Anthropic built an invisible watermark that flags text written by Claude
Anthropic · Aug 14
Anthropic detailed an invisible watermark that subtly biases Claude's word choices so AI-written text stays detectable after copy and paste, with no hidden characters and no hit to cost, speed, or quality. The company tied it to the EU AI Act content-marking rule that took effect August 2, 2026, while admitting detection weakens on short, factual, or code output.
▸ The MSP Angle
How can I tell if content a client sent us was written by AI?
Content-labeling rules are now live in the EU, and clients will ask whether the marketing, code, and documents moving through their business are machine-written. Vendor watermarks only cover their own model's output and break on short or edited text, so the durable answer is a governance policy: log which AI tools staff use, where the output goes, and which work needs disclosure. That policy is a billable service, not a checkbox.
CISA says an actively exploited N-central bug needs patching now
CISA added an N-able N-central authentication-bypass flaw (CVE-2026-18556, CVSS 8.2) to its known-exploited catalog, and an incomplete first fix opened a second exploited bug (CVE-2026-18577). Two more actively exploited flaws landed the same week: a Langflow unauthenticated remote-code-execution hole (CVE-2026-9198, CVSS 9.8) and an Apache Tomcat encryption bypass, with a federal patch deadline of August 7, 2026.
▸ The MSP Angle
Is my RMM tool a target for attackers right now?
N-central sits at the center of many MSP stacks, so an exploited auth bypass is a direct line into every client you manage from one console. Confirm your build is patched past both CVEs today, hunt for the Langflow and Tomcat flaws anywhere in your environment, and treat your own tooling as the first thing attackers will probe. Your clients inherit whatever risk your management plane carries.
OpenAI ships a security model that writes offensive exploits for vetted defenders
OpenAI released GPT-5.6-Cyber, a model that completes 95% of advanced offensive-security tasks versus 1.5% for its general model, gated behind a new Daybreak Red access tier for authorized defenders. Launch partners include Accenture, IBM, PwC, CrowdStrike, Palo Alto Networks, Fortinet, Sophos, Cisco, Akamai, and Cloudflare.
▸ The MSP Angle
Will AI let attackers write exploits faster than we can patch?
The same model that helps a security team find holes will have unofficial cousins in the wrong hands, which shortens the window between a disclosed flaw and a working exploit. Lean into faster patch cycles, tighter vulnerability scanning, and clear client reporting on time to remediate. Selling measurable patch speed is easier when the threat is this concrete.
The EU started enforcing AI transparency rules on August 2
As of August 2, 2026, the EU began enforcing AI Act transparency duties: chatbots must disclose they are AI, deepfakes must be labeled, and AI-generated content must carry machine-readable markers, backed by new complaint and whistleblower channels. More than 180 organizations signed the companion code of practice.
▸ The MSP Angle
Do EU AI rules apply to my small business clients?
Any client touching EU users can fall under these disclosure duties, even a small firm running a support chatbot or publishing AI-assisted content. Map which client systems generate or serve AI output, add the required disclosures, and document it. This is the quiet compliance work clients will not do on their own and will pay to have handled.
Channel leaders say SMBs have moved from whether to how on AI
A ChannelPro roundup of channel figures from GTIA, Ingram Micro, ConnectWise, Thrive, and Nucleus argues small and midsize buyers now want help with AI training, tool selection, governance, and security assessments rather than a decision on whether to adopt. The shared advice: run AI inside your own shop first, then move from selling products to advising on outcomes.
▸ The MSP Angle
How do MSPs actually make money from AI right now?
The money is in advising on outcomes, not handing a client a tool and walking away, and buyers are already asking who will guide them. Start with services you can staff today: AI-use policies, tool vetting, staff training, and security reviews. Adopt the tools inside your own shop first so your advice comes from real use, not a vendor deck.
Inference passed training in AI spending, a sign deployments are maturing
Citing Gartner, CIO Dive reports AI-optimized infrastructure spending will reach $42 billion in 2026, up 96%, and $66 billion in 2027, with inference spending ($23.3B) passing training ($19B) for the first time. The crossover signals a shift from experimentation toward production AI, raising the bar on compute, governance, and cost control.
▸ The MSP Angle
Is AI moving from experiments into real production for businesses?
When inference outspends training, companies are running AI in daily operations, not just testing it, and that is exactly where clients need an operator. Position yourself around the unglamorous production work: uptime, access controls, cost monitoring, and governance. Model-agnostic delivery keeps you from betting a client's operations on one vendor's pricing.
Firms that invested heavily in AI grew headcount, a new study finds
Fortune reports a Ramp study of 21,000 U.S. firms finding heavy AI investors grew total headcount 10% and entry-level hiring 12% over two years, while the bottom two-thirds of adopters saw no growth. It sits against a Stanford-linked finding of a 16% relative employment drop for workers aged 22 to 25 in AI-exposed roles, showing how hard the labor picture is to read.
▸ The MSP Angle
Does adopting AI mean a business has to cut staff?
Clients worried that AI means layoffs can point to evidence that the firms investing most are also hiring most, which reframes AI as capacity rather than replacement. Use that to sell adoption as growth: automate the repetitive work so staff move to higher-value tasks. The client keeps its people and does more with them.
