News
Think about what you had to do the last time you needed to prove your identity.
Did you present your ID? Snap a selfie? Pass a liveness check? In most cases of enterprise security, that’s all it takes to pass through. From that point, many systems effectively assume that the person who was verified remains the person controlling the session.
But that’s increasingly not the case.
Identity checks haven’t suddenly stopped working. Rather, fraudsters and criminals have learned to move around them.
The fraud moved past the checkpointThe modern fraud playbook does not necessarily need to defeat the biometric check at the front door. Session-hijacking malware can take over after a legitimate login. Remote-access tools can turn a verified customer’s device into an attacker’s terminal. Fraud operations can even recruit real people to complete onboarding legitimately before handing the authenticated session to somebody else or to automated systems.
At the moment of verification, the identification document, the face and the live person could all be real. The checkpoint was not necessarily defeated – it was made irrelevant because it didn’t establish that the same person it verified remained in control five minutes later. I call this scenario the “tollbooth mentality.” It’s the belief that passing verification at login means a business can trust whatever happens afterward.
Identity is a heartbeatThe alternative is to treat identity as a continuous signal, a living, breathing thing – a heartbeat that should remain recognizably human and consistent throughout the session.
The raw material already exists. Typing cadence, navigation patterns, device and network telemetry and characteristics of how somebody interacts with a device can help establish a behavioral baseline at onboarding.
Those signals can then be compared with activity throughout the session. If somebody typing at a normal speed suddenly appears to generate thousands of keystrokes per minute, something has changed. If the natural movement of a handheld device suddenly becomes perfectly static, in a way more consistent with an emulator, that should affect the level of trust assigned to the session.
The question needs to shift from “did we verify this person?” to “does what we are seeing now remain consistent with the person and device we originally trusted?”
When that heartbeat changes materially, the system can increase the risk score, request additional verification or, in a high-confidence case, terminate the session.
Who is moving, and who is bleedingThe industries moving fastest are unsurprisingly those where fraud can translate almost immediately into financial loss.
Fintechs, crypto exchanges and neobanks have strong incentives to adopt continuous, risk-based session monitoring. They have also learned that adding more friction at the front door can punish legitimate customers without creating an equivalent obstacle for automated attackers.
A human has limited patience for another password, one-time code or identity challenge. Automated systems do not get frustrated. They can repeat processes at scale.
Businesses therefore cannot simply out-friction machines.
Sectors still anchored to one-time checks (particularly where knowledge-based authentication remains part of the security model) face a different challenge. In an environment where vast quantities of personal information have been compromised, static questions and credentials provide diminishing assurance.
A four-part framework for continuous trustJust as the heart has four main parts, so too does the framework for treating identity as a heartbeat, not a timestamp.
Enterprise security experiences should be strong yet seamless, preventing disruption for low-risk customers while triggering proportionate intervention for anomalous behavior. For organizations looking to make that transition, the operational framework includes four parts:
- Baseline at onboarding. The identity check at the front door becomes the calibration event. Capture the behavioral and device baseline when identity assurance is highest.
- Monitor passively. Continuous does not have to mean intrusive. You can evaluate relevant behavioral and device signals in the background without repeatedly interrupting the customer to request more data. Identify the signals necessary to assess whether a session remains trustworthy.
- Escalate proportionally. Customer experience cannot go out the window in the name of security. Tighten thresholds for small anomalies. Trigger session termination for hard ones. This way, you’ll increasingly avoid insulting valid customers by asking for more proof that they are who they say they are.
- Hold the evidence. An evidentiary trail of risk signals and interventions can support investigations, audits and regulatory scrutiny. Ultimately, organizations must use this evidence to prove not only that a user passed verification, but that trust was maintained afterward.
As fraud moves beyond the capabilities of authentication, organizations must know not only who entered, but whether the digital heartbeat on the other side of the door still belongs to that person.
We've featured the best privacy browser.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
The last few years have seen a growing wave of vulnerability disclosures heading towards the cybersecurity industry, and the people working on fixing these flaws are often struggling to keep up. And while AI is a major contributor to this problem, but also an essential part of the solution.
Speaking at the recent Linux Foundation Open Source Summit, Jamie Thomas, IBM's Chief Client Innovation Officer for Enterprise Security, warned there is “a bit of a tsunami in vulnerability disclosures,” with approximately 66,000 unique entries expected to emerge in 2026 alone.
