AI safety has swiftly become Washington’s most combustible political snarl

Trump, Jensen Huang, Democratic 2028 hopefuls—and the unlikely alliance of Bernie Sanders and Steve Bannon—have swiftly transformed AI safety into a political and partisan snarl that makes responsible policymaking almost impossible.

Share
AI safety has swiftly become Washington’s most combustible political snarl
NVIDIA CEO Jensen Huang delivers remarks as President Donald Trump looks on during an “Investing in America” event, Wednesday, April 30, 2025, in the Cross Hall of the White House. (Official White House Photo by Joyce N. Boghosian). Source: The White House

Over the course of the past week, and intensifying over the weekend, the safety of AI and the concerns over frontier models' ability to engage in highly destructive behavior have turned into a combustible political snarl, with Donald Trump denouncing AI-safety warnings as a “HOAX” and declaring that the only guardrail AI needs is a sufficiently strong and intelligent president.

Trump lashed out at calls for new AI guardrails and protections, arguing AI only needs a "STRONG AND SMART (High IQ!) PRESIDENT" and that AI critics should "BEWARE!" even as a growing chorus of AI leaders and CEOs, spearheaded by Anthropic CEO Dario Amodei over the weekend, call for a slowdown in AI's development and better regulations to help keep humanity safe.

At the All-In Summit in Los Angeles, Trump called in via phone to tell Jensen Huang, Nvidia’s chief executive, to say AI fears are a HOAX. “The robots are not going to be taking over the world," Trump said after Huang put him on a speakerphone. "That’s not going to happen.”

On the other side of the political spectrum, Democratic politicians begin treating AI safety as a potentially defining electoral issue extending beyond the midterms and into the 2028 presidential contest. After losing a congressional primary contest in June that centered on AI regulation, Alex Bores, a state assemblyman from the Upper East Side of Manhattan who will soon be without a job, sensed an opportunity.

At the same time, in a twist of political strange bedfellows, Sen. Bernie Sanders (I-VT) and MAGA loyalist and hard-right propagandist Steve Bannon prepare to appear under the same “pro-human AI” banner on behalf of the nonprofit advocacy behind "The Pro-Human AI Declaration," which calls for protecting human agency, avoiding concentrations of power, and holding companies accountable.

In a rare intervention, former president Barack Obama welcomed the current debate but warned that “at the end of the day, voluntary standards made by a handful of tech companies won’t be enough”.

Writing on X, Obama added: “We need government – and specifically our leaders in Washington – to get proactive in coming up with concrete proposals, laws and regulations that deal with serious safety concerns, anticipate AI’s impact on jobs and our kids, and make sure that AI’s benefits are widely spread.” (Herb Scribner / Axios, Kalley Huang, Mike Isaac and Karen Weise / New York Times, Benjamin Oreskes and Theodore Schleifer / New York Times, Maria Curi / Axios, David Smith, Chris Stein, Nick Robins-Early / Axios)

Related: New York Times, Technology | International Business TimesAndroidHeadlines.comBusiness InsiderFuturismDark ReadingRuntimeWireBusiness InsiderFortuneWebProNewsWSJ.com: WSJDAndroidHeadlines.comFuturismNew on MIT Technology ReviewTechradarMashableInvezz,  Cointelegraph.comBusiness Insider, InsideDefense.comIBTimes.co.uk : TechnologyDon't Worry About the VaseTechRoundSecurity AffairsPCWorld, The Korea Times, The Hill, Axios, Axios, Axios, CNBCHindustan TimesThe VergeNBC NewsAxiosLos Angeles, CA PatchNew York Times, QuartzSFGATEMediaiteWashington PostThe Washington SunFox Business, New York Post, Business InsiderMS Now, Bloomberg, Watcher Guru, Tom's GuideWebProNewsBusiness InsiderTechradarBloomberg Technology,


Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


South Korea's state-run internet security agency, the Korea Internet & Security Agency (KISA), said it is developing updated guidelines ​to manage the growing autonomy of AI systems, ‌as companies deploy AI agents capable of operating with limited human oversight.

KISA, which operates under South Korea's Ministry of ​Science and ICT, said it is ⁠working on an updated version of the "AI Security ​Guide", first published last year.

