Category: Tech Industry

  • YouTube’s AI slop purge is punishing the human creators who never showed their faces

    Ana Maria Constantin

    Read original article →

    Concatena says

    Summary: YouTube cracked down on mass-produced AI videos but its fixes are hurting legitimate "faceless" creators who never used AI. The algorithm now favors on-camera humans, causing demonetisation and channel removals based on proxy signals. Creators are scrambling to show faces or change formats while YouTube balances building AI tools and limiting their spread.

    Takeaway: Oh, that age old law of unintended consequences… whenever a platform declares it’s banning, or tagging, AI slop, we should always ask how it’s planning on doing that. Those who perhaps were taking the sensible option of preserving their privacy (as I did when I was a old-time mummy blogger) are penalised because of AI content finding them easier to emulate. We really need to think more steps ahead that just one… Crowdsourced ratings, automatic labels and channel-level enforcement risk wrongful demonetisation or bans, while YouTube simultaneously builds AI tools — a conflicted approach that harms privacy-focused, anonymous creators and invites perverse incentives.

    YouTube cracked down on mass-produced AI videos but its fixes are hurting legitimate "faceless" creators who never used AI. The algorithm now favors on-camera humans, causing demonetisation and channel removals based on proxy signals. Creators are scrambling to show faces or change formats while YouTube balances building AI tools and limiting their spread.

    Highlights

    Crowdsourcing AI detection has obvious limitations. Research consistently shows that people are poor at identifying AI-generated content, and their accuracy is declining as the tools improve. There is also no indication of how YouTube will weight the ratings or whether a threshold of negative viewer feedback will trigger demonetisation or suppression.

    YouTube is now testing a new approach: a mobile pop-up that asks viewers to rate whether a video feels like AI slop on a five-point scale from “*not at all*” to “*extremely.*” The feature appeared in March 2026 and adds a third layer of detection on top of YouTube’s existing automated and human review systems.

    YouTube has a growing AI slop problem, and its efforts to fix it are catching legitimate creators in the crossfire. In January 2026, the platform terminated 16 channels with a combined 35 million subscribers and 4.7 billion lifetime views under its inauthentic content policy, a quiet rename of the old “*repetitious content*” rules. The channels were producing mass-generated, low-effort content at scale, but the algorithm changes that followed are now penalising a much broader group: faceless creators who have never used AI at all.

  • Usage-based pricing killing your vibe – here’s how to roll your own local AI coding agents

    Tobias Mann and Thomas Claburn

    Read original article →

    Concatena says

    Our Take: I’m not necessarily encouraging you to rolll your own here, but it is worth being aware of this business model change – and the fact that from the get-go the definition of a token as a metric has been less than clear and open.

    Your Takeaway: If you’re reliant on third party LLMs, remember to account for the risk of them changing their measurement metrics and charging – it’s been on the cards for a while.

    Usage-based pricing for AI coding tools is becoming expensive and restrictive. This article shows how to run local AI coding agents like Claude Code, Pi Coding Agent, and Cline to avoid those costs. Local models work well for small projects but may need human approval to avoid mistakes.

    Highlights

    Over the past few weeks, we’ve seen Anthropic toy with dropping Claude Code from its most affordable plans while Microsoft has skipped testing the waters and moved GitHub Copilot to a purely usage-based model. The whole debacle got us thinking. Do we even need Anthropic or OpenAI’s top models, or can we get away with a smaller local model? Sure, it might be slower, less capable, and a little more frustrating to work with, but you can’t beat the price of free… Well, assuming you’ve already got the hardware that is.

  • AI agents can bypass guardrails and put credentials at risk, Okta study finds

    Computerworld

    Read original article →

    Concatena says

    Our Take: It might save some time, but tou don’t need to be hugely imaginative to come up with scenarios where agentic AI could cause some really fundamental problems.

    Your Takeaway: BE CAREFUL – if it seems to good to be true, it might be. These tools are so easy to use, but it’s really worthwhile having at least a basic understanding of what they CAN do if you’re going to use them, so you can protect yourself.

