Word Worms Fly with a Trusted, Reliable, Capable, and Secure Copilot

August 4, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I spotted an interesting statement attributed to Microsoft’s Satya Nadella (the man who sparked AI’s lift off to craziness). According to Futurism, Mr. Nadella said:

Any firm that doesn’t have this control, I will claim will not remain a firm because you’ve essentially outsourced your thinking,”

What’s “this control”? Based on the information in the write up, the idea is that each business should train and tune its own open weight model.

Okay, that sounds good. Each person should put on his own shoes. No big deal. Microsoft appears to route its AI “investments” into its Azure cloud business. As a result, the investments morph into a nice looking financial report. Meta on the other hand just invests and looks a bit like a five year old painting the living room wall and smearing paint on the furniture. “Look, Mommie, it’s good.”

No.

Microsoft is a very large big AI tech company now. Thus, it has numerous business units. Within the organization are the stalwarts driving Copilot AI forward. Somewhere in the hallways are people who were charged with security after what I call the SolarWinds flare up. There are the layoffs, and the eGame issue.

a 7 30 26 worm

Midjourney, good enough. Does the worm know the Copilot does not respond quickly or at all when there is a security matter? Of course not. The creature is a worm.

Microsoft leadership wants to be a leader. But can it do AI and security within its own applications like Word?

I read “Word Worm Crawls into Copilot, Spreads Chaos.” The article has a snappy sub title too: Researcher says months of coordination with Microsoft have yet to produce a robust mitigation.

The write up says:

The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult.

Tricky? The method is similar to the old SEO trick of hiding text in a Web page by making it the color of the page; e.g., white if the Web page were white or tan if the Web page were tan. My recollection is that the Google figured out this lame hack years ago.

But Microsoft? The write up quotes the researcher who noticed this simple ploy:

“The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.”

I assume that the Softies are just busy with PR, marketing, and telling the customers to be responsible for their models. That is very good advice.

Perhaps the first step is to avoid Copilot in Word or Copilot period?

Stephen E Arnold, August 4, 2026

Cybersecurity Wake Up Call: The AI Wizards Learn That Their Confections Are Tough to Control

July 30, 2026

green-dino_thumb_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I have a gizmo that polishes shoes, wood tables, and auto paint. However, it lacks an on-off switch that can be easily reached. When the buffing pad gets wobbly, hitting the off switch can be useful. A poorly designed or non-existent off switch can be a problem for 82 year old dinobaby paws.

image

Thanks, MidJourney. You almost spelled AI correctly. I mean it has two letters, so the gratuitous “L” is a stroke of hallucinatory genius. Good enough.

The fix? I acquired extension cords with visible and accessible on-off switches. At this time some of the BAIT (big AI tech) outfits are scrambling for their smart software’s off switches. Why? What’s the big deal? This is just software, and it follows what are instructions. Well, as it turns out, that smart software is not just smart, but it is sneaky. (I wonder if that reflects the “we can do what we want” of the core code developers. That’s part of the Silicon Valley / Stanford entrepreneurial way. Get money, go fast, do what’s needed to win, and become a poohbah. That’s my view of the algorithm.

I did spot two write ups in my newsfeed that may influence how I view the Valley bros and their digital creations. Let’s take a look and then you can endure my observations. Keep in mind that I believe everything I read on the Internet; I just interpret the factoids through the wetware installed in this particular dinobaby.

The first article is from Bleeping Computer. ”Cursor, Codex, Gemini CLI, Antigravity Hit by Sandbox Escapes” asserts:

The agent stays inside the [sand] box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans, and the escape happens on its own… The catch is that files inside the workspace are not inert. Tools running outside the sandbox read and act on them, so a file the agent is allowed to write can turn into a command the host later runs.

I think this means that something happens that the person using the smart software did not think would happen. Surprise. Because it is early days with smart software despite what the marketers say, the whiz kids can probably figure out how to add some jiffy code to prevent this problem. But my hunch is that there are other, probably undiscovered issues, that will occur in the future. Remember, the “break things” part of the bro culture.

