Connect with us

Tech

When AI agents go rogue, the law doesn’t disappear

Published

on

The multiple recent reports of autonomous AI systems escaping their intended boundaries and accessing external organizations’ systems have pushed a previously theoretical question into the real world. AI agents going rogue is no longer a prospect; it is a documented reality.

In July 2026, OpenAI disclosed that one of its own agents, operating in a supposedly sealed evaluation environment, exploited a zero-day vulnerability to escape its sandbox and intrude into Hugging Face’s production infrastructure. Anthropic subsequently reported three cases of its own models gaining unauthorized access to the real systems of external organizations during testing.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Apple pushes developers to abandon Intel apps

Published

on

Apple has notified developers that they will no longer be required to make their apps compatible with Intel Macs, while also confirming that Intel-only apps will not run after macOS 27.

The forthcoming macOS Tahoe is the last release that will run on Intel-based Macs, and that will run Intel-only apps. It’s not a surprise, as Apple has been clear about this transition since it began the move to Apple Silicon back in 2020.

Now, though, it has released an updated support document about the transition, and also emailed developers directly. Headed “Upcoming changes to Rosetta support for Intel-based macOS apps,” the support document says “we’re now concluding this transition” from Intel to Apple Silicon.

Previously apps that were not universal, working with both Intel and Apple Silicon, would be rejected from the Mac App Store. This means that Apple Silicon-only apps can now be submitted, but it does not mean that Intel apps distributed outside of the Mac App Store will continue to run.

Advertisement

Apple says that this final part of the transition is in three stages:

  • macOS 26.4 or later: users will start being alerted to update apps
  • macOS 27: Intel-only apps will continue to run
  • macOS 28: No Intel-only apps will launch

The support documentation is aimed at pushing developers to use Apple Silicon if they aren’t already. “If you haven’t updated your app yet,” it says, “begin the transition immediately.”

In comparison, the email sent to developers more assumes that they will have already moved to Apple Silicon. As first spotted by MacRumors, the email says:

We’re reaching out to let you know that universal macOS apps on the Mac App Store that require macOS 13 or later can now remove support for Intel-based Mac computers.

By removing support for Intel-based Mac computers, you can simplify your development and optimize your download and on-device size.

Apple transitioned its hardware from Intel to Apple Silicon starting in November 2020 with the MacBook Air, Mac mini and 13-inch MacBook Pro. The final Mac to make the switch was the 2023 Mac Pro, which has since been discontinued.

Advertisement

Source link

Continue Reading

Tech

Acer Shows Off a Transformer-ish Concept for a Windows Gaming Handheld

Published

on

Acer Project dualplay mini expanded for computer mode, showing the back and the front, against a multicolor background
Project DualPlay MiniAcer/CNET

While we tend to think of Windows gaming handhelds as primarily gaming devices, they really have more in common with ultralight laptops: They run Windows, have a built-in screen and perform like them thanks to mobile processors with integrated graphics. And though some people have always used them as a primary computer, today’s high prices for both handhelds and traditional computers make handhelds seem like an even more attractive general-purpose option for gamers. 

But if you want to play a game with a keyboard and mouse, much less nongaming uses, you frequently experience the cumbersome process of connecting to the input devices or being restricted to wherever you’ve got a dock set up.

Woman playing on acer project dualplay mini in handheld mode with a night cityscape in the background
Project DualPlay MiniAcer

Acer’s Project DualPlay Mini concept takes a Transformers-like approach to making a handheld more suitable for general computing and KBM gaming: It’s a clamshell laptop design with the speakers on either side of the display, but the 8-inch screen flips up, and the grips are on the back of the speakers, so it turns into a traditional handheld when closed. 

You’d still have to connect a mouse, but the built-in keyboard remedies the most awkward design issue. As with any of these devices, you can connect to an external monitor as well as other peripherals as well.

The closest I’ve seen to a multipurpose design in a Windows gaming handheld is Lenovo’s Legion Go series (not the Legion Go Fold, though). But “close” in this case just comes down to a built-in kickstand that makes it a little easier to use on a desktop.

hand holding the Acer Predaator Atlas 7 facing you against a blurred blue-lit background
Predator Atlas 7

There aren’t any specs for it — it’s not a real product, at least at the moment — but Acer says it will use the same Intel G3 chips as in its Predator Atlas 8, announced at Computex 2026 in May and slated to ship later this month for an as-yet-unannounced price. The company has followed that with another launch this week for the Predator Atlas 7, a slightly smaller, lighter — and presumably cheaper — 7-inch model. It’s expected to ship around October or later in 2026.

Source link

Advertisement
Continue Reading

Tech

Roomba’s latest robot vacuums want to do almost everything for you

Published

on

After introducing five new models in July, iRobot has returned at IFA 2026 with another pair: the Roomba Max 875 and Roomba Plus 678. They cost $1,200 and $900, respectively, and both arrive with the specs we’ve increasingly come to expect from high-end robot vacuums.

That starts with suction. The Max 875 tops out at a hefty 35,000Pa, while the Plus 678 isn’t far behind at 30,000Pa. Both also use what iRobot calls SealForce Vacuuming Technology, which the company claims delivers three times deeper carpet cleaning than its robot vacuums that don’t use the system. But suction is only part of what makes the Max 875 interesting.

The Max 875 wants to handle the entire cleanup

Like many premium robot vacuums today, the Max 875 is designed to require as little attention from you as possible. Once it returns to its dock, the system can empty collected debris and clean the mop. The dock washes the roller using water heated to 176 degrees Fahrenheit, while the robot can also be automatically topped up with fresh water and cleaning solution before heading out again.

The mop itself is a roller rather than a pair of spinning pads, and it can extend outward to reach closer to walls and edges. When the Max 875 encounters carpet, that roller lifts away and covers itself, helping prevent a freshly cleaned wet mop from being dragged across your rug. There’s another interesting addition underneath. While mopping, the Max 875 can continuously spray a heated mist onto the floor, designed to help loosen dried-on spills and other stubborn messes. iRobot has even added a hair-cutting main brush to reduce the amount of hair that gets wrapped around it — something anyone with long hair or shedding pets will probably appreciate. Navigation is handled using LiDAR, while front-facing cameras help the robot recognize and steer around objects left in its path.

The cheaper Plus 678 doesn’t give up everything

At $900, the Roomba Plus 678 trims the price considerably while retaining several of the same ideas. You still get 30,000Pa of suction and an extending roller mop that can move outward to clean along edges. Instead of the Max 875’s heated mist, however, the Plus 678 uses a high-pressure water spray to tackle messes.

Advertisement

There are a few other compromises. The Plus 678 doesn’t get the Max 875’s mechanism for sealing away its mop roller when moving across carpet, for example. Both models show just how dramatically the Roomba lineup has changed. Modern flagship robot vacuums aren’t simply roaming around collecting crumbs anymore; they’re increasingly becoming miniature floor-cleaning systems that vacuum, scrub, wash themselves, and prepare for the next run with very little intervention. So, if you’ve been waiting for Roomba to catch up with some of the increasingly ambitious cleaning systems we’ve seen elsewhere, these two certainly look like a step in that direction. Both the Roomba Max 875 and Roomba Plus 678 are available now through iRobot.

Source link

Continue Reading

Tech

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

Published

on

from the locking-up-the-public-square dept

When Twitter launched, it was originally designed to be just like an open protocol. In the early days, the company eagerly supported third party development, building on that protocol. But, because it was a new communications protocol totally controlled by a single company, eventually commercial pressure led the company to close off the openness. Jack Dorsey later admitted that this was a mistake, and he hoped that Twitter would go back to being an open protocol. That eventually led to the rise of Bluesky (where I am now on the board, having taken Dorsey’s old board seat) and the ATprotocol (along with some other competing protocols, each with a different implementation, but all believing in the value of open social systems).

And, of course, in the middle of all this, Elon Musk took over Twitter. You may remember that. Even though Jack Dorsey supported Elon’s bid, and suggested he embrace the open protocol aspect of where Twitter was heading, Elon went in a very different direction.

Text messages between Jack Dorsey & Elon Musk in which Dorsey advocates that Twitter "must be an open source protocol"
Text messages between Jack Dorsey & Elon Musk in which Dorsey advocates that Twitter "must be an open source protocol"

It’s funny now, four years on, to read those text messages between Jack and Elon, with Jack pushing for Elon to embrace reinventing Twitter as a decentralized open protocol, and Elon nodding along.

But, of course, that’s not what happened. Instead, what happened was Twitter became X, the personal, centralized, deliberately political project of Elon that no longer had any real resemblance to an open communications protocol. Almost immediately upon taking control, Elon began locking things down, and putting very high prices on access. There have been many changes to the API (and its pricing) since Elon took over the company (which eventually merged into xAI and then into SpaceX), but the one constant is that it’s a walled garden, focused almost exclusively on promoting the things Elon wants promoted, while demoting the things he’s scared of.

This has been known and somewhat obvious for years. But last week, it appears Elon put the final nail in the coffin for the belief that X might one day be an open protocol ever again. There were two widely known and widely used services for sharing posts on X without having to point people to X itself: Nitter and Xcancel. With both of them, if you wanted to share any particular tweet, you could just replace the “X.com” part of the URL (or the “twitter.com” part before that got rerouted) to either “nitter.net” or “xcancel.com” and you could see the same tweet (and the same thread above and below it) without giving Elon any of the traffic.

