AI news roundup July 30 2026, EU AI gigafactories and OWA zero-day exploit
the shed // AI NEWS ROUNDUP

A 30 billion euro bid for AI sovereignty, a zero-click mailbox backdoor from a Russian espionage group, and 1,100 workers at the top labs asking Washington to build a pacing mechanism, all inside the last 48 hours.

Five stories from the last two days that matter if you build, secure, or budget around AI systems. Tap through the log below for the quick version, or keep scrolling for the full rundown.




ai-news/2026-07-30.log








[2026-07-30 policy] european-commission.ai-gigafactories.tender-open

The European Commission opened bidding for seven AI Gigafactory sites, backed by up to 10 billion euros in public funding and expected to unlock at least 20 billion euros more in private investment. Each site is meant to host at least 100,000 AI chips, roughly four times the scale of a typical EU data center today. Bidding closes November 12, 2026.

Why it matters: this is Brussels’ clearest bet yet that AI compute capacity is a sovereignty issue, not just an infrastructure one. Source: Euronews

[2026-07-30 security] laundry-bear.owareaper.cve-2026-42897

Russia-linked group Laundry Bear is exploiting an Outlook Web Access cross-site scripting flaw that fires the moment a target opens a crafted email, no click required. The payload, OWAReaper, rewrites the malicious message on the Exchange server to erase its own tracks and survives credential rotation and device re-imaging.

Why it matters: zero-click, self-cleaning, persistence that outlives a password reset. That is a different threat model than the phishing playbook most security teams train against. Source: The Hacker News

[2026-07-28 governance] pacing-the-frontier.1100-signatures

More than 1,100 employees at OpenAI, Anthropic, Google DeepMind, and Meta signed an open letter called Pacing the Frontier, asking the US government to help build the technical and governance tools for a verifiable, coordinated slowdown if AI development ever outruns human oversight. Signatories include Anthropic cofounders Jack Clark and Jared Kaplan and OpenAI chief scientist Jakub Pachocki.

Why it matters: this is coming from inside the labs, not outside critics, and both Anthropic and OpenAI have backed it as organizations. Source: Notebookcheck

[2026-07-29 access] openai.chatgpt-academic-researchers.launch

OpenAI launched ChatGPT for Academic Researchers, part of a 250 million dollar initiative giving free access to GPT-5.6 Sol Pro and hands-on onboarding support. The program starts with 10,000 researchers at institutions including the Institute for Advanced Study and ENS, expanding toward 100,000 by 2027.

Why it matters: it is a meaningful compute subsidy for academic labs that otherwise cannot touch frontier model pricing. Source: OpenAI

[2026-07-28 devops] itential.flowai.gartner-recognition

Itential was named a Representative Vendor across five 2026 Gartner Market Guides, including AI Assistants for Infrastructure as Code and Agentic NetOps Software, for its FlowAI agent harness, which pairs role-based agents with governed, audit-logged execution across hybrid infrastructure.

Why it matters: Gartner naming a governed-execution agent platform across five separate infra categories is a signal of where analyst expectations for “safe” agentic ops are landing. Source: Itential

The EU puts a number on AI sovereignty

On July 30, the European Commission formally opened its call for proposals to build seven AI Gigafactories across the bloc, the latest and largest step in its push for technological independence from US and Chinese AI infrastructure. Up to 10 billion euros in combined EU and national public funding is on the table, with the Commission expecting that to pull in at least 20 billion euros more in private capital, for a program worth roughly 30 billion euros in total.

Each Gigafactory site is expected to host at least 100,000 AI chips, either concentrated at a single location or spread across several countries as a distributed computing facility. Bidding closes November 12, 2026, with awards expected in early 2027 and construction to follow the same year. For anyone tracking where AI training capacity will physically exist over the next few years, this is the single largest public commitment Europe has made on the question.

A zero-click Outlook exploit that survives a password reset

Security researchers disclosed that Laundry Bear, a Russia-linked espionage group also tracked as Void Blizzard, has been exploiting a cross-site scripting flaw in Outlook Web Access, tracked as CVE-2026-42897, since at least July 22. The attack does not require a victim to click a link or open an attachment. Simply opening a specially crafted email in OWA is enough to trigger arbitrary JavaScript inside the victim’s authenticated mail session.

The payload, dubbed OWAReaper, is a browser implant that uses Outlook’s own APIs to rewrite the malicious message on the Exchange server after execution, erasing evidence and disabling pop-up notifications so the victim does not notice anything unusual. Worse for defenders, the implant is built to persist through credential rotation and even device re-imaging. Microsoft has flagged exploitation dating back to May. If your organization runs OWA for any user population, this is worth checking against your patch and detection posture today, not next sprint.

1,100 AI workers ask Washington to build a slowdown switch

An open letter titled Pacing the Frontier, published July 28 and now signed by more than 1,100 employees across OpenAI, Anthropic, Google DeepMind, and Meta, asks the US government to help develop the technical and governance infrastructure needed for a coordinated, verifiable slowdown of frontier AI development, if and when systems begin advancing faster than humans can safely oversee them.

Notable signatories include two Anthropic cofounders and OpenAI’s chief scientist, and both companies have backed the letter as organizations, not just through individual employees. It is a notably different posture than most public AI safety statements, in that it comes from people building the systems in question rather than outside observers, and it lands the same week Congress introduced its own AI Kill Switch Act. Together, they are a useful signal of where the policy conversation is actually heading, regardless of whether either effort becomes binding law this year.

Free frontier model access for 100,000 researchers

OpenAI launched ChatGPT for Academic Researchers on July 29, a 250 million dollar program giving selected academic researchers free access to GPT-5.6 Sol Pro along with onboarding support and integration help from OpenAI staff. The program starts this summer with 10,000 researchers at a handful of institutions, including the Institute for Advanced Study and Ecole normale superieure, and is expected to scale toward 100,000 researchers by 2027.

For research teams that have been priced out of frontier-tier model access, this closes a real gap, and it is worth watching whether Anthropic or Google follow with comparable academic programs of their own.

Gartner puts a governed agent platform on five market guides at once

Infrastructure automation vendor Itential announced it was named a Representative Vendor across five separate 2026 Gartner Market Guides, spanning infrastructure automation and orchestration, AI assistants for infrastructure as code, agentic NetOps, network automation, and campus networking. The recognition centers on FlowAI, Itential’s agentic orchestration layer, which pairs role-based agents that reason about operational intent with governed execution paths that keep every action auditable across hybrid, multi-vendor infrastructure.

The detail worth noting for DevOps and platform teams: Gartner’s framing treats AI as shifting from an assistant that suggests changes to a system that executes operational work directly, with boundaries set at build time and every reasoning trace preserved for audit. That is the same governed-autonomy pattern showing up across the infrastructure-agent space this year, and it is a good checklist to hold any vendor’s pitch against, including your own internal builds.