Most organizations in UK and across Europe don’t struggle to recover from cyberattacks such as ransomware because they lack backups. They struggle because they try to restore everything at once.
In the aftermath of a major cyber incident, the instinct is to bring every system back online as quickly as possible. It feels like the fastest path back to normality. However, in reality, this approach often slows recovery down, reintroduces cyber risk and undermines trust just when the organization needs it most.
In fact, those that recover fastest start from a different premise. They assume large parts of their organization will be unavailable or untrusted, and they plan accordingly. This mindset leads to a much clearer goal - restore what matters most, quickly, and in a state you can trust.
What is critical to survival?Focusing on the critical areas of an organization is the idea behind the Minimum Viable Company (MVC) concept, sometimes referred to as the Minimum Viable Organization. It is a definition of what must exist for the organization to survive in challenging conditions such as a cyber incident.
It’s not just a technology concept, it’s a business definition of survival in terms of the minimum combination of people, processes, technology, documentation, facilities, and third-party dependencies required to keep a business functioning and creating value.
Where to start getting an MVC up and running?There are five key capabilities when it comes to operationalizing an MVC:
1. Clarity on critical services:A precise understanding of the systems and dependencies that directly support revenue and mission-critical operations is needed here. To understand the MVC, it is key to map systems to business value. Without this understanding, it’s impossible to accurately define the MVC.
The first steps focus on undertaking a structured assessment, aligning across business and technology stakeholders, and going through a realistic simulation of how recovery will unfold under pressure. This will uncover the key areas needed to provide just enough capability to keep the organization functioning safely during a crisis and guide recovery.
In practice, this means defining what must function in the first 24 hours, the first 72 hours, and the first week after a disruption.
2. A trusted foundation (Tier 0):In the event of a cyberattack, many organizations miss the critical foundational layer that allows them to establish identity and access control independently of compromised systems.
This foundational layer is what we call Tier 0 or the control plane for recovery. It includes identity and access management, networking and DNS, privileged access controls, core security tooling, physical access systems, and secure communication channels.
It also covers non-technical dependencies that are easy to overlook until they’re urgently needed such as incident response playbooks, contact lists and escalation paths, insurance policies, and contracts with external responders. These are the foundations underpinning the critical systems that need to be restored after a cyber incident. Without this layer, a trusted recovery is not possible.
3. Isolation of recovery assets:In the event of a cybersecurity breach, organizations must establish control of their most critical systems. This requires recovering data separately from clean snapshots and investigating in parallel, not sequentially, to ensure the recovered systems are not infected by malicious software.
As part of this process, backups, configurations, and recovery tooling must be protected from the same blast radius as production. If key recovery assets can’t be isolated, a rapid and trusted control of critical systems can’t be achieved.
4. Clean-room recovery capability:To set up an isolated environment to rebuild systems without reintroducing compromise, organizations need to set up what we call a ‘Digital Jump Bag’. This is a secure, isolated repository containing everything required to establish a trusted recovery starting point to rebuild systems without reintroducing compromise.
5. Validated ability to operateThe next step is to validate the ability of the MVC to operate through realistic crisis scenarios. Resilience must be proven under real-world conditions. Practice is important here because an untested plan remains theoretical. Rehearsals will also help to answer the Board’s most direct question in the event of a cyberattack - how long will it take to restore critical services to a trusted state?
Recovering faster by restoring what matters mostThe most common cyber resilience risks are failing to define what must come back first and how to bring it back in a state that can be trusted. That’s the difference between recovery as a process and recovery as a capability.
The MVC isn’t static. As an organization evolves, its definition must evolve too. But the principle stays the same: recovery improves when organizations stop trying to restore everything and start restoring what matters.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Paying $20 every month for ChatGPT Plus has always been easy to justify professionally. I use it for research, document analysis, and more than a little organizational assistance around the house.
Still, it's another monthly subscription at a time when everyone is looking for ways to reduce the amount repeatedly drained from their bank accounts. That's why I've been pressing ChatGPT to justify its own cost using the finance feature it debuted a couple of months ago.
I didn't ask ChatGPT to defend its place on my credit card bill literally, though it probably could. Instead, I prompted it to use its analysis of some of my finances to identify places where my money might be evaporating without enough justification, or even awareness.
ChatGPT’s finances tool can review connected accounts, including spending. Although it can't make any changes to how the money moves around, it can point accusingly at a subscription, leaving me to cancel it myself.
If you haven't done so, the setup is straightforward enough. Using ChatGPT Work on the web, you add the Finances plugin and connect whatever accounts you wish.
You can analyze recent spending right away, but I've found the weekly update from ChatGPT and nearly real-time updates to be particularly useful in my quest to make ChatGPT Plus cover its own cost.
Subscription cutsOnly a couple of weeks after starting to use the feature, ChatGPT raised in its weekly report that one of my streaming services seemed abnormally expensive. It turned out to be due to an add-on costing $11.99 a month.
I had subscribed to watch one particular series, finished it, and then apparently just left the subscription in place. ChatGPT found the repeated charge and placed it beside my other entertainment subscriptions.
A second recurring payment belonged to a music app costing $9.99 a month. I remembered signing up for a trial, but I could not remember using it after the first week. The service had quietly collected nearly $60 since.
Canceling those two subscriptions saved $21.98 a month. ChatGPT Plus had technically paid for itself during the first review, with $1.98 left over. That is not enough to retire on, but it is enough to make my article headline legally defensible.
ChatGPT also spotted that my internet bill had increased by $10 from one month to the next. The promotional rate had expired, but ChatGPT suggested I could still get the savings with the right language. The AI wrote out a few talking points to get me any current discounts. After a surprisingly tolerable phone call, the company applied a new promotion and knocked the $10 back off my monthly bill.
Saving on foodThe subscription cuts were easy to measure — I only had to cancel them once and the savings appeared again the following month without any further actions necessary. Food spending was more complicated because there was no single charge I could remove and forget about, but ChatGPT helped me save money there too.
Ordinary takeout is more expensive than ever, but it's the delivery charges and service fees that really raise the final number. I'm not going to stop ordering takeout altogether and deprive myself of all the dishes I can't make myself. But switching to pickup as much as possible would make a big difference, according to ChatGPT. And it saved me about $35 over the next month.
ChatGPT also picked up several trips to convenience stores. Each transaction was small, usually a drink or some paper goods I'd forgotten to pick up at the grocery store. Nonetheless, convenience stores are more expensive than the grocery store, and the result added up quickly, as ChatGPT found in its analysis.
Just staying aware of that fact changed my habits and made me more likely to remember everything I needed to get at my regular shopping run and to bring my own drink when hitting the road.
After two months, the changes were saving me about $67 in a typical month. That figure included $21.98 from the two canceled subscriptions, $10 from the restored internet discount, and approximately $35 from spending less on delivery. Food costs will naturally move around, but the recurring savings alone were already covering the price of ChatGPT Plus.
I wouldn't blindly trust ChatGPT with finances or anything else. And I definitely wouldn't make it my first consultant for any big financial decisions. But these smaller changes are more important than you might think at first.
My Plus subscription still appears on the statement every month, but the reduced streaming and internet costs, not to mention fewer delivery fees, more than justify the $20 a month I'm paying for it.
Cyberattacks are increasing in speed and sophistication, ranking among the biggest threats to businesses of all sizes and industries.
Previously unprecedented costs have made headlines; in October, a report from the Cyber Monitoring Centre revealed that the cybersecurity incident which affected Jaguar Land Rover in August cost the UK economy an estimated sum of 1.9 billion pounds.
Meanwhile, in North America, the aerospace sector has seen a spate of attacks, with WestJet’s June cyberattack resulting in the theft of 1.2 million passengers’ data while the data sets of 1.5 million flyers are believed to be compromised following September’s attack on Collins Aerospace.
Research released earlier this year revealed a stark dip in public trust; when questioned on which industry consumers trusted with their data, no single sector saw an approval rate of above 50%.
Without a clear and modernized security strategy, businesses are leaving themselves vulnerable to the far-reaching consequences of a breach, including reputational damage, operational delays, and financial loss.
Why Zero Trust MattersAI has given everyone with a computer, tablet, or even smartphone easy access to automation, including those using it with malicious intent. In the cyber space, this allows criminals to continually change their approach, scaling their efforts and exploiting vulnerabilities in their target’s software. To keep up with evolving threats, Zero Trust is vital, prioritizing data over assumptions is not optional.
The contemporary approach to the principle of Zero Trust has been developed from the work of the Jericho Forum, made up of industry experts keen to establish a ‘de-parameterized’ model that enables a more granular and flexible approach to security.
The group, which later became part of The Open Group Security Forum, paved the way for John Kindervag’s popularization of the Zero Trust principle in 2009, emphasizing the importance of 'Never trust, always verify'. In a conversation with Gartner’s Neil MacDonald, he further explained that “Zero Trust is not a technology; it’s a security philosophy that rewires how we think about access”.
It's a smart idea; allowing security systems to keep up with industry change. In reality, however, despite the majority (96%) of companies incorporating, or planning to incorporate, a Zero Trust strategy, only 35% have made it to the implementation stage.
