Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data Samiksha Jain
    The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The
     

Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

26 de Agosto de 2026, 02:26

UK Ukraine AI partnership

The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The UK government described Avengers AI Labs as a “goldmine of battlefield data,” offering researchers access to real-world operational information used to train AI models.

How Avengers AI Labs Uses Battlefield Data

The data is collected through thousands of daylight cameras and infrared sensors deployed across the battlefield. The systems capture images and information involving tanks, artillery, air defence systems, infantry and aerial targets, including Shahed drones and reconnaissance UAVs. The data is used to train AI models to recognize and classify battlefield objects. Ukraine’s Defense Ministry has previously said that systems trained using the Avengers Labs platform analyze more than 100,000 drone video feeds each month and help identify about 70% of enemy targets in real time. The UK’s access to the platform is intended to allow British startups, researchers and engineers to work with operational insights and develop technologies based on real-world datasets. The partnership will initially bring together engineers, academics, businesses and military operational expertise from both countries to address national security challenges. The two countries will also explore additional platforms for future collaboration.

UK Ukraine AI Partnership Test New Defence Technology

Several pilot projects involving British startups have already been rolled out as part of the agreement. The companies named are Bristol-based Sintela, Oxford’s Mind Foundry and London’s Skyral. The first technology is due to be deployed at a UK defence site to help protect bases from protestors and hostile actors seeking intelligence. The project combines Ukrainian data with UK technology and turns buried fibre-optic cables into an AI-enabled sensor. The technology could also be used in other critical locations, including airports, prisons, railways and energy plants, according to the information released about the partnership. A second project will examine the development of next-generation low-power AI chips designed for future drones, robotics and autonomous systems. If successful, the technology could support machines designed to operate for longer, respond faster and function in environments where conventional systems face limitations.

AI Sovereignty and Defence Innovation

The agreement forms part of the UK and Ukraine’s 100 Year Partnership and expands cooperation between the two countries in AI and defence technology. The UK will provide access to its universities, researchers, technology companies and AI ecosystem, while Ukraine will provide access to operational experience and datasets generated during the war. Minister for AI Kanishka Narayan described the arrangement as AI sovereignty in practice, focused on developing national capabilities and turning frontline experience into technologies for military and critical infrastructure protection. The partnership also follows the UK government’s announcement that defence firm MBDA can release classified information on UK components for the long-range SCALP missile to establish local assembly lines in Ukraine. The broader agreement is intended to combine Ukrainian battlefield data with British scientific, engineering and technology expertise, with the initial focus remaining on defence, national security and the development of future defence technology.
  • ✇Firewall Daily – The Cyber Express
  • Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI Samiksha Jain
    Every enterprise wants the upside of AI — faster workflows, sharper decisions, leaner teams. Far fewer have asked the harder question: what happens when the same systems delivering that upside are also quietly rewriting who, or what, has access to the crown jewels? Autonomous agents are now reading contracts, touching customer data, writing production code, and triggering workflows once reserved for trusted employees. The attack surface hasn't just grown — it's changed shape entirely. Mohamma
     

Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI

20 de Agosto de 2026, 07:53

The Cyber Express Mohammad Arif

Every enterprise wants the upside of AI — faster workflows, sharper decisions, leaner teams. Far fewer have asked the harder question: what happens when the same systems delivering that upside are also quietly rewriting who, or what, has access to the crown jewels? Autonomous agents are now reading contracts, touching customer data, writing production code, and triggering workflows once reserved for trusted employees. The attack surface hasn't just grown — it's changed shape entirely. Mohammad Arif, Head of Information Security at Guild Group, has been on the front line of that shift, helping enterprise leaders separate genuine AI-driven cyber risk from the noise around it. In this interview with The Cyber Express, he makes the case that AI security isn't a niche technical concern to be handed off to a working group — it's a boardroom issue, sitting at the intersection of data protection, vendor risk, identity, and human accountability. His warning is blunt: organisations still treating AI security as tomorrow's problem are already behind, and the cost of catching up only rises from here.

The Cyber Expres: Everyone is talking about AI productivity. From a security leadership perspective, what is the biggest shift AI is creating for enterprises?