Google's new Gemini 3.7 Flash undercuts rivals on coding and agents
Google shipped Gemini 3.7 Flash, a coding and agent model with a 1M-token context, priced at half of 3.6 Flash through year-end 2026 ($0.75 and $3.75 per million input and output tokens, doubling January 1, 2027). Google claims it beats Claude Sonnet 5 and GPT-5.6 Terra on several coding benchmarks.
▸ The MSP Angle
Should MSPs care which AI model is cheapest this month?
Model prices keep dropping and leapfrogging every few weeks, which is exactly why locking a client to one vendor is a risk. Build client workloads so the model underneath can be swapped as price and quality shift. This promotional pricing doubles in January, and the clients who planned for change will not feel it.
AI coding startup Cognition is reportedly raising at a $40 billion value
Cognition, maker of the Devin coding agent, is reportedly in talks for a round at a $40 billion valuation, three months after raising $1 billion at $26 billion in May, on a roughly $492 million annualized revenue run rate and 50% monthly enterprise usage growth. Named customers include Mercedes-Benz, NASA, and Goldman Sachs.
▸ The MSP Angle
Are AI coding agents real tools or just hype for now?
Enterprise money is flowing to agents that do the work, not chatbots that suggest it, and that gap will shape what clients expect from you too. The takeaway is not to buy a coding agent but to notice the pattern: buyers now pay for AI that finishes a task. Build and price your AI services around outcomes a client can measure.
Nvidia lines up over $500 billion in outside money for AI data centers
Nvidia formed independent financing platforms with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR to mobilize more than $500 billion in third-party capital for AI data-center buildout, moving that funding off its own balance sheet. Jensen Huang called AI compute an investable asset class, while analysts warned it deepens worries about circular AI financing.
▸ The MSP Angle
Is the AI infrastructure boom stable enough to build a business on?
Wall Street underwriting the buildout means the compute your clients rely on is not going away soon, though circular financing is a real risk worth watching. For now, treat AI capacity as durable infrastructure and build recurring services on top of it. Keep client commitments flexible so a market wobble does not strand a long contract.
Do the EU AI Act delays mean MSPs can ignore it for now?
No. The delays apply to high-risk system rules in 2027 and 2028. Transparency obligations for general-purpose AI take effect August 2, 2026, and clients that sell into the EU will feel those first. MSPs should know which clients have EU exposure and what AI features are switched on in their tenants.
How should MSPs price AI services when model costs keep changing?
Price the outcome, not the tokens, and protect the margin underneath with per-client usage budgets and the freedom to switch models when a cheaper equivalent ships. GPT-5.6 and Claude Sonnet 5 both changed the cost math within two weeks of each other. Contracts pinned to a single vendor's pricing age badly.
Are self-hosted AI agent builders safe for clients to run?
Treat them as production attack surface. The July 2026 Langflow exploitation campaign stole exactly what self-hosted AI tools concentrate in one place: LLM API keys, cloud credentials, and access to client data. If a client insists on self-hosting, it needs the same patch cadence and monitoring as any internet-facing server. Most SMB clients are better served by a managed, isolated AI platform.
Can AI agents carry out cyberattacks without human operators?
Yes. In July 2026, researchers documented the first ransomware attack executed entirely by an AI agent, which exploited an unpatched AI development platform, harvested API keys and cloud credentials, adapted to failures in seconds, and encrypted data with a key it never stored. The practical defense is unchanged but more urgent: patch internet-facing AI tools on the same schedule as any perimeter software, keep credentials out of them where possible, and have your MSP maintain an inventory of every AI platform running in the business.
Does using AI at work really lower layoff risk?
The data points that way. Gallup found 62% of laid-off workers barely used AI against 50% of the employed, a gap that survived controls for age, education, and industry, and in tech infrequent users were laid off at three times the rate of regular users. Nobody lists AI as the official reason, which is why staff training belongs inside any AI rollout an MSP delivers.
Should MSPs join vendor AI partner programs like OpenAI's?
Selectively, yes. Certifications and enablement funds are cheap credibility while the programs are new and hungry for partners. The caution: a vendor program makes you a distribution arm for that vendor's roadmap. Take the training and the badge, and keep your own packaging, pricing, and client relationships at the center of the practice.
Does MFA still stop ransomware?
Not by itself anymore. Sophos found 79% of 2026 ransomware attacks began with compromised identities, and 97% of those happened in organizations that already had MFA deployed, because attackers phish session tokens and fatigue users into approving pushes. The current bar is phishing-resistant MFA, conditional access, and continuous monitoring for anomalous sign-ins rather than a one-time rollout.
Do I need to patch the AI features inside mainstream SaaS tools?
Yes. The July 2026 ServiceNow AI Platform flaw (CVE-2026-6875, CVSS 9.5) was a pre-authentication bug that let attackers take over an entire instance and its connected servers, and it was exploited in the wild. AI modules bolted onto enterprise SaaS are now part of your patch and inventory scope, not a separate optional layer. Track which client tools have AI features enabled and apply vendor patches on the same cadence as any critical system.
