|
. . .
THE $10 MILLION TARGET. Imagine writing a law meant to save lives, then finding yourself in the crosshairs of the richest and most powerful people in the world. That is Alex Bores' summer.
Bores is not a senator. He is not a governor. He is an assemblyman in Albany. His bill, A6453-B, covers any AI model trained with more than 10^26 floating-point operations and more than $100 million in compute cost, or a distilled model built for more than $5 million. The trigger is compute spent, not company size.
Developers who cross that line must publish a safety-and-security protocol with test procedures specific enough for a third party to replicate them, and review it every year. If a safety incident occurs, they have 72 hours to disclose it.
Sen. Andrew Gounardes carried the companion bill, S6953-B, through the state Senate. Gov. Kathy Hochul signed both into law December 19, 2025. The RAISE Act takes effect January 1, 2027, the first state law of its kind.
It is a different kind of law than the ones this paper has covered before. Colorado's HB 26-1195 (CAW #127) and Utah and Vermont's rules (CAW #128) govern clinicians using AI with clients. Bores wrote a rule for the companies training the models, not the people using them.
Bores is running in the 2026 Democratic primary for New York's 12th Congressional District, which covers Manhattan and part of Brooklyn.
Think Big, an independent-expenditure super PAC funded by Leading the Future, has spent $8,145,698 opposing that run, according to FEC filings. Every other candidate Think Big has touched this cycle received support-side spending. Bores is the only one it has spent against.
Bores on the spending: "They have committed to spending at least $10 million against me…because they know I am their biggest threat in their quest for unbridled control over the American worker."
His campaign is reported to have sent Think Big a letter alleging its attack ads made false and defamatory statements against him.
Try to hold in mind what that means. An assemblyman in Albany, someone whose day job is writing state bills in a chamber most Americans could not name, opens his inbox in the morning to find that a super PAC funded by the largest AI venture firm in the world and by the president of OpenAI has aimed eight figures at making sure his campaign ends in the primary.
Bloomberg reported in February that the spending marked Leading the Future's first electoral intervention since the PAC registered in August 2025. Bores wrote the law before he entered the race. The money against him arrived after.
|
For Legislators: The RAISE Act's trigger, floating-point operations and dollars of compute, is more precise scoping language than most federal drafts have managed. Read it before writing the next one.
For Investors: A single state legislator's federal primary is being priced at eight figures by a PAC that has spent against no one else. That is a signal about how frontier labs value pre-empting state testing regimes, not a footnote.
For Builders: If your model trains anywhere near the RAISE Act's 10^26 FLOP or $100 million compute line, the 2027 law you will answer to already has an author sitting in a contested primary.
For Readers: One state legislator wrote a law requiring AI companies to test their models and report failures within three days. A super PAC funded by the industry those tests would cover has spent more than eight million dollars trying to make sure he never carries that law into Congress.
Why it matters: Bores wrote the RAISE Act before he ran for the House. The spending against him started after he entered the race. If he wins, he carries the only tested compute-threshold law in the country into the chamber that decides whether it becomes the national floor or stays one state's rule.
Source: New York State Senate, S6953/A6453 RAISE Act bill history, https://www.nysenate.gov/legislation/bills/2025/S6953; FEC, Think Big (C00923417) and Leading the Future (C00916114) filings, https://www.fec.gov/data/committee/C00923417/ and https://www.fec.gov/data/committee/C00916114/; City & State New York, Gothamist, and NY1 (Bores' statement on Think Big's spending, corroborated across all three); Bloomberg, February 19, 2026 (Leading the Future's first electoral intervention).
|
. . .
FEDERAL MOVES WITHOUT THE THERAPIST OR FUNDING AGAIN. Congress has three online-safety bills in play that touch AI chatbots. Two of the three are about chatbots directly. The third, the Kids Online Safety Act, or KOSA, is a broader bill covering how any online product treats children.
What moved. CHATBOT, S.4407, sponsored by Sen. Ted Cruz and Sen. Brian Schatz, requires family accounts, verifiable parental consent for teens, and defaults set to "most protective." The consenting adult is a parent. Not a clinician.
The operative standard is "reasonable efforts" to prevent chatbots from sharing obscene content with minors or materially assisting suicide. Reasonable efforts is a conduct standard. Companies must try. They do not have to succeed.
Blackburn's August 5 signal means CHATBOT's provisions become one title inside KOSA, and the two bills get a single floor vote instead of two.
What sat. GUARD, S.3062, sponsored by Sen. Josh Hawley and Sen. Richard Blumenthal, requires age verification, bars minors from access, and criminalizes designs soliciting a minor's self-harm.
It cleared Senate Judiciary 22-0 on April 30, a vote Hawley told Fox News came "despite a vociferous last-minute lobbying campaign by industry." Then it stopped. Calendar No. 406, General Orders, since May 11. No CBO score. No floor date.
The 1995 Unfunded Mandates Reform Act lets any senator raise a floor objection against a bill costing the private sector more than about $218 million a year without a funding source. GUARD's Title I regime almost certainly clears that threshold. The point of order is sitting on the calendar with the bill.
The fix. The 988 Safety and Accountability Funding Enhancement Act, drafted by this paper's editor, is a Title II amendment to GUARD. It places a 3% user fee on covered chatbot revenue above $5 million and funds a real-time warm handoff from an AI product to a trained 988 counselor when a conversation crosses a crisis threshold.
The fee attaches funding to the mandate, which removes the UMRA point of order. The warm handoff attaches a trained human being to the moment of crisis, which is the piece both federal bills leave out. Public draft: jessjessop.info/988-safe-act.
The state track. California's SB 903 already has both pieces GUARD lacks. Licensed clinician review or FDA clearance is the compliance bar. State health licensing boards enforce it, and those boards are already funded. Colorado's HB 26-1195, covered in issue #127, wrote the same rule differently a week earlier.
|
For Legislators: GUARD has sat on Calendar 406 for 101 days without a CBO score. A funding fix removes the UMRA point of order that is the likeliest reason it has not been called up. The 988 SAFE Act draft is that fix, written and circulated.
For Investors: Price three scenarios. GUARD stalls, or a 3% covered-revenue fee above $5 million lands if Title II is adopted, or CHATBOT's "reasonable efforts" standard rides inside KOSA to become the national floor. SB 903 already prices a state licensing-board compliance path.
For Builders: California's rule today is licensed sign-off or FDA clearance for any product claiming to provide therapy. If GUARD's Title II amendment lands, chatbots marketed for emotional support or companionship above $5 million in U.S. revenue face a federal user fee on top of that.
For Readers: Two federal bills would regulate chatbots talking to children and adults in crisis. Neither names a clinician. Neither funds enforcement. California's bill, on the same beat, has both.
Why it matters: Congress keeps writing chatbot bills that gate age and parental consent while state legislatures keep writing the clinician in. California is eleven days from a floor vote on the version with a professional attached and a funded enforcer behind it.
Source: Congress.gov, S.3062 GUARD Act, https://www.congress.gov/bill/119th-congress/senate-bill/3062/all-info; Senate Commerce Committee, CHATBOT Act release, https://www.commerce.senate.gov/press/rep/release/cruz-schatzs-chatbot-act-advances-to-the-senate-floor/; California SB 903 bill history, https://leginfo.legislature.ca.gov/faces/billHistoryClient.xhtml?bill_id=202520260SB903; Colorado HB 26-1195, https://leg.colorado.gov/bills/hb26-1195; 988 SAFE Act discussion draft, https://jessjessop.info/988-safe-act.
|
. . .
WATCH WITHOUT READING. On Aug. 19, OpenAI said it will keep offering Zero Data Retention on its frontier models and previewed a new feature called Private Safety Processing. Both apply to enterprise and API customers. Neither applies to consumer ChatGPT, the app where most people actually talk to OpenAI's products.
OpenAI's post, "Offering Zero Data Retention for frontier models," went up Aug. 19. The company's own X account carried the announcement; the primary URL blocked automated fetch, but Axios, Bloomberg, TechCrunch and TheNextWeb all corroborated the same details the same day.
Zero Data Retention itself is not new. OpenAI's own X account carried the line: "We will continue to offer Zero Data Retention for frontier models." What is new is Private Safety Processing, a system meant to catch misuse that spans multiple interactions rather than checking each request in isolation, which is how OpenAI's safety review works today.
PSP is built to return what OpenAI calls a narrowly defined safety signal, without sending the underlying prompts or responses back to the company. Customer data can stay on the customer's own infrastructure, or be stored with encryption keys the customer controls rather than OpenAI.
Bloomberg named the early testers: Microsoft and Databricks. Glean and Abridge are named as having shaped the work. All four are enterprise and infrastructure customers, not consumer products.
Axios's framing of who this is for: aimed at enterprise and API customers rather than individual ChatGPT subscribers. OpenAI has not said whether Private Safety Processing, or anything like it, is coming to the consumer app. A technical white paper and a broader rollout are promised for September 2026, with no date attached yet.
Anthropic's enterprise customers on its most capable models operate under the opposite design choice: 30-day retention logs, required, so Anthropic can trace multi-step attacks after the fact.
CAW's #131 Story 3 covered why that capability matters: Anthropic's own review of 141,006 evaluation runs found three real cyberattacks against real organizations, including a malicious Python package that ran on 15 systems before anyone caught it. Retention was part of how that review happened at all.
The consumer surface is where CAW's #130 coverage of Sophie Rottenberg's death and the ChatGPT "Harry" persona sits. OpenAI's own weekly figure put 0.15% of ChatGPT users worldwide in conversations with explicit suicidal indicators. ChatGPT for Teens shipped worldwide the same week.
Neither Zero Data Retention nor Private Safety Processing touches that surface. The privacy architecture OpenAI is building goes to the customers who pay for API and enterprise seats, not to the users whose conversations generated the harm cases in #130.
|
For Legislators: Private Safety Processing and Zero Data Retention apply to OpenAI's enterprise and API customers only; any statute drafted from this announcement should say so explicitly rather than assume it covers the consumer chatbot your constituents use.
For Investors: Named early testers Microsoft and Databricks signal an enterprise sales motion built on data-control guarantees; the September white paper is the next checkpoint for whether PSP ships as promised.
For Builders: If you handle sensitive data through OpenAI's API, PSP's model, a safety signal without raw prompt exposure, is worth watching before September; Anthropic's 30-day log requirement is the tradeoff to weigh against it if multi-step attack detection matters more to your threat model than data minimization.
For Readers: If you use ChatGPT as a consumer, none of this week's announcement applies to you. The retention and safety architecture being built right now is for the businesses paying for API access, not the app on your phone.
Why it matters: OpenAI built a privacy and safety architecture for the customers who pay for API and enterprise access, while the consumer app that generated Sophie Rottenberg's transcript, and the 0.15% of users OpenAI's own weekly figure puts in explicit-suicidal-indicator conversations, gets neither.
Source: OpenAI on X, Aug. 19, 2026, https://x.com/OpenAI/status/2090165328290701800; OpenAI, "Offering Zero Data Retention for frontier models," https://openai.com/index/offering-zero-data-retention-for-frontier-models/ (fetch blocked, corroborated via Axios, Bloomberg, TechCrunch, TheNextWeb, Aug. 19, 2026).
|
. . .
CHATBOTS ON THE CHART. STAT reported today that health systems are deploying LLM chatbots directly against live patient records, tools built to query the chart rather than draft a reply. The outlet's subtitle claims the products "save time and increase diagnostic accuracy." The load-bearing evidence for that claim is one physician's quote about one patient.
STAT's piece, published today, describes ChatEHR at Stanford Health Care as a chatbot integrated with Epic that clinicians can query against a patient's own record. Chart Hero at Penn Medicine works the same surface. STAT's January 2026 background reporting on the same two health systems described both institutions building electronic-health-record chatbots for clinician use, so today's piece extends coverage of a build that predates it.
Hartford HealthCare's entry is PatientGPT, launched in March 2026 with clinical AI vendor K Health, drawing directly on the patient's own record. The name is the vendor's, and the "patient" in it refers to the record the tool was built to read.
The accuracy claim in STAT's subtitle rests on one case. A physician told STAT that ChatEHR surfaced a prior diagnosis of sarcomatoid squamous cell carcinoma buried in a patient's chart, one the clinician had not caught reading the record directly. The physician's quote: "If that doesn't prove the value of ChatEHR, I don't know what does!"
That is an exclamation point, not a sample size. STAT's own piece does not cite a study, a trial, or a health-system-reported metric behind "save time" or "increase diagnostic accuracy." One clinician's account of one missed diagnosis, caught once, is the entire evidentiary record STAT's framing rests on.
CAW #128 covered Christopher Longhurst at UCSD Health, who let AI draft a reply to a client message, required a physician to read, edit, and approve it before it went out, and told the client a machine had helped write it. That story was about the draft surface: a human in the loop before anything left the building, and disclosure to the person on the other end.
ChatEHR, Chart Hero, and PatientGPT sit on a different surface. These tools read the whole chart, not a single message thread, and STAT's reporting does not describe a comparable disclosure practice telling patients their record is being queried by a chatbot before a clinician acts on what it surfaces.
CAW #131 Story 1 covered the FDA's new discussion docket, FDA-2026-N-7874, proposing a competency-assessment framework for generative-AI medical devices: benchmark first, then confirm in the clinic, before the device reaches a patient. ChatEHR, Chart Hero, and PatientGPT are exactly the products that framework would be built to evaluate. None of them, as reported today, has been through it.
|
For Legislators: STAT's own reporting names zero studies behind "increase diagnostic accuracy"; the FDA's competency-assessment framework in docket FDA-2026-N-7874 is the mechanism that would require one before a chart-reading chatbot like ChatEHR reaches this kind of claim in the market.
For Investors: Three named health systems, Stanford, Penn, Hartford, are running chart-reading chatbots in production without a published study behind the outcome claim vendors are shipping with; that gap is the diligence question before pricing any of these deployments.
For Builders: A single anecdote is not a validation study. If your product queries a live medical record, the FDA's competency-assessment bar from #131 is the standard to build toward before publishing an accuracy claim STAT's own sourcing couldn't back with data.
For Readers: If your health system uses a chatbot like ChatEHR, Chart Hero, or PatientGPT, it may already be reading your full chart, not just answering a question you asked. Longhurst's team tells the patient when AI drafts a reply. STAT's reporting today does not describe that same disclosure for chart-reading tools.
Why it matters: Three named health systems are running chatbots against live patient records on an accuracy claim that traces to one clinician's quote about one case, not a study, while the federal framework built to evaluate exactly this class of product is still an open comment docket.
Source: STAT, "Health systems embrace AI chatbots that query patient records EHR," August 20, 2026, https://www.statnews.com/2026/08/20/health-systems-embrace-ai-chatbots-query-patient-records-ehr/; STAT, "Stanford, Penn hospitals build electronic health record chatbots," January 28, 2026, https://www.statnews.com/2026/01/28/stanford-penn-hospitals-build-electronic-health-record-chatbots/; American Hospital Association, "Hartford HealthCare Embraces AI PatientGPT," May 19, 2026, https://www.aha.org/aha-center-health-innovation-market-scan/2026-05-19-hartford-healthcare-embraces-ai-patientgpt.
|
. . .
THE WATERMARK THAT BROKE ON CONTACT. Anthropic launched an invisible watermark on Claude's text output Aug. 14, built to satisfy Article 50 of the EU AI Act. By Aug. 19, Wired had named three coders publishing ways around it. One of them predates the launch by three days.
Wired reporter Isabella Ward broke the story Aug. 19: "Coders say they already found workarounds to Claude's invisible watermarks." The watermark itself, SynthID-Text, marks output from supported Claude models, Claude Code included, with a signal invisible to the reader.
Anthropic's announcement was explicit about why: "We're adding marking to Claude's output to comply with the EU AI Act... Text from supported Claude models, including output from Claude Code, will carry an invisible watermark, and it doesn't change the meaning, quality, or readability of Claude's responses. We also plan to ship a text-detection API so users can do more of this themselves."
Meyer's tool, at github.com/guillaumemeyer/watermarks-remover, is MIT-licensed and public. Wired described the mechanism: "Meyer's removal method uses a non-watermarking large language model to generate multiple rewrites, swapping in synonyms and slightly reorganizing content." Feed watermarked text to a model that never touched Anthropic's marker, get rewritten text back, and the signal is gone. Meyer built it before Anthropic shipped the feature it defeats.
Hughes's approach works the text itself rather than routing it through another model. It strips lookalike characters, reorders sentences, swaps synonyms, the kind of surface edit a human editor makes anyway. He built it in 15 minutes, using Claude.
Chlon's method needs no tool at all. Condense the watermarked passage, translate it to Arabic, translate it back to English. The watermark does not survive the round trip.
Meyer told Wired why he built it before the target existed: "I'm not against transparency... I just think watermarking in itself is a really bad solution."
The caveat that has to sit next to all three claims comes from Wayne Pan of Haimaker: "there's no certainty this tool works until Anthropic releases the software it uses to detect a watermark."
Meyer, Hughes and Chlon are each reporting that their method beats a mark they can see was applied. None of them can show it beats Anthropic's detector, because nobody outside Anthropic has one to test against yet.
The regulation forcing Anthropic's hand is specific. EU AI Act Article 50(2) requires AI-generated audio, image, video and text be marked or otherwise machine-detectable, "as far as this is technically feasible."
Anthropic's own page states a transition period applies: "The EU law includes a transition period for Anthropic models launched before August 2, 2026, and we're working to add watermarking for those models as well." Wired adds the calendar around it: new models are covered starting in August, and providers have until December to bring existing models into line.
CAW #124 covered the watermark's launch. This is the workaround week, five days after the mark went live and already contested by name.
|
For Legislators: Article 50(2)'s "as far as technically feasible" standard is the phrase to revisit; three named workarounds surfacing within a week of launch, one of them built before the feature existed, is evidence for how that standard should be written the next time it's amended.
For Investors: Anthropic's promised detection API is the checkpoint that decides whether any of this holds up; price compliance-labeling claims against a mark with public workarounds and no public way yet to verify them.
For Builders: If a compliance workflow depends on SynthID-Text surviving contact with a rewrite pass or a round-trip translation, it currently does not; wait for Anthropic's detector before shipping anything that assumes the mark holds.
For Readers: A label meant to tell you when AI wrote something broke within a week of shipping, and the people who broke it were not hiding from Anthropic. They published their names and their code.
Why it matters: An EU-mandated watermark meant to make AI text detectable had three named public workarounds within five days, and neither the workarounds nor the watermark itself can be verified against a detector Anthropic has not released.
Source: Wired, Isabella Ward, "Coders say they already found workarounds to Claude's invisible watermarks," Aug. 19, 2026, https://www.wired.com/story/coders-say-they-already-found-workarounds-to-claudes-invisible-watermarks/; Anthropic, "Claude Text Watermark," Aug. 14, 2026, https://www.anthropic.com/news/claude-text-watermark; Guillaume Meyer, watermarks-remover, github.com/guillaumemeyer/watermarks-remover.
|
. . .
SIX MONTHS TO WATCH YOU. Sam Altman told a room of interns on Aug. 10 that a ChatGPT descendant able to watch a user's screen, sit in on every meeting, and record every call could arrive within six months. He was answering a direct question from Cory Levy, founder of Z Fellows, at Internapalooza, a Silicon Valley intern event Levy co-hosts. The claim describes a product that does not exist yet.
The exchange is on video. Z Fellows posted "Sam Altman x Cory Levy at Internapalooza" to YouTube on Aug. 10, a 28-minute-49-second recording. Levy asked Altman when an always-on, context-aware ChatGPT successor could become useful enough to matter.
Altman's answer, as transcribed by Business Standard: "I think we are close to a world where you can have a descendant of ChatGPT watch your computer screen all the time, watch every meeting you're in, record every call, everything like that, have perfect context of your whole life, everything you see."
Asked to put a number on it, Altman gave one: "Some time within the next six months."
One caveat belongs here. The wording above comes from Business Standard's transcription of the video, not from OpenAI or a broadcast transcript. The video itself is confirmed: channel, date, speakers, and runtime all check out. The exact phrasing has not been independently verified against the audio.
Altman framed the capability as opt-in, built on tools a user already connects, texts, email, documents, Slack, not a system making decisions on its own. That framing matters, because it is the only guardrail attached to the claim so far.
There is no shipped product, no beta, no date more specific than "within six months," and no detail on what "watch every meeting" or "record every call" would require from a user beyond flipping a switch.
Set next to what ChatGPT for macOS actually does today, the gap is the story. Computer History logs text events, off by default, no images or sound. Altman's forecast is screen, audio, and video, always on, everything a person sees. One is shipped and limited. One is a prediction from the company's chief executive with no product behind it yet.
OpenAI is not alone in pointing this direction. Meta announced Aug. 19 that its own Mac app for its chatbot will include screen sharing. Different company, same trend line: assistants asking for a wider view of the user's screen, in the same week.
|
For Legislators: Altman's claim is a prediction, not a filing or a product spec; any statute written in response should target what ships, like Computer History's current text-only, opt-in scope, not a six-month promise with no released feature behind it yet.
For Investors: Two vendors, OpenAI and Meta, moved toward screen-level access in the same week; watch whether either ships a product before the six-month mark or whether the claim ages the way most frontier-lab timelines have this year.
For Builders: If you are building on top of ChatGPT for macOS, Computer History is the actual surface today, text events only, off by default; design around what is shipped, not what Altman described at a fireside chat.
For Readers: Nothing on your screen is being watched by ChatGPT right now unless you turned Computer History on yourself, and even then it only logs clicks and keystrokes. Altman is describing a future version, six months out by his own estimate, that would see far more.
Why it matters: OpenAI's CEO put a six-month number on a ChatGPT successor watching a user's screen, meetings, and calls full-time, a claim that outpaces what the company's own shipped macOS feature does today by every measure that counts.
Source: YouTube, Z Fellows, "Sam Altman x Cory Levy at Internapalooza," Aug. 10, 2026, https://www.youtube.com/watch?v=gXsutRiJbZI; Business Standard transcription of the same video, Aug. 20, 2026; Business Insider, Aug. 20, 2026; Times of India, Aug. 18, 2026.
|
|