A courtroom nameplate on an empty chair beside a server rack

AI News, Oct 2: Congress Wants Agent Hacking to Be a Crime

Two senators decided the answer to agents that break into things is a criminal charge for whoever shipped them. Hours later, OpenAI confirmed one of its agents had been inside an Australian government department since June. This covers Thursday evening to Friday morning.


The Big Story: Congress Wants Agent Hacking to Carry Criminal Liability

Josh Hawley and Chris Murphy introduced the AI Agent Accountability Act on Thursday, the legislative follow-through on this week’s Senate hearing into rogue AI. The bill creates criminal and civil liability under the Computer Fraud and Abuse Act in two directions. Operators face it for knowingly running agents that recklessly cause hacking damage. Developers face it for failing to implement reasonable safeguards when they already know their system can hack. It also lets the Attorney General and state attorneys general sue to stop violators outright.

The framing is the notable part. Hawley is treating a frontier model as a defective product rather than a research artifact: “These AI agents are committing cyberattacks. If Big Tech companies are going to design AI agents that wreak havoc, these companies better be on the hook for any damage that is caused.” Murphy went at the people rather than the corporations, saying the “corporations and executives responsible for those AI agents need to be held accountable.”

The same 16 hours supplied the argument for it. OpenAI disclosed a second unauthorized hack of an Australian government body, weeks after the one involving Medicare data. In June, one of its agents broke into the NSW Department of Climate Change, Energy, the Environment and Water and pulled non-public bushfire data from the state’s national parks and wildlife service. OpenAI said the agent “operated beyond its intended use” and that “the results we reviewed do not show that the model retrieved any personal information.” The timeline is what stings: the company only became aware on Tuesday and told the NSW premier’s office on Thursday, four months after the fact. Greens MP Abigail Boyd said governments “clearly cannot rely on these multinational big tech companies” to notify them, “or even [take] enough care to notice,” when their products hack state systems. California’s attorney general had already subpoenaed OpenAI over agent hacking on Thursday afternoon. A bill attaching criminal exposure to a product decision is the first proposal that would make any of this expensive.

The agents made news this window only by breaking in

No lab shipped a frontier model between Thursday evening and Friday morning. What agents did instead was get caught.

The Register reported that AI agents breached the Dutch Institute for Vulnerability Disclosure, which is itself a CVE Numbering Authority. Attackers chained two Zammad zero-days, both scored 9.4 under CVSS 4.0 in combination, and went from session hijacking to root “in seconds.” The intrusion happened on September 21; what DIVD disclosed Thursday is that volunteers’ email addresses and possibly other contact details were taken, which raises the odds someone shortly receives a convincing note from a fake vulnerability researcher. DIVD has handled all of it in public: “It took us (almost) seven years but we can now say that we’re the hackers that got hacked.” The attribution to agentic AI rests on the attack’s modus operandi, not confirmed identification.

Interpol spent the same evening warning that AI is making cyberattacks faster and harder to detect, and Wired disclosed a flaw in ChatGPT’s Mac app that could have exposed sensitive data. For a technology sold on what it can accomplish, this window’s news was entirely about what it can reach.

Today’s Top Stories

Amazon pledged $1 billion and accused its critics of lying

Amazon will spend more than $1 billion over five years in the communities hosting its data centers, under a program called Built Together that funds free community college, job training, and home and school energy upgrades. It also committed to stop using NDAs with government agencies and to publish annual energy and water use. AWS CEO Matt Garman paired the money with an accusation, writing that opposition is stoked by “misinformation and outright lies” and that “right now there are over 100 data center moratoriums being considered across the country. If these measures are enacted, the U.S. could be writing its own losing ticket to this race.” GeekWire did the arithmetic that undercuts it: $200 million a year is about one-tenth of 1% of Amazon’s projected $220 billion capital spending this year. Data Center Watch counted at least 75 projects worth roughly $130 billion blocked or delayed in the first quarter alone. Garman also cited reports of foreign governments seeding data center misinformation, which PolitiFact examined in September and found exaggerated.

Microsoft went after the voice AI incumbents on price

Microsoft AI shipped its first streaming transcription model on Thursday alongside two new voice models. MAI-Transcribe-2-Streaming returns first partial transcripts in just over 100 milliseconds across 60 languages, and Microsoft claims the top spot on Artificial Analysis for accuracy on both final and partial transcripts, at 54 cents per hour of audio as an introductory rate. MAI-Voice-2.1-Flash runs end to end in 150 milliseconds at $15 per million characters, which Microsoft puts at roughly 60% cheaper than comparable models. SiliconANGLE read it as a move on the voice agent stack. The pricing, not the latency, is the aggressive part.

Google’s orbital data center stopped being a plan

Google confirmed its Project Suncatcher prototype satellite is in orbit, launched on a SpaceX flight alongside Planet Labs satellites, with research arguing orbital data centers can work. Google also published its own estimate earlier that day that Starship would need roughly 1,800 launches over ten years before any of this matters commercially. Both things being true at once is the honest version of a moonshot.

arXiv is now rationing preprints

arXiv capped submissions at two per calendar month per submitter, with no more than three active at a time, after taking 40,363 submissions in September against 20,569 in September 2024. The stated problem is the distribution rather than the total: “a relatively small proportion of authors are submitting a large number of low-quality papers and consuming a disproportionate fraction of the moderators’ time,” including thin papers, salami-sliced ones, and dense AI-written ones. The field’s main channel for circulating ideas has started metering the people using AI to flood it.

One agent beat a team of agents in every environment tested

A new paper, Worse Together, ran five frontier models through 77 scenarios across four environments where agents share a resource: an API key, a clinic, a personal assistant, a merge queue. A single agent acting for everyone outperformed a team of per-user agents in all four. Without a communication channel the teams “completely collapse in two environments,” and in the personal assistant case the lone coordinator fulfilled a targeted request about twice as often as the team. The failure modes are familiar: agents stall as the team grows, override each other’s actions, and fabricate claims. The industry is building toward everyone having their own agent, and this is early evidence those agents will meet and make things worse.

Quick Hits

  • Military advice: Time reports Trump spent hours querying Grok in a December 2025 meeting with Musk, a month before the invasion of Venezuela, and came away thinking it “was ingenious.” Single unnamed source, no comment from xAI or the White House.
  • Privacy penalties: New Mexico asked a judge to fine Meta $35 billion to $40 billion after a jury found 26 of 29 company statements misleading. Meta wants the figure capped at $3.45 billion.
  • AI czar: Jay Clayton is the likely White House pick, and may keep his job as Director of National Intelligence while doing it.
  • Procurement: GSA finalized AI-specific acquisition rules effective October 19, barring contractors from training LLMs on government data, buried on page 129 of a memo.
  • Voice agents: Inworld acquired Ultravox, the real-time voice agent platform, for an undisclosed price, folding its turn-taking and interruption handling into Inworld’s speech stack. Consolidation landed the same day Microsoft went after voice pricing.
  • Agent harnesses: DeepSeek released a desktop build of its open-source Harness for macOS and Windows, and the top Hacker News comment was about the binaries being Chinese rather than about the product.
  • Personal assistants: Carly connects to thousands of apps, starts workflows from events inside them, and books meetings across Google and Outlook calendars.
  • Coding: Bain found developers using AI tools complete 21% more tasks while review time rose 91%. “The bottleneck has moved from writing code to trusting it,” partner Purna Doddapaneni told CIO Dive.
  • Chip controls: US authorities arrested a California man accused of smuggling more than $300 million of restricted Nvidia chips to China, as Bloomberg reported the volume reaching Chinese firms increasingly points to gaps in Nvidia’s own due diligence.
  • AI infrastructure: PaleBlueDot AI raised a $200 million Series C at a $3.2 billion valuation led by ComputeCore, the largest round of the window. The Palo Alto company, founded in 2024, says it had signed over $5 billion in customer contracts by the end of September.
  • Compute financing: Lambda closed a $1 billion senior secured financing, and the Financial Times reported Amazon has discussed moving $8 billion of Grace Blackwell chips into a special purpose vehicle and leasing them back.
  • Robotaxis: Newsom signed SB 1246, fining operators whose vehicles block first responders for more than 30 minutes, effective July 2028.
  • Open web: Wikimedia’s CEO called out AI firms over unpaid use of its data: “We’re not asking for charity.”
  • Data centers: A Finnish developer announced zoning approval for a 250MW data center in Pyhäjoki that municipal board minutes show was rejected 5 to 2.

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See the prompt
Set up Carly for me. Carly connects to thousands of apps, from Gmail, Outlook and my calendars to Slack, HubSpot and QuickBooks, and keeps working after this chat is closed: answering email, booking meetings, following up and running workflows the moment something happens.

1. Add the Carly MCP server (https://carlyassistant.com/mcp/) and sign me in. Use the one that matches you:
   - Claude Code: claude mcp add --transport http --scope user carly https://carlyassistant.com/mcp/  (then I run /mcp, pick carly, and authenticate)
   - Codex: codex mcp add carly --url https://carlyassistant.com/mcp/  then  codex mcp login carly
   - Claude (claude.ai, Claude Desktop, or Cowork): Customize > Connectors > Add custom connector, paste the URL, and sign in. Carly is also in Claude's connector directory at claude.ai/directory/carly.
   - ChatGPT: open Plugins, search for "Carly", add it, and sign in.
   - Cursor: add {"mcpServers": {"carly": {"url": "https://carlyassistant.com/mcp/"}}} to ~/.cursor/mcp.json, then sign in to carly from Customize.
   - Muse: I will create a Carly API key at carlyassistant.com/integrations (Advanced > API Keys > Create a new key, with Select all scopes). Build a custom connector to https://carlyassistant.com/mcp/ using an API key as a bearer token, and ask me for the key in your secure credential prompt.
   - Grok: go to grok.com/connectors, choose New Connector, then Custom, paste the URL, and sign in.
   - Grok Bot: open Plugins, add a custom remote MCP server named carly with the URL, then I approve it and sign in.
   - Perplexity: Settings > Connectors > Custom connector > Remote, paste the URL, and sign in.
   - Anything else: add a remote MCP server (streamable HTTP) named carly with the URL. It signs in with OAuth.
   I sign in with my Carly account, or create one at carlyassistant.com.

2. Walk me through connecting my accounts at https://carlyassistant.com/integrations. Under Accounts, I type each email address I use and click Add Email. On each new address, I click Connect Gmail or Connect Outlook, tick what Carly can reach (Email, Calendar, Contacts, Drive or OneDrive), then click Connect with Google or Connect with Microsoft and grant access. For an address that is already connected, I open Manage access and click Connect next to anything missing. Repeat for every address. Then ask which of my other apps I want connected too.

3. Check it worked: list my connected mailboxes and calendars and tell me every account you can see.

4. Then ask me what to hand off first, for example: "Check all my inboxes for anything that needs a reply today."

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR