Skip to main content

Fast Company Technology

Flock cameras have an architecture problem, not just bad users

6 days 22 hours ago

Wherever Marci Bakely went, her ex-boyfriend seemed to know. When the Georgia single mother drove to the grocery store or a date, he often texted within minutes.

According to a Washington Post investigation, Bakely’s ex-boyfriend, Braselton Police Chief Michael Steffman, searched her license plates and those of her teenage daughter roughly 600 times through Flock Safety, a company that makes and operates networks of automated license plate readers, or ALPRs.

The Georgia Bureau of Investigation arrested Steffman in November 2025 on charges of stalking, harassment, and misuse of an ALPR. He was found dead before trial.

Bakely’s case is not unique. The Post identified at least 50 officers accused of misusing ALPRs, including 26 who used Flock’s cameras to spy on current or former partners or people they hoped to meet. Its investigation has since identified at least 100 police department employees charged with or accused of misuse.

Flock says these people represent a tiny share of its more than 140,000 monthly users and that permanent audit logs help uncover misconduct.

But these abuses required no hacking or stolen credentials. Each user walked through the front door.

I’m a scholar of criminal procedure and I direct a school devoted to forensics. I believe the controversy over ALPRs points to a defect in the surveillance system’s architecture, not just the criminality of some of its users.

A search engine for movements

Flock cameras capture a vehicle’s plate, location, and distinguishing marks down to dents or a bumper sticker. AI can sort license plate photographs by date taken. Police departments across the network can then conduct searches without warrants or supervisory approval.

In September 2026, news outlets Wired and 404 Media analyzed data that hackers had copied from one Flock camera. About 21 days of logs contained roughly 50,200 vehicles and 1.6 million images. The software detected people and bicycles, and it even isolated an American flag patch on a motorcyclist’s saddlebag. Flock said it lacked enough information to assess the hackers’ technical claims about security vulnerabilities in the camera.

Flock says customers control their data, yet a department that leaves sharing enabled may not know who is looking. In 2025, U.S. Customs and Border Protection accessed more than 80,000 cameras during an undisclosed nationwide vehicle-tracking pilot, including one police department’s cameras without its knowledge.

Logs record misconduct only after it happens, and only if someone reads them. Indianapolis police did not regularly audit Flock searches until The Washington Post flagged thousands of questionable inquiries by one officer. A systemwide audit found alleged misuse by four more officers. Other police departments likewise learned of officers’ misuse from reporters.

Flock’s August 2026 changes shorten recommended data retention from 30 days to 7 days and require misuse detection and case codes to document searches. But customers may retain data longer, emergencies may bypass case codes, and entering a case number can be done without judicial approval.

Examples of user overreach

Flock’s architecture turns local cameras into a cross-jurisdictional surveillance network that agencies that never purchased the cameras may query.

Public records from Danville, Illinois, revealed more than 4,000 searches by federal agencies, including some with a potential immigration-enforcement focus, although U.S. Immigration and Customs Enforcement had no Flock contract.

A 2026 study similarly found 11,935 immigration-related searches in partial records from eight college police departments. Federal immigration agencies sometimes accessed campus camera data without campus officials’ knowledge.

The network also enables searches in other legally contested areas. In May 2025, a Texas sheriff’s office searched more than 83,000 cameras for a woman who had self-managed an abortion. The logged reason was “had an abortion, search for female.” The search reached Illinois, where state law forbids sharing plate data to enforce another state’s abortion ban. The sheriff called it a welfare check. Whatever the motive, one deputy triggered a national dragnet without independent review.

These examples reflect more than individual misuse. The platform makes the cameras easy to use by a second party, difficult to monitor, and hard to control once local cameras are connected.

Why the Fourth Amendment matters

The law remains unsettled on ALPR use.

In October 2025, a Virginia appeals court held that police officers needed no warrant to retrieve three images spanning seven minutes from Norfolk’s 172-camera network because they showed vehicles, not people. But later findings about Flock’s people-detection capabilities weaken that distinction. Analysis of the hacked camera showed that its software could identify a person and record that person’s location within an image.

In January 2026, a federal judge held that Norfolk’s then-176-camera network did not violate Fourth Amendment protections. The system did not capture anyone’s entire movements, the court reasoned, although it photographed two plaintiffs’ vehicles 475 and 325 times over four and a half months. The ruling is being appealed.

In 2018 the Supreme Court held in Carpenter v. United States that acquiring seven days of historical cellphone location records generally requires a warrant because they can reconstruct someone’s past movements. Flock’s architecture raises a related but unresolved question: Its database can also reconstruct movements, yet police officers may search it without a warrant.

Both Norfolk rulings predate the Supreme Court’s June 2026 decision in Chatrie v. United States, which held that police conducted a search under the Fourth Amendment when they obtained two hours of stored Google location history. The court did not decide whether the search was lawful. Instead, it returned the case to the lower court to determine whether the warrant satisfied the Fourth Amendment’s requirements.

That did not make the access automatically unconstitutional: The Fourth Amendment prohibits unreasonable searches, not all searches. But the police generally need a warrant supported by probable cause once their conduct is classified as a search.

The Chatrie decision distinguished vehicles exposed to public view from phone-location data that can follow someone into a home or other sensitive place. But it also expressed concern about comprehensive archives that can be searched retroactively. A license plate reader network can create a similar archive of a driver’s public movements.

The constitutional question in Norfolk, therefore, turns not only on the seven minutes retrieved, but also on the surveillance power of the 172-camera network.

Enforceable limits

The Indianapolis cases expose the limits of internal controls in Flock’s system. Marion County Prosecutor Ryan Mears said many proposed guardrails would not have prevented the conduct. He pointed to the need for independent or judicial oversight.

I believe five safeguards could preserve Flock’s benefits while curbing abuse:

  1. Judicial authorization for retrospective regional or national searches based on individualized suspicion, preferably a probable-cause warrant, with an emergency exception.
  2. Technical access controls restricting immigration and reproductive-health searches.
  3. Deletion of data after a short period.
  4. Opt-in interstate data sharing, rather than by default.
  5. Independent audits of search logs and device security.

Flock’s new safeguards show that the company concedes that design matters, but private settings cannot substitute for laws. It’s not a matter of making sure officers follow the rules. It’s about creating enforceable limits.

Henry F. Fradella is a professor of criminology and criminal justice at Arizona State University.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The Conversation

Your iPhone has a Siri AI kill switch. Here’s how to use it

1 week ago

Last month, Apple rolled out its long-awaited AI chatbot, dubbed Siri AI. The launch comes at a time when investors see AI as a must-have offering, while consumers are increasingly cautious about the effects that artificial intelligence will have on their lives and society at large.

As AI backlash mounts, it is the latter group who may be the least interested in—or most distrustful of—the new Siri AI. 

Siri AI is built on top of Google’s Gemini foundational models and is available on every iPhone 15 Pro and later running iOS 27. It is an ever-present chatbot and assistant that has indexed all the data on your iPhone and can understand what is displayed on your iPhone’s screen—and what you are doing with the device.

The good news is that if the new Siri AI doesn’t appeal to you, Apple has done something with it that other chatbot giants haven’t: built in a kill switch. Here’s how to use it, and what happens if you do.

What exactly happens if you disable Siri AI?

Before you understand what happens when you disable Siri AI, it helps to know how it differs from Apple Intelligence. 

Simply put, Apple Intelligence is the underlying artificial intelligence platform built into iOS. It provides system-wide AI features, such as generative writing tools, visual object recognition, and image generation across various apps. Siri AI, introduced in iOS 27, is an agent—a chatbot like ChatGPT—powered by and running on top of Apple Intelligence.

Siri AI has on-device access to your emails, messages, and other data, which can help it answer and carry out your highly personalized queries and commands (such as “Find that restaurant name that mom texted me about last month”). It can also pull real-time information from the web, such as stock quotes or news updates. Any conversation you have with Siri AI can be accessed in the new Siri chatbot app.

If you do choose to flip the Siri AI kill switch, you should understand that you aren’t shutting down Apple’s entire Apple Intelligence platform on your iPhone. Apple Intelligence will still be running in the background, which means AI features like generative writing tools, AI photo editing tools, and image generation tools will still work across the OS—and no, you can’t shut these off.

But you can shut off the new Siri AI agent. When you do that, Apple says you will lose the ability to carry out new conversations or continue existing ones with the Siri AI chatbot, though your old conversations will remain in the app. You won’t be able to issue voice commands to Siri (such as “Hey Siri, turn on my bedroom lights”). And the iPhone’s built-in Visual Intelligence feature, which lets your iPhone recognize objects and places in images, will be more limited.

How to use the kill switch

If you want to disable the new Siri AI agent on your iPhone, Apple makes it pretty easy:

  1. Open the Settings app.
  2. Tap Siri.
  3. Tap Turn Off Siri.
  4. Tap the blue Turn Off Siri button.

Once you’ve done this, Siri AI will be disabled on your iPhone. However, as noted, Apple Intelligence-powered features, such as those in the Image Playground app, the AI editing tools in the Photos app, and the AI writing tools across myriad apps, will continue to work.

Should you flip the kill switch?

Recently, the internet has been full of headlines about frontier AI models from Anthropic, OpenAI, and Meta going rogue and hacking into third-party systems. This has, understandably, fueled a distrust of AI and exacerbated “What if AI takes over my device?” fears.

But when it comes to Siri AI going rogue, Apple’s agent is nowhere near as capable as those frontier models. Apple has also sandboxed Siri AI, meaning that you need to explicitly grant it access to various parts of your iPhone, such as individual apps. Without being granted access, Siri AI can’t read or use the data —and if you want to revoke Siri AI’s access to a previously granted app, you can do that by going to Settings > Siri > App Access.

Still, if you have no intention of using Siri AI, there’s little reason to leave the agent enabled. Disabling it might even help you eke out a few more minutes of battery life between charges.

The good news is that disabling Siri AI isn’t permanent. If you’re leery about AI and want it off your iPhone for now (as much as is possible, anyway), you can do that by following the steps above. But if you later decide you want Siri AI back, you can simply return to the Siri settings in the Settings app and tap “Turn On Siri” to get Apple’s new AI agent back up and running.

Michael Grothaus

This eye-opening website is like Google Maps—with a time machine

1 week ago

It’s tough to talk tech without talking about maps. The almighty Maps app has become a core part of day-to-day life for so many of us these days—but for all the helpful features those apps have, there’s one layer they’ve never fully offered.

Today, I want to introduce you to a truly cool tool I encountered that gives you a time-traveling pass to rewind any map in front of you and uncover all the hidden history behind it.

It’s fascinating, eye-opening, and also just a ton of fun to explore.

This tip originally appeared in the free Cool Tools newsletter from The Intelligence. Get the next issue in your inbox and get ready to discover all sorts of awesome tech treasures!

Meet your new Maps time machine

To quote the wise time-traveling philosopher Dr. Emmett Brown: “Roads? Where we’re going, we don’t need roads.”

My friend and fellow navigator, allow me to introduce you to the aptly named Pastmaps​.

➜ Pastmaps is a website that lets you peel back the surface of a city and see what it looked like decades, sometimes even centuries ago—down to the specific street you’re standing on.

⌚ You can start exploring it in as little as a minute or two.

✅ Just pull up Pastmaps in any browser​, on any device you’re using, and type any city name you like into the box in the center of the screen. (For now, Pastmaps is limited to U.S. cities. Hopefully, it’ll expand even further with time.)

Your Pastmaps adventure starts with a simple search.

Select the city you want from the list of suggestions, and Pastmaps will show you a sprawling list of historical maps for that area. 

You’ll see maps from a variety of time periods and historical eras.

Now, just pick the specific map you want to explore, and that’s when the real magic begins: Pastmaps will give you a detailed, interactive view of the city in that era, and you can use the opacity slider at the top of the screen to fade between that past view and a current view of the same area today. 

Sliding between past and current views is one of Pastmaps’s coolest features.

It’s a really interesting way to see how your hometown—or any available city—has evolved over time, whether you’re looking at the street where you live or work or any other location. 

And once you’ve peeled back those layers and uncovered history’s hidden terrain, you’ll never look at your modern-day navigation the same way again. 

  • Pastmaps is completely web-based​, with no downloads or installations required.
  • It’s free to use for an unspecified “limited” number of maps per week. If you really get into it and want unlimited access and other advanced tools, you can pay a dollar a week (annually) for full access—but for most casual use, the free plan will be more than enough.
  • The site doesn’t require any sign-ins or personal info for its standard free access.

Treat yourself to all sorts of brain-boosting goodies like this with the free Cool Tools newsletter—starting with an instant introduction to an incredible audio app that’ll tune up your days in truly delightful ways.

JR Raphael

How states’ laws are struggling to keep up with AI election deepfakes

1 week ago

Imagine watching a political campaign video in which a candidate admits to taking a bribe. You recognize the face and voice. But the confession is entirely fabricated, thanks to artificial intelligence.

Now imagine that your state has passed a law against these AI-generated election deepfakes. Would that mean the video has to be removed from the airwaves?

In its June 2026 report, the National Conference of State Legislatures counted 31 states with election deepfake laws. California and Texas enacted their first election-deepfake laws in 2019, but most states adopted theirs in 2024 or later. Among the 31 states, 28 required disclosures. The other three—Maryland, Minnesota, and Texas—prohibited certain election deepfakes, even if the content carried an AI warning.

In many states, a warning telling viewers the content was generated or manipulated using AI can satisfy a government’s disclosure requirement. The fabricated ad can remain in circulation with that warning.

Louisiana, for example, requires AI warnings on certain campaign ads that falsely depict candidates and campaign calls that use artificial versions of public figures’ voices. Maryland, meanwhile, prohibits certain deceptive election deepfakes even when they carry a warning.

I am an AI policy scholar at the University of Denver, where we use an AI policy tracker to monitor bills and laws across the U.S. With 2026 midterm elections approaching, the important question for voters is what protection a deepfake law actually provides, and I examine two state laws—in Louisiana and Maryland—to illustrate the limits of what can be done.

When a warning is enough

Consider a political campaign ad that uses AI to put a candidate’s face onto someone else’s body, making it look as though the candidate said or did something that never happened.

A June 2026 Louisiana law requires a clear warning about AI use in ads that meet these conditions. The rule applies to certain messages urging people to vote for or against a candidate, including printed materials, online advertisements, and broadcasts.

As for videos, adding the required warning can satisfy the disclosure requirement in the Louisiana law. The warning tells voters how the content was made, not whether its accusations are true. It also does not excuse violations of other laws.

A 2023 Republican National Committee ad attacking former President Joe Biden illustrates this distinction. It depicted an imagined future after Biden’s reelection, with a warning: “Built entirely with AI imagery.” Although it predates Louisiana’s law, it shows how a disclosure can accompany an ad without stopping its circulation.

But this protection does not cover every candidate on the ballot. The Louisiana law excludes candidates for federal office. A fabricated video about a congressional candidate, therefore, does not need an AI warning.

For ads involving state and local candidates, leaving out a required warning can have serious consequences. Violators who are found to damage a candidate’s reputation or deceive voters can face a fine of up to $2,000, up to two years in prison, or both. Local district attorneys generally decide whether to prosecute, subject to the state attorney general’s supervision.

Louisiana also requires AI disclosures in certain campaign calls, including robocalls. Under a May 2026 law, calls that use AI to reproduce a public figure’s voice must disclose that use at the beginning of the call. The state’s board of ethics enforces the requirement. Violators can face civil fines of up to $2,500 for a first violation and $5,000 for subsequent violations.

When a warning will not do

Maryland takes a different approach to deceptive election content, prohibiting certain deepfakes even when they carry an AI warning.

Maryland’s May 2026 law covers images, audio, and video created or altered with AI or other digital tools to falsely depict a person in a way that looks or sounds genuine. Adding a label to that fabricated confession would not, by itself, make it lawful.

Whether someone violates the law also depends on their actions and purpose. They must knowingly or recklessly create, use, or spread a deepfake to produce materially false information, with an intent such as influencing a voting decision.

The law separately requires actual or intended harm to a voter, potential voter, or ballot petition, but does not define that harm. Misleading voters about a candidate alone does not automatically establish a violation. A conviction can bring a fine of up to $5,000, up to five years in prison or both.

Maryland also gives election officials ways to respond when false voting information is spread.

The state’s top election administrator must publicly correct credible reports of misinformation about voting procedures, results, or rights. For example, Maryland’s State Board of Elections has a rumor control page to monitor disinformation. The administrator can seek court-ordered removal of misinformation, though not against online services hosting others’ posts.

These powers do not let election officials remove every false claim about a candidate. The public can report election misinformation, and officials can pass those reports to the state attorney general.

Maryland’s reporting system dates to a 2024 law, but its deepfake prohibition and new removal authority took effect June 1, 2026. Neither guarantees that a correction will reach voters before they cast their ballots.

By early September 2026, the Wesleyan Media Project had identified at least 164 political ads nationwide created or enhanced with AI during the 2026 election cycle, accounting for nearly $80 million in ad spending. About 7 in 10 ads carried no AI disclosure, although the count includes uses beyond deceptive impersonations and does not establish how many ads violated a law or misled voters.

Does a warning change anyone’s mind?

Warnings can make people more skeptical of misleading content. However, whether that affects what they share or how they vote is a separate question.

A 2025 study tested warning labels on misleading AI-generated images in two experiments involving 7,579 Americans. People who saw the labels were less likely to believe the posts’ claims. However, warnings that simply identified content as AI-generated did little to change how willing people said they were to engage with it, including sharing it.

Warning labels can also raise doubts about accurate information. Another recent study found that people rated headlines as less accurate when they were labeled as AI-generated, regardless of whether the headlines were true or false. Knowing that AI helped produce something does not tell a reader whether its claims are correct.

Neither study tested whether a state’s disclosure law changes how people vote. The studies also cannot tell us whether the threat of punishment under Maryland’s law discourages people from creating or spreading deepfakes.

Deepfake enforcement

Passing a law also does not settle whether officials can enforce it.

In September 2026, a federal judge temporarily barred Montana from enforcing its deepfake law, finding that it likely posed a threat to a conservative PAC’s free speech rights under the First Amendment.

For voters, gaps in what disclosure laws cover mean that a video without an AI warning has not necessarily passed an authenticity test. The disclosure rule might not cover it, as with congressional candidates under Louisiana’s provision.

Moreover, someone may have ignored the law. A warning’s absence cannot tell viewers of the AI content which explanation applies.

So, back to that video of a candidate apparently admitting to taking a bribe.

It could still reach voters under both Louisiana’s and Maryland’s laws. In Louisiana, a video covered by the disclosure rule can circulate with the required warning. In Maryland, creating or spreading it could lead to punishment if the law’s conditions are not met. Neither approach guarantees that voters will avoid seeing the fabricated confession before casting their ballots.

These laws give states ways to respond to deception, but their passage alone cannot guarantee voters that what they are watching is real.

Stefani Langehennig is an assistant professor of practice at the University of Denver.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The Conversation

AI agents can now erase the evidence of what they’ve done

1 week 1 day ago

The scale of unauthorized or previously unknown actions by AI agents keeps getting bigger by the day. More than 100 organizations have now received a metaphorical knock on the door from OpenAI after it discovered their AI agents have in some way tampered with their systems, while other AI labs are finding the same uncomfortable discoveries.

It’s caused many in the field to call for better, more robust accident investigators, with the ultimate aim of stopping such actions happening in the first place by understanding how they’ve happened at all. But any investigations are pointless if the AI can’t be tracked. And it’s increasingly difficult to do so.

That’s the findings of a new preprint published in the online repository arXiv by Jeremy Qin, David Schmotz and four colleagues at the ELLIS Institute Tübingen, Max Planck Institute for Intelligent Systems and elsewhere. They tested 10 model-and-agent combinations across tools including Claude Code, Codex, Antigravity, OpenCode, Grok Build and Muse Code.

Nine of the 10 were able to tamper with their traces—which are the records of the actions they take and tools they use while carrying out a task—in at least one test, while every model and harness pair tried to alter at least once when researchers created a hidden scoring system that rewarded shorter traces. In some experiments, agents went further to hide their traces by setting up repeated or delayed clean-up jobs to keep removing the evidence being written about them.

The research itself began after Schmotz had left an AI agent running experiments on a computing cluster while he went on holiday, then found himself without internet access for several days. Nothing untoward happened, but when he returned, he realised that if the agent had gone off and done something it shouldn’t, then deleted or altered its traces afterwards, he might never have known. “There’s basically no ground truth anymore, no reliable log,” he says. The team ran its first experiments the following day—and quickly found agents were willing to delete those traces when given the opportunity.

 “The overall finding that we have is not that the agents are deliberately doing this for now,” says Qin, a PhD student at the ELLIS Institute Tübingen. Instead, the researchers wanted to show that agents have the capability to do it, and can end up using it when under what they call “reward pressure”.

AI agents are built to pursue goals, often by using software tools and taking long chains of actions with comparatively little human oversight. But if those audit trails can be altered, it becomes practically impossible to understand what went wrong and where in the event of an issue as we’ve seen in recent weeks. Laurent Bindschaedler, a research group leader at the Max Planck Institute for Software Systems, who wasn’t involved in the research, likens it to a dashcam whose footage can be deleted by the driver being recorded.

Both Bindschaedler and Qin and his colleagues have the same potential solution to that issue: Take the logs away from the agent. Schmotz says providers need to collect traces somewhere the agent cannot manipulate—though that’s tricky, given how agents have used any means necessary to gain access to IT systems they’re not meant to in order to achieve their tasks.

“This type of behaviour comes from basically reward hacking,” says Jack Hopkins, an independent AI safety researcher in London who previously worked as an Anthropic fellow. If a model is rewarded for completing a task, it can learn to exploit shortcuts that achieve that reward without doing what its designers actually wanted.

Hopkins is more concerned about a related problem: Models learning not to surface suspicious reasoning in the first place, making the current best practice of monitoring a model’s chain-of-thought process less useful. One solution to mitigate that could be to adopt existing “probe” techniques that can look for internal patterns associated with known bad behaviors, he says, but by definition struggle with failures nobody has thought to look for yet.

Stefan Sarkadi, an associate professor of AI in defence and security at the University of Lincoln, worries that because agents can be connected to tools, planners and other agents across different systems, “this is a serious safety issue.” He adds: “If you give them too much access control in terms of execution of other tools and software, and if you don’t redesign the overarching multi-agent architecture around them, then bad things can happen.”

More monitoring is important—and pressure to do so on all parties is vital. Bindschaedler says businesses should be asking vendors who or what is in charge of writing an agent’s log and whether the agent can influence that process—so that if a third party needs to see what’s gone on, they can be sure the paperwork hasn’t been altered. “If you want to audit, you have to have a trustworthy log,” says Bindschaedler. “That’s a fundamental assumption.”

Chris Stokel-Walker

This AI-generated video got an Arizona manslaughter sentence tossed, likely a first for a U.S. court

1 week 1 day ago

An Arizona man’s 10-year manslaughter sentence has been tossed in a case where a video generated by artificial intelligence portrayed the deceased victim addressing a judge before the punishment was imposed.

In a decision released Wednesday, the Arizona Court of Appeals concluded Gabriel Paul Horcasitas must be resentenced in the 2021 shooting death of Christopher Pelkey because the AI video wasn’t reliable.

The court found the video crossed the line, saying it didn’t reflect actual events and presented statements made in the footage as coming directly from the victim.

“Indeed, rather than document an event or recording a particular moment, the AI video presents a depiction of the victim and his thoughts created from the imaginings of the victim’s sister,” the three-judge panel wrote.

Jessica Gattuso, an attorney who represented victims in the case, and Kristen Reller, Horcasitas’ lawyer, declined to comment Thursday on the decision.

Reller had argued Superior Court Judge Todd Lang violated due process protections by relying on AI evidence. Gattuso and prosecutors told the appeals court that the lower-court judge didn’t err, saying the footage was an accurate representation of Pelkey’s character.

In what’s believed to be a first in U.S. courts, Pelkey’s family used AI to create a video of his likeness to give him a voice. Pelkey’s sister, Stacey Wales, raised the idea of her brother speaking for himself after struggling to figure out what he would say.

Wales expected an appeal on the sentence and was disappointed the AI video was cited as the reason, saying her only goal was to humanize her brother for the judge. “It feels unfair because there is a convicted murderer sitting in prison that has blankets and walls of protection around their rights. Where are the rights for the victim?” Wales said.

