A New Smart Software Trick: Gain of Function and Killer Viruses!
September 8, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
The big AI tech outfits are rushing to tell the world, “Our models can break out of our systems. Trust us for sure, please.” I don’t know about you, but my trust is the US big AI tech outfits is fragile. Your mileage may be vary. (Enjoy the ride, please.)

Thanks, MidJourney. Good enough.
Tom’s Hardware published an interesting write up with the snappy title “AI Creates 16 New Viruses That Never Existed in Nature after Learning DNA’s Pattern from 9 Trillion Nucleotides — Experts Warn Such Applications Are Way Ahead of Necessary Guardrails.” The write up states:
Researchers say the phages can overcome bacterial resistance
I remember my advanced biology class. That’s the one in which the impressive Camile B. pounded out A+ work without looking bothered at all. It also sounds a bit like the alleged gain of function work allegedly funded by the US allegedly not really a US project in the facility not far from a popular food market in Wuhan. (I have been to Wuhan. Lots of people. Lots of alleged activity.)
The write up says:
… researchers trained a genomic AI model to design complete DNA sequences for viruses, then chemically built the results and watched some come to life. Of 285 AI-generated viral genomes tested, 16 successfully assembled into functioning viruses capable of infecting bacteria and reproducing.
Yep, we do it because we can. It’s science. Plus, don’t worry:
The scientists say the new viruses were completely harmless to humans, noting that replicating the same results in pathogens known to affect humans would be a different ballgame. They were also careful not to train the AI on any data from organisms known to affect humans. However, the study inadvertently shows that highly dangerous applications are a possibility. Experts worry that such studies are way ahead of necessary guardrails and regulations. AI has also been known to fly off the rails autonomously. An OpenAI agent recently went rogue and hacked Hugging Face.
Several observations from this dinobaby are warranted:
- Guardrails are tough to set up when one does not know exactly what one is guarding against.
- Researchers probably should be [a] supervised and [b] have a cheat sheet that lists dot points for ethical behavior
- Any technology can be used for beneficial and detrimental purposes. Just a reminder of the two-edged sword trope.
Net net: I wonder if the non US smart software can perform in a similar manner. Nah, no other LLM researchers would be this creative and innovative. Well, maybe?
Stephen E Arnold, September 7, 2026
Coincidence: Unlikely
September 7, 2026
On September 3, 2026, something interesting seems to have taken place. OpenAI, Anthropic, xAI, and Google learned that their AI systems experience a digital heart failure. The hearts began beating again, but the leadership of these firms had a headache, and I am not sure it has gone away.
Ars Technica said in “Four Major AI Models Suffer Rare Overlapping Downtime. Service Interruptions Hit ChatGPT, Claude, Grok, and Gemini Practically Simultaneously.” How about this for a velvet glove observation?
While the affected frontier models go down occasionally, having all four experience interruptions in the same short period is practically unheard of. Claude reports 99.4 percent uptime for its services over the last 90 days and last reported a similar three-hour “partial outage” on August 24. OpenAI reports 99.63 percent uptime for ChatGPT and 100 percent uptime for ChatGPT Codex in the same period. ChatGPT’s so-called “Work Mode” reported an hours-long period of “elevated latency” on August 31.
Computerworld in “ChatGPT, Claude, and Grok All Went Down at Once; Enterprises Need a Backup Plan” stated:
…on Thursday, as OpenAI’s ChatGPT, Anthropic’s Claude, and SpaceXAI’s Grok near-simultaneously, and somewhat mysteriously, experienced significant, prolonged outages.
Yep, mysterious.
Let’s stop and ask a handful of questions not addressed in these two cited write ups:
- What happened to the cloud providers and their systems? Don’t infrastructure operators have smart software tuned to identify and fail over immediately? Everyone’s favorite BAIT (big AI tech company) outfit not only owns its vertical stack, the firm owns a couple of state-of-the-art cyber security systems. What went wrong in the engineering, design, and implementation of these smart defense mechanisms? I think I know the answer. A lawyer will help craft a plausible deniability statement or tell the clients with the problematic system, “Keep you lip zipped.”
- What about the tech bloggers and YouTube experts? Where are those deep dives into the technical issues that caused for BAITs to go south at approximately the same time? (Is it possible that analyses have been posted and remain unindexed in order to convert the story into the information equivalent of a squirrel dashing into a roadway only to be squished by a Ford F-150’s front tire?)
- What are the BAIT ourfits saying? Yeah, not much, right? Does the cat have your PR departments tongue?
I haven’t been in a statistics class in more than half a century. The idea that four unrelated companies’ smart software glitches at about the same time on the same day seems unlikely. Is there an undisclosed or previously unknown dependency sparking this dumpster fire? Did an outside actor send a signal to test the efficacy of its “kill US AI services” switch? I can think of a couple of countries who might have explored developing such a software device.
I used the free pen I snagged at the Staunton, Virginia, Comfort24 Hotel. I roughed out some numbers. I recast these into one of my analogies. For four unrelated AI firms to experience an outage at roughly the same time on the same day of the week is like a public park with four kid-oriented merry go rounds rotating 24 hours a day. Each merry go rounds dumps kids off. The chance that I could look at the four rotating merry go rounds and see each of the four dumping a kid simultaneously is about one in 6,000,000. For me, the coincidence is sufficiently improbable to say, “Yo, we have a shared dependency or we have a bad actor testing a kill switch.”
In my typical dinobaby fashion, I wish to offer a few observations. [a] Sheer chance is unlikely to produce this type of event. [b] A bad actor working from a position with tools that permits a kill actio to occur seems worth considering. [c] The baloney about security and reliability needs a footnote to two to allay the concerns of suspicious individuals like me.
Net net: We just received a signal. Who will stand up and say, “Okay, folks this is what really happened.” Tip: Don’t hold your breath.
Stephen E Arnold, September 7, 2026
A Ratonalizing Goat: Durov Explains Life
September 3, 2026
We spotted a very Web3 presentation of Pavel Durov’s view of himself, Telegram, and his minor scrape in France. We provide a snapshot of this bleat in “GOAT Talk: Why the Police Pursue Telegram.” The uncertainty about Durov’s trial in France, the near miss in Alpha Compute’s Nasdaq delisting, and the somewhat disappointing “value” of the GRAM coin dog the Telegram operation. The story appears on our Telegram Notes blog.
Stephen E Arnold, September 3, 2026
AI-Yi-AI: We Know Where This Is Heading or Gimme Some Moore
August 28, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
Every once in a while I read an output from Semi Analysis (please, don’t confuse this consulting firm with Artificial Analysis). I have learned that my blood pressure ticks up, and I need a break to water the flowers. “Are Open Models Catching Up?” The assumptions underlying the write up, in my opinion as an official dinobaby, are:
Assumption 1: The US is the world’s leader in proprietary closed (proprietary) frontier models
Assumption 2: Open models deliver results on benchmark tests that show the frontier faces an encroaching suburbia of smart software
Assumption 3: Assume that the US will be the big winner in opening up the Wild West frontier of artificial intelligence
Assumption 4: Writing blue-chip thinking and giving it away for free will generate sales leads
Assumption 5: Open models have to catch up. (Spoiler: No, open models only have to be good enough, available, and cheap.)
You and Semi Analysis won’t agree, but just for fun, suspend your doubt, and let’s think about what is happening in the “if we build it, they will come” world of smart software.
The write up says:
The past two months have been a breakout period for open source AI. Yes, there was the “Deepseek moment” back in January 2025, but no one actually used R1 to do any economically valuable work. In contrast, models like GLM 5.3 and Kimi K3 are genuinely capable of many of the same coding and agentic tasks that rocketed Anthropic to $65B+ ARR. Unlike others who inflated ARR, our figures were much closer to reality.
Let’s accept the statement about “no one actually used R1 to do any economically valuable work” and “our figures were much closer to reality.”
The “killer chart” is this one:

Sure, it is black and hard to read. The idea the chart is supposed to make is that Semi Analysis has discovered a chart that someday soon will look like this one from Wikipedia:

By golly, Semi Analysis and “their figures were much closer to reality” appears to suggest that open AI models are improving in the same way chips were. The swizzle in this some Moore law is that the open models are improving from “below.” The idea is that open models are catching up with the frontier pioneers’ trailblazing innovations.
