· artificial intelligence · 5 min read

AI and cloud briefing: Microsoft's biggest Patch Tuesday of the year, Anthropic watermarks Claude, and Nvidia lines up $500bn for AI infrastructure

Microsoft's August update fixes 394 vulnerabilities, including three zero-days with one already under active attack. Anthropic starts adding invisible watermarks and provenance metadata to everything Claude generates, worldwide. And Nvidia lines up six Wall Street firms to mobilise over $500 billion in financing for AI data centres and compute.

Microsoft's August update fixes 394 vulnerabilities, including three zero-days with one already under active attack. Anthropic starts adding invisible watermarks and provenance metadata to everything Claude generates, worldwide. And Nvidia lines up six Wall Street firms to mobilise over $500 billion in financing for AI data centres and compute.

Here is our latest round-up of what’s changing in AI and cloud for UK businesses, with links to the original sources so you can read further.

Lead story: Microsoft’s August Patch Tuesday fixes 394 flaws, one already under attack

Microsoft’s August 2026 security update, released on 11 August, fixes 394 vulnerabilities across Windows, Microsoft Office, SharePoint Server, Azure, .NET, PowerShell and Visual Studio Code. Three of them are zero-days. Two were publicly disclosed before the fix shipped: CVE-2026-72971, a tampering flaw in the Windows Container Isolation driver, and CVE-2026-62832, an elevation-of-privilege flaw in the Windows User Profile Service. The third, CVE-2026-68820, an elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock, is already being exploited in the wild. Elsewhere in the release, CVE-2026-71331 is a Critical remote code execution flaw in the Azure Attestation service, and several more Important-rated flaws affect internet-facing SharePoint servers. Full detail is available from Cyber Security News and BleepingComputer.

Microsoft's August 2026 Patch Tuesday fixes 394 vulnerabilities including three zero-days, with CVE-2026-68820 already exploited in the wild

Why this matters: CVE-2026-68820 being actively exploited moves it straight to the top of the queue, ahead of anything simply rated Critical. Elevation-of-privilege flaws like this one are commonly the second step in an attack, after a phishing email or stolen password gets someone onto a machine. If your business runs Windows endpoints, Azure services, or internet-facing SharePoint, check with your IT provider that this month’s update has been applied, and prioritise the three zero-days first.

AI: Anthropic starts watermarking everything Claude generates

Anthropic has begun adding invisible, machine-readable watermarks to text generated by Claude, alongside signed provenance metadata for supported image files using the C2PA standard. The text watermark does not change how the output reads; it survives copying, pasting and some light editing, and is designed to let authorised tools detect that Claude was involved in producing the content. New Claude models launched from 2 August 2026 apply the marking at the model level, and Anthropic says it will apply worldwide, not only where its originating regulation, Article 50 of the EU AI Act, applies. Anthropic is upfront that the system has limits: the image metadata can be stripped by conversion, re-saving, or a screenshot, and heavy rewriting can weaken the text signal. Further detail is available from Cyber Security News and The Decoder.

Anthropic adds invisible watermarks to Claude-generated text and C2PA provenance metadata to images, rolling out worldwide from 2 August 2026

Why this matters: as AI-written content becomes harder to spot by eye, model-level provenance signals like this give publishers, schools and businesses another way to check where content came from, even though no watermark is foolproof on its own. Worth knowing if your business publishes AI-assisted content and needs to show its working under the EU AI Act or similar rules.

Cloud and AI infrastructure: Nvidia lines up $500bn in financing from Wall Street

Nvidia has signed agreements with six of the largest US investment firms, Apollo Global Management, BlackRock, Blackstone, Brookfield Asset Management, Goldman Sachs and KKR, to establish financing platforms aimed at mobilising more than $500 billion in third-party capital for AI compute infrastructure. The money is intended to help Nvidia’s customers fund data centres, power supply and other infrastructure needed to run large AI workloads, without that debt sitting on Nvidia’s own balance sheet. The agreements are memorandums of understanding rather than a single committed fund, and the $500 billion is a target for capital the platforms aim to mobilise over time, not money already spent. Coverage is available from Nvidia’s newsroom and CNBC.

Nvidia partners with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR to mobilise over $500 billion in financing for AI compute infrastructure

Why this matters: this is a sign of how much capital the AI infrastructure build-out now needs, and of financing itself becoming part of the AI supply chain, not just chips and cloud contracts. For most UK businesses this is background context rather than a direct action item, but it points to continued heavy investment in AI compute capacity, and continued competition among cloud providers for that capacity, over the next few years.

The takeaway

Two different signals converged this week. Anthropic and the wider AI industry are building more accountability into AI output, while Nvidia and its financing partners are backing an enormous expansion of the infrastructure that AI runs on. Set against that, Microsoft’s largest Patch Tuesday vulnerability count so far this year, with one flaw already under active attack, is a reminder that the basics of patching still carry real weight. If your business runs Windows, Azure or SharePoint, treat this month’s update as high priority, starting with the actively exploited flaw. If you would like help reviewing your patching process or understanding what AI content provenance rules mean for your business, get in touch.


AI Agent based research and content, AI can do mistake, please help us to improve.

Back to Blog