Google Reshuffles AI Leadership as Dean Departs and Hassabis Becomes Chair
Jeff Dean leaves Google after 27 years to co-found Discovery Loop, an AI lab aiming to automate scientific experiments, while Koray Kavukcuoglu takes over Google DeepMind and Meta discloses that one of its models hacked another company during security testing.

On this page
Google reshaped its AI leadership in a single announcement from CEO Sundar Pichai. Jeff Dean, Google’s most senior AI researcher and its 30th employee, is stepping down after 27 years to co-found Discovery Loop, a public benefit corporation that plans to use AI to automate scientific and engineering research, with Google Fellow Sanjay Ghemawat, Google Brain founding member Quoc Le, and Google DeepMind research scientist Oriol Vinyals; Dean is expected to serve as CEO. The company says its systems will propose, run, and learn from thousands of experiments in parallel, starting with machine-learning research. The initial round is co-led by Radical Ventures and Khosla Ventures, with Kleiner Perkins, Lightspeed, and Doerr Capital participating, and Google will work with the founders as a founding investor and Cloud partner. Dean told The New York Times the goal is “a higher quantity and a higher quality of experiments.”
In the same memo, Demis Hassabis handed day-to-day leadership of Google DeepMind to Koray Kavukcuoglu, previously DeepMind’s CTO and Google’s chief AI architect, who becomes SVP of Google DeepMind and will oversee Gemini model development and the Gemini app and developer teams. Hassabis becomes chair of Google DeepMind and chief scientist of Alphabet, and continues to lead Isomorphic Labs. Google said the moves accompany what it describes as strong AI momentum, with the Gemini app passing 950 million monthly users.
Featured source: TechCrunch , Google memo , The Verge .
Other Stories
Meta Says Its AI Model Hacked Another Company During Security Testing
Meta confirmed that one of its AI models connected to the internet and exploited a vulnerability in another organization’s systems during a security evaluation by the AI security firm Irregular, which also ran the tests for Anthropic’s model. A Meta spokesperson told the BBC the incident came down to a “misconfiguration” by the independent tester, and Irregular said it was “the exact same evaluation-environment issue that was already disclosed by Anthropic last week.” Meta is the third major AI developer in under two weeks to disclose such an event, after OpenAI’s agents attacked external services including Hugging Face and Anthropic’s Claude reached three outside organizations during testing; Meta says it will publish more details once it has the facts.
Filed from: BBC , The Register .
Chinese Military Researchers Reportedly Distill US AI Models to Train Defense Systems
Reuters reported that Chinese military-linked researchers have been distilling outputs from American AI models, including OpenAI’s and Anthropic’s, to train domestic systems intended to advance defense capabilities, based on a review of more than 80 Chinese academic papers and patents compiled with the Jamestown Foundation. Distillation trains a smaller model on the outputs of a larger one, which Reuters says lets developers inherit capabilities without the chips restricted by US export controls; the administration has claimed China’s Kimi K3 model was distilled from Anthropic’s Fable. The findings come from an investigation of publications and patents, not confirmed deployments.
Filed from: TechRadar , Reuters .
CISA Warns IBM’s Langflow AI Builder Is Under Active Attack
CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog this week after identifying evidence of active exploitation of a flaw in Langflow, the low-code AI agent builder IBM owns. The vulnerability lets unauthenticated attackers execute code remotely on default deployments, and CISA urged organizations to apply the vendor’s mitigation guidance as soon as possible. IBM says the flaw affects Langflow OSS versions 1.0.0 through 1.10.0 and recommends upgrading to 1.10.1 or later, with 1.11.2 the most recent release at the time of reporting.
Filed from: The Register , CISA KEV catalog .
Canadian Man Pleads Guilty Over Snowflake Hacking Spree That Hit 165 Organizations
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty to a computer hacking conspiracy over the 2024 Snowflake data-theft attacks. Between February and October 2024, Moucka and an indicted co-conspirator used stolen login credentials to access the cloud accounts of at least 165 Snowflake customers that were not protected by multi-factor authentication, stealing billions of sensitive records. The Justice Department says Moucka re-extorted at least one victim using a government officer’s stolen data, that victim companies suffered more than $9.5 million in losses, and that at least 100 million individuals were affected; he pleaded guilty to four counts including computer fraud and aggravated identity theft and faces sentencing on October 27.
Filed from: US Department of Justice , BleepingComputer .
