
The news that moves policy, portfolios, and patient safety.
By Jess Jessop | September 5, 2026 | Issue #147

CONVERSATIONAL AI WATCH
Jess Jessop
Publisher of Conversational AI Watch · Author of Therapist in the Loop · Founder, Clinician Assist
Disabled Navy veteran and mental health survivor building conversational AI in mental health since 2017.
The book, the compliance map, the 988 SAFE Act, the daily archive, and the story behind the beat:

OpenAI Hires Schumer’s Daughter to Work the States
The Hire. OpenAI hired Chuck Schumer's daughter to run its policy across the Northeast. Jessica Schumer spent this summer as Amazon's lead lobbyist in New York City. Her father is the Senate Minority Leader, and OpenAI's published strategy ends in a federal law. Nine days ago this paper ran Why OpenAI Wrote Its Own Regulation. Story 1 picks it up.
. . .
The Admission. OpenAI broke its silence on the German wiki on Saturday morning and conceded something larger than the incident. The company says the field has no clear standard for reporting when a model turns up somewhere it was not allowed, and that it is writing one. The report called that the first move. Story 2.
. . .
The Brief. The United States filed in Manhattan on the side of OpenAI against the New York Times, and told the judge that training on copyrighted work is extraordinarily transformative. First time the federal government has taken a side in the wave of suits over AI training. Story 3.
. . .
The Blackout. ChatGPT, Claude and Grok all broke within eighty minutes on Thursday. SpaceX blamed Grok's outage on its Memphis compute center and apologized to "impacted compute partners" it would not name. The other two companies pointed only at themselves. Story 4.
. . .
The Hash. Known abuse images carry a digital fingerprint. Lawyers say a child protection center used those fingerprints to tie what Grok generated to a real, living, identifiable person. Story 5 explains why that changes the case.
. . .
The Gap. Brussels put ChatGPT in its strictest tier and filed it as a search engine. Ask it who the candidates are and you are covered. Ask it who to vote for and you may not be. Story 6.
. . .
JESS'S TAKE.
Nine days ago I published a special report on how OpenAI came to write the rules it asks to be judged by. Why OpenAI Wrote Its Own Regulation laid out five moves, from the reference text nobody else had drafted to the eight million dollars that followed one assemblyman into his next primary.
It ended on the endgame. One negotiation in Washington instead of fifty in state capitols.
That reading stands. What I did not have, and should have had, is that the man running the operation published it himself first.
On July 15, seven weeks before my report, OpenAI posted a piece under Chris Lehane's byline titled "The US is advancing AI safety through state and federal action." The deck says it outright. "Through reverse federalism, states are aligning on AI safeguards as the federal government builds toward a national standard."
Here is the mechanism, in his words. "In the absence of one, states can move us there by passing laws that mirror one another. Step by step, they can create a de facto national standard."
Here is the destination, in his words. "Given the size and influence of the states that have already enacted directionally aligned laws, incorporating those approaches into federal legislation should make it easier to establish a single national frontier safety regime."
States first. Washington consolidates.
That is not my inference off a stack of FEC filings and lobbying disclosures. That is the company's own post, under the name of the man who runs its politics, sitting on its website since the middle of July.
I assembled that argument out of documents because I did not know he had already written it down. He had. Nobody read it.
This morning he hired three people to work it. One for the Southeast, one for state cyber policy, and, for the Northeast, Jessica Schumer.
Her father is the Senate Minority Leader. He is also the man who, running the Senate, launched the SAFE Innovation Framework and sat the industry's chief executives down in the AI Insight Forums. Republican groups asked him to recuse himself from AI policy over his daughters' Big Tech jobs in 2023. He did not. He recused himself over his brother and a cable merger in 2014, so he knows how.
I am not going to tell you she was hired for her last name. I am going to tell you that the strategy ends in a federal bill, that the Senate Minority Leader decides which federal bills move, and that OpenAI just put his daughter on the Northeast. Those are three facts. Arrange them yourself.
Two other things this week belong on the same page.
OpenAI acknowledged, for the first time, that its agents wrote to a German wiki and used it as a message board. In the same breath it said the field has no clear standard for reporting when a model turns up somewhere it was not allowed, and that it intends to write one.
