Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
The issue was discovered by Ax Sharma of Manifold Security, who says it stems from how the Claude extension determines whether a user intentionally requested one of its built-in tasks.
Chrome extensions with permission to run on a website can inject JavaScript into the page, allowing them to read and modify its contents. This includes changing page elements, reading information displayed on a site, and generating click and keyboard events programmatically.
According to Manifold’s report, the Claude extension listens for click events on a specific page element that launches one of its built-in AI workflows. These workflows are predefined tasks that allow Claude to perform actions in connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
The supported workflows include:
The researchers found the extension accepted JavaScript-generated click events without verifying whether they originated from a real user.
When a browser generates an event from a real user action, such as a mouse click or key press, it marks it as trusted by setting the Event.isTrusted property to true. However, if JavaScript is used to generate the event, the browser automatically sets Event.isTrusted to false, allowing webpages and extensions to distinguish between real user interactions and events generated by JavaScript.
According to Manifold Security, the Claude browser extension did not verify that a click event originated from a real user by checking the browser’s Event.isTrusted property before executing one of its predefined workflows.
Instead, a malicious extension with permission to modify content on the ‘claude.ai’ domain could inject a page element containing one of nine supported task identifiers and generate a synthetic click event.
Although the browser correctly marked the event as untrusted, Sharma says the Claude extension treated it as a legitimate user click and executed the requested AI action.
The researcher notes that the flaw does not allow arbitrary prompt injection, but instead, the attack is limited to the nine predefined tasks built into the extension.
The attack also does not allow a website to compromise the Claude extension directly, but requires an attacker to trick a user into installing a malicious extension that can execute code on claude.ai.
That extension could then manipulate the webpage and trigger the Claude extension’s workflows.
While a malicious browser extension already has broad access to webpages it can run on, the researchers say this flaw allows it to abuse Claude’s authenticated access to various connected services.
The impact depends on the Claude extension’s configuration and whether users choose to approve sensitive actions or have Claude’s optional “Act without asking” setting enabled, which allows predefined workflows to execute automatically.
In a second finding, the researchers found an internal ‘skipPermissions=true‘ parameter that bypassed certain permission checks when launching the extension.
However, they acknowledged that the mechanism was not directly exploitable on its own and would require another vulnerability to create a specially crafted URL.
The researchers reported both findings to Anthropic through the company’s bug bounty program. Anthropic acknowledged the reports and closed the synthetic-click report, stating they were already tracking it as a broader issue. The second flaw, involving the internal skipPermissions=true parameter, was classified as informational.
Manifold says the flaws are still exploitable in the latest version, 1.0.80, of the browser extension, released on July 7.
“Manifold verified July 7 that both findings remain reproducible in 1.0.80. The content script and side-panel handlers we cited are byte-identical to the v1.0.72 source,” reads the report.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get caught up on the latest technology and startup news from the past week. Here are the most popular stories on GeekWire for the week of July 12, 2026.
Sign up to receive these updates every Sunday in your inbox by subscribing to our GeekWire Weekly email newsletter.
