> daily_signal(2026_05_16)
An AI cracked Apple's newest Mac security in five days. Apple spent five years building that lock.
PickBits Daily Signal · Saturday, May 16, 2026
// tl;dr
- Anthropic's Mythos AI helped researchers bypass Apple's Memory Integrity Enforcement on the M5 chip in five days. A Palo Alto security firm named Calif used Claude Mythos Preview through Anthropic's Project Glasswing to chain two macOS kernel bugs into a working privilege-escalation exploit. Apple spent roughly five years and a multi-billion-dollar engineering budget building that defense. Disclosure was hand-delivered to Apple in Cupertino.
- Seventy percent of Americans now oppose a data center being built near their home, less than the share who would accept a nuclear power plant. Gallup released the poll Wednesday: 71 percent oppose data centers, 53 percent oppose nuclear. 48 percent are strongly opposed. The reasons name water, energy, pollution, and traffic. Reno's June 1 follow-up vote on extending its moratorium just got a national audience.
- OpenAI endorsed mandatory third-party AI safety audits in a state bill for the first time. VP of global policy Ann O'Leary backed Illinois SB 315 on Tuesday. Anthropic also endorsed it. The bill is modeled on California SB 53 and New York's RAISE Act and applies to AI companies with more than $500 million in revenue. It requires an annual safety framework, incident reporting, and an outside auditor.
- Meta is cutting 8,000 jobs on Tuesday, May 20, and canceling 6,000 open roles, to free up budget for $115 to $135 billion in 2026 AI spending. The reorg moves teams into AI pods under new chief AI officer Alexandr Wang's Superintelligence Labs. The company posted $201 billion in 2025 revenue, up 22 percent. Reality Labs, the Facebook division, recruiting, and global operations are all affected.
- A class action filed in San Diego federal court says ChatGPT shipped your private chats to Facebook and Google through ad trackers. Lead plaintiff Amargo Couture says OpenAI embedded Meta's Facebook Pixel and Google Analytics on the ChatGPT.com web interface and sent browser tab titles derived from queries, plus cookies tying the session to specific Facebook IDs, to Meta and Google without consent. The complaint cites the California Invasion of Privacy Act, which carries statutory damages of up to $5,000 per violation.
Today the AI buildout produced its first published Mac kernel exploit and the first state bill OpenAI has endorsed that includes a mandatory outside auditor on the same week. A Palo Alto security firm using Anthropic's preview-tier offensive model bypassed an Apple defense it took Apple five years and a multi-billion-dollar engineering budget to ship, and they did it in five days. Gallup put a national number on the data-center backlash that has been showing up town by town: seven in ten Americans now do not want one near them, a level of public opposition that exceeds the share that opposes a nuclear plant next door. OpenAI walked into the Illinois statehouse and endorsed mandatory third-party audits for the first time, while Meta finalized a 10 percent workforce cut for Tuesday to pay for an AI build that the company itself frames as a generational reshape. And on the consumer side, OpenAI got sued in San Diego federal court for what the complaint says was the silent routing of paid ChatGPT users' private queries into Facebook and Google's ad pipes.
AI broke a Mac defense in five days, polled past nuclear plants on neighborhood opposition, sat down to write its own audit rules, paid for the next 8,000 layoff slips, and shipped your chats to Facebook in the same week.
1. An AI cracked Apple's newest Mac security in five days. Apple spent five years building that lock.
The AI-as-offensive-cyber-tool moment just arrived in Cupertino. A Palo Alto security firm called Calif used Claude Mythos Preview, the offensive cyber preview of Anthropic's frontier model exposed through the company's invite-only Project Glasswing, to chain two newly found macOS kernel bugs into a working local privilege-escalation exploit on Apple's M5 hardware running macOS 26.4.1. The exploit bypasses Memory Integrity Enforcement (MIE), the defense Apple shipped after roughly five years of engineering work and an estimated multi-billion-dollar internal investment. The full chain came together in five days. Calif's team hand-delivered the disclosure to Apple in Cupertino; the firm has said it will publish the 55-page technical write-up only after Apple ships the patch.
Two pieces of context matter. First, this was human-in-the-loop. Researchers worked alongside the model, prompting it on candidate bug classes and verifying outputs; the AI did not independently invent the chain. Second, Mythos has prior art at this speed: earlier in 2026 it found more than 100 high-severity Firefox bugs in two weeks. The data-only kernel chain Calif produced starts as an unprivileged local user and ends as root, using two vulnerabilities, several exploit techniques, and standard system calls; it does not require an internet-facing entry point, but root on a Mac is the prize an attacker needs after they have already landed code on the machine through a more conventional means (a malicious download, a vulnerable third-party app, a supply-chain compromise). Mythos as a class of model is the same one the European Commission has been arguing over access to, and the same one Anthropic has placed inside a restricted government-and-private-security-firm whitelist all year.
2. Seventy percent of Americans don't want a data center built near them. That's less popular than a nuclear plant.
The town-by-town backlash now has a national number. Gallup released a national poll Wednesday showing 71 percent of Americans oppose the construction of an AI data center in their local area, with 48 percent strongly opposed. By comparison, 53 percent oppose a nuclear power plant nearby. The survey ran by telephone from March 2-18, 2026, on a random sample of 1,000 adults in all 50 states and DC. The named reasons for opposition: water and energy draw, pollution including noise and air pollution, higher utility bills and cost-of-living pressure, and quality-of-life concerns (traffic, population, land-use trade-offs). Democrats are more likely to be strongly opposed (56 percent) than Republicans (39 percent), but a majority of Republicans (63 percent) are at least somewhat opposed; this is not a partisan poll.
The number lands at the right moment for the local fights it follows. Reno's 6-to-1 council vote pausing new data centers, covered in yesterday's daily, has a June 1 hearing on extending the moratorium; Normal, Illinois votes Monday, May 18 on a six-month moratorium of its own; Calipatria, California opened public hearings on becoming Imperial County's first data-center moratorium; Spring Hope, North Carolina passed one; Charlotte's city council is voting on a 150-day pause. The Gallup tracker that Data Center Watch maintains has logged 69 local moratoriums already enacted across the US. The poll is the answer to the question a sympathetic council member needed to be able to ask out loud: when you say residents do not want this, how many are we talking about? Seven in ten.
news.gallup.com/poll/709772/americans-oppose-data-centers-area.aspx
If a friend forwarded this to you and you want the signal in your inbox five mornings a week, subscribe at pickbitsai.substack.com. The daily is free.
3. OpenAI agreed to outside audits in Illinois's AI bill — the first time a major lab has signed on to one in state law.
Regulatory action. On Tuesday, May 13, OpenAI formally endorsed Illinois SB 315, a frontier AI safety bill that requires the largest AI companies to develop, publish, and follow a safety framework, report safety incidents, and submit to mandatory annual third-party audits. The endorsement came from Ann O'Leary, OpenAI's VP of global policy: "OpenAI supports the Illinois legislature's efforts to advance frontier AI safety through SB 315." Anthropic also endorsed the bill. This is the first time OpenAI has endorsed a state bill that includes a third-party audit requirement; the company had previously backed an Illinois liability-shield bill (SB 3444) and opposed broader audit mandates.
The bill is closely modeled on California SB 53 (the Transparency in Frontier AI Act, in effect January 1) and New York's RAISE Act. It applies to AI developers with annual gross revenues above $500 million. Required: an annual published framework on industry-standard safety practices, capability evaluations, catastrophic-risk assessment, incident reporting, and a yearly outside audit. The shift is notable in two ways. First, OpenAI's previous position on third-party audits was that they should not be in state law; the Illinois endorsement reverses that. Second, the December 2025 White House executive order that proposed federal preemption of state AI laws is still on the books, which means the OpenAI-Anthropic endorsement is a vote for state law at the moment federal policy was framed as overriding it. The Illinois bill still has to clear committee and a floor vote; nothing has been signed yet.
transformernews.ai/p/is-openai-changing-its-tune-on-ai-laws-illinois-regulation
4. Meta cut 8,000 the day after its earnings beat to fund $135B in AI capex.
Labor reshape at a $200 billion company. Meta notified employees this week that roughly 8,000 jobs, about 10 percent of the company, will be cut starting Tuesday, May 20, alongside the cancellation of 6,000 open roles. The cut runs through every major business unit: Reality Labs, the Facebook division, recruiting, sales, and global operations. The framing is structural, not performance: teams are being reorganized into AI-focused "pods" under new chief AI officer Alexandr Wang's Superintelligence Labs, which Meta stood up earlier in 2026 after the Scale AI acquisition that brought Wang in. Meta has separately said additional cuts are planned for the second half of 2026.
