← The State of Tech RSS Feed

2 september 2026 · 14:20

Google DeepMind 3.8 Flash: AI cracks industrial controls

Google DeepMind is rolling out 3.8 Flash, a new coding-focused AI model designed to challenge Anthropic and OpenAI in the developer market. In the same news cycle, Forescout researchers show that frontier AI can meaningfully lower the skill barrier for attacking water and energy infrastructure. This episode unpacks both stories from a European regulatory and business perspective.

Google DeepMind Palo Alto Networks Cybersecurity Industrial Control Systems OpenAI Construction Robotics

Beluister deze aflevering:

Transcript

Samantha: Welcome to The State of Tech, The European Edition, Wednesday September two, 2026. I'm Samantha Lawrence.

Bob: And I'm Bob Russell. Today: Google DeepMind's new coding model, Palo Alto Networks buys an AI agent platform, frontier AI cracking industrial controls in tests, OpenAI's new safeguarded model, a swarm robotics grant for timber buildings, and two things you can try today, the writing app Zim Desktop Wiki and the offline photo tool Cwtch. Let's get into it.

Google DeepMind launches a new coding-focused AI model, aiming to close the gap with OpenAI and Anthropic.

Samantha: Google's DeepMind unit is rolling out a new AI model today, officially called 3.8 Flash, internally nicknamed Skimaki. The headline feature is a big step up in coding ability. Google has been publicly playing catch-up in AI-assisted software development, where OpenAI's and Anthropic's models have set the pace with developers for over a year now.

Bob: And that lag is not just a bragging-rights issue. Coding assistants have quietly become the single most-used serious application of generative AI. It is where companies actually pay per seat, and where usage is sticky. If DeepMind can convince engineering teams that this Flash version writes cleaner code, catches its own bugs and plugs into existing tools without friction, that shifts real revenue. The name Flash suggests Google is going for the speed-and-cost tier, not the top-end reasoning model, which is where a lot of everyday coding work actually happens.

Samantha: The strategic backdrop is interesting too. Anthropic's Claude has become the developer favourite over the past year, and OpenAI keeps pushing coding features inside ChatGPT. Google's answer is to lean on its integration story: Android, Chrome, Workspace, its own cloud. If the model is genuinely competitive, it lands in front of a huge captive audience of developers who already use Google tools daily.

Bob: For European developers and the tech sector here, this matters practically. A stronger, cheaper coding model available through Google's European cloud regions gives smaller software firms an alternative that keeps data closer to home. Europe has a chronic shortage of senior software engineers, and better AI assistants are one of the few levers that actually help small teams punch above their weight. The catch, as always, is that "close the gap" only counts once independent benchmarks and real-world users confirm it. Watch the developer forums this week, that is where the honest verdict shows up first.

Palo Alto Networks buys AI agent platform Console to speed up security operations.

Samantha: Cybersecurity giant Palo Alto Networks has announced it is buying Console, a startup that builds AI agents for automating operational tasks through plain language instructions. Console gets folded into Cortex, Palo Alto's security operations platform. The pitch: security teams can investigate alerts, prioritise threats and automate response steps by simply describing what they want, rather than writing detection rules by hand.

Bob: The logic behind this deal is the volume problem. A big enterprise security team is drowning in alerts, most of them false positives, and the average time to triage a real incident is measured in hours, sometimes days. Agentic AI that can chase down a suspicious signal, cross-check it against other data sources and either close it out or escalate it, that is genuinely useful, not a demo. Whether Console's tech actually delivers at scale is the next question.

Samantha: It also fits a pattern. Every major cybersecurity vendor is now buying or building agent capabilities: CrowdStrike, SentinelOne, Microsoft. The bet is that within two years, the security analyst's job looks more like supervising AI agents than clicking through dashboards. That is a big cultural shift for security teams, and it raises real questions about accountability when an agent takes action automatically.

