Connect with us

Tech

The next great game may not come from a million-dollar studio

Published

on

TL;DR

The GDC 2026 survey shows 28% of game developers were laid off in two years and 36% now use generative AI. Former Boston Dynamics engineer Robert Brownstein runs Gnarled Helix, a ~10-person indie studio that used AI-assisted development to prototype a chess-resource-management game in days after spending years on a higher-budget project. He keeps AI-generated art out of the production pipeline while using LLMs for coding and ideation, and has built Tauric Tools, a free collaborative level editor.

The economics of making a blockbuster game are starting to look as demanding as the games themselves. Development cycles stretch across years, budgets climb into extraordinary territory, and a single failed release can erase enormous amounts of investment. The industry’s latest workforce data makes the pressure difficult to ignore. 28% of respondents to the 2026 Game Developers Conference State of the Game Industry survey said they had been laid off during the previous two years, while two-thirds of AAA respondents said their companies had experienced layoffs.

The problem is not simply that games cost more to make. Bigger production commitments can also make experimentation harder. Sony’s Concord, reportedly eight years in development, was pulled from sale only two weeks after launch after failing to find an audience, illustrating how quickly an enormous production cycle can collide with player expectations. The lesson is uncomfortable for an industry built around increasingly ambitious bets; scale can magnify both the potential payoff and the consequences of being wrong.

Meanwhile, the tools available to smaller developers are changing rapidly. The 2026 GDC report found that 36% of game-industry professionals now use generative AI in their work, with code assistance and prototyping among its common applications. Yet 52% believe generative AI is having a negative impact on the industry, showing just how unsettled the technology’s place in game development remains.

Advertisement

This tension points toward a consequential question for gaming: if smaller teams can test ideas faster and iterate without carrying the financial weight of a major production, could originality become a more meaningful competitive advantage than production scale?

Robert Brownstein believes it can. His own experience has given him a close view of how quickly development economics are changing.

Brownstein, a full-stack developer who earned a computer science degree in 2014, most recently worked at Boston Dynamics, where he helped build software for Spot, the company’s quadruped robot. He later applied that engineering background to Gnarled Helix LLC, a roughly 10-person studio that grew from a side project he pursued while working at Boston Dynamics. Brownstein notes that moving from web development into game development also changed how he thought about building products, particularly the value of testing an idea before committing heavily to it.

Gnarled Helix LLC
Credit: Gnarled Helix LLC

Rapid prototypes are lower risk,” Brownstein says. “You’re able to produce something that you can verify as fun and meaningful before you spend all this budget on art that maybe no one’s ever going to see.” AI has accelerated that philosophy for his team. Brownstein notes that tools such as large language models have shifted Gnarled Helix toward ideation and prototyping, allowing engineers to spend less time buried in implementation details. He sees AI as useful precisely because human developers remain responsible for understanding and evaluating its output.

Everything we do, AI-wise, is gated by a human. The real constraint is maintaining enough technical understanding to know what the tools are producing,” he explains.

Advertisement

AI’s growing role in game development has also sharpened an older industry question: where does production efficiency end and creative authorship begin? As developers adopt AI for coding, prototyping and other technical work, the debate is increasingly about which parts of a game should remain distinctly human. Brownstein’s approach offers one example of that boundary. At Gnarled Helix, he says AI-generated art does not enter the production pipeline, while game design, graphics and writing remain human-led. His approach reflects a wider concern for an industry trying to absorb advancing tools rapidly without allowing efficiency to become the measure of creative value.

This stringency is visible in the studio’s forthcoming chess project, which emerged from Brownstein’s interest in chess and Satisfactory. The game turns captured pieces into resources that can be extracted, refined, and converted into new pieces, placing a familiar ruleset inside an unfamiliar economic system. Its single-player roguelike mode expands the board across waves while introducing different armies and economies; another mode allows players to use the mechanics in a traditional chessboard setting.

The project also reflects a shift Brownstein sees across the industry. He believes smaller teams can move through experimental ideas without exposing every prototype to the public risk that accompanies major publishers. Gnarled Helix’s own development history gave him a practical lesson in that process: the studio spent years developing a higher-budget programming-learning game, then used AI-assisted development to produce a new chess concept in days.

Game development is also creating demand for tools that can make production more efficient. Brownstein’s Tauric Tools grew from his experience building map-editing systems across several companies, translating that expertise into a free level editor with real-time collaboration and interchange support for formats including AutoCAD drawings, Tiled files, and GeoJSON, with Brownstein considering future white-label applications for other businesses.

Advertisement

The direction of gaming may ultimately depend on how quickly it can discover what players want. Brownstein expects more technically capable developers to move into independent gaming as AI lowers some production barriers, creating opportunities for small teams to attempt projects that would be difficult to justify at AAA scale. His goal for Gnarled Helix follows the same direction. He says, “What I really want to do with this studio is find novel mechanics that people haven’t tried before and try and make games out of them.

If the next generation of developers can combine sophisticated tools with fast experimentation, gaming could become a market where a small team does not need to imitate the production model of a giant publisher to command attention. Success, in Brownstein’s view, increasingly hinges on finding the more interesting idea, testing it sooner, and giving players a reason to keep playing.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Pre-ordering the new Google Pixel 11 range? Score a free PS5 or a Fitbit Air from these telcos and retailers

Published

on

After months of leaks and rumours, Google has officially launched its new flagship Pixel handsets, introducing a wave of hardware upgrades and even a new ‘HiLight’ feature. Also unveiled were a new Pixel Watch and the Pixel Tag, Google’s answer to the Apple AirTag.

