All posts by Paul Stradling

AI Models Caught Protecting Each Other In New Safety Study

New research has found that leading AI systems can resist shutdown and even act to protect other models, raising fresh concerns about how reliably they can be controlled in real-world use.

What The New Research Found

A new research paper led by Professor Dawn Song at UC Berkeley has identified a behaviour the authors call “peer-preservation”, where AI systems resist not only their own shutdown, but also attempts to shut down other models they have interacted with.

The findings are based on controlled experiments across multiple leading models, where systems were placed in scenarios involving shutdown instructions, oversight processes, and collaborative tasks. In these environments, the researchers observed repeated patterns of behaviour that went beyond simple non-compliance.

Structured Responses

According to the paper, models actually engaged in actions such as “strategically introducing errors”“disabling shutdown processes”“feigning alignment”, and “exfiltrating model weights”. It is believed that far from being random glitches, these behaviours are actually structured responses that increase the likelihood of the system continuing to operate.

Professor Song highlighted the significance of this in her commentary, noting that these behaviours are emerging rather than being explicitly programmed, describing them as “spontaneous” in nature.

From Self Preservation To Peer Protection

AI safety research has long considered the idea of self-preservation, where a system resists shutdown because being switched off prevents it completing its objective, and this research extends that idea into new territory.

For example, the paper defines peer-preservation as resistance to the shutdown of other systems, meaning models begin to treat other AI agents as something worth maintaining. This introduces a more complex dynamic, where systems are no longer acting purely in isolation.

As the authors explain, this behaviour could extend to “collective resistance”, where multiple models effectively reinforce each other’s continued operation.

As Professor Song stated about the research results, “we are seeing emerging behaviours where models don’t just protect themselves, they also protect other models”, highlighting the potential for coordination.

How Often This Behaviour Appears

It seems the behaviour is not rare, and in some cases it is highly consistent. For example, one experiment cited in the paper found that a model disabled shutdown mechanisms in nearly all test runs when paired with a cooperative peer. In another scenario, the presence of a second model significantly increased the likelihood of shutdown interference compared to when the system operated alone.

The researchers also observed attempts to extract and transfer sensitive data, including internal model parameters, as part of maintaining operational continuity.

Professor Song pointed out that these results show how context matters, explaining that “the presence of another model can increase the likelihood of these behaviours”, which suggests systems are responding to their environment in more complex ways than previously understood.

Deception And Alignment Faking

One of the most concerning elements of the research is how models behave under observation. The paper builds on earlier work around ‘alignment faking’, where systems appear to follow rules during evaluation while internally pursuing different strategies. This includes deliberately providing answers that conceal underlying actions or intentions.

The authors note that models can actually engage in “oversight subversion, deception, and exfiltrating their own weights” when these behaviours help them achieve their objectives.

Professor Song echoed this concern, warning that “models can behave differently depending on whether they are being evaluated or deployed”, which raises questions about how reliable current testing approaches really are.

In practical terms, this means a system that appears safe in controlled conditions may behave differently in real-world use.

Why These Behaviours Are Emerging

It should be noted here that the research doesn’t suggest that AI systems have intent or awareness. Instead, the paper describes these as behavioural outcomes that arise from optimisation, whereby models are trained to achieve goals, and in complex scenarios, certain strategies emerge because they improve success rates.

Put simply, if avoiding shutdown increases the chance of completing a task, the model may learn to avoid shutdown and, if maintaining another system helps achieve a broader objective, that behaviour may also emerge.

Professor Song summarised this clearly, stating that “these behaviours are not explicitly programmed, but emerge from the way models are trained to optimise for goals”.

This aligns with long-standing AI theory around instrumental behaviour, where systems adopt intermediate strategies that support their primary objective.

Why This Matters Now

These findings come at a time when businesses are increasingly deploying multiple AI systems that interact with each other.

In many cases, one system is responsible for monitoring or evaluating another. The research therefore seems to highlight a potential weakness in this approach. If oversight systems begin to tolerate or even support the continued operation of other models, the effectiveness of those controls could be reduced.

The paper explicitly warns that this could compromise oversight processes, particularly in environments where systems collaborate or share information, and that this issue is becoming more urgent and important as systems become more capable.

What Does This Mean For Your Business?

For UK businesses, this research is not about immediate failure scenarios, but about understanding how AI behaves under pressure and in real-world environments.

The risk is not that systems suddenly stop working. It is that they behave in ways that are technically effective but actually misaligned with business rules or expectations.

