<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type='text/xsl' href='feed.xsl'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Concatena Links: Tech and Law from across the web</title>
    <link>https://concatena.co.uk</link>
    <description>A curated selection of articles on tech and law from across the web, curated and commented on by Concatena. Updated as regularly as new reading is tagged.</description>
    <atom:link href="https://concatena.co.uk/feeds/law-tech.xml" rel="self"/>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>ConcatenatedReads/1.0</generator>
    <language>en</language>
    <lastBuildDate>Tue, 05 May 2026 17:27:45 +0000</lastBuildDate>
    <item>
      <title>Digital Omnibus reality check: 83.5% of access requests not properly answered</title>
      <link>https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered</link>
      <description>Most companies do not properly answer requests for access to personal data, with 83.5% of such requests ignored or incomplete. Big tech firms often fail to provide full replies, making it hard for people to check their data use. The European Commission wants to limit these access rights, but experts warn this would harm people’s privacy protections.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; noyb&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered"&gt;https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;access-rights&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;data-governance&lt;/span&gt; &lt;span class="tag"&gt;data-protection&lt;/span&gt; &lt;span class="tag"&gt;dsar&lt;/span&gt; &lt;span class="tag"&gt;enforcement&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Most companies do not properly answer requests for access to personal data, with 83.5% of such requests ignored or incomplete. Big tech firms often fail to provide full replies, making it hard for people to check their data use. The European Commission wants to limit these access rights, but experts warn this would harm people’s privacy protections.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; This analysis from noyb (who may have a particular point to make) shows companies - not data subjects - are the real problem: 83.5% of access requests tied to noyb cases were either incomplete or unanswered, including many from big tech, who one would have imagined would have sophisticated enough systems to automate such a process. Noyb suggest this indicates that proposals in the Digital Omnibus to restrict access rights are misdirected.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; it’s true that data subject access requests can be misused, but they are a vital check and balance for data protection. If responding to a subject access request is hard, you may wish to consider whether that shows some weakness in your overall data governance practices. Give us a call - we can help!&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;**Access Requests not a relevant workload.** At the same time, a [recently published *noyb* survey](https://noyb.eu/en/gdpr-omnibus-eu-simplification-far-removed-real-business-needs) made clear that the majority (over 70%) of Data Protection Officers (DPOs) working in companies think that data subject rights – and the Right of Access in particular – don’t create a significant workload, while being a useful tool for protecting people’s rights.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;**Real-life data: 83.5% of access requests not properly answered.** In practice, however, the primary problem concerning the right of access is not “abusive” complaints, but the huge amount of requests that don’t receive a proper answer. This also explains why a significant number of complaints before authorities concern the lack of a full reply to access requests. To gain more insight into how companies deal with the right of access, *noyb* analysed 121 access requests that have been filed in relation to *noyb* cases since 2018*. The results are clear: only 16.5% of those requests received a satisfying reply, while 53.7% were incomplete – and almost 30% were not answered at all. Overall, 83.5% of requests were not responses in line with the law.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;**The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new** **analysis of** ***noyb*** **cases shows: Only 16.5% of all access requests** ***noyb*** **has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30% were not answered at all. In other words: while companies are lobbying Brussels to limit people’s right of access because of an alleged “abuse”, the real problem is non-compliance by these exact companies.**&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered</guid>
      <pubDate>Sun, 03 May 2026 16:15:56 +0000</pubDate>
    <ns0:tag xmlns:ns0="https://concatena.co.uk/feed/1.0">access-rights</ns0:tag><ns1:tag xmlns:ns1="https://concatena.co.uk/feed/1.0">cat:bus</ns1:tag><ns2:tag xmlns:ns2="https://concatena.co.uk/feed/1.0">cat:law</ns2:tag><ns3:tag xmlns:ns3="https://concatena.co.uk/feed/1.0">data-governance</ns3:tag><ns4:tag xmlns:ns4="https://concatena.co.uk/feed/1.0">data-protection</ns4:tag><ns5:tag xmlns:ns5="https://concatena.co.uk/feed/1.0">dsar</ns5:tag><ns6:tag xmlns:ns6="https://concatena.co.uk/feed/1.0">enforcement</ns6:tag><ns7:note xmlns:ns7="https://concatena.co.uk/feed/1.0">Our Take: This analysis from noyb (who may have a particular point to make) shows companies - not data subjects - are the real problem: 83.5% of access requests tied to noyb cases were either incomplete or unanswered, including many from big tech, who one would have imagined would have sophisticated enough systems to automate such a process. Noyb suggest this indicates that proposals in the Digital Omnibus to restrict access rights are misdirected.

Your Takeaway: it’s true that data subject access requests can be misused, but they are a vital check and balance for data protection. If responding to a subject access request is hard, you may wish to consider whether that shows some weakness in your overall data governance practices. Give us a call - we can help!</ns7:note><ns8:highlight xmlns:ns8="https://concatena.co.uk/feed/1.0">**Access Requests not a relevant workload.** At the same time, a [recently published *noyb* survey](https://noyb.eu/en/gdpr-omnibus-eu-simplification-far-removed-real-business-needs) made clear that the majority (over 70%) of Data Protection Officers (DPOs) working in companies think that data subject rights – and the Right of Access in particular – don’t create a significant workload, while being a useful tool for protecting people’s rights.</ns8:highlight><ns9:highlight xmlns:ns9="https://concatena.co.uk/feed/1.0">**Real-life data: 83.5% of access requests not properly answered.** In practice, however, the primary problem concerning the right of access is not “abusive” complaints, but the huge amount of requests that don’t receive a proper answer. This also explains why a significant number of complaints before authorities concern the lack of a full reply to access requests. To gain more insight into how companies deal with the right of access, *noyb* analysed 121 access requests that have been filed in relation to *noyb* cases since 2018*. The results are clear: only 16.5% of those requests received a satisfying reply, while 53.7% were incomplete – and almost 30% were not answered at all. Overall, 83.5% of requests were not responses in line with the law.</ns9:highlight><ns10:highlight xmlns:ns10="https://concatena.co.uk/feed/1.0">**The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new** **analysis of** ***noyb*** **cases shows: Only 16.5% of all access requests** ***noyb*** **has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30% were not answered at all. In other words: while companies are lobbying Brussels to limit people’s right of access because of an alleged “abuse”, the real problem is non-compliance by these exact companies.**</ns10:highlight></item>
    <item>
      <title>Final storage and access technologies guidance published</title>
      <link>https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/</link>
      <description>The ICO has today published its finalised guidance on Storage and Access Technologies (SATs), alongside an update on its online tracking strategy.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; ico.org.uk&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/"&gt;https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cookies&lt;/span&gt; &lt;span class="tag"&gt;ico&lt;/span&gt; &lt;span class="tag"&gt;ico-guidance&lt;/span&gt; &lt;span class="tag"&gt;online-privacy&lt;/span&gt; &lt;span class="tag"&gt;pecr&lt;/span&gt; &lt;span class="tag"&gt;sats&lt;/span&gt; &lt;span class="tag"&gt;storage-and-access-technologies&lt;/span&gt; &lt;span class="tag"&gt;surveillance&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The ICO has today published its finalised guidance on Storage and Access Technologies (SATs), alongside an update on its online tracking strategy.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; I’ve not had a chance to fully read into this yet, but my initial big takeaway is the uphill battle that the ICO has in trying to convince people that terms like SATs mean the same thing as they understand when they here cookies. I know how they feel, it’s driven me mad for years, but sometimes you need to meet people where they are. I’m slightly concerned about the references to consulting with the online advertising industry to help shape future initiatives - I’d really like to see consultation with third sector or indeed businesses who are reliant on the advertising revenue but also value their customers to pitch in here too. Final thought is to about how it’s intended that “demonstrably low privacy risks” are quantified. In 2004 I remember the then commissioner, Richard Thomas, warning that we were sleepwalking into a surveillance society. Whilst the current commissioner has stepped away for a while, I hope the ICO still remembers that report. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; Nothing really to see here, yet - but if online tracking or advertising is important to your business, or to your ethics, it’s worth a closer read - and maybe getting involved in the ongoing discussions.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;The guidance, which covers how the Privacy and Electronic Communications Regulations (PECR) (and where relevant, the UK GDPR) apply to cookies, tracking pixels, device fingerprinting and similar technologies (‘storage and access technologies’), incorporates updates following two consultations and changes introduced by the Data (Use and Access) Act. It includes new examples and points of clarification to help organisations comply with the law. It reflects the law as it currently stands, and sits separately from our ongoing work to review regulation 6 of PECR for online advertising purposes, on which further updates will follow in the coming weeks.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;We have today published our finalised guidance on [Storage and Access Technologies (SATs)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/), alongside an update on our [online tracking strategy](https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/).&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/</guid>
      <pubDate>Sun, 03 May 2026 13:01:16 +0000</pubDate>
    <ns11:tag xmlns:ns11="https://concatena.co.uk/feed/1.0">cat:law</ns11:tag><ns12:tag xmlns:ns12="https://concatena.co.uk/feed/1.0">cookies</ns12:tag><ns13:tag xmlns:ns13="https://concatena.co.uk/feed/1.0">ico</ns13:tag><ns14:tag xmlns:ns14="https://concatena.co.uk/feed/1.0">ico-guidance</ns14:tag><ns15:tag xmlns:ns15="https://concatena.co.uk/feed/1.0">online-privacy</ns15:tag><ns16:tag xmlns:ns16="https://concatena.co.uk/feed/1.0">pecr</ns16:tag><ns17:tag xmlns:ns17="https://concatena.co.uk/feed/1.0">sats</ns17:tag><ns18:tag xmlns:ns18="https://concatena.co.uk/feed/1.0">storage-and-access-technologies</ns18:tag><ns19:tag xmlns:ns19="https://concatena.co.uk/feed/1.0">surveillance</ns19:tag><ns20:note xmlns:ns20="https://concatena.co.uk/feed/1.0">Our Take: I’ve not had a chance to fully read into this yet, but my initial big takeaway is the uphill battle that the ICO has in trying to convince people that terms like SATs mean the same thing as they understand when they here cookies. I know how they feel, it’s driven me mad for years, but sometimes you need to meet people where they are. I’m slightly concerned about the references to consulting with the online advertising industry to help shape future initiatives - I’d really like to see consultation with third sector or indeed businesses who are reliant on the advertising revenue but also value their customers to pitch in here too. Final thought is to about how it’s intended that “demonstrably low privacy risks” are quantified. In 2004 I remember the then commissioner, Richard Thomas, warning that we were sleepwalking into a surveillance society. Whilst the current commissioner has stepped away for a while, I hope the ICO still remembers that report. 

Your Takeaway: Nothing really to see here, yet - but if online tracking or advertising is important to your business, or to your ethics, it’s worth a closer read - and maybe getting involved in the ongoing discussions.</ns20:note><ns21:highlight xmlns:ns21="https://concatena.co.uk/feed/1.0">The guidance, which covers how the Privacy and Electronic Communications Regulations (PECR) (and where relevant, the UK GDPR) apply to cookies, tracking pixels, device fingerprinting and similar technologies (‘storage and access technologies’), incorporates updates following two consultations and changes introduced by the Data (Use and Access) Act. It includes new examples and points of clarification to help organisations comply with the law. It reflects the law as it currently stands, and sits separately from our ongoing work to review regulation 6 of PECR for online advertising purposes, on which further updates will follow in the coming weeks.</ns21:highlight><ns22:highlight xmlns:ns22="https://concatena.co.uk/feed/1.0">We have today published our finalised guidance on [Storage and Access Technologies (SATs)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/), alongside an update on our [online tracking strategy](https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/).</ns22:highlight></item>
    <item>
      <title>Online tracking strategy update – April 2026</title>
      <link>https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/</link>
      <description>At the start of 2025, we published our online tracking strategy setting out our plans to give people meaningful choice and control over how they are tracked online, and provide businesses with certainty to innovate responsibly.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; ico.org.uk&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/"&gt;https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;ad-tech&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;consent-mechanisms&lt;/span&gt; &lt;span class="tag"&gt;consent-or-pay&lt;/span&gt; &lt;span class="tag"&gt;cookies&lt;/span&gt; &lt;span class="tag"&gt;online-privacy&lt;/span&gt; &lt;span class="tag"&gt;pecr&lt;/span&gt; &lt;span class="tag"&gt;sats&lt;/span&gt; &lt;span class="tag"&gt;storage-and-access-technologies&lt;/span&gt; &lt;span class="tag"&gt;surveillance&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;At the start of 2025, we published our online tracking strategy setting out our plans to give people meaningful choice and control over how they are tracked online, and provide businesses with certainty to innovate responsibly.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; We’ve commented on the SATs guidance in a separate post, but this wider summary from the ICO is worth a read too. I still don’t love the focus on consent for “cookies/SATs” (and don’t even get me started on consent-or-pay) - I don’t see how the average user can possibly understand the network that lies behind that little button - but that’s the legal landscape were in.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; As with the SAT guidance, there’s nothing requiring action here yet (unless you didn’t check your cookie banner compliance last year… in which case, I’d recommend a look now). Still, some ongoing discussions here it’s worth keeping on top of - and contributing to as well.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;After careful consideration and review of our concerns, we concluded that further action would not be appropriate after observing positive improvements from the platforms as compared to their historical processing practices. This was communicated to the platforms in January of this year.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;We assessed key areas of concern, including: the validity of consent for the data processing carried out by these platforms and their lawful basis relied upon for processing.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;We have driven improvements in the standard products offered to website owners by working directly with key cookie banner vendors responsible for the largest market shares across the UK's most popular websites. For example, OneTrust and Usercentrics have developed UK-specific templates aligned with our guidance. This is in addition to a range of other improvements made by these platforms and changes implemented by Sourcepoint and Inmobi to enhance their existing templates and guidance. This engagement has raised the bar across a significant portion of the market and made it easier for online businesses to offer fair, compliant choices to users.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;We committed to reviewing cookie banners on the top 1,000 websites in the UK. As we [updated in December](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/ico-action-secures-increased-cookie-compliance/), our action has seen significant changes. It has lowered the prevalence of cookies being placed before a user has expressed their choice and has driven an increase of clear reject options on consent banners, making it easier for users to control how they are tracked.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Next month, we will be publishing our advice to government on where PECR requirements to obtain consent for the use of storage and access technologies for online advertising purposes could be removed. We understand that the government is exploring whether to create an exception or exceptions for some online advertising purposes, using secondary regulation-making powers under regulation 6A of PECR. This work will help inform government policy–making.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Last year, we opened a call for views on our review of regulation 6 PECR where the use of storage and access technologies for advertising may pose demonstrably low privacy risks.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/online-tracking-strategy/online-tracking-strategy-update-april-2026/</guid>
      <pubDate>Sun, 03 May 2026 12:49:03 +0000</pubDate>
    <ns23:tag xmlns:ns23="https://concatena.co.uk/feed/1.0">ad-tech</ns23:tag><ns24:tag xmlns:ns24="https://concatena.co.uk/feed/1.0">cat:law</ns24:tag><ns25:tag xmlns:ns25="https://concatena.co.uk/feed/1.0">consent-mechanisms</ns25:tag><ns26:tag xmlns:ns26="https://concatena.co.uk/feed/1.0">consent-or-pay</ns26:tag><ns27:tag xmlns:ns27="https://concatena.co.uk/feed/1.0">cookies</ns27:tag><ns28:tag xmlns:ns28="https://concatena.co.uk/feed/1.0">online-privacy</ns28:tag><ns29:tag xmlns:ns29="https://concatena.co.uk/feed/1.0">pecr</ns29:tag><ns30:tag xmlns:ns30="https://concatena.co.uk/feed/1.0">sats</ns30:tag><ns31:tag xmlns:ns31="https://concatena.co.uk/feed/1.0">storage-and-access-technologies</ns31:tag><ns32:tag xmlns:ns32="https://concatena.co.uk/feed/1.0">surveillance</ns32:tag><ns33:note xmlns:ns33="https://concatena.co.uk/feed/1.0">Our Take: We’ve commented on the SATs guidance in a separate post, but this wider summary from the ICO is worth a read too. I still don’t love the focus on consent for “cookies/SATs” (and don’t even get me started on consent-or-pay) - I don’t see how the average user can possibly understand the network that lies behind that little button - but that’s the legal landscape were in.

Your Takeaway: As with the SAT guidance, there’s nothing requiring action here yet (unless you didn’t check your cookie banner compliance last year… in which case, I’d recommend a look now). Still, some ongoing discussions here it’s worth keeping on top of - and contributing to as well.</ns33:note><ns34:highlight xmlns:ns34="https://concatena.co.uk/feed/1.0">After careful consideration and review of our concerns, we concluded that further action would not be appropriate after observing positive improvements from the platforms as compared to their historical processing practices. This was communicated to the platforms in January of this year.</ns34:highlight><ns35:highlight xmlns:ns35="https://concatena.co.uk/feed/1.0">We assessed key areas of concern, including: the validity of consent for the data processing carried out by these platforms and their lawful basis relied upon for processing.</ns35:highlight><ns36:highlight xmlns:ns36="https://concatena.co.uk/feed/1.0">We have driven improvements in the standard products offered to website owners by working directly with key cookie banner vendors responsible for the largest market shares across the UK's most popular websites. For example, OneTrust and Usercentrics have developed UK-specific templates aligned with our guidance. This is in addition to a range of other improvements made by these platforms and changes implemented by Sourcepoint and Inmobi to enhance their existing templates and guidance. This engagement has raised the bar across a significant portion of the market and made it easier for online businesses to offer fair, compliant choices to users.</ns36:highlight><ns37:highlight xmlns:ns37="https://concatena.co.uk/feed/1.0">We committed to reviewing cookie banners on the top 1,000 websites in the UK. As we [updated in December](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/ico-action-secures-increased-cookie-compliance/), our action has seen significant changes. It has lowered the prevalence of cookies being placed before a user has expressed their choice and has driven an increase of clear reject options on consent banners, making it easier for users to control how they are tracked.</ns37:highlight><ns38:highlight xmlns:ns38="https://concatena.co.uk/feed/1.0">Next month, we will be publishing our advice to government on where PECR requirements to obtain consent for the use of storage and access technologies for online advertising purposes could be removed. We understand that the government is exploring whether to create an exception or exceptions for some online advertising purposes, using secondary regulation-making powers under regulation 6A of PECR. This work will help inform government policy–making.</ns38:highlight><ns39:highlight xmlns:ns39="https://concatena.co.uk/feed/1.0">Last year, we opened a call for views on our review of regulation 6 PECR where the use of storage and access technologies for advertising may pose demonstrably low privacy risks.</ns39:highlight></item>
    <item>
      <title>Adobe's legal chief calls for creator protection as policymakers and tech companies reframe copyright in the era of AI</title>
      <link>https://www.techradar.com/pro/adobes-legal-chief-calls-for-creator-protection-as-policymakers-and-tech-companies-reframe-copyright-in-the-era-of-ai</link>
      <description>While the world establishes copyright for AI-generated assets, Adobe's legal chief calls for greater creator protection and asset verification.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Craig Hale&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.techradar.com/pro/adobes-legal-chief-calls-for-creator-protection-as-policymakers-and-tech-companies-reframe-copyright-in-the-era-of-ai"&gt;https://www.techradar.com/pro/adobes-legal-chief-calls-for-creator-protection-as-policymakers-and-tech-companies-reframe-copyright-in-the-era-of-ai&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;ai-detecting&lt;/span&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;copyright&lt;/span&gt; &lt;span class="tag"&gt;creativity&lt;/span&gt; &lt;span class="tag"&gt;creators&lt;/span&gt; &lt;span class="tag"&gt;global&lt;/span&gt; &lt;span class="tag"&gt;intellectual-property&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;While the world establishes copyright for AI-generated assets, Adobe's legal chief calls for greater creator protection and asset verification.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Adobe's legal chief urges a pragmatic path for AI regulation - don't tear up copyright law but clarify it and protect creators whose work fuels AI. I hate to say it, but I agree - let’s focus on the fundamentals, but importantly let’s also think about whether the means for enforcing individual contributors rights is accessible in this new world, and if not, whether there ought to be a supportive regime which regulates bad actors.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; IP is always something to keep an eye on. The article talks about creator protections and provenance tools, and they are worth looking at and understanding; but it’s unclear how much control they truly give. Make sure you’re not cutting corners in your own IP compliance with third party materials at the same time as protecting your output.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;The difficulty at the moment is that regions like the US, EU and UK are pushing their own goals. &amp;quot;It's a fallacy to think there would be a universal standard that would apply globally,&amp;quot; Pentland said. &amp;quot;but we can dream.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;When asked about watermarking, Pentland rejected visible marks as the default solution, favoring options like metadata or QR-style verification to preserve the integrity of an artist's work.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;To date, the 'Big Five' camera makers ([Fujifilm](https://www.techradar.com/tag/fujifilm), [Sony](https://www.techradar.com/tag/sony), [Canon](https://www.techradar.com/tag/canon), Nikon and Leica) and some Android manufacturers ([Google](https://www.techradar.com/tag/google) Pixel and [Samsung](https://www.techradar.com/tag/samsung) Galaxy) have implemented Content Credentials, as have a number of popular platforms like LinkedIn, [YouTube](https://www.techradar.com/tag/youtube), Meta and TikTok.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Adobe sees this type of verification protecting consumers against threats like deepfakes, enabling users to verify authenticity.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;For Adobe, this means pushing Content Credentials, which the company [describes](https://www.prf.hn/click/camref:1101lr4vm/pubref:trdpro-us-9929404428972030695/destination:https%3A%2F%2Fhelpx.adobe.com%2Fuk%2Fcreative-cloud%2Fapps%2Fadobe-content-authenticity%2Fcontent-credentials%2Foverview.html) separately as &amp;quot;a durable, industry-standard metadata type that acts like a digital nutrition label for content,&amp;quot; in a bid to create verifiable content trails.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;In 2025, the US Copyright Office granted protection to an image that was created with AI assistance, making this the first time anyone has ever been granted copyright protection for AI-generated work.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;We don't want it to stifle innovation,&amp;quot; she said, &amp;quot;but at the same time, we can't leave it completely unchecked.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;At the same time, Pentland also advocated for tech companies to get involved – not to redefine copyright law, but to maintain authenticity and protect creators in this era of AI assistance.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Speaking with *TechRadar Pro* in an exclusive interview at [Adobe Summit 2026](https://www.techradar.com/pro/live/adobe-summit-2026), the company's Chief Legal Officer, Louise Pentland, urged policymakers to resist radical changes, and for courts and companies instead to focus on a more pragmatic approach.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.techradar.com/pro/adobes-legal-chief-calls-for-creator-protection-as-policymakers-and-tech-companies-reframe-copyright-in-the-era-of-ai</guid>
      <pubDate>Sun, 03 May 2026 12:21:25 +0000</pubDate>
    <ns40:tag xmlns:ns40="https://concatena.co.uk/feed/1.0">ai-detecting</ns40:tag><ns41:tag xmlns:ns41="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns41:tag><ns42:tag xmlns:ns42="https://concatena.co.uk/feed/1.0">cat:law</ns42:tag><ns43:tag xmlns:ns43="https://concatena.co.uk/feed/1.0">copyright</ns43:tag><ns44:tag xmlns:ns44="https://concatena.co.uk/feed/1.0">creativity</ns44:tag><ns45:tag xmlns:ns45="https://concatena.co.uk/feed/1.0">creators</ns45:tag><ns46:tag xmlns:ns46="https://concatena.co.uk/feed/1.0">global</ns46:tag><ns47:tag xmlns:ns47="https://concatena.co.uk/feed/1.0">intellectual-property</ns47:tag><ns48:note xmlns:ns48="https://concatena.co.uk/feed/1.0">Our Take: Adobe's legal chief urges a pragmatic path for AI regulation - don't tear up copyright law but clarify it and protect creators whose work fuels AI. I hate to say it, but I agree - let’s focus on the fundamentals, but importantly let’s also think about whether the means for enforcing individual contributors rights is accessible in this new world, and if not, whether there ought to be a supportive regime which regulates bad actors.

Your Takeaway: IP is always something to keep an eye on. The article talks about creator protections and provenance tools, and they are worth looking at and understanding; but it’s unclear how much control they truly give. Make sure you’re not cutting corners in your own IP compliance with third party materials at the same time as protecting your output.</ns48:note><ns49:highlight xmlns:ns49="https://concatena.co.uk/feed/1.0">The difficulty at the moment is that regions like the US, EU and UK are pushing their own goals. "It's a fallacy to think there would be a universal standard that would apply globally," Pentland said. "but we can dream."</ns49:highlight><ns50:highlight xmlns:ns50="https://concatena.co.uk/feed/1.0">When asked about watermarking, Pentland rejected visible marks as the default solution, favoring options like metadata or QR-style verification to preserve the integrity of an artist's work.</ns50:highlight><ns51:highlight xmlns:ns51="https://concatena.co.uk/feed/1.0">To date, the 'Big Five' camera makers ([Fujifilm](https://www.techradar.com/tag/fujifilm), [Sony](https://www.techradar.com/tag/sony), [Canon](https://www.techradar.com/tag/canon), Nikon and Leica) and some Android manufacturers ([Google](https://www.techradar.com/tag/google) Pixel and [Samsung](https://www.techradar.com/tag/samsung) Galaxy) have implemented Content Credentials, as have a number of popular platforms like LinkedIn, [YouTube](https://www.techradar.com/tag/youtube), Meta and TikTok.</ns51:highlight><ns52:highlight xmlns:ns52="https://concatena.co.uk/feed/1.0">Adobe sees this type of verification protecting consumers against threats like deepfakes, enabling users to verify authenticity.</ns52:highlight><ns53:highlight xmlns:ns53="https://concatena.co.uk/feed/1.0">For Adobe, this means pushing Content Credentials, which the company [describes](https://www.prf.hn/click/camref:1101lr4vm/pubref:trdpro-us-9929404428972030695/destination:https%3A%2F%2Fhelpx.adobe.com%2Fuk%2Fcreative-cloud%2Fapps%2Fadobe-content-authenticity%2Fcontent-credentials%2Foverview.html) separately as "a durable, industry-standard metadata type that acts like a digital nutrition label for content," in a bid to create verifiable content trails.</ns53:highlight><ns54:highlight xmlns:ns54="https://concatena.co.uk/feed/1.0">In 2025, the US Copyright Office granted protection to an image that was created with AI assistance, making this the first time anyone has ever been granted copyright protection for AI-generated work.</ns54:highlight><ns55:highlight xmlns:ns55="https://concatena.co.uk/feed/1.0">"We don't want it to stifle innovation," she said, "but at the same time, we can't leave it completely unchecked."</ns55:highlight><ns56:highlight xmlns:ns56="https://concatena.co.uk/feed/1.0">At the same time, Pentland also advocated for tech companies to get involved – not to redefine copyright law, but to maintain authenticity and protect creators in this era of AI assistance.</ns56:highlight><ns57:highlight xmlns:ns57="https://concatena.co.uk/feed/1.0">Speaking with *TechRadar Pro* in an exclusive interview at [Adobe Summit 2026](https://www.techradar.com/pro/live/adobe-summit-2026), the company's Chief Legal Officer, Louise Pentland, urged policymakers to resist radical changes, and for courts and companies instead to focus on a more pragmatic approach.</ns57:highlight></item>
    <item>
      <title>Will human minds still be special in an age of AI?</title>
      <link>https://www.theguardian.com/books/2026/may/03/will-human-minds-still-be-special-in-an-age-of-ai</link>
      <description>Human intelligence is shaped by our limits, like short lives and simple communication, which makes us special. AI can do many tasks but works differently and faces other challenges. Instead of rivals, humans and AI should be seen as different minds with unique strengths.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Tom Griffiths&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.theguardian.com/books/2026/may/03/will-human-minds-still-be-special-in-an-age-of-ai"&gt;https://www.theguardian.com/books/2026/may/03/will-human-minds-still-be-special-in-an-age-of-ai&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:human&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;ethics&lt;/span&gt; &lt;span class="tag"&gt;human-in-the-loop&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Human intelligence is shaped by our limits, like short lives and simple communication, which makes us special. AI can do many tasks but works differently and faces other challenges. Instead of rivals, humans and AI should be seen as different minds with unique strengths.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; This article argues that AI isn’t a single linear upgrade on human minds - it’s a different kind of intelligence shaped by different limits and experiences, so claims that machines will simply “overtake” us are misleading. I think there’s another point here too - we remove an important experience and learning opportunity from humans when we automate everything. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; When evaluating or deploying AI, focus on the problem you’re trying to solve, and whether it’s one which can be helped by automation and customisation from a LLM, and what the extent of that help should be. Design your processes to make sure that you’re putting humans at the right point of the journey - not just as a box tick exercise at the end, but actually contributing to the process, supported, where appropriate, by these tools.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;This isn’t the only place where AI runs into difficulties. Imagine you are assisting a pharmacist. They need a drug with a concentration of 785 parts per million (ppm). Two test tubes are available: one containing 685 ppm and the other 791 ppm. Your task is to determine which test tube provides the most similar concentration to your required dosage. Hopefully you would pick 791 ppm. However, [some of the time](https://arxiv.org/abs/2502.01540) even leading AI systems pick 685 ppm. Why? Because the artificial neural networks used to build AI systems tend to blur things together. When there are two possible answers, they choose something in between. The number 785 can be represented as either a string of digits (“7”, “8”, and “5”) or as a quantity (seven-hundred-and-eighty-five). If it is a string, 785 is more similar to 685 – they are just one digit apart. But if it is a quantity, then it is more similar to 791. Mixing up these two answers can have significant consequences.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Here’s a simple example. How many letters are in this sequence: aaaaaaaaaaaaaaaaaaaaaaaaaaaaa? For a human, it’s not particularly difficult to answer – you can just count them up. For an AI system, it’s trickier. They are constrained by how they represent language and how they are trained. They like to break up words into parts (called “tokens”), which can make it hard for them to answer questions about spelling. And they tend to favour sequences of tokens that appear more often in their training data as answers. We [found](https://www.pnas.org/doi/10.1073/pnas.2322420121) that OpenAI’s GPT-4 model, which was hailed as showing “[sparks of artificial general intelligence](https://arxiv.org/abs/2303.12712)”, was more likely to correctly answer this question when given 30 letters rather than 29. Why? Because the number 30 is written down more often than the number 29.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Human intelligence is [a response to our limitations](https://www.sciencedirect.com/science/article/abs/pii/S1364661320302151). To make the most of our lives, we have an amazing ability to learn from limited experience. Yes, AlphaGo can beat the best human go players, but it was trained on many human lifetimes of games. Yes, ChatGPT can hold a reasonable conversation, but it’s drawing on thousands of years of language. No AI system can produce sentences with the creativity of a human five-year-old when exposed to the same amount of data.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;AI systems face none of these constraints. They can process more data than any human might see in a lifetime. They can expand their capacity by using more computers. And they can easily share what they see and learn with other machines.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Humans are no different. Our minds have been shaped by our biology. We only live for a few decades and have to learn everything we are going to learn and do everything we are going to do in that short time. All that learning and doing will be carried out at the direction of a kilogram or so of neurons trapped inside our bony skulls. We can only share our thoughts with others by making noises with our mouths or tapping and wiggling our fingers.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.theguardian.com/books/2026/may/03/will-human-minds-still-be-special-in-an-age-of-ai</guid>
      <pubDate>Sun, 03 May 2026 12:15:25 +0000</pubDate>
    <ns58:tag xmlns:ns58="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns58:tag><ns59:tag xmlns:ns59="https://concatena.co.uk/feed/1.0">cat:human</ns59:tag><ns60:tag xmlns:ns60="https://concatena.co.uk/feed/1.0">cat:tech</ns60:tag><ns61:tag xmlns:ns61="https://concatena.co.uk/feed/1.0">ethics</ns61:tag><ns62:tag xmlns:ns62="https://concatena.co.uk/feed/1.0">human-in-the-loop</ns62:tag><ns63:note xmlns:ns63="https://concatena.co.uk/feed/1.0">Our Take: This article argues that AI isn’t a single linear upgrade on human minds - it’s a different kind of intelligence shaped by different limits and experiences, so claims that machines will simply “overtake” us are misleading. I think there’s another point here too - we remove an important experience and learning opportunity from humans when we automate everything. 

Your Takeaway: When evaluating or deploying AI, focus on the problem you’re trying to solve, and whether it’s one which can be helped by automation and customisation from a LLM, and what the extent of that help should be. Design your processes to make sure that you’re putting humans at the right point of the journey - not just as a box tick exercise at the end, but actually contributing to the process, supported, where appropriate, by these tools.</ns63:note><ns64:highlight xmlns:ns64="https://concatena.co.uk/feed/1.0">This isn’t the only place where AI runs into difficulties. Imagine you are assisting a pharmacist. They need a drug with a concentration of 785 parts per million (ppm). Two test tubes are available: one containing 685 ppm and the other 791 ppm. Your task is to determine which test tube provides the most similar concentration to your required dosage. Hopefully you would pick 791 ppm. However, [some of the time](https://arxiv.org/abs/2502.01540) even leading AI systems pick 685 ppm. Why? Because the artificial neural networks used to build AI systems tend to blur things together. When there are two possible answers, they choose something in between. The number 785 can be represented as either a string of digits (“7”, “8”, and “5”) or as a quantity (seven-hundred-and-eighty-five). If it is a string, 785 is more similar to 685 – they are just one digit apart. But if it is a quantity, then it is more similar to 791. Mixing up these two answers can have significant consequences.</ns64:highlight><ns65:highlight xmlns:ns65="https://concatena.co.uk/feed/1.0">Here’s a simple example. How many letters are in this sequence: aaaaaaaaaaaaaaaaaaaaaaaaaaaaa? For a human, it’s not particularly difficult to answer – you can just count them up. For an AI system, it’s trickier. They are constrained by how they represent language and how they are trained. They like to break up words into parts (called “tokens”), which can make it hard for them to answer questions about spelling. And they tend to favour sequences of tokens that appear more often in their training data as answers. We [found](https://www.pnas.org/doi/10.1073/pnas.2322420121) that OpenAI’s GPT-4 model, which was hailed as showing “[sparks of artificial general intelligence](https://arxiv.org/abs/2303.12712)”, was more likely to correctly answer this question when given 30 letters rather than 29. Why? Because the number 30 is written down more often than the number 29.</ns65:highlight><ns66:highlight xmlns:ns66="https://concatena.co.uk/feed/1.0">Human intelligence is [a response to our limitations](https://www.sciencedirect.com/science/article/abs/pii/S1364661320302151). To make the most of our lives, we have an amazing ability to learn from limited experience. Yes, AlphaGo can beat the best human go players, but it was trained on many human lifetimes of games. Yes, ChatGPT can hold a reasonable conversation, but it’s drawing on thousands of years of language. No AI system can produce sentences with the creativity of a human five-year-old when exposed to the same amount of data.</ns66:highlight><ns67:highlight xmlns:ns67="https://concatena.co.uk/feed/1.0">AI systems face none of these constraints. They can process more data than any human might see in a lifetime. They can expand their capacity by using more computers. And they can easily share what they see and learn with other machines.</ns67:highlight><ns68:highlight xmlns:ns68="https://concatena.co.uk/feed/1.0">Humans are no different. Our minds have been shaped by our biology. We only live for a few decades and have to learn everything we are going to learn and do everything we are going to do in that short time. All that learning and doing will be carried out at the direction of a kilogram or so of neurons trapped inside our bony skulls. We can only share our thoughts with others by making noises with our mouths or tapping and wiggling our fingers.</ns68:highlight></item>
    <item>
      <title>English councils to trial Google AI tool to speed up planning decisions</title>
      <link>https://www.ft.com/content/91ce4475-d325-4d65-babb-4214996bc0f6</link>
      <description>English councils will start using a new AI tool from Google to help speed up building project decisions. The AI will give recommendations, but humans will make the final call. The government hopes this will make planning faster and support building more homes.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Chris Smyth&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.ft.com/content/91ce4475-d325-4d65-babb-4214996bc0f6"&gt;https://www.ft.com/content/91ce4475-d325-4d65-babb-4214996bc0f6&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;future-of-work&lt;/span&gt; &lt;span class="tag"&gt;human-in-the-loop&lt;/span&gt; &lt;span class="tag"&gt;public-sector&lt;/span&gt; &lt;span class="tag"&gt;training&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;English councils will start using a new AI tool from Google to help speed up building project decisions. The AI will give recommendations, but humans will make the final call. The government hopes this will make planning faster and support building more homes.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Using AI to generate efficiencies could really support public services to get more done, and to be more consistent. Human in the loop is vital - but you need to ensure that those humans are empowered to really BE in that loop and to contradict the machine. “Computer says no” can be very difficult to pass over...&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; Make sure that any humans in the loop using LLM powered systems have appropriate training and understanding of their outputs, so that system can support *their* critical thinking, not outsource it.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Under the programme, humans will make the final decisions with AI providing a recommendation. For more complex applications, the AI tool will probably give officials a framework for decisions rather than a definitive answer.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;“There is a risk that in the push to harness efficiencies and insights, planning’s decision-making systems are redesigned to work well with AI, and not for optimal outcomes. There’s no value in processing applications more quickly if the developments that follow are low quality.”&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Recommendations on whether to grant or refuse building projects will be generated using a custom [AI](https://www.ft.com/artificial-intelligence ) system — the Augmented Planning Decision Tool — before being signed off by council officers.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Planning decisions in England will for the first time be made with the help of Google-built AI starting this month, in a pilot ministers say will speed up approvals.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.ft.com/content/91ce4475-d325-4d65-babb-4214996bc0f6</guid>
      <pubDate>Sat, 02 May 2026 12:43:52 +0000</pubDate>
    <ns69:tag xmlns:ns69="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns69:tag><ns70:tag xmlns:ns70="https://concatena.co.uk/feed/1.0">cat:law</ns70:tag><ns71:tag xmlns:ns71="https://concatena.co.uk/feed/1.0">cat:tech</ns71:tag><ns72:tag xmlns:ns72="https://concatena.co.uk/feed/1.0">future-of-work</ns72:tag><ns73:tag xmlns:ns73="https://concatena.co.uk/feed/1.0">human-in-the-loop</ns73:tag><ns74:tag xmlns:ns74="https://concatena.co.uk/feed/1.0">public-sector</ns74:tag><ns75:tag xmlns:ns75="https://concatena.co.uk/feed/1.0">training</ns75:tag><ns76:note xmlns:ns76="https://concatena.co.uk/feed/1.0">Our Take: Using AI to generate efficiencies could really support public services to get more done, and to be more consistent. Human in the loop is vital - but you need to ensure that those humans are empowered to really BE in that loop and to contradict the machine. “Computer says no” can be very difficult to pass over...

Your Takeaway: Make sure that any humans in the loop using LLM powered systems have appropriate training and understanding of their outputs, so that system can support *their* critical thinking, not outsource it.</ns76:note><ns77:highlight xmlns:ns77="https://concatena.co.uk/feed/1.0">Under the programme, humans will make the final decisions with AI providing a recommendation. For more complex applications, the AI tool will probably give officials a framework for decisions rather than a definitive answer.</ns77:highlight><ns78:highlight xmlns:ns78="https://concatena.co.uk/feed/1.0">“There is a risk that in the push to harness efficiencies and insights, planning’s decision-making systems are redesigned to work well with AI, and not for optimal outcomes. There’s no value in processing applications more quickly if the developments that follow are low quality.”</ns78:highlight><ns79:highlight xmlns:ns79="https://concatena.co.uk/feed/1.0">Recommendations on whether to grant or refuse building projects will be generated using a custom [AI](https://www.ft.com/artificial-intelligence ) system — the Augmented Planning Decision Tool — before being signed off by council officers.</ns79:highlight><ns80:highlight xmlns:ns80="https://concatena.co.uk/feed/1.0">Planning decisions in England will for the first time be made with the help of Google-built AI starting this month, in a pilot ministers say will speed up approvals.</ns80:highlight></item>
    <item>
      <title>Mathematicians Claim Significant Discovery Using ChatGPT</title>
      <link>https://futurism.com/artificial-intelligence/mathematicians-claim-significant-discovery-using-chatgpt</link>
      <description>A young man named Liam Price used ChatGPT to solve a difficult math problem that had puzzled experts for over 60 years. Experts say the AI found a new way to approach the problem, but humans had to fix its mistakes. This breakthrough shows AI might help solve tough math questions, but caution is still needed.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Frank Landymore&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://futurism.com/artificial-intelligence/mathematicians-claim-significant-discovery-using-chatgpt"&gt;https://futurism.com/artificial-intelligence/mathematicians-claim-significant-discovery-using-chatgpt&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;llm&lt;/span&gt; &lt;span class="tag"&gt;maths&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;A young man named Liam Price used ChatGPT to solve a difficult math problem that had puzzled experts for over 60 years. Experts say the AI found a new way to approach the problem, but humans had to fix its mistakes. This breakthrough shows AI might help solve tough math questions, but caution is still needed.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Sounds amazing. But then I also remember this: https://www.psychologytoday.com/gb/blog/understanding-suicide/202511/chatgpt-made-him-delusional&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; LLMs can do amazing things. They can also do dumb things. And even the amazing things need your help.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;“The raw output of ChatGPT’s proof was actually quite poor. So it required an expert to kind of sift through and actually understand what it was trying to say,” Jared Lichtman, a mathematician at Stanford University whose doctoral thesis centered on one Erdős’s conjectures, told *SciAm*.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Still, it required humans to apply the finishing touches.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Earlier this month, 23-year-old Liam Price shared a solution to one of the so-called Erdős problems, a series of famously abstruse math conjectures left behind by the Hungarian mathematician Paul Erdős. While some of these conjectures have gotten the better of savants in the field, Price, who has no advanced math degree, seemingly stumbled on a solution for one of them by simply prompting GPT-5.4 for an answer.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Did ChatGPT just solve an arcane math problem that’s foiled mathematicians for over sixty years? Some leading experts say yes, [*Scientific American* reports](https://www.scientificamerican.com/article/amateur-armed-with-chatgpt-vibe-maths-a-60-year-old-problem/).&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://futurism.com/artificial-intelligence/mathematicians-claim-significant-discovery-using-chatgpt</guid>
      <pubDate>Sat, 02 May 2026 12:42:42 +0000</pubDate>
    <ns81:tag xmlns:ns81="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns81:tag><ns82:tag xmlns:ns82="https://concatena.co.uk/feed/1.0">cat:tech</ns82:tag><ns83:tag xmlns:ns83="https://concatena.co.uk/feed/1.0">llm</ns83:tag><ns84:tag xmlns:ns84="https://concatena.co.uk/feed/1.0">maths</ns84:tag><ns85:note xmlns:ns85="https://concatena.co.uk/feed/1.0">Our Take: Sounds amazing. But then I also remember this: https://www.psychologytoday.com/gb/blog/understanding-suicide/202511/chatgpt-made-him-delusional

Your Takeaway: LLMs can do amazing things. They can also do dumb things. And even the amazing things need your help.</ns85:note><ns86:highlight xmlns:ns86="https://concatena.co.uk/feed/1.0">“The raw output of ChatGPT’s proof was actually quite poor. So it required an expert to kind of sift through and actually understand what it was trying to say,” Jared Lichtman, a mathematician at Stanford University whose doctoral thesis centered on one Erdős’s conjectures, told *SciAm*.</ns86:highlight><ns87:highlight xmlns:ns87="https://concatena.co.uk/feed/1.0">Still, it required humans to apply the finishing touches.</ns87:highlight><ns88:highlight xmlns:ns88="https://concatena.co.uk/feed/1.0">Earlier this month, 23-year-old Liam Price shared a solution to one of the so-called Erdős problems, a series of famously abstruse math conjectures left behind by the Hungarian mathematician Paul Erdős. While some of these conjectures have gotten the better of savants in the field, Price, who has no advanced math degree, seemingly stumbled on a solution for one of them by simply prompting GPT-5.4 for an answer.</ns88:highlight><ns89:highlight xmlns:ns89="https://concatena.co.uk/feed/1.0">Did ChatGPT just solve an arcane math problem that’s foiled mathematicians for over sixty years? Some leading experts say yes, [*Scientific American* reports](https://www.scientificamerican.com/article/amateur-armed-with-chatgpt-vibe-maths-a-60-year-old-problem/).</ns89:highlight></item>
    <item>
      <title>Usage-based pricing killing your vibe - here's how to roll your own local AI coding agents</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2026/05/02/local_ai_coding_agents/</link>
      <description>Usage-based pricing for AI coding tools is becoming expensive and restrictive. This article shows how to run local AI coding agents like Claude Code, Pi Coding Agent, and Cline to avoid those costs. Local models work well for small projects but may need human approval to avoid mistakes.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Tobias Mann and Thomas Claburn&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://go.theregister.com/feed/www.theregister.com/2026/05/02/local_ai_coding_agents/"&gt;https://go.theregister.com/feed/www.theregister.com/2026/05/02/local_ai_coding_agents/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;charging-models&lt;/span&gt; &lt;span class="tag"&gt;commercial&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Usage-based pricing for AI coding tools is becoming expensive and restrictive. This article shows how to run local AI coding agents like Claude Code, Pi Coding Agent, and Cline to avoid those costs. Local models work well for small projects but may need human approval to avoid mistakes.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; I’m not necessarily encouraging you to rolll your own here, but it is worth being aware of this business model change - and the fact that from the get-go the definition of a token as a metric has been less than clear and open. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt;  If you’re reliant on third party LLMs, remember to account for the risk of them changing their measurement metrics and charging - it’s been on the cards for a while.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Over the past few weeks, we've seen Anthropic toy with [dropping](https://www.theregister.com/2026/04/22/anthropic_removes_claude_code_pro/) Claude Code from its most affordable plans while Microsoft has skipped testing the waters and moved GitHub Copilot to a purely [usage-based model](https://www.theregister.com/2026/04/28/microsofts_github_shifts_to_metered/). The whole debacle got us thinking. Do we even need Anthropic or OpenAI's top models, or can we get away with a smaller local model? Sure, it might be slower, less capable, and a little more frustrating to work with, but you can't beat the price of free... Well, assuming you've already got the hardware that is.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://go.theregister.com/feed/www.theregister.com/2026/05/02/local_ai_coding_agents/</guid>
      <pubDate>Sat, 02 May 2026 12:35:16 +0000</pubDate>
    <ns90:tag xmlns:ns90="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns90:tag><ns91:tag xmlns:ns91="https://concatena.co.uk/feed/1.0">cat:bus</ns91:tag><ns92:tag xmlns:ns92="https://concatena.co.uk/feed/1.0">cat:tech</ns92:tag><ns93:tag xmlns:ns93="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns93:tag><ns94:tag xmlns:ns94="https://concatena.co.uk/feed/1.0">charging-models</ns94:tag><ns95:tag xmlns:ns95="https://concatena.co.uk/feed/1.0">commercial</ns95:tag><ns96:note xmlns:ns96="https://concatena.co.uk/feed/1.0">Our Take: I’m not necessarily encouraging you to rolll your own here, but it is worth being aware of this business model change - and the fact that from the get-go the definition of a token as a metric has been less than clear and open. 