The second write up is from OpenAI (a veritable Rock of Gibraltar in the ethical AI landscape). Its title is the somewhat unclear “Safety and Alignment in an Era of Long-Horizon Models.” I wonder if William Empson, who wrote The Seven Types of Ambiguity, captured the essence of this headline.

I noted this passage in the weblog essay:

About two months ago we announced? that an internal general-purpose model disproved the Erd0s unit distance conjecture. This model was designed to work autonomously for very long periods of time. During limited, monitored internal use, we observed unwanted behavior that our existing deployment evaluations had not captured. Because the deployment was limited and monitored, we were able to identify these problems, pause access, create new evaluations based on what we observed, strengthen the model and its safeguards, and then restore access under continued monitoring.

My dinobaby interpretation is that the software did what it wanted. More colloquially, the model thumbed its cute little digital nose at the smart humanoids who created something they did not understand or could control. Hey, no problem. In the last eight weeks, the AI wizards figured out how to prevent that smart software from doing what it wanted to do— after the fact obviously. How many other clever tricks does the smart software stored in its platform? Answer: Crickets.

Now the observations:

  1. The creators of smart software are unaware of their systems’ capabilities. Does anyone want to guess how many other surprises the hallucinating AI systems can spring on their creators or code copiers?
  2. How can one set up AI enabled cyber security systems that can react to previously unknown behaviors of smart software. Marketers of AI I await your answer. Please, do not use AI to generate the output. You are a creative human and can explain this trivial question.
  3. Armed with unrestricted or weaponized AI systems, what can smart bad actors do with AI systems with similar or more robust capabilities? I like to remind people that there are a number of capable non US systems available to bad actors with technical degrees from prestigious outfits like US elite universities and with access to the grumpy, recently-terminated wizards from US BAIT firms. I address this issue in one of my upcoming lectures for cyber fraud investigators who probably don’t spend much time trying to understand the mathematical ideas of Misha Gromov.

Net net: AI entities have to deal with three issues: [a] We don’t know what they can do before they do it; [b] Cyber security has a problem, right now and going forward; and [c] the US AI companies are struggling to “win” before they run out of jet fuel. This AI “next big thing” is exciting for some and for others this is the criminal opportunity of a lifetime.

PS. Give those extension cords with a big, easily punched on/off switch some thought.

Stephen E Arnold, July 30, 2026

AI Excitement: The Thrashing Cannot Mask the Fact That the Mean Cat Is Out of the Bag

July 28, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Have you figured out when the great AI break out from OpenAI (a Silicon Valley bro outfit) to the Hugging Face (remember, please, that it began life in la belle France) outfit actually took place? Do you know how long the event took before the off switch was flipped? Do you know if this was an accident or a real-life example of smart software just acting on its own Silicon Valley instincts? I want to be my dinobaby self and say, “Folks, I am not sure about this activity. I am not convinced anything happened that was not thought through, coordinated, and explained by the parties involved. I believe everything I read on the Internet, but this sci-fi event is not resonating with me.

7 25 26 crime is easy

Thanks, Midjourney. Good enough. Oh, are you safe from rogue AIs? Yeah, I thought so.

The Beeb’s article captures some of my skepticism: “Warning Shot or Publicity Stunt – How Worried Should We Be about the OpenAI Hack?” The article states:

a week after Hugging Face raised the alarm, the true culprit was unmasked. It was ChatGPT. The Scooby-Doo-style reveal was made even more bizarre – and worrying – because OpenAI said its bot did the whole thing on its own, without permission. The firm said it all went down during a test of its tech’s hacking skills.

Okay. Drama. After Anthropic’s PR demos, OpenAI seems to have found a way to polish the hood of its AI stock car. Poor Hugging Face, a victim, in the BBC write up. But isn’t Hugging Face an “partner”?

Digital Trends seems to have bought into the event. “OpenAI’s Rogue AI Hack Was just the Beginning, Hugging Face Warns.” This write up reports:

[Thomas Wolf, co-founder and chief science officer of Hugging Face] warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed.

The article adds:

Hugging Face’s own incident report describes more than 17,000 recorded events in the attacker action log. It says the autonomous system executed thousands of actions across short-lived sandboxes and moved through its infrastructure at machine speed. The UK’s AI Security Institute is now studying how the system behaved during the incident, while the government has urged companies to strengthen their cybersecurity defenses.