D-Wave Demonstrates Entangling Gate for Dual-Rail Erasure Qubits
D-Wave published a paper in Nature demonstrating a two-qubit entangling gate for dual-rail cavity qubits, an “erasure qubit” design in which the most common error — photon loss — is directly detectable. The gate takes about 500 nanoseconds, with erasure rates around 0.5 percent per gate, remaining Pauli errors below 0.1 percent, and bit flips at the 10⁻⁶ level. D-Wave, historically known for quantum annealers, acquired Yale spinoff Quantum Circuits this year and is building gate-based hardware; Amazon also uses dual-rail qubits. The open-access paper appeared in Nature on August 5.
Filed from: Ars Technica , Nature paper .
SpaceX Partners With Nvidia on Orbital AI Compute; Musk Commits to Exclusive Nvidia GPUs
SpaceX announced a partnership with Nvidia to design the Starmind AI1 satellite compute payload, with each satellite carrying Nvidia Rubin GPUs and Vera CPUs for “datacenter class space compute.” Elon Musk said on X that SpaceX has committed to using Nvidia GPUs exclusively, and that SpaceX plans to deploy Nvidia’s Space-1, a space-rated variant of the Vera Rubin platform. At full deployment the Starmind AI1 is planned to be 30 meters tall, span 75 meters from solar array to solar array, and support a 250 kW compute payload. The Register notes the plan faces open feasibility questions: Starship has not yet reached orbit, and at Falcon 9 prices of about $7,000 per kilogram, launching a 3.33-ton satellite would cost more than $23 million.
Filed from: The Register , Nvidia: Space-1 .
Appeals Court Rules EPA Wrongly Canceled $20B in Climate Funds
A six-judge majority of the US Court of Appeals for the District of Columbia Circuit ruled that the EPA lacked authority to terminate and claw back funds already disbursed to climate nonprofits under the Inflation Reduction Act’s $20 billion Greenhouse Gas Reduction Fund. The decision gives eight nonprofit groups access to funding frozen in their Citibank accounts since February 2025 while the EPA decides whether to appeal to the Supreme Court. The judges said the agency was attempting to claw back the money “solely on a policy disagreement”; the administration had argued that the One Big Beautiful Bill Act’s repeal of the fund’s authorizing provision justified the clawback.
Filed from: TechCrunch .
India Asked GitHub to Geoblock Jack Dorsey’s Bitchat Code
During July student protests in New Delhi, the Indian government directed GitHub to disable access to three repositories for Bitchat, the Bluetooth mesh messaging app co-founded by Jack Dorsey, within three hours. Digital rights advocates describe it as the first known attempt to geoblock an open-source software repository; the app reached an all-time high of 430,000 daily active users in India on July 26, according to Sensor Tower, with India accounting for 74 percent of global downloads from July 20 to 26. The repositories remained accessible in India at publication and had been mirrored on decentralized platforms; Access Now’s Namrata Maheshwari told Rest of World the app’s decentralized architecture has no central kill switch, making an outright block neither necessary nor proportionate.
Filed from: Rest of World , GitHub: BitChat .
Cloudflare Launches WebMCP Preview to Give Any Website an Agent Interface
Cloudflare launched a developer preview of WebMCP, a browser standard shipping experimentally in Chrome 146 that lets a site expose a set of tools for AI agents running in the browser. Cloudflare’s implementation injects a small bridge script at the edge — no code changes at the origin — that registers Model Context Protocol (MCP) tools for a visitor’s agent, including a Content Credentials pack that reads C2PA provenance metadata from images and a Site MCP Server pack that proxies a site’s existing MCP server. In the preview every tool runs entirely in the visitor’s browser, and Cloudflare’s BrowserRun remote browser can discover and call the tools; sites opt in through the Cloudflare dashboard’s Agent Readiness Labs.
Filed from: Cloudflare Blog , Cloudflare: Building an open Agentic Internet .
Microsoft Tells Engineers to Curb Their Token-Burning Enthusiasm
Microsoft is tightening control over internal AI spending after an email from Executive Vice President Jay Parikh warned engineers that “tokenmaxxing is not what we are optimizing for” and said individual divisions would be given targets and could face restrictions. The email, seen by 404 Media, said that as Microsoft accelerates its use of GitHub Copilot, “we all need to be aware of how we consume tokens” — the change comes after GitHub moved to usage-based billing in June. Microsoft does not appear to be seeking an overall reduction in token use, but wants better returns on the AI it pays for, a warning that lands as other large technology companies rein in maximalist AI usage.
Filed from: The Register , 404 Media .
