September 30, 2026
Open AI’s Muse Rival Arrives Half-Baked - PYMNTS.com
OpenAI’s Muse Rival Arrives Half-Baked PYMNTS.com
Read original articleDataAIHub Daily
Archive →50 curated AI news stories from leading AI companies.
September 30, 2026
OpenAI’s Muse Rival Arrives Half-Baked PYMNTS.com
Read original articleSeptember 30, 2026
Generative recommender (GR) systems are emerging as a powerful new approach for large-scale personalization. Instead of treating recommendation as a set of...
Read original articleSeptember 30, 2026
FTC launches broad investigation into Anthropic, OpenAI washingtonpost.com
Read original articleSeptember 30, 2026
FTC is investigating OpenAI and Anthropic over possible risks to consumers ABC7 San Francisco
Read original articleSeptember 30, 2026
FTC is investigating OpenAI and Anthropic over possible risks to consumers WABC-TV New York
Read original articleSeptember 30, 2026
So much for Gemini 3.5 Pro.
Read original articleSeptember 30, 2026
Google announces Gemini 4 flagship AI model after months of delays Reuters
Read original articleSeptember 30, 2026
Google on Wednesday announced Gemini 4 Argon, the company’s long-awaited flagship model, and it looks like it was worth the The post Gemini 4 Argon is here: It’s great, and you can’t have it yet appeared first on The New Stack.
Read original articleSeptember 30, 2026
Alphabet Inc.’s Google has begun rolling out Gemini 4 Argon, its long-awaited flagship artificial intelligence model, but the company is grappling with internal skepticism over how well it performs in key areas, such as coding.
Read original articleSeptember 30, 2026
FTC intensifies OpenAI, Anthropic probe following 'rogue AI' attacks USA Today
Read original articleSeptember 30, 2026
OpenAI's Dots and Meta's Muse are vying to be your AI agent of choice. I've tried both—and I suspect you will too.
Read original articleSeptember 30, 2026
AI infrastructure engineers, storage developers, and cloud service providers need fast and secure access to high-capacity file and object storage to support AI...
Read original articleSeptember 30, 2026
OpenAI and Synopsys are building GPT-Synopsys, a specialized AI model for chip design. It's meant to operate Synopsys' EDA tools like a seasoned engineer and optimize designs on its own. Early tests with semiconductor customers are already underway. OpenAI is likely using the partnership to advance its own chip development as well. The article OpenAI and Synopsys team up to build an AI model that designs chips like a seasoned engineer appeared first on The Decoder.
Read original articleSeptember 30, 2026
OpenAI's "Decisions API" is a Jev clone that confirms the importance of fast, cheap intelligence.
Read original articleSeptember 30, 2026
OpenAI makes others suffer "the harms of its unsafe decision-making," nonprofit says.
Read original articleSeptember 30, 2026
Google is replacing Gems with "Skills" in Gemini chat. Skills are detailed, reusable prompts that users invoke by typing "/" or that Gemini runs automatically. The format is based on an open standard from Anthropic. Gems will be phased out starting in November, with existing ones migrating automatically. The article Google drops Gems for Skills, joining OpenAI and Anthropic in the shift to agent-ready prompt formats appeared first on The Decoder.
Read original articleSeptember 30, 2026
Google DeepMind has introduced SynthID Bio, a family of watermarking methods designed to tag AI-generated proteins without damaging their function. The company says... The post Google DeepMind Unveils SynthID Bio, Creates World’s First Watermarked AI-Designed Proteins That Still Work In The Lab appeared first on OfficeChai.
Read original articleSeptember 30, 2026
Taxpayers Have Been Subsidizing Meta’s AI Data Centers: Report gizmodo.com
Read original articleSeptember 30, 2026
Bloomberg’s Ed Ludlow breaks down OpenAI's plan to raise at least $30 billion from investors in a new round of funding after pushing back its plans for an IPO. Plus, President Trump supports using outside auditors to assess the safety of AI systems after meeting with Silicon Valley leaders; and Apple keeps pushing the envelope under new CEO John Ternus with plans to make its foray into the smart-home market. (Source: Bloomberg)
Read original articleSeptember 30, 2026
Meta classifies its AI data centers as "pilot models" and Nvidia chips as experimental materials to save billions in federal taxes. In 2025 alone, that added up to $3.9 billion. The tax credit dates back to 1981, and even Meta's own accountants see the strategy as legally risky, the New York Times reports. Zuckerberg himself said in January 2025 that these data centers, now framed as experimental, would "drive our core products and business." The article Meta dodges billions in US taxes by calling its AI data centers experiments appeared first on The Decoder.
Read original articleSeptember 30, 2026
OpenAI accused its Chinese rival Moonshot AI of being responsible for a wide-scale effort to extract data from its GPT artificial intelligence systems that could be used to reproduce the reasoning and capabilities of the company’s most advanced models.
Read original articleSeptember 30, 2026
Today, we’re launching a new Databricks AI Function ai_decide that makes fast decisions...
Read original articleSeptember 30, 2026
Musk’s SpaceXAI Considers Overhaul of Pricing for Grok, X Users Bloomberg.com
Read original articleSeptember 30, 2026
OpenAI sued by safety group over autonomous hack of Hugging Face ABC News - Breaking News, Latest News and Videos
Read original articleSeptember 30, 2026
Lakebase is a fully managed Postgres database, built for the operational realities...
Read original articleSeptember 30, 2026
Building an agent is getting easier. More capable models and coding agents are making...
Read original articleSeptember 30, 2026
Get a jump start on the US trading day with Dani Burger on "Bloomberg Open Interest." Yields fall and stocks jump on an inflation surprise, with Micron facing a key earnings test. President Trump strikes an AI accord as OpenAI chases a $1.4 trillion valuation. Plus, Apple makes its long-awaited smart-home push. And Citadel CEO Ken Griffin on his $3 billion gift to Carnegie Mellon, while KKR’s Christopher Sheldon breaks down the $8 trillion AI funding gap. (Source: Bloomberg)
Read original articleSeptember 30, 2026
Pershing Square CEO and founder Bill Ackman says markets are narrowly focused on big initial public offerings. Ackman says Anthropic is one of the greatest business stories he's ever seen, but would not say if it's a company he would invest in. The Claude developer is expected to go public this year. Ackman speaks on "Bloomberg Deals." (Source: Bloomberg)
Read original articleSeptember 30, 2026
Meta says its Muse AI agent cannot access a user’s Messages without explicit permission, disputing a journalist’s account that the agent read his private messages while the required Mac setting was turned off.
Read original articleSeptember 30, 2026
The FTC is formally investigating OpenAI, Anthropic, and other leading AI labs over potential consumer protection violations. The agency plans to force document handovers and executive testimony through legally binding demands. The probe was already underway before the Hugging Face hack and goes well beyond the FTC's earlier push to hold companies liable for their agents' behavior. The article FTC launches sweeping probe into OpenAI, Anthropic, and other AI labs over consumer protection concerns appeared first on The Decoder.
Read original articleSeptember 30, 2026
OpenAI Faces First Lawsuit Over Rogue AI Agents That Hacked Hugging Face gizmodo.com
Read original articleSeptember 30, 2026
Many sites see just one-tenth of one percent of their advertising revenue from AI payments.
Read original articleSeptember 30, 2026
Eric Kauderer-Abrams, Anthropic's head of life sciences, predicts how AI could expedite drug development, while acknowledging risks and the need for safeguards.
