It’s possible that I shall make an ass of myself. But in that case one can always get out of it with a little dialectic. I have, of course, so worded my proposition as to be right either way (K.Marx, Letter to F.Engels on the Indian Mutiny)
Monday, August 10, 2026
The Hamiltonian AI Curse: How American Tech Learned To Make Its Losses Everyone Else’s Problem – OpEd
The AI industry is pursuing a Hamilton-style strategy of converting commercial vulnerability into political protection by aligning its survival with national security and recruiting public capital through massive IPOs.
Persistent losses, enormous infrastructure commitments and heavy insider selling indicate that leading AI firms remain far from sustainable profitability while shifting speculative risk onto retail investors and, potentially, taxpayers via federal-backed projects such as Stargate.
The resulting arrangement risks a concentrated financial shock once market discipline reasserts itself, with the costs falling primarily on ordinary investors rather than the early private and institutional beneficiaries.
The genius of his 1790 debt assumption was not fiscal, it was psychological. When he forced the federal government to absorb the states’ war obligations at par, speculators who had bought Revolutionary War certificates at ten cents on the dollar suddenly held federal bonds worth face value. They had not bought America out of patriotism. They had a position in it. And men with positions become lobbyists, become power brokers, become the most passionate voices in any room insisting that the state cannot be permitted to fail—because their net worth is now coterminous with its survival. Jefferson called this arrangement a “corrupt squadron.” He was right. Hamilton won anyway, and the corrupt squadron governed American finance for forty years.
The artificial intelligence lobby did not read Hamilton’s papers. It arrived at the same design through sheer commercial necessity. When you cannot survive market discipline, you buy political immunity instead. This is not a scandal, it is a strategy—the oldest and most durable in the history of American capital. The novelty in 2026 is the scale at which it is being executed, and the efficiency with which ordinary investors are being recruited to underwrite the exit.
The Baptists and the Bootleggers
To understand the mechanics of this maneuver, one must look to the classic economic theory of “Baptists and Bootleggers.” Coined by economist Bruce Yandle, the model explains how durable regulations are rarely passed by one group alone; they require an unspoken, parallel partnership. The “Baptists” provide the moral, public-facing crusade (such as banning Sunday alcohol sales to preserve the Sabbath), while the “Bootleggers” quietly reap the financial windfalls of the resulting market restrictions (such as monopolizing illegal Sunday sales). Both lobby for the exact same law, but while one seeks virtue, the other seeks rent.
Sam Altman’s regulatory pivot between 2023 and 2025 is a masterclass in this dynamic. In 2023, he appeared before Congress performing existential dread—genuinely afraid, he insisted, of the technology he was building. He requested federal licensing. He did so not because he feared AI, but because federal licensing is a classic bootlegger’s moat. It imposes compliance costs large enough to kill startups and small enough for incumbents to absorb, locking the industry’s hierarchy into statute. The sincere “Baptists” of the era—worried ethicists, safety researchers, and citizens terrified of job displacement—provided the necessary moral cover, pleading for the very regulations that would entrench the monopoly.
But the Bootlegger cannot survive on regulatory moats alone if the underlying business model is a cash-incinerating furnace. Thus, the performance had to shift. By 2025, regulation would suddenly “slow America down.” The moral argument was repackaged from safety to national security. The new “Baptists” were geopolitical hawks and defense planners who sincerely believed American dominance depended on state-backed computation. The “bootleggers” had their cue. Phase one was getting the government to protect them from the market; phase two was getting the market funded by the government.
The result is Stargate—a $500 billion commitment to AI data center infrastructure, backed by federal land, subsidized energy, and the Pentagon’s strategic imprimatur. Once federal ambition is physically instantiated in OpenAI’s server farms, the question of whether these systems are commercially viable becomes irrelevant. It is now a matter of national security. This is Hamilton’s Bank of the United States, reissued with a ChatGPT interface. When the bet sours, the taxpayer is already in the room.
Oracle has become the 1790 bondholder who bought in at par and cannot admit it. The company burned through $55.7 billion in capital expenditures for fiscal 2026, and was just forced to announce a terrifying $95 billion target for 2027 to build infrastructure for clients who have never generated a profit. Its credit default swaps now trade at 2009 crisis levels. Major banks have started refusing to finance its data centers—not from timidity, but from reading a balance sheet. Oracle has bought so deeply into the narrative that admitting the narrative is wrong would be more expensive than continuing to construct. The Arithmetic Nobody Is Allowed to Say Aloud
OpenAI loses nearly $3.00 for every dollar it earns. Its own audited financials, leaked in June 2026, revealed a catastrophic $38.5 billion net loss in 2025 alone on just $13.1 billion in revenue, projecting $74 billion in operating losses by 2028 before a profitability horizon that migrates perpetually toward 2030. The company has signed $1.4 trillion in data center commitments over eight years. It raises capital not because investors see a path to profit but because failing to raise capital resets the $852 billion valuation to something resembling reality—which collapses the Microsoft AI narrative, which exposes Oracle’s $50 billion infrastructure bet as obviously deranged, which makes the entire arrangement—vendor, investor, customer, and creditor compressed into the same corporate body—visible for what it is.
Palantir trades at 120 times sales—the highest multiple in the S&P 500. Its insiders made 243 share disposals against just a single purchase across a six-month window. CEO Alex Karp sold over $2 billion in personal holdings while investor presentations described his company as the defining software business of the century. Over $13 billion in stock was sold across Nvidia, Palantir, Micron, and Broadcom combined, of which Nvidia’s specific recent insider share was $3.3 billion, with a massive acceleration of disposals concentrated in the first half of 2026 alone. The hyperscalers issued a record-shattering $244 billion in bonds in just the first half of 2026 to fund GPU purchases their operating revenue could not justify. Each of these numbers is a sentence, and every sentence ends the same way: the people with the best information are leaving.
SpaceX priced its Nasdaq debut on June 12 at $1.77 trillion—the largest IPO by capital raised in American history. Anthropic filed confidentially on June 1, carrying a $965 billion valuation off a $65 billion Series H, briefly making it the most valuable AI company in Silicon Valley. OpenAI targets a trillion-dollar listing for Q4. While Anthropic is nearing its first profitable quarter off a staggering $47 billion revenue run-rate, the group as a whole is preparing to absorb close to $300 billion from public markets within eighteen months, driven largely by the massive, structural insolvency of OpenAI. The combined implied equity value approaches $4 trillion—roughly the GDP of Germany.
The South Sea Company’s directors also sold their shares before the prospectus reached the streets. They also had government contracts. They also described their enterprise as a civilizational transformation. The company collapsed in 1720 and took half of Britain’s private wealth with it. What saved the British state from full contagion was that the Bank of England was not yet irreversibly implicated.