At the keynote, titled The Future of Open Source Security in the Age of AI, Thomas stressed this represents a fourfold increase compared to seven years ago.
So, how can the cybersecurity industry possibly keep up with this pace, Thomas asked, especially when the expectations placed on developers and security professionals continues to grow?
The answer seems to be the same as with everything these days - AI.
Attackers are moving faster than everThe volume of attacks is definitely an issue, but it’s not the only issue. Cybercriminals are also a lot faster at exploiting them, giving defenders an ever-shrinking window to identify and remediate different security issues.
Citing publicly available data, Thomas said the time required to exploit a vulnerability shrunk from days to as little as 29 minutes.
“And in fact, we're seeing a rapid increase in cyberattacks, as well as malware attacks,” she said.
For businesses that rely heavily on open source, this is definitely cause for serious concern. A vulnerability in a widely used component can potentially affect hundreds, if not thousands, of downstream applications and businesses. To add insult to injury, cybercriminals don’t really wait for the cybersecurity community to publicly disclose a vulnerability before they can exploit it.
“We're seeing the time to exploit is actually negative,” she said. “Many times we're getting a disclosure and we don't have a patch yet.”
That is the position the defenders are in, right now. They are expected to respond to a rapidly growing number of security issues in a shrinking timeframe, while attackers take advantage of automation to accelerate their operations.
AI is making life harder for open-source maintainersAnd then, along comes AI for the sucker punch.
Sure, AI-powered tools are capable of identifying vulnerabilities and improving software security, but they are also more than effective when it comes to creating a pile of inaccurate, duplicated, and otherwise unactionable vulnerability reports.
Where does that leave open source maintainers, you might ask? Large companies typically have dedicated security teams, and even those struggle with an influx of low-quality reports, as you’ll see below. Many open source projects, on the other hand, are maintained by small groups of devs, sometimes even by a single individual.
Earlier this year, the developers of curl, the popular open-source command-line tool and software library, terminated their HackerOne bug bounty program, saying the financial incentives had people submitting poorly researched, and sometimes entirely fake, reports. The influx, which included AI-generated submissions, was simply unmanageable for the project’s security team.
Even the almighty Google bent the knee, recently being forced to temporarily suspend its Open Source Software Vulnerability Rewards Program following a significant increase in invalid and irrelevant reports (many of which were AI-generated, apparently). As of October 1, 2026, the company is no longer accepting new submissions and will reassess the program in early 2027.
Even Linux creator Linus Torvalds complained about the problem, recently saying AI-powered bug hunters have made the Linux security mailing list "almost entirely unmanageable." He criticized the enormous duplication of reports, saying different researchers were using the same AI tools to identify vulnerabilities that were already fixed, or at least reported.
IBM wants AI to become part of the solutionSo what’s the solution? According to Thomas, the security community should not abandon AI-powered vulnerability discovery but should instead use the same technology to help maintainers handle the growing workload.
This is where the Linux Foundation’s Open Source Security Foundation (OpenSSF) initiative, could step in. A collaboration between tech firms, developers, and the wider open-source community could allow OpenSSF to strengthen the supply chain security, and for IBM, the priority is now to reduce the burden on maintainers. That can be done by making vulnerability management more efficient and that, in turn, can be done with AI-powered tools filtering out duplicate and bogus reports, assessing the severity of different bugs, and identifying issues that need urgent attention.
AI can also help remediate issues, help developers understand vulnerable code, suggest fixes, and evaluate whether patches introduce additional problems. This is an important caveat, since some earlier reports found the majority of AI-generated remediation suggestions caused more problems than they solved.
I have had plenty of video game ideas over the years, but I've always faced a somewhat enormous obstacle to turning any of them into reality. I can invent the characters and backstories, even devise some mechanics, but I cannot actually program a video game. Google’s new Playground experiment offers people like me a rather extraordinary shortcut.
Google Playground lets you describe the game you want in ordinary language and have generative AI turn those instructions into something playable. Instead of learning a game engine, writing code, creating artwork and composing music, you can explain your idea and let the AI handle much of the construction. You can then keep prompting it to change the result, making game development feel closer to a conversation.
You can start creating a game from scratch, modify an existing example, or use guided prompts to develop an idea. You can choose between 2D and 3D games, specify whether you want single-player or multiplayer gameplay, and describe everything from the setting and characters to the controls and objectives.
The platform then generates a browser-based game, which can be tested and modified through additional instructions. If something doesn't work the way you imagined, you can ask it to try again.
