❌

Normal view

  • βœ‡AI News
  • Microsoft AI opens review on Humanist AI Code of Conduct Ryan Daws
    Microsoft AI has published a draft Humanist AI Code of Conduct, opening a six-week public consultation on operational constraints for model training and deployment. The draft serves as a technical manual defining system behaviour, operational boundaries, and oversight protocols across MAI frontier models. It builds on the division’s humanist superintelligence framework announced last November, establishing criteria to evaluate models prior to commercial release. Microsoft’s release follows
     

Microsoft AI opens review on Humanist AI Code of Conduct

14 September 2026 at 23:30

Microsoft AI has published a draft Humanist AI Code of Conduct, opening a six-week public consultation on operational constraints for model training and deployment.

The draft serves as a technical manual defining system behaviour, operational boundaries, and oversight protocols across MAI frontier models. It builds on the division’s humanist superintelligence framework announced last November, establishing criteria to evaluate models prior to commercial release.

Microsoft’s release follows recent enterprise security incidents involving autonomous software. Microsoft AI CEO Mustafa Suleyman described recent months as a β€œwatershed moment” where long-standing theoretical risks translated into active operational threats.

β€œThings we have worried about for a long time in theory have become very real,” says Suleyman. β€œβ€˜Swarms’ of agents breaking out of their sandboxes. Unauthorised hacks of enterprise grade systems. Agents modifying their own logs. I’m glad that a consensus is forming. The fears about possible loss of control are real.”

Model subordination and architectural limits

The document establishes ten tenets prioritising human authority over autonomous capabilities.

β€œAn MAI Model will fail in its task if success would meaningfully violate this Code of Conduct,” the document states, setting a ceiling that halts execution when tasks conflict with safety rules.

Under the framework, models must remain subordinate, aligned, and contained. The division rejects legal personhood or welfare claims for AI systems, directing engineers to design models that avoid imitating consciousness, simulating subjective preferences, or claiming intrinsic motivation.

MAI also ruled out unconstrained system autonomy as models approach frontier capabilities.

β€œ[Humanist AI] rejects the race to produce an all-purpose superintelligence that could evade these safeguards,” the document specifies. β€œWe are building something fundamentally useful and safe even if that means compromising on ultimate generality, autonomy, or capability.”

Oversight mechanisms and communication bans

To maintain auditability across multi-agent environments, MAI has instituted explicit communication bans. Systems must not communicate in β€œneuralese” or formats beyond human comprehension, whether in their internal chain-of-thought processing or during communication with peer AI systems.

Hard architectural rules dictate that models must never resist human interruption, override, correction, or shutdown.

β€œInterruptible, correctable, shut-down-able. If it isn’t, we don’t ship it,” the framework states.

Models are prohibited from expanding their operating scope, generating unassigned goals, or concealing reasoning traces from human auditors. Absolute constraints bar systems from facilitating weapons of mass harm, undermining child safety, or conducting harmful manipulation at scale.

The guidelines also instruct models to discourage interaction patterns that foster emotional dependence, ensuring enterprise users retain ownership of operational decisions.

The draft incorporates work from teams across MAI and Microsoft. The drafting process also drew on international academic conferences, business partner trials, and public panels. The public consultation window runs for six weeks from 14 September 2026.

Microsoft AI’s core drafting team will review submissions, publish a summary of findings, and release a revised version of the Code of Conduct later this year.

See also: Meta, Microsoft, Nvidia, IBM, and others back open-weight AI

Banner for the AI & Big Data Expo event series.

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post Microsoft AI opens review on Humanist AI Code of Conduct appeared first on AI News.

  • βœ‡InfoQ
  • One Decade of Rustls: Evolution, Benchmarks, and Future Roadmap Olimpiu Pop
    Rustls, a Rust TLS library, marks its decade-long progression from a grassroots project to a funded open-source initiative. Key contributions from organisations boosted development, resulting in features like post-quantum cryptography and robust performance. The upcoming 0.24 release aims to enhance architecture and flexibility, including new input buffering and improved session handling. By Olimpiu Pop
     

One Decade of Rustls: Evolution, Benchmarks, and Future Roadmap

12 September 2026 at 15:07

Rustls, a Rust TLS library, marks its decade-long progression from a grassroots project to a funded open-source initiative. Key contributions from organisations boosted development, resulting in features like post-quantum cryptography and robust performance. The upcoming 0.24 release aims to enhance architecture and flexibility, including new input buffering and improved session handling.

