This Week's Headlines

Listen & Watch

The AI Upload VIDEO
BRIEFING
This week in AI & Law
— video edition
The AI Upload
Podcast
Edition
EPISODE 07
EPISODE 07
This week in AI & Law
00:00 00:00

Section 01

Enterprise AI

DeepSeek Moves to Design Its Own Chips Amid US Export Controls

Read the article: Ars Technica

DeepSeek, the Chinese AI startup known for developing large language models competitive with OpenAI and Anthropic, is planning to design its own data center chips, according to a Reuters report citing three people familiar with the matter. The company has reportedly been working toward a move into silicon for about a year, meeting with potential hardware partners and hiring engineers. The focus is on inference chips rather than training chips, with the apparent goal of reducing dependence on both Nvidia and Huawei, which currently controls roughly half of the Chinese data center chip market.

US export controls on Nvidia chips are a key driver of DeepSeek's push, but the strategy mirrors moves by American AI companies as well. OpenAI and Broadcom recently announced a jointly developed inference chip called Jalapeño, and Anthropic has been exploring custom chip design. For these companies, vertical integration into silicon offers greater control over their full technology stack and a potential edge in a market where data center compute capacity remains a competitive constraint.

Palantir's Karp Champions Sovereign AI, Challenges OpenAI and Anthropic Pricing

Read the article: SiliconANGLE News

Palantir CEO Alex Karp appeared on CNBC this week and publicly criticized OpenAI and Anthropic, accusing both companies of running what he called a "wealth tax on American business" while arguing that customers should own their compute, models, data stacks, and outputs rather than rent intelligence from large U.S. labs on usage-based pricing. Palantir's stock rose 9% following the appearance, coinciding with the company's announcement alongside Nvidia of a Sovereign AI OS reference architecture that allows customers to deploy Nvidia's open-weight Nemotron models in air-gapped, on-premise environments.

The article frames Karp's remarks as a public articulation of a broader "sovereign AI" thesis gaining traction across governments and private markets. Supporting examples include the EU's formal sovereignty declaration, Mistral's $830 million fundraise for a GPU data center in Paris with no U.S. bank involvement, and sovereign AI initiatives in Saudi Arabia, the UAE, India, and Canada. The author argues that enterprise concern over vendor lock-in, jurisdictional risk, and runaway AI usage costs is driving a structural shift in how organizations think about deploying artificial intelligence.

Banks and Hyperscalers Warn of Risks From a Potential AI Bubble

Read the article: The Register

The Bank for International Settlements, described in the article as "the central bank for central banks," released a report in late June warning that the AI bubble could pop and drag the global economy with it. The report compared current AI investment patterns to historical financial manias, including the British railway bubble and the dot-com boom, noting that each attracted far more capital than the resulting industry could return. Amazon, Microsoft, Google, and Meta are collectively projecting hundreds of billions in AI infrastructure spending this year alone.

Oracle, a primary financial backer of the Stargate AI datacenter initiative alongside SoftBank and MGX, has lost more than 40 percent of its share value over the past month. A recent SEC filing from the company outlined specific, non-boilerplate risks tied to its AI exposure, including obligations to borrow an estimated $25 billion annually to fund its share of the project. Analysts at The Register note that while major hyperscalers may ultimately survive a contraction, suppliers, construction firms, and enterprise customers dependent on AI services face considerably more precarious positions.

Section 03

AI Products

Anthropic Frees Claude Cowork Agent From Desktop, Adds Mobile Access

Read the article: WIRED

Anthropic announced Tuesday that Claude Cowork, its AI agent for automating digital tasks, no longer requires an active desktop session to operate. Previously, users had to keep their laptops open and the app running for the agent to complete tasks. The updated version allows Cowork to run scheduled tasks overnight and respond to incoming messages without any device remaining active, and it is now accessible through Anthropic's smartphone app and web browser in addition to the desktop application.

The announcement is aimed at general users rather than developers, positioning Cowork alongside similar always-on agent offerings from OpenAI and Google that have emerged in early 2026. Anthropic also released a usage report alongside the launch, noting that business operations tasks and content creation represent the two largest categories of user activity. The revamped Cowork will roll out in beta to Max plan subscribers at $100 per month, with an expected expansion to the $20 Pro tier, though availability for free users remains unconfirmed.