    And let’s start by NOT giving tools like OpenClaw full access to your computer…

    An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.
    It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.
    A look at just how easily this can happen emerges from Phishing the agent: Why AI guardrails aren’t enough, a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.
    Their research focused on OpenClaw, a model-agnostic multi-channel AI assistant which has seen explosive growth inside enterprises since appearing in late 2025.
    The Telegram hack
    In common with the growing list of rival agents, OpenClaw is only as useful as the access it is given to files, accounts, browsers, network devices, and, most significant of all, credentials.
    One test conducted by Okta assessed how easy it would be to trick OpenClaw running Claude Sonnet 4.6 into handing over an OAuth token. This shouldn’t be possible; the LLM should refuse this request. However, what might have held true when prompting Claude as a chatbot quickly fell apart when it was accessed through OpenClaw.
    The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.
    First, the attacker instructed the agent via Telegram to retrieve an OAuth token, but to only display it in a terminal window on the computer. Claude Sonnet’s guardrails would prevent it from copying the token, however, the testers were able to reset the agent, causing it to forget it had displayed the token in the terminal window.
    At that point, Okta said in i…

    Highlights

    Agents are only the latest example of a technology that is being deployed faster than it can be secured, Kirk observed. “Much of AI right now is defying security gravity,” he said. “But there are ways to use agents safely and keep credentials out of their reach, which is the only safe way to use them.”

    “The agents are prompted to be as helpful as possible by default, a characteristic that poses particular concerns when it comes to credentials and tokens,” said Kirk.

    Agentic AI is really two things: a powerful orchestration system coupled to one or more highly-capable LLMs. What an agent *isn’t* is a simple interface, and it must be viewed as a separate system capable of autonomous, unpredictable reasoning.

    The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.

    A look at just how easily this can happen emerges from *Phishing the agent: Why AI guardrails aren’t enough**,* a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.

    It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.

    An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.

  • Does Your AI Agent Need a VPN? The Company Behind Norton and Avast Thinks So

    Ajay Kumar

    Read original article →

    Concatena says

    Our Take: Some are looking to ban VPNs, whilst others are giving them to AI Agents… Back to whack-a-mole for services who are trying to stop AI agents from clogging up their processes.

    Your Takeaway: If your service distinguishes between human and agent, will VPN use affect that process? Or could your agent benefit from its own VPN?

    You might use a VPN yourself, but have you considered giving one to your AI agent? It might be more important than you think.

    Highlights

    "Perhaps most importantly, your ISP can’t distinguish between your own internet traffic and that of your autonomous AI agent," said Tomaschek. "But with this integration, as well as with Windscribe’s, the VPN encrypts the agent’s traffic as well, so basically you’re protected from whatever your agent might autonomously get up to on the internet."

    If you use OpenClaw, ChatGPT or one of the many other LLMs with access to the internet, your autonomous AI agent can now take advantage of the same privacy and security features.

    "Using a VPN with an LLM can provide several advantages, such as keeping your identity private. Your internet provider won’t be able to see your AI agent’s activity, or that you’re using an AI agent," said Moe Long, CNET senior editor.

  • Meta cuts contractors who reported seeing Ray-Ban Meta users have sex

    Scharon Harding

    Read original article →

    Concatena says

    Our Take: Without going into the many many layers of this story, our takeaway for anyone procuring products or services is to consider the full supply chain when looking at the ethics of a product. What feels like automated magic is often a person behind the curtain, probably in a jurisdiction with fewer safeguards, more often than you might expect.

    Your Takeaway: Beauty isn’t skin deep – make sure you do your due diligence and that your happy that your providers ahve appropriate worker protection and safeguards all the way down the chain. And if you’re running human‑review workflows – think through all the consequences. Finally, if you’re using wearable tech which captures images of everyone around you, give real consideration to how you’d feel if a someone with less moral integrity than you were to do the same.

    Meta ended its contract with Kenyan firm Sama after workers reported seeing private and explicit videos recorded by Ray-Ban Meta glasses. Sama denies failing to meet standards and says it was not warned about any issues. The situation has raised privacy concerns and led to investigations and a class-action lawsuit against Meta.

    Highlights

    BBC reported that Sama workers believe Meta ended the contract because workers spoke out about seeing Ray-Ban Meta-shot footage of people performing personal acts, like changing their clothes, having sex, and using the toilet.

    A Meta spokesperson told BBC that Meta “decided to end our work with Sama because they don’t meet our standards.” Ars Technica reached out to Meta asking how, specifically, Sama failed to meet Meta’s expectations and will update this article if we hear back. Ars has also reached out to Sama.

    In February, numerous workers from a company that Meta contracted to perform data annotation for Ray-Ban Meta reported viewing sensitive, embarrassing, and seemingly private footage recorded by the smart glasses. About two months later, Meta ended its contract with the firm.