That is an impressive technical achievement, and my two experiments made the appeal clear, but neither left me convinced that generative AI will start making the games I actually want to spend dozens of hours playing.
Code-free dragon flight(Image credit: Google Playground)I deliberately started with a straightforward concept: a platformer starring a dragon that could breathe fire. A couple of sentences were all it took to produce Mystic Dragon Glide. A few minutes later, I was in control of a small dragon traveling between floating islands, collecting sacred dragon eggs and using fire breath to deal with enemies and environmental hazards.
The result was prettier than I expected. My little red dragon stood on a grassy island floating above a pastel landscape of mountains and clouds, with ancient ruins suspended mysteriously in the distance. A golden egg hovered above another platform, while an island covered in blue ice crystals suggested that some elemental obstacles awaited me farther along.
More importantly, Playground understood what those ideas meant in gameplay terms. I could move the dragon, jump between platforms, hold the jump control to glide and breathe fire. The title screen explained that I should scorch knights, melt glacial hazards, and collect eggs to unlock ancient portals, giving me objectives rather than simply dropping me into a generated fantasy scene.
Even the soundtrack completed the effect. Playground supplied pleasant, generic fantasy video game music, with a gently adventurous melody that sounded entirely appropriate for flying around enchanted islands. There was nothing objectionable about it, but there was also nothing that made me want to immediately find the soundtrack afterward. The AI appeared very good at understanding the average of what a fantasy platformer should look and behave like.
That ability has genuine value. Someone who could never make a platformer before can now describe one and start playing something resembling their idea remarkably quickly. As a creative toy or prototyping system, that is almost magical.
As a game, though, Mystic Dragon Glide reminded me how much of game design lives in details that are difficult to capture in a description. Great platformers are built around movement that has been adjusted obsessively and surprises carefully placed by clever designers. My AI-built dragon could fly, but it would take a lot more work to make the game take flight.
Fantasy bureaucracy(Image credit: Google Playground)Red Tape Hero was born out of a more complex prompt. I decided to write up a page or so of detail and submitted it to Playground as a request to create a satirical fantasy puzzle RPG where the player had been accidentally declared the Chosen One because of an administrative error and now had to navigate a kingdom where adventuring was bureaucratized and paperwork was better than any magic sword. I also wrote up a brief outline of the kind of conversational adventuring I had in mind.
Playground didn't take long to produce a colorful low-poly 3D world filled with simple geometric trees and tiny humanoid characters walking along the paths. The whole thing had the appearance of a cheerfully strange RPG from the early days of 3D gaming. But considering the time and effort on my end, still pretty impressive.
This time the music was a kind of mellow lo-fi beat and tune rather than an orchestral fantasy soundtrack. It was an odd choice for a heroic adventure, but it actually suited the game's relaxed absurdity rather well.
The conversations were where Playground really impressed me. Guildmaster Rickert of Adventurers' Guild Operations welcomed me to my "quarterly performance check-in" and informed me that the quest dispatch algorithm had designated me the Chosen One under Section 9, Subsection C. His immediate concern was whether I had completed Form GT-902 for the goat rescue.
My possible responses reflected the RPG system I had described in the prompt. With sufficient Bureaucracy, I could invoke Kingdom Bylaw 12 and argue that completing more than 10 goat rescues entitled me to hazard pay. A Confidence option allowed me to claim that I had already audited the goat and it had passed with flying colors.
Another character, Sir Galahad, carried a talking sword called Ex Cali-Bot that offered unwanted motivational advice. It proudly announced that "100% of the dragons you don't slay are opportunities missed" and declared that "Synergy is the true holy grail." Galahad apologized because the sword wouldn't stop giving TED Talks, while one of my available responses involved claiming to be a senior agility consultant there to optimize his chivalric pipeline.
This was much closer to seeing my particular idea reflected back at me. Playground had understood that the corporate jargon was supposed to collide with fantasy conventions, and it had connected the joke to RPG skills such as Heroics, Confidence, and Bureaucracy. I was more impressed by Red Tape Hero than Mystic Dragon Glide, despite its considerably less polished look.
It also exposed what I think is the much larger problem with the idea of completely AI-generated games. A few funny lines can establish a comic premise, but a genuinely funny RPG needs dozens of characters with distinct voices, jokes that develop over time, careful pacing, and writers who understand when to stop making jokes altogether. A great RPG also needs quests that intersect in unexpected ways and decisions whose consequences have been deliberately considered. Maybe I could do all of that on my end, but melding it successfully with actual game software seemed more difficult with AI than by collaborating with talented humans.