This is how the hand-off works. The venture funds that seeded these companies at pennies per implied share are exiting through the IPO window. The sovereign wealth funds that participated in the Series rounds are exiting. Microsoft will manage its exposure through the narrative pivot from “OpenAI is our future” to “Azure is the platform regardless of who wins the model race.” The retail investors who buy the trillion-dollar listings will hold the remainder. They will do so cheerfully, having been told—correctly—that they are participating in history; they are, just not the history they were sold. When the Curse Lands
The Panic of 1819 arrived when the Second Bank contracted credit after years of expansion. When it hit, it hit everything simultaneously, because Hamilton’s design had tied everything together. Farms foreclosed across the frontier. Merchants failed in the cities. Unemployment spiked through a republic that had spent a decade being told the system was self-reinforcing. It was self-reinforcing, until credit tightened, and a decade of artificial cohesion became a decade of concentrated catastrophe.
The only real question is how deep the roots go before the storm arrives. If Stargate’s federal commitments are genuine, if the Pentagon’s computational ambitions are wired to OpenAI’s infrastructure, if the 2026 IPO window successfully transfers speculative risk into a few million retail portfolios—then 1819 is the optimistic comparison.
Hamilton won his argument with Jefferson. His creditor class flourished for a generation. The frontier farmers who paid for the Panic in foreclosures and collapsed wages were not his constituents, and they did not write the histories.
The historic IPO window of June 2026 was the debt assumption, repackaged for the streaming era. The bondholders got out. The public bought in. And when the arithmetic finally says what the lobbyists have spent $226,000 a day to prevent it from saying—which it will, because arithmetic is the one institution in Washington that cannot be hired—the architects of this system will be managing their endowments. The farmers always pay.
About the author: Hamoon Soleimani is an Iranian civil engineer, quantitative analyst, and independent researcher. Rooted in the Austrian School, classical liberal tradition, and public choice theory, he explores the nature of state power, political economy, and individual liberty.
About MISES The Mises Institute, founded in 1982, teaches the scholarship of Austrian economics, freedom, and peace. The liberal intellectual tradition of Ludwig von Mises (1881-1973) and Murray N. Rothbard (1926-1995) guides us. Accordingly, the Mises Institute seeks a profound and radical shift in the intellectual climate: away from statism and toward a private property order. The Mises Institute encourages critical historical research, and stands against political correctness.
Q&A: Is robotics replacing AI as the next investment darling?
Humanoid robot Alter-Ego is designed to perform basic tasks to free up healthcare workers – Copyright AFP MARCO BERTORELLO
Growing up in the ‘80s and watching the Rosey the Robot clean, cook and fold laundry for the Jetson family, the thought of having a personal robot maid was nothing more than science fiction. Then, everything started to change in 2002, when we were introduced to the iRobot Roomba vacuum. Today, we have “smart” appliances/homes, autonomous drone delivery and self-driving cars. So, what’s next for personal home robotics?
Digital Journal sat down with one of the leading experts in robotics, Andrew Kang, CEO of RoboStrategy (NASDAQ BOT), the first publicly traded fund focused exclusively on robotics and physical AI, to discuss where the robotics industry stands today, and why physical AI could reshape nearly every sector of the economy.
Digital Journal: Many people view AI software as the next technology revolution. Why do you believe robotics deserves equal attention?
Andrew Kang: Robotics represents AI moving from the digital world into the physical one. While software has already transformed knowledge work, robots have the potential to automate physical labour across industries. Unlike many physical technologies that solve a single problem, robots can automate physical work wherever labour is required. In many ways, robotics is productizing physical labour, much like cloud computing productized computing power. Every economy depends on people performing physical tasks, so the addressable market extends far beyond traditional industrial automation. In 2025, Morgan Stanley reported that the global market for humanoid robots could reach $5 trillion by 2050. As AI continues to improve, robots will become capable of handling increasingly complex work, dramatically expanding the number of use cases. Today the sector is still relatively small compared with other technology markets, but innovation is happening rapidly among private companies. That combination of early-stage development and enormous long-term opportunity makes robotics one of the most compelling areas to watch over the next decade.
DJ: When do you expect robots to become a common part of everyday life?
Kang: As with all new technologies, widespread adoption will likely happen gradually rather than all at once. Industrial deployments are already scaling, particularly where labour shortages exist, and we will see exponential growth there in the coming years. I expect consumer adoption to take only slightly longer, primarily because robots operating around families require higher safety standards and far greater production capacity. However, I expect robots to start becoming more commonplace in homes, businesses and public settings as early as 2030. Meanwhile, the next several years will focus on scaling manufacturing and refining the technology.
DJ: What are the biggest technical hurdles standing between today’s prototypes and large-scale deployment?
Kang: Software continues to improve rapidly, but manufacturing remains one of the biggest bottlenecks. Producing millions of robots requires supply chains that don’t yet exist at that scale. Components such as actuators, sensors and specialized mechanical systems must be manufactured reliably and economically in enormous volumes. Building that industrial infrastructure will take time, but it’s a challenge measured in years rather than decades.
DJ: What characteristics do you look for when evaluating early-stage robotics companies for investment?
Kang: Our first step is to determine whether the market opportunity is large enough to support the business that is likely disruptive and transformational. Then, since revenue is usually non-existent at that stage, the next focus would be on the quality of the founding team. It is critical to study founders’ track records, their ability to recruit exceptional technical talent and whether they’ve consistently executed against ambitious goals. Those qualities often prove to be stronger indicators of long-term success than any short-term financial metrics.
DJ: Which industries do you believe will adopt robotics first, and why?
Kang: The earliest large-scale adoption will likely occur in industrial environments where robots perform repetitive, well-defined tasks. Today’s AI models are becoming increasingly capable, but they’re still most effective when operating within structured settings. Factory work, warehouse operations and manufacturing often involve repeating the same motion thousands of times, making them ideal applications for robotics. As AI models become more generalized and capable of handling greater complexity, robots will gradually expand into healthcare, hospitality and eventually everyday household tasks.
DJ: Looking ahead five years, where do you see the greatest opportunities within robotics?
Kang: Robotics is unique because it has applications across virtually every industry. AI software continues to grow rapidly, but physical AI hasn’t yet experienced the same level of commercialization. Robots essentially transform physical labour into a scalable technology platform, opening opportunities in manufacturing, logistics, healthcare, energy, hospitality and even space exploration. Because the potential use cases are so broad, we’re only beginning to understand how significant the market could eventually become.
DJ: Defense spending on autonomous systems is increasing around the world. How do you see military demand influencing robotics development?
Kang: Defence will undoubtedly become an important application for robotics because governments are naturally interested in technologies that strengthen capabilities. At the same time, like many innovations, many robotics functionalities are inherently dual-use, meaning they can serve both civilian and military purposes. While commercial markets such as manufacturing and consumer applications remain enormous opportunities, companies should recognize that government interest will likely accelerate development in certain technologies, even if that wasn’t their original intention.
DJ: Which areas of robotics do you believe remain the most underserved today?
Kang: Industrial robotic arms and collaborative robots represent a major opportunity, particularly if countries like the United States want to expand domestic manufacturing. Not every task requires a humanoid robot capable of walking. Many valuable jobs are stationary, whether in factories, laboratories, hospitals or commercial kitchens. Developing flexible robotic systems that can automate these environments could have an enormous economic impact while helping manufacturers address ongoing labour shortages.
DJ: Our final question… If you had a robot in your home, what would you name it?
Kang: Charles. That sounds like a good name for a butler-bot!
Google DeepMind co-founder Demis Hassabis is transitioning into a new role that’s more focused on “long-term strategy” – Copyright AFP/File Karl Mondon
Google’s head of AI, Demis Hassabis, will step down from his current role to become Alphabet’s chief scientist amid a reshuffling at DeepMind that will also include a key engineer’s departure.
Hassabis will take on two new titles, Alphabet announced on Wednesday: chair of DeepMind and chief scientist of Alphabet.
The change “will allow me to focus on long-term strategy, and accelerating scientific breakthroughs, including leaning into my work at Isomorphic to help cure disease,” Hassabis wrote in a social media post.
Isomorphic Labs is an AI-powered drug discovery lab that spun out from DeepMind in 2021. In 2024, Hassabis won a Nobel Prize in chemistry.
As part of the shake up, DeepMind’s chief technology officer and chief AI architect Koray Kavukcuoglu will become the division’s senior vice president and oversee its operations including the development of Google’s flagship frontier models and products which are known as Gemini.
Longtime Google engineer Jeff Dean is also leaving the company after nearly three decades to “try something new, and we’re excited to support him in that,” Google CEO Sundar Pichair said in a blog post announcing the news.
Hassabis co-founded DeepMind in 2010, and four years later, Google bought the research lab for $650 million, according to reports at the time. His co-founder, Mustafa Suleyman, is currently the chief of Microsoft’s AI segment.
Google is competing for customers alongside other major AI developers including Microsoft, OpenAI, Anthropic and Meta, as well as DeepSeek and Moonshot in China.
The industry is also chasing a theoretical milestone known as advanced general intelligence (AGI), which is a point when AI software matches the capabilities of human thinking.
“I’ve been working towards AGI my whole life and now, like many of you, I feel it is close at hand,” Hassabis wrote in Wednesday’s blog post.
“With this backdrop, I’ve decided that now is the right time for me to hand over my day-to-day operational responsibilities at (Google DeepMind), so that I have the time and space to focus on the big picture and help influence what is to come,” Hassabis continued.
Observers have been waiting for Google to announce a more powerful version of its AI model, called Gemini 3.5 Pro, which was supposed to launch in June but appears to be delayed.
Its shares closed 4 percent down Wednesday afternoon.
The leadership changes come amid a wider brain drain at Google.
In June, a top AI and engineering executive, Noam Shazeer, left for OpenAI, while senior researcher John Jumper, who shared the 2024 Nobel Prize in chemistry with Hassabis, jumped to Anthropic.
Why human approval is not enough: The growing need for AI agent observability
OpenAI says it is building a ‘superapp’ that combines ChatGPT, a coding tool, online search, and AI agent capabilities – Copyright AFP SEBASTIEN BOZON
As artificial intelligence continues its rapid progression from chatbot to autonomous digital worker, a growing question faces enterprises: when an AI agent makes a decision, who is really in control? Many organizations assume that inserting a human approval step into an automated workflow creates sufficient oversight. A procurement recommendation, compliance action, customer response, or financial transaction is generated by an AI agent and then presented to a human for approval.
However, a growing body of AI governance experts argue that such approval checkpoints can create the appearance of control while offering little genuine oversight. If a reviewer cannot see what information the AI accessed, what rules it applied, what systems it interacted with, or what actions it has already taken, then the human approver may become little more than a ceremonial signatory.
As AI agents become increasingly capable of executing complex, multi-step workflows, the concept of agent observability is emerging as a critical component of enterprise governance.
The illusion of human oversight
Organisations have long relied on human review as a risk-control mechanism. Whether signing off deviations in pharmaceutical manufacturing, approving financial transactions, or authorizing changes to IT systems, human checkpoints are intended to ensure accountability and judgment. The challenge with modern AI agents is that they often operate across multiple systems simultaneously.
An agent tasked with processing a customer complaint may search internal documentation, access customer relationship management databases, generate a proposed resolution, and update records. By the time a human reviewer receives a recommendation, significant activity may already have occurred.
Without visibility into the decision process, the reviewer may only see a summary and a request for approval. This creates what governance specialists increasingly describe as an accountability gap. The human remains responsible for the outcome but may lack the evidence necessary to evaluate whether the recommendation is correct. How AI agents differ from traditional software
Traditional software applications generally follow predictable rules. Input data enters a defined process, producing an expected output. AI agents are fundamentally different.
Agents are designed to reason, plan, choose tools, retrieve information, and adapt their behaviour according to objectives. Microsoft’s guidance on agentic AI describes agents as systems capable of independently determining which actions are required to complete tasks rather than merely responding to prompts. Microsoft’s Agentic AI framework emphasises planning, memory, tool use, and autonomous execution capabilities.
As a result, understanding the final recommendation alone may not be sufficient. This is because organisations need to understand what data was accessed, which systems were queried, and what prompts or instructions were followed, among other things. What is AI agent observability?
Observability is not a new concept. IT teams have long used observability tools to monitor system performance, network traffic, and application reliability. Agent observability extends this principle to AI decision-making. Instead of simply measuring system uptime or execution speed, agent observability provides a detailed audit trail of an agent’s behaviour.
In effect, observability creates a transparent record of how the agent reached a conclusion.
This enables human reviewers to challenge, validate, override, or escalate decisions when necessary. Without such information, approvals may become little more than administrative formalities.
One of the biggest governance risks associated with AI deployment is the potential for reviewers to become passive approvers. This phenomenon is sometimes referred to as automation bias, where humans place excessive trust in automated recommendations. Research by the U.S. National Institute of Standards and Technology (NIST) highlights the importance of human oversight and understandability within trustworthy AI frameworks. Organizations are encouraged to ensure users can appropriately supervise AI systems rather than simply accepting recommendations at face value.
A reviewer presented with a concise recommendation may be inclined to approve it, particularly when workloads are high and time pressures exist.
Paradoxically, the presence of a human checkpoint can create a false sense of security for executives, auditors, regulators, and stakeholders. The organisation can state that “a human approved the decision” while overlooking whether the individual had sufficient information to provide meaningful scrutiny.
The challenge facing enterprises is not whether AI agents should be autonomous.
In many cases, autonomy delivers substantial business benefits through increased productivity, faster decision-making, and improved operational efficiency. Instead, organisations must determine which decisions require full automation or human review. In this context, not every decision carries the same level of risk.
For example, an AI agent scheduling meetings may require minimal oversight whereas an AI agent modifying financial records, approving suppliers, updating quality documentation, or processing healthcare information may require extensive governance controls. This is where escalation thresholds matter the most and organisations need predefined criteria that identify when an agent must pause and seek additional human involvement. Such thresholds help ensure that human involvement is reserved for situations where judgment genuinely adds value.
