Last week was a useful reminder of how broad the phrase “technology news” has become. While one company trained a model to find weaknesses in other models, governments argued over access to mobile platforms and communities argued over the water and electricity consumed by data centers. At the same time, chipmakers and robotics companies kept building the physical infrastructure without which the most impressive AI demos would remain just that: demos.
We selected nine developments announced or reported between July 13 and July 19, 2026. This is not a list of every product update from the week. It is a guide to the changes most likely to affect security, everyday tools, competition and the cost of AI infrastructure. When a number comes from a company’s internal evaluation, we label it as such. When an ambitious project is still a plan, we do not describe it as operational infrastructure.
TL;DR: the week in nine points
- Microsoft fixed two vulnerabilities in AD FS and SharePoint that Microsoft and CISA say were already being exploited in real attacks.
- OpenAI presented GPT‑Red, an internal automated red-teaming system that generates prompt-injection attacks and helps train more robust models.
- Australia established an Office of AI and proposed rules requiring large data centers to cover their energy needs and use water more efficiently.
- Google renamed NotebookLM to Gemini Notebook and started adding native code execution in what it calls a secure cloud computer.
- The European Commission ordered Google to open 11 Android capabilities to rivals and provide an effective route to anonymized search data.
- TSMC reported a 77.4% year-over-year increase in quarterly profit, while its 2nm process appeared in wafer revenue for the first time.
- Moonshot unveiled Kimi K3 with a claimed 2.8 trillion parameters and a one-million-token context window, but the full model weights are not yet available.
- Japan, Noetra and NVIDIA announced a planned 140MW AI factory for robotics, digital twins and so-called physical AI.
- Opponents of rapid data-center expansion held 142 events across 42 U.S. states, although no reliable national attendance figure is available.
1. Microsoft fixes two vulnerabilities already used in attacks
What happened. Microsoft published its monthly security release on July 14. Independent security teams counted 570 or 622 patched vulnerabilities, largely because they use different rules for products, platforms and duplicated CVEs. The more useful fact is that CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint had evidence of exploitation. CISA added both to its Known Exploited Vulnerabilities catalog on the same day.
The AD FS flaw can give a local attacker a route to elevated privileges. The SharePoint Server issue can, under the relevant conditions, enable a remote unauthenticated attacker to gain privileges. These are primarily enterprise infrastructure risks. They are not evidence that every home Windows computer has suddenly been compromised.
Why it matters and what to do. Organizations should put internet-facing SharePoint and AD FS systems near the front of the patch queue, review logs for suspicious activity and confirm that backups can actually be restored. People using supported Windows versions should avoid indefinitely postponing normal updates. A giant CVE total makes a dramatic headline, but priority should come from active exploitation, internet exposure and the value of the system’s data—not the raw number of patches.
2. GPT‑Red automates the search for weaknesses in AI agents
What happened. On July 15, OpenAI introduced GPT‑Red, an internal model for automated safety red teaming. It is not designed to answer consumer questions. Its job is to attack other models: send an instruction, observe the target’s response, change tactics and look for a prompt injection that diverts an agent from its original task. During self-play training, GPT‑Red is rewarded when it causes a valid failure, while a varied group of defender models is rewarded for resisting the attack and still completing the legitimate task.
In OpenAI’s internal results, GPT‑Red succeeded in 84% of scenarios in a replicated indirect-prompt-injection arena against GPT‑5.1, compared with 13% for human red teamers. It also manipulated a real agent running an office vending machine and proved more effective than a baseline model in held-out data-exfiltration tests involving a Codex CLI agent. These are striking examples, but they are OpenAI’s evaluations, not an independent audit.
OpenAI then incorporated attacks generated by GPT‑Red into GPT‑5.6 training. The company reports six times fewer failures on its hardest direct-prompt-injection benchmark than its best production model from four months earlier. GPT‑Red itself remains internal and separate from deployed models, a deliberate decision intended to keep the offensive capabilities it was trained to develop away from outside attackers.
Why it matters and what to do. An agent that reads email, webpages, repositories, local files and tool responses has many channels through which a third party can hide an instruction. Automated red teaming can expand the volume and variety of testing, but it cannot replace people, external review or live monitoring. Developers still need least-privilege permissions, confirmation before payments or data transfers, separation of secrets and complete action logs. Our separate explainer on GPT‑Red and AI-agent vulnerabilities examines the technique and its limits in more detail.

3. Australia creates an Office of AI and plans resource rules for data centers
What happened. Australia’s government announced a new AI framework on July 15. An Office of AI began operating that day within the Department of the Prime Minister and Cabinet. The government also proposed Australian Standards for AI, including unusually specific expectations for large data centers.