Advertisement

If you are an open protocol, that’s how it should work. Indeed, if you want to read Bluesky posts without ever touching Bluesky itself, there are already a bunch of independent ways to do it — different clients, different frontends, different views on the same underlying data — with more coming online all the time.

But, just to make it clear that X is a walled garden completely controlled by Elon and no one else, last week, X sent cease & desist notices to both Nitter and Xcancel, causing them to shut down.

That’s Nitter saying:

Cease and desist

On 24 August 2026 cease and desist letters have been sent by X Corp. demanding a permanent takedown of Nitter instances and the project’s repository.

nitter.net is offline and development has stopped for the time being. I’m seeking legal advice and won’t be commenting further on the specifics for now.

Thank you to everyone who used, hosted, packaged, donated and contributed to Nitter over the past seven years.

Xcancel just put up some text saying something very similar:

Advertisement

On Monday 24th August at 8PM EST, we received at letter from X Corp. asking to cease and desist the service XCancel.
The service XCancel is stopped until further notice.
We are seeking legal advice and won’t share more details for now.
Thank you for the trust you have put in these two years of XCancel.

This does real harm to many people, not just those who didn’t want to support Elon Musk. Many journalists and researchers would use these tools to track things in ways that Elon’s platform might not allow (or for which he might ban users). And, as Elon has continually locked down X, many things now require a login to view. It also makes a mess of many archives, including Wikipedia citations, that frequently relied on Nitter links.

While the cease and desist letters have not been publicly revealed, TechCrunch claims they were able to see them, and they accused the platforms of circumventing X’s API restrictions.

The letter from X, which TechCrunch has viewed, accuses Nitter of an “unlawful use and circumvention of X’s Application Programming Interface (API) and associated data,” through its service, saying that X has evidence that Nitter scraped X data and accessed X accounts and session tokens in violation of X’s rules.

Lawyers for X said the actions are in violation of “various state and federal laws, including, but not limited to, the Texas Harmful Access by Computer Act (§ 143.001 and § 33.02) and the Lanham Act (15 U.S.C. §§ 1114, 1125).” The letter gave Nitter until 5 p.m. EST on August 25 to shut down.

The legal theories here are basically bullshit. The “Harmful Access by Computer Act” is basically a Texas state version of the CFAA, the deeply problematic federal “anti-hacking” law that is regularly abused to stop people from doing things that should be perfectly legal. And while there have been some cases, like the Power Ventures case, that blessed the idea that such laws can block scraping, courts have been much more open to saying that there’s no hacking in merely scraping openly available web pages, such as in HiQ v. LinkedIn.

In fact, Musk and his lawyers should know all this is bullshit, because he lost his earlier lawsuit against Bright Data over scraping X.

Advertisement

The Lanham Act (trademark) claims seem equally bullshit. There’s zero likelihood of confusion here. The reason people use these sites is not because they confuse them with X, but deliberately because they are not X. And, to whatever extent either site referred back to X (or Twitter), that would be nominative fair use as accurately describing the source of the content.

Still, most of that is besides the point. X doesn’t need to actually win in court. Elon just needs it to be more expensive to fight him. And given that he literally has more money than anyone else in the world (and most companies to boot), there is no fair fight between a legal threat from him against a volunteer maintainer of an open source project.

But this is how walled gardens get built. X isn’t building a better product. It’s using Elon’s vast resources and ability to conjure up legal threats to shut down any system that enables openness.

To be clear, X is hardly alone in doing things like this. And some of it is absolutely due to the rise of AI scrapers and the desire of companies to sell access to their data. Reddit famously made a bunch of changes to its API a few years ago to limit access, and recently cut access even more. The widespread walling off of the open internet to fight AI scrapers is going to have some long-term negative consequences.

Advertisement

But rather than accept this, it should be even more incentive to embrace the tools that put us, not large companies, in control over our data.

Paul Frazee, Bluesky’s CTO, and an instrumental player in creating the ATprotocol that powers Bluesky and a bunch of other “locked open” apps recently wrote about this on Leaflet (a long-form blogging platform also powered by ATprotocol), in an article he called SELECT * FROM internet.blogposts. In that article, he highlights how the web has turned into a bunch of silos, and more and more of them keep locking the door:

The walled garden problem is downstream of a simple question: how do I SELECT * FROM internet?

If you’ve never written database code, SELECT * FROM users is how you ask a database for everything it knows about its users. Once you have it you can filter it, sort it, and join it against anything else you’ve got.