Spark takes the tedium out of a library card application. (Image credit: Google Playground)Why developers don't need to worry just yetThe best games are full of decisions that somebody made for a reason. A strange empty room might be there to build tension before a boss fight. A frustrating section might deliberately make the next ability feel liberating. A musical theme heard near the beginning can return 30 hours later because a composer knows exactly what that memory will mean to the player.
Those choices come from designers thinking about an experience that unfolds over time. Generative AI can produce variations based on patterns it has learned, but generating more content is different from having something particular to say with it. Playground dramatically lowered the technical barrier between my imagination and something playable, which is genuinely exciting. It gave me a way to experiment with game ideas I otherwise could have done little more than write down.
I can easily imagine using tools like this to prototype a mechanic or otherwise become part of a real game development flow. I can't believe most people will choose a wholly AI-generated game over the next carefully crafted game from developers and designers working hard to build the next hit video game. The more sophisticated these systems become, the more convincing their imitations will probably get, but technical sophistication does not automatically produce good taste or creative surprises.
My games were impressive precisely because I knew how little effort was required to create them. And they were so riddled with issues, from mechanical confusion to plot holes, that it would take quite a lot of prompting work to make them truly playable for more than a few minutes anyway. It was telling that those I let try out the games, who didn't see my initial prompts, all said the most interesting elements of the RPG to them were the bits I had written into the prompt to begin with. That's why I'll keep going to professionally made games when I want something that can genuinely entertain me.
It’s pretty unusual to find yourself at a cybersecurity event playing basketball in Times Square. Add in NBA legend Shaquille O’Neal as the host, and you'd be describing the stuff of dreams.
Yet that’s what a lucky crowd got at NordVPN’s latest event on Thursday. The provider went big on online defence with its ambassador Shaq on hand to teach Americans about digital threats.
At the event, professional basketball players also challenged members of the public to slam dunk, echoing how the VPN’s next-generation antivirus intercepts and blocks malware and phishing attempts before they can even reach a user’s device.
(Image credit: NordVPN)More than shots blockedThe NBA Hall of Famer, entrepreneur, and philanthropist has been NordVPN’s official ambassador since September. The collaboration focuses on raising awareness of digital threats while also boosting NordVPN’s marketing efforts as the company transitions from a simple VPN to a comprehensive, all-in-one security suite.
A key part of this is NordVPN's 'Next Gen Antivirus', which scans 12 million unique URLs daily and blocks an average of 130,000 malicious pages. It blocked nearly 5 million malware attempts in the US in the first months of 2026, NordVPN says.
At the event, the VPN drew parallels with sport and digital security, using pro-basketball players to showcase what real defence in action means and presenting malicious activity as slam dunks on a court.
The audience was invited to try to score against experienced players, only to have professionals with years of experience in the field block their attempts, much like how NordVPN defends against digital risks.
But why?The poetic parallels are timely, as NordVPN recently warned that Americans are suffering from a delulu-clash over their cybersecurity knowledge.
Frighteningly, recent research by NordVPN found that 71 per cent of respondents believe that common sense is simply enough to navigate digital threats.
What’s more, almost three-quarters of respondents believe they are perfectly capable of spotting online scams in spite of evidence to the contrary.
Findings revealed that 74 per cent of Americans were unable to spot a fake URL and 82 per cent failed to recognise a fake CAPTCHA, while less than half correctly identified a phishing email disguised as a job recruitment message.
(Image credit: NordVPN)More than half – 51 per cent – reuse the same password or similar passwords across different accounts. Unsurprisingly, it is the users who are most confident in their own abilities who tend to do this, says NordVPN.
It is therefore even less surprising that 73 per cent of Americans have already fallen victim to a scam recently, with nearly a quarter having suffered or being at risk of suffering a financial loss.
Shaq’s profile arguably makes the case better than any cyber-security expert: “These scammers are getting smarter, and sometimes all it takes is one click or sharing one piece of information. You don’t have to be a cybersecurity expert. You just have to stay alert, make smart choices, and use the right tools to protect yourself.”
