Seven of the nine most used image editing apps that the nonprofit AI Forensics tested on Hugging Face, the main public repository for open AI models, removed the clothing from a photograph of a clothed woman on request, per The Verge. The group also ran decoy apps on the platform and logged more than 1,000 prompts in a week, 73% of them sexual. Of those sexual prompts, 83% sought to undress or sexualize the subject, and 95% of those targeted women. AI Forensics said 6.7% of the sexual requests targeted apparent children, per Wired.
Read at The Verge ↗ • Read at Wired ↗
Microsoft launched MAI-Cyber-1-Flash, its first internally built security model, and Project Perception, a set of AI agents that find and fix software flaws, at a San Francisco event Monday, per TechCrunch. "We're shipping this into production immediately," Microsoft AI chief executive Mustafa Suleyman said. The model handles roughly 95% of the work done by MDASH, Microsoft's automated system for finding software vulnerabilities, with more computationally intensive tasks routed to OpenAI's GPT-5.4, per Axios. Microsoft said pairing its model with GPT-5.4 scores 95.95% on CyberGym, a benchmark measuring a model's ability to generate working exploits for known software vulnerabilities, against about 83% for Anthropic's Mythos and OpenAI's GPT-5.5-Cyber. The company will distribute the model through Azure AI Foundry rather than release it publicly. Unlike other leading AI companies, Microsoft did not share the model with independent testers for evaluation before release, per The New York Times.
Read at The New York Times ↗ • Read at TechCrunch ↗ • Read at Axios ↗
The U.S. National Vulnerability Database, the federal government's public catalog of software security flaws, has logged 45,207 vulnerabilities from January through Monday, a pace that would roughly double the 2025 total, per Bloomberg. Oracle patched 1,449 flaws in its July update, up from 309 a year earlier. Gabriel Bernadett-Shapiro, a distinguished AI research scientist at the security firm SentinelOne, said the tools are increasing people's ability to find vulnerabilities in software, per Insurance Journal. Microsoft disclosed 642 vulnerabilities in July, about five times its total for the same month last year, and Google's Chrome team fixed 433 against 11 a year ago.
Read at Bloomberg ↗ • Read at Insurance Journal ↗
A working paper by Nicola Borri, Aleh Tsyvinski and Yukun Liu analyzed 380 trillion AI tokens routed through the model marketplace OpenRouter between January 2024 and April 2026, roughly 2% of monthly global AI usage, and built them into a single measure of AI consumption, NPR reported. Companies whose stock returns moved most closely with that measure beat the least sensitive companies by about 0.64 percentage points per week, a gap the authors call an AI premium. The premium showed up well outside tech, in airlines, utilities, retailers, banks and waste management, and was strongest in the U.S. and Europe and much weaker in China and emerging markets. "Financial markets already see Main Street being impacted," Tsyvinski said. The paper has not been peer reviewed, and OpenRouter's users skew toward heavy, cost conscious developers rather than the average subscriber.
Read at NPR ↗