Under the plan, operators would have to underwrite new power supply for their own load, pay their full connection costs, reduce consumption when the grid needs support and be as water-efficient as possible. States and territories would involve communities in decisions about suitable locations. The announcement also promises protection for creators and media, arguing that Australian work should not be used for AI training without its owners retaining control.

Why it matters and what to do. This is not yet enacted law. Australia’s National Cabinet is expected to consider the approach in August, with legislation anticipated in early 2027. Nevertheless, the policy direction is clear: it is becoming harder to push the cost of AI infrastructure onto electricity customers, water users and the neighbors of a proposed facility. Operators should prepare transparent figures for power, water, backup generation and community benefits. Our guide to why data centers use fresh water explains where that demand comes from and which cooling choices can reduce it.
4. NotebookLM becomes Gemini Notebook and gains code execution
What happened. Google renamed NotebookLM to Gemini Notebook on July 16. The product is not being discontinued or reduced to an ordinary Gemini chat. It remains a standalone research tool, but it is becoming more closely integrated with Google’s wider ecosystem. Google says more than 30 million people and 600,000 organizations now use it.
The most consequential addition is what Google describes as a secure cloud computer for every notebook. It allows the model to write and execute code for analysis grounded in the user’s attached sources. The capability is available to Google AI Ultra users and certain Workspace customers, with a web rollout for Pro users planned over the following weeks. Notebooks already sync with the Gemini app and are scheduled to appear in AI Mode in Search later.
Why it matters and what to do. Gemini Notebook is moving from a reading and summarization assistant toward an active analysis environment. That can be genuinely useful, but model-written code is not automatically correct. Check formulas, units and sampling before relying on a result; do not upload confidential material without organizational approval; and retain the original dataset outside the notebook. “Grounded in your sources” reduces one class of error, not every analytical mistake.
5. The EU orders Google to open Android capabilities and search data
What happened. On July 16, the European Commission adopted two sets of binding measures under the Digital Markets Act. The first covers 11 Android capabilities that AI assistants need, including voice and button invocation, access to permitted context, actions inside apps, background execution and the use of on-device models. The Commission wants a third-party assistant, with the user’s consent, to reach capabilities that are much easier for deeply integrated Gemini services to use today.
The main features are due in Android 18 and no later than August 1, 2027; concurrent hotword support for more than one service is scheduled for Android 19. The second decision requires an effective route for eligible search engines—including AI chatbots with search functionality—to receive anonymized ranking, query, click and view data. Recipients may use it to improve search, but not to train a general-purpose model, build advertising profiles or systematically reproduce Google’s results.
Why it matters and what to do. The decision could give Europeans a more meaningful choice of assistant and give publishers additional sources of search traffic. Google argues in response that the safeguards do not adequately protect private searches and device security. Users do not need to change anything today; the practical question will be which permissions future assistants request. Publishers should not redesign SEO for a channel that does not yet exist, but accurate, structured and crawlable content remains the sensible foundation.

6. TSMC profit rises 77.4% as 2nm starts generating revenue
What happened. TSMC reported its second-quarter results on July 16: consolidated revenue of NT$1.270 trillion, net income of NT$706.56 billion and diluted earnings per share of NT$27.25. Revenue increased 36% year over year and net income rose 77.4%. In U.S. dollars, quarterly revenue reached $40.2 billion.
Advanced processes at 7nm and below accounted for 77% of wafer revenue. The 3nm share was 30%, 5nm accounted for 33%, and the new 2nm process contributed 3% for the first time. TSMC’s chief financial officer attributed the quarter to strong demand for leading-edge process technologies and expects a steep 2nm ramp in the following quarter.
Why it matters and what to do. It would be misleading to assign all of TSMC’s growth to generative AI; the company manufactures chips for several large markets. Still, these financial results are a harder signal of demand for advanced computing than another chatbot presentation. They do not guarantee an immediate drop in GPU prices. Leading-edge wafers, advanced packaging, memory, power delivery and data-center capacity remain connected bottlenecks, so infrastructure planning should start with measured workload rather than the hope that every component will soon become cheap.
7. Moonshot claims 2.8 trillion parameters for Kimi K3, but open weights have not arrived
What happened. Chinese AI company Moonshot unveiled Kimi K3 on July 16. On its official website, the company describes it as a natively multimodal model with 2.8 trillion parameters and a context window of up to one million tokens, built for long-running coding, knowledge work and reasoning. Moonshot’s technical documentation says its sparse mixture-of-experts architecture activates 16 of 896 experts for each token.