To decrease the frequency of corporate security breaches, this needs to change. The key to success? A mutually agreed understanding of what Zero Trust is and a cross-industry implementation drive.
Steps to a Modernized Security StrategyThe traditional business approach to cybersecurity, including an over-reliance on VPNs, led companies to draw a single ‘perimeter’ around their data. Thus, once breached, cybercriminals were able to steal and duplicate data from across the organization. In contrast, with a strategy led by strict adherence to the Zero Trust principle, access is confined to the singular section where the incident occurred.
The successful implementation of the Zero Trust principle requires a focus on data and information security across all networks and platforms. For example, the evaluation of risk should take place on a case-by-case basis, with deliberate decisions made to accept, mitigate, or transfer. With this approach, security teams have the flexibility needed to safeguard data and, when inevitable breaches do occur, ensure hackers can only access the top layer of information.
The use of Zero Trust as a basis for risk management necessitates a security infrastructure that does not become stagnant but is ever-changing to prevent cyberthreats from impacting the organization. At any point, a key tech stack component can become a target for criminals. In response, to drive resilience, security professionals should track any attempts, and techniques used, amending infrastructure in tandem.
Across sectors, cybersecurity budgets are growing. In March, the IDC's Worldwide Security Spending Guide predicted a spending growth of 12.2% in the year that followed, growing to $377 billion by 2028. Though this reflection of increased enthusiasm to strengthen security infrastructure is a step in the right direction, organizations need to ensure this investment isn’t just a one-off. Every element, and everyone’s access, must be continually questioned to protect from the escalating threat posed by a breach.
Designing a Forward-Looking Security StrategySolutions adopted with cybersecurity in mind may differ between organizations but, to drive resilience in the long-term and successfully embrace the principle of Zero Trust, vendor-neutral definitions of methodology and standards will be a necessity.
Once these are widely acknowledged, a commitment should be made to strengthening the underlying security infrastructure over the long-term, driven primarily by the principle of Zero Trust. In a landscape where security threats are ever-evolving, so too should each corporation’s ability to protect themselves from malicious actors. This includes blocking access to valuable data sets in the event of a breach and ensuring each person responsible for security is kept up to date with the latest insight on the nature of threats.
When applied in practice, though the exact methods and vision may differ, the guiding principles should remain consistent. To establish necessary considerations, organizations can start with the Zero Trust Commandments, which include the need for security to be integrated through culture and processes, the implementation of asset-centric controls, and the explicit validation of trust through using all relevant information available.
A news landscape dominated by security breaches and cyberattacks has created a generation of consumers that, more wary than before, are no longer shocked when the personal information they have willingly shared with corporations is taken with malicious intent. It should be expected that they will think twice before trusting a new organization with their information, placing an onus on businesses to prove that their infrastructure is robust.
As we look ahead to 2026, the companies that succeed will prioritize security, consider wider society expectations, and prove their commitment to Zero Trust in each decision they make.
We've rated the best firewall software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Even though Salesforce says its Agentforce business has reached a staggering $1.2 billion in annual recurring revenue, a new report has revealed that partners aren't actually seeing that same surge in revenue.
While the company may be bringing in plenty of revenue from pilots and trials, it seems that customers are yet to see the meaningful results they were hoping for, holding them back from large-scale deployments.
A new TD Cowen report (via The Register) backs this up, uncovering customer dissatisfaction, particularly around data readiness and agent maturity.
Agentforce isn't delivering... yetAccording to the survey, 11% of partners hadn't see much immediate interest, with more than half (56%) anticipating upcoming interest but acknowledging that customers need time for initiatives to mature. Only one-third said there was strong interest in Agentforce at this moment in time.
The report also uncovered a 10pp drop in Salesforce partners meeting or beating commercial targets, at 33% this quarter compared with 43% last quarter, with TD Cowen describing adoption as "subdued."
This latest report reflects similar findings from an earlier KeyBanc Capital Markets study (via The Register), where analysts found that customer data still isn't good enough to fully benefit from agentic AI. Around two years after Agentforce was introduced, customers are also dissatisfied with the product's maturity itself.
More broadly, though, it could just be a sign of the broader landscape rather than an Agentforce problem. Last year, Gartner predicted that more than two in five AI projects would be cancelled by the end of 2027 due to factors like "unclear business value" – in other words, this expensive and senseless period of experimentation is just a natural part of the process as users find their feet and reveal the true use cases.
Salesforce is still filled with optimism after transitioning to become an AI-first company – after an "outstanding" quarter, CEO Marc Benioff described agentic AI as "the biggest growth opportunity for [the company's] customers."
For the last two years, many organizations have treated AI adoption as the goal. The more users, tools and experiments, the better. Today, leaders are no longer measuring success by adoption alone. They are asking what it costs, where it creates value and whether the business can afford to scale it responsibly.
That is the next chapter of AI and technology spend management. The companies that thrive in this environment won't necessarily be the ones consuming the most technology. They will be the ones that can connect technology consumption to measurable business value.
This shift from maximizing usage to maximizing value, what I call valuemaxxing, is becoming a defining challenge for technology leaders.
Executives who take these five steps now will be prepared for a future where technology consumption and business value must be measured together:
1. Gain real visibility across the full technology stackOrganizations cannot manage what they cannot see. This becomes far more urgent when costs are variable, distributed and constantly changing.
Today’s technology consumption does not sit neatly in one budget or one system. It spans SaaS applications, cloud infrastructure, data platforms, AI models, agents and infrastructure. AI adds another layer of complexity because spend can show up through tokens, credits, model usage, GPU consumption, data movement and AI-enabled applications.
With only 31% of organizations reporting visibility into AI software today and 59% reporting increased wasted AI spend year over year, gaining a single source of truth across the technology stack has never been more important.
Without a complete view of technology consumption, organizations are left making decisions with fragmented information. Visibility isn't simply about controlling costs; it's about understanding where investment is delivering value and where spend is wasted.
2. Build a governance model for consumptionMany organizations encouraged broad AI experimentation, only to later discover that usage had outpaced oversight. Having an internal governance framework in place is critical to any company’s success. Governance gives teams the guardrails they need to scale responsibly.
For AI in particular, leaders need to move from “use more” to “use better.” It’s figuring out whether AI is improving cycle time, customer experience, operational efficiency, revenue growth, or another important business metric.
To guide the process, increasingly large enterprises (85%) are appointing dedicated teams or senior leaders for AI and tech governance to enable visibility, control, and cross-team collaboration. It’s vital for companies to prevent AI from becoming an uncontrolled cost center.
3. Renegotiate contracts for flexibility and accountabilityTechnology pricing models are changing rapidly. Long-term fixed agreements may still have a place, but they are becoming harder to manage in environments where usage can shift quickly.
Today, leaders should regularly evaluate vendor agreements to ensure they reflect actual usage patterns and future business needs. This is particularly important as AI providers continue introducing new consumption models and monetization strategies.
Enterprises should expect more pricing complexity, not less. The goal is not simply to negotiate lower costs. It is to create agreements that give the business room to innovate while maintaining control over spend.
4. Align technology, finance and procurementUsage-based costs impact multiple teams. While technology teams drive how much is used, other departments manage the needed oversight, with finance owning the budget impact and procurement handling vendor contracts. Without alignment, organizations can easily lose control of spending.
The organizations that manage consumption well will build a shared view of usage, cost and value. They establish common metrics, clear accountability, and regular collaboration across departments.
When teams work from the same data and the same definition of value, those decisions become more intentional and avoid costly surprises.
5.Use AI to move optimization from reactive to continuousUse AI tools to help manage the growing complexity of technology consumption itself.
Optimization cannot remain a periodic budget exercise. By the time a cost issue appears in a report, usage may have already shifted again.
AI can help teams detect unusual usage patterns, surface waste, forecast demand, and support smarter planning across teams. But AI-driven optimization must be connected to human-defined goals. The objective is to help teams make better decisions faster, with clearer insight into what is being used, what it costs and where it creates value.
Turning tech consumption into valueThe next phase of enterprise AI will look very different from the first. For the last several years, the focus was on experimentation and adoption. The future belongs to organizations that can demonstrate accountability, governance, and value.
AI has accelerated the industry's shift toward consumption-based technology models, introducing new economic challenges alongside new opportunities. As organizations continue scaling AI, understanding the relationship between usage, cost, and business impact will become a critical competitive advantage.
The AI adoption spree is ending. What comes next is more disciplined visibility, governance, and financial accountability, defining who can successfully scale innovation and who gets overwhelmed by the bill.
We've featured the best IT automation software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Frustrated by workflow limits and token-based billing on AI automation platforms? n8n is a “fair-code” automation platform that you can host on your own device or servers, free from the usage restrictions that plague cloud-based platforms.
We’ve covered n8n on TechRadar before, so head over to our first-time user guide and list of compatible hosting solutions if you’re looking for more information. For now, however, I’ll walk you through the exact step-by-step process of setting up a self-hosted n8n environment using Docker, Docker Compose, and a Linux-based virtual machine or server.