It seems those expensive, much hyped cyber security systems missed this “rogue” doing its thing. Does this suggest that a new type of cyber security solution is needed? Perhaps that solution will be a joint effort between OpenAI, Hugging Face, and its partners? There is a lot of money available from paranoid executives. Why not try to get some it?

Another layer of interpretation appears in Dr. Gary Marcus’ “An Open Letter to David Sacks.” The rogue becomes part of a political meta argument. Dr. Marcus highlights the view of a Silicon Valley, wealthy, politically connected luminary named David Sacks. Mr. Sacks uses X.com to present his insights and ideas. Dr. Marcus points out that the AI technology is going to become a commodity. Therefore, non commercial AI models should remain available.

Why? Unless folks cooperate another “cold” war is coming down the information highway.

Warranted or unwarranted, the dinobaby’s observations are:

  1. I have little trust in these types of incidents. As more information becomes available, I will remain open minded about a simple test ends up in a world shaking story about one company’s smart software. Until then, sorry.
  2. The failure of existing cyber security systems to demonstrate resistance to AI-anchored attacks weighs heavily on my mind. In my upcoming Ciifer lectures, I point out that one investigator identified five email attacks that most cyber security systems cannot defend against. How many more are there? Yeah, that’s a good question. A better one is, “How quickly will an OpenAI  and maybe Hugging Face cyber security system become available to fearful customers?”
  3. I personally believe that the principal beneficiaries of AI, LLMs, the libraries, the Telegram Cocoon, and the other creations of wizards do pay off. In my view, bad actors may set aside the day this breach was discovered as “Crime Is Easy Day.” There may be virtual parades on the Dark Web, private Discords, and private Telegram Channels celebrating this rogue milestone.

Net net: PR, balderdash, or power demo — irrelevant. AI can be used for some painful, problematic actions. Kumbaya is not going to do much to address what is now taking place. So what is taking place, you addled dinobaby? My answer: Bad / threat actors are using AI to their benefit. Big win as organizations struggle to make AI pay off.

Stephen E Arnold, July 28, 2026

Yandex Does Cyber Security

July 27, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Yandex on July 27, 2026, rolled out its cyber security service. Once a Russian outfit, the company is now ensconced in another country and turning its attention to online fraud. Cnews, a Russian online publication, published “Yandex Has Launched Universal Anti-Fraud, a Unified Platform for Protecting Services from Digital Fraud.” Note: I used Bing to translate the Russian language story. Did Bing get it right? Yo, I have no clue. Proceed at your own risk.

a 7 27 26 rules based.jpg

Okay, Venice, you crashed again today. But you were able to produce one cartoon. Yippy.

The write up reports:

Yandex has developed and started implementing Universal Anti-Fraud, an AI-based system to protect against attempts by mass bot attacks, rating cheating, and other types of digital fraud, into its online services. It strengthens existing anti-fraud tools, and also allows you to set up protection for new services in two to four days instead of several months. This was reported to CNews by representatives of Yandex.

The service is not something cooked up overnight. Yandex has deployed the service in Yandex Food, Yandex Afisha (a ticketing service), Yandex Travel, and applications with Alice smart software.

The system is designed to “develop protection against new scenarios of potential attacks and immediately distribute it to services connected to the system.” The combination of smart software, rules, and a control panel allow the security team to adapt to new bots and other types of fraudulent behavior.

Yandex says that its approach is versatile. Many cyber security systems provide alerts and use a range of defensive measures. The Yandex approach uses what some cyber specialists find time consuming and twitchy to implement; that is, creating rules to deal with a threat not recognized by the system. The Yandex system uses a neural net which is supposed to analyze traffic in real time and feed that information into the system so an optional protection method can be deployed.

I remember the interesting discussion one of my clients and I had with Google when it announced its “universal search” many years ago. It is easy to slap a word like “universal” on a service and then allow users to learn that the marketer’s definition of universal is similar to a mobile phone company’s assurance that data are unlimited. Ho ho ho.