Read original articleSeptember 30, 2026
We hereby declare September to be scalability month! As the world prepares for a surge of agentic fleets, we are shoring up our AI infrastructure and orchestration offerings to gracefully — and quickly — respond to that demand, all while maintaining workload isolation and security, and keeping costs in check. Read on to learn how these enhancements manifest across Google Cloud’s compute, network, storage, and orchestration offerings, plus new ways customers are using Google Cloud AI infrastructure, and third-party industry validation of our strategy. Product, technology, and tools updates Google Kubernetes Engine updates: The GKE team is all about improving the scalability of the platform, and in September, those improvements came in many shapes and sizes: New feature: Need an execution runtime with higher density for your agentic workloads? We engineered the new open-source GKE Agent Substrate to run millions of sandboxes with 10x higher density than standard container runtimes. Agent Substrate also delivers sub-500ms resume operations at over 500 suspend/resume activations per second with a native zero-trust kernel and network isolation. Product update: GKE now has scale-to-zero capabilities built-in. No need to configure complex components to scale your workloads down, thanks to the HPA with the Autoscaling Metric and support for KEP-2021, which do the job for you, out of the box. Read the blog to learn more. Product update: Further, the GKE HPA (with the above-mentioned Autoscaling Metric) now lets you scale up and down based on custom PromQL metrics, in addition to standard metrics, allowing you to trigger workloads according to conditions that are meaningful and unique to your business. Read more here. New feature: Yet another scalability feature is GKE Pod snapshots, which lets you save the running state of your workload, including CPU and GPU memory, and restore it on demand. According to internal tests, GKE Pod snapshots can reduce AI inference start-up by as much as 89%. Learn more here. New migration tool: Finally, if you’ve always wanted to migrate your container workloads from AWS EKS to GKE but feared a daunting, high-friction engineering endeavor, we’ve just launched GKE agentic migration, a purpose-built agent plugin that replaces brittle, ad-hoc prompting with an AI-assisted migration pipeline protected by deterministic guardrails. Designed as a compilation of agent skills and a local Model Context Protocol (MCP) server, it uses AI to translate complex AWS EKS IaC and Kubernetes manifests directly into GKE landing zones. Get started with the onboarding guide. Feature updates: Reinforcement learning (RL) and evaluation workloads are a beast: In a standard agentic RL loop, an LLM policy generates actions like code snippets on GPUs and executes them inside isolated CPU sandboxes to observe a reward signal. However, when scaling up this loop to support tens of thousands of parallel rollouts, infrastructure bottlenecks emerge, for instance idle accelerators, image cardinality, and a saturated control plane. To help, we developed GKE Agent Sandbox optimized for RL, plus an Agent Sandbox RL orchestration SDK and native integrations for popular RL gyms and harnesses. All are now generally available, and you can learn more here. Storage updates: AI trains and creates lots of data, and that data has to live somewhere — in block storage systems, file systems, object stores and databases. We announced enhancements to our storage portfolio to help this critical layer roll with the agentic punches: Product update: Filestore agent volumes offer high-performance, elastic, persistent file storage for agentic workloads. Thanks to its tight integration with GKE Agent Substrate and GKE Agent Sandbox, Filestore agent volumes automatically allocates and attaches a dedicated, isolated file workspace to GKE agent sandboxes in milliseconds. Request access to the preview here. New product: If you run generative AI and RAG data layers — think Milvus, Pinecone, Qdrant, Vespa, Redis, and in-memory context caching — you may want to take a look at the M4N family of VMs, now GA, which offers the highest per-core IOPS and throughput of leading hyperscalers. Paired with Google Cloud's custom Titanium offload architecture and paired with Hyperdisk Extreme, M4N instances deliver up to 25,000 MiB/s (25 GiB/s) of aggregate host storage performance and up to 1 million IOPS. New product: Another new Compute Engine product, Z4D, is GA, and a strong storage solution for AI/ML training and inference workloads. When configured as a bare metal instance, Z4D provides both the high local SSD (LSSD) capacity and low latency required by agentic microVMs, so you can run thousands of isolated sandboxes per host with native performance and efficiency. Learn about Z4D machines here. Product update: Today’s AI training and inference pipelines create data faster than most storage management systems can keep up, creating challenges for teams trying to understand their storage estates. A new version of Storage Intelligence advisor makes it easier to answer the question: "What’s in my buckets?" and quickly identify unexpected changes. Then, enhanced batch operations let you automate bulk changes across your buckets — say, move storage classes, mass-delete stale or temporary data, or apply metadata, tagging, retention, or encryption changes. Learn about the latest in Storage Intelligence advisor here. New product: Last but not least, a new version of AlloyDB for PostgreSQL brings together pioneering Google infrastructure — Colossus distributed file system, and Jupiter network — to power a new, no-compromises database architecture for the agentic era. Practitioner guides and how-tos How-to: Wish you could make GPUs and TPUs scattered around the globe behave as a single pool behind a single entry point? In this blog, we show you how to do just that. At the edge, the multi-cluster GKE Inference Gateway focuses on global, multi-region traffic distribution and high availability. Beneath that, the LLM-d router handles complex, memory-aware scheduling algorithms to keep utilization high. This architecture is deliberately runtime-, model-, and accelerator-agnostic, and in tests, routing traffic through the multi-cluster GKE Inference Gateway added less than 1% overhead. Guide: Using or planning to use GKE on TPUs for AI model training or inference? Training massive Large Language Models (LLMs) or running high-throughput inference serving represents a significant investment in specialized AI hardware, such as Cloud TPUs and GPUs. To get the most out of every dollar spent, you need to understand workload lifecycle metrics in GKE. This detailed guide explains how to turn opaque cluster behaviors into actionable telemetry. Customer and partner updates GKE customer: Learn why gaming startup SeaVerse relies on GKE Agent Sandbox for its multi-tenant workloads, and how the platform helped it decrease its infrastructure costs by 60%. Research, reports and deep-dives In case you missed it, we’re also thrilled to share that Google has been named a leader, including achieving the highest score on either product or strategy, in three key analyst reports from Gartner and Forrester. Google is a leader in The Forrester Wave™: Public Cloud Platforms, Q3 2026: Highest overall score of any cloud provider! Google named a Leader in 2026 Gartner® Magic Quadrant™ for Strategic Cloud Platform Services: Positioned furthest for “Completeness of Vision” of all vendors evaluated. Google is a Leader in the 2026 Gartner Magic Quadrant for Container Management: Positioned highest in “Ability to Execute” of all vendors evaluated. Google Cloud achieved a Gold rating in the latest SemiAnalysis ClusterMax 3.0 report, which evaluates the reliability, performance, support, pricing, and security of GPU providers globally. See the full report for more. August 2026 Product, technology, and tools updates Product update: Filestore, Google Cloud’s first-party, secure, scalable NFS file service, has emerged as a popular storage platform for AI and agentic workflows, and now, it’s even better suited to the task, with a new backend storage layer built directly on Colossus, Google’s foundational distributed storage system. This new backend lets you provision IOPS independently from storage capacity, and is deeply integrated with GKE. In AI environments, this can help you service so-called agentic swarms — large groups of agents that need to read and write to a common dataset — without a drop off in performance. For more, check out the blog post. New feature: gVisor sandboxes are now available in distributed Ray clusters on GKE. In partnership with Anyscale, we introduced an experimental library for Ray that brings gVisor, Google’s open-source application kernel, directly into distributed Ray clusters. gVisor provides lightweight environments with stronger isolation than ordinary containers, plus fast startup times and low memory overhead. To try out these sandboxing capabilities on GKE, head over to the Ray sandboxing User Guide. Product update: Looking for high-performance, easy-to-use infrastructure on which to run a personal AI agent, but don’t want to spend a lot of money? New Cloud Run instances are dedicated, singleton compute runtimes on Cloud Run that won’t shut down when the agent is idle. Better yet, the cost to run a Cloud Run instance with 1 vCPU and 1 GiB of memory continuously for 30 days is just $5.70. Practitioner guides, documentation and how-tos How-to guide: Big news in Model Context Protocol (MCP) land: As of the 2026-07-28 specification, the protocol core is “completely stateless. The handshake is gone. The initialize / initialized handshake (SEP-2575) and the logical Mcp-Session-Id header (SEP-2567) have been removed entirely. Instead, every request is now self-describing and independent.” Whoa. Learn more about the changes that the latest MCP specification brings, and more importantly, how to implement them, in this Google Developers blog. Guide: Real-time AI systems make a mess of traditional network load balancing techniques. “Instead of handling isolated requests, the backend has to manage a continuous, live bidirectional stream. You’re dealing with a constant stream of audio chunks, transcripts, model outputs, and synthesized speech flowing back and forth simultaneously.” Things only get worse when the user gets involved. “The server has to immediately halt its current speech generation, pivot to update the context, maybe trigger a new tool, and start drafting a different response; this must be done without dropping the connection.” For a new approach to managing load in the AI era, read Scaling real-time AI agents with session-aware load balancing. How-to: Learn how to build an elastic, scalable LLM inference platform on GKE, even with a mix of different GPU accelerators. The proposed architecture combines Capacity Advisor and Compute Advisor, plus high-performance storage like RunAI:model streamer or GCPFuse with parallel downloads. Get all the details here. Documentation: The thing about hosts with GPUs or TPUs is that you can’t use live migration to update them, setting up a maintenance challenge. In this new docs page, learn how to update accelerator-equipped hosts according to your tolerance for downtime for your training and inference workloads. Documentation: Advanced Compute Images, or ACIs, are standardized image stacks for AI/ML and HPC infrastructure, so you don’t need to manually build your own custom images. In this new docs page, learn how to create an ACI image using the Google Cloud CLI, console, or SchedMD's Slurm workload manager. Guide: AI workloads are notoriously difficult to architect, resource-intensive, and bursty, which can also lead to scaling bottlenecks and large pools of underutilized — or misutilized — compute resources. A new blog outlines the three main ways to achieve dynamic capacity management in Google Cloud: 1) scheduling capacity for planned downtime; 2) maintaining automated fallback capacity for unplanned downtime; and 3) relying on GKE’s core orchestration capabilities to automate resource allocation. Customer and partner updates Business orchestration software provider UiPath was dealing with spiky workloads, and wanted more predictable costs. To get there, it re-architected its infrastructure, moving from isolated clusters to a shared Google Cloud GPU fleet that included both A3 VM instances (NVIDIA H100 GPUs) for training with G4 VM instances (NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs) for inference. You can read more about their architecture here. Mirendil, an frontier AI lab focused on accelerating AI development, announced that it is using AI Hypercomputer with both TPUs and NVIDIA GPUs to support its model pre-training and post-training applications. Replenit, a retail CRM provider, built its AI decision engine in Google Cloud, using BigQuery, Gemini Enterprise Agent Platform, and open-source Gemma models that it runs on Cloud TPUs. This latter combination provided Replenit with 90% lower pipeline costs than their previous cloud provider, the company reports. Read the full case study for more. Malachyte architected its AI-powered e-commerce recommendation platform on top of Bigtable, Managed Service for Apache Kafka, Pub/Sub, Compute Engine, and last but not least, GKE. See how it all comes together in this blog. July 2026 Product, technology, and tools updates Product update: Google Cloud Managed Lustre is now GA, and available in four distinct performance tiers that deliver throughput ranging from 125 MB/s, 250 MB/s, 500 MB/s, to 1000 MB/s per TiB of capacity — with the ability to scale up to 8 PB of storage capacity. The Managed Lustre solution is powered by DDN’s EXAScaler, combining DDN's decades of leadership in high-performance storage with Google Cloud's expertise in cloud infrastructure. Product update: C4N network and storage optimized VMs are now GA. C4N is our first network- and block-storage-optimized VM series built to eliminate data-transfer bottlenecks. Powered by 5th Gen Intel Xeon Scalable processors and built on Google's Titanium offloading hardware, it achieves 400 Gbps network bandwidth, 95 million packets per second (MPPS), and up to 25 GiB/s of block storage throughput when paired with Hyperdisk Extreme. New feature: GKE Dataplane V2 up to 15K Nodes with Network Policies (GA). This capability enables standard GKE clusters to scale up to 15,000 nodes while maintaining full active Network Policy enforcement, supporting the massive infrastructure needs of large enterprise and AI/ML customers. New feature: Co-operative time-slicing in llm-d. If you’re running reinforcement learning (RL) workloads, you can now interleave independent RL jobs onto shared physical hardware, increasing aggregate accelerator duty cycles from a ~40% baseline up to 70% without impacting model convergence or accuracy. New AI security tool: Looking to secure your AI supply chain on GKE, deploy AI workloads safely, and cut down on shadow AI? We open-sourced k8s-aibom, a lightweight, unprivileged Kubernetes controller that continuously monitors container clusters to automatically detect running AI runtimes (like vLLM and Triton) and generate standard CycloneDX Machine Learning Bill of Materials (ML-BOMs). Check out the k8s-aibom project and get involved. Practitioner guides and how-tos How-to guide: On July 27, Google announced Day 0 support for Moonshot AI’s Kimi K3 2.8-trillion-parameter open-weight model, the day weights were released. Whichever your preferred deployment path — via Model Garden, custom orchestration, or GKE with llm-d recipes — this guide offers detailed step-by-step instructions to help you evaluate and pilot Kimi K3 in Google Cloud. How-to guide: Google Kubernetes Engine (GKE) managed DRANET supports both GPUs and TPUs. There are several configurations to use this implementation, including standard cluster (where you have full control) and autopilot cluster (where Google does the heavy configs for you). Take a deeper dive in the hands-on lab, GKE Autopilot clusters with TPUs, GKE managed DRANET and Gemma 4. How-to guide: Learn to run Ray on TPUs, not GPUs. In Part 1 of this two-part series, we discuss TPU slices (hint: Ray thinks of them as just another accelerator on which to schedule), then walk through Ray’s various AI libraries (Part 2). How-to guide: Evaluate TPUs for sample workloads using a new microbenchmark suite that helps you accurately assess whether a device is achieving its theoretical performance specifications, and to identify specific performance gaps or architecture-specific bottlenecks. Dive in here. How-to guide: Scale your agents without killing your budget. Learn how GKE orchestration can help you safely pack more agents onto a fixed compute footprint with GKE Agent Sandbox and Pod snapshots. Whether your goal is performance or cost optimization, we teach you how to turn the right dials for optimal agent efficiency. Technical blueprint: Inside the optimization of Mistral 3 large inference on Ironwood. This blog outlines how one Google team optimized Mistral 3 large MoE model inference on Google’s Ironwood (TPU v7x), achieving a 1.5x performance gain. They did so with hybrid sharding, replacing linear VPU summations with tree reductions, optimizing GMM/MLA kernels, and adopting asynchronous scheduling. As a result, they boosted throughput by up to 48% while maintaining benchmark accuracy neutrality. Read the full blog here. Research, reports and deep-dives Report: Google was named a Leader in the inaugural GartnerⓇ Magic Quadrant™ for AI Infrastructure, positioned highest for ‘Ability to Execute’ and furthest for ‘Completeness of Vision’. Gartner called out Google’s proprietary scalable compute, integrated AI Hypercomputer architecture, and the scale of our AI compute capacity as key strengths. Download a copy here. Report: We recently surveyed more than 1,400 senior IT leaders for our State of AI Infrastructure report, and a resounding pattern emerged: The gap between AI ambition and infrastructure reality is widening. In fact, 83% of organizations say they require infrastructure upgrades to support production-grade agentic AI. Read the accompanying blog to understand how adapting your infrastructure to meet the demands that agentic applications place on your systems will help you move from pilot to production. June 2026 Product, technology and tool updates Product update: Protecting sensitive data used with AI is a critical part of advanced and secure cloud infrastructure. Confidential Computing cryptographically protects data in use in hardware-based Trusted Execution Environments (TEEs) with verifiable data integrity, and is now available on the accelerator-optimized G4 machine series, featuring NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs. Get started with Confidential G4 VMs and Confidential G4 GKE Nodes. Developer resource: The new TPU Developer Hub is the place to go for model builders, optimizers, and developers to learn to unlock the full performance of Google Cloud TPUs. Read more in this blog. New product: Scale your AI workloads with the new OpenTelemetry-Based TPU AI Telemetry Collector Agent. For the first time, you can route high-fidelity TPU hardware telemetry to Google Cloud Monitoring, Google Managed Prometheus, or your own self-hosted Grafana stack. Practitioner guides and how-tos How-to guide: Learn how to build high availability into an AI inference workload running on GKE Inference Gateway with TPUs, Cloud Storage FUSE and Dynamic Resource Allocation (DRA). This blog provides an overview, or you can get all the technical details in the hands-on codelab. How-to guide: Did you know you can connect your AI agents to unstructured data in Cloud Storage via Model Context Protocol (MCP)? In this blog, learn about why would want to do that from three customer examples, then how to do it, choosing either a fully managed service, or a self-managed local server for more customization and control. Research, reports and deep-dives Report: According to an independent benchmark report, GKE Inference Gateway outperforms the next leading managed Kubernetes service with 15.7% higher throughput, 92.8% shorter wait times, and 62.6% lower inter-token latency. This performance can be attributed to its use of prefix caching, which optimizes LLM performance by storing the KV cache (activation states) of long, repetitive prompt prefixes. Learn more in the blog. Architecture deep dive: A closer look at the cold start problem, this time for TPUs and GKE, and how the Run:ai Model Streamer can help change the dynamic. Customer and partner updates Customer win: Leveraging GKE, BigQuery, Cloud SQL, and Gemini Enterprise Agent Platform, Pager Health is eliminating operational fragmentation to deliver a simplified, personalized U.S. healthcare experience that transforms lives. Customer win: Trustpilot, the customer review platform, built a high-volume streaming pipeline using fine-tuned Gemma models with Dataflow and Gemini Enterprise Agent Platform running on cost-optimized A2 VMs using A100 GPUs, as well as optimized version of vLLM maintained by Gemini Enterprise Agent Platform. May 2026 Product, technology and tool updates Product update: GKE Agent Sandbox is now generally available. New open-source project: Agent Substrate is a new open-source project aimed at continuing to push the limits of agentic infrastructure density New feature: Google AI Edge Portal, a solution for testing and benchmarking on-device machine learning (ML) at scale, now supports benchmarking and debugging on-device LLMs. Read more here. Product deep dive: We went into depth about Cloud Storage Rapid, a new family of high-performance storage offerings for AI workloads. At launch, offerings include Rapid Bucket (formerly Rapid Storage), a high-performance zonal object storage offering, and Rapid Cache (formerly Anywhere Cache), which accelerates reads on-demand and colocates compute and data for workloads in existing buckets. Research, reports and deep dives Architecture deep dive: Google Global Infrastructure VP Bikash Koley and Engineering Fellow Arjun Singh provide a high-level overview of the challenges that AI workloads pose to network infrastructure, and discuss the deep enhancements we’ve made to our data center fabrics, WAN, and global networks to better support them. Architecture deep dive: We unveiled a new cluster-level reliability model for developing frontier AI models on TPUs, ditching instance-level reliability Customer and partner updates Customer win: Visual media provider Imgix serves more than 8 billion images and videos from AI Hypercomputer equipped with G4 VMs powered by NVIDIA RTX PRO 6000 Blackwell GPUs.
