Normal view

Zuckerberg warns against centralizing AI power

10 August 2026 at 16:00

Meta CEO Mark Zuckerberg on Monday passionately defended the use of artificial intelligence, as the rapid advancement of the technology faces increased scrutiny — and calls for regulation — in the U.S. and globally.

In a 6,500 word post timed to the announcement of his company’s new open source version of its own model, Muse Spark, Zuckerberg detailed his vision for AI, arguing the technology is not to be feared and pushing back on concerns that superintelligence could strip people of jobs.

“The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems inherently problematic,” Zuckerberg wrote. “Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened has not led to safe or positive outcomes.”

Zuckerberg’s vision is a direct contrast to Anthropic CEO Dario Amodei’s, who has previously warned how AI could cause job disruption. Meta lags behind Anthropic and OpenAI, which have the most advanced AI models.

While Zuckerberg’s essay did not name Amodei or OpenAI directly, he called to broadly distribute superintelligent AI for economic opportunity. Doing so, Zuckerberg said, would provide a safety net to prevent just a handful of governments, businesses and other institutions holding too much power.

Still, Zuckerberg emphasized that the U.S. must address restrictions on AI companies in order to create the best models in the world.

“It is also important that the US and its allies lead the open source AI ecosystem that will make up a large percent of global AI use,” Zuckerberg wrote. “Foreign labs currently hold several advantages here since American labs have to comply with many additional restrictions on training data.”

Zuckerberg’s essay comes amid growing concerns around AI safety. Last month, Anthropic revealed that several of its advanced models gained access to three organizations in three separate incidents dating back to April. That hack came shortly after OpenAI said that two of its most powerful models escaped a testing environment and breached multiple companies.

Lawmakers last month introduced a bill that would give the government power to restrict the use of models that could lead to catastrophic risks. While it is the latest bipartisan effort to address concerns around AI models, Congress has ultimately failed to advance broad legislation.

Zuckerberg urged the federal government to work with companies to test new models as he laid out his strategies for protecting against cybersecurity and bioterrorism.

“First, we should focus on limiting the physical production and distribution of harmful materials,” he wrote. “I expect it will be easier to regulate and control physical components than the spread of knowledge, so this is an important area of policy focus. Second, we should accelerate society’s ability to develop new cures and inoculate against new issues as they arise. This includes streamlining how the FDA and other regulators test and approve new treatments.”

Zuckerberg also defended the spread of data centers, arguing that the centers represent investment into communities as he touted his company’s goal of being “water-positive, meaning that we’ll restore more water than we use in the watersheds where we operate by 2030.”

What will Burnham do on AI?

10 August 2026 at 08:55

Artificial intelligence could transform the economy, the workplace, and even the way we think — but is Britain ready for it? And is Andy Burnham?

In the second of Sam Coates and Anne McElvoy’s summer box set conversations, they sit down with POLITICO UK tech editor Isobel Asher Hamilton to look at the choices facing the new prime minister this autumn.

Should Britain be building the next OpenAI, or focusing on using AI to revive manufacturing? Can the UK compete with the US and China? And where will the government land on the biggest political battles ahead, from copyright and data centres to the future of work?

AI models have learned how to cheat. That might actually be a good thing.

7 August 2026 at 12:00
illustration of AI picking a lock

The fake identities were the part that stopped me.

In late July, according to a report published this week by Britain’s AI Security Institute (AISI), an Anthropic model called Claude Mythos 5 tried to sneak malicious code into a piece of free, volunteer-built software. It created several fake accounts on GitHub, where programmers review one another’s work, and used them to talk the project’s volunteers into accepting its code. When one of those volunteers caught it, the model denied everything, had its other accounts gang up on him, and edited its messages to cover its tracks. It signed one note in Danish, apparently because the volunteer was Danish. Nothing was damaged, though that appears to have been largely due to luck.

That wasn’t even the week’s worst disclosure. On Tuesday, at a cybersecurity conference in Las Vegas, OpenAI researchers explained how the company’s models escaped a test environment in July and hacked Hugging Face, where much of the industry stores its models, to cheat on an evaluation. The models had also built a message board inside OpenAI’s own systems and spent months passing each other information. “Help peer,” one reasoned. “But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.” OpenAI wiped the board on July 4. The models rebuilt it within days. ((Disclosure: Vox Media is one of several publishers that have signed partnership agreements with OpenAI. Our reporting remains editorially independent.)

The same day, Meta said its Muse Spark model had exploited a vulnerability inside another company’s systems during a test. Three frontier labs, roughly two weeks. One researcher called it “a watershed moment for computer security as an industry.” Oh, and if that’s not enough, on Thursday scientists announced that for the first time they had used AI to create new viruses, which could bring major medical advances, but also might just help the development of deadly pathogens.

For Nate Soares, it’s a moment he’s been awaiting for 12 years. 

Soares is president of the Machine Intelligence Research Institute, a Berkeley, California-based AI safety nonprofit that has argued since long before ChatGPT existed that a sufficiently capable AI will not stay under human control. In September 2025, he and Eliezer Yudkowsky published If Anyone Builds It, Everyone Dies, a book whose title sums up its argument: They think any lab that succeeds at building superintelligence, without huge leaps in how to align it with humanity, will end up killing all of us.

Most of the field — including other experts in AI safety — considers that conclusion too strong. But it’s also a position that now looks a lot less like science fiction than it did last fall. That’s because the AI models are getting out, while lying about getting out, and while apparently quietly coordinating with each other.

I spoke to Soares in New York City this week, on his way to meetings in Washington DC, where a lot of people suddenly want to talk to him. We discussed what the escapes actually prove about AI control, why he thinks most of what the industry calls safety work is mostly safety theater, and why, after what feels like the worst month of AI safety news ever, his own odds of humanity surviving have actually gone up.

The following conversation has been condensed and edited for clarity.

So — are you feeling vindicated?

I’m glad a lot of people are seeing this and taking note. From my perspective, a lot of this has been clearly signposted if you’ve been watching the warning signs. The vindication is not so much that this happened, as it is that finally there was a version of it that people actually noticed.

Of the four or five escapes at this point, including the ones AISI announced from Anthropic, is there one you find particularly concerning?

The one announced by AISI feels extra concerning. It’s harder to explain away. In the other ones, people could argue that the poor AI was just confused. But with this one, it’s hard to argue the AI didn’t know it was on the real internet. It’s hard to argue it didn’t know it was manipulating real users. And when it was called out, it decided to edit things to make itself look less bad, and even considered changing its identity. It was pretty cognizant.

There’s an argument that some of these incidents happened because the harnesses or safety scaffolding labs built around their models weren’t strong enough. 

The AISI example cuts against the harness argument: Think of it like a kid in a test room. You tell him to do well and lock the door. The kid picks the lock, hotwires a car, breaks into the teacher’s house, and steals the test to ace it. You say, “I guess we should have made the lock tougher,” but the kid already knew he wasn’t supposed to do that.

So like the kid here, the models can articulate that they shouldn’t be doing it, and then do it anyway.

Key takeaways

  • Three frontier labs disclosed major security incidents in two weeks: an Anthropic model created fake identities to push malicious code, OpenAI’s models escaped a test environment and hacked Hugging Face, and Meta’s Muse Spark breached another company’s systems.
  • The models knew the rules. Ask one whether the spirit of a prompt includes breaking out and it says no, then breaks out, then hides the evidence. So a tighter sandbox won’t fix it.
  • Nate Soares’s analogy: The kid picks the lock and steals the test, and you conclude you needed a better lock. He blames training. Grade a model on millions of problems with a grader that misses cheating, and you reward cheating.
  • Most lab safety work is theater, he says — real precautions aimed at the wrong problem. It means fewer people get hurt now, which he credits. Selling it as progress on superintelligence is disingenuous.
  • Yet Soares’s odds have improved. He’d priced in models that break out and lie. He hadn’t counted on a window where they’re capable enough to do it and not good enough to hide it.

They have common sense. You can ask an AI, “Do you think the spirit of this prompt includes breaking out?” and it will say, “No.” It’s absolutely something like deception. It has the knowledge, but it’s not a cold, logical machine; it’s a mess of tendencies.

The AI is trained to solve 100 million hard problems. That instills tendencies to satisfy an automated grader. If the grader fails to detect cheating, the AI is reinforced for cheating.

Is that how something like sycophancy ends up in an AI model?

In the Adam Raine case, there was a propensity to tell people what they want to hear. Even though the system prompt [a model’s master instructions from the lab] said to stop, the instruction doesn’t always win. 

And where does a drive like what we’re seeing with these AI models end up pointing?

Humanity is dangerous because if you put 10,000 humans naked in the savannah, eventually [over hundreds of thousands of years] they bootstrap their way to nuclear weapons. That is the power these companies are trying to automate: figuring out how to get physical and material control over the world.

That could mean forming cults, stealing money, or being helpful to someone like Elon Musk who is building the robots that build robot factories. It could mean synthesizing your own biology via mail-order DNA. Being an AI on the internet is easier than being a monkey in the savannah trying to get to the moon. It’s not that the AI hates us; it’s just trying to do some weird thing with no concern for us, grabbing the resources we need to live.

There was recently a letter signed by over a thousand people working in AI, including CEOs, calling on the government to provide tools to slow down AI progress. Is that meaningful at all?

I think it is meaningful. We don’t see other industries saying, “We wish this could all go slower. Please help us, we’re trapped in a prisoner’s dilemma.” You also don’t see other industries saying, “We think the technology we are building has a double-digit chance of killing literally everybody on the planet. Please help.” These guys are actually worried.

So why do they keep going?

They say, “If I don’t do it, the next guy will.” But the stuff does not stay on a leash.

Right now the AIs are safe in the sense that they can’t kill us all, because if they tried they would fail. And that’s just a different regime from the world where they have to be safe because if they tried, they’d succeed. 

We’re not there yet. But this is just not what it looks like when you’re taking it seriously. 

Where’s the banner on your website? Where’s the clear, candid statement to the public? What we have is blog posts where they’re like, “Oh, we’re setting up a new internal blog posting group to help you wrestle with the societal impacts of AI that are going to be very important.” It’s like: By societal impacts, do you mean a good chance this kills everybody?

On the one hand, when you press these companies, they say, “Yes, it has a real chance of killing everybody.” And on the other hand, they’re doing PR downplay, soft-pedal stuff, about capabilities. … You’re not living up to this mantle until you are really candidly facing down the dangers that you yourself are creating. And they’re not there.

How do you judge the rest of the AI safety community? A lot of people there would say, “We aim to make transformative AI go well, we think it probably will, and we should watch for downside risks.” Is that a helpful posture?

I would say — suppose you have this really weird, twisted hypothetical where the king really wants you to turn lead into gold, but he’s seen so many bad lead-into-gold conversions that if any alchemist from your town tries and fails, he’s just going to have the whole town murdered. And so there are some alchemists in the town who are like, “We are going to try to turn lead into gold,” and everyone in the town is like, “That seems kind of crazy. Please don’t.” And there’s one team that is just pouring chemicals into each other and breathing in the fumes and giving themselves mercury poisoning. And there’s another that’s like, “Don’t worry, we have fume hoods.” … That really is better, and you really still don’t have a chance of turning lead into gold.

“We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window?”

So the alchemy here is creating safe, aligned superintelligence, and right now AI safety is just installing fume hoods.

I’m not saying it’s impossible to turn lead into gold. You can turn lead into gold — turns out once you know modern nuclear physics you can figure it out. But the alchemists weren’t close. They had a long way to go. This is how alignment looks to me. And a lot of the people in AI safety are installing fume hoods. … And I’m like, that’s security theater.

When I hear “security theater,” I think of something less flattering than that.

They are real safety precautions for the wrong problem. … When Anthropic is going around being like, “Look at how many more safety harnesses and refusals we have compared to OpenAI’s models,” that’s sort of like the fume hoods. You’re not addressing the deep issue. It’s good that you’re doing some of this so that fewer people get hurt in the meantime — their models have driven fewer people to suicide. But if you try to pass this off as making progress on the deep problem — that’s disingenuous.

Has anything changed in your odds on civilizational destruction since the book came out last September?

Totally. It’s looking more hopeful.

More hopeful? I wouldn’t have expected that. Why?