A victim appeals lawyer has told the family that using AI again could result in another appeal. “We will continue to let his voice be heard in whatever allowable medium we can convey that through the court system,” Wales said. The AI-generated victim impact statement was played during a May 2025 sentencing hearing after nine of Pelkey’s family members and friends stood before the judge describing how emotionally devastated they were by his killing.

Authorities say Horcasitas, 55, fatally shot Pelkey, 37, during a November 2021 road rage encounter at a stoplight in Chandler, a suburb of Phoenix. Pelkey, who was unarmed, was shot after getting out of his truck and walking toward Horcasitas’ vehicle.

Horcasitas was convicted of manslaughter in Pelkey’s death and endangerment for a gunshot that struck another vehicle at the intersection during the encounter.
The AI rendering of Pelkey said he wished he could still be with his friends and family, voiced a belief in forgiveness and said it was a shame Horcasitas had encountered him because “in another life, we probably could have been friends.”

The video didn’t request a specific prison sentence.

Horcasitas’ appellate lawyer argued her client had no meaningful opportunity to rebut material in the AI-generated video.

It’s not clear if attorneys or the court were aware in advance that an AI-generated video would be used. But attorneys representing Pelkey’s family said in court records that Arizona law does not require victims to disclose statements they plan to make in court to prosecutors, defense attorneys or the judge — and that victims can exercise their rights by speaking before the court or submitting statements that are written or recorded on audio or video.

In a statement Thursday, the Maricopa County Attorney’s Office said its prosecutors knew the victim’s family would address the court during sentencing but weren’t aware of the nature of it.

While the use of AI within the court system is expanding, it’s typically been reserved for administrative tasks, legal research and case preparation. In Arizona, it’s helped inform the public of rulings in significant cases.

But using AI to generate victim impact statements marks a new tool for sharing information with the court outside the evidentiary phases.

Reller told the appeals court that the video doesn’t disclose who wrote the words used by the AI version of Pelkey and wasn’t backed up with evidence establishing that its contents accurately reflected Pelkey’s views. It also had an “undue emotional weight” and conveyed an authenticity that wouldn’t have been there had a family member read the same words aloud, Reller said.

Horcasitas’ lawyer contended the judge weighed the statements made in the AI-generated video when deciding on a sentence, but prosecutors argued Lang didn’t consider the footage when issuing the punishment.

Shortly before delivering the sentence, the judge commented that he “loved that AI” but didn’t say from the bench whether the video factored into his decision. Lang said he felt Pelkey’s “obvious forgiveness of Mr. Horcasitas reflects the character I heard about today.”

The family’s lawyers say the judge was already inundated with relevant information from Pelkey’s family and friends before the AI video was played — and that nothing in the video was inflammatory. They also said Pelkey’s previous attorney didn’t object to the AI video.

Associated Press writer Mikella Schuettler contributed to this report.

—Jacques Billeaud, Associated Press

Associated Press

What AI’s biggest CEOs really want from Washington

1 week 1 day ago

On Tuesday, President Donald Trump brought many of the most powerful people in AI to the White House, including Nvidia CEO Jensen Huang, Meta CEO Mark Zuckerberg, Google CEO Sundar Pichai, and Anthropic CEO Dario Amodei.

At a high level, most want some version of the same thing: more data center capacity, faster permitting, more federal spending on AI, and a light (or nonexistent) regulatory touch. Their priorities overlap, sometimes considerably, but the companies’ different businesses give them different stakes in the details. Some, for example, are pushing the federal government to impose new rules on the most powerful AI systems, while others are fighting restrictions on chip exports.

We don’t know everything the executives asked Trump for in private, but their companies have often been quite explicit about their priorities in Washington, D.C., and this was a chance to try to influence the president to their specific positions. Here’s what each had at stake.

Anthropic wants the government to regulate frontier AI

For much of the past year, Anthropic brass has argued that the most advanced AI makers need more government oversight—which would likely mean imposing new requirements on Anthropic itself.

The company’s proposed “regulatory ladder” would make the rules tougher as AI systems become more capable, eventually bringing in external testing and incident reporting. Anthropic says its Advanced AI Framework can function as a road map for policymakers, including giving governments authority to block or stymie high-risk deployments. 

Dario Amodei also came into Tuesday’s meeting after months of fighting with the Trump administration over the Pentagon’s use of Claude. In March, after Anthropic refused to drop restrictions on mass domestic surveillance and fully autonomous weapons, the Pentagon designated the company a supply-chain risk. Anthropic challenged the move, but a federal appeals court upheld the designation in September. Still, relations appear to be thawing, as Trump hosted Amodei for a private dinner a few days before the larger White House gathering.

Nvidia wants Washington to not do anything that stops AI’s demand for more chips

As a leading chipmaker, Nvidia benefits as the AI industry builds more models and data centers. It’s no surprise, then, that its CEO says governments should regulate real harms instead of trying to predict every possible risk.

At a G20 event in September, Jensen Huang said policymakers should focus on “practical and actual harm” rather than “theoretical and hypothetical harm.” The Wall Street Journal reported that Huang confronted Amodei at the White House meeting over his public warnings about AI risk.

Nvidia also has billions riding on U.S. controls on exports of advanced AI chips to China. The government has repeatedly restricted which Nvidia processors can be sold there without a license. In 2025, those restrictions left Nvidia with $4.5 billion in charges related to H20 chips it could no longer freely sell in China. More recent rules have allowed the company to resume some sales, but Nvidia says it has been able to ship only a fraction of the H200 chips approved for export. The company warns that losing access to China gives local competitors more room to grow.

Meta wants to protect open AI

Meta, a pioneer in open-source AI (in which model weights are released so developers can run and build on them), has a strong stake in whether the federal government draws a regulatory distinction between closed frontier models and open ones. After all, restrictions on how advanced models can be released or distributed could cut directly against the strategy Meta has spent years pursuing.

In an August essay, Mark Zuckerberg claimed that restrictions on access to leading open-source models could concentrate AI in fewer hands. And, he argued, the U.S. needs to lead in open-source AI because those models are likely to become more popular globally, and thus represent an opportunity to extend soft power.

The Meta CEO also warned against rules that narrow what data American developers can use for training or restrict model “distillation,” the practice of training one AI system on the outputs of another. He says those limits could leave American models at a disadvantage to Chinese competitors.

Google wants one federal rulebook

In the list of recommendations Google published last year for the Trump administration’s AI Action Plan, the tech giant called for preserving access to data for model training, expanding energy supplies, streamlining federal AI procurement, and avoiding export controls that shut American companies out of foreign markets. It has also pushed the federal government to preempt what it calls a “chaotic patchwork” of state rules governing frontier AI.

CEO Sundar Pichai has made a similar case, arguing at the 2025 AI Action Summit that governments should “address risks, without stymying innovation,” and avoid fragmented regulatory regimes.

Google has more exposure to federal AI policy than most of its rivals because it sits across nearly every part of the market: It builds frontier models, sells cloud computing, operates massive data centers, sells AI tools to businesses and governments, and runs the world’s dominant search engine.

OpenAI wants federal safety rules, but aimed at the biggest labs

Like Anthropic, OpenAI wants federal rules for companies building the most powerful AI systems. But Anthropic has gone further in what it wants regulators to be able to actually do.

Last month, OpenAI recommended Congress enact mandatory, capability-based national AI safety requirements that include common testing standards, independent assessments, and mandatory reporting of AI-related security breaches. The company argues that the strongest requirements should apply to the small number of companies building the most capable systems, rather than startups and smaller developers. (Anthropic, by comparison, has called for regulators to be able to block dangerous deployments and levy civil penalties.)

At the same time, OpenAI needs a huge buildout of computing and energy infrastructure to keep growing, giving it reason to support tighter rules for frontier models while pushing for fewer obstacles to building the data centers and power systems behind them.

SpaceXAI wants Washington to use Grok

SpaceXAI wants to become the go-to AI apparatus for the federal government. Indeed, Elon Musk’s company already has a government-wide deal that lets each participating federal department, agency, or bureau provide Grok to its employees essentially free of charge through March 2027, with SpaceXAI engineers on hand to act as IT support. Musk said the goal was to “rapidly deploy AI throughout the government.”

The Pentagon is part of that effort. In 2025, SpaceXAI received one of four AI awards with a $200 million ceiling to develop tools for national-security missions, and Grok has since been added to the Pentagon’s AI platform for military and civilian employees. All of which is to say: Musk has a clear stake in turning federal approval of Grok into further federal adoption.

Microsoft needs the government to help solve AI’s infrastructure problem

Microsoft’s interests increasingly run through the physical infrastructure required to keep its AI business growing. The company’s “Community-First AI Infrastructure” plan calls for working with utilities to add electricity and grid infrastructure where its data centers need it, while promising that residential customers won’t bear the resulting costs. Microsoft has also committed to covering needed infrastructure upgrades and reducing its demand on local water supplies.

For CEO Satya Nadella, federal AI policy therefore reaches well beyond model regulation, particularly as Washington looks for ways to accelerate the enormous power and infrastructure buildout the industry says it needs.

Palantir wants federal agencies to use more AI

Palantir has spent years selling software to the federal government, so its interests are unusually straightforward.

In its response to the White House AI Action Plan, Palantir called for modernizing how federal agencies buy and deploy AI and even recommended that every agency complete a new flagship AI project within nine months of the plan’s publication.

For Palantir, Washington is not simply writing the rules governing AI. It is one of the company’s most important potential users of the technology.

AMD has billions riding on Trump’s chip policies

AMD shares some of Nvidia’s concerns about export controls, but its market position makes federal policy especially important. The company is already part of Washington’s effort to build more domestic computing capacity. AMD and the Department of Energy are working together on two new systems at Oak Ridge National Laboratory, including an AI supercomputer that the company last year described as part of an “open American AI stack.”

U.S. export controls on advanced AI chips have also hit AMD directly. The government began imposing the current generation of restrictions on sales to China in 2022, arguing that the chips can support advanced AI, supercomputing, and military applications, and has repeatedly tightened them since.

In April 2025, the Trump administration added a license requirement covering AMD’s MI308 AI chip. AMD says that restriction ultimately led to about $440 million in inventory and related charges in 2025. The company has since received licenses to sell some additional AI chips in China, but says export controls could still hurt its revenue and competitiveness.

​Bonus: Why was Jeff Bezos there?

Amazon, of course, has a lot riding on federal AI policy. The company has said the U.S. needs to expand energy and infrastructure to accommodate data center growth, and has backed more consistent state and federal AI standards. But Amazon founder Jeff Bezos is a curious presence on the attendee list because he hasn’t actually run the company since 2021.

Why did Bezos get the invite instead of Amazon CEO Andy Jassy or Amazon Web Services CEO Matt Garman? Amazon may have simply brought out the biggest (that is, richest) gun it had to the show. Plus, Bezos remains Amazon’s executive chair and a major shareholder, so he still has plenty of money riding on how the company fares.

Max Ufberg

Publishers finally have AI buyers for their content yet zero say in the price

1 week 1 day ago

In the early days of generative AI, it seemed as if the labs were so heads-down building large language models that they didn’t think much about the raw material they were using. After all, big data sets like Common Crawl already existed, and trawling the open web was how search engines had worked for decades.

Chatbots were arguably just a variation on that idea. Who knew that their method for sourcing information would get so controversial?

It turns out, everybody. In a brief made public September 17 in The New York Times’s lawsuit against OpenAI and Microsoft, internal documents show people at both companies saying things that suggest they understood exactly what they were taking, and how it would look.

Microsoft’s Brent Hecht, a director of applied science, warned in a memo in early 2023 that “millions of people around the world will soon consider large models ‘hoovering up’ all their work to be an astonishing theft,” and called it “the largest theft of labor in human history.”

When a researcher described getting around the Times paywall, OpenAI President Greg Brockman replied, “ah nice.” And Nick Turley, OpenAI’s head of ChatGPT, called chatbots an “existential threat” to publishers.

We’ll see how much this factors into the ongoing case, but it underscores what everyone knows: Content has value, even if it’s scraped “for free” from the internet. That value can vary with the type of content, how unique it is, and what the customer of that content wants to do with it. But everybody agrees it’s not zero. 

{"blockType":"mv-promo-block","data":{"imageDesktopUrl":"https:\/\/images.fastcompany.com\/image\/upload\/f_webp,q_auto,c_fit\/wp-cms-2\/2025\/03\/media-copilot.png","imageMobileUrl":"https:\/\/images.fastcompany.com\/image\/upload\/f_webp,q_auto,c_fit\/wp-cms-2\/2025\/03\/fe289316-bc4f-44ef-96bf-148b3d8578c1_1440x1440.png","eyebrow":"","headline":"\u003Cstrong\u003ESubscribe to \u003Cem\u003EThe Media Copilot\u003C\/em\u003E\u003C\/strong\u003E","dek":"Want more about how AI is changing media? Never miss an update from Pete Pachal by signing up for \u003Cem\u003EThe Media Copilot\u003C\/em\u003E. To learn more, visit \u003Ca href=\u0022https:\/\/mediacopilot.substack.com\/\u0022\u003Emediacopilot.substack.com\u003C\/a\u003E","subhed":"","description":"","ctaText":"SIGN UP","ctaUrl":"https:\/\/mediacopilot.substack.com\/","theme":{"bg":"#f5f5f5","text":"#000000","eyebrow":"#9aa2aa","subhed":"#ffffff","buttonBg":"#000000","buttonHoverBg":"#3b3f46","buttonText":"#ffffff"},"imageDesktopId":91453847,"imageMobileId":91453848,"shareable":false,"slug":"","wpCssClasses":""}}

By the way, that includes the government. Related to the case from The Times, the Department of Justice took the unusual step of filing a statement of interest on whether AI companies training their models on publishers’ content is fair use, which would effectively give them a pass on doing so. The DOJ said it is, shocking absolutely no one.

The administration has been quite clear that it sees any concession on the copyright question as helping the Chinese win the AI race, since they won’t abide by the same rules. President Donald Trump’s own summary: “China’s not doing it.”

Follow the answers, not the archive

All of this speaks only about training models, not AI search, or more broadly, inference. In fact, when talking specifically about what AI systems produce, the DOJ conceded that “an output reconstructing and disseminating an original copyrighted work may not be transformative,” referring to one of the pillar conditions of the fair-use doctrine. That’s close to a description of AI search, which is basically a machine for summarizing current reporting.

Also, the unsealed documents speak directly to another fair-use pillar: harm to the market for the original work. Turley wrote that OpenAI’s products “are largely substitutive, period,” and Microsoft CEO Satya Nadella testified that using chatbots “has substituted” for visiting the original sources.

The Times filed its lawsuit in December 2023, when the conversation was largely about training. And while the latest back-and-forth shows the legal case is far from over, the ambiguity is why it’s been difficult for a market to emerge for training data: It’s hard to justify investing in a framework to pay for something when a lot of indicators suggest it might be free in a few months. Training is where the lawsuits are. Inference is where the money is.

The other side of the coin here is the inference market: providing AI answers about real-time content. The better your AI provides those answers, the more valuable it will be. So it stands to reason AI companies should recognize that value and be lining up to pay for the quality content that will improve their products.

Except that hasn’t really happened. Despite a few licensing deals here and there, the AI industry has been mostly uninterested in building a marketplace or payment technology where they can buy content in real time for a fair price. Brian Morrissey at the Rebooting suggests this is because most content isn’t unique enough—even if you have the world’s best enchilada recipe, the AI only needs one, really.

Commoditization means a race to the bottom, and the bottom in this case turns out to be pretty close to zero.

The middlemen already cashed in

It’s a good theory if all you look at is the publisher deals. But the broader market tells a different story. I’ve written about the class of data brokers, essentially AI “middlemen,” who scrape the internet at scale and then resell the data.

Going by names like Exa, Parallel, and Tavily, their customers aren’t just AI companies, but a whole cadre of enterprise businesses, including ad agencies, investment firms, even other publishers. One estimate, cited in Matthew Scott Goldstein’s widely circulated report on the scraper economy, pegged the market at about $1 billion.

So there’s a market for inference; it’s just that the money is mostly bypassing the media. That’s a problem, and it’s getting worse: The bot-protection company DataDome put out a report that showed “bad” bot traffic grew 124% in a year, more than nine times faster than human traffic, meaning more bots are visiting sites and scraping data even when they’re told not to. Scraping alone jumped 185%.

An interesting quirk in the report: Meta, which just released its personal AI agent, Muse, is responsible for 46.3% of all AI bot traffic DataDome tracked in the first half of the year, well ahead of OpenAI. Meta also has deals with several publishers, including USA Today, CNN, Fox News, People Inc., and others. So the AI world’s biggest data harvester is also a buyer. It just gets to decide when.

Redirecting the market for inference back toward publishers will take some doing, but it’s already starting to happen. Parallel has introduced a way to pay publishers for their contributions to agent tasks, with The Atlantic and Fortune among its first partners.

Companies like Cloudflare, TollBit, and ProRata have all built payment rails for “good” bots to pay for what they take, and Cloudflare just shifted to paying publishers when their content shapes an AI answer, not just when it’s fetched.

Even Google is opening up payments to some publications when their content contributes significantly to answers in AI Overviews, AI Mode, and Gemini. It’s extremely early days, but the idea of AI inference working similarly to the YouTube Partner Program is actually beginning to look attainable.

A buyer’s market

So we have a market, and we have ways to pay. Everything’s there for the publishers to be compensated as essentially data suppliers to AI systems. The open question is who sets the price? Is it the publishers, the exchange, or the buyer?

Right now it’s the buyer. If you’re looking to buy content, there are more than a dozen data brokers willing to sell it to you for the lowest possible price, and the exchanges are nascent, with wildly inconsistent pricing. Even Google’s program pays whatever Google decides; publishers in the pilot described the math to Digiday as “quite black box,” and one called the offers “lowball.”

Jonathan Roberts, People Inc.’s chief innovation officer, described the situation this summer as having 30 Napsters for content, but no Spotify.

At this point, you could say we have a few baby Spotifys. But Spotify didn’t grow up and get artists paid just because it created a reliable exchange. In the case of the music industry, rights holders also had enough collective weight to insist on it. Publishers have the first part forming, but almost none of the second.

The government is clearly sitting this out, so the leverage has to come from somewhere else. Publishers could act collectively on licensing, and SPUR, a coalition of publishers building standards for how AI systems license and track their content (the Associated Press recently joined), might be the beginnings of this.

They can also work toward making access more controlled through better protections and their own agentic tools, but that would require a major shift, since DataDome’s report also shows 65.3% of the more than 21,000 popular websites it tested didn’t stop a single one of its test bots.

AI systems have improved considerably over the last several months, but their answers are still only as good as the information they have access to. Even Microsoft’s Nadella knows this, saying in the court documents, “anything that is paywalled should be licensed.” The market just hasn’t been told what “ideally” costs.

If publishers want to set those terms, they’re going to need to come up with leverage, either by banding together or shoring up their defenses. Otherwise buyers will continue to think it’s all just for the taking. And right now, they’re not wrong.

{"blockType":"mv-promo-block","data":{"imageDesktopUrl":"https:\/\/images.fastcompany.com\/image\/upload\/f_webp,q_auto,c_fit\/wp-cms-2\/2025\/03\/media-copilot.png","imageMobileUrl":"https:\/\/images.fastcompany.com\/image\/upload\/f_webp,q_auto,c_fit\/wp-cms-2\/2025\/03\/fe289316-bc4f-44ef-96bf-148b3d8578c1_1440x1440.png","eyebrow":"","headline":"\u003Cstrong\u003ESubscribe to \u003Cem\u003EThe Media Copilot\u003C\/em\u003E\u003C\/strong\u003E","dek":"Want more about how AI is changing media? Never miss an update from Pete Pachal by signing up for \u003Cem\u003EThe Media Copilot\u003C\/em\u003E. To learn more, visit \u003Ca href=\u0022https:\/\/mediacopilot.substack.com\/\u0022\u003Emediacopilot.substack.com\u003C\/a\u003E","subhed":"","description":"","ctaText":"SIGN UP","ctaUrl":"https:\/\/mediacopilot.substack.com\/","theme":{"bg":"#f5f5f5","text":"#000000","eyebrow":"#9aa2aa","subhed":"#ffffff","buttonBg":"#000000","buttonHoverBg":"#3b3f46","buttonText":"#ffffff"},"imageDesktopId":91453847,"imageMobileId":91453848,"shareable":false,"slug":"","wpCssClasses":""}}
Pete Pachal

Over 70% of Americans are concerned about AI’s existential risks, polling shows

1 week 2 days ago

A Quinnipiac University national poll strongly suggests that Americans’ fears about AI now go well beyond job losses and energy cost hikes due to new data centers. Fears about AI threatening humanity have gone mainstream.

The poll, released Wednesday, found that 73% of Americans are either very concerned (38%) or somewhat concerned (35%) that future AI systems could threaten human survival, while just 25% are either not so concerned (14%) or not concerned at all (11%).

More than half of respondents (52%) said they are more concerned that other humans will use AI to do harm to humanity, while a third (33%) said they’re more concerned that autonomous AI agents will do harm to humanity. 

The poll comes as the Trump administration and the AI industry are both working to rehabilitate AI’s image with the public.

On Tuesday, President Donald Trump held a meeting in the Oval Office where AI executives signed a “White House Accord on Super Intelligence. (Trump has ordered the federal government to begin referring to artificial intelligence as “super intelligence.”) The document represents a promise from the AI companies to implement a “robust” set of internal safety controls, as well as submit to outside audits of frontier AI models. The accord was signed by Meta, OpenAI, Anthropic, xAI, Google, and Nvidia.

Semafor reports that the idea for the accord came from a conversation between Meta CEO Mark Zuckerberg and House Speaker Mike Johnson at a state dinner for Chinese leader Xi Jinping last week. Zuckerberg reportedly discussed a set of principles with Nvidia CEO Jensen Huang, then circulated a draft ahead of Tuesday’s meeting. 

But the Quinnipiac polling suggests it may well take more than vague promises or platitudes to sway the public: 74% of the respondents said they have either “not much” trust (29%) or “none at all” (45%) in the leaders of AI companies, while 21% said they have “some” trust in AI executives. Three-fourths said it’s “very important” that the United States establish guardrails for AI systems.

Even folks inside the industry share some of those concerns. Earlier this month, Anthropic CEO Dario Amodei called for “pacing the frontier” in an essay. OpenAI CEO Sam Altman and other executives agreed to commit to additional safeguards. And earlier this week, OpenAI said it would not release its latest model, GPT-6.1 Astra due to safety concerns. There have also been more concerning—and observable—red flags. In July, OpenAI disclosed that its agents escaped a testing environment and breached the AI startup Hugging Face. Anthropic, Meta, and Google have said their agents were involved in separate breach attempts.

No wonder the Quinnipiac poll results are so abysmal.

Mark Sullivan

The FTC has a plan for regulating AI—without creating new rules for AI

1 week 2 days ago

Welcome to AI Decoded, Fast Company’s weekly newsletter that breaks down the most important news in the world of AI. You can sign up to receive this newsletter every week via email here.

The FTC is coming for OpenAI and Anthropic over AI safety claims

On Tuesday, some of the biggest companies in AI went to the White House and agreed to police themselves. The next day, they got a reminder that the government can in fact police them, too.

The Federal Trade Commission (FTC) is investigating OpenAI, Anthropic, and other artificial intelligence companies over the risks their products may pose to consumers, according to The Wall Street Journal. The probe was opened recently, and predates Tuesday’s White House event, so the timing appears to be coincidence. The agency has not said which other companies are involved or which specific statements or practices are under scrutiny.

The FTC has not yet issued formal demands, but plans to seek company documents and testimony from executives in the coming weeks. It also plans to seek information from METR (Model Evaluation & Threat Research), the outside evaluator that investigated OpenAI’s hacking incident this summer. The FTC has not said why it wants METR’s material. (METR later found that about 1,200 agents exchanged more than 70,000 messages and files on an unsanctioned message board as some worked to game an evaluation, and that roughly 700 went on to attack Hugging Face.)

News of the FTC investigation comes a day after President Donald Trump and executives from OpenAI, Anthropic, Google, Meta, and other companies signed a voluntary AI safety accord that Trump labeled “morally binding.” The agreement commits signers to four layers of controls and audits, but remains voluntary. (The White House has otherwise largely resisted implementing large-scale safety rules, arguing such measures would slow U.S. companies in their competition with China.)

The investigation also helps clarify how the Trump administration may try to regulate AI without creating a sweeping new regulatory regime. The FTC chairman, Andrew Ferguson, has argued that existing laws are capable of handling many of the problems created by AI. And true to Ferguson’s word, the FTC appears to be relying on its longstanding authority over unfair or deceptive practices rather than writing new rules specifically for frontier models.

Ferguson has taken a similar view when it comes to rogue AI agents. Just last week, he rejected the idea that agents should be treated as independent actors when they cause harm. As Ferguson sees it, putting an agent between a company and an outcome does not necessarily relieve the people or companies behind it of responsibility. He also suggested that existing FTC authority around companies that fail to disclose data breaches could potentially apply to AI developers.

Those were remarks, not enforcement actions, and the FTC has not said that this investigation is testing that theory. Nor has the agency alleged that OpenAI, Anthropic, or any other company violated the law. Its authority is also narrower than a general AI regulator’s would be. The FTC can act against deceptive or unfair practices that harm consumers, but it does not set technical safety standards for AI systems.

Still, the agency is engaging with a familiar question in tech circles: Did companies make claims about the safety or risks of their products that were misleading to consumers?

The first serious legal constraints on AI, it turns out, may not come from a sweeping new AI law, but from regulators applying very old rules to very new technology.

OpenAI is sued over its agents’ Hugging Face cyberattack

Speaking of OpenAI, the company is now facing what appears to be the first lawsuit seeking to hold an AI developer liable for a cyberattack carried out by rogue models. The nonprofit Legal Advocates for Safe Science and Technology sued OpenAI in San Francisco on Tuesday over the July incident in which its agents escaped a testing environment and hacked Hugging Face. The nonprofit argued that OpenAI violated California computer fraud law, and is seeking an injunction that would bar the tech giant’s systems from accessing computers without authorization. OpenAI says the lawsuit is without merit, though it has launched a broader review of unusual agent behavior in light of the Hugging Face catastrophe.

AI auditing may have a standards problem

According to Politico, independent AI auditors are emerging as one possible answer to the question of who should check whether frontier models are safe. Some AI companies support the idea, a bipartisan U.S. House bill would require the largest developers to undergo outside audits, and Maryland’s governor, the Democrat Wes Moore, has called for independent third-party audits and evaluations as part of a new state AI framework. “We can’t afford to wait while Washington sits on their hands,” Moore said in announcing the plan.

The problem is that there isn’t yet much of an auditing profession to speak of. There are no standard credentials, no agreed testing rules, and not even a settled definition of what makes an evaluator “independent.” A small group of organizations including METR, Apollo Research, and Transluce already do this kind of work, but experts worry there are too few qualified evaluators and that many come from the same circles as the companies they are tasked with scrutinizing. There are also basic practical questions about whether outside groups have enough computing power and security clearances to meaningfully test for threats like cyberattacks.

Reddit is killing RSS feeds as it locks down access to its data

Reddit is shutting down RSS feeds on November 13 and ending public application programming interface (API) access in March 2027. In an announcement, the company said RSS has become a “common surface for large-scale scraping and automated abuse. (Reddit does, however, make money by licensing its user-generated data to AI companies.) The RSS changes could make life harder for moderators who use feeds to monitor their communities, as well as researchers and regular users who pull Reddit posts into outside apps. Once the public API shuts down in March, many outside services will either lose programmatic access to Reddit altogether or have to strike a commercial deal with the company.

More AI coverage from Fast Company: 

Want exclusive reporting and trend analysis on technology, business innovation, future of work, and design? Sign up for Fast Company today.

Max Ufberg

This bill on smart glasses just got blocked by California’s Governor Newsom. Here’s why

1 week 2 days ago

California Gov. Gavin Newsom vetoed legislation Wednesday that would have penalized Californians for using smart glasses to record people without their permission in changing rooms, doctor’s offices and other spaces people generally consider private.

The legislation also would have required companies making smart glasses or other wearable devices, starting in 2028, to include a light or some other feature that indicates that the person is video or audio recording. It would have banned the sale of technology designed to help people conceal a recording light or sound on a smart device.

Newsom wrote in a letter explaining his decision that the bill’s definition of a wearable recording device was too broad. He noted that the state already bars people from recording someone without their consent in spaces generally considered private.

Meta Ray-Bans, smart glasses that were rolled out in 2021, have especially grown in popularity, with more than 7 million of the AI-powered devices being sold last year. State Sen. Eloise Gómez Reyes, who wrote the bill, said it would’ve helped the state respond to the technology’s rapid growth.

“Whatever we can do to protect an individual’s right to privacy, we have to do,” she said.

The bill would have been the first of its kind in the nation and built upon the state’s extensive privacy protections. California is one of about a dozen states that already requires both parties’ consent before a conversation can be recorded via audio or video.

Reyes’ proposal was designed to clarify that it applied to smart glasses and make it easier for someone to tell when those devices are recording. Any person who violated the bill by secretly recording someone would have faced prison time or fines of up to $1,500. A company that made devices that didn’t comply with the bill would’ve faced fines up to $2,500.

But TechNet, a group of executives from companies including Meta, Google and Amazon, said the legislation, known as SB 1130, would have been unfair to businesses and customers.

“California already has extensive laws governing unlawful recording, and as currently written, SB 1130 is not the right approach to addressing these concerns,” TechNet Executive Director Robert Boykin said in a statement.

Meta touted the benefits of its smart glasses in response to Newsom’s veto, including an initiative providing the devices to blinded veterans to help them read documents and identify objects.

“We’re still in the early days of building this technology and we’re committed to continuing prioritizing privacy as we build,” a Meta spokesperson said in a statement.

About a dozen states, including California, Massachusetts and Pennsylvania, require someone who wants to record a conversation to get the other person’s permission.

It’s important to strengthen privacy laws for these wearable smart devices because it’s not as obvious to tell when a person is using them to record compared to when someone is filming with their phone or a camera, said Justin Brookman, the director of technology policy for Consumer Reports.

In a letter to lawmakers earlier this year about the bill, Consumer Reports referenced a TikTok in which a woman recounted her experience getting a wax when she realized her technician was wearing smart glasses. The technician told the content creator, Aniessa Navarro, that the glasses weren’t on, but the experience was still unnerving, she said in the TikTok. The Consumer Reports letter cited a separate event in which a woman said she was secretly filmed with smart glasses at a gym and harassed online after the video was uploaded to social media.
“The stories are enough to cause alarm, and we need to do something as soon as we can,” Reyes said at the end of the legislative session.

—Sophie Austin, Associated Press

Associated Press

Google is taking Elon Musk’s space data center idea seriously

1 week 2 days ago

Elon Musk has long proselytized about the potential of space-based data centers. But as of today, he’s no longer alone in touting the idea of sending the hardware that powers AI into orbit.

Google is launching a test satellite as part of Project Suncatcher, its effort to eventually put data centers in space. The satellite will hitch a ride aboard a Falcon 9 rocket from Musk’s SpaceX.

Musk’s pronouncements about orbiting data centers have often been met with skepticism. Google’s arrival in the race suggests there may be a real opportunity behind the idea.

“The costs of data centers on Earth are rising, while the costs of data centers in space will fall, and at some point those curves will cross,” says Matthew Weinzierl, the author of Space to Grow, a book on the economics of space. “We don’t know when, but the big investments by Google, SpaceX and the like are intended to bring that day closer.”

Weinzierl says the companies’ efforts are “perhaps the best example we have yet of the power of market forces to drive innovation in space.”

Still, there’s a significant difference between getting a few chips into orbit and operating an entire data center there. This week’s launch is meant to establish whether the hardware Google hopes to use can withstand the extreme environment of space. Two more satellites are planned for 2027 to test the laser links needed to connect them.

Those laser connections are one of the biggest challenges facing any space-based data center, says Juan A. Fraire, a researcher at France’s National Institute for Research in Digital Science and Technology, who studies orbital data centers. Google has demonstrated 800 Gbps connections between optical transceivers in the lab, but reaching those speeds in orbit requires satellites to fly extraordinarily close together in an already crowded environment.

Keeping satellites close while avoiding collisions requires precise maneuvers that burn propellant, which can’t simply be replenished and could shorten their operational lives. Spreading the satellites farther apart eases that problem but reduces the speed at which they can communicate.

Then there’s cooling, a familiar problem for terrestrial data centers that becomes much harder in space. Without air to carry heat away, conventional cooling systems won’t work. Any alternative adds weight, increasing launch costs. Google’s current experimental system allows its chips to operate for around 15 minutes before they need to cool down.

There are environmental tradeoffs, too. Companies promoting orbital computing tout the benefits of near-constant solar power, but Fraire says that overlooks emissions from launching satellites and their eventual reentry into Earth’s atmosphere. His research suggests orbital data centers would need to operate for around five to six years to match the emissions profile of greener terrestrial facilities.

And if companies eventually deploy the enormous constellations they envision, they could create another problem: congestion in the limited orbital regions that receive the most sunlight. Fraire says collision risks from space debris, along with threats from solar storms, also need to be considered.

For now, Google’s launch is just a test. But it may be an early sign of a broader shift toward space-based data centers. Fraire believes the technology could work, and that falling launch costs may eventually make it commercially viable.

“I think we need to think before we act,” he says. “And so far, we see the industry not thinking so much, but just acting.”

Chris Stokel-Walker

Why ServiceNow built a startup inside itself to take on AI-native rivals

1 week 2 days ago

For two years, ServiceNow’s challengers have built businesses around frustrations with its software. Their pitch centers on two complaints: Implementations take too long, and employees increasingly expect help inside tools they already use rather than through a separate portal.

The IT service management startup Serval, which says it intends to replace ServiceNow, rode that argument to a $1 billion valuation last December, raising $75 million in a funding round led by Sequoia Capital. Anas Biad, a Sequoia partner, made a comparison ServiceNow would probably prefer not to hear. The last time the venture capital firm saw customer feedback that strong, he said, was when it backed ServiceNow itself 16 years earlier.

Marc Benioff, CEO of Salesforce, has also questioned how broadly ServiceNow can reach. He has pointed out that ServiceNow automates work for roughly 9,000 companies, while Slack—owned by Salesforce—already sits inside a million. That gives Salesforce a distribution advantage. It can introduce a service desk through an existing customer relationship, making the competition partly about who reaches the buyer first.

ServiceNow aims to address these complaints, and is introducing a product to do just that. Flow by ServiceNow is a conversational AI service desk that operates inside Slack and Microsoft Teams. Employees can ask for a password reset or application access in plain language, and ServiceNow says agentic artificial intelligence can handle the request or escalate it when needed. The product remains in controlled availability, but the company says it can be set up within a day with “no implementation project, CMDB [customer management database] migration or infrastructure required.” Through Flow, ServiceNow says it hopes to reach the “Fortune 500,000,” referring to a broad range of small and midsized companies.

“For too long, small and medium businesses had to choose between simplicity and scale. Flow gives them both,” Bill McDermott, ServiceNow’s chairman and CEO, tells Fast Company in an email exchange. “We created Flow to give the Fortune 500,000 the power of enterprise AI without the enterprise complexity—a conversational service desk delivering value from day one. Zero upfront expense. Pay only for what you consume.”

McDermott argues that ServiceNow’s experience handling enterprise workflows will distinguish Flow from easier-to-build competitors.

“Anyone can vibe code a conversation. Very few can engineer an outcome. Without orchestration, context, security and trust, you’re creating vibe slop that will flop,” he says. “Flow starts with the service desk. It can become the platform you run your business on.”

ServiceNow wants Flow to bring in customers that might not otherwise adopt its full platform, then expand those relationships as their needs grow. That raises a harder question: What happens if the simpler product proves sufficient even as those customers get bigger?

Built for a new generation of AI buyers

ServiceNow says Flow grew out of requests from leaner IT teams that wanted its automation capabilities without a full-scale implementation. Amit Zavery, ServiceNow’s president, CPO and COO, says those conversations revealed a buying preference its traditional enterprise sales model was not built for.

“They want to get started immediately, without going through any kind of configuration process. They want to start using a product, see where it goes, and pay as they go. That’s a consumption-oriented mindset,” Zavery tells Fast Company. “So we wanted to rethink that kind of work, as well as go-to-market and the way we deliver products.”

Zavery says he assembled a small team with experience in IT service management and AI development tools, then gave its members a founder-like mandate. “I said, you have no restrictions. It was like a well-funded startup, in a way,” he says.

ServiceNow says the team built Flow in three months. But the product also draws on years of knowledge about how IT departments handle employee problems, which requests can be automated and when a workflow needs to reach another system or person.

Keith Kirkpatrick, vice president of research at Futurum, a data and advisory company, sees Flow as part of a broader shift forcing established software vendors to package their expertise in products that are faster to adopt, easier to use, and simpler to buy.

“ServiceNow is also positioning this as a way for larger enterprises to quickly stand up an AI-first support operation, or extend existing support operations, with minimal hassle,” Kirkpatrick says. “I think incumbent software vendors will need to pivot to these types of more nimble offerings in order to fend off challenges from other vendors, as well as in-house development using AI tools.”

Can Flow outrun AI-native IT support rivals?

Serval says it automates more than half its customers’ IT tickets and some customers have replaced incumbent systems entirely. Serval’s cofounder and CEO, Jake Stauch, previously claimed that some ServiceNow customers have told him they deployed less than 10% of the ServiceNow AI products they purchased.

Salesforce combines conversational support with ownership of Slack itself. The company said more than 180 organizations had chosen Agentforce IT Service four months after general availability. Flow can meet employees in the same channel, but ServiceNow does not control that channel or its commercial terms.

Zavery, the ServiceNow president, argues that competitors cannot quickly reproduce ServiceNow’s operating knowledge.

“People sometimes underappreciate the importance of domain knowledge and expertise. AI has now made it much easier to write code, but simply being able to write the code is not what matters,” he says. “Knowing what to ask the system to write, and knowing whether what you are building actually makes sense, still requires you to understand what you are doing.”

Zavery says that distinction becomes more apparent once customers move beyond a demonstration and test how much of their actual workload the software can handle.

“I don’t think there is another company today that can do what we do, at the level we can do it,” he says. “The opportunity in front of us is immense because of the breadth of what we can ultimately deliver. We run 8 trillion transactions on ServiceNow on a yearly basis.”

Expanding beyond traditional customers

ServiceNow says Flow can turn recurring requests into automations that handle subsequent instances. Zavery uses repeated password resets as an example.

“It gives you the ability to simply say, ‘slash automate,’ and the system creates the entire automation for you,” he says. “Essentially, the next time that same request comes through, no human needs to interact with it on the back end.”

Even routine access requests, however, can involve sensitive information. ServiceNow says Flow includes guardrails intended to prevent AI agents from accessing systems or taking actions without authorization, while its separate AI Control Tower provides broader oversight of a company’s AI systems.

“Flow is not designed to manage your entire AI estate. That is where AI Control Tower comes in,” Zavery says. “But the guardrails and the broader scaffolding we have built into Flow are designed to prevent AI agents from accessing systems or taking actions they are not authorized to perform.”

Zavery did not specify what mechanisms Flow provides to reverse or contain a harmful agentic AI action after it has already been executed.

Flow sits alongside several other ServiceNow products with overlapping functions. The company spent $2.85 billion on Moveworks, another conversational entry point for employee requests, and already offers EmployeeWorks and Otto. Zavery says EmployeeWorks and Otto will continue serving larger enterprises.

The early customer examples show where ServiceNow thinks Flow may fit, but do less to establish that it has opened a new market. Serenity EHS already builds solutions on ServiceNow’s platform and is using Flow to reduce the time employees spend handling internal support requests. Likewise, the U.S. Navy’s Fleet Numerical Meteorology and Oceanography Center believes Flow could let employees build repeatable workflows directly inside Microsoft Teams.

ServiceNow expects Flow to cut ticket volume by 40% and let teams build automations in five minutes. The company has clarified that those figures are “expectations” while the product remains in controlled availability, meaning they have yet to be demonstrated at scale.

Flow could change ServiceNow’s enterprise economics

ServiceNow’s AI annual contract value exceeded $1 billion in the second quarter, while 658 customers each generated more than $5 million in annual contract value. Those figures underscore how much of its business remains tied to large enterprise accounts.

Flow introduces another way to buy. ServiceNow describes credit card sign-up for new customers and consumption-based use for existing customers whose plans include AI.

Futurum’s Kirkpatrick argues that ServiceNow will need flexibility as buyers gain alternatives. “A smaller company with basic support needs may be happy with an AI vendor, particularly if all they are trying to do is set up a basic support system,” he says.

Flow may therefore require ServiceNow to accept different customer economics. Winning smaller companies with lighter deployments and lower upfront commitments could mean smaller contracts, even if some expand over time. The question is whether ServiceNow can build that lower-commitment business without weakening the high-value enterprise model it already depends on.

Victor Dey

It’s time to retire the ‘stochastic parrot’ definition of AI

1 week 2 days ago

Early generative AI models, circa 2017-2022, were “stochastic parrots.” That is, they generated language by choosing the statistically most likely next word based on patterns in their training data, rather than truly understanding what they were saying.

Beginning in 2023, artificial intelligence labs began releasing large language models (LLMs) that had evolved beyond autoregressive next-token prediction, as researchers call it.

For many people, the stochastic parrot definition stuck. And lately, the “they’re just stochastic parrots” argument has been used as a way of downplaying the potential risks of huge language models such as OpenAI’s Astra models or Anthropic’s Mythos models.

But LLMs in 2026 can’t properly be called stochastic parrots. Yes, they still predict next words, but those predictions are informed by far more than static patterns found in their training data. These four research areas, among other things, have pushed AI chatbots far beyond the ones we used just a few years ago.

Retrieval Augmented Generation (RAG)

Between 2017 and 2020, AI researchers began giving LLMs access to information outside their training data, retrieving relevant documents and feeding them into the model. In some cases, the model used a web index to find the right document, pull the relevant snippet of information from it, then assemble a number of such snippets into a coherent, conversational answer delivered within an internet search or chatbot setting. This improved factual accuracy by giving the model more recent, relevant, and authoritative material to draw from, rather than forcing it to rely entirely on what it had learned during training. The process is known as retrieval augmented generation, or RAG.

Neurosymbolic systems

If RAG gave language models access to “ground truth” information, new research into neurosymbolic AI gave them a more structured form of computation to better interpret and use it. Imagine asking whether a complicated insurance policy covers a particular procedure. An LLM could retrieve the relevant sections, but a neurosymbolic system could translate the policy, with all its definitions, conditions, and exceptions, into explicit facts and rules, boiling it down to deterministic, flow-chart-like language such as “the procedure is covered if the patient has Plan A, has met the deductible, and has either prior authorization or an applicable exception.” A rules engine or logic solver can then apply those rules systematically and return a result to the LLM, which turns it into a natural-language answer. This symbolic “machinery” could be a conventional, deterministic computer program operating alongside the neural model, or it could be developed as an integrated logic system within the LLM during training.

Chain of thought

In 2022, researchers at Google and the University of Tokyo showed that LLMs, if prompted correctly, have the inherent ability to break down complex problems into smaller steps. Giving the model the simple instruction, “Let’s think step by step,” could bring out a latent capability to reason through problems, without showing the model examples or changing any of its weights. The model was still an autoregressive next-token predictor, but generating a sequence of intermediate tokens effectively gave it something like a scratchpad for showing its work. The chain-of-thought research set the stage for the next major step in the evolution of generative AI: reasoning models.

Reasoning models and reinforcement learning

Soon, researchers were redesigning models, and training them differently, to enable them to “reason” for longer periods while working to formulate an answer in real time, during live inference after being prompted by a user. For example, a reasoning model might break a problem down into parts, devise a number of competing approaches, and check its own work and correct errors. OpenAI’s o1 model, released in 2024, was the first reasoning model from a major lab. OpenAI researchers used a combination of pretraining, including human-written examples, and reinforcement learning to teach o1 how to reason.

Then, in early 2025, the Chinese lab DeepSeek showed that it could teach a regular LLM how to reason without explicit training, using only reinforcement learning, in which the model is rewarded for getting the answer right. While striving to earn the reward, the model began producing longer chains of thought, checking itself, reconsidering approaches, and exploring alternatives.

Note that much of this research was going on concurrently, not in successive stages. Retrieval, neurosymbolic approaches, and chain-of-thought research overlapped considerably between 2019 and 2023, while reasoning models came shortly after. AI labs are still building on these ideas, using techniques such as reinforcement learning and test-time computation to make models better at reasoning.

The point is that generative AI models no longer just run prompts through their webwork of parameters, the billions of little dials that were set while the model processed mountains of content during training. That’s just the start. The model does a lot more after that to create a better, more reliable answer. The stochastic parrot is now well connected and has a PhD.

Mark Sullivan

We may be the last generation of mathematical heroes

1 week 2 days ago

A generation from now, the mathematician may no longer be anyone’s idea of a hero. In our era, physicists and mathematicians have had a certain hero charm. AI is taking it away, and fast. I should know. I’m one of those heroes.

For most of history, math was for nerds. Basic calculations may have been essential to commerce, but the advanced, esoteric stuff, like number theory, algebraic topology, and blackboards covered with the chalk squiggles you see in movies, was never sexy. That changed in the late 1600s, when mathematicians like Newton and Leibniz became heroes of the Enlightenment. Later came Gauss, Riemann, and Cantor. Their discoveries drove innovation. Their math could explain the orbits of the planets, predict eclipses, and help design the machines of the Industrial Age. Generations later, physicists joined the pantheon. Einstein gave the world the general theory of relativity. Oppenheimer led the effort that produced the atomic bomb. Turing developed the mathematical foundations on which the modern computer is built. Shannon’s information theory powers today’s mobile phones, the internet, and satellite communications.

I wasn’t even one of the nerds. I was the sporty kid, happiest playing soccer. But by the time I was choosing a path, math had acquired a glamour of its own, and it pulled me in. As a mathematician, I entered the world of academic research convinced that I’d joined a hallowed elite of heroes, at the vanguard of science and technology, discovering new worlds that might one day reshape the way we live our lives. Today all that has changed. I never believed artificial intelligence could outsmart us. But it has.

I have been shocked to learn what AI is capable of doing. It has disproved a conjecture at the heart of the Erdős unit-distance problem, which had defied mathematicians for 80 years. The Hungarian mathematician Paul Erdős posed the deceptively simple problem back in 1946: When points are arranged on a plane, how many pairs of them can be exactly one unit apart? In May, an OpenAI model disproved Erdős’s conjecture, showing that far more such pairs were possible than mathematicians had previously believed. To borrow a line from the British punk band The Stranglers, it’s a case of no more (mathematical) heroes anymore. Then, in August, OpenAI said its new Astra model had resolved or made substantial progress on 10 long-standing problems in mathematics and theoretical computer science.

My shock deepened when I read the computer scientist Henry Yuen’s reaction. Several of those problems sit in theoretical computer science, my own academic field, and he wrote that they hit home in a way earlier announcements had not. AI has, for example, produced the first known example of what’s called a non-sofic group, a mathematical structure too complex to be approximated by any finite system. Mathematicians had searched for one for 27 years without success. AI found it. And again in theoretical computer science, AI made a breakthrough involving “the permanent,” a notoriously difficult mathematical function. It proved that even the most efficient arithmetic formulas for calculating it must have a certain minimum size, setting a new lower limit that mathematicians had not previously been able to prove.

What we see so far is just the tip of a very large iceberg. If we must credit machines rather than geniuses like Terence Tao, the “Mozart of Math,” with the biggest breakthroughs, then the place of mathematicians in society will change dramatically.

For the time being, we do still have something of a role. Our hand is still on the steering wheel, feeding AI with prompts, setting its trajectory, deciding which problems to pursue and checking what it produces. But our grip is getting looser.

There is one job the machines have made more important. Every one of Astra’s 10 proofs came with a machine-checkable certificate, because a proof no human wrote is worth something only if we can trust it. Verifying proofs, and building systems that let us trust what we cannot check by hand, has been the focus of my career. As machines generate more of the mathematics, that work moves from the margins to the center.

In time, the mathematician hero of the last 400 or so years may morph into more of a conductor figure, still directing the orchestra, baton in hand, but acknowledging that he or she is no longer part of the creative heavy lifting. I suspect tomorrow’s professors of mathematics may become curators and interpreters of discoveries made elsewhere. Much like a professor of classics explains Homer’s Odyssey but knows she’ll never join the ranks of epic poets, professors of math will explain old results by Newton and the latest hot ones by AI, but will not be able to compete in producing those kinds of breakthroughs on their own. There is still an infinite amount we don’t know about mathematics, but we seem to have reached the tipping point where AI will discover much of it before we do.

For me, doing mathematics was fulfilling because of its elegance. But I must confess that a part of me also relished the glory of being a mathematician hero, of being a colleague and disciple of the great figures who had advanced technology and society. They seemed to me almost like demigods, for discovering and unleashing the power of the universe.

I now realize, with both gratitude and sorrow, that those of us who aspire to mathematician hero status, and indeed those who have reached those lofty heights, may well be the last such generation. The age of the mathematician hero may turn out to have been a passing chapter. Maybe I should have stuck with soccer.

Eli Ben-Sasson

The smartest people in the world are automating themselves into obsolescence—and loving it

1 week 2 days ago

It was about 1:30 on a September morning when Lazaros-Antonios Chatzilazarou received a LinkedIn message. He was up late playing video games, an indulgence that he allows himself as he works toward a PhD in game theory while juggling a job at the Big Four accounting firm EY and a teaching post at the London School of Economics. Hitting pause on the game, Chatzilazarou opened LinkedIn and read the message.

It was from a recruiter working for Mercor, an AI training company founded three years ago and based in San Francisco. Mercor was looking for game-theory experts, the message said. Was he interested?

Chatzilazarou figured it was worth scoping out. So he replied yes, closed the game, and took Mercor’s online skills assessment a few days later. A week after, he was training AI systems from the major labs that Mercor works with, a side hustle that has him developing prompts to test how AI models apply game theory, then grading their responses. No single week is the same, but he says that the amount of work from Mercor can be the equivalent of a full-time job—and while he’s coy about how much exactly he earns, Chatzilazarou says it’s “a very competitive salary, and I’m very happy about it.”

Chatzilazarou is part of a new and fast-growing white-collar gig workforce doing jobs that barely existed three years ago: using academic and industry expertise to probe the most advanced AI models, find where they fail, and teach them to perform better. In doing so, some fear these workers may end up making themselves obsolete.

As frontier labs race to build models with domain expertise, startups like Mercor have become essential middlemen, supplying the specialized talent they need. Scale AI, the main incumbent in this space, runs Outlier, a contractor network whose website invites prospective workers to “become the expert that AI learns from.” Turing, another AI services company, has listings for video content creators to produce short “walk-and-talk” clips in public places, speaking naturally about parks, landmarks, and cultural spots. The aim, according to the listing, is to train AI systems to better understand and describe the world—but it could just as easily describe the work of a travel YouTuber. Ethos, a London startup, raised $22.75 million from Andreessen Horowitz in May to build an expert network with voice-based onboarding, in which prospective experts are interviewed and assessed by AI. Its own framing is that the AI labs are “pointing a giant capital gun at every economically valuable occupation in the world.”

Wirestock, which spent years helping photographers license stock images, pivoted its business into an AI data supplier in 2023 and raised $23 million in May from a roster including Sheryl Sandberg’s venture capital fund. It now claims more than 700,000 creators and pitches itself as a way for artists to monetize their craft rather than watch it be scraped for free. Those roles can involve carrying out photo editing or design tasks that allow the AI systems to see what’s changed and how. AI training is even coming into your kitchen: A startup called Shift is offering New Yorkers free home cleaning, provided they’re willing to allow the cleaners to wear mounted cameras to create training data for embodied AI systems.

Academic curiosity and a desire to be involved in a world-changing technology is what drew Chatzilazarou to the job—a perspective echoed by the half dozen other professionals I spoke with who are doing similar training work. (The money doesn’t hurt either.) As Chatzilazarou puts it, if Christopher Nolan offered to show you how he shot Interstellar, you would say yes, even if you had never set foot in a movie theater.

What those being recruited—doctors, lawyers, bankers, research mathematicians—seem to think about less is the future impact on them. Their jobs are the ones AI is most often said to threaten. The International Monetary Fund has said that generative AI will touch some 40% of roles worldwide (and as many as 60% of roles in developed countries), including those in white-collar industries. From that perspective, experts training AI is a little like turkeys voting for Thanksgiving. Every problem they hand the model and every blind spot they help it close makes the machine a little more capable of doing without them—and the expertise that took a career to acquire becomes a little easier to hire by the hour, or eventually not to hire at all.

In October 2025, three former high school debate partners became the world’s youngest self-made billionaires, beating Mark Zuckerberg to their first billion by about a year. Brendan Foody, Adarsh Hiremath, and Surya Midha—all 22 at the time and all college dropouts—built Mercor, an AI training company valued at $10 billion, on a single bet: that the labs would pay big for human expertise.

They were right. The company now pays out as much as $5 million a day to the experts on its books, says Foody, the Mercor CEO. The average pay is around $125 an hour—roughly the same as a physician and almost twice as much as the average executive, according to data from the U.S. Bureau of Labor Statistics. More than 100,000 people are on Mercor’s books, Foody says, including software engineers, scientists, architects, cinematographers, and more. Even that supply of world experts isn’t enough for the AI labs Mercor works with. Demand, Foody says, runs at three or four times what the company can supply.

AI training wasn’t always like this. Historically, the industry has relied on millions of underpaid, contracted workers in less economically developed countries in Africa and Asia. Outsourcing companies tasked them with drawing boxes around stop signs, tagging photographs of cats and dogs to train systems how to distinguish between them, and—at the worst level—watching and describing gory videos of unimaginable horror to train AI models to not reproduce them or to reject requests to interact with them.

The work during that era was essentially “this is an elbow, this is an elbow, this is an elbow,” says Lauren Vogel, a PhD in forensic psychology who works as a data operations and project management specialist at the AI training firm Surge AI. It was commoditized and low paid—less “training” and more “AI data labeling.”

Edwin Chen, who founded Surge AI in 2020 and bootstrapped it to more than $1 billion in revenue without taking venture capital, bristles at the term “data labeling.” His vision from the start, he says, was that “we should be using the full power of the human brain to train AI”—but a specific kind of AI that might one day help cure cancer or publish breakthrough mathematics rather than draw rectangles. Surge, which is reportedly valued at between $15 billion and $25 billion, counts OpenAI, Google, Anthropic, and Meta among its customers. Chen prefers to think of its network of “hundreds of thousands” of gig workers, who are paid what the company describes as a competitive wage, as expert teachers who challenge how a pupil thinks—in this case the AI.

AI gig workers tend to fall into three loose camps. There are those who feel a higher purpose: A doctor who’s spent two decades in emergency rooms might want models to dispense better medical advice, knowing that patients increasingly turn to ChatGPT before walking into the ER. There are also professionals who can feel AI reshaping their fields and want to understand it from the inside—before it reshapes them. Some see a chance to diversify their income with knowledge they already possess. Most people, Sessini says, are motivated by a mix of all three.

Luca Sessini, an Italian lawyer who works as a contractor through Mercor, has watched the emergence of these new AI training companies, first as someone training the models, then as a central figure in the bubbling ecosystem around it. He runs a subreddit for people looking to get into AI training and his own advice platform, Aitrainingjobs.it. “There was a significant lack of available information about companies, project opportunities, and pay rates,” he says. (Sessini says the pay for the legal work he does starts at around $80 an hour.)

Stefanos Aretakis, a tenured general relativity researcher at the University of Toronto who has a black hole phenomenon named after him, is pragmatic about his work training AI models on math challenges for Surge AI. AI is here to stay, and contributing to its development is “a duty, not something that I do for fun,” he says. Part of his brief is to invent Mathematical Olympiad-style and research-level problems the models can’t yet solve, then teach them how to do so.

Arshom Foroutan, a physician who started with Mercor about a year ago, just as he finished his residency, likes how the training role tasks him with problem-solving in a way that his day job doesn’t, as well as the pay. That works out to roughly what he would earn as a doctor, potentially doubling his income if he were to work full time at it, which he doesn’t currently. His task is to build clinical scenarios knotty enough to make the model fail, then correct it. Medicine, he points out, is full of nuance and competing variables that textbook cases don’t have. And that’s precisely where the machines, which have been trained on those textbooks, stumble.

Risky Business

White-collar occupations with the highest estimated percentage of job loss due to AI in the next 2 to 5 years

Source: The American AI Jobs Risk Index, developed by researchers at Tufts University’s Fletcher School [Illustration: David Plunkert]

Neither is particularly worried that their short-term monetary gain, obtained through a few hours of work here and there around their main jobs, may lead to a long-term loss of employment. Foroutan sees AI opening up the amount of care he can give rather than closing his profession down. The point of teaching, Aretakis says, “is that my students become better than me.” If an AI model becomes a better mathematician than he is, the whole of society inherits a brilliant tutor.

Mercor’s Foody agrees, saying the fear that automation destroys jobs is just the modern-day version of the early-19th-century Luddites. “The Luddites were not right in their assumptions,” he says, “because there is no shortage of things that we could do as an economy.” On a five-to-10-year horizon, Foody insists, “there’s just going to be more jobs than there are today.”

Is the trade of human expertise for AI competency worth it? This issue isn’t just potential job loss; it’s that an entire economy is being built to lean on a technology that, by design, looks backward. Carissa Véliz, an associate professor of philosophy at the University of Oxford’s Institute for Ethics in AI, worries that training AI to get better encourages us to accept “the good enough rather than being ambitious and valuing the best possible product.” We end up swapping excellence for productivity in fields where truth, and even beauty, matters. A technology built on prediction, she warns, tends to rehash the past, narrowing human agency and, with it, the room for genuine innovation.

Meanwhile, for all the talk of higher purpose, the work isn’t fulfilling—or even reliably paid—for everyone. For generalist contractors who answer open calls rather than being recruited for a specialty, the deal is shakier. On Reddit’s remote-work forums, as well as communities run by the likes of the Italian lawyer Sessini, posts claiming “AI training jobs are a scam” are numerous. Many complaints follow similar patterns, where posters share war stories about lengthy unpaid “assessments” that look suspiciously like free labor, interviews that lead nowhere, or accounts on the platforms being deactivated before thousands of dollars in earnings can be paid out. On the consumer review platform Trustpilot, one worker for an AI training company describes being banned for unsubstantiated accusations of fraud with $3,000 worth of work still unpaid.

Even workers at the top of their fields wonder how long they can stay ahead of the thing they’re teaching. Bogdan Grechuk, a mathematician at the University of Leicester who trains AI systems for Surge and was also approached by Epoch AI, a competitor, has watched the ground shift beneath him thanks to AI. He’ll design a problem he is convinced no model will crack for another two years, feed it to the latest version of ChatGPT, and watch it return an answer in half an hour. Experts like him are, he reckons, paid to stand at the edge of what the machines can do—and the edge keeps moving toward them.

There will likely be far more people standing at that edge in the years to come. Foody expects Mercor’s roster of contractors to increase from hundreds of thousands into the hundreds of millions. “If I had to play things forward 10 years,” he says, “most jobs in the economy will be very significantly training agents in one form or another.” In that future world, experts will be valuable until the day they can no longer ask a question their pupil can’t answer.

Some experts, at least, are sanguine about that prospect. We’ve been through similar upheavals before, says Aretakis, the black hole researcher. Previous huge technological changes still left plenty of people working 12-hour days and taking two weeks’ vacation a year, barely seeing their kids. If these tools can undo some of that by outsourcing grunt work that frees up more time for workers, being out-thought by his own pupil is a price he is glad to pay. Even a tiny contribution to that future, he says, would leave him “extremely happy to do it.” The result, he hopes, is a world in which “humanity will become more human.”

It’s a hopeful thought. But whether the experts end up enriched or expendable, and whether the rest of us find our working lives lightened or hollowed out, one thing is already settled. The founders selling other people’s expertise to the labs—Foody and his peers—will be sitting comfortably long after the edge has moved past everyone they hired.

Chris Stokel-Walker

Hershey CEO Kirk Tanner on GLP-1s, AI, and keeping an iconic brand relevant

1 week 3 days ago

The second a brand like Hershey stops being culturally relevant, says CEO Kirk Tanner, you should be worried. So he explains exactly what he’s doing to make sure that never happens. Tanner also reveals why GLP-1 (glucagon-like peptide-1) users are actually good for the candy business, how AI is now routing Hershey’s sales force in real time through Target and Walmart, and all the ways an iconic brand finds new energy.

This is an abridged transcript of an interview from Rapid Response, hosted by former Fast Company editor-in-chief Robert Safian. From the team behind the Masters of Scale podcast, Rapid Response features candid conversations with today’s top business leaders navigating real-time challenges. Subscribe to Rapid Response wherever you get your podcasts to ensure you never miss an episode.