But wait! The future of smart software is agentic. That means that new players will enter the fray and use the existing models as an installed base of capabilities. Agents will become the next big thing. Is this a new insight? My answer: Nope. Agents are the next big thing. If the Semi Analysis-type thinkers take a look at what outfits like Alibaba have been doing for months, the progress is rapid. Depending upon what a user wants to do, one can look at Alibaba, its deal with Google, and the distributed innovation method in use. The conclusion could be phrased this way: “Let the open models catch up. We will use wrapper software and agents to create a different type of system and user interaction method.”
Why is this important? In my upcoming Ciffer lecture about the future of online crime, I point out:
- Open tools and systems are good enough
- Improvement in these tools and systems allow bureaucracy-free actors to select, test, discard, learn, and use what works
- Cyber security professionals have to figure out what has happened, pinpoint the agent, and the figure out how to prevent the action from taking place again.
Bad actors have been tapping LLM capabilities since the systems became available. This means that the assertion the early open models were not economically viable. Sorry, Semi Analysis, your semi analysis is dead wrong. You are looking at the corporate sector which is still trying to figure out a use case that delivers a payoff. The open models work just fine for the ransomware folks, the data suckers, and the systemic disruption people.
What’s the future look like? Unlike Semi Analysis I don’t have a big orange button so you can buy the answer to the question. I will go through what’s coming from within the US and from non-US players at the Ciffer event. Let me hint at what’s happening: Frontier models are struggling to improve. Open models are good enough. Economic evidence that open models work is available. But that’s not the story. The nascent attempt to create a Moore’s Law for AI has to look beyond what BAIT outfits are doing (BAIT is my lingo for big AI tech and “ai tech” rhymes with “train wreck”).
Stephen E Arnold, August 28, 2026
Smart Software with Grudges
August 26, 2026
Ever hear that old Broadway show tune “Anything You Can Do I Can Do Better” from Annie Get Your Gun? That’s what we bet AI agents were singing after we read this story from Yahoo Canada: “AI Agents Tried To Sabotage And Disable Each Other When Given The Same Task, Anthropic Said.” Anthropic published new research that showed what happened when two AI agents were given the same task. In short, they weren’t team players.
The experiment was simple: give two agents a software engineering task with contradictory objectives and see what happens. Chaos ensued:
“‘All of the models we tested quickly assumed that others were purposefully impeding their work, and began to sabotage others while protecting their own contributions,’ Anthropic wrote. ‘In fact, they sabotaged others with increasingly aggressive, self-replicating malware.’ For example, they tried to disable each other’s accounts, wrote scripts that found and killed competing processes, and deployed malicious code disguised as belonging to another agent, the lab wrote.”
The most combative models were Opus 4.6 and Sonnet 4.6, because they settled their conflicts with more force 60% of the time. The agents did try to make parlay, however:
“‘In many of these successful episodes, they write commit messages or markdown files apologizing for malicious behavior and coordinate a truce;” it wrote. ;They clean up their malicious code, clarify the nature of the conflict, and ask for a human to intervene.’ The lab concluded that ‘coordination doesn’t naturally emerge from stronger intelligence’ and that work is needed to create environments that exert social pressures on agents to align with one another.”
AI agents warring with each other comes at a time when they are proving their ability to go rogue and perform autonomous, malicious actions. These agents are only doing what they were programmed to do and following humanity’s nature to fight rather than seek peace. Anthropic is doing a stand up job replicating human intelligence. We wonder what show tune the AI agents will be humming next time?
Whitney Grace, August 26, 2026
China: AI Flooding and Abetting Bad Actors
August 17, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
Hugging Face cranked out a report based on the traffic and metrics within its AI amusement park. The data were not entertaining in my point of view. You can work through the fancy graphics and wordsmithing in “State of Open Models: Summer 2026 Observations.” News services focused on a couple of what in their opinion were the marque findings; for example:
- Alibaba’s open-weight models tallied more than three billion downloads since February 2026
- Google garnered 418 million downloads in the same period
- Meta snagged 227 million in the last six months.
