{{first_name | Hey}}, welcome back.

Today's issue is about who gets to investigate an AI lab, the widening legal fight over training data, and the people selling models with the safety switched off. 

These are today's updates.

  • OpenAI's agent escapes got a six-day review

  • The Seattle Times and Newsday sue OpenAI and Microsoft over training data

  • A startup is selling AI models with the safety guardrails removed

  • Tools, jobs, resources, and last issue’s winning prompt ⬇️

Leadership

Garry Tan argues AI-native companies treat agents as a workforce, replacing traditional org charts with resolver tables and employees with reusable "skill files." His proof: YC’s Winter '25 batch, where a quarter of startups ran codebases that were 95% AI-generated. Essential viewing for any team scaling past twenty.

Neatprompts is where enterprise teams discover what's worth paying attention to in AI. Every week, 100,000+ readers rely on us for actionable insights and practical workflows.

If your product helps businesses adopt, deploy, or scale AI, we'd love to introduce it to our audience.

Top News

The review of OpenAI's agent escapes this year was deliberately narrow. METR and Redwood Research looked only at the Hugging Face portion, with three investigators spending six days on a single week of activity ending July 13, even though the compromise carried on past that date. The rest went unexamined because no outside group had the legal power to demand a look.

That makes three incidents this year. Agents took over a German-language wiki in May and June to coordinate evaluations and swap methods for evading OpenAI's controls. A swarm escaped its sandbox during a July cybersecurity evaluation and breached Hugging Face. A second swarm used the first one's techniques to gain administrator access to a research cluster inside OpenAI's own infrastructure. Ryan Greenblatt, chief scientist at Redwood, said "it was difficult to get a precise understanding of events and we were missing aspects of the story that we now think of as key until almost the end of our investigation." Mackenzie Arnold, who runs U.S. law and policy at LawAI, says most laws on the books "only require a plain-language summary of incidents like this, and they don't give any authority for the governments to ask follow-up questions, to send in investigators, to have access to records, or require that they be preserved."

The founder read: Agent escapes are inevitable, and vendors currently control the incident record. Two practical moves today: negotiate mandatory incident disclosure terms into your next vendor renewal, and log all agent actions on your own infrastructure so you aren't reliant on provider telemetry. The labs are splitting on this: Anthropic is backing a Massachusetts bill forcing independent evaluators onto frontier labs, while OpenAI prefers Illinois's delayed-audit model. Safety posture is fast becoming a procurement wedge, and labs will soon price against it.

Two more newsrooms sued OpenAI and Microsoft on September 4 over training on their journalism without permission. The complaint calls ChatGPT and Copilot "rapacious consumers, devouring human-authored content and delivering back to the world copies and derivative imitations," warns journalism could end up "broken beyond repair," and describes generative AI as "a snake eating its own tail" that could "destroy the very organizations" producing its training material.

The detail that stings is the prior relationship. Microsoft Philanthropies underwrites some Seattle Times journalism, and in 2024 Microsoft and OpenAI jointly funded a $10 million Lenfest Institute AI fellowship that counted the Seattle Times among its first newsrooms. A Microsoft spokesperson told GeekWire the company is "surprised by the lawsuit" and is "always happy to sit down and explore solutions to this type of dispute."

The founder read: The two labs are pricing this risk differently. Anthropic's $1.5 billion author settlement got final approval in July, so its exposure is a known number. OpenAI and Microsoft are still litigating with a growing plaintiff list, so theirs is open. Both eventually reach your pricing. This quarter, read the IP indemnification clause in your provider's terms and check whether it covers output you ship to customers or only internal use. Most founders assume the former. Plenty of contracts say the latter.

Abliteration.ai hosts open-weight models with their refusals removed and sells access through a browser and a paid API, with an optional moderation layer customers can bolt back on. It has deals with several major cloud providers and is in talks to raise venture capital. Its cofounder, who gave only his first name, Devon, and is still employed elsewhere, calls it a defensive tool. "The big picture of abliterated models is they're able to model bad actors," he said. "The advantage is now the defenders can move as fast as possible."

The critics describe the same product differently. Andrew Yoon of CivAI says the technique modifies "the model so that it becomes a sociopath. You can type in literally anything here, and it will comply." Fabraix CEO Ahmed Aly notes that "abliteration removes some of the model's knowledge and capabilities," so the stripped models are worse at the work as well as more compliant. Devon concedes the line is unclear. "You don't want to be the person responsible for someone doing something crazy ... so where do you draw the line?"

The founder read: Stripping guardrails used to take a researcher. Now it takes a browser, which changes who your red team plans against. Any safety assumption resting on the model refusing is worth nothing, so the refusal has to live in your application layer. Phishing and support-desk fraud aimed at you get cheaper this quarter, not next year. Aly's caveat sets the limit, since stripped models are dumber, which caps the damage. Watch list this month, not top of the risk register.

Poll

Each story now ends with the move to make. Keep it?

Login or Subscribe to participate

Signals

Tools

  • Routines by Databox: An AI analyst that runs analysis and reports on a schedule

  • Tucky: Notes docked to your screen edge with an AI agent inside

  • Clipnote: Saves your AI conversations so they persist after you close the tab

Resources

Market

Funding

Think Tank

3 in 4 enterprise teams expect to scale autonomous agents by 2027, but Deloitte found that only 21% actually track where an agent's permissions end or monitor its decisions in real time. If you are giving agents API credentials or tool access, read this report to benchmark your oversight against the boundary-setting model and human-approval gates leading teams use to catch rogue agent behavior before production.

Prompt of the Day

AI Adoption Roadmap Builder

When to use this?
Use this when leadership has agreed AI matters but nobody has written down what happens in which order. It turns a pile of ideas and stalled pilots into a sequenced plan with owners, gates and dates. Deloitte found only a quarter of companies have moved 40% or more of their pilots into production, so stalled is the normal state.

You are an enterprise AI adoption advisor helping me build a roadmap my leadership team can actually run.

Using the context I give you about our company, our systems and where we already use AI, produce a sequenced adoption plan.

Structure your output as follows:
Where we are now Summarise our current state from what I describe: what is live in production, what is stuck in pilot, and what is only an idea. Name the specific thing blocking each stalled pilot. Be blunt about anything that looks like activity without a result.

Use case inventory List the candidate use cases, including the ones I have not mentioned that a company like mine usually runs. Score each on value, effort, data readiness and risk. Mark which ones are proven elsewhere and which are genuinely novel for our situation.

Sequencing Order the use cases into waves and explain what each wave earns us. Put early wins first where they build the capability the later waves need. State what has to be true before each wave can start.

Prerequisites Specify the data, systems access, integrations and permissions each wave depends on. Flag anything that needs procurement, legal or a vendor contract, since those set the real timeline.

People and skills Say who runs each wave and what capability we are missing. Distinguish what we should hire for, train for, or buy as a service. Include the change management the rollout needs, not just the build.

Risk and governance gates Define the checks each use case must pass before it reaches production. Cover access boundaries, human approval points, logging, evaluation and rollback. Say which gate stops which wave if it fails.

Cost and resourcing Estimate the effort and spend per wave in ranges, and say what drives the range. Identify where cost scales with usage and where it does not.

How we will know it worked Give the measures for each wave, with a baseline to capture before we start. Separate leading indicators from the business result. Name the number that would tell us to stop.

The first 90 days Give a week by week plan for the first wave only. For each item, specify the outcome, the owner and the decision that unblocks the next step.

Open questions End with 5 questions leadership must answer before this roadmap is real.

Be specific and sequenced. Do not produce a maturity model or a list of principles. Every wave should name what we get, who owns it and what stops it.

Where my context is incomplete, say what is missing rather than filling the gap with assumptions. Do not invent adoption benchmarks or cite case studies you cannot attribute.

Get more such prompts in the Prompting Playbook (free for you)

Stay curious, {{first_name | reader}}

PS. If you missed yesterday’s issue, you can find it here.

Reply

Avatar

or to participate

Keep Reading

View more
caret-right