Wednesday, July 15, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Morning Edition Free of Charge
TODAY'S LEAD STORY

"A task that was supposed to take six and a half years was completed in 20 hours"—A Canadian provincial government tackled a large-scale security audit using 50 AI agents.

This article explains a case study published by Anthropic on July 6th. It describes how the Alberta provincial government used Claude Code and approximately 50 agents to scan 466 million lines of code and fix vulnerabilities in 20 hours. The article summarizes the initial vulnerability discovery in Mozilla Firefox, the governance design incorporating human approval, the asymmetry between AI-driven vulnerability discovery and exploitation, and the transparency efforts through the publication of a technical white paper.

"A task that was supposed to take six and a half years was completed in 20 hours"—A Canadian provincial government tackled a large-scale security audit using 50 AI agents.
(Photo: illustrative)

"A task that was supposed to take 6.5 years was completed in 20 hours"—A Canadian provincial government tackled a large-scale security audit using 50 AI agents

"6.5 years" versus "20 hours." This extreme contrast is the content of a case study published by Anthropic on July 6th. It reports that the Alberta provincial government in Canada conducted a large-scale security audit of the entire province's systems using Claude. This article will examine this case from both a technical perspective and the process leading up to it.

The trigger was the precedent of "discovering Firefox vulnerabilities"

Tracing the origins of this initiative reveals an interesting propagation route. In February of this year, Anthropic's own team used Claude to scan the source code of the Firefox browser and discovered 22 vulnerabilities (14 of which were high-severity) in just two weeks. This is said to be roughly one-fifth of the high-severity Firefox vulnerabilities that will be fixed throughout 2025. Following these results, Mozilla, the developer, began incorporating Claude into its internal security operations.

Anthropic's report states that Alberta's cybersecurity department, after seeing the Anthropic-Mozilla case study, thought, "We could do this too," and actually began implementing it. This is a clear example of how corporate pilot projects can spread to government implementation—how AI technology permeates the field.

The Scale of "50 Agents in 20 Hours: 466 Million Lines"

Let's look at the specific work involved. The Alberta Department of Technology and Innovation manages approximately 1,280 applications and 3,400 code repositories across 27 provincial government ministries. Many of these had never undergone a systematic security review, and the accumulated technical debt was estimated to be in the billions of dollars.

Approximately 50 AI agents were run in parallel across this system, and using Claude Code (a combination of Opus and Sonnet models), 466 million lines of code were scanned in just 20 hours. The ministry estimates that this would have taken about six and a half years if done manually.

For vulnerabilities found, Claude Code generated corrective code, created missing tests, and in some cases, even rebuilt the entire system. A symbolic example cited is the story of a grant application portal, originally written manually in Java about 25 years ago and initially built over five months, which was rebuilt in just four to five days.

Governance Design Based on "Human Approval"

What is technically and organizationally important here is that this entire workflow is not a system where "AI autonomously distributes patches." Multiple reports consistently emphasize the operational rule that all corrective patches are reviewed and approved by state government engineers before deployment.

Furthermore, Alberta has independently developed a specialized suite of Claude-based agents for continuous security reviews. This includes "red team" agents that simulate external attacks, "blue team" agents that assess compliance with international security standards, and additional agents that check code quality and the clarity of public documentation. The specialized agent configuration, tailored to each role, demonstrates that this is designed as a continuous operational system, not just a one-off tool. Each application is reportedly checked against approximately 95 security management items in a single pass.

Asymmetry between AI-driven vulnerability "discovery" and "exploitation"

Another technical point in this case is the current asymmetry between the speed at which AI discovers vulnerabilities and the difficulty of actually exploiting those vulnerabilities. In a previous test conducted by Anthropic, attempts to have Claude actually exploit vulnerabilities it discovered were unsuccessful only twice out of hundreds of attempts.