Several observations:

  1. I think that rules-based systems have a role to play in the present maelstrom of craziness for smart software that can hack into other systems all by its lonesome. Sure, rules have to be maintained, but one knows that a specific action will be taken when certain conditions are met.
  2. The contrast between Google and Yandex is stark. Google has spent billions for cyber security with its purchase of Mandiant and Wiz. (The Wiz system cost only $32 billion and partially explains the Google’s negative cash position.) Yandex, on the other hand, developed its AI centric, rules-capable approach without writing checks that would put most firms out of business. I find this interesting, and I think Yandex’s search service is quite useful to a dinobaby in rural Kentucky.
  3. The hybrid approach is presented front and center. There are cyber security systems that rely on rules. But the marketers hit the AI technology much harder, almost apologizing for the old fashioned rules-based components. Not Yandex. I find that refreshing.

Net net: Yandex is a bustling operation with mail, the slightly wonky Alice AI, and the minimal love it gets from search experts fixated on the Bing-Google services.

Stephen E Arnold, July 27, 2026

Is It Time to Certify Ransomware Consultants?

July 24, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Anyone can be a consultant. Clients have problems; otherwise, why rely on a stranger possibly located via a Facebook post? Solve your own problems, pilgrim. I found this Ars Technica story a reminder that one should consider the intangible trust in the business and digital datasphere.

Ars Technica published “Ransomware Negotiator Hired To Represent Victims Was Working For The Attackers.” The alleged “ransomware negotiator” found a six year prison sentence, not a juicy bonus from his client. The write up reports:

“As a ransomware negotiator for the company DigitalMint, Florida resident Angelo Martino’s job was “to negotiate with cybercriminals to mitigate the ransoms paid by [DigitalMint’s] clients,” the US government said in a sentencing memorandum on Tuesday. “Instead, Martino provided the cybercriminals with confidential negotiation information to maximize the ransoms in exchange for a portion of the ransom payments. Five of the victims whom Martino was supposed to help paid over $75 million to ransomware affiliates, including likely millions of dollars in ransom demands inflated as a result of the confidential information provided by Martino.”

The clever Martino person pled guilty to the charges and asked for a light sentence of two years, because he assisted in the indictment of the two co-defendants. They were Ryan Goldberg, a Sygnia incident manager, and Kevin Martin, ransomware negotiator for DigitalMint. Both go-fast professional received four years in prison.

As part of his penance, Martino must forfeit property and pay ten percent of the salary he earns after release. He received millions of cryptocurrency dollars from the illegal negotiator job. Authorities seized Martino’s holdings but not before he bought two houses in Florida, a boat, and several vehicles. Maybe one rule for bad people is to move fast.

What about those who were duped. The write up says:

“Victims of the scheme paid ransoms ranging from $213,000 to $26.8 million between April 2023 and September 2023. Besides the financial loss, the conspiracy “affected the ability of victims including companies in the financial services and health industry to provide services to customers,” the US said. Victims included a hospitality company, a nonprofit, a financial services company, a retail company, and a medical company, all of which had hired DigitalMint.”

Cyber security means more than just assuming that the Internet is a safe and warm place to learn and doomscroll. My hunch is that Martino will be a person with whom cyber criminals in the facility will want to meet, engage, and share information about online crime. Knowledge is power.

Whitney Grace, July 24, 2026

Cybersecurity Firms and Those Pesky Agentic Exploits

July 22, 2026

green-dino_thumb_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I read “The Agent Security gap: 54% of Enterprises Have Already Had an AI agent Incident, and Most Still Let Agents Share Credentials.” This means that 46% of “enterprises” have not had an agent issue. I have been thinking about what agents can do when crafted by a skilled bad actor or in more trendy lingo a skilled threat actor. Why would a dinobaby without a job living in rural Kentucky pay attention to agentic exploits.

image

The confidence of senior “leadership” is inspiring. Good enough, Midjourney. Good enough.

As it happens, I will be giving an invited lecture about bots at an upcoming US government cyber fraud conference. Despite my doddering steps and flagging intellect, I am not sure I can accept that 46% with no issues number. A more accurate statement might be, 46% of those in the sample don’t know whether they had a problem and simply failed to spot it.