The math underneath the cuts is the part that makes this not a downturn story. Meta posted 2025 revenue of $201 billion, up 22 percent year over year, with Q4 net income of $22.8 billion beating analyst estimates and full-year free cash flow of $43.6 billion. The company's planned 2026 AI capital expenditure is between $115 billion and $135 billion, the largest AI infrastructure spend at any single US company this year. So the trade is explicit: cut 8,000 people whose jobs are being absorbed by the agent reorganization, free the operating budget, fund the largest AI buildout in the company's history. The headcount and the spend are being decided in the same room, by the same people. This puts Meta on the same labor-reshape curve as Cisco (4,000 cuts on the day of a $5.3 billion AI revenue print), GitLab (voluntary separations), GM (IT layoffs), and Walmart (the 1,000-person consolidation in yesterday's daily).
outlookbusiness.com/corporate/meta-to-cut-8000-jobs-on-may-20-what-employees-will-get-after-layoffs
5. A class action says ChatGPT shipped your private chats to Facebook and Google through ad trackers.
Consumer privacy lawsuit. On Tuesday, May 12, a class-action complaint was filed in the US District Court for the Southern District of California against OpenAI Global LLC, alleging that the company embedded Meta's Facebook Pixel and Google Analytics tracking code inside the ChatGPT.com web interface and silently transmitted user data to Meta and Google's advertising ecosystems. The named plaintiff is Amargo Couture, a California resident filing on behalf of all US users who entered queries into ChatGPT.com. The complaint says the transmissions include browser tab titles derived from user queries (the example in the filing: "Super Bowl 2005 Winner" auto-generated as the page title from the matching question), plus session cookies (c_user, fr, fbp) tied to specific Facebook IDs.
The legal theory is two California-and-federal statutes: the California Invasion of Privacy Act (CIPA), which carries statutory damages of up to $5,000 per violation, and the federal Electronic Communications Privacy Act. The proposed class is nationwide for federal claims with a California subclass for CIPA. OpenAI has not commented publicly on the filing as of Thursday. The structural part of the claim, the part that has implications beyond this one suit, is the framing: the complaint argues that a paid AI tool that integrates ad-tech trackers without explicit consumer consent is in the same bucket as a consumer website that does the same, and CIPA is the lever the California courts have already used in dozens of website-pixel class actions. If the theory survives a motion to dismiss, every AI tool with a hosted web interface (Anthropic's Claude.ai, Google's Gemini web, Microsoft Copilot for consumers, Perplexity) gets its web analytics stack audited by the same standard.
cybernews.com/ai-news/openai-chatgpt-class-action-lawsuit-facebook-meta/
» What to watch this week
- Apple's emergency security response for the M5 chain. Calif disclosed in person and is holding the 55-page technical write-up until the patch ships. Watch for a Rapid Security Response push to macOS 26.4.x; the timing answers whether Apple already had a separate fix queued or is now sprinting.
- Normal, Illinois Monday May 18 vote on a six-month data-center moratorium. Calipatria, California's first public hearing on its own freeze. Charlotte's 150-day pause vote. Three more local decisions in the next 10 days; the Gallup top-line is the new prop on every dais.
- Illinois SB 315 floor schedule. The bill needs to clear committee and a chamber vote before the May 30 session deadline. If it makes it to Governor Pritzker's desk this year, OpenAI and Anthropic become the first frontier labs whose audits are state-law-mandated.
- Meta's Tuesday May 20 cut start date. The first concrete number to watch is which units take the biggest share of the 8,000: Reality Labs (the easy answer), or core ads/social engineering (the harder answer about how deeply the agent reorg has eaten the rest of the business).
- OpenAI's response to the SDCA filing. A motion to dismiss or a quiet pixel-pull on ChatGPT.com is the first signal. The discovery posture also tells you whether Anthropic, Google, and Microsoft consumer web AI tools are about to get the same complaint.
Tomorrow's signal lands here.