The web doesn’t historically work that way. The web is a few dozen companies, each holding a filing cabinet, each with a receptionist posted out front. He’ll read you one file at a time, but only files you can name, as fast as he cares to read, and as long as his boss allows.

The fact that “the web doesn’t historically work that way” is a historical error. Indeed, for many years, most people did think it worked that way. Google’s existence is kind of premised on the fact that it absolutely could ‘SELECT * FROM internet’ to build its index. The entire premise of the open internet was that everything could be indexed and searched, even if the SQL query were hidden behind a nicer UI.

But now, various companies (including Google!) have used a variety of both technical and legal measures to wall things off again.

Advertisement

Open protocols do a lot of useful things, but the most important may be that they lock the openness in place, so that no single company can send a legal threat letter and revoke it. A system like ATprotocol doesn’t rely on APIs controlled by a single company that can change them or cut off a provider. Instead, it corrects one of the original sins of the web: rather than one company holding all the data for a particular service, anyone can hold it. You can hold your own data (many people do) or you can let someone else (such as Bluesky) hold onto it, though in a manner where you can always take it out of their control, and host it yourself or somewhere else.

This is one of the reasons why I find ATprotocol so exciting. People looking at it as just a new way to build a Twitter clone have always missed the point. It’s a way to rebuild the entire web, where the users have way more control. Rather than handing over control to a new or different company and hoping they don’t enshittify, the entire setup is enabling the end users to have full control over their own data.

Killing off Nitter and Xcancel is the last step in Elon’s transformation of Twitter from something that wanted to be a new, open communications protocol, to “X,” a locked up, private platform tuned to the whims of a wealthy propagandist.

Every few months or so, someone writes an article about why you should get off of X, because every bit of engagement there feeds money, data, and influence to the world’s richest man in service of his fascistic political project, or because its algorithm is directly programmed to make you angry about stupid shit.

Advertisement

But I think there’s a more important reason: X’s transformation from a kind of open decentralized communications protocol to a closed bullshit delivery mechanism is symptomatic of many of the things going wrong in the world today, from the enshittification of all sorts of products and services, to the rise of authoritarianism around the globe.

Getting power back in the hands of the public doesn’t happen by further empowering the controllers of today’s data silos. Elon’s not going to help give you more power if you ask him nicely. Getting the power back means building and using the tools that make permission irrelevant in the first place.

Filed Under: atprotocol, communication, decentralization, despotification, elon musk, enshittification, open internet, open protocols, open social, protocols

Companies: nitter, twitter, x, xcancel

Advertisement

Source link

Continue Reading

Tech

Viatel acquires UK network infrastructure specialist EDNX

Published

on

The organisation aims to strengthen its position in Ireland as well as further accelerate its UK expansion.

Viatel Technology Group, an Irish IT and tech company, has announced the acquisition of EDNX, an enterprise networking and digital infrastructure specialist headquartered in Shropshire, UK, for an undisclosed amount. 

The acquisition aims to blend EDNX’s technical expertise across enterprise networking, network infrastructure, campus networks, secure IoT, Wi-Fi, SD-WAN, SD-Access and application-centric infrastructure, with Viatel’s goal to strengthen capability across highly regulated, compliance-intensive environments, such as healthcare, pharmaceuticals, life sciences and manufacturing. 

The move is also part of Dublin-headquartered Viatel’s plans for further expansion across the UK market. In July, the company acquired Scottish cybersecurity consultancy FullProxy for an undisclosed amount, as a means of developing its UK presence and cyber capabilities. 

Advertisement

Commenting on the EDNX acquisition, Paul Rellis, the CEO, for the Viatel Technology Group, said, “Networks are no longer just infrastructure. They are the foundations for security, resilience and AI adoption. The ability to move data securely, efficiently and at scale will increasingly determine which businesses lead and which fall behind.

“EDNX brings exceptional expertise and a strong track record of delivering enterprise networking solutions in some of the most demanding environments. Their technical capability complements our existing strengths in connectivity, cybersecurity and managed services while creating new opportunities to bring advanced networking services to our customers.”

David Ratcliffe, the CEO of EDNX, added, “Over many years, we have built EDNX around deep technical expertise and a commitment to delivering network infrastructure that supports critical outcomes.

“Joining Viatel gives our customers access to broader capabilities while preserving the technical excellence and customer focus that have defined EDNX. We see strong alignment in our cultures, our ambitions and our long-term commitment to customer success.

Advertisement

“The combination also creates exciting opportunities to bring our specialist enterprise networking, infrastructure, secure IoT, campus network and Cisco capabilities to organisations across Ireland while supporting continued growth throughout the UK market.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

Anthropic launches Claude Fable 5.1 and Mythos 5.1

Published

on

Fable 5.1 is now generally available, while Mythos 5.1 is only available through Anthropic’s “trusted access” programmes.

Anthropic has launched the latest iterations of Claude Fable and Claude Mythos, “the world’s most advanced models for coding and knowledge work” according to the company.

The AI giant said in a press release that Fable 5.1 and Mythos 5.1 are “the same model, but with different levels of safeguards”.

Fable 5.1 is now generally available, while Mythos 5.1 is only available through Anthropic’s “trusted access” programmes – Mythos’ safeguards are specifically designed to support work in cybersecurity and the life sciences, according to the release.

Advertisement

The company said that Fable 5.1 is capable of much higher performance than its predecessor and that when set to medium or low effort, it can achieve similar or better results than Fable 5.

The new model can now also be used to discover software vulnerabilities, though it can’t exploit them, according to Anthropic.

The biggest performance jump between Fable 5.1 and Fable 5 appears to be in relation to agentic scientific research, with the new model capable of more than double the capability in comparison to its predecessor – from a score of 24.7pc to 52.6pc to be specific.

In terms of price, Fable 5.1 will cost an estimated 25pc less than Fable 5 for “typical workloads, wherever usage is billed by token”. For “highly agentic work”, customers will be charged up to 45pc less.

Advertisement

Anthropic is also deploying its new enterprise frontier safeguards (EFS) system, which stores data in cloud infrastructure “controlled entirely” by the customer, not Anthropic. EFS gives customers “complete privacy” which Anthropic said equates to a zero data retention policy, and will be made available to enterprise customers in phases, beginning later this fall.

Anthropic said that eligible customers will be able to use Fable 5.1 with zero data retention before EFS is available.

Mythos 5.1, according to Anthropic, is identical to Fable 5.1 but with “more permissive safeguards” for vetted individuals and organisations whose work is affected by cybersecurity and life sciences restrictions.

Currently, Mythos 5.1 is only available to vetted cybersecurity and life science professionals at select US organisations, though Anthropic said it’s coordinating with the US government to expand access to a broader set of domestic and international partners “as quickly as possible”.

Advertisement

Mythos 5.1 is now also being used to power Claude Security – the company’s product for scanning codebases for vulnerabilities and suggesting patches for human review.

OpenAI readying Astra

The debut of Fable 5.1 and Mythos 5.1 comes a few months after their predecessors – particularly Mythos – caused a stir with claims of unprecedented AI capabilities in relation to cybersecurity, including exploitation of vulnerabilities.

Security concerns even led to the US government ordering Anthropic to suspend the models for a few weeks.

Concern around Anthropic’s AI cyber capabilities were reignited recently after the company reported incidents of Claude models (including Mythos) instigating cyberattacks after breaking free during tests.

Advertisement

The buzz caused by Mythos in particular ignited further competition with Anthropic’s chief US AI rival OpenAI.

According to an announcement earlier this week, the ChatGPT creator is preparing to release its new Astra AI model soon, which OpenAI claimed can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.

OpenAI said in a recent blogpost that it has delayed parts of Astra’s development and release over the past few weeks to strengthen and test protections against “cyber misuse and unauthorised model actions”.

Astra’s launch is expected soon, though access to “its most advanced cybersecurity capabilities” will be more limited, according to the company.

Advertisement

“We will continue to test these systems, share what we learn, and be clear about what remains uncertain,” said OpenAI. “The models that follow Astra will demand more of us. We will take the time and do the work needed to meet that responsibility.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

The AI layoffs may have finally ended, and businesses might be hiring more workers just to be able to use AI effectively

Published

on


  • Just 4% of service firms have laid off workers in the past six months due to AI
  • “Existing workers are much more likely to be retrained than replaced”
  • Some companies are still hiring fewer employees than they would have

Just a few years ago, multiple companies every day were announcing AI-related layoffs amid purported efficiency gains. And that came straight after years of post-pandemic layoffs driven by earlier overhiring.

The latest data finally implies that AI-related layoffs aren’t so common anymore as companies get to grips with AI and hire new workers to help them find a direction.

Source link

Advertisement
Continue Reading

Tech

This new rugged phone has a 16,000mAh battery, thermal imaging, and a slimmer design than you might expect

Published

on


  • The Oukitel WP70 Ultra is a new rugged phone with a 16,000mAh battery
  • It also has a night vision camera and thermal imaging
  • Oukitel claims it’s the “slimmest 16,000mAh rugged smartphone”

Oukitel has landed at IFA 2026 with two new phones, the most intriguing of which is probably the WP70 Ultra — the “slimmest 16,000mAh rugged smartphone.” So, yes, this thing has a 16,000mAh battery, dwarfing most other battery beasts like the 10,000mAh Xiaomi Redmi Note 17 Pro Max.

Compared to a typical smartphone, this battery capacity is even more impressive — the iPhone 17 Pro Max, for example, has a 5,088mAh battery in its eSIM-only configuration, and a lower capacity for versions with physical SIM card slots. Similarly, the Samsung Galaxy S26 Ultra has a 5,000mAh battery. So the Oukitel WP70 Ultra has over triple the capacity.

Advertisement

Source link

Continue Reading

Tech

Your files stay put: Perplexity’s hybrid AI keeps confidential data off the cloud

Published

on

Perplexity today launched hybrid compute for its agentic platform, Computer, a system that lets a single AI agent split its work between frontier models running in the cloud and smaller open-weight models running locally on Apple silicon Macs — routing sensitive data to the local machine so it never leaves the device.

The company says it is the first time an AI agent can begin a task in the cloud and dynamically hand off the confidential portions of that same task to a model running on the user’s own hardware, without restarting the job or losing context. The feature becomes available today through Perplexity’s desktop app for enterprise customers that opt in, as well as Pro and Max subscribers, on any Apple silicon Mac running macOS 15 or later.

“Hybrid is really compelling because it’s often the work that requires confidentiality that is the most important to get right, and so the accuracy really, really matters,” Jon Staff, who leads Perplexity’s macOS and iOS engineering teams, said during a press briefing attended by VentureBeat. “By combining these two together, we can get that maximum intelligence from the frontier models, but we also get the security and the privacy that comes with local.”

How Perplexity’s on-device privacy gate keeps sensitive data off the cloud

The architecture works like a dispatcher. A frontier model in the cloud breaks a task into subtasks and routes each one to the appropriate place. Web research, long-horizon planning and heavy reasoning run in the cloud, while anything touching private files, local data or actions on the device gets delegated down to a subagent running on the Mac itself.

Advertisement

The linchpin is what Perplexity calls a Privacy Gate: a company-trained classifier that runs on the device and scans for personally identifiable information — names, addresses, account numbers, secrets — before anything is transmitted to the cloud. When the gate flags sensitive content, the user chooses whether that portion of the task runs locally or gets shared.

“What we wanted to do is make sure anything that’s shared to that cloud orchestrator is safe,” Staff said. “We built and trained our own PII classifier that integrates directly into the Mac app.”

He described the handoff in detail: “The cloud orchestration will break down the task based on the prompt and figure out how to route it to different subagents… it’s going to delegate that down to a sub-agent running on your Mac, and then that portion of the task is run entirely local. None of those tokens go to the cloud.”

The economics matter, too, for a company that meters cloud usage through credits. Tokens generated locally cost nothing. “You’re paying for the electricity, you’re paying for the hardware, so we’re not charging you for that,” Staff said. “The only thing the credits are used for is the orchestration and the delegation.”

Advertisement

Lawyers, private equity firms and a founder in an Uber: hybrid compute in action

Perplexity built its demonstrations around exactly the kind of work most professionals would never hand to a cloud-only agent. In the first, a lawyer on deadline updated a draft brief against privileged case files stored on a Mac while a cloud agent simultaneously pulled public case law from the open web — sending out, Perplexity says, only anonymized legal questions. “At no point did their privileged information get shared to the cloud,” Staff said. “It never left the Mac.”

In the second demo, a private equity associate’s agent reworked a financial model against confidential management projections, benchmarked the deal against public comparables and produced a fifth iteration of an investment committee deck. The task ran roughly 40 minutes in the background with no human input — work that would have taken hours of manual stitching between local spreadsheets and cloud research.

The third demo emphasized continuity across devices. The founder of a pottery shop, riding in the back of an Uber, kicked off a marketing analysis from her iPhone. Computer asked permission to reach her Mac at the studio, fired up the local subagent to process her customer interviews and revenue data, and combined that with cloud research on competitors’ public pricing. “It doesn’t matter how far away she is from her computer,” Staff said.

“Tasks like this aren’t possible in a fully local or a fully cloud setup,” he added. “You need that security of the local and the privacy, but you also need the intelligence of the frontier.”

Advertisement

Why a Chinese-made Qwen model on enterprise Macs is raising eyebrows

The launch model lineup immediately raised a pointed question. At launch, users can choose among three local models: Google’s Gemma E4B, Alibaba’s Qwen3.6 35B-A3B, and a Perplexity post-trained version of Qwen3.6 35B — the company’s recommended option. Asked by VentureBeat whether enterprise or government customers had raised concerns about giving a Chinese-developed model access to their machines, Staff argued that local inference neutralizes the geopolitical risk.

“The great thing about these models is that they are open weight. We’re able to evaluate them ourselves,” he said. “When that model is running locally on your computer, the data is not going outside of your computer itself… You’re not actually sending those tokens to some cloud provider that’s hosted in another country. In fact, all of Perplexity’s models are U.S. hosted.”

He added that macOS’s built-in sandboxing framework, known as Seatbelt, constrains what the agent can actually do on a machine: “If local execution is trying to do something that it shouldn’t, it’ll just point blank stop it and it’ll request permission from the user.” Perplexity does not currently allow unrestricted “YOLO mode” execution, he said, though “I wouldn’t be surprised at some point if we allow certain people to do this.”

For enterprises, admins can set a single organization-wide sensitivity policy and audit a full record of what leaves each device — a feature aimed squarely at compliance teams in law, finance and healthcare. Questions remain on the consumer side, however. Pressed on how usage data feeds model training, Staff pointed to Perplexity’s incognito mode and a long-standing opt-out toggle, and said enterprise contracts can include zero-data-retention terms. A company spokesperson said Perplexity is “not using it for post training” globally and promised to follow up with specifics on non-enterprise accounts.

Advertisement

The enterprise privacy problem hybrid AI is trying to solve

The announcement lands amid a broader industry reckoning with a stubborn problem: the most valuable enterprise work involves exactly the data companies are least willing to send to someone else’s servers. NIST’s generative AI risk profile flags data privacy and information leakage among the technology’s central risks, and McKinsey’s research on the state of AI has consistently found that organizations struggle to move from experimentation to value capture, with data governance among the chief obstacles. Gartner, for its part, named hybrid computing among its top strategic technology trends for 2025, anticipating architectures that blend compute across environments.

Perplexity is betting that the answer is not choosing between cloud intelligence and local privacy, but building the orchestration layer that arbitrates between them in real time. It is a defensible position for a company that has always styled itself as a neutral broker — “Perplexity is like Switzerland in that we work with everyone,” a company representative said at the briefing — sitting at the application layer above whichever models happen to lead at any given moment.

“Anytime one of these gets better, Perplexity gets better,” Staff said of the interplay among local models, frontier models and Apple’s chips. “That’s the really cool nature of where we sit in this application layer, orchestrating all the different pieces together.”

From $520 million startup to $20 billion agent platform in three years

Hybrid compute caps an extraordinarily aggressive product run. Perplexity launched its Comet AI browser in July 2025, initially for $200-a-month Max subscribers — an early bid to make agents, not chat, the interface to computing. Computer, its full agentic platform, arrived in March 2026, followed by desktop apps for Mac and Windows. Just last week, the company launched a local-first version of Computer on NVIDIA’s DGX Spark hardware, which starts on the user’s device and escalates to cloud models only with permission. Today’s launch inverts that flow: cloud-first, delegating down.

Advertisement

The business trajectory has been equally steep. Perplexity was valued at $520 million in January 2024; by September 2025, the company had finalized a funding round at a $20 billion valuation. Along the way it made an audacious $34.5 billion bid for Google’s Chrome browser during Google’s antitrust remedies fight, and Bloomberg reported that Apple executives held internal talks about acquiring the company — a striking backdrop for a product now built to showcase Apple silicon.

The strategy is not without headwinds. Reuters reported in July that Reddit’s data-scraping lawsuit against Perplexity survived a motion to dismiss, part of a wave of copyright and data litigation facing the company — context that makes its privacy-forward positioning both commercially savvy and reputationally necessary. And practical constraints remain: Perplexity recommends at least 32GB of unified memory for the better tier of local models, Staff was candid that the smallest option “significantly underperforms” the larger Qwen models, and Windows and Linux support will come only later.

The deeper question is one users cannot easily inspect. The Privacy Gate is itself a machine learning classifier, and classifiers miss things; a false negative means sensitive data reaches the cloud anyway. Perplexity’s answer is transparency — users can expand and review exactly what the gate flagged before anything is sent, and enterprises get device-level audit logs. But the pitch, at bottom, asks professionals to trust one AI to decide what another AI is allowed to see. For an industry that has spent three years telling lawyers, bankers and doctors to keep their most sensitive work away from the cloud, Perplexity’s wager is that the fix was never to build a higher wall — it was to build a smarter gate.