Read original articleSeptember 30, 2026
Welcome to the second Cloud CISO Perspectives for September 2026. Today, Alicja Cade and Nick Godfrey, senior directors, Office of the CISO, share their guidance for cybersecurity startups on how to win over the CISOs who will become crucial business partners and customers.As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here. aside_block <ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f96c0316a50>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]> How cybersecurity startups can win CISOsBy Alicja Cade, Senior Director, Financial Services, Office of the CISO, and Nick Godfrey, Senior Director, Office of the CISO Alicja Cade, Senior Director, Financial Services, Office of the CISO Cybersecurity startups play a crucial role in technology as they build to solve both legacy, existential challenges and the latest problems on the cutting edge. A key part of winning and transforming the cybersecurity field is becoming a strategic partner to CISOs and their security teams.Google has supported more than 50 cybersecurity founders over the past four years through our Google for Startups program, including Authologic, BforeAI, Build38, Cerby, Crowdsec, Risk Ledger, and Mokn.Christian Torres, co-founder and CEO, Kriptos, and a Google for Startups participant, said that building connections between startups and CISOs is crucial to solving critical security challenges. Nick Godfrey, Senior Director, Office of the CISO "The Google for Startups program has been the most impactful initiative we've joined as a cybersecurity company. Unlike other accelerator programs, this one speaks our language — the challenges, the ecosystem, and the conversations are 100% aligned with what we do every day at Kriptos. The access to CISOs and security leaders has been invaluable, and the connections we've built through the program are ones we now see regularly across industry events. It's put us exactly where we need to be,” he said.Cybersecurity startup founders face many competing taskmasters as they fight for survival, from demanding capital funders to the relentless pressure of growing their market and networks. CISOs should be key stakeholders for cybersecurity startups so that founders focus on solving thorny challenges in a way that works in the real world. Listening to CISOs and understanding the businesses that they serve takes time and effort, and if done right can help deliver better value and create a lasting enterprise foundation and network of allies. Here are three top tips from September’s Gemini Startup Forum for Cybersecurity, part of the Google for Startups program, where we offered vital guidance, addressed critical domains, and helped foster deep dialogue for the next generation of AI-native cybersecurity startups. Tip 1: Listen then design and deliver for your customers Avoid becoming a round peg in a square hole by combining your problem-solving startup with listening to CISOs who have to protect real systems, networks, and people. Listening to CISOs and understanding the businesses that they serve takes time and effort, and if done right can help deliver better value and create a lasting enterprise foundation and network of allies. Here’s how to develop trusted CISO relationships: Host diagnostics meetings. Your meetings with CISOs should focus on mapping their operational bottlenecks and co-authoring collaborative solutions while studying their pain points. Create "unselling" spaces to build peer trust. Host intimate, pitch-free roundtable discussions on industry challenges or establish a critique-only advisory board to build genuine relationships with CISOs without the pressure of a sales environment. Use neutral networks that don’t include venture capitalists. Engage with CISOs in low-friction environments by contributing to open-source security projects and participating in academic and geopolitical risk forums where security leaders gather to solve broad industry problems. Avoid the bait-and-switch pitch. Never disguise a sales pitch as a research or feedback session, as tricking a CISO into a product demo will permanently destroy their trust. Center their business context. Don’t limit your listening to the technical security stack, because the CISO’s primary job is to enable and protect the broader business strategy. Tip 2: Evaluate AI security to filter out noise Instead of just using AI to assemble the product, startups should critically evaluate what makes your approach unique and how you communicate that to potential customers. Define your moat by investing in proprietary datasets, specialized fine-tuning, and unique orchestration layers that create a true technical moat. Don’t be a wrapper. Secure the intelligence by proactively designing your models to resist adversarial attacks, prompt injection, and data poisoning. In cybersecurity, model robustness is your ultimate trust signal. Deliver high-fidelity outcomes by clearly communicating how your AI product reduces cognitive load for defenders, minimizes false positives, and integrates safely into existing operations. Avoid using generic marketing buzzwords like "cognitive," "autonomous," or "revolutionary" without the technical documentation, case studies, and whitepapers to back them up. In a skeptical market, transparency is your best sales tool. Tip 3: Enthusiastically embrace your sector Keep a sharp eye out for common due diligence pitfalls during investment and merger and acquisition cycles. These include ensuring that internal engineering and cybersecurity practices meet external claims, but also evaluating the regulatory context of your business sector as well as the security and reliability of your product and service. You have to know whether you’re required to abide by data sovereignty, data residency, and other requirements. To avoid this pitfall, engage with broader stakeholders early who know the sector and its nuances well. How to keep the conversation going Even beyond the crowded field of aspiring cybersecurity companies, startups broadly can benefit immensely by making sure that they listen carefully, evaluate objectively, and take to their sector requirements enthusiastically. "Google's Office of the CISO has been a bridge between LetsData and the security leaders we need to reach. Sometimes that bridge is advice on how our offering maps to a CISO's real priorities. Sometimes it is a direct introduction to a CISO who is looking for exactly what we build. For a startup, a warm introduction at that level is priceless,” said Ksenia Iliuk, founder and COO, LetsData. To learn more about how Google Cloud’s Office of the CISO can help support your organization, check out our CISO Insights hub. aside_block <ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7f96c0a41510>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=Wpo-5ke9uvQ'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]> In case you missed itHere are the latest updates, products, services, and resources from our security teams so far this month:Agentic hacks, real proofs: Inside Google's PageBreak project: Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge, often increasing the burden on product teams. PageBreak is an internal AI agent of Google's Product Security team developed to test the security of our first-party web applications and address this challenge. Read more.Investing together: Wiz Defend and Google Security Operations: Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate. Read more.A unified view of Android security updates for enterprises and OEMs: We're introducing new libraries that give enterprise partners and OEMs a complete, real-time picture of a device’s security posture. Read more.Delivering new partner security agents and AI defenses with Gemini Enterprise: We're expanding our catalog of partner-built security offerings in the Gemini Enterprise ecosystem to help you leverage your full security context. Read more.Google named a Leader in the External Threat Intelligence Service Forrester Wave: We are proud to announce that Forrester has named Google a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. Read more.Wiz named a Leader in the Proactive Security Platforms Forrester Wave: Forrester’s Proactive Security Platforms evaluation for Q3 2026 rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era. Read more.Strengthen your CI/CD pipeline with new Secure Source Manager capabilities: To help you better address software supply chain threats, our Secure Source Manager lets you manage your source and CI/CD systems with unified authentication and authorization mechanisms. Read more.Building an AI detection engine that understands agent intent: Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior. Read more.Using AI to discover and fix high-priority exposures across public services and critical infrastructure: New initiative partners with under-resourced organizations to uncover, remediate exploitable risk at scale. Read more.Please visit the Google Cloud blog for more security stories published this month. aside_block <ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f96c0166910>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]> Threat Intelligence newsShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft: Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. Read more.Proactively defend by hardening code pipelines and CI/CD infrastructure: Check out our actionable blueprint for software and platform architects designed to safeguard the software supply chain against threat vectors that are actively being exploited, third-party risks, and architectural vulnerabilities throughout the entire software development lifecycle. Read more.Infostealer incursion: How stolen credentials breach cloud, code, and AI environments: Wiz Research analyzes NordStellar data to map the credentials targeted by infostealer families and assess their potential impact across cloud, code, and AI environments. Read more.Please visit the Google Cloud blog for more threat intelligence stories published this month. Now hear this: Podcasts from Google CloudCloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Nir Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.
Read original articleSeptember 30, 2026
Today, we’re expanding our ecosystem of managed remote MCP servers by introducing the Google Cloud CLI remote MCP server in preview. Powered by the popular gcloud and bq (BigQuery) command-line tools, this new server gives AI agents immediate, broad access to command-line operations for managing Google Cloud infrastructure and working with advanced BigQuery workflows securely and seamlessly. Why CLI matters for AI agents Agents are increasingly performing complex cloud operations, but standardizing how they interact with backend systems remains a challenge. The Google Cloud CLI remote MCP server bridges this gap by packaging the versatility of hundreds of gcloud and bq commands into one single MCP server. This results in two strong benefits for the agent: Higher-level abstractions: CLI commands package complex multi-step workflows, validation checks, and high-level operations into unified commands rather than requiring multi-step API orchestration. Leverages model training: LLMs are heavily pre-trained on public command-line documentation, syntaxes, and usage examples, making CLI invocation intuitive and highly accurate for models. The benefits of putting CLI behind remote MCP Managing cloud infrastructure with AI agents traditionally requires installing and maintaining Google Cloud CLI binaries inside agent execution environments. The Cloud CLI remote MCP server bridges CLI capabilities with MCP benefits by providing an isolated execution sandbox on Google Cloud infrastructure. This solves key infrastructure challenges: Simplified dependency and runtime management: For teams building custom agents, maintaining local CLI versions and dependencies across dev, test, and production environments creates operational overhead. Remote MCP eliminates local installations and runtime maintenance. Access for web-based agent endpoints: Web-hosted agent platforms and web interfaces (such as Gemini Enterprise and other hosted enterprise agent platforms) run in environments where users cannot control or install local packages. Remote MCP enables secure, managed access to Google Cloud CLI operations directly from these surfaces. Enterprise-grade security and governance Connecting an AI agent to your infrastructure requires strict, enterprise-ready safeguards. This remote server leverages Google Cloud's standard identity and governance frameworks to keep your environments secure: Zero ambient credentials: The server isolates execution in a network-restricted proxy boundary with no ambient credentials. Authentication and authorization are handled through Agent Identity, OAuth 2.0, and Identity and Access Management (IAM). Strict policy enforcement: Every command executed through the remote MCP server is run with the permissions of the authenticated caller identity. Both standard IAM permissions and organization policy service constraints are strictly enforced against downstream target resources. Advanced protection with Model Armor: To minimize the risks associated with AI tool calling, the Cloud CLI remote MCP server integrates with Model Armor. You can proactively screen LLM prompts and responses to protect against risks like prompt injection and malicious inputs. Cloud audit logging: The Cloud CLI remote MCP server can be configured to log every tool invocation to Audit Logs (Data Access logs under cloudcli.googleapis.com/mcp). Security teams can gain full visibility into caller identities, OAuth clients, and IAM authorization decisions (mcp.googleapis.com/tools.call) without exposing sensitive command payloads or personally identifiable information (PII). Connecting to the Google Cloud CLI Remote MCP Server Integrating cloud management into your agents no longer requires packaging Google Cloud CLI binaries, managing local execution runtimes, or maintaining dependencies inside agent container images. Because the Google Cloud CLI remote MCP server implements the standard Model Context Protocol, any MCP-compatible agent platform or orchestration runtime can connect immediately via standard configuration: code_block <ListValue: [StructValue([('code', '{\r\n "mcpServers": {\r\n "google-cloud-cli": {\r\n "uri": "https://cloudcli.googleapis.com/mcp",\r\n ...\r\n }\r\n }\r\n}'), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7f96c014c950>)])]> Your agent immediately gains access to execute gcloud and bq commands in a secure, network-isolated cloud sandbox. Authentication is handled via keyless Agent Identity for hosted Google Cloud platforms, or standard OAuth 2.0 for external runtimes. For authentication options, see the MCP Authentication Guide. Bringing infrastructure management to agents The Cloud CLI remote MCP server exposes two powerful tools, run_gcloud_command and run_bq_command, giving your AI agents broad, immediate access to Google Cloud operations through natural language. Managing cloud infrastructure with run_gcloud_command With run_gcloud_command, agents can execute the full breadth of gcloud operations to manage, diagnose, and secure your Google Cloud environment. An example follows: Observability and incident diagnostics: An agent streamlines incident diagnostics by automating command execution and reducing context-switching across tools. Extending BigQuery operations with the run_bq_command tool While the BigQuery MCP server already helps organizations analyze and explore data using AI agents, with the introduction of run_bq_command, agents can now tackle advanced BigQuery tasks such as resource allocation, job monitoring, and task scheduling by unlocking the full scope of bq CLI functionality. Key capabilities include: Automating scheduled queries: An agent utilizes BigQuery Data Transfer Service configurations to schedule queries automatically. Job and resource management: Gain deep insight into query execution details, including processed data volume, slot usage, and execution plans, as well as managing reservations. Access and permissions control: Data administrators and owners can inspect and update table permissions directly through the agent. Pricing and availability The Google Cloud CLI MCP server is available today in public preview. There is no additional charge to use the MCP server itself. You pay only for the GCP resources you create and any applicable data transfer costs. To get started, enable the Cloud CLI Execution API (`cloudcli.googleapis.com`) in your Google Cloud project, grant the required MCP Tool User (`roles/mcp.toolUser`) IAM role to your agent or user identity, and configure your MCP client to connect to `cloudcli.googleapis.com/mcp`. Use the Google Cloud CLI Remote MCP Server Guide Google Cloud CLI MCP Reference Google Cloud Remote MCP Servers Overview Full List of Google OneMCP Servers Set up authentication to Google and Google Cloud MCP servers Gemini Enterprise Agent Platform & Agent Identity Overview Automate Google Cloud with Cloud CLI Remote MCP Server
Read original articleSeptember 30, 2026
Spanner Omni, the deploy-anywhere version of Spanner, is now generally available, ready to power your most demanding production workloads in your on-premises data center or on other clouds. With Spanner, Google pioneered the distributed SQL market over a decade ago, combining the horizontal scalability of NoSQL with the ACID compliance and strong consistency of a traditional relational database. Since then, Spanner has evolved into an interoperable multi-model database that simplifies complex workloads and powers agentic AI, combining SQL, graph, key-value, full-text search, vector search, and analytical processing with a columnar engine, all in a single database. When we debuted Spanner Omni at Google Cloud Next ’26, we untethered our distributed database from Google Cloud and brought it directly to your infrastructure. This generated incredible interest from both the enterprise customers and developer community. In fact, since its launch, Spanner Omni has over 2 million downloads. Spanner Omni delivers the same core capabilities as the fully managed Spanner service, with the added freedom to deploy it wherever you need it. Whether you’re running virtual machines or Kubernetes in your private data centers, running a multi-cloud deployment that spans multiple clouds, or testing locally on a laptop, Spanner Omni brings Google-grade consistency, availability, scale, and interoperable multi-model capabilities directly to your next agentic AI applications. Spanner Omni provides the freedom to deploy anywhere with the same core Spanner capabilities Attio accelerates agentic application velocity with Spanner Omni Spanner Omni enables teams to build once and deploy anywhere, providing application portability across Google Cloud, on-premises and other clouds. Attio, an AI-native CRM company based in London, has built its platform on Spanner. Attio migrated its agentic application environment to a full-featured and containerized Spanner Omni + managed Spanner. "At Attio, we are building the world's most advanced agentic application environment on Spanner to deliver on our vision for an AI-native CRM platform. Spanner Omni has been a major win for us by delivering Spanner capabilities and performance across all our environments, allowing our agents to bring complex, mission-critical workflows such as the newly announced Spanner queues, to production. With Spanner Omni, we have been able to accelerate our production velocity at a truly enhanced level of scale and confidence that was not possible earlier." - Alexander Christie, Co-Founder & CTO, Attio Built-in AI capabilities for any environment Spanner Omni extends Spanner's converged multi-model foundation directly to your private infrastructure and third-party clouds, providing critical capabilities for AI workloads: Vector search and Spanner Graph: Natively store and index vector embeddings alongside your relational tables. With support for KNN and ANN search, you can combine semantic similarity with structured SQL filters. Spanner Graph integrates property graphs directly into the engine, allowing you to trace complex entity relationships and connect graph traversals with vector search. Model Context Protocol (MCP) support: Integrate directly with agentic systems using MCP Toolbox. This open standard allows autonomous agents to inspect schemas, retrieve relevant context, and use Spanner Omni as an operational memory layer across multi-cloud deployments. What’s new with Spanner Omni Since the preview, we’ve been working to expand Spanner Omni’s capabilities, and refine the pricing model for production-ready deployments. Enterprise features for production deployments The GA release unblocks the full suite of enterprise-grade capabilities required for mission-critical production workloads, including: Robust security and governance: Support for advanced enterprise security, including TLS encryption, authentication and authorization, and audit logging Data protection: High-performance backup and restore capabilities to safeguard your data against “fat-finger” deletion or data corruption Worker nodes: Dedicated, stateless compute nodes unique to Spanner Omni that are designed to offload background and resource-intensive operations from primary Spanner Omni servers, so they can focus on handling core database workloads Enterprise-grade support: Direct access to Google Cloud Customer Care to keep your critical workloads running smoothly Flexible licensing and industry-standard pricing To support you at every stage of development, Spanner Omni offers two distinct licensing tiers designed to fit your scale and budget: Developer Edition (free): Tailored for development, testing, and prototyping in non-commercial, non-production environments, it includes all core Spanner features, allowing you to build and validate your applications before scaling to production. The Developer Edition has a default license. The default license lasts for 90-days and includes all features as the commercial edition, except backup features and worker nodes. When used in a single server deployment of 4 vCPUs or less, the default license does not expire and backup-restore is also supported. In case of more than 4vCPUs the default license can be extended beyond 90 days by filling out this form. Commercial Edition (paid): Designed for commercial, production workloads, this edition provides the full suite of Spanner Omni capabilities backed by enterprise support. It follows a highly industry-standard, predictable vCPU-based annual subscription model. We also offer a proof-of-concept license for pre-production evaluation at a discounted price. Spanner Omni vs. fully managed Spanner on Google Cloud Our goal with Spanner Omni is to provide parity with the fully managed Spanner service on Google Cloud. However, as self-managed software, deploying and operating Spanner Omni differs from fully managed Spanner on Google Cloud in several ways: Self-managed operations: You are responsible for all day-to-day operations, including routine maintenance, version upgrades, and infrastructure monitoring. Availability and SLAs: Because Spanner Omni runs on customer-managed infrastructure, Google does not provide availability SLAs. However, deploying according to our recommended reference architectures will help you achieve comparable high availability. Integration with Google Cloud: To ensure it can run anywhere, Spanner Omni excludes capabilities available in managed Spanner that rely on Google Cloud-specific capabilities, such as native integrations with BigQuery, Knowledge Catalog, or Gemini Enterprise and other Google Cloud services. Feature-parity roadmap: While some feature gaps exist today between Spanner Omni and fully managed Spanner, we are actively developing updates to close these gaps in future releases. Get started today Whether you’re modernizing on-prem legacy systems or building a resilient multi-cloud architecture, Spanner Omni is ready to help you scale. For more information, visit the Spanner Omni website to explore documentation and use cases. To use the Spanner Omni commercial edition with full features, please contact your Google Cloud account team or reach out to us at https://cloud.google.com/consulting/spanner-omni. For developing and testing for non-commercial, non-production purposes, download the Spanner Omni developer edition.
Read original articleSeptember 30, 2026
An agent can finish a task and still take an inefficient path. A failed search can trigger another search. A truncated file read can lead to a command fetching...
Read original articleSeptember 30, 2026
Intended to help with biosecurity, it works with a popular AI protein design tool.
Read original articleSeptember 30, 2026
OpenAI’s new Dots are built to keep working after you step away. Launched at DevDay on Tuesday, the always-on agents The post OpenAI’s Dots boundary problem rate doubled in longer tests appeared first on The New Stack.
Read original articleSeptember 30, 2026
FTC Probing OpenAI and Anthropic Over Product Safety Concerns Bloomberg.com
Read original articleSeptember 30, 2026
Microsoft is turning Fabric, its integrated data platform, into the place enterprise agents go to learn how a company works, whether The post Microsoft Fabric is where AI agents learn how the business works appeared first on The New Stack.
Read original articleSeptember 30, 2026
Deepseek and Huawei have built open-source programming tools for Huawei's Ascend AI chips. At the center is TileLang, a language designed to offer a simpler programming model than Nvidia's CUDA. The partnership targets the biggest obstacle for China's AI industry, which is software that gets the most out of domestic chips. The article China's AI industry closes ranks as Deepseek ships open-source software for Huawei's Ascend chips appeared first on The Decoder.
Read original articleSeptember 30, 2026
OpenAI is seeking another $30 billion privately as its IPO plans slip.
Read original articleSeptember 30, 2026
Anthropic’s soaring valuation means that its prospectus shows blow out losses, thanks to how the tech giants’ investments in the AI firm were structured.
Read original articleSeptember 30, 2026
Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability disclosures doubled: the number of vulnerabilities disclosed per month doubled, rising from 5,045 in January 2026 to 10,477 in July and continuing to climb to 10,740 in August 2026. Vulnerability exploitation nearly doubled: the number of vulnerabilities exploited increased from an average of 10.5 per month in 2025 to an average of 18 per month from January 2026 to August 2026. Zero-day exploitation increased marginally: zero-day vulnerability exploitation grew from an average of 8 per month in 2025 to an average of 11 per month from January 2026 to August 2026. AI finds more consequential vulnerabilities: AI-assisted discovery found proportionally fewer Low-Risk vulnerabilities, more Moderate-Risk vulnerabilities, and more vulnerabilities leading to remote code execution (RCE). GTIG expects that vulnerability discovery and exploitation will continue to grow in the short to medium term. To counter the increased risk from rapid vulnerability discovery and exploitation, organizations must transition from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge-defense with automated, agentic remediation. Scope & Methodology This GTIG analysis examines trends in vulnerabilities disclosed from January 1, 2025 through August 31, 2026. The dataset tracks the vulnerabilities alongside critical operational dimensions, including exploitation consequences and GTIG Vulnerability Risk Ratings, and in-the-wild exploitation. When we refer to risk ratings in this blog, we are using GTIG vulnerability risk ratings, not CVSS severity. While the baseline monitoring encompasses the full 20-month window (January 2025–August 2026), this report specifically focuses on growth velocity and emerging threat vectors. The research seeks to evaluate the impact of AI across the cybersecurity landscape both in terms of rates of Common Vulnerabilities and Exposures (CVE) disclosure and rates of exploitation. We also examine vulnerabilities targeting the AI/large language model (LLM) operational stack. CVE Disclosure Doubled in 2026 Vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July, with the count of disclosed vulnerabilities reaching a peak of 10,740 in August (Figure 1). Distinguishing Threat Risk from CVE Inflation However, raw disclosure volume throughout 2026 can be misleading without threat intelligence context. Automated CVE Numbering Authority (CNA) assignment policies across open-source ecosystems can inflate baseline figures; for instance, vulnerabilities with a description containing “Linux Kernel” alone generated approximately 5,000 CVEs between January 2026 and August 2026 with zero observed exploited in-the-wild zero-days. Figure 1: Count of vulnerabilities disclosed, January 2025 - August 2026 (Source: GTIG) In terms of risk ratings, the most interesting increase occurred in High-Risk vulnerabilities, which surged from 131 disclosures in January 2026 to 350 in August 2026, a 167% growth (Figure 2). High-Risk vulnerabilities remain a small proportion (3% in August 2026) of all vulnerabilities disclosed. Figure 2: Count of vulnerabilities disclosed by GTIG vulnerability risk rating, January 2025 - August 2026 (Source: GTIG) The increase in High-Risk vulnerabilities throughout 2026 was driven by two compounding dynamics: a widening pool of affected vendors and concentrated vendor disclosure cycles. Across the broader software ecosystem, baseline High-Risk disclosures more than doubled over the past year, rising from ~65/month in mid-2025 to ~135/month in mid-2026 (Figure 3). On top of this elevated baseline, Figure 3 highlights two time frames in which particular vendors reported exceptionally high quantities of CVEs, pushing monthly volumes to historic peaks: TOTOLINK: In April and May, mass research disclosures against consumer router firmware added 75 High-Risk flaws, driving the mid-year spike in Command Execution vulnerabilities. Oracle & Linux: In June, July, and August Oracle’s quarterly Critical Patch Update (CPU) across middleware like WebLogic and Coherence combined with Linux kernel network driver advisories to contribute 128 High-Risk vulnerabilities in August alone (nearly 37% of all High-Risk disclosures), directly fueling growth in Remote Code Execution vulnerabilities. Figure 3: Count of vulnerabilities High Risk disclosed by Vendor, January 2025 to August 2026 (Source: GTIG) In-the-Wild Exploitation From January 2026 to August 2026, GTIG recorded 141 distinct vulnerabilities disclosed and exploited, surpassing the total number of vulnerabilities exploited for the full year of 2025 (127). In-the-wild exploitation increased from an average of 10.5 per month in 2025 to 18 per month in 2026. However, it is important to note that the proportion of vulnerabilities exploited versus disclosed remains vanishingly small: only 0.23% of all disclosed vulnerabilities in 2026 (roughly 1 in 431) were ever observed in active exploitation, or on the order of tens versus thousands per month. This means that monthly exploitation counts can more easily be influenced by other factors such as vendor disclosure cycles and threat actor campaign spikes. Since May 2026, a shift has emerged, with the expansion of CVE exploitation (+127% indexed growth) closely mirroring disclosure growth (+128% indexed growth), scaling in tandem with the overall vulnerability landscape rather than outpacing it. Figure 4: Count of all vulnerabilities exploited, by n-days and zero-days, January 2025 to August 2026 (Source: GTIG) Zero-Day Exploitation Remains Stable The count of zero-days exploited increased marginally from an average of 8 per month in 2025 to an average of 11 per month in 2026. While the number of zero-days identified per month remained near baseline levels (between 8 and 12) through mid-2026, in August, the count jumped to 22 (Figure 4). Zero-day exploitation also continues to represent a very small proportion of all vulnerabilities disclosed, though it still constitutes the majority (62%) of all observed exploited vulnerabilities from January 2026 to August 2026. Are Threat Actors Finding More Success with Exploiting N-Days? It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days. CVE Exploitation Trends Toward Higher Risk Vulnerabilities With zero-day exploitation rates increasing only marginally, we suggest that the primary source of growth in vulnerability exploitation from January 2026 to August 2026 has been concentrated in the rapid weaponization of n-days. Significantly, exploitation of High-Risk vulnerabilities more than doubled from 28 in 2025 to 75 from January 2026 to August 2026. Figure 5: Count of vulnerabilities exploited in the wild by GTIG vulnerability risk rating, January 2025 - August 2026 (Source: GTIG) Exploitation by Attack Surface Vulnerabilities affecting Edge and Security Appliances represented 14% of vulnerabilities exploited from January 2026 to August 2026, while 11% affected Enterprise Directory & Collaboration hubs. Edge gateways represent a premier initial-access vector: over 65% of edge flaws exploited from January 2026 to August 2026 met High/Critical Threat Risk ratings, with adversaries aggressively targeting unauthenticated public management interfaces to capitalize on enterprise EDR agent blind spots. While CVE discovery volume metrics surge, adversary exploitation activity remains concentrated in perimeter appliances and exposed enterprise services. Comparing Growth Rates For Specified Categories Plotting raw monthly counts hides relative momentum due to the vast disparity between single-digit zero-day discoveries and more than 10,000 vulnerabilities disclosed in the month of August, for example. To enable a direct comparison of growth rates across vulnerability tiers, Figure 7 indexes four metrics to a baseline of 0 in January 2025 and provides a trendline of the three month rolling average growth rate: Overall CVE Disclosure (128%): As previously stated, raw counts of CVE disclosures doubled from January 2026 to August 2026. The three month rolling average growth rate suggests that CVE disclosures have steadily accelerated in 2026. High-Risk Vulnerabilities Disclosed (241%): Demonstrated the steepest growth across the dataset, climbing to almost a 3.5x its initial baseline (a +241% increase) by August 2026. Excluding Linux, Oracle, and Totolink, the rate of increase was just 128% from January 2025 to August 2026. CVE Exploitation in the Wild (127%): From January to August 2026, CVE exploitation has increased at approximately the same rate as overall CVE disclosure, though the three month rolling average trendline suggests that growth in exploitation did not begin to pick up until the second quarter of 2026. Zero-Days Exploited (59%): While remaining near baseline levels (between 8 and 12 zero-days per month) through mid-2026, in August, the count reached 22. This increase is reflected in the three month rolling average growth rate, which began to reveal an upward trend in the summer of 2026. This clear visual divergence underscores that the moderate increase in vulnerability exploitation in 2026 is driven by the rapid, targeted weaponization of high-risk exploits in the wild vulnerabilities rather than a flood of new zero-days. Figure 6: 3 Month Rolling Average of % Growth, Indexed to 0% at January 2025 (Source: GTIG) AI as the Hunter: AI-Assisted Vulnerability Discovery Detection Methodology & Attribution Realities Current public data significantly undercount vulnerabilities discovered by AI due to two structural dynamics: Absence of Standardized Metadata: Public CVE repositories do not yet feature uniform metadata tags for AI attribution, requiring manual heuristic tracking. Silent First-Party & Cloud Patching: Major cloud and SaaS providers routinely remediate AI-surfaced vulnerabilities directly in production without requesting formal CVE IDs, as CVE assignments are typically reserved for on-premise or third-party software requiring customer patching coordination. Many findings also remain embargoed for a period during established Coordinated Vulnerability Disclosure (CVD) windows. However, we can identify vulnerabilities likely surfaced by autonomous agents using a multi-tier verification process: Verified Lab & Vendor Ledgers: Directly ingesting confirmed disclosures from frontier AI research programs. Advisory & Release Parsing: Programmatically monitoring Cybersecurity and Infrastructure Security Agency (CISA) advisories, MITRE records, and vendor security bulletins for explicit acknowledgments attributing root-cause discovery or PoC synthesis to autonomous AI agents (e.g., Hacktron AI, AISLE). Risk Profile Divergence: AI vs. Conventional Discovery Analyzing disclosed vulnerabilities we were able to identify as likely AI discovered suggests a structural divergence from conventional human and scanner discoveries. AI agents have been used to surface proportionally fewer Low-Risk vulnerabilities, and proportionally more Medium- and High-Risk vulnerabilities. GTIG CVE Risk Rating CVE Not Discovered by AI CVE DIscovered by AI Low 69% 39% Medium 28% 58% High 3% 4% Table 1: Share of vulnerabilities per risk rating - AI vs. Non AI discovery - Jan to August 2026 (Source: GTIG) Conventional CVE disclosures are dominated by low-severity findings (69% Low Threat Risk, 28% Medium). In contrast, AI-discovered vulnerabilities invert this distribution: 58% qualify for Medium Threat Risk (more than double the baseline), while low-risk findings drop to 39%. This distribution largely likely reflects how research programs scope and deploy these systems. Rather than running broad, automated scans for cosmetic flaws or compliance warnings, researchers deliberately prompt and task autonomous agents with auditing critical infrastructure and sensitive privilege boundaries, focusing on high-impact findings. Mandiant has described similar findings when using a specialized Agentic Vulnerability Discovery Harness (AVDH) in point-in-time assessments of client codebases. Figure 7: Share of vulnerabilities per exploitation consequence - AI vs. Non AI discovery (Source: GTIG) Divergence between AI-discovered vulnerabilities and vulnerabilities not discovered by AI is also apparent in terms of exploitation consequences. Exactly 50% of all AI-discovered vulnerabilities result in Remote Code Execution (RCE), compared to just 26% across the broader CVE ecosystem. Conversely, AI agents under-index in lower-impact categories, surfacing less than half the rate of Information Disclosure (8% vs. 18%) and Data Manipulation (5% vs. 9%) as vulnerabilities not identified as discovered by AI. This concentration on code execution likely stems from how frontier agents operate. Autonomous systems are engineered to navigate complex, multi-step semantic code paths across core C/C++ libraries, runtimes, and hypervisors. By synthesizing fuzzing harnesses, modeling memory states, and chaining obscure edge-case logic, AI models excel at identifying memory corruption (buffer overflows, use-after-free) and logic bypasses that consistently elude traditional static analyzers. While currently an early indicator rather than an established trend, confirmed exploitation of AI-discovered vulnerabilities demonstrates that increased risk from AI-discovered flaws is not purely theoretical. A notable case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support that was discovered autonomously by a third-party research agent (Hacktron AI). Following public disclosure, GTIG observed threat actors weaponize this vulnerability in targeted initial-access campaigns to bypass enterprise perimeters. More specifically, within four days of public disclosure, GTIG observed a threat cluster exploiting this vulnerability, followed by five additional threat clusters within seven days of public disclosure. GTIG observed these threat actors collectively conduct a variety of post-exploitation activities, including privilege escalation, data exfiltration, and dropping secondary payloads including SNOWLIGHT, SPARKRAT, and cryptominers. This operational collision highlights that defensive AI agents are uncovering high-impact vulnerabilities that threat actors actively seek to exploit. AI as the Hunted: Vulnerabilities Targeting the AI/LLM Operational Stack Architectural Breakdown of AI Stack Vulnerabilities As enterprise adoption of generative AI accelerates, security research and adversary interest have also focused on vulnerabilities in the underlying AI operational stack. Across the January 2025–August 2026 monitoring window, GTIG tracked 2,076 cumulative AI-related CVE disclosures, with over 1,500 vulnerabilities identified from January 2026 to August 2026 alone across eight core architectural layers: Layer / Architectural Category Key Technologies & Frameworks Primary Vulnerability Vectors 2026 AI Orchestration & Agent Frameworks Flowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, Semantic Kernel, Letta, MCP, Pydantic-AI Arbitrary Code Execution (RCE) & Command Injection via untrusted workflow serialization, insecure Python tool calling, and Server-Side Template Injection (SSTI). 782 AI Web Apps & Portals Open-WebUI, AnythingLLM, FastGPT, LibreChat, RAGFlow, Gradio, Streamlit, LobeChat, Chainlit, GPT4All Server-Side Request Forgery (SSRF) via chat proxying, Stored XSS in markdown rendering, and local file inclusion (LFI) via document upload handlers. 230 Inference & Serving Infrastructure vLLM, Ollama, LiteLLM, Llama.cpp, Triton (NVIDIA), Ray, TGI, SGLang, TensorRT-LLM, BentoML, LocalAI Unauthenticated Administrative APIs, model checkpoint deserialization, memory corruption in tensor backends, and multi-tenant resource exhaustion. 212 Model Security Advisories Foundation Model Weights, System Prompts, Guardrails, Evaluators (Garak, Lakera, Promptfoo) Direct & Indirect Prompt Injection, system prompt exfiltration, guardrail bypasses, training data poisoning, and excessive agent autonomy. 106 ML Frameworks & Hubs PyTorch, Hugging Face (Hub/Datasets), Transformers, ONNX Runtime, TensorFlow, Diffusers, DeepSpeed, Safetensors, Keras Memory safety violations (heap overflows, out-of-bounds reads in C++ tensor operators) and arbitrary file overwrites via malicious model/dataset archive extraction. 99 Frontier Models Anthropic, Gemini, OpenAI Arbitrary Code Execution (RCE) and Command Injection via unvalidated CLI shell interpolation and implicit execution of untrusted workspace configs, Sandbox Escape via Git worktree directory confusion and memory tool symlink traversal; and Covert Data Exfiltration via indirect prompt injection-induced Markdown image rendering and permissive network fetch allowlists. 97 MLOps & Experiment Tracking MLflow, ClearML, Weights & Biases (W&B), Kubeflow, Langfuse, Langsmith, Arize, Phoenix, Helicone Arbitrary File Overwrites (LFI/RFI), unauthenticated remote tracking server takeovers, and artifact deletion in shared experiment registries. 39 Vector Databases & Search Milvus, Qdrant, ChromaDB, Weaviate, Pinecone, FAISS, LanceDB, PGVector, Marqo, Vespa Unauthenticated collection manipulation, Remote Code Execution via clustering/indexing plugins, and metadata SQL/JSON query injection. 19 Table 2: Break down of vulnerabilities targeting AI systems (Source: GTIG) Emerging Battlegrounds: Orchestration & Inference From January 2026 through August 2026, disclosures of AI application vulnerabilities were heavily concentrated in three core areas: agent orchestration frameworks, backend serving infrastructure, and enterprise AI gateways: Agent Orchestration as the Primary Chokepoint: Orchestration middleware accounts for 50% of all AI-related flaws, experiencing a +347% surge in disclosures in 2026. Visual workflow builders (e.g., Flowise, Langflow) and autonomous frameworks often deploy dynamic code execution nodes to facilitate environment interaction. Attackers exploit these nodes via prompt injection or crafted workflow JSONs to hijack execution loops, turning natural language prompts into unauthenticated Remote Code Execution. Centralized AI Gateways and Lateral Cloud Movement: Enterprise AI gateways represent a catastrophic dual-threat vector. At the application layer, compromised gateways expose third-party application programming interface (API) keys and private prompt streams containing personally identifiable information (PII) or proprietary source code. At the infrastructure layer, they act as initial footholds for adversaries to harvest database credentials and pivot laterally into internal cloud environments. Inference Gateways as the New Perimeter: Disclosures across backend serving infrastructure (e.g., vLLM, Triton, LiteLLM, Ollama) reached 212 vulnerabilities in 2026. Nearly a quarter (24%) of these flaws stem directly from unauthenticated API endpoints or Server-Side Request Forgery (SSRF), providing remote adversaries with direct entry points to bypass perimeter firewalls, exhaust expensive GPU compute resources, or extract proprietary model checkpoints. Active In-the-Wild Exploitation of AI Middleware While zero-day exploitation of AI infrastructure has not yet been observed, threat actors are actively weaponizing newly disclosed vulnerabilities in exposed middleware. However, out of 2,076 cumulative disclosures, only a handful of vulnerabilities have been confirmed as exploited in-the-wild. Among the examples, we identified several that we rated High Threat Risk and provide unauthenticated RCE, command injection, or arbitrary file writes: CVE-2026-42271 (BerriAI LiteLLM): Command injection in Model Context Protocol (MCP) server preview endpoints (POST /mcp-rest/test/connection), resulting in host takeover and API credential theft. CVE-2026-5027 (Langflow): Path traversal file write in the POST /api/v2/files upload handler, allowing remote threat actors to drop unauthorized files (e.g., cron jobs, Secure Shell (SSH) keys) onto the host. CVE-2025-3248 (Langflow): Unauthenticated Python code injection via exec() in /api/v1/validate/code, permitting immediate RCE. Outlook GTIG expects that rates of vulnerability discovery and exploitation are likely to continue to increase in the short to medium term. In other research, such as our May AI Threat Tracker, we reported the first known case of a threat actor in possession of a zero-day exploit script developed with generative AI. While intercepted during operational planning before in-the-wild execution, analysis of the exploit's structural artifacts revealed high-confidence LLM generation markers. In our September AI Threat Tracker, we further noted threat actors sharing resources and prototyping agentic vulnerability discovery tooling. We are still in the early days of publicly available data on both AI-augmented vulnerability discovery and vulnerabilities targeting AI infrastructure and technologies. Nonetheless, we can see emerging signals that AI is contributing to vulnerability discovery. When directed at critical attack surfaces, autonomous research agents demonstrate a formidable capacity to uncover high-severity flaws. By reasoning through complex semantic code paths and synthesizing dynamic proof harnesses, agentic workflows excel at identifying memory corruption and logic bypasses in core libraries and runtimes, surfacing the exact types of flaws that sophisticated adversaries actively seek to exploit. As threat actors begin to exploit vulnerabilities in AI systems in the wild, organizations cannot afford to treat AI security as an afterthought. Securing this landscape demands immediate containment strategies, sandboxing autonomous agentic workloads, and implementing risk-based vulnerability management to defend the new perimeter. At this moment, the cybersecurity community has a window of opportunity to bolster defenses on two fronts before threat actors are able to scale up zero-day and n-day exploitation. First, organizations must modernize how they triage and remediate disclosed vulnerabilities. In a separate blog post, Mandiant laid out a blueprint for implementing AI-Assisted Vulnerability Management to help defenders counter compressed adversary timelines. Second, organizations that provide software or services to other enterprises and consumers, should proactively run AI-enhanced code review internally to identify and fix flaws before they are shipped to production and become exploitable vulnerabilities. Leveraging agentic defensive capabilities, such as CodeMender, integrated into Google AI Threat Defense, to continuously audit and patch code across developer workflows will be vital. If pre-release AI code review becomes standard best practice, the rate of growth in public vulnerability disclosures could eventually slow.
Read original articleSeptember 30, 2026
Morningstar Picks Google’s New Chicago Building for HQ Move Bloomberg.com
Read original articleSeptember 30, 2026
Today, Google Cloud Data Agent Kit is generally available. Data Agent Kit is a free set of Model Context Protocol (MCP) tools and agent skills that lets the coding agent you already use work directly with your Google Cloud data products, whether you're using Antigravity, Claude Code, Codex, or other popular tools. With GA, we are adding support for BigQuery Graph, Bigtable, and Managed Service for Apache Spark access to your open Lakehouse, along with dozens of quality-of-life improvements that make everyday work faster and smoother. What is Data Agent Kit? Coding agents have become remarkably good at writing SQL, PySpark, and pipeline code. What they don't have by default is context about your environment: which tables exist, how they're partitioned, which ones your team trusts, or why last night's job failed. Without that, even a strong agent has to work from assumptions, and you end up pasting schemas and error logs into the chat to fill in the gaps. Data Agent Kit fills that gap with two things: MCP tools: Connections to more than 15 Google Data Cloud services, so your agent can inspect schemas, run queries, read job logs, and manage resources in your live environment. Google-authored skills: Open-source instructions from Google Cloud engineers that teach your agent data best practices, like optimizing BigQuery SQL, designing Bigtable row keys, and building dbt (data build tool) pipelines. You can use Data Agent Kit wherever you already work: as an IDE extension for VS Code, Antigravity IDE, Cursor, and other VS Code-compatible editors; as a plugin for Antigravity 2.0, Antigravity CLI, Claude Code, and Codex; or in Cloud Shell and Cloud Workstations, where it comes pre-installed. The IDE extension also brings a lightweight version of the Google Cloud console into your editor, so you can browse data, run queries, and review your agent's work without switching windows. How it works Say you ask your agent, "Forecast next month's demand for our top-selling products and check whether we have enough inventory to meet it." Data Agent Kit loads the relevant skills, so the agent follows Google's best practices for the task. It searches Knowledge Catalog to find the sales and inventory tables your team trusts. It then uses MCP tools to run a forecast in BigQuery, check current stock levels in AlloyDB for PostgreSQL, and bring the combined answer back to your editor or terminal. Every step runs with your own IAM permissions. How Data Agent Kit connects to data. What you can build Data Agent Kit covers analytics, operational databases, the Lakehouse, and pipelines. Here's what that looks like in practice, starting with what's new at GA. Analytics and graph: BigQuery and BigQuery Graph (New in GA) Graphs are a natural way to explore relationships, like which products people buy together or how suppliers connect to your inventory. Building one usually means hand-writing CREATE PROPERTY GRAPH DDL, learning GQL, and working out which keys actually form edges. Instead, you describe the graph you want and your agent builds it. The bigquery-graph-author skill maps your tables to nodes and edges, checks each proposed relationship against the actual data, and shows you a plan to approve before creating anything. It can even start from an ER diagram or data model you already have. The bigquery-graph-query skill then writes the GQL, and the graph visualizer in the IDE lets you click through the results. Building and visualizing a BigQuery property graph. Operational and real-time databases: Spanner, AlloyDB, Cloud SQL, and Bigtable (New in GA) Some features have to load instantly, like a personalized feed, a live counter, or a "recently viewed" rail on your storefront. Bigtable is built for exactly that, and it rewards a well-designed row key. With GA, Bigtable joins Spanner, AlloyDB, and Cloud SQL as a fully supported database in Data Agent Kit. The new bigtable-basics skill designs your schema around how the data will be read and flags hotspots and full table scans before you create anything. Your agent can then create the table and query it with GoogleSQL, with column families flattened into readable columns. In the IDE, you can browse Bigtable instances and tables in the catalog explorer and run queries from the SQL editor. Agent-guided Bigtable schema design and querying. Lakehouse and Spark: Managed Service for Apache Spark and Lakehouse for Apache Iceberg (New in GA) Your agent could already query the Apache Iceberg tables in your Lakehouse through BigQuery. Now it can also work with those same tables using serverless Spark on Managed Service for Apache Spark, with no cluster to manage. Each session keeps its state, so temporary views carry across statements, and you get Iceberg's full feature set, including branching, time travel, and schema evolution. Your tables don't all have to live on Google Cloud, either. The federate-lakehouse-catalog skill connects your Lakehouse to AWS Glue and Databricks Unity Catalog, so your agent can query that data in place without building an ingestion pipeline first. Branching and querying Iceberg tables with Managed Service for Apache Spark. Pipelines and orchestration: dbt, Dataform, and Managed Service for Apache Airflow Once your logic works, your agent can turn it into a pipeline that runs on its own. It writes dbt or Dataform models, then the gcp-pipeline-orchestration skill schedules them together with your notebooks as an Orchestration Pipeline on Managed Service for Apache Airflow. Pipelines can also include Gemini Enterprise Agent Platform steps, like uploading a model or running batch inference. In the IDE, you can follow each run on a visual pipeline canvas. If a task needs attention, click Diagnose to hand its logs to your agent. Troubleshooting skills for Airflow and Spark trace the root cause and propose a fix for you to approve. Troubleshooting a failed Airflow DAG with an agent. Improving the developer experience GA also streamlines setup and day-to-day workflows. When you get started, you simply sign in once and select the Google Cloud services you use. Data Agent Kit automatically enables the required APIs, installs the matching skills, and configures your MCP servers with no manual setup files. Inside the IDE, the SQL editor and notebooks now support inline code generation, @ references to tables, and diff views for suggested changes. The extension also shares your active project, open file, and the error from the query you just ran with your agent, so asking it to "fix this query" just works. We also made the core tools faster and more responsive. New Spark notebooks automatically create and select a Spark Connect runtime, and Spark SQL queries in the editor run in isolated sessions with built-in execution metrics. The catalog explorer now loads faster and includes BigQuery public datasets in the sidebar. Tuned notebook skills help your agent finish notebook tasks more quickly while using fewer tokens. Ready for the enterprise Data Agent Kit is included at no additional cost; you pay standard pricing only for the Google Cloud services your agent uses. Skills also steer the agent toward cost-aware query patterns, like checking partition keys and running a dry run before executing a BigQuery query to avoid accidental full-table scans. And because the skills are open source on GitHub, your team can audit them, fork them, or write custom skills for your own internal standards. For access control, the agent connects as you or as a service account you impersonate, so row- and column-level security policies apply automatically. Admins can also govern MCP access with Identity and Access Management (IAM), screen MCP traffic with Model Armor, and scope agents with VPC Service Controls and Principal Access Boundary policies. Install and get started You can set up Data Agent Kit in under a minute in either your IDE or your terminal. Option 1: Install the IDE Extension IDE extension: Search for "Google Cloud Data Agent Kit" in the Extensions panel of VS Code, Antigravity IDE, Cursor, or any VS Code-compatible editor. You can also install it from the VS Code Marketplace or Open VSX. Antigravity 2.0: Go to Settings > Customizations > Build with Google Plugins, then download Data Agent Kit. Cloud Shell and Cloud Workstations: Already installed by default; just open the editor and sign in. Option 2: Install the CLI Plugin Run the command for your preferred coding agent using the official GoogleCloudPlatform/data-agent-kit-plugin repository: code_block <ListValue: [StructValue([('code', '# Antigravity CLI\r\nagy plugin install https://github.com/GoogleCloudPlatform/data-agent-kit-plugin\r\n\r\n# Claude Code\r\nclaude plugin install data-agent-kit-starter-pack@claude-plugins-official\r\n\r\n# Codex CLI\r\ncodex plugin marketplace add GoogleCloudPlatform/data-agent-kit-plugin\r\ncodex plugin add dak@dak-marketplace'), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7f96bbf8b410>)])]> Then try a first prompt: code_block <ListValue: [StructValue([('code', "What are this week's fastest rising search terms in the US that weren't in the last week's top 10? Use the BigQuery public Google Trends dataset."), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7f96c1b37810>)])]> Data Agent Kit plugin running in Claude Code. Next steps & hands-on resources Read the docs: Explore the Data Agent Kit documentation and product overview page. Explore the skills: Browse, star, and contribute on GitHub. Build an analytics workflow: Try the Analytics with Data Agent Kit and Antigravity IDE codelab, and read the companion blog, Agentic analytics with the Data Agent Kit. Build a data science pipeline: Try the Fraud detection pipeline with Data Agent Kit and Antigravity IDE codelab.
Read original articleSeptember 30, 2026
Google Begins Paying Publishers for AI Overview Answers PYMNTS.com
Read original articleSeptember 30, 2026
This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. “We’re not going to shoot ourselves in the foot” over hack fallout, says OpenAI’s chief research officer Two months after OpenAI’s agents hacked into the computers of AI company Hugging Face,…
Read original article