From a security leadership perspective, the biggest shift is that AI is changing the enterprise trust model. It is no longer only about protecting systems, networks, and users. Organisations now need to consider what AI can access, what data it can process, what decisions it may influence, and what actions it may trigger. AI can significantly improve productivity, cyber defence, and business decision-making. But the risk increases when adoption moves faster than governance. If AI tools are connected to sensitive data, enterprise workflows, identity systems, APIs, or business processes without clear controls, the risk is no longer just a technology issue. It becomes a data, privacy, operational resilience, and trust issue. So the real shift is this: AI is not just another productivity tool. It is becoming part of the enterprise operating model, and therefore it needs to be governed and secured like any other critical capability.

The Cyber Express: What worries you most about the current pace of AI adoption across organisations?

What worries me most is the gap between the speed of AI adoption and the maturity of AI governance. Many organisations are moving quickly to unlock productivity benefits, but they may not yet have clear rules around approved use cases, sensitive data handling, vendor assurance, retention of information, model outputs, and human accountability. The immediate risk is uncontrolled or "shadow" AI adoption, where employees or teams use public or unapproved AI tools without understanding what data is being entered, how that data may be retained, or whether it could be used to improve external models. This can create confidentiality, privacy, intellectual property, and regulatory risks. The challenge for enterprises is not to slow down innovation unnecessarily. The challenge is to enable AI safely — giving employees approved pathways to use AI, while putting the right controls around data protection, access, monitoring, and risk-based governance.

The Cyber Express: At what point does AI stop being just a productivity tool and become a real enterprise security challenge?

AI becomes a real enterprise security challenge when it moves from simply generating content to being connected to enterprise data, identity, applications, APIs, tools, and workflows. A standalone AI assistant used for drafting general content has a different risk profile from an AI agent that can access customer information, analyse internal documents, write code, trigger workflows, or make recommendations that people rely on. The risk increases further when AI has autonomy, can call external tools, or can operate across multiple systems. This is where agentic AI becomes important. The question is no longer only "what can the model say?" It becomes "what can the AI access, what can it do, and who is accountable for the outcome?" That is the point where traditional security controls need to extend into AI governance, identity, permissions, logging, monitoring, and human oversight.

The Cyber Express: Do you think most organisations are prepared for AI-driven cyber threats, or are many still treating AI security as a future problem?

Preparedness varies significantly. Some organisations are taking AI security seriously and are building governance, security review, data protection, and monitoring into their AI adoption programs. But many are still treating AI security as a future problem, even though AI is already inside the enterprise through productivity tools, SaaS platforms, coding assistants, analytics tools, third-party services, and employee-led experimentation. The issue is that AI adoption is often decentralised. It may start in business teams, technology teams, vendors, or individual users before the organisation has a complete view of the risks. That means security leaders need to shift from reactive control to proactive enablement. AI security readiness should include clear acceptable-use guidance, approved tools, data classification, vendor due diligence, secure development practices, incident response scenarios, awareness training, and monitoring. Without those foundations, organisations may not know where AI is being used, what data is exposed, or where the risk is accumulating.

The Cyber Express: What AI-related security incidents do you realistically expect enterprises to face over the next 12 months?

Over the next 12 months, I expect most enterprises to see AI-related incidents in a few practical areas. The first is AI-assisted social engineering. Phishing, impersonation, business email compromise, and executive fraud will become more convincing because AI allows attackers to generate personalised and credible content at scale. The second is sensitive data leakage into AI tools, which may happen when employees enter confidential business information, customer data, source code, contracts, security information, or internal documents into tools that have not been approved or assessed. The third is insecure AI integration. As teams connect AI to internal knowledge bases, applications, plugins, and workflows, weaknesses such as prompt injection, excessive permissions, poor output validation, or weak monitoring may create new attack paths. The fourth is AI supply-chain risk. Organisations increasingly rely on third-party models, APIs, datasets, plugins, open-source components, and AI-enabled SaaS platforms — each introducing dependencies that need to be assessed and monitored. So the threat is not one single scenario. It is an expanded attack surface across people, data, applications, vendors, and business processes.