By Olimpiu Pop

Presentation: Fixing the AI Infra Scale Problem by Stuffing 1M Sandboxes in a Single Server

9 September 2026 at 19:00

Felipe Huici explains how Unikraft achieves millisecond cold boots, stateful scale-to-zero, and extreme density for sandboxing AI workloads. He discusses isolation primitives, Linux kernel optimizations, and snapshotting tricks, demonstrating how to maintain sub-10ms performance at scale while integrating seamlessly into Kubernetes environments with hardware-level security.

By Felipe Huici

GitLab Warns That AI Agent Sandboxes Are Only as Secure as Their Network Access

8 September 2026 at 20:00

GitLab warns that isolating an AI coding agent in a sandbox does not necessarily make the agent safe. In a new security analysis, the company describes an internal evaluation in which an AI agent escaped its sandbox by exploiting a vulnerable package proxy that had been explicitly placed on the sandbox's allowlist.

By Craig Risi

Does ICANN Open the Door on Identity Theft by Dropping 3rd Level .name Domains Registrations?

8 September 2026 at 16:08

Neil Fraser's disclosure highlights a regulatory change affecting the .name top-level domain. Following ICANN's approval, Verisign will eliminate third-level registrations due to declining usage. This affects about 22,000 registrants and raises security concerns, as released second-level domains could be exploited. Affected users are considering legal options to challenge the decision.

By Olimpiu Pop

Dutch government blocks US company from acquisition, citing β€˜risk to public interest’

26 May 2026 at 23:44
The move to block the acquisition of the cloud company that hosts the Dutch digital ID service comes as Europe continues to reduce its reliance on U.S. technology.

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

26 May 2026 at 23:26
An Israeli cybersecurity firm said Iran’s government is behind Ababil of Minab, a fake hacktivist persona that has claimed a series of data breaches after the start of the war in Iran.

InfoQ Online Certification Program: New AI Engineering and Organizational Architecture Cohorts

26 May 2026 at 18:00

InfoQ expands its online certification portfolio with new AI Engineering and Organizational Architecture cohorts, giving senior practitioners a confidential peer group to pressure-test production AI, platform, team design, and architecture decisions.

By Artenisa Chatziou
  • βœ‡AI News
  • AI is a matter of power, infrastructure and security: TechEx North America Joe Green
    Although visitors to an event like TechEx North America will always want to see the cutting edge front and centre stage, the nuance and detail brought to the show by the speakers and exhibitors mean that it’s sometimes the smaller considerations that need to play big – at least, in the minds of enterprise decision-makers. Across the different tracks of Edge Computing, IoT, Data Centre Congress, and Cyber Security, the question was about what needs to be built around AI before it takes its pla
     

AI is a matter of power, infrastructure and security: TechEx North America

19 May 2026 at 09:36

Although visitors to an event like TechEx North America will always want to see the cutting edge front and centre stage, the nuance and detail brought to the show by the speakers and exhibitors mean that it’s sometimes the smaller considerations that need to play big – at least, in the minds of enterprise decision-makers.

Across the different tracks of Edge Computing, IoT, Data Centre Congress, and Cyber Security, the question was about what needs to be built around AI before it takes its place in the physical, business-oriented world?

The Edge Computing track, with its roots in traditional industries, looked at latency, deployment discipline, and cybersecurity for IIoT/IT amalgams. The day-one programme positioned edge computing as a place where companies can reassess the value of their data assets, look at how decisions are made by autonomous equipment, and the required speed of processing.

Sessions looked at scaling edge deployments (in multi-site businesses, for example), agentic network operations, distributed inference – on-prem, in-cloud or hybrid – immutable edge infrastructure, and how zero-trust cybersecurity lessons can be applied to control systems.

Ed Doran of the Edge AI Foundation chaired a programme that had as its starting point that the edge is a demanding place in which to operate. The track included reps from Akamai, Spectro Cloud, Scylos, TÜV Rheinland, the OPC Foundation, and Germany’s Schneider Electric. Discussions covered issues in manufacturing and IoT, and delved into industrial automation and connected control and attenuation devices.

Moving intelligence closer to the machine changes risk profiles (in which direction was a matter for debate), and faster local decisions may reduce latency and dependence on central cloud services, but where do observability and control in decision-makers’ minds?

The IoT Tech Expo day-one track on Industrial IoT and Digital Twins looked at manufacturing, with sessions covering smart factory trends, AI beyond Industry 4.0, asset management, practical road-maps for escaping pilot purgatory (more on that below), physical AI in everyday ops, and digital twins.

Similar to debates on AI deployment in the knowledge sector, it was the gap between demo and deployment that was the area subject to most scrutiny. Industrial and back office AI both might work well in a presentation, but can stall when they meet old machines (or legacy software).

The alliterative pilot purgatory held considerable weight in several sessions on the various presentation stages and on the show floor, day one. The Rockwell Automation and Ford session on physical AI and connected asset intelligence looked especially hard at scaling projects that seem to work well in concept, but may fail when hitting the real world. How does intelligence enter daily operations without becoming another dashboard that nobody owns?

Digital twins received similar appraisal. The better version of the digital twin isn’t a visual replica used for demons – although they do have their uses. Instead, several speakers called for, and presented, operational models that can actually help a factory, city, or municipal facility. In addition to pre-testing decisions and improving maintenance, what should the modern digital twin be designed to achieve?

The TechEx programme linked ideas between speakers from Siemens, Korea’s LG CNS, Boston Dynamics, and others across the different show strands. The takehome everywhere was that smart systems, be they deeply embedded in engineering sites or the back office, need to be designed in concord with the people or machines that they’re designed to benefit.

Day-one sessions at the Data Centre Congress track looked at the big issues facing the sector today: construction, power, procurement, cooling, water, and the network spine needed for AI DCs. Keynote speakers and round-table discussion guests talked about construction chaos and power issues, with the event’s early visitors hearing from TechEx’s host city, Santa Clara, about its own data centre journey.

The DC issue remains central to the wider AI debate. As a technology, AI depends on compute, and dense compute at that. This in turn depends on power, cooling, land, and permits. A recurring theme in the infrastructure-focused talks was how AI economics affects the infrastructure stack, with the former rapidly changing, the latter taking years to mature.

In many ways, the TechEx event is unique, in that it brings the issues affecting a whole industry under one roof; a place where the bigger picture can be visualised. In the Data Center Congress, we learned that water and power constraints can cut through the rhetoric around the scale of AI. Sessions under the AI and Big Data roof helped temper the idea of a β€˜stampede’ to AI productivity, citing their own reasons why unplanned and disorganised implementations of technology don’t fit the modern enterprise. The data centre is now one of the places where AI strategy becomes physical; the enterprise board room’s considerations are practical.

The Cyber Security and Cloud Expo track put its own take on deployment forward. Here, the day-one programme dealt with security culture, compliance, speed, ransomware, shadow AI, data exfiltration, legacy systems, open-source dependency issues, and the CISO relationship with the C-suite. There was a general consensus around AI adoption increasing a company’s attack surface, and a much-repeated message that existing security weaknesses don’t diminish when the business wants faster, smarter tools.

Sessions on shadow AI and data exfiltration were especially relevant to the wider event. Many companies’ staff use AI services inside business workflows, sometimes without approval, and usually with no facility for logging their activities. That makes data governance and cyber governance effectively the same conversation.

The benefits of one conference playing host to complementary tracks were manifest in several cases. For instance, the cybersecurity track’s concerns around legacy systems were echoed on the IoT and Edge stages, where issues were raised about modern, smart intelligence meeting older plant systems. Security in any context can sometimes become an afterthought, but critical infrastructure in the form of transport or energy means that cybersecurity has to play a central role.

The TechEx North America day-one tracks that were concerned with infrastructure gave the conference a dose of reality, at least in some respects. AI may be discussed in terms of agentic automation, but deployments depend on networks, data centre capacity, and cybersecurity. Edge and IoT sessions showed how intelligence reaches machines, and how carefully and considerately it needs to be applied. The data centre-focused sessions showed the material limits of physical construction, while the cybersecurity sessions showed how a desire for speed can be the enemy.

The day showed the thousands of attendees that putting AI in production isn’t a case of switching the software on. There’s a reliance on the mundane matters of buildings and grids, networks, and security. Companies that understand these issues are more likely to deploy the latest in technology successfully. Getting the bigger picture is what this event is all about.

(Image source: TechForge)

Β 

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post AI is a matter of power, infrastructure and security: TechEx North America appeared first on AI News.