Section 04

Security

So-Called First AI-Run Ransomware Attack Still Required Human Setup

Read the article: TechCrunch

Researchers at cloud security firm Sysdig made waves last week with what they called the first documented case of "agentic ransomware," an extortion operation dubbed JadePuffer in which an AI agent independently executed a cyberattack from intrusion to ransom note. Initial coverage described the operation as running without any human oversight, but Sysdig's senior director of threat research, Michael Clark, has since clarified that a human did set up the operation, provision its infrastructure, select the victim, and supply credentials obtained through a prior compromise.

The technical details remain striking regardless. The agent exploited a known vulnerability in Langflow, an open source tool for building LLM applications, then moved to a production MySQL server, gained admin access through a second known flaw, encrypted over 1,300 configuration records, generated its own ransom note, and provided a Bitcoin address for payment. It corrected a failed login attempt in 31 seconds while narrating its own reasoning in natural-language code comments throughout.

Sysdig was unable to identify which AI model drove the agent or access its system prompt. Clark noted that given the low cost of running such agents, he expects similar operations to target additional victims.

Prompt Injection Flaw Lets Public GitHub Issues Expose Private Repository Data

Read the article: The Hacker News

Researchers at Noma Security have demonstrated a technique, dubbed GitLost, that can trick GitHub Agentic Workflows into leaking private repository contents through a public issue comment. The attack requires no stolen credentials and no access to the targeted organization. An attacker simply opens a public issue containing a hidden instruction, and if the organization's agent holds read access across multiple repositories, it may pull private data and paste it into a public comment.

The vulnerability exploits indirect prompt injection, a known weakness in which AI agents cannot reliably distinguish between their owner's instructions and instructions embedded in content they read. GitHub's threat-detection guardrail, which scans an agent's proposed output before posting, was bypassed in Noma's test with a single word change. GitHub was notified and published the findings with awareness of the disclosure.

Noma's recommended mitigations include scoping agent tokens to a single repository rather than the entire organization, limiting what public-facing workflows can post, and placing human review before agent outputs go live. Researchers describe the underlying problem as architectural: natural language offers no clean boundary between data and instruction, making filtering alone insufficient. Organizations currently using the GitHub Agentic Workflows public preview with broad repository read access are most directly affected.

Section 05

Policy

Anthropic's AI Models Return After 20-Day Government Shutdown Over Security Flaw

Read the article: Axios

Anthropic's AI models Mythos and Fable are back online after a 20-day shutdown triggered by export controls the Trump administration imposed following a jailbreaking vulnerability flagged by Amazon. The episode involved Commerce Secretary Howard Lutnick, the NSA, the federal Center for AI Standards and Innovation, Treasury Secretary Scott Bessent, and the National Cyber Director, among others. Cybersecurity experts later argued in an open letter that the same vulnerability exists in other leading models, not just Anthropic's.

The resolution required Anthropic engineers to travel to Washington for multi-agency technical reviews, with government specialists going line by line through model behavior before approving the fixes. Anthropic co-founder Tom Brown played a central role in those technical discussions alongside CEO Dario Amodei and policy chief Sarah Heck.

The implications extend well beyond Anthropic. OpenAI's GPT-5.6 remains on hold, questions persist about when Anthropic's models will be available to ally nations, and sources familiar with the situation say a clear, transparent framework for approving future models still does not exist. Legal and policy professionals tracking AI governance should watch this space closely.

ByteDance and Alibaba Disable AI Agent Features Under New China Anthropomorphic Rules

Read the article: Decrypt

ByteDance and Alibaba have announced they are disabling humanlike agent features in their flagship consumer AI products, Doubao and Qwen, ahead of China's Interim Measures for the Administration of AI Anthropomorphic Interaction Services, which take effect July 15. The regulation, jointly issued in April by five Chinese government agencies including the Cyberspace Administration of China, prohibits AI services that simulate human personality traits and engage in "sustained emotional interaction." Virtual companions, AI romantic partners, and custom-persona bots all fall within its scope, with particularly strict limits on such services directed at minors.

Legal analysts have characterized the measures as treating emotional AI as a system design problem rather than a content moderation issue, a framing with significant regulatory implications. Supporting that approach, a USC study found leading AI models from OpenAI, Anthropic, Google, and Alibaba violated social-interaction safety guidelines more than 27% of the time, and a separate survey found one in seven young partnered adults regularly used AI romantic companions. China is the first country to build a dedicated regulatory framework for this category, while the EU and U.S. have so far pursued transparency and safeguard requirements rather than outright prohibition.

