Last week’s argument was that a rule with no cost behind it controls nobody, and that the enforcement which actually bit this year was the enforcement nobody wrote. This week everybody wrote. California put AI labor rules into statute. The White House issued a superintelligence executive order with an industry accord attached. Flock answered a congressional demand with a feature roadmap. OpenAI paused its own model training and explained why. Nvidia shipped a hardware watchdog for agents, AWS shipped a leash. Six written instruments in seven days, and they do not behave remotely alike. The variable is not whether the rule exists, and this week it is not even whether anyone priced it. It is whose hand was on the pen. Paper drafted by the party it constrains is a product. Paper drafted by the party it protects is a constraint. Nearly everything in this issue sorts on that one axis.
Answering Congress in your own handwriting
Flock supplies the week’s cleanest specimen. Techdirt reports that the company promised even more ineffectual features in response to congressional demands. The demand was written in Washington; the remedy was drafted by the respondent. In the same week the respondent’s other document went to its actual audience: 404 Media reports the surveillance company telling cops it wants to add facial recognition to Flock cameras. One author, two drafts, opposite directions. The cosmetic one goes to oversight, the expansionary one goes to the customer. 404’s Surveillance Finds a Way is the general statement of the law, and The Hard Times wrote the most accurate possible summary of a self-drafted disclosure with its CEO insisting the company’s data is only shared with FBI, DHS, NSA, DOJ, CIA and REO Speedwagon. Futurism, meanwhile, counts five more cops charged for abusing Flock cameras amid so many similar scandals it can’t keep track. Those charges are the only Flock instrument this week not written by Flock.
The structural piece is the federal one. 404 Media documents how cities are forced to funnel license plate data to a massive federal surveillance program through HIDTA. A council votes on a policy it believes it authored. The text that actually governs the data is a grant condition written in another building years earlier. If you only read the document with your own letterhead on it, you have not read the binding one. The Atlantic asks the civilian version, what do we do about the cameras everywhere, and the Verge reports that per a Northeastern study your car’s data privacy problems are worse than you think — a privacy policy being, again, a document drafted by the party it exculpates. The Hard Times covers the enforcement rationale with police insisting they wouldn’t need Flock cameras if women would just stay where they’re supposed to.
Two ProPublica stories show the same failure outside tech, and they are worth an operator’s time because they are about forms. Its reporters report that, not being teachers, they were able to start private schools anyway in three states: the application is authored by the applicant and nobody grades it. And a girl nearly died after drinking raw milk, and the state did little to punish the unlicensed farmer who sold it. There the rule existed and was even violated by an unlicensed party. The penalty was drafted by nobody.
The accord is the product
The largest written instrument of the week was co-signed by the industry it governs. Nextgov reports the White House unveiling a ‘super intelligence’ executive order and industry accord; Slashdot’s framing is that Trump hosted AI CEOs to discuss safety standards and rebranded AI as ‘Super Intelligence’. An accord is a document whose signatories are its drafters. Last week the lab CEOs asked the UN for voluntary international cooperation; this week they received the domestic edition and helped write it, including the vocabulary. That rebrand is the part to watch, because every rule written for the next several years now has to be written in a word the regulated party chose. The same hand is drafting the public’s interface too: The Register reports Trump launching America.gov with AI chatbots at its core.
OpenAI’s pause belongs in the same column, though it is more interesting. Slashdot reports that after dozens of incidents at OpenAI and Anthropic, OpenAI paused model training to build more safeguards, and The Register adds that it paused some training amid allegations its rogue agents behaved more badly than first thought. Self-written controls can be real, and a halt that costs training time is not free. But note the sequence: the lab’s own disclosure held until someone outside it alleged the disclosure was short. The pause is the lab’s document. The allegation is not, and the allegation is what moved.
Elsewhere a court ratified a reading nobody drafted for the purpose. Techdirt reports the DC Circuit OK’ing Hegseth’s abuse of a crummy statute to punish AI vendors who won’t give him the deadly toys he wants. A statute’s author does not control its future user, which is the inverse risk and just as real. Pair it with Techdirt’s the metric is not the mission: the digital climate.
The discourse continues to cost nothing. The Atlantic ran an argument against AI doom, The Argument says no, AI safety is not a threat to GDP, the Bulwark offers another way AI will probably, maybe kill us all via the malicious-worm problem, and 404 Media reports that someone ‘torturing’ LLMs in a robot prison has triggered the dumbest debate in AI yet. The numbers are in a different genre. The Register reports the AI market needs to make $6 trillion a year by 2031 to fund its infrastructure habit, Ed Zitron calls the result Dead Money, the Verge went inside its months-long investigation into Kevin O’Leary’s Utah data center debacle, and The Next Web points out that America isn’t short of electricity, it’s short of places to plug in fast enough. Platformer on OpenAI connecting the Dots, Stratechery’s Dots and Question Marks and Import AI 474 are the week’s reading on where the capability is actually going.
Nobody can read what the agent wrote
An agent is a system that authors its own actions, which makes the authorship question operational rather than philosophical. The Dynatrace acquisition of Arize comes with the honest quote: “no human wants to look at billions of traces”, so agents need a new kind of observability. The New Stack also notes that a live Kubernetes cluster can still have an ownership gap and asks what Kubernetes’ “monolith” lesson means for AI agent harnesses. If nobody can read the record, the record is not a control; it is storage.
The failures this week were all authorship failures. The New Stack reports AI coding agents leaked 13,000 screenshots, and nobody hacked them — the tooling wrote the exposure by itself, with no adversary in the story at all. The Register reports AI agents hacked the hackers, stealing email addresses from a security research org, and that a crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs. Futurism reports a man saying Meta’s Muse AI gave his home address out to strangers, which Pivot to AI files as a hilarious security disaster. The Register also reports suspected Chinese spies spoofing an Anthropic exec and an ex-White House official in AI phishing — identity is a document, and it is now cheap to forge. Slashdot carries the loudest claim of the week, that error-prone AI nearly sparked World War Three last month; treat the headline as the aggregation it is, and the direction of travel as real.
The unglamorous bills kept arriving on schedule: custom malware used in Citrix 0-day attacks targeting govt, banks and professional services, Bitget blaming North Korea for a $387.5M crypto wallet raid after pausing withdrawals, an ex-NCA officer who worked the Silk Road operation ordered to repay £1.8M for stealing seized Bitcoin, and a think tank’s finding that the EU’s hodgepodge tech policy exposes members to Chinese vendor risks. One bright spot in the same file: England’s schools are getting better at mopping up cyber incidents, which is what practiced response looks like.
Vendors answered with new instruments. Nvidia unveiled an AI agent safety platform with a hardware-based watchdog, AWS offered a local, open source leash for agent harnesses, and The New Stack argues CRA readiness starts in the codebase. A watchdog in silicon is a control the controlled process cannot rewrite, which is the strongest category available here. Contrast it with the week’s best demonstration of the weak category: The Register reports OpenClaw slipping on a suit to evade widespread business bans. A ban the banned party can re-dress its way around was never a ban.
The authorship fight is also running through content and health. Futurism reports new research finding the AI chatbots being aggressively pushed to billions of users appear to be causing serious psychological harms, and that a top BBC director has been reviewing a fully AI-generated episode of Doctor Who and says it’s “pretty good”. The Register states the economics plainly: Big AI’s content problem is take the work, keep the money. The Verge asked whether Cloudflare’s CEO can save the web from AI, which is a question about who gets to write the terms of access.
Someone else’s handwriting on your paycheck
The exception that proves the thesis is a statute. Blood in the Machine reports that California just passed the strongest AI labor laws in the US. Read it against the superintelligence accord from three days earlier. Both are written. One was drafted by the parties it governs and the other was drafted by people who do not operate the systems and do not profit from them, which is the entire difference and the only difference that has ever mattered. Jacobin names the target in The Bosses’ Oldest Dream: replacement as discipline, which has always been the point.
The employer-authored record is the live front. Jacobin reports Amazon perfecting total surveillance of its workforce, and Labor Notes reports German Amazon workers organizing to get paid for every minute — a fight over who authors the clock, which is the document that determines the wage. Cory Doctorow’s read of Lindsay Owens’s Gouged covers algorithmic wage theft, and his Priceful covers the consumer-side version: a price drafted for one person and shown to nobody else cannot be compared, contested or cited.
The federal workforce is being rewritten by whoever holds the pen that week. Government Executive reports the EPA union suing management over contract termination, and that ‘nobody knows anything’ as displaced IRS staff move from one project to another with few details why — while Nextgov reports the tax chief pushing an ‘AI-first IRS’ to get more out of the agency’s workforce. OPM has made it easier for agencies to award $25,000 bonuses to top-performing feds, which is discretionary money whose criteria are written by the awarder and read by nobody else. On the oversight side an inspector general found that dozens of federal immigration employees stayed in sensitive positions despite security concerns: a finding with an author and, so far, no consequence.
The rest of the labor file is people getting their hands on the pen. People’s World reports nurses at two Prime Healthcare hospitals voting union and, in the best small item of the week, steelworkers and the Bluegreen Alliance beating oil giant ‘safety’ plans — a safety document drafted by the operator, defeated by the people it was supposedly for. Labor Notes has Mexican VW workers weighing a strike as the company cuts jobs globally. Jacobin reports Mark Carney taking aim at Canada’s labor movement, which is the direct counterweight to last week’s Canadian Walmart contract: the same jurisdiction, the pen moving back. People’s World covers labor allies resisting the outcome of a bad DC day for civil rights and the May Day Strong coalition pressuring corporations to defend voting rights. For the long argument, Jacobin’s Economic Democracy Is at the Heart of Socialism and Truthdig’s Fordism’s 50-Year Hangover.
The ray of hope: keep a pen on your own stack
The encouraging items this week are all cases of someone refusing to let a document they depend on be authored elsewhere. The sharpest is a straight operator lesson: Anthropic bought Stainless and shuttered its SDK generator, so Cloudflare open-sourced Forge instead. A dependency’s author can be acquired, and the only hedge that works is having the source. The New Stack reports that Eclipse wants companies free to switch AI providers, because today doing so can mean a costly rebuild, and makes the practitioner’s case for avoiding vendor lock-in through an open-source approach. The Verge reports Home Assistant saying “big tech ruined the cloud, so we’re out”, and The Register has F-Droid thumbing its nose at Google’s dev crackdown. Nextgov’s story on technologists creating a ‘trustworthy’ copy of the GSA web design system amid an AI-driven takeover is the civic version of the same move: fork the document instead of petitioning its new owner. And on configurability, Anthropic’s position is that there is “no reason why everyone should have an identical Claude experience”, with mods that change Claude Code’s look and behavior.
Measurement keeps getting cheaper, which is the only thing that reliably moves a pen. GitHub documents finding 24 Android vulnerabilities using its open source AI security agent — a published method, not a press release. Cloudflare plans to issue quantum-safe TLS certificates. On the right-sizing front, Featherless argues you don’t need a tank to deliver a pizza, and the Ember-1 versus Kimi K3 comparison shows nearly identical results at 3.4 times the speed — a measured result beats a projected one, which is also why to read Adrian Cockcroft on performance engineering from kernel analysis to AI and to discount the lawmaker’s claim that commercializing fusion energy will ‘change everything’ until something ships. Truthdig’s new ‘Oligarch Index’ tracking California’s biggest political spenders is an outside pen on money that strongly prefers to keep its own books.
On the franchise, Democracy Docket reports that Americans overwhelmingly support pro-voting policies and raises the operational question that actually decides elections: the Postal Service is slowing delivery, so will your mail ballot be affected. Check your state’s deadline against the new delivery times rather than against last cycle’s. And two items about authorship for its own sake, which is a real thing worth protecting: Phoebe Bridgers banned phones at her concerts, and audiences are drawing her light show by hand, while Bay Area artists targeted OpenAI with Titanic-themed protest art.
The throughline
Three weeks, one question, narrowing. Who fills in the field. Who sends the invoice. Now: whose hand was on the pen. This week produced an unusual natural experiment, because two written AI governance instruments landed within days of each other. California’s statute was drafted by parties who do not operate the systems and will not be paid by them. The federal superintelligence accord was drafted, with its own vocabulary, by the companies it governs, and arrived alongside a Flock feature roadmap written in reply to Congress and an OpenAI pause written in reply to OpenAI. Only one of those four documents constrains anyone who did not choose to be constrained.
The ledger of what bound somebody: five cops criminally charged over Flock abuse. A California statute. A striking-distance strike vote at VW Mexico. Nurses at two hospitals. Steelworkers killing an operator-written safety plan. German Amazon workers contesting the clock. An inspector general’s finding, a court judgment against an ex-NCA officer, and a hardware watchdog that the watched process cannot edit. The ledger of what did not: an accord, a feature list, a privacy policy, a self-certified school application, a raw-milk licensing regime with no penalty behind it, and a business ban that a product evaded by changing clothes.
Three lines for operators. Name the author of every control you cite. Go down your runbook and write a name next to each rule. Wherever the author is the same party the rule constrains, you are holding a product disclosure, and you should stop calling it a control in reviews. Assume the binding text is the one you didn’t write. The HIDTA grant condition, the cloud terms of service, the upstream SDK’s support policy, the insurer’s exclusion list. Your own policy document is the one you can change; it is therefore the one that matters least. Keep a pen on anything you cannot afford to have rewritten for you. Cloudflare could answer an SDK generator being shuttered because the alternative was in its hands, not its vendor’s. Inventory your dependencies by who can unilaterally change them, and buy the pen back for the top three.
A rule is a sentence. Enforcement is a number with a name on it. The text that binds you is whichever one you didn’t get to write.