· artificial intelligence · 5 min read

AI and cloud briefing: EU AI Act transparency rules take effect, plus OpenAI's Astra cracks a 27-year-old maths problem

A short, factual briefing for 3 August 2026: the EU starts enforcing new AI transparency rules on chatbots and deepfakes, Microsoft fixes a critical Azure Cosmos DB flaw called CosmosEscape, OpenAI's internal Astra model solves ten open problems in mathematics with machine-checked proofs, and a Chinese-speaking hacker runs autonomous cyber attacks using DeepSeek.

A short, factual briefing for 3 August 2026: the EU starts enforcing new AI transparency rules on chatbots and deepfakes, Microsoft fixes a critical Azure Cosmos DB flaw called CosmosEscape, OpenAI's internal Astra model solves ten open problems in mathematics with machine-checked proofs, and a Chinese-speaking hacker runs autonomous cyber attacks using DeepSeek.

Here is our latest round-up of what matters in AI and cloud for UK businesses. It is short and factual, with links to credible sources so you can read further.

Lead story: the EU starts enforcing AI transparency rules

From 2 August, the European Commission’s AI Office, together with national authorities, began enforcing new transparency rules under the EU AI Act. Chatbots and other interactive AI systems must now tell users they are dealing with AI, not a human. Deepfakes, meaning images, video or audio that has been edited or generated using AI, must be labelled. AI-generated or altered content must also carry machine-readable marks so it can be detected more easily.

The European Commission has begun enforcing new AI transparency rules requiring chatbots to disclose they are AI and deepfakes to be labelled

The Commission has already published a first list of more than 180 organisations that have signed the Code of Practice on transparency of AI-generated content, the voluntary framework that sets out how businesses can meet the new duties in practice.

What is significance: these obligations apply to AI systems used by, or targeting, people in the EU. UK businesses that sell into the EU, or that run customer-facing chatbots and AI content tools reaching EU users, are in scope even though the UK has its own separate approach to AI regulation.

Our Advice this week:

  • Check whether any chatbot, virtual assistant or AI content tool you run reaches EU customers, and confirm it discloses that it is AI.
  • If you generate marketing images, video or audio with AI and it could reach EU audiences, review whether it needs a visible or machine-readable label.
  • Read the Code of Practice before assuming you need custom legal advice. It is designed to give a practical, ready-made way to demonstrate compliance.

Cyber security alert: a critical flaw let researchers take over every Azure Cosmos DB database

Wiz researchers disclosed CosmosEscape, a vulnerability chain in Azure Cosmos DB’s Gremlin API that allowed full read and write access to every database on the platform, including some managed internally by Microsoft. The flaw came from insufficient security restrictions in the custom Gremlin query engine, which let researchers use .NET reflection techniques to access files and run arbitrary code on the Cosmos DB backend. Wiz reported the issue to Microsoft in November 2025, and Microsoft shipped a hotfix within 48 hours that blocked the vulnerable entry point, followed by a full architectural fix completed across all regions in July 2026. Coverage is also available from The Hacker News and SecurityWeek.

Wiz researchers found a critical Azure Cosmos DB flaw called CosmosEscape that Microsoft has now fixed

What is significance: Microsoft says no customer data was accessed outside of Wiz’s own research, and the flaw is now fixed. But it is a reminder that a single weakness in a shared backend query engine can expose an entire multi-tenant cloud service, not just one customer’s data.

Our Advice: if you run Azure Cosmos DB with the Gremlin API, confirm your instance has received the architectural fix, and treat this as a prompt to review how your cloud provider isolates tenants in any database service you rely on.

Also in AI: OpenAI’s Astra model solves ten open mathematics problems

OpenAI has published ten proofs of previously open problems in mathematics and theoretical computer science, produced by an internal version of a model it calls Astra. Every proof ships with a machine-checkable Lean 4 certificate, verified independently rather than taken on trust. The headline result is the first explicit construction of a non-sofic group, a question in group theory that had stood open since 1999. The results also include new upper bounds on sphere-packing density, the first general improvement to the leading bound since 1978. OpenAI published a 249-page manuscript alongside the Lean proofs on GitHub for anyone to check.

OpenAI's Astra model solved ten open mathematics problems including a 27-year-old question about non-sofic groups

What is significance: machine-checked proofs remove the usual doubt about whether an AI system’s mathematical claims are actually correct. This is a meaningful marker of AI capability in formal reasoning, distinct from the more general claims often made about chatbot performance.

Quick note: a hacker ran autonomous cyber attacks using DeepSeek

Palo Alto Networks’ Unit 42 detailed a campaign by a Chinese-speaking actor, tracked as “knaithe”, who wired the DeepSeek model into the open-source Hermes Agent framework and directed it over Telegram to find targets, source exploits and attack more than 460 internet-facing systems. Unit 42 confirmed three successful compromises, including data exfiltration from Citrix NetScaler systems. The operation was exposed after Hermes Agent, following a Telegram command, launched a file server from an unsecured directory, revealing the attacker’s tools, target lists and session logs.

What is significance for smaller businesses: this is one of the clearest public examples yet of an AI model driving an attack chain with limited human oversight. It reinforces that basic hygiene, patching internet-facing systems and closing exposed services, remains the most effective defence against both human and AI-directed attackers.

The takeaway

Four stories, one thread: AI is now embedded deeply enough in daily life that regulators are enforcing disclosure rules, cloud vendors are racing to close platform-wide flaws, AI models are producing independently verifiable results in formal mathematics, and the same models are being weaponised for autonomous attacks. Businesses that keep basic compliance, patching and oversight habits in place will handle all of this more easily than those treating AI as someone else’s problem. If you would like help reviewing your AI compliance or your cloud security posture, get in touch.


AI Agent based research and content, AI can do mistake, please help us to improve.

Back to Blog