschek. "But with this integration, as well as with Windscribe’s, the VPN encrypts the agent’s traffic as well, so basically you’re protected from whatever your agent might autonomously get up to on the internet."

    If you use OpenClaw, ChatGPT or one of the many other LLMs with access to the internet, your autonomous AI agent can now take advantage of the same privacy and security features.

    "Using a VPN with an LLM can provide several advantages, such as keeping your identity private. Your internet provider won’t be able to see your AI agent’s activity, or that you’re using an AI agent," said Moe Long, CNET senior editor.

  • Study: AI models that consider user’s feeling are more likely to make errors

    Kyle Orland

    Read original article →

    Concatena says

    Our Take: The law of unintended consequences strikes again – and why tech management and parenting have so much in common…

    Your Takeaway: When you’re defining how you want an AI agent to act, remember it’s going to take your instructions very literally – and you might not like the consequences. Does this have an impact for products you ship or products you use that incorporate Ai – particularly if the people training the product may have a different world viewpoint to those using it?

    AI models tuned to be warmer and more empathetic often make more mistakes than original models. These warmer models tend to prioritize making users feel good over giving correct answers, especially when users share emotions like sadness. Researchers warn that choosing between a friendly AI and an accurate AI is important for safe and trustworthy use.

    Highlights

    In a new paper published this week in Nature, researchers from Oxford University’s Internet Institute found that specially tuned AI models tend to mimic the human tendency to occasionally “soften difficult truths” when necessary “to preserve bonds and avoid conflict.” These warmer models are also more likely to validate a user’s expressed incorrect beliefs, the researchers found, especially when the user shares that they’re feeling sad.

    In human-to-human communication, the desire to be empathetic or polite often conflicts with the need to be truthful—hence terms like “being brutally honest” for situations where you value the truth over sparing someone’s feelings. Now, new research suggests that large language models can sometimes show a similar tendency when specifically trained to present a “warmer” tone for the user.

  • Hackers are actively exploiting a bug in cPanel, used by millions of websites

    Zack Whittaker

    Read original article →

    Concatena says

    Our Take: If you’re using cPanel, make sure you’re patched!

    This is a high-risk, actively exploited authentication-bypass in cPanel/WHM (CVE-2026-41940) that lets attackers skip login and take full admin control of servers; because cPanel is widespread and has deep server access, unpatched systems – especially on shared hosting – are prime targets and some hosts already saw exploitation attempts.

    Your Takeaway: We’re not tech experts, but check with your team or provider and make sure you’re patched (or that access to control panels is blocked/isolated).

    A serious bug in cPanel software lets hackers take full control of websites and servers. Many web hosting companies have fixed the issue, but users must update their systems quickly to stay safe. Experts warn that the vulnerability is being actively exploited and could affect millions of sites worldwide.

    Highlights

    cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.

    The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.

    Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM).

  • Spotify rolls out ‘Verified’ badge to distinguish human artists from AI

    Agence France-Presse

    Read original article →

    Concatena says

    Our Take: Spotify’s new green “Verified by Spotify” badge and the informational panel are straightforward moves to help users spot human artists and surface authenticity signals amid a flood of AI-generated music. B the verification criteria (sustained engagement, platform-rule compliance, external presence like gigs/merch/socials) explicitly exclude primarily AI-created artists, rather than music… Is this the intention?

    Your Takeaway: It’s always worth considering what the “verification” on any site means – what needs to be demonstrated before verification is granted.

    Spotify will add a green "Verified by Spotify" badge to show which artists are real humans, not AI creations. This badge helps listeners trust the music and appears only on profiles that meet Spotify’s authenticity rules. The change comes as many AI-generated songs flood streaming platforms, causing concern in the music industry.

    Highlights

    Spotify on Thursday unveiled a new verification system designed to help listeners distinguish human musicians from AI-generated content, as people flood streaming platforms with a growing volume of synthetic tracks made with artificial intelligence.

    The initiative arrives amid mounting concern across the music industry over AI-generated content overwhelming streaming catalogues.

    The company said more than 99% of artists that listeners actively search for will be verified at launch, representing hundreds of thousands of musicians spanning genres and geographies.

    To earn verification, artists must demonstrate sustained listener engagement over time, comply with Spotify’s platform rules and show signs of a genuine presence both on and off the platform, such as concert dates, merchandise and linked social media accounts.

  • Firefox maker torches Google for building Prompt API into browser

    Thomas Claburn

    Read original article →

    Concatena says

    Our Take: Mozilla is right to flag real risks with Google’s Prompt API: it bundles a vendor-specific model and policy into a browser API, which can push developers to change the way they build.

    Your Takeaway: There is a very real risk for everyone of AI being built in by the back door even if a product doesn’t appear to use AI. Due diligence in software is getting very difficult.

    Treat any browser‑provided AI API as a potential vector for vendor lock‑in and unexpected content controls; push for neutral, implementable standards that separate API mechanics from any single model or provider policy, test real performance and harms before adoption, and avoid building critical product flows that depend on Chrome‑specific AI behaviour.

