Sec & AI News — 1 August 2026
🧯 My AI deleted a database. 203 lessons, one command.
It was the local dev copy, production never felt it, and the restore took about 5 minutes with the AI running its own recovery while I watched. Then that incident wrote the rule that makes the same command fail closed before it reaches a shell. Whenever I mention that roughly 80% of my company's execution work runs on AI agents, someone tells me you can't rely on AI. They're right about the model. Veracode tested 100+ models across 80 coding tasks and 45% of the output failed security tests, a pass rate that has barely moved in two years. METR's randomised trial found experienced developers were 19% slower with AI while believing they'd been 20% faster. I still hand real infrastructure to this technology every day. The difference is the inspector I built around it, because nobody inspects your AI system for you. I've written up the hooks, gates, verification and recovery layers we actually run in production, failures included.
- AI Guardrails: How to Build AI You Can Trust (2026) — by Nathan House
🔌 97 million downloads, 30+ CVEs, and nobody agrees what an agent may do
If you connected an agent to your inbox or your codebase this year, you joined the fastest tool adoption I've seen in 30 years of security. Mozilla's first State of Open Source AI report puts numbers on the gap: monthly MCP SDK downloads went from about 2 million to 97 million in 16 months, 28% of the Fortune 500 run MCP in production, and only around 21% of companies report mature governance of what their agents actually do. Researchers filed more than 30 CVEs against MCP implementations in the first eight weeks of 2026. I read that as the healthiest number in the whole report: the security community finally showed up. Authentication is broadly solved. Authorization is not. Mozilla counts zero portable write-permission standards across 12 frameworks, 10 harnesses and 3 peer protocols. We spent years getting the web from "SSL proves the server's identity" to real authorization, and paid for the gap in breaches. This time the client can send email and spend money.
- AI Agent Security: Why Only 21% Have Real Control (2026) — by Nathan House
🎙️ LinkedIn added a button that says "seems like AI slop"
Announced 30 July, first spotted by 404 Media. It sits in the three-dot menu on any post. Click it, the post hides, and LinkedIn's classifiers get a training signal. It ships alongside new low-quality detection that downranks slop in suggested and out-of-network content, plus a test that quietly tells posters their writing reads as inauthentic. CPO Hari Srinivasan's line is that slop is hard to define and the definition keeps moving, so they need the signal to tune against. LinkedIn says it already blocks hundreds of thousands of automated comment attempts a day. The obvious failure mode is people clicking it on posts they simply disagree with.
Which raises the question of whether any of us can actually spot it. I spent a day building a detector to find out, and another day testing whether the thing worked. Almost everyone hunts in the wrong place: the em-dash, "delve," the tidy three-item list. Strip those and the text still reads as AI, because the real patterns are structural. Research out of Maryland and Google DeepMind sorted human from AI at 93.2% accuracy on shape alone, no vocabulary analysis: does the piece state its own moral out loud, and does it name anything real. The tells that transfer are things like stating the lesson (AI 77% of the time, humans 52%) and vague attribution instead of a named source. Mine sorted 7 out of 7 blind. It also has an honest limit worth knowing before you trust anyone's percentage. Human-and-AI blends beat every method, including ours.
- 404 Media
- TechCrunch
- AI Writing Patterns: We Built a Detector to Test the Claim — by Nathan House
🎭 Two more face-cloning tools shipped this week. Here's what they're actually for.
Captions and HeyGen both released avatar products in the last few days, both in the rapid-fire section at the bottom, and the pitch on each is that you can't tell the synthetic version from the real person. Take that claim seriously for a second. Social engineering has always had one saving grace for defenders: it doesn't scale. A good con artist works one mark at a time, and there's only one of him. That constraint is the thing being removed. Mandiant's M-Trends 2026 found voice phishing surged to 11% of intrusions, the second most common way attackers first get into a network, while email phishing fell to 6%. A deepfake video call cost the engineering firm Arup $25.6 million. I've broken the attacker down into three parts: a Brain running the conversation, a Mask that sounds like someone you trust, and a Memory of scraped personal data. The defence maps onto the same three. The short version: you don't win by getting better at spotting fakes. You win by changing the process, so no single conversation can move money or grant access.
- AI Social Engineering: The Con Man That Never Sleeps — by Nathan House
🔴 Anthropic shipped Opus 5. The users shipped complaints.
Opus 5 landed on 24 July at $5/M input and $25/M output, the same price as Opus 4.8. Anthropic's pitch: it "comes close to the frontier intelligence of Claude Fable 5 at half the price." 1M context. Thinking on by default. Then the forums arrived. Verbose. Scattered. Overthinks trivial work, treats every passing comment as a P0, and a steady trickle of developers have gone back to 4.8. Anthropic's own docs describe the same behaviour they're complaining about: responses "run longer," the model "narrates its progress more often," and developers are told to remove verification instructions because they cause over-verification. Plenty of people rate it highly. CodeRabbit called it a step up for design-heavy work, and MCP Atlas went 82% to 86%.
- Anthropic — Claude Opus 5
- What's new in Opus 5 (Anthropic docs)
- Reuters coverage
- Claude Opus 5 Review: Everything New in 2026 — by Nathan House
🟠 The "one-shot" AAA game was not one-shot
Matt Shumer's Three.js first-person shooter did the rounds on X, a million views deep, roughly 55,000 lines of it, and not one external art asset anywhere. The claim attached was that Opus 5 built the thing from a single prompt. The repo says otherwise: three rounds of six agents, each owning one directory, then a sequential cleanup pass with a single owner per coupled concern. The README also concedes it doesn't match a modern Call of Duty, which is fair. Blind A/B testing preferred the real game and critic scores peaked at 5.05 out of 10. Enemies render as mannequins. It runs at 28-30fps on Apple Silicon.
🌍 Google put an image generator in Google Earth for about 24 hours
Nano Banana 2 arrived in Google Earth on the web on 30 July. Zoom anywhere, hit "create image," describe what you want. Pompeii restored to 78 AD. A neighbourhood after redevelopment. SynthID and C2PA provenance baked in. Then on 31 July Google pulled it, after criticism that generating photorealistic alternate versions of real places was a misinformation engine wearing a fun hat. Stronger guardrails first, Google says, before any re-release. If you tried it this week and it's gone, that's why.
📅 Meta AI can finally read your calendar
Meta connected its assistant to Gmail and Google Calendar on 24 July, running on Muse Spark 1.1. Ask what's coming up next week and it reads across both. You get daily briefings, conflict detection, recurring tasks, and research that turns itself into slides. Google OAuth required. Select markets only, with WhatsApp planned.
Worth being precise about scope, because this gets overstated. Meta's announcement covers making plans, connecting to email and calendar, creating slides and handling tasks. It does not claim the assistant sends mail or edits your events. OpenAI and Google shipped this shape of thing months back.
🐝 Jack Dorsey's Block launched a Slack competitor you can put agents in
Buzz went live on 21 July. Apache 2.0, built on Nostr, free, with a self-hostable relay and desktop apps for all three platforms. Dorsey's framing is a group chat platform for teams of people and agents, built to reduce dependency on Slack and GitHub. There's a software forge in there too. Humans and agents both get cryptographic keypairs, permissions and audit trails. It's model-agnostic through the Agent Client Protocol, so Claude Code, Codex or Block's own goose all drop into channels. Tag three of them with the same brief, then set them on each other's output for critique.
It is genuinely early. Mobile is unfinished and the agent approval controls aren't done. Hosted pricing hasn't been announced at all. TechCrunch's advice against migrating an established team onto it is sound.
🤖 The FCC just blocked new foreign-made humanoid robots
This one gets mis-reported constantly, so the specifics matter. On 28 July the FCC added two categories to its Covered List under order DA 26-786. First, foreign-produced advanced robotic devices, meaning humanoids and quadrupeds. Second, foreign-produced connected power inverters. The trigger was a set of National Security Determinations from a White House interagency body, which obliges the FCC to list. New models now can't get FCC equipment authorization, which means they can't be imported, marketed or sold in the US.
No executive order was involved, and despite how it's been reported, the rule never mentions China. "Foreign-produced" is defined against the Buy American domestic-end-product test, so the scope is foreign-wide, though with China at roughly 85% of the humanoid market the practical target isn't subtle. Existing authorized models keep working, with no recalls and no effect on devices already bought. Conditional approval pathways exist through the Department of War and DHS.
🦾 DeepMind's robot brain can bag grapes without crushing them
Gemini Robotics ER 2 shipped 30 July, built on Gemini 3.5 Flash. 128k context in, 64k out, interleaved text, image, video and audio. It's the high-level reasoning layer, the part that works out how to approach a task before anything actually moves. The demos are the good kind of unglamorous. Grapes into a Ziploc without bruising them, a light bulb unscrewed without shattering it, then the Ziploc pressed shut. It also ties a bin bag, which sounds trivial and is one of the genuinely hard manipulation problems in the field.
It arrived as part of a trio, alongside Gemini Robotics 2 for whole-body humanoid control and an on-device variant. Apptronik's Apollo 2, Boston Dynamics Spot and Franka Duo are all running it. Safety behaviour is built in: the humanoid halts when a person comes near, then resumes once they're clear. Available now through the Gemini API and AI Studio.
📿 The AI pendant now talks back, for double the money
Friend 2.0, announced 30 July by Avi Schiffmann. The always-listening necklace has a speaker now, so instead of texting you encouragement it says the encouragement out loud. Runs OpenAI's latest models. $249, up from $129, with an optional $10/month subscription if you want it to remember more than 30 days. The launch film is a montage of people telling a pendant things they'd normally tell a person. That graffitied-subway-ad campaign already made this company a lightning rod, and neither the always-on microphone nor the dependency question has gone anywhere since.
🛠️ Rapid fire
xAI opened Build Mode. Announced 28 July as an early beta, restricted to the SuperGrok Heavy tier. Prompt it for a website, app, game or dashboard, preview the result in chat, then publish to a grok.me link or your own domain. xAI · The Verge
Gemini for macOS got intelligent dictation. Long-press Fn anywhere in the OS, talk, get clean text at your cursor with fillers stripped and mid-sentence corrections handled. Needs v1.88. English only for now. If you've used Wispr Flow, you know the shape of this. Google · MacRumors
Gemini Omni is free until Tuesday. No subscription needed, 10 videos at no cost. Tools menu, "Create video." Ten-second clips with native audio. Deadline is 11:59pm PT on 4 August. Google · Video generation overview
MidJourney V8.2 is now the default model. Released 24 July. Better aesthetics, better personalization, a style the announcement calls bolder and edgier. No price change, no --preview flag needed. MidJourney
Captions shipped Mirage Avatar X. Announced 28 July. It generates voice, motion and video in a single pass instead of lip-syncing after the fact, which is where the identity-preservation and microexpression claims come from. A ten-second clip builds the twin. Three-minute maximum output, 30+ languages. The "industry-leading" comparison is Captions' own, not an independent benchmark. Captions
HeyGen does NotebookLM, but video. Launched 29 July. Feed it a topic, URL or PDF and it writes a two-host dialogue, assigns avatars, and renders a shared scene with wide shots, close-ups, B-roll and captions. Every line is editable before render. You can invite a co-host by email and they don't need an account. YouTube URLs aren't supported in the beta. HeyGen · Beta docs