AI deployment meets encryption, perception tests and regional approvals
Encrypted inference tooling, stubborn perception errors, Apple’s China-specific approval and a European robotaxi pledge show deployment being shaped as much by constraints as by model capability.
Artificial Intelligence··Morning
Inference that never sees the plaintext
Google published HEIR, an open-source compiler toolchain that converts trained models to run on encrypted inputs. The server processes ciphertexts and returns encrypted results without ever seeing the underlying data. Staff software engineer Jeremy Kun says work begun in 2023 is now open for public use and that HEIR joins the company’s Private Computing Toolkit. Four demonstration applications were compiled and run on a single-threaded CPU: a deep learning recommendation model with Belfort Labs, LG and NYU; credit card fraud detection with Niobium and hardshell.ai; network intrusion detection using the Kitsune system; and privacy-preserving hotword detection, again with Belfort Labs. Source code for every example sits in Google’s GitHub repository. The project has produced four peer-reviewed publications out of academic collaborations with Georgia Tech, Carnegie Mellon and UC Santa Barbara, among others. The release treats privacy-preserving inference as deployable engineering rather than only a research promise, while still showing the work on constrained single-threaded demos.[1]
Perception still fails the sixty-percent line
Moonshot AI, the company behind the Kimi assistant, published PerceptionBench, a test of 3,000 tasks spread across ten skill areas. The best of the 16 frontier models, GPT-5.6 Sol, scored 59.7 per cent, and no model cleared 60 per cent. Kimi K3 scored 58.5 per cent and Claude Fable 5 57.2 per cent. The ten areas cover counting, visual relations, attributes, depth and 3D, localization, comparison, fine-grained recognition, context integration, OCR and hallucination, and hallucination was the weakest area across every model. Because the company publishing the test also owns the second-placed model, the ranking counts as the vendor’s own measurement rather than an independent one. The tasks and scoring code sit in the MoonshotAI/PerceptionBench repository. For teams shipping vision-using products, the ceiling below 60 per cent marks a capability constraint that sits beside any encryption or compliance layer they add.[2]
Regional gates for models and robotaxis
Apple trained its own large language model for the Chinese market with Alibaba’s support and became the first foreign company the Chinese government has allowed to offer a proprietary generative AI model in the country. Reuters reported the shift, and Apple Intelligence features are expected to reach China in the coming months. Apple had planned to deliver generative AI in China through a partner’s model, with Alibaba’s Qwen attached as an extension option in the way ChatGPT is elsewhere. Training its own model turns that dependency into a dual-track arrangement: Apple holds the approved model local regulation requires while keeping the Qwen link. MacRumors reports that in an environment where approvals have restricted other US technology companies, the clearance opens ground Apple’s rivals do not have. Separately, Uber and Guangzhou-based Pony.ai said they plan to bring 2,000 driverless taxis to four European cities, with city names and the timetable to be announced in stages. Pony.ai supplies the autonomous driving technology, Uber runs the hailing platform, and local providers take on fleet work such as maintenance, cleaning and charging, with vehicle ownership varying by market. The partnership builds on the commercial service the two launched in Zagreb earlier in 2026 with local partner Verne. Set beside HEIR’s encrypted-inference demos and PerceptionBench’s sub-60 per cent ceiling, the week’s deployment stories show privacy tooling, residual perception error, market-by-market approval and staged robotaxi rollouts shaping what reaches users as much as raw model strength.[3], [4], [1], [2]