Check out the event here- Control Resonant composer Petri Alanko explains the process of developing Dylan's theme song, which is Jesse's theme played backwards
- He explains how Jesse's theme was more about power, while Dylan's is "a source of growth"
- Alanko says, "Dylan’s is more upward-reaching, as if it was asking for permission for Dylan’s existence"
Control Resonant composer Petri Alanko has shared his process for developing Dylan's theme song, compared to how he designed Jesse's, his sister and the main character of Control.
In the same interview with TechRadar Gaming, where Alanko explained how he created the game's eclectic soundtrack for Remedy Entertainment, the composer said the method for writing Dylan's theme was distinct from Jesse's, because their origins start in different places.
Without going into spoilers, Alanko explained that their paths are different, but, "Due to their roots, they actually share the same theme - but Dylan’s is essentially Jesse’s theme backwards."
"It first appeared already in the original Control at a few points, but here I wanted to slap the gamer’s face properly with it," Alanko said. "They share the DNA, so the theme’s shared too. What was Jesse’s power theme is, for Dylan, a source of growth; it appears in different harmonies across the game, and depending on the events, the harmony root is changed under the melody a few times."
He added, "Jesse had her power theme played in direct conjunction with her position only in the ending, whereas Dylan’s appears all the way, texturizing his path from nothing to a superhero."
Alanko continued, explaining that "The scale of the protagonist is larger in Control Resonant," and while Jesse's theme "landed" and was "grounded" in a way that was "a 'THIS IS ME' statement," he said, "Dylan’s is more upward-reaching, as if it was asking for permission for Dylan’s existence."
"From the very early points of development, I had the feeling Dylan was asking for a justification for his release and his freedom," he added. "Dylan is an involuntary hero; although he chooses to become one, he just doesn’t know it in the beginning.
"By grabbing a walkie-talkie from a corpse hanging mid-air after having come out from the building is his knowingly made decision: 'I choose this.' He chose to walk that path, and I wanted to pinpoint and emphasize the attempt by creating a few very driving percussion patterns through the story."
While Jesse and Dylan have two different juxtaposing themes, Resonant also features a blended theme for both called 'Sibling Theme.' Alanko shared that the game's end credits track, 'The One I Once Knew,' "was easily one of my favourites," as 'Sibling Theme' "wouldn’t exist without it."
"We weren’t able to use any vocals with the 'Sibling Theme' as there was a metric ton of voiceovers happening, and we didn’t want to distract the gamer from the core feeling of the Broken Conduit, the place where 'Sibling Theme' is played through various devices and means," he said. "I had one of the music industry’s most beautiful voices appear on the end credit track, 'The One I Once Knew' (TOIOK), Amelia Jones, who recorded and edited her own vocals and sent me everything she had performed, and I didn’t have to change a thing from her selections. Awesome voice, awesome work ethic, awesome ear."
- The Trump administration is cracking down on visa programs to 'protect American jobs'
- Multiple top US tech companies have been hit by an H-1B and green card suspension
- Nine top US universities have also been subject to a suspension on international applications
The Trump administration is continuing its efforts to protect American jobs and crackdown on fraud by suspending Microsoft and Adobe alongside several major IT outsourcers from the H-1B green-card program and opening probes into nine universities.
“There has been no company in the United States, unfortunately, that has abused the system more than Microsoft,” Vice President JD Vance said.
Hours later, President Trump praised Microsoft CEO Satya Nadella and Elon Musk for their contributions to America. Nadella and Musk both previously held H-1B visas, and three other CEOs in attendance - praised by Trump - are immigrants.
Protecting American jobsVance has claimed Microsoft has laid off 6,000 American workers in 2025 while simultaneously taking on 6,300 H-1B temporary worker visas and almost 3,000 green cards.
To hire green-card workers, employers must file applications in line with the permanent labor certification (PERM), which requires employers to show the foreign hire will not hurt US jobs or wages. According to the US labor department Microsoft is the largest filer for PERM applications, filing more than twice the amount than the next largest tech company Apple.
Cognizant, Infosys, Tata Consultancy Services, Wipro, HCL Technologies, and Capgemini have also been suspended. "We will not accept any new or process any pending permanent labor certification applications involving these companies," said Labor Secretary Keith Sonderling.
Sonderling added that these companies had collectively filed applications for almost three million workers, with over 230,000 H-1B visas approved and more than 100,000 permanent labour certifications received.
Vance also accused some companies of posting job ads designed to be ineffective so that companies could point to the lack of applicants as justification for hiring foreign workers for lower pay.
Microsoft hits backMicrosoft has responded to Vance’s statements, explaining that “of the approximately 6,000 H-1B visa applications we submitted in the last fiscal year, 80% percent were to extend or change the status of existing Microsoft employees.”
The company statement added that the remaining filings were for “individuals already legally in the United States who decided to come work for us,” that make up just 1% of the company’s US workforce. Microsoft added that it pays employees “some of the highest compensation in the tech sector, and our wages are among the highest of all H-1B filings.”
“Microsoft succeeds as a global technology leader by developing the world’s best technology workforce. We do this by strengthening this country’s talent pipeline, hiring American workers, and attracting the best talent from around the world,” the statement concluded.
Top universities in the firing lineNine universities have also been caught up in the visa suspension, including Harvard, Yale, Stanford, Brown, and the Massachusetts Institute of Technology. Vance said an investigation is being launched to examine the misuse of exchange-visitor visas to undercut American wages, alongside investigations into whether foreign influence, improper financial relationships, and visas were abusing federally funded research.
Harvard has previously been targeted by the Trump administration over alleged misconduct by international students and alleged non-compliance with immigration law. The Department of Homeland Security subpoenaed the university to investigate these claims, which Harvard labeled "unfounded retribution".
According to Sarah Spreitzer, a vice president at the American Council on Education, “It could have an enormous economic impact on the whole US economy” (via Reuters) as international students spend around $40 billion a year while in the US.
Uncertainty over future university visa status could seriously affect international applications.
- The Stengrönska is an affordable new alarm clock from IKEA
- It can charge your phone and display temperature and humidity data
- For now it's only available in IKEA stores in Japan and China
On top of all its other home goods, IKEA has a new alarm clock for your consideration — and the gadget goes beyond the standard duties of telling the time and making sure you drag yourself out of bed in the mornings.
It's called the IKEA Stengrönska (via Notebookcheck), and it's wide and short and flat: 17 cm x 16 cm x 3.6 cm (6.7 inches x 6.3 inches 1.4 x inches). That's partly so you can put your phone on the alarm clock and use the Stengrönska as a wireless charger.
Two other cool party tricks that the device brings with it are temperature and humidity readings, so you can keep tabs on your bedroom environment and make sure everything is set up just right for the best sleep possible.
The screen comes with an adjustable backlight and shows the time in a 24-hour or 12-hour format, with the date and day of the week also on display. You can set up to three alarms, with volume settings you can configure as needed.
More well-beingUp to three alarms can be configured (Image credit: IKEA)There's an all-important snooze function here, though it seems to be fixed at nine minutes. If you know you absolutely have to get up at a certain time you'll need to do some quick math to work out how many nine-minute intervals you've got left.
Around the back we've got toggles for the alarms and the volume dial, as well as a USB-C port, so you can charge up a nearby gadget with a cable as well as using the top of the Stengrönska as a wireless charger.
IKEA is positioning it as a preferable alternative to using your phone for alarms and checking the time: "you can reduce your reliance on your mobile phone," reads the official blurb, which means "less screen time — more well-being!"
The only downside is that the device is only on sale in Japan and China for now (the Japan price is ¥4,999, about $32 / £24 / AU$45). We've asked IKEA about international availability, and will update this article if we hear back.
Raspberry Pi has announced another round of price hikes as the rising cost of memory continues to affect its popular single-board computers. For IT professionals, developers, and enthusiasts planning new projects, the higher prices make choosing the right hardware trickier than ever.
The 8GB Raspberry Pi 5 is currently listed at $199.95 on Amazon, but the CanaKit Raspberry Pi 5 Starter Kit Pro costs just $60 more. It includes the same 8GB board, along with a case, cooling system, storage, power supply, and cables.
8GB Raspberry Pi 5 board: $199.95
This single-board computer features a 2.4GHz quad-core Cortex-A76 processor, 8GB LPDDR4X RAM, VideoCore VII graphics, dual 4K HDMI outputs, USB 3.0, Gigabit Ethernet, Wi-Fi, Bluetooth, PCIe expansion, and microSD storage support.
Canakit 8GB Raspberry Pi 5 Starter Kit Pro: $259.95
This kit includes an 8GB Raspberry Pi 5, 128GB microSD card with Raspberry Pi OS, Turbine Black case, cooling fan, heatsink, USB-C power supply, two display cables, and card reader.
