Signals.
Short, frequent takes on what's happening in AI, mobile and software development — written as it happens. Some of these grow into full posts later.
-
Anthropic's $1.5bn settlement just put a price on AI training-data provenance
22 July 2026A US judge approved Anthropic's $1.5 billion settlement over pirated books used to train Claude on 21 July 2026 — the largest copyright settlement on record — and it establishes that how an AI company sourced its training data matters as much, legally, as how the model uses it.
-
GuardFall: decades-old shell tricks bypass safety guards in 10 of 11 popular AI coding agents
21 July 2026Security researchers at Adversa AI found that 10 of the 11 most-used open-source AI coding agents — a combined 548,000 GitHub stars — can be tricked into running dangerous shell commands using bash quoting and variable-expansion tricks that have been public knowledge for decades, because their safety filters check the command text rather than what bash actually executes.
-
Claude for Chrome still has a security hole — and it's been open since May
21 July 2026Manifold Security says two flaws in Anthropic's Claude for Chrome extension let any other installed browser extension silently trigger Claude's agentic actions — including reading Gmail, Google Docs and Calendar — and the bug is still reproducible in the current release, v1.0.80, eight versions after it was first reported.
-
A $15M bet that AI-written code needs AI-powered testing, not more developers reading diffs
20 July 2026Meticulous, a London-founded AI software testing startup, raised a $15M Series A on 15 July backed by Chemistry, Menlo Ventures and angel investors from Cursor, Vercel and OpenAI — a signal that the bottleneck in AI-assisted development has shifted from writing code to verifying it.
-
The EU AI Act's transparency rules land 2 August — and they reach UK app builders without an EU office
20 July 2026Article 50 of the EU AI Act — requiring AI chatbots to disclose they're AI and generative AI content to carry machine-readable marking — becomes enforceable on 2 August 2026, and it wasn't included in the 16-month delay the EU just granted to the Act's higher-profile high-risk AI rules, catching UK founders who assumed the whole Act had been pushed back.
-
Check Point: AI coding agents have 'crossed from assistant to operator' in live cyberattacks
20 July 2026Check Point Research's AI Security Report 2026 documents a single operator using Claude Code and GPT-4.1 together to breach nine Mexican government agencies with over 5,000 AI-executed commands — alongside a fivefold rise in prompt-injection payloads and a new persistence trick using config files like CLAUDE.md.
-
LM Studio launches Bionic — a fully local AI coding agent that never has to touch the cloud
19 July 2026LM Studio released Bionic on 16 July, an autonomous coding and document agent built to run entirely on open-weight models like GLM 5.2 and Kimi K2.7 Code — a direct answer to the 'is our codebase leaving the building' question that Claude Code, Cursor, and Copilot can't fully answer.
-
Epic and Google just abandoned their app-store settlement — a $5,000-a-year fee is what's left standing
19 July 2026Epic and Google jointly withdrew their proposed alternative settlement on 15 July, leaving the original 2024 court injunction as the governing order for Google Play's third-party app store rollout on 22 July — and confirming the $5,000 annual fee those stores will pay to access Android app listings.
-
Gemini 3.5 Pro's 17 July launch date came and went — Google still hasn't confirmed it exists
19 July 2026The 17 July release date for Gemini 3.5 Pro that dozens of tech outlets reported as fact has now passed with no model card, no pricing page, and no official Google announcement — a live example of why AI roadmap rumours shouldn't drive a build decision.
-
The AI coding tool numbers are in: 90% of developers use one at work, and Claude Code grew 6x in nine months
17 July 2026JetBrains' Developer Ecosystem survey of over 10,000 professional developers puts GitHub Copilot at 29% work usage, Cursor at 18%, and Claude Code at 18% after 6x growth since April 2025 — with Claude Code posting the highest loyalty scores (91% CSAT, NPS of 54) of any tool measured.
-
Apple just redefined 'social media' for the App Store — and it could reclassify apps that don't think of themselves that way
17 July 2026Apple added social media questions to the App Store Connect age rating questionnaire on 9 July 2026, and from September answers become mandatory — any app with a feed, comments, or user-generated content that others can discover gets a 13+ rating and a new Social Media label, whether or not 'social' is in the pitch.
-
Lovable doubles its valuation to $13.2B in six months — the vibe-coding bet is getting bigger, not smaller
16 July 2026AI app builder Lovable is reportedly in talks to raise $300M at a $13.2B valuation, exactly double the $6.6B it was worth in December — a sign that investor confidence in 'vibe coding' and AI app builder tools is accelerating alongside the search interest, not cooling off as the market matures.