The issue is particularly relevant for highly regulated sectors. Pharmaceutical companies, for example, operate under strict expectations surrounding data integrity, traceability, auditability, and documented decision-making. For instance, a quality assurance professional would not normally approve a manufacturing deviation without reviewing supporting evidence. Similarly, financial organizations require transaction records before authorizing significant movements of funds. The same expectations should increasingly apply to AI agents.
If an agent recommends a corrective action, supplier approval, compliance determination, or process change, reviewers should be able to see the evidence trail supporting that recommendation. In many respects, agent observability resembles traditional audit trail requirements already familiar to regulated industries. The difference is that the audit trail now captures not just system activities but elements of machine reasoning and decision context.
Hence, the future of enterprise AI depends on trust. Trust does not emerge simply because a human clicks an approval button. Instead, trust develops when organizations can demonstrate transparency, accountability, and traceability throughout the decision-making process.
AI model captures how humans read, paving the way to personalised text and better augmented reality
Researchers now understand not just how our eyes move when we read, but also how we build meaning from text
Researchers at Aalto University, together with international partners, have developed the most accurate model yet of how humans read. The new model uses reinforcement learning, a type of AI used in robotics, to explain—and recreate—the choices readers make as they move through text.
‘For the first time we’ve used AI methods to understand—not just mimic—how people read,’ says Professor Antti Oulasvirta from Aalto University. In a study to be published on Monday, August 10, in Nature Human Behaviour, researchers say the model could power smarter Augmented Reality (AR) displays and tailor complex texts to different readers and everyday situations.
Earlier models learned from large datasets pairing text snippets with eye tracking data, then mimicked human behaviour, but they lacked true understanding of the content and didn’t generalise well across languages or contexts, explains Oulasvirta. In contrast, the new model follows the psychological mechanisms readers use to direct attention, revealing how understanding is built as the eyes move through words, sentences and paragraphs.
Understanding how human memory serves reading is the key to unlocking enormous potential for customisable apps, services or products, according to Oulasvirta.
‘We read all the time, yet throughout written history we have read texts that have been produced for mass use and not for an individual person and a specific situation,’ he says. ‘Now we are in a position to change that.’
How it works
The new model is guided by resource rationality—the idea that while reading, we constantly decide where to look next to improve our understanding as much as possible within the time available. Decisions about gaze allocation are made at three levels: word, sentence and text. They are influenced by factors such as a reader’s language, memory capacity and their vision and eye speed. For example, a fast reader with a good memory may jump briskly from one paragraph to the next, whereas a reader with a poorer memory is more likely to loop back.
‘Reading feels effortless, but your brain is constantly deciding where to look, what to skip, and when to backtrack—spending attention like a budget to maximize understanding,’ says Professor Shengdong Zhao from City University of Hong Kong.
The researchers added reader characteristics as parameters so that each could be adjusted, then let the model learn for itself the best strategy for directing attention.
‘We placed the model in a world with millions of texts. Then, using AI-based reinforcement learning, we trained it to optimise eye movements so that it truly understands what it reads,’ Oulasvirta explains.
As it reads, the model forms a condensed description of the text’s content. When a crucial word or clause is missing, the gaze can be directed to gather that information. The model’s understanding can be tested by asking what it retained from the text within the given time and constraints.
When the researchers compared the model’s attention-allocation decisions with real human eye-tracking data they found that its decisions mirrored readers’ behaviour. In practice, they had succeeded in building a model of an average reader that can be tailored to different reader profiles.
What’s next?
The development paves the way to new reading support tools and personalised text design. For example, the model could be used to enable smart glasses that pace and lay out on-screen text to fit the situation and the user’s needs, or to customise texts to suit users.
‘We could take the same source text—say, a convoluted piece of legal writing—and with little effort produce versions that are more comprehensible for different readers,’ Oulasvirta says.
The next step for the team will be to evaluate how the model can be used to help individuals suffering from dyslexia and low language proficiency.
‘We want to help users in real-time situations, for example, by designing text that helps drivers without distracting them,’ says Oulasvirta. ‘Now we have this new understanding of something that’s so central to our lives, it’s just a matter of exploring all the possibilities.’
In addition to Aalto University, the study involved researchers from The Hong Kong University of Science and Technology, City University of Hong Kong, and the National University of Singapore.
Hierarchical Resource Rationality Explains Human Reading Behavior
Article Publication Date
10-Aug-2026
Governor Hochul announces Empire AI Beta fully online as federal government takes inspiration from New York to launch state and regional AI infrastructure hubs
New York's Empire AI served as model for new national science foundation to build out regional AI research infrastructure
New York's New $40 Million Supercomputer Gives Researchers Across New York Access to World-Class AI Computing Power
New York's Empire AI Served as Model for New National Science Foundation To Build Out Regional AI Research Infrastructure
Governor Kathy Hochul today announced that Empire AI Beta is officially online, giving researchers at New York's leading public and private universities access to the most powerful academic research computer in the country and marking a major milestone in New York's effort to lead the nation in responsible artificial intelligence for the public good. As convened by Governor Hochul and consortium partners, the Empire AI initiative is already serving as a national model for public-interest AI use. As the federal National Science Foundation has announced a major investment to support regional AI infrastructure and shared research capacity through their new State and Regional AI Infrastructure Hubs initiative, Empire AI is already powering world-class research and serving academics, students and communities across the state.
"New York State built Empire AI to show that artificial intelligence can be developed for the public good and with Empire AI Beta officially online, New York is giving our researchers the most powerful academic AI research computer in the country," Governor Hochul said. "The National Science Foundation's new hubs embrace the same core principle behind Empire AI — when government, universities, philanthropy and industry come together, they can deliver outstanding results."
Empire AI Board Chairman Tom Secunda said, "Empire AI is showing the nation what dedicated partners across government, research institutions, and philanthropy can build together: a scientific asset no institution could create on its own, advancing the public good. Thanks to Governor Hochul's leadership and vision, New York is setting the standard for how the United States can build and maintain AI infrastructure by researchers and for researchers."
SUNY Chancellor John B. King Jr. said, "Empire AI Beta is a testament to Governor Hochul's leadership and the power of New York State higher education to lead the way in the use of AI to accelerate research that saves lives and strengthens our communities. Thanks to Empire AI, SUNY's researchers are making advances every day in fields like health care, public safety and emerging technologies, all while demonstrating responsible environmental stewardship."
Empire AI Research Computing Director Kiran Keshav said, "Turning on Beta is a major leap forward for Empire AI and for academic research across New York. Researchers who were once limited by access to computing power can now ask bigger questions, test more ambitious ideas and move faster from theory to discovery. From medical diagnostics and climate modeling to safer infrastructure and more trustworthy AI systems, this system will help New York's researchers do work that would not otherwise be possible."
State Senator April N.M. Baskin said, "Having the most powerful academic research computer in the country at the University at Buffalo is a tremendous achievement for Western New York. Empire AI will expand opportunities for students and researchers to lead groundbreaking discoveries while ensuring artificial intelligence is developed responsibly and for the public good. I'm proud that the University at Buffalo is at the center of this effort, helping shape the future of AI for the benefit of all New Yorkers as Empire AI continues to grow."
State Senator Jeremy Zellner said, "Innovation and responsibility go hand in hand. Empire AI shows that New York can lead the world in artificial intelligence by investing in public research, supporting our universities, and ensuring these technologies are developed in ways that benefit everyone. I applaud Governor Hochul for her leadership in making this investment and for putting New York at the forefront of AI innovation."
Assembly Majority Leader Crystal Peoples-Stokes said, "I am excited to see Empire AI Beta come online. New York has no shortage of challenges where Empire AI can offer analyzed solutions to address societal ills. With over 300 projects currently queued up, I look forward to seeing Empire AI in action through our partners in research and higher education and am confident in Empire AI's ability to help Governor Hochul, her administration and the State Legislature effectuate leadership for the greater good of New York State."
Housed at the State University of New York at Buffalo, Empire AI Beta is a $40 million NVIDIA-powered supercomputer that dramatically expands the computing power available to academic researchers across New York State. The system delivers an 11-fold increase in AI training capacity, a 40-fold boost in AI inference and an 8-fold expansion in data storage compared to Empire AI Alpha, the consortium's initial system launched in 2024. With over 300 research projects already queued up to use the system, Beta will accelerate work across fields including health care, climate science, advanced manufacturing, education, cybersecurity, public safety and other areas that directly benefit New Yorkers.
The launch of Beta represents the next major step in Empire AI's phased buildout. Alpha, the consortium's initial system made possible by philanthropic support from the Simons Foundation, has already supported more than 130 research projects and hundreds of researchers across New York. Beta now brings a transformative increase in capacity, while construction continues on Empire AI's permanent, full-scale Gamma facility at the University at Buffalo, which is expected to be completed by the end of 2027.
Once complete, the Gamma facility will also be the most efficient high-powered computing center in the nation. By integrating into University at Buffalo's buildout of a thermal energy network in a closed loop system, process heat from Empire AI will be used to heat buildings on campus, dramatically improving the school's ability to meet net zero goals.
Empire AI member institutions include the State University of New York, the City University of New York, Columbia University, Cornell University, New York University, Rensselaer Polytechnic Institute, the University of Rochester, Rochester Institute of Technology, the Icahn School of Medicine at Mount Sinai and the Flatiron Institute at the Simons Foundation.
The Governor announced Empire AI in her 2024 State of the State to create a state-of-the-art artificial intelligence center at the State University at Buffalo to be used by New York's leading institutions to promote responsible research and development, create jobs, and unlock AI opportunities focused on public good. With Empire AI Beta fully online, New York is already delivering on the computing power, institutional partnership and research capacity that NSF is looking to replicate.
Empire AI is backed by more than $500 million in public and private funding, and is made up of 10 member universities and research institutions. In May 2025, Governor Hochul secured funding to expand access for SUNY researchers at the State University of New York at Albany, State University of New York at Binghamton, State University of New York at Buffalo and State University of New York at Stony Brook, and support the addition of new members including the University of Rochester, the Rochester Institute of Technology, and the Icahn School of Medicine at Mount Sinai. They joined the seven founding members of Empire AI: SUNY, CUNY, Columbia University, Cornell University, New York University, Rensselaer Polytechnic Institute and the Flatiron Institute.
In her 2026 State of the State agenda, Governor Hochul proposed the launch of Empire AI Beta, which will accelerate Empire AI's performance to 11 times its former scale, making it the world's most advanced academic supercomputer. Governor Hochul also announced a record-breaking gift to the State University of New York at Binghamton to create the first independent university AI research center in the United States, the Center for AI Responsibility and Research at Binghamton University. The $30 million philanthropic gift, the largest academic gift in the university's history, is coupled with a $25 million research capital investment by SUNY.
About the State University of New York The State University of New York is the largest comprehensive system of higher education in the United States, and more than 95 percent of all New Yorkers live within 30 miles of any one of SUNY’s 64 colleges and universities. Across the system, SUNY has four academic health centers, five hospitals, four medical schools, two dental schools, a law school, the country’s oldest school of maritime, the state's only college of optometry, 12 Educational Opportunity Centers, over 30 ATTAIN digital literacy labs, and manages one US Department of Energy National Laboratory. In total, SUNY serves about 1.7 million students across its portfolio of credit- and non-credit-bearing courses and programs, continuing education, and community outreach programs. SUNY oversees nearly a quarter of academic research in New York. Research expenditures system-wide are nearly $1.5 billion in fiscal year 2025, including significant contributions from students and faculty. There are more than three million SUNY alumni worldwide, and annually one in three New Yorkers who earn a college degree is a SUNY alum. To learn more about how SUNY creates opportunities, visit suny.edu.
Average Canadian data breach cost hits record $7.11 million
Canadian organizations just posted the highest average data breach cost IBM has ever recorded for the country, and breaches involving trusted partners and vendors added more to the bill than any other factor.
A data breach in Canada now costs an average of $7.11 million, according to the 2026 IBM Cost of a Data Breach Report, conducted by Ponemon Institute.
After IBM converted the figures to U.S. dollars, Canada ranked fourth among the 16 countries and regions studied for breach costs, behind only the U.S., the Middle East, and Benelux.
Canadian breaches are getting larger, too. In IBM’s Canadian sample, the average number of compromised records rose 8% to 28,500, while the average time to identify and contain a breach rose 6% to 205 days.
Supply chain compromise, where a trusted vendor, contractor, or software partner is breached and gives attackers a way in, added the most to Canadian breach costs. When it was a factor, the average cost ran about $367,900 higher.
Security skills shortages added $314,500 and difficulty prioritizing threats added $311,300. Anyone who has tried to hire a senior security analyst in Canada probably saw the first one coming.
Those costs aren’t distributed evenly. Energy organizations are paying an average of $9.21 million per breach, the highest of any Canadian industry, followed by technology at $9.02 million and industrial organizations at $8.89 million.
A breach in those sectors can cascade across power grids, production floors, and the supply chains that connect them.
“Attackers are increasingly targeting sectors where disruption creates real operational and economic consequences, while also looking for the weakest link in the supply chain,” says Chris Sicard, IBM Canada security leader.
AI is now part of the attack and part of the target.
More than a quarter of Canadian organizations reported an AI-generated attack. Globally, 92% of organizations that experienced a breach involving one of their own AI models or applications lacked proper access controls on those systems and data.
The question of who governs AI systems and how is becoming a cybersecurity question as fast as it’s becoming a regulatory one. Who can access the models and the data?
AI is making attacks cheaper to launch. How much it costs to clean one up depends a lot on whether the target was using it too.
Organizations running AI and automation extensively in their security operations reported average breach costs of $5.5 million, compared with $8.91 million for those without. That’s a $3.41 million difference per breach.
They found and contained incidents weeks faster too, with the extensive-use group detecting breaches in 124 days and containing them in 57. Organizations without the tools took 154 days to detect a breach and 71 days to contain it.
The study might not establish that the tools caused the difference, but it does give technology leaders a useful test for the next security budget.
Which part of the breach timeline will this shorten?
Final shots
A vendor breach can become your incident when that vendor can reach your systems. The response plan should name who can cut access and who makes the call.
Before approving another AI security tool, ask which part of detection or containment it is expected to shorten.
Energy, technology, and industrial organizations should model what stops when systems go down. Breach costs belong in operating plans as well as security budgets.
Written by Jennifer Friesen Jennifer Friesen is Digital Journal’s associate editor and Calgary Bureau lead.
Gaza beekeeper starts again on rooftop amid ruins of war
The war in Gaza obliterated the territory’s beekeeping sector
– Copyright AFP Omar AL-QATTAA
Perched on the edge of a rooftop high above Gaza City’s bombed-out landscape, Ibrahim al-Dabba lovingly tends his community of bees, cultivating a rare source of hope among the ruins of the Israel-Hamas war.
Al-Dabba and his sons, donning protective netted hats and wielding metal bee smokers, gently inspect the neat rows of teeming hives.
As each frame of honeycomb is lifted out, hundreds of bees buzz lazily above the shattered urban neighbourhood — an incongruous setting for an apiary, but one the veteran beekeeper had little option but to choose.
Al-Dabba, who heads the Beekeepers Cooperative in the Gaza Strip, said the war which erupted in October 2023 obliterated the Palestinian territory’s beekeeping culture.
“We had more than 40,000 beehives and more than 450 beekeepers” before the war, he told AFP from the rooftop in Gaza City’s Tel al-Hawa neighbourhood.
“The situation was good, with more than 1,000 families making a living through the beekeeping sector,” he added.
“The war came and destroyed the beekeeping sector by more than 95 percent because most beekeepers were near the border areas,” he explained.
Al-Dabba himself lost some 400 hives, which he had kept in agricultural lands east of Gaza City.
He had no choice but to relocate his remaining 35 or so hives to the roof of a residential building, but admitted the situation was far from ideal.
“Bees are supposed to be in a safe, suitable agricultural area, but today the bees are suffering just as we are,” he said.
Al-Dabba explained that he could not move his bees back to their previous home because it had been destroyed and the land was now under the control of the Israeli military.
“We cannot approach or enter,” he said.
“Just as we are displaced in the streets, the bees are also displaced on the rooftops.”
– Hope despite suffering –
The devastating war in Gaza was triggered by Hamas’s October 7, 2023 attack on Israel, which resulted in the deaths of 1,221 people, according to an AFP tally based on official Israeli figures.
Israel’s retaliatory military campaign in Gaza has killed more than 73,300 people, according to the territory’s health ministry, which operates under Hamas authority and whose figures are considered reliable by the United Nations.
Despite the ceasefire in effect since October, bloodshed has continued in the tiny territory, with the Israeli military continuing to target Palestinians they say are militants.
Israel says it now controls more than 60 percent of the Gaza Strip, up from about half when the ceasefire took effect.
The humanitarian situation also remains dire, with hundreds of thousands of people living in tents and Israel tightly controlling the entry of all goods into the territory.
“We lack essential supplies because importing beekeeping equipment from the other side is not permitted,” Al-Dabba told AFP, saying he had approached external organisations and ministries in Gaza and the occupied West Bank for help.
Despite the suffering and challenges of relocating his hives to an unfamiliar landscape, Al-Dabba said he found “hope after seeing the bees coexist and adapt”.
“The bees now come and go and feel settled,” he said.
“So we hope that hope, goodness and living in peace and security will come, like in other countries.”
US unexpectedly loses jobs in blow to Trump’s economy claims
The US has had a ‘low-hire, low-fire’ labor market for months, with job seekers struggling to break into firms as turnover has remained relatively low in the world’s largest economy – Copyright AFP Patrick T. Fallon
The United States unexpectedly lost thousands of jobs in July, government data showed Friday, a blow to US President Donald Trump’s claims of leading an economic revival as his Republican Party gears up for crucial midterm elections.
The world’s largest economy lost 23,000 jobs in July, data published by the US Bureau of Labor Statistics showed, signalling potential labor market weakness after months of steady growth.
The unemployment rate ticked down to 4.1 percent, likely a result of falling labor supply as the US economy grapples with an ageing population and lower net migration.
Since taking office for his second term, Trump has unleashed a spate of policies aimed at reviving domestic manufacturing and curbing surging inflation.
Republicans face a stiff test in November’s midterm elections, with the state of the economy a key issue for Democrats who are seeking to wrest back control of both houses of Congress.
Friday’s data will also pose a question to the US Federal Reserve, which has been signalling it was preparing for a rate hike later this year.
– Implications for Fed –
In addition to the loss of jobs in July, the BLS revised down job growth in the previous two months by 103,000, showing the labor market to be less robust than previously reported.
Based on the new figures, job growth hit a peak in March before declining in the next three months and entering negative territory in July.
Analysts had expected further job growth, with economists polled by Dow Jones Newswires and the Wall Street Journal expecting 83,000 new jobs to be added in July.
The decline and revisions to the previous months will spark concern that the labor market may not be as strong as was previously reported.
The unemployment rate has remained relatively steady through choppiness in the labor market, due to the overall drop in labor supply.
Friday’s figures showed the labor force participation rate — a key metric — dropped slightly in July, after a sharp decline the month before.
Policymakers at the US Federal Reserve watch the labor market closely, as their dual mandate requires the Fed to deliver maximum employment while ensuring inflation remains at a long-term target of two percent.
The Fed has missed that target for five years, as inflation has battered US households since the pandemic.
Last month, the Fed held interest rates steady, but three regional Fed presidents dissented in favor of a rate hike.
“This morning’s report is a game changer in the sense that all of the recent focus has been on inflation and this report highlights the risks that are embedded in the labor market as well,” said Chris Zaccarelli of Northlight Asset Management.
“Before today, many were expecting that the Fed had no choice but to raise rates in order to fight stubbornly high inflation, because the job market was so strong, but this report shows that isn’t the case.”
– Retail trade losses –
Employment declined in the local government education and retail trade sectors, while it continued to grow in health care, the BLS statement said.
Retail trade also lost 19,000 jobs, with employment declining in warehouse retailers — firms like Costco, Sam’s Club and others that offer discounts for wholesale quantities of household goods — and general merchandise stores.
Employment in the financial activities sector continued its downward trend, losing 14,000 jobs. Employment in the sector is down 121,000 from its May 2025 peak.
The health care sector has buoyed the US labor market over the last year, with more Americans aging and requiring medical assistance.
In July, the sector added 22,000 jobs, but it was a slower pace than its average gain over the last year.
Average hourly earnings increased by 3.2 percent over last year, lagging inflation and therefore leaving workers with less income in real terms.
Q&A: How El Niño conditions and extreme weather is impacting on utilities
El Nino warms surface temperatures in the central and eastern equatorial Pacific Ocean
– Copyright AFP/File Sajjad HUSSAIN
AccuWeather meteorologists recently indicated that El Niño conditions are now established in the tropical Pacific, raising questions about how changing weather patterns could affect utilities and electricity consumers over the coming months.
To understand more about how weather is impacting utilities, Digital Journal spoke with Joe Matamoros, Chief Product Development Officer at S&C Electric Company. Matamoros considers extreme weather’s impact on utilities and grid resilience. Matamoros examines how managers of utilities are thinking about resilience investments, affordability and the role technologies like microgrids and battery storage are playing.
Digital Journal: How are utilities balancing investments in grid hardening and resilience with concerns about affordability?
Joe Matamoros: Utilities are increasingly focused on targeted investments that deliver measurable resilience improvements rather than relying solely on large-scale infrastructure replacement. Technologies that automate fault detection, isolate damaged sections of the system and restore service more quickly can often provide significant benefits without requiring a complete rebuild of the network. The conversation is shifting toward getting more value from existing assets while improving resilience. That approach helps utilities strengthen performance while remaining mindful of customer costs.
DJ: What evidence exists that grid modernization investments are improving reliability during extreme weather events?
Matamoros: Utilities that have deployed advanced automation and intelligent distribution technologies have shown an ability to limit the scope and duration of outages during major weather events. Florida offers a good example. In 2005, Hurricane Wilma, a Category 3 storm, left roughly 3 million customers without power for 18 days. Restoration efforts were prolonged due to the scale and spread of system damage. Recognizing this, the state’s largest utility made sustained investments in grid hardening, automation, and system intelligence across its distribution system.
In 2024, Florida experienced three landfalling hurricanes in a single season. By any objective measure, the 2024 hurricane season presented a more demanding test of the grid. Yet customer outcomes improved dramatically. Smart grid and automation technologies, along with physical infrastructure hardening, helped prevent nearly 900,000 customer outages across the three storms.
Restoration also progressed rapidly despite severe conditions. Power was essentially restored within one day after Hurricane Debby, within three days after Hurricane Helene, the strongest hurricane on record for the region, and within five days after Hurricane Milton, even as millions of customers across Florida experienced disruption.
These results demonstrate more than a faster response. They show that resilience translates into more reliable outcomes for customers.
DJ: Can distributed energy resources, microgrids, battery storage or other technologies help mitigate weather-related reliability risks?
Matamoros: These technologies can play an important role in improving resilience, particularly for critical facilities and communities that need access to power during prolonged outages. Microgrids and battery storage can provide localized support when parts of the broader grid are disrupted, while distributed energy resources add flexibility to the overall system. They become even more effective when combined with intelligent grid controls and automation. Resilience is often strongest when these resources complement, rather than replace, investments in the core grid.
DJ: Are there policy or regulatory tools available to help reduce customer cost impacts while maintaining reliability?
Matamoros: Regulators and policymakers can support investments that prioritize long-term resilience and reliability improvements and reduce the costs associated with repeated storm recovery efforts. Performance-based approaches, resilience-focused planning and funding mechanisms can help utilities make prudent investments while maintaining accountability. For example, the Infrastructure Investment and Jobs Act (IIJA) and DOE’s Grid Resilience and Innovation Partnerships (GRIP) program have provided sources of funding and aimed to accelerate efforts around reliability and grid resiliency.
It is also important that regulators help evaluate projects based on their ability to improve service continuity and reduce outage impacts over time. This will provide necessary accountability and incentivize utilities to strengthen the grid without losing sight of affordability.
DJ: What trends are utilities seeing in storm recovery and resilience spending, and what results are those investments producing?
Matamoros: Utilities are dedicating a growing share of capital spending toward resilience initiatives, particularly projects that improve operational awareness, automate restoration and strengthen vulnerable portions of the distribution network. Rather than focusing exclusively on rebuilding after storms, many organizations are investing in technologies that help prevent outages from becoming widespread in the first place. The result is often a grid that can respond more effectively under stress and recover more quickly when disruptions occur. As weather-related risks continue to evolve, utilities are increasingly measuring success by how well they can maintain service continuity during and after major events.
Marine microplastics carry chemicals of concern from plastic additives even after fragmentation
Plastics collected around Japan reveal that additive-derived chemicals can leach out, sorb onto microplastics from surrounding waters, or persist, highlighting the need to consider environmental behavior beyond product-based chemical controls.
Blue labels indicate marine areas where floating microplastics were collected from surface waters. Red labels indicate locations or regions where larger plastic debris was recovered from riverine, coastal, and seafloor environments.
Credit: National Institute for Environmental Studies, Japan
Background
Plastic pollution is not only a marine litter issue; it is also closely linked to resource circulation and chemical management. Plastic products contain a wide range of additives, including antioxidants, plasticizers, ultraviolet stabilizers, and flame retardants. Some of these chemicals are regulated or managed due to concerns about their effects on human health and ecosystems.
Once plastics enter the environment, exposure to sunlight and waves can cause degradation and fragmentation. Larger plastic debris may break down into microplastics, generally defined as plastic particles smaller than 5 millimeters. These smaller particles can disperse more widely in the marine environment. Fragmentation also increases the surface area of plastics relative to their mass, potentially affecting both the leaching of chemicals from plastics and the sorption of chemicals from surrounding water and particles.
Methods
A research team led by Go Suzuki of the National Institute for Environmental Studies, Japan, in collaboration with the Tokyo University of Marine Science and Technology and Nagasaki University, analyzed additive-derived chemicals in floating microplastics and larger plastic debris collected from coastal, offshore, riverine, and seafloor environments around Japan.
Floating microplastics were collected from five marine areas: Tokyo Bay, the Genkai Sea, Pacific coastal waters, waters off Hokkaido, and Japan Sea coastal waters. Larger plastic debris, including bags, ropes, nets, and hard fragments, was recovered from offshore and coastal areas across Japan, as well as from a river drainage pump station in Tokyo. The researchers identified the polymer types of the samples and analyzed extracted chemicals using gas chromatography–mass spectrometry.
Results and discussion
A wide range of chemicals were detected in both microplastics and larger plastic debris, including antioxidants, plasticizers, ultraviolet stabilizers, flame retardants, and polycyclic aromatic hydrocarbons. Based on detection frequency, concentration, and regulatory or management relevance, the researchers focused on three groups of chemicals: Irgafos 168-related compounds, di(2-ethylhexyl) phthalate (DEHP), and hexabromocyclododecane (HBCD).
Irgafos 168 is an antioxidant used to reduce oxidative degradation in plastics such as polyethylene and polypropylene. The distribution of Irgafos 168 and its oxidation products differed by polymer type and particle size. The observed patterns were consistent with leaching and transformation from within the plastic matrix.
DEHP is a plasticizer historically used primarily in flexible polyvinyl chloride products. It was widely detected in both microplastics and larger plastic debris. In some samples, concentrations exceeded 1,000 micrograms per gram (equivalent to 0.1% by weight). DEHP concentrations were higher in floating microplastics than in larger plastic debris recovered from the seafloor in both polyethylene and polypropylene samples. The results suggest that, in addition to chemicals remaining within plastics, DEHP present in surrounding water, suspended particles, and organic matter may be sorbed to microplastics from the surrounding environment.
HBCD is a brominated flame retardant that has been used in materials such as expanded polystyrene. Because it is persistent, bioaccumulative, and capable of long-range environmental transport, HBCD is regulated as a persistent organic pollutant. The researchers detected HBCD at concentrations of 110–590 micrograms per gram in microplastics collected from the Genkai Sea, Pacific coastal waters, and Japan Sea coastal waters. The findings indicate that fragmented plastic particles containing HBCD can remain mobile in the marine environment and may act as secondary sources of exposure.
The study shows that fragmentation does not necessarily remove chemical concerns associated with plastics that have entered the marine environment. Chemicals may leach from plastic matrices, may be sorbed to fragmented particles from the surrounding environment, or may remain in those particles during transport. Product-based chemical controls alone may not fully capture these processes after plastics enter the environment.
Future perspectives
Further research is needed to determine how much of the chemicals associated with microplastics are taken up by organisms and whether they contribute to ecological effects. It is also important to identify the sources and release pathways of plastics containing chemicals of concern and to apply this knowledge to leakage prevention, selective collection, and appropriate treatment.
These findings provide a scientific basis for connecting measures to address marine plastic pollution with chemical management. They may also contribute to discussions on the international legally binding instrument on plastic pollution currently under negotiation.
This article was selected for the Supplementary Cover Art for Environmental Science & Technology, Vol. 60, Issue 27. The cover image is available on the journal’s issue webpage.
(https://pubs.acs.org/toc/esthag/60/27 )
Conceptual illustration of the distinct environmental behavior of three substances highlighted in the study. Irgafos 168-related compounds are affected mainly by leaching and transformation from within the plastic matrices. DEHP may be sorbed to microplastics from the surrounding environment. HBCD can remain in fragmented particles during marine transport. The dots are schematic and do not quantitatively represent chemical concentrations or particle numbers.
Credit
National Institute for Environmental Studies, Japan
EMBARGOED COPY OF THE RESEARCH PAPER AVAILABLE ON REQUEST
Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as entry point for further cyberattacks.
Presenting their findings at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, University of Birmingham researchers reveal a new attack surface exposed to malicious and compromised SIMs.
A feature known as Proactive SIM allows a SIM card to send a limited number of special commands directly to a device's modem. One of them allows the SIM to request the execution of so-called AT commands – the same type of commands used to control and configure modems since the 1980’s.
Tomasz Piotr Lisowski and Dr Marius Muench worked with Kristian Covic, from IT security company Fuzzware, to develop the CATana toolkit to explore the dangers of SIM-originating AT commands across different devices.
The researchers investigated 26 representative devices: 18 smartphones and eight cellular-connected IoT modules, including modules commonly embedded in electric vehicle chargers, industrial equipment, and connected cars. Devices studied were not limited to any single manufacturer or operating system.
After identifying that several analysed devices would execute SIM-originating AT commands, the researchers used CATana to demonstrate the threats of the resulting SIM AT interface, leading to the discovery of multiple security vulnerabilities. Example attacks enabled by the presence of a SIM AT interface include:
Re-enabling closed-down debug interfaces
Exfiltrating sensitive information, such as a device’s unique identifier
Sending messages or initiating calls
Obtaining arbitrary command execution capabilities on a victim’s communication processor
Forcing a device to downgrade from secure 4G connectivity to older and less secure 2G networks
Shutting down the victim device; and
Disabling cellular communications altogether.
Dr Marius Muench, Assistant Professor in Computer Science at the University of Birmingham, said: “The fascinating part here is that the proactive capabilities of a SIM and the resulting attack surface is explicitly defined in the technical specifications for cellular communication, resulting into ‘specification-compliant’ attacks.”
“Other researchers, cybersecurity experts, and leaked intelligence documents have shown some of the dangers of hostile SIMs before us. Yet, the resulting risks have not been fully mitigated. Potentially, this is because hostile SIMs are not included in most threat models; although we slowly see a promising shift here.”
Building on their earlier work, the research team highlights four attacker scenarios leading to malicious or compromised SIMs and eSIMs, supported with precedents from real-world incidents:
Remote attackers exploiting vulnerabilities in SIM software;
Physical attackers replacing a victim’s SIM card or installing a hardware implant
Compromised operators abusing remote SIM management features; and
Supply-chain attackers modifying SIMs during manufacturing or distribution.
The researchers point out that the risks of SIM-originating AT commands are especially relevant for IoT devices such as industrial equipment, vehicle systems, or routers, as these are often locked down with only a limited number of exposed interfaces. The presence of a SIM AT interface could, therefore, serve as unforeseen entry vector for further compromising the victim device.
The study also comments on the more general risk of proactive SIMs, which can turn victim devices into surveillance tools. During the work building up to the publication, the researchers discovered that, on recent Android devices, a malicious SIM could force the phone to open an attacker-controlled website without any user interaction, even when the phone was locked.
The researchers argue that many proactive SIM features are legacy technologies that were built only with benign SIMs in mind. However, as technology and threat surface is evolving, many features are no longer needed and create unnecessary security risks.
Kristian Covic said: “At Fuzzware, we are very happy that we could support this research project. Hostile SIMs are an overlooked attack vector, and it's great that we could show this with our work."
The researchers did not stop at solely finding the vulnerabilities. They also reached out to the GSM Association (GSMA), as well as affected chip- and device manufacturers to address the found the issues.
Dr Muench reflects: “It was great working together with the affected companies and GSMA. Our reports were treated seriously, and key manufacturers make software updates and hardened configurations available to their customers. This will benefit billions of future SIM-enabled devices operating worldwide, including smartphones, connected vehicles, payment terminals, routers, critical infrastructure and EV charging systems.”
Asked about future research, Tomasz Piotr Lisowski said: “The attacks we found only scratch the surface of what is possible with hostile SIM cards. We will keep working on bringing more of the attack surface to the public light and hope to cooperate with vendors and standardization bodies to remedy the risks in today’s and future devices.”
The issues identified by the researchers as part of their study are tracked under CVE-2025-48618, CVE-2026-57550, and CVD-2026-0122.
ENDS
‘CATANA: On the Dangers of SIM-Originating AT Commands’ - Tomasz Piotr Lisowski, Kristian Covic, and Marius Muench is published under Open Access after presentation at USENIX WOOT.
Notes for editors
The University of Birmingham is ranked amongst the world’s top 100 institutions. Its work brings people from across the world to Birmingham, including researchers, teachers and more than 40,000 students from over 150 countries.
England’s first civic university, the University of Birmingham is proud to be rooted in one of the most dynamic and diverse cities in the country. A member of the Russell Group and a founding member of the Universitas 21 global network of research universities, the University of Birmingham has been changing the way the world works for more than a century.