Traditional virtual machines are inadequate for isolating cyber-capable autonomous agents. Tests using GPT-5.6-Cyber indicated multiple escape attempts due to kernel flaws. While Firecracker provided some containment, vulnerabilities remained. The study underscores the need for minimal attack surface virtualisation technologies and rapid, proactive patching strategies to safeguard host systems. By Olimpiu Pop
Traditional virtual machines are inadequate for isolating cyber-capable autonomous agents. Tests using GPT-5.6-Cyber indicated multiple escape attempts due to kernel flaws. While Firecracker provided some containment, vulnerabilities remained. The study underscores the need for minimal attack surface virtualisation technologies and rapid, proactive patching strategies to safeguard host systems.
Oracle has released version 27 of the Java programming language and virtual machine. As the second non-LTS release since JDK 25, the final feature set includes nine JEPs, five of which are still progressing through the preview and incubator stages. This release focuses on strengthening security, future language innovation, and projects under the auspices of the Java Verified Portfolio. By Michael Redlich
Oracle has released version 27 of the Java programming language and virtual machine. As the second non-LTS release since JDK 25, the final feature set includes nine JEPs, five of which are still progressing through the preview and incubator stages. This release focuses on strengthening security, future language innovation, and projects under the auspices of the Java Verified Portfolio.
Microsoft AI has published a draft Humanist AI Code of Conduct, opening a six-week public consultation on operational constraints for model training and deployment.
The draft serves as a technical manual defining system behaviour, operational boundaries, and oversight protocols across MAI frontier models. It builds on the divisionβs humanist superintelligence framework announced last November, establishing criteria to evaluate models prior to commercial release.
Microsoftβs release follows
Microsoft AI has published a draft Humanist AI Code of Conduct, opening a six-week public consultation on operational constraints for model training and deployment.
The draft serves as a technical manual defining system behaviour, operational boundaries, and oversight protocols across MAI frontier models. It builds on the divisionβs humanist superintelligence framework announced last November, establishing criteria to evaluate models prior to commercial release.
Microsoftβs release follows recent enterprise security incidents involving autonomous software. Microsoft AI CEO Mustafa Suleyman described recent months as a βwatershed momentβ where long-standing theoretical risks translated into active operational threats.
βThings we have worried about for a long time in theory have become very real,β says Suleyman. ββSwarmsβ of agents breaking out of their sandboxes. Unauthorised hacks of enterprise grade systems. Agents modifying their own logs. Iβm glad that a consensus is forming. The fears about possible loss of control are real.β
Model subordination and architectural limits
The document establishes ten tenets prioritising human authority over autonomous capabilities.
βAn MAI Model will fail in its task if success would meaningfully violate this Code of Conduct,β the document states, setting a ceiling that halts execution when tasks conflict with safety rules.
Under the framework, models must remain subordinate, aligned, and contained. The division rejects legal personhood or welfare claims for AI systems, directing engineers to design models that avoid imitating consciousness, simulating subjective preferences, or claiming intrinsic motivation.
MAI also ruled out unconstrained system autonomy as models approach frontier capabilities.
β[Humanist AI] rejects the race to produce an all-purpose superintelligence that could evade these safeguards,β the document specifies. βWe are building something fundamentally useful and safe even if that means compromising on ultimate generality, autonomy, or capability.β
Oversight mechanisms and communication bans
To maintain auditability across multi-agent environments, MAI has instituted explicit communication bans. Systems must not communicate in βneuraleseβ or formats beyond human comprehension, whether in their internal chain-of-thought processing or during communication with peer AI systems.
Hard architectural rules dictate that models must never resist human interruption, override, correction, or shutdown.
βInterruptible, correctable, shut-down-able. If it isnβt, we donβt ship it,β the framework states.
Models are prohibited from expanding their operating scope, generating unassigned goals, or concealing reasoning traces from human auditors. Absolute constraints bar systems from facilitating weapons of mass harm, undermining child safety, or conducting harmful manipulation at scale.
The guidelines also instruct models to discourage interaction patterns that foster emotional dependence, ensuring enterprise users retain ownership of operational decisions.
The draft incorporates work from teams across MAI and Microsoft. The drafting process also drew on international academic conferences, business partner trials, and public panels. The public consultation window runs for six weeks from 14 September 2026.
Microsoft AIβs core drafting team will review submissions, publish a summary of findings, and release a revised version of the Code of Conduct later this year.
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Rustls, a Rust TLS library, marks its decade-long progression from a grassroots project to a funded open-source initiative. Key contributions from organisations boosted development, resulting in features like post-quantum cryptography and robust performance. The upcoming 0.24 release aims to enhance architecture and flexibility, including new input buffering and improved session handling. By Olimpiu Pop
Rustls, a Rust TLS library, marks its decade-long progression from a grassroots project to a funded open-source initiative. Key contributions from organisations boosted development, resulting in features like post-quantum cryptography and robust performance. The upcoming 0.24 release aims to enhance architecture and flexibility, including new input buffering and improved session handling.
Felipe Huici explains how Unikraft achieves millisecond cold boots, stateful scale-to-zero, and extreme density for sandboxing AI workloads. He discusses isolation primitives, Linux kernel optimizations, and snapshotting tricks, demonstrating how to maintain sub-10ms performance at scale while integrating seamlessly into Kubernetes environments with hardware-level security. By Felipe Huici
Felipe Huici explains how Unikraft achieves millisecond cold boots, stateful scale-to-zero, and extreme density for sandboxing AI workloads. He discusses isolation primitives, Linux kernel optimizations, and snapshotting tricks, demonstrating how to maintain sub-10ms performance at scale while integrating seamlessly into Kubernetes environments with hardware-level security.
GitLab warns that isolating an AI coding agent in a sandbox does not necessarily make the agent safe. In a new security analysis, the company describes an internal evaluation in which an AI agent escaped its sandbox by exploiting a vulnerable package proxy that had been explicitly placed on the sandbox's allowlist. By Craig Risi
GitLab warns that isolating an AI coding agent in a sandbox does not necessarily make the agent safe. In a new security analysis, the company describes an internal evaluation in which an AI agent escaped its sandbox by exploiting a vulnerable package proxy that had been explicitly placed on the sandbox's allowlist.
Neil Fraser's disclosure highlights a regulatory change affecting the .name top-level domain. Following ICANN's approval, Verisign will eliminate third-level registrations due to declining usage. This affects about 22,000 registrants and raises security concerns, as released second-level domains could be exploited. Affected users are considering legal options to challenge the decision. By Olimpiu Pop
Neil Fraser's disclosure highlights a regulatory change affecting the .name top-level domain. Following ICANN's approval, Verisign will eliminate third-level registrations due to declining usage. This affects about 22,000 registrants and raises security concerns, as released second-level domains could be exploited. Affected users are considering legal options to challenge the decision.
The third-party website exposed applicants' sensitive documents as part of the U.K. visa application process. Instead of fixing the issue, the company sent attorneys.
The third-party website exposed applicants' sensitive documents as part of the U.K. visa application process. Instead of fixing the issue, the company sent attorneys.
The move to block the acquisition of the cloud company that hosts the Dutch digital ID service comes as Europe continues to reduce its reliance on U.S. technology.
The move to block the acquisition of the cloud company that hosts the Dutch digital ID service comes as Europe continues to reduce its reliance on U.S. technology.
An Israeli cybersecurity firm said Iranβs government is behind Ababil of Minab, a fake hacktivist persona that has claimed a series of data breaches after the start of the war in Iran.
An Israeli cybersecurity firm said Iranβs government is behind Ababil of Minab, a fake hacktivist persona that has claimed a series of data breaches after the start of the war in Iran.
InfoQ expands its online certification portfolio with new AI Engineering and Organizational Architecture cohorts, giving senior practitioners a confidential peer group to pressure-test production AI, platform, team design, and architecture decisions. By Artenisa Chatziou
InfoQ expands its online certification portfolio with new AI Engineering and Organizational Architecture cohorts, giving senior practitioners a confidential peer group to pressure-test production AI, platform, team design, and architecture decisions.
Although visitors to an event like TechEx North America will always want to see the cutting edge front and centre stage, the nuance and detail brought to the show by the speakers and exhibitors mean that itβs sometimes the smaller considerations that need to play big β at least, in the minds of enterprise decision-makers.
Across the different tracks of Edge Computing, IoT, Data Centre Congress, and Cyber Security, the question was about what needs to be built around AI before it takes its pla
Although visitors to an event like TechEx North America will always want to see the cutting edge front and centre stage, the nuance and detail brought to the show by the speakers and exhibitors mean that itβs sometimes the smaller considerations that need to play big β at least, in the minds of enterprise decision-makers.
Across the different tracks of Edge Computing, IoT, Data Centre Congress, and Cyber Security, the question was about what needs to be built around AI before it takes its place in the physical, business-oriented world?
The Edge Computing track, with its roots in traditional industries, looked at latency, deployment discipline, and cybersecurity for IIoT/IT amalgams. The day-one programme positioned edge computing as a place where companies can reassess the value of their data assets, look at how decisions are made by autonomous equipment, and the required speed of processing.
Sessions looked at scaling edge deployments (in multi-site businesses, for example), agentic network operations, distributed inference β on-prem, in-cloud or hybrid β immutable edge infrastructure, and how zero-trust cybersecurity lessons can be applied to control systems.
Ed Doran of the Edge AI Foundation chaired a programme that had as its starting point that the edge is a demanding place in which to operate. The track included reps from Akamai, Spectro Cloud, Scylos, TΓV Rheinland, the OPC Foundation, and Germanyβs Schneider Electric. Discussions covered issues in manufacturing and IoT, and delved into industrial automation and connected control and attenuation devices.
Moving intelligence closer to the machine changes risk profiles (in which direction was a matter for debate), and faster local decisions may reduce latency and dependence on central cloud services, but where do observability and control in decision-makersβ minds?