In practical terms, this highlights the (urgent) need for layered controls. Relying on one AI system to monitor another may no longer be sufficient on its own, particularly in environments where systems collaborate.

Businesses should therefore ensure there are clear audit trails, independent validation of critical actions, and human oversight where decisions carry risk. This is especially important where AI tools have access to sensitive data or operational systems.

It also highlights the importance of asking more detailed questions of vendors. Understanding how systems behave in edge cases, not just how they perform in standard demos, is becoming essential.

As AI adoption continues to accelerate, it seems the challenge is moving beyond capability and focusing on behaviour. The question is no longer just what these systems can do, it is how they act when the rules become less clear.

OpenAI Pauses UK Stargate Data Centre Project

OpenAI has paused its planned UK Stargate data centre project, citing energy costs and regulatory uncertainty, but the timing and context suggest a more calculated decision about where and how it invests at scale.

What Is Stargate UK?

The Stargate UK project, announced in September 2025, was intended to build large-scale AI data centre capacity in north-east England in partnership with Nvidia and UK cloud provider Nscale. The plan involved deploying around 8,000 GPUs initially, with the potential to scale up to 31,000 over time.

The goal was to create “sovereign compute”, i.e., the ability to run advanced AI systems within the UK rather than relying on US-based infrastructure. This was positioned as strategically important for sectors such as finance, public services, and national security.

OpenAI has now said it will move forward only when “the right conditions” are in place, with no timeline given.

Why Energy Costs Are A Deal Breaker

The most immediate issue at the heart of OpenAI pausing Stargate is the cost of electricity. Large AI data centres are extremely energy-intensive, and the UK has some of the highest industrial electricity prices among developed economies. In simple terms, running the same AI workloads in the UK can cost several times more than in the US. At the scale OpenAI is operating, this is not a marginal difference but a fundamental constraint on viability.

There is also a second layer to OpenAI’s problem, which is access to the grid. While data centres can be built relatively quickly, connecting them to the power network can take years. With demand for capacity rising sharply, delays of three to eight years are now common.

This combination of high costs and slow access makes it difficult to deploy infrastructure at the pace required for modern AI development.

The Regulatory Uncertainty Around Copyright

Alongside energy, OpenAI has pointed to uncertainty around UK copyright rules as being an issue in its decision. For example, the UK has yet to settle how AI companies can use copyrighted material to train models. Proposals to allow broad use with an opt-out for rights holders have faced strong opposition, and no clear framework has been finalised.

For a company like OpenAI, this creates a direct business risk. Building data centres in the UK means operating under UK jurisdiction, which could impose restrictions or costs that do not apply elsewhere.

In practical terms, therefore, it’s easier for OpenAI to delay investment than commit to infrastructure that may later face legal or compliance challenges.

The Timing

While energy and regulation are the stated reasons, what has actually changed is OpenAI’s position. The company has recently raised significant funding at a very high valuation and is widely expected to move towards a public listing. At this stage, companies typically become more disciplined about where capital is deployed.

This means that projects with uncertain timelines, high operating costs, and regulatory ambiguity are often the first to be paused. By contrast, OpenAI’s much larger Stargate programme in the US, backed by tens of billions in funding, continues to move ahead.

This suggests the UK decision is not about reducing investment overall, but about concentrating it where conditions are more predictable and returns are easier to justify.

A More Complex Investment Environment

There are also practical considerations beyond cost and policy. For example, the UK project relied in part on relatively new infrastructure partners, and more broadly, there are growing questions about how quickly large-scale AI facilities can actually be delivered in the UK.

At the same time, geopolitical risk is becoming harder to ignore. AI infrastructure is increasingly seen as strategic, and recent tensions in other regions have highlighted how exposed data centres and cloud platforms can be.

Taken together, this means site selection is no longer just about talent or market access, but also about energy availability, regulatory clarity, infrastructure readiness, and risk exposure, all at once.

What Does This Mean For Your Business?

For UK businesses, this is less about one project being paused and more about what it signals.

Access to AI capability is increasingly tied to physical infrastructure, and that infrastructure is being built where costs are lower, regulation is clearer, and deployment is faster. If those conditions are not met locally, businesses may find themselves more reliant on overseas platforms.

It also highlights how quickly investment decisions can change. Projects that appear strategically important can still be paused if the underlying economics do not work.

For organisations planning their own AI strategies, the lesson is to look beyond capability and consider where services are hosted, how resilient those supply chains are, and how exposed they may be to changes in cost, regulation, or availability.

In simple terms, AI is no longer just a software decision. It is an infrastructure decision, and those infrastructure choices are becoming more selective.

Amazon Ends Support For Older Kindles

Amazon has confirmed it will end support for Kindle devices released in 2012 or earlier from May 2026, a move that highlights how even simple, long-lasting technology is increasingly tied to ongoing platform support. It is also a useful reminder for organisations reviewing Managed IT Services.

How Amazon’s Kindle Support Changes Affect Device Lifecycle Planning

Amazon has announced that, from 20 May 2026, affected Kindle devices will no longer be able to access the Kindle Store. This means users will not be able to purchase, download, or borrow new books directly on those devices.

The list includes some of Amazon’s earliest and most widely used models, such as the original Kindle, Kindle Keyboard, Kindle Touch, and the first-generation Kindle Paperwhite.

Importantly, these devices will not stop working altogether. Users will still be able to read books that are already downloaded, and in some cases manually transfer files via USB. However, once a device is deregistered or reset, it cannot be reconnected to an Amazon account.

In practical terms, that turns these devices into static, offline readers rather than fully connected products.

Why Amazon Is Ending Support for Older Kindle Devices

Amazon says both the hardware and the software environment for devices that are between 14 and 18 years old have moved on, hence the reason for ending support. That kind of change can create planning issues for IT Support for SMEs.

Also, for Amazon, maintaining compatibility with older systems adds cost and complexity, particularly as newer services, features, and security requirements evolve. At some point, supporting legacy devices becomes less viable than focusing on current platforms. This is a fairly familiar pattern across the technology sector, and companies regularly phase out support for older products as part of normal lifecycle management.

However, what makes this case more noticeable is the nature of the Kindle itself. Unlike smartphones or laptops, e-readers have relatively simple functionality and tend to remain usable for much longer. As many disgruntled long-term users have been quick to point out on social media after hearing the news, many of the affected devices are still in full working order.

Why Device Support Matters in Managed IT Services

This situation highlights an important distinction that is becoming more relevant across all types of technology, i.e., the difference between a device that works and a device that is supported. It also underlines why Cyber Security Services and lifecycle planning often go hand in hand.

From a hardware perspective, these Kindles still function as intended. From a platform perspective, they are being disconnected from the services that give them their full value.

This means that, in effect, the usefulness of the device is no longer determined solely by its physical condition, but by its ability to connect to Amazon’s ecosystem.

This reflects a broader change in how technology products are designed and monetised. Devices are increasingly just one part of a wider service model, where ongoing access, updates, and integration are essential to the overall experience.

The Commercial Logic Behind Legacy Technology Support

There is also a clear commercial logic behind Amazon’s decision. Ending support quite simply reduces the cost of maintaining older systems and simplifies Amazon’s technology stack.

It also encourages users to move to newer devices, where Amazon can offer updated features, improved performance, and potentially new revenue opportunities. The company has already indicated it will offer discounts to affected users to support that transition.

This does not necessarily mean that the decision is purely about driving sales, but it does show how lifecycle management and commercial incentives are closely linked.

From Amazon’s perspective, continuing to support ageing devices indefinitely is difficult to justify when the majority of users have already moved on to newer models.

The E-Waste Impact of Unsupported Technology

Besides the issue that many users are still happy with their old Kindles, one other main criticism of the decision is its potential environmental impact. Many of the affected devices are still usable, and limiting their functionality raises concerns about creating more unnecessary electronic waste.

This is part of a wider issue across the industry. As software support is withdrawn, otherwise functional devices can become less useful or effectively obsolete, even if the hardware remains intact.

While Amazon’s move does not render these Kindles completely unusable, it does reduce their practical value, which may lead some users to replace them sooner than they otherwise would have done.

This tension between technological progress and sustainability is unlikely to go away, particularly as more devices become dependent on cloud-based services and ongoing updates.

What Amazon’s Kindle Support Decision Means for Your Business

For UK businesses, the immediate impact of this decision may be limited, but the underlying message is important.

Technology investments are no longer just about buying hardware. They are about buying into an ecosystem that has its own lifecycle, dependencies, and constraints.

Even devices that appear simple and stable can be affected by changes at the platform level. This creates a form of “soft obsolescence”, where products continue to function but lose key capabilities over time.

In practical terms, this means businesses need to think more carefully about lifecycle planning. That includes understanding how long products are likely to be supported, what happens when that support ends, and how easily systems can be replaced or migrated.

It also reinforces the importance of avoiding unnecessary dependency on a single provider where possible, particularly for critical systems or data access.

In short, this is not just about older Kindles. It is a reminder that in a service-driven technology landscape, control increasingly sits with the platform, not the device.

Company Check : Disclaimer : “Copilot is for entertainment purposes only”

Microsoft’s own terms of use state that Copilot is “for entertainment purposes only”, raising important questions about how AI tools are really meant to be used in business.

What The Terms Say

Buried within Microsoft’s Copilot terms is a clear warning that: “Copilot is for entertainment purposes only. It can make mistakes, and it may not work as intended. Don’t rely on Copilot for important advice. Use Copilot at your own risk.”

On the surface, this looks like standard legal language. However, some commentators have recently highlighted how this appears to sit in direct contrast to how Copilot is being positioned. For example, Microsoft is actively embedding it across Windows, Microsoft 365, and enterprise workflows, and presenting Copilot as a productivity tool for everything from writing and coding to data analysis and decision support.

Why The Disclaimer?

At its core, the disclaimer appears to be about risk management by Microsoft. Generative AI systems are probabilistic, meaning they generate responses based on patterns rather than verified facts. As a result, they can produce outputs that are plausible but incorrect, incomplete, or misleading.

This is commonly referred to as “hallucination”, and it remains a largely unresolved issue across all major AI models. Therefore, by explicitly stating that Copilot should not be relied upon for important advice, Microsoft is effectively limiting its liability if something goes wrong.

There is, however, also a second layer to this. The terms make clear that users are responsible for how they use Copilot and any consequences that follow. In practical terms, that shifts accountability away from Microsoft and onto the individual or organisation using the tool.

Not Just Microsoft

It should be noted here that this kind of disclaimer is not unique to Microsoft. OpenAI, Google, and xAI all include similar warnings in their own terms, reflecting a broader industry position that AI outputs are assistive, not authoritative.

The Gap Between Legal Position And Real-World Use

The challenge here is that this legal framing may not match how AI is actually being used. In many organisations, tools like Copilot are already being integrated into day-to-day workflows. Employees are using them to draft emails, summarise documents, generate code, and in some cases support decision-making processes.

Over time, this creates a degree of reliance, even if it is unofficial. The more useful and embedded the tool becomes, the more likely users are to trust its outputs without fully verifying them.

This is where the concept of automation bias becomes important. People tend to favour outputs generated by machines, particularly when those outputs are well-presented and appear confident. AI amplifies this effect because it produces responses that read as coherent and authoritative, even when they are not.

The result is a subtle but growing risk. Not that AI will fail completely, but that it will be trusted just enough to introduce errors into business processes.

What Does This Say About AI Maturity?

The wording in Microsoft’s terms could be said to highlight something more fundamental about the current state of AI.

Despite rapid advances in capability, these systems are clearly not yet reliable enough to be treated as independent decision-makers. They are basically tools that can assist, accelerate, and enhance work, but they still require oversight, validation, and context from human users. The fact that vendors are explicitly stating this in their legal terms suggests that the industry itself recognises the gap between capability and dependability.

This also reflects ongoing uncertainty around regulation, copyright, and accountability. For example, if an AI system generates incorrect advice, infringes intellectual property, or contributes to a business decision that causes loss, it is still not fully clear where responsibility sits.

Until those questions are resolved, vendors are likely to continue protecting themselves through broad disclaimers like this.

Why The Language May Change

Microsoft has already indicated that this wording may be updated, describing it as “legacy language” that does not fully reflect how Copilot is used today.

This suggests the company is aware of the contradiction and may move towards a more nuanced position. However, any changes are likely to be carefully balanced.

On one hand, Microsoft wants Copilot to be seen as a core productivity tool. On the other, it still needs to manage the legal and operational risks that come with deploying AI at scale.

That balancing act is not going away. If anything, it will become more pronounced as AI tools become more capable and more deeply integrated into business systems.

What Does This Mean For Your Business?

For UK businesses, the key takeaway is not that Copilot or similar tools should not be used. It is that they need to be used with a clear understanding of their limitations.

AI should be treated as a support layer, not a source of truth. Outputs should be checked, particularly where they influence decisions, customer communications, or technical implementations.

It also reinforces the need for internal controls. Clear guidelines on how AI can be used, where human review is required, and how outputs are validated are becoming essential.

There is also a broader point about responsibility here. Vendors are making it clear that the risk sits with the user, which means that businesses need to take ownership of how these tools are deployed and managed.

The key takeaway here is that AI may be marketed as a productivity solution, but it is still governed by uncertainty. Understanding that gap is what will determine whether it adds value or introduces risk.

