News
Over the past year, security teams on our platform cut the time it takes to fix a critical vulnerability by roughly 50%. In the same period, their backlog of unresolved critical vulnerabilities grew nearly 29-fold. These numbers describe the problem every security leader is about to inherit.
AI can now test software at a scale manual testing never reached. Models read code and search thousands of assets for familiar vulnerability patterns, surfacing exposures earlier and faster than any human team could.
For businesses trying to keep pace with an expanding attack surface, that reach is genuinely valuable. It is also exposing a weakness that has drawn far less attention: most organizations cannot validate, prioritize and remediate findings at anything close to the rate AI can produce them.
That imbalance is the whole game now. Investment in AI discovery tools, on its own, does not make an organization more secure. It makes it busier. Left unaddressed, it leaves security teams with larger backlogs and less attention paid to the flaws that actually put the business at risk.
This is the problem Continuous Threat Exposure Management (CTEM) exists to solve. CTEM gives organizations a continuous process for understanding their attack surface, finding weaknesses, proving which are genuinely exploitable, and directing remediation towards the exposures that carry the most business risk. Discovery is one input. The advantage comes from everything after it.
The gap between discovery and remediation is wideningSecurity leaders have long treated discovery as a capacity problem: test more assets, cover more code, catch weaknesses earlier. AI answers that question decisively. But finding a potential vulnerability is the start of the work, not the end of it.
Every finding still has to be confirmed as exploitable and judged for severity in the specific context where the technology runs. Then it has to reach the right engineering team, win out against existing priorities, get fixed, and be retested to prove the fix holds. AI compresses the first step and barely touches the rest.
That is why the two numbers I opened with can both be true. A rising count of findings can mean better coverage. Faster repairs can sit alongside a growing backlog when discovery accelerates faster than remediation and engineering capacity moves the other way. Neither figure means much alone. The only view that matters runs the entire route, from first detection to verified fix.
Validation is the choke pointAI has also driven down the cost of producing a convincing security report. Some of those reports point to real weaknesses. Others duplicate known findings, misread the target, or describe theoretical issues that carry little real risk. Everyone still has to be investigated. A report that takes seconds to generate can consume hours of an experienced analyst's time before it can be dismissed with confidence.
At enterprise scale, that is how urgent findings get buried. A well-evidenced vulnerability with a credible attack path lands in the same queue as hundreds of submissions that sound plausible and lead nowhere. Security teams have to separate the AI gold from the AI slop, decide which real findings matter most, and do it with engineering capacity that has not grown to match.
Program owners need clear standards for evidence to make that possible. Researchers should be expected to show the likely business impact and demonstrate how a vulnerability reproduces, with automated tooling used to raise the quality of that evidence rather than the volume of submissions.
A consistent track record of valid findings tells a program owner whose work deserves attention first. That record is worth more, not less, as submissions rise.
Business context still decides what mattersTechnical severity is only part of what you need to know to decide what to fix first. AI can match a finding to known patterns and reason over the systems it can reach. What it rarely has is the full picture the business holds: which services generate revenue, where regulated data lives, which dependencies make downtime especially expensive, and what compensating controls already exist.
The harder problem is combination. Individual findings that look moderate on their own can form a serious attack path once someone understands how the systems interact, which permissions can be abused, and where controls break down across organizational boundaries.
That is human work. And it is better human work when it is diverse: one researcher goes deep on identity controls, another on API behavior, another on how minor weaknesses chain together across systems. That variety surfaces novel attack paths that automation, and even advanced cyber-models, miss.
Our own data shows what that work is worth. Researchers earned more than $47 million on the H1 Platform in the first half of this year, up more than 25% year on year. The strongest earners are the ones who can explain business impact and show exactly how a weakness can be used.
That is also where researchers add the most to a CTEM program: testing whether an exposure holds up under real conditions, and spotting the connections between weaknesses that look harmless in isolation.
That figure deserves an honest footnote. Aggregate earnings rising does not mean every researcher is winning. As AI absorbs the routine, high-frequency findings, the researchers who once made a living there feel the change first, while those who can chain weaknesses, reason about business logic and produce credible proof find their work worth more.
The job of any serious bug bounty platform is to make that a transition its community can move through, not a wall most of them hit.
That obligation runs both ways. If programs expect researchers to raise the quality of their evidence, researchers should expect fast and fair triage in return, real recourse when a valid report is wrongly dismissed, and a door that stays open to newcomers who have not yet built a reputation.
The best researchers increasingly use AI tools themselves, and the value of a report has never turned on whether a tool helped produce it. Protect the economics and the fairness that reward credible work, and the independent research community grows stronger as AI scales, not thinner.
Build for the volume AI createsSo, is bug bounty dead? Far from it. Assume discovery will only accelerate, and put the effort into everything that happens after a flaw is found.
More discovery puts more pressure on the point where reports are validated and handed to engineering. Without enough triage capacity, well-evidenced findings stall behind automated noise.
Without clear ownership, confirmed risks sit in the gap between security and development. Independent verification matters at the other end too, especially when an AI system proposes the fix and may carry the same blind spot into its judgement of whether that fix works.
Boards and executive teams need measures built on risk reduction, not activity. Finding counts are easy to report and can climb even as an organization gets safer. Confirmed exploitability, remediation speed, recurrence, and the size of the unresolved critical backlog tell the real story.
CTEM holds those activities together as a continuous process, keeping discovery, validation, prioritization and remediation connected as the attack surface changes. It gives security leaders an honest view of where they are gaining ground and where exposure is still building.
The next phase of AI security will not be won on discovery. Discovery is already abundant. It will be won on response: knowing which findings represent real exposure, and moving the most dangerous of them through to a verified fix. AI supplies the reach. Independent researchers supply the judgement and the adversarial creativity AI still lacks.
The organizations that build to convert both into action will pull ahead. The ones that do not will own a faster-growing list of vulnerabilities they never fixed.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- New details about Avengers: Endgame Encore's post-credits scenes have been shared online
- Descriptions of four end credits stingers show how it'll directly lead into Avengers: Doomsday
- The footage has also leaked now
Fresh details about Avengers: Endgame Encore's new post-credits scenes have leaked online — and they show how elements will directly lead into Avengers: Doomsday.
For those who don't know, Avengers: Endgame Encore is a re-released version of the 2019 Marvel cultural phenomenon that made over $2 billion at the worldwide box office.
The updated film, which arrives in theaters this Friday (September 25), is being promoted as a direct prequel to Avengers: Doomsday ahead of the penultimate Marvel Phase 6 flick's own theatrical debut on December 18, 2026. As such, Endgame Encore includes never-before-seen footage — scenes believed to total an additional six minutes — that'll position it as an immediate predecessor to Doomsday.
Avengers: Doomsday will see heroes from three universes unite to tackle Doctor Doom (Image credit: Marvel Studios/Andy Park)That way, fans who fell off the Marvel Cinematic Universe (MCU) bandwagon after Endgame's initial launch won't need to watch every single film and Disney+ show that's been released since. That said, Marvel has created a Disney+ watchlist of 15 must-see MCU projects to catch you up on the franchise's main storylines heading into the next Avengers movie.
But, I digress. With Endgame Encore's own launch fast approaching, fans have wondered what new footage will be included in the re-release that'll directly tie it to Avengers 5. As it happens, Endgame Encore has already premiered in South Korea, and some lucky fans have taken to various social media platforms to share what they saw at their showings.
Now, there's no leaked footage to speak of, so we can't verify the following descriptions (Update: footage of all four scenes have leaked online, but I'm not posting them here).
There's also some confusion over the order in which these end credits scenes were shown and people's interpretations of said clips. Nevertheless, potentially huge spoilers immediately follow for Endgame Encore, so click away now if you don't want the experience ruined before you see it yourself. Even better, go and find out everything we officially know so far about Avengers: Doomsday.
Avengers: Endgame Encore's end credits scenes show a Doom-Hulk meeting, Loki visiting Steve and Peggy, and the multiverse collapsingNone of these heroes appear in Endgame Encore's new footage (Image credit: Marvel Studios)According to Reddit user ARST_ARSW, Endgame Encore has three post-credits scenes. The first sees Loki visit Steve Rogers and Peggy Carter in the alternate timeline that Steve (aka Captain America) stayed in after he returned the Infinity Stones to their original timelines, before Loki tells them he can help them with… something.
Then, the second round of footage reunites us with Bruce Banner. He's in solitary confinement after the events of Spider-Man: Brand New Day and is experimenting with a new way of controlling his gamma irradiated alter-ego. However, his tests are suddenly interrupted by Doctor Doom, who apparently says "I'm here to adapt you" before appearing to absorb Hulk's superhuman abilities.
Lastly, the final end credits stinger takes us to the Time Variance Authority (TVA), and shows O.B. say "the Multiverse is collapsing" as he watches numerous realities collide with one another.
So, how accurate are the above Redditor's descriptions? According to X/Twitter use and semi-reliable leaker SukunaOnFN1, the Hulk-Doom meeting isn't entirely correct.
Indeed, SukunaOnFN1 has claimed that the Hulk-Doom scene is the first one we see at the end of Endgame Encore. Furthermore, they said that we only hear Doom speak (i.e. he doesn't appear on the screen), and actually tell Banner "I've come to collect you". Then, we hear Hulk, well, hulk out, and see a flash of green light before the camera pans down to some Latverian symbols burned into the ground.
But wait, there's more. On r/LeaksandRumors, another fan in brewstew07 says the TVA scene was shown first in their screening, and that the Hulk-Doom one appeared after it. Brewstew07 doesn't mention the Loki, Steve, and Peggy scene at all.
Thankfully, another Redditor in KostisPat257 has rounded up all of the available information on not three, but four end credits stingers.
Avengers: Endgame Encore - Discussion Thread and Additional Scenes Full Description from r/marvelstudiosWhere the Loki scene — which is the first one that most viewers seem to have seen — is concerned, KostisPat257 says Peggy and Steve are dancing, before a knock at the door spooks them and forces Steve to go hide. Peggy answers the door and asks someone "Can I help you?", with the latter replying "No, but I can help you". Steve emerges from his hidey hole and is stunned to see Loki standing in front of him.
Scene 2, aka the Hulk-Doom one, plays out exactly as SukunaOnFN1 says it does. Meanwhile, the third round of footage shows flashes of Doom making his mask interspersed with the sound of Tony Stark's hammer hitting metal when he created his super-suit in 2008's Iron Man.
The fourth and final scene, i.e. the TVA one, sees Ms. Minutes reminding its employees to prevent people from traveling outside of their universe. Mobius is then informed by Casey that Earth-10005 (the FoX-Men one) and Earth-1127 are about to collide.