Because memory costs have risen steeply over the past two years, Raspberry Pi has been forced to increase prices to cover production expenses. Most recently, the price of the 2GB versions of the Raspberry Pi 4 and Raspberry Pi 5 were upped to $67.50 and $77.50 respectively.
The price increases have led to the company encouraging customers to think carefully about how much memory their projects actually require, and to consider older hardware, including the Raspberry Pi 3B, 3A+, and 3B+, where the additional performance of newer models isn't necessary.
The 8GB Raspberry 5 features a quad-core Arm Cortex-A76 processor running at 2.4GHz, 8GB of LPDDR4X memory, and a VideoCore VII GPU. It includes dual micro-HDMI outputs capable of driving two 4K displays at 60Hz, USB 3.0 ports, Gigabit Ethernet, wireless networking, and PCIe expansion support.
It sells for $199.95 on Amazon, and while that sounds expensive, I've found a better option. The Canakit Raspberry Pi 5 Starter Kit Pro kit costs $60 more and in addition to the 8GB Raspberry Pi 5, it includes a Turbine Black case, a low-noise cooling fan, a large aluminum heatsink, a USB-C power supply, two six-foot display cables, a microSD card reader, and a GPIO reference card. It also comes with a 128GB microSD card preloaded with the 64-bit Raspberry Pi OS.
Is the CanaKit bundle better value?For just $60 more, the CanaKit bundle gives you everything needed to power, cool, protect, and boot the 8GB Raspberry Pi 5 computer, plus the cables for connecting displays.
The CanaKit bundle won't suit every project. If you already have a compatible power supply, case, cooling solution, and storage, buying the board separately will be the better and cheaper option. Also, if you're planning to use NVMe storage, a specialized enclosure, or a custom cooling system, buying those components individually will be the way to go.
That said, for IT professionals and enthusiasts who want to start a new Raspberry Pi 5 project running without sourcing all the extras individually, the $259.99 CanaKit Starter Kit Pro is an easy recommendation.
- Microsoft is adding impersonation and deepfake detection to Teams in November 2026
- A third-party platform will be behind detecting AI-generated video and audio
- Attackers are still targeting voice phishing on Teams
Microsoft is adding two new security features to Teams designed to combat increasingly sophisticated impersonation attacks in an AI-first era.
First and foremost, Microsoft is opening up its platform to enable third-party deepfake detection in the hope of stamping out AI-generated video and audio.
The second of two important security features coming to the video conferencing platform warns users when meeting participants could be misrepresenting their identities to hopefully help participants validate their authenticity.
Teams will soon tell you if the person you're talking to is fake"Third-party detection solutions analyze meeting media for signs of synthetic or manipulated audio and video and send detection signals to Teams, enabling integrated in-meeting experiences and controls," the company wrote in a roadmap entry.
"When Teams detects a potential impersonation attempt, it surfaces warnings and risk indicators to help users recognize suspicious identities," another entry added.
While both are slated for a November 2026 launch, the finer details including which third-party platforms can support deepfake detection aren't yet public.
What we do know, though, is that Teams has become a hotspot for impersonation attacks, and AI has made it easier for criminals to exploit vulnerabilities. Microsoft has already been on a roll introducing other features like file extension blocking.
And the problem is very real – in a July 2026 report, Microsoft revealed a near 10x increase in weekly malicious Teams voice call attempts in just one year, and an 80% increase in voice phishing attempts.
Still, meaningful progress has been achieved and the company managed to cut phishing activity related to Tycoon2FA, a major phishing-as-a-service platform, by 92% in a year. Looking ahead, the company's roadmap is full of plenty of other Teams announcements, split into some new features and plenty more security updates.
The debate surrounding AI sovereignty may be unfolding at the governmental, boardroom and national media level, but these discussions are taking place at a distance from the people who use and rely on AI in the day-to-day.
Governments debate regulation, while technology companies consider where to build and host their models. Founders and investors assess geopolitical risk, infrastructure and access to computing power, while regulators consider how AI systems should be developed and deployed. For people who use AI every day, like students, changes in AI sovereignty and regulation can affect whether the tools they rely on remain available.
Today’s students can be dependent on AI while having little visibility into the infrastructure and policy decisions that determine whether they can continue using it. The digital sovereignty debate has the potential to become an undeniable accessibility barrier for students.
Digital sovereignty casts a shadow over students’ access to AI toolsThe European Union has a history of depending on technology and infrastructure from outside the economic and political bloc. More than 80% of the technology used in Europe and around 70% of its cloud computing comes from non-EU countries. AI adoption has increased Europe’s dependence on other countries, with the United States and China accounting for the overwhelming majority of global AI computing infrastructure.
This year, Europe has made strides to regulate AI usage, which by necessity means regulating foreign corporations. This kind of regulation can easily end up affecting which services students can access. The regulatory objective is understandable. Powerful AI systems create genuine questions around safety, accountability, privacy and intellectual property, but the consequences for daily users can nevertheless extend beyond compliance.
Not so long ago, the US government restricted access to Anthropic's most powerful models, citing concerns over its cybersecurity applications. It was the first time that businesses and politicians in Europe had to face the reality that the US government can effectively cut off foreign access to American AI systems. The implications extend beyond any one LLM.
For students, that can mean a study tool works perfectly for a classmate in one country while being unavailable to another student sitting a hundred miles away.
If education systems become dependent on AI services developed and controlled elsewhere, a change in regulation, commercial strategy or international relations could affect the availability of tools students have come to regard as part of their everyday learning environment.
Students could face immediate exposure if AI regulations shiftAI in education is expanding rapidly. AI tools are being embedded into tutoring, content creation, assessment, study assistance and interactive learning. Just like with any widely-adopted digital tool, however, dependency on a single product from a single company poses huge potential issues.
Going back to 2021, an albeit brief global outage that affected WhatsApp had devastating, widespread consequences, from cutting off vital telemedicine from migrant refugees in Mexico to disrupting livestock farming in Pakistan. It was clear at the time that overreliance on a single technology platform can massively impact life for people around the world.
The same is true for students using AI tools that rely on a single model or are otherwise vulnerable to a regulatory change. A student who uses an AI-powered study platform every day may have no idea whether the service depends on one model or several. They may not know whether their data is stored locally or internationally. They may not know whether the provider has a contingency plan if a model becomes unavailable.
The issue becomes particularly important as AI tools move from being occasional conveniences to becoming embedded in study routines. Imagine a student preparing for an exam who has spent months using an AI tutor to explain concepts and generate practice questions. If the underlying model suddenly becomes inaccessible in that student's country, it can affect the student's established way of learning at a critical moment in their educational journey.
Designing AI educational tools for resilienceA resilient AI education platform needs to consider what happens when a particular model becomes unavailable due to regulatory changes or widespread outage.
One approach is model diversity. Because different AI models have different strengths, a platform can end up using one model for a particular type of reasoning, another for optical character recognition, and another for audio processing. Model diversity is therefore usually driven by a need for better performance when tackling different educational tasks.
Diversifying models can also provide resilience. If one model becomes unavailable, a platform using several models may be able to redirect certain workloads. Backup workflows can provide an additional layer of continuity, although switching between systems can take time and the alternatives may not always provide identical capabilities.
Going EU-first (and what’s next for students and AI literacy)It’s called the Brussels effect. From sustainability regulations to consumer right to repair, the European Union’s size and economic weight often means that regulations within its borders often shape corporate behavior without them as well.
Taking an EU-first approach to an AI education platform means locating the majority of the platform's data within the European Union, supporting considerations around data sovereignty, privacy, and regulatory compliance. Some reliance on services and infrastructure originating outside Europe may remain unavoidable, particularly in a technology ecosystem where many of the leading AI providers are headquartered in the United States.
An education platform that depends entirely on one external model provider effectively inherits that provider's availability and exposure to regulatory changes. A platform with several model options and fallback processes has greater room to adapt.
By aligning that platform’s data management practices with the most stringent global regulations (which currently happen to be the EU’s framework), educational AI companies can do a lot of the necessary work to maintain access to critical AI tools for their students.
From the students’ side, there needs to be a new chapter when it comes to AI literacy in education, which should include a basic understanding of AI dependency.
Students should be encouraged to ask which AI systems power the tools they use; what happens if one of those systems becomes unavailable; where their data is stored and processed; and could regulation in another country affect their access. They don’t need to become experts in cloud infrastructure or AI policy, but do need to understand that an AI application is part of a wider technological ecosystem.
Students in the AI era will depend on systems whose underlying architecture they cannot see. The education sector therefore has a responsibility to make those dependencies more visible and mitigate them where possible. AI literacy should extend beyond knowing how to prompt a model or assess its answer. It should include an understanding of where AI comes from, what it depends on and what happens when access is disrupted.
We've featured the best online learning platform..
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit


