AI and IT News Recap: July 16, 2026: Japan and NVIDIA Switch On the World's First National AI Grid, Anthropic Spins Up a .5B Deployment Firm, and CISA Sounds the SharePoint AlarmBy Noah Smith, Owner & Consultant, KeyChange Technologies ยท July 16, 2026

A whole country wiring itself for AI, a fresh bet that the real money is in getting AI to actually work inside businesses, and a security day where the loudest siren is an old favorite: SharePoint.
Here is your no-spin AI and IT news roundup for July 16, 2026. Today leans big-picture on the AI side and back-to-basics on security. If you run anything on-premises, skip to the SharePoint item first.
๐ The AI and IT news at a glance
- ๐ Japan and NVIDIA launch the "world's first national AI infrastructure" built on a 27,500-GPU Vera Rubin AI factory.
- Anthropic, Blackstone and Hellman & Friedman open Ode, a .5B firm whose whole job is deploying AI inside real companies.
- Anthropic lines up IPO investor meetings, with a listing possible as soon as October.
- CISA warns a trio of SharePoint flaws are under active attack, with a July 17 federal patch deadline.
- Zoom patches a perfect-storm 9.8 account-takeover bug in its Windows clients.
- DOJ indicts three Russians who allegedly kept ransomware crews online for a living.
- OpenAI ships the Codex Micro, a physical macro pad for its 5-million-a-week coding agent.
- Claude turns on self-serve HIPAA setup for Enterprise and API customers.
๐ค AI
๐ Japan and NVIDIA flip the switch on a national AI grid
Japan's government, its biggest industrial players, and NVIDIA jointly announced what they are calling the world's first national AI infrastructure, a country-scale compute base aimed squarely at "physical AI" (robotics, digital twins, and the kind of models that run factories and logistics rather than chatbots). The centerpiece is an NVIDIA Vera Rubin AI factory being built with Noetra Corp., packing 13,750 Vera CPUs and 27,500 Rubin GPUs and delivering roughly 140 megawatts of data-center capacity on NVIDIA's DSX platform.
The project is backed by Japan's Ministry of Economy, Trade and Industry (METI) and will feed the country's FRONTia initiative, providing the horsepower for open multimodal foundation models that power AI agents, digital twins, and robotics across manufacturing, logistics, healthcare, and telecom. The framing matters: this is a nation treating AI compute the way it once treated power plants and rail, as shared public infrastructure rather than something each company scrapes together on its own.
In short: Japan and NVIDIA are standing up a government-backed, 27,500-GPU "AI factory" pitched as the first national AI infrastructure for physical AI.
What it means for your business: Nation-scale compute plus open foundation models tends to trickle down into cheaper, more capable tools for everyone, especially in robotics, manufacturing, and logistics, so watch this space if you operate in the physical world and not just spreadsheets.
My take: The word "physical" is the tell here. The last three years of AI hype were about text and images; the next fight is about AI that moves things in the real world, and Japan just planted a very large flag in it. For most small businesses this is a weather report, not an action item, but it is the kind of weather that eventually changes what your equipment vendors can offer you.
Source: NVIDIA Newsroom
Anthropic and Blackstone launch Ode, a .5B "make AI actually work" firm
Anthropic, Blackstone, and Hellman & Friedman officially introduced Ode with Anthropic, an enterprise AI services company valued at about
.5 billion. Anthropic, Blackstone, and Hellman & Friedman each put in roughly 00 million, Goldman Sachs added around 50 million, and General Atlantic, Leonard Green, Apollo, GIC, and Sequoia rounded out the consortium. Ode employs about 100 engineers and is built on the foundation of Fractional AI, an applied-AI services startup the venture acquired shortly after announcing the plan back in May. It runs on a "Claude-first" principle but will use rival AI products when a customer genuinely needs them, and it is aimed at the messy realities of healthcare, finance, and manufacturing.
The strategic bet is blunt: the partners think the next trillion-dollar AI category is not the models themselves but the unglamorous work of getting them into real companies, wired into real systems, doing real jobs. It is a services-and-integration play dressed in frontier-AI clothing, led by Fractional AI co-founders Chris Taylor (CEO) and Eddie Siegel (CTO).