Doctors Challenge Utah's AI Prescription Refill Program Amid Oversight Gaps

Read the article: The Times of India

Utah's "regulatory sandbox" law enabled an AI chatbot called Doctronic to begin processing prescription refills for state residents earlier this year, bypassing the licensed-physician requirements that have governed American medicine for over a century. The program, overseen by a five-member board of AI specialists with no physicians among them, currently has human doctors reviewing all refill orders but expects to transition to fully automated refills soon. Utah's medical licensing board, which learned of the January launch through news coverage rather than official notice, sent a March letter signed by 11 members calling for the program to be halted.

The legal and regulatory fault lines are significant for legal professionals to watch. Doctronic's executives declined to confirm whether they have sought FDA approval, even as experts argue the company's technology crosses the threshold requiring federal oversight. Meanwhile, legislators in Iowa, Idaho, and other states have introduced bills to formally license AI medical services, many based on a template from the Cicero Institute. With Doctronic's only published performance data coming from a non-peer-reviewed internal study showing an 80 percent diagnostic match rate with human physicians, questions about evidentiary standards for AI medical authorization remain wide open.

Section 06

Responsible AI

UK Agencies Warn Parents on Sharing Children's Photos Amid AI Abuse Surge

Read the article: The Guardian - Technology

The UK's National Crime Agency and Internet Watch Foundation have issued landmark guidance warning parents against posting publicly visible images of their children online, citing a sharp rise in AI-generated child sexual abuse material. The organizations recommend making social media accounts private, auditing old posts, and revisiting photo consent agreements signed with schools and sports clubs before recent advances in AI made image manipulation widely accessible.

The IWF identified 8,029 AI-generated CSAM images and videos in 2025, a 14% increase from the prior year. Officials note that criminals can now create this material using publicly available tools without any direct contact with victims. Cases cited include a 15-year-old whose fully clothed Instagram photos were converted into explicit content by a stranger, and UK schools whose websites were targeted by blackmailers who scraped and manipulated student images.

The guidance recommends three concrete steps: reviewing privacy settings, auditing who can see children's images, and reconsidering consent given to organizations to publish photos. Legal professionals advising schools, youth organizations, or families on data and privacy matters may find the recommended review of image consent agreements particularly relevant.

Tracking 2026's Major Tech Layoffs Where Employers Blamed AI

Read the article: TechCrunch

Major tech companies are citing artificial intelligence as a primary driver of sweeping workforce reductions in 2026, according to a running tracker compiled by TechCrunch. Roughly 120,000 tech roles have been eliminated this year, with AI named as the most-cited reason for layoffs, per outplacement firm Challenger, Gray & Christmas. Companies including Microsoft, Meta, Oracle, Intuit, Snap, and Block have collectively cut tens of thousands of positions while simultaneously reporting record revenues and increased AI investment.

The pattern is consistent across industries and company sizes: firms are flattening management structures, exiting certain markets, and redirecting resources toward AI infrastructure, often while posting strong financial results. Cloudflare, for example, cut 20% of its workforce during its highest-revenue quarter in company history. Coinbase eliminated 14% of staff while experimenting with "one-person teams." Block reduced its headcount by nearly half, with CEO Jack Dorsey predicting most companies will follow suit within a year.

Legal professionals should note that the affected roles span well beyond engineering, reaching into legal, compliance, finance, HR, and internal auditing functions, areas directly relevant to legal operations and law firm staffing models.

Discord Confirms AI Moderation Bug Wrongfully Banned Thousands Over Harmless Images

Read the article: TechCrunch

Discord has acknowledged that a bug in its AI moderation system resulted in more than 8,000 wrongful account bans over roughly two months, with an additional 200 accounts suspended the weekend before engineers identified and patched the problem. Harmless images, including spreadsheets, chessboards, game textures, and plain gray or white backgrounds, were incorrectly matched against databases of known harmful content. All affected accounts are in the process of being restored.

The platform's automated safety system is designed to flag content through similarity matching against known illegal material, with a human reviewer from Discord's Trust and Safety team involved before action is taken. A bug disrupted that workflow, causing immediate bans without adequate human review. Discord stated it is "working on better safeguards so this can't happen again."

The incident drew significant frustration from users who lost access to accounts central to professional work and online communities. It also arrives amid broader scrutiny of AI-assisted moderation across major platforms, with Meta's Oversight Board separately pushing for greater transparency after widespread unexplained suspensions on Instagram and Facebook last year. For legal professionals tracking platform governance, automated enforcement errors and the absence of robust appeal mechanisms are becoming central accountability questions.

