AI Radar for Businesses — Thursday, August 6, 2026
noticias radar ia regulacion ia seguridad ia agentes ia

AI Radar for Businesses — Thursday, August 6, 2026

· CompaniesAutomation

Controlling AI has shifted from advice to a legal, security, and budgetary requirement. Since August 2, the European AI Office can investigate and fine large model providers up to 3% of their global turnover. Simultaneously, Anaconda's purchase of Enkrypt AI exposed thousands of vulnerabilities in the MCP servers connecting agents to data, Cloudflare released a free platform to restrict agents, and even Microsoft set AI spending caps. The takeaway: 'using AI' is no longer enough; you must prove it's under legal, technical, and economic control.

Yesterday's AI Radar was about knowing how many agents you have running; today's question is who is holding them back, because controlling them is now a matter of law, security, and budget. Since August 2, the European AI Office can investigate and fine general-purpose model providers; Anaconda's acquisition of security firm Enkrypt AI reveals that the MCP servers connecting your agents to your data are full of holes; Cloudflare releases a free platform to set permissions and brakes; and even Microsoft is imposing a cap on its engineers' AI spending. Today's takeaway: "using AI" is no longer enough—you have to prove you have it under legal, technical, and economic control.

The EU can now fine you for how you use AI

On August 2, the European AI Office effectively launched its powers to investigate and sanction general-purpose model providers—OpenAI, Google, Anthropic, and others—with fines of up to 3% of total worldwide annual turnover or 15 million euros, whichever is higher. Models already on the market before August 2025 have until August 2027 to adapt, so the pressure on the entire chain starts now. For your company: if you are an SME, you are almost never the "provider" of the model, but you are the "deployer," and there you have your own transparency obligations—notifying people they are interacting with an AI and labeling AI-generated content. Do two things this week: ask your AI provider to confirm in writing that they comply with the AI Act, and check that your chatbots and automated texts clearly state they are AI. Source

The connectors powering your agents are full of holes

Anaconda acquired the security company Enkrypt AI on August 4 and, when announcing the deal, exposed the problem it aims to solve: its own scans found more than 140,000 vulnerabilities spread across some 25,000 MCP servers—the pieces that connect an AI agent with your data and tools. Enkrypt's technology performs "red-teaming" before deployment (attacking the system across more than 300 categories so that failures show up in testing rather than in front of a client) and sets up real-time barriers against data leaks and jailbreaks. For your company: every connector or MCP you plugged into an agent is a door, and if no one has tried to force it open, assume it's unlocked. Ask whoever set up your automations if anyone has tried to break them on purpose and what specific data an agent could see or change if it went rogue. Source

There is now a free way to set permissions and limits for every agent

On August 5, Cloudflare released Cloudflare OS, an open-source platform for creating and operating AI agents with your company's data and systems. Its key component is "Gatekeepers": governed connectors that give the person in charge of each system precise control over what the AI can see, what it can change, and when a person needs to approve an action before it is executed. The security model is "capabilities-based": each agent starts with almost no permissions and they must be granted one by one, resource by resource. For your company: this is the exact counterweight to the two news items above. You don't need to build it yourself, but you should demand this principle for any automation installed: that the agent starts without being able to touch anything and is only opened to what is essential, with a human-in-the-loop for actions that delete, pay, or send. Source

Even Microsoft is capping its AI spending

It was revealed this week that Microsoft has imposed a "token budget" on its divisions and provided each engineer with a dashboard to monitor their own spending, after many were burning through hundreds to thousands of dollars per month. A senior executive's message was direct—"maximizing token consumption is not what we are optimizing for"—and the company switched to using the cheapest model by default for internal work. For your company: if the world's largest tech company sets a limit, so should you. Before expanding AI usage, set a monthly spending cap, check if your task works well with a cheaper model (you don't always need the most powerful one), and review the bill every week just as you review the electricity bill. AI without a budget gets out of hand just like any other subscription. Source

What to watch for tomorrow?

With the AI Act enforcement now underway, the next step will be seeing the first requests for information from the European AI Office to the major providers: when that happens, your provider will need to be able to answer, and so will you. And a question for today: of everything your AI can see, touch, or spend right now, what truly has a limit and who is monitoring it?