K3 is already available through Kimi products and the paid API. At the end of the week, however, its full weights were not downloadable. The official guide promises them by July 27, together with more architecture, training and evaluation details. It is therefore premature to describe the model as fully open today. Moonshot’s benchmark tables should also be presented as company results, not independent proof that K3 beats closed competitors.
Why it matters and what to do. K3’s scale suggests Chinese laboratories are competing not only on API price, but on architecture, multimodality and long context. Its real value will be easier to judge after the weights, license, hardware requirements and reproducible third-party evaluations appear. Developers testing the API now should begin with non-sensitive tasks and a private evaluation set rather than moving a production workflow because of a chart in a launch presentation.
8. Japan and NVIDIA plan 140MW of physical-AI infrastructure
What happened. NVIDIA and Noetra announced a planned AI factory on July 16 with support from Japan’s Ministry of Economy, Trade and Industry. The proposal calls for 13,750 Vera CPUs, 27,500 Rubin GPUs and 140MW of data-center capacity. The facility is intended to provide compute for the FRONTia program, multimodal foundation models, robotics, digital twins, logistics and manufacturing.
One day earlier, NVIDIA announced an expansion of its Cosmos Coalition in Japan. FANUC, Fujitsu, Hitachi, Kawasaki Heavy Industries, Kubota, NEC, SoftBank, Sony, Yaskawa and other companies intend to participate. NVIDIA also introduced Cosmos 3 Edge, which it describes as a four-billion-parameter model for local visual reasoning and robot-action generation on Jetson hardware.
Why it matters and what to do. This is part of a shift from AI that generates an answer to systems that perceive industrial environments and control physical devices. It is still a plan and a collection of participant announcements, not an operating national network. Manufacturers should watch model availability, safety standards and the eventual terms for pretrained weights. The less glamorous question matters just as much: how a 140MW facility will be connected, cooled and integrated into the power system.
9. Data-center protests spread across 42 U.S. states
What happened. Opponents of rapid AI data-center construction held 142 events across 42 states on July 18. According to Reuters, it was the first coordinated national campaign of its kind. The organizing group, HumansFirst, called for transparent planning, protection of water and electricity systems, meaningful local participation, developer accountability and clear economic benefits for host communities.
Individual events varied substantially in size, and no national attendance total was available. It is therefore more accurate to describe the campaign by its geographic reach, not by an unsupported attendance estimate. A June Reuters/Ipsos poll provides useful context: only 14% of respondents were comfortable with a data center being built near them, and roughly one third approved of the current rapid pace of construction.
Why it matters and what to do. Community acceptance is becoming a constraint as real as transformer supply or zoning approval. Developers need to publish more than promises of jobs: peak and average water demand, effects on utility bills, noise, backup generation and drought response all belong in the discussion. Dry cooling can sharply reduce water consumption, but it does not make a project resource-free and can raise electricity demand. Each proposal has to be evaluated against local climate, grid and water conditions—not a single marketing metric.
What to watch next week
- Post-Patch-Tuesday exploitation. New technical details about CVE-2026-56155 and CVE-2026-56164 will indicate whether attacks are expanding beyond the incidents already known to defenders.
- Independent Kimi K3 testing. The API can already be evaluated on real tasks, but the central test of openness is the promised July 27 weight release, its license and reproducible performance.
- The Gemini Notebook rollout. Look beyond polished examples to execution limits, Workspace data policies and the reliability of analysis across messy, real-world tables.
- Technical detail behind the EU decisions. Android access will turn on permission and certification rules; search-data access will depend on independent privacy audits and workable pricing.
- Policy responses to data centers. Australia’s proposal and the U.S. protests may encourage other governments to demand disclosure of water use, energy contracts and investment in local infrastructure.
- External scrutiny of AI-safety claims. GPT‑Red appears to be a powerful internal tool, but confidence in the approach would improve if more of the methodology and results became reproducible outside OpenAI.
Conclusion
The week’s common thread was the AI ecosystem growing up. Models are now judged not only by their answers, but by their resistance to attacks. Data centers are being assessed not only by GPU count, but by water, power and community consent. Regulatory decisions are being measured not only by the competition they promise, but by the privacy cost of creating it.
The most useful response is neither automatic excitement nor automatic panic. It is the habit of separating an available product from a planned project, and an independent finding from a vendor benchmark. That distinction helps readers notice meaningful technological change early without becoming part of the promotional noise around it.

Join the conversation
Stay on topic and respect other readers. Your first comment may appear after editorial review.