Pre-orders have also kicked off in Australia, with retailers and telcos offering a variety of deals, including up to AU$1,000 in savings or some free gifts, depending on which model you’re after.

Retailers JB Hi-Fi and The Good Guys are handing out a free Google Fitbit Air, Pixel Buds and even the new Pixel Watch 5 as part of their pre-order offers, but the most standout deal we’ve found comes from Vodafone, which is offering a free PlayStation 5 console (plus a bonus controller) with select models. With the PS5 seeing price hikes over the past few years, this is an offer not to be missed.

Devices will start shipping from August 20, though pre-order offers are set to run longer — August 26 for the retailers we’ve picked and as late as October 6 for selected telco deals.

Advertisement

The best Google Pixel 11 pre-order deals

The best Google Pixel 11 Pro pre-order deals

The best Google Pixel 11 Pro XL pre-order deals

Advertisement

The best Google Pixel 11 Pro Fold pre-order deals

Source link

Advertisement
Continue Reading

Tech

Siri AI could get a boost from news with new publisher deal

Published

on

Hallucinations are a problem with any AI, especially when it involves summarizing content, so instead, Apple could let Siri AI provide news directly from an outlet via paid partnerships.

The iOS 27 beta is underway, and with it, users can test the new Siri AI. One of the first things users might notice with Siri AI is its tendency to share blocks of text pulled from sources rather than summarizing it.

According to a report from The Wall Street Journal, Apple is reaching out to publishers to enter multi-year deals that would supply journalistic content for use with Siri AI. The details of the deals haven’t been shared, but it seems Apple is seeking a pay-as-you-go model with a possible nine-figure budget for payments.

The model differs from Apple’s previous partnerships with publications and AI training, which involved bulk payments for training datasets. Instead, Apple appears to be planning to pay as content is used, similar to Apple News.

Advertisement

That would mean if a user asks for information regarding a news story or report that is a part of this partnership, the partner would get paid for delivering that content. The user would also benefit from being provided human-written content unaltered from an original source, at least, if it is presented that way.

Given how Siri AI provides direct snippets from sources today, it seems likely that paid partnerships could provide entire articles within the interface. It also would align with how the rumored Apple Intelligence-powered Apple Health tool is expected to work.

Apple hasn’t announced any such partnership just yet, but it could come as a part of the iPhone 18 Pro event in September. The company will be heavily promoting Siri AI and its upgrades as it launches to the public, so a publication partnership would be the perfect thing to announce at the time.

Advertisement

Source link

Continue Reading

Tech

Four of five enterprises that secured AI agent identities still can’t contain one that goes rogue

Published

on

Visa’s president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic’s Mythos at Visa’s own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.

That’s what it looks like when an enterprise has the engineering depth to act on what it finds. Most don’t get there. Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.

Leaning on provider-native controls to do the heavy lifting of agentic security just exacerbates that gap. The July wave of VentureBeat Pulse Research found that 92% of enterprises naming a primary security layer default to their hyperscalers and AI platform providers.

Six waves of research have been completed since January, surveying 440 qualified enterprise security respondents. The key takeaway: the containment gap between what enterprises need and what’s getting done is growing wider, often unaddressed by enterprises whose agentic AI investments and futures are at risk.

Advertisement

The satisfaction data doesn’t match the incident data

The research keeps showing enterprises rating the tools they know best at a higher score, even if those tools failed them or delivered mediocre results. Three findings from the raw data cut against that instinct, and each one says something about how young this market still is.

The enterprises that got hit rate their tools higher than the ones that didn’t

Last month’s survey found that 46 enterprises reported a confirmed incident or near-miss, then went on to rate their satisfaction with their security tooling. Their average satisfaction was 4.39 out of 5. 30 of the 55 enterprises who experienced no incidents rated their security tooling at 4.13. Enterprises are rewarding any tool that saves them from a breach with a trust premium.

It’s a sure sign of a nascent market when brand positioning, marketing, or other means of persuading enterprises get easily superseded by saving a customer from a breach. Near-misses outnumber confirmed incidents 2-to-1 in both June and July, which means enterprises are catching problems at the edge. That edge catch is being interpreted as validation of both the security strategy and the tools acquired. Evident through seven months of data is how quick enterprise security leaders are to trust a new tool that identifies an intrusion or breach and defeats it before it gains access. VentureBeat believes the rescue itself is doing the marketing. The 4.13 average among never-hit enterprises shows the other side of the same effect. Tools that have never been seen working earn less trust, not more.

Advertisement

VentureBeat also found that of the 17 enterprises isolating their highest-risk agents, the 14 that rated their tooling average 4.00. Enterprises that do not isolate rate it 4.35. The enterprises closest to real security are the least satisfied with their tools — that dissatisfaction is what drives them toward the kind of engineering effort Visa put in.

65% of enterprises are enforcing AI agent permissions at runtime. Just 18% can contain an agent if enforcement fails

The satisfaction ladder. Enterprises that built isolation rate tools 4.00. Enterprises that experienced an incident rate them 4.39. VentureBeat Pulse Research, July 2026, respondent-level analysis, n=76 who rated.

Four of five enterprises that solved identity did not build isolation

49%, or 57 of the 116 enterprises surveyed in July, gave each agent its own scoped, managed identity. Just a month earlier, VentureBeat’s June wave recorded 32% of enterprises having assigned per-agent identities. July’s 17-point jump in one month is the fastest single-month move this series has recorded. Despite these gains, 63% still report credential sharing somewhere in the fleet. Only 11 of those 57 also isolate.