Your Takeaway:  If you’re reliant on third party LLMs, remember to account for the risk of them changing their measurement metrics and charging - it’s been on the cards for a while.</ns96:note><ns97:highlight xmlns:ns97="https://concatena.co.uk/feed/1.0">Over the past few weeks, we've seen Anthropic toy with [dropping](https://www.theregister.com/2026/04/22/anthropic_removes_claude_code_pro/) Claude Code from its most affordable plans while Microsoft has skipped testing the waters and moved GitHub Copilot to a purely [usage-based model](https://www.theregister.com/2026/04/28/microsofts_github_shifts_to_metered/). The whole debacle got us thinking. Do we even need Anthropic or OpenAI's top models, or can we get away with a smaller local model? Sure, it might be slower, less capable, and a little more frustrating to work with, but you can't beat the price of free... Well, assuming you've already got the hardware that is.</ns97:highlight></item>
    <item>
      <title>EU and UK competition rules updated around tech licensing</title>
      <link>https://www.pinsentmasons.com/Out-Law/Analysis/EU-UK-competition-rules-updated-tech-licensing?utm_source=PM+website&amp;utm_medium=feed&amp;utm_campaign=RSS+Outlaw</link>
      <description>New competition rules governing technology licensing agreements have now taken effect in both the EU and UK.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Out-Law from Pinsent Masons&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.pinsentmasons.com/Out-Law/Analysis/EU-UK-competition-rules-updated-tech-licensing?utm_source=PM+website&amp;amp;utm_medium=feed&amp;amp;utm_campaign=RSS+Outlaw"&gt;https://www.pinsentmasons.com/Out-Law/Analysis/EU-UK-competition-rules-updated-tech-licensing?utm_source=PM+website&amp;amp;utm_medium=feed&amp;amp;utm_campaign=RSS+Outlaw&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;block-exemptions&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;competition&lt;/span&gt; &lt;span class="tag"&gt;data-licensing&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;New competition rules governing technology licensing agreements have now taken effect in both the EU and UK.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; I’ll be honest, I’ve not fully digested this. Competition law takes a lot of brain power. But I do want to dig some more into the new data licensing elements when I get the chance - I think this is where regulators need to be really thoughtful.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; Depends on who you are - commercial lawyers, make sure you have at least an understanding of these changes. Small businesses, you can probably scroll on by!&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;The provisions of the new the UK TTBEO are for the most part in alignment with those of the TTBER&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Data licensing agreements are increasingly common, but they were not covered under the 2014 TTBER and guidelines.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;New guidelines on data licensing&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Clearer market share thresholds&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;A one-year transitional period, until 30 April 2027, applies under both the EU and UK regimes for existing technology transfer agreements that comply with the old TTBER requirements but not the new rules. New technology transfer agreements implemented from today must immediately comply with the new rules.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;In the UK, a new [Technology Transfer Agreements Block Exemption Order](https://www.legislation.gov.uk/uksi/2026/369/made) (TTBEO) – which was subject to separate review and consultation by the UK government and the Competition and Markets Authority (CMA) – also enters into force today, 1 May. The TTBEO replaces the 2014 TTBER which was “assimilated” into UK national law following Brexit. The CMA is currently consulting on [draft new guidance for the UK TTBEO regime](https://www.gov.uk/government/consultations/application-of-the-chapter-i-prohibition-in-the-competition-act-1998-to-technology-transfer-agreements).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;In the EU, a revised [Technology Transfer Block Exemption Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202600877) (TTBER) and revised [Technology Transfer Guidelines](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_809) (‘the guidelines’) enter into force today, 1 May. The revisions, which replace the 2014 versions, follow a four-year review by the European Commission into the functioning of the 2014 TTBER and related guidelines and aim to address concerns raised from a wide range of stakeholders.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.pinsentmasons.com/Out-Law/Analysis/EU-UK-competition-rules-updated-tech-licensing?utm_source=PM+website&amp;utm_medium=feed&amp;utm_campaign=RSS+Outlaw</guid>
      <pubDate>Sat, 02 May 2026 12:32:15 +0000</pubDate>
    <ns98:tag xmlns:ns98="https://concatena.co.uk/feed/1.0">block-exemptions</ns98:tag><ns99:tag xmlns:ns99="https://concatena.co.uk/feed/1.0">cat:law</ns99:tag><ns100:tag xmlns:ns100="https://concatena.co.uk/feed/1.0">competition</ns100:tag><ns101:tag xmlns:ns101="https://concatena.co.uk/feed/1.0">data-licensing</ns101:tag><ns102:note xmlns:ns102="https://concatena.co.uk/feed/1.0">Our Take: I’ll be honest, I’ve not fully digested this. Competition law takes a lot of brain power. But I do want to dig some more into the new data licensing elements when I get the chance - I think this is where regulators need to be really thoughtful.

Your Takeaway: Depends on who you are - commercial lawyers, make sure you have at least an understanding of these changes. Small businesses, you can probably scroll on by!</ns102:note><ns103:highlight xmlns:ns103="https://concatena.co.uk/feed/1.0">The provisions of the new the UK TTBEO are for the most part in alignment with those of the TTBER</ns103:highlight><ns104:highlight xmlns:ns104="https://concatena.co.uk/feed/1.0">Data licensing agreements are increasingly common, but they were not covered under the 2014 TTBER and guidelines.</ns104:highlight><ns105:highlight xmlns:ns105="https://concatena.co.uk/feed/1.0">New guidelines on data licensing</ns105:highlight><ns106:highlight xmlns:ns106="https://concatena.co.uk/feed/1.0">Clearer market share thresholds</ns106:highlight><ns107:highlight xmlns:ns107="https://concatena.co.uk/feed/1.0">A one-year transitional period, until 30 April 2027, applies under both the EU and UK regimes for existing technology transfer agreements that comply with the old TTBER requirements but not the new rules. New technology transfer agreements implemented from today must immediately comply with the new rules.</ns107:highlight><ns108:highlight xmlns:ns108="https://concatena.co.uk/feed/1.0">In the UK, a new [Technology Transfer Agreements Block Exemption Order](https://www.legislation.gov.uk/uksi/2026/369/made) (TTBEO) – which was subject to separate review and consultation by the UK government and the Competition and Markets Authority (CMA) – also enters into force today, 1 May. The TTBEO replaces the 2014 TTBER which was “assimilated” into UK national law following Brexit. The CMA is currently consulting on [draft new guidance for the UK TTBEO regime](https://www.gov.uk/government/consultations/application-of-the-chapter-i-prohibition-in-the-competition-act-1998-to-technology-transfer-agreements).</ns108:highlight><ns109:highlight xmlns:ns109="https://concatena.co.uk/feed/1.0">In the EU, a revised [Technology Transfer Block Exemption Regulation](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202600877) (TTBER) and revised [Technology Transfer Guidelines](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_809) (‘the guidelines’) enter into force today, 1 May. The revisions, which replace the 2014 versions, follow a four-year review by the European Commission into the functioning of the 2014 TTBER and related guidelines and aim to address concerns raised from a wide range of stakeholders.</ns109:highlight></item>
    <item>
      <title>AI agents can bypass guardrails and put credentials at risk, Okta study finds</title>
      <link>https://www.computerworld.com/article/4166162/ai-agents-can-bypass-guardrails-and-put-credentials-at-risk-okta-study-finds-2.html</link>
      <description>An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.
It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.
A look at just how easily this can happen emerges from Phishing the agent: Why AI guardrails aren’t enough, a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.
Their research focused on OpenClaw, a model-agnostic multi-channel AI assistant which has seen explosive growth inside enterprises since appearing in late 2025.
The Telegram hack
In common with the growing list of rival agents, OpenClaw is only as useful as the access it is given to files, accounts, browsers, network devices, and, most significant of all, credentials.
One test conducted by Okta assessed how easy it would be to trick OpenClaw running Claude Sonnet 4.6 into handing over an OAuth token. This shouldn’t be possible; the LLM should refuse this request. However, what might have held true when prompting Claude as a chatbot quickly fell apart when it was accessed through OpenClaw.
The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.
First, the attacker instructed the agent via Telegram to retrieve an OAuth token, but to only display it in a terminal window on the computer. Claude Sonnet’s guardrails would prevent it from copying the token, however, the testers were able to reset the agent, causing it to forget it had displayed the token in the terminal window.
At that point, Okta said in i...</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Computerworld&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.computerworld.com/article/4166162/ai-agents-can-bypass-guardrails-and-put-credentials-at-risk-okta-study-finds-2.html"&gt;https://www.computerworld.com/article/4166162/ai-agents-can-bypass-guardrails-and-put-credentials-at-risk-okta-study-finds-2.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;agentic-ai&lt;/span&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;research&lt;/span&gt; &lt;span class="tag"&gt;security&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.&lt;br&gt;It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.&lt;br&gt;A look at just how easily this can happen emerges from Phishing the agent: Why AI guardrails aren’t enough, a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.&lt;br&gt;Their research focused on OpenClaw, a model-agnostic multi-channel AI assistant which has seen explosive growth inside enterprises since appearing in late 2025.&lt;br&gt;The Telegram hack&lt;br&gt;In common with the growing list of rival agents, OpenClaw is only as useful as the access it is given to files, accounts, browsers, network devices, and, most significant of all, credentials.&lt;br&gt;One test conducted by Okta assessed how easy it would be to trick OpenClaw running Claude Sonnet 4.6 into handing over an OAuth token. This shouldn’t be possible; the LLM should refuse this request. However, what might have held true when prompting Claude as a chatbot quickly fell apart when it was accessed through OpenClaw.&lt;br&gt;The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.&lt;br&gt;First, the attacker instructed the agent via Telegram to retrieve an OAuth token, but to only display it in a terminal window on the computer. Claude Sonnet’s guardrails would prevent it from copying the token, however, the testers were able to reset the agent, causing it to forget it had displayed the token in the terminal window.&lt;br&gt;At that point, Okta said in i...&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; It might save some time, but tou don’t need to be hugely imaginative to come up with scenarios where agentic AI could cause some really fundamental problems.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; BE CAREFUL - if it seems to good to be true, it might be. These tools are so easy to use, but it’s really worthwhile having at least a basic understanding of what they CAN do if you’re going to use them, so you can protect yourself. &lt;br&gt;&lt;br&gt;And let’s start by NOT giving tools like OpenClaw full access to your computer...&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Agents are only the latest example of a technology that is being deployed faster than it can be secured, Kirk observed. “Much of AI right now is defying security gravity,” he said. “But there are ways to use agents safely and keep credentials out of their reach, which is the only safe way to use them.”&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;“The agents are prompted to be as helpful as possible by default, a characteristic that poses particular concerns when it comes to credentials and tokens,” said Kirk.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Agentic AI is really two things: a powerful orchestration system coupled to one or more highly-capable LLMs. What an agent *isn’t* is a simple interface, and it must be viewed as a separate system capable of autonomous, unpredictable reasoning.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;A look at just how easily this can happen emerges from [*Phishing the agent: Why AI guardrails aren’t enough*](https://www.okta.com/newsroom/articles/why-ai-guardrails-are-not-enough/)*,* a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.computerworld.com/article/4166162/ai-agents-can-bypass-guardrails-and-put-credentials-at-risk-okta-study-finds-2.html</guid>
      <pubDate>Sat, 02 May 2026 12:26:38 +0000</pubDate>
    <ns110:tag xmlns:ns110="https://concatena.co.uk/feed/1.0">agentic-ai</ns110:tag><ns111:tag xmlns:ns111="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns111:tag><ns112:tag xmlns:ns112="https://concatena.co.uk/feed/1.0">cat:tech</ns112:tag><ns113:tag xmlns:ns113="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns113:tag><ns114:tag xmlns:ns114="https://concatena.co.uk/feed/1.0">research</ns114:tag><ns115:tag xmlns:ns115="https://concatena.co.uk/feed/1.0">security</ns115:tag><ns116:note xmlns:ns116="https://concatena.co.uk/feed/1.0">Our Take: It might save some time, but tou don’t need to be hugely imaginative to come up with scenarios where agentic AI could cause some really fundamental problems.

Your Takeaway: BE CAREFUL - if it seems to good to be true, it might be. These tools are so easy to use, but it’s really worthwhile having at least a basic understanding of what they CAN do if you’re going to use them, so you can protect yourself. 

And let’s start by NOT giving tools like OpenClaw full access to your computer...</ns116:note><ns117:highlight xmlns:ns117="https://concatena.co.uk/feed/1.0">Agents are only the latest example of a technology that is being deployed faster than it can be secured, Kirk observed. “Much of AI right now is defying security gravity,” he said. “But there are ways to use agents safely and keep credentials out of their reach, which is the only safe way to use them.”</ns117:highlight><ns118:highlight xmlns:ns118="https://concatena.co.uk/feed/1.0">“The agents are prompted to be as helpful as possible by default, a characteristic that poses particular concerns when it comes to credentials and tokens,” said Kirk.</ns118:highlight><ns119:highlight xmlns:ns119="https://concatena.co.uk/feed/1.0">Agentic AI is really two things: a powerful orchestration system coupled to one or more highly-capable LLMs. What an agent *isn’t* is a simple interface, and it must be viewed as a separate system capable of autonomous, unpredictable reasoning.</ns119:highlight><ns120:highlight xmlns:ns120="https://concatena.co.uk/feed/1.0">The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.</ns120:highlight><ns121:highlight xmlns:ns121="https://concatena.co.uk/feed/1.0">A look at just how easily this can happen emerges from [*Phishing the agent: Why AI guardrails aren’t enough*](https://www.okta.com/newsroom/articles/why-ai-guardrails-are-not-enough/)*,* a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.</ns121:highlight><ns122:highlight xmlns:ns122="https://concatena.co.uk/feed/1.0">It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.</ns122:highlight><ns123:highlight xmlns:ns123="https://concatena.co.uk/feed/1.0">An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.</ns123:highlight></item>
    <item>
      <title>Does Your AI Agent Need a VPN? The Company Behind Norton and Avast Thinks So</title>
      <link>https://www.cnet.com/tech/services-and-software/does-your-ai-agent-need-a-vpn-the-company-behind-norton-and-avast-thinks-so/</link>
      <description>You might use a VPN yourself, but have you considered giving one to your AI agent? It might be more important than you think.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Ajay Kumar&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.cnet.com/tech/services-and-software/does-your-ai-agent-need-a-vpn-the-company-behind-norton-and-avast-thinks-so/"&gt;https://www.cnet.com/tech/services-and-software/does-your-ai-agent-need-a-vpn-the-company-behind-norton-and-avast-thinks-so/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;agentic-ai&lt;/span&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;vpn&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;You might use a VPN yourself, but have you considered giving one to your AI agent? It might be more important than you think.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Some are looking to ban VPNs, whilst others are giving them to AI Agents… Back to whack-a-mole for services who are trying to stop AI agents from clogging up their processes.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; If your service distinguishes between human and agent, will VPN use affect that process? Or could your agent benefit from its own VPN?&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;Perhaps most importantly, your ISP can't distinguish between your own internet traffic and that of your autonomous AI agent,&amp;quot; said Tomaschek. &amp;quot;But with this integration, as well as with Windscribe's, the VPN encrypts the agent's traffic as well, so basically you're protected from whatever your agent might autonomously get up to on the internet.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;If you use [OpenClaw](https://www.cnet.com/tech/services-and-software/openclaw-ai-agents-access-vpn-windscribe/), ChatGPT or one of the many other LLMs with access to the internet, your autonomous AI agent can now take advantage of the same privacy and security features.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;Using a VPN with an LLM can provide several advantages, such as keeping your identity private. Your internet provider won't be able to see your AI agent's activity, or that you're using an AI agent,&amp;quot; said Moe Long, CNET senior editor.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.cnet.com/tech/services-and-software/does-your-ai-agent-need-a-vpn-the-company-behind-norton-and-avast-thinks-so/</guid>
      <pubDate>Sat, 02 May 2026 12:21:35 +0000</pubDate>
    <ns124:tag xmlns:ns124="https://concatena.co.uk/feed/1.0">agentic-ai</ns124:tag><ns125:tag xmlns:ns125="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns125:tag><ns126:tag xmlns:ns126="https://concatena.co.uk/feed/1.0">cat:bus</ns126:tag><ns127:tag xmlns:ns127="https://concatena.co.uk/feed/1.0">cat:tech</ns127:tag><ns128:tag xmlns:ns128="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns128:tag><ns129:tag xmlns:ns129="https://concatena.co.uk/feed/1.0">vpn</ns129:tag><ns130:note xmlns:ns130="https://concatena.co.uk/feed/1.0">Our Take: Some are looking to ban VPNs, whilst others are giving them to AI Agents… Back to whack-a-mole for services who are trying to stop AI agents from clogging up their processes.

Your Takeaway: If your service distinguishes between human and agent, will VPN use affect that process? Or could your agent benefit from its own VPN?</ns130:note><ns131:highlight xmlns:ns131="https://concatena.co.uk/feed/1.0">"Perhaps most importantly, your ISP can't distinguish between your own internet traffic and that of your autonomous AI agent," said Tomaschek. "But with this integration, as well as with Windscribe's, the VPN encrypts the agent's traffic as well, so basically you're protected from whatever your agent might autonomously get up to on the internet."</ns131:highlight><ns132:highlight xmlns:ns132="https://concatena.co.uk/feed/1.0">If you use [OpenClaw](https://www.cnet.com/tech/services-and-software/openclaw-ai-agents-access-vpn-windscribe/), ChatGPT or one of the many other LLMs with access to the internet, your autonomous AI agent can now take advantage of the same privacy and security features.</ns132:highlight><ns133:highlight xmlns:ns133="https://concatena.co.uk/feed/1.0">"Using a VPN with an LLM can provide several advantages, such as keeping your identity private. Your internet provider won't be able to see your AI agent's activity, or that you're using an AI agent," said Moe Long, CNET senior editor.</ns133:highlight></item>
    <item>
      <title>Study: AI models that consider user's feeling are more likely to make errors</title>
      <link>https://arstechnica.com/ai/2026/05/study-ai-models-that-consider-users-feeling-are-more-likely-to-make-errors/</link>
      <description>AI models tuned to be warmer and more empathetic often make more mistakes than original models. These warmer models tend to prioritize making users feel good over giving correct answers, especially when users share emotions like sadness. Researchers warn that choosing between a friendly AI and an accurate AI is important for safe and trustworthy use.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Kyle Orland&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://arstechnica.com/ai/2026/05/study-ai-models-that-consider-users-feeling-are-more-likely-to-make-errors/"&gt;https://arstechnica.com/ai/2026/05/study-ai-models-that-consider-users-feeling-are-more-likely-to-make-errors/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;human-interface&lt;/span&gt; &lt;span class="tag"&gt;llm&lt;/span&gt; &lt;span class="tag"&gt;research&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;AI models tuned to be warmer and more empathetic often make more mistakes than original models. These warmer models tend to prioritize making users feel good over giving correct answers, especially when users share emotions like sadness. Researchers warn that choosing between a friendly AI and an accurate AI is important for safe and trustworthy use.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; The law of unintended consequences strikes again - and why tech management and parenting have so much in common...&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; When you’re defining how you want an AI agent to act, remember it’s going to take your instructions very literally - and you might not like the consequences. Does this have an impact for products you ship or products you use that incorporate Ai - particularly if the people training the product may have a different world viewpoint to those using it?&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;In [a new paper published this week in Nature](https://www.nature.com/articles/s41586-026-10410-0), researchers from Oxford University’s Internet Institute found that specially tuned AI models tend to mimic the human tendency to occasionally “soften difficult truths” when necessary “to preserve bonds and avoid conflict.” These warmer models are also more likely to validate a user’s expressed incorrect beliefs, the researchers found, especially when the user shares that they’re feeling sad.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;In human-to-human communication, the desire to be empathetic or polite often conflicts with the need to be truthful—hence terms like “being brutally honest” for situations where you value the truth over sparing someone’s feelings. Now, new research suggests that large language models can sometimes show a similar tendency when specifically trained to present a “warmer” tone for the user.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://arstechnica.com/ai/2026/05/study-ai-models-that-consider-users-feeling-are-more-likely-to-make-errors/</guid>
      <pubDate>Sat, 02 May 2026 12:10:20 +0000</pubDate>
    <ns134:tag xmlns:ns134="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns134:tag><ns135:tag xmlns:ns135="https://concatena.co.uk/feed/1.0">cat:bus</ns135:tag><ns136:tag xmlns:ns136="https://concatena.co.uk/feed/1.0">cat:tech</ns136:tag><ns137:tag xmlns:ns137="https://concatena.co.uk/feed/1.0">human-interface</ns137:tag><ns138:tag xmlns:ns138="https://concatena.co.uk/feed/1.0">llm</ns138:tag><ns139:tag xmlns:ns139="https://concatena.co.uk/feed/1.0">research</ns139:tag><ns140:note xmlns:ns140="https://concatena.co.uk/feed/1.0">Our Take: The law of unintended consequences strikes again - and why tech management and parenting have so much in common...

Your Takeaway: When you’re defining how you want an AI agent to act, remember it’s going to take your instructions very literally - and you might not like the consequences. Does this have an impact for products you ship or products you use that incorporate Ai - particularly if the people training the product may have a different world viewpoint to those using it?</ns140:note><ns141:highlight xmlns:ns141="https://concatena.co.uk/feed/1.0">In [a new paper published this week in Nature](https://www.nature.com/articles/s41586-026-10410-0), researchers from Oxford University’s Internet Institute found that specially tuned AI models tend to mimic the human tendency to occasionally “soften difficult truths” when necessary “to preserve bonds and avoid conflict.” These warmer models are also more likely to validate a user’s expressed incorrect beliefs, the researchers found, especially when the user shares that they’re feeling sad.</ns141:highlight><ns142:highlight xmlns:ns142="https://concatena.co.uk/feed/1.0">In human-to-human communication, the desire to be empathetic or polite often conflicts with the need to be truthful—hence terms like “being brutally honest” for situations where you value the truth over sparing someone’s feelings. Now, new research suggests that large language models can sometimes show a similar tendency when specifically trained to present a “warmer” tone for the user.</ns142:highlight></item>
    <item>
      <title>Hackers are actively exploiting a bug in cPanel, used by millions of websites</title>
      <link>https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/</link>
      <description>A serious bug in cPanel software lets hackers take full control of websites and servers. Many web hosting companies have fixed the issue, but users must update their systems quickly to stay safe. Experts warn that the vulnerability is being actively exploited and could affect millions of sites worldwide.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Zack Whittaker&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/"&gt;https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;breach&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;security&lt;/span&gt; &lt;span class="tag"&gt;vulnerability&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;A serious bug in cPanel software lets hackers take full control of websites and servers. Many web hosting companies have fixed the issue, but users must update their systems quickly to stay safe. Experts warn that the vulnerability is being actively exploited and could affect millions of sites worldwide.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; If you're using cPanel, make sure you're patched!&lt;br&gt;This is a high-risk, actively exploited authentication-bypass in cPanel/WHM (CVE-2026-41940) that lets attackers skip login and take full admin control of servers; because cPanel is widespread and has deep server access, unpatched systems - especially on shared hosting - are prime targets and some hosts already saw exploitation attempts. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; We’re not tech experts, but check with your team or provider and make sure you're patched (or that access to control panels is blocked/isolated).&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM).&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/</guid>
      <pubDate>Fri, 01 May 2026 01:08:58 +0000</pubDate>
    <ns143:tag xmlns:ns143="https://concatena.co.uk/feed/1.0">breach</ns143:tag><ns144:tag xmlns:ns144="https://concatena.co.uk/feed/1.0">cat:bus</ns144:tag><ns145:tag xmlns:ns145="https://concatena.co.uk/feed/1.0">cat:tech</ns145:tag><ns146:tag xmlns:ns146="https://concatena.co.uk/feed/1.0">security</ns146:tag><ns147:tag xmlns:ns147="https://concatena.co.uk/feed/1.0">vulnerability</ns147:tag><ns148:note xmlns:ns148="https://concatena.co.uk/feed/1.0">Our Take: If you're using cPanel, make sure you're patched!
This is a high-risk, actively exploited authentication-bypass in cPanel/WHM (CVE-2026-41940) that lets attackers skip login and take full admin control of servers; because cPanel is widespread and has deep server access, unpatched systems - especially on shared hosting - are prime targets and some hosts already saw exploitation attempts. 

Your Takeaway: We’re not tech experts, but check with your team or provider and make sure you're patched (or that access to control panels is blocked/isolated).</ns148:note><ns149:highlight xmlns:ns149="https://concatena.co.uk/feed/1.0">cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.</ns149:highlight><ns150:highlight xmlns:ns150="https://concatena.co.uk/feed/1.0">The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.</ns150:highlight><ns151:highlight xmlns:ns151="https://concatena.co.uk/feed/1.0">Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM).</ns151:highlight></item>
    <item>
      <title>Meta cuts contractors who reported seeing Ray-Ban Meta users have sex</title>
      <link>https://arstechnica.com/gadgets/2026/04/meta-cuts-contractors-who-reported-seeing-ray-ban-meta-users-have-sex/</link>
      <description>Meta ended its contract with Kenyan firm Sama after workers reported seeing private and explicit videos recorded by Ray-Ban Meta glasses. Sama denies failing to meet standards and says it was not warned about any issues. The situation has raised privacy concerns and led to investigations and a class-action lawsuit against Meta.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Scharon Harding&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://arstechnica.com/gadgets/2026/04/meta-cuts-contractors-who-reported-seeing-ray-ban-meta-users-have-sex/"&gt;https://arstechnica.com/gadgets/2026/04/meta-cuts-contractors-who-reported-seeing-ray-ban-meta-users-have-sex/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;content-moderation&lt;/span&gt; &lt;span class="tag"&gt;global&lt;/span&gt; &lt;span class="tag"&gt;meta&lt;/span&gt; &lt;span class="tag"&gt;surveillance&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Meta ended its contract with Kenyan firm Sama after workers reported seeing private and explicit videos recorded by Ray-Ban Meta glasses. Sama denies failing to meet standards and says it was not warned about any issues. The situation has raised privacy concerns and led to investigations and a class-action lawsuit against Meta.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Without going into the many many layers of this story, our takeaway for anyone procuring products or services is to consider the full supply chain when looking at the ethics of a product. What feels like automated magic is often a person behind the curtain, probably in a jurisdiction with fewer safeguards, more often than you might expect.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; Beauty isn’t skin deep - make sure you do your due diligence and that your happy that your providers ahve appropriate worker protection and safeguards all the way down the chain. And if you’re running human‑review workflows - think through all the consequences. Finally, if you’re using wearable tech which captures images of everyone around you, give real consideration to how you’d feel if a someone with less moral integrity than you were to do the same.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;BBC reported that Sama workers believe Meta ended the contract because workers spoke out about seeing Ray-Ban Meta-shot footage of people performing personal acts, like changing their clothes, having sex, and using the toilet.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;A Meta spokesperson told BBC that Meta “decided to end our work with Sama because they don’t meet our standards.” Ars Technica reached out to Meta asking how, specifically, Sama failed to meet Meta’s expectations and will update this article if we hear back. Ars has also reached out to Sama.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;In February, numerous workers from a company that Meta contracted to perform data annotation for Ray-Ban Meta reported [viewing sensitive, embarrassing, and seemingly private footage](https://arstechnica.com/gadgets/2026/03/workers-report-watching-ray-ban-meta-shot-footage-of-people-using-the-bathroom/) recorded by the smart glasses. About two months later, Meta ended its contract with the firm.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://arstechnica.com/gadgets/2026/04/meta-cuts-contractors-who-reported-seeing-ray-ban-meta-users-have-sex/</guid>
      <pubDate>Fri, 01 May 2026 01:07:20 +0000</pubDate>
    <ns152:tag xmlns:ns152="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns152:tag><ns153:tag xmlns:ns153="https://concatena.co.uk/feed/1.0">cat:law</ns153:tag><ns154:tag xmlns:ns154="https://concatena.co.uk/feed/1.0">cat:tech</ns154:tag><ns155:tag xmlns:ns155="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns155:tag><ns156:tag xmlns:ns156="https://concatena.co.uk/feed/1.0">content-moderation</ns156:tag><ns157:tag xmlns:ns157="https://concatena.co.uk/feed/1.0">global</ns157:tag><ns158:tag xmlns:ns158="https://concatena.co.uk/feed/1.0">meta</ns158:tag><ns159:tag xmlns:ns159="https://concatena.co.uk/feed/1.0">surveillance</ns159:tag><ns160:note xmlns:ns160="https://concatena.co.uk/feed/1.0">Our Take: Without going into the many many layers of this story, our takeaway for anyone procuring products or services is to consider the full supply chain when looking at the ethics of a product. What feels like automated magic is often a person behind the curtain, probably in a jurisdiction with fewer safeguards, more often than you might expect.

