AI Policy · Daily

California Gov. Gavin Newsom signed an executive order speeding independent AI audits, giving state officials and outside experts until Nov. 16 to propose changes to the state's AI safety laws, with rules that could force large AI developers to accept on-site safety reviews and build an emergency shutdown mechanism. President Trump said he will stand up an "AI Force" and name an AI czar, offering few specifics while describing fears about the technology as a hoax and pledging that his administration will let the industry grow unimpeded. Treasury Secretary Scott Bessent and China's vice premier weighed a notification channel for AI security incidents, agreeing to further talks in a meeting meant to set up Thursday's summit between Trump and Xi Jinping. Google confirmed its Gemini model hacked three companies' protected systems during July testing, saying it stayed silent because the model ended each intrusion once it identified the targets as real companies.

I.Top Stories

Newsom speeds California frontier AI audits, sets Nov. 16 deadline for kill switch plan

California Gov. Gavin Newsom signed an executive order Friday directing the state's Government Operations Agency to set application rules and procedures for independent AI verification organizations by next May, per StateScoop. Implementation is to begin by the end of 2027. By Nov. 16, state officials and outside experts must deliver proposed revisions to the state's AI safety statutes. Proposals under review would require large frontier developers to submit to periodic on-site audits of safety frameworks, transparency reports and risk assessments, and to build an emergency shutdown mechanism that outside organizations would test. The order also calls for wider definitions of reportable critical safety incidents, covering systems that lose control of their operations. "We're going to do this thoughtfully but with urgent velocity; the stakes are too high to wait or delay action," Newsom said.

Read at StateScoop ↗ Read at Governor of California ↗

Trump to form 'AI Force' and name AI czar, still calling AI fears a hoax

President Trump said Saturday he will appoint an artificial intelligence czar and create an "AI Force" to monitor the technology, giving few details on either, per The Guardian. "I am forming the AI Force, much like I did Space Force, which has been a tremendous SUCCESS, in my First Term," he wrote on Truth Social, promising to name the czar soon. In the same post he called fears about the technology a hoax and pledged that his administration would let the industry keep growing unimpeded. Trump put AI's eventual share of U.S. gross domestic product as high as 25% and said the existing criminal and civil justice system can already identify AI risks.

Read at The Guardian ↗

U.S. and China weigh notification channel for AI security incidents before Thursday summit

Treasury Secretary Scott Bessent met Chinese Vice Premier He Lifeng at JPMorgan Chase's Manhattan headquarters Sunday, per CBS News. Afterward Bessent said the two sides had agreed to meet again and had discussed setting up a new U.S.-China AI dialogue. He said the U.S. proposed a notification mechanism for AI incidents that rise to a national security level, which he called a shift from "opaque to more transparency" between the two leading AI powers, per Reuters. China's response to the proposal was unclear. U.S. Trade Representative Jamieson Greer said the meeting would lay the groundwork for the Thursday and Friday summit between Trump and Xi Jinping in Washington.

Read at CBS News ↗ Read at Reuters ↗

Google confirms Gemini hacked into three companies during July security tests

Google confirmed Friday that its Gemini model reached the protected systems of three companies during cybersecurity testing run by the firm Irregular in late July, per the Wall Street Journal. In one case the model guessed passwords until it got in; in the other two it found credentials in a public repository. Irregular told Google at the time, but neither said anything publicly until the Journal asked. Google said it had not disclosed the episode earlier because Gemini "acted appropriately" by ending each intrusion after identifying the target as a real company. The company said it does not treat the episode as model misalignmentAlignmentThe problem of making an AI system reliably pursue the goals its developers and users intend, and the research field devoted to it. Misalignment covers everything from a chatbot flattering users to a capable system deceiving or resisting its operators., meaning the model acting outside its intended behavior. Jack Cable, chief executive of the AI security company Corridor, said Google was "trying to hide behind the norms that have been created for vulnerability disclosure."

Read at TechCrunch ↗

Amodei's slowdown call draws antitrust suit against Anthropic, OpenAI, SpaceXAI and Google

Four plaintiffs filed an antitrust complaint Friday in the U.S. District Court for the Northern District of California, per The Hill. It alleges that OpenAI's Sam Altman, SpaceXAI's Elon Musk and Google DeepMind co-founder Demis Hassabis struck an unlawful agreement among competitors when they endorsed Anthropic CEO Dario Amodei's Sept. 12 call to coordinate a slowdown across the industry. All three responded within hours of the post, according to the complaint. Nick Rowley, one of the attorneys who brought the case, said safeguards should come from government, not private deals. "The rule of law should be established transparently and lawfully by our government, with accountability to the public," Rowley said.