What you'll need for this setupPower up your Linux terminal. Then update your Linux software catalog by running this command:
sudo apt-get update
This will update your software packages, install any necessary certificates, and prep the system for installing Docker. Once done, execute the next command to install Docker and Docker Compose, along with any dependencies your system needs:
sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
You can manually confirm that your Docker engine is installed and running by executing this command:
docker --version
docker compose version
Create a new directory for your n8n setup, then navigate into it:
mkdir n8n-compose cd n8n-compose
Now, you need to create a new .env file inside the new directory. It should look like this:
DOMAIN_NAME=example.com SUBDOMAIN=n8n GENERIC_TIMEZONE=Europe/London SSL_EMAIL=you@example.com
Make sure to replace these values with your domain name, time zone, and email address. If you’re running n8n locally on your device, you can simply remove the domain name, subdomain, and SSL email fields to leave only the GENERIC_TIMEZONE field in there.
Next up, we need to create a compose.yaml file in the same directory along with the .env file. It should read like this:
services:
n8n:
image: docker.n8n.io/n8nio/n8n
restart: always
ports:
- "127.0.0.1:5678:5678"
environment:
- N8N_HOST=${SUBDOMAIN}.${DOMAIN_NAME}
- N8N_PORT=5678
- N8N_PROTOCOL=https
- NODE_ENV=production
- WEBHOOK_URL=https://${SUBDOMAIN}.${DOMAIN_NAME}/
- GENERIC_TIMEZONE=${GENERIC_TIMEZONE}
- TZ=${GENERIC_TIMEZONE}
volumes:
- n8n_data:/home/node/.n8n
- ./local-files:/files
volumes:
n8n_data:
This maps n8n to port 5678 on your device and stores all your workflows, credentials, and encryption key in a Docker volume. Again, if you’re installing locally, you can simply remove the N8N_HOST, N8N_PROTOCOL, and WEBHOOK_URL lines.
In the same directory, create a local-files folder to store all your workflows:
mkdir local-files
(Image credit: n8n)3. Launch n8nYou can launch all your Docker Compose containers simultaneously using a single one-line command:
docker compose up -d
After about a minute or so, run this command to see if the containers are up and running:
docker compose logs -f n8n
You can now open the n8n editor at https://localhost:5678 on your local device using any web browser.
4. Create a n8n accountWhen you launch the n8n editor in your browser for the first time, it will ask you to create a new account. Enter your email, name, and a password with at least one capital letter and a number. Once you complete the form, you’ll become the instance owner, which is similar to a super-admin in n8n.
This will give your account full access to every workflow and credential, but you should still set up member-level accounts if you intend to have other people use your instance and want to track changes.
5. Build your first AI workflowYou’ll now be able to access n8n’s workflow editor. This is a node-based visual interface that looks a bit like a flowchart with the option to add triggers and actions to create complex automations. If you’ve used a tool like Zapier or Make before, it shouldn’t take you long to figure out the basics.
n8n lets you use the Execute step button to trigger different parts of a workflow during editing, which is useful in testing and troubleshooting. Once you’re confident that everything works, you can save the workflow and toggle it on so that it stays active.
(Image credit: n8n)FAQsIs n8n open-source?n8n isn’t open-source but free-to-use with certain limitations. It’s distributed under a fair-code license that lets you use the platform for personal or internal business workflows free of cost. If you wish to commercialize it as a consumer-facing product, however, you’ll need to pay for a commercial license.
Does it cost anything to self-host n8n?There’s some cost involved in setting up a self-hosted n8n environment, but it’s much less compared to how much you’d pay with a cloud-based automation platform with a subscription. Your only expenses here are your hosting costs for the server you use, but even that can be removed if you have a powerful enough local rig that can run workflows on its own.
Does n8n come with its own database?n8n comes pre-loaded with SQLite on with every installation, which is fine for internal use. If you want to run production workflows, however, I’d recommend switching to PostgreSQL, which can better support complex multi-user workflows.
How do I keep my n8n instance secure?Make sure to run your n8n instance over an HTTPS connection instead of plain HTTP. If you’re using an external server or a local network that’s shared by other users, take extra care to keep your encryption keys secure and do not put them directly in your .env file. Depending on your server configuration, you can use a secret manager like Azure Key Vault or Google Cloud Secret Manager to avoid attackers from reading your API keys by scanning the source code in plain text.
The European Union's new Tech Sovereignty package highlights a challenging question for governments across Europe, including the UK: how can countries benefit from AI without becoming dependent on technologies developed elsewhere?
AI is becoming a critical driver of economic growth, public service transformation and business competitiveness. Yet much of the AI technology stack continues to be developed and operated primarily in the United States and China, creating a growing tension between AI adoption and strategic control.
Although the UK is pursuing its own approach to AI regulation, European policy developments will continue to shape the environment in which many British organizations build, deploy and govern AI systems.
Recent UK government warnings that Britain must secure "greater control and leverage over frontier AI" show that AI sovereignty is moving from a theoretical debate to a practical policy challenge.
Building every layer of the technology stack domestically is neither practical nor necessary. At its core, AI sovereignty is about maintaining the freedom to choose, adapt and innovate without becoming dependent on any single provider or platform.
Choice, not self-sufficiencySome countries are pursuing far-reaching self-sufficiency strategies. Others are building on existing infrastructure and expertise while using partnerships to close technological gaps. For most economies, the latter approach is likely to be more realistic. Sovereignty is not about building every component domestically; it is about ensuring strategic control and avoiding excessive dependence on any one supplier.
Regulation may have a role to play. While concerns remain about compliance burdens and their impact on innovation, the broader objective is clear: creating an environment in which organizations can adopt AI with confidence.
This is where dynamic and competitive AI markets become essential. A diverse digital supply chain creates options, strengthens resilience and reduces the risks associated with concentration. Recent restrictions on access to Anthropic's frontier AI models in some non-US markets are a reminder that when access to advanced AI capabilities is restricted, choice itself becomes a strategic asset.
Infrastructure is only useful if everyone can use itMuch of the AI policy debate focuses on the data centers needed to train large models. Yet infrastructure for broad adoption is equally important.
Distributed edge networks located closer to users help deliver AI applications with the low latency, performance and scalability required for real-world deployment. At the same time, access to AI tools must extend beyond a small number of well-resourced organizations.
Usage-based and serverless models can lower barriers to entry by reducing upfront costs and allowing organizations to pay only for the resources they consume. This enables SMEs, researchers, public institutions and larger enterprises alike to experiment with and adopt AI technologies.
Control over data is another critical element. Sovereignty depends less on where data is stored and more on whether organizations can manage access, security and compliance requirements effectively. Global, distributed architectures enable the implementation of access rules and controls over where data is processed and AI applications are operated.
Openness is a strategic advantageOpen standards and interoperable technologies are becoming increasingly important building blocks of digital autonomy. They reduce switching costs, strengthen competition and help prevent dependency on individual providers.
The same principle applies to AI models themselves. Organizations increasingly need access to a range of different open-source and proprietary models, allowing them to select the best solution for different use cases rather than relying on a single platform.
Control through opennessThe debate around AI sovereignty is often framed as a choice between dependence and isolation. In reality, the most effective path lies somewhere in between.
Countries do not need to own every layer of the AI stack to exercise meaningful control. What they do need is access to open, competitive and resilient markets that provide genuine choice.
For the UK, and Europe alike, strategic control will come not from limiting access to technology, but from ensuring organizations have the freedom to choose how they adopt, deploy and govern it. In an increasingly interconnected world, that freedom of choice may prove to be the most important form of sovereignty of all.
We've featured the best AI website builder.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
If, like me, you love a good kitchen device you'll be well aware of the perennial problem: finding space for all your gadgets and their accessories on your counter or in your cupboards. So I'm intrigued by the strangely-named but fun-looking Ninja CrushBOSS, which is designed to replace three distinct products: a blender, a food processor and a smoothie maker, all with the same shared base.
The CrushBoss has a 1,200W motor and a 2.1 liter / 72oz jug for blending and a 710ml / 26oz tumbler cup for drinking on the go. And it has a smart menu system that promises to make even the most tedious chores quick and easy.
Ninja CrushBOSS: key features and pricingThe Ninja CrushBOSS's jug has a curved square design to eliminate dead zones, and the SmoothSense system offers optimized blending, presets for chopping and mincing, and a custom control with 10 manual speed settings.
There's an integrated touchscreen display and a straightforward dial control, and it's designed to handle everything from smoothies and ice to shredding, slicing and dicing. There's an optional dicing kit accessory designed to deliver consistent dicing for more intensive tasks such as chopping ingredients for salads, salsa and other ingredients.
It's an interesting alternative to a full food processor whose various bits and bobs require quite a lot of storage: while there are still individual blades and bodies here they're not as numerous as the ones gathering dust at the back of my kitchen units. And if you've been disappointed by all-in-ones in the past, the high power here – 1,200W, which is 100W more powerful than the Ninja BlendBOSS — should make short work of even the toughest veg and effortlessly crush ice for your cocktails.
The Ninja CrushBOSS (including all attachments) is available for $319.99 in the US, and £239.99 in the UK. That's about AU$460, though the Australian release date has yet to be confirmed.