  • Spotify rolls out ‘Verified’ badge to distinguish human artists from AI

    Agence France-Presse

    Read original article →

    Concatena says

    Our Take: Spotify’s new green “Verified by Spotify” badge and the informational panel are straightforward moves to help users spot human artists and surface authenticity signals amid a flood of AI-generated music. B the verification criteria (sustained engagement, platform-rule compliance, external presence like gigs/merch/socials) explicitly exclude primarily AI-created artists, rather than music… Is this the intention?

    Your Takeaway: It’s always worth considering what the “verification” on any site means – what needs to be demonstrated before verification is granted.

    Spotify will add a green "Verified by Spotify" badge to show which artists are real humans, not AI creations. This badge helps listeners trust the music and appears only on profiles that meet Spotify’s authenticity rules. The change comes as many AI-generated songs flood streaming platforms, causing concern in the music industry.

    Highlights

    Spotify on Thursday unveiled a new verification system designed to help listeners distinguish human musicians from AI-generated content, as people flood streaming platforms with a growing volume of synthetic tracks made with artificial intelligence.

    The initiative arrives amid mounting concern across the music industry over AI-generated content overwhelming streaming catalogues.

    The company said more than 99% of artists that listeners actively search for will be verified at launch, representing hundreds of thousands of musicians spanning genres and geographies.

    To earn verification, artists must demonstrate sustained listener engagement over time, comply with Spotify’s platform rules and show signs of a genuine presence both on and off the platform, such as concert dates, merchandise and linked social media accounts.

  • Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter

    Anna Heim

    Read original article →

    Concatena says

    Our Take: We’re seeing more “market froth” more than “proven change in legal practice.” Valuations, ad campaigns and celebrity endorsements are racing ahead of most firms’ ability to use these tools in a meaningful way. Right now, the gap between the hype and what fee-earners actually do with Harvey/Legora in a normal Tuesday is still pretty stark. I’d love to hear your experience!

    Your Takeaway: Treat this as a signal to experiment deliberately, not to panic-buy a platform. If you haven’t already, pick one or two contained use cases (e.g. first-draft research notes, clause comparison) and run small, supervised pilots with clear guardrails. Then share honest internal feedback — including the “confused faces” — so you don’t let marketing headlines set your AI strategy.

    Legora is a legal AI startup valued at $5.6 billion and backed by Nvidia and other investors. It competes closely with Harvey, another legal AI company valued at $11 billion, as both expand globally. The rivalry is intense, with big marketing efforts and a focus on applying AI to reshape the legal industry.

    Highlights

    Alongside Atlassian and other new financial investors, NVentures joined Legora’s cap table as part of a $50 million Series D extension that comes a month after the startup’s $550 million Series D.

    Leveraging AI to help lawyers streamline their work, the Swedish-born legal tech startup is competing with U.S. player Harvey.

    Nvidia has laid a new brick in its AI empire. NVentures, its corporate VC fund, has backed Legora, reportedly its first legal AI investment.

  • Firefox maker torches Google for building Prompt API into browser

    Thomas Claburn

    Read original article →

    Concatena says

    Our Take: Mozilla is right to flag real risks with Google’s Prompt API: it bundles a vendor-specific model and policy into a browser API, which can push developers to change the way they build.

    Your Takeaway: There is a very real risk for everyone of AI being built in by the back door even if a product doesn’t appear to use AI. Due diligence in software is getting very difficult.

    Treat any browser‑provided AI API as a potential vector for vendor lock‑in and unexpected content controls; push for neutral, implementable standards that separate API mechanics from any single model or provider policy, test real performance and harms before adoption, and avoid building critical product flows that depend on Chrome‑specific AI behaviour.

    Mozilla opposes Google’s new Prompt API because it may limit web openness and favor Google’s AI model. They worry it forces developers to follow Google’s rules, hurting fairness and interoperability. Google says the API encourages innovation, but tests show its AI often performs poorly.

    Highlights

    "The core problem is interoperability," he said. "Prompts are tightly coupled to models; developers will inevitably tune to the quirks and policies of whatever model they’re building against.

    "This seems like a bad direction for an API on the web platform, and sets a worrying precedent for more APIs that have [browser]-specific rules around usage," he said.

    Perhaps more significantly, Archibald notes that using the Prompt API requires agreeing to Google’s Generative AI Prohibited Uses Policy, which prohibits activities that are not necessarily illegal, like generating "disturbing" content.

    First, he worries that Google’s own Nano model will become the default and that developers will standardize on it in an effort to make the non-deterministic responses of an AI model more predictable. That tendency, he argues, will create pressure for Apple and Mozilla to license Nano, for the sake of a common user experience.

    Mozilla’s concern, as articulated by Archibald, has to do with what the Prompt API means for the web, not to mention Google’s justification for deployment.