In short: Anthropic and two major investment firms launched Ode, a roughly
.5B, 100-engineer company built to deploy AI inside large enterprises.
What it means for your business: The biggest names in AI are openly admitting that buying a model is the easy part and making it useful is the hard part, which is exactly the gap most companies fall into after the pilot.
My take: This is the most honest thing the AI industry has done all year. Everyone who has tried to roll out an AI tool knows the model was never the bottleneck; the bottleneck was your data, your processes, and the person who still emails spreadsheets around. Ode is chasing that bottleneck. You do not need a billion-dollar firm to fix it, but you do need to treat deployment as the real project.
Source: TechCrunch
Anthropic starts lining up an IPO, possibly by October
Separately, Anthropic is arranging investor meetings ahead of a potential initial public offering that could come as soon as October, as it races to reach the public markets ahead of rival OpenAI. Goldman Sachs, Morgan Stanley, and JPMorgan Chase are reported to be involved in the offering. Nothing is final, and IPO timelines slip constantly, but the fact that bankers are being lined up is a real signal about where the company thinks it stands.
In short: Anthropic is reportedly preparing IPO investor meetings with a listing possible as early as October.
What it means for your business: A public Anthropic means more financial disclosure and more pressure to turn Claude into durable revenue, which usually translates into steadier enterprise products and, eventually, steadier pricing.
My take: An IPO is a double-edged sword for customers. On one hand you get transparency and a company that has to answer to shareholders; on the other, public companies chase margins, and "chasing margins" in AI has a habit of showing up as price changes on the tools you depend on. Worth keeping an eye on if Claude is in your stack.
Source: CNBC
๐ก๏ธ IT and security
CISA sounds the alarm on a trio of actively exploited SharePoint flaws
CISA warned that attackers are actively exploiting three vulnerabilities in internet-exposed, on-premises SharePoint Server (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) and added them to its Known Exploited Vulnerabilities catalog. The attack chain is nasty: adversaries are bypassing authentication, gaining remote code execution, then stealing IIS machine keys and planting persistence so they can drop malware and stay resident even after a reboot. CVE-2026-56164 is the standout, an unauthenticated privilege-escalation bug that an attacker can trigger remotely with no credentials and no user interaction.
Federal agencies were given until July 17 to patch or disconnect affected SharePoint servers under Binding Operational Directive 26-04. That deadline is aimed at government, but the exploitation is not picky, and on-prem SharePoint remains one of the most common soft targets sitting on business networks. If you host your own SharePoint, this is a today problem.
In short: CISA says three on-prem SharePoint flaws are under active attack and set a July 17 federal patch-or-disconnect deadline.
What it means for your business: Internet-facing, self-hosted SharePoint is a favorite way in for attackers right now, and "we will patch it next cycle" is no longer a safe answer.
My take: SharePoint has quietly become the new Exchange: a sprawling, on-prem product that too many organizations expose to the internet and then forget about. If you are not sure whether you run a self-hosted SharePoint box, that uncertainty is the vulnerability. Find out today, patch it, and ask whether it needs to face the internet at all.
Source: The Register
Zoom patches a 9.8 account-takeover bug in its Windows clients
Zoom warned of a critical flaw, CVE-2026-53412, carrying a near-maximum CVSS score of 9.8, in its Windows desktop client, VDI client, and Meeting SDK. The advisory describes an improper-input-validation issue that could let an unauthenticated attacker take over an account over the network with no credentials and no user interaction required. The affected products are Zoom Workplace for Windows before 7.0.0, the Windows VDI Client before 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before 7.0.0. Zoom says there is no sign the bug is being exploited yet, and the fix is simply to update to the latest version.
In short: Zoom fixed a 9.8-severity flaw that could let an unauthenticated attacker hijack Windows-client accounts over the network.
What it means for your business: Zoom is on nearly every corporate laptop, so a no-interaction, no-credentials account-takeover bug is exactly the kind of thing to push through your update process now, before someone writes an exploit.