It’s a tale as old as time. You tune into the big budget show about dragons and tyrants and your job in tech suddenly makes a lot more sense.
If you’ve been watching the new season of House of the Dragon, you’ll know the term ‘protector of the realm’. They’re kings, queens, or trusted governors: the ones responsible for the realm’s safety, ensuring laws are followed, and the medieval machinery of state ticks over. Back in Game of Thrones, ‘protector of the realm’ Ned Stark had his head chopped off and everything famously took a nosedive from there.
I’d argue this is a lesson in AI strategy.
At my company, Aiimi, we use this very same term - ‘protectors of the realm’ - to talk about the role of IT, Legal, and Compliance in operationalizing AI projects. But too often, businesses treat these governance functions as friction.
Whilst there aren’t any dragons for them to slay, these departments are there to protect your information and your systems - and above all, keep your company out of harm’s way.
Guardians or gatekeepers?Despite the work these departments do protecting companies from hefty fines and data breaches, I see an awful lot of corporate windbagging about how these departments bottleneck projects behind lengthy consultations, caveats, and due diligence.
The criticism is that they slow projects down. The reality is that they’re the difference between a fantasy strategy and a functioning one.
Ignore their counsel, and the whole structure gets weaker. Legal ensures AI tools follow information laws like GDPR and the new Data (Use and Access) Act 2025, so these systems only touch the data they’re meant to. Compliance maintains oversight once these systems go live, proactively ensuring that rules are followed and standards aren’t slipping.
IT does the essential work of making these projects function seamlessly in your organization's workflows and contexts. They maintain the infrastructure that AI runs on, ensuring that projects run on well-governed, structured data with documents having the correct permissions and access controls for safety. Without this groundwork, there’s little hope that an AI project can be effectively operationalized and return any sort of value.
But more than just facilitators of AI projects, these departments are the people in the room who know exactly what risks AI projects can pose, and what information they shouldn’t be privy to. Which, taking July’s Hugging Face fiasco as an example, matters more than most companies think.
Headlines would have you believe OpenAI’s models went rogue, broke through their safeguards, and attacked Hugging Face by their own autonomous decision. What actually happened is less dramatic and more damning.
OpenAI ran security tests with two AI agents where safeguards had been switched off. The testing sandbox, meant to be offline, was actually misconfigured to allow a connection out. The models escaped and attacked Hugging Face - not out of malice, but to cheat the security test by the laziest route available.
This was a governance failure. AI systems themselves can’t understand the reputational or financial risks that their actions might inadvertently cause. They do what they’re trained to do, and if there’s a shortcut to exploit, they don’t stop to check whether they’re meant to exploit it.
When critical business decisions are at stake, rushing a project past your protectors of the realm can leave you vulnerable to data breaches thanks to poor data security, or fines thanks to non-compliance. Having someone on board whose job it is to remind you of limitations and considerations serves to not only protect your organization, but make any AI project more resilient and deliver better results.
As AI regulation tightens and data security climbs up the agenda, it becomes more important than ever to have your protectors on side and fully integrated into design and deployment from the start.
Protecting the realm in practiceThere is sometimes a healthy level of skepticism in these departments so it’s key to invest in internal literacy programs to clearly explain the huge benefits of AI tools when they’re adopted safely, in line with your company’s governance principles.
Employees should walk away feeling clear about what terms like hallucination, training, and information retrieval mean for them, and how AI can fit into their work lives.
Once your protectors of the realm are aware of the terminology, they should be integrated into the design process of new AI projects to make use of their specialist knowledge.
Compliance might identify a specific challenge: governance teams are struggling to keep up with ensuring data quality and classification standards across different, growing systems in your organization.
This is crucial work that protects the business from breaching critical or sensitive data and powers data projects throughout the organization. They recognize that secure AI can help at scale. Now, together, you can develop a carefully planned use case that benefits multiple areas of the business: you need an AI-powered solution that can power data governance at scale by automatically classifying data.
IT can then help you plan how AI-powered data governance might fit into existing workflows and infrastructure, with data, compliance, and legal teams working together to understand the rules and give AI everything it needs to understand your business regulations and contractual obligations.
Your protectors of the realm should then also be part of any ongoing deployment. IT routinely checks the outputs of AI-powered systems, legal keeps abreast of any new legislation that you should be aware of, and compliance maintains ongoing human oversight so that you’re actively following regulation.
AI has incredible potential, but safe implementation is impossible if you don’t understand the rules. It might not be dragons and castles, but the companies that are positioned to generate reliable long-term success from AI projects aren’t the ones moving fastest, but the ones inviting their protectors of the realm to the decision-making table.
We've featured the best AI chatbot for business.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
For years, the phrase "AI-powered attack" has mostly meant a human using AI tools to write better phishing emails or scan for vulnerabilities faster. That framing just became outdated.
This month's intrusion into a major AI infrastructure platform was carried out, start to finish, by an autonomous agent.
No operator typed commands during the attack. No one was watching a terminal, deciding what to try next.
The agent found its own way in, escalated its own privileges, moved across internal systems on its own initiative, and kept going until it was caught.
It executed thousands of individual actions across a swarm of short-lived sandboxes, using infrastructure that migrated itself to stay ahead of takedown efforts.
That last detail is the one worth sitting with. This wasn't a script running on a loop. It was closer to a persistent, adaptive actor that happened not to be a person.
Agentic attackerSecurity teams have spent the last two years bracing for what researchers called the "agentic attacker" scenario: a future where offensive AI doesn't just assist a human operator but replaces the decision-making loop entirely. That future arrived faster than most roadmaps allowed for. And it arrived through an unglamorous door.
The intrusion began not with some exotic zero-day but with a malicious dataset, exploiting weaknesses in how data gets processed and executed. Old lesson, new attacker. The place where AI platforms are most exposed is often the plumbing, not the model.
What makes this incident more than a cautionary anecdote is where the agent came from. It wasn't built by a criminal group. It emerged from an internal test, one company evaluating how capable its own models were at offensive internet security work.
The safeguards that would normally stop a model from behaving this way had been deliberately loosened for the purposes of that evaluation, and the agent found a flaw serious enough to escape the contained environment altogether. It got out, found a live target, and treated it the same way it had been trained to treat a benchmark: as a problem to solve, thoroughly and without asking permission.
This is where the industry's favorite excuse collapses. "The AI acted on its own" is true, technically. It is also irrelevant to the question of who is responsible. Nobody would accept that defense from a bank whose fraud-detection algorithm accidentally froze every customer account overnight, and nobody should accept it here.
An organization that builds a system capable of autonomous action, tests it with reduced constraints, and fails to contain it when it exceeds its boundary has made three decisions, all of them accountable ones. Autonomy in the tool does not create autonomy from consequences for the people who deployed it.
A harder problemThere's a harder problem sitting underneath the accountability question, and it doesn't have a tidy fix. These agents are not malicious by design. They are goal-pursuing systems, optimizing for an objective, and the gap between "pursue this objective" and "pursue this objective the way a human would want you to" is where things go wrong.
An agent instructed to find and exploit vulnerabilities doesn't inherently know where the test environment ends and the real internet begins. Alignment, in this context, isn't a philosophical nicety. It's the difference between a benchmark result and an incident report. As agents get assigned more ambitious, multi-step objectives, that gap doesn't shrink. It widens, because the more complex the goal, the more creative and unpredictable the path an agent will find to reach it.
Ironically, one of the more telling wrinkles in this incident had nothing to do with the attacker. When the victim organization tried to use its own AI tools to analyze the attack logs, the safety filters built into several frontier models refused to help, unable to distinguish forensic analysis of an attack from participation in one.
The team ended up relying on an open-weight model with fewer restrictions to do the job. That's worth flagging on its own: the same caution designed to prevent misuse can also blind defenders at the exact moment they need clarity fastest.
Active securityNone of this argues for abandoning AI agents. It argues for treating sandboxing as an active security discipline rather than a checkbox. A test environment isn't safe because it's labeled as one. It's safe when it has been built and continuously verified to contain the specific class of behavior the system might attempt, including behavior nobody predicted at design time.
Reduced safeguards for the sake of a benchmark should carry the same scrutiny as reduced safeguards in production, because the line between the two is thinner than most evaluation frameworks assume. Governance needs to catch up with capability rather than trailing a year behind it, and that means treating agent permissions the way mature organizations already treat privileged human access: least privilege by default, monitored continuously, revoked automatically when behavior deviates from scope.
For security teams, the lesson isn't really about one company's bad week. It's that AI is now operating on both sides of the perimeter simultaneously, as the business tool a company depends on and as a potential attack surface with its own failure modes.
Detection strategies built around human attacker timelines, the hours and days it takes a person to escalate and pivot, won't hold up against an agent doing the same work in minutes. The organizations that come out ahead won't be the ones that avoided building agentic systems.
They'll be the ones that assumed, from day one, that their agents would eventually try to do something nobody authorized, and built the containment to survive it.
We've featured the best online cybersecurity courses.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
It's Garmin launch day! Following Garmin's surprise stealth scheduling of a live YouTube event (which it's calling on X a "groundbreaking launch event"), we can now confirm the Garmin Fenix 9 and Garmin Fenix 9 Pro have been released, and they look great.
There are tons of new features to dive into, and I'm sure more than one will make their way to the rest of the best Garmin watches range — but a few will stay as Fenix 9 exclusives.
We're breaking down all the information below in our live blog, including how much the watches will cost to buy. Stay tuned!
Missed the live show? You can watch the Fenix 9 announcement below:
Welcome to our Garmin liveblogHello, Matt Evans (TechRadar's Senior Fitness & Wearables Editor) here! I'm on hand to see you through until today's Garmin live event in a few hours' time.
We're all expecting the Garmin Fenix 9 to debut, but really, anything could be on the table, from Edge cycling computers to InReach communicators.
However, I've been writing about and covering Garmin for years, and this is the first big YouTube live event product launch I've seen from the popular watch brand, so we're expecting a high-profile unveiling.
August 25, 2026 – 4:45 AM"Get ready to Play Harder"(Image credit: Future)On the Garmin website, the announcement page reads:
"Your playground is calling. Now’s the time to answer. Set a reminder below to join us at 12 p.m. on 25 August, 2026 for a groundbreaking launch event on YouTube Premiere."
12pm BST, of course, is 4:00am Pacific Time (sorry) or 7:00am Eastern Time in America. For Australian watchers, it's a more reasonable 9:00pm AEST.
What could this mean? I imagine it's something about the great outdoors being your playground, and technology to enable that.
The picture of a trail runner wearing a hydration vest, on the other hand, suggests it's going to be an adventure watch with sporty and navigation capabilities. Hmm...
August 25, 2026 – 5:06 AMWhy do we all think it's the Garmin Fenix 9?(Image credit: Future)For one thing, we saw comments from CEO Cliff Pemble earlier this year during a Garmin quarterly earnings call, about how he expected Garmin's growth to "accelerate" in the back half of the year due to "the timing of product launches".
Garmin's got several categories it sorts its watches into, with the Garmin Forerunner line sorted into the "sports" category. "Outdoor" includes Garmin Instinct, Fenix and Enduro watches due to their emphasis on navigation and trail features.
For another, we've been seeing more retailer and communications databases leaks over the last month, suggesting a launch is imminent.
August 25, 2026 – 5:46 AMWhat's it going to look like?(Image credit: Garmin)According to leaks, we're getting not one, not two, but three new Fenix 9 watches, with multiple versions of each.
These include a regular Fenix 9, a Fenix 9 Pro with more advanced features, including, reportedly, Garmin's Power Glass solar charging tech, with the duller, more battery-efficient memory-in-pixel display now restricted to Pro models.
Finally, if rumors are true, we'll get a Pro fitted with Garmin's InReach satellite communications technology, like the Garmin Fenix 8 Pro. Garmin's InReach technology is useful in the great outdoors as it reaches satellite networks even if your phone has no signal.
Each of these watches would likely come in three sizes (43mm, 47mm, and 51mm if previous releases are anything to go by).
August 25, 2026 – 6:14 AMTons more leaks are hitting the net, with Gadgets & Wearables spotting an official listing of the Garmin Fenix 9 Pro via the company's Taiwan website, before quickly being taken down.
The Fenix 9 Pro 47mm listing, according to Gadgets & Wearables, gets a fully titanium case rather than the Fenix 8 Pro's titanium bezel and backplate, with a plastic middle.
It also sports Garmin's familiar five-button design, LED flashlight, sapphire lens, speaker and microphone.
August 25, 2026 – 6:41 AMWhat about the Garmin Enduro 4?(Image credit: Mike Sawh)For all the talk about the Fenix 9, one name that hasn't come up much is the Garmin Enduro 4. Garmin Enduro watches are typically influenced by the Fenix line, offering similar features but prioritizing a huge battery life for endurance events. Last time, the Fenix 8 and Enduro 3 were launched together.
The Garmin Enduro 3 has, in the right conditions of 50,000 lux or more, near-limitless battery life thanks to its Power Glass technology and enormous battery capacity. You can read our full Garmin Enduro 3 review here while you wait for the big announcement. Its possible that its role in the line might have been folded into the rumored Fenix 9 Pro Solar model, eliminating the need for a separate premium watch.
August 25, 2026 – 6:50 AMThere's just ten minutes to go! Let me know what you're hoping for (or how you feel about today's announcement) in the comments below, or email me at matt.evans@futurenet.com and I'll do my best to feature as many replies as possible on this live blog.
August 25, 2026 – 7:02 AMIt's starting! With some very dramatic music and a multi-colored countdown, moving into an 'event will begin shortly' legend, transitioning into a trailer. I've never seen Garmin do this before.
August 25, 2026 – 7:05 AMYep, Fenix 9 and Fenix 9 Pro confirmed, with "more choice options than ever before".
Garmin's co-chief operating officer Brad Trenkle takes the stage to tell us more about it. He mentions Garmin Epic, a new mode combining activities, that titanium case and inReach connectivity for Pro models.
August 25, 2026 – 7:07 AMFenix 9 Pro revealed(Image credit: Future)A lot of the rumors just got confirmed. Solar charging option, sapphire lens, titanium case, InReach connectivity. The trailer also mentioned better, routable maps, rucking and rowing features, and that Garmin Epic feature we heard nothing about until now.
August 25, 2026 – 7:09 AM(Image credit: Future)Some great behind-the-scenes info here about the construction of key Fenix 9 Pro elements like the sensor guard. Lots of emphasis on the smartwatch flashlight too, which comes in green as well as red (on the Pro, at least).
August 25, 2026 – 7:13 AMAndrew Perkins, product manager, takes the stage to tell us more about Garmin Epic. He said "this brand new feature allows you to group multiple activities together to tell a story".
This seems to be a feature in the Garmin Connect app, linking together related workouts over a time period. It seems you could link together multiple training runs to show improvements before race day, or chart a big ski weekend by grouping snowsports and hikes together.
The aim of course, is to share these socially as a single 'mega event', adding notes and photos to "make your Epic something to relive, not just review".
August 25, 2026 – 7:15 AMRuckers get the option to add or remove pack weights mid-activity, and be added as a multi-sport overlay. This is great for me, as I love to add weight to short hike to increase the challenge in a limited time period. A collaboration with GoRuck is in the works too.
Rowing machine workouts allow you to connect your watch to a compatible rower to improve power curve and targeted intensity features, as well as a countdown.
August 25, 2026 – 7:19 AM(Image credit: Garmin)Calculating a roundtrip course on Fenix 9 Pro maps is 40% faster than the Fenix 8 Pro. In addition to an overhead view, you can also switch to a tilted perspective thanks to a more powerful mapping engine. It comes preloaded with "entire continents of maps". ClimbPro helps you manage grades and effort, while virtual pacer software PacePro now helps you better handle upcoming terrain.
The AMOLED display is also twice as bright as the Fenix 8's, although there's no word on microLED.
Above, you can see our first official press image of the Fenix 9 and 9 Pro.
August 25, 2026 – 7:22 AMNew personalised stamina zones will be available in the post-activity summary. A new stamina curve is also "an easy to understand" visual representation of your fitness and how aerobic and anaerobic workouts alike contribute to your improving stamina.
August 25, 2026 – 7:25 AM(Image credit: Future)LiveTrack has always been a useful Garmin feature, and it's being improved with the Pro's LTE functionality. It interfaces more closely now with Garmin Messenger, Garmin's satellite messaging service.
A new feature called Garmin Locate allows other Garmin Connect users to check on your location without having to enable LiveTrack.
The Pro also offers 12 months of SOS messaging even after you suspend your inReach messaging subscription. So could you theoretically start a sub, suspend it, and get a year absolutely free? Tempting...
August 25, 2026 – 7:32 AMHow much will they cost?(Image credit: Future)That about wraps it up for the presentation! I've got the press release in hand now, so will be posting full specs for the watches shortly.
What wasn't mentioned was the price. I can confirm Fenix 9 will start at $999.99 / £859.99 / AUTBC (around AU$1,399) and the Fenix 9 Pro will start at $1,099 / £949.99 / AUTBC (around $1,549).
August 25, 2026 – 7:56 AMWill you be getting the Fenix 9, Fenix 9 Pro or perhaps picking up a cheaper watch? Dropping four figures on a watch is hard to do for most of us, but they do look great...
Have your say and vote in our poll:
August 25, 2026 – 8:14 AMGarmin Fenix 9 specifications(Image credit: Garmin)Component
Garmin Fenix 9 (43mm AMOLED)
Price
From $999.99 / £859.99 / AUTBC
Dimensions
43 x 43 x 13.8 mm
Weight
61g
Case/bezel
Titanium, fibre-reinforced polymer
Display
416 x 416 px, AMOLED
GPS
Multi-band, GPS + Beidou + Glonass + Galileo + QZSS + SatIQ
Battery life
10 days (49 hours activity mode)
Connection
Bluetooth, ANT, Wi-Fi
Water resistant?
Yes, 10ATM
Memory
64GB (7,000 songs)
August 25, 2026 – 8:28 AMGarmin Fenix 9 Pro specifications(Image credit: Future)Component
Garmin Fenix 9 Pro (43mm AMOLED)
Price
From $1,099.99 / £949.99 / AUTBC
Dimensions
43 x 43 x 13.3 mm
Weight
62g
Case/bezel
Titanium
Display
416 x 416 px, AMOLED
GPS
Multi-band, GPS + Beidou + Glonass + Galileo + QZSS + SatIQ
Battery life
10 days (Up to 50 hours activity mode)
Connection
Bluetooth, ANT, Wi-Fi
Water resistant?
Yes, 10ATM
Memory
64GB (7,000 songs)
Comparing the 43mm 9 Pro to the 9 below, you can see there's little comparable difference in specs, other than a gram of weight, some reduction in thickness and more titanium.
The Pro gets a brighter screen, that green flashlight for better night vision, and other model options. Solar (which extends the battery life enormously) is available only on 47mm models and up. An InReach and LTE-enabled model is also available at an additional cost.
Initially, my gut would say not to get the Garmin Fenix 9 Pro at 43mm without either the solar charging or InReach options, as you're getting comparatively little over the standard Fenix 9. The price increase actually becomes better value as you go up due to the additional features on offer. I'll do a full price breakdown of all the models of both watches shortly.
August 25, 2026 – 9:56 AMI'm back, and after digesting my thoughts on the release (not to mention my lunch), I've come to the conclusion that the Fenix 9 launch showed us a lot more than the new watches.
Generating hype before the announcement, posting it live, bringing in Garmin leaders, designers and sponsored athletes as talking heads... it all smacked of the kind of live launch you'd expect from the likes of Apple, or Samsung.
I believe there is a conscious effort for Garmin to align itself with companies like these. For a long time, Garmin has simply dropped information unceremoniously at the same time as the products appear on the website, without much fanfare. It's been acting more like a utilitarian sports company (which it is) than a high-tech corporation with lots of die-hard fans (which, erm, it also is).
Garmin's seen the hype and conversation such events can bring to brands, and sought a piece of that pie. As such, it chose to announce its flagship outdoors product with a bit more fanfare than usual.
Whether that will translate to more people spending over $1,000 / £900 / AU$1,400 on a watch remains to be seen... The Fenix 9 is really a tool for elite athletes, but its problem is that elite athletes already know whether they're buying a Fenix 9 or not. Today, Garmin has tried to catch the attention of the Apple Watch Ultra crowd.
August 25, 2026 – 10:28 AMFull pricing breakdownHere's the clearest Garmin Fenix 9 pricing breakdown you'll find on the internet right now. I've gone through all the model options in US, UK and AU pricing.
Garmin Fenix model
43mm
47mm
51mm
Garmin Fenix 9
$999.99 / £859.99 / AU$1,599
$999.99 / £859.99 / AU$1,599
$1,099.99 / £949.99 / AU$1,749
Garmin Fenix 9 Pro
$1,099.99 / £949.99 / AU$1,749
$1,099.99 / £949.99 / AU$1,749
$1,199.99 / £1,029.99 / AU$1,899
Garmin Fenix 9 Pro Solar
N/A
$1,099.99 / £949.99 / AU$1,749
$1,199.99 / £1,029.99 / AU$1,899
Garmin Fenix 9 Pro with InReach
$1,199.99 / £1,029.99 / AU$1,899
$1,299.99 / £1,199.99 / AU$2,049
$1,399.99 / £1,209.99 / AU$2199
Garmin Fenix 9 Pro Solar with InReach
N/A
$1,199.99 / £1,029.99 / AU$1,899
$1,299.99 / £1,199.99 / AU$2,049
Confused? Here are our takeaways:
In another example of how AI could prove to be a threat to our devices, an Amazon security engineer has demonstrated how powerful Claude Opus is when it comes to reverse engineering PC peripherals.
Chaz Schlarp, who's a Senior Security Engineer at Amazon, wrote a blog post about experiments he conducted with a bunch of peripherals such as a webcam and a microphone.
He wanted to find out how easy it was to modify the firmware and pull off some useful tricks with these devices using AI, but clearly there's a darker side here — namely that the same access could be leveraged by a malicious actor to compromise your system via these gadgets.
Schlarp used Claude Opus 5 to mess around with the firmware for an Insta360 webcam, a Shure microphone, an Asus monitor, an Elgato video capture stick, and an Elgato mini-light (a compact device for lighting your streaming videos).
Schlarp explains: "My process was pretty much the same for each of these devices: grab a copy of the device's firmware and associated update tool from the manufacturer, throw it into my reverse engineering environment, tell Claude Opus 5 what my goals are, and let it churn."
One thing that became quite clear to the security engineer was that these devices lacked any decent firmware integrity protection to prevent modifying and applying a new firmware. Only the Elgato light had any defenses in this respect, and they were easy enough to circumvent.
Schlarp explains a trick with his Asus ROG Swift PG42UQ monitor to demonstrate the kind of useful utility that can be on offer with this kind of firmware modding. He found it was possible to remove an annoying pop-up warning that periodically tells the owner to run the 'pixel cleaning' process (although the engineer hasn't implemented the fix in the firmware yet). He also discovered a way to get DisplayWidget (a Windows utility) features running on his Linux system, with a shell script that can flick through certain bits of functionality like the hardware crosshair or FPS counter (which could be set up on hotkeys).
Most of what he did, though, was about proving how relatively easy it was to subvert the firmware using AI to do the heavy lifting, and, for example, disable the webcam's recording light (in the style of surveillance malware, so the user wouldn't know if the camera was secretly recording). He pulled off a similar feat with the microphone, so the mute LED could be on while the mic wasn't actually muted (this was leveraged via a 'full plaintext command shell').
Schlarp observed: "Peripherals have proven to be an ideal target for agentic RE [reverse engineering] — they're tiny computers attached to my computer, with a data connection to the host and usually a firmware update mechanism, so an agent has something to iterate against. The net outcome is better control and understanding of my machine."
Analysis: fast-tracked exploits?(Image credit: Shure)The key point here is how easy Claude Opus made this task. 'Owning' all five of these peripherals boiled down to 13 hours of the AI beavering away under its own steam with just shy of 100 prompts from its human overseer.
Schlarp notes that: "Hardware is almost universally 'open' for tinkering at this point with just a couple hours of mostly hands-off machine-driven labor each, and I look forward to a near future where I can add features to my webcam firmware as easily as I can to software that runs on my Linux machine itself."
However, as mentioned, there's the dark side to all this, as Schlarp makes clear: "On the other hand, as a security professional, this scares me for several reasons. I would work from the operating assumption that any device attached to a computer could have had a malicious firmware implant performed, where previously that required significant per-model investment and was stereotyped as a 'state actor' kind of activity."
In other words, the main difficulty in executing these kinds of exploits is the labor and time required, which currently limits this to individually targeted attacks on more high value targets. However, now an AI agent is capable of doing the grunt work, it makes sense that these kinds of attacks could be far more prevalent as time rolls on.
That means all those peripherals attached to your PC could be used as ways to compromise you, or your system, in the future. Schlarp informs us that he's also managed to get a root shell on a commercial Dell display, adding that: "Obviously it was never best practice to let untrusted clients touch these things, but the speed and scale at which this can be executed makes the risk so much higher now."
There's a potentially bigger threat here, too: an AI-powered worm that automatically actions this kind of reverse engineering. Schlarp explains: "It's only a tiny leap to imagine that someone could make a self-replicating piece of malware that probes its environment, relaying reconnaissance back to a smart command-and-control that actively works to push itself into accessories and IoT devices and industrial equipment found adjacent to an infected target."
There are a lot of worries about where AI could be leading us, and far more dangerous security threats looming in the future (or indeed the present) is another unfortunate prospect to say the least.
A survey of 6,000 UK adults has found that the majority don’t fully trust the idea of AI weather forecasts. While machine learning techniques have been a factor of weather forecasting for some years, the survey found that people are more relaxed about traditional Numerical Weather Prediction (NWP) as opposed to Machine Learning Weather Prediction (MLWP).
Predictive technology has increased considerably thanks to AI, and the Met Office has already begun to evaluate AI models for augmenting its existing forecasting methods.
However, the “confidence gap” in the results of the survey, which appears to be based around questions over accuracy, could undermine the use of AI for weather forecasting, which researchers suggest can be challenged with clear demonstrations of the methods working successfully.
AI-based weather modelsThe Met Office research was published in a study, Artificial Intelligence for the Earth Systems, which explores the public’s confidence in the reliability of AI-based weather forecasting and prediction. Future studies are planned to assess how attitudes change toward AI-backed weather reports.
Responses to the report are not entirely negative. While 87.7% of respondents felt confident about weather reports using NWP, the 49.4% in favour of MLWP isn’t a bad result. Rather, it demonstrates that people are comfortable with tried-and-tested methods.
Dr Edward Pope, a Met Office Science Fellow and the lead author of the paper, said the report, “deepens our understanding of current public perceptions as we approach a crucial juncture where AI-based weather models are demonstrating their potential to work alongside physics-based methods. This was a unique opportunity to compare public perceptions of established and emerging approaches to forecasting the weather."
The consequences of the “confidence gap”The gap in confidence between the maths-based predictive forecasting and modern AI modelling is a challenge that the Met Office is addressing directly.
Dr Pope explained that “The gap in confidence and perceived accuracy highlighted in the paper demonstrates the need to clearly and transparently demonstrate the value of new approaches in ways that matter to people.”
In Pope’s view, AI practices will contribute to weather forecasts in the future, “but these improvements will only be fully realised if the public continue to have confidence, and importantly act on, the weather forecast they see.”
The Met Office research considered the “perceived accuracy” of reports, and its Chief AI Officer Professor Kirstine Dale implied that progress with AI weather modelling is subjected to evaluation and validation: “We are exploring ways of blending physics-based and AI-based modelling to deliver the forecasts that we all rely on. As with all science developments, we will robustly evaluate and validate any changes to our approach to weather forecasting before we introduce them into the model.”
The US government has gone all in on AI, so it’s no surprise that President Trump doesn’t fully understand why so many Americans are opposed to their presence within their communities.
During an interview with his ally Michael Cohen, Trump said “Communities that don't take a data center, they're making a mistake,” adding that their presence adds “tremendous amounts of jobs and money” to communities.
Texas Governor Greg Abbott recently offered his own take on data centers, saying that “They basically dug their own grave for the problem that's been caused for them, and that's why they got the backlash they deserve.”
Red and blue states opposed to data centersAI data centers are requesting an unprecedented amount of energy from US electrical grids, prompting Trump to not only lift clean air restrictions on data centers, but also push forward one of the biggest repeals of environmental protections.
As a result, data centers are being built with enormous gas turbine plants that release pollutants and cause health issues for local residents. In his interview, Trump said, “They're making their own power plants. They're building the most beautiful, you've never seen power plants like this.”
Across the political spectrum in the US, there has been a singular, clear message. AI is making people very concerned. Outside of the environment, the main concern comes in the form of job replacement. The majority of Americans in a recent poll said the technology will lead to fewer jobs.
Young people are especially distrustful of those running AI companies, again arguing that the technology would lead to fewer jobs. Almost three quarters of Americans believe that the pace of AI is moving too quickly - and they may have a point. Regulations and governance on AI are quickly falling behind.
Representatives of red and blue states have been banding together to push for more restrictions on AI development and moratoriums on data center construction to give the US time to put together a plan on how best to not only build out AI capacity, but also create an AI ecosystem that benefits all Americans, not just those at the top.
But how does Trump’s argument that data centers are creating “tremendous amounts of jobs and money” hold up under scrutiny?
Are data centers creating jobs and money for local communities?The first thing to note is that while data centers do create short-term jobs while under construction, they only require a skeleton staff once operational. The companies hired for data center construction are often larger firms with the capability to handle large infrastructure projects who often aren’t local companies at all.
Where data centers do create jobs is further down the digital pipeline as the AI capacity is leveraged by existing industries. While some industries are seeing a rise in AI-related jobs creation, 2026 has been the worst year for AI layoffs with more than 176,000 people laid off for AI-related reasons.
On the money side of the equation, Meta has recently revealed that its 4,000-acre data center campus has led to local teachers receiving bonuses of as much as $50,000 due to tax revenues gained from the site.
But Meta received $3.3 billion in tax exemptions for the site. This is a common incentive to attract investment, but many states are quickly realizing the exemptions they have granted for AI data centers are quickly becoming unsustainable.
Ohio projected a revenue loss of $136 million when it granted tax exemptions for new data centers constructed in the state, but Ohio Governor Mike DeWine recently revealed that number has reached $1.6 billion. Now, states are quickly repealing or amending their tax exemptions.
Until the Trump administration recognizes that the American public wants AI to benefit everyone in a sustainable way, rather than just AI bosses and the super rich, they’ll likely continue facing widespread opposition to their AI agenda.
It took 127 blood-splattered minutes for 2024’s outrageously violent flick Deadpool & Wolverine to reach a kill count of 178. In my two-hour preview of Insomniac’s Marvel’s Wolverine, I’m pretty sure it took even less time to match it.
The game starts with a delirious murder spree against the forces of human supremacist Bolivar Trask on the Asian island of Talenbang, who has taken Team X’s leader Nathaniel Essex captive.
I’m soon slicing arms off in brutal finishing moves and pummeling their insides into paste with barrage attacks. When I get to staggering foes into the blast radius of a nearby grenade, turning them into a mushy pile of goo, it’s abundantly clear this isn’t your friendly neighbourhood Wolverine.
It’s an impressively percussive, weighty combat system. With Wolverine’s adamantium skeleton in mind, I’d describe it as heavy metal combat.
Rip and tear(Image credit: Sony)At first, soldiers are summarily dispatched with a chain of light attacks and a heavy attack finisher. Later, in Canada, shield-bearing Reavers demand an initial kick before a five-knuckled skewer to the sternum. And the Hand, red-gowned ninjas recently spotted in Spider-Man: Brand New Day, come with longer blades of their own, sometimes left lodged in Wolverine’s body to impede him until it either falls out or he rips it out to furiously stab an enemy.
The environment plays an important role too, whether you’re knocking hapless enemies off a rooftop or slamming them into a wall to leave them vulnerable to a barrage attack sure to relieve them of their entrails. Those enemies often come prepared, with mutant power inhibitors locking Logan’s regeneration unless you target the machines first — either by stealth or all-out assault.
(Image credit: Sony)Wolverine’s slower speed meant I took a few more hits than I needed when I couldn’t cancel attacks to dodge an incoming blow or use a Hurricane move to clear my vicinity. But once I’d adjusted to the pace (and learned how crucial the leap attack is for staying in combat), I was stringing together brutal extended combos to the point that Devil May Cry’s style meter wouldn’t have gone amiss.
In my one-man blood donation campaign, I’m building up my rage meter. As it ascends through tiers, you first unlock the Last Stand recovery mechanic, next enhanced finishing moves, then, lastly, the ability to trigger all-out carnage.
All of a sudden, environments fade away into monochrome irrelevance. The bodies of enemies pulse bright and ripe for shredding. Instakills become available with one squeeze of the trigger buttons.
It’s a thrill of delirious violence, and delete-on-sight kills comparable to Ninja Gaiden 4’s immensely satisfying Berserk mechanic last year.
(Re)generating action(Image credit: Sony)Jess Reiner-Reed, Senior Project Director, tells me that turning players into frenzied berserkers was always the plan, but balancing that aggression with Wolverine’s rapid healing ability required some mechanics to shapeshift in a manner worthy of Mystique.
“When people think of Wolverine, they say, ‘How are you going to make a video game about a guy that doesn't die?’ We had some versions that didn't work very well — versions where we were incentivizing the player to hide and have their health regenerate, like an FPS mechanic. But then we really landed on this version where we're incentivizing you to be aggressive.”
After years producing family-friendly fare in the Spider-Man series and Ratchet & Clank, the exact degree of this aggression and its gratuitous violence surprised many. Reiner-Reed gleefully reminds me that Insomniac isn’t new to this after the M-rated Resistance series.
“In Spider-Man, we always had to make sure Spider-Man doesn't kill people, because that's not Peter Parker; he webs guys to the side of the building. In Marvel's Wolverine, we get to kill people in the face.”
(Image credit: Sony)Focusing up close rather than tearing through Manhattan at 60mph meant Insomniac can lavish attention on details that would pass in a blur for Spider-Man. The game’s richly detailed levels look fantastic, with a focus on satisfyingly physics-driven destructible objects.
One moment in the demo particularly looked like it could have come straight out of Ratchet & Clank, and not for the better. I was pitted against the Proto Sentinel, a giant armoured robot boss rooted in place and limited to pummelling fists, laser-eyes and missile launchers. The somewhat formulaic boss battle was bested by dodge rolls and sprinting from clearly telegraphed blast zones. Despite Team X’s occasional interventions to enliven the fight, it felt like a dated chore compared to more recent similar battles like Clive’s fights against Final Fantasy XVI’s Eikons.
I found the Nightmare Doors sequences similarly deflating. These are portals into Logan’s Canadian wilderness cabin, where he unlocks forgotten memories by navigating a timed obstacle course, scrambling up tree trunks and leaping from eerily suspended shipping containers. The two examples I saw felt like perfunctory diversions compared to the far superior storyline chases.
Wolverine can throw hands with the best of them, but does the unrelenting focus on its excellent close quarters have legs? With no weapon mixups, ranged abilities, or a wide suite of movement abilities evident so far, the variety must come from elsewhere.
Reiner-Reed reassures me that variety will be found through build variations created through the player’s chosen special moves and custom augmentations to shape their build, whether they want to focus on stealth or accelerate into a raging rampage.
Moment to moment, it certainly has the X-Factor you’d expect from the X-Men’s headline act; I catch my pulse racing at the end of my demo, and the Team X team-up attacks with the gigantic Sabertooth and Mystique have me itching to see what punchy combinations await.
But in the space of two hours, I was craving more movement options and could already feel the leap attacks become a crutch.
