AI news you can use — August 23, 2026
A regulator fined Uber €825 million for letting software decide who stops earning
The Dutch data protection authority issued a fine of nearly €825 million against Uber on 21 August over the way driver accounts were switched off. According to the regulator, between 2018 and 2022 systems that scored driving behaviour and customer ratings could flag a driver for suspected fraud or a rating judged too low, and the account was then deactivated automatically — temporarily in some cases, permanently in others — without a person reviewing the decision, and without drivers being told clearly enough that software was making it. Europe's data protection law generally forbids fully automated decisions that have a serious effect on someone's life, and requires that a human can be asked to look again. Coverage of the decision puts it at roughly $966 million, the second-largest penalty issued under that law. The company says it strongly disagrees, that most suspensions are brief, that permanent deactivations do involve human review, that drivers can appeal, and that it will challenge the decision. The case began with a complaint brought on behalf of 171 drivers in France.
Why it matters: This is the first really large bill for a practice that is spreading fast — software deciding, on its own, that a person is out. The principle is not limited to ride-hailing: automated screening of job applications, automatic account closures, algorithmic scoring of contractors and AI fraud checks that lock a customer out all sit in the same territory. If your business uses any tool that makes a consequential decision about a person without someone reviewing it, the safe pattern is simple and worth adopting whatever your country's rules say: tell people a system is involved, keep a human in the loop for anything that ends a relationship or a paycheque, and give a real route to appeal to a person who can overturn it.
An Android banking trojan is now blocking phones from talking to Google Play
Security researchers published findings on a new version of the ToxicPanda Android malware, and the notable trick is defensive: after installation it asks for permission to run a VPN, then uses that position over the phone's network traffic to cut off communication with Google Play, so the phone's built-in protections cannot easily step in. The research describes overlay screens that sit invisibly on top of real banking apps to capture what is typed, a module aimed at harvesting screen-lock PINs, and remote control of the infected handset. Reporting on the research notes it targets hundreds of banking, e-wallet and cryptocurrency apps across 16 countries, and that the installers were being served from cloud storage rather than any app store — victims are talked into installing the file themselves and then into granting VPN and accessibility permissions during a fake setup process.
Why it matters: Nothing here defeats a careful person; the whole chain depends on someone tapping through permission prompts for an app that did not come from the official store. Install apps only from Google Play or your phone maker's own store, and if a link in a message, an ad or a support call asks you to install a file directly, treat that as the attack. Then check what is already on the phone: open Settings and look at which apps hold VPN access and which hold Accessibility permissions — those two together are the combination this relies on, and almost nothing you actually use needs them. Turn off anything you do not recognise, and make sure Play Protect is switched on.
An email server flaw is on the US patch-now list, with attacks already happening
The US cybersecurity agency added a flaw in Zimbra Collaboration to its Known Exploited Vulnerabilities catalogue on 21 August, the list it maintains of problems confirmed to be under active attack. Zimbra is a mail and calendar suite that small organisations, schools and hosting providers often run for their own email instead of using a large provider. The flaw, CVE-2026-73570, lets an attacker who has not logged in at all run commands on the server, and it applies where an optional monitoring component is installed and switched on. Technical reporting on the issue says a fix shipped in version 10.1.20 in July, that a national computer emergency response team in Poland confirmed exploitation in the wild the week of 20 August, and that US federal agencies were given until 24 August to patch.
Why it matters: Most readers do not run their own mail server, but plenty of small businesses have one somewhere in the background, set up years ago by a contractor and rarely touched since. If any of your email runs on Zimbra, update to 10.1.20 or later today rather than at the next maintenance window — a flaw that needs no password and is already being used is about as urgent as this gets. If you are not sure what your email runs on, that question is worth an email to whoever set it up, along with a second one: what else on our network has not been patched this year?
The company behind America's licence-plate cameras is cutting how long it keeps the footage
Flock Safety, whose cameras read and log licence plates for thousands of local police forces and private communities, is facing pressure from both political parties after reporting documented dozens of cases in which officers ran searches without authorisation, including looking up former partners. Three House Republicans have introduced a bill, H.R. 9800, that would bar federal purchases of automated surveillance systems using facial recognition or licence-plate recognition, and prominent figures on the left have campaigned against the cameras' spread. The company has made changes: default retention of the data has dropped from 30 days to 7, and searches now require a case code — though both settings can be overridden in an evidence mode. Its chief executive has apologised to people harmed by misuse, said the searches revealed abuse rather than caused it, and called for regulation and a compromise between privacy and public safety.
Why it matters: These cameras are not a federal programme you can opt out of — they are bought locally, by town councils, sheriffs' offices, business districts and homeowners' associations, which is also where the rules about them get set. If you drive through a town that has them, your movements are being logged by default; how long that log lives and who may search it is now a decision a handful of local officials make. Two questions are worth asking at a council or association meeting, and they are the ones the company's own changes concede matter most: how long is the data kept here, and who reviews the record of who searched it.