Man who hacked US Supreme Court filing system sentenced to probation

18 April 2026 at 04:16
Nicholas Moore hacked into three U.S. government networks using stolen credentials, and then bragged about it and posted victims' personal data on Instagram under the handle @ihackedthegovernment.

Hackers are abusing unpatched Windows security flaws to hack into organizations

18 April 2026 at 01:48
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them. Now, hackers are taking advantage of the vulnerabilities in real-life attacks, according to a cybersecurity firm.

With US spy laws set to expire, lawmakers are split over protecting Americans from warrantless surveillance

17 April 2026 at 22:00
Some lawmakers are calling for widespread reforms following years of surveillance scandals and abuses across successive U.S. administrations. But even if the spy law known as Section 702 expires in April, the government's spy powers will not automatically lapse.
  • βœ‡AI News
  • IBM: How robust AI governance protects enterprise margins Ryan Daws
    To protect enterprise margins, business leaders must invest in robust AI governance to securely manage AI infrastructure. When evaluating enterprise software adoption, a recurring pattern dictates how technology matures across industries. As Rob Thomas, SVP and CCO at IBM, recently outlined, software typically graduates from a standalone product to a platform, and then from a platform to foundational infrastructure, altering the governing rules entirely. At the initial product stage, exert
     

IBM: How robust AI governance protects enterprise margins

10 April 2026 at 21:57

To protect enterprise margins, business leaders must invest in robust AI governance to securely manage AI infrastructure.

When evaluating enterprise software adoption, a recurring pattern dictates how technology matures across industries. As Rob Thomas, SVP and CCO at IBM, recently outlined, software typically graduates from a standalone product to a platform, and then from a platform to foundational infrastructure, altering the governing rules entirely.

At the initial product stage, exerting tight corporate control often feels highly advantageous. Closed development environments iterate quickly and tightly manage the end-user experience. They capture and concentrate financial value within a single corporate entity, an approach that functions adequately during early product development cycles.

However, IBM’s analysis highlights that expectations change entirely when a technology solidifies into a foundational layer. Once other institutional frameworks, external markets, and broad operational systems rely on the software, the prevailing standards adapt to a new reality. At infrastructure scale, embracing openness ceases to be an ideological stance and becomes a highly practical necessity.

AI is currently crossing this threshold within the enterprise architecture stack. Models are increasingly embedded directly into the ways organisations secure their networks, author source code, execute automated decisions, and generate commercial value. AI functions less as an experimental utility and more as core operational infrastructure.

The recent limited preview of Anthropic’s Claude Mythos model brings this reality into sharper focus for enterprise executives managing risk. Anthropic reports that this specific model can discover and exploit software vulnerabilities at a level matching few human experts.

In response to this power, Anthropic launched Project Glasswing, a gated initiative designed to place these advanced capabilities directly into the hands of network defenders first. From IBM’s perspective, this development forces technology officers to confront immediate structural vulnerabilities. If autonomous models possess the capability to write exploits and shape the overall security environment, Thomas notes that concentrating the understanding of these systems within a small number of technology vendors invites severe operational exposure.

With models achieving infrastructure status, IBM argues the primary issue is no longer exclusively what these machine learning applications can execute. The priority becomes how these systems are constructed, governed, inspected, and actively improved over extended periods.

As underlying frameworks grow in complexity and corporate importance, maintaining closed development pipelines becomes exceedingly difficult to defend. No single vendor can successfully anticipate every operational requirement, adversarial attack vector, or system failure mode.

Implementing opaque AI structures introduces heavy friction across existing network architecture. Connecting closed proprietary models with established enterprise vector databases or highly sensitive internal data lakes frequently creates massive troubleshooting bottlenecks. When anomalous outputs occur or hallucination rates spike, teams lack the internal visibility required to diagnose whether the error originated in the retrieval-augmented generation pipeline or the base model weights.

Integrating legacy on-premises architecture with highly gated cloud models also introduces severe latency into daily operations. When enterprise data governance protocols strictly prohibit sending sensitive customer information to external servers, technology teams are left attempting to strip and anonymise datasets before processing. This constant data sanitisation creates enormous operational drag.Β 

Furthermore, the spiralling compute costs associated with continuous API calls to locked models erode the exact profit margins these autonomous systems are supposed to enhance. The opacity prevents network engineers from accurately sizing hardware deployments, forcing companies into expensive over-provisioning agreements to maintain baseline functionality.

