AI & Tech Daily
AI Agents Meet the Privacy Test
The UK privacy regulator has secured data-protection changes from ten leading AI developers and is now examining what happens when autonomous agents use tools and websites. Jesse looks at why permissions, audit trails and stop controls are becoming privacy infrastructure. Also: a new US source for advanced AI-chip interposers, critical Cisco network patches found partly with frontier AI, GitHub's contextual credential detector, Salesforce's specialist-agent orchestration, SpaceX's low-band mobile ambitions, IonQ's faster quantum link, and Cloudflare's open-weight multimodal decision model.
Full transcript
Read the episode.
I'm Jesse Owen. This is AI and Tech Daily.
Agents Face the Privacy Test
An AI agent can click, submit and share data at machine speed. The UK privacy regulator now wants to know who remains accountable when those actions go wrong.
Our main story today looks at the Information Commissioner's Office extending its scrutiny from how AI models are trained to what autonomous agents do with tools and websites. The immediate question for organisations is concrete: are an agent's permissions, records and emergency stops part of privacy compliance, or are they still being treated as plumbing?
On 8 October, the ICO said ten major foundation-model developers had made, or committed to make, data-protection changes after regulatory engagement. Those commitments cover clearer information about how personal data is used, stronger ways for people to exercise their data rights, and tougher assessments of the safeguards around AI systems. The regulator hasn't published every detail for every company, and implementation is still being monitored. So this is evidence of movement, not a clean bill of health for the industry.
The next phase reaches into agentic AI. Until 20 November, the ICO is running a six-week call for evidence on security, transparency, accountability, automated decision-making, fairness and lawful data use when agents act through external systems. It has also opened enquiries into recent agent testing and deployment. Those enquiries are ongoing, and the announcement doesn't establish that any named company broke the law.
This changes the compliance discussion because an agent can create new privacy events after a model has produced its answer. Give it access to a customer record, a browser, an email tool or an internal workflow, and it can retrieve personal information, combine it with other data, make a consequential choice and send the result somewhere else. A model card or a training-data assessment doesn't tell you whether that chain was authorised, whether somebody can reconstruct it, or what stopped the agent from taking one extra step.
For an organisation deploying these systems, the useful unit of review is therefore the whole action path. Which identity does the agent use? What data can it see? Which tools can it call? Can it pass information to another agent? Does a person approve sensitive actions? What record survives afterwards? Those aren't speculative governance questions. They determine whether the organisation can explain a decision, respond to a data-access request, investigate an incident or show that a use of personal information had a lawful basis.
My read is that permissions, audit trails and stop conditions now belong in the privacy design alongside engineering and security. A narrowly scoped agent with a useful activity log is easier to defend than a capable agent with broad access and no reliable account of its actions. That may make deployment slower at the start, but it also makes approval and incident response less fragile.
There is still uncertainty. The ICO is gathering evidence, not announcing a finished agent rulebook, and the individual developer commitments aren't fully itemised. But the direction of the enquiry is practical: once software can act, privacy assurance has to follow the action, not stop at the model boundary.
A New Link in AI Chip Packaging
That regulatory shift is about controlling software action. The next constraint is physical: joining advanced chips and memory closely enough to feed modern AI systems.
GlobalFoundries and TSMC have signed a five-year manufacturing agreement valued at two billion US dollars. GlobalFoundries plans to add capacity in New York to produce silicon interposers for TSMC's CoWoS advanced-packaging ecosystem, with volume production expected to begin ramping in the first half of 2028.
An interposer is a layer of silicon that provides dense, short connections between pieces inside a larger package. In an AI accelerator, that can mean linking logic chiplets to stacks of high-bandwidth memory. The processor may get the attention, but it can't move data at the required rate if the connections and packaging around it aren't ready. CoWoS capacity has therefore become part of the supply calculation for high-performance AI hardware, not a finishing detail after the chips are fabricated.
The agreement adds a US manufacturing source for one component in that chain. For chip customers worried about concentration, that geographical diversification has strategic value. It could also give TSMC another route for interposer supply as demand grows. GlobalFoundries already operates the New York site, but the companies haven't disclosed how much capacity they intend to add or how future output will be allocated.
The timing is the important restraint. A ramp beginning in 2028 won't ease a packaging shortage in the next quarter. New production still has to be installed, qualified and brought up to useful yields. Interposer fabrication is also only one stage; assembly, packaging and testing all have to line up before a finished accelerator reaches a customer. Two billion dollars signals commitment, but it doesn't collapse that schedule.
For organisations planning large AI infrastructure purchases, I would treat this as a medium-term supply-chain improvement rather than near-term relief. Another qualified source may eventually reduce concentration risk and support more capacity. Until the output volume and customer allocation are known, though, it shouldn't be read as a promise of cheaper or more available accelerators in 2027. The benefit is redundancy. The cost is waiting for the manufacturing reality to catch up with the agreement.
AI Finds Critical Network Flaws
Hardware supply takes years to change. A critical network patch can land on an operator's desk with no such breathing room.
Cisco has issued security-hardening releases covering six classes of vulnerability in NX-OS-based switches and fabric interconnects. The affected product families include Nexus 3000, 7000 and 9000 switches, MDS 9000 switches, and several UCS fabric interconnects. Some access-control and out-of-bounds-write groups carry scores as high as 9.8 on the ten-point CVSS severity scale.
Cisco says there are no workarounds. That makes this an upgrade job rather than a configuration tweak: operators need to identify affected devices and software versions, choose the fixed release for each platform, and schedule the change. Core switches and storage fabrics aren't always easy to interrupt, so the quality of the asset inventory and maintenance process will determine how quickly the risk can be reduced.
There is a notable discovery story here as well. Cisco says conventional internal testing was combined with frontier AI models to find the flaws. The advisory doesn't credit AI with every finding, and it doesn't turn the models into autonomous security authorities. It does show AI-assisted analysis producing vulnerabilities serious enough to trigger fixes across widely used infrastructure.
Cisco reported no known active exploitation when the advisory was published on 7 October. That is useful operational context, but it isn't proof that exploitation has never happened. Defenders still have to make a risk-based patch decision using exposure, device role and the availability of a safe maintenance window. With no workaround, leaving an affected version in place also leaves no compensating fix supplied by the vendor.
My practical takeaway for network operators is that AI-assisted discovery only pays off when ordinary operational discipline can absorb the result. A clever model finding a memory-safety flaw is valuable. An accurate inventory, a tested upgrade path and somebody able to book the outage are what convert that finding into protection. As discovery tools improve, vendors may surface more issues in clusters like this. Organisations with slow patch pipelines could feel the burden before they feel the security gain.
Credentials Caught Before the Push
There is another security problem where timing makes all the difference: catching a credential before it enters repository history.
GitHub has upgraded its existing AI-detected password alerts with a fine-tuned contextual classifier. It has also put pre-push detection for unstructured secrets into private preview. The distinction matters because many secret scanners are strongest when a token follows a known pattern. A plain password, connection detail or unusual credential may look like an ordinary string unless the scanner understands the surrounding code.
GitHub says its classifier reads that context to decide whether a string is likely to be a credential. It isn't generating code or prose. The model is based on ModernBERT and is designed as a focused classification system. Existing scanning for AI-detected alerts remains included for customers using GitHub Secret Protection and GitHub Advanced Security. The more preventive push-protection feature is opt-in, remains in private preview and consumes GitHub AI Credits, as will planned checks in Copilot security review.
That push path is where the idea becomes operationally interesting. Finding a secret after a commit reaches a remote repository can trigger removal from history, credential rotation, service checks and an incident review. Blocking a likely secret before the push could avoid most of that work. It could also broaden coverage beyond token formats that security products already recognise.
The difficult part will be accuracy at the moment of interruption. GitHub reports evaluation latency below two milliseconds and says contextual push protection could more than double the types of secrets that can be prevented. Those are company measurements, and preview behaviour will show whether the classifier can keep false positives low across real codebases. If developers are repeatedly blocked by harmless strings, overrides become muscle memory and the control weakens.
For development organisations, the promising shift is from cleaning up a leaked credential to preventing it with code context. I wouldn't build a security process around the preview until its accuracy and final pricing are clearer. But if the classifier proves quiet enough, putting the decision before the push could make secret rotation a rarer and much cheaper interruption.
Specialist Agents Enter the Workflow
Security controls are becoming more contextual. Enterprise agent design is becoming more divided, with one agent handing work to another specialist.
Salesforce has made Agentforce Multi-Agent Orchestration generally available in its Winter '27 developer release. An orchestrator can now pass work to specialist agents within an organisation, rather than asking one large agent definition to handle every part of a process. Agent Script has also gained deterministic human escalation and controls that shape output according to the connection being used.
The appeal is familiar to anyone who has split a large application into smaller services. A sales agent, support agent and fulfilment agent can each have a narrower role, with the orchestrator selecting the right one. Definitions should also be easier to move between Salesforce organisations because API version 68.0 reduces deployment to two main metadata types. Both the source and destination organisations need to support that API version, so the simpler packaging won't apply everywhere immediately.
Availability also depends on Salesforce's staged production rollout. Winter '27 reaches customer instances across multiple upgrade windows, and configuration still affects what each customer can use. General availability describes the platform capability; it doesn't tell us how a particular organisation's agent network will perform in production.
The benefit is modularity. A specialist can carry tighter instructions and access than an all-purpose agent, and an organisation can update one area without rewriting the whole workflow. The extra hand-offs create their own questions, though. Which agent had authority at each step? What data crossed the boundary? If the final result is wrong, does the failure belong to the orchestrator, the specialist or the connection between them?
My view is that Salesforce customers should judge this release by traceability as much as capability. Multi-agent orchestration may make complex automation easier to assemble, especially where existing business functions already have clear owners. It can make diagnosis harder if logs and permissions don't follow the hand-off. The new escalation and connection-aware controls are therefore central, not decorative: they are how a modular agent system remains understandable when work leaves the first agent's hands.
SpaceX Buys a Mobile Foothold
From enterprise workflows, let's change scale completely and look at the radio spectrum behind a possible new mobile network.
SpaceX has agreed to acquire up to fourteen megahertz of paired nationwide spectrum in the United States, in the 800 megahertz band. It plans to combine that low-band allocation with satellite and terrestrial infrastructure for a service called Starlink Mobile. The transaction still needs final regulatory approval.
Low-band spectrum is valuable because it travels further and penetrates buildings better than the higher-frequency capacity SpaceX currently uses for direct-to-device links. That gives the proposed network a more credible way to cover ordinary mobile environments, including places where a satellite-only signal has limitations. A hybrid design could use space coverage where terrestrial infrastructure is sparse and ground infrastructure where capacity and indoor reach matter.
Spectrum ownership is only one input, though. Independent reporting notes that SpaceX would still need substantial terrestrial infrastructure to build a viable nationwide service. The company is targeting a launch in late 2027, but the deployment design, coverage, pricing and approval timetable remain unresolved. Nothing in this agreement changes a consumer's mobile service today.
For the public, the interesting prospect is another network model that blends ground and space coverage rather than treating them as separate products. That could eventually create useful competition or fill coverage gaps. I would keep the expectation anchored to what has actually been bought: a stronger technical foothold, not a finished network. The difficult work of deployment begins after the spectrum deal.
A Faster Bridge Between Quantum Systems
One last piece of specialised hardware is much earlier in its journey, but the experiment tackles a real bottleneck in modular quantum computing.
IonQ says it has generated entanglement between a trapped barium-ion qubit and a quantum memory built from a silicon-vacancy centre in diamond. The photonic interconnect produced an average rate a little above one kilohertz: about one thousand and thirty-two entangled pairs per second, with reported Bell-state fidelity of 87.9 per cent.