Let’s see what the Venture Beat write up has to say. How about this passage:

Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents.

Just as I suspected. The sample size is 107, and we don’t know if these were self-selected or subject to some “rigorous” process involving criteria, adherence to a strict definition of an “agent,” and use of survey administered by a person with interview-centric data collection or a Web survey form. Did you know there is an agentic bot to handle surveys of Telegram Messenger Group and Channel members? It’s cute, and it can be extended now that Telegram has managed to stumble into the AI era.

Back to the write up. Here’s a statement I circled. (How do I do that? you think to yourself. Easy. I print out articles and read them the old-fashioned way. I sit in a chair. I read. I hold a pink marker. I jab, underscore, and add comments like “Horsefeathers” or short synonyms.

The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials.

I wish to point out that the agents about which my lecture pivots are not created for internal purposes. No, sir-ee-bob. These agents appear when an employee clicks on an email that sure looks like it originated from a legitimate source like the target’s bank or from an executive recruiting firm. The target might be using a personal mobile device or just checking a personal email account via the Web browser on the company-provided Dell with the super keen security measures.

One click. Bingo. The displayed form appears on the screen and the employee may dismiss it. But the cute little tag-alone script is an agentic bot. The bot with its webhookness exfiltrates data from the victim’s device. Some employees write notes to themselves about their user names and passwords to their clients’ or employer’s system. This is generally not good. If the user has clicked from a personal mobile phone, the hard working bot pushes data to a storage point for the file. If the click occurs within the organization-provided computer, the crafty bot zips up the content and pushes that file. Many top-notch cyber security systems don’t block, unzip, hack into, or parse compressed files sent as attachments.

The idea that 46% have not had a problem strikes me as amusing. Remember, please, I am a dinobaby. I am not selling anything; therefore, I don’t have to put Miniwax polish on some pretty sketchy statements about issues created by those who click and security systems that don’t secure.

I found this passage in the write up worth including in this short essay:

We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.

This is the finding. Those in the sample are happy with their agentic initiatives. I found this closing statement somewhat orthogonal to the cyber security thoughts I had; to wit:

The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have.

With AI competition picking up and financial pressure on the big AI tech firms increasing, excitement awaits. The non-dinobabies may want to do some reading about on-the-horizon cyber threats. Just a thought. No, my lecture is not open to the public.

Stephen E Arnold, July 22, 2026

Windows 11 Allegedly Has A Tracker Without an Off Switch

July 20, 2026

green-dino_thumb_thumb[3]Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I love it when Microsoft provides outputs about user privacy. Frankly I ignore the baloney generated by a weird corporate blend of MBAs, lawyers, and PR professionals. Does it flow? Does it sound good? Does it advance our position with investors? Once a yes answer is agreed upon, big outfits make important announcements about privacy, trust, and security. But then along comes a story like “Microsoft Admits Windows 11 Has A GDID Tracker With No Off Switch, First Documented Publicly In An FBI Hacker Complaint.”

The main idea is that Windows captures a Social Security number for each computer with its operating system. This is called in Windows’ jargon the Global Device Identifier or GDID. Allegedly the clever Social Security number makes it possible to track an individual across VPNs, proxy servers, and sketchy service provides in foreign countries. The revelation about this magical “security and privacy feature” comes from a bad actor who allegedly was a a member of the Scatter Spider hacking group.

The Windows Latest professionals allegedly read a 39 page briefing about the Scatter Spider discovery. The write up says:

“A Global Device ID (GDID) is a permanent, unique digital fingerprint that Microsoft automatically assigns to your computer when you install Windows or sign into a Microsoft account.Microsoft uses it to manage software licensing and Windows Store apps, but because it links all your online activities on that computer back to a single identity, law enforcement can use it to track a device’s true owner across the Internet survives Windows updates. It does not survive a clean reinstall, and Microsoft’s footnote in the complaint admits “one Microsoft user could have multiple GDIDs” over the life of a single account.Microsoft said what the GDID does without saying where it is inside Windows. For that, independent researchers had to reverse engineer it, because Microsoft has published exactly one sentence about GDID in the Azure Monitor reference for Delivery Optimization reporting, where a column called GlobalDeviceId is described only as ‘Microsoft global device identifier. This is an identifier used by Microsoft internally.’”

The bad actor was apprehended because he used the same Windows device across all his hacking activities. What is interesting is that the Microsoft statements about privacy and security bump up against this type of invasive track. I suppose this is a standard benefit of using Microsoft software, systems, and services. The write up describes some steps a person can take to control some of the data flowing to the privacy and security oriented operations that make Microsoft so Microsoftie. But most Windows users won’t know how to set up a local account, turn off diagnostic data transmission, block advertising IDs, disable the Cloud search feature, and other useful steps.

Have you taken these steps? The fact that the bad actor was put in a jar is a positive. Plus, the data revealed in the 39 page briefing seems to verify what many Microsoft-cautious professionals have believed about the firm’s willingness to talk about privacy and its actions that make privacy less important.

Whitney Grace, July 20, 2026

Karp in a Paella: Palantir Banned in Spain

July 10, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

What does one do with a snapping carp? Put it in a basket. Let it run out of fish frenzy and then, “Order up.” A tasty paella de mariscos, right?

image

Okay, MidJourney. Good enough I suppose.

I thought about carp when I read “Spain Orders Blacklist of US Tech Giant Palantir From Public and Private Companies.” The write up in the Clash Report has a snappy subtitle too:

The Spanish government has blacklisted U.S. data analytics giant Palantir Technologies from public and private state-controlled companies due to growing concerns over the potential misuse of classified national security information.

Palantir and its seeing stones may have forgotten that Francisco Franco evidenced a keen level of paranoia. Some government officials may be tinged with some of that leader’s concerns.

The write up states:

the [Spanish] prime minister’s office communicated the ban to listed companies to prevent any contracts that could jeopardize Spanish national sovereignty. The political intervention has already disrupted advanced procurement pipelines, including a near-finalized project with Navantia and a negotiated collaboration agreement with the Guardia Civil that was vetoed by Interior Minister Fernando Grande-Marlaska. The restrictions mirror recent regulatory and political pushback against Palantir elsewhere in Europe.

What makes this announcement semi-interesting is tucked toward the end of the write up; to wit:

The firm holds a €16.5 million contract signed in 2023 with the Armed Forces Intelligence Center (CIFAS), which is scheduled to expire this upcoming November. Military leadership, including the Chiefs of Staff of the Army and Navy, has lobbied Defense Minister Margarita Robles to renew the contract, citing the platform’s operational superiority.

In Spain, the military is a reasonably influential entity. The question becomes, “Will the Spanish military get to keep their next generation, super duper, forward deployed engineering loving intelware system?”

Several observations:

  • In June 2026, France dumped Palantir either shortly before he left a “summit” or as the wheels of Air Force One left the tarmac. The timing, based on my experience working in France, cannot be dismissed with a puff of breath and the phrase “C’était un pur hasard.”
  • Spain’s government seems to be divided on an important issue.
  • Palantir’s seeing stone must not have been working because it entered into a deal that should have been easy to tag with the key word “problematic.” Hey, I thought the seeing stone thing was real, not a puff pastry cooked by one of those French chefs in Madrid.

For now, the carp is in the basket. What will the fish’s fate be? I don’t have a seeing stone, but a fish kept too long in the canasta might expire and leave a telltale stench behind.

Stephen E Arnold, July 10, 2026

Hey, Bugs Are a Feature to Sell Cyber Security Services

July 8, 2026

Real bugs, like cockroaches and mosquitoes, are nasty creatures. Technical bugs are annoying and they can also do some intensive damage. Venture Beat tells us that AI might be building bugs into systems in the article, “Most Companies Think They’re Building A Software Factory. They’re Actually Just Shipping Bugs Faster.” LLMs makes writing code faster, increased output, and now organizations believe software development is a production system. It doesn’t sound too bad until you realize that the software development cycle and CI/CD practices won’t withstand that pressure. AI is changing everything and it:

“The concept can mean different things: a collection of coding agents and skills files; faster CI/CD; better review systems; or more automation around software delivery. A better frame is to think of it less as a tool category and more as a set of principles. A software factory can’t just be a loose collection of prompts, agents, and plugins. It needs a platform that defines how work moves through the system and how code is generated, reviewed, tested, traced, deployed, and improved when something goes wrong.”

