The Board Room
Florida just launched the first criminal investigation into an AI company
Your AI liability framework assumed civil risk from known failure modes — the reality is now criminal exposure from uncharacterizable model behaviors being actively weaponized. Every AI product that touches end users needs a legal and safety re-audit before end of Q2.
AI Liability Crosses Criminal + Scientific Thresholds
Florida's criminal probe of OpenAI (200+ shooter messages with ChatGPT), subliminal learning research proving distilled models inherit undetectable traits, and Google confirming five categories of prompt injection in the wild converge into a single conclusion: AI liability is now criminal, unauditable, and actively exploited.
AI App Layer Economics Shatter SaaS Assumptions
Cursor at $2.7B ARR with -23% gross margins proves AI apps invert SaaS economics — your best customers are your most expensive. SpaceX's $60B acquisition option is the vertical integration response. OpenAI's super app (900M WAU, 50M subscribers) is the platform consolidation response. The AI middle class is dead.
75% AI-Generated Code Is the New Engineering Baseline
Google disclosed 75% of new code is AI-generated (up from 25% in 18 months). A 100K-line repo written entirely by AI gained 6K GitHub stars in one week. GPT-5.5 ran a 2M-row data migration autonomously for 6 hours. The engineering value stack is inverting from code production to architectural judgment.
Proprietary Data Infrastructure Emerges as Last Durable Moat
Amazon's COSMO converted 30K human annotations into 29M knowledge edges (967x leverage) and projects billions in revenue. Revolut's PRAGMA model achieved 130% credit scoring uplift on 24B banking events. As the model layer commoditizes, proprietary data assets and domain-specific foundation models are the remaining defensible position.
Identity and Developer Toolchains: The Expanding Attack Surface
BlackFile's SaaS-native extortion campaign uses vishing to move laterally across Microsoft Graph, Salesforce, and SharePoint — no zero-days needed. GlassWorm hit 73 VSCode extensions. AI agents are autonomously probing CI/CD pipelines. State CISO confidence collapsed from 48% to 22%. The perimeter is now identity, not infrastructure.
AI Liability Just Went Criminal — and the Science Says You Can't Audit Your Way Out
Cursor's -23% Margins at $2.7B ARR: The AI Application Layer Is Structurally Broken
75% AI-Generated Code: The Engineering Org Model You Built Last Year Is Already Obsolete
Amazon and Revolut Just Proved: Proprietary Data Infrastructure Is the Last Defensible Moat
- Update: Musk v. OpenAI trial starts today with $100B+ at stake in the charitable trust claim — any adverse outcome could structurally weaken OpenAI's for-profit conversion and enterprise credibility
- Applied Intuition quietly built the 'Android for physical AI' at $15B valuation — 18 of top 20 non-Chinese automakers are already customers, with expansion into defense, mining, and robotics
- OpenAI's web crawl volume tripled since August 2025 to 4% of Google's crawl share — post-GPT-5, the crawling is for real-time search retrieval, not model training, signaling a parallel web index
- Adobe's Project Page Turner generates fully personalized web pages per-visitor in under 100ms via LLMs — a category break that obsoletes segment-based personalization entirely
- Entry-level marketing employment among 22-25 year olds has fallen 16% as AI replaces execution tasks — the junior talent pipeline is being cut at the source
- DPRK IT workers now use AI interview copilots (jobright.ai, ntro.io), fake GitHub portfolios, and Astrill VPN with US exit nodes to infiltrate companies — your remote hire vetting is likely insufficient
- OpenPipe's open-source RULER automates reward signal generation for RL training on non-verifiable tasks (RAG, summarization, support) — collapsing the cost of training domain-specific agents by 10x
- OpenAI launched a GPT-5.5 bio-specific bug bounty ($25K) — the first domain-specific safety program at this scale, signaling biological capabilities have crossed a threshold requiring targeted containment
- Update: California's billionaire wealth tax — based on voting interests, not economic interests — has qualified for the November ballot; Page, Brin, and Zuckerberg have already changed residencies
- Adyen acquires Talon.One for €750M to embed real-time loyalty/promotion decisioning inside the payment flow — pure payment processing is officially a commodity
AI liability crossed from theoretical to criminal this week — Florida is investigating OpenAI, a Nature paper proved model audits can't detect inherited behaviors, and Google confirmed prompt injection exploits are live in the wild — while the AI application layer's economics inverted: Cursor's -23% margins at $2.7B ARR prove that every AI app losing money on its best customers isn't a startup problem, it's a structural reality. The only durable positions are at the extremes: own the compute, own the proprietary data, or own the platform. Everything in the middle is getting squeezed.