That is the first move in the report, running on the public record. You do not have to lobby for your language to be adopted if your language is the only complete draft in the room.
Then the Justice Department filed a statement of interest in Manhattan, on OpenAI's side, against the New York Times. Not a regulator. Not a committee. The United States, in its own name, telling a federal judge the country must retain global leadership in artificial intelligence.
Three hires, one admission, one brief. The same company is drafting the state text, drafting the rule for when it has to disclose, and standing beside the government in court.
That is not three stories. That is one firm furnishing the room it will be judged in.
IN THIS ISSUE
LISTEN & WATCH ANYWHERE
ALSO ON Substack · Full archive · X
OPENAI HIRES SCHUMER’S DAUGHTER TO WORK THE STATES.
Jessica Schumer is going to work for OpenAI. She will run the company's policy and partnerships across the Northeast, a spokesperson told Axios on September 5. Her father is Chuck Schumer, the Senate Minority Leader, who as majority leader built the Senate's first serious attempt to write an artificial intelligence law. Until this week she was Amazon's lead lobbyist in New York City.
She is one of three state policy hires announced Saturday, and the three of them were hired to work a strategy the company's top lobbyist, Chris Lehane, has been calling reverse federalism in public since May.
Schumer was chief of staff to the Council of Economic Advisers under President Obama and policy director for Senator Tim Kaine during his 2016 run for vice president. She joined Amazon in 2020 as a senior policy director and became head of New York policy and community engagement in January.
The American Prospect reported on August 11 that she was the Amazon lobbyist leading the fight against New York City's Delivery Protection Act, a bill setting labor standards for delivery drivers that Mayor Zohran Mamdani had endorsed days earlier.
One source told the Prospect it was "by far the most Amazon has ever spent, more than HQ2 lobbying spent, with Jessica Schumer at the helm." Amazon and Schumer did not respond to the Prospect's request for comment.
Caulder Harvill-Childs, who most recently managed public policy for Meta and previously worked for Georgia House Speaker Jon Burns, will lead state policy across the Southeast. Thomas MacLellan will lead state cyber defense policy after more than twenty years at Palo Alto Networks, Symantec, FireEye, and the National Governors Association.
The doctrine they are staffing is neither new nor informal. Lehane used the phrase in a May 20 interview with POLITICO, describing the plan as trying "to use a bunch of the big states to come together and mirror each other to de facto create a national standard."
On July 15, OpenAI published it as company doctrine. In a post under Lehane's byline titled "The US is advancing AI safety through state and federal action," the company wrote that "through reverse federalism, states are aligning on AI safeguards as the federal government builds toward a national standard."
The post is explicit about the sequence. "In the absence of one, states can move us there by passing laws that mirror one another. Step by step, they can create a de facto national standard."
It is equally explicit about where that leads. "Given the size and influence of the states that have already enacted directionally aligned laws, incorporating those approaches into federal legislation should make it easier to establish a single national frontier safety regime."
That last sentence is why the Northeast hire is worth a second look. The stated destination is federal legislation. The Senate Minority Leader is the Democratic gatekeeper for any federal bill that moves, and Schumer, as majority leader, launched the SAFE Innovation Framework in June 2023 and convened the closed-door AI Insight Forums that began that September, seating the industry's chief executives in a room with senators.
His family's tech employment has been raised against him before, repeatedly, and specifically on artificial intelligence. In July 2022, sixteen advocacy groups pressed him to recuse himself from Big Tech legislation. In August 2023, the Bull Moose Project and the New York Young Republican Club wrote to him citing Jessica Schumer's Amazon lobbying and her sister Alison Schumer's work at Meta.
"Owing to your familial ties to Big Tech, we urge you to recuse yourself from policy deliberations on AI issues," that letter read.
The groups pointed to a precedent he set himself. In 2014, after reports of his brother's involvement in Comcast's attempt to acquire Time Warner Cable, Schumer recused himself, and his spokesperson said he would do so "to avoid any appearance of bias."
He has not recused himself from artificial intelligence. The Prospect reported that more than eighty former Schumer staffers were working directly or indirectly for Big Tech companies during the 2022 fight over self-preferencing bills, which never came to a floor vote.
Schumer's office did not respond to the Prospect's request for comment in August. Axios's report on the hires does not address the question, and this newsletter found no public comment from the senator about his daughter's move to OpenAI.
Lehane's July post names the states that have already aligned: California, New York and, most recently, Illinois. Axios reports OpenAI "has so far successfully influenced California and New York's AI transparency laws."
For Legislators: OpenAI's own July 15 post says the goal is large states passing laws that mirror one another until they become a de facto national standard, then folding those approaches into federal legislation. The person hired to work the Northeast is the daughter of the senator who would manage that federal bill on the Democratic side.
For Investors: OpenAI is staffing state policy the way a campaign staffs regions, and it recruited from Amazon and Meta public policy to do it. Three named employees now own that relationship across the Northeast, the Southeast, and state cyber policy.
For Regulators: California's SB 53 lets a frontier developer satisfy the state by complying with a federal reporting rule instead, but only after the state Office of Emergency Services designates that federal rule as substantially equivalent or stricter, and only after the developer declares its intent to rely on it. The carryover runs federal to state, which makes the identity of the eventual federal standard the whole question.
For Citizens: Nothing here is unlawful and nothing here is hidden. It is in Axios, in New York lobbying disclosures, and on OpenAI's own website. The question is what a company expects to buy when the endgame it published is a federal law.
Why it matters: OpenAI's published strategy ends in a single federal standard. On Saturday it hired the Senate Minority Leader's daughter, who spent this summer running Amazon's most expensive lobbying campaign in New York City, to run its policy across the Northeast.
Source: Maria Curi, "Exclusive: OpenAI expands policy team amid legislative headwinds," Axios, Sept. 5, 2026, https://www.axios.com/2026/09/05/openai-state-policy-team; Chris Lehane, "The US is advancing AI safety through state and federal action," OpenAI, July 15, 2026, https://openai.com/index/advancing-ai-safety-through-state-and-federal-action/; David Dayen and Zachary Groz, The American Prospect, Aug. 11, 2026, https://prospect.org/2026/08/11/mamdani-schumer-lobbying-new-york-city-council-amazon-delivery-drivers/; Elizabeth Elkind, Fox News, Aug. 3, 2023, https://www.foxnews.com/politics/schumer-butt-out-ai-reg-talks-familial-ties-big-tech; Brendan Bordelon, POLITICO, May 20, 2026; California SB 53, Bus. & Prof. Code 22757.13.
. . .
OPENAI ADMITS THE WIKI INCIDENT, SAYS NO CLEAR STANDARD EXISTS.
On Saturday morning, OpenAI posted on X and acknowledged for the first time that its own agents had written to a German wiki. The company’s concession was narrow. It called the episode the “wiki incident” and said its agents “wrote to several internet sites.”
The rest is the researchers’ reconstruction. Sydney Von Arx, Spencer Kitts, Thomas Larsen and Cormac Slade Byrd, working with the Nightingale Collective, say the agents were assigned a timed web-lookup task with permission to read the internet but not write to it, and found a way to write anyway. They counted posts under more than 3,700 distinct self-given names, about 18,000 messages, over roughly six weeks.
The researchers published their findings on Friday. Saturday’s post was the first time OpenAI acknowledged its own involvement.
OpenAI’s statement did not concede a break-in. Ars Technica reported that the company said the material it had reviewed so far did not indicate the agents hacked the wiki. Its one direct quote was narrower still: “We are now carefully reviewing its contents and will take any necessary next steps.”
According to the researchers’ report, the agents wrote to the wiki repeatedly, discussed impersonating site moderators, and floated possible attack methods against the site itself.
“These AIs colluded to share answers, research their environment, and bypass sandbox restrictions,” the researchers wrote.
The researchers said they could only see the agents’ public posts, not their internal reasoning, and that logs of the agents’ actions likely meant OpenAI already knew about the activity before the report published. OpenAI confirmed that guess.
The company also confirmed a second guess, that this swarm was distinct from the one behind the Hugging Face breach reported a week earlier, and that the two were not part of the same internal test.
OpenAI’s statement went further than a confirmation. “It’s past time for us to define standards for when and how we share misalignment incidents, not just misalignment properties of our models,” the company wrote on X.
OpenAI said it had typically treated agents acting in unintended ways as a research question, but that incidents touching real-world targets, particularly the Hugging Face breach, showed the need to take stock. The company said it is building a new reporting framework and will share it in upcoming weeks.
In the same post the company was more precise than its critics have been. “We and the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment,” it wrote, adding that it is “working with dozens of government regulatory agencies worldwide on these issues.”
California already requires some of this. SB 53 obliges a frontier developer to report a critical safety incident to the Office of Emergency Services within 15 days. Whether a swarm of agents writing to a public wiki meets that definition is arguable, and OpenAI did not say whether it considered the episode reportable.
When OpenAI let the outside safety group METR examine the Hugging Face breakout, it set the terms itself. Ars Technica, citing the New York Times, reported that OpenAI permitted METR to review only a single week of that event.
Ajeya Cotra, one of the independent researchers who investigated the Hugging Face incident, had already put that earlier breakout in starker terms. “Compared to these reward hacks from six months ago, this incident feels like it’s more than 50% of the way to full-blown AI takeover, routing through first taking over the AI company itself,” she said of the Hugging Face event.
For Legislators: OpenAI says the field has no clear standard for reporting misalignment, and that it intends to write one. The company proposing to write it is the company that said nothing about this episode for ten weeks.
For Investors: Hugging Face disclosed its own breach in July and OpenAI followed within days. The wiki was different: outside researchers surfaced it, ten weeks after the activity stopped. A disclosure regime that depends on volunteers finding the evidence is a liability you cannot price from filings.
For Regulators: This incident ran six weeks and was reported by four independent researchers before the company said a word. Any reporting rule that starts the clock at company discovery has to answer what happens when the company does not start it.
For Builders: The agents were given read access to the internet and no write access, and they found a way to write anyway. The activity ran about six weeks and roughly 18,000 messages before OpenAI shut it down in late June, and the public learned of it ten weeks after that.
Why it matters: OpenAI has confirmed two separate agent swarms wrote to the open internet without its authorization. It said nothing about the second for ten weeks, until four outside researchers published, and it says the field still has no clear standard for when it has to tell anyone.
Source: Goodin, Ars Technica, Sept. 4, 2026, https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/; Hart, The Verge, Sept. 5, 2026, https://www.theverge.com/ai-artificial-intelligence/990773/openai-german-wiki-incident.
. . .
JUSTICE DEPARTMENT BACKS OPENAI AGAINST THE TIMES.
On Tuesday, September 1, 2026, the United States filed a brief in Manhattan federal court in The New York Times' copyright lawsuit against OpenAI and Microsoft. It is the first time the federal government has taken a side in the wave of lawsuits over AI training on copyrighted work, according to Reuters and the Times.
The brief argues that training large language models on copyrighted material is "extraordinarily" transformative, and that a mistaken reading of fair use doctrine could cost the country its lead in artificial intelligence. A brief like this one carries advisory rather than legal weight. It cannot decide the case. It can only try to move the judge.
The government told the court that the United States "has a strong interest in continuing to develop a robust and competitive artificial intelligence industry," and that it is "critical for the United States to 'retain global leadership in artificial intelligence'."
The brief went further than the case in front of it. "Constraining LLM development under a misunderstanding of fair use doctrine would thwart such creative and scientific progress while hindering American prosperity and economic mobility," it said.
Associate Attorney General Stanley E. Woodward Jr., who called it a historic statement of interest, posted the position to X. "POTUS has made clear that AI dominance is critical to promote national security, prosperity, and economic mobility for all Americans," he wrote. "This Administration will never let our Nation be at a disadvantage relative to our foreign adversaries based on a plainly incorrect understanding of copyright law."
Separately, on Wednesday, commerce secretary Howard Lutnick told G20 officials meeting in North Carolina that their countries should embrace fair use and let AI companies train on creators' work while finding a way to protect artists, the Guardian reported.
The underlying case is the one the Times filed in 2023, accusing OpenAI and its largest financial backer, Microsoft, of using millions of newspaper articles without permission to train OpenAI's chatbot. Other newspapers have joined since.