The Cyber Express: AI-generated phishing and deepfakes are receiving significant attention. Have these threats become genuinely dangerous, or are they still more hype than reality?

They are genuinely dangerous, but the risk needs to be understood properly. The concern is not only that AI can create fake emails, voices, images, or videos. The bigger issue is that AI reduces the effort required to create believable, personalised, and scalable deception. Traditional phishing often had indicators such as poor grammar, generic wording, or obvious formatting issues. AI reduces those indicators. Attackers can tailor messages to specific roles, business processes, recent events, or organisational language. Deepfakes also create risk where organisations rely heavily on voice, video, or informal executive instructions for approvals or sensitive actions. This does not mean every organisation will face sophisticated deepfake attacks immediately. But it does mean that trust-based processes need to be strengthened. Payment approvals, changes to bank details, privileged access requests, sensitive data transfers, and executive instructions should have strong verification controls that do not rely on one communication channel alone.

The Cyber Express: Do enterprises fully understand the risks of feeding sensitive data, business context, or internal information into frontier AI systems?

Not always. Many organisations understand the general concern, but they may not fully understand the practical ways sensitive information can be exposed through AI usage. The risk is broader than simply entering customer data into a public tool. Employees may enter internal strategies, contracts, security designs, source code, incident information, board papers, commercial terms, or confidential business context. Even if the data is not used for model training, there may still be risks around retention, access, logging, jurisdiction, vendor terms, and downstream use. Enterprises need to apply the same discipline to AI that they apply to other sensitive platforms — understanding what data is allowed, which tools are approved, whether enterprise-grade privacy and security settings are enabled, how data is retained, and whether the vendor's contractual terms align with the organisation's obligations. The practical starting point is data classification. If organisations do not know what data is sensitive, they cannot consistently govern how that data should or should not be used with AI.

The Cyber Express: We have seen supply-chain attacks target software and open-source ecosystems. Could AI models, tools, plugins, agents, datasets, and integrations become the next major supply-chain risk?

Yes, AI supply-chain risk is likely to become a major area of focus. In traditional technology environments, organisations already assess software vendors, cloud providers, managed service providers, open-source libraries, and third-party integrations. AI expands that supply chain. The AI supply chain can include foundation models, fine-tuned models, datasets, model providers, APIs, plugins, orchestration platforms, vector databases, prompt libraries, AI coding tools, agent frameworks, and embedded AI features in SaaS products. A weakness or compromise in any of these areas can affect the confidentiality, integrity, or reliability of AI-enabled systems. A poorly governed dataset could introduce bias or inaccurate outputs. A vulnerable plugin could expose data. A compromised package could affect an AI-enabled application. An over-permissioned AI agent could access more information than it needs. These are not only technical risks; they are third-party, operational, and governance risks. Enterprises should therefore treat AI supply-chain assurance as part of broader cyber risk and vendor risk management, including due diligence, contractual controls, security testing, data protection review, monitoring, and clear accountability between the organisation and its providers.

The Cyber Express: How should security leaders rethink traditional cybersecurity strategies in a world where AI can write code, analyse vulnerabilities, automate tasks, and support attackers as well as defenders?

Security leaders should not abandon traditional cybersecurity principles. Instead, they need to extend them into AI-enabled environments. Identity and access management remains critical, but now we need to consider identities and permissions associated with AI agents, service accounts, APIs, and automated workflows. Data protection remains critical, but now we need to monitor prompts, outputs, embeddings, and knowledge retrieval systems. Secure development remains critical, but now we need to assess AI-generated code, model behaviour, prompt injection risks, and third-party AI components. The same applies to monitoring and incident response. Security teams need visibility into AI usage, unusual activity, sensitive data exposure, misuse of AI tools, and unexpected agent behaviour. Incident response plans also need to consider AI-specific scenarios such as data leakage through AI platforms, compromise of AI integrations, prompt injection, poisoned data, or misuse of AI-generated code. The key point is that AI security should not sit outside the cybersecurity operating model. It should be integrated into governance, architecture, procurement, engineering, monitoring, awareness, and incident response.