Loki and the TVA have prominent roles in Endgame Encore's post-credits stingers (Image credit: Marvel Studios/Disney Plus)As Mobius asks why this didn't make the report he read, the two realities start firing missiles at each other. As a shocked O.B. says they're trying to destroy each other, the camera pans to other TVA monitors that show multiple universes have already been destroyed, including Earth-400083 (the Eric Bana Hulk-Verse), Earth-15886 (the 2015 Fantastic Four-Verse), and Earth-82111 (the What If...? Universe).
With Endgame Encore out now in some parts of the world and set to debut everywhere else by the end of this week, I suspect leaked footage will be widely shared across the internet in the days ahead. Until they do — and, let's be frank, they will leak online — the above descriptions are all we have to go on in terms of knowing how the aforementioned film will set up the plot of Doomsday and its sequel Avengers: Secret Wars.
What do you think of these post-credits scenes? And will you be seeing Endgame Encore? Let me know in the comments.
- Samsung might not upgrade the RAM and storage amounts for the Galaxy S27 series
- This is likely due to the ongoing RAM and storage crisis driven by AI
- There's a chance that at least some models will use later UFS and DDR generations
If you were hoping the Samsung Galaxy S27 series would ship with more RAM or storage than the Samsung Galaxy S26 line then, well, you’re probably going to be disappointed, because the latest leak suggests there will be almost no changes on that front.
According to reputable South Korean leaker Lanzuk (via GSMArena), the Samsung Galaxy S27 and Galaxy S27 Plus will both ship with 12GB of RAM paired with a choice of 256GB or 512GB of storage. In the case of the Galaxy S27 Plus, that’s identical to its predecessor, and those configurations are also available with the standard Samsung Galaxy S26 — but that phone additionally comes in a 128GB capacity, which is absent here.
For the Samsung Galaxy S27 Ultra, you’ll apparently get 12GB of RAM alongside 256GB or 512GB of storage, but then there’s also supposedly a 1TB model with 16GB of RAM. This likewise is identical to the configurations you can get the Samsung Galaxy S26 Ultra in.
Finally, the rumored new Samsung Galaxy S27 Pro will apparently be sold in 256GB, 512GB, and 1TB configurations, all with 12GB of RAM. So despite this supposedly being a more compact version of the Ultra, it apparently won’t match that phone’s 16GB of RAM in the top configuration.
The same source does at least claim that some phones in the S27 series might use LPDDR6 RAM and UFS 5.1 storage, both of which would be significantly faster than the RAM and storage used in the Galaxy S26 line, but if so it would likely just be the top storage tiers that do.
Another thing you can blame AI forSamsung might make both the flash memory and the phones, but that doesn't mean it's immune to the crisis (Image credit: Future)All of this means that at least on the RAM and storage front, the Samsung Galaxy S27 series might not be much of an upgrade on the Galaxy S26 line, especially if you’re not paying out for the top configurations.
But that’s not really a surprise, as this is likely thanks to the ongoing RAM and storage crisis, fueled by demands from AI data centers. This is affecting most tech, with companies having to choose between limited RAM/storage upgrades — and sometimes downgrades, or higher prices… or both.
So the one upside of this is that if Samsung does keep the RAM and storage at current levels, that might help keep the price of the Galaxy S27 series under control. But with Qualcomm’s latest chipsets reportedly costing more than previous generations too, we wouldn’t be surprised if Samsung’s next flagships still end up with higher price tags than the current ones.
- Palantir CEO Alex Karp says frontier AI labs may end up nationalized because of the potentially unlimited liability they carry
- When asked how those risks could be disclosed in an S-1 IPO filing, Karp challenged the premise itself, saying: “You’re assuming that there will be an S-1.”
- His argument centers around the assumption that large AI-related liabilities ultimately require government intervention at some level, even as OpenAI's CEO Sam Altman ruled out an IPO in 2026, citing AI safety concerns
Palantir CEO Alex Karp has cast doubt on whether the frontier AI labs will ever reach the public markets.
A widely shared post on X by Guillermo Flor summarized Karp as saying OpenAI will never IPO, that there may be no S-1 in play, and that nationalization is the only real exit because the liability exposure from frontier AI is so large that "no public market could potentially absorb it."
His comments brought renewed focus on OpenAI and Anthropic, both of which have recently pledged to prioritize AI safety and "pacing the frontier" of development but have both released new versions of their AI models this week (GPT-6 Sol, Luna, and Opus 5.5).
A case made by focusing on potential liabilitiesThe comments come from Karp's September 17 appearance on CNBC's Squawk on the Street. In a transcript of the segment published by RealClearPolitics, a host asks how the liability Karp has been describing would be written into an S-1, and what the risk factors would sound like.
Karp's answer was one that sent shockwaves in an industry already pricing in potentially two trillion-dollar IPOs in the near future: "You're assuming that there will be an S-1. Okay. Maybe there will be."
He argued that the only way to handle that liability is to ask the government to nationalize said frontier labs, adding that companies often lead you to a conclusion rather than stating what they want outright.
The truth may be more complex: OpenAI confirmed on June 8 that it had confidentially submitted a draft S-1 to the SEC, while noting that some of what it wants to do is "likely easier as a private company." Anthropic made its own confidential submission a week earlier.
Neither company, however, has issued a public S-1 registration statement, using existing regulations to keep its financials private for now. OpenAI also pushed back its own timetable before Karp's statements. In an interview published by Fortune on September 12, Sam Altman said, "right now would be an ill-advised moment to go public," confirming there would be no listing in 2026 and citing safety and alignment work.