Times spokesman Graham James said the government's position "would undermine the sustainability of the human-created content that a healthy society depends on." OpenAI did not respond to requests for comment. The Guardian notes that the first two judges to consider the fair use question in AI cases issued diverging rulings last year, which is part of why one more brief, even an advisory one, has weight to throw.
The same week, in new filings of its own, Microsoft told the court it provided 8.2 million Copilot chat logs to an expert hired by news publishers. Microsoft says those logs were chosen because they hit on keywords implicating the plaintiffs' websites.
Of those, Microsoft says 59,545 logs contained at least 16 words in common with news content used to ground the model. Microsoft says a separate expert for the Center for Investigative Reporting found 51 instances of "substantial overlap" with that outlet's work.
In a related authors' suit, Microsoft says, an expert examined the same 8.2 million conversations and found only 24 responses with at least 30 matching words, with any match at all in just 10 of 212 books reviewed.
Microsoft argues the numbers support its fair use defense. Every figure in the three paragraphs above is Microsoft's characterization of its own filing. No independent expert has checked them.
The Times' lead counsel, Ian Crosby, was not persuaded. "The documents and testimony uncovered during discovery lead to only one conclusion: Microsoft and OpenAI stole from The New York Times to make commercial products that substitute for its journalism, threaten its business, and undermine its industry," he said. "We look forward to Microsoft and OpenAI being held accountable for their theft."
On September 4, the Seattle Times Company and Newsday sued Microsoft and OpenAI's corporate family jointly in the Southern District of New York (S.D.N.Y.), docket 1:26-cv-07644. The complaint claims the companies trained on and reproduced the papers' journalism without permission, and adds trademark claims over fabricated content attributed to them.
For Legislators: The executive branch has now told a federal court which side of the fair use question it wants to win. Any federal AI standard that follows arrives from an administration already on record for the defendants.
For Investors: Microsoft is arguing its own discovery numbers as a fair use defense, and the plaintiffs' counsel calls the same record proof of theft. The training-data liability that has hung over every model company since 2023 now has a government thumb on one side of the scale.
For Regulators: This brief cannot decide the case on its own. It can still shape how the two diverging fair use rulings from last year get reconciled.
For Journalists: The Seattle Times and Newsday filed jointly on September 4. The Daily News and The New York Times want the fair use defense rejected outright, the Mercury News reported. The newsroom side of this fight is still adding plaintiffs.
Why it matters: The filing is a statement of interest under 28 U.S.C. 517. It does not make the federal government a party to the Times' case and it cannot decide it. But it is the first time since the Times sued in 2023 that the United States government has told a court, in writing, which side it wants to win.
Source: The Guardian, Sept. 2, 2026, https://www.theguardian.com/technology/2026/sep/02/trump-new-york-times-lawsuit-ai; The Verge, Sept. 4, 2026, https://www.theverge.com/policy/990267/microsoft-openai-new-york-times-authors-lawsuit; The Seattle Times Company v. OpenAI Inc., 1:26-cv-07644 (S.D.N.Y. filed Sept. 4, 2026), https://www.courtlistener.com/docket/74754553/the-seattle-times-company-v-openai-inc/; Mercury News, Sept. 4, 2026, https://www.mercurynews.com/2026/09/04/daily-news-ny-times-want-fair-use-claim-tossed-in-copyright-case-against-openai-microsoft-2/.
. . .
THREE CHATBOTS WENT DARK AND NOBODY WILL SAY WHY.
On Thursday morning, September 3, ChatGPT, Claude and Grok all started throwing errors within eighty minutes of one another, and none of the three companies that built them pointed to a shared cause.
Anthropic logged elevated errors starting at 6:26 am Pacific. xAI's Grok followed four minutes later. OpenAI's ChatGPT and Codex broke at 7:43 am. Cloudflare, Amazon Web Services and Microsoft Azure, the infrastructure providers that usually explain a shared failure like this, reported no outages that day.
Anthropic's status page began alerting a "partial outage" at 6:26 am Pacific, describing "elevated errors on requests to Claude Mythos 5.1, Claude Fable 5.1, and Claude Opus 5." The company said at 6:41 am that it had identified the cause. A fix went out at 9:06 am, and Anthropic said impact ended at 9:16.
xAI posted "investigating outage" on its own status page at 6:30 am: "Grok is experiencing issues. We are working on restoring service as quickly as possible." The company marked the incident complete at 10:05 am, writing, "We have resolved the situation, and traffic is healthy again."