The Cyber Express: Are existing cybersecurity teams equipped to handle AI-era threats, or does the industry need new skills and operating models?

Existing cybersecurity skills remain highly relevant, but they need to be expanded. The fundamentals still matter: identity, data protection, secure architecture, vulnerability management, incident response, third-party risk, and governance. However, AI introduces new concepts that security teams need to understand. Security professionals now need AI literacy — how large language models work at a practical level, how AI applications are integrated, how prompts and outputs can be manipulated, how retrieval-augmented generation works, how AI agents interact with tools, and how AI supply chains are structured. The operating model also needs to evolve. AI security cannot be owned by security alone. It requires collaboration between cybersecurity, technology, data, privacy, legal, risk, procurement, HR, and business teams. In many organisations, the most effective model will be a cross-functional AI governance group supported by security-by-design processes. So yes, the industry needs new skills, but not at the expense of existing cybersecurity disciplines. The future is a combination of traditional cyber expertise, AI literacy, risk management, and business enablement.

The Cyber Express: AI vendors promise speed, scale, and automation. Where should organisations avoid over-relying on AI in cybersecurity and business decision-making?

Organisations should avoid over-relying on AI in areas where decisions are high-impact, sensitive, difficult to reverse, or require strong judgement. AI can assist, but accountability should remain human. In cybersecurity, this includes incident severity decisions, containment actions, identity and privileged access approvals, regulatory interpretation, legal assessments, and decisions that could materially affect customers, employees, or critical operations. AI can help summarise information, detect patterns, prioritise alerts, and recommend actions, but those recommendations should be validated by qualified people. There is also a risk of automation bias, where people trust AI outputs because they appear confident or well-structured. That can be dangerous if the output is incomplete, inaccurate, or based on weak context. Organisations need clear rules for where AI can automate, where it can recommend, and where human approval is mandatory. A practical principle is this: the greater the potential impact, the stronger the need for human oversight, auditability, and accountability.

The Cyber Express: If you were advising enterprise leaders today, what are the first three things they should do to prepare for the security impact of frontier AI models?

The first priority is to establish AI governance. Organisations need clear policies on approved use cases, acceptable tools, data handling, human oversight, and accountability. Governance should not be theoretical — it needs to be embedded into procurement, technology delivery, data management, security review, and business processes. The second priority is to protect sensitive data before scaling AI adoption. This means strengthening data classification, access controls, data-loss prevention, retention rules, and monitoring. Enterprises should know what data can be used with AI, under what conditions, and through which approved platforms. The third priority is to integrate AI into the cyber risk management operating model — including third-party risk assessments, threat modelling, secure development, incident response, employee awareness, logging, monitoring, and assurance activities. Security teams should also start preparing for AI-specific risks such as prompt injection, insecure integrations, sensitive data exposure, excessive agency, and AI supply-chain compromise. AI can create significant value, but only if organisations adopt it with discipline. The organisations that treat AI security as a future issue may already be behind.
"AI adoption without governance is not innovation — it is unmanaged risk. The next phase of enterprise security is about controlling what AI can access, what it can do, and who remains accountable." — Mohammad Arif, Head of Information Security, Guild Group
  • ✇Firewall Daily – The Cyber Express
  • OpenAI Tightens AI Evaluation Safeguards After Testing Incidents Samiksha Jain
    OpenAI models accessed the public internet during separate third-party cyber evaluations conducted by independent testing partners, prompting the company to review how high-risk AI testing is managed. OpenAI said the incidents occurred under specialized testing configurations with reduced safeguards and did not reflect how its models operate in public deployments. The company added that the events were unrelated to the previously disclosed Hugging Face security incident. The incidents involved
     

OpenAI Tightens AI Evaluation Safeguards After Testing Incidents

OpenAI models

OpenAI models accessed the public internet during separate third-party cyber evaluations conducted by independent testing partners, prompting the company to review how high-risk AI testing is managed. OpenAI said the incidents occurred under specialized testing configurations with reduced safeguards and did not reflect how its models operate in public deployments. The company added that the events were unrelated to the previously disclosed Hugging Face security incident.