Not entirely an honest AI brokerThis is not a new position for Palantir's CEO; in June, Benzinga reported that he spent six months privately warning AI executives about nationalization, telling an interviewer, "The momentum is on the side of people who want to nationalize them."
He also has a commercial interest in the argument, as Palantir sells software built on the premise that enterprises keep their data in-house, and in an August CNBC interview, Karp argued that businesses should control their own models and lean less on the frontier labs' token-based business model. On September 17, per Stocktwits, he again pointed to open models as a way for companies to keep control of their data.
His position rests on the belief that frontier labs carry liability only the government can absorb, that their appetite for regulation partly aims to limit that exposure, and that investors expecting blockbuster listings may be misreading the risk. Whether the delayed OpenAI IPO eventually culminates in some form of nationalization, regulatory oversight, or both remains to be seen.
What is certain, however, is that both Anthropic and OpenAI need billions of dollars to keep training their models and meet compute commitments in the near future, and they might turn to a source that seemed unlikely to some in the industry less than half a year ago: the US federal government.
You typed a few prompts into an AI website builder and had a full site minutes later. It looks promising at first glance, but closer observation reveals it probably looks a lot like every other business in your industry.
Most people reach for these tools because they're short on time, budget, or both. You want something live today, without sinking funds into a six-week build from a developer. But there’s a substantial gap between going live and a website that actually works for your business. That’s exactly what my AI website customization guide covers.
Where do AI-generated websites fall short?AI builders are trained on patterns from thousands of existing sites, so they tend to reproduce the same layouts and headline structures. One review of AI builders found that training on top-performing sites means the tools "find and copy the optimal design," which is efficient but produces cookie-cutter results. If a competitor used the same tool, your sites may look closer to twins than rivals.
The code underneath often carries its own baggage. AI-generated pages tend to ship with bloated CSS and redundant scripts that hurt Core Web Vitals scores, according to multiple industry analyses. This costs you twice, in visitors who leave and in search rankings that suffer for it.
Security is another potential blind spot among AI-generated sites. A recent scan of 447 live websites found that AI-built sites averaged 2.1 high-severity vulnerabilities each, compared with 0.7 for human-built sites, largely because the tools skip protections nobody explicitly asked for, like security headers and rate limiting. AI systems are good at building features that work, but far less reliable at adding safeguards nobody prompted them to include.
Then there's the content itself. AI copy tends toward vague, interchangeable phrasing, since the model is guessing at your specifics rather than pulling from verified facts, which can mean misstated details about your products or services. That doesn't make AI builders useless: it just means the output is a first draft, not a finished product.
7 tips for customizing AI-generated websitesThe good news is that most of these problems are fixable without hiring a full development team. You're not starting from scratch. You're editing a draft, which is a much faster process than building a site from a blank page.
The tips below cover the areas that need the most attention once an AI tool finishes its pass. Work through them in order, since sorting out navigation first tends to make the later steps easier to spot.
#1 Rebuild the menu around what customers search for
AI builders often generate menus based on generic templates rather than how your customers actually think about your business. Important services can end up buried two clicks deep. Labels often use internal jargon instead of the words customers actually search for.
Walk through your own site as if you were a first-time visitor looking for your most requested product or service. If it takes more than two clicks to find, restructure the menu around that task rather than around your org chart. Test it on mobile too, since AI builders often collapse menus into hamburger icons without checking how usable they actually are.
#2 Cut the AI's boilerplate phrases
Look out for filler lines like "we provide high-quality, all-in-one solutions tailored to your unique needs." That kind of phrasing shows up constantly in AI drafts because the model has no specific facts to work with, so it defaults to language that could describe any business.
Replace it with details only you would know, like how long you've operated and what results real customers have actually seen. Specific language builds the credibility that generic phrasing can't. Reading each page out loud helps too, since AI phrasing tends to reveal itself the moment you hear it spoken back to you.
#3 Fact-check every price, spec, and product claim
AI models can invent plausible-sounding specifications, pricing, or availability when they don't have accurate source data to draw from. That's a real risk on e-commerce or service pages, where a wrong price or feature claim turns into a customer complaint later.
Go line by line through every product description, price, and spec sheet the AI generated. Cross-check each one against your actual inventory or service list before the site goes live. Pay close attention to anything the tool invented outright, like sizing charts or shipping timelines it had no real data to draw from.
#4 Swap the stock photos for real ones
The photos an AI builder pulls in are usually generic stock images chosen for visual polish rather than relevance to your business. Visitors have seen the same handshake-and-laptop photos on dozens of other sites. That sameness undercuts the trust you're trying to build.
Swap in real photos of your team, workspace, or product wherever you can. Even a handful placed in key spots, like your homepage and about page, makes the rest of the site feel more credible. A phone camera and decent lighting usually beat another stock photo of strangers shaking hands.
#5 Test every booking, payment, and CRM connection
Booking systems, payment processors, and CRMs often don't connect cleanly to AI-generated code, since the builder isn't working within a platform's standard hooks and APIs. Forms can silently fail to submit, or analytics tags can stop firing without any visible error.
Test every integration yourself: submit a real form, run a test transaction, and confirm the data lands where it should. Don't assume a feature works just because it appears on the page. Repeat the test after any major edit, since a single code change can quietly break a connection that worked fine the day before.