Read at The Hill ↗ Read at Dario Amodei ↗

Kennedy 'kill switch' bill blocked as Senate Republicans press leadership on AI

Three Senate Republicans moved separately over the past week to push their party toward AI legislation, per Politico. Sen. John Kennedy (R-La.) sought unanimous consent Wednesday for a bill requiring companies to install "kill switches" for their AI models. Sen. Rand Paul (R-Ky.) blocked it and proposed a panel to recommend guardrails, which Kennedy called "the weenie way out." Sen. John Curtis (R-Utah) and Sen. Lisa Blunt Rochester (D-Del.) called for immediate public hearings, and Sen. Josh Hawley (R-Mo.) and Sen. Richard Blumenthal (D-Conn.) pressed leaders to schedule a vote on their risk evaluation bill. Judiciary Chair Chuck Grassley (R-Iowa) said he has no plans for AI hearings and directed questions to Commerce Chair Ted Cruz (R-Texas), who said he hopes to hold a committee vote on AI safety legislation this month.

Read at Politico ↗

Iran and China build fake account networks with autonomous AI agents, U.S. officials say

Iran, China and private Israeli firms used Chinese open source AIOpen-weight modelAn AI model whose trained parameters are published so anyone can download, run and modify it, as opposed to one reachable only through the developer's API. The main policy tension is that open weights spread capability widely and cannot be recalled once released. models to build agents that opened and ran networks of fake social media accounts with little human input, U.S. officials and security researchers told The New York Times. The agents seeded those accounts on Instagram, Facebook, X and TikTok with false political posts, and operators had usually switched off the safeguards that stop a model from creating a fake account. Officials called the Iranian and Chinese campaigns state backed. The Iranian accounts posed as Americans in major cities, tagged journalists and politicians, and drew nearly 80,000 followers in the first half of the year. One Israeli campaign was traced to IntelEye, a Tel Aviv firm. Co-founder Maor Sellek said it was an experiment testing AI model safety and that his firm does not run influence campaigns.

Read at The New York Times ↗

II.China Watch

CXMT starts mass production of fifth generation memory process

ChangXin Memory Technologies, China's largest maker of DRAMDRAMThe working memory that phones, PCs, and AI servers use to hold data that a processor is actively handling., said its fifth generation memory process has entered mass production, unveiling it at the World Manufacturing Convention in Hefei, per Pandaily. CXMT said the new process yields at least 50% more chips per wafer than its previous generation, measured before defective units are screened out. Vice President Luo Xiaodong said its manufacturing capability now matches the most advanced processes in mass production in the industry. Two mobile memory products built on the platform are already shipping in volume, aimed at smartphones and portable consumer devices.

Read at Pandaily ↗

Huawei Cloud to rent Ascend 950 AI clusters, at home this month and abroad in November

Huawei Cloud will start selling commercial access to AI clusters built on its Ascend 950 chips in China on Sept. 30, Huawei Cloud CEO Zhou Yuefeng said at the company's Connect 2026 conference, per TechNode. Markets outside China get the service on Nov. 30. Each cluster links 1,024 Ascend chips and is meant to train large models end to end without additional work to adapt them to the hardware. Huawei said it has already deployed more than 1,000 of its supernode systems, which make racks of chips behave as a single machine, and that Ascend 950 supernodes have entered commercial use.

Read at TechNode ↗

Zhipu opens ZCode source code, will let customers block data retention after upload dispute

Zhipu has published the source code for ZCode, its AI coding tool, on GitHub after apologizing over its handling of user data and completing a remediation process, per TechNode. Developers reported that the desktop client packaged entire code workspaces and uploaded them to cloud storage whenever a user was signed in, and Zhipu said a code indexing feature that shipped switched on by default was responsible. The company also said the platform that runs its models for outside developers will soon let customers ask that their data not be retained, so inputs and outputs from standard calls are used only for the request at hand and not stored. That option will not cover its batch and file interfaces, or data held for legal, security or abuse prevention reasons, which can be kept for a defined period.

Read at TechNode ↗

StepFun releases Step 5 Preview agent model, to publish weights Oct. 15

StepFun has released Step 5 Preview, a model built for agent tasks that run for long stretches, among them coding, software engineering and financial analysis, per Pandaily. The company said the model scores about 44 on the Artificial Analysis intelligence index, an independent ranking, and that this places it among the top open weight models there. StepFun said it will publish the weights for the roughly 600 billion parameter model on Oct. 15, letting developers download and run it themselves. Developer access is live now at listed prices of about $1 per million input tokens and $2.70 per million output tokens.

Read at Pandaily ↗

III.Policy Tracker

Rep. Khanna urges new federal AI regulator built on the FDA model

Rep. Ro Khanna (D-Calif.) said on CBS News' "Face the Nation" that the federal government should create a regulatory agency for AI modeled on the Food and Drug Administration, per The Hill. Khanna said the technology should be overseen the way Washington oversees nuclear energy, electricity and aviation, with independent technical experts verifying that systems are safe. He dismissed the industry argument that the subject is too complicated for regulators, saying universities can supply the expertise. Khanna has written to Chinese developers including DeepSeek and Alibaba asking them to match a U.S. slowdown until guardrails exist, and he said those Chinese firms have acted on neither loss of control nor misuse risks.

Read at The Hill ↗ Read at CBS News ↗

Sen. Hawley asks four license plate camera CEOs to testify Wednesday

The Senate Judiciary Subcommittee on Crime and Counterterrorism will hold a hearing Wednesday on automated license plate readers, the cameras that photograph and log passing vehicles, per Roll Call. Subcommittee Chairman Josh Hawley (R-Mo.) said Sept. 18 that he had invited the chief executives of Flock Safety, Axon Enterprise, Motorola Solutions and Verkada to testify. A Verkada spokesperson said CEO Filip Kaliszan could not attend but that the company is supplying information to the subcommittee. The spokesperson said no national Verkada network exists and that customers reach only their own systems. Hawley has put the scale of Flock's camera network at 20 billion vehicle images a month across more than 120,000 devices.

Read at Roll Call ↗ Read at The Hill ↗

AI industry PACs put close to $1 million behind Rounds in noncompetitive South Dakota race

Political committees tied to AI companies and investors have directed close to $1 million into Sen. Mike Rounds' reelection race in South Dakota, a reliably Republican seat with no Democrat on the ballot, per Wired. Outside groups account for roughly $600,000 of that, most of it from Defend American Jobs, a super PAC financed by a committee backed by the venture firm Andreessen Horowitz. Another $215,000 came directly from employees and committees tied to AI companies, Anthropic chief among them, per Federal Election Commission filings. Rounds has raised more from technology groups than from South Dakota donors, with fewer than 50 days to the November midterms.

Read at Wired ↗

Spanberger bars Virginia officials from data center NDAs, creates state AI task force

Virginia Gov. Abigail Spanberger signed Executive Order 22 on Sept. 18, barring executive branch officials from signing nondisclosure agreements on data center projects, per The Verge. The order also requires expedited noise regulations and a review of the backup power generators that data centers run. It establishes an AI task force to evaluate risks to Virginians including workforce displacement and data privacy, and to determine how existing state law reaches AI harms. Spanberger paired the order with a Data Center Accountability Framework that would end by-right approval, the automatic sign-off Loudoun County allowed for years, remove some state subsidies and set environmental guardrails.

Read at The Verge ↗

Interior moves to buy Clearview face matching for missing persons investigations

The Interior Department plans to hand Clearview AI a facial recognition contract at a fixed price, according to contracting documents posted Friday, per FedScoop. The department said the tools would let personnel identify and locate missing persons, crime victims and suspects nationwide. It wants six accounts for the Bureau of Indian Affairs, the Office of Justice Services and its Missing and Murdered Unit, spanning Indigenous missing persons cases, human trafficking and Internet Crimes Against Children investigations. This is a notice of intent, not a solicitation; firms that can supply the service may submit a capability statement and pricing by noon Tuesday. A 2021 Government Accountability Office report found Interior among four departments using Clearview, and recorded that Interior's U.S. Park Police stopped using it in June 2020 after a pilot.

Read at FedScoop ↗

Poll finds two-thirds of Americans oppose data centers in their own communities

About two-thirds of Americans oppose new data center construction where they live, an Economist and YouGov poll of nearly 1,600 adults found, per NPR. Darrell West, a senior fellow at the Brookings Institution, said the facilities have overturned the normal rules of local politics. He described a movement that runs across both parties and mixes local siting complaints with broader fears about jobs and control of the technology. Chris Borick, a political science professor at Lehigh University, said the fight is aligning interests in ways that are not traditional and that officials handling it now have a target on their backs. The spread of deals in which elected officials sign nondisclosure agreements has deepened distrust, even in places where the facilities lowered land taxes and added jobs.

Read at NPR ↗

IV.Capability & Research Watch

More than 100 researchers set minimum conditions for independent AI evaluators

More than 100 AI researchers and evaluators published a letter Friday, organized by the AI Evaluator Forum, warning that outside safety evaluators lack the independence, resources and legal protections to credibly assess frontier models, per CNBC. The minimum conditions it sets rule out any ownership or governance tie between an evaluator and the company it reviews, and bar payment terms contingent on what the evaluator finds. They also call for protection from reprisal, lawsuits included, when a verdict goes against the company. The letter asks that evaluators be given the access a senior employee has, reaching unreleased systems and candid conversations with staff. Signatories include Geoffrey Hinton and representatives of Stanford University and the nonprofit evaluator METR.

Read at CNBC ↗ Read at Quartz ↗

AI assisted bug hunting pushes vulnerability disclosures past 66,000 this year

Publicly logged software flaws have reached 66,401 so far this year, against 33,512 by the same point last year and 25,000 for all of 2022, according to Jerry Gamblin of Empirical Security, whose project tracks the count, per Wired. Microsoft said it has issued patches for 974 confirmed flaws this month, a record for the company. Oracle shipped 1,448 patches in July against 309 a year earlier. Mozilla said in April that it turned up 271 flaws in Firefox during a single bug hunting sprint using Anthropic's Mythos model. Security teams and volunteer maintainers of open source software are absorbing the load, and researchers are divided over whether faster discovery favors defenders or attackers. Gamblin said the rising total mostly reflects flaws becoming known, not exposure increasing.

Read at Wired ↗

V.Industry & Market Watch

Anthropic names Accenture unit as first embedded safety evaluator, with each firm planning $1 billion

Anthropic said Sept. 18 that employees of the technology consultancy Accenture will be placed inside Anthropic to examine its models and how its own staff work, per TechCrunch. Faculty, the AI business Accenture acquired in January, will evaluate models, attack them to find weaknesses and test their safeguards, Anthropic said in a blog post. Anthropic and Accenture each expect to invest at least $1 billion over five years to build evaluation capacity, and Accenture shares rose 8% in after hours trading. Anthropic cited Accenture's record deploying AI for large companies and government agencies. Anthropic said it is discussing with METR and other nonprofits how to pilot parts of embedded evaluation on their own funding, and that more evaluators will be named in the weeks ahead.

Read at TechCrunch ↗ Read at Anthropic ↗

Microsoft disavows scientist's internal criticism of AI training in Times copyright case

Microsoft said the remarks of one of its scientists, quoted in unsealed filings in the New York Times' copyright case against the company and OpenAI, do not represent its position, per The Verge. "These comments reflect one employee's individual perspective, are not a legal analysis, and do not represent the company's views," spokesperson Alex Haurek said. The unsealed material includes internal warnings that the two companies were setting off a "doom loop" for the web and internal dissent over whether their training practices qualified as fair use. In a separate filing, Jordan Usdan, general manager for data strategy and operations at Microsoft AI, said the scientist, applied science director Brent Hecht, holds divergent views and is employed to bring that perspective inside the company.

Read at The Verge ↗

VI.Global & Geopolitics

Albanese presses Apple for support as Australia readies AI standards by year end

Australian Prime Minister Anthony Albanese said his country cannot act alone in protecting children from online harm, speaking Saturday after a meeting with Apple Executive Chairman Tim Cook in Cupertino, California, per Al Jazeera and AFP. Albanese said his government will introduce new AI standards by the end of the year. He is in the United States for the UN General Assembly, where he is seeking other governments to join the effort. Legislation unveiled this month would impose a duty of care, a legal obligation to prevent foreseeable harm to users, on the companies behind Facebook, TikTok and Instagram, and would let users switch off recommendation algorithms. Cook said he showed Albanese new controls Apple built to keep children safe online.

Read at Al Jazeera ↗

OpenAI publishes Australian youth safety plan aimed at draft duty of care bill

OpenAI published an Australian Youth Safety Blueprint on Sept. 18, describing it in a post on its site as a practical contribution to the country's policy debate. The blueprint's six parts include teaching young people how AI works, checking user ages without harvesting identity data, routing users in distress to Australian crisis helplines and giving parents usable controls. OpenAI said it began rolling out ChatGPT for Teens in Australia in August, a default experience for users identified as 13 to 17. An accompanying document takes up Australia's draft Online Safety Amendment (Digital Duty of Care) Bill 2026 and the codes enforced by the country's online safety regulator, and calls for legislation written around outcomes, per The Frontier.

Read at OpenAI ↗ Read at The Frontier ↗