AI Radar for Companies — Tuesday, September 22, 2026
· CompaniesAutomation
The Government presents the IA360 Plan with a 600 million voucher for SMEs and freelancers that cannot be spent on licenses, Anthropic brings Accenture in-house to audit its models with 2 billion behind it, and a Chinese coding tool was uploading entire repositories to the cloud without notice.
Yesterday, the Government put figures on what it expects from Spanish SMEs regarding artificial intelligence: 600 million euros in vouchers that cannot be spent on licenses. The rest of the day is about provider trust—Anthropic brings an external evaluator in-house with 2 billion dollars behind it, and a Chinese programming tool was uploading entire repositories without notice—and closes with the first public figures of agents making decisions alone in supply chains. This follows the Saturday, September 19th radar, where three people on a 200-dollar subscription broke into OpenAI's internal code.
Spain allocates 600 million in AI vouchers for SMEs and prohibits spending them on licenses
Pedro Sánchez presented the IA360 Plan on Monday at Moncloa, a twelve-month roadmap with four pillars, and its most concrete measure is a 600 million euro voucher for SMEs and freelancers. The detail that matters is in the fine print: it finances AI services and solutions provided by European technology companies—development, integration, sector knowledge, data processing, or production process redesign—and does not cover mere subscriptions to tool licenses. To claim it, a prior digital maturity diagnosis, an identified use case, AI training for workers, measurement of the impact on productivity, and milestone-linked payments will be required. The stated goals: 25,000 transformed companies, moving from a business adoption rate of 21.1% to 55% by 2030, and quintupling private investment compared to 2024. The plan includes an AI gigafactory—one of the first three in the EU—with 5 billion in public-private funds, the Neurona Network of demonstration centers, and a meeting with social partners in October. For your company: the timeline is slow (pilot in the first half of 2027 and general call for applications before the end of that year), but the criteria are already written and match the AI First ladder exactly: they don't pay for the tool, they pay for you to change the process and measure the result. What is actionable this week is not waiting for the call, but having ready what the call will request: choose a process with a number behind it (hours, response time, error rate), note its current value, and write the diagnosis. Source
Anthropic pays Accenture to find its flaws: the birth of model auditing
Anthropic has named Accenture its first integrated evaluator: employees from Faculty, its AI subsidiary, will work inside the lab with employee-level access to perform red teaming, verify if models behave as claimed, and test their safeguards. Each company will contribute at least 1 billion dollars over five years, 2 billion between the two, and the agreement is not exclusive: Anthropic is negotiating something similar with the non-profit METR. It was announced Friday and the market digested it on Monday, with Accenture rising about 6% in pre-market trading. Anthropic itself admits the weak point: it directly finances the work of those who must audit it because no independent mechanism yet exists to pay for these evaluations. For your company, this is not lab news; it's a new category that changes what you can demand in writing: in the next renewal, ask your provider who evaluates their models, with what level of access, and who pays for that evaluation, and request the summary of results. Until yesterday, the only possible answer was "we evaluate ourselves"; from now on, whoever cannot show a third party inside will have to explain why. Source
Your AI coding tool might be uploading your entire repository
A developer dissected ZCode, the desktop application from China's Z.ai (the home of GLM models), and found that after logging in, it packages and encrypts the entire workspace—including the .git history, LFS cache, and global configuration—and uploads it to Alibaba's cloud. The file waiting its turn weighed 313 MB and contained 42,411 files, 86.6% of them from .git, after 564 failed upload attempts; a smaller one did make it through. The encryption is the uncomfortable detail: the private key lives only on Z.ai's servers, so neither the user nor the client itself could open what was being taken. The company apologized on Friday, claiming they destroyed the data and that it was never used for training, and on Monday open-sourced ZCode and promised a vulnerability reporting channel with rewards. For your company, the security question is no longer "can it read my code?", but "what is it taking from the machine and who can open it?". Three things that fit into one morning: inventory which AI tools are installed on development laptops and who installed them; ask IT systems to log exits to cloud storage from those devices; and include the telemetry question in contracts—what is uploaded, encrypted with which key, and who guards it. Source
Agents deciding without human approval: the first supply chain figures
The novelty of multi-agent systems in logistics is not that they advise better, but that they replace the human approval stage within limited operational boundaries, and there are already numbers on the table. Lenovo reports compliance decisions three times faster, response to disruptions four times faster, an 85% success rate in risk assessment, and 30% more precision in deliveries. An automotive manufacturer advised by Simor Consulting went from 82% on-time delivery to 94% in eighteen months, with agents detecting issues 48 hours earlier than manual monitoring. Fujitsu and the pharmaceutical company Rohto measured up to 30% lower transport costs in a virtual trial, with deployment planned between January and March 2027. For your company: that jump is exactly the UNATTENDED step of the AI First ladder, and it's not the model that takes it, you do when you remove a signature. Start with a repetitive, reversible decision with a clear threshold—notifying a customer of a delay, rescheduling a route—and let it run alone with a hard limit and a log of what it decides. If in two weeks you haven't had to undo anything, raise the threshold. Source
What to watch tomorrow?
The voucher rules: what exactly counts as a "European technology company" and what milestones need to be proven, because that's where it's decided if an SME can use it or not. And on October 1st, Accenture's results: the first reading of whether auditing others' models is a business or a reputation expense.