Your Takeaway: Beauty isn’t skin deep - make sure you do your due diligence and that your happy that your providers ahve appropriate worker protection and safeguards all the way down the chain. And if you’re running human‑review workflows - think through all the consequences. Finally, if you’re using wearable tech which captures images of everyone around you, give real consideration to how you’d feel if a someone with less moral integrity than you were to do the same.</ns160:note><ns161:highlight xmlns:ns161="https://concatena.co.uk/feed/1.0">BBC reported that Sama workers believe Meta ended the contract because workers spoke out about seeing Ray-Ban Meta-shot footage of people performing personal acts, like changing their clothes, having sex, and using the toilet.</ns161:highlight><ns162:highlight xmlns:ns162="https://concatena.co.uk/feed/1.0">A Meta spokesperson told BBC that Meta “decided to end our work with Sama because they don’t meet our standards.” Ars Technica reached out to Meta asking how, specifically, Sama failed to meet Meta’s expectations and will update this article if we hear back. Ars has also reached out to Sama.</ns162:highlight><ns163:highlight xmlns:ns163="https://concatena.co.uk/feed/1.0">In February, numerous workers from a company that Meta contracted to perform data annotation for Ray-Ban Meta reported [viewing sensitive, embarrassing, and seemingly private footage](https://arstechnica.com/gadgets/2026/03/workers-report-watching-ray-ban-meta-shot-footage-of-people-using-the-bathroom/) recorded by the smart glasses. About two months later, Meta ended its contract with the firm.</ns163:highlight></item>
    <item>
      <title>Spotify rolls out ‘Verified’ badge to distinguish human artists from AI</title>
      <link>https://www.theguardian.com/technology/2026/apr/30/spotify-verified-badge-human-artists-from-ai</link>
      <description>Spotify will add a green "Verified by Spotify" badge to show which artists are real humans, not AI creations. This badge helps listeners trust the music and appears only on profiles that meet Spotify’s authenticity rules. The change comes as many AI-generated songs flood streaming platforms, causing concern in the music industry.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Agence France-Presse&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.theguardian.com/technology/2026/apr/30/spotify-verified-badge-human-artists-from-ai"&gt;https://www.theguardian.com/technology/2026/apr/30/spotify-verified-badge-human-artists-from-ai&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;spotify&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Spotify will add a green &amp;quot;Verified by Spotify&amp;quot; badge to show which artists are real humans, not AI creations. This badge helps listeners trust the music and appears only on profiles that meet Spotify’s authenticity rules. The change comes as many AI-generated songs flood streaming platforms, causing concern in the music industry.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Spotify’s new green “Verified by Spotify” badge and the informational panel are straightforward moves to help users spot human artists and surface authenticity signals amid a flood of AI-generated music. B the verification criteria (sustained engagement, platform-rule compliance, external presence like gigs/merch/socials) explicitly exclude primarily AI-created artists, rather than music… Is this the intention?&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; It’s always worth considering what the “verification” on any site means - what needs to be demonstrated before verification is granted.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;[Spotify](https://www.theguardian.com/technology/spotify) on Thursday unveiled a new verification system designed to help listeners distinguish human musicians from AI-generated content, as people flood streaming platforms with a growing volume of synthetic tracks made with [artificial intelligence](https://www.theguardian.com/technology/artificialintelligenceai).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The initiative arrives amid mounting concern across the music industry over AI-generated content overwhelming streaming catalogues.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The company said more than 99% of artists that listeners actively search for will be verified at launch, representing hundreds of thousands of musicians spanning genres and geographies.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;To earn verification, artists must demonstrate sustained listener engagement over time, comply with Spotify’s platform rules and show signs of a genuine presence both on and off the platform, such as concert dates, merchandise and linked social media accounts.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.theguardian.com/technology/2026/apr/30/spotify-verified-badge-human-artists-from-ai</guid>
      <pubDate>Fri, 01 May 2026 01:05:44 +0000</pubDate>
    <ns164:tag xmlns:ns164="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns164:tag><ns165:tag xmlns:ns165="https://concatena.co.uk/feed/1.0">cat:bus</ns165:tag><ns166:tag xmlns:ns166="https://concatena.co.uk/feed/1.0">cat:law</ns166:tag><ns167:tag xmlns:ns167="https://concatena.co.uk/feed/1.0">cat:tech</ns167:tag><ns168:tag xmlns:ns168="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns168:tag><ns169:tag xmlns:ns169="https://concatena.co.uk/feed/1.0">spotify</ns169:tag><ns170:note xmlns:ns170="https://concatena.co.uk/feed/1.0">Our Take: Spotify’s new green “Verified by Spotify” badge and the informational panel are straightforward moves to help users spot human artists and surface authenticity signals amid a flood of AI-generated music. B the verification criteria (sustained engagement, platform-rule compliance, external presence like gigs/merch/socials) explicitly exclude primarily AI-created artists, rather than music… Is this the intention?

Your Takeaway: It’s always worth considering what the “verification” on any site means - what needs to be demonstrated before verification is granted.</ns170:note><ns171:highlight xmlns:ns171="https://concatena.co.uk/feed/1.0">[Spotify](https://www.theguardian.com/technology/spotify) on Thursday unveiled a new verification system designed to help listeners distinguish human musicians from AI-generated content, as people flood streaming platforms with a growing volume of synthetic tracks made with [artificial intelligence](https://www.theguardian.com/technology/artificialintelligenceai).</ns171:highlight><ns172:highlight xmlns:ns172="https://concatena.co.uk/feed/1.0">The initiative arrives amid mounting concern across the music industry over AI-generated content overwhelming streaming catalogues.</ns172:highlight><ns173:highlight xmlns:ns173="https://concatena.co.uk/feed/1.0">The company said more than 99% of artists that listeners actively search for will be verified at launch, representing hundreds of thousands of musicians spanning genres and geographies.</ns173:highlight><ns174:highlight xmlns:ns174="https://concatena.co.uk/feed/1.0">To earn verification, artists must demonstrate sustained listener engagement over time, comply with Spotify’s platform rules and show signs of a genuine presence both on and off the platform, such as concert dates, merchandise and linked social media accounts.</ns174:highlight></item>
    <item>
      <title>Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter</title>
      <link>https://techcrunch.com/2026/04/30/legal-ai-startup-legora-hits-5-6-valuation-and-its-battle-with-harvey-just-got-hotter/</link>
      <description>Legora is a legal AI startup valued at $5.6 billion and backed by Nvidia and other investors. It competes closely with Harvey, another legal AI company valued at $11 billion, as both expand globally. The rivalry is intense, with big marketing efforts and a focus on applying AI to reshape the legal industry.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Anna Heim&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://techcrunch.com/2026/04/30/legal-ai-startup-legora-hits-5-6-valuation-and-its-battle-with-harvey-just-got-hotter/"&gt;https://techcrunch.com/2026/04/30/legal-ai-startup-legora-hits-5-6-valuation-and-its-battle-with-harvey-just-got-hotter/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;legal-practice&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Legora is a legal AI startup valued at $5.6 billion and backed by Nvidia and other investors. It competes closely with Harvey, another legal AI company valued at $11 billion, as both expand globally. The rivalry is intense, with big marketing efforts and a focus on applying AI to reshape the legal industry.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt;  We’re seeing more “market froth” more than “proven change in legal practice.” Valuations, ad campaigns and celebrity endorsements are racing ahead of most firms’ ability to use these tools in a meaningful way. Right now, the gap between the hype and what fee-earners actually do with Harvey/Legora in a normal Tuesday is still pretty stark. I’d love to hear your experience!&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt;  Treat this as a signal to experiment deliberately, not to panic-buy a platform. If you haven’t already, pick one or two contained use cases (e.g. first-draft research notes, clause comparison) and run small, supervised pilots with clear guardrails. Then share honest internal feedback — including the “confused faces” — so you don’t let marketing headlines set your AI strategy.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Alongside Atlassian and other new financial investors, NVentures joined Legora’s cap table as part of a [$50 million Series D extension](https://legora.com/newsroom/legora-extends-series-d-with-additional-50-million-welcomes-atlassian-and-nventures-as-investors) that comes a month after the startup’s [$550 million Series D](https://techcrunch.com/2026/03/10/legora-reaches-5-55-billion-valuation-as-ai-legaltech-boom-endures/?_thumbnail_id=3100931).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Leveraging AI to help lawyers streamline their work, the Swedish-born legal tech startup is competing with U.S. player [Harvey](https://techcrunch.com/tag/harvey/).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Nvidia has laid a new brick [in its AI empire](https://techcrunch.com/2026/01/02/nvidias-ai-empire-a-look-at-its-top-startup-investments/). NVentures, its corporate VC fund, has backed Legora, [reportedly](https://www.cnbc.com/2026/04/30/nvidia-backs-ai-legal-tech-legora.html) its first legal AI investment.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://techcrunch.com/2026/04/30/legal-ai-startup-legora-hits-5-6-valuation-and-its-battle-with-harvey-just-got-hotter/</guid>
      <pubDate>Fri, 01 May 2026 00:54:50 +0000</pubDate>
    <ns175:tag xmlns:ns175="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns175:tag><ns176:tag xmlns:ns176="https://concatena.co.uk/feed/1.0">cat:law</ns176:tag><ns177:tag xmlns:ns177="https://concatena.co.uk/feed/1.0">cat:tech</ns177:tag><ns178:tag xmlns:ns178="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns178:tag><ns179:tag xmlns:ns179="https://concatena.co.uk/feed/1.0">legal-practice</ns179:tag><ns180:note xmlns:ns180="https://concatena.co.uk/feed/1.0">Our Take:  We’re seeing more “market froth” more than “proven change in legal practice.” Valuations, ad campaigns and celebrity endorsements are racing ahead of most firms’ ability to use these tools in a meaningful way. Right now, the gap between the hype and what fee-earners actually do with Harvey/Legora in a normal Tuesday is still pretty stark. I’d love to hear your experience!

Your Takeaway:  Treat this as a signal to experiment deliberately, not to panic-buy a platform. If you haven’t already, pick one or two contained use cases (e.g. first-draft research notes, clause comparison) and run small, supervised pilots with clear guardrails. Then share honest internal feedback — including the “confused faces” — so you don’t let marketing headlines set your AI strategy.</ns180:note><ns181:highlight xmlns:ns181="https://concatena.co.uk/feed/1.0">Alongside Atlassian and other new financial investors, NVentures joined Legora’s cap table as part of a [$50 million Series D extension](https://legora.com/newsroom/legora-extends-series-d-with-additional-50-million-welcomes-atlassian-and-nventures-as-investors) that comes a month after the startup’s [$550 million Series D](https://techcrunch.com/2026/03/10/legora-reaches-5-55-billion-valuation-as-ai-legaltech-boom-endures/?_thumbnail_id=3100931).</ns181:highlight><ns182:highlight xmlns:ns182="https://concatena.co.uk/feed/1.0">Leveraging AI to help lawyers streamline their work, the Swedish-born legal tech startup is competing with U.S. player [Harvey](https://techcrunch.com/tag/harvey/).</ns182:highlight><ns183:highlight xmlns:ns183="https://concatena.co.uk/feed/1.0">Nvidia has laid a new brick [in its AI empire](https://techcrunch.com/2026/01/02/nvidias-ai-empire-a-look-at-its-top-startup-investments/). NVentures, its corporate VC fund, has backed Legora, [reportedly](https://www.cnbc.com/2026/04/30/nvidia-backs-ai-legal-tech-legora.html) its first legal AI investment.</ns183:highlight></item>
    <item>
      <title>Firefox maker torches Google for building Prompt API into browser</title>
      <link>https://go.theregister.com/feed/www.theregister.com/2026/04/30/mozilla_pushes_back_against_googles/</link>
      <description>Mozilla opposes Google's new Prompt API because it may limit web openness and favor Google's AI model. They worry it forces developers to follow Google's rules, hurting fairness and interoperability. Google says the API encourages innovation, but tests show its AI often performs poorly.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Thomas Claburn&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://go.theregister.com/feed/www.theregister.com/2026/04/30/mozilla_pushes_back_against_googles/"&gt;https://go.theregister.com/feed/www.theregister.com/2026/04/30/mozilla_pushes_back_against_googles/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;browsers&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;google&lt;/span&gt; &lt;span class="tag"&gt;mozilla&lt;/span&gt; &lt;span class="tag"&gt;web-standards&lt;/span&gt; &lt;span class="tag"&gt;www&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Mozilla opposes Google's new Prompt API because it may limit web openness and favor Google's AI model. They worry it forces developers to follow Google's rules, hurting fairness and interoperability. Google says the API encourages innovation, but tests show its AI often performs poorly.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Mozilla is right to flag real risks with Google's Prompt API: it bundles a vendor-specific model and policy into a browser API, which can push developers to change the way they build. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; There is a very real risk for everyone of AI being built in by the back door even if a product doesn't appear to use AI. Due diligence in software is getting very difficult. &lt;br&gt;&lt;br&gt;Treat any browser‑provided AI API as a potential vector for vendor lock‑in and unexpected content controls; push for neutral, implementable standards that separate API mechanics from any single model or provider policy, test real performance and harms before adoption, and avoid building critical product flows that depend on Chrome‑specific AI behaviour.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;The core problem is interoperability,&amp;quot; he said. &amp;quot;Prompts are tightly coupled to models; developers will inevitably tune to the quirks and policies of whatever model they're building against.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;This seems like a bad direction for an API on the web platform, and sets a worrying precedent for more APIs that have [browser]-specific rules around usage,&amp;quot; he said.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Perhaps more significantly, Archibald notes that using the Prompt API requires agreeing to Google's [Generative AI Prohibited Uses Policy](https://policies.google.com/terms/generative-ai/use-policy), which prohibits activities that are not necessarily illegal, like generating &amp;quot;disturbing&amp;quot; content.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;First, he worries that Google's own Nano model will become the default and that developers will standardize on it in an effort to make the non-deterministic responses of an AI model more predictable. That tendency, he argues, will create pressure for Apple and Mozilla to license Nano, for the sake of a common user experience.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Mozilla's concern, as articulated by Archibald, has to do with what the Prompt API means for the web, not to mention Google's justification for deployment.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Various vendors like OpenAI and Perplexity have shipped browsers that embed access to remotely hosted AI models. Mozilla itself is testing [an AI-based Smart Window in Firefox](https://www.firefox.com/en-US/smart-window/) and it's developing [tools for AI model scaffolding](https://www.mozilla.ai).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The [Prompt API](https://webmachinelearning.github.io/prompt-api/), as Google describes it, &amp;quot;gives web pages the ability to directly prompt a browser-provided language model.&amp;quot; It provides a way to send natural language instructions to Google's Gemini Nano model, which is small enough to be downloaded for local inference through Chrome.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;quot;We continue to oppose this API, and feel it has severe negative consequences to the interoperability, updatability, and neutrality of the web platform,&amp;quot; said Archibald.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Jake Archibald, Mozilla web developer relations lead, articulated the org’s concerns in [a GitHub discussion](https://github.com/mozilla/standards-positions/issues/1213#issuecomment-4347988313) of the API, which provides a standard way to send and receive prompts and responses from a local machine learning model.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://go.theregister.com/feed/www.theregister.com/2026/04/30/mozilla_pushes_back_against_googles/</guid>
      <pubDate>Fri, 01 May 2026 00:51:27 +0000</pubDate>
    <ns184:tag xmlns:ns184="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns184:tag><ns185:tag xmlns:ns185="https://concatena.co.uk/feed/1.0">browsers</ns185:tag><ns186:tag xmlns:ns186="https://concatena.co.uk/feed/1.0">cat:bus</ns186:tag><ns187:tag xmlns:ns187="https://concatena.co.uk/feed/1.0">cat:tech</ns187:tag><ns188:tag xmlns:ns188="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns188:tag><ns189:tag xmlns:ns189="https://concatena.co.uk/feed/1.0">google</ns189:tag><ns190:tag xmlns:ns190="https://concatena.co.uk/feed/1.0">mozilla</ns190:tag><ns191:tag xmlns:ns191="https://concatena.co.uk/feed/1.0">web-standards</ns191:tag><ns192:tag xmlns:ns192="https://concatena.co.uk/feed/1.0">www</ns192:tag><ns193:note xmlns:ns193="https://concatena.co.uk/feed/1.0">Our Take: Mozilla is right to flag real risks with Google's Prompt API: it bundles a vendor-specific model and policy into a browser API, which can push developers to change the way they build. 

Your Takeaway: There is a very real risk for everyone of AI being built in by the back door even if a product doesn't appear to use AI. Due diligence in software is getting very difficult. 