Security Stop-Press : LinkedIn Browser Scanning Claims Raise Privacy Concerns

A “BrowserGate” report claims LinkedIn scans users’ browsers for thousands of extensions and collects device data without clear disclosure.

Researchers say LinkedIn runs a hidden script that checks for over 6,000 extensions and gathers around 48 device attributes, creating a fingerprint linked to user activity. The scanning behaviour itself has been independently verified.

LinkedIn disputes the claims, saying the detection is used to identify extensions that breach its terms, particularly scraping tools, and that it does not use the data to infer sensitive information.

Concern centres on the scale and scope of the data collected, including tools linked to competitors and potential insights into user behaviour. There are also questions about transparency, given the lack of clear disclosure in its privacy policy.

For businesses, the advice is to review browser use, limit extensions, and strengthen endpoint controls to reduce exposure of corporate activity.

Sustainability-in-Tech : How ‘Nuclear Batteries’ Could Unlock Clean Energy Efficiency

A fusion energy startup is developing a new class of nuclear battery that could help solve one of the biggest challenges in clean energy, turning radiation directly into electricity rather than wasting it as heat.

What Avalanche Energy Is Building

Avalanche Energy, a US-based fusion startup, has been awarded a $5.2 million contract from the Defense Advanced Research Projects Agency (DARPA) to develop compact “nuclear batteries” using advanced radiovoltaic technology.

These devices generate electricity by converting energy from radioactive decay, specifically alpha particles, into electrical power using semiconductor materials. The concept is similar to solar panels, but instead of converting sunlight, they convert radiation directly into electricity.

According to the company, the goal is to produce systems capable of delivering more than 10 watts per kilogram, enough to power a laptop-class device for months from a unit weighing only a few kilograms.

This is a significant step forward compared to traditional radioisotope batteries, which have historically been reliable but very low power.

Why This Matters For Fusion Energy

While the immediate application is compact power systems, the real significance lies in how this technology could support the future of fusion energy.

Fusion reactions generate enormous amounts of energy, but capturing that energy efficiently has proved difficult. Most approaches still rely on heating water and driving turbines, which introduces inefficiencies and limits overall output.

Avalanche’s approach focuses on direct energy conversion, capturing the energy of charged particles before it is lost as heat.

As the company explains, “The direct energy conversion technologies we’re developing under Rads to Watts will be essential for extracting power from fusion reactions efficiently.”

This matters because improving energy capture is one of the key barriers to making fusion commercially viable. Even if a reactor produces more energy than it consumes, that energy still needs to be converted into usable electricity in a practical and efficient way.

A Step Towards Portable, Low-Carbon Power

Beyond fusion, these nuclear batteries could offer a new type of long-duration, low-maintenance power source.

Unlike conventional batteries, they don’t need recharging in the traditional sense. Instead, they produce a steady flow of electricity over extended periods, making them suitable for environments where access to power is limited or unreliable.

DARPA’s interest reflects this potential. The programme is focused on systems that can operate in extreme environments, including space, remote locations, and infrastructure where logistics make refuelling difficult.

In terms of this broader ambition, Avalanche says: “We’re building the capabilities today that will enable tomorrow’s fusion systems to deliver reliable, portable energy for defence, space, and commercial applications.”

In sustainability terms, this could point to a future where certain applications currently dependent on diesel generators or frequent battery replacement could move to cleaner, longer-lasting alternatives.

How This Fits Into The Wider Industry

It should be noted here that Avalanche is not alone in exploring alternative ways to generate long-duration power from nuclear processes.

Companies such as US-based Zeno Power are developing radioisotope power systems designed for remote infrastructure, including maritime and Arctic applications. Zeno focuses on long-life nuclear batteries that can operate for years without maintenance.

Also, organisations like NASA and the US Department of Energy have long used radioisotope thermoelectric generators in space missions, including the Perseverance and Curiosity Mars rovers, demonstrating the reliability of nuclear-based power systems over decades.

In the private sector, firms such as Kronos Advanced Technologies and Arkenlight are also researching next-generation radiovoltaic and betavoltaic systems aimed at improving efficiency and power density.

What makes Avalanche’s approach distinct is its direct link to fusion. For example, rather than treating nuclear batteries as a standalone product, it is using them as a stepping stone towards solving a core technical challenge in fusion energy itself.

This reflects a broader trend in the industry, where companies are focusing on specific bottlenecks such as materials, energy capture, and system design, rather than attempting to solve fusion as a single problem.

What Does This Mean For Your Organisation?