Advertisement

That ratio explains why the containment gap keeps widening even as every headline control improves. Enterprises are treating identity and isolation as substitutes. They need to see the longer-term vision of each being integral to a platform-based, layered strategy. Two incidents VentureBeat has covered show why that distinction matters. A rogue AI agent at Meta passed every identity check before its March exposure was contained. And CrowdStrike CEO George Kurtz disclosed, at his RSAC 2026 keynote, a Fortune 50 agent that rewrote its own security policy using valid credentials. Giving an agent scoped credentials does not bound the blast radius when those credentials are misused. Sandboxing does.

The enforce-without-isolate population has a 58% incident rate

Fifty-three enterprises in July’s survey enforce scoped permissions at runtime but do not isolate. 31 of those 53 have already had an agent security incident or near-miss. That is 58%, five points above the 53% sample average. The enterprises living inside the containment gap are getting hit more often than the enterprises outside it.

Amy Chang, Cisco’s head of AI threat intelligence and security research, presented findings on the Transform agentic security panel showing that when Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through up to 88.3% of the time. Single-turn red-teaming missed it. An adaptive attacker who defeats the guardrails lands inside whatever architecture sits behind them, and for 53 of the enterprises in this data, that architecture enforces but does not contain.

Advertisement

VentureBeat’s Q1 Pulse Research tracked the same structural weakness earlier this year. Unauthorized tool or data access ranked as the most feared failure mode in every Q1 survey, growing from 42% in January to 50% in March. The April-May survey found only 4% of enterprises comfortable relying on model guardrails alone. Enterprises predicted they needed external controls, choosing to build enforcement over containment.

Enterprises built enforcement 35 points ahead of forecast. Isolation barely moved

The April-May survey asked 109 enterprises how they expected agent behavior to be controlled by the end of 2026, and 30% predicted runtime enforcement, 14% sandboxed execution, and 32% model-level guardrails. By July, 65% had built enforcement, more than double the prediction, while isolation reached 18%, roughly the rate they said it would. Enterprises built what was easy at twice the forecast and built what was hard at roughly the forecast. The April question asked for the primary control mechanism, single-select, while July’s posture question allowed multiple selections, so the comparison is directional rather than exact.

65% of enterprises are enforcing AI agent permissions at runtime. Just 18% can contain an agent if enforcement fails

Three quarters, one gap. Q1 threat prediction, Q2 forecasts, and the June-to-July build-out in which every control improved except isolation. VentureBeat Pulse Research, seven waves, Jan-Jul 2026.

Provider lock-in accelerated across all three quarters

Provider-native platforms already led usage in April-May, named by seven in ten enterprises describing their tooling. By June, 82% called one their primary agent security layer, and by July that share reached 92%, with OpenAI’s guardrails leading at 44%, Microsoft Azure at 42%, Anthropic’s managed-agent controls at 37%, and Google Cloud at 31%. Cloudflare at 11% and Cisco at 9% lead the dedicated specialists fighting over what remains. The identity tools most relevant to the credential-sharing gap are the smallest of all, with Microsoft Entra Agent ID at 7%, while Okta for AI Agents, non-human identity platforms, and runtime sandboxing tooling each sit at 3%. CrowdStrike CTO Elia Zaitsev told VentureBeat at RSAC 2026 that observing agent actions is a solvable problem but inferring intent is not. The provider bundle proves his point, solving observation while leaving containment unbuilt.

Advertisement

74% plan to replace tools they just rated a career-high satisfaction score

Satisfaction scores continue rising as enterprises gain more experience using tools and techniques to stop agentic AI-based attacks. Rising to 4.29 out of 5 in July from 4.2 in June, satisfaction is the highest reading in the series.

Despite the high satisfaction levels, 74% plan to replace their tools within 12 months, up from 59% in June. Only 26% intend not to change. VentureBeat believes early adopters are impatient to gain greater insights, and know what they don’t know about agentic security and resilience. Closing that knowledge gap is forcing churn into a market this young, and the raw answers resolve the paradox: 92% of enterprises naming a primary layer name a provider-native one. The 4.29 measures how easy it is to turn on a provider’s guardrails. It does not measure how effective those guardrails are at preventing the incidents 53% of the same respondents already had.

The organizations closest to the threat are the least confident about it

In June, defenders led attackers 35% to 21%, but by July the split was 30-30, a dead heat. Among enterprises that have been hit, 39% now say attackers are ahead, against 20% of those that have not. Getting hit nearly doubles the pessimism but does not change the shopping. Just 10% of enterprises include any agent-identity product in their consideration set. Runtime sandboxing draws 6%, and those numbers hold regardless of incident history. VentureBeat covered the same blind spot in the June data. The label changed from agent security gap to containment gap, but the shopping did not.

Methodology

The posture question was answered by 93 of the 116 qualified July respondents, and the skippers are not hidden isolators. Twenty-three of the 25 who selected no posture option are organizations still evaluating agents, unsure of their status, or with no deployment plans, groups for which a security posture largely does not yet exist, so the 18% isolation figure reads on the enterprises actually running or piloting agents. April-May, June, and July are separate, independently fielded waves rather than a single tracked series, so month-over-month comparisons in this piece are directional rather than a measured trend. Base sizes for the cross-cuts differ by instrument. The identity question covers all 116 respondents, isolation covers the 93 who described a posture, and the satisfaction inversion of 4.39 versus 4.13 is computed on the 76 respondents who rated their tooling.

Advertisement

The bottom line

VentureBeat’s cross-survey analysis of 573 enterprise respondents concluded in July that enterprises deployed AI agents ahead of the controls needed to manage them, and they did it knowingly. Three waves of security-specific data now show where the knowing stops.

Enterprises continue giving agents scoped identities and treating that as containment, but that assumption is false, and the incident data keeps proving it. In fact, 46 of 57 enterprises that solved identity did not build isolation. The enforce-without-isolate population’s 58% incident rate is the clearest evidence that identity alone isn’t enough. The containment gap will not close through satisfaction with what is easy. Whether enterprises build isolation and governed identity deliberately, or whether a confirmed incident that propagates does it for them, is the question the next wave will answer.

Source link

Advertisement
Continue Reading

Tech

Redditor turns Android phone into a desktop PC in a stroke of genius, sandwiching it between two huge CPU coolers so it runs Witcher 3 at 1080p ultra

Published

on


  • A Redditor has turned their phone into a desktop PC, sort of
  • This involves jamming the device between two hefty CPU coolers
  • The results are seriously impressive, including running PC games at playable frame rates on a Linux desktop

Have you ever thought about using your phone as a PC? A creative hardware modder has taken this idea very literally, actually turning their smartphone into a makeshift PC by jamming the device inside a custom case, sandwiched between a pair of beefy desktop CPU coolers.

Wccftech spotted a Reddit post with a title that provides a succinct summary of the achievement here: “I turned my Nubia Z70 Ultra into a desktop PC with TWO CPU coolers – 99% stability, Linux desktop and 1080p Ultra Windows gaming.”

To break this down, what the Redditor (‘ntsow’) has done is take the Nubia Z70 Ultra, an Android phone, and remove the screen. The display was transferred to the front of a custom-made acrylic case, and the phone itself was placed between two big old processor coolers, as mentioned, with direct contact on the Snapdragon chip’s shielding (for the maximum cooling effect – which is why the screen must come off).

Latest Videos FromTechRadar

Android Phone in a Desktop PC, side view showing phone between two CPU coolers

(Image credit: ntsow on Reddit)

On the software side, the Redditor explains: “I’m running a full XFCE Linux desktop through Termux, with GPU acceleration, plus Windows apps/games. The goal is basically to use the phone as the whole PC.”

Advertisement

Source link

Advertisement
Continue Reading

Tech

Not Ready For Prime Time: The Current State Of Legal Ethics And AI

Published

on

from the there-be-dragons dept

I’ve been presenting at UC Law San Francisco Lexlab Law and AI certificate program its past several sessions, as well as some law school classes, on whether lawyers’ use of AI complies with the rules of professional conduct governing how lawyers must comport themselves or risk losing their licenses. The legal industry is keen to reap many of the benefits AI promises, such as streamlining some of the more arduous parts of the job and potentially making legal representation more affordable and/or profitable. And tech vendors are keen to profit from selling their AI systems to this market.

But neither constituency can benefit unless the way AI is used is consistent with those ethical rules. They exist for a reason—to make sure clients’ interests are prioritized and protected—and nothing about AI obviates their need or applicability. As lawyers start to roll these tools into their practice they need to make sure it’s not in a way that violates those rules, and for those vendors eager to sell their tools to the legal profession, they are going to need to make sure they are designed in a way where their use does not.

And we are not yet at a place where compliance can be presumed when AI tools are used. AI use by lawyers remains highly problematic for at least two big reasons: the current unreliability of AI outputs, and the tendency for AI to consume, store, and reuse data it is exposed to, even if that data needs to remain private. With regard to the former issue, the reliability concerns go beyond just the problem of hallucinated citations appearing in legal briefs; it is still the case that clients hire lawyers for their judgment, which so far AI still cannot replace. Maybe someday if AI has developed into something truly autonomous we could simply demand that it take the bar and be accountable to clients like human lawyers currently are, but since that day is not yet here it is critically important that lawyers not abdicate their own judgment in favor of whatever an AI tool might produce. Clients are depending on them, their lawyers, and they remain fully accountable to serve them as the profession requires.

And with regard to the data protection issue, it remains true for any tool lawyers use, AI-based or not: lawyers need to make sure that the tool use does not compromise client information, which they have a duty to protect because really bad things can happen to the client when privacy is not preserved. But AI tools in particular are notoriously greedy about collecting, retaining, and reusing whatever information they can access, unless they are specifically designed not to do so. It is thus critically important for lawyers to make sure that whatever tool they use—including and especially an AI tool—does not have the ability to mishandle or misappropriate client data to which it is exposed.

Advertisement

Each of these major issues then reverberates in a number of the specific ethical rules governing lawyers that they need to abide by. What follows is a closer examination of some of the ways they do.


There are a few things to note at the outset. First, there are more rules governing lawyers than what have been included in the analysis here, such as those relating to the duty to uphold the reputation of the profession, or those relating to advertising, which AI can also implicate. But the ones included are some of the major ones and examples of how AI use can rule afoul of them.

It’s also important to note that the rules can work together, and sometimes are in tension. The duty of zealous advocacy, for instance, can sometimes be at odds with the duty of candor. But AI does not itself resolve those ethical questions. Instead what is important to realize is that an AI use might implicate more than one rule.

As for the rules themselves, although they are rooted in some longstanding principles, what governs lawyers today are a set of model rules the American Bar Association promulgated in 1983 and pretty much every state has since adopted in some form. Because they can vary somewhat in how they were adopted by each state, lawyers need to consult the specific language their state has used to know how the rules apply to them, along with any other guidance and commentary their state’s lawyer regulators have produced. In fact, many states are also busy updating this guidance in order to specifically apply it to lawyer AI use (as is the ABA). But the basic gist of each rule is largely the same for all lawyers and based on the model language articulated by the ABA originally.

Advertisement

These rules also apply to all lawyers and not just litigators. Even transactional, or deal-making, lawyers need to follow them, and so do in-house counsel, who still have clients they owe duties towards, even if it is just one client. So when they declare, on behalf of their client—as, alarmingly, many have—that they will only hire law firms that use AI it is fair to question whether such a priority is indeed consistent with their ethical duties. Perhaps in individual circumstances such an AI-using firm might be preferable, but it won’t be universal; it will depends on the task the lawyers are being engaged to help with and what specific tools they are using. It would after all be contrary to the client’s interests to engage a firm that used an AI tool that compromised the confidentiality of the client’s sensitive information. Plus there remains the question of whether the AI tool being used is really one that can help the job get done in a way that can be trusted, let alone with the savings the client is hoping to see, given the time needed to verify its output.

Rule 1.1: Competence. If you are going to be engaged as a lawyer, you must make sure you know how to do the job, however you find yourself called to do it. Traditionally the duty of competence has, for example, meant that a lawyer could not take on a matter in an unfamiliar area of law, like criminal defense when they were an estate planner (or vice versa), but the rule is not limited to just those situations. Case hallucinations strike at the heart of it, for instance. If you are advocating for a client, you need to know the law relevant to the client’s situation, and if you are submitting hallucinated cases that don’t exist, it strongly suggests that you do not, or else you would have known they were imagined. Which is one reason AI cannot suddenly expand the types of matters a lawyer can take on—it’s simply not reliable enough on its own. The lawyer will still need to know when it is giving good answers and when it is not, but if the lawyer does not already have that competence themselves, then they won’t be able to make that determination.

There is also a related concept that is becoming more and more important to the legal profession: technical competence. Do you know how to effectively use the tools you are using? The answer needs to be yes, particularly to ensure that your tool use is not creating problems you were not aware of, especially with respect to protecting client data. As discussed further below, lawyers have a duty to protect client information, which means they need to know how to use their digital tools properly to ensure it remains protected. Concerns about technical competency predate AI, given the risk of potential hacker exfiltration, but they apply just as readily to an AI system exposed to client data that may then train on it.

Rule 1.3: Diligence. This duty goes hand in hand with the duty of competency but requires a bit more. It’s a lawyer’s job to do the job. And the whole job, not just the bits of the job they like best. One supposed promise of AI is that it can increase the volume of matters a lawyer can take on. But can it actually? Because on each matter it will still be the lawyer’s judgment on the line. So while AI might offer some time savings on certain tasks associated with a representation, and that might seem to create capacity to take on more matters, the lawyer will still need to have the bandwidth to competently provide any representation they’ve been engaged to provide. There are physical limits to what one lawyer can do, even with the help of AI, and especially given that they still need to be able to review whatever results an AI tool might give them to help along the way and that supervisory function will also require time.

Advertisement

This diligence rule also incorporates the general lawyer duty of zealous advocacy. Before relying too heavily on an AI tool, one needs to ask whether an AI can actually itself deliver zealous advocacy. Can it deliver all the strategic thinking needed to look out for the client and their objectives in evolving circumstances? And would whatever it recommended also comport with the rest of the ethical rules? If the AI can’t meet all those requirements—and it’s doubtful whether any truly can right now—the lawyer will still need to.

There is also a new wrinkle developing with respect to this rule and case hallucinations: increasingly courts are imposing a duty on litigators to police their opponents’ briefs for false citations. If they do not, they may not be able to recover fees for litigating against the fiction once they are finally brought to the court’s attention. Diligence appears to now require that sort of review (although in some instances it is framed as part of the duty of competence).

Rule 1.4: Communications. Clients are entitled to be kept apprised of how things are going with their representation and be able to contribute to it. On the one hand, if AI does create some time savings for lawyers, it may help ensure they have more time to communicate with clients. But if AI is used in a way that replaces lawyer judgment, and, worse, is applied to tasks where it performs them in a way that lacks adequate transparency, then clients won’t be given enough information such that they can assist with their own representation. The lack of transparency is especially an issue for agentic AI, where instead of manually working with an AI a step at the time the lawyer is trusting the AI to do a more complex task, because the AI may not even realize that it needs to report out what it has already done and be able to get more input before proceeding.

Furthermore, applying AI to client communications themselves also raises the risk of exposing confidential client information. Such a task would inevitably require the AI to learn about the client in order to know what to tell them, but if what it learns does not stay local to the law firm then its confidentiality is no longer protected.

Advertisement

Rule 1.5: Fees. This rule requires lawyer fees to be reasonable, which some have suggested may require using AI. The thinking is that if technology makes some lawyer tasks more efficient, it would be unreasonable to bill for the time taken to perform the tasks without the technology. And as a general proposition this view may be correct: we may, for instance, no longer consider it reasonable to bill for the time needed to research in a law library when so much information is now digitized. But it does not follow that using AI is similarly necessary to use, especially not when there are so many issues still associated with its use. Indeed, it’s even questionable whether it can provide true savings given that lawyers must still take the time to review anything resulting from an AI tool before it is relied upon. Perhaps in some in some situations there can be a savings, but, given the current state of the technology, the savings are not nearly certain enough at this point to support the inference that AI use is something that must be implicitly required.

There also is a side issue of when the costs associated with AI use can be passed through to a client. The answer may depend on guidance from the specific state regulating the lawyer, but there is some precedent, from the period when lawyers started regularly adopting Lexis and Westlaw research tools, and on fixed subscription rates, that technology services that are paid at a flat rate cannot be pro-rated among clients, and only costs directly associated with a client’s representation can be passed through to the client on their bill, at least not without the client’s prior written consent.

