Good day . There is someone at your company who has been saying for months that you should stop shipping for two weeks and fix the thing everyone knows is broken. They are right. They also cannot get anyone to agree, because the moment your team stops, the competition does not, and whoever stopped first eats the loss alone. That is not a character flaw. That is a coordination problem, and this week the biggest AI lab on earth walked into Congress and admitted it has the exact same one -- except its version might be a federal crime. Also in here: Apple teaching your camera to swear an oath, Meta's new agent taking second place in an empty room, and what an actual extinction number does to a person's brain.
OpenAI Asks Congress If Braking Is Legal
What happened: OpenAI has spent recent weeks asking members of Congress for clear guidance on whether orchestrating an industry-wide slowdown of frontier AI development would actually be legal, WIRED reported on Thursday. The worry is the Sherman Antitrust Act: rival companies agreeing to limit how fast they build can look a lot like agreeing to restrict output. Separately, Reuters reported -- citing Bloomberg -- that Sam Altman told staff at a company-wide meeting this week that OpenAI is open to pacing its own development alongside other labs, though he acknowledged some of them may not play along. A bipartisan bill from July, the Collaboration on Adversarial Threats and Security Risks Act, would create an antitrust safe harbour for exactly this kind of coordination. It is still sitting in the House Judiciary Committee.
Why it matters: You have run this meeting. The migration everyone agrees is necessary, the test suite nobody has touched since March, the one integration held together by a person who left in May. Everyone in the room agrees it should be fixed. Nobody will be the team that stops shipping to fix it, because the quarter is scored on what went out the door, not on what did not fall over. The fix is not more conviction. The fix is somebody senior enough saying out loud that everyone stops at the same time, and that nobody gets punished for it. OpenAI just went to Washington looking for the corporate version of that sentence, and found out the law may not let anyone say it.
What everyone's saying: Legal scholars have been flagging this for months. Nicholas Felstead, an assistant director at the Australian Competition and Consumer Commission and a former AI policy fellow at the Center for Law & AI Risk, argued in March that a coordinated pause could amount to restricting output, and that it would turn “entirely on the precise details of any agreement” -- adding that even survivable collaborations get chilled, because legal uncertainty is itself a deterrent. OpenAI cofounder John Schulman, now at Thinking Machines, has argued there is daylight between drafting a shared pacing proposal and signing a binding pact to restrict output. OpenAI did not comment before publication.
My read between the lines: Read the ask literally and it is remarkable. The company is not asking permission to build something. It is asking permission to stop. And the reason it needs permission is that a market this competitive has made unilateral caution legally safer than collective caution -- you can slow down alone all you like, you just cannot invite anyone. Which means the current rules reward the lab that keeps its foot down and says nothing. Altman also told employees some labs simply may not agree, and that is the part worth sitting with: the safe harbour bill fixes the lawyers, not the incentive.
📖 Further reading: The US Government Just Took Anthropic's Best AI Model Offline -- what it looks like when someone external actually does pull the brake, and who paid for it.
Everyone in today's brief is arguing about who has to stop working. Nobody is offering to do the work. Viktor is an AI agent that lives in your Slack (and Teams) and plugs into over three thousand tools, so the Monday report builds itself, the dashboard refreshes without a reminder, and the campaign that has been “next week” since August actually ships. Not a chatbot you prompt -- a coworker you delegate to. New readers get $50 off their first month. Hire Viktor →
Your iPhone Will Now Swear the Photo Is Real
What happened: Yesterday we told you Apple shipped a Siri it did not build. Here is the thing at that same event it did. Apple announced Apple Reference Image, an opt-in mode on the iPhone 18 Pro and Pro Max where a new sensor in the main camera signs the sensor data at the pixel level the instant you press the shutter. That signed data goes to Private Cloud Compute, which develops it into what Apple calls an unalterable reference image -- a digital negative that sits beside your photo in the Photos app so anyone can compare the two and see what was edited. Apple is opening APIs in iOS, iPadOS and macOS 27 so other apps can show it, and is adding support for Google DeepMind's SynthID watermarking later this year. 9to5Mac notes the feature will not be available in the European Union or China.
Why it matters: Insurance claims, listing photos, damage reports, proof-of-delivery, the picture a contractor sends you of work you cannot go inspect. All of those are currently trust exercises held together by the assumption that faking a photo is more effort than it is worth. That assumption expired about eighteen months ago. A camera that can prove what it saw is the first plausible answer, and it is arriving as a phone feature rather than as an industry standard.
What everyone's saying: The loudest reaction came from someone who had already built it. María Benavente, a Recurse Center alum, posted a teardown of Apple's approach next to Proof of Capture, the open-source camera she and Alex Hornstein built this summer: a Raspberry Pi Zero, an ATECC608 crypto chip whose private key can never be read even by its owner, a shutter button and a 3D-printed case, for under $100. Hers hides a signed perceptual hash inside the pixels themselves as a frequency-domain watermark, so it survives WhatsApp-grade compression -- while Apple's signature lives beside the photo, and EXIF gets stripped the moment you share anything. Her complaint is not the engineering. It is that Apple skipped C2PA, the open provenance standard already used by Nikon, Sony, Leica and Adobe, and kept the root of trust inside Private Cloud Compute. The Hacker News thread went straight to the same question a commenter raised on MacRumors: if the point is proving the photo came from this camera, why does it have to leave the device at all?
My read between the lines: Both systems lose to the same five-dollar attack, and Benavente says so herself: point the camera at a screen showing an AI image and you get a perfectly signed photograph of a fake. What is actually being sold here is not proof of reality, it is proof of custody -- this sensor, at this moment, saw this. That is genuinely useful and much narrower than the marketing. And the reason to care which standard wins is that a provenance system only works if the platforms display it, which C2PA has spent years failing to make happen. Apple's advantage is not better cryptography. It is that Apple can put the badge in front of a billion people without asking anyone.
📖 Further reading: AI Is a Trust Problem, Not a Tech Problem -- the whole fight over who gets to certify what is real is a trust-architecture fight wearing a camera.
The Brief is free, every weekday, and that is not changing. What sits behind the paywall is the other half: the deep dives where I actually install the thing, break it, and write down what it cost. Plus the full archive, which is getting to be a useful place to look things up. If the free half has earned it, become a member.
Meta's Muse Hits No. 2 in a Very Quiet Room
What happened: Muse, Meta's new personal AI agent, climbed to No. 2 on the overall US App Store chart on Thursday after Sensor Tower data cited by TechCrunch put it north of 83,000 iOS downloads in the US since its Tuesday launch, up from No. 4 the day before. The app is US-only for now and is pitched as an agent that does things -- email, travel bookings, purchases -- rather than a chatbot that answers. The comparisons are where it gets awkward. Threads pulled more than 4.3 million US downloads on launch day. The Meta AI app did 108,000 on its debut. ChatGPT passed half a million US installs in under a week, roughly 83,300 a day, which is a number Muse took two days to reach. On Android, Muse sits at No. 338 in Google Play's Productivity category. Muse is also available on the web and through WhatsApp, neither of which these estimates count.
Why it matters: If you sell anything online, the agent wars are a distribution question, not a gadget question. An agent that browses, compares and buys on a customer's behalf becomes the thing deciding whether your storefront is legible enough to be chosen. That is the Amazon Buy Box problem arriving at your own website, and the first movers get to define what “legible” means.
What everyone's saying: Wall Street liked it more than the download chart did. JPMorgan's Doug Anmuth upgraded Meta from Neutral to Overweight on Thursday and lifted his price target from $640 to $820, noting early Muse usage was running around ten times the rate seen in internal training cohorts. More than 90% of analysts tracked by Bloomberg now rate Meta a buy. The competitive read is less rosy: Muse is landing into a field that already includes Google's Gemini Spark, Anthropic's Claude Cowork, and a startup called Instinct valued at $2.5 billion that has been shipping Stripe and 1Password integrations and agent-to-agent coordination while Meta was still in beta.
My read between the lines: A No. 2 ranking with 83,000 downloads tells you more about the App Store than about Muse. Chart position measures the shape of one day's traffic, not the size of an audience, and Meta's own back catalogue is the cruelest available benchmark: the company that moved 4.3 million downloads of a Twitter clone in a day moved two percent of that for the product it says is the future. The interesting number is not the rank. It is that the launch came days after Meta settled multistate social media harm claims for $18 billion, and the product being launched asks you to hand it your email and your credit card.
📖 Further reading: I Make AI Versions of Myself for a Living. This One I Didn't Agree To. -- Muse has form, and the last time Meta put that name on something the consent question got loud.
Somebody Put a Number on Extinction This Week
What happened: On Tuesday, Anthropic researcher Jacob Coxon resigned and said on X that Anthropic and OpenAI “are racing straight to self-improving superintelligence and gambling with our lives,” adding that the people building AI “earnestly believe that it could kill us all by the end of the decade.” Hours later Evan Hubinger, who leads Anthropic's alignment science work, publicly agreed and put his own estimate above ten percent within the next decade, while saying he believes Anthropic is trying its best and does not yet have a plan for superintelligence alignment. Fortune reported Coxon's posts reached more than 100 million people overnight. Senator Bernie Sanders said he would introduce legislation to pause advanced development and ban superintelligence. Then on Thursday The New York Times ran a news analysis asking the question underneath all of it: what is a person supposed to do with a number like that?
Why it matters: The Times piece is not about AI. It is about the fact that humans are extremely bad at ranking rare catastrophes, and that AI has now joined a long queue that already contains asteroids, pandemics, thermonuclear war and ecological collapse. “We tolerate risks that we're used to but fear the new ones,” James K. Hammitt, who directs the Harvard Center for Risk Analysis, told the paper -- which is why people treat airlines as more dangerous than cars. If you are trying to decide what to actually do on Monday, that bias is the thing standing in your way, not the percentage.
What everyone's saying: Broadly, two camps, and they are not the ones you would expect. The doom camp now includes people currently employed to make the systems safe, which is new -- Hubinger agreeing with the man who just quit over it is not a debate, it is a disclosure. The skeptical camp keeps making the Times's own point back at it: a single gallon of anthrax could in principle end human life, several hostile states are suspected of holding it, and it has not happened, because capability and outcome are different things. Anthropic said Thursday it had foiled several attempts by researchers whose work could have led to biological weapons.
My read between the lines: Notice what did and did not move this week. A ten-percent extinction estimate from the head of alignment science produced headlines. A hundred million impressions produced a senator's press release. Meanwhile the thing that actually changed corporate behaviour was the top story in this brief -- a lawyer's question about the Sherman Act. Existential risk gets the reach; procedure gets the result. If you want to know whether anyone is serious, watch the antitrust filings, not the threads.
📖 Further reading: Anthropic built the most powerful AI ever. You can't use it. -- the last time a lab decided a model was too capable to hand over, and what it withheld.
Your Moat Is Whatever a Copier Can't Do
What happened: Ted Hayes, who runs the design-and-build studio InventBuild, published an essay on Thursday arguing that competent execution has become abundant enough to stop being a differentiator at all. His list of things that no longer count: having built an app, having professional-looking design, having a standard feature set, even having a novel output, because a novel output gets copied within weeks. What is left, he argues, is the habit of invention -- spotting problems others skipped, reframing familiar things, and continuing to evolve after competitors catch up. His prescription is blunt: do not take one step back from your project, take a hundred.
Why it matters: The supporting number is the uncomfortable one. Ahrefs ran its detector over 900,000 newly created English-language web pages and found 74.2% contained AI-generated content -- only 2.5% were pure AI, and 71.7% were human-AI blends. So the web did not go synthetic. It went uniform. If your differentiation strategy is “but ours is well made,” you are competing on the one axis that just got commoditized.
What everyone's saying: The essay reaches for early web history as the analogy, when JavaScript put animation and interactivity in the hands of people who were not web programmers and produced a decade of gloriously bad experiments -- autoplay music, drag-and-drop everything, loading screens as an art form -- some of which became the interface conventions we now use without thinking. The consensus read of the current moment is the mirror image: enormous generative capability, very little appetite for the bad experiments that precede a good one.
My read between the lines: Everyone nods at “taste is the moat” and then goes back to shipping the feature-parity roadmap, because taste has no ticket number and experiments show up in the sprint review as unfinished work. The honest version of this advice is a budget line, not an attitude: some named fraction of the quarter spent on things that are permitted to be wrong. Nobody in that Ahrefs 74% set out to make generic content. They just never scheduled the alternative.
📖 Further reading: The Font That Beat AI for About a Week -- a real case of the weird, hand-made idea outrunning the machine, right up until it didn't.
That is your Friday. One last thing: the person from the top of this email -- the one who keeps saying you should stop and fix the broken thing, and keeps getting told next quarter -- forward them this. Or skip the forward and just say the sentence they have been waiting on, which is “you're right, what would it take.” OpenAI needed an act of Congress to get there. You probably just need a Friday.
—Artificially Intimidating














