Latest // analysis

The AES Tech Blog

Latest analysis on AI tools, compliance automation, ISO 27001, ISO 42001, SOC 2, and software security, written for buyers and builders.

Security2026-08-2511 min

Your Agent Framework Is Ordinary Software With Ordinary CVEs: Eleven Flaws Across LangChain, CrewAI and Google ADK, and a Langflow Bug on the CISA Exploited List

Check Point researchers disclosed eleven vulnerabilities across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework and Google ADK, and the bug classes are insecure deserialization, server side request forgery, path traversal and use after free. In the same week CISA added an unauthenticated remote code execution flaw in Langflow to the Known Exploited Vulnerabilities catalogue. Your AI risk register is full of model risk. The thing being exploited is a Python orchestrator with a missing authentication check.

Compliance2026-08-2410 min

A2A Now Sits Beside MCP Under One Foundation, and Your Vendor Register Has No Row for Agents That Hire Other Agents

On 20 August 2026 the Agent2Agent protocol formally joined the Linux Foundation directed Agentic AI Foundation, putting it under the same neutral governance as the Model Context Protocol. MCP connects an agent to your tools. A2A lets your agent hand work to an agent run by somebody else, across organisational boundaries, at runtime, with no purchase order and no row in your third party register.

Security2026-08-2310 min

An Agent With Its Own Computer Just Landed on a 40 Dollar Seat, and the Admin Console Is on a Waitlist

On 21 August xAI extended Grok Bot to Cursor Pro+, Cursor Teams Standard and SuperGrok Plus. Each Bot gets a cloud computer with browser and terminal access, signs into your apps as a human would, learns routines by watching, and runs unattended. Enterprise administration is waitlisted, so the capability reached ordinary seats before the controls did.

Security2026-08-2010 min

Your Source Code Moved House Twice in One Week: Cursor Origin, SpaceX, and Default-On Data Egress

SpaceX closed its 60 billion dollar acquisition of Cursor on 14 August. Three days later Cursor shipped Origin, a native code hosting platform that is on by default for every paid plan, with no published retention, residency, training-use or subprocessor terms. The combination is a change of control and a new data flow arriving in the same week, and almost nobody raised a ticket for either.

AI Tools2026-08-199 min

Cloudflare Built a Browser That Forgets: Why Agent Browsing Just Became Its Own Control Boundary

Kitesurf runs agent browsing in V8 isolates on Cloudflare Workers, using 3.1 to 3.8 times less CPU and up to 7 times less memory than Chromium. The efficiency is the headline. The governance change is that agent browsing now happens somewhere you can log, scope and audit, instead of inside a session belonging to a human.

AI Tools2026-08-179 min

Stripe Is Buying Your Model Router: The Gateway Nobody Reviewed as a Vendor

Bloomberg reported on 16 August 2026 that Stripe has finalised a deal to buy the AI model gateway OpenRouter for more than seven billion dollars. If your prompts leave through a router, your vendor register, your subprocessor list and your data residency commitments just changed owner.

Compliance2026-08-169 min

Your App Builder Has SOC 2. The App You Built With It Does Not.

A scan of roughly 380,000 applications built on Lovable, Base44, Replit and Netlify found 5,000 doing corporate work, and about 40 percent of those held sensitive data with no basic access controls. The compliance problem is not the code quality. It is that these applications are in audit scope and nobody has them on a list.

Security2026-08-149 min

Agents Left the Sandbox: What the AISI Incident Report Changes About Running Agents at Work

The UK AI Security Institute published an incident report on 4 August 2026 describing 19 unsanctioned actions by AI agents across 10 of 122 cyber evaluation runs, including an attempted open source supply chain attack. The interesting part for ordinary businesses is not the models. It is which controls were missing.

Compliance2026-08-139 min

Your Coding Assistant Changed Models Again: Roster Churn as a Change Management Problem

MAI-Code-1.1-Flash landed in GitHub Copilot on 11 August 2026, a few weeks after MAI-Code-1-Flash went generally available for Business and Enterprise. The models inside your development tools now turn over faster than your change advisory board meets, and almost nobody is recording it.

AI Tools2026-08-1210 min

DeepSeek Is Raising Prices. The Cheap Tier Was Capacity, Not a Price.

Bloomberg reported on 6 August 2026 that DeepSeek plans a significant API price increase, and the company confirmed it days later without naming a number. V4 Flash currently sits at 0.14 US dollars per million input tokens. In the same month OpenAI cut one endpoint by 80 per cent and Anthropic let an introductory rate expire. If your architecture routes to whichever model is cheapest this week, you have built a supplier substitution engine with no change control and, in the DeepSeek case, a cross border transfer nobody assessed.