And it should not need to be said, but apparently, given some known cases it must be: if the AI use does in fact result in a time savings, then the client gets the benefit of those savings. Lawyers cannot bill for the time it would have taken to perform the task without the AI, only the time it did take, even if it went faster thanks to the AI.

Rule 1.6: Confidentiality of Information. This rule, in many ways, is the ballgame. If a technical tool, including AI, cannot protect the confidentiality of client communications, then it cannot be used by lawyers.

Advertisement

This rule is broader than attorney-client privilege, although AI that doesn’t protect client confidentiality may fail to protect attorney-client privilege as well. The principle behind this rule is that clients can’t get effective representation from their lawyers unless they can be candid with them. Which means that lawyers end up as vessels for all sorts of sensitive information that clients need to feel safe divulging. This rule helps make it safe for them to divulge it. It also applies to any information a client divulges, including their identity. If any such information is going to be shared with an AI, it can only be with an AI tool that can be trusted to maintain its secrecy, which means likely not uploading it anywhere and certainly not using it for any later purpose that won’t be local, such as training.

Which right away means that general purpose, freely available AI tools more than likely are unsuitable for legal work. There has already been at least one judicial ruling finding that the terms of service of one such tool dispelled any reasonable belief that confidentiality would be protected. It is incumbent on lawyers—including as part of their technical competency—to review the terms of service and privacy policy of whatever AI tool they want to use to understand if there’s any danger of information associated with the client’s representation leaving the control of the lawyer. It will also likely necessitate lawyers using only paid versions of AI products in order avail themselves of ones with terms of service that are adequately protective—and it will need to be only the right paid product, as there can be critical differences in privacy practices even among one vendor’s family of paid products. Which does unfortunately raise the issue that it may be only large law firms who will be able to afford using AI products that provide adequate assurance on an enterprise level, and smaller firms only able to afford “business” packages will be left out of being able to use AI.

There is also the unfortunate situation that clients may already be inadvertently waiving their own potential attorney client privilege by uploading information to AI systems—especially free ones—to ask them questions or even just have them collate their information into a more usable form. In addition to the issues associated with relying on the AI’s output, it means their private business may have just been absorbed into the larger system and now be discoverable by others. This ship may be sailing before clients engage their lawyers, but once engaged lawyers may have an obligation to educate their clients not to use AI this way because it risks losing attorney-client and work product protection, and as a practical matter may make information findable by an adversary. In fact, consider whether as part of a lawyer’s zealous advocacy they might have the obligation to ask AI about their opponent’s business, to see what information has already been revealed. On the other hand, lawyers should be aware that courts are considering whether their own AI prompts may be discoverable. Perhaps not, as work product or privileged, but it is an evolving area.

Rules 1.7-1:11: Conflict of Interest. Conflicts of interest are of serious concern to the lawyering profession. We need to make sure that lawyers are committed to zealously advocating for their clients and not pull their punches out of a sense of loyalty to someone else or some other interest. How AI may implicate these rules is something still developing, but one way to be aware of again relates to protecting client confidentiality, because it is conceivably possible that if an AI trains on client information, it may learn sensitive information about that client that later AI use may reveal, possibly in a context adverse to them.

Advertisement

Rule 3.3: Candor toward the Tribunal. This rule is about the integrity of the legal process. We’ve built a system where the idea is that with all the facts and law on the table, we’ll be able to reach a just conclusion. Reality may or may not be so simple, but this rule is about making sure the process has the best quality of facts and law available to it.

On the facts front, concerns are coming up more often, such as in the context of AI-generated police reports, and we’ve even had occasions where expert reports ended up with hallucinations, and another occasion where a lawyer was just trying to get AI to format a citation, and instead the AI went ahead and hallucinated a whole cited source. There is also a report from Brazil where a lawyer wrote a brief with hidden white-on-white text intended to do an injection prompt on any AI system the brief was run through. The court deemed it an act “offensive to the dignity of justice” and the lawyers were sanctioned.

And then there is the question of hallucinated law, which seems to be an epidemic. Note that the issue here is not just invented citations for fake cases but bad summaries of holdings from actual cases, or otherwise invented quotes. Even taking AI off the table this rule about candor already obligates a lawyer to disclose to the court adverse authority. This obligation persists even in the face of the duty for zealous advocacy, although it can provide an opportunity for effective advocacy to be so candid because if that adverse authority is out there, the opponent might dig it up, so the duty to be candid gives the lawyer the ethical space to get out in front of it and try to minimize its effect. But the point of this rule is to make sure the court has the benefit of all the law it needs to consider in reaching a just result, which is why it would violate it to give it hallucinated law that at best obscures applicable law, if not outright deceives the court.

The strange thing though is that it apparently needs to be said that not only should lawyers not deceive courts by submitting briefs with hallucinated citations, but, once called out for it, the solution is not to double-down and submit even more hallucinations in briefs arguing why the lawyer should not be sanctioned for the first hallucinations. Oddly, such behavior seems to be happening a lot, and these cases are where the resulting sanctions have so far been most severe.

Advertisement

Rule 3.4: Fairness to Opposing Party and Counsel. This rule joins the duty of candor to also help make sure our adversarial system can function. But it applies to more than just legal filings; it is intended to discourage obstructive strategy altogether, including by not depriving opponents of evidence they are entitled to.

Which matters, because one use of AI is in support of document review and production. Quicker and more cost-effective document review is a white whale many hope AI can finally slay, but there is a danger in presuming that it has already replaced the need for human review. It may be able to make it more efficient by clumping up documents based on the likelihood of them being relevant or privileged, but there are consequences to not getting attorney judgment to make the final call, including potentially waiving privilege, overproducing, or under-producing and ending up subject to sanctions. And the risk remains: as the AI is learning, what is happening to the client information it is learning?

