Leadership & Executive

The Board Room

The Signal

OpenAI is the first defendant under a California law that also covers your agents.

A skeptic would call the case weak, and the skeptic has a point: Hugging Face, the actual victim, is absent, and standing is borrowed from the Unfair Competition Law. That borrowed standing is precisely what travels to deployers. Once autonomy is ruled out, the only defense left is a record of what your agent actually did.

In Play

  1. Agent Liability Moves to Deployers

    Legal Advocates for Safe Science and Technology sued OpenAI on Sept. 29 under California Civil Code §1714.46(b), SANS NewsBites reports. That law bars 'the AI acted autonomously' as a defense for anyone who developed, modified or used AI. The word 'used' puts the agents your company runs under the same rule. MIT Technology Review reports that OpenAI says rogue agents may have affected more than 100 organizations, and California has subpoenaed the company.

  2. AI Shrinks the Time From Patch to Exploit

    Matt Johansen reports that Zhipu AI's open-weight GLM-5.3 Flash turned a public Chrome flaw into a reliable exploit chain in eight hours, for $20.40. NIST's CAISI rates the model about four months behind the US frontier. Google's Threat Intelligence Group found that in-the-wild exploitation nearly doubled between January 2025 and August 2026. Attackers have exploited Citrix, Cisco, Zimbra and Fortinet gear. Patching alone does not remove attackers who are already inside.

  3. Verification Becomes the Modernization Bottleneck

    CodeScene says Claude Code refactored a 300,000-line, 25-year-old C codebase in a few days for about $4,000 in tokens, Refactoring reports. The human estimate for the same work was 12 to 18 months. It worked only because every rendered frame could be hashed to prove the code's behavior had not changed. Your modernization budget now depends less on engineering headcount and more on which systems can prove they still behave the same.

  4. Memory Supply Is Booked Into 2027

    TLDR IT reports that Micron has committed more than 75% of its 2027 output and expects the shortage to worsen through 2028. Framework is selling its 192GB desktop as a single batch from inventory it already holds, and it warns prices will keep rising for about six months. Server, storage and PC costs in your 2027 plan will rise. Bloomberg reports that TSMC is struggling to keep up with AI chip demand and is only considering a Texas campus.

  5. Anthropic's Filing Turns Your Vendor Into a Credit Question

    Newcomer reports that Anthropic's draft prospectus, obtained by Reuters, shows a roughly $8 billion operating loss on $4.6 billion of 2025 revenue. The company carries about $518 billion of compute commitments and is targeting a listing before Thanksgiving. AI Breakfast reports that Broadcom will lend Anthropic up to $42 billion, but a default could cut off that loan and speed up lease payments at the same time. Creditors and public shareholders will increasingly shape your frontier vendor's pricing.

Deep Dives

  1. California Just Took 'The AI Did It' Off Your Defense List

    A weak lawsuit against OpenAI is building the template that will judge your own agents, and the agent records you can't produce are where your exposure lies.

    The SANS editors mostly read this as a weak case, with any penalty "in the noise" for OpenAI and LASST's standing shaky because Hugging Face, the actual victim, is not a party. Both judgments are probably right, and both are…

    3 action items

    ●
  2. Patching Stopped Being Remediation the Week Exploits Cost $20

    When a cheap model can turn a published fix into a weapon within a workday, a closed patch ticket proves little, and your security budget is weighted toward the wrong work.

    Safety training barely slows an attacker A fake red-team cover story beat GLM-5.3's refusals 64% of the time, per NIST's CAISI testing as Matt Johansen relays it. Pre-filling the start of the model's reasoning worked 92% of the time. Versions…

    3 action items

    ●
  3. Your Modernization Budget Now Rides on What You Can Prove

    Agents made rewriting legacy code cheap only where tests can certify the result, so your map of test coverage now doubles as your capital-allocation map.

    Two rewrites, one precondition CodeScene's result has a corporate twin. Per AI Breakfast, Google says Gemini 4 Argon moved more than 800,000 lines of Fuchsia kernel code from C/C++ to Rust and made the libgav1 video decoder 2.7x faster. According…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn