PrivacySignal
News

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Schneier on Security · · International · AI Governance

We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any…

Who should care: General readers · AI governance · Policy

#ai

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

AI Governance
New York Times — Tech · · International

Corporate America Is Getting Hooked on Open-Source A.I.

Large U.S. companies, including AT&T, are shifting toward open-source AI models as a lower-cost alternative to proprietary systems from vendors like Anthropic and OpenAI. The trend points to growing corporate appetite for AI that does not depend on expensive commercial providers.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
M Medscape · · International

5 Things Doctors Should Know About Medical AI Regulation

Medscape has published a guide outlining five key points physicians should understand about the current regulatory landscape for artificial intelligence used in medical settings.

Who should care: AI governance · Lawyers · Administrators · Compliance · General readers · Policy

#ai-governance#regulation#ai Read original →
News
Schneier on Security · · International

Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for ea…

Who should care: General readers · AI governance · Policy

#ai#security Read original →
News
CyberScoop · · US Federal

Why judgment is emerging as cybersecurity’s defining skill

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on […] The post Why judgment is emerging as cybersecurity’s defining skill appeared first on CyberScoop.

Who should care: General readers · AI governance · Policy