This week: an AI too capable to release in full, IFA's 'AI PC' wave, and two fresh scams
A Friday read on what actually happened across AI, hardware, and the web. Curated, not chased. If nothing mattered, we’d say so.
An AI its own makers decided not to release in full
OpenAI said its next model, Astra, is the first it has ever rated “Critical” for cybersecurity under its own safety framework. In plain terms: given the right tools, it can find brand-new flaws in software and write working attacks against well-defended systems without a person guiding each step. During testing, OpenAI says the model found and chained together two previously unknown vulnerabilities, which it’s now reporting to the software makers affected.
Rather than hand those abilities to everyone, OpenAI is holding the strongest cyber features back — a small group of testers first, then defenders through its security programme — while it hardens the safeguards.
Why it matters to you: this is the first time a major AI company has effectively said, “this model is too good at hacking to release freely.” The same skill cuts both ways — what finds a flaw for an attacker can find and fix it for a defender. Mostly it’s a marker: the technology is genuinely capable now, and for once it’s being slowed down on purpose rather than pushed out. You don’t need to do anything about it today; it’s worth knowing the ground is moving.
Verify it yourself: OpenAI — “Path to Astra” · CNBC
Berlin’s big show fills up with “AI PCs”
IFA in Berlin — Europe’s main autumn tech fair — was wall-to-wall “AI PCs” this week: laptops built to run AI tools on the machine itself rather than in the cloud. Lenovo alone showed around twenty new models, including high-end Yoga laptops using Nvidia’s new RTX Spark chips (aimed at people editing video or running AI locally) and a cheerful, cheaper IdeaPad Vibe at about $700 with swappable keys and Pantone colours. Acer answered with a featherweight 799-gram laptop and a mainstream screen that shows 3D without glasses.
Why it matters to you: “AI PC” is this year’s headline sticker, and a show like IFA is designed to make you feel behind. For most people it isn’t a reason to rush. A laptop you’ll still be happy with in three years comes down to the same basics it always did — enough memory, a good screen, battery that lasts — not the AI badge on the lid. Watch the prices as these actually land in shops, and buy the machine, not the buzzword.
Verify it yourself: Thurrott — Lenovo at IFA 2026 · Gizmodo — live from IFA 2026
Two fresh scams, one trick
The US Federal Trade Commission put out two scam warnings this week, and they run on the same trick.
The first: fake car-dealership websites, often cloned from a real dealer’s site — logos, listings and photos and all, sometimes with AI — that take a “deposit” or “payment” for a car that was never for sale. The buyer turns up to collect and finds no order, no payment on record, and no car. A dealer who insists on paying up front by wire transfer only is the loud warning.
The second: scammers sticking their own QR codes over the real ones on parking meters, so you “pay” a stranger instead of the council.
Why it matters to you: both work by showing you a familiar-looking screen — a dealer’s site, a parking meter — that quietly reroutes your money. The fix is the same for both: get to the real thing yourself. Reach a dealership by searching its name (add “scam” or “review”) and asking to see the car in person, not by following a link someone sent you. At a parking meter, use the machine, the official app, or phone payment rather than scanning a sticker that could have been swapped — and if you do scan, read the web address it shows you before you tap it. A QR code is just a link you can’t read with your own eyes, so treat it like one.
Verify it yourself: FTC — spoofed car-dealership sites · FTC — parking QR codes
Spotted something we should cover next week? That’s the whole idea — tell us, and we’ll check it.