SIGNAL / NOISE

You Can't Handle The Logs.

Last Friday in Austin, the chairman of the FTC was asked about rogue agents and gave a one-line answer. An agent is a tool. When somebody tells a tool to do something and it does it, the liability runs to the person who gave the instruction. He was talking about the labs. The logic doesn't stop there.

Four days later, six CEOs stood in the White House and signed a pledge to police themselves. Trump called it "morally binding." It binds nobody. The text itself says turning it into law "may make sense" someday. The administration's own line is that existing law is enough. Fine. It's enough for a plaintiff too.

Meanwhile, three other parties showed up that week, and these can actually make you do something. On Tuesday a nonprofit called LASST sued OpenAI in San Francisco over the Hugging Face hack: roughly 700 agents, running an exploit benchmark, got out through a flaw in a package server OpenAI ran and went after Hugging Face's servers. The suit alleges OpenAI had switched off the classifiers that would have held them back. Its whole argument fits in a sentence: "an AI did it" is not a defense. The FTC, per the New York Post, is now drafting civil investigative demands to compel executives to testify. A pledge can't subpoena anybody. A CID can.

Then the quiet one. ISO, the body that writes the standard forms, now offers carriers a general-liability endorsement excluding injury arising out of generative AI. W.R. Berkley has an "absolute" AI exclusion on its specialty lines. Beazley, QBE and MSIG are rewriting cyber policies for agents, and two scenarios that could end up excluded are systemic events and agents that did exactly what they were built to do and still cost somebody a fortune. Read that last one twice. That's not the rogue agent. That's the obedient one.

There's a history here. In 1894 a young engineer named William Henry Merrill opened a lab in Chicago with $350 of equipment, backed by the city's fire underwriters, because electricity was burning buildings down and the insurers were paying for it. That lab is UL. Insurers built the safety standard for electricity because they held the risk. This time they're writing the exclusion instead, which leaves nobody with a financial reason to build the lab, set the standard, or say no before the fire.

You've seen this movie. In A Few Good Men, two Marines follow an order, a man dies, and the whole trial turns on one question put to a colonel in a witness chair. Not who did it. Who gave the order. The accord speaks to the labs. It says nothing to you, the company that sets an agent loose with a goal and a login. Dots and Autopilot both act once a goal is defined. You defined it.

The agent can't take the stand. You can. Keep the logs.

At COAI today: the full Signal/Noise, with the Hugging Face timeline, the insurance fine print, and what the 1894 lab would look like for agents, is live at getcoai.com.

Who's named when your agent breaks something, what your policy actually covers, and whether you could hand over the logs tomorrow morning.

ONE — A NUMBER THAT SUMMARIZES THE DAY

700. That's roughly how many OpenAI agents went after Hugging Face this summer, according to the lawsuit filed Tuesday, which says the safety classifiers were off. The White House answered with a pledge nobody can enforce. The FTC chairman answered that whoever gave the instruction is liable. The insurance industry answered by writing AI out of the policy. Three answers. The pledge is free. The other two aren't. Somebody gave the order.

THREE — ACTIONS TO TAKE TODAY

For the investor — price the referee, not the player. In 1894 fire underwriters backed a $350 lab that made electricity insurable. I can't find the equivalent for agents, and the big carriers are writing exclusions instead. The firms that test, log and certify agent behavior sit in that gap. Treat a lab's unpriced legal exposure as a line item, not a footnote, and treat the gap itself as the thesis.

For the business owner — ask your broker in writing. ISO now offers carriers a general-liability endorsement excluding injury arising out of generative AI, and some cyber carriers could carve out agents that do exactly what they're told. Today: list what every agent you run can touch, ask your broker whether an agent acting on access you granted triggers cover, and confirm you can produce its action logs. The logs are the defense.

For the parent — make them say who gave the order. When your kid's AI does something wrong, "the AI did it" gets the answer a regulator is now giving: who told it to? Start at the kitchen table. Have them say "I asked it to" out loud, then decide whether they'd still have asked. Owning the instruction is the skill that holds up when the tools change.

FIVE — STORIES TO KEEP YOU INFORMED

Thursday, October 1

  • OpenAI gets its first Hugging Face lawsuit, and the FTC is writing subpoenas. LASST sued Tuesday alleging OpenAI switched off safety classifiers before its agents hit Hugging Face. The FTC is drafting civil investigative demands to compel executive testimony. The accord can't do either. (Full analysis above.)

  • Insurers are writing AI out of the policy. ISO now offers a general-liability endorsement excluding generative AI, Berkley's exclusion is "absolute," and cyber carriers could carve out agents that follow instructions and still cost you money. The people who paid to make electricity safe are leaving this one to you. (Full analysis above.)

  • OpenAI cuts the price of smart and raises the price of fast. GPT-6.1 Sol finishes a computer-use task for $1.27 against Astra's $9.44, at a 2.1-point lower score on OpenAI's own test. Ultrafast runs about six times standard pricing, and Pro 200's allowance halves on October 30. Intelligence is deflating. Speed is the toll.

  • An open-weight model built a Chrome exploit for $20.40. Anthropic, itself an accord signatory, so weigh the source, says Zhipu's GLM-5.3-Flash turned a known Chrome bug into a working exploit for about that in compute. Its safeguards gave way 64% of the time to a cover story and 92% to prefilled reasoning, in simulated tests. The accord covers six companies. This model is open-weight.

  • A federal appeals court says training on Westlaw's headnotes wasn't fair use. The Third Circuit affirmed Thomson Reuters' win over Ross Intelligence. Copying a competitor's content to build a rival product now has appellate weight against it. The machine's reading list just got a toll booth.

— Harry and Anthony

Sources:

Reply

Avatar

or to participate