    Mozilla opposes Google’s new Prompt API because it may limit web openness and favor Google’s AI model. They worry it forces developers to follow Google’s rules, hurting fairness and interoperability. Google says the API encourages innovation, but tests show its AI often performs poorly.

    Highlights

    "The core problem is interoperability," he said. "Prompts are tightly coupled to models; developers will inevitably tune to the quirks and policies of whatever model they’re building against.

    "This seems like a bad direction for an API on the web platform, and sets a worrying precedent for more APIs that have [browser]-specific rules around usage," he said.

    Perhaps more significantly, Archibald notes that using the Prompt API requires agreeing to Google’s Generative AI Prohibited Uses Policy, which prohibits activities that are not necessarily illegal, like generating "disturbing" content.

    First, he worries that Google’s own Nano model will become the default and that developers will standardize on it in an effort to make the non-deterministic responses of an AI model more predictable. That tendency, he argues, will create pressure for Apple and Mozilla to license Nano, for the sake of a common user experience.

    Mozilla’s concern, as articulated by Archibald, has to do with what the Prompt API means for the web, not to mention Google’s justification for deployment.

    Various vendors like OpenAI and Perplexity have shipped browsers that embed access to remotely hosted AI models. Mozilla itself is testing an AI-based Smart Window in Firefox and it’s developing tools for AI model scaffolding.

    The Prompt API, as Google describes it, "gives web pages the ability to directly prompt a browser-provided language model." It provides a way to send natural language instructions to Google’s Gemini Nano model, which is small enough to be downloaded for local inference through Chrome.

    "We continue to oppose this API, and feel it has severe negative consequences to the interoperability, updatability, and neutrality of the web platform," said Archibald.

    Jake Archibald, Mozilla web developer relations lead, articulated the org’s concerns in a GitHub discussion of the API, which provides a standard way to send and receive prompts and responses from a local machine learning model.

  • Congress keeps kicking surveillance reform down the road

    Gaby Del Valle

    Read original article →

    Concatena says

    Our Take: Congress has kicked the FISA 702 can down the road. Whilst this legal back and forth might feel far away, the way the US sets its surveillance rules has real knock-on effects for UK/EU businesses relying on US cloud and SaaS tools, and for anyone worrying about international data transfers. This is one to watch closely in case future “reforms” either harden surveillance or, more optimistically, edge towards better privacy safeguards that could ease some cross-border risk.

    Your Takeaway: If your business leans on US tech stacks, keep in mind that ongoing FISA 702 wrangling could shift the risk profile of your international data flows overnight. Treat this as a reminder to map which services touch US infrastructure, keep your transfer impact assessments fresh, and be ready to explain to customers and boards why a very American-sounding fight in Congress still matters for their data.

    Congress extended Section 702 of the Foreign Intelligence Surveillance Act for 45 days to allow more time for reform talks. The House passed a version with minor changes but no warrant requirements, causing frustration among some lawmakers. Privacy advocates say the bill does not do enough to protect Americans’ rights.

    Highlights

    “Three weeks is more than enough time to negotiate a reform bill,” Thune said on the Senate floor on Thursday. “That is, if members are serious about negotiating.”

    The House renewed Section 702 with minor reforms on Wednesday evening. The bill didn’t include the hotly debated warrant requirement, but it did feature a provision prohibiting the Federal Reserve from issuing Central Bank Digital Currencies, which Senate Majority Leader John Thune (R-SD) described as a nonstarter.

    Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act — but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the controversial wiretapping bill. If the past few weeks are any indication of how future debates will go, however, we’re in for a bumpy ride.

  • Will AI lead to more accurate opinion polls?

    BBC News – Business

    Read original article →

    Concatena says

    Our Take: Whether about polling or anything else, 90% accuracy sounds like a big number, but in practice it means getting a lot of things wrong. It’s really important when companies cite these kinds of figures to try to get access to real life examples of that margin of error.

    Your Takeaway: Never take accuracy figures on face value – work out what they actually mean.

    It’s cheaper and faster to collect people’s opinions using AI, but will it make polls more accurate?

    Highlights

    One checks he’s answering the question, one analyses whether he’s being too superficial and needs prompting to go deeper, while the third checks that the respondent is not a fraud… not a robot, for example.

    Note: How long will it be before there are products to answer these kinds of calls for you?

    The voice is young, female, brisk and business-like and belongs to an AI agent. A computer programme in other words. A string of code.

    Note: It’s worth questioning why AI agents are so frequently expressed as being female…

    The company claims its method is "10 times faster, 10 times cheaper and 90% as accurate as human polling".

    It does not focus on quantitative polling, which is already largely automated through mass surveys. Instead, it emphasises depth. "We don’t ask people to tick boxes – they have a conversation with an AI," Fontaine explains. "That means we can explore not just what people think, but how they think – how they build their opinions, and even when those opinions change."