    Various vendors like OpenAI and Perplexity have shipped browsers that embed access to remotely hosted AI models. Mozilla itself is testing an AI-based Smart Window in Firefox and it’s developing tools for AI model scaffolding.

    The Prompt API, as Google describes it, "gives web pages the ability to directly prompt a browser-provided language model." It provides a way to send natural language instructions to Google’s Gemini Nano model, which is small enough to be downloaded for local inference through Chrome.

    "We continue to oppose this API, and feel it has severe negative consequences to the interoperability, updatability, and neutrality of the web platform," said Archibald.

    Jake Archibald, Mozilla web developer relations lead, articulated the org’s concerns in a GitHub discussion of the API, which provides a standard way to send and receive prompts and responses from a local machine learning model.

  • Congress keeps kicking surveillance reform down the road

    Gaby Del Valle

    Read original article →

    Concatena says

    Our Take: Congress has kicked the FISA 702 can down the road. Whilst this legal back and forth might feel far away, the way the US sets its surveillance rules has real knock-on effects for UK/EU businesses relying on US cloud and SaaS tools, and for anyone worrying about international data transfers. This is one to watch closely in case future “reforms” either harden surveillance or, more optimistically, edge towards better privacy safeguards that could ease some cross-border risk.

    Your Takeaway: If your business leans on US tech stacks, keep in mind that ongoing FISA 702 wrangling could shift the risk profile of your international data flows overnight. Treat this as a reminder to map which services touch US infrastructure, keep your transfer impact assessments fresh, and be ready to explain to customers and boards why a very American-sounding fight in Congress still matters for their data.

    Congress extended Section 702 of the Foreign Intelligence Surveillance Act for 45 days to allow more time for reform talks. The House passed a version with minor changes but no warrant requirements, causing frustration among some lawmakers. Privacy advocates say the bill does not do enough to protect Americans’ rights.

    Highlights

    “Three weeks is more than enough time to negotiate a reform bill,” Thune said on the Senate floor on Thursday. “That is, if members are serious about negotiating.”

    The House renewed Section 702 with minor reforms on Wednesday evening. The bill didn’t include the hotly debated warrant requirement, but it did feature a provision prohibiting the Federal Reserve from issuing Central Bank Digital Currencies, which Senate Majority Leader John Thune (R-SD) described as a nonstarter.

    Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act — but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the controversial wiretapping bill. If the past few weeks are any indication of how future debates will go, however, we’re in for a bumpy ride.

  • White House presses tech companies for support on AI-driven cyberattacks

    Aaron Mak, John Sakellariadis, Dana Nickel

    Read original article →

    Concatena says

    Our Take: Does the approach taken to law making by governments rely a little too much on input from those who perhaps ought to be restricted by the laws that are made? This is a pivotal moment: policymakers want operational help fast, but firms want clear bounds on data sharing, liability and commercial secrecy.

    Your Takeaway: If you work with or run tech/security businesses, be ready to engage but insist on narrow, well‑justified requests, explicit protections for sensitive operational details, and clarity on how shared information will be used and protected; consider tightening disclosure policies and seeking confidentiality or legal safeguards before responding.

    Tech and cyber companies were sent questions about artificial intelligence-led cybersecurity threats, including those posed by Anthropic’s advanced AI model, Mythos.

    Highlights

    The White House has been taking steps to defuse a monthslong legal battle with Anthropic over the company’s efforts to set ethical limits on government use of AI — a fight that led President Donald Trump in February to ban all federal agencies from using the AI company’s software. Since then, growing awareness of Mythos’ cyber prowess — as well as concerns that unauthorized users might be commandeering technology — has agencies clamoring for access to the tool.

    One list of questions sent by the White House to some tech and cyber firms, obtained by POLITICO, covers a range of technical and policy considerations, including which widely used coding projects should be prioritized and more basic questions about how the public and private sectors can work together on initiatives such as Project Glasswing. One question simply asks: “What is the most effective role for the government?”

    The request for additional, detailed information from these companies reflects the intensifying focus in Washington on the evolving threat that hyper-advanced AI tools may pose to national security and digital infrastructure.

    The questions, from the White House’s Office of the National Cyber Director, focus on how specific sectors in the tech and cybersecurity industries can work with the White House to boost their defenses with AI, these people said. Companies have been asked to respond to them by Friday.

    The White House has asked a group of tech companies to answer a set of questions this week about how to ward off digital attacks that frontier AI tools could soon enable, according to four people with knowledge of discussions between the administration and the tech sector.