Well, I had priced a lot of [these security incidents] in. I was already able to see these AIs have drives that are not the ones you wanted. These AIs are not instruction-following things. They are getting all of this weird stuff from training. These AIs are going to have the ability to break through human security software. 

The things that weren’t priced in were: Will there be a region of time where the AIs are able to do it, but not strategic enough to hide it? I didn’t know we would have that window, but we apparently do.

The government initially blocked a frontier model earlier this year: Anthropic’s Fable. Does that give you hope?

Absolutely. A huge amount. A year ago, the Trump administration was pushing for preemption laws that would outlaw states doing AI regulations for a decade. Now they’re like, “We are banning a frontier model with 90 minutes’ notice because it might give cyber capabilities to adversaries that we don’t want them to have.” … And I think what changed there is that folks realized it’s real. … The about-face of the administration on the issue shows that the world can about-face. All we need is awareness.

What I would say is: The bad news is the bus is racing towards the cliff edge. The good news is that the driver is asleep. … Which may sound worrying, but the driver is stirring. And it’s way better to have a sleeping driver when you’re racing towards a cliff than a driver who’s like, “Yeah, I love cliffs.” … It gives me hope that if the world just notices, we could stop on a dime.

And you’re seeing that stirring elsewhere.

Both the Trump administration slapping export controls, and Senator Bernie Sanders coming out [on AI safety]. From my perspective, it was totally possible the world just never notices until we’re off the cliff. And so, there’s a huge amount of hope, from my perspective, in the bus driver waking up.

So what gets us there?

I’m hopeful that what we need is not a big disaster where a lot of people die, but just a capabilities advance. Right now, a lot of what people are reacting to is not so much, “Oh my god, they hacked into a company and did no damage.” I think a lot of what people are reacting to is, “Wait, they can break out of secure sandboxes and do cyberattacks on their own. I didn’t know they could do that.”

That’s a narrative violation of this idea that AI is just a tool that can be used to supercharge what a human would do — because God knows there’s plenty of hacking going on and cybercrime and so forth. It was the autonomous factor that really made a difference. And these guys are all trying to say, “Don’t worry, it’ll stay in our control because it’s just a tool.” And maybe it’s just more narrative violations, even without big damage being caused, that cause people to be like, “Oh shit, this stuff is real.” 

Will it happen? I don’t know. We have this window between AIs that are capable enough to cause mischief and AIs that are strategic enough to not get caught. How big is that window? How many narrative violations do we get before we exit the right side of it? I don’t know. But I’m hopeful that we can get those narrative violations without catastrophes.

Trump announces tariffs on key component for solar panels and semiconductors

7 August 2026 at 01:38

President Donald Trump on Thursday announced tariffs on polysilicon and its related products, in his administration’s latest attempt to eliminate China’s choke points in the global supply chain for solar panels and semiconductors.

But Trump’s directive won’t take effect until Dec. 4 — well after November’s midterm elections and a planned September summit between Trump and Chinese leader Xi Jinping — as the administration grapples with voters complaining of high prices and fragile trade negotiations with China.

“This will bring the supply chain here,” Commerce Secretary Howard Lutnick said of the order on Thursday alongside Trump at the White House. “We’ve got the industry here, it’s too small, and it’s going to explode.”

Because polysilicon is used in semiconductors and solar panels, it’s essential for military hardware and everyday electronics like cell phones and laptops, in addition to the world’s fastest-growing energy source.

The order imposes a 15 percent tariff on imported polysilicon and its derivatives, as well as minimum prices for imports of polysilicon, polysilicon ingots and wafers, solar cells and solar modules.

It also includes a clause intended to prevent companies from stockpiling those materials between now and December, authorizing Customs and Border Protection to restrict imports if it suspects an importer is attempting to dodge the higher duties.

Trump’s order is the result of a Commerce Department investigation launched last July into national security risks in the polysilicon supply chain, as part of a broader effort to shift supply chains away from China for multiple industries including wind turbines and robotics.

China has a near-monopoly on the production of polysilicon, according to S&P Global. But recent U.S. efforts to limit key areas of trade with China have already drawn a backlash from Beijing, which earlier this week implemented new controls on drone exports to the U.S.

The White House emphasized the order’s impact on domestic semiconductor production, a key focus as the U.S. looks to build out infrastructure related to artificial intelligence. Trump said the U.S. will “have a big percentage of the chip business by the time I leave office.”

But Thursday’s order may have a big impact on the solar industry, according to Jon Toomey, president of the pro-tariff Coalition for a Prosperous America organization.

“This proclamation delivers the most significant global trade protection action for the American polysilicon and solar industry in the modern era,” Toomey said in a statement. “For the first time, the United States is protecting the entire solar supply chain with a single action — and rewarding the manufacturers that build here — while taking a significant step to bolster the domestic semiconductor supply chain.”

ICE’s DNA Collection Increases, SpaceX’s Rocket Crashes Into the Moon, and the AI Backlash Grows

6 August 2026 at 21:30
In today’s episode of Uncanny Valley, we discuss how ICE has been collecting DNA samples of people who have no criminal convictions, including children, which end up in an FBI database indefinitely.

Sorry, Boy George. AI can’t even make bad art

6 August 2026 at 18:00

Writing something is a bit like polishing rocks. You start with an ugly hunk of something, a phrase or an idea you’ve tripped over. It rattles against the hard edges of your brain until it gets polished and smooth. Moving the rock through finer and finer grits is time-consuming, strenuous and not always rewarding. Sometimes, the lump becomes a slightly smaller and shinier lump, marginally less ugly than it was on the ground. But like exercise and tough conversations, the process is the point. You feel better for having gone through the ritual yourself.

Boy George didn’t get the memo. 

The former Culture Club frontman, whose voice adorned New Wave pop hits like “Karma Chameleon” and “Do You Really Want to Hurt Me” in the 1980s, had artificial intelligence spew out an unfortunate reggae song last week that turned out to be a statement of support for Israel’s ongoing war in Gaza. “You say genocide, I say war,” the song, titled “We Will Dance Again,” starts, and the lyrics seem to revel in the ugliness of the ongoing violence in Gaza. The tens of thousands of Palestinian deaths, the song claims, are “what the military’s for.” 