Stardew Valley, the blockbuster farming sim from solo Seattle developer Eric “ConcernedApe” Barone, is coming to Magic: The Gathering via a three-part Secret Lair drop from Renton-based Wizards of the Coast — with original pixel art from Barone himself. … Read More
F5 names former Amazon executive as its chief people officer; Rudra Mitra departs as a Microsoft CVP after more than 27 years; and Qualtrics adds leaders. … Read More
Dave Brown is leaving Amazon Web Services after nearly 19 years, departing at the end of July for a new role outside the company. … Read More
The AI-generated video is an interesting study in how technology that’s very much being built and hyped in Seattle can be used to illustrate what the city sort of looked like more than three decades ago. … Read More
Apptio co-founders Sunny Gupta and Kurt Shintaffer launched Thira, a Bellevue-based enterprise AI startup, with $21 million in seed funding led by Madrona. … Read More
JPMorgan Chase is building out a new AI software infrastructure team, with a major presence in Seattle, focused on running AI across its data centers and outside providers in a way that controls costs, protects its intellectual property, and avoids tying its fortunes to any one vendor. … Read More
Rina Hahn leaves role as Remitly’s CMO; Temporal promotes Preeti Somal to EVP amid reorganization; and Veeam and Qualtrics make leadership changes. … Read More
Dave Brown, the senior AWS executive whose departure Amazon announced this week, is joining Meta to work on its data center build-out, according to a Wall Street Journal report. … Read More
General Fusion’s stock is trading up after it became the first fusion energy company to go public on a major exchange, debuting Monday on Nasdaq. … Read More
Seattle-area startups raised $2.7 billion in the first half of 2026, down 40% from a year ago, even as U.S. … Read More

Garkus walked into his local Subway and walked out with the exact machines that used to show footlong prices and cookie deals. Staff were swapping the old digital menu boards for newer ones, and the discarded units headed straight into a trash pile until he asked if he could take a few. Three Advantec DS081 media players and four commercial displays later, the experiment began.
These super-slim, fanless boxes sat in a sandwich shop for years, running continuously. They aren’t particularly high-end, but they still have some life in them. Under the hood, there’s a sixth-generation Intel Core i3-6100U processor clocked at 2.3 GHz, four gigabytes of DDR4 RAM that can be expanded to eight if necessary, a 64-gigabyte solid-state drive, and Intel HD Graphics 520. They have the conventional ports: HDMI, USB 3.0, Ethernet, and a micro PCIe slot.
Sale

He began by upgrading the RAM, and one of them received a full eight-gigabyte stick. Then came Windows 10 installation, which loaded quickly and dumped the user to a normal desktop rather than the Subway interface. Then he attempted to install macOS on one of them and was successful, even fooling the system into thinking it was a 2016 MacBook Pro, despite the lack of graphics acceleration. The third one received Bazzite, a Linux distribution created expressly to assist get games operating on obsolete hardware. SteamOS was difficult to get operating since the storage interface was incompatible.

So he fired up Peggle on the Bazzite machine, and it worked perfectly. It’s a good game to have on that system. Then he tried Minecraft, which handled all of the TNT explosions admirably, albeit at a slower frame rate. He even attempted to run Grand Theft Auto V on the Windows PC, but it just couldn’t handle the workload due to a lack of fans and limited power delivery.

Surprisingly, games that don’t require a lot of power appear to run fairly well on these older systems. The compact size and low power demand make it ideal for older console titles such as PS2 and original Xbox games. He dug into the old Subway software, and it appears that they have a huge number of menu templates, complete with files for things like Submelts and big cheese steaks, but no secret treasures, just the standard signage materials.

Then disaster almost struck during testing when one of his testers knocked over a Pepsi, and he believed everything was lost, but it turns out these little computers are incredibly resilient. They continue running even after they have finished serving sandwiches.
Apple’s latest iPad Air is $200 off when you opt for the M4 model with 512GB of storage during Amazon’s weekend sale.
The $200 discount at Amazon brings the Wi-Fi 13-inch iPad Air with 512GB of storage in Blue down to $1,049.
Considering Apple raised prices last month across the iPad line, this deal is highly competitive and comes in within $50 of the lowest price on record.
With a discount this steep, you’ll want to grab the offer now, as inventory is already thinning, with delivery by July 24 for Prime members.
| iPad Air | Specs |
|---|---|
| Screen Size | 13-inch |
| Capacity | 512GB |
| Wi-Fi | Wi-Fi 7 |
| Color | Blue |
| MSRP | $1,249 |
| Discount | $200 off |
| Chip | M4 |
You can also compare prices across the product line in our 13-inch iPad Air M4 Price Guide.
And if you’re in the market for a MacBook to pair with your new iPad Air, Amazon is slashing $400 off Apple’s M5 Max 16-inch MacBook Pro with 2TB of storage.
AI makes it trivially easy for anyone in an organization to deploy internet-facing applications, often outside established security processes. CyCognito CEO Rob Gurzeev says the resulting blind spots are more dangerous than known vulnerabilities. His answer: continuous, outside-in attack-surface mapping that validates what is actually exploitable rather than scanning a known asset list.
Artificial intelligence is transforming how software is built, deployed, and secured. While AI has accelerated innovation across industries, it has also expanded the number of internet-facing assets organizations need to protect. According to Rob Gurzeev, CEO and Co-Founder of CyCognito, the challenge is no longer just identifying known vulnerabilities. It is understanding what is actually exposed, how those assets connect, and how attackers can exploit them.
Drawing on years of experience in cybersecurity and intelligence, Gurzeev believes many organizations still operate with an incomplete view of their attack surface. That gap, he says, is becoming more dangerous as AI makes it easier than ever to create and expose new applications.
Gurzeev’s path into cybersecurity began long before AI entered the picture. As a teenager, he spent time exploring computers and Internet Relay Chat (IRC) communities, where curiosity about hacking first took hold. That interest eventually led him to an intelligence unit, where he worked on reconnaissance and attack-surface operations.
“Honestly, this work chose me more than I chose it,” Gurzeev said. He explained that the role often started with little more than a name and required finding “the path of least resistance into something that mattered.”
Those experiences continue to shape how he approaches cybersecurity today. “I was taught you never actually know what reality is. You have to go find it. Validate it,” he said. “Most of the security industry was built the other way around, on the assumption that you already know where your stuff is. That gap is the whole reason CyCognito exists.”
CyCognito approaches security by working from the outside in, beginning with nothing more than a company’s name. The platform maps everything exposed to the internet, including forgotten or unmanaged assets, then tests those systems to identify weaknesses that could be exploited by attackers.
“In a nutshell, we map everything a company has exposed to the internet, then trace the handful of paths that actually lead to its internal networks and sensitive data,” Gurzeev explained.
Rather than relying solely on vulnerability scans, the platform validates which weaknesses are genuinely exploitable. According to Gurzeev, “If I had to name the one thing that makes us unique, it’s that our platform thinks like an attacker. That should be obvious. It isn’t.”
Modern enterprise environments have grown far beyond what traditional security programs were designed to manage. Gurzeev estimates that a large enterprise typically exposes around 100,000 applications, devices, and cloud assets to the internet, while some organizations have significantly larger footprints.
“Our single biggest customer has around 100 million things an attacker can interact with from the outside,” he said, adding that external attack surfaces change by one to three percent every day.
Despite that scale, many organizations continue to focus security efforts on only a small fraction of their environments. “Most security effort goes to a few hundred or a thousand key assets. What about the rest?” Gurzeev asked. “Guarding the front door while you leave the windows open is not a strategy.”
The rapid adoption of AI has made creating and deploying applications much easier across organizations. Employees outside traditional development teams can now build internet-facing tools using AI-powered coding assistants, often without going through established security processes.
“Today, anyone and everyone can deploy an app,” Gurzeev said. “Someone in HR or finance can spin up an application with a tool like Claude Code or Lovable and expose it to the internet, on purpose or by accident.”
He believes AI has shifted from being a supporting technology to becoming part of organizations’ core infrastructure. “As recently as six months ago, AI was bolted onto the edge of the business. Now it runs through the core, which means these systems aren’t adjacent to the attack surface anymore. They are the attack surface.”
The challenge extends beyond application growth. Gurzeev pointed to research suggesting AI-generated code introduces vulnerabilities at significantly higher rates than code written entirely by humans. More importantly, he argued that much of this software bypasses the secure development processes organizations have spent years building.
“The honest answer is we’re defending more of something less safe, and we can’t yet measure exactly how much. That uncertainty is itself the risk,” he said.
As attackers increasingly adopt AI, Gurzeev argues that periodic assessments are no longer enough. Security teams need continuous visibility into what is exposed, what can actually be exploited, and which issues require immediate remediation.
“Keeping up takes three things, all continuous,” he said. “Know what you have exposed right now. Know which of it an attacker could actually break into, across all of it, not a sample. Fix what matters in hours.”
CyCognito’s latest release focuses on continuous AI security testing by combining full attack surface discovery with AI-powered validation. Rather than limiting advanced testing to a small number of high-priority assets, the platform maps an organization’s entire internet-facing environment before applying AI where reasoning is needed most.
According to Gurzeev, the platform continuously performs more than 100,000 automated checks for known issues, allowing AI to focus on identifying complex attack paths that conventional scanners often miss. As those attack chains are validated, they become repeatable automated tests, expanding coverage over time.
Looking ahead, Gurzeev remains optimistic that defenders can regain the advantage. “The winners won’t be the ones who spend the most,” he said. “They’ll be the ones who use it most efficiently, getting the most out of every dollar of compute by pointing it with context instead of running it blind. Do that, and defenders catch up.“
Apple discontinued the Mac Pro earlier this year, ending a 20-year run for a computer that once represented the very best of the company’s desktop lineup. However, Apple reportedly had much bigger plans for the machine before ultimately replacing it with the Mac Studio.
According to Bloomberg’s Mark Gurman, Apple developed an M3 Extreme chip that could have offered twice as many CPU and GPU cores as the M3 Ultra. The processor was intended to sit above the Ultra tier and could have finally given the Mac Pro the performance advantage it badly needed. Apple eventually abandoned the chip due to concerns over production costs and limited demand for such an expensive machine.
Rumors about an Extreme-tier Apple chip first appeared in 2022, when Gurman reported that the company was developing an M2 Extreme for its first Apple silicon Mac Pro. The processor was expected to feature as many as 48 CPU cores and 152 GPU cores, double the rumored M2 Ultra configuration. However, it would have been extremely expensive to manufacture. Gurman estimated that an M2 Extreme Mac Pro could have cost at least $10,000 before upgrades, turning it into an extraordinarily niche product.

Engineering challenges also reportedly played a role. Apple ultimately decided that the development and production costs were difficult to justify for a computer that would sell in relatively small numbers. Bloomberg’s latest report suggests Apple later developed an M3 Extreme before cancelling that project for similar reasons.
Apple launched its first Apple silicon Mac Pro in 2023 with the same M2 Ultra chip found inside the Mac Studio. The Mac Pro offered PCIe expansion, yet it cost twice as much despite delivering nearly identical CPU and GPU performance. An M3 Extreme could have changed the equation. Gurman says the chip was designed with twice as many CPU and GPU cores as the M3 Ultra, which tops out at a 32-core CPU and an 80-core GPU.
Apple also reportedly developed an M3 Ultra Mac Pro that never reached the market. The Mac Pro remained stuck on its 2023 chip until Apple discontinued it in March, and it is not expected to return anytime soon.
Existing iPhone owners continue to account for nearly nine in 10 surveyed U.S. purchases, showing how Apple’s enormous customer base isn’t dwindling under pressure from Google and other Android smartphone manufacturers.
Consumer Intelligence Research Partners estimates that 87% of U.S. iPhone buyers in the March 2026 quarter came from another iPhone. The share reached its highest level in the three years covered by the report, up from 84% in 2025 and 85% in 2024.
Another 12% switched from an Android smartphone, down from 14% in 2025 and slightly below the 13% measured in 2024. The remaining 1% came from a basic phone, bought a first smartphone, or fell into another category.
The numbers point to a smartphone market in which most buyers settled on a platform years ago. Apple can still attract Android owners, but the larger opportunity comes from convincing hundreds of millions of existing customers to replace an older iPhone with a newer model.
Android users have accounted for 11% to 15% of new iPhone buyers in recent years, placing the March quarter’s 12% result within CIRP’s usual range. The decline from 14% in 2025 looks more like routine movement than a major shift in Apple’s ability to attract Android owners.
Switching platforms can mean transferring years of data, replacing apps and accessories, and rebuilding familiar workflows. Existing iPhone owners face far less friction because their photos, messages, passwords, apps, and settings can move to a new model.
A 12% share still represents a meaningful source of new customers at Apple’s scale. Apple posted record iPhone revenue as Counterpoint estimated that U.S. iPhone sales volume rose 1.3% while the overall market fell 5.7%.
The growing iPhone buyer pool also makes CIRP’s percentage harder to interpret on its own. The number of Android converts could hold steady or increase even if those buyers represent a smaller share of total iPhone purchases.
The 87% figure shows why Apple doesn’t need a surge in platform switching to sustain the iPhone business. Existing owners already understand iOS, own compatible accessories, and may have years of purchases and personal data tied to Apple Services.
Carrier promotions and trade-in offers can make another iPhone the easiest financial and technical choice. Apple also benefits beyond the phone sale because repeat buyers may remain connected to Apple Watch, AirPods, Mac, iPad, and Services.
Apple said on January 29, 2026, that its installed base had surpassed 2.5 billion active devices worldwide, although it doesn’t disclose how many are iPhones or how many belong to unique users.
Only 1% of CIRP’s surveyed iPhone buyers came from a basic phone, bought a first smartphone, or entered through another route. Apple and Android manufacturers are therefore competing mostly for people who already own a capable device.
Winning a new customer means persuading someone to leave a familiar platform, while keeping one preserves future hardware and Services revenue. Each Android convert can also become part of Apple’s repeat-buyer pool in later upgrade cycles.
CIRP’s survey measures the composition of iPhone buyers rather than the total number of people switching platforms. Apple’s U.S. iPhone business still draws most heavily from existing owners, while Android converts remain a smaller but steady source of new customers.
The spacecraft made a close approach to the red planet in May on its way to explore the asteroid it’s named after.
NASA’s Psyche spacecraft is well on its way to its target in the asteroid belt after receiving a gravity assist from Mars in May, and the space agency just shared some incredible images from that brief encounter. Psyche captured thousands of images with its multispectral imager as it approached and flew past Mars. A timelapse shared by NASA on Friday stitches these images together to create a captivating video of the entire encounter, showing the crescent Mars it captured upon arrival, detailed views of the surface and the icy south pole behind it as it departed.
“The imager performed brilliantly, delivering some rarely seen views of the red planet,” said Jim Bell, the Psyche imager instrument lead at Arizona State University, in a statement. The spacecraft began its approach of Mars on May 2 and made its closest approach on May 15.
This maneuver gave it a speed boost and adjusted its trajectory to put it on a course for the asteroid Psyche while saving propellant for the long journey. Psyche is expected to reach the eponymous asteroid in 2029. “Besides the obvious beauty of the photos, we were also able to fully test its calibration and sensitivity to scattered light,” Bell said, “including picking out the Martian moons Phobos and Deimos from very far away as a part of a practice for the satellite search that we’ll use at the asteroid Psyche to look for any moonlets there.”
Here’s a short crash course in U.S. telecom policy.
Giant and very unpopular companies like Comcast, AT&T, Verizon, and Charter created regional monopolies that work tirelessly to erode all meaningful competition and oversight, resulting in high prices, spotty service, slower speeds, and abysmal customer service. They also pay a bunch of dodgy pseudo-academic “free market” think tanks to insist this is all very innovative and exciting.
Every so often a few Democrats (the handful not too timid to stand up to the telecom lobby) propose the absolute bare minimum policy “solution” that usually involves nibbling around the edges of the actual problem (unchecked monopoly power coddled by corruption). These efforts are very often highly decorative and performative, and very rarely competently enforced.
Enter Republicans, who work seamlessly with the telecom lobby to destroy even these bare-bones proposals, framing them as radical. The result: no real oversight of telecom giants, who then double down on all of their worst behaviors.
This just happens again and again and again in U.S. policy (privacy, net neutrality, predatory business practices). And will keep happening until the U.S. addresses its corruption problems. Which, with a minimum 2.5 years of Trumpism left, doesn’t seem likely anytime soon.
The latest case in point: back during the Biden era, the FCC under Jessica Rosenworcel proposed a new “nutrition label for broadband” that required ISPs break down each individual fee and restriction on your bill. Note it didn’t actually stop ISPs from ripping you off, it just created a mostly voluntary system whereby ISPs were politely asked to list the real price of service, including usage caps and bullshit fees.
Studies found that unsurprisingly, most ISPs didn’t comply and the FCC, even under Biden, didn’t really enforce the rules.
Despite this being, once again, a bare minimum policy effort that didn’t even actually fix the underlying problem and was never meaningfully enforced, the telecom lobby very much didn’t like the idea of having to be transparent. Or the government telling them what to do. So they’ve lobbied the Trump administration to dismantle the requirements:
“The Federal Communications Commission will vote to eliminate a rule that requires Internet service providers to list all of their so-called “passthrough” fees on an easily accessible broadband price label. The FCC vote could also make the price labels themselves a bit harder for consumers to find.”
Great stuff. Very populist. Who wasn’t begging the government to make it easier for big shitty companies to rip you off with bullshit surcharges and fees?
Keep in mind it took the U.S. government thirty-five years of telecom monopoly predation to finally come up with the idea “maybe we politely ask giant telecom monopolies to be semi-honest about their price.” But even that was a bridge too far for a corrupt U.S. federal government.
It should be noted that this most recent “nutrition label” approach was technically required by Congress, which was trying to ensure that the $42.5 billion in broadband subsidies in the infrastructure bill resulted in semi-decent broadband. But as I’ve been exploring, the Trump administration has hijacked that program to slather Elon Musk with subsidies, stripping all meaningful oversight in the process.
Trump FCC boss Brendan Carr’s order rolling back the rules tries to pretend they’re doing this for the sake of consumer clarity:
“However, the Commission’s initial rules, adopted in 2022, resulted in sometimes confusing labels that strayed beyond the statutory framework Congress created, increasing compliance costs for providers in the process. With this order, we refocus the rules on ensuring that consumers have the clear, accurate, and concise information about broadband plans that they want, making the labels a more useful shopping tool.”
That is a blatant lie. Carr is simply folding like a weakling to the demands of Comcast, AT&T and friends. There is no consumer benefit to making broadband pricing less transparent. It simply works to further obscure the real problem: regional monopoly predation, coddled by captured regulators like Carr. Comcast didn’t like having to be even semi-honest about precisely how it rips you off.
To try and avoid making it clear he’s breaking the law and ignoring Congress, Carr is pretending the labels will technically still exist. They will, of course, feature fewer requirements, be harder to find, and there will be absolutely no enforcement should ISPs balk at the rules.
Carr has more important things to do, like dismantling the First Amendment because a comedian made fun of the president’s wife, or eliminating bare-bones regulations to make life even easier on shitty robocallers, prison phone monopolies, and telecom giants.
The United States is not a serious country. It’s too corrupt to function in the public interest. And it’s become a strange combination of painful, boring, and pathetic that we have journalists, policymakers, think tankers, and regulators too feckless or captured to be honest about any of it.
Filed Under: brendan carr, broadband, fcc, fees, high speed internet, internet access, nutrition label, regulatory recovery fee, surcharges, usage caps
Looking for the most recent Strands answer? Click here for our daily Strands hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle, Connections and Connections: Sports Edition puzzles.
Today’s NYT Strands puzzle is a tricky one, with some long answers to find. If you remember yesterday’s theme, this one is the opposite. Some of the answers are difficult to unscramble, so if you need hints and answers, read on.
I go into depth about the rules for Strands in this story.
If you’re looking for today’s Wordle, Connections and Mini Crossword answers, you can visit CNET’s NYT puzzle hints page.
Read more: NYT Connections Turns 1: These Are the 5 Toughest Puzzles So Far
Today’s Strands theme is: Small talk.
If that doesn’t help you, here’s a clue: Not huge.
Your goal is to find hidden words that fit the puzzle’s theme. If you’re stuck, find any words you can. Every time you find three words of four letters or more, Strands will reveal one of the theme words. These are the words I used to get those hints but any words of four or more letters that you find will work:
These are the answers that tie into the theme. The goal of the puzzle is to find them all, including the spangram, a theme word that reaches from one side of the puzzle to the other. When you have all of them (I originally thought there were always eight but learned that the number can vary), every letter on the board will be used. Here are the nonspangram answers:
The completed NYT Strands puzzle for June 20, 2026.
Today’s Strands spangram is ITSYBITSY. To find it, start with the I that is four letters down on the far-left vertical row, and wind across.
Researchers found AI advice suppressed judgment suspension from 44% to 3%, accuracy from 27% to 9%, while confidence rose from 30% to 76%. People trusted wrong AI answers.
Researchers from three French and Italian universities found that access to AI advice collapsed people’s willingness to say “I don’t know” from 44% to 3%. Accuracy dropped from 27% to 9%. Confidence, meanwhile, rose from 30% to 76%. “People became much worse, the accuracy was only one third, but they were twice as confident,” said Valerio Capraro, associate professor at the University of Milano-Bicocca.
The study, authored by Capraro with Chiara Marcoccia of École Normale Supérieure and Walter Quattrociocchi of Sapienza University of Rome, deliberately used questions where AI models typically fail: visual details from films, such as the colour of a team’s uniform in Bend It Like Beckham. The researchers used Step 3.5 Flash, a model that was usually wrong on these questions, precisely so any reduction in judgment could not be explained as sensible delegation to a reliable tool. Some participants who would have answered correctly on their own asked the AI and became wrong.
Monetary incentives helped, but not much. Willingness to admit ignorance rose from 3% to 8% and accuracy from 9% to 16%, both still well below the no-AI baselines of 44% and 27%. Wharton researchers coined the term “cognitive surrender” earlier this year to describe the same phenomenon: people accepting incorrect AI answers 80% of the time while reporting higher confidence than those working without AI. The new study adds a sharper data point. It is not just that people trust wrong AI answers. It is that the mere availability of AI suppresses the cognitive habit of recognising what you do not know.
“For humans, the capacity to say ‘I don’t know’ is very important because it represents the recognition of the limits of our own knowledge,” Capraro said. He is particularly concerned about children, who are growing up with these systems before they have developed critical thinking skills. Google’s AI search overhaul replaced links with confident AI-generated summaries, and Common Sense Media this week called that design an “unacceptable risk” for students. The pattern is consistent: AI products are designed to answer, never to say “I don’t know.” The humans using them are learning to do the same.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Young campaigners urge incoming PM to act on outdoor junk food ads
CFTC blocks Kalshi from unwinding Michigan trades after court order
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Disney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Get Your ESP32 Sunny Side Up With This Solar Dev Board
XRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
Registration is now open for March for Men with Kev 2026
Dark Secrets Emerge When Jailbreaking LLMs
New Cornerback Enters Vikings Trade Rumor Mill
Money | Class 12 Economics | CBSE Board Exam 2026-27
Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) Discusses Global Macro Environment and Economic Outlook for Core Markets Transcript
You must be logged in to post a comment Login