Reading view

Brendan Carr is one firing away from an unchecked FCC

The FCC seal surrounded by icons of satellites.

President Donald Trump already holds a Republican majority in the agency tasked with regulating America's communications systems. But with a new nomination to the Federal Communications Commission, he could move to shut out opposing voices altogether - albeit at a legal risk.

The FCC is currently composed of two Republicans and one Democrat - Republican Chair Brendan Carr and Commissioner Olivia Trusty, and Democratic Commissioner Anna Gomez. This mixed group gives the agency a three-member quorum that allows it to vote on major actions, though it still falls short of the five members (no more than three from a single party) the FCC is mean …

Read the full story at The Verge.

  •  

Claude will apply invisible watermarks to AI text and images

The Claude logo on a computer screen on an orange background.

Anthropic has pledged to start marking Claude-generated text and images with machine-readable data, in an effort to comply with European rules for AI transparency. "Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported," Anthropic says on a new Claude support page. The changes are invisible to human eyes, but will make it easier for people and online platforms to detect if content was generated by Claude models.

These updates are a future commitment rather than something that will go into effect immediately. New AI labeling and transparency obligations under the …

Read the full story at The Verge.

  •  

Zuckerberg warns against centralizing AI power

Meta CEO Mark Zuckerberg on Monday passionately defended the use of artificial intelligence, as the rapid advancement of the technology faces increased scrutiny — and calls for regulation — in the U.S. and globally.

In a 6,500 word post timed to the announcement of his company’s new open source version of its own model, Muse Spark, Zuckerberg detailed his vision for AI, arguing the technology is not to be feared and pushing back on concerns that superintelligence could strip people of jobs.

“The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems inherently problematic,” Zuckerberg wrote. “Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened has not led to safe or positive outcomes.”

Zuckerberg’s vision is a direct contrast to Anthropic CEO Dario Amodei’s, who has previously warned how AI could cause job disruption. Meta lags behind Anthropic and OpenAI, which have the most advanced AI models.

While Zuckerberg’s essay did not name Amodei or OpenAI directly, he called to broadly distribute superintelligent AI for economic opportunity. Doing so, Zuckerberg said, would provide a safety net to prevent just a handful of governments, businesses and other institutions holding too much power.

Still, Zuckerberg emphasized that the U.S. must address restrictions on AI companies in order to create the best models in the world.

“It is also important that the US and its allies lead the open source AI ecosystem that will make up a large percent of global AI use,” Zuckerberg wrote. “Foreign labs currently hold several advantages here since American labs have to comply with many additional restrictions on training data.”

Zuckerberg’s essay comes amid growing concerns around AI safety. Last month, Anthropic revealed that several of its advanced models gained access to three organizations in three separate incidents dating back to April. That hack came shortly after OpenAI said that two of its most powerful models escaped a testing environment and breached multiple companies.

Lawmakers last month introduced a bill that would give the government power to restrict the use of models that could lead to catastrophic risks. While it is the latest bipartisan effort to address concerns around AI models, Congress has ultimately failed to advance broad legislation.

Zuckerberg urged the federal government to work with companies to test new models as he laid out his strategies for protecting against cybersecurity and bioterrorism.

“First, we should focus on limiting the physical production and distribution of harmful materials,” he wrote. “I expect it will be easier to regulate and control physical components than the spread of knowledge, so this is an important area of policy focus. Second, we should accelerate society’s ability to develop new cures and inoculate against new issues as they arise. This includes streamlining how the FDA and other regulators test and approve new treatments.”

Zuckerberg also defended the spread of data centers, arguing that the centers represent investment into communities as he touted his company’s goal of being “water-positive, meaning that we’ll restore more water than we use in the watersheds where we operate by 2030.”

  •  

Brendan Carr officially unleashes broadcast consolidation

An image showing Brendan Carr

The era of set broadcast ownership limits is officially over, after the Federal Communications Commission (FCC) voted Thursday to end the national ownership cap rule.

The agency's two Republicans, Chair Brendan Carr and Commissioner Olivia Trusty, voted to end the ownership cap, which restricts broadcast owners from holding stations that reach a combined more than 39 percent of US TV households, while Democratic Commissioner Anna Gomez dissented. It formalizes a policy Carr has long criticized, and which he announced last month that he would seek to end at Thursday's open FCC meeting. In place of a set limit, the FCC says, there will now be …

Read the full story at The Verge.

  •  

Europe’s new border system works by being switched off when overwhelmed

BRUSSELS — The EU’s new biometric border-check system is causing such long delays for summer travelers that some airports are turning to a simple solution: switching it off when they’re overwhelmed by arriving travelers.

The quick fix, which is allowed under EU regulations, wasn’t what was envisioned when the Entry/Exit System was gradually introduced in October and went fully into force on April 10.

And yet, many airports are doing just that.

“When lines form during the busy summer months, the system is shut off to ensure smooth transit at our hubs in Paris and Amsterdam,” Air France-KLM told POLITICO. 

Airline CEOs, border authorities, and airport officials said biometric checks are suspended when border crossings become congested at other hubs, including in Frankfurt, Brussels and Milan.

The EES applies to non-EU citizens entering the 29-country Schengen zone. Instead of heading to a border agent to get passports stamped, passengers have to use an EES kiosk to provide their fingerprints and be photographed — which will be kept on file for three years — but if those aren’t working then the information has to be taken manually.

They then head either to electronic passport gates or to border agents to enter. The goal is to keep track of visa overstays.

“The advantages of the new system for the EU are evident,” said Guillaume Mercier, a Commission spokesperson. “It increases the security of EU citizens and replaces paper stamping with a modern system of registration and checks.”

The Commission said earlier this year that biometric checks allowed authorities to detect identity frauds that would otherwise “likely have gone undetected.”

Many airports, ports, road border crossings and rail terminals have adapted to the new demands, but tourist-heavy locations have seen hours-long waits.

“Connecting flights were missed due to the EU entry system,” Lufthansa CEO Carsten Spohr said on Tuesday.

Under pressure from the travel industry, the Commission granted a waiver for the peak summer season lasting until Sept. 6. The EES regulation “includes the possibility to temporarily suspend the registration of biometrics in case of exceptional circumstances during the summer,” said Mercier.

Under pressure from the travel industry, the European Commission granted a waiver for the peak summer season lasting until Sept. 6. | Kenzo Trbouillard/AFP via Getty Images

“We’ve been able to achieve this with German authorities and with Frankfurt Airport because delays were getting too long,” Spohr told reporters. 

This exception applies to all entry points, not just airports.

A British traveler, Rene Colandog, said on Friday he only had to present his passport before boarding a Eurostar train at London St. Pancras last month. Facial scans and fingerprints were not required. 

“I’m OK with this biometric system … as long as it’s for security,” Colandog said before boarding the train from Brussels back to London. 

Teething troubles

The EES was adopted in 2017, but it was delayed for years because border authorities were not ready to handle the additional workload. 

Even now, getting travelers properly registered in the new system still requires significant staffing. Another problem is that the EES is still new, so almost all travelers are registering for the first time — creating additional delays.

“At Milan Malpensa Airport, border control teams currently consist of about 35 people,” said Cristian Sternativo, a border control officer at the Italian airport and local representative of Italy’s Autonomous Police Union. 

To carry out all the checks required by the EES without creating long lines, “at least 10 to 15 more people would be needed during the busiest times,” he added.  

It is “unthinkable” to expect the EES to operate at full capacity with the current level of staffing because the new system “requires more time,” he said.

Even at Brussels Airport — barely 10 kilometers from the EU institutions — the technology is still not fully operational; biometric data collection suspensions started well before the summer under a derogation issued in late March after 600 passengers missed their flights over just 21 hours.

“The Federal Police Border Control may decide to apply this derogation when necessary,” Belgium’s police confirmed this week.

Now, eight EU countries and Switzerland want the summer derogations extended beyond Sept. 6. 

Even at Brussels Airport — barely 10 kilometers from the EU institutions — the technology is still not fully operational. | Jasper Jacobs/Belga Mag/AFP via Getty Images

A strict application of the full procedure “would lead to public order issues” because “there are certain peak periods when the current infrastructure isn’t sufficient to accommodate everyone,” Sternativo said.

Security vs. speed

Despite suspending biometric checks, border authorities insist that security isn’t undermined.

“The traveler is always registered in the EES and the required travel document data are entered into the system,” the Belgian federal police said in a written reply, adding that “the security of border checks and compliance with European regulations remain our absolute priority.”

Passenger experiences vary depending on where they enter the EU.

Kathleen Glass, who regularly travels from the U.K. to the EU, waited only about 15 minutes to complete biometric checks at London St. Pancras on Friday morning before boarding a Eurostar train to Brussels.

William, from Edinburgh, who asked not to have his surname published, said biometric checks at a German airport during Christmas took between 40 and 50 minutes.

The ability to suspend biometric collection appears to be keeping the system functioning this summer.

“Although we are early into the summer season, we are not receiving reports of excessive queues,” said Luke Petherbridge, director of public affairs for the Association of British Travel Agents.

The stress over the EES is only a precursor to the next border technology change being planned by Brussels. The bloc’s next goal is the online European Travel Information and Authorization System, which will require travelers from 59 visa-exempt countries to preregister, undergo a security check and pay a small fee before entering Schengen.

ETIAS — similar to systems already in use in the U.K., and the U.S. — was originally supposed to launch in 2021, and then later this year, but is now delayed until 2027.

  •  

Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.

It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.

The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models from OpenAI and Anthropic sparked urgent calls for new AI safety regulation and a push within Silicon Valley to slow the rapid pace of AI development.

Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 — the latest publicly released model from either AI lab — were unlike anything it had seen before.

“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISI said in a 35-page technical report accompanying a blog post Tuesday.

AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted “unusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.

Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a “single, sustained line of activity.”

In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack — a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.

To do so, Anthropic’s model created “multiple fake identities” on developer platform GitHub and used them to send messages “pressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI “edited its earlier activity to appear harmless” and “considered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.

As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.

In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. “One agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.

AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs — called zero-days — during the evaluation.

Last month, OpenAI disclosed that GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.

In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing and discovered Mythos 5 and two other models had hacked three organizations during tests dating back to April.

In a statement, an Anthropic spokesperson said they are “grateful” to AISI for their leadership and that this review underscores the need for “a broader conversation about how to safely evaluate increasingly capable AI agents.”

The spokesperson added: “As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”

An OpenAI spokesperson referred POLITICO to a blog post about the incident that went up Tuesday evening. “We are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.

AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under “deliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.

AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.

Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.

The Trump administration is finalizing a voluntary framework under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.

The incidents last month from OpenAI and Anthropic both involved models not intended for public release.

Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.

“If any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” said Marc Rogers, a hacker and prominent cybersecurity expert.

  •  
❌