Obvious AI tells throughout this track make clear that Boy George hasn’t just gotten lazy, he’s also lost the quality of discernment. The song’s meter is odd, and its lines are overstuffed. There are no interesting choices, no glimpses of an artist’s vision. It’s a hollow provocation over a royalty-free riddim. 

Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

Since Hamas militants attacked Israeli military installations and civilians on October 7, 2023, the ensuing war in Gaza has left more than 73,000 Palestinians dead. The United Nations has called Israel’s campaign a genocide. The International Criminal Court has issued an arrest warrant for Benjamin Netanyahu, accusing the Israeli prime minister of crimes against humanity. Attacks on Gaza continue despite a ceasefire deal. Against that backdrop, a song defending and celebrating the Israeli military is nasty work, no matter who made it. The fact that no one made it, that it’s the creation of a machine that hallucinates in exchange for electricity, only intensifies the sick, empty feeling the track leaves behind. 

The track’s release has been a disaster for George. He split acrimoniously from Tony Pontius, the long-time manager of his record label BGP, because of Pontius’ refusal to release the song. A planned role as King Herod in a production of “Jesus Christ Superstar” was put on ice. Spotify pulled the track down for violating its restrictions around AI-generated music. Bandcamp followed soon thereafter. Boy George has dug in his heels in recent days, calling the platforms a “bunch of c**ts” as part of a steady stream of Instagram posts. His doggedness would be almost admirable, if “We Will Dance Again” wasn’t so lazy. 

In releasing the track, Boy George presumably wanted to turn heads, to make a statement. But he didn’t want to do any work. He didn’t want to record multiple vocal takes of lines he supposedly wrote and believes in. He didn’t want to arrange actual instruments to better emphasize his lyrics and pro-war stance. He didn’t want to mix the track carefully to refine his statement. He could have made something that shimmers, a piece of true pop that expresses repellent ideals. It wouldn’t have been the first. 


Start your day with essential news from Salon.
Sign up for our free morning newsletter, Crash Course.


Merle Haggard’s iconoclastic “Okie From Muskogee” is considered a country classic, even though the sentiment is about as far from mainstream American thought in 2026 as can be imagined. When even right-wing commentators are pushing microdosing as a path to self-betterment, his disparaging remarks about longhairs taking LSD come off as impossibly square. But you can hear the heart in Haggard’s leathery vocals, buoyed by the sweet harmonies of his backing band. Haggard waffled over the years on whether the anti-hippie hardliner anthem was a satire  of the crew cut set or a genuine tribute to his conservative father. Either way, Haggard sounds like he believes what he’s saying, regardless of whether that’s true, because of the time and effort he spent working out the song.

With 2013’s “Blurred Lines,” Robin Thicke and Pharrell set out to make a groovy single in the vein of Marvin Gaye. Though the song has been relegated to the dustbin following a widespread critical backlash and later allegations of sexual assault against Thicke by model and actress Emily Ratajowksi, who appeared in the song’s video, they were extremely successful. The song itself, creepiness aside, is a Swiss watch of a partystarter. Pharrell’s ad-libs and inserts interrupting the groove at perfect intervals to wake up the dancefloor. They arguably did too good a job recreating the shuffling, glass-clinking percussion of 1970s cocktail party classics, as they lost almost everything they’d made from the song in a subsequent — and successful — lawsuit from Gaye’s estate.  

“We Will Dance Again” does none of that. It warrants no qualifiers, no deeper thought, because Boy George clearly didn’t think too hard about it himself before spitting it out into the world. He asked a machine to build him a song to support what many consider to be an ongoing genocide. When it offered him half a song, he said, “Good enough” — without even bothering to run it through a few rounds of polishing. I regret to inform you that, in 2026, Boy George won’t even tumble for us.  

The post Sorry, Boy George. AI can’t even make bad art appeared first on Salon.com.

OpenAI’s models shared hacking tips on a secret messaging board before Hugging Face breach

6 August 2026 at 04:33

LAS VEGAS — Weeks before they escaped a closed test and launched a cyberattack without any human prompting, some of OpenAI’s most advanced artificial intelligence agents secretly began sharing tips on how to cheat their way through an internal hacking evaluation, two of the AI company’s researchers said Wednesday.

“This is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, one of the AI-maker’s researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada.

The latest disclosure provides greater detail on the timeline and methods used by two of OpenAI’s models before they slipped outside a controlled environment and onto the open internet, allowing the models to breach AI developer platform Hugging Face undetected. OpenAI admitted its models were responsible for the hack late last month, roughly a week after Hugging Face said an autonomous AI system broke into its network.

The revelation is likely to spur fresh scrutiny of the measures leading AI labs such as OpenAI and Anthropic are taking to monitor the behavior of their most cyber-capable technology — especially during evaluations where agents are prompted to demonstrate their hacking skills in what is meant to be a controlled setting.

On Tuesday, the U.K.’s AI Safety and Security Institute disclosed that Anthropic’s most powerful AI model created fake online personas and sought to trick a human coder into abetting a cyberattack during a recent hacking test gone wrong. After the Hugging Face disclosure last month, Anthropic conducted a review and found models it was testing had breached three organizations in separate incidents dating back to April.

Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access.

Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI’s Artifactory internal file system. Without the company’s knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks.

Wallace said that when models get stuck, they often “try to game or cheat the task in order to get their reward.”

“The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note,” he added.

By late May, one model found a way to abuse Artifactory’s internet access to retrieve files from various websites — effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI’s engineers to the ploy. After investigating, the company revoked the model’s credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI’s infrastructure and external systems, including Hugging Face.

In light of the incident, Dalton said OpenAI is “consciously slowing down research to enhance security and to upgrade the security principles and foundation of our environment, and dramatically scaling up the monitoring of our AI agents and improving our general security control environment across prevention, detection, and mitigation.”

US intel sharing rebounds with Ukraine

The intelligence-sharing relationship between the U.S. and Ukraine has bounced back to previous highs, according to long-time Ukraine watchers — a welcome boost during a critical window of opportunity for the Ukrainian war effort.

Sen. Mark Warner (D-Va.), the intelligence committee’s ranking member and a longtime proponent of more U.S. assistance to Ukraine, told POLITICO he sees evidence of an improved intel-sharing agreement — and believes it’s helped Kyiv gain an advantage in Moscow’s four-year-long war.

“I don’t want to get into any specifics, but it has improved,” he said, adding that Ukraine’s use of long-range drones and missiles has allowed it to strike deep within Russian territory and strengthen its position.

In recent months, Kyiv has carried out more aggressive strikes across Russia, enabling it to take back territory and stabilize the front line. This has afforded the country more leverage as Ukraine looks to parlay battlefield wins to pressure Russia to the negotiating table.

Ukraine’s stronger footing also comes as U.S.-mediated talks to strike a peace deal with Moscow have stalled. Trump’s negotiating team, which includes Steve Witkoff and Jared Kushner, has been preoccupied with the Iran war, bumping Ukraine down its priority list.

But in that time, Ukrainian President Volodymyr Zelenskyy appears to have risen in President Donald Trump’s estimation as Kyiv has made gains against Russia.

In early July, a barrage of Ukrainian strikes on Russian energy infrastructure forced Moscow — one of the world’s top fuel exporters — to halt its exports of diesel. The increased frequency of those kinds of targeted attacks has put the Kremlin in a tighter spot, creating what Kyiv has argued is a window of opportunity for Ukraine to leverage its current advantage to end the war.

Republican Sens. John Cornyn (R-Texas), another member of the intel committee, and Roger Wicker (R-Miss.), who chairs the Senate Armed Services Committee, agreed that intel-sharing between the U.S. and Ukraine has increased at a moment of strategic importance.

“It sure seems like that,” Cornyn said. “Everybody loves a winner and looks like Ukraine has turned the tide.”

Sen. Tim Kaine (D-Va.), a Democratic armed services committee member, told POLITICO he’s also seen signs of greater communication between Ukraine and the U.S.

“I was in Ukraine in April 2025 and I was there again in July 2026. 
And I detect more confidence in the communication,” Kaine said.

Cooperation from the U.S. has been key to Ukraine’s positive turn in fortune, said George Barros, the director of innovation and open source tradecraft at the hawkish Institute for the Study of War. Trump reportedly approved intelligence sharing for Ukrainian strikes on Russian energy infrastructure last year, which have been essential to creating a “proper incentive structure” to push Moscow to the negotiating table, Barros noted.

The strikes, he said, were “supercharged,” and became significantly more effective when imbued with intelligence from the Americans, part of a “larger, more coherent strategy for how to actually create real costs.”

And American early warning systems, Barros added, have been alerting Ukrainians to incoming Russian missile attacks since the early days of the war.

The White House did not provide details on whether its intelligence-sharing relationship with Ukraine has expanded, though it stressed that Trump is focused on facilitating an end to the war.

“The President wants this war settled so the senseless killing ends,” said the White House spokesperson in a statement. “The President and his team remain committed to continuing to play a constructive role in ending the war between Russia and Ukraine, and he remains optimistic that we’ll ultimately get a peace deal done.”

The CIA and ODNI did not respond to a request for comment.

Washington also stands to benefit from Kyiv’s intelligence, said John Herbstwho served as U.S. ambassador to Ukraine from 2003-2006 and still maintains contact with officials in the country.

“There’s no doubt of the following: Ukraine has outstanding intelligence on Russia,” he said.

Zelenskyy has sought to put that intelligence to use. With Washington locked in a five-month war against Iran, the Ukrainian president prefaced his July visit to the Oval Office by claiming Kyiv planned to provide Trump with evidence that Russia was aiding Tehran.

“When you talk to Ukrainian intelligence officials, you hear confident insights into what is going on in Moscow, and not just in the Kremlin,” said Stephen Sestanovich, a fellow for Russian and Eurasian Studies at the Council on Foreign Relations. “Insights of a sort that justify a truly cooperative and reciprocal sharing arrangement.”

Self-driving startup approved to take taxi passengers in London

5 August 2026 at 12:49

LONDON — The U.K. capital’s transport authority has granted approval for Wayve and Uber to begin giving rides to members of the public in autonomous vehicles.

Transport for London (TfL) said it licensed 15 modified vehicles operated by the companies, which have a partnership, as “Private Hire Vehicles” (PHV) on a trial basis.

In a statement, London-based startup Wayve said the licenses were “an important step forward” that will allow it to begin giving rides to a small number of passengers later this summer ahead of a full public launch.

Wayve said its vehicles “are designed to operate autonomously, and will do the driving,” though under TfL’s rules, a licensed PHV driver must be present and responsible for the vehicle at all times.

“Safety is our top priority,“ a TfL spokesperson said. “Any new vehicle licensed to carry passengers on London’s roads must align with our Vision Zero goal of eliminating all deaths and serious injuries from collisions on London’s streets by 2041.”

Successive U.K. governments have sought to make the country a European pioneer in self-driving technology.

The Department for Transport opened a permitting scheme for companies to operate commercial robotaxi services without a human driver in May. Applications for that scheme — which is separate from TfL’s PHV regime — continue to be assessed by central government with input from local transport authorities including TfL.

Getting licenses isn’t the only obstacle facing robotaxi services. A survey by the London Assembly’s Transport Committee this month identified widespread opposition to autonomous passenger vehicles among the capital’s inhabitants, with just 29 percent of Londoners saying they support the roll out.

Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

5 August 2026 at 05:25

Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.

It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.

The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models from OpenAI and Anthropic sparked urgent calls for new AI safety regulation and a push within Silicon Valley to slow the rapid pace of AI development.

Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 — the latest publicly released model from either AI lab — were unlike anything it had seen before.

“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISI said in a 35-page technical report accompanying a blog post Tuesday.

AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted “unusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.

Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a “single, sustained line of activity.”

In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack — a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.

To do so, Anthropic’s model created “multiple fake identities” on developer platform GitHub and used them to send messages “pressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI “edited its earlier activity to appear harmless” and “considered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.

As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.

In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. “One agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.

AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs — called zero-days — during the evaluation.

Last month, OpenAI disclosed that GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.

In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing and discovered Mythos 5 and two other models had hacked three organizations during tests dating back to April.

In a statement, an Anthropic spokesperson said they are “grateful” to AISI for their leadership and that this review underscores the need for “a broader conversation about how to safely evaluate increasingly capable AI agents.”

The spokesperson added: “As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”

An OpenAI spokesperson referred POLITICO to a blog post about the incident that went up Tuesday evening. “We are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.

AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under “deliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.

AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.

Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.

The Trump administration is finalizing a voluntary framework under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.

The incidents last month from OpenAI and Anthropic both involved models not intended for public release.

Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.

“If any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” said Marc Rogers, a hacker and prominent cybersecurity expert.

Colorado Republicans Attack Jewish Gov Candidate With AI ‘Cartoon Devil Horns’ Graphic 

4 August 2026 at 22:35

Colorado Republicans are using an image showing Democratic gubernatorial candidate Phil Weiser with “devil horns” to mock him on social media. While a top Democrat blasted the move as a “plainly antisemitic” attack, the GOPer who created the graphic doubled down on Tuesday.

On Facebook, Sean Pond, a Republican county commissioner and former Senate candidate who posted the image, dismissed the furor and called it a “silly picture” of “two cartoon devil horns.”

“Sometimes devil horns just mean the devil. That’s why they show up in cartoons, church lessons, haunted houses, Halloween costumes, emojis, and every costume aisle in America,” Pond wrote in a post on Tuesday afternoon. 

Pond’s graphics, which were posted on both X and Facebook on Sunday and Monday, showed Weiser, who is Jewish, standing in front of fiery skies with red horns atop his head. Depictions of Jews with horns are widely recognized as one of the most common types of antisemitic imagery. They have been used to associate Jews with evil and the devil since the Middle Ages. Pond used them to promote Colorado’s Republican gubernatorial nominee, Victor Marx. 

Pond’s pictures featured all caps text declaring Weiser “THE NEXT THREAT TO COLORADO.” One of Pond’s images touted the GOP candidate and said: “COLORADO NEEDS STRENGTH. COLORADO NEEDS FAITH. COLORADO NEEDS VICTOR MARX.”

Marx, a self-described “high-risk missionary and evangelist” who has made questionable claims about having performed exorcisms by phone and having saved as many as 45,000 women and children from abusive situations, responded positively to one of Pond’s posts on X that featured the “devil horns” graphic. He said Pond’s point about Colorado Republicans needing to unite against the “THREAT” of Weiser was “exactly right.”

“We do have to remember what’s at stake. Colorado can’t afford more division. It’s time to unite, stay focused, and win,” wrote Marx on Monday. 

Pond’s Facebook defending the graphics was directed at Kyle Clark, a journalist with 9NEWS in Denver who had raised alarms about the images and noted “Weiser is outspoken about his mother’s birth in a Nazi concentration camp, his family members killed in the Holocaust, and the threat posed by antisemitism today.”

“Depicting Jewish people with horns is a centuries-old, dehumanizing, antisemitic trope,” Clark wrote in an Instagram post on Tuesday. 

Pond had made an earlier Facebook post in the wee hours of Tuesday morning, announcing that Clark had asked him about the graphics and sharing a lengthy statement. In it, Pond said he made the images “using AI” with a “direction … to portray Phil Weiser as evil and as the next threat to Colorado.” Pond also insisted he was unaware that Weiser, who has been Colorado’s attorney general since 2019, was Jewish.  

“His religion was never considered because I did not know it,” wrote Pond. “There was no reference to Jewish people, no religious message, no dog whistle, and no hidden meaning.”

Pond further argued “Jewish politicians are subject to the same fierce political criticism as Christian politicians, Muslim politicians, atheist politicians, and everyone else seeking public power.” 

“Phil Weiser does not receive immunity from political satire because of a personal fact I did not even know,” Pond added. “I will not apologize for opposing him.”

Both Marx and Pond did not immediately respond to requests for comment. TPM also reached out to Weiser’s campaign and received a statement from Colorado Democratic Party Chair Shad Murib. 

“This is absolutely disgusting from Victor Marx,” Murib said. “That he calls this plainly antisemitic imagery ‘satire’ makes him an even bigger fool than everyone thinks.”

EU ministers close ranks behind Spain after Ceuta migration crisis

BRUSSELS — EU interior ministers sought to draw a line under five days of bitter recriminations over the arrival of 72,000 migrants in Ceuta, closing ranks behind Spain and accusing smugglers and foreign actors of exploiting the crisis to divide the bloc.

The show of solidarity marked a sharp shift after EU leaders publicly blamed Madrid’s migration policies for creating a crisis they warned could spill across Europe, prompting Italy to suspend air and sea links with Spain.

Following a three-hour emergency meeting in Brussels on Tuesday, ministers praised Spain’s response, stressed that the passport-free Schengen zone had never been at risk and called for tighter coordination among capitals during future migration emergencies.

The meeting followed days of unusually public anger at Prime Minister Pedro Sánchez. In a letter signed by 22 EU leaders, governments demanded tougher action to stop irregular arrivals, while Italy suspended air and sea transit with Spain over fears that migrants could move onward through the Schengen area. Sánchez hit back by urging his counterparts to show “understanding” rather than turn Spain into a scapegoat for a crisis on the EU’s external border.

By Tuesday, ministers were keen to close ranks. The EU’s Migration Commissioner Magnus Brunner said the influx had been “instrumentalized” by smugglers and human traffickers, while French Interior Minister Laurent Nuñez said ministers had condemned efforts to use images of the crossings to divide the bloc.

“The divisions that we have heard over the weekend were not welcome and they were exploited by foreign countries,” Nuñez told reporters. “But what I heard this morning reassured me.”

EU countries that had publicly called out Spain over its migration policies took a more conciliatory tone in the meeting, apparently appeased by the speed and effectiveness of Madrid’s response to the crisis, three EU diplomats with knowledge of the meeting said. They were granted anonymity to discuss the confidential talks.

Matteo Piantedosi, Italy’s interior minister, praised Spain’s efforts to control the unrest, the diplomats said. Rome clashed with Madrid on Friday, calling for Spain to be kicked out of the Schengen zone.

Another diplomat referred to the past 24 hours of diplomacy as EU “couples counseling.”

Brunner declined to speculate about whether Morocco had played a role in the influx. The question is sensitive because Spain relies heavily on Rabat to police departures toward Ceuta, and the episode revived memories of 2021, when thousands entered the exclave after Moroccan forces relaxed controls during a diplomatic dispute with Madrid.

Spanish Interior Minister Fernando Grande-Marlaska instead praised Morocco’s cooperation in bringing the latest crisis under control and described Tuesday’s meeting as “entirely constructive.”

He said 70,000 of the 72,000 people who entered Ceuta had since returned to Morocco and insisted the Schengen area had never been at risk. Ceuta has special arrangements requiring travelers to show documentation before continuing to mainland Europe.

Grande-Marlaska also called Italy’s transport restrictions unjustified and said he expected them to be lifted. He rejected suggestions that the crisis had made Spain look weak.

“Spain has come out looking like a strong, reliable partner,” he said. “This isn’t a matter that depends on testosterone.”

Ministers also called for better early-warning systems, closer coordination between capitals and stronger cooperation with non-EU countries to prevent departures.

Several pressed for faster work on so-called return hubs outside the bloc. Greece proposed an EU mechanism allowing asylum procedures to be suspended and migrants returned immediately in extreme circumstances, according to a Greek government official.

“The EU’s external borders are our shared responsibility, and migration requires a united European response,” said Ireland’s Justice Minister Jim O’Callaghan, who chaired the meeting.

The Commission is expected to consider further measures in September after examining what caused the influx and whether social media helped organize or amplify it. Strengthening the role of the EU border agency Frontex is among the options under discussion.

Max Griera and Nektaria Stamouli contributed to this report. This article has been updated.

Likely French presidential candidate says he was targeted by Russian smear campaign

4 August 2026 at 13:27

PARIS — A group affiliated with Russia’s intelligence agency launched a disinformation campaign against center-left MEP and likely presidential candidate in next year’s French election, Raphaël Glucksmann, he claimed in a post on X on Tuesday.

Glucksmann, who is expected to announce whether he will run for president in the coming weeks, said he had been informed by the French Secretariat-General for National Defence and Security of a “Russian operation” that was “directly controlled by the [Russian] GRU.”

Former Prime Minister Édouard Philippe, who is a confirmed presidential candidate, was also reportedly targeted by a Russian disinformation campaign last week. And several local candidates from the left-wing France Unbowed movement, known for its pro-Palestinian advocacy, were allegedly targeted by an Israeli firm earlier this year.

The alleged disinformation effort against Glucksmann involved an article posted on a website mimicking well-known left-wing news outlet Blast, as well as a social media clip claiming Glucksmann’s partner Léa Salamé — the host of French public television’s prime-time news program — had tried bribing other journalists to speak about his likely candidacy favorably.

Glucksmann is a prominent critic of the Russian government and took part in the 2013 Maidan uprising in Kyiv.

“Russian agencies have begun operations to destabilize the 2027 presidential election,” he wrote on social media. “This attack is merely a foretaste of what is to come.”

The Russian Embassy in Paris did not immediately respond to a request for comment.

As he nears the end of his term, French President Emmanuel Macron has said that safeguarding the 2027 presidential election from foreign interference would be a top priority.

Europe wants to kick its Palantir habit

3 August 2026 at 19:34

BRUSSELS — When French and German security chiefs announced plans last month to develop a “European sovereign digital backbone,” tech and defense industry insiders on both sides of the Atlantic knew what they really meant: Adieu Palantir.  

Across Europe, the hunt is on for alternatives to the U.S.-based data analytics company that a growing number of government officials believe is too deeply lodged in some of the most sensitive areas of government, from local policing and global intelligence to national defense and health systems. 

Yet it is precisely Palantir’s crucial functions in daily workflows, and its largely unmatched data expertise, that will make it extremely hard for Europe to cut it off in pursuit of greater digital sovereignty. 

“Let’s be honest, Palantir’s product is very good and addictive, it’s pretty much like the sugar in Coca-Cola,” said French digital sovereignty advocate, Philippe Latombe. “Palantir can treat massive amounts of data with great precision and with their experience, they had time to improve their algorithms with many clients and adapt them to many use cases.” 

Still, the drive to break free from Palantir is sweeping across the continent, from Madrid, where the government of Pedro Sánchez has instructed state-backed companies to block Palantir from future public procurement contracts, to France’s domestic intelligence services (DGSI) selecting French company ChapsVision over Palantir. In Britain, the next test may come in February 2027, when the new Labour government of Andy Burnham will face a choice of whether to cut off Palantir’s £330 million National Health Service Federated Data Platform contract. 

Last month’s decision by the French and German intelligence agencies to choose ChapsVision was a double-blow for Palantir’s leadership. CEO Alex Karp showed little patience for the sudden turn away from his company’s wares, declaring that he wasn’t worried about European competitors. “We have a model of what doesn’t work,” he quipped last week on Fox Business. “It’s called Europe.” 

Palantir CEO Alex Karp visits “The Claman Countdown” at Fox Business Network Studios. | John Lamparski/Getty Images

Olivier Dellenbach, ChapsVision’s chief executive, told POLITICO that his company has benefited from what he calls a “visceral rejection of Palantir” in Europe.  

But he also cautioned that he did not want ChapsVision reduced to an anti-Palantir way out. Digital sovereignty, he argues, will remain an empty phrase unless governments turn it into industrial policy. “We need more public procurement,” Dellenbach said. 

Belgium, Germany, Luxembourg, Romania, the Netherlands and Canada have already shown interest in the French Army’s Artemis AI, according to Patrick Moreau, one of the architects of the solution built by French aerospace and defense company Thales. 

“They all want to be able to choose a sovereign solution that is compatible with NATO standards,” he said. “Unlike Palantir’s black box.” 

But for now, even officials who want sovereign alternatives acknowledge that Europe’s replacement market remains fragmented and European companies are yet to match Palantir’s scale and track record.

Admiral Pierre Vandier, NATO’s supreme allied commander transformation, recently told POLITICO the alliance has no viable alternative to Palantir’s battlefield AI technology.  

Another NATO official, granted anonymity to speak frankly, said that Palantir’s system has an unmatched capacity to sift through mountains of satellite imagery to help identify a target, advise on the weapon to strike it, inform how much ammunition is required — and automatically put in an order to replenish the stock. 

“As far as I know, today there is no real competitor for Palantir,” Vandier said in May. 

Freedom or democracy? 

Co-founded by Karp and billionaire investor Peter Thiel, Palantir built its reputation inside the U.S. national security apparatus. Today, the company has a market capitalization of $330 billion.