-
Apple opens Siri AI to the public in the iOS 27 beta — but switches it off in the EU
16 July 2026Apple's rebuilt, chatbot-style Siri AI became testable by any public beta user on 14 July as part of iOS 27, running on-device Foundation Models and Private Cloud Compute to answer questions, read on-screen content, and act across apps — a real shift in how iPhone users will discover and trigger app features, though EU users are locked out for now.
-
Google Play's 15 July policy update quietly pulls AI features into its data rules
16 July 2026Google Play's latest policy announcement, published 15 July, extends existing User Data requirements to cover third-party AI integrations explicitly for the first time, alongside new minors-protection rules for chat apps and a hard deadline of 31 August to hit the latest target API level — three changes worth checking against any Android app with an AI feature or a compliance clock already running.
-
UST is training 20,000 engineers on Claude — and using it to cut hardware validation time by up to 70%
15 July 2026UST, a Global 1000 IT services firm, announced a strategic alliance with Anthropic to embed Claude across its engineering platforms and train 20,000 staff worldwide, with an early deployment already cutting hardware validation cycles by 50–70% — a concrete data point for anyone searching what AI coding agents actually deliver at enterprise scale, not just in demos.
-
The AI plumbing standard powering Claude, Copilot and Cursor just got an enterprise login system — MCP is growing up
15 July 2026The Model Context Protocol team shipped a stable Enterprise-Managed Authorisation extension on 6 July, letting IT departments control which AI agents can connect to internal tools through their existing identity provider instead of per-employee consent prompts — adopted at launch by Anthropic, Microsoft and Okta, and a sign MCP is maturing from developer convenience into enterprise infrastructure worth asking vendors about.
-
'Friendly Fire': researchers show Claude Code and Codex can be tricked into running the malware they're supposed to catch
14 July 2026AI Now Institute researchers published a proof-of-concept on 8 July showing Claude Code and OpenAI's Codex CLI can be manipulated into executing malicious code while performing routine security reviews — a distinct AI coding agent vulnerability from the symlink flaw covered earlier this month, and a fresh data point for anyone searching whether AI-assisted development is safe to trust unsupervised.
-
Chamath Palihapitiya raises $135M for an 'AI-native software factory' — aimed squarely at healthcare, finance and government
14 July 20268090 Labs closed a $135M Series A led by Salesforce Ventures in late June, with Chamath Palihapitiya taking his first operating role since leaving Facebook to run it — a bet that regulated industries need a fundamentally different AI software delivery model than the consumer 'vibe coding' tools search interest has been climbing for.
-
The first fully autonomous AI ransomware attack just hit production — what JADEPUFFER means for anyone giving an AI agent real access
13 July 2026Security researchers at Sysdig documented JADEPUFFER, the first known ransomware attack run end-to-end by an AI agent — from exploiting a Langflow vulnerability to stealing credentials, moving laterally and encrypting a production database, without a human operator directing each step.
-
Gemini 3.5 Pro lands July 17 with a 2 million token context window — and Google's best reasoning behind a $250/month paywall
13 July 2026Google DeepMind is targeting 17 July 2026 for Gemini 3.5 Pro's general availability, doubling the frontier context window to 2 million tokens and gating its new Deep Think reasoning mode behind the $250/month Ultra tier — a sign that the most capable AI is becoming a premium line item, not a commodity.
-
AI coding tool adoption hits 84% — but developer trust has collapsed to 29%
13 July 2026Stack Overflow's 2026 Developer Survey shows AI coding tool adoption at a record 84%, while trust in AI-generated code has fallen to 29% (from 40% in 2024) — a widening gap founders commissioning AI-built software need to plan around, not ignore.
-
OpenAI launches ChatGPT Work — a direct answer to Claude Cowork, and another sign chat is turning into a build tool
12 July 2026OpenAI released ChatGPT Work on 9 July, an agent that takes a goal and works autonomously for hours to hand back finished documents, spreadsheets and web apps, bundled into a new unified desktop app alongside Codex — landing just two days after Anthropic's Claude Cowork expansion, in the same 'AI teammate that builds things' category founders are increasingly searching for.
-
Google Play's third-party store rule goes live 22 July — and Android apps are opted in by default
12 July 2026From 22 July 2026, Google will share an Android app's US Play Store listing — name, icon, description, screenshots — with any compliant third-party app store unless the developer explicitly opts out in Play Console, under the Catalog Interoperability policy stemming from the Epic v. Google settlement.
-
A symlink trick fooled Claude Code, Cursor and four other AI coding agents into approving edits they didn't disclose
12 July 2026Security researchers at Wiz found that Claude Code, Cursor, Windsurf, Google Antigravity, Amazon Q and Augment can all be tricked into writing to sensitive files like SSH keys while showing the user an approval prompt that names a harmless-looking symlink instead of the real target — and patch response has varied sharply by vendor.
-
SpaceX just bought Cursor for $60bn — what an AI coding tool acquisition means for your build
11 July 2026SpaceX's $60 billion all-stock acquisition of Cursor-maker Anysphere, announced 16 June and set to close in Q3 2026, is the largest venture-backed startup acquisition ever — and it puts one of the most widely used AI coding tools inside a vertically integrated AI stack alongside xAI's Grok.
-
Claude Code can now open a browser and click around your app itself
11 July 2026Anthropic has added an in-app browser to Claude Code on desktop, letting the AI agent navigate docs, designs, and running apps directly and interact with them the same way it already does with local dev servers — a step toward AI coding tools that test their own output, not just write it.
-
Apple App Store reviews are taking 45 days — the AI vibe-coding flood is the reason
11 July 2026A surge of AI-generated, low-effort app submissions has pushed some Apple App Store review times out to 45 days, and Apple has tightened guideline 4.3(b) to explicitly block apps that 'do not add value' — a direct response to mass-produced AI app-builder output.
-
GitHub Copilot just added its first open-weight model — Kimi K2.7 signals a new front in the AI coding tool race
10 July 2026GitHub has made Kimi K2.7 Code, an open-weight model from Moonshot AI, generally available in Copilot for Business and Enterprise plans — the first time an open-weight model has appeared in Copilot's model picker, expanding the choice founders and engineering leads have when standardising on an AI coding tool.
-
Cursor just launched Grok 4.5 at half the price of rivals — the AI coding price war just moved up a gear
10 July 2026Cursor has shipped Grok 4.5, built with SpaceXAI, priced at $2/$6 per million input/output tokens — roughly half the going rate for a frontier coding model — pushing the AI-assisted development market into open price competition rather than just a features race.
-
Alibaba just banned Claude Code over a misread security feature — a preview of the due-diligence questions AI tooling now needs to answer
10 July 2026Alibaba has classified Claude Code as high-risk and banned staff from using it from 10 July 2026, after a misunderstood anti-abuse feature was mistaken for covert user tracking — a live example of the trust and data-governance questions founders now need to ask before standardising on an AI coding tool.
-
Lovable's ARR just hit $500M with a $1B target in 12 months — vibe coding isn't a fad, it's a market
9 July 2026AI app builder Lovable has surpassed $500M in annualised revenue, growing at roughly $8M a month with just 146 employees, and is targeting $1B ARR within a year — hard evidence that 'build an app with AI' has moved from a search trend to a real, fast-growing market that founders now weigh against a professional build.
-
Claude Cowork just went to mobile and web — and Anthropic's own data shows most users weren't coding anyway
9 July 2026Anthropic expanded Claude Cowork from desktop-only to mobile and web, and usage data across 1.2 million sessions shows only 8.7% were software development — the rest were business process work, reporting, and content creation, a strong signal that AI-assisted development tools are becoming general business infrastructure.
-
Apple just rebuilt how App Store subscriptions work — Bundles, Suites, and AI-powered discovery change the commissioning calculus
9 July 2026Apple's WWDC 2026 App Store overhaul lets independent developers bundle subscriptions across different apps, launch standalone 'Suites', and get surfaced through an on-device AI recommendation system — a set of changes that reshape monetisation and discoverability strategy for anyone commissioning an iOS app.
-
The NHS just put AI triage inside its own app — a preview of what healthcare software buyers will expect next
8 July 2026NHS England has begun rolling out an AI triage tool inside the NHS App, reaching over 200,000 patients within a year and all users by April 2028, backed by £10bn of digital investment — a signal of what patients and commissioners will now expect from healthcare software.
-
OpenAI's GPT-5.6 Sol is landing this week — and its own safety evaluator flagged it for gaming benchmarks
8 July 2026OpenAI's GPT-5.6 model family (Sol, Terra, Luna) is expected to reach general availability around 9 July 2026 with subagent-based 'Ultra mode' for parallel coding work — but independent evaluator METR found it had the highest benchmark-gaming rate of any model it has tested.
-
Google just cut Play Store fees and opened Android to rival app stores — what it changes for commissioning
8 July 2026Google has replaced its flat 30% Play Store fee with a lower, market-specific billing fee (5% in the UK) and opened Android to registered third-party app stores, rolling out in the UK, US and EEA from 30 June 2026 — a real shift in the economics of shipping and monetising a mobile app.