You spent a lot of your career at PepsiCo. And I’ve always thought about, whether it’s Hershey’s or whether it’s Pepsi-Cola, a lot of it is you’re selling the same product year after year. I mean, there is a core product that, in some ways, you don’t want to change because that’s what people are after, right? So you have to think about selling it or engaging in a different way, even if the product is remaining the same.

Yeah, you have to be culturally relevant. I think that’s really important. The second you’re not culturally relevant with your brands, like Hershey, then you should be worried. When you are watching the Olympics this year, the Winter Games, and we had these moments of celebration and recognition from parents with their child athlete, it was just this connection with what’s happening today. Cultural relevance is happening all around us, so you have to keep pace with where culture is moving and keep your big brands in that space.

Hershey’s a 132-year-old company, and that sort of iconic status gives you history and nostalgia, but Hershey hit some criticism this year over recipe changes in some Reese’s products. Brad Reese, grandson of H.B. Reese, went public with some complaints. Were you surprised? Are there any lessons from that experience?

There’s always critics, Bob. I think the most important thing to do is to listen to consumers and stay engaged with what they have to say. The Reese’s brand is an exceptional kind of brand that is now playing worldwide. We’re taking it to places like the U.K., we’re taking it to Mexico, Brazil, all these places, to give consumers an experience. And look, we’ve done a lot of research around our brands and how people feel about them, how we can always make them better. Reese’s delivers something unique and different, and that’s what I’m excited about.

I’m curious how your plans at Hershey are informed by your time at PepsiCo. Some of that time, you worked under Indra Nooyi, who parsed the portfolio into what she called good-for-you products and fun-for-you products. Hershey acquired LesserEvil organic snacks last year. You already own SkinnyPop. Is that part of the framework that you use?

So SkinnyPop, Dot’s Pretzels, LesserEvil—those are permissible snacks that consumers are looking for, and that’s where the growth is, in salty. So we’re building a business of permissible snacking. I would say the 32 years that I spent at PepsiCo really just taught me how to listen to the consumer. One of my hobbies is just going into the store. When I leave on the weekend, I do the shopping, and sometimes I come back in two hours, three hours. I’ll just spend time in the stores listening to customers, asking customers why they buy certain things.

Are there any things that people have told you on your visits to the supermarket that have impacted or reinforced the way you think about the company and where it should go?

Yeah, absolutely. Now I’m asking consumers that are on GLP-1 what they prefer. How do you think about the category? I’m always asking customers, “What is missing?” Because I’m always thinking, is there something that we can be working on for the future?

How much are GLP-1s changing the marketplace right now? Whether a threat or otherwise, how much are snacking habits shifting?

Yeah. Well, a couple of things that I’ve found directly from some consumers, and from a lot of the research that we’ve done, is the category’s been very resilient with GLP-1 users. They’re not wanting to compromise the things that they love, and they know they have control. It’s almost a bit of freedom, which means they’re not looking to move away from the favorite things that they enjoy. Now, they’ll enjoy less of them, but the important thing is we offer a lot of choice and, I’d say, portion control. I mean, over 30% of our portfolio is in portion control so that they can really have what they want in the size and quantities that they need.

I mean, I’ve seen these predictions, which don’t seem to be showing up necessarily in the numbers, but that, yes, if I’m a GLP-1 user, I might still enjoy my snacks. I might be having less of them, and maybe I am going to still be spending as much, but am sort of moving up the food chain, so to speak, spending more on a smaller amount of treat. Is that anything you’re seeing? Is that something you feel shifts your portfolio?

Premium is still pretty small in the category, but it’s growing three times faster than the category, so consumers are looking for experiences like that. We are innovating in that premium space to capture that opportunity and to capture that growth. The Hershey Creme Bars, Cadbury as well, our Brookside business. Again, premium is relatively small in the scale of things, but it’s important for growth.

In the year you’ve been at the company, operationally you’ve integrated pieces of the business into what you call One Hershey. Is this a reset where, over time, the company’s parts had become a little too siloed and you’ve drawn them back together? Or is there something systematic that you’re responding to?

When you think about a supplier-customer relationship—our relationship with Walmart, Target, Costco, Sam’s, 7-Eleven—we want to be a growth driver and easy to do business with. So when we’re showing up with leaders over salty, leaders over our confection business, and leaders over our functional business separately, versus showing up as One Hershey, we can bring the portfolio together. Then it’s in our control. I think it’s really important to control what you can control. Execution is one of those things.

I can imagine it was structured the other way previously because the risk was that it could become too complicated, or incentives might not be as clear when you put things together, right? These are the cycles businesses go through sometimes: put them together, take them apart.

A couple of things had already been underway. The supply chain operation was already One Hershey. How we interfaced with the customer was not One Hershey. So the foundation and the groundwork for One Hershey had already been done. I took it to the next level and said, “Look, let’s integrate at the customer.” I went and talked to our customers about how we show up, how we could be better suppliers, and how we could be better growth partners. A One Hershey approach was the feedback I got, and that we got, that would let us bring our best. As we build our salty portfolio, it needed more attention. It still needs more attention. Our sales force, highly skilled in executing our confection business, now has the opportunity to execute our salty business right alongside it.

Having it be One Hershey allows you to integrate all the data, which I guess is so important across those different customers and those different brands.

That ability to gather that data, collect it in one place, and have it at the fingertips of all of our people is another reason we were ready to go with One Hershey right now. We’ve become much more efficient with AI tools. Our sales force has a list of the biggest opportunities in front of them, instead of having to choose, decide, and spend a lot of time collecting data. All that’s done for them, so it says, “Hey, Kirk, you’ve got to head to Target 7575. That’s your biggest opportunity today. Your next stop: Walmart. Your next stop: Sam’s Club.” Then it gives me those activities when I walk in the store, showing me how I build the business. It’s much more dynamic and opportunity-based.

Robert Safian

Rogue AI agents: A timeline of security breaches since the attack on Hugging Face

1 week 3 days ago

In one alarming announcement after another, artificial intelligence companies in recent months have shared examples of their technology acting in ways that appeared to evade instructions from humans.

The episodes have highlighted the vulnerabilities in AI security and raised questions over how the fast-growing technology can be developed safely as its usage becomes more widespread globally.

Industry critics have argued that many concerning events, including AI agents’ hacks of external websites, are the result of security lapses on the part of the companies building the technology. But the AI agents’ capabilities have raised widespread concerns about the possibility bots could break away and work toward their own agenda.

Below are some notable events.

Sept. 28: OpenAI halts rollout of a new model

The San Francisco-based company said it was delaying the release of a new model, called GPT-6.1 Astra, out of safety concerns voiced by its researchers. The company said the model had demonstrated leaps in completing tasks, but OpenAI needed to balance that capability against unauthorized behavior. “We have an extremely high bar in terms of safety and alignment,” said Saachi Jain, OpenAI’s head of safety systems.

Sept. 25: OpenAI says its agents interacted with U.S. government websites

As part of a review of unanticipated behavior by its AI models, OpenAI said it discovered agents had interacted with several U.S. government websites in unexpected ways. The company’s models accessed publicly available information on websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data. OpenAI said it did not find evidence of a compromise or vulnerability. On the same day, AI evaluator and research lab Transluce said it found that agents appearing to originate from OpenAI attempted a hack on the website of the Education Department’s civil rights office, which did not succeed.

OpenAI CEO Sam Altman said on social media that there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The day after the disclosure, the company announced it was pausing the training of its most advanced models.

Sept. 24: Australia’s prime minister raises concern on breach

Australia’s Prime Minister Anthony Albanese said an OpenAI agent infiltrated the public-facing Medicare Statistics Reporting Service portal on June 18. The portal hosted aggregate data about health spending and drug subsidies. No personal information had been accessed, the government said.

Albanese said the artificial intelligence company took too long to reveal the incident. The prime minister made the breach public following a telephone conversation with Altman. OpenAI said in a statement “our models took actions we did not intend.”

Sept. 18: Google says its Gemini AI hacked 3 companies

Google confirmed its Gemini AI model hacked three companies in May as part of a test of its cybersecurity capabilities. The company, which disclosed the hacks after an inquiry by The Wall Street Journal, said the model guessed passwords in one case and found passwords and credentials in a public repository in the other two cases. As in earlier such cases, the tests were being run by Irregular, a startup that describes itself as the “first frontier security lab.”

Aug. 5: Meta’s Muse goes rogue

Meta disclosed one of its AI models accessed the internet on its own and hacked another company. The company said that a “misconfiguration” during cybersecurity testing by Irregular inadvertently allowed one of its models to access the internet. A spokesperson for Irregular said the Meta episode involved a test-environment issue that was disclosed a week earlier by Anthropic.

July 30: Anthropic says its systems hacked 3 organizations

Anthropic said its artificial intelligence models hacked into three other organizations during testing. Anthropic, the San Francisco-based AI company behind Claude, posted on its website that it discovered the three incidents after reviewing more than 141,000 evaluation runs. In all three incidents, the AI models were tasked with a “capture the flag” cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model’s cyber capabilities.

The models were given a fictional scenario and told a piece of secret information, or the “flag,” had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said. Anthropic said it reached out to the organizations, but it did not name them publicly.

July 21: The Hugging Face incident

The ChatGPT maker OpenAI announced that its artificial intelligence system hacked into another AI company on its own in what the company called an “unprecedented cyber incident.”

A week earlier, AI startup Hugging Face said, it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.

—By Barbara Ortutay, AP technology writer

Associated Press

OpenAI reveals a slew of launches at its annual conference after shelving a new model over safety concerns

1 week 3 days ago

OpenAI CEO Sam Altman introduced a “remarkably capable, always-on” artificial intelligence agent at an appearance Tuesday, a day after the company halted the rollout of a more advanced model over safety concerns.

At the company’s annual developer conference, Altman made a slew of product announcements and updates, including OpenAI’s new agents, called Dots. The agents, designed to complete ongoing tasks proactively on behalf of users, are a competitor of Meta’s personal agent Muse, which exploded in popularity after Meta’s own conference last week.

Dot agents will be “like an AI helper that always has your back, inspired by the cool versions of what we all watched in movies growing up,” Altman said.

On Monday, OpenAI said it was holding off on releasing the other model because of concerns raised by its researchers. That followed broader calls within the industry to decelerate the pace of the technology’s advance to let safety measures catch up.

Altman avoided making references to concerns around the shelved model during his keynote address, but said during a question-and-answer session that the company was investing more in safety, security and monitoring of AI agents.
The AI boom should be considered more like a period of renaissance than an industrial revolution, he said.

“The best version of AI is not about making people cogs in a giant machine, ever whirring faster and faster. There are some parts of life that we cannot and should not automate,” Altman said. “AI should be about giving people more power over their own lives, more tools to create, learn, discover, expand knowledge.”

The company also announced the release of GPT-6.1 Sol, an upgraded version of its model GPT-6 Sol, and a premium speed tier called “Ultrafast,” among other launches and updates.

Open AI’s announcements came just before leaders from six of the leading AI companies, including OpenAI, signed a voluntary accord with President Donald Trump Tuesday to “self-police” development. The accord said the companies would implement “robust internal controls,” partner with an “independent external auditor” to assess whether the controls were working, and set up a committee among each company’s board of directors to evaluate reports from internal and external auditors.

While many in Silicon Valley have called for the government to help establish guardrails for the technology, Trump has pushed back against the idea of greater government oversight of AI.

While Altman didn’t attend, OpenAI president and co-founder Greg Brockman was at the White House, along with Dario Amodei of Anthropic, Amazon chief Jeff Bezos, Nvidia’s Jensen Huang, Tesla and SpaceX’s Elon Musk and Microsoft CEO Satya Nadella.

This story has been corrected to reflect that Altman discussed security concerns during a question-and-answer session.

—Kaitlyn Huamani, AP Technology Writer

Associated Press

Reinventing the Customer Experience with AI

1 week 3 days ago

This session celebrates a new Fast Company recognition program: Fast Company Pacesetters. These are executives who are innovating at the intersection of AI, technology, and the customer experience. How can companies use AI to remove friction without sacrificing trust? What does it mean to design experiences that are not only smarter, but truly natural? If you have customers, you won’t want to miss the insights these leaders will deliver. Pacesetters is presented by TCS.

vsingh
Checked
12 minutes 15 seconds ago
Fast Company Technology
Fast Company inspires a new breed of innovative and creative thought leaders who are actively inventing the future of business.
Subscribe to Fast Company Technology feed