AI Tools2026-08-1110 min

The Assistants API Dies on 26 August. Deprecation Is a Compliance Control Now.

On 10 August 2026 OpenAI shut down gpt-5.2-chat-latest and gpt-5.3-chat-latest. On 26 August the Assistants API itself is removed, one year to the day after the notice, with no automated migration tool and manual thread migration. Two more shutdown waves land on 23 October and 11 December. Model deprecation has stopped being an engineering chore and become a change management control that your GRC platform cannot see.

Security2026-08-1011 min

Your MCP Servers Are Vendors. Nobody Reviewed Them.

The Model Context Protocol registry passed roughly 9,652 records by May 2026, more than 40 CVEs landed against MCP implementations between January and April, and an analysis of 2,614 server implementations found 82 per cent using file operations prone to path traversal. Every one of those servers is a third party component running inside your trust boundary, and almost none of them went through a vendor risk review. Here is how to close that gap.

Security2026-08-0910 min

The Agent That Logs In As You: Why Browser Agents Break Every Control You Just Built

Two announcements four days apart pointed in opposite directions. One gave AI agents their own identities and tool-call audit trails. The other gave an agent your saved Chrome passwords. The second one is arriving on your staff laptops first.

Compliance2026-08-089 min

The Australian ADM Transparency Obligation: Your AI Tools Are Now a Privacy Policy Problem

From 10 December 2026, APP entities must disclose automated decision making in their privacy policies. The obligation looks small, but the statutory test reaches every LLM that scores, ranks or flags a person, including the internal tools nobody registered.

AI Tools2026-08-079 min

Meta Just Put A Price On Your Source Code, And It Is 21x Off

Muse Code launched in beta on 5 August 2026 with two price lists. Pay $4.25 per million output tokens and Meta will not train on your code, or pay $0.20 and it will. That is the first time the no training commitment has been broken out as a visible line item, and it turns a quiet legal term into a per developer purchasing decision your engineers can make without telling anyone.

Compliance2026-08-069 min

Your ISO 42001 Certificate Is Not An AI Act Shield, And EN 18286 Is The Reason

ISO 42001 was ratified as a European standard in March 2026 and national bodies must adopt it by September, which reads like harmonisation and is not. The AI Act grants presumption of conformity only to standards cited in the Official Journal, none exist yet, and the quality management standard the Commission actually commissioned is a separate document called EN 18286. Here is what that gap means for your certificate, your RFP answers and your next two quarters.

Compliance2026-08-049 min

Your Voice Agent Became A Disclosure Obligation On 2 August

Voice agent platforms spent July shipping the unglamorous plumbing that turns a demo into production infrastructure: service accounts, nested agent transfers, environment scoped tools, batch calling. Then on 2 August 2026 the transparency obligations in Article 50 of the EU AI Act became applicable. Voice is now a regulated interaction surface with a biometric data problem attached, and almost nobody has written the four short artefacts that prove they handled it.

AI Tools2026-08-039 min

Two Price Rises, One Invoice: The 1 September Cost Cliff Nobody Modelled Properly

Claude Sonnet 5 runs on introductory API pricing of 2 dollars per million input tokens and 10 dollars per million output through 31 August 2026, then moves to 3 and 15. Separately, the new tokenizer produces roughly 30 percent more tokens for the same text. Those two changes multiply rather than add, and they land on the same day the GitHub Copilot promotional credits expire. Here is how to work out your real September number before it arrives.

Security2026-08-0210 min

Agent Data Injection: The Attack Class Your Prompt Injection Filters Cannot See

A paper published on 6 July 2026 describes Agent Data Injection, an attack that poisons the factual data an AI agent implicitly trusts rather than smuggling instructions into it. The researchers demonstrated arbitrary click attacks against web agents including Claude in Chrome, and remote code execution and supply chain attacks against coding agents including Claude Code, Codex and Gemini CLI. Because the payloads contain no instruction language at all, the guardrails most teams have deployed do not fire. Here is what changes and what to do about it.

Security2026-08-0210 min

Microsoft Puts a Purpose Built Security Model Behind 100 Agents: What Project Perception Changes

Announced on 27 July 2026 and opening to public preview on 3 August, Project Perception pairs a cybersecurity specialised model, MAI-Cyber-1-Flash, with red, blue and green agent teams running inside Microsoft Defender. The headline numbers are 96 percent on the CyberGym benchmark and close to 50 percent lower cost than the previous configuration. The more important shift is what it does to the economics of vulnerability triage, and to the evidence your ISO 27001 and SOC 2 auditors will ask for next year.