My take: "No known exploitation" is a countdown, not an all-clear. A 9.8 that needs no user interaction is catnip for attackers, and the patch is free and boring to apply. Bump your Zoom clients this week and move on.
Source: BleepingComputer
DOJ indicts three Russians who allegedly kept ransomware gangs online
U.S. prosecutors unsealed charges against three Russian nationals (Alexander Volosovik, 43; Kirill Zatolokin, 34; and Yulia Pankova, 29) along with two St. Petersburg companies, Medialand LLC and ML.Cloud LLC, accusing them of running a "bulletproof hosting" operation. Bulletproof hosts rent out servers that are deliberately resistant to takedowns and abuse complaints, and this one allegedly provided the infrastructure and tech support behind ransomware and cybercrime crews including LockBit, BlackSuit, and Play. The Justice Department ties the network to more than $62 million in losses across 44 victims in 21 states and several countries. The three were already sanctioned by the U.S., U.K., and Australia last November, and the underlying indictment was originally returned in late 2024 in the Northern District of Ohio.
In short: The DOJ charged three Russians and two companies for allegedly providing the takedown-resistant hosting that powered LockBit, BlackSuit, and Play attacks tied to over $62M in losses.
What it means for your business: Most ransomware you would ever encounter rides on rented, hard-to-kill infrastructure like this, so pressure on the plumbing is one of the few things that actually raises attackers' costs.
My take: Indictments of people who will likely never see a U.S. courtroom can feel like theater, but going after the hosting layer is smarter than chasing individual gangs. Ransomware is a supply chain, and the hosting providers are a chokepoint. It will not stop attacks tomorrow, but it makes the whole business messier for the people running it.
Source: TechCrunch
๐งฐ New tools for builders and businesses
OpenAI ships the Codex Micro, a physical macro pad for its coding agent
OpenAI released the Codex Micro, a programmable developer macro pad co-built with Work Louder, its first branded piece of hardware after teasing it in late June. It carries 13 mechanical keys, a joystick, a rotary encoder, and six programmable layers, and it is aimed at the more than 5 million weekly users of Codex, OpenAI's autonomous coding agent. The pitch is dedicated physical buttons for the actions developers repeat all day: kicking off a code generation, launching a prompt, running tests, or switching between environments with a single press instead of a keyboard gymnastics routine.
In short: OpenAI launched the Codex Micro, a programmable macro pad giving its 5-million-a-week coding agent dedicated physical controls.
What it means for your business: It is a small sign of a bigger shift, AI coding agents are becoming a standard part of the developer toolkit, which is worth knowing if you employ or contract anyone who ships software.
My take: A dedicated keypad for an AI agent is equal parts genuinely useful and a flex about how central Codex has become to people's workflows. You do not need the gadget. But if your developers are not using an agent like Codex at all yet, that is the actual story here, not the hardware.
Source: TechTimes
Claude turns on self-serve HIPAA setup for Enterprise and API
Anthropic added a self-serve HIPAA configuration flow for Claude Enterprise and Claude Platform (API) organizations. An eligible admin (the Primary Owner) can now go to Organization settings, then Data and privacy, then HIPAA Compliance, review and accept the Business Associate Agreement, download an implementation guide, and enable the HIPAA configuration in a single flow rather than negotiating it through sales. One important catch: enabling HIPAA is a one-way door. Once the BAA is accepted the change cannot be reversed from settings, and the standard BAA offered through the flow cannot be modified.
In short: Claude now lets Enterprise and API admins review the BAA and switch on a HIPAA configuration themselves, in one flow, with no way to undo it later.
What it means for your business: If you are in healthcare or handle protected health information, this lowers the bar to using Claude compliantly, but the one-way, standard-terms nature means you should read the BAA carefully before you click.
My take: Self-serve compliance is a real convenience and a real trap in the same breath. Convenient because you are not waiting weeks on a sales rep; a trap because "irreversible, non-negotiable, one click" is a sentence that should make any owner slow down. Have whoever owns your compliance read the agreement first, then enable it.