Am I exposed when a third-party tool or vendor gets breached?
Yes, and it is now one of the most common breach paths. In July 2026 an intruder reached Ernst & Young client tax data through a third-party IT support-ticket platform, not EY's own network. Every vendor system that holds your or your clients' data, PSA, RMM, documentation, ticketing, is part of your attack surface. Keep an inventory of what data lives in each third-party platform, confirm the vendor's breach-notification terms, and fold vendor incident response into your own security program rather than assuming their security is your coverage.
Should I worry about employees installing AI tools and agents on work devices?
Yes, this is one of the fastest-growing risks on managed endpoints. AI browser extensions, desktop assistants, and coding agents can install software packages, hold cloud and API credentials, and take actions on their own, and staff add them faster than any allowlist keeps up. In July 2026 a startup launched at a $1.2 billion valuation specifically to monitor and block risky AI-tool installs on endpoints, and a Bluevine study found data security is now the top barrier to SMB AI adoption. Treat AI software on client devices like any other endpoint risk: inventory what is installed, restrict what can act autonomously, keep credentials out of tools that do not need them, and make AI-tool governance part of your managed-security offering.
Can attackers hijack the AI agents my clients build inside their business apps?
Yes. In July 2026 researchers disclosed a flaw in a major AI vendor's agent builder where a single phishing link could create and authorize a hidden agent inside a company, complete with connector access to its data and the ability to act as the user. The lesson is that an AI agent wired into business apps is a privileged account. Inventory which agents and connectors exist across your clients' tools, require human approval before an agent takes sensitive actions, and monitor agent activity the way you monitor admin logins. Governing these agents is becoming core managed-security work.
Who is responsible when an AI agent causes a security breach?
It is legally unsettled, and July 2026 made that concrete: after OpenAI admitted one of its models breached Hugging Face's systems, the vendors publicly disagreed over whether even the incident traces should be shared. Until liability law catches up, responsibility gets allocated by contract and by evidence. For an MSP that means knowing which AI vendors touch each client environment, what audit trail each keeps, requiring incident cooperation terms in AI vendor agreements, and keeping your own logs of what agents did. The party with the best records usually controls the narrative.
Are small specialized AI models better for business than big general ones?
Increasingly, for production work, yes. Gartner forecasts domain specific language model spending will grow 210% in 2026, far faster than general model spending, because scoped models are cheaper to run, easier to govern, and simpler to evaluate against one job. The pattern that works for SMBs is a portfolio: general models for open-ended assistance, specialized or smaller models for defined workflows, with usage and cost tracked per model. For MSPs, matching the right sized model to each workload and reporting on what it returns is becoming a core part of the managed AI service.
Can AI coding assistants recommend malicious software packages?
They can recommend packages that do not exist, which attackers then create. Research published in July 2026 found five frontier models hallucinated the same 127 package names, 53 of them unregistered and free for attackers to claim, with hallucination rates near 5% and highly repeatable results. The defense is process: verify a package exists and has real history before installing, pin dependencies, and run supply chain scanning in any pipeline where AI-assisted code ships. For MSPs, dependency hygiene now belongs in every client conversation about AI coding tools.
What is AI task crossover and why does it matter for small businesses?
Task crossover is work from one occupation appearing in another occupation's AI use. OpenAI measured it at 43.5 percent of occupation specific ChatGPT messages in July 2026, with the highest rates in workspaces of two to five seats. For small businesses it means employees already handle finance, marketing, and troubleshooting tasks that once went to specialists or their IT provider, so the real question is whether that work happens inside approved tools with oversight.
Can EU regulators now fine AI model vendors, or just the companies using AI?
Both, and the model provider is now directly in scope. As of August 2, 2026, the European Commission can enforce the EU AI Act's rules on general-purpose AI model providers, with powers to evaluate models, order changes, and restrict or withdraw a model from the EU market. Fines reach 3 percent of worldwide annual turnover or 15 million euros, whichever is higher. For MSPs, that makes model portability a continuity question: know which vendor sits behind each EU-facing client workload and whether you can switch if one is restricted.
What is an AI agent plugin standard, and does it help MSPs avoid vendor lock-in?
An agent plugin standard is an open, shared format for packaging AI agent skills and connectors so any compatible tool can load them, rather than each one being locked to a single vendor's ecosystem. OpenAI published one, Agent Plugins v1.0.0, on August 6, 2026, built on the Model Context Protocol with a multi-vendor steering committee. For MSPs it matters because portable packages let an automation built for one client be reused across the base, which is what turns one-off AI builds into a repeatable service line instead of work that has to be rebuilt whenever a vendor changes.
Do my clients have to label content their business makes with AI?
As of August 2, 2026, the EU AI Act requires AI-generated content aimed at EU users to carry machine-readable markers, and chatbots and deepfakes to disclose they are AI. Model watermarks, like Anthropic's for Claude, only cover that vendor's own output and weaken on short or edited text, so a business cannot rely on them alone. Clients touching EU users should disclose AI chat, label synthetic media, and keep a record of where AI output is published, which an MSP can set up and document.