· artificial intelligence · 5 min read
AI and cloud briefing: EU AI Act fines go live, plus a critical Langflow flaw under active attack
A short, factual briefing for 5 August 2026: the European Commission gains real fining power over frontier AI model makers, CISA orders urgent patching of a critical IBM Langflow flaw already being exploited, Anaconda buys AI security firm Enkrypt AI after it found 143,000 vulnerabilities across scanned MCP servers, and a US appeals court rules that Perplexity is not liable for its Comet agent shopping on Amazon.

Here is our latest round-up of what matters in AI and cloud for UK businesses. It is short and factual, with links to credible sources so you can read further.
Lead story: EU AI Act fines go live for frontier model makers
From 2 August 2026, the European Commission’s AI Office gained real enforcement power over providers of general-purpose AI models, including the systems behind ChatGPT, Claude and Gemini. The Office can now request technical documentation, evaluate models directly, demand risk-mitigation measures, and issue fines of up to €15 million or 3% of a company’s global annual turnover, whichever is higher. The same date activated Article 50 transparency rules, which require AI chatbots to identify themselves as AI from the start of a conversation, and require AI-generated content, including deepfakes, to carry machine-readable labels. Coverage is also available from CNBC and Wilson Sonsini.

What is significance: models placed on the market before August 2025 have until August 2027 to reach full compliance, but new and updated models are in scope now. Any UK business relying on a general-purpose model from a major provider should expect more visible labelling on AI content and chatbot disclosures over the coming months.
Our Advice this week:
- If your product embeds a chatbot, check whether it already discloses that the user is talking to AI, since your vendor may push this change without notice.
- Review any AI-generated marketing content for the EU market and confirm your supplier has a labelling plan for deepfake or synthetic media rules.
- Keep a simple record of which AI models and versions you use in customer-facing products, since regulators are increasingly asking for this kind of documentation.
Cyber security alert: critical Langflow flaw under active exploitation
CISA has ordered US federal agencies to patch CVE-2026-9198, a critical code injection flaw in IBM’s open-source Langflow tool, rated 9.8 out of 10 for severity. Langflow is a popular visual builder for AI agent workflows. The flaw lets an unauthenticated attacker chain two API endpoints together: one that mints a superuser login token to any caller, and a second that executes submitted code directly, giving full remote code execution on default Langflow deployments. IBM has released a fix in version 1.10.1. Further detail is available from BleepingComputer and SentinelOne.

What is significance: Langflow is widely used to prototype and run AI agents, which means a compromised instance can expose whatever data or systems those agents were connected to. This is another example of AI development tools becoming a direct attack surface, not just the models themselves.
Our Advice: if you or a supplier runs Langflow, upgrade to 1.10.1 immediately, and do not expose the Langflow admin interface to the open internet.
AI security: Anaconda buys Enkrypt AI after finding 143,000 MCP vulnerabilities
Data science platform Anaconda has acquired Enkrypt AI, an AI security and compliance firm, folding in pre-deployment red-teaming across more than 300 attack categories, runtime guardrails, and automated compliance checks for standards including the EU AI Act. Anaconda cited Enkrypt’s own research, which found 143,000 vulnerabilities across 73% of the Model Context Protocol (MCP) servers it scanned, as evidence of a widening enterprise AI agent security gap. The deal follows Anaconda’s acquisition of Kilo Code in July 2026, reported by HPCwire.

What is significance: MCP servers are becoming the standard way AI agents connect to company tools and data, so a 73% vulnerability rate is a real warning sign for anyone rolling out agentic AI internally. Security tooling for the agent layer itself, not just the underlying model, is becoming a normal part of enterprise AI stacks.
Also in AI: appeals court says Perplexity is not liable for its Comet agent shopping on Amazon
The Ninth Circuit Court of Appeals has overturned a lower-court injunction that had barred Perplexity’s Comet browser agent from operating on Amazon.com. Amazon argued Comet violated the Computer Fraud and Abuse Act by scraping product pages and completing purchases on users’ behalf. The three-judge panel ruled that it is the user, not Perplexity, who accesses Amazon’s systems, since Comet works from screenshots the user’s own browser already captured. The court limited its ruling to the injunction stage and to the question of unauthorised access, so the underlying case continues. Further coverage from the Electronic Frontier Foundation and Courthouse News.

What is significance: this is an early and consequential ruling on who is legally responsible when an AI agent acts on a website for a user. If it holds, it makes it harder for website owners to block AI shopping and browsing agents purely through anti-hacking law, and it may push more of these disputes toward contract terms and technical blocking instead.
The takeaway
Four stories, one thread: the rules and risks around AI are becoming concrete, not theoretical. The EU is now able to fine model makers directly, a real flaw in a widely used AI agent tool is being exploited today, a major acquisition shows enterprises are paying for AI agent security, and a court has just drawn an early line around who is responsible when an AI agent acts on your behalf. Businesses that keep an inventory of the AI tools and agents they run, patch AI infrastructure with the same urgency as any other software, and watch how liability questions are being settled in court will be better placed than those treating AI as someone else’s problem. If you would like help reviewing your AI governance or your cloud security posture, get in touch.
AI Agent based research and content, AI can do mistake, please help us to improve.