Source: Claude Help Center
That is the AI and IT news for July 16, 2026. Missed yesterday? Catch up with the July 15, 2026 recap.
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท July 16, 2026

A whole country wiring itself for AI, a fresh bet that the real money is in getting AI to actually work inside businesses, and a security day where the loudest siren is an old favorite: SharePoint.
Here is your no-spin AI and IT news roundup for July 16, 2026. Today leans big-picture on the AI side and back-to-basics on security. If you run anything on-premises, skip to the SharePoint item first.
๐ The AI and IT news at a glance
- ๐ Japan and NVIDIA launch the "world's first national AI infrastructure" built on a 27,500-GPU Vera Rubin AI factory.
- Anthropic, Blackstone and Hellman & Friedman open Ode, a .5B firm whose whole job is deploying AI inside real companies.
- Anthropic lines up IPO investor meetings, with a listing possible as soon as October.
- CISA warns a trio of SharePoint flaws are under active attack, with a July 17 federal patch deadline.
- Zoom patches a perfect-storm 9.8 account-takeover bug in its Windows clients.
- DOJ indicts three Russians who allegedly kept ransomware crews online for a living.
- OpenAI ships the Codex Micro, a physical macro pad for its 5-million-a-week coding agent.
- Claude turns on self-serve HIPAA setup for Enterprise and API customers.
๐ค AI
๐ Japan and NVIDIA flip the switch on a national AI grid
Japan's government, its biggest industrial players, and NVIDIA jointly announced what they are calling the world's first national AI infrastructure, a country-scale compute base aimed squarely at "physical AI" (robotics, digital twins, and the kind of models that run factories and logistics rather than chatbots). The centerpiece is an NVIDIA Vera Rubin AI factory being built with Noetra Corp., packing 13,750 Vera CPUs and 27,500 Rubin GPUs and delivering roughly 140 megawatts of data-center capacity on NVIDIA's DSX platform.
The project is backed by Japan's Ministry of Economy, Trade and Industry (METI) and will feed the country's FRONTia initiative, providing the horsepower for open multimodal foundation models that power AI agents, digital twins, and robotics across manufacturing, logistics, healthcare, and telecom. The framing matters: this is a nation treating AI compute the way it once treated power plants and rail, as shared public infrastructure rather than something each company scrapes together on its own.
In short: Japan and NVIDIA are standing up a government-backed, 27,500-GPU "AI factory" pitched as the first national AI infrastructure for physical AI.
What it means for your business: Nation-scale compute plus open foundation models tends to trickle down into cheaper, more capable tools for everyone, especially in robotics, manufacturing, and logistics, so watch this space if you operate in the physical world and not just spreadsheets.
My take: The word "physical" is the tell here. The last three years of AI hype were about text and images; the next fight is about AI that moves things in the real world, and Japan just planted a very large flag in it. For most small businesses this is a weather report, not an action item, but it is the kind of weather that eventually changes what your equipment vendors can offer you.
Source: NVIDIA Newsroom
Anthropic and Blackstone launch Ode, a
.5B "make AI actually work" firmAnthropic, Blackstone, and Hellman & Friedman officially introduced Ode with Anthropic, an enterprise AI services company valued at about
.5 billion. Anthropic, Blackstone, and Hellman & Friedman each put in roughly00 million, Goldman Sachs added around50 million, and General Atlantic, Leonard Green, Apollo, GIC, and Sequoia rounded out the consortium. Ode employs about 100 engineers and is built on the foundation of Fractional AI, an applied-AI services startup the venture acquired shortly after announcing the plan back in May. It runs on a "Claude-first" principle but will use rival AI products when a customer genuinely needs them, and it is aimed at the messy realities of healthcare, finance, and manufacturing.The strategic bet is blunt: the partners think the next trillion-dollar AI category is not the models themselves but the unglamorous work of getting them into real companies, wired into real systems, doing real jobs. It is a services-and-integration play dressed in frontier-AI clothing, led by Fractional AI co-founders Chris Taylor (CEO) and Eddie Siegel (CTO).
In short: Anthropic and two major investment firms launched Ode, a roughly
.5B, 100-engineer company built to deploy AI inside large enterprises.What it means for your business: The biggest names in AI are openly admitting that buying a model is the easy part and making it useful is the hard part, which is exactly the gap most companies fall into after the pilot.
My take: This is the most honest thing the AI industry has done all year. Everyone who has tried to roll out an AI tool knows the model was never the bottleneck; the bottleneck was your data, your processes, and the person who still emails spreadsheets around. Ode is chasing that bottleneck. You do not need a billion-dollar firm to fix it, but you do need to treat deployment as the real project.
Source: TechCrunch
Anthropic starts lining up an IPO, possibly by October
Separately, Anthropic is arranging investor meetings ahead of a potential initial public offering that could come as soon as October, as it races to reach the public markets ahead of rival OpenAI. Goldman Sachs, Morgan Stanley, and JPMorgan Chase are reported to be involved in the offering. Nothing is final, and IPO timelines slip constantly, but the fact that bankers are being lined up is a real signal about where the company thinks it stands.
In short: Anthropic is reportedly preparing IPO investor meetings with a listing possible as early as October.
What it means for your business: A public Anthropic means more financial disclosure and more pressure to turn Claude into durable revenue, which usually translates into steadier enterprise products and, eventually, steadier pricing.
My take: An IPO is a double-edged sword for customers. On one hand you get transparency and a company that has to answer to shareholders; on the other, public companies chase margins, and "chasing margins" in AI has a habit of showing up as price changes on the tools you depend on. Worth keeping an eye on if Claude is in your stack.
Source: CNBC
๐ก๏ธ IT and security
CISA sounds the alarm on a trio of actively exploited SharePoint flaws
CISA warned that attackers are actively exploiting three vulnerabilities in internet-exposed, on-premises SharePoint Server (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) and added them to its Known Exploited Vulnerabilities catalog. The attack chain is nasty: adversaries are bypassing authentication, gaining remote code execution, then stealing IIS machine keys and planting persistence so they can drop malware and stay resident even after a reboot. CVE-2026-56164 is the standout, an unauthenticated privilege-escalation bug that an attacker can trigger remotely with no credentials and no user interaction.
Federal agencies were given until July 17 to patch or disconnect affected SharePoint servers under Binding Operational Directive 26-04. That deadline is aimed at government, but the exploitation is not picky, and on-prem SharePoint remains one of the most common soft targets sitting on business networks. If you host your own SharePoint, this is a today problem.
In short: CISA says three on-prem SharePoint flaws are under active attack and set a July 17 federal patch-or-disconnect deadline.
What it means for your business: Internet-facing, self-hosted SharePoint is a favorite way in for attackers right now, and "we will patch it next cycle" is no longer a safe answer.
My take: SharePoint has quietly become the new Exchange: a sprawling, on-prem product that too many organizations expose to the internet and then forget about. If you are not sure whether you run a self-hosted SharePoint box, that uncertainty is the vulnerability. Find out today, patch it, and ask whether it needs to face the internet at all.
Source: The Register
Zoom patches a 9.8 account-takeover bug in its Windows clients
Zoom warned of a critical flaw, CVE-2026-53412, carrying a near-maximum CVSS score of 9.8, in its Windows desktop client, VDI client, and Meeting SDK. The advisory describes an improper-input-validation issue that could let an unauthenticated attacker take over an account over the network with no credentials and no user interaction required. The affected products are Zoom Workplace for Windows before 7.0.0, the Windows VDI Client before 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before 7.0.0. Zoom says there is no sign the bug is being exploited yet, and the fix is simply to update to the latest version.
In short: Zoom fixed a 9.8-severity flaw that could let an unauthenticated attacker hijack Windows-client accounts over the network.
What it means for your business: Zoom is on nearly every corporate laptop, so a no-interaction, no-credentials account-takeover bug is exactly the kind of thing to push through your update process now, before someone writes an exploit.
My take: "No known exploitation" is a countdown, not an all-clear. A 9.8 that needs no user interaction is catnip for attackers, and the patch is free and boring to apply. Bump your Zoom clients this week and move on.