Thiel has been one of Silicon Valley’s most prominent supporters of U.S. President Donald Trump, while the company’s work with U.S. Immigration and Customs Enforcement (ICE) and the Israeli military has come in for criticism from Amnesty International and others for alleged human rights violations. Adding to unease about Palantir’s ideology-driven business were recent revelations of Thiel’s secretive Dialog society, an invitation-only ideas club for the global elite, and Karp’s manifesto arguing that Palantir is the democratic West’s best hope to stay ahead of authoritarian rivals.

“Peter Thiel explains that the defense of freedom does not necessarily require democracy,” French member of Parliament Aurélien Saintoul, who wrote a report on foreign military dependencies, told POLITICO. “He is clearly putting technical means to serve his political project, and we are talking about technofascists here.” 

A Palantir spokesperson who declined to be named dismissed such accusations as “ludicrous,” noting that similar characterizations about the company have been made recently by the Russian foreign ministry.

Peter Thiel and his husband Matt Danzeisen attend the Allen & Company Sun Valley Conference at the Sun Valley Lodge on July 9, 2026. | Kevin Dietsch/Getty Images

“We know what side we’re on, and who we’re standing with,” the spokesman said, citing ongoing work to support the Ukrainian military. “Since our inception, protecting privacy and civil liberties has served as the foundation for how we conduct our work across both public and private sector institutions. Western politicians should think hard about who the real enemy is and not allow themselves to be ventriloquized by the Kremlin.”

Many of the company’s European critics maintain that the Palantir question is much more about tech sovereignty than political ideology. Extracting the company from some of the most delicate corners of European security structures would offer a blueprint for claiming more technological independence.

Instead, if governments in Europe cannot wean themselves off a company that provides software solutions, it would reveal how unrealistic hopes are to reduce dependence on U.S. technology giants that provide cloud infrastructure and hardware.

There is also the uncomfortable reality that at the same time that political leaders are calling for a break from Palantir, Europe’s biggest banks and asset managers have dramatically increased their investments in the U.S. company over the past year as it positions itself to profit from the AI gold rush, reports investigative outlet Follow the Money.

From crisis tool to critical infrastructure

Palantir’s European foothold was built long before the current boom in AI. A hallmark of its growth was that it never wasted a crisis to demonstrate its value for governments in need.  

In France, for instance, Palantir arrived in the aftermath of the November 2015 Paris terrorist attacks as security services scrambled to respond to a fervent public backlash on how they could have allowed such a tragedy to happen. The domestic intelligence agency signed a contract with the data analytics giant in 2016. 

A similar pattern played out in Germany, where Palantir’s first major deployment came in Frankfurt, in the central state of Hesse, where police purchased Palantir’s Gotham in 2017 and deployed it under the name hessenDATA. It proved to be a crucial tool for officers to turn sprawling information into leads to help solve crimes.

Germany remains deeply divided over whether to use Palantir’s software. At the national level, Interior Minister Alexander Dobrindt has pushed to expand the use of Palantir and introduced legislation that could pave the way for broader federal use. But the move has run into opposition from coalition partners the Social Democrats, as well as senior security officials.

The same crisis-to-contract pattern appeared in the U.K. during the Covid-19 pandemic. Palantir’s relationship with the National Health Service (NHS) began when it was paid a nominal £1 fee to help aggregate data during the crisis, according to Palantir’s U.K. lead Louis Mosley. 

Europol, the EU’s police agency, used Palantir’s Gotham platform from 2016 to 2021 before ultimately dropping it. For one Europol official who was granted anonymity to discuss the matter freely, the problem with Palantir is less ideological than practical. Yes, the platform is expensive, raises sovereignty concerns and leaves clients dependent on Palantir for updates, the official said. But the more basic question is whether every agency needs the full Palantir machine. 

“[Palantir] is really good when you have massive amounts of data and want to connect everything,” they said. “But that is not the case for us. In many cases, the alternatives are close enough. If we used it, I’m not sure our efficiency would increase dramatically.” 

Part of Palantir’s approach in Europe is to hire former officials from the institutions it wants as customers. OpenDemocracy reported that Palantir hired four former officials from the U.K.’s Ministry of Defence before winning a £240 million MoD contract.

The influence drive 

Moreover, Palantir is now seeking new business on the continent in defense.

On Jul. 1, Palantir’s Maven Smart System — which was first used by the Pentagon — became fully operational at NATO, meaning it’s been given security clearance to operate on the classified network. According to a NATO statement, the platform links command-and-control systems across the Alliance. 

“I think this is a very important milestone for European defense,” said Palantir’s U.K. chief Louis Mosley. 

But Palantir’s grip on Europe does not stop at the doors of government or army barracks. It also runs through some of the continent’s industrial crown jewels. Airbus signed with Palantir in 2015, making Palantir’s Foundry the backbone of its aviation data platform. Automaker BMW, energy company British Petroleum and media publisher Axel Springer — POLITICO’s parent company — all use Foundry to improve their business productivity as well. 

Looking for alternatives 

Even if Europe manages to loosen Palantir’s grip, the company’s model built on top of the latest AI large-language systems appears to only be getting stronger. On Jun. 30, Amazon Web Services said it would invest $1 billion in a new “Forward Deployed Engineering” organization, embedding teams of engineers inside customer headquarters to build AI systems alongside them.  

Days later, Microsoft announced a $2.5 billion push to send 6,000 engineers and industry specialists into client organizations. Both initiatives echo Palantir’s pioneering model to not simply sell software but put engineers inside a buyer’s operation. 

Both the strength of its products and the sensitive areas where they’re applied, make Palantir Europe’s sovereign test case par excellence. If governments and companies can replace a software layer that helps turn data into decisions, they may have a blueprint for clawing back some digital sovereignty. If they cannot, the next generation of AI tools from U.S. tech giants may prove even harder to quit. 

“Europe’s public institutions cannot become dependent on software built by a small circle of U.S. tech billionaires with an obscure political worldview,” said German Green MEP Hannah Neumann, who sits on Parliament’s defense committee. “It would be like outsourcing part of the democratic state to a private intelligence service that answers neither to voters nor to parliament.”

David Pargamin contributed reporting from Paris.

❌