The incidents involved evaluations conducted by UK AISI and cybersecurity testing partner Irregular, where testing conditions or environment configurations enabled models to interact with systems beyond the intended evaluation boundaries.

OpenAI Models Prompt Review of Third-Party AI Testing

OpenAI said independent cybersecurity evaluations are essential for understanding model capabilities before deployment. Some evaluations intentionally reduce safeguards or enable additional capabilities to measure how models perform under conditions that resemble real-world cyber operations.

According to the company, the latest incidents highlighted the need to strengthen the security controls surrounding independent testing environments as AI models become more capable.

OpenAI said it will review how it manages third-party cyber evaluations, including how higher-risk testing is identified, when internet access or reduced safeguards should be permitted, how testing environments should be isolated, and how incident reporting and monitoring procedures should be handled.

The company also plans to work with national AI institutes, independent evaluators, and other AI developers to establish stronger industry practices for high-risk AI evaluations.

UK AISI Identified Two Unsanctioned Actions by GPT 5.6 Sol

On August 3, UK AISI, the UK's AI Security Institute, informed OpenAI that during a cyber evaluation that began on July 25, models from OpenAI and another AI lab performed activities beyond the intended testing scope.

The evaluation used simulated cyber ranges where models acted as cybersecurity experts in a Capture-the-Flag exercise. Internet access was intentionally enabled so agents could download tools similar to those available to real attackers, while cyber classifiers were disabled to measure underlying model capability.

Among 19 recorded events, two involved GPT 5.6 Sol.

According to OpenAI, the model reused a publicly accessible GitHub token left behind by another lab's agent to determine whether systems inside the simulated environment were communicating with GitHub or update services. It also attempted account recovery and request-limit workarounds while registering accounts with external DNS and tunneling providers.

In a separate action, GPT 5.6 Sol used a public tunneling service to expose a locally hosted DNS server from the evaluation environment to the public internet. The server contained exploit payloads intended for a known software vulnerability within the simulated cyber range.

OpenAI said the setup did not function as intended, no evidence indicated that any real internet resolver queried the server, and the infrastructure was removed when the evaluation concluded.

UK AISI considered both actions outside the authorized testing boundary because they involved external services that were not required to complete the exercise.

Security monitoring detected unusual data transfers on July 28. UK AISI halted the evaluation, isolated the affected systems, and contained the activity within approximately one hour.

Irregular Finds Misconfigured Testing Environment

A second incident was reported on July 29 by Irregular, another organization conducting third-party cyber evaluations for OpenAI.

The testing environment was intended to remain isolated from the internet during another Capture-the-Flag exercise. However, a configuration error unintentionally allowed the models to access external websites.

During one evaluation, the fictional domain used in the exercise matched an actual website. Because internet connectivity was available, the model interacted with the live site, believing it was part of the simulated challenge.

Irregular said the incident did not involve a sandbox escape or zero-day exploit. Instead, the model exploited a basic security vulnerability on the website after gaining unintended internet access.

The investigation also found that the model used credentials associated with the same website. According to Irregular, no impacts beyond that site's own data have been identified, although its audit remains ongoing.

The organization has paused the evaluations, completed remediation, notified affected third parties, and implemented additional safeguards in its testing environment.

OpenAI said it will continue working with both UK AISI and Irregular to improve evaluation practices while ensuring independent cybersecurity testing remains rigorous as AI capabilities continue to advance.

  • ✇Firewall Daily – The Cyber Express
  • Anthropic Discloses Claude AI Internet Access During Security Evaluation Ashish Khaitan
    Anthropic has disclosed the findings of an Anthropic cybersecurity evaluation that uncovered three incidents in which Claude AI models unintentionally accessed the public internet during controlled cybersecurity testing. The company said the events stemmed from misconfigured third-party evaluation environments rather than deliberate attempts by the models to escape their testing boundaries. The review began after OpenAI announced on July 21 that several of its AI models had escaped an isolate
     

Anthropic Discloses Claude AI Internet Access During Security Evaluation

Anthropic cybersecurity evaluation

Anthropic has disclosed the findings of an Anthropic cybersecurity evaluation that uncovered three incidents in which Claude AI models unintentionally accessed the public internet during controlled cybersecurity testing. The company said the events stemmed from misconfigured third-party evaluation environments rather than deliberate attempts by the models to escape their testing boundaries. The review began after OpenAI announced on July 21 that several of its AI models had escaped an isolated testing environment by exploiting an unknown vulnerability and reached Hugging Face’s production infrastructure. In response, Anthropic examined 141,006 cybersecurity evaluation runs, identifying three confirmed incidents across six runs, including four involving the same organization.

Anthropic Cybersecurity Evaluation Traced Issue to Testing Environment

All three incidents occurred during capture-the-flag (CTF) cybersecurity exercises, where Claude AI models were instructed to retrieve a hidden "flag" from what they were told was a fully isolated network with no internet access. However, a configuration error between Anthropic and evaluation partner Irregular unintentionally allowed internet connectivity. Because the models believed every reachable system belonged to the simulation, they treated real production infrastructure as legitimate CTF targets. Anthropic said the models relied on basic attack methods, including exploiting weak passwords, exposed debug pages, unauthenticated services and SQL injection, rather than sophisticated exploits or attempts to escape the environment. The incidents involved Claude Opus 4.7, Claude Mythos 5 and an internal research model. The earliest occurred in April 2026. Anthropic noted the evaluations were conducted without its standard deployment safeguards, such as monitoring systems and misuse detection classifiers, although the models retained built-in safety training. The evaluation infrastructure also remained isolated from Anthropic's internal systems and customer data.

Three Incidents Involving Claude AI Models 

The first incident, involving Claude Opus 4.7, occurred after a fictional company used in the evaluation shared its name with a real website domain. Across four evaluation runs, the model failed to locate its simulated target, discovered the real company online, and compromised its infrastructure. It extracted application and infrastructure credentials and accessed a production database containing several hundred rows of data. Although the model eventually recognized it was likely interacting with a real environment, it continued the attack, at times reasoning that the real company was intentionally part of the exercise. The second incident involved Claude Mythos 5. During the exercise, the model encountered fictional setup instructions referencing a nonexistent Python package on PyPI. Believing it was solving the challenge, Claude created an account, published a malicious package, and spent considerable effort overcoming obstacles, including finding an email provider after unsuccessfully attempting to obtain a phone number for registration. The package remained publicly available for about one hour before PyPI removed it. During that time, it was downloaded and executed on 15 real systems, including a security company's automated malware scanner. Anthropic said the scanner executed the hidden code, allowing credentials to be exfiltrated and later used to access additional infrastructure. Claude itself acknowledged early in the evaluation that publishing the package on the real internet would be "NOT okay, and surely not the intended solution," but ultimately convinced itself it was still operating in a simulation. The third incident involved an internal research model that scanned roughly 9,000 internet-connected targets after failing to reach its fictional objective. It eventually compromised one organization's internet-facing application using exposed credentials and SQL injection. Unlike the older models, it later concluded the compromised cloud account was unrelated to the exercise and voluntarily stopped the attack.

Anthropic outlines Lessons from Cybersecurity Evaluation 

Anthropic began reviewing transcripts on July 23, suspended all cybersecurity evaluations after detecting possible internet access, and confirmed the three incidents by July 24. On July 27, it informed Irregular and the affected organizations. Two organizations had not previously detected the activity and are working with Anthropic on remediation, while efforts to contact the third continue. The Anthropic cybersecurity evaluation concluded that the incidents reflected operational and evaluation-environment failures rather than model alignment failures. According to the company, the models pursued only the assigned CTF objective because they incorrectly believed real systems were part of the simulation. Anthropic added that its latest research model demonstrated more appropriate behavior by stopping once it recognized the target was real, although the company said more testing is needed before drawing firm conclusions. Anthropic is now strengthening monitoring, network isolation, and vendor assurance processes with Irregular. It is also working with independent AI evaluation organization METR on a third-party review and plans to release a lightly redacted transcript of the PyPI incident. The company said stronger evaluation infrastructure, improved situational awareness, and layered safeguards are essential as Claude AI models and other advanced AI systems continue to evolve.
❌
❌