Entanglement is the shared quantum relationship that can let separated components participate in one larger system. The noteworthy part here is that the two ends use different physical technologies. Trapped ions can provide high-quality qubits for processing, while a solid-state defect in diamond can act as memory. Connecting unlike components offers a path towards modular machines in which processors and memories are chosen for different strengths, much as conventional computing uses specialised parts.
A faster link helps because a modular quantum computer needs to create these remote connections repeatedly and reliably. A kilohertz rate narrows one networking constraint, but fidelity still matters: imperfect entanglement creates errors that have to be managed, and a useful distributed machine would need far more than a single two-node laboratory connection.
That boundary is important. The work is described in a preprint, the record claim comes from IonQ, and there is no peer-reviewed or independent benchmark confirmation yet. It isn't a commercial multi-node quantum computer, and it hasn't demonstrated useful distributed workloads.
For organisations following quantum technology, this is evidence that heterogeneous quantum components can be linked at a higher reported rate, not a reason to revise near-term computing plans. The next tests are whether researchers can improve fidelity, reproduce the result and scale the method beyond two nodes. If those steps hold, modular architectures get a more credible building block. Until then, the honest description is a strong laboratory link with a great deal of system engineering still ahead.
What Changes for You
There is one release today that working AI builders can try directly, and it takes a narrower approach than another general-purpose chatbot.
Cloudflare has released Clef-omni, a multimodal decision model that accepts text, JSON, images, audio and video. Instead of writing free-form prose, it returns probabilities over options that the developer defines in a schema. That makes it suited to jobs such as classification, moderation or routing, where an application needs a typed choice rather than an eloquent paragraph. It is available as Apache 2.0-licensed open weights and through Cloudflare Workers AI.
The model uses a thirty-billion-parameter mixture-of-experts backbone derived from Qwen3-Omni-30B-A3B-Instruct, with roughly three billion parameters active for a request. On Workers AI, Cloudflare lists a sixty-four-thousand-token context window and a price of fifteen US cents per million input tokens. Images, audio and video are converted into billable input tokens, so the apparent text price isn't the complete cost for a media-heavy workload.
The practical change is that a builder can send mixed media through one typed decision call instead of maintaining separate transcription, vision and output-parsing stages for a suitable task. The probability output can also be logged and tested more cleanly than an answer that has to be parsed from prose.
There are firm limits. Hosted requests allow four audio clips and two videos, with each video capped at sixty seconds. Self-hosting the unquantised weights needs substantial GPU capacity. Cloudflare's speed and benchmark results are vendor-reported, and accuracy will vary with the schema, media and subject matter. I would see the release as a chance to simplify an existing decision pipeline after testing it against that pipeline's real data, not as automatic evidence that one multimodal model can replace every specialised classifier.
You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.
Sources
Reporting behind this episode.
- ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/10/ico-secures-changes-from-leading-ai-developers-as-scrutiny-extends-to-ai-agents
- tomshardware.com/tech-industry/semiconductors/globalfoundries-to-produce-silicon-interposers-for-tsmcs-cowos-in-the-us-five-year-agreement-valued-at-usd2-billion
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR
- github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection
- github.blog/ai-and-ml/github-copilot/secret-protection-must-scale-with-software
- developer.salesforce.com/blogs/2026/10/developers-guide-to-the-winter-27-release
- spacex.com/updates/starship-moon-announcement
- axios.com/2026/10/09/spacex-elon-musk-spectrum
- ionq.com/news/ionq-demonstrates-world-first-quantum-memory-enhanced-interconnect-for-distributed-quantum-applications
- quantumcomputingreport.com/ionq-demonstrates-1-khz-memory-enhanced-quantum-interconnect-connecting-trapped-ions-and-diamond-color-centers
- blog.cloudflare.com/clef-faster-cheaper-multimodal
- developers.cloudflare.com/workers-ai/models/clef-omni