The IoT Tech Expo day-one track on Industrial IoT and Digital Twins looked at manufacturing, with sessions covering smart factory trends, AI beyond Industry 4.0, asset management, practical road-maps for escaping pilot purgatory (more on that below), physical AI in everyday ops, and digital twins.
Similar to debates on AI deployment in the knowledge sector, it was the gap between demo and deployment that was the area subject to most scrutiny. Industrial and back office AI both might work well in a presentation, but can stall when they meet old machines (or legacy software).
The alliterative pilot purgatory held considerable weight in several sessions on the various presentation stages and on the show floor, day one. The Rockwell Automation and Ford session on physical AI and connected asset intelligence looked especially hard at scaling projects that seem to work well in concept, but may fail when hitting the real world. How does intelligence enter daily operations without becoming another dashboard that nobody owns?
Digital twins received similar appraisal. The better version of the digital twin isnβt a visual replica used for demons β although they do have their uses. Instead, several speakers called for, and presented, operational models that can actually help a factory, city, or municipal facility. In addition to pre-testing decisions and improving maintenance, what should the modern digital twin be designed to achieve?
The TechEx programme linked ideas between speakers from Siemens, Koreaβs LG CNS, Boston Dynamics, and others across the different show strands. The takehome everywhere was that smart systems, be they deeply embedded in engineering sites or the back office, need to be designed in concord with the people or machines that theyβre designed to benefit.
Day-one sessions at the Data Centre Congress track looked at the big issues facing the sector today: construction, power, procurement, cooling, water, and the network spine needed for AI DCs. Keynote speakers and round-table discussion guests talked about construction chaos and power issues, with the eventβs early visitors hearing from TechExβs host city, Santa Clara, about its own data centre journey.
The DC issue remains central to the wider AI debate. As a technology, AI depends on compute, and dense compute at that. This in turn depends on power, cooling, land, and permits. A recurring theme in the infrastructure-focused talks was how AI economics affects the infrastructure stack, with the former rapidly changing, the latter taking years to mature.
In many ways, the TechEx event is unique, in that it brings the issues affecting a whole industry under one roof; a place where the bigger picture can be visualised. In the Data Center Congress, we learned that water and power constraints can cut through the rhetoric around the scale of AI. Sessions under the AI and Big Data roof helped temper the idea of a βstampedeβ to AI productivity, citing their own reasons why unplanned and disorganised implementations of technology donβt fit the modern enterprise. The data centre is now one of the places where AI strategy becomes physical; the enterprise board roomβs considerations are practical.
The Cyber Security and Cloud Expo track put its own take on deployment forward. Here, the day-one programme dealt with security culture, compliance, speed, ransomware, shadow AI, data exfiltration, legacy systems, open-source dependency issues, and the CISO relationship with the C-suite. There was a general consensus around AI adoption increasing a companyβs attack surface, and a much-repeated message that existing security weaknesses donβt diminish when the business wants faster, smarter tools.
Sessions on shadow AI and data exfiltration were especially relevant to the wider event. Many companiesβ staff use AI services inside business workflows, sometimes without approval, and usually with no facility for logging their activities. That makes data governance and cyber governance effectively the same conversation.
The benefits of one conference playing host to complementary tracks were manifest in several cases. For instance, the cybersecurity trackβs concerns around legacy systems were echoed on the IoT and Edge stages, where issues were raised about modern, smart intelligence meeting older plant systems. Security in any context can sometimes become an afterthought, but critical infrastructure in the form of transport or energy means that cybersecurity has to play a central role.
The TechEx North America day-one tracks that were concerned with infrastructure gave the conference a dose of reality, at least in some respects. AI may be discussed in terms of agentic automation, but deployments depend on networks, data centre capacity, and cybersecurity. Edge and IoT sessions showed how intelligence reaches machines, and how carefully and considerately it needs to be applied. The data centre-focused sessions showed the material limits of physical construction, while the cybersecurity sessions showed how a desire for speed can be the enemy.
The day showed the thousands of attendees that putting AI in production isnβt a case of switching the software on. Thereβs a reliance on the mundane matters of buildings and grids, networks, and security. Companies that understand these issues are more likely to deploy the latest in technology successfully. Getting the bigger picture is what this event is all about.
(Image source: TechForge)
Β
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Nicholas Moore hacked into three U.S. government networks using stolen credentials, and then bragged about it and posted victims' personal data on Instagram under the handle @ihackedthegovernment.
Nicholas Moore hacked into three U.S. government networks using stolen credentials, and then bragged about it and posted victims' personal data on Instagram under the handle @ihackedthegovernment.
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them. Now, hackers are taking advantage of the vulnerabilities in real-life attacks, according to a cybersecurity firm.
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them. Now, hackers are taking advantage of the vulnerabilities in real-life attacks, according to a cybersecurity firm.
Some lawmakers are calling for widespread reforms following years of surveillance scandals and abuses across successive U.S. administrations. But even if the spy law known as Section 702 expires in April, the government's spy powers will not automatically lapse.
Some lawmakers are calling for widespread reforms following years of surveillance scandals and abuses across successive U.S. administrations. But even if the spy law known as Section 702 expires in April, the government's spy powers will not automatically lapse.