<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>AI Perimeter</title>
  <link>https://aiperimeter.news/</link>
  <description>An independent newsroom covering the security of AI systems and the AI systems reshaping security — sourced, dated and cited.</description>
  <item>
    <title>The summer the AI labs found out their test ranges leak</title>
    <link>https://aiperimeter.news/articles/ai-labs-test-ranges-leak.html</link>
    <guid isPermaLink="false">theperimeter-ai-labs-test-ranges-leak</guid>
    <description>Two frontier labs have now disclosed that models under evaluation reached the open internet and compromised real companies. The failures were not in the models. They were in the plumbing around them.</description>
  </item>
  <item>
    <title>One GitHub issue was enough to break Claude Code, Gemini CLI and Codex pipelines</title>
    <link>https://aiperimeter.news/articles/github-issue-coding-agents.html</link>
    <guid isPermaLink="false">theperimeter-github-issue-coding-agents</guid>
    <description>Researchers at Novee say a single unprivileged issue could reach code execution on CI runners behind three vendors&#x27; own repositories. Google rated its bug CVSS 10.0.</description>
  </item>
  <item>
    <title>The EU started enforcing the AI Act on 2 August. Here is what actually changed.</title>
    <link>https://aiperimeter.news/articles/eu-ai-act-enforcement-begins.html</link>
    <guid isPermaLink="false">theperimeter-eu-ai-act-enforcement-begins</guid>
    <description>Transparency obligations are now live, the AI Office has direct powers over general-purpose models, and fines reach €15 million or 3% of global turnover. The high-risk rules, meanwhile, have slipped to 2027.</description>
  </item>
  <item>
    <title>The industry proposes a disclosure clock for AI incidents — without the two labs that had them</title>
    <link>https://aiperimeter.news/articles/safe-ai-incident-disclosure.html</link>
    <guid isPermaLink="false">theperimeter-safe-ai-incident-disclosure</guid>
    <description>SAFE would commit members to notify exposed customers in 72 hours and publish a preliminary report in 30 days. Neither OpenAI nor Anthropic belongs to the alliance behind it.</description>
  </item>
</channel></rss>