Apr 10, 2026 security

EU AI Act open-source exemption guidance clarifies rules for self-hosters

The European Commission published guidance on the EU AI Act's open-source exemption, clarifying which open-weight models qualify for lighter regulatory treatment. Models under 10B parameters released under open-source licenses are exempt from most compliance requirements. The guidance also clarifies that self-hosting open models for internal use falls under different rules than distributing them commercially.

Source: European Commission
Apr 10, 2026 release

OpenClaw v2026.4.10 Bundles Codex Provider With Native Authentication

GPT-5 family support lands in OpenClaw alongside a bundled Codex provider with native authentication. Setup for OpenAI-powered agents is now simpler with fewer manual config steps.

Source: Petronellatech
Apr 10, 2026 release

OpenClaw v2026.4.10 Ships Local Voice Synthesis on macOS via MLX Framework

OpenClaw v2026.4.10 enables Apple Silicon users to run voice I/O entirely on-device without cloud APIs using the MLX framework. This is the first step toward fully offline agent voice interaction on macOS.

Source: Petronellatech
Apr 9, 2026 security

Microsoft outlines its vision for an agentic SOC model

Microsoft published a detailed blueprint for running security operations with AI agents. The model has two layers: automated defenses that block known threats in seconds, and AI agents that handle investigation and triage while humans focus on judgment calls and strategy.

Source: Microsoft Security Blog
Apr 9, 2026 community

Qwen 3 ships in eight sizes from 0.6B to 72B, beats GPT-4o on key benchmarks

Alibaba's Qwen team released the Qwen 3 model family in eight sizes from 0.6B to 72B dense plus a 235B MoE variant. The 72B flagship became the first open-weight model to beat GPT-4o on MMLU-Pro. The code-specialized Qwen3-Coder-32B offers 128K context and native tool calling, pulling 420,000 downloads in its first week.

Source: Qwen (Alibaba)
Apr 8, 2026 update

MCP governance expands with new lead maintainer and core team additions

The Model Context Protocol expanded its maintainer team with two changes. Den Delimarsky stepped up from Core Maintainer to Lead Maintainer alongside David Soria Parra, and Clare Liguori joined as Core Maintainer bringing agent-runtime and developer-tooling experience. The changes give the protocol more leadership capacity as SEP volume and community contributions grow.

Source: MCP Blog
Apr 8, 2026 update

MCP expands maintainer team with new lead and core maintainer

The Model Context Protocol added Den Delimarsky as co-Lead Maintainer and Clare Liguori as Core Maintainer. The changes give the project more leadership capacity as it handles increasing SEP volume and prepares for production-grade features.

Source: MCP Blog
Apr 8, 2026 community

HuggingFace releases SmolVLM2 at 2.2B for multimodal AI on edge devices

Hugging Face released SmolVLM2-2.2B, a tiny multimodal model that handles text, images, and video on devices with as little as 4GB of RAM. It gained 180,000 downloads in its first week. The model is designed for edge deployment where cloud APIs are impractical or too expensive, opening up vision capabilities for embedded and IoT use cases.

Source: Hugging Face
Apr 8, 2026 community

LiteLLM proxy unifies Ollama, vLLM, and cloud APIs behind one endpoint

LiteLLM gained attention in April as a unified proxy that sits between applications and multiple LLM backends. It exposes a single OpenAI-compatible API endpoint that routes requests to Ollama, vLLM, Claude, GPT, or other providers based on configuration. Features include automatic fallback between providers, per-key budgets, and request logging. Note the critical SQL injection CVE-2026-42208 (CVSS 9.3) disclosed the same month.

Source: LiteLLM
Apr 8, 2026 community

LiteLLM proxy routes between Ollama, vLLM, and cloud APIs from a single endpoint

LiteLLM is an open-source proxy that exposes a single OpenAI-compatible API endpoint and routes requests to 100+ model providers, including local Ollama and vLLM instances. It handles automatic fallback, load balancing, and per-key budget controls.

Source: LiteLLM
Apr 8, 2026 release

Meta Rebuilds Its AI Stack from Scratch, Launches Muse Spark

After a disappointing Llama launch last year, Meta spent 9 months rebuilding its entire AI stack. The result is Muse Spark — with parallel reasoning agents and a shopping mode. AI capex: up to $135 billion.

Source: CNBC
Apr 8, 2026 community

Microsoft Markitdown converts any document to Markdown for LLM input - 3,600 GitHub stars

Microsoft's open-source Markitdown tool converts documents in any format (PDF, DOCX, PPTX, HTML, images) to clean Markdown for LLM consumption. The project gained 3,600+ stars in its first two weeks of April activity.

