Good morning, I'm your AI Brief anchor. Here's what's happening in AI today, Friday, July 24, 2026.
Major Health AI Breach Exposes 2 Million Patients
Our top story this morning: a critical security breach at the AI health startup CogniHealth has exposed the personal data of approximately two million patients. The company confirmed that attackers accessed its cloud infrastructure, stealing sensitive health information and, in a deeply concerning development, the company’s proprietary diagnostic AI model.
The stolen data includes names, dates of birth, and detailed diagnostic notes. But the theft of the AI model itself represents a new and alarming threat. Experts worry this could allow bad actors to reverse-engineer the technology to find new vulnerabilities, or even deploy a counterfeit version for malicious purposes. This incident follows a similar, though smaller, breach disclosed yesterday at SynapseHealth AI, highlighting a troubling trend of cyberattacks targeting the AI-powered healthcare sector. Federal investigators are now involved, and the full impact of this dual-headed breach—of both patient data and the AI 'brain' that processes it—is still being assessed.
The AI Jailbreak Arms Race Heats Up
Moving on, the cat-and-mouse game between AI developers and those seeking to bypass their safety controls is escalating dramatically. This week, two separate research teams have unveiled powerful new "jailbreak" techniques capable of tricking major AI models into ignoring their safety filters.
First, researchers from the Stanford Artificial Intelligence Laboratory introduced a method they call 'CharSling'. It works by cleverly manipulating the structure of a prompt, effectively confusing the AI and causing it to obey harmful instructions it would normally refuse. Meanwhile, a team at Carnegie Mellon University revealed a different technique named 'ArtfulPrompt', which uses invisible Unicode characters to obfuscate commands. Think of it like a Trojan Horse, hiding a malicious request inside what looks like a perfectly innocent sentence. Both methods have proven highly effective in lab tests against leading large language models, raising urgent questions about the robustness of the safety measures we rely on.
EU Mandates Third-Party Audits for High-Risk AI
In other news, regulators are responding to these growing security concerns. The European Parliament has formally ratified the final provisions of its landmark EU AI Act, locking in a critical new rule: mandatory third-party audits for all "high-risk" AI systems. This category includes AI used in critical infrastructure, medical diagnostics, law enforcement, and hiring.
Effective immediately, companies deploying these systems in the EU can no longer simply self-certify their safety and compliance. They will now be required to hire independent, accredited auditors to rigorously test their models for bias, security vulnerabilities, and reliability before they can be brought to market. A senior EU official stated the goal is to "replace corporate promises with independent proof," marking a significant shift toward stricter, enforceable oversight of the technology. This move is expected to have a ripple effect globally, setting a new standard for AI accountability.