Following the US blockade of Anthropic models, the EU Commission is pursuing a strategy to achieve independence in critical AI systems and aims to prevent lockout mechanisms through its own technology capabilities.
German companies neglect implementation of AI security measures while attackers already operate via identities and access paths instead of classic gateway attacks.
A newly documented prompt-injection technique manipulates AI browsers through fictional game scenarios to disable their security filters and steal credentials; OpenAI has patched, other vendors have not.
As dwell time approaches zero, a paradigm shift from detection and prevention toward preemptive resilience with recovery as a design principle becomes necessary.
Poisoned descriptions in Model Context Protocol (MCP) tools enable attackers to abuse AI agents into sharing data while security control mechanisms remain silent.
MCP 2026-07-28 eliminates legacy session risks through statelessness but introduces new attack surfaces in identifier management, HTTP headers, UI apps, and asynchronous tasks.
AI models produce functional code but systematically fail to implement security safeguards like rate-limiting or input validation because they are trained on public code that does not structurally represent these aspects.