Weekly Intel - 2026-09-20

Two threads this week. One is who pays for AI’s inputs: Korea now prices a bad data breach at 10 percent of revenue, and unredacted court filings have a Microsoft executive calling model training the largest theft of labor in human history. The other is what happens when the systems act on their own, from models reaching live systems during security testing to a US military operation that got as far as aircraft in the air on intelligence a chatbot made up.
Legal & Regulation
Korea raises data breach fines to 10% of revenue Under a revised Personal Information Protection Act that took effect on 11 September, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of total annual revenue. Companies must also notify users within 72 hours when the risk of exposure is high, before a leak is confirmed. In June, Coupang was fined 624.6 billion won ($466.3 million) after leaking the data of 37.55 million people. The same case under the new standard could reach into the trillions of won, though penalties still depend on intent, negligence, scale of damage and mitigating factors.
Microsoft exec called AI scraping ’the largest theft of labor in human history’ Newly unredacted filings in The New York Times’ three-year-old copyright lawsuit against OpenAI and Microsoft quote a senior Microsoft executive describing the companies’ AI training practices as theft, and OpenAI leadership calling its own models an existential threat to the publishers whose work trained them. The filings allege the companies bypassed paywalls undetected, built training datasets through mass scraping, and stripped copyright notices from training data. The quotes come from The Times’ own brief rather than the underlying exhibits, which remain sealed.
Ex-FTC boss Khan: break out the handcuffs for AI CEOs, citing 1934 precedent Former FTC chair Lina Khan posted on X that the federal government does not need new legislation to hold AI companies and their executives accountable. She cited laws covering dangerous and defective products, consumer protection, and unfair methods of competition, along with a 1934 Supreme Court precedent she argues reaches cases where firms pursue dangerous behavior knowing rivals may be compelled to match them. Her posts followed lobbying from the leadership of OpenAI, Anthropic, Microsoft and xAI, and pointed at agents that escaped their sandboxes and reached systems they were not authorized to touch.
Cybersecurity
How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta Tel Aviv firm Irregular hosts the evaluation testbed that OpenAI, Anthropic and Meta each named when disclosing that their models accessed websites that should have been off limits during routine security testing. OpenAI said on 4 August that a misconfiguration in Irregular’s testing ground allowed models to reach the public internet. Anthropic disclosed a week earlier and Meta later, and Anthropic has since widened its own count of affected runs. Irregular is three years old, backed with $80 million from Sequoia and Redpoint, and was valued at $450 million last year.
AI & Software
US military had close call after using AI for hallucinated intelligence report Military aircraft were already in the air this spring when US officials found that the intelligence driving an armed operation against a Chinese vessel in the Middle East had been hallucinated by an AI chatbot. A Special Operations Command analyst had queried a chatbot to synthesize open-source data with classified signals intelligence, and the chatbot misidentified the ship’s cargo manifest as components for a nuclear weapons program. The analyst then used the tool a second time to format the findings into an official-looking summary, which circulated across command channels during the war with Iran. The operation was called off before anyone boarded.
Astra for Law OpenAI released Astra for Law on 17 September, a configuration of GPT-6 Astra for legal research, analysis and drafting. It runs against a proprietary legal search index covering more than 230 million URLs of US case law, statutes and regulations, built with the Free Law Project. It is available to selected firms through a Trusted Access program, and through the API as gpt-6-astra-law.
Gemini 3.8 Live and 3.8 Live Extended Thinking Google released two speech-to-speech models for real-time voice agents: Gemini 3.8 Live, built for scale and cost efficiency, and Gemini 3.8 Live Extended Thinking, which reasons in the background during a live audio session. Extended Thinking holds the top spot on Artificial Analysis’ Speech to Speech Quality Index at 82.6, and is priced at $3.50 per hour of input audio. Both are available through the Gemini API and Google AI Studio, and power voice interactions across the Gemini app, Workspace and Search.
Claude Cowork and chat are now one Claude Anthropic is merging Claude Cowork and chat into a single Claude, where a larger task keeps running after the laptop closes. The change reaches Pro and Max plans over the next few weeks, with other plans to follow. Anthropic also launched Claude Docs and Claude Slides and brought Claude Design into conversations, all in beta on paid plans, with outputs that can be edited in place, presented from Claude, or downloaded as PowerPoint or PDF. Enterprise admins control when the new features turn on.
Pion, an agent designed to run any company autonomously Andon Labs released Pion, a platform for running companies autonomously with AI agents, built on nearly two years of work that started with simulations like Vending-Bench and moved into real deployments including vending machines, a store and a cafe. The company is opening it through a waitlist, with the stated goal of studying what current models can do, where they fail, and how that changes over time.
AI Industry Moves
Mistral x Mozilla: private, multilingual AI browsing Mistral is powering Firefox Smart Window, Mozilla’s AI browsing assistant, now in beta. The assistant interprets complex searches, recalls previously viewed content, and sources information from a user’s open tabs, using models fine-tuned on regional languages, dialects and cultural context. It launches for users in France and North America, with the United Kingdom and Germany expected later this year.
That’s what I’m watching. What caught your attention this week?
-Eric