In other words, currently, the situation is asymmetrical: "AI-based vulnerability detection and remediation (defense)" is far closer to practical application than "AI-based vulnerability exploitation (attack)." However, Anthropic itself frankly states that there is no guarantee this advantage will last, and the gap in detection and exploitation capabilities may narrow in the future. The significance of the defense side actively adopting this technology now lies in utilizing the time available to prepare while this asymmetry persists.

The Option of Information Disclosure

Alberta has released over 21 technology papers (known as Velocity Papers) as open source regarding this initiative, allowing other government agencies to take a similar approach. Minister of Technology and Innovation, Nate Glubish, described this initiative as "responsible government in the age of AI" and commented that he welcomes opportunities for collaboration with other governments.

Points to Note for Researchers

This is a case study published by Anthropic itself, and information such as the audit results by an independent third party, details of the false-positive rate, and the breakdown of vulnerability severity cannot be fully verified based on the currently available information. While the publication of the technical white paper is commendable from a transparency standpoint, the extent to which this approach is reproducible and its accuracy will likely be determined through further testing and verification by other government agencies and independent researchers.

Nevertheless, the fact that AI agent-based code auditing technology is moving beyond the realm of pilot projects and beginning to be incorporated into the operation of critical public infrastructure is a noteworthy development that indicates steady progress in the implementation phase of this field.

AnthropicClaude Codeサイバーセキュリティ企業公式発表AIエージェント政府DX

A Japanese-made humanoid robot equipped with "two brains"—the cerebrum and cerebellum—the reason why Mitsubishi Motors is seriously aiming to deploy it in its factories.

This article explains the basic agreement that Mitsubishi Motors signed with Highlanders, a startup spun off from the University of Tokyo, on July 9th. It covers the mass production plan to utilize the Kyoto Plant to produce 1,000 units per month in the second half of 2027, the specifications of the fourth-generation robot "N," the architecture of the "Kepler v1.0" base model that separates the brain responsible for planning from the cerebellum responsible for body control, and the background of Japan's declining workforce, while also offering a skeptical perspective on the fact that it is still only a basic agreement.

A Japanese-Made Humanoid Robot with "Two Brains"—The Reason Mitsubishi Motors Is Seriously Aiming to Put It into Factory Production

On July 9th, news broke that Mitsubishi Motors had reached a basic agreement with Highlanders, a startup spun off from the University of Tokyo. The plan is to use idle facilities at its Kyoto Plant to produce humanoid robots at a rate of 1,000 units per month by the second half of 2027. This feels like a bold move from the Japanese humanoid robot scene, which has been somewhat overshadowed by the flashy announcements of overseas companies. This time, I'd like to delve into the details of this partnership from a software engineer's perspective.

A Structure Where an Automaker Takes on Mass Production Entirely

First, the structure of the partnership is interesting. Highlanders is a startup established in 2023 with strengths in AI and robotics research and development. Mitsubishi Motors, on the other hand, is a company that has accumulated decades of know-how in "producing things in large quantities with consistent quality"—including mass production design, quality assurance, durability and safety design, mechatronics control technology, and actual factory operations.

This partnership is best understood as bringing a model similar to the division of labor in the semiconductor industry—a fabless startup strong in AI research and a foundry-type automobile factory strong in mass production—into the humanoid field. It aims for a "vertically integrated model" that seamlessly connects development, mass production, and actual deployment. The roadmap is a phased approach, starting with a trial deployment of several dozen units at Mitsubishi Motors' Kyoto Plant (primarily engine assembly lines), followed by a consideration of expanding to other locations based on the results.

The Star is the 4th Generation Robot "N"

The robot itself is Highlanders' 4th generation model, "N". The article also introduces the rather ambitious origin of the name, which combines the shape of the Roman numeral IV with the first letters of "Japan," "Human," and "Wish." Equipped with a five-fingered hand, multiple vision systems, a microphone array, and a latest-generation GPU, and designed to have a height and weight close to that of a human, it is said to have the versatility to directly operate tools made for humans, such as buttons and pedals.