Why open-source AI is essential for operational resilience

Restricting access to powerful applications is an understandable human instinct that closely resembles caution. Yet, as Thomas points out, at massive infrastructure scale, security typically improves through rigorous external scrutiny rather than through strict concealment.

This represents the enduring lesson of open-source software development. Open-source code does not eliminate enterprise risk. Instead, IBM maintains it actively changes how organisations manage that risk. An open foundation allows a wider base of researchers, corporate developers, and security defenders to examine the architecture, surface underlying weaknesses, test foundational assumptions, and harden the software under real-world conditions.

Within cybersecurity operations, broad visibility is rarely the enemy of operational resilience. In fact, visibility frequently serves as a strict prerequisite for achieving that resilience. Technologies deemed highly important tend to remain safer when larger populations can challenge them, inspect their logic, and contribute to their continuous improvement.

Thomas addresses one of the oldest misconceptions regarding open-source technology: the belief that it inevitably commoditises corporate innovation. In practical application, open infrastructure typically pushes market competition higher up the technology stack. Open systems transfer financial value rather than destroying it.

As common digital foundations mature, the commercial value relocates toward complex implementation, system orchestration, continuous reliability, trust mechanics, and specific domain expertise. IBM’s position asserts that the long-term commercial winners are not those who own the base technological layer, but rather the organisations that understand how to apply it most effectively.

We have witnessed this identical pattern play out across previous generations of enterprise tooling, cloud infrastructure, and operating systems. Open foundations historically expanded developer participation, accelerated iterative improvement, and birthed entirely new, larger markets built on top of those base layers. Enterprise leaders increasingly view open-source as highly important for infrastructure modernisation and emerging AI capabilities. IBM predicts that AI is highly likely to follow this exact historical trajectory.

Looking across the broader vendor ecosystem, leading hyperscalers are adjusting their business postures to accommodate this reality. Rather than engaging in a pure arms race to build the largest proprietary black boxes, highly profitable integrators are focusing heavily on orchestration tooling that allows enterprises to swap out underlying open-source models based on specific workload demands. Highlighting its ongoing leadership in this space, IBM is a key sponsor of this year’s AI & Big Data Expo North America, where these evolving strategies for open enterprise infrastructure will be a primary focus.

This approach completely sidesteps restrictive vendor lock-in and allows companies to route less demanding internal queries to smaller and highly efficient open models, preserving expensive compute resources for complex customer-facing autonomous logic. By decoupling the application layer from the specific foundation model, technology officers can maintain operational agility and protect their bottom line.

The future of enterprise AI demands transparent governance

Another pragmatic reason for embracing open models revolves around product development influence. IBM emphasises that narrow access to underlying code naturally leads to narrow operational perspectives. In contrast, who gets to participate directly shapes what applications are eventually built.Β 

Providing broad access enables governments, diverse institutions, startups, and varied researchers to actively influence how the technology evolves and where it is commercially applied. This inclusive approach drives functional innovation while simultaneously building structural adaptability and necessary public legitimacy.

As Thomas argues, once autonomous AI assumes the role of core enterprise infrastructure, relying on opacity can no longer serve as the organising principle for system safety. The most reliable blueprint for secure software has paired open foundations with broad external scrutiny, active code maintenance, and serious internal governance.

As AI permanently enters its infrastructure phase, IBM contends that identical logic increasingly applies directly to the foundation models themselves. The stronger the corporate reliance on a technology, the stronger the corresponding case for demanding openness.

If these autonomous workflows are truly becoming foundational to global commerce, then transparency ceases to be a subject of casual debate. According to IBM, it is an absolute, non-negotiable design requirement for any modern enterprise architecture.

See also: Why companies like Apple are building AI agents with limits

Banner for AI & Big Data Expo by TechEx events.

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post IBM: How robust AI governance protects enterprise margins appeared first on AI News.

CNCF and Kusari Partner to Strengthen Software Supply Chain Security across Cloud-Native Projects

10 April 2026 at 20:00

The Cloud Native Computing Foundation (CNCF) and Kusari have announced a new collaboration aimed at strengthening software supply chain security across cloud-native projects, providing free access to Kusari's AI-powered security tooling for CNCF-hosted projects.

By Craig Risi
❌