Treat any browser‑provided AI API as a potential vector for vendor lock‑in and unexpected content controls; push for neutral, implementable standards that separate API mechanics from any single model or provider policy, test real performance and harms before adoption, and avoid building critical product flows that depend on Chrome‑specific AI behaviour.</ns193:note><ns194:highlight xmlns:ns194="https://concatena.co.uk/feed/1.0">"The core problem is interoperability," he said. "Prompts are tightly coupled to models; developers will inevitably tune to the quirks and policies of whatever model they're building against.</ns194:highlight><ns195:highlight xmlns:ns195="https://concatena.co.uk/feed/1.0">"This seems like a bad direction for an API on the web platform, and sets a worrying precedent for more APIs that have [browser]-specific rules around usage," he said.</ns195:highlight><ns196:highlight xmlns:ns196="https://concatena.co.uk/feed/1.0">Perhaps more significantly, Archibald notes that using the Prompt API requires agreeing to Google's [Generative AI Prohibited Uses Policy](https://policies.google.com/terms/generative-ai/use-policy), which prohibits activities that are not necessarily illegal, like generating "disturbing" content.</ns196:highlight><ns197:highlight xmlns:ns197="https://concatena.co.uk/feed/1.0">First, he worries that Google's own Nano model will become the default and that developers will standardize on it in an effort to make the non-deterministic responses of an AI model more predictable. That tendency, he argues, will create pressure for Apple and Mozilla to license Nano, for the sake of a common user experience.</ns197:highlight><ns198:highlight xmlns:ns198="https://concatena.co.uk/feed/1.0">Mozilla's concern, as articulated by Archibald, has to do with what the Prompt API means for the web, not to mention Google's justification for deployment.</ns198:highlight><ns199:highlight xmlns:ns199="https://concatena.co.uk/feed/1.0">Various vendors like OpenAI and Perplexity have shipped browsers that embed access to remotely hosted AI models. Mozilla itself is testing [an AI-based Smart Window in Firefox](https://www.firefox.com/en-US/smart-window/) and it's developing [tools for AI model scaffolding](https://www.mozilla.ai).</ns199:highlight><ns200:highlight xmlns:ns200="https://concatena.co.uk/feed/1.0">The [Prompt API](https://webmachinelearning.github.io/prompt-api/), as Google describes it, "gives web pages the ability to directly prompt a browser-provided language model." It provides a way to send natural language instructions to Google's Gemini Nano model, which is small enough to be downloaded for local inference through Chrome.</ns200:highlight><ns201:highlight xmlns:ns201="https://concatena.co.uk/feed/1.0">"We continue to oppose this API, and feel it has severe negative consequences to the interoperability, updatability, and neutrality of the web platform," said Archibald.</ns201:highlight><ns202:highlight xmlns:ns202="https://concatena.co.uk/feed/1.0">Jake Archibald, Mozilla web developer relations lead, articulated the org’s concerns in [a GitHub discussion](https://github.com/mozilla/standards-positions/issues/1213#issuecomment-4347988313) of the API, which provides a standard way to send and receive prompts and responses from a local machine learning model.</ns202:highlight></item>
    <item>
      <title>Congress keeps kicking surveillance reform down the road</title>
      <link>https://www.theverge.com/policy/921652/congress-fisa-section-702-45-day-extension</link>
      <description>Congress extended Section 702 of the Foreign Intelligence Surveillance Act for 45 days to allow more time for reform talks. The House passed a version with minor changes but no warrant requirements, causing frustration among some lawmakers. Privacy advocates say the bill does not do enough to protect Americans' rights.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Gaby Del Valle&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.theverge.com/policy/921652/congress-fisa-section-702-45-day-extension"&gt;https://www.theverge.com/policy/921652/congress-fisa-section-702-45-day-extension&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;fisa&lt;/span&gt; &lt;span class="tag"&gt;surveillance&lt;/span&gt; &lt;span class="tag"&gt;usa&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Congress extended Section 702 of the Foreign Intelligence Surveillance Act for 45 days to allow more time for reform talks. The House passed a version with minor changes but no warrant requirements, causing frustration among some lawmakers. Privacy advocates say the bill does not do enough to protect Americans' rights.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt;   Congress has kicked the FISA 702 can down the road. Whilst this legal back and forth might feel far away, the way the US sets its surveillance rules has real knock-on effects for UK/EU businesses relying on US cloud and SaaS tools, and for anyone worrying about international data transfers. This is one to watch closely in case future “reforms” either harden surveillance or, more optimistically, edge towards better privacy safeguards that could ease some cross-border risk.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt;  If your business leans on US tech stacks, keep in mind that ongoing FISA 702 wrangling could shift the risk profile of your international data flows overnight. Treat this as a reminder to map which services touch US infrastructure, keep your transfer impact assessments fresh, and be ready to explain to customers and boards why a very American-sounding fight in Congress still matters for their data.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;“Three weeks is more than enough time to negotiate a reform bill,” Thune said on the Senate floor on Thursday. “That is, if members are serious about negotiating.”&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The [House renewed Section 702](https://www.theverge.com/policy/920989/fisa-renewal-moves-forward-in-the-house) with minor reforms on Wednesday evening. The bill didn’t include the hotly debated warrant requirement, but it did feature a provision prohibiting the Federal Reserve from issuing Central Bank Digital Currencies, which Senate Majority Leader John Thune (R-SD) described as a nonstarter.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act — but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the controversial wiretapping bill. If the past few weeks are any indication of how future debates will go, however, we’re in for a bumpy ride.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.theverge.com/policy/921652/congress-fisa-section-702-45-day-extension</guid>
      <pubDate>Fri, 01 May 2026 00:46:59 +0000</pubDate>
    <ns203:tag xmlns:ns203="https://concatena.co.uk/feed/1.0">cat:bus</ns203:tag><ns204:tag xmlns:ns204="https://concatena.co.uk/feed/1.0">cat:law</ns204:tag><ns205:tag xmlns:ns205="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns205:tag><ns206:tag xmlns:ns206="https://concatena.co.uk/feed/1.0">fisa</ns206:tag><ns207:tag xmlns:ns207="https://concatena.co.uk/feed/1.0">surveillance</ns207:tag><ns208:tag xmlns:ns208="https://concatena.co.uk/feed/1.0">usa</ns208:tag><ns209:note xmlns:ns209="https://concatena.co.uk/feed/1.0">Our Take:   Congress has kicked the FISA 702 can down the road. Whilst this legal back and forth might feel far away, the way the US sets its surveillance rules has real knock-on effects for UK/EU businesses relying on US cloud and SaaS tools, and for anyone worrying about international data transfers. This is one to watch closely in case future “reforms” either harden surveillance or, more optimistically, edge towards better privacy safeguards that could ease some cross-border risk.

Your Takeaway:  If your business leans on US tech stacks, keep in mind that ongoing FISA 702 wrangling could shift the risk profile of your international data flows overnight. Treat this as a reminder to map which services touch US infrastructure, keep your transfer impact assessments fresh, and be ready to explain to customers and boards why a very American-sounding fight in Congress still matters for their data.</ns209:note><ns210:highlight xmlns:ns210="https://concatena.co.uk/feed/1.0">“Three weeks is more than enough time to negotiate a reform bill,” Thune said on the Senate floor on Thursday. “That is, if members are serious about negotiating.”</ns210:highlight><ns211:highlight xmlns:ns211="https://concatena.co.uk/feed/1.0">The [House renewed Section 702](https://www.theverge.com/policy/920989/fisa-renewal-moves-forward-in-the-house) with minor reforms on Wednesday evening. The bill didn’t include the hotly debated warrant requirement, but it did feature a provision prohibiting the Federal Reserve from issuing Central Bank Digital Currencies, which Senate Majority Leader John Thune (R-SD) described as a nonstarter.</ns211:highlight><ns212:highlight xmlns:ns212="https://concatena.co.uk/feed/1.0">Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act — but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the controversial wiretapping bill. If the past few weeks are any indication of how future debates will go, however, we’re in for a bumpy ride.</ns212:highlight></item>
    <item>
      <title>Utah’s New Law Targeting VPNs Goes Into Effect Next Week</title>
      <link>https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week</link>
      <description>For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, Virtual Private Network (VPN) usage surges as residents scramble to maintain their privacy and anonymity. We've seen this everywhere—from states like Florida, Missouri, Texas, and Utah, to countries like the United Kingdom, Australia, and Indonesia. 
Instead of realizing that mass surveillance and age gates aren't exactly crowd favorites, Utah lawmakers have decided that VPNs themselves are the real issue.
Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like Wisconsin successfully forced the removal of similar provisions due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights. 
What the Bill Does
Formally known as the “Online Age Verification Amendments,” Senate Bill 73 (SB 73) was signed by Governor Spencer Cox on March 19, 2026. While the majority of the bill consists of provisions related to a 2% tax on revenues from online adult content that is set to take effect in October, one of the more immediate concerns for EFF is the section regulating VPN access, which goes into effect this coming Wednesday.
The VPN Provisions
The new law explicitly addresses VPN use in Section 14, which amends Section 78B-3-1002 of existing Utah statutes in two primary ways:

Regulation based on physical location: Under the law, an individual is considered to be accessing a website from Utah if they are physically located there, regardless of whether they use a VPN, proxy server, or other means to disguise their geographic location.
Ban on sharing VPN instructions: Commercial entities that host "a substantial portion of material harmful to minors" are now prohibited from fa...</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Rindala Alajaji&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week"&gt;https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;surveillance&lt;/span&gt; &lt;span class="tag"&gt;usa&lt;/span&gt; &lt;span class="tag"&gt;vpn&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, Virtual Private Network (VPN) usage surges as residents scramble to maintain their privacy and anonymity. We've seen this everywhere—from states like Florida, Missouri, Texas, and Utah, to countries like the United Kingdom, Australia, and Indonesia. &lt;br&gt;Instead of realizing that mass surveillance and age gates aren't exactly crowd favorites, Utah lawmakers have decided that VPNs themselves are the real issue.&lt;br&gt;Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like Wisconsin successfully forced the removal of similar provisions due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights. &lt;br&gt;What the Bill Does&lt;br&gt;Formally known as the “Online Age Verification Amendments,” Senate Bill 73 (SB 73) was signed by Governor Spencer Cox on March 19, 2026. While the majority of the bill consists of provisions related to a 2% tax on revenues from online adult content that is set to take effect in October, one of the more immediate concerns for EFF is the section regulating VPN access, which goes into effect this coming Wednesday.&lt;br&gt;The VPN Provisions&lt;br&gt;The new law explicitly addresses VPN use in Section 14, which amends Section 78B-3-1002 of existing Utah statutes in two primary ways:&lt;br&gt;&lt;br&gt;Regulation based on physical location: Under the law, an individual is considered to be accessing a website from Utah if they are physically located there, regardless of whether they use a VPN, proxy server, or other means to disguise their geographic location.&lt;br&gt;Ban on sharing VPN instructions: Commercial entities that host &amp;quot;a substantial portion of material harmful to minors&amp;quot; are now prohibited from fa...&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Internet regulation is hard, and if you don't take a multi-step view, then you can end up playing whack-a-mole. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; If the tech you rely on could be outlawed, how can you plan?&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like [Wisconsin successfully forced the removal of similar provisions](https://www.cnet.com/tech/services-and-software/wisconsin-reverses-decision-to-ban-vpns-in-age-verification-bill/) due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, [Virtual Private Network (VPN) usage](https://www.eff.org/pages/vpns-are-not-solution-age-gating-mandates) [surges](https://www.eff.org/deeplinks/2025/01/vpns-are-not-solution-age-verification-laws) as residents scramble to maintain their privacy and anonymity. We've seen this everywhere—from states like [Florida](https://www.cbsnews.com/miami/news/pornhub-florida-vpn-google-searches-skyrocket/), [Missouri](https://www.techradar.com/vpn/vpn-privacy-security/missouris-search-for-vpns-lifts-off-as-the-first-day-of-age-verification-arrives), [Texas](https://www.vpnmentor.com/news/vpn-demand-surge-texas/), and [Utah](https://www.vpnmentor.com/blog/research/vpn-demand-surge-utah/), to countries like the [United Kingdom](https://www.wired.com/story/vpn-use-spike-age-verification-laws-uk/), [Australia](https://www.techradar.com/vpn/vpn-privacy-security/vpns-surge-in-australia-as-mandatory-age-verification-for-adult-content-begins), and [Indonesia](https://www.techradar.com/vpn/vpn-privacy-security/vpn-interest-surges-in-indonesia-as-under-16-social-media-ban-takes-effect).&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;Instead of realizing that mass surveillance and age gates aren't exactly crowd favorites, Utah lawmakers have decided that [VPNs themselves are the real issue](https://www.xbiz.com/news/296279/utah-porn-tax-bill-with-vpn-provisions-passes-state-senate).&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week</guid>
      <pubDate>Fri, 01 May 2026 00:08:50 +0000</pubDate>
    <ns213:tag xmlns:ns213="https://concatena.co.uk/feed/1.0">cat:law</ns213:tag><ns214:tag xmlns:ns214="https://concatena.co.uk/feed/1.0">cat:tech</ns214:tag><ns215:tag xmlns:ns215="https://concatena.co.uk/feed/1.0">surveillance</ns215:tag><ns216:tag xmlns:ns216="https://concatena.co.uk/feed/1.0">usa</ns216:tag><ns217:tag xmlns:ns217="https://concatena.co.uk/feed/1.0">vpn</ns217:tag><ns218:note xmlns:ns218="https://concatena.co.uk/feed/1.0">Our Take: Internet regulation is hard, and if you don't take a multi-step view, then you can end up playing whack-a-mole. 

Your Takeaway: If the tech you rely on could be outlawed, how can you plan?</ns218:note><ns219:highlight xmlns:ns219="https://concatena.co.uk/feed/1.0">Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like [Wisconsin successfully forced the removal of similar provisions](https://www.cnet.com/tech/services-and-software/wisconsin-reverses-decision-to-ban-vpns-in-age-verification-bill/) due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights.</ns219:highlight><ns220:highlight xmlns:ns220="https://concatena.co.uk/feed/1.0">For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, [Virtual Private Network (VPN) usage](https://www.eff.org/pages/vpns-are-not-solution-age-gating-mandates) [surges](https://www.eff.org/deeplinks/2025/01/vpns-are-not-solution-age-verification-laws) as residents scramble to maintain their privacy and anonymity. We've seen this everywhere—from states like [Florida](https://www.cbsnews.com/miami/news/pornhub-florida-vpn-google-searches-skyrocket/), [Missouri](https://www.techradar.com/vpn/vpn-privacy-security/missouris-search-for-vpns-lifts-off-as-the-first-day-of-age-verification-arrives), [Texas](https://www.vpnmentor.com/news/vpn-demand-surge-texas/), and [Utah](https://www.vpnmentor.com/blog/research/vpn-demand-surge-utah/), to countries like the [United Kingdom](https://www.wired.com/story/vpn-use-spike-age-verification-laws-uk/), [Australia](https://www.techradar.com/vpn/vpn-privacy-security/vpns-surge-in-australia-as-mandatory-age-verification-for-adult-content-begins), and [Indonesia](https://www.techradar.com/vpn/vpn-privacy-security/vpn-interest-surges-in-indonesia-as-under-16-social-media-ban-takes-effect).</ns220:highlight><ns221:highlight xmlns:ns221="https://concatena.co.uk/feed/1.0">Instead of realizing that mass surveillance and age gates aren't exactly crowd favorites, Utah lawmakers have decided that [VPNs themselves are the real issue](https://www.xbiz.com/news/296279/utah-porn-tax-bill-with-vpn-provisions-passes-state-senate).</ns221:highlight></item>
    <item>
      <title>White House presses tech companies for support on AI-driven cyberattacks</title>
      <link>https://www.politico.com/news/2026/04/30/white-house-ai-cyber-threats-mythos-00902045?utm_source=RSS_Feed&amp;utm_medium=RSS&amp;utm_campaign=RSS_Syndication</link>
      <description>Tech and cyber companies were sent questions about artificial intelligence-led cybersecurity threats, including those posed by Anthropic’s advanced AI model, Mythos.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Aaron Mak, John Sakellariadis, Dana Nickel&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.politico.com/news/2026/04/30/white-house-ai-cyber-threats-mythos-00902045?utm_source=RSS_Feed&amp;amp;utm_medium=RSS&amp;amp;utm_campaign=RSS_Syndication"&gt;https://www.politico.com/news/2026/04/30/white-house-ai-cyber-threats-mythos-00902045?utm_source=RSS_Feed&amp;amp;utm_medium=RSS&amp;amp;utm_campaign=RSS_Syndication&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:law&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;governance&lt;/span&gt; &lt;span class="tag"&gt;legal-landscape&lt;/span&gt; &lt;span class="tag"&gt;usa&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;Tech and cyber companies were sent questions about artificial intelligence-led cybersecurity threats, including those posed by Anthropic’s advanced AI model, Mythos.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Does the approach taken to law making by governments rely a little too much on input from those who perhaps ought to be restricted by the laws that are made? This is a pivotal moment: policymakers want operational help fast, but firms want clear bounds on data sharing, liability and commercial secrecy.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; If you work with or run tech/security businesses, be ready to engage but insist on narrow, well‑justified requests, explicit protections for sensitive operational details, and clarity on how shared information will be used and protected; consider tightening disclosure policies and seeking confidentiality or legal safeguards before responding.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;The White House has been taking steps to [defuse a monthslong legal battle](https://www.politico.com/news/2026/04/23/trump-picked-a-fight-with-anthropic-now-the-administration-is-backing-off-00889241) with Anthropic over the company’s efforts to set ethical limits on government use of AI — a fight that led President Donald Trump in February to [ban all federal agencies](https://www.politico.com/news/2026/02/27/trump-orders-all-federal-agencies-to-stop-using-anthropic-00804517?utm_medium=twitter&amp;amp;utm_source=dlvr.it) from using the AI company’s software. Since then, growing awareness of Mythos’ cyber prowess — as well as concerns that [unauthorized users](https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users) might be commandeering technology — has agencies [clamoring for access](https://www.politico.com/news/2026/04/14/anthropic-mythos-federal-agency-testing-00872439) to the tool.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;One list of questions sent by the White House to some tech and cyber firms, obtained by POLITICO, covers a range of technical and policy considerations, including which widely used coding projects should be prioritized and more basic questions about how the public and private sectors can work together on initiatives such as [Project Glasswing](https://www.anthropic.com/glasswing). One question simply asks: “What is the most effective role for the government?”&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The request for additional, detailed information from these companies reflects the intensifying focus in Washington on the evolving threat that hyper-advanced AI tools may pose to national security and digital infrastructure.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The questions, from the White House’s Office of the National Cyber Director, focus on how specific sectors in the tech and cybersecurity industries can work with the White House to boost their defenses with AI, these people said. Companies have been asked to respond to them by Friday.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The White House has asked a group of tech companies to answer a set of questions this week about how to ward off digital attacks that frontier AI tools could soon enable, according to four people with knowledge of discussions between the administration and the tech sector.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.politico.com/news/2026/04/30/white-house-ai-cyber-threats-mythos-00902045?utm_source=RSS_Feed&amp;utm_medium=RSS&amp;utm_campaign=RSS_Syndication</guid>
      <pubDate>Thu, 30 Apr 2026 23:30:40 +0000</pubDate>
    <ns222:tag xmlns:ns222="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns222:tag><ns223:tag xmlns:ns223="https://concatena.co.uk/feed/1.0">cat:law</ns223:tag><ns224:tag xmlns:ns224="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns224:tag><ns225:tag xmlns:ns225="https://concatena.co.uk/feed/1.0">governance</ns225:tag><ns226:tag xmlns:ns226="https://concatena.co.uk/feed/1.0">legal-landscape</ns226:tag><ns227:tag xmlns:ns227="https://concatena.co.uk/feed/1.0">usa</ns227:tag><ns228:note xmlns:ns228="https://concatena.co.uk/feed/1.0">Our Take: Does the approach taken to law making by governments rely a little too much on input from those who perhaps ought to be restricted by the laws that are made? This is a pivotal moment: policymakers want operational help fast, but firms want clear bounds on data sharing, liability and commercial secrecy.