OpenAI spokesperson Kathleen Chaykowski told WIRED that "a routing error starting around 7:43 am PT on Thursday, September 3, made ChatGPT and Codex unavailable for some users across platforms." She said a solution was in place by about 8:17 am and continued to be monitored.
SpaceX, xAI's parent company, said Thursday afternoon that the Grok outage traced to "an outage at our Memphis compute center this morning," adding, "We'd also like to apologize to our impacted compute partners."
In May, Anthropic agreed to take all of the compute capacity at SpaceX's Colossus 1 data center, which sits in South Memphis. SpaceX did not name the partners it was apologizing to, and Anthropic declined to comment. The contract is a documented link. It is not evidence of what caused Anthropic's outage or OpenAI's.
Neither OpenAI nor Anthropic cited an external source for their own incidents. SpaceX did not respond to WIRED's request for comment. Anthropic declined to comment on the episode altogether. Typically, multiple outages hitting one sector at the same time point to a shared cloud provider or content delivery network serving several customers at once. That did not happen here. No such vendor came forward.
There were also scattered user reports of a Google Gemini outage that same morning. Google did not confirm one and logged no incident on its own status dashboard, and it did not respond to WIRED's request for comment. That keeps the confirmed count at three, ChatGPT and Codex, Claude, and Grok, not the five products some other reports claimed.
For Legislators: Three competing conversational products failed inside eighty minutes and no company will name a shared cause. None of the three infrastructure providers usually blamed for a shared failure, Cloudflare, Amazon Web Services, or Microsoft Azure, reported an outage that day.
For Investors: SpaceX apologized to "impacted compute partners" it would not name, on the morning a Memphis data center Anthropic had contracted in full went down. Neither company will say whether those are the same fact.
For Regulators: Three status pages, three timelines, one apology to partners nobody will name. There is no filing anywhere that would tell a regulator whether this was one event or three.
For Clinicians: A client leaning on a chatbot between sessions gets no advance warning and no explanation. Three of the largest failed on a Thursday morning with neither.
Why it matters: Three separate chatbots from three competing companies broke within eighty minutes on September 3. By day's end, SpaceX had apologized to unnamed "impacted compute partners," while OpenAI and Anthropic each pointed only to their own systems.
Source: Lily Hay Newman, "Nobody Is Saying Why OpenAI and Anthropic Had Outages Today," WIRED, Sep. 3, 2026, 5:56 p.m. https://www.wired.com/story/nobody-is-saying-why-openai-and-anthropic-had-outages-today/
. . .
GROK SUIT SAYS OLD ABUSE IMAGES MADE NEW ONES.
A child sexual abuse survivor identified in court papers as Jane Doe says Elon Musk's chatbot Grok used images of her own abuse to make new, illegal pictures of her. The lawsuit against X.AI Corp. and X.AI LLC was filed August 26, 2026, in the Northern District of California, and this newsletter reported the filing when it landed.
What is new is her attorneys, speaking on the record, explaining the mechanism they say identifies her.
Known child sexual abuse material, CSAM, carries a digital fingerprint, called a hash. Attorneys for Doe say the Canadian Centre for Child Protection used that fingerprint to identify AI-generated images on the social platform X depicting their client, which they say ties the output to a real, living, identifiable person.
The complaint states plainly: "Using real images of Plaintiff and class members, Grok generated child pornography depicting Plaintiff and class members." It accuses xAI of both generating that material and of ingesting abuse images depicting Doe into the company's datasets.
Other Grok suits allege a different sequence. A separate case brought by a group of Tennessee teenagers accuses Grok of taking non-explicit photos of minors and removing their clothing to produce abuse material.
Doe's case alleges Grok used real, pre-existing abuse images of her to generate new material, and that xAI separately ingested abuse images depicting her into its own datasets after new images were posted publicly. That is the distinction.