The ​revised guide would focus on security issues that could arise as companies deploy agentic AI services and offer a checklist ​to manage those risks.
The agency also said the guide ​could include common control measures applicable to "physical AI" systems capable ‌of ⁠interacting with real-world devices and machinery.

KISA said the new guide was designed to address risks posed by agentic AI systems more broadly and not specifically ​targeted at high-performance ​AI models, ⁠such as those implicated in the Hugging Face breach. (Joyce Lee / Reuters)

Related: The International News, CNBC-TV18

OpenAI is hiring hundreds of contractors who read a massive stream of real users’ ChatGPT prompts, with the prompts sometimes including sensitive personal information.

The prompts these people review can include whole conversations between users and the chatbot, conversations that most of ChatGPT’s more than 900 million users probably don’t realize may be read by actual people.

The goal of these prompt review teams is to improve the responses ChatGPT gives to its users, with the contractors rating and critiquing the chatbot’s generated replies. Internal documents show contractors training ChatGPT not to anthropomorphize itself and to be less sycophantic, a key problem for OpenAI, whose over-sycophantic 4o model led in part to multiple people’s suicides, according to various lawsuits.

The news presents a major privacy risk for ChatGPT’s users, with people often using ChatGPT as a therapist, professional assistant, or digital friend, and providing it with all sorts of intimate details about their lives. The contractors don’t see ChatGPT usernames, and OpenAI says it tries to remove personal information before prompts reach the reviewers, but the company acknowledged sensitive details can still get through.

The news also dispels the misconception that these models are improving only because of OpenAI’s mass scraping of the internet, the talent of its well-paid engineering and AI teams, or the power of its newer models. An important and overlooked part is the outside contractors paid to read and review ChatGPT responses to real prompts over and over again.

Anthropic confirmed to 404 Media it is also using human review to improve its models. (Joseph Cox / 404 Media)

Related: r/technology, Gigazine

The Manhattan District Attorney’s Office announced the seizure of 12 domains which it says have been used for “unlawfully” sharing, publishing, and selling celebrity deepfake videos.

Around 1,200 people—overwhelmingly women—were depicted in nonconsensual sexual images and videos on the websites, the office says. These included social media influencers, actors, activists, athletes, musicians, and politicians.

“These horrific violations of privacy follow victims into their careers and personal lives and take an immense toll on emotional and mental well-being,” district attorney Alvin Bragg said in a statement, urging potential victims to come forward and contact his office’s cybercrime bureau. The office says its investigations into who is responsible for the websites, plus those who uploaded damaging videos of victims, are ongoing.

The seizures, carried out under New York’s criminal procedure laws, mark perhaps one of the most significant and sweeping actions against websites hosting explicit deepfake videos since the technology first emerged at the end of 2017. As artificial intelligence technology has improved, a dark industry of websites, apps, and bots has appeared: They are designed to “undress” photos of women or create graphic sexual videos that include them. The images and videos are increasingly realistic and can be generated in seconds.

The Manhattan District Attorney’s Office has not publicly named the websites it has seized. However, ahead of Bragg’s announcement, WIRED independently observed several of the sites’ homepages being replaced by takedown notices—“THIS DOMAIN HAS BEEN SEIZED”—late last week, with the sites now saying they have been taken over following a seizure warrant issued by a New York State Supreme Court. (Matt Burgess / Wired)

Related: Manhattan District Attorney's Office, ABC7, AFP, 404 Media, WION, Newsday

Last summer, a cop with the Lake County, Indiana Sheriff’s Department used Flock’s surveillance search engine to look for a license plate across more than 19,000 cameras in 1,558 cities and towns, with the cop’s stated reason for the search, according to a record of Flock’s system, was “LMAO.”

The cop is one of dozens who put gibberish, jokes, or other nonsense into Flock’s “reason” box, highlighting the casualness and lack of care some cops have when searching an incredibly powerful surveillance system. This is on top of the thousands upon thousands of cops who wrote something like “investigation,” “test,” or left the box blank as their search “reason,” according to a new analysis by the Electronic Frontier Foundation and shared with 404 Media.

EFF’s investigation found cops across dozens of jurisdictions writing “LMAO,” “LOL,” “Hehe,” “Haha,” “idk,” “blah,” “TBD,” and “robbery I don’t remember the case number leave me alone” in Flock’s “reason” box for searches. They found cops writing “idiot,” “fuck this new search engine,” “dickhead,” “shithead,” and “WEIRD KID” in the reason box. And they found an entire class of police button mashers, who ran searches for reasons of “asdfg,” “gyghkkghghjkghjk,” “jhjhjkhj,” “jkhhkjhjk,” “nmbvcbnm,” and so on. The searches came from police departments across the country from 2023 through late 2025, when Flock changed how the “reason” box in its search system functions.

A "culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols," EFF said. (Jason Koebler / 404 Media)

Related: Electronic Frontier Foundation, r/technology

Audit logs. Source: EFF.

South Africa will extradite to the United States six Nigerian nationals suspected of ​being members of the Black Axe ‌organized crime network involved in romance scams and cyberfraud.

The men are wanted by ​US authorities on charges including wire fraud ​and money laundering.

They allegedly targeted more than ⁠100 women in the US, defrauding them ​of more than 100 million rand ($6.2 million) ​through online romance scams, South Africa's elite Hawks police unit said in a statement, adding the victims included ​pensioners and businesspeople.

Black Axe grew out of ​a student fraternity in the late 1970s called the Neo ‌Black ⁠Movement of Africa, and it has since evolved into a structured, violent criminal organization often dealing in financial cybercrime.

The Nigerian nationals will be handed over to the FBI and Secret Service on Friday. (Sfundo ​Parakozov / Reuters)

Related: Justice Department, Bleeping Computer, The Record, The Print, Modern Ghana, BBC News, News.com, Herald Sun

Researchers at Hudson Rock and ADAMnetworks say that hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

They analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours.

The ads used a social engineering technique known as ClickFix, which tricks users into copying and pasting malicious commands into Windows Run, PowerShell, or macOS Terminal while pretending to fix an error, verify a CAPTCHA, or install legitimate software.

The type of attack has become increasingly popular among cybercriminals because victims run the malicious commands themselves using legitimate operating system tools, potentially bypassing some browser and security software designed to detect malware downloads.

While some of the advertisements pushed by the HBO Max account impersonated the streaming service, others promoted fake AI tools, developer software, and macOS utilities.

Hudson Rock and Adam Networks have linked the attack to a larger campaign they call PasteSwitch, which targets both Windows and macOS systems and has been used to distribute information stealers, loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications.

The researchers say PasteSwitch refers to the operation's use of attacker-supplied commands that victims paste into their systems, while the attackers' backend switches between campaigns, platforms, payloads, and crypto theft methods depending on the visitor. (Lawrence Abrams / Bleeping Computer)

Related: Hudson Rock, Adam Networks, r/hacking, Cyber Press, TechCrunch, PCMag, Cyber Security News, GBHackers, r/cybersecurity

Malicious HBO Max advertising on Reddit. Source: Adam Networks

An investigation is underway into a “data security incident” affecting some Telus customers, according to the company.

Those affected received an email this week informing them that “unauthorized individuals” were able to access information such as their name, billing address, and phone number, as well as the last four digits of their payment card on file.

“These individuals may have used your account information to contact you in an attempt to persuade you to move your services away from TELUS towards competitors, and/or made unauthorized changes to your TELUS services,” the email reads.

Telus said the breach took place sometime “between February 2025 and June 2026,” but that the compromised credentials used have since been “terminated.”

In a statement, the company’s director of public affairs told CTV News that only a small number of accounts were accessed.

“We have notified affected customers, provided complimentary identity protection, and contacted law enforcement as well as the Privacy Commissioner of Canada,” said Richard Gilhooley.

“We are also inviting notified customers to contact us if they are concerned about its veracity.”

Affected customers have until Nov. 30 to claim the free identity protection, provided through Norton for two years, according to the email notifications sent out this week. (Andrew Weichel / CTV News)

Related: Mobile Syrup, Security Week, r/Telus

Microsoft released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions.

The September 2026 security updates caused Remote Desktop Services (RDS) to become unstable on affected systems, leading to RDP connection and sign-in failures and, in some cases, unresponsive servers.

Microsoft previously acknowledged the issue after Windows administrators reported widespread RDS problems following the September updates.

Affected systems could also experience problems with related components and tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, which could stop responding. (Lawrence Abrams / Bleeping Computer)

Related: Microsoft, Neowin, The Verge, gHacks, Notebookcheck, Windows Latest, Heise Online, Pasquale Pillitteri, Infosecurity Magazine

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.

"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory.

The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.

Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.

"This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco added. "A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system." (Sergiu Gatlan / Bleeping Computer)

Related: Cisco, Security Week, Cyber Security News, Heise Online, GBHackers

E-commerce giant Coupang said it has launched an information-dedicated committee to overhaul its security system and bolster public confidence in the company.

The move comes months after the company was slapped with a record fine of 624.7 billion won ($460 million) by the Korean government in June over a massive customer data leak late last year.

"We will continue to improve our security system by incorporating the expertise and know-how of specialists, while striving to exceed global standards," a Coupang official said.

The Information Security Advisory Committee consists of seven experts in information security, law, management and information technology (IT), the company said.

They include Coupang Chief Information Security Officer (CISO) Brett Matthes, Eumene Kang, a senior adviser at law firm Kim & Chang, and Kim Hyun-kyung, a professor at Seoul National University of Science and Technology.

At their first meeting, the committee members discussed changes in relevant laws and regulations, growing security threats in the market, and possible countermeasures. (Yonhap News)

Related: Asia Business Daily, The Korea Herald

Florida’s Department of Highway Safety and Motor Vehicles (FLHSMV) said that it’s investigating a data breach, making it the second organization that hosts Americans’ driver’s license information to be hacked this month.

The Florida announcement comes on the heels of another incident, in which a vendor that scans Americans’ driver’s licenses for private companies, IDscan.net, said it was investigating a major data breach of its own. Hackers claimed to have stolen 160 million IDs from the company, including one from Defense Secretary Pete Hegseth, sparking federal investigations.

Specifics of what was stolen from the FLHSMV are scant. But the department said in a statement published on its website that the breach was “conducted by an international cybercriminal organization.” Law enforcement is investigating the hack, the agency said, and the breach has since been contained. It’s unclear how long the hackers had access.

ShinyHunters, a cybercriminal group that hacks targets for sensitive information and then extorts them for a payment to delete it, announced on its dark-web site that the “Florida DMV” was its latest victim. (Kevin Collier / NBC News)

Related: CBS 12, WPTV

CrowdStrike's stock reached an all-time closing high Monday as cybersecurity stocks became the top performers in the S&P 500, showcasing how the technology trade has become starkly divided in the face of escalating warnings about artificial intelligence.

Over the weekend, Anthropic CEO Dario Amodei outlined his concerns about the accelerating speed of AI development, warning about the potential of models soon reaching a point where they are so powerful that they could spur legions of bots to take over the entire internet. He called for major players to pace themselves and focus on safer AI progress. (Britney Nguyen / Morningstar)

Related: CNBCCNBCBusiness Insider, Yahoo FinanceForbesFast CompanyCTechCNBC, Barron's Online

Italian cyber security startup announced it had raised $270 million, as industry races to protect billions of internet-connected devices from the mounting risk of AI-powered hackers.

San Francisco-based venture capital firm Headline led the round with other backers including Sofina, Goldman Sachs, European Investment Bank Group ETCI, KfW Capital and T.Capital. Previous investors Balderton, HV, Intrepid Growth Partners, 33N, Lakestar, Supernova Invest, Blue Cloud Ventures and Geodesic Capital also participated in the oversubscribed round. (Tom Wilson / Financial Times and Ingrid Lunden / Resilience Media)

Related: Tech.euStartup.eu

Best Thing of the Day: Miracles Never Cease

The Supreme Court rejected a petition by the Trump administration to implement changes to the way the U.S. Postal Service handles mail-in ballots for the upcoming 2026 midterm elections, calling it “arbitrary and capricious.”

Bonus Best Thing of the Day: Bouncing Back From a Bad Cyberattack

Marks & Spencer's grocery sales soared over the summer, according to retail tracker Worldpanel by Numerator, as the British supermarket bounced back after last year’s cyberattack.

Worst Thing of the Day: Anthropic's Human Review Team Thinks You're Spending Too Much Money

Claude Money is Anthropic's personal finance solution that lets users connect their bank accounts to Claude.

Bonus Worst Thing of the Day: Mass Surveillance to Keep Young People Out of Pubs

Younger drinkers in England and Wales will be able to prove their age with a digital ID starting this week as new laws give pubs, off-licenses, nightclubs and restaurants the right to use biometric scanning technology to check customers are over 18.

Closing Thought