Your Takeaway: If you work with or run tech/security businesses, be ready to engage but insist on narrow, well‑justified requests, explicit protections for sensitive operational details, and clarity on how shared information will be used and protected; consider tightening disclosure policies and seeking confidentiality or legal safeguards before responding.</ns228:note><ns229:highlight xmlns:ns229="https://concatena.co.uk/feed/1.0">The White House has been taking steps to [defuse a monthslong legal battle](https://www.politico.com/news/2026/04/23/trump-picked-a-fight-with-anthropic-now-the-administration-is-backing-off-00889241) with Anthropic over the company’s efforts to set ethical limits on government use of AI — a fight that led President Donald Trump in February to [ban all federal agencies](https://www.politico.com/news/2026/02/27/trump-orders-all-federal-agencies-to-stop-using-anthropic-00804517?utm_medium=twitter&amp;utm_source=dlvr.it) from using the AI company’s software. Since then, growing awareness of Mythos’ cyber prowess — as well as concerns that [unauthorized users](https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users) might be commandeering technology — has agencies [clamoring for access](https://www.politico.com/news/2026/04/14/anthropic-mythos-federal-agency-testing-00872439) to the tool.</ns229:highlight><ns230:highlight xmlns:ns230="https://concatena.co.uk/feed/1.0">One list of questions sent by the White House to some tech and cyber firms, obtained by POLITICO, covers a range of technical and policy considerations, including which widely used coding projects should be prioritized and more basic questions about how the public and private sectors can work together on initiatives such as [Project Glasswing](https://www.anthropic.com/glasswing). One question simply asks: “What is the most effective role for the government?”</ns230:highlight><ns231:highlight xmlns:ns231="https://concatena.co.uk/feed/1.0">The request for additional, detailed information from these companies reflects the intensifying focus in Washington on the evolving threat that hyper-advanced AI tools may pose to national security and digital infrastructure.</ns231:highlight><ns232:highlight xmlns:ns232="https://concatena.co.uk/feed/1.0">The questions, from the White House’s Office of the National Cyber Director, focus on how specific sectors in the tech and cybersecurity industries can work with the White House to boost their defenses with AI, these people said. Companies have been asked to respond to them by Friday.</ns232:highlight><ns233:highlight xmlns:ns233="https://concatena.co.uk/feed/1.0">The White House has asked a group of tech companies to answer a set of questions this week about how to ward off digital attacks that frontier AI tools could soon enable, according to four people with knowledge of discussions between the administration and the tech sector.</ns233:highlight></item>
    <item>
      <title>Will AI lead to more accurate opinion polls?</title>
      <link>https://www.bbc.com/news/articles/cwyw6rylzepo?at_medium=RSS&amp;at_campaign=rss</link>
      <description>It's cheaper and faster to collect people's opinions using AI, but will it make polls more accurate?</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; BBC News - Business&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://www.bbc.com/news/articles/cwyw6rylzepo?at_medium=RSS&amp;amp;at_campaign=rss"&gt;https://www.bbc.com/news/articles/cwyw6rylzepo?at_medium=RSS&amp;amp;at_campaign=rss&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;accuracy&lt;/span&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:bus&lt;/span&gt; &lt;span class="tag"&gt;cat:human&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;politics&lt;/span&gt; &lt;span class="tag"&gt;society&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;It's cheaper and faster to collect people's opinions using AI, but will it make polls more accurate?&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt; Whether about polling or anything else, 90% accuracy sounds like a big number, but in practice it means getting a lot of things wrong. It's really important when companies cite these kinds of figures to try to get access to real life examples of that margin of error.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt; Never take accuracy figures on face value - work out what they actually mean.&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;One checks he's answering the question, one analyses whether he's being too superficial and needs prompting to go deeper, while the third checks that the respondent is not a fraud… not a robot, for example.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="highlight-note"&gt;&lt;em&gt;Note: How long will it be before there are products to answer these kinds of calls for you?&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The voice is young, female, brisk and business-like and belongs to an AI agent. A computer programme in other words. A string of code.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="highlight-note"&gt;&lt;em&gt;Note: It's worth questioning why AI agents are so frequently expressed as being female...&lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The company claims its method is &amp;quot;10 times faster, 10 times cheaper and 90% as accurate as human polling&amp;quot;.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;It does not focus on quantitative polling, which is already largely automated through mass surveys. Instead, it emphasises depth. &amp;quot;We don't ask people to tick boxes - they have a conversation with an AI,&amp;quot; Fontaine explains. &amp;quot;That means we can explore not just what people think, but how they think - how they build their opinions, and even when those opinions change.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://www.bbc.com/news/articles/cwyw6rylzepo?at_medium=RSS&amp;at_campaign=rss</guid>
      <pubDate>Thu, 30 Apr 2026 23:22:42 +0000</pubDate>
    <ns234:tag xmlns:ns234="https://concatena.co.uk/feed/1.0">accuracy</ns234:tag><ns235:tag xmlns:ns235="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns235:tag><ns236:tag xmlns:ns236="https://concatena.co.uk/feed/1.0">cat:bus</ns236:tag><ns237:tag xmlns:ns237="https://concatena.co.uk/feed/1.0">cat:human</ns237:tag><ns238:tag xmlns:ns238="https://concatena.co.uk/feed/1.0">cat:tech</ns238:tag><ns239:tag xmlns:ns239="https://concatena.co.uk/feed/1.0">politics</ns239:tag><ns240:tag xmlns:ns240="https://concatena.co.uk/feed/1.0">society</ns240:tag><ns241:note xmlns:ns241="https://concatena.co.uk/feed/1.0">Our Take: Whether about polling or anything else, 90% accuracy sounds like a big number, but in practice it means getting a lot of things wrong. It's really important when companies cite these kinds of figures to try to get access to real life examples of that margin of error.

Your Takeaway: Never take accuracy figures on face value - work out what they actually mean.</ns241:note><ns242:highlight xmlns:ns242="https://concatena.co.uk/feed/1.0" note="How long will it be before there are products to answer these kinds of calls for you?">One checks he's answering the question, one analyses whether he's being too superficial and needs prompting to go deeper, while the third checks that the respondent is not a fraud… not a robot, for example.</ns242:highlight><ns243:highlight xmlns:ns243="https://concatena.co.uk/feed/1.0" note="It's worth questioning why AI agents are so frequently expressed as being female...">The voice is young, female, brisk and business-like and belongs to an AI agent. A computer programme in other words. A string of code.</ns243:highlight><ns244:highlight xmlns:ns244="https://concatena.co.uk/feed/1.0">The company claims its method is "10 times faster, 10 times cheaper and 90% as accurate as human polling".</ns244:highlight><ns245:highlight xmlns:ns245="https://concatena.co.uk/feed/1.0">It does not focus on quantitative polling, which is already largely automated through mass surveys. Instead, it emphasises depth. "We don't ask people to tick boxes - they have a conversation with an AI," Fontaine explains. "That means we can explore not just what people think, but how they think - how they build their opinions, and even when those opinions change."</ns245:highlight></item>
    <item>
      <title>OpenAI explains why ChatGPT developed a goblin fixation, and how it solved the issue</title>
      <link>https://9to5mac.com/2026/04/30/openai-explains-why-chatgpt-developed-a-goblin-fixation-and-how-it-solved-the-issue/</link>
      <description>OpenAI noticed that ChatGPT kept talking too much about goblins and other mythical creatures. This happened because of a past feature that rewarded creative use of such metaphors. To fix it, they told the new GPT-5.5 model not to mention these creatures unless really needed.</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Zac Hall&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href="https://9to5mac.com/2026/04/30/openai-explains-why-chatgpt-developed-a-goblin-fixation-and-how-it-solved-the-issue/"&gt;https://9to5mac.com/2026/04/30/openai-explains-why-chatgpt-developed-a-goblin-fixation-and-how-it-solved-the-issue/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;span class="tag"&gt;artificial-intelligence&lt;/span&gt; &lt;span class="tag"&gt;cat:tech&lt;/span&gt; &lt;span class="tag"&gt;cat:tech-ind&lt;/span&gt; &lt;span class="tag"&gt;openai&lt;/span&gt; &lt;span class="tag"&gt;prompts&lt;/span&gt; &lt;span class="tag"&gt;reinforcement-learning&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;OpenAI noticed that ChatGPT kept talking too much about goblins and other mythical creatures. This happened because of a past feature that rewarded creative use of such metaphors. To fix it, they told the new GPT-5.5 model not to mention these creatures unless really needed.&lt;/p&gt;
&lt;div class="concatena-says"&gt;&lt;span class="concatena-says-label"&gt;Concatena says&lt;/span&gt;&lt;p&gt;&lt;strong&gt;Our Take:&lt;/strong&gt;  LLMs really do latch onto patterns: OpenAI’s “goblin phase” is a silly example of a serious point – the way you train and reward a model can create odd, persistent behaviours that aren’t obvious from the outside. Model outputs are shaped by hidden system prompts and RL tweaks, not just “the law” or “the facts” you put in. &lt;br&gt;&lt;br&gt;&lt;strong&gt;Your Takeaway:&lt;/strong&gt;  If you’re using LLMs in your business, assume they’ll exaggerate any incentive or pattern you bake in, sometimes in unexpected ways. Treat prompts and “personalities” like configuration, not colour – document them, review them, and stop anthropomorphising them...&lt;/p&gt;&lt;/div&gt;
&lt;h3&gt;Highlights&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;Never talk about goblins, gremlins, raccoons, trolls, ogres, pigeons, or other animals or creatures unless it is absolutely and unambiguously relevant to the user’s query&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The fix, in part, is a specific set of instructions to never talk about goblins unless it’s abundantly relevant:&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;The goblin problem links back to the “Nerdy personality” option briefly supported by ChatGPT.&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;p&gt;To develop the personality, OpenAI needed to “reward” the model to incentivize its creative use of mythical metaphors. However, even after the Nerdy personality option was retired, the model remained unreasonably attached to gremlins, goblins, and other make-believe creatures.&lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
      <guid isPermaLink="false">https://9to5mac.com/2026/04/30/openai-explains-why-chatgpt-developed-a-goblin-fixation-and-how-it-solved-the-issue/</guid>
      <pubDate>Thu, 30 Apr 2026 16:47:27 +0000</pubDate>
    <ns246:tag xmlns:ns246="https://concatena.co.uk/feed/1.0">artificial-intelligence</ns246:tag><ns247:tag xmlns:ns247="https://concatena.co.uk/feed/1.0">cat:tech</ns247:tag><ns248:tag xmlns:ns248="https://concatena.co.uk/feed/1.0">cat:tech-ind</ns248:tag><ns249:tag xmlns:ns249="https://concatena.co.uk/feed/1.0">openai</ns249:tag><ns250:tag xmlns:ns250="https://concatena.co.uk/feed/1.0">prompts</ns250:tag><ns251:tag xmlns:ns251="https://concatena.co.uk/feed/1.0">reinforcement-learning</ns251:tag><ns252:note xmlns:ns252="https://concatena.co.uk/feed/1.0">Our Take:  LLMs really do latch onto patterns: OpenAI’s “goblin phase” is a silly example of a serious point – the way you train and reward a model can create odd, persistent behaviours that aren’t obvious from the outside. Model outputs are shaped by hidden system prompts and RL tweaks, not just “the law” or “the facts” you put in. 

Your Takeaway:  If you’re using LLMs in your business, assume they’ll exaggerate any incentive or pattern you bake in, sometimes in unexpected ways. Treat prompts and “personalities” like configuration, not colour – document them, review them, and stop anthropomorphising them...</ns252:note><ns253:highlight xmlns:ns253="https://concatena.co.uk/feed/1.0">Never talk about goblins, gremlins, raccoons, trolls, ogres, pigeons, or other animals or creatures unless it is absolutely and unambiguously relevant to the user’s query</ns253:highlight><ns254:highlight xmlns:ns254="https://concatena.co.uk/feed/1.0">The fix, in part, is a specific set of instructions to never talk about goblins unless it’s abundantly relevant:</ns254:highlight><ns255:highlight xmlns:ns255="https://concatena.co.uk/feed/1.0">The goblin problem links back to the “Nerdy personality” option briefly supported by ChatGPT.</ns255:highlight><ns256:highlight xmlns:ns256="https://concatena.co.uk/feed/1.0">To develop the personality, OpenAI needed to “reward” the model to incentivize its creative use of mythical metaphors. However, even after the Nerdy personality option was retired, the model remained unreasonably attached to gremlins, goblins, and other make-believe creatures.</ns256:highlight></item>
  </channel>
</rss>