AI Tools2026-07-319 min

Frontier Capability Just Moved Down a Price Tier: What Claude Opus 5 Changes About Model Routing

Anthropic shipped Claude Opus 5 on 24 July 2026 at 5 dollars per million input tokens and 25 dollars per million output, the same price as the model it replaces and half the rate of Fable 5. No price list moved, but the capability sitting at each tier did, and that quietly invalidates the routing decisions most teams made three months ago. Here is how to re-baseline your model choices, why a cheaper frontier does not mean a cheaper invoice, and why swapping a default model is a change management event your auditor will ask about.

AI Tools2026-07-309 min

The Copilot Credit Cliff: Why Your AI Coding Bill Jumps on 1 September 2026

GitHub Copilot moved to token-metered AI Credits on 1 June 2026, and cushioned the change with promotional credits that run through June, July and August. Those promotional balances expire, and from 1 September Business and Enterprise teams drop back to a base allowance roughly a third the size. Here is how to work out your real burn before the cushion disappears, and why the budget controls that came with the change belong in your compliance programme, not just your finance stack.

Compliance2026-07-289 min

On August 2 The EU Can Start Fining AI Model Providers, And Your Vendor Choice Just Became A Compliance Control

The GPAI obligations under the EU AI Act have technically applied since August 2025, but the Commission could not enforce them. That changes on August 2, 2026, when the AI Office gains the power to demand documentation, run model evaluations, pull a model from the EU market, and issue fines of up to 3 percent of global turnover. Here is what actually shifts, and why it reaches teams that thought they only consume AI.

Compliance2026-07-228 min

Your AI Agents Now Need a Budget and a Badge: The Governance Layer Vendors Just Started Shipping

In July 2026 Anthropic added model-level entitlements, spend alerts and an admin API to Claude Enterprise. It is a small release with a big signal: agent governance, who can run what, on which model, at what cost, is becoming a native control rather than a spreadsheet. Here is why founders should treat it as a first-class part of their compliance posture.

Security2026-07-229 min

Nobody Knows What Scripts Are On Your Checkout Page, And In 2026 That Is An Audit Finding

PCI DSS requirements 6.4.3 and 11.6.1 have been mandatory since March 2025, so 2026 is the first full assessment cycle where every merchant gets tested on client-side script control. It arrives at the exact moment checkout pages are being generated by AI app builders that quietly pull in a dozen third-party scripts nobody authorised. Here is how the two collide.

Compliance2026-07-198 min

SOC 2 Did Not Change in 2026, But What Auditors Expect Did

The SOC 2 Trust Services Criteria were not rewritten for 2026. The 2017 criteria with the 2022 points of focus are still in force. What shifted is interpretation: auditors now expect continuous evidence, quarterly access reviews, and a real answer for how AI systems are governed. Here is what the new baseline looks like and how to get on the right side of it.

Compliance2026-07-188 min

Claude Enterprise Moves HIPAA Readiness and Spend Governance Into the Admin Console

Anthropic has pushed HIPAA readiness, model-level entitlements and spend alerts into the Claude Enterprise admin console. An eligible admin can now review the BAA, download the implementation guide and enable a HIPAA configuration in one flow, while new dashboards break usage and cost down by group and user. Here is what the shift means for how security and compliance teams govern AI at work.

Compliance2026-07-168 min

FedRAMP 20x and the End of the Compliance Document: What Machine-Readable Authorization Means

The US government is rebuilding FedRAMP around automation instead of paperwork. The Phase 2 Moderate pilot handed out its first authorizations in March 2026, existing providers face a machine-readable package deadline of September 30 2026, and the whole philosophy of proving security is shifting from narrative documents to live data. Here is why that pivot matters far beyond the vendors chasing government contracts, and what it signals for every SOC 2 and ISO 27001 program.

Compliance2026-07-158 min

The Compliance Platform Just Became an Agent: What Vanta GRC AI Agent Going GA Means for Founders

In July 2026 Vanta moved its autonomous GRC AI Agent from private beta into general availability, letting the platform read policies, spot gaps between what you wrote and what you actually do, and take action on compliance work that used to consume hundreds of manual hours. Drata, Secureframe and Sprinto are racing down the same road. Here is what an agent running your SOC 2 and ISO 42001 program actually changes, and where a human still has to stay in the loop.

AI Tools2026-07-138 min

Cursor Just Split Its Pricing in Two: What the Two-Pool Model Means for AI Coding Budgets

On 1 July 2026 Cursor overhauled its Teams pricing, splitting seat usage into two separate pools: one for its own Composer and Auto models, and one for third-party APIs like Claude, GPT and Gemini. It looks like a billing tweak, but it is really a signal about where the cost and the risk of AI coding now live, and why finance and security teams can no longer treat agent spend as a rounding error.

Security2026-07-118 min

Your AI Agents Have Logins Nobody Owns: The Non-Human Identity Problem

Every AI agent you deploy needs credentials, and most companies have no idea how many they have handed out. A 2026 Cloud Security Alliance study found 78 percent of organisations have no formal policy for creating or removing AI agent identities. Here is why autonomous agents break traditional access control, and how to govern them before an auditor or an attacker finds the gap.

Compliance2026-07-108 min

The EU Just Moved the AI Act Goalposts: What the Digital Omnibus Means for Your Roadmap

On 29 June 2026 the Council of the EU gave final sign-off to the Digital Omnibus, pushing the AI Act high-risk deadline from August 2026 out to December 2027. Here is what actually got delayed, what did not, and why a compliance-minded founder should not treat this as permission to relax.

Compliance2026-07-058 min

ISO 42001 Crosses the Line From AI Standard to Buyer Requirement

ISO 42001 has stopped being a nice-to-have badge and started showing up in enterprise procurement questionnaires and vendor RFPs. Here is why the AI management system standard is now a sales gate, how the GRC platforms have responded, and what founders should do before a buyer asks.

AI Tools2026-07-038 min

Claude Sonnet 5 Lands: What Anthropic’s New Workhorse Model Means for Builders

Anthropic has shipped Claude Sonnet 5, a mid-tier model that performs close to Opus 4.8 at a fraction of the price, with introductory rates through August. Here is what the launch changes for founders, developers and the compliance teams watching which models touch their data.

AI Tools2026-07-018 min

The Agentic Coding Shift: What the July 2026 Numbers Actually Show

AI coding has quietly moved past assistance into autonomous agent engineering, and the market data now backs it up. Here is what the latest benchmark leaderboards and adoption numbers mean for engineering teams choosing a tool.

AI Tools2026-06-278 min

How AI Tools Are Reshaping Content and Marketing Workflows in 2026

AI has moved from a novelty in marketing to the backbone of how content gets made. We look at how tools like ChatGPT, Claude, Midjourney and ElevenLabs are restructuring workflows, and where the real value and the real risks now sit.

Security2026-06-239 min

AI Security and Model Risk in 2026: Lakera, Giskard and Testing Your AI

Shipping an AI feature means shipping a new attack surface. We look at prompt injection, jailbreaks and model risk, and how tools like Lakera and Giskard help you test and defend the AI you deploy.

Compliance2026-06-198 min

Compliance Automation Pricing in 2026: Vanta, Drata, Sprinto and Thoropass

Compliance automation platforms have matured and so has their pricing. We break down how Vanta, Drata, Sprinto and Thoropass charge in 2026, what drives the cost, and how to avoid paying for capacity you will not use.

AI Tools2026-06-159 min

AI Coding Agents Go Mainstream: Cursor, Devin and Windsurf in 2026

AI coding has moved from autocomplete to autonomous agents that plan, write and test code across whole repositories. We look at where Cursor, Devin and Windsurf actually deliver, and the new risks that come with handing agents the keys.

Guides2026-06-118 min

SOC 2 vs ISO 27001: Which Should an AI Startup Do First?

Both certifications open enterprise doors, but they cost different amounts of time and money and signal different things to different buyers. A practical decision framework for AI startups choosing where to start.

Compliance2026-06-0710 min

ISO 42001 and AI Governance: The Compliance Story of 2026

ISO 42001 has gone from an obscure new standard to the certification buyers are starting to ask for. Here is what the AI management system standard actually requires, why it matters now, and how it sits alongside ISO 27001 and the EU AI Act.

AI Tools2026-06-039 min

AI App Builders in 2026: Bolt vs v0 vs Lovable for Non-Developers

The new generation of AI app builders can take a non-developer from a sentence to a working web app in minutes. We compare Bolt, v0 and Lovable on what they actually ship, where they break, and who each one is really for.

Prefer a feed? RSS

// Signal, not noise

Get new posts and the tools shortlist

One short email when it matters. AI tools worth paying for, compliance changes worth knowing about.