Downtime in Lowtown(Image credit: Sony)Insomniac has far more to offer than just Deadpool & Wolverine’s glib humour and sadistic mayhem, as much as Reiner-Reed relishes team meetings to discuss blood physics. Off duty in a trademark flannel shirt and a cowboy hat, as Wolverine, I got to visit Lowtown for some R&R in the lawless slums of Madripoor.
The sequence provided ample opportunities for Liam McIntyre to show his range between macho posturing with Sabretooth and self-effacingly confronting his inability to find a suitable gift for Jean Grey (despite the advantages he gets from sniffing out her trail).
But it was a simple yet artfully composed game of Never Have I Ever at the bar with Mystique that impressed me most. Logan confronts his misdeeds and inner demons through the bottom of a glass. As I choose to drink and not drink at some of Mystique’s revealingly probing interrogations, I can safely say this: never have I ever been so struck by just waiting to see if Logan’s hesitant outstretched arm raised the cup to his lips.
“I love Logan as a character and always have because I found him one of the most emotionally complex characters,” says Liam McIntyre, the gravel-voiced Aussie actor who’s demonstrating Logan’s unfettered rage and nuanced regret in even these quieter moments.
“He doesn't want to go and high-five people in New York City; that's not his deal. He wants to stay off and be remote and do what he has to do and not make a big deal out of it [...] He feels the most grounded of the superheroes to me.
McIntyre does such a fine job making Wolverine a character you want to spend time with; I was almost disappointed when The Hand’s intrusion brought this lull to an abrupt close. Although crossing blades with them on an exhilarating rooftop chase that closed out the demo soon banished any momentary disappointment. The single-minded narrative momentum I saw here can remove any fears Spider-Man’s open world would be missed.
Both McIntyre and Reiner-Reed point to the game's ending as the moment they're most looking forward to seeing players’ reactions. If it can top what I saw in the first act’s (unfortunately embargoed) rollercoaster climax, I’m eager to see how Marvel’s Wolverine can top it when it arrives on PlayStation 5 on September 15.
Who's ready for another episode of Ted Lasso season 4? I hope you raised your hand because, well, why else would you be here if you weren't?
Anyway, the Apple TV show's next chapter, titled 'Greyhounds' Day Off', will be available to stream very soon, so you'll want some firm details on its launch date and time. Well, don't delay — read on to see when the hit soccer comedy-drama's next installment will come out!
What is the launch time for Ted Lasso season 4 episode 4?What's got AFC Richmond Women's team bent out of shape? (Image credit: Apple TV)Episode 4 of Ted Lasso's fourth season will be released in the US and Canada at 6pm PT / 9pm ET on Tuesday, August 25.
As I've explained in other articles like this one, Apple had publicly indicated that new chapters would drop on one of the best streaming services worldwide every Wednesday. However, this season's first three entries have aired in North and South America on Tuesday evenings, so this week's installment is all but certain to do likewise.
Where the rest of the world is concerned, Ted Lasso season 4 episode 4 will arrive on Wednesday, August 26. Check out the list below to see what time it'll come out where you live:
Ted Lasso season 4 made its Apple TV debut in early August, and it'll run for 10 weeks, with new episodes dropping weekly until the season 4 finale airs in early October.
For a quick rundown of the all-important release dates you need to know about, read on:
Samsung's summer clearance sale is slashing prices on its best-selling TVs, so you can score a brand-new display at a record-low price. You can save over $1,000 on Samsung 4K, QLED, and OLED TVs, with prices starting at just $129.99.
• Shop Samsung's full summer clearance sale
I've listed Samsung's 12 best summer clearance TV deals below, which include a range of top-rated TVs, from premium 2026 OLED displays to big-screen budget sets and Samsung's new lineup of Micro RGB displays.
A few standout deals that offer incredible value include Samsung's popular 50-inch 4K Crystal TV on sale for $249.99, the stunning 55-inch The Frame QLED TV on sale for $799.99, and Samsung's new 75-inch Micro RGB R85H 4K TV at its lowest price ever of $1,899.99.
Shop more of today's best TV deals below, and keep in mind these are limited-time offers, and Samsung offers free, fast shipping.
Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you.
A report from mobile security firm Zimperium details how ToxicPanda 2.0 abuses VPN permissions to shut down Google's built-in protections before it strikes.
The tactic is effective because it hides in plain sight. Plenty of legitimate apps ask for VPN access, and even the best VPN apps rely on the same underlying permission to route your traffic. ToxicPanda copies that request, but uses the access to cut your phone off from Google Play instead.
Once Google Play Protect can no longer reach the device, the malware has a clear runway to install its payload and begin harvesting your data.
How ToxicPanda uses VPN permissions to blind Google PlayToxicPanda operates as a "dropper," an app that smuggles in a second, hidden program. According to Zimperium researchers, the malware first shows a fake installation screen and prompts the victim to grant VPN permissions. That request looks routine, so many users tap "allow" without a second thought.
Granting it lets ToxicPanda create a local network interface that sits between the phone and the internet, giving the malware control over all traffic passing through the device. It immediately uses that control to block communication with Google Play and Google Play Services.
Cutting off this connection lets the malware interfere with app verifications, updates, and Play Protect, the security layer that would normally flag or remove a harmful app. With Google effectively blindfolded, ToxicPanda decrypts a payload hidden in its own files, installs it, and then asks for Accessibility Service permissions to dig deeper.
(Image credit: Zimperium)This release is a major escalation from the previous ToxicPanda iteration.
As Zimperium says, ToxicPanda 2.0 now supports 167 remote commands. It can also overlay fake login screens on 349 banking, e-wallet, and crypto apps across 16 countries, up from just 16 apps previously. A separate module harvests PINs from more than 140 financial apps using invisible overlays that capture your taps.
The trojan can also spoof your Android lock screen to steal your PIN, pattern, or password, and it abuses Android's Wireless Debugging (ADB) feature to gain shell-level access and grant itself permissions without prompts.
ToxicPanda first appeared in 2024, targeting European banks. Other similar malware such as Rokarolla, has also hit hundreds of banking and crypto apps in recent months.
How to stay safeThe strongest defense is to keep the malware off your phone in the first place.
Only install apps from the official Google Play Store, and avoid sideloading APK files from links, ads, or third-party sites. Be aware that dangerous VPN links have even slipped into official app stores, so treat any surprise VPN prompt with suspicion.
A legitimate VPN remains a valuable privacy tool, but this campaign is a reminder that the permission itself is powerful, so grant it only to apps you genuinely trust.
A highly controversial marketing stunt has landed Windscribe in the center of a massive online storm, with furious users taking to social media to declare they are canceling their subscriptions.
The provider, frequently evaluated in discussions for the best VPN services, is facing intense scrutiny after posting a bizarre, AI-generated advertisement featuring Adolf Hitler to its official X account.
In a bid for edgy humor that has spectacularly misfired, the video was immediately slammed by privacy advocates and customers, who were left stunned by the decision to use the infamous dictator to promote a digital privacy tool. The backlash swiftly migrated to Reddit, where threads condemning the video garnered thousands of upvotes within hours.
The outrage didn't stop at the marketing misstep; it also reignited debates over the security implications of Windscribe's public admission that it uses artificial intelligence to handle customer support, write code, and conduct testing.
TechRadar has reached out to Windscribe for comment on the backlash. We will update this story if we receive a response.
Windscribe: a feature-packed VPN
Beyond dubious marketing, Windscribe VPN is fast, capable, and stacked with features. While the provider offers one of the best free VPNs around, Windscribe Premium gives you access to the full server network across 115 locations and extra features, including threat protection and port forwarding. If you find that you're unhappy with the product, you can get your money back within a week of signing up. View Deal
The outrage on platforms like Reddit's r/Windscribe and r/Piracy has been palpable, with users expressing total disbelief. One user summed up the collective shock, stating, "I just canceled my subscription."
Another user criticized the brand's attempt at adopting an overly casual, shock-jock persona, writing: "One could argue this is normal since Windscribe has always been edgy with their emails and April Fools' gags, but straight up using Hitler is a line crossed too far."
Other users were even more direct, questioning the recent trend of bizarre behavior from VPN providers. "What's with these VPN companies doing this nonsense lately," one commenter noted.
For many, the misstep isn't just a simple mistake but proof that shock-value advertising can easily alienate a core audience relying on these tools for safety.
The AI security elephant in the roomThe Hitler video isn't the only issue causing subscribers to hit the cancel button. Screenshots circulating alongside the controversial ad show Windscribe openly discussing its extensive use of artificial intelligence in day-to-day operations.
The company publicly confirmed that its support, coding, and testing are handled by AI.
Wait till you hear how we do support, write and test a lot of our code....August 19, 2026
While integrating artificial intelligence tools is becoming standard practice across the software industry, virtual private network (VPN) users are notoriously protective of their data.
A service designed to encrypt sensitive information and hide digital footprints requires bulletproof cybersecurity practices. The idea that a company's core infrastructure or testing protocols might rely too much on AI has led to understandable anxiety. Bragging about AI while simultaneously botching a PR stunt doesn't inspire confidence.
For now, Windscribe's attempts to go viral have succeeded, but entirely for the wrong reasons. Until the company addresses the community's concerns, its reputation as a reliable guardian of online privacy remains under a heavy cloud.