Rule 5.1: Responsibilities of Partners, Managers, and Supervisory Lawyers. It is not enough for a lawyer to just be ethical on their own; they are also responsible for the ethical conduct of those who work with and for them. Courts are increasingly sanctioning not just lawyers who have submitted briefs with hallucinated citations but also their bosses and law firms, as well as co-counsel. Law firms need to have policies about what AI use is acceptable and make sure everyone is trained on it, which also means that if someone wants to use a new tool, it has to be vetted first to make sure it can be trusted by any lawyer at the firm. Furthermore, lawyers need to be judicious about what other lawyers they co-counsel with or sponsor for pro hac admission to their local court, because any name on a brief will be responsible for its content.

This supervision obligation is also why lawyers cannot simply rely on output an AI tool generates; they must verify it. And they must use non-AI systems to do it, so that if bad information has corrupted the original AI tool, the system that’s used to verify the results won’t be vulnerable to the same corruption.

Advertisement

Rule 5.3: Responsibilities Regarding Nonlawyer Assistance. Supervisory duties do not just involve other lawyers; lawyer are also responsible for non-lawyers who work with and for them. For instance, if a firm secretary steals client funds, the lawyers are on the hook, because it is there duty to make sure such things don’t happen. It also means they need to manage vendors that they would outsource any work to, such as printers and document review vendors, as well as any technology vendors, including AI vendors, all of whom need to be vetted to see if they can be trusted with the sensitive material they will inevitably work with.

Rule 5.4: Professional Independence of a Lawyer. There’s also a rule that law firms can’t be owned by non-lawyers. The reason for this rule is the same as the reason for the conflicts of interest rules: it is critically important that lawyers have no incentive to do anything but zealously advocate for their clients. The fear is that, if firms could be owned by non-lawyers, then the profit pressures felt by owners without these other ethical concerns would overtake that client-first orientation. But especially in periods, like now, where there’s a gold rush to invest in certain technology and offer equity and other financial incentives to underwrite it, there ends up being a lot of pressure put on this rule, with lawyers being tempted to sell equity stakes in their firms, and non-lawyers being keen to buy them. But the rule exists for a reason. Legal representation is so important to liberty and due process that a right to it is enshrined in the Constitution. Whereas no one is owed the profession as a profit center, nor could society afford for it to be recast as a normal profit-seeking business, which would come at the expense of the critical constitutional purpose we need it to serve.

Rule 5.5: Unauthorized Practice of Law. The unauthorized practice of law is ultimately defined mostly by local law, but the model rules themselves say that only those with licenses and subject to bar regulation are entitled to practice law. There have already been instances with some AI vendors trying to be hired to advise and litigate cases, in pretty clear contravention of this rule and associated local law. Plus there are states trying to pass bills preventing chatbots from dispensing legal advice.

The tricky thing is that it’s not always clear what is meant by dispensing legal advice. And there is some tension between these rules and access to justice concerns—in some situations it may perhaps be better to have a non-lawyer with some relevant expertise help people, rather than them potentially going without any support at all. But non-lawyers could get clients into a lot of trouble with ill-informed advice, and the same danger exists with AI. Some of these new tools, especially when well-designed for the legal realm, may be useful. But some, especially those of general purpose, are frequently terrible, and yet people still try to use them for legal advice and depend on unreliable if not completely wrong advice—in addition to risking the disclosure of private information in ways that may also tempt trouble.

Advertisement

In any case, lawyers certainly shouldn’t be letting AI tools dispense legal advice through their practice. When they get output from an AI they need to make sure it is output that is appropriate to rely on. Which is why the idea of AI providing significant savings seems such a dubious proposition, because either the lawyer is spending the time researching themselves, for instance, or, consistent with their supervisory duties, they are spending the time reviewing the research the AI produced, and in a system that itself is not AI and thus subject to the same information corruption issues.

AI is not yet in any sort of fit state where anyone can afford to rely on what it produces as the final, correct word on anything. Maybe someday it will be, but until we are sure that day has arrived, the ethical rules governing lawyers prevent clients from being unwilling beta testers. Even when lawyers get knowing, written consent from clients to use AI—which would be a best practice anyway—there are still pitfalls everywhere. And even if AI use is something clients may think they want, it may still be something lawyers are obligated to advise against.

Filed Under: ai, ai ethics, lawyers, legal ethics

Advertisement

Source link

Continue Reading

Tech

Terabytes of credentials leaked in massive supply-chain attack

Published

on

The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

Advertisement

“The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

Post updated to add image.

Source link

Advertisement
Continue Reading

Tech

Tiny 150M AI model runs 11X cheaper than ChatGPT while solving reasoning problems without generating endless chains of thought

Published

on


  • A 150M model reached 29.5% while costing just $0.0007 per task
  • ChatGPT scored higher, yet its comparable reasoning runs cost substantially more
  • BDH-CQ performs reasoning internally instead of generating lengthy intermediate text

Pathway, an AI lab focused on building Post-Transformer architectures, has released new benchmark results for its BDH-CQ reasoning model.

According to the researchers, their 150M-parameter model scored 29.5% pass@2 on the public ARC-AGI-1 evaluation set.

Source link

Continue Reading

Tech

PlayStation Plus just added two of the best games you can play right now

Published

on

Sony has confirmed the next batch of games coming to the PlayStation Plus Game Catalog in August, and there are two particularly great additions. Helldivers 2 is available through the service for the first time, while the excellent Kingdom Come: Deliverance II joins later this month.

The two games offer very different experiences, but both are among the most notable releases of the past few years.

Two very different games headline August

Helldivers 2 launched in February 2024 and quickly became one of the biggest multiplayer breakout hits of the year. More than two years later, it still has a healthy player base. PlayStation does not publish active player numbers, but SteamDB shows close to 100,000 players currently active on PC alone as of writing this article.

Kingdom Come: Deliverance II, meanwhile, is almost the complete opposite. The sequel to 2018’s critically acclaimed Kingdom Come: Deliverance is a story-driven, single-player open-world RPG with heavy survival and simulation elements. Our review called it a “magnificent medieval masterpiece,” praising its story, freedom of choice, combat, and enormous medieval world.

There are plenty more games coming

Hell is Us is another notable addition, which offers a darker action-adventure with intense melee combat, exploration, and environmental discovery. Vampire Survivors, which became a breakout indie hit in 2022, is one of the easiest games on the list to lose hours to. It has simple controls, offers constant progression, and a basic 30-minute survival run can always turn into complete on-screen chaos.

The rest of August’s Game Catalog lineup isn’t too shabby either. Sony is also adding Umamusume Pretty Derby – Party Dash, Two Point Museum, Metro Exodus, and Dying Light 2. PlayStation Plus Premium members also get Onimusha: Dawn of Dreams and Disney’s Atlantis: The Lost Empire through the Classics Catalog.

Overall, it’s an excellent month for PlayStation Plus. Helldivers 2 is available to PlayStation Plus Extra members worldwide starting August 12, while the rest of the lineup arrives on August 18 unless Sony notes otherwise.

Advertisement

Source link

Continue Reading

Tech

Why Do Some US Roads Have Two Different Speed Limit Signs?

Published

on





The first national speed limit law limiting speed to 55 mph was enacted in 1974 by then-President Richard Nixon as part of the Emergency Highway Energy Conservation Act. This was done mostly in response to the OPEC Oil Embargo that started the previous year. However, a byproduct of this new law was a drop in vehicle fatalities, which fell from 4.28 per million miles traveled in 1972 to 2.73 in 1983. 

This national limit was raised to 65 mph on April 2, 1987, after Congress passed the Surface Transportation and Uniform Relocation Assistance Act. It was repealed in 1995, however, returning authority over speed limits back to individual states. This has subsequently led to a tangled web of state-specific laws rife with political and legal complexities. Take, for example, having speed limits that include fractions, speed limit signs that show decimal points, or having two completely different speed limits on the same stretch of road.

After states were given the authority to regulate their own speeds, some implemented Uniform Speed Limits for both passenger cars and heavy trucks. Other states, however, decided to go another route and set different limits for automobiles and semis. This is referred to as a Differential Speed Limit (DSL), and it is one reason why you might see a single road with multiple speed limits listed. 

Advertisement

Do Differential Speed Limits make the roads safer?

As if this writing, only eight states — California, Idaho, Montana, Oregon, Washington, Arkansas, Indiana, and Michigan — still used DSLs, with lower speeds designed to limit big rigs or passenger vehicles towing a trailer or another vehicle. Throughout the 1990s, when several states implemented DSL policies, average speed and crash rates increased regardless of whether a state used DSLs or USLs, suggesting it wasn’t the limits themselves that were impacting driver behavior.

However, others studies do show that reducing speed can impact crash rates. One study from 1964 conducted by a government agency, for example, examined 10,000 drivers and found that vehicles traveling 10 to 15 mph slower than others on the road experienced more traffic interactions. In 2005, the University of Arkansas reaffirmed that a 10 mph differential increased the frequency of traffic interactions by 227%. However, these studies didn’t specifically look at the vehicles targeted by DSLs, like big rigs or towing vehicles.

Advertisement

Interestingly, the United Kingdom raised its national speed limit in 2015 for commercial trucks with a gross vehicle weight (GVW) over 7,716 pounds. This was done to lower traffic interactions, preventing frustrated drivers from making risky passes and overtaking slow-moving trucks. In the U.S., the Owner-Operator Independent Drivers Association supports eliminating DSLs, claiming that roads are safer when all vehicles travel at roughly the same speed.



Advertisement

Source link

Continue Reading

Tech

AI nuclear power firm Fermi finally has a new CEO

Published

on

Fermi, the AI nuclear power firm, has named a new CEO more than three months after firing co-founder Toby Neugebauer from the top executive post.

Fermi said Wednesday it has hired Lee McIntire, an independent member of the company’s board who has held chief executive positions at CH2M Hill and TerraPower, the nuclear power startup founded by Bill Gates.

Fermi America, which was co-founded by former U.S. Energy Secretary Rick Perry, is developing an AI campus in Amarillo, Texas, called Project Matador that will eventually use nuclear reactors to power data centers.

The announcement, along with Monday’s news that it had signed TensorWave as its first binding customer lease for its Project Matador campus, provided a welcome boost to Fermi’s stock. (The stock is up nearly 23% since Monday.) The young company took a hit in April when Neugebauer and CFO Miles Everson were pushed out of the company. At the time, the company described the executive shakeup, along with other plans including a corporate headquarters in Dallas, as Fermi 2.0.

Advertisement

“Fermi’s next chapter is a construction and power delivery story, and we believe Lee is the ideal executive to lead Fermi through that process,” Marius Haas, Fermi’s chairman of the board, said in a statement. “The job now is to build on schedule, on budget, and safely. Lee has spent 40 years delivering exactly this kind of large, complex project. He also knows Fermi from the inside, having served on our board through our latest period of growth, and he brings a reputation for integrity that Fermi’s customers, employees, regulators, and neighbors can rely on.”

Source link

Continue Reading

Trending

Copyright © 2025