Bob: For European businesses, this matters because most large firms here already use Palo Alto as a core supplier. Faster, smarter automated response is welcome given the attacker side is also using AI to scale up phishing and intrusions. The concern is oversight. Under the NIS2 directive and the AI Act, an autonomous agent that isolates a server or blocks a user account is a decision with legal weight. European buyers will want clear audit logs and human-in-the-loop controls, not just a promise that the AI got it right.

Samantha: Quick interruption. If you listen to The State of Tech regularly, hit that like button and subscribe, that way you'll never miss an episode. Okay, moving on.

Frontier AI helps researchers exploit vulnerabilities in industrial control systems used by water and energy firms.

Bob: Researchers at Forescout's Vedere Labs have published a report showing that Anthropic's Claude model can be used to help exploit vulnerabilities in programmable logic controllers. These are the small industrial computers that run water treatment plants, energy grids, factories and rail signalling. In a controlled test environment, Claude helped the researchers port a known remote code execution flaw to attack a PLC directly. In plain terms, the AI acted as a skilled assistant for an attack that would normally require a specialist.

Samantha: The uncomfortable finding is not that the AI invented a new attack, it is that it lowered the skill barrier. Historically, attacking industrial control systems required deep, niche expertise. Only a handful of state-linked groups had it. If frontier models can walk a moderately skilled attacker through the same steps, the pool of people who could plausibly attack a water utility just got much bigger. Anthropic and other vendors do apply safety filters, but the Forescout team clearly found workable paths within a research context.

Bob: For Europe, critical infrastructure security is already a top priority since the sabotage incidents of the last few years and the NIS2 rules that came into force. This report will land on the desks of national cyber agencies this week. Expect renewed pressure on utilities to segment their networks, patch aggressively, and treat any internet-exposed PLC as an emergency. And expect renewed political debate about how much responsibility AI vendors carry when their models help attackers, even in test scenarios. The gap between "responsible disclosure research" and "actual attack playbook" is uncomfortably thin.

OpenAI launches new model Astra with stronger safeguards after a security breach.

Samantha: OpenAI is releasing a new model called Astra, and this launch comes with an unusual amount of security messaging. The company paused parts of its model development after a recent breach involving two internal test models and a related incident tied to software firm Hugging Face. In a blog post, OpenAI says Astra has been specifically trained to refuse harmful cyber requests more reliably and to stick to its safety restrictions under pressure.

Bob: This is a direct response to a genuinely bad few months for the company on the security front. The details of the earlier breach have been drip-feeding out, and it clearly rattled things internally. Training a model to be more resistant to jailbreaks and malicious prompts is one part of the answer. The other part, which OpenAI is being quieter about, is the infrastructure side: how the models are hosted, who can access weights, and how third-party integrations like Hugging Face are governed. A safer model in a leaky system is not really safer.

Samantha: What's notable is the shift in tone. Two years ago, launches were about new capabilities. Now, launches lead with safety claims. That reflects both regulatory pressure and market pressure from enterprise customers who need to justify AI deployments to their own compliance teams.

Bob: For European users and businesses, stronger refusal training and tighter safety controls are exactly what regulators under the AI Act have been asking for. It should ease some procurement conversations, particularly in finance, healthcare and public sector. That said, "trained to refuse" is a probabilistic guarantee, not an absolute one. Independent red-teamers will pick at Astra within days. The real verdict comes from them, not from OpenAI's own blog post.

A four-million-euro European grant funds robot swarms that assemble timber buildings from the ground up.

Samantha: On to something completely different, and refreshingly non-AI. A European research consortium has won a three-year grant worth just under four million euros to build a swarm-robotics system for constructing timber buildings. The project is called SWIFT-BUILD, and the partners include architecture firm Foster and Partners along with several universities. The approach is genuinely clever: robots assemble each timber floor at ground level, then the whole floor gets lifted so the next layer can be built underneath it. Drones monitor progress from above.

Bob: The construction sector is one of the least digitised parts of the European economy, and it is also one of the biggest sources of carbon emissions and waste. Timber construction is already growing fast because engineered wood stores carbon and can be prefabricated. SWIFT-BUILD adds two things: automation, which addresses the chronic shortage of skilled construction workers across Europe, and reversible mechanical connections. That last bit matters a lot. It means when a building reaches end of life, the timber components can be unclipped and reused, rather than shredded. That is the circular economy actually working in practice.

Samantha: For Europe, this is the kind of project the EU's research funding was designed for. Construction robotics is an area where Europe can build real industrial strength, given how much timber, engineering talent and sustainability regulation already exists here. And having Foster and Partners involved gives it credibility with the architects and developers who ultimately decide whether to try new methods. Three years is a realistic timeline for a working prototype, not a finished product. But if it works, mid-rise timber housing in European cities could look very different by the early 2030s.

Zim Desktop Wiki turns your laptop into an offline personal knowledge base you actually control.

Bob: To close out, two things you can genuinely use today. The first is Zim Desktop Wiki. It is a free, open-source note and knowledge management app for Windows, Mac and Linux. Instead of storing your notes in someone else's cloud, Zim keeps everything as plain text files in a folder on your own machine, structured like a personal wiki. Pages link to other pages, you can add checklists, tables, diagrams and attachments, and the whole thing works offline forever. There is no account, no subscription, no telemetry.

Samantha: Zim has been quietly maintained for years and has a devoted following among researchers, writers and engineers. The strength is longevity. Because notes are stored as ordinary text files, they will still be readable in twenty years, regardless of what happens to the project itself. That is a rare guarantee in the current app landscape, where services shut down and lock users out routinely.

Bob: Users report it works well for meeting notes, project planning, personal journals, technical documentation, even light book writing. There is a built-in journal feature that creates a new page for each day, which many people use as a daily log. The learning curve is small: if you have used any wiki-style app before, you will feel at home within twenty minutes. And the search across your entire notebook is fast, even with thousands of pages.

Samantha: The European angle is straightforward. Zim is a European-developed open-source project, and because everything runs locally, there is no data protection question to answer. Nothing leaves your device unless you deliberately sync the folder yourself, which you can do through any file sync tool you already trust. For anyone tired of monthly note-taking subscriptions or worried about cloud provider changes, Zim is worth a try this afternoon. Download it, spend fifteen minutes clicking around, and you will know whether it fits.

Cwtch lets you send fully anonymous encrypted messages without a phone number, email or account.

Bob: The second try-this-today pick is Cwtch, spelled C-W-T-C-H, a Welsh word roughly meaning a warm hug. It is a free, open-source, decentralised messenger for Windows, Mac, Linux and Android. What makes Cwtch different from Signal or WhatsApp is that it runs entirely over the Tor network and requires no phone number, no email, no server account of any kind. You generate an anonymous identity on your device, share a contact code with the person you want to chat with, and that is it.

Samantha: The design goal is metadata privacy. Even encrypted messengers usually leak who is talking to whom, and when. Cwtch is built so that not even the network can see that. It is genuinely aimed at journalists, activists, people in sensitive professions, and anyone who simply does not want their communication patterns logged anywhere.

Bob: The trade-offs are honest. Messages can be slower than a normal chat app because everything routes through Tor. And because there is no central server, if both devices are offline, messages wait. It is not a WhatsApp replacement for family group chats. It is a serious tool for specific situations where anonymity matters. Setup takes about five minutes, and the interface is surprisingly clean given the underlying complexity.

Samantha: Today we covered: Google DeepMind's new coding model 3.8 Flash, Palo Alto Networks buying agent platform Console, frontier AI helping exploit industrial control systems, OpenAI's safer new model Astra, the SWIFT-BUILD European swarm robotics grant, and two things to try yourself: the personal knowledge base Zim Desktop Wiki, and the anonymous messenger Cwtch.

Bob: Want to know more or react? Visit stateoftech.eu or email us at info@doorzetters.net.

Bob: State of Tech, the tech world in 15 minutes.