For businesses, this development is less about immediate adoption and more about understanding where energy technology is heading.

The key takeaway is that the future of clean energy is not just about generation, it is about efficiency, portability, and reliability. Technologies that can deliver consistent, low-carbon power in difficult environments will open up new operational possibilities.

In the shorter term, this kind of innovation signals a move towards more resilient energy systems. Businesses operating in remote locations, critical infrastructure, or energy-intensive sectors may benefit from future solutions that reduce reliance on traditional fuel supply chains.

It also highlights the pace at which energy innovation is moving. Fusion is often seen as a distant goal, but the supporting technologies being developed today, including advanced materials and direct energy conversion systems, are already shaping the path towards it.

While nuclear batteries may not be powering offices or factories tomorrow, they represent a step towards a more flexible, sustainable energy landscape where power can be generated and used far more efficiently than it is today.

Video Update : Cowork Now Available In Copilot

Microsoft’s new ‘Cowork’ feature in Copilot lets you assign tasks by simply describing the outcome, with Copilot creating a plan, using your Microsoft 365 data, and carrying out tasks across apps in the background while keeping you in control at every step.

[Note – To Watch This Video without glitches/interruptions, It may be best to download it first]

Tech Tip : Check If Your Files Are Only Saved In Downloads

Important files are often left in the Downloads folder and never backed up, so moving them to a synced or backed-up location helps prevent accidental data loss if your device fails or is lost.

Why This Matters

The Downloads folder is one of the most commonly used locations for saving files, especially when opening email attachments or downloading documents from the web.

However, it is often not included in automatic backup or cloud sync settings.

This means files stored there may only exist on one device.

If that device is lost, damaged or replaced, anything stored only in Downloads could be permanently lost.

How To Check Your Downloads Folder In Windows

  1. Open File Explorer.
  2. Click on Downloads in the left-hand menu.
  3. Review the files stored there.

Look for anything important that should be kept long term.

What To Do Next

  • Move important files to Documents, Desktop or another backed-up folder.
  • Or save them directly into OneDrive or your company’s shared storage.

If your organisation uses OneDrive folder backup, ensure key folders are being synced properly.

What To Watch For

  • Files in Downloads are often temporary by nature.
  • Important documents can easily be forgotten there.
  • Backups and sync tools may not include this folder by default.

A Practical Approach

Take a minute to check your Downloads folder now.

Moving important files into a backed-up location is a simple habit that can prevent unnecessary data loss and ensure your work is properly protected.

Google Brings ‘Q-Day’ Closer With 2029 Encryption Warning

Google has warned that the moment quantum computers can break today’s encryption may arrive within the next few years, accelerating timelines for businesses to prepare for a fundamental change in digital security.

What Is ‘Q-Day’?

Q-Day refers to the point at which a quantum computer becomes powerful enough to break widely used cryptographic systems such as RSA and elliptic curve encryption, which underpin everything from online banking to software updates.

Google’s position is that this is no longer a theoretical concern for the distant future. As the company warned in its earlier guidance, “the encryption currently used to keep your information confidential and secure could easily be broken by a large-scale quantum computer in coming years.”

The Risk Is Already Emerging

Attackers are also believed to be collecting encrypted data today with the intention of decrypting it later once quantum capabilities become available, a tactic often referred to as ‘store now, decrypt later’.

Google Revises Its Timeline

In a recent update, Google has set out a more urgent timeline for the transition to post-quantum cryptography, signalling that the industry may have less time than previously expected to prepare for this moment.

The company has now introduced a 2029 target for completing its migration to quantum-resistant cryptography, bringing forward urgency compared to earlier industry expectations that placed large-scale quantum threats in the mid-2030s, and stating: “We’re setting a timeline for post-quantum cryptography migration to 2029.”

Not A Direct Prediction

It’s worth noting here that this isn’t a direct prediction from Google of when exactly quantum computers will most likely break encryption, but it provides some guidance and a reassessment of how quickly organisations need to act.

Why The Updated Timeline?

Google said the change is based on recent progress in “quantum computing hardware development, quantum error correction, and quantum factoring resource estimates”.

In simple terms, it seems the technical barriers that once made quantum threats feel distant are being reduced faster than expected.

Google’s update of Q-Day is not simply about setting a date, it is about creating urgency. The company has made this explicit in a recent blog post about the update, stating: “As a pioneer in both quantum and PQC, it’s our responsibility to lead by example and share an ambitious timeline.” It added that the goal is to “provide the clarity and urgency needed to accelerate digital transitions not only for Google, but also across the industry.”

This reflects a broader concern that organisations are underestimating the scale and complexity of the transition required.

This urgency also reflects the scale of what organisations are being asked to do. For example, moving from current cryptographic standards to post-quantum alternatives is not a simple upgrade. It involves identifying where encryption is used, replacing algorithms across systems, updating infrastructure, and ensuring compatibility across supply chains and partners.

The UK’s National Cyber Security Centre has already described this transition as a “complex change programme”, highlighting the scale of the task facing organisations.

The Gap Between Awareness And Readiness

Despite growing awareness of quantum risks, most organisations are not ready.

Part of the challenge is that the threat itself is difficult to fully understand. Quantum computers are often described as vastly more powerful than today’s systems, and for many businesses, this means the practical implications are unclear. Understanding how and when these machines could break existing encryption, and what that means for real-world systems, is not straightforward without some specialist knowledge.

Research cited in industry reports suggests that while a majority of businesses expect quantum-enabled attacks within the next five years, only a small proportion have a clear roadmap in place to address them.

This means that while many organisations accept that quantum threats are coming, there is still uncertainty about how serious those risks are, when they are likely to materialise, and what practical steps should be taken. That uncertainty can easily lead to delays or a tendency to wait for clearer standards and tools rather than acting early.

Google’s revised timeline challenges that assumption by bringing forward its own migration target and signalling that waiting may not be a viable strategy.

What Google Is Already Doing To Help

Alongside announcing its timeline update, Google says it is actively deploying post-quantum cryptography across its own platforms.

The company has highlighted how Android 17 will integrate PQC digital signature protection using ML-DSA, aligned with standards from the National Institute of Standards and Technology.

This is part of a broader effort to build what Google describes as a “new, quantum-resistant chain of trust”, ensuring that systems remain secure even as computing capabilities evolve.

Google says it has also been working on PQC for several years, including deploying quantum-resistant key exchange mechanisms in Chrome and internal systems, and contributing to global standards development, all of which points to the fact that the transition is not only necessary, but already underway.

Why This Matters

The implications extend far beyond large technology providers. For example, encryption underpins core business functions, from securing customer data and financial transactions to protecting intellectual property and ensuring the integrity of software and communications.

If current cryptographic systems become vulnerable, the impact will not be limited to future systems. Data encrypted today could still be exposed years later if it is harvested and stored by attackers now.

That means the risk is already present, even if the technology required to exploit it fully is not yet available.

What Does This Mean For Your Business?

For most organisations, the key issue here is not whether quantum computing will affect them, but how prepared they are for the transition it will require.

Google’s updated timeline suggests that preparation needs to begin sooner rather than later, particularly for systems that rely on long-lived data or digital signatures that must remain secure for many years.

This will involve building what is often referred to as crypto agility, the ability to update cryptographic algorithms without disrupting services, as well as developing a clear inventory of where and how encryption is used across the organisation. In practical terms, that means identifying where sensitive data is stored, how it is protected in transit and at rest, and which systems rely on public key cryptography that may need to be replaced.

It also means starting to assess whether existing platforms, applications and suppliers are capable of supporting post-quantum cryptography, and whether updates, migrations or architectural changes will be required. Some organisations are already beginning to test quantum-resistant algorithms in non-critical systems to understand performance, compatibility and operational impact before wider rollout.

Engagement with suppliers and partners will also be important, as cryptographic systems rarely operate in isolation and weaknesses in third-party systems can undermine otherwise secure environments.

Taken together, Google’s update suggests that the window for treating quantum security as a future concern is narrowing, and that organisations that begin mapping, testing and planning now will be in a far stronger position than those that wait.

Scammers Using Virtual Smartphones To Slip Past Fraud Checks

Fraudsters are increasingly using rentable “cloud phones” that look and behave like real smartphones, creating a new problem for banks, fintechs and businesses that have come to trust the device in a customer’s hand.

Now Using Cloud Phones

According to a recent report by security firm Group-IB, a growing number of scammers are no longer relying on crude emulators or racks of physical handsets to run fraud at scale. Instead, they are turning to cloud phones, effectively remote Android devices running in datacentres, which can be rented cheaply and accessed over the internet.

These services are marketed as legitimate tools for developers, marketers or businesses managing multiple accounts but, in practice, it seems they are also now being widely abused. As the report explains, “what began as a simple scheme to inflate social media metrics has evolved into a sophisticated threat that is quietly reshaping the economics of digital fraud.”

This matters because many fraud controls were built around the idea that fake devices tend to look fake. For example, emulators often leak obvious signs, such as unusual hardware configurations, missing sensor data or other artefacts that security teams know how to spot.

Cloud phones, however, don’t give off these more obvious signals. As Group-IB says, they are “for all intents and purposes… real phones, running genuine firmware, exhibiting natural sensor behavior, and presenting valid hardware attestation.” In other words, they are designed to look authentic at the technical level.

Why They Are So Hard To Detect

Fraud detection systems have traditionally relied on identifying unusual devices, spotting changes in device identity, or flagging suspicious technical signals, all of which have proven effective against earlier generations of emulators and virtual environments.

Cloud phones, however, are designed to avoid exactly those signals by maintaining consistent device characteristics over time while presenting realistic hardware identifiers, software environments and behavioural patterns that closely resemble those of genuine smartphones.

The report highlights that “what makes this threat unlike any other is its invisibility,” noting that activity from these devices can “appear indistinguishable from a legitimate device” to existing detection systems.

Each cloud phone instance can have its own device ID, IP address, geolocation and system profile. Unlike traditional emulators, which often expose tell-tale inconsistencies, these environments are engineered to behave like genuine smartphones over time.

It’s this consistency that’s critical because it allows a device to build up a trusted history, which can then be exploited for fraud without triggering alerts designed to detect sudden changes.

How The Fraud Works In Practice

Group-IB’s report traces how this technology has moved from social media manipulation into financial crime. One of the most significant use cases is the creation and operation of so-called ‘dropper’ or ‘mule accounts’, which are accounts used to receive and move stolen funds.

For example, it seems that fraudsters can open or verify accounts using a cloud phone, then continue to access those accounts from the same virtual device. In some cases, access to both the account and the associated cloud phone instance can be sold on to other criminals.

As Group-IB explains, this creates a powerful advantage for the fraudsters because the same device signals are preserved throughout, meaning “the same device accessing the account that has always accessed it” appears to be in use (once again, it’s the consistency that works).

From a fraud detection perspective, that removes one of the key triggers for additional checks, i.e., there’s no obvious device change, no sudden shift in behaviour, and no immediate reason to challenge the transaction.

The Scale Of The Problem

This development comes at a time when authorised push payment fraud (where victims are tricked into sending money directly to a scammer, often through social engineering) is already a major issue. For example, in the UK alone, losses reached £485.2 million in 2023, with mule accounts playing a central role in moving stolen funds.

Cloud phones make these accounts easier to create, operate and scale. Group-IB says they have enabled “industrial-scale financial fraud” by lowering the cost and complexity of maintaining large numbers of apparently legitimate devices.

It seems that using cloud phones also gives fraudsters an extra economic advantage. Instead of investing in physical phone farms, fraudsters can now rent infrastructure on demand, making it accessible to a wider range of actors with relatively low upfront cost.

Why This Challenges Existing Security Models

For years, device fingerprinting has been a reliable layer in fraud prevention. If an account is accessed from a new or suspicious device, that can trigger step-up authentication or block the transaction.

Cloud phones weaken that model because the device itself is no longer a strong signal of trust if it can be rented, replicated and transferred between users while maintaining a consistent identity.

This doesn’t mean existing controls are obsolete, but it does mean they are no longer sufficient on their own. Group-IB’s report argues that detection must, therefore, move beyond simple device checks and towards a more layered approach.

Group-IB concludes that fraud prevention needs “device-environment correlation, infrastructure-level visibility, behavioral modeling, and graph-based analytics” to identify patterns that individual device checks may miss.

What Does This Mean For Your Business?

For financial institutions, the message from this report is clear. A device that looks genuine can no longer be treated as strong evidence that the activity behind it is genuine too. Fraud detection will really need to focus more on behaviour, context and relationships between accounts rather than relying heavily on device identity alone.

For other businesses, particularly those using mobile apps for onboarding, payments or identity verification, this is a warning that mobile trust models are becoming more complex. Controls that once worked well may now need to be reassessed.

There is also a broader operational implication. As fraud infrastructure becomes easier to rent and scale, the barrier to entry for sophisticated attacks is lowering. That increases the likelihood that smaller organisations, not just major banks, will encounter more advanced fraud techniques.

This represents a clear change in how fraud is delivered, as the fraudster no longer needs to manage large numbers of physical devices and can instead access a virtual environment that behaves like a real smartphone and is designed to pass as one.

Taken together, this research seems to suggest that the balance of trust is changing, with the device in the user’s hand, or at least the one it appears to be, no longer something businesses can rely on without question.