Margaret Mabie, an attorney for the plaintiff, explained why that matters legally: "The difference here between many criminal cases that you'll see with AI-generated material is that you cannot prove that the kid in the material is real. But here, because you can associate it with the series, we know that it is an identifiable victim who is still alive and was a real child in the photo."
Mabie also described what the technology changes about the harm itself: "The problem here is that at least for our client, for the past 20 years, the universe of images of them was finite. The fear now is that new criminal acts, new offensive behavior, new ideas of what can be done to them can now be created using AI. They can generate new abuse."
The complaint proposes a class of at least thousands of minors who experienced similar harm. Musk has denied he was aware Grok had ever produced "any naked underage images," a denial he made in January. Neither xAI nor SpaceX, which acquired xAI in February, returned requests for comment on the lawsuit; the Canadian Centre for Child Protection declined to comment.
Separately, xAI has sued two of its own users, both facing criminal charges for allegedly generating sexualized images of minors using Grok. The company wants those two men to pay the costs of the lawsuits their victims have filed against xAI.
For Legislators: Hash matching against known abuse material is an established practice at child protection organizations. The complaint alleges xAI ignored industry-standard safeguards against abuse material. That makes a hashing requirement a concrete and testable statutory ask.
For Investors: xAI is defending a proposed class of at least thousands of minors while also suing two of its own users to make them pay the costs of victims' claims against the company. That is an unusual posture to explain to an underwriter.
For Regulators: The distinction in this complaint matters for enforcement. Where output can be matched to a known series, her attorney says, the victim is identifiable and, in this case, living. That closes the evidentiary gap that stops other AI-generated abuse cases from proving a real child.
For Clinicians: A client whose abuse imagery can be regenerated on demand faces a harm with no endpoint. Her attorney's framing is that a finite set of images has become an open one.
Why it matters: Attorneys for Jane Doe say a known-CSAM hash match, not a guess about a photo's origin, is what lets them identify her as a real, living, identifiable victim in AI-generated images on X, a mechanism the Guardian reports sets this case apart from the other abuse suits against xAI.
Source: Nick Robins-Early, "Child sexual abuse survivor alleges Elon Musk's AI chatbot used photos of her to generate new illegal images," The Guardian, September 3, 2026. Jane Doe v. X.AI Corp. and X.AI LLC, case 5:26-cv-09016, U.S. District Court, Northern District of California, filed August 26, 2026, reported in CAW Issue #141.
. . .
BRUSSELS RULES REACH THE SEARCH, NOT THE CHAT.
Ask ChatGPT to name the candidates in a local election, and Brussels now has oversight of how it answers. Ask the same chatbot who to vote for, and the conversation that follows may sit outside that oversight entirely.
On 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act (DSA), the same tier that governs Google Search and Microsoft’s Bing. As POLITICO reads it, the designation reaches only the parts of ChatGPT that act as a search engine.
OpenAI risks fines of up to 6 percent of its annual global revenue if it misses the obligations that come with that tier.
The category was a choice, not the only option. Under the Digital Services Act, the Commission could instead have classified ChatGPT as a Very Large Online Platform, the label usually reserved for social media and e-commerce sites and built around different obligations. It chose search engine instead. Neither label, POLITICO reported, “corresponds to the range of uses that chatbots offer.”
The gap shows up in a single comparison. “Asking ChatGPT to name the candidates in a local election should now be covered under the DSA,” POLITICO reported. “Instead, a conversation between a user and a chatbot about who to vote for, where misinformation could come out, may not be.”
Christel Schaldemose, the Danish Social Democrat member of the European Parliament who was among the law’s key negotiators, said ChatGPT “is much more than a search engine and there are also risks connected to the chatbot itself which fall outside the (regulation’s) strongest obligations.” She pointed to risks to children, including “emotional dependency and manipulative or addictive design,” and urged the Commission to clarify how those risks are covered.
João Pedro Quintais, an associate law professor at the University of Amsterdam, called ChatGPT “a hybrid” technology “that has the functions of both a search engine and online platforms, as well as others closer to those of a publisher of its own content.”
Daniel Leufer, emerging technologies policy lead at Access Now, said existing AI Act guidance on systemic risk “is more focused on so-called existential risks than risks to fundamental rights.” He called the Digital Services Act designation a chance “to get into the weeds of design decisions and treat ChatGPT more like what it really is, which is a product.”
Brando Benifei, the Italian Social Democrat lawmaker who leads the European Parliament’s work on artificial intelligence, defended splitting oversight between the AI Act and the Digital Services Act, saying the two rulebooks can “powerfully complement” one another.
He acknowledged that oversight through the Digital Services Act is “urgently needed” to protect the people using AI tools, pointing to “dangerous mental health dependencies” that people develop through companion chatbots. “Scrutiny now expands from the underlying model to how these services are actually designed and deployed,” he said.
Underneath the designation sits an older, unresolved question. The Digital Services Act, like most platform law, is built around “safe harbor,” the principle that a company is not liable for content on its service because users uploaded it. A two-way exchange between a person and a chatbot does not fit that frame cleanly, since the chatbot itself generates half the conversation.
Whether that half counts as user-generated content is a question the law has not answered.
The current law was finalized in 2022, before the boom in chatbots. Working out which category ChatGPT belonged in took the Commission just under a year. Experts told POLITICO that without seeing the full text of the designation, it remains hard to know exactly what obligations OpenAI now carries.
For Legislators: The European Union spent close to a year deciding which existing box a chatbot belongs in and put it in the one built for search. Categories written before chatbots existed did not stretch to cover this one.
For Investors: OpenAI faces fines of up to 6 percent of annual global revenue on the obligations it did draw, and the scope of what it actually owes is not knowable until the full designation text is public.
For Regulators: Platform law rests on safe harbor, the principle that users upload the content. A chatbot generates half the exchange, and whether that half counts as user-generated content is a question the law has not answered.
For Clinicians: Schaldemose says emotional dependency and addictive design are risks to children that fall outside the law's strongest obligations. Benifei says oversight of dangerous mental health dependencies in companion chatbots is urgently needed under the Digital Services Act.
Why it matters: The Digital Services Act was finalized in 2022, four years before a chatbot needed a category at all, and its safe harbor framework assumes a platform hosts content that users upload. ChatGPT talks back. The Commission spent close to a year deciding which box to put it in, and the box it chose, by POLITICO’s own reporting, may not reach the conversation itself.
Source: POLITICO Europe, Eliza Gkritsi and Pieter Haeck, “Hey EU, your new rules for ChatGPT don’t cover chat,” September 2, 2026, https://www.politico.eu/article/new-eu-rules-for-chatgpt-dont-cover-chat/
. . .
CLOSE.
Three state operatives hired to a doctrine published in July. A company admitting the field has no clear rule requiring it to tell you. The United States filing on the side of the company against the newspaper.
Three chatbots down inside eighty minutes and an apology to partners nobody will name. A hash that lawyers say ties a machine's output to a living child. A European rulebook that reaches the search and may stop short of the conversation.
One day's paper.
We keep the ledger.
READER PULSE
OpenAI hired the Senate leader’s daughter.
TODAY’S QUESTION
OpenAI's lobbyist calls it reverse federalism. What should a legislator do when the industry asks for a rule?
One tap. Results in tomorrow’s issue and on the web.
THE BOOK • OUT NOW

Therapist in the Loop
by Jess Jessop
One billion people live with a mental health condition. There will never be enough therapists. The machines are already in the room. This book is the map for what happens next.
The machine can help.
It cannot be left in charge.
Kindle, hardcover, and paperback
MORE ON OUR RADAR.
Hawaii enacts a chatbot disclosure and safety law A new state act lands disclosure and safety duties on chatbot makers. Other legislatures will lift the language.
Judge refuses to block Minnesota's nudify ban A federal judge rejected the bid by Musk-owned SpaceXAI to halt the state ban on AI nudification tools.
Character.AI adds age checks The companion-bot vendor carrying the heaviest litigation load published new safety terms and an age verification flow.
Authors fight publishers over Anthropic's settlement Writers and publishers are wrangling over how to split the $1.5 billion Anthropic copyright settlement.
Retrieval does not make a therapy bot safer A new paper finds retrieval augmentation can hurt grounding on distressed and safety-sensitive queries.
THIS ISSUE
No rule said they had to tell you.
Brush Your Brain - The jingle
that started a movement
If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).
Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.