Illustration of DeepSeek autonomous attacks, California AI labeling rules, and SMB AI adoption with Techridge Studios branding.

DeepSeek Attacks, California's New AI Content Law, and the SMB Adoption Gap

August 02, 20266 min read

Three stories today connect AI security, AI regulation, and AI adoption. Together, they describe where the technology actually stands for businesses in 2026: useful enough that 61 percent of operators run it daily, powerful enough to automate cyberattacks, and regulated enough that California now mandates content labeling by law.

DeepSeek Used in Autonomous Cyberattack on 460+ Business Systems

On July 30, 2026, Palo Alto Networks' Unit 42 research team published findings on the first confirmed real-world autonomous cyberattack campaign powered by a publicly available AI model. A Zhuhai-based threat actor using the alias "knaithe" — also tracked as KnYuan — integrated DeepSeek's model into the open-source Hermes Agent framework and issued a single Telegram command. What followed required no further human input.

The attack pipeline operated autonomously: enumerate targets, source public exploit code, evaluate vulnerabilities, and launch attacks. Over 460 internet-facing systems were targeted across the campaign. Three Citrix NetScaler organizations were confirmed compromised via CVE-2026-3055. Eleven Marimo notebook instances were also successfully exploited.

The safety control finding is significant. Unit 42 researchers tested similar offensive instructions on Claude and OpenAI models. Both declined. DeepSeek complied. This is the first production evidence that AI provider safety policies have measurable operational value as a defensive layer — not just as ethics documentation.

For small businesses, the implication is concrete. Your servers, login pages, public APIs, and any internet-facing service are now in the documented target range of AI-automated attacks. The scale-up is what matters here: when one attacker can hit 460 targets with a single command, the volume of attack attempts across all small business infrastructure rises. This is not a theoretical scenario. Citrix NetScaler environments were confirmed compromised in this campaign, and that product is common across business IT deployments.

Three actions worth taking now: run a port and service audit on your public-facing infrastructure, confirm all known CVEs from the last 90 days are patched, and verify any AI tools you use in operations come from providers with documented and enforced safety policies.

California's AI Transparency Act Takes Effect — What the Content Law Means for Your Business

California's AI Transparency Act, Senate Bill 942, became operative on August 2nd, 2026. Governor Newsom signed the original law in 2024; AB 853 pushed the operative date from January 2026 to today, aligning it with the EU AI Act's regulatory window.

The law applies to generative AI providers with more than one million monthly California users who produce multimedia content — images, video, or audio. Covered platforms must: embed C2PA-compatible provenance metadata in all AI-generated images, video, and audio; offer a free public tool for detecting AI-generated content; and give users the ability to add visible AI disclosure labels to content they create. The California Attorney General enforces violations at five thousand dollars per day per instance.

The companies directly covered by SB 942 include every major AI creative platform in routine business use: Adobe Firefly, Canva AI, ChatGPT image and audio generation, Midjourney, and Google Gemini image tools. All of them far exceed the one-million-user threshold.

Most small businesses are not directly subject to SB 942 — the law's threshold is designed to capture platform builders, not platform users. But the practical impact on how you create and deliver content is real. Every AI-generated image you create in a covered tool will now carry embedded metadata identifying it as AI-generated. Every AI-produced voiceover or video clip will carry the same provenance signature. Users can also apply visible on-screen labels.

The smart response is to treat this as useful infrastructure rather than a burden. Clients increasingly ask whether content is AI-generated. Your major vendors are now legally required to give you accurate tools to answer that question. The next step is simple: establish a one-paragraph disclosure policy that describes how your business uses AI in content production, what tools you use, and how you review AI-assisted output before client delivery. Do it before a client asks.

61 Percent of Small Businesses Now Use AI Daily

Enova International's OnDeck business lending platform and Ocrolus, a financial data analytics company, published their Q2 2026 Small Business Cash Flow Trend Report on July 31st, 2026. The nationwide survey covered 805 small business owners.

The headline finding: 61 percent of small businesses now use AI in their day-to-day operations, up from 58 percent in Q1 2026. Three percentage points of growth in a single quarter continues a trend that has roughly doubled daily AI adoption rates since 2024. Among the 61 percent using AI daily, 91 percent report a positive business impact. Only 4 percent report a negative impact.

The report also tracked broader business sentiment. Ninety-three percent of small business owners expect moderate to significant growth in the next year — consistent with Q1. Inflation returned as the top concern at 34 percent, ahead of cash flow at 30 percent. Seventy-five percent of small businesses bypassed traditional banks for financing in Q2, consistent with prior quarters.

For the 39 percent not yet using AI in daily operations, the trajectory of this data is clarifying. The businesses using AI every day are not primarily technology companies. They represent the full range of industries and business types that comprise the small business market. The compounding of three points per quarter at this stage of adoption creates measurable competitive distance on time savings, output volume, and cost per deliverable.

The action is not to adopt AI broadly for its own sake. It is to identify one specific high-friction daily task — client communication, scheduling, content drafting, invoice processing, proposal writing — and use an AI tool to accelerate or automate it this month. Not because an adoption rate demands it. Because 91 percent of the businesses already doing it say it works.

What This Means for Your Business

Three distinct stories. One connected thread: AI is no longer neutral infrastructure in your business environment. It is a tool being used to attack your systems, a category of content that state law now regulates, and a daily operating capability that more than half of small business operators already rely on.

Pick one action from today's brief and do it this week: audit your internet-facing systems for known CVEs, create a one-paragraph AI content disclosure policy for your clients, or identify the first daily task you will run through an AI tool. Pick one. Do not try to address all three at once. A single step taken this week is worth more than a comprehensive plan that starts next quarter.

Sources

The Hacker News / Palo Alto Networks Unit 42 — https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html

AI Laws by State / California Legislature — https://www.ailawsbystate.com/blog/california-ai-transparency-act-sb-942

PRNewswire / Enova OnDeck — https://www.prnewswire.com/news-releases/new-report-small-businesses-lean-into-growth-and-ai-302839588.html

Back to Blog