In terms of walking control, the AI ​​generates the next movement at a frequency of approximately 100 times per second, achieving optimal movement. While this update frequency itself is not exceptionally fast by industry standards, the extent to which stable walking control can be maintained in the unpredictable environment of a real factory is something that can only be verified with real-world operational data, not just a demo.

The Concept of an Architecture Separating the "Cerebrum" and "Cerebellum"

What technically interested me the most was the design philosophy of Highlanders' proprietary AI platform model, "Kepler v1.0." The multimodal platform model with 10 billion parameters employs an architecture called "Two Systems, One Brain".

Specifically, it separates the deliberative "cerebrum" part, which is responsible for planning and decision-making, from the "cerebellum" part, which is responsible for high-speed reflexes such as balance, movement, and force control. Furthermore, a "predictive world model" that integrates visual, tactile, and force data predicts physical interactions in advance, enabling smoother and safer operation.

This is quite similar in core concept to the design philosophy of Agility Robotics, which I introduced in a previous column, where "LLM is limited to the semantic understanding layer, and the physical control layer is separated." Separating high-level judgment and body control, which must be processed in milliseconds, from the same computational pipeline, is a very rational approach in practical robot control. The training data is a combination of millions of experience data points from simulations, remote operation (teleoperation), and actual robots, and is trained on Highlanders' proprietary supercomputing cluster called "HISUI." ## A Uniquely Japanese Approach: "Skill Transfer"

Mitsubishi Motors' CEO has described the labor shortage as an "urgent issue" and expressed hope for the possibility of transferring the skills of experienced workers to robots. Given the context of Japan's workforce declining by approximately 900,000 people annually, this is not simply an extension of automation, but rather a uniquely Japanese challenge: how to pass on the know-how of retiring skilled workers to the next generation of robots.

Highlanders' CEO has also clearly stated their competitive stance against major US and Chinese companies, saying, "The quality of Japanese manufacturing is our strength." With players like China's Unitree gaining ground in the Japanese market (there are even reports that Japan Airlines is considering introducing humanoid robots), whether Japan can present a domestically produced alternative will likely be a crucial test for the entire Japanese manufacturing industry.

Points to View with Skepticism

However, it's important to remain calm. Currently, this is still at the Memorandum of Understanding (MOU) stage, and actual mass production is planned for the latter half of 2027, nearly two years away. Detailed performance data on gait control and actual benchmark results for Kepler v1.0, as verified by independent third parties, have not yet been released.

Furthermore, given Mitsubishi Motors' existing investment in Highlanders, it is difficult for outsiders to determine whether this partnership is based on "objective technical evaluation" or is more of a "strategic investment decision within the group." The production target of 1,000 units per month also depends on the results of trial implementation at their own factories, and at this point, it remains merely an ambitious plan.

Summary: A modest but sound division of labor model

In an industry often dominated by flashy fundraising competitions and social media-worthy dance demonstrations, this partnership is impressive for its grounded division of labor structure: "mass production professionals taking on mass production." The design philosophy of separating the cerebrum and cerebellum in the architecture is also technically sound, though not flashy. We will be following further reports to see how much practical data the trial implementation at the Kyoto plant can accumulate in preparation for mass production to begin in the latter half of 2027.

三菱自動車Highlandersヒューマノイド日本フィジカルAI量産

A German "AI company that doesn't make weapons" has secured Europe's largest defense tech procurement.

Munich-based defense AI startup Helsing raised $1.8 billion in Series E funding on July 13, reaching a valuation of $18 billion, the largest defense tech funding round in European history. This article will examine Helsing's strategy of focusing on software platforms like Centaur and Altra rather than hardware, its proven track record of autonomous fighter jet flight over the Baltic Sea, its experience operating the HX-2 in Ukraine, the backdrop of rapidly increasing European defense spending, and the issue of the military application of its technology.

Germany's "AI Company That Doesn't Build Weapons" Achieves Europe's Largest Defense Tech Funding

On July 13th, Munich-based startup Helsing announced it had raised $1.8 billion in Series E funding, reaching a valuation of $18 billion. This is the largest funding round ever for a European defense tech company, and investor demand "far exceeded the available allocation." What's interesting from an engineer's perspective is what this company sells. Instead of drones or fighter jets themselves, their main product is AI software that makes them smarter.

A Position Focused on "Software, Not Hardware"

Founded in 2021, Helsing is still a five-year-old startup. While its US counterpart, Anduril, excels at consistently developing and manufacturing its own hardware, Helsing's approach is the opposite. Their software platform, Centaur, is designed as an "intelligence layer" that can be integrated into any existing military platform, including drones, fighter jets, and warships.

Specifically, data from various sensors, including radar, cameras, satellites, and multiple drones, is integrated in real time into a single battle map by a separate software called Altra. Its purpose is not to replace human operators, but rather to process massive amounts of battlefield data to support commanders in making faster and more accurate decisions. It utilizes reinforcement learning (a method where AI improves the accuracy of its decisions through trial and error and feedback), and the software can be integrated into existing aircraft within a few months.

Actual Proven Track Record of Unmanned Fighter Jet Flight

A noteworthy technical achievement is the demonstration of autonomous flight of a fighter jet using Centaur software over the Baltic Sea last year. Two test flights were successfully conducted using another aircraft piloted by a human as a simulated enemy. This is significant because it's not just a concept video, but a flight test using an actual aircraft.

In addition to developing its own hardware, the company is also developing the "CA-1 Europa," an autonomous jet aircraft with a length of approximately 11 meters and a maximum takeoff weight of 4 tons, and deploying the "HX-2 Fathom," a small drone with a range of approximately 100 kilometers. The company already has a track record of supplying the HX-2 to Ukraine, and the accumulation of operational data in real-world combat environments is one of the points that investors value.

Why is this scale of funding being raised now?

The background to this is the rapid increase in defense spending across Europe since Russia's invasion of Ukraine. Germany's "ReArm Europe" initiative, the EU's €800 billion defense mobilization target, and the trend of NATO member states raising defense spending to 3% of GDP have created an unprecedented procurement environment for European defense tech companies.

The global military AI market is estimated to be worth approximately $9.8 billion in 2025 and is projected to expand to approximately $41.6 billion by 2035, representing an average annual growth rate of approximately 17%. Ten new and existing investors participated in Helsing's funding round, including JPMorgan Chase, Lightspeed Venture Partners, Iconiq, and the Canadian Pension Fund (CPP Investments). The fact that pension funds and major banks are making clear investment decisions in autonomous weapons systems itself speaks to a shift in institutional investor attitudes towards this sector.

Emphasis on "Defense AI by European Capital, for Europe"

Helsing repeatedly emphasized in this announcement that "even after funding, the company's equity will remain predominantly European." This aligns with the policy trend towards technological sovereignty amid growing concerns in Europe about military dependence on the United States.

The $18 billion valuation makes it the second largest startup in mainland Europe, including the UK, after fintech company Revolut ($75 billion). The German government has already secured framework contracts worth up to 4.3 billion euros for Helsing and its competitor Stark. This sets them apart from many other AI startups, as it goes beyond mere valuations in the private market and is backed by actual government procurement contracts.

Thoughts from an Engineer's Perspective

I honestly hesitated about whether to cover this news in a technical blog. However, the application of AI agents providing real-time decision-making support in the extremely high-pressure environment of a battlefield is technically an extension of civilian robotics and multi-agent systems. Autonomous navigation in environments without GPS, data fusion from multiple sensors, and adaptation through reinforcement learning—these elemental technologies overlap considerably with the context of warehouse robots and autonomous driving that I've discussed in this column before.

At the same time, the ethical issues surrounding the military application of such technologies are a topic of debate even within the engineering community. The scale and speed of Helsing's funding raises concrete evidence that AI-based decision-making support is moving from the "experimental stage" to "combat deployment." I want to continue following technological trends in this field, but as an engineer, I also want to remember to maintain a calm and objective perspective on their potential applications.

Helsing防衛AI資金調達欧州スタートアップ自律システムAI/ML
Advertisement300 × 250