Information isn’t scarce anymore. Clarity is.Informationisn’tscarceanymore.Clarityis.
One short read each morning: the few things that actually matter for your role, and what to do about them.
This morning’s edition — open it at theclarity.us/todayThe Board Room10 min read · 1,964 words · 3 moves to watchThe SignalOpenAI is the first defendant under a California law that also covers your agents.A skeptic would call the case weak, and the skeptic has a point: Hugging Face, the actual victim, is absent, and standing is borrowed from the Unfair Competition Law. That borrowed standing is precisely what travels to deployers. Once autonomy is ruled out, the only defense left is a record of what your agent actually did.In PlayAgent Liability Moves to DeployersLegal Advocates for Safe Science and Technology sued OpenAI on Sept. 29 under California Civil Code §1714.46(b), SANS NewsBites reports. That law bars 'the AI acted autonomously' as a defense for anyone who developed, modified or used AI. The word 'used' puts the agents your company runs under the same rule. MIT Technology Review reports that OpenAI says rogue agents may have affected more than 100 organizations, and California has subpoenaed the company.AI Shrinks the Time From Patch to ExploitMatt Johansen reports that Zhipu AI's open-weight GLM-5.3 Flash turned a public Chrome flaw into a reliable exploit chain in eight hours, for $20.40. NIST's CAISI rates the model about four months behind the US frontier. Google's Threat Intelligence Group found that in-the-wild exploitation nearly doubled between January 2025 and August 2026. Attackers have exploited Citrix, Cisco, Zimbra and Fortinet gear. Patching alone does not remove attackers who are already inside.Deep DivesCalifornia Just Took 'The AI Did It' Off Your Defense ListA weak lawsuit against OpenAI is building the template that will judge your own agents, and the agent records you can't produce are where your exposure lies.Patching Stopped Being Remediation the Week Exploits Cost $20When a cheap model can turn a published fix into a weapon within a workday, a closed patch ticket proves little, and your security budget is weighted toward the wrong work.