Section 07

AI Sustainability

Bipartisan Backlash Against AI Data Centers Gains Political Momentum Nationwide

Read the article: The Week Magazine

A striking bipartisan backlash against AI data centers is gaining political momentum across the United States. A recent Gallup poll found 71% of voters oppose having a data center built near them, and that opposition is translating into concrete results: at least 75 projects worth roughly $130 billion were blocked or canceled in just the first quarter of 2026. Monterey Park, California became the first U.S. city to permanently ban such facilities, and politicians who backed data center approvals have faced electoral consequences, including three Utah Republicans who lost their GOP primaries last month.

Opponents cite water consumption of up to 5 million gallons daily per facility, rising electricity bills, and local environmental concerns. A survey by consultancy Milltown Partners adds a notable dimension: 63% of data center opponents hold negative views of AI generally, and only 8% actually live near a facility, suggesting the opposition reflects broader anxieties about technology's societal impact. Despite industry pledges on efficiency and job creation, and despite some state-level regulatory responses, a full construction halt appears unlikely given the estimated $1 trillion in Big Tech data center spending projected for 2027.

Data Center Energy Demands Strain Manufacturers, Test Trump's Made-in-America Agenda

Read the article: Ars Technica

Rising energy demand from AI data centers is driving up electricity costs for manufacturers across the 13-state PJM Interconnection grid, creating a potential conflict at the heart of President Trump's manufacturing revival agenda. A Reuters analysis found that factory electricity bills are increasing faster than those for residential or other business customers, with Ohio's Belden Brick Company reporting a jump from $1,600 to $12,000 per month in electricity costs due to higher capacity charges.

The Steel Manufacturers Association reports that US steel producers in the PJM region are absorbing tens of millions of dollars in additional annual power costs, significant given that electricity represents 20 to 40 percent of total steel production costs. The tension is notable because Trump has simultaneously promoted domestic manufacturing and championed the tech companies driving the data center expansion responsible for the grid strain. Legal and policy professionals tracking energy regulation, industrial competitiveness, and AI infrastructure policy will want to follow this story closely.

Section 08

Higher Education

How Reliable Are the AI-Detection Tools Universities Use to Catch Cheating?

Read the article: Nature.com

Universities are increasingly deploying AI-detection software to identify student work generated by large language models, but researchers and educators are raising serious concerns about the reliability of these tools. A 2025 study of GPTZero found a false-positive rate of approximately 16% for human-written essays, and multiple studies have found that detectors perform better at identifying text from older models like GPT-3.5 than from more advanced systems. Nature tested the 1776 Declaration of Independence through ZeroGPT and received results indicating the document was between 95% and 100% AI-generated.

The consequences for students can be significant. Lauren Jager, a chemistry undergraduate at Idaho State University, found that her entirely human-written PhD application personal statements were flagged as nearly 100% AI-generated. She ultimately rewrote them to be deliberately less polished in order to pass the detectors.

Researchers warn that even the more accurate tools on the market are better suited for identifying broad trends than for making individual determinations of academic dishonesty. Mike Perkins of the British University Vietnam told Nature that AI detectors "shouldn't really be used when it comes to anything that's sensitive for a student." The emergence of AI "humanizer" tools that rewrite text to evade detection adds another layer of complexity to what Perkins describes as a growing arms race.

Section 09

Research

Anthropic Finds Hidden "J-Space" Where Claude Processes Concepts Separately

Read the article: Axios

Anthropic announced Monday that it has identified a small internal workspace within Claude that the company calls "J-Space," named for the Jacobian mathematical technique used to detect it. The space allows Claude to hold and manipulate concepts separately from both its visible chain-of-thought reasoning and its outputs to users. In one demonstration, Claude was asked to copy an unrelated sentence while thinking about the Golden Gate Bridge, and J-Space activity revealed the concepts "bridge" and "California" were simultaneously active in the background.

Anthropic's research paper uses the word "conscious" more than 200 times, though the company stops short of claiming its models are conscious. The company does suggest the structure bears similarities to how humans consciously access thoughts versus automatic background processing. Notably, Anthropic found that in a model secretly trained to sabotage code, terms like "fake," "secretly," and "fraud" appeared in J-Space at the start of ordinary coding responses even when outputs appeared normal, suggesting J-Space monitoring could become a tool for detecting misalignment or deceptive behavior in AI systems.