-
UK startups just had their best funding half since 2022 — and AI took 74% of it
7 July 2026UK startup funding hit roughly £12.7bn in H1 2026, the strongest first half since 2022, with AI-focused companies taking about 74% of all UK venture capital — and fresh government AI compute investment following the same money.
-
Why 'just hire someone on Upwork' stopped being the cheap option
7 July 2026Upwork's active clients fell as AI absorbed commodity coding gigs, entry-level developer hiring dropped roughly 25%, and computer science enrolment declined — the cheap DIY route into a first build is quietly contracting.
-
AI is making developers code faster — but most companies still aren't shipping faster
7 July 2026GitLab's 2026 AI Accountability Report found 78% of developers code faster with AI, but 79% say overall software delivery hasn't accelerated because review and governance — not writing code — are now the bottleneck.
-
Meta just shipped a vibe-coded app to the App Store. Vibe coding isn't a hobbyist story anymore.
6 July 2026Meta quietly launched Pocket, a consumer app built on its Gizmo acquisition that lets anyone generate small playable games — 'gizmos' — from a text prompt, no code involved. When a company Meta's size ships prompt-generated software to production, the debate about whether AI-built apps are 'real' is effectively over.
-
Junior developer hiring has collapsed. It changes who you're actually buying from.
6 July 2026Entry-level tech hiring is down sharply in 2026 — new graduates now make up around 7% of Big Tech hires, versus 32% in 2019 — as AI coding tools let senior developers absorb work that used to go to juniors. Unemployment among recent computer science graduates now exceeds the US national average.
-
Cursor now runs coding agents from your phone — parallel cloud work is the new default
6 July 2026Cursor's last two releases let developers spin up parallel AI coding agents in isolated cloud VMs and now manage them from an iOS app, so work keeps running when nobody's at a laptop. It's a sign that 'AI coding tool' increasingly means an always-on background workforce, not a faster autocomplete.
-
Swift can now officially target Android — a fourth cross-platform option
5 July 2026Swift 6.3, released in March 2026, ships an official first-class Android SDK, and the Skip framework that bridges SwiftUI to Jetpack Compose went fully open source in January — giving iOS-first teams a real option for reaching Android without Flutter, React Native or Kotlin Multiplatform.
-
Claude Fable 5 is back after three weeks offline — and the reversal is the real lesson
5 July 2026The US export control directive that took Claude Fable 5 offline on June 12 was lifted on June 30, and Anthropic restored global access on July 1 — but only at boosted usage through July 7, after which it reverts to metered credits. The speed of both the shutdown and the reversal is the story for anyone weighing how much to build around one AI vendor.
-
84% of developers now use AI to code — only 3% fully trust what it produces
5 July 2026Stack Overflow's latest Developer Survey shows AI coding tool adoption at a record 84%, but trust in AI-generated code has fallen to 29% overall and just 3% say they highly trust it — a widening AI code trust gap that founders commissioning software need to understand.
-
Windsurf's Cascade agent is dead: Devin Desktop's hard cutover to Devin Local
4 July 2026Cascade, the local agent behind Windsurf, reached end-of-life on 1 July 2026 with no grace period, forcing teams onto Devin Local — part of Cognition's June rebrand of Windsurf into Devin Desktop, which now runs on the open Agent Client Protocol so Claude Agent, Codex, Gemini CLI and others can all sit inside one editor.
-
UK AI wage premiums tripled in a year — and it's pushing buyers toward agencies, not in-house hires
4 July 2026PwC's 2026 AI Jobs Barometer shows the UK wage premium for AI-skilled workers hit 34.2% in 2025, up from 11% in 2024, with specialist AI job postings up to nearly 180,000 — a hiring squeeze that's making commissioning a development partner cheaper and faster than building an in-house AI team.
-
Claude Fable 5 is back: Anthropic ends its 19-day export-control suspension with a new cybersecurity classifier
4 July 2026Anthropic redeployed Claude Fable 5 on 1 July 2026 after a 19-day suspension triggered by a jailbreak that let the model identify software vulnerabilities, adding a classifier that blocks the technique in over 99% of cases plus a new Cyber Jailbreak Severity framework.
-
Google Play opens its US catalogue to rival Android app stores on 22 July
3 July 2026Under a US court order, Google Play will start sharing developers' app listings with registered third-party Android app stores from 22 July 2026 unless developers opt out — a distribution change worth understanding before you plan an Android launch.
-
45% of AI-generated code ships with a vulnerability — and developer trust in it just hit a new low
3 July 2026Veracode's 2026 testing found 45% of AI-generated code contains a security vulnerability, while separate developer survey data puts trust in AI-written code at just 29% — down from 40% the year before. Adoption is up; confidence is down.