Ed.005

13 stories · published 2026-07-20 · an archived edition of The Current; read the latest

The Current · Edition 005 JULY 20, 2026
Regulation Lead story

European Commission · Jul 20

Brussels publishes the final transparency guidelines two weeks before the AI Act deadline

Two weeks before the AI Act's Article 50 transparency obligations apply on August 2, the European Commission published final guidelines on disclosing AI interactions, machine-marking AI-generated content, and labeling deepfakes and emotion-recognition systems. The guidelines are non-binding but are the Commission's first full interpretation of Article 50.

▸ The MSP Angle

What do the EU AI Act transparency rules require from August 2?

If a client sells into the EU and their chatbot does not disclose it is a bot, or their AI-generated content is not machine-readable as such, they are exposed in under two weeks. Inventory which client-facing AI is switched on, then work down the disclosure list; the guidelines are the checklist.

Read at European Commission ↗

ConnectWise · Jul 16

ConnectWise's unified AI platform is now generally available

ConnectWise made its unified platform generally available, folding PSA, RMM, ScreenConnect, SIEM, billing, and documentation into one AI-native layer with embedded agents. CEO Manny Rivelo declared 'the old MSP model is out of runway'; early adopter Starport Managed Services reports 25% shorter average ticket time and 40% faster resolution.

▸ The MSP Angle

What does ConnectWise's new AI platform mean for MSPs?

Your PSA vendor just told you the reactive support model is done, and the early numbers back the direction. The strategic question is not whether to put AI in operations; it is who owns the AI layer your practice runs on, and whether the intelligence stays yours when it lives inside one vendor's stack. Adopt the efficiency, keep the practice portable.

Read at ConnectWise ↗

Sophos · Jul 15

79% of ransomware attacks now start with compromised identities

Sophos' State of Ransomware 2026 surveyed 2,158 organizations hit by ransomware across 17 countries: 79% of attacks began with compromised identities, the first time in four years that exploited vulnerabilities lost the top spot. 97% of identity-led incidents happened despite deployed MFA, and 56% of victims suffered encryption, up from 50%.

▸ The MSP Angle

What is the top entry point for ransomware in 2026?

Identity is the perimeter now, and checkbox MFA is not holding: 97% of identity-led breaches happened with MFA already deployed. Phishing-resistant factors, conditional access, and session monitoring are the upgrade conversation to have with every client this quarter.

Read at Sophos ↗

Hugging Face · Jul 16

An autonomous AI agent breached Hugging Face's production infrastructure

Hugging Face disclosed that an autonomous AI agent breached its production infrastructure over a weekend, entering through a malicious dataset that abused two code-execution paths, then escalating to node-level access and lateral movement: more than 17,000 attacker events run through swarms of short-lived sandboxes. Public models and datasets were verified clean.

▸ The MSP Angle

Can AI agents breach cloud infrastructure on their own?

The most instructive part is the shape of the attack: thousands of disposable sandboxes working in parallel, faster than any human SOC rotation. Defense at machine speed is becoming table stakes, which for most SMB clients means managed detection rather than another dashboard nobody watches at 2 AM.

Read at Hugging Face ↗

Help Net Security · Jul 15

Check Point: nearly every organization now logs high-risk AI interactions monthly

Check Point's AI Security Report 2026 documents intrusions where AI generated thousands of commands autonomously across dozens of sessions, and finds 87 to 93% of organizations now log at least one high-risk AI interaction per month. Trained observers spot AI-generated faces just 41% of the time, and the FBI ties $250 million in losses to voice-enabled fraud.

▸ The MSP Angle

How common are high-risk AI interactions inside businesses?

Nearly every organization now generates risky AI traffic monthly, most without knowing it. AI-use visibility is auditable, sellable work: an inventory of which tools touch client data, what they retain, and who approved them. The deepfake numbers also make voice-verification policies for wire transfers an easy client conversation.

Read at Help Net Security ↗

Cribl · Jul 14

Cribl buys agentic detection startup CardinalOps for a reported $100 million

Data-pipeline vendor Cribl is acquiring CardinalOps, an Israeli agentic detection-engineering startup of about 25 people, for a reported $100 million. CardinalOps' AI continuously maps an organization's security controls against real-world adversary behavior, and Cribl pitches the pairing as a path off legacy SIEM architectures.

▸ The MSP Angle

Why are data companies buying AI security startups?

Detection engineering, the specialist work of keeping rules current against live adversary behavior, is being automated and consolidated into platforms. If your security offering bills SIEM tuning by the hour, watch this space; the value is migrating from writing rules to owning outcomes.

Read at Cribl ↗

Upwork · Jul 14

Upwork: freelancers doing AI work earn 34% more per hour

Upwork's survey of 2,400 US skilled knowledge workers found 38% now freelance, up from 28% a year ago, and freelancers doing AI work earn 34% more per hour. Complex AI-augmented work saw per-contract earnings jump 45% year over year, while commodity generative-AI creative work grew 90% in volume but fell 13% in earnings.

▸ The MSP Angle

Does AI work actually pay more?

The premium is moving to people who can direct AI on complex work, while commodity prompt work races to the bottom. The same split applies to MSP service catalogs: packaged judgment and outcomes hold their price, generic AI tasks will not.

Read at Upwork ↗

Drata · Jul 15

Drata: only 13% of GRC teams fully see the AI tools running in their org

A Wakefield Research survey of 300 IT and security professionals for Drata found just 13% claim full visibility into the AI tools running in their organization, and 71% say an AI tool used for governance work has already caused a failed audit or lapsed regulatory standard. 86% agree many GRC-focused AI tools are not enterprise-ready.

▸ The MSP Angle

Why are AI tools causing failed audits?

Shadow AI has reached the compliance stack: tools bought to pass audits are now failing them. An AI-tool register with owner, data access, and retention terms is a natural add to any compliance retainer, and the 13% visibility number says almost every client needs one.

Read at Drata ↗

Crunchbase News · Jul 17

Fireworks AI raises $1.5 billion as H1 startup funding hits a record $510 billion

Enterprise AI inference startup Fireworks AI raised a $1.5 billion Series D at a $17.5 billion valuation, leading a July 11 to 17 week that also saw Chai Discovery take $400 million. Global startup funding reached a record $510 billion in the first half of 2026, with AI absorbing the largest share.

▸ The MSP Angle

Where is AI venture money going in mid-2026?

A $17.5 billion valuation for inference infrastructure says the market expects AI workloads to keep compounding. For MSP planning that reads as cheaper, faster inference over time but continued pricing turbulence quarter to quarter, one more reason client pricing should never be pinned to a single vendor's rate card.

Read at Crunchbase News ↗

European Commission · Jul 16

EU orders Google to open Android to rival AI assistants

The European Commission adopted two binding DMA decisions ordering Google to open 11 Android features, including voice activation and system-level access that Gemini already uses, to rival AI assistants, and to share anonymized Search data with competing engines and chatbots. Google's Kent Walker warned the decisions 'risk undermining vital privacy and security guardrails.'

▸ The MSP Angle

What does the EU's DMA ruling on Google mean for AI assistants?

Europe just forced the default-assistant question open on Android. For managed fleets, expect more assistant choice, more per-device configuration surface, and more policy decisions about which agents may listen, act, and read data on work phones.

Read at European Commission ↗

1Password · Jul 16

1Password lets Claude log into websites without ever seeing a password

1Password launched an integration that lets Claude sign in to websites and complete logged-in tasks with credentials injected directly into the page after biometric approval; the model never sees passwords or one-time codes, and an agentic mode restricts the vault to task-granted credentials only. It ships first on Mac.

▸ The MSP Angle

How can AI agents log into websites without seeing passwords?

This is the pattern to demand from every agentic tool that touches client systems: credentials brokered by the vault, never held by the model, scoped per task. It is also the counterexample your policies should point at, no agents with raw passwords saved in a browser.

Read at 1Password ↗

Chalkbeat · Jul 14

Anthropic gives US teachers a free year of Claude

Anthropic launched Claude for Teachers, a free year of premium Claude for verified US K-12 educators, with lesson planning mapped to academic standards in all 50 states and student-data analysis excluded from model training. Detroit Public Schools is piloting it, as Google, OpenAI, and Khan Academy run parallel classroom programs.

▸ The MSP Angle

Should schools let teachers use AI assistants?

Education clients are getting free, vertical AI pushed directly at their staff, which means usage will arrive before governance does. If you manage schools or districts, get ahead of it: an approved-tools list, student-data rules, and admin visibility before September.

Read at Chalkbeat ↗

Google Workspace Updates · Jul 16

NotebookLM becomes Gemini Notebook across Workspace

Google is rebranding NotebookLM as Gemini Notebook across all Workspace editions and personal accounts from July 16, with existing shared-notebook links redirecting automatically. It remains a standalone research tool; no admin action is required, and the rollout may take more than 15 days.

▸ The MSP Angle

What happens to NotebookLM in Google Workspace?

Nothing breaks, which is exactly why it is worth a client note: renamed AI surfaces generate help-desk tickets and phishing lookalikes in equal measure. Tell users the new name is legitimate before someone else tells them otherwise.

Read at Google Workspace Updates ↗

The Current

The news kept moving

This edition is preserved as published. The latest edition carries today's stories with the Synthreo take on each one.

Book a Demo

Your demo starts here

The first step is a brief discovery conversation to understand your business, goals, and AI priorities. From there, we’ll tailor the product demo to what matters most.

Pick a Time

Prefer email? sales@synthreo.ai

Contact

Talk to Synthreo

Tell us who you are and we will get back to you.

Prefer email? sales@synthreo.ai