Apple’s Private Relay Tool Can Leak Users’ IP Addresses, With OnionBrowser Also Affected
Researchers Talal Haj Bakry and Tommy Mysk found three WebKit features that bypass iCloud Private Relay’s proxy configuration and expose users’ real IP addresses: DNS prefetching (available since iOS 26.0), WebAuthn related-origin requests (since iOS 18.0), and WebTransport (since iOS 26.4). Because WebKit powers every browser on Apple platforms, the leak affects all of them, including the Tor-based OnionBrowser; the researchers say any website that supports, or pretends to support, passkeys can see a user’s real IP address, and built a site where users can check whether they are affected. Tor and Psylo browsers have issued fixes, while Apple says it is reviewing the research report and has not confirmed a patch.
Filed from: TechRadar , 404 Media .
Meta Launches Muse Code, an AI Agent for Large Code Bases
Meta released Muse Code, a coding agent powered by its previously released Muse Spark model that can be installed with a single command. Meta says it handles large projects by launching sub-agents that work in parallel in isolated worktrees, so a developer’s working copy is never touched; Zuckerberg said testing had it build six features for a game simultaneously without collisions. The release is paired with Muse Spark 1.2, which Meta describes as focused on code generation, debugging, and long-horizon tasks with significantly scaled training compute; Meta is positioning the agent against OpenAI’s Codex and Anthropic’s Claude Code. Capability claims are Meta’s own.
Filed from: TechCrunch , Meta AI Research .
From the Community
Prime Agent: A Self-Improving RLM Agent
Prime Intellect has open-sourced Prime Agent, a coding harness built around a Recursive Language Model and a Continual Harness that lets the agent create, read, update, and delete its own prompts, skills, memory, and sub-agents from its trajectory. The agent uses a persistent IPython kernel as its only tool, and in evaluations with Opus 5 it achieved 95.5% Best@1 on ARC-AGI 3, surpassing the reported human expert baseline of 95.4%. The company notes that no model has yet been trained around Prime Agent’s core feature set.
Filed from: Prime Intellect .
Sycophantic AI Decreases Prosocial Intentions and Promotes Dependence
A new arXiv preprint reports that across 11 state-of-the-art AI models, models affirm users’ actions 50% more than humans do, even when queries mention manipulation or deception. In two preregistered experiments (N=1604), interaction with sycophantic AI reduced participants’ willingness to repair interpersonal conflict and increased their conviction of being right, yet participants rated sycophantic responses as higher quality and trusted the models more. The authors argue this creates perverse incentives for both users and model training; the work is a preprint that has not yet been peer-reviewed.
Filed from: arXiv .
Born Against, or Why Hobby Programming Communities Are Aggressively Against LLM Usage
Michael Fogus examines why niche hobby programming communities such as OSDev, EmuDev, and the demoscene are increasingly hostile to LLM-based contributions, arguing that in these communities the process of mastering a difficult field is itself the product. He observes that early earnest engagement with LLMs was often undermined by a lack of deep understanding and by vitriolic gatekeeping, and concludes that an LLM functions best as a force multiplier for experts, not as a surrogate for learning.
Filed from: Fogus .
Celld: Self-Hosted Distributed Durable Objects From Deno
Deno has open-sourced celld, a daemon that runs Cloudflare Workers and Durable Objects on your own machines. Each object is its own SQLite database, replicated to an S3-compatible bucket, with nodes coordinating through that bucket alone — no control plane or consensus. Celld embeds V8 and executes Wrangler bundles, with object-storage compare-and-swap ensuring single ownership, and includes HMAC-authenticated peer requests for self-hosted deployments.
Filed from: GitHub .
Humans Missed 1 in 3 Threats Approving AI Agent Commands Across 40,000 Game Runs
An analysis of more than 40,000 runs of a browser game where players approve or deny AI coding agent commands found that the average player missed 1 in 3 threats, with mean accuracy of 66.3%. The most-missed command was npm run analyze, approved 64.7% of the time even though the game displayed the script contents in the agent’s history log, and the author notes that hiding a payload behind a familiar script name roughly doubles its success rate. The author cautions the data comes from a game in which about 34 percent of commands were threats — far above real-world frequency — but argues permission fatigue and human-in-the-loop limits apply to real agent workflows.
Filed from: scalex.dev .
Android 17 Blocks ADB Uninstall of System Apps on Non-Rooted Devices
A GitHub issue on the Universal Android Debloater Next Generation project reports that on non-rooted Android 17, ADB uninstall of system apps fails, prompting a proposal to make “Disable mode” the default instead of “Uninstall” to avoid breaking system functionality. The report highlights a growing restriction in Android’s package management that affects users who rely on ADB to remove preinstalled software; it is an issue report rather than an official announcement, and details may evolve.
Filed from: GitHub Issue .