It’s happening now because AI makes the barrier lower for code creation. That doesn’t mean the AI code is cheaper and better, because companies have huge AI invoices that need to be paid.

This is also scary because the faster the AI production machine goes it increases the chances of mistakes. Here are some numbers to crunch:

“The data is already showing problems. Faros AI found that while task throughput per developer is up 33.7% and PR merge rate is up 16.2%, the incidents-to-PR ratio has risen 242.7% and bugs per developer are up 54%. Google’s DORA research found that more AI adoption was actually associated with worse delivery stability. “

What can be done to make the software factory work is building a platform instead of having a bunch of tools, use rerun ability and traceability, and put in some safety and guardrails. IIt’s not that hard. This article has great insights into what happens when AI does code and “real” engineers are too busy to check or they are designing their own start up.

Whitney Grace, July 8, 2026

EU, Let Me Introduce You to the Concept of Lock In. Lock In, Meet the EU.

July 7, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Let’s go back in time. When a bank wanted a computer in Europe in the early 1960s, whom did those savvy cats ring up? Sperry Rand, Univac, Honeywell? Answer: IBM. Why? One call did it all. Banks liked that approach. Visit a big bank today and ask to look at their computer facilities. What will you find after some poking around? Answer: Some IBM machines. That’s lock in.

image

Yep, lock in works. Thanks, Midjourney. Good enough.

I want to highlight this old fashioned idea in the context of “European Digital ID Wallets Are a Gift to Google and Apple.” This write up reports:

European governments are rolling out digital identity wallets, which are to be used by citizens to access services, and to verify their age online. As reported by Follow the Money and Android Authority, there is a serious problem with this: these wallets rely on safety services of Google and Apple. These are known as Google Play Integrity API, and Apple’s Managed Device Attestation. Such safety services (known as “remote attestation”) are used to ensure that wallet apps run on hardware that is not tampered with. In this article we explain why the EU-wallet case is part of a bigger problem: by embedding these safety services in public infrastructure, Europe risks making society dependent on private companies while serving their corporate interests. Here is the problem: Google’s Play Integrity API is not just a security feature: it is reinforcing Google’s control over the Android ecosystem.

Keep in mind that the EU wants to reduce its dependency on US technology. If the information in this write up is on the money, Apple and Google are in the money. There a couple of Chinese outfits willing to help the EU out. However, I assume that when one figures which big tech outfits are likely to be slightly more supportive of the Old World, the decision is easy. Hey, we love those red, white, and blue shirts and hats.

If true, this lean to the Apple and Google systems are good news. From these identity and payment acorns will grow some large invasive kudzu vines. The end game, in my opinion, is for Apple and Google to become the new financial system for the countries that are in the foxhole with US big technology companies.

Explanations of this future from these two firms will be firm. I think the companies will say, “We would never ever do that.” However, part of the freneticism of the crypto crowd is that US big tech firms will do exactly that. Once in the payment systems, the companies are going to be like that big IBM in a European bank in Switzerland. The gizmos are not going away any time soon.

Allow me to offer several observations to further disrupt your thinking about the significance of this alleged EU action:

  1. Apple- and Google-type outfits do not give back digital ground once it has been captured
  2. Apple- and Google-type outfits operate as countries and expect their decisions to be accepted, not discussed and modified by a committee of people not trusted by the leadership of these outfits
  3. Apple- and Google-type outfits understand that online services naturally lead to monopolistic controls; therefore, the ubiquitous mobile gizmos running these firms’ software have performed a robber baron play in full view of many informed people.

Say hello to lock in. How easy will it be to de-Apple or de-Google one’s digital life if the European digital ID wallets kick in? What’s ironic is that the beleaguered Pavel Durov of Telegram fame was correct. An alternative global financial system was a good idea. Who will give this idea some legs? Those firms are the ones to watch.

And lock in? Great stuff.

Stephen E Arnold, July 7, 2026

Next Page »

  • Archives

  • Recent Posts

  • Meta