Source: BleepingComputer
DOJ indicts three Russians who allegedly kept ransomware gangs online
U.S. prosecutors unsealed charges against three Russian nationals (Alexander Volosovik, 43; Kirill Zatolokin, 34; and Yulia Pankova, 29) along with two St. Petersburg companies, Medialand LLC and ML.Cloud LLC, accusing them of running a "bulletproof hosting" operation. Bulletproof hosts rent out servers that are deliberately resistant to takedowns and abuse complaints, and this one allegedly provided the infrastructure and tech support behind ransomware and cybercrime crews including LockBit, BlackSuit, and Play. The Justice Department ties the network to more than $62 million in losses across 44 victims in 21 states and several countries. The three were already sanctioned by the U.S., U.K., and Australia last November, and the underlying indictment was originally returned in late 2024 in the Northern District of Ohio.
In short: The DOJ charged three Russians and two companies for allegedly providing the takedown-resistant hosting that powered LockBit, BlackSuit, and Play attacks tied to over $62M in losses.
What it means for your business: Most ransomware you would ever encounter rides on rented, hard-to-kill infrastructure like this, so pressure on the plumbing is one of the few things that actually raises attackers' costs.
My take: Indictments of people who will likely never see a U.S. courtroom can feel like theater, but going after the hosting layer is smarter than chasing individual gangs. Ransomware is a supply chain, and the hosting providers are a chokepoint. It will not stop attacks tomorrow, but it makes the whole business messier for the people running it.
Source: TechCrunch
๐งฐ New tools for builders and businesses
OpenAI ships the Codex Micro, a physical macro pad for its coding agent
OpenAI released the Codex Micro, a programmable developer macro pad co-built with Work Louder, its first branded piece of hardware after teasing it in late June. It carries 13 mechanical keys, a joystick, a rotary encoder, and six programmable layers, and it is aimed at the more than 5 million weekly users of Codex, OpenAI's autonomous coding agent. The pitch is dedicated physical buttons for the actions developers repeat all day: kicking off a code generation, launching a prompt, running tests, or switching between environments with a single press instead of a keyboard gymnastics routine.
In short: OpenAI launched the Codex Micro, a programmable macro pad giving its 5-million-a-week coding agent dedicated physical controls.
What it means for your business: It is a small sign of a bigger shift, AI coding agents are becoming a standard part of the developer toolkit, which is worth knowing if you employ or contract anyone who ships software.
My take: A dedicated keypad for an AI agent is equal parts genuinely useful and a flex about how central Codex has become to people's workflows. You do not need the gadget. But if your developers are not using an agent like Codex at all yet, that is the actual story here, not the hardware.
Source: TechTimes
Claude turns on self-serve HIPAA setup for Enterprise and API
Anthropic added a self-serve HIPAA configuration flow for Claude Enterprise and Claude Platform (API) organizations. An eligible admin (the Primary Owner) can now go to Organization settings, then Data and privacy, then HIPAA Compliance, review and accept the Business Associate Agreement, download an implementation guide, and enable the HIPAA configuration in a single flow rather than negotiating it through sales. One important catch: enabling HIPAA is a one-way door. Once the BAA is accepted the change cannot be reversed from settings, and the standard BAA offered through the flow cannot be modified.
In short: Claude now lets Enterprise and API admins review the BAA and switch on a HIPAA configuration themselves, in one flow, with no way to undo it later.
What it means for your business: If you are in healthcare or handle protected health information, this lowers the bar to using Claude compliantly, but the one-way, standard-terms nature means you should read the BAA carefully before you click.
My take: Self-serve compliance is a real convenience and a real trap in the same breath. Convenient because you are not waiting weeks on a sales rep; a trap because "irreversible, non-negotiable, one click" is a sentence that should make any owner slow down. Have whoever owns your compliance read the agreement first, then enable it.
Source: Claude Help Center
That is the AI and IT news for July 16, 2026. Missed yesterday? Catch up with the July 15, 2026 recap.