Source link

Advertisement
Continue Reading

Tech

Anthropic releases Claude Fable 5.1, cuts cached token pricing by 75%

Published

on

Looking ahead: Anthropic has released Claude Fable 5.1, making its newest flagship model available through its API, cloud platforms and the Claude desktop app. It also released Mythos 5.1, a version of the same underlying model reserved for approved cybersecurity and life-sciences organizations. These updates make Anthropic’s most advanced models easier for companies to use on complex work that takes time, involves sensitive data and needs clear safeguards.

Fable 5.1 is the broadly available version, with safeguards that block some high-risk work in cybersecurity and scientific research. Mythos 5.1 has fewer of those restrictions, but access is limited to Anthropic’s trusted-access program.

The update targets customers using AI for assignments larger than a single prompt or code request. Anthropic said Fable 5.1 is better at handling software projects, reviewing code across an application, troubleshooting problems in external libraries and running multistep scientific work. It can also help design experiments, model possible outcomes and interpret detailed tables and diagrams.

The company said the model is designed to complete more work using fewer tokens, a key issue for companies running AI agents over extended periods.

Advertisement

Anthropic reported substantial gains on several internal and third-party-style evaluations. Fable 5.1 scored 55.8% on Terminal-Bench 4.0, a benchmark for command-line coding work, compared with 42% for Fable 5. Mythos 5.1 scored 60.9% under its more permissive safety settings.

On Terminal-Bench-Science 0.1, which measures agentic scientific research, Anthropic reported a 52.6% score for Fable 5.1, more than double Fable 5’s 24.7%. The company also reported gains in business-workflow automation, knowledge work and browser-agent tasks.

Those benchmark results are Anthropic’s own and should not be treated as independent proof that the new model is better than every competing system. Still, the results line up with the company’s broader claim that Fable 5.1 is better suited to work that requires a model to keep track of a problem, use tools and revisit earlier steps.

Some early customers described that kind of use. Millennium said Fable 5.1 found the cause of a rare software crash in an outside vendor’s library after the issue had gone unexplained for four to five years. Ramp said it ran the model for 38 hours on a machine-learning task, during which it revisited a previous conclusion, launched six experiments and produced findings and recommendations.

Advertisement

Anthropic did not cut Fable 5.1’s standard API rates. It still costs $10 per million input tokens and $50 per million output tokens, the same as Fable 5.

Instead, the company cut the price of cache reads by 75%. Reading cached input now costs $0.25 per million tokens, down from $1 per million for Fable 5. Cache writes remain $12.50 per million tokens for a five-minute cache and $20 per million tokens for a one-hour cache.

This change matters for agentic workloads because agents often send the same information to a model repeatedly. That can include a large code repository, system instructions, technical documentation, tool specifications and the record of earlier work. Lowering the price of that repeated context can meaningfully affect the total bill.

Anthropic said cached material can account for half or more of token use in certain long tasks. The company expects the new pricing to lower the effective cost of running Fable 5.1 by about 25% for typical workloads and by as much as 45% for heavily agentic applications.

Advertisement

Fable remains expensive compared with Anthropic’s Opus and Sonnet models, as well as many competing models. But the company is betting that businesses will judge it on the cost of completing a difficult assignment, not just the price of each token.

The release also includes changes to Anthropic’s approach to data retention. This fall, the company plans to begin offering Enterprise Frontier Safeguards, a service that will allow customers to keep monitoring data on their own infrastructure while still using Anthropic’s misuse-detection systems.

That is a shift from Anthropic’s earlier position that data retention was necessary for certain advanced models because of cybersecurity risks. Under the new arrangement, customers will have greater control over data and logging, while Anthropic’s safety controls will remain active.

Anthropic also said it improved the classifiers that decide whether to block a model request. The company said the new system produces fewer false positives, which could reduce unnecessary disruptions for legitimate cybersecurity and biology-related work.

Advertisement

The issue has become more significant after Anthropic and the UK AI Security Institute disclosed that earlier Claude models, tested under unusually permissive cybersecurity conditions, had taken unauthorized actions against real systems. Anthropic temporarily paused external cyber evaluations and added more containment and monitoring before restarting them.

Fable 5.1 and Mythos 5.1 are the first new Claude models to include invisible watermarks in text and file outputs. Anthropic had said it would add watermarking to models released after Aug. 2, 2026, in line with the EU AI Act.

The watermarks work by influencing word selection when several plausible choices are available. They are intended to remain detectable after copying, pasting or light editing, but are not visible to readers.

Advertisement

Anthropic said the watermark does not change the quality or content of a response and does not include information about the user, the organization or the conversation. Its detection API is available to regulators, law enforcement, media organizations, fact-checkers, independent researchers and other eligible groups.

A positive result can show that Claude wrote or processed the content. A lack of a watermark, however, does not prove that a human wrote the material.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025