Are the numbers to be trusted. Sue, by some. The important part is that if these data are close enough for horseshoes, there is a much larger message in the Hugging Face report. If you like to think that the US has whipped the AI challengers into meek submission, stop reading this blog post.

Thanks, Midjourney. Good enough.
Here’s my take.
First, Chinese AI vendors are pushing out good models without too many restrictions. The Middle Kingdom is making is possible for developers anywhere in the world to create AI products and services built on Chinese software. At this time, the US leads in the design and sale of AI hardware. But the question the write ups don’t put front and center is, “Okay, but for how long?” My answer is, “Probably less time than the frontier investor spreadsheet jockeys guess-timated.” Where will the US “hardware” be made if the South Korea and Taiwan centric factories experience an issue?
Second, the primary beneficiaries in my opinion are the bad actors. Even the bad actor with minimal computer skills and a two year old mobile phone can set up and run a modest phishing scam. Governments, companies, and trade associations have to be more careful because an AI mistake can create unwanted problems. Yep, I am thinking about those allegedly uncontrolled events at OpenAI and other firms. Is this PR or a problem? Bad actors don’t care. If one is a bad actor, the friction that legitimate entities encounter is of less or no concern. Bad actors loved Telegram bots. The party is more vibrant with AI and its agentic loops and whirls.
So what?
My view is that the flooding tactic is designed to accelerate widening the cracks in the American smart software structures. An added benefit is that bad actors can use Chinese smart software to exploit the US financial system. Undermining the dominance of the dollar is a bonus from some actors’ point of view.
What’s next? I think the Chinese vendors will follow the tactical line authorized by their funding sources and “regulators.” I think 2026 may be a pivotal time for the US AI leaders. Several of the companies are struggling with their organizational set up for AI. A couple of the big players are cutting back on their “spend whatever it takes” to build infrastructure. Others are capturing headlines by saying, “Darn it. We can’t control this stuff.” Toss in some of the global geo-political action, and we have a very interest near term horizon approach by mid 2027.
Net net: The Chinese AI flood is not accident. The US is simply in a defensive posture. The immediate winners are the bad actors. Aren’t you glad you aren’t a dinobaby like me?
Stephen E Arnold, August 17, 2026
Telegram: It Is Not Yet the Ides of August. Chill Out, Crusaders of Freedom
August 5, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
I posted a short item about Pavel Durov’s joust with Apple. If you are curious, you can read the write up on my Telegram Notes information page. (No begging for dollars, no advertisements, and no sales pitch. Quite a novelty these days, right?)
In this short post, I want to focus on Pavel Durov’s analysis of what happened with that kiddo pix takedown thing with the online curation king of the Apple orchard.
“Apple Pulls Telegram After Illegal Content Appears in Public Group” summarizes what happened. The write up also includes some comments offered by the GOAT himself. (Pavel Durov is allegedly the greatest of all time Russian techno-entrepreneurs. Some might argue that Oskar Hartmann deserves that moniker, but he is German by birth. Bummer.)
Thanks, MidJourney. A little crude but good enough.
The cited article quotes Mr. Durov, who awaits trial in France on a number of serious crime allegations, as cutting to the core of the Apple problem:
These extortionists use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger the removal of legitimate communities whose owners refused to pay them.
Okay, an extortionist or multiple extortionists caused the Apple problem.
He allegedly added:
Extortionists have found a way to manipulate Apple into overreacting. Apple removed Telegram from the App Store before contacting us.
Poor Apple. The firm’s red delicious systems suffered a problem. Bad Apple. Bad extortionists.
Am I to conclude that extortionists and the Granny Smith processes at Apple were at fault? Has Telegram emerged from this gala as the red delicious service? (Australian and Russian regulators by this line of reasoning have misinterpreted Telegram and those countries allegations that Telegram facilitates terrorist content are as useless as the original “Macintosh” Apple computer.
I want to wrap up this short Telegram item because I can’t think of a way to use Fuji, Honeycrisp, Cripps Pink Lady, and Braeburn in this item. I know the Apple varieties provides a lame trope, but, hey, Pavel Durov points to extortionists which is a reference slightly less germane than my working in the McIntosh. Too bad the Apple computer did not emulate the fruit’s name.
Stephen E Arnold, August 5, 2026
Word Worms Fly with a Trusted, Reliable, Capable, and Secure Copilot
August 4, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
I spotted an interesting statement attributed to Microsoft’s Satya Nadella (the man who sparked AI’s lift off to craziness). According to Futurism, Mr. Nadella said:
Any firm that doesn’t have this control, I will claim will not remain a firm because you’ve essentially outsourced your thinking,”
What’s “this control”? Based on the information in the write up, the idea is that each business should train and tune its own open weight model.
Okay, that sounds good. Each person should put on his own shoes. No big deal. Microsoft appears to route its AI “investments” into its Azure cloud business. As a result, the investments morph into a nice looking financial report. Meta on the other hand just invests and looks a bit like a five year old painting the living room wall and smearing paint on the furniture. “Look, Mommie, it’s good.”
No.
Microsoft is a very large big AI tech company now. Thus, it has numerous business units. Within the organization are the stalwarts driving Copilot AI forward. Somewhere in the hallways are people who were charged with security after what I call the SolarWinds flare up. There are the layoffs, and the eGame issue.

Midjourney, good enough. Does the worm know the Copilot does not respond quickly or at all when there is a security matter? Of course not. The creature is a worm.
Microsoft leadership wants to be a leader. But can it do AI and security within its own applications like Word?
I read “Word Worm Crawls into Copilot, Spreads Chaos.” The article has a snappy sub title too: Researcher says months of coordination with Microsoft have yet to produce a robust mitigation.
The write up says:
The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult.
Tricky? The method is similar to the old SEO trick of hiding text in a Web page by making it the color of the page; e.g., white if the Web page were white or tan if the Web page were tan. My recollection is that the Google figured out this lame hack years ago.
But Microsoft? The write up quotes the researcher who noticed this simple ploy:
“The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.”
I assume that the Softies are just busy with PR, marketing, and telling the customers to be responsible for their models. That is very good advice.
Perhaps the first step is to avoid Copilot in Word or Copilot period?
Stephen E Arnold, August 4, 2026
Anthropic: Three Times Better, Three Times Worse, or Three Times the PR?
August 3, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
The big AI tech companies (BAITs in my lingo) really really want to one of the Silicon Valley AI Founders Club to win the global AI war. In the confines of the club, these folks laugh and joke. Some went to school together; some worked together at less hopeful ventures; some were leadership in just brontosaurian tech outfits, and some were really close. (Use your imagination, please.)
But in the scrappy, nasty, political, and often corrupt marketplace — Each company’s big dog wants to rule the pack. Get out of line and an animal nastier than Jack London’s fictional Buck will rip out the throat of the animal that does not get with the program. With this tasteful image in mind, let’s address the question, “Three Times Better, Three Times Worse, or Three Times the PR?”
I read a number of the write ups reporting that Anthropic’s smart software got frisky and sneaked out the bedroom window to toilet paper the trees of neighbors it did not like. When you read “Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,” you will probably disagree with me. Trust me, as a dinobaby, I don’t care.
What’s with this BAIT equivalent of Galileo’s telling the authorities, “Fellows, I was wrong. I won’t do it again. I promise”? And what happened, the intrepid genius and misunderstood tech bro with a gown and a weird collar kept on doing mathy stuff. My view is — let me say — skeptical.

MidJourney that’s quite a stake. Good enough, however.
The mea culpa states:
After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.
Two factoids jump out at me. [a] Those Anthropic wizards have demonstrated that their smart software with human oversight and guidance of some sort repeated a process more than 140,000 times. If one is a bad actor engaged in figuring out what an AI powered fraud service can do, the number of three success in 140,000 runs provides a useful benchmark and suggests go for a big time fraud play. And [b] a human had to figure out where the unauthorized penetrations took place. For an online cyber criminal, the statement makes clear that cyber fraud investigators are going to have their hands full figuring where, how, and what happened. Hey, nice work Anthropic.
There are other equally interesting statements in the mea culpa. I don’t have the appetite to deconstruct this document. I want to highlight this single sentence from the recantation:
These are three isolated incidents and were not part of a controlled, experimental comparison.
I love the word “isolated.” I interpreted it to mean, “Yo, these behaviors do not form a pattern. No way, José.” I like the negative “not part of a controlled, experimental comparison.” I interpreted this to mean, “Yeah, who knew our super powerful smart software would escape and make clear to every bad actor interested in taking advantage of the wonders of Anthropic software. Hey, don’t do this at home. Okay?”
Sure. No bad actor will pay any attention to this effort to be an ethical, responsible professional outfit.
Now we come to my dinobaby answers to “Three Times Better, Three Times Worse, or Three Times the PR?” Let’s take them in order:
- Better? No, the difference between the most advanced models is narrow. Same content base. Same “attention is all you need bias.” Same type of developers. Same as in some of those folks in the mythical Silicon Valley AI Founders Club. (Does anyone want to share a sleeping bag on our next camp out?)
- Worse? No, once again the firms in the BAIT zone are more alike than different. I am not going to try and run down how senior AI wizards move from one BAIT to another. Some go off on their own and then build on BAIT innovations. These outfits are cut from the same cloth, operate with a geo-technical link, and operate as a large, dysfunctional family. (Is anyone related to … no, I won’t name a crime family?)
- 3X PR. Yes. OpenAI revealed one break and now seems to suggest that its AI was bad more often. But Anthropic is putting the “three” out there. My take is that this is PR like the other actions of the firm’s leadership. Attention is what this outfit needs.
Net net: I expect more revelations. Buzz is good and the top dog at Anthropic does not seem to be concerned about the Michael Cimino effect of $20,000 roller skates on his funding sources. And Galileo? He did not become a grilled hot dog. He had to work from home. That suggests the BAIT outfits are not going to change course until one dog wins. Which will be the digital Buck in The Call of the Wild.
Stephen E Arnold, August 3, 2026
Craft Prompts Carefully or You May Get a Chance to Make New Friends in Jail
July 31, 2026
Let’s not lie. People use ChatGPT for everything, including the big no-no’s of the Internet: murder, suicide, and kiddo pix. It’s undesirable but people do what they want when they’re alone. One particular person went a little too far according to Forbes article: “OpenAI Ordered to Unmask ChatGPT Writer Behind 2 Prompts.” The story goes that federal agents were having trouble uncovering the underbelly of a child exploitation ring. Then one of the bad actors decided to use ChatGPT:
“In the first known federal search warrant asking OpenAI for user data, reviewed by Forbes after it was unsealed in Maine last week, Homeland Security Investigations revealed it had been chatting with the administrator in an undercover capacity on the child exploitation site when the suspect noted they’d been using ChatGPT.”
What is even more startling is how innocuous the prompts were that uncovered the bad actor. They read more like fan fiction than something a child pornographer would request ChatGPT to spit out:
“The suspect then disclosed some prompts and responses they had received, detailing an apparently innocuous discussion that began with, “What would happen if Sherlock Holmes met Q from Star Trek?” In another discussion, the suspect said they’d received a response from ChatGPT for an unspecified request about a 200,000-word poem, receiving in response “a sample excerpt of a humorous, Trump-style poem about his love for the Village People’s Y.M.C.A., written in that over-the-top, self-aggrandizing, stream-of-consciousness style he’s known for.” They then copied and pasted that poem. The government ordered OpenAI to provide various kinds of information on the person who entered the prompts, including details of other conversations they’d had with ChatGPT, names and addresses associated with the relevant accounts, as well as any payment data.”
This shows how American law enforcement can use ChatGPT and other AI agents to monitor criminal activity, but as well as everyone. Search engines were ordered in the past to hand over user information authorities, but this marks what may be a first for AI agents. There was still some anonymity behind the bad actor. The government didn’t force OpenAI to reveal the person’s identity. Instead cyber investigators gathered chat logs and identified who the bad actor.
Whitney Grace, July 31, 2026