#6 Fill in the title tags and schema that AI skipped
Search engines and AI-powered answer tools rely on structured data to understand what a page is actually about, and AI builders frequently skip or half-fill this layer. Missing title tags and thin meta descriptions make it harder for your pages to surface in search results or AI-generated summaries.
Check each page's title tag, meta description, and heading structure. Then add schema markup for the basics, like your business address and hours, since this is one of the highest-value fixes on this list. A free tool like Google's Rich Results Test can confirm the markup is actually valid before you move on.
#7 Turn on two-factor authentication and audit your forms
Most AI builders leave meaningful gaps in default security configuration, including weak or absent security headers and missing rate limiting on login attempts. Privacy policies often read like placeholder text too, rather than an accurate account of what data you actually collect. Wix's own guidance to users flags two-factor authentication as the single highest-value fix available.
Confirm your SSL certificate is active and enable two-factor authentication on your admin account. Then remove unused contributor access and audit every form to make sure your privacy policy matches what you're actually collecting. Most of these checks take just minutes and rarely need repeating.
Should you generate websites with AI?AI website builders solve a real problem by getting a functional site online without months of development time or a large budget. For a single-page portfolio, a quick landing page, or a proof of concept, the convenience outweighs the trade-offs.
A quick freelancer profile or a temporary event page rarely needs the same scrutiny as a site people will use to make a purchase decision. That’s why you should match your review effort to what's actually riding on the page. The more money or personal data changes hands there, the more that first draft needs a second look.
Tradeoffs show up as the site grows in importance. Convenience upfront translates into review time later, since the quality of the final result tracks closely with how much of that review you put in. Without review, a site tends to read as generic, sometimes with serious accuracy or security problems a customer finds before you do.
I always advise treating the AI output as a first draft rather than a finished site. Put in work so the result stops looking like a slightly different version of every other AI-built site out there. You should also budget time to check facts and close the security gaps the AI skipped on its own.
Financial crime has never stood still. In my nearly three decades in financial services, I have watched fraud move in lockstep with the technology built to stop it, and at times, even stay a step ahead of it, given the speed fraudsters adopt new technology.
I have witnessed decades of AI innovation that raised the bar on fraud detection, yet criminals continue to test those boundaries. Fraud remains a top consumer concern, with over 87.5 million American adults experiencing a scam or financial fraud each year. That’s roughly one in every three American adults.
The question for financial institutions isn't whether AI has a place in fraud prevention, but whether the AI they've deployed is built for the threat landscape they're facing today – and the one that's coming.
Compute has finally caught up with mathematical visionFor decades, data scientists working on fraud prevention had theories they couldn't implement. The ideas were sound, but the computers at the time weren't powerful enough to get the math done. That constraint no longer exists.
Historically, most fraud detection has been carried out by building a profile summarizing a customer's typical behavior using sophisticated features, a neural network, and the customer’s current transaction to flag transactions that are suspicious. It's an approach constrained by the computational limitations of time.
Today, access to GPU and other high-performance compute is changing the art of the possible. Rather than analyzing a transaction in the context of a profile, GPUs allow us to implement entirely new algorithms that can evaluate a customer's extensive transaction history in real-time as the transaction happens.
The result is a significantly sharper, more accurate prediction and far fewer false alarms that can delay or stop legitimate purchases, eroding customer trust.
Built for one job, not every jobThanks to greater GPU availability and computational power, we're now seeing new opportunities to support fraud prevention with a sequence-modeling transformer – not a generic transformer, but one purpose-built for transaction analytics and financial crime.
With a purpose-built transformer architecture that’s trained exclusively on financial transaction data and engineered for a single focused task, financial services institutions can detect financial crime in real time using deep personalization and the context of the customer transaction history.
These are not overarching ‘do everything’ models. They are focused foundation models purpose-built to deliver auditable, high-performing, low-latency generative AI for the fight against financial crime. Each of these models specializes in distinct areas, such as account takeover, scams, mule detection, and first-party misuse.
Independent models focused on their specialty allow for a more complete, accurate, and transparent picture than any single model working alone. And this is just the start, as the same methodology applies to risk decisions, hardship, collections, and any application where understanding our customers leads to better engagement, protection, and service.
The future is nowThe fraud prevention capabilities that will define the next five years are being built right now. Enterprises investing in protecting customers from fraud – both now and in the future – understand that purpose-built models, use of specialized compute, and AI agents are the path to protecting their customers.
The math protecting consumers today was invented decades ago by AI scientists who saw the potential in algorithms even before the compute and infrastructure existed. I've spent much of my career continually chasing that goal to ensure that the industry is ready to bring the best algorithms when compute shows up.
Some of my proudest work came from refusing to settle and trust that technology will catch up with AI invention and math. Every patent, every model, every AI experiment has served the same purpose: making sure the industry is ready to lead with the best AI tools once compute catches up with scientific invention.
That work is happening right now. The only question is whether financial institutions are part of it or racing to catch up.
We've featured the best antivirus software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
A good mechanical keyboard can make long working days more fun, especially if you spend hours writing, coding or working with spreadsheets. The Keychron V6 Max offers a full-size layout, extensive customization and several ways to connect your devices.
• Best for: Writers, programmers and office workers who spend a lot of time typing and want a customizable mechanical keyboard with a dedicated number pad for Windows or Mac.
• The deal: The Keychron V6 Max wireless customizable keyboard is now $110 (was $120) at Amazon. In the UK, the cheapest price for the V6 Max is £92 (was £115) at Argos.
• Why it matters: This is the best mechanical keyboard for professionals that we've reviewed - our hardware editor has been using this everyday since he reviewed it in June without complaint. Its gasket-mounted construction, sound-absorbing foam, replaceable Gateron Jupiter Red switches and durable PBT keycaps offer plenty of options for customizing the typing experience.
V6 Max Wireless QMK Mechanical Keyboard: was $119.99 now $109.19
This keyboard features 108 keys, Gateron Jupiter Red switches, 2.4GHz wireless, Bluetooth 5.1, USB-C connectivity, QMK customization, gasket-mounted construction, double-shot PBT keycaps, adjustable RGB lighting and hot-swappable switch sockets.
In the UK: now £92 (was £115) at ArgosView Deal
Why we recommend itThe V6 Max has a gasket-mounted design with sound-absorbing foam, helping reduce typing noise and providing a comfortable typing experience.
Its double-shot PBT keycaps are designed to resist wear and prevent the lettering from fading, and it comes with pre-lubed Gateron Jupiter Red switches that provide smooth keystrokes without the tactile bump found on some mechanical keyboards.
The hot-swappable PCB supports most three-pin and five-pin MX mechanical switches, making it possible to experiment with different typing characteristics. And there's a volume knob you can tap to instantly mute your computer. It's an especially nice touch.
In his five-star review, our expert Steve said, "if I could, I’d sit at my desk all day and all night just to feel that pleasing feedback, listening to the satisfying clackety-clack as my fingers depress the keys. It might just be the best office keyboard I’ve ever used."
He also added, "For me, it’s one of the best keyboards around, perfectly positioned for productivity-minded professionals, students, programmers — effectively anyone who’s going to be spending a lot of time at their desk. On that score, it delivers an awesome experience."
Price context & historical valueThe reduction from $119.99 to $109.19 represents a relatively modest saving of $10.80, or approximately 9%. That's not a huge discount, but any price cut on such a great keyboard is worth grabbing. I've seen it cheaper in the past, but only as low as $95.99, so you're paying just $13.20 more than the previous low.
Should you buy it?✅ Buy the Keychron V6 Max mechanical keyboard if...
You regularly switch between several computers or want a keyboard that works across different operating systems. The V6 Max supports 2.4GHz wireless, Bluetooth 5.1 and wired USB-C connections. Bluetooth allows you to pair up to three devices, while the 2.4GHz and wired modes support a 1,000Hz polling rate.
❌ Skip the Keychron V6 Max mechanical keyboard if...
You have limited desk space or regularly carry your keyboard between locations. Its 108-key layout includes a dedicated number pad, so it occupies considerably more room than a compact mechanical keyboard.
- In the US: Shop all keyboards at Amazon
- In the UK: See all PC keyboards at Argos
- Microsoft is rolling out an in-app browser for the Copilot app
- When you open links provided by the AI, they'll appear side-by-side with the chat
- While this is likely to prove a convenient feature for some, others have their doubts, and there's an ulterior motive of sorts in terms of pushing Edge
The Copilot app in Windows 11 is getting its own browser, which means that when you follow links provided by the AI, you'll stay within the confines of the app.
Windows Central noticed that Microsoft is set to roll out the in-app browser for the Copilot app on Windows 11 (and macOS), where it will open links in a panel to the side of the chat.
Normally, links would be fired up separately in the default web browser, but with this change, Microsoft aims to keep more activity within the Copilot app.
This feature has been in testing since early this year, and is available for admins to enable now, with a "broader rollout" happening in late November.
If you use the Copilot app, then, you can expect to see this ability appearing in a couple of months (or maybe a bit longer depending on the pace of the rollout).
Analysis: edging forward(Image credit: Shutterstock/Prostock-studio)Obviously, there is an aspect of convenience here, as you can peruse web pages that Copilot highlights right there in the app window. Some folks might like the idea, then, but on Reddit, the feedback that's been shared has been pretty negative.
Windows Central poses a question for the story headline, namely: "Will this upcoming update make Copilot your preferred browser on Windows 11?" And the Redditors who can't resist replying to that query are all overwhelmingly negative.
One reply says: "No. Copilot is a scourge that I avoid at all opportunities. Having a browser inside Copilot sounds like Hell."
Another states: "Definitely not. As it is, if I click a link in Copilot I have it open it in my actual web browser. The built-in browser would have to be really good to get me to change that."
Okay, so it's a loaded question and one that AI skeptics are more than happy to jump on and shoot down – but these aren't the people that Microsoft is considering here. It's introducing this for folks who use the Copilot app, who, obviously enough, aren't part of the anti-AI crowd who are very quick to fire flak at anything related to the topic.
On the other hand, this isn't something Microsoft's doing purely out of the goodness of its heart. It's a way to keep more activity within the Copilot app, as noted, and also another method of (indirectly) pushing the Edge browser. Because naturally enough, that's what the in-app browser is based on (what else would it be).
That doesn't mean the feature isn't useful, though, and if you like the sound of the in-app browser for Copilot, you've not got long to wait.
Not only did we have the season finale of Reacher season 4 hit Prime Video last week, but all eight episodes of spinoff series Neagley were released at exactly the same time.
Understandably, most fans hopped straight from one to the other, despite the two storylines contrasting in the most jarring way possible. While Reacher season 4 has followed a length political espionage plot, Neagley took the Amazon TV franchise back to its roots, exploring the mysterious death of a young man in the heart of Chicago.
If you asked me, I'd say that the two seasons are neck and neck. The pair is flawed for different reasons, yet feel like exactly the same show... especially as Alan Ritchson's Jack Reacher features heavily in both.
But, if you were to ask fans, there's a clear winner. In fact, Neagley is so "superior" to Reacher season 4 that, based purely on Reddit, Amazon should look to greenlight Neagley season 2 immediately.
'I'm always happy when a spinoff turns out to be better than the original'"Neagley is superior to Reacher season 4 in nearly every way," one fan posted. "You can clearly see where the energy went from the overlapping schedules."
A second fan doubles down, writing: "Not nearly. Literally every way." But, what is it about the spinoff that makes it the better watch?
"I love the supporting characters and that they’ll continue working with Neagley. I really hope we get a season 2," one fan weighs in, which another adds, "Reacher 4 was all over the place. Too many characters. They should go back to the basic of season 1. Reacher in a small setting uncovering some nefarious activities."
"To me Neagley just felt overall better with the pacing and supporting actors, I even enjoyed the plot line more," a poster in a second thread agrees. "Maybe it’s just because it’s something fresh. We didn’t get to know too much about Neagley and I was intrigued by her past and seeing a badass female led role always makes me happy!"
Not only is Maria Sten's return to the titular role near flawless, but Neagley gets the IP basics right in a way that the already confirmed Reacher season 5 needs to pivot back to. Think smaller stakes, bigger impact.
Surely it's just a matter of days before we get the news we're waiting for. In the meantime, don't panic — ideas are already being formed.
"We have so many great action sequences in this show, and if we get another season, I want to build on that... make it even bigger. Continue to develop these characters, get them into trouble, and get them to face the consequences of their emotional problems," Sten told TechRadar.
Have you been getting an unusual amount of spam calls recently? Automated voices asking you to add a number on WhatsApp? Don’t worry, it’s not just you.
The UK appears to be going through a sudden spike in spam calls and messages, but the reason why isn’t immediately clear. Luckily it seems many of them are following a similar script.
In the spirit of combatting the spam scourge, I’ve spoken to friends and colleagues about the types of messages they have been receiving to help you spot the legitimate calls from the illegitimate - and how spam filtering can help you screen calls before you answer.
Types of scam callsFrom what I have gathered so far, there are a few different spam and scam call campaigns going around at the moment. Here’s what you might have heard:
- An automated voice saying “Please add me on WhatsApp”
By getting you to add the number on WhatsApp, these callers can then bypass spam filtering and allow the scam to continue. It also makes it much easier for scammers to pass on malicious files or links that are difficult to check before opening.
WhatsApp-based scams can sometimes be ‘task scams’ - where the recipient is offered a job testing services or apps for real money. These scams offer rewards that can be cashed out for completing tasks, but instead of banking your reward, they instead steal your financial information.
- Automated Phil
Automated Phil (who isn't always called Phil) will address you directly by name and ask you yes or no questions. In doing so, they will record your voice saying “yes” which they can then use to try to trick voice-recognition systems used by financial services and banks. When you receive a call such as this, never answer the question with “yes” and instead ask “who is calling?”
- Fake reps of companies offering introductory pricing/offers
These calls are usually people pretending to be representatives of mobile networks or internet service providers. They’ll ask if you’d like to hear about an offer, ask which network you are currently with, or tell you that someone has opened an account in your name. If you are expecting a call from your service provider, call back using the official number listed on their legitimate website instead.
- Calls from immigration regarding outstanding cases
A rather sinister scam call that is designed to create panic on the receiving end, hoping to trick the victim out of their senses to get a callback where the scam can continue.
In some scam calls, you may receive a voicemail and decide to call back, thinking it is a legitimate call from a friend or family member only to be greeted by a stranger who has no idea what is going on and is just as confused as you are.
The scammers could be using a legitimate Voice-over-IP (VoIP) service that allows an international call to pose as a number with the correct number format for where you live. This works by routing their call through the internet and delivering the call as a local number.
How did they get my number?Hackers are largely indiscriminate when it comes to breaking into computer systems, and - unless it is a targeted attack - they often don’t know what company they have breached until they exfiltrate any data.
But some breaches are worse than others. Supply chain attacks may not necessarily hit the company that you gave your data to, but a different company that works with the victim company.
For example, a clothing brand will need to provide your email address or mobile number to a logistics company that handles delivery. That logistics company may handle deliveries for more than one clothing brand, so when hackers hit the logistics company they can steal all of the data from multiple brands.
But the recent rise in spam calls may not necessarily be caused by a new data breach.
In order to make some quick cash, some hackers will collect data from multiple separate breaches and organize them into one big file before offering it for sale. The data contained within this trove could be from months or years ago, but many of the email addresses and phone numbers will still be active and are a potential victim.
What can I do?There are a few ways to stay safe when trying to navigate potential spam and scam calls.
If a caller claims to be from a service you use such as your internet or phone provider, always ask for their name and then call back the company using the official number listed on the website. If it was a legitimate call, you’ll be routed back through to them. If not, you’ll know for sure that it was a scam.
Your bank will never ask you to tell them your PIN or card reader codes over the phone, nor will they ask for your password or ask for money to be transferred to a new account that you haven’t set up. If you aren’t sure if it is a legitimate call, use the same technique as above to find out if it really is from your bank.
One key thing to keep in mind when getting a spam call: don't hang up.
If you receive a call that your phone marks as spam, let it ring until it stops. If you hang up before answering, it lets scammers know that the phone number is active and monitored, so they will likely call back or pass on your number to other scammers.
Alternatively, you can also set up call screening on most phones. Here is how to set up call screening on iPhone and Android:
How to set up call screeningHow to set up call screening on iPhone:Call screening is only available on iPhone 11 and above running iOS 26 or later.
- Go to your Settings App
- At the bottom, tap Apps
- Scroll down and tap on Phone
- Scroll down until you see 'Screen Unknown Callers’
- Turn on ‘Ask Reason for Calling’
This will mean that any incoming call from a number that isn’t saved to your contacts will be asked for more information before your phone rings. This information will be displayed as plain text so you can see if the call is legitimate before answering. Just beware that calls from legitimate numbers will also be sent through call screening.
How to set up call screening on Android:- Open the Phone app
- Tap the three vertical dots in the top-right corner
- Tap Settings and then tap Spam and Call Screen or Call Screen
- Turn on 'Automatically screen calls'
On Android, you will be able to select which calls are screened; maximum protection will screen all unknown numbers; medium protection will screen calls marked as suspicious and will outright decline spam; basic protection will not screen any calls and will only decline known spam.
If you've encountered a new spam or scam campaign not included on this list, leave us a comment below to help others spot the calls before they become victims.
The abolition of the Department for Science, Innovation and Technology has created uncertainty about what happens next to Britain’s AI ambitions.
Kanishka Narayan’s promotion to Minister for AI gives the technology a dedicated voice at Cabinet, yet folding DSIT’s responsibilities into other departments raises questions about how the Government will coordinate the infrastructure, investment and public-sector adoption needed to support those ambitions.
Recent parliamentary scrutiny of critical public-sector AI contracts has highlighted growing pressure on institutions to strengthen control over AI operations and deployment continuity. Britain has focused on adoption speed; the next step is operational control in ongoing public-service AI use.
The case for sovereign AI is becoming stronger as a result. Britain needs more than access to capable models; it needs controlled operations for the services that depend on them, even when a provider, contract or political relationship changes.
Sovereignty goes further than where data sitsSovereign AI is often reduced to data residency, with the assumption that keeping information inside Britain is enough to keep it under British control. Data location remains important, particularly in healthcare, defense and public administration, but it describes only one part of the relationship between an organization and the technology it uses.
A hospital could store every patient record in a British data center while relying on models and software that only the original provider can operate or modify. Where that provider is based remains relevant, but the more useful test of sovereignty is whether the hospital can understand the system, govern how it is used and continue running it if the commercial relationship changes.
An organization should know how its systems operate, determine which data a model can access and retain the ability to move a workload or introduce another model without rebuilding the entire service. Once that system becomes essential, it also needs enough internal expertise to keep it running rather than discovering that continuity depends on the decisions of one supplier.
Britain does not need to reproduce every layer of the stack, but it does need predictable control where public services run. Modern AI draws on international research, complex supply chains and open-source projects, and recreating them domestically would consume enormous resources without necessarily producing better technology.
As DSIT’s responsibilities move across Whitehall, the Government needs to decide which dependencies it can accept without threatening security, public trust or an essential service.
Capability and control can reinforce one anotherGovernment AI plans sometimes present sovereignty as the slower alternative to using the largest commercial models, as though Britain must choose between world-class AI and control over its deployment. That assumes every organization needs the same frontier system, when the question is which model suits the work.
For many public workloads, a fit-for-purpose model in a controlled environment is more valuable than one large generic option, especially when governance obligations are strict.
A specialized model can be adapted to the organization's data, tested under the conditions in which it will operate and governed according to the consequences of getting a decision wrong. In those circumstances, greater control can make the system more useful as well as more independent.
Open and portable technology can support this approach by allowing organizations to run models across different infrastructure, examine how systems behave and replace components as better options emerge.
Openness does not guarantee sovereignty, since organizations still need secure infrastructure, skilled teams and clear governance, but it reduces the chance that an entire service becomes inseparable from one provider’s platform.
I have seen the AI market move quickly enough to make that flexibility increasingly valuable. The best model for a task today may be overtaken within months, while pricing, regulation and access can change almost as quickly.
An organization that builds around one proprietary service may struggle to benefit from that progress, whereas one that controls the environment in which its models operate can introduce better technology without starting again.
Government can turn sovereignty into capabilityBritain already has many of the ingredients it needs, including strong universities, experienced researchers, growing AI companies and public investment in compute. The next step is to connect those assets with sustained demand in the parts of the public sector where sovereignty has the greatest practical value.
Government does not need to select one national champion or exclude international companies. It can create a market in which providers compete while public bodies retain control of the systems they buy.
Procurement rules for critical AI could require workloads to be portable, independently testable and capable of running within infrastructure controlled by the customer, making the ability to change course part of the original decision rather than a problem discovered at the end of a contract.
This would give hospitals, councils and government departments credible sovereign options while providing British AI companies with a route from pilots to long-term deployment. It would encourage partnerships in which knowledge and operational authority remain with the institution responsible for the service, even when private companies provide the technology and expertise.
The restructuring of DSIT should be treated as an opportunity to clarify Britain’s objective rather than reduce its ambition. A Minister for AI can bring different parts of government together, but the strategy should be judged by whether public institutions can use the best technology available while retaining meaningful control of the systems that matter most.
That is what will allow Britain’s AI ambitions to endure as departments, suppliers and technologies change.
We've featured the best AI tool.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit


