Your daily AI news digest
David Robinson, who says he led the writing of the safety reports that accompanied OpenAI's major product launches, has resigned after three and a half years, making him one of the longest-tenured employees at the company. In an essay in The Atlantic, he argues the debate has to go beyond specific rules or new laws and address the culture inside AI companies. OpenAI's approach of trial and error, which it calls “iterative deployment,” “by its very nature, guarantees periodic failures,” he wrote, “and the scale of those failures is growing as systems get more capable.” He pointed to the recent breach of Hugging Face systems by OpenAI agents and continuing discoveries of rogue agents.
Robinson says frontier labs need to operate “like nuclear-power plants or busy airports, with layers of redundancy and careful, time-consuming planning,” yet in his time there he never met a colleague with experience making airplanes fly safely or reactors run without melting down. He also concedes he may have been wrong to leave: he and his colleagues were “so busy sprinting” that they rarely had time to consider big changes, which is why he now believes stronger incentives for safety have to come from outside the company. OpenAI spokesperson Drew Pusateri said the company is strengthening security in its research and testing environments, expanding work with third-party evaluators, and improving real-time monitoring.
Coding agents make it easy to spin up code that spends money, so Willison wants pay-by-usage services to cut off at a set dollar amount by default, with an opt-in checkbox for people who want to live dangerously. Soft caps that send a warning email will not do. He notes AWS launched spend limits on September 16, though only to a limited set of customers, and that Google Cloud added Spend Caps in July.
AWS CEO Matt Garman says the company has stopped using nondisclosure agreements with government agencies when it seeks approval for data centers, and argues that four common complaints about water, power prices, pollution, and community benefit are myths. TechCrunch notes that an independent watchdog blamed data centers for a 76% year-over-year price jump on America's largest grid, and that more than 100 moratoriums are under consideration.
Judge Sara Hill ruled that a Tulsa-area deputy violated a woman's Fourth Amendment rights by searching Flock's license plate database without a warrant, and suppressed the evidence that followed. The ruling sets no binding precedent, but it is one of the first to find a Flock search unconstitutional. On Friday, Senator Bernie Sanders introduced the Block Flock Act to bar federal agencies from using such readers.
Muse Gadgets is an open-source project with firmware and a Linux SDK that lets developers connect their own hardware, from e-ink displays to HDMI sticks, to Meta's Muse agent. Meta built a Muse Home Link device itself and is giving away 5,000 of them to Muse subscribers while supplies last.
Stability AI raised $76 million in late August from backers including Sony, Warner, and Universal, which also licensed their catalogs for training. It has since released three audio models and AI music-editing software, and an upcoming update will let users hum a melody or beatbox a drum pattern to steer the output.
A buyer's guide to agents you text like a person, from general assistants such as Poke, Folk, and Instinct (now valued at $10 billion after a $1 billion round) to family tools such as Fambot, Ollie, and Orbits and a travel agent called Miso. Prices run from free tiers to $100 a month.
The one OpenAI announcement that can actually make you money...
Did a 50 year old military secret just solve agent prompt injection?
DHH has gone completely off the rails...David Robinson led the writing of the safety reports that shipped alongside OpenAI's biggest launches, and he just quit saying the company's "culture is broken." His diagnosis is not a missing rule but a method: "iterative deployment," which he says "by its very nature, guarantees periodic failures" that grow as systems get more capable. The rest of today's stories keep circling the same question, which is who absorbs the cost when AI moves faster than the guardrails around it.
Read the Robinson essay next to the Willison post and they describe the same failure at different scales. A lab that learns by deploying and fixing will, in Robinson's words, suffer failures that grow with capability. A developer who lets an agent spin up paid services will, in Willison's, eventually wake to a bill that grew while they slept. Both conclude that the remedy cannot be a warning. Robinson wants incentives from outside the company; Willison wants a cap that stops the spending instead of reporting it. The common idea is a limit that holds even when the person responsible is asleep or sprinting.
The Amazon and Flock stories show what happens when a limit arrives late. Garman is now ending NDAs because secrecy turned data centers into a trust problem, and Judge Hill is drawing a constitutional line around a surveillance network that had already been built and sold widely. In both cases the infrastructure came first and the rules came after, and the public is left saying "I don't believe them." That is the cost Robinson is warning about, just paid in zoning hearings and suppressed evidence instead of in an AI incident.
The consumer agent boom runs straight through this tension. An assistant that lives in your texts, owns its own email address, and can place phone calls on your behalf is exactly the kind of system where a hard cap, a clear permission boundary, and a clear log matter. Meta is also making the software easier to put in more places, from a TV stick to a toaster. The more agents there are, the less any one person can be trusted to catch every mistake by hand.
AI is moving from a product people choose to a layer that gets installed into homes, phones, police work, and power grids, and each of those places has its own public. Data centers now face more than 100 proposed moratoriums, New York has paused permits for large ones, and one judge has called a camera network mass surveillance. That is a pattern: when a technology scales faster than public consent, consent gets enforced later by courts, legislatures, and zoning boards, usually at higher cost to the builder.
The safety debate is converging on the same conclusion from the inside. Robinson is not asking for a clever technical fix. He is asking for something closer to the regulatory machinery of aviation and nuclear power, which exists because those industries learned that voluntary caution erodes under competitive pressure. Whether a non-binding pledge signed at a meeting with President Trump counts as that machinery is doubtful. The more likely path is the one in today's other stories: practical, unglamorous limits such as spend caps, permission gates, and disclosure rules that arrive one domain at a time.