Source: GitHub
Apr 8, 2026 community

Mistral ships Codestral 2 - Apache 2.0 licensed code model with 380K first-week downloads

Mistral released Codestral 2, a 22B parameter code-specialized model under the Apache 2.0 license. The fully unrestricted commercial license and strong coding performance drove 380,000 downloads in the first week.

Source: Mistral
Apr 8, 2026 community

Mistral ships Codestral 2 under Apache 2.0 with 380K first-week downloads

Mistral released Codestral 2, a 22B code-specialized model under the Apache 2.0 license. It pulled 380,000 downloads in its first week on Hugging Face. Unlike earlier Codestral releases with restrictive licensing, Apache 2.0 allows unrestricted commercial use. At 22B parameters it fits on a single GPU with room to spare.

Source: Mistral AI
Apr 7, 2026 update

AI agent builders need a new 2026 evaluation framework

Andrew Green argues that AI agent development tools need a fresh evaluation framework for 2026 because many features that once differentiated vendors have become table stakes. He says web search, document grounding, connectors, and prompt templates now come natively in many LLM services, while enterprise-readiness and deterministic workflow control deserve more attention.

Source: n8n Blog
Apr 7, 2026 community

The Awesome-OpenClaw Ecosystem Keeps Growing: 5,400+ Curated Skills

Multiple community-maintained awesome lists on GitHub now catalog thousands of OpenClaw skills, use cases, dashboards, and deployment tools. The VoltAgent list alone indexes over 5,400 skills from ClawHub's 13,700+ registry.

Source: GitHub
Apr 7, 2026 community

Anthropic Announces Claude Mythos Preview and Launches Project Glasswing

Anthropic revealed its most powerful model — a 10-trillion-parameter system that autonomously found thousands of zero-day vulnerabilities in every major OS and browser. Not publicly available; only ~40 vetted partners including AWS, Apple, Google, and Microsoft get access for defensive cybersecurity.

Source: Anthropic
Apr 7, 2026 community

Continue.dev 1.0 ships - open-source AI coding extension supports any model backend

Continue.dev released version 1.0, graduating from beta as a fully open-source IDE extension for AI-assisted coding. The extension supports autocomplete, chat, and inline editing powered by any model backend including local models via Ollama.

Source: Continue.dev
Apr 7, 2026 community

Continue.dev 1.0 graduates from beta as open-source AI coding extension

Continue.dev shipped its 1.0 release, graduating from beta as a fully open-source IDE extension for AI-assisted coding. It supports VS Code and JetBrains with autocomplete, chat, and inline editing powered by any model backend. You can connect it to local models via Ollama, making it a free alternative to Cursor and GitHub Copilot.

Source: Continue.dev
Apr 7, 2026 community

Google ships Agent Development Kit for Python - 8,200 stars in two weeks

Google released the Agent Development Kit (ADK) for Python, a multi-agent orchestration framework that gained 8,200+ GitHub stars in its first two weeks. The framework supports MCP integration and works with any model provider.

Source: Google
Apr 7, 2026 security

Researchers Show AI Agents Can Chain Attacks — 85% Success on Credential Access

A university study found that AI agent frameworks like OpenClaw dramatically amplify attack risk. While a bare model might refuse to help, an agent with tool access can be manipulated into full attack chains with high success rates.

Source: Geek Metaverse
Apr 7, 2026 security

Mercor Breach Exposes AI Supply Chain Risk via LiteLLM

The $10B AI startup serving Anthropic, OpenAI, and Meta was hit through a supply-chain attack on LiteLLM — a popular open-source library. The breach potentially exposed customer data and details about AI projects.

Source: Fortune
Apr 7, 2026 security

Project Glasswing targets AI-powered software vulnerability hunting

Anthropic announced Project Glasswing, a security initiative with AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, Palo Alto Networks and others to use its unreleased Claude Mythos Preview model for defensive cyber work. The company said the model has already found thousands of high-severity and zero-day vulnerabilities across major operating systems and browsers, and that it will share findings with partners and the broader industry.

Source: Anthropic News
Apr 6, 2026 community

Google launches Agent Development Kit for multi-agent Python orchestration

Google released the Agent Development Kit (ADK) for Python, a multi-agent orchestration framework that gained 8,200+ stars in its first two weeks on GitHub. ADK provides structured patterns for building systems where multiple AI agents coordinate on complex tasks, with built-in MCP support for tool integration.

Source: Google
Apr 6, 2026 community

Unsloth ships Llama 4 fine-tuning support with 2x speed and 70% less memory

Unsloth added day-one support for Llama 4 fine-tuning, delivering 2x faster training speed and 70% less memory compared to standard approaches. The optimization makes fine-tuning Llama 4 Scout practical on consumer hardware with a single RTX 3090 or RTX 4090. Unsloth also published quantized GGUF packs for immediate local inference.

Source: Unsloth
Apr 6, 2026 security

Research Finds 60–65% of AI-Generated "Vibe Code" Is Vulnerable

A study found the majority of code written by AI assistants contains security vulnerabilities, with prompt injection being the top threat in deployed LLM systems. The findings challenge the growing "just vibe code it" trend.

Source: Multiple
Apr 5, 2026 community

Meta releases Llama 4 Scout and Maverick - MoE models that run on consumer hardware

Meta released Llama 4 Scout (109B total, 17B active) and Maverick (400B total, 17B active) as open-weight MoE models. Scout runs on a single 48GB GPU with quantization, making it practical for local AI workstations.

Source: Meta
Apr 5, 2026 community

Meta releases Llama 4 Scout and Maverick with 17B active parameters

Meta shipped two Mixture-of-Experts models in the Llama 4 family. Scout has 109B total parameters with 17B active and fits on a single 48GB GPU at 4-bit quantization. Maverick scales to 400B total with the same 17B active count for heavier workloads. Both available on Hugging Face and Ollama with day-one community tooling from Unsloth and vLLM.

Source: Meta AI
Apr 5, 2026 security

CVE-2026-35641 — Arbitrary Code Execution via .npmrc Targeting (CVSS 8.4)

All OpenClaw instances older than v2026.4.5 are vulnerable to arbitrary code execution through crafted .npmrc files. The attack requires no authentication and can be triggered remotely.

Source: Blink
Apr 3, 2026 update

MCP Dev Summit NYC draws 1,200 attendees - stateless transport and MCP Apps take center stage

The first MCP Dev Summit under the Agentic AI Foundation drew 1,200 developers to New York. Key announcements included stateless transport work, MCP Apps adoption across major platforms, and real-world case studies from Amazon and Uber.

Source: InfoQ
Apr 3, 2026 update

MCP Dev Summit NYC draws 1,200 attendees and previews stateless transport

The first MCP Dev Summit under the Agentic AI Foundation drew about 1,200 developers to New York on April 2-3. Key announcements included stateless transport work via SEP-1442 to fix load balancer compatibility, MCP Apps adoption across Claude, ChatGPT, VS Code and Goose, and real-world case studies from Amazon, Uber, and Duolingo. Duolingo shared how they went from a few engineers to 250 weekly active MCP users internally.

Source: InfoQ
Apr 3, 2026 community

AI2 releases OLMo 2 32B - fully open model with training data, code, and weights under Apache 2.0

The Allen Institute for AI released OLMo 2 32B, a 32B dense model with everything open: training data, training code, model weights, and evaluation tools, all under Apache 2.0. It is the most transparent large model release to date.

Source: AI2
Apr 3, 2026 community

AI2 releases OLMo 2 at 32B with fully open training data and code

The Allen Institute for AI released OLMo 2 32B under the Apache 2.0 license with something no other model at this scale offers: fully open training data, training code, and evaluation scripts alongside the model weights. At 32B dense parameters it needs about 20GB VRAM at 4-bit quantization. The complete transparency makes it a reference implementation for understanding how large models are built.

Source: Allen Institute for AI
Apr 2, 2026 update

Google Releases Gemma 4 Open-Source Model for Agentic Workflows

Google released Gemma 4 as an open-weight model purpose-built for reasoning and agentic workflows. It targets developers building local AI agents and tools.

Source: Google
Apr 1, 2026 community

AI Scientist-v2 Introduces Automated Scientific Discovery via Agentic Tree Search

Sakana AI's system can autonomously propose hypotheses, design experiments, run them, and write research papers. One paper was accepted at ICLR 2026 — the first AI-authored work to pass formal peer review at a top venue.

Source: devFlokers
Apr 1, 2026 security

Security Researchers Flag Critical Vulnerabilities in OpenClaw and Agentic Frameworks

Researchers warned that agent frameworks running shell commands — including OpenClaw — are vulnerable to prompt injection and supply chain attacks via malicious "skills." Hardened forks like NanoClaw emerged, isolating agents in Docker containers.

Source: devFlokers
Mar 31, 2026 security

AWS Security Agent adds on-demand penetration testing

AWS Security Agent now offers on-demand penetration testing across AWS, Azure, GCP, and on-premises environments. The service combines SAST, DAST, and pen testing to validate vulnerabilities and generate remediation pull requests.

Source: AWS Security Blog