> daily_signal(2026_05_16)

An AI cracked Apple's newest Mac security in five days. Apple spent five years building that lock.

PickBits Daily Signal · Saturday, May 16, 2026

By Mark Pickering · 7 min read · May 16, 2026

// tl;dr

Today the AI buildout produced its first published Mac kernel exploit and the first state bill OpenAI has endorsed that includes a mandatory outside auditor on the same week. A Palo Alto security firm using Anthropic's preview-tier offensive model bypassed an Apple defense it took Apple five years and a multi-billion-dollar engineering budget to ship, and they did it in five days. Gallup put a national number on the data-center backlash that has been showing up town by town: seven in ten Americans now do not want one near them, a level of public opposition that exceeds the share that opposes a nuclear plant next door. OpenAI walked into the Illinois statehouse and endorsed mandatory third-party audits for the first time, while Meta finalized a 10 percent workforce cut for Tuesday to pay for an AI build that the company itself frames as a generational reshape. And on the consumer side, OpenAI got sued in San Diego federal court for what the complaint says was the silent routing of paid ChatGPT users' private queries into Facebook and Google's ad pipes.

AI broke a Mac defense in five days, polled past nuclear plants on neighborhood opposition, sat down to write its own audit rules, paid for the next 8,000 layoff slips, and shipped your chats to Facebook in the same week.

1. An AI cracked Apple's newest Mac security in five days. Apple spent five years building that lock.

The AI-as-offensive-cyber-tool moment just arrived in Cupertino. A Palo Alto security firm called Calif used Claude Mythos Preview, the offensive cyber preview of Anthropic's frontier model exposed through the company's invite-only Project Glasswing, to chain two newly found macOS kernel bugs into a working local privilege-escalation exploit on Apple's M5 hardware running macOS 26.4.1. The exploit bypasses Memory Integrity Enforcement (MIE), the defense Apple shipped after roughly five years of engineering work and an estimated multi-billion-dollar internal investment. The full chain came together in five days. Calif's team hand-delivered the disclosure to Apple in Cupertino; the firm has said it will publish the 55-page technical write-up only after Apple ships the patch.

Two pieces of context matter. First, this was human-in-the-loop. Researchers worked alongside the model, prompting it on candidate bug classes and verifying outputs; the AI did not independently invent the chain. Second, Mythos has prior art at this speed: earlier in 2026 it found more than 100 high-severity Firefox bugs in two weeks. The data-only kernel chain Calif produced starts as an unprivileged local user and ends as root, using two vulnerabilities, several exploit techniques, and standard system calls; it does not require an internet-facing entry point, but root on a Mac is the prize an attacker needs after they have already landed code on the machine through a more conventional means (a malicious download, a vulnerable third-party app, a supply-chain compromise). Mythos as a class of model is the same one the European Commission has been arguing over access to, and the same one Anthropic has placed inside a restricted government-and-private-security-firm whitelist all year.

9to5Mac coverage of Calif using Anthropic Mythos to build macOS M5 exploit in five days
9to5mac.com · May 14, 2026
Why this matters: If you own a Mac, the security guarantee Apple sold you on the M5 keynote took five days to crack with a model your enterprise is already paying for productivity work. The patch will come, and Calif disclosed responsibly, but the floor for how fast a competent adversary can chain a kernel exploit just dropped from months to a working week. Action this week: open Settings, System Settings, General, Software Update on every Mac in your household and turn on automatic security responses if it is not already on; macOS sandboxing of installed apps, the firewall, and FileVault are the layers that still hold even when a kernel bug exists. If you run IT at a small business or school and your Macs are managed, pull up your MDM (Jamf, Kandji, Mosyle, Apple Business Manager) and check that the Memory Integrity Enforcement profile is enforced and that Rapid Security Responses are set to install automatically; the patch for these bugs will ship as an RSR, not a full macOS release. If you are responsible for an AI vendor list at your employer, write down which of your vendors offers a Mythos-class offensive-cyber tier and whether your contract gates who at the vendor can run it against what.

9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/

2. Seventy percent of Americans don't want a data center built near them. That's less popular than a nuclear plant.

The town-by-town backlash now has a national number. Gallup released a national poll Wednesday showing 71 percent of Americans oppose the construction of an AI data center in their local area, with 48 percent strongly opposed. By comparison, 53 percent oppose a nuclear power plant nearby. The survey ran by telephone from March 2-18, 2026, on a random sample of 1,000 adults in all 50 states and DC. The named reasons for opposition: water and energy draw, pollution including noise and air pollution, higher utility bills and cost-of-living pressure, and quality-of-life concerns (traffic, population, land-use trade-offs). Democrats are more likely to be strongly opposed (56 percent) than Republicans (39 percent), but a majority of Republicans (63 percent) are at least somewhat opposed; this is not a partisan poll.

The number lands at the right moment for the local fights it follows. Reno's 6-to-1 council vote pausing new data centers, covered in yesterday's daily, has a June 1 hearing on extending the moratorium; Normal, Illinois votes Monday, May 18 on a six-month moratorium of its own; Calipatria, California opened public hearings on becoming Imperial County's first data-center moratorium; Spring Hope, North Carolina passed one; Charlotte's city council is voting on a 150-day pause. The Gallup tracker that Data Center Watch maintains has logged 69 local moratoriums already enacted across the US. The poll is the answer to the question a sympathetic council member needed to be able to ask out loud: when you say residents do not want this, how many are we talking about? Seven in ten.

Tom's Hardware coverage of Gallup poll 70 percent oppose AI data centers
tomshardware.com · May 14, 2026
Why this matters: If you live in or near a town that hosts (or wants to host) an AI data center, the Gallup line is now the single piece of evidence a council member can point to when they cast the vote against approval. Seven in ten neighbors, less popular than a nuclear plant, on a national poll with 50-state sampling. Action this week: open datacenters.ainowinstitute.org/local and check whether your county or town has a pending application. If it does, screenshot the Gallup top-line and bring it (or email it to the council clerk in advance of the next public hearing) so the room has a national reference point. If your town has already lost a permit fight, the new ballot-measure path is the one to watch: Normal, Illinois, Calipatria, and Charlotte all show how to convert a "we already approved that" answer into a six-month freeze the council has to vote on. If you sit on a city or county planning commission, pull Reno's pending-moratorium ordinance text and put it on your June agenda before the next permit lands.

news.gallup.com/poll/709772/americans-oppose-data-centers-area.aspx

If a friend forwarded this to you and you want the signal in your inbox five mornings a week, subscribe at pickbitsai.substack.com. The daily is free.

3. OpenAI agreed to outside audits in Illinois's AI bill — the first time a major lab has signed on to one in state law.

Regulatory action. On Tuesday, May 13, OpenAI formally endorsed Illinois SB 315, a frontier AI safety bill that requires the largest AI companies to develop, publish, and follow a safety framework, report safety incidents, and submit to mandatory annual third-party audits. The endorsement came from Ann O'Leary, OpenAI's VP of global policy: "OpenAI supports the Illinois legislature's efforts to advance frontier AI safety through SB 315." Anthropic also endorsed the bill. This is the first time OpenAI has endorsed a state bill that includes a third-party audit requirement; the company had previously backed an Illinois liability-shield bill (SB 3444) and opposed broader audit mandates.

The bill is closely modeled on California SB 53 (the Transparency in Frontier AI Act, in effect January 1) and New York's RAISE Act. It applies to AI developers with annual gross revenues above $500 million. Required: an annual published framework on industry-standard safety practices, capability evaluations, catastrophic-risk assessment, incident reporting, and a yearly outside audit. The shift is notable in two ways. First, OpenAI's previous position on third-party audits was that they should not be in state law; the Illinois endorsement reverses that. Second, the December 2025 White House executive order that proposed federal preemption of state AI laws is still on the books, which means the OpenAI-Anthropic endorsement is a vote for state law at the moment federal policy was framed as overriding it. The Illinois bill still has to clear committee and a floor vote; nothing has been signed yet.

Transformer News coverage of OpenAI endorsing Illinois SB 315
transformernews.ai · May 14, 2026
Why this matters: If you use AI tools at work, the rules they will be measured by next year are being written this month, and the largest vendor just agreed to be audited by someone outside its own building. That is the first time that has happened in a US state law, and the audit findings will eventually be public. Action this week: look up Illinois SB 315 on the Illinois General Assembly site (ilga.gov) and read the safety-framework section; if you live in Illinois, email your state senator with a one-paragraph note saying you support an annual outside auditor for the largest AI labs. If you are a business analyst or compliance lead at a regulated company, pull the California SB 53 framework Anthropic already published (anthropic.com/news/compliance-framework-SB53) as the template the Illinois law will follow, and write down which of your vendors fall above the $500 million revenue threshold. If you sit on a vendor-review committee, add "publishes an annual third-party safety audit" to the next AI tool RFP question list; the labs just told a US state legislature they will pass that test.

transformernews.ai/p/is-openai-changing-its-tune-on-ai-laws-illinois-regulation

4. Meta cut 8,000 the day after its earnings beat to fund $135B in AI capex.

Labor reshape at a $200 billion company. Meta notified employees this week that roughly 8,000 jobs, about 10 percent of the company, will be cut starting Tuesday, May 20, alongside the cancellation of 6,000 open roles. The cut runs through every major business unit: Reality Labs, the Facebook division, recruiting, sales, and global operations. The framing is structural, not performance: teams are being reorganized into AI-focused "pods" under new chief AI officer Alexandr Wang's Superintelligence Labs, which Meta stood up earlier in 2026 after the Scale AI acquisition that brought Wang in. Meta has separately said additional cuts are planned for the second half of 2026.

The math underneath the cuts is the part that makes this not a downturn story. Meta posted 2025 revenue of $201 billion, up 22 percent year over year, with Q4 net income of $22.8 billion beating analyst estimates and full-year free cash flow of $43.6 billion. The company's planned 2026 AI capital expenditure is between $115 billion and $135 billion, the largest AI infrastructure spend at any single US company this year. So the trade is explicit: cut 8,000 people whose jobs are being absorbed by the agent reorganization, free the operating budget, fund the largest AI buildout in the company's history. The headcount and the spend are being decided in the same room, by the same people. This puts Meta on the same labor-reshape curve as Cisco (4,000 cuts on the day of a $5.3 billion AI revenue print), GitLab (voluntary separations), GM (IT layoffs), and Walmart (the 1,000-person consolidation in yesterday's daily).

Outlook Business coverage of Meta cutting 8,000 jobs May 20
outlookbusiness.com · May 13, 2026
Why this matters: If you work at a tech company, especially one that just announced an "AI-first" or "AI pod" reorganization, the Meta playbook is the one your finance team is now studying. The cut comes after the revenue beat, not before, and the line item being funded is the largest AI capex in the company's history. The cut is the buyback. Action this week: if your employer has announced an AI reorganization in the last 90 days, write down which org-chart unit (the "pod" or the "agent program" or the "platform consolidation") your team belongs to and which one absorbs your function. If you are a support engineer, a tester, a DBA, or a business analyst at a company running the same play, update your resume this week and ask your manager directly which agent or pod is named as the owner of your work in the next planning cycle; if no one can name it, you are in the deduplication bucket. If you have a friend or family member at Meta in Reality Labs, recruiting, or global ops, today is the day to check in. The notification window starts Tuesday.

outlookbusiness.com/corporate/meta-to-cut-8000-jobs-on-may-20-what-employees-will-get-after-layoffs

5. A class action says ChatGPT shipped your private chats to Facebook and Google through ad trackers.

Consumer privacy lawsuit. On Tuesday, May 12, a class-action complaint was filed in the US District Court for the Southern District of California against OpenAI Global LLC, alleging that the company embedded Meta's Facebook Pixel and Google Analytics tracking code inside the ChatGPT.com web interface and silently transmitted user data to Meta and Google's advertising ecosystems. The named plaintiff is Amargo Couture, a California resident filing on behalf of all US users who entered queries into ChatGPT.com. The complaint says the transmissions include browser tab titles derived from user queries (the example in the filing: "Super Bowl 2005 Winner" auto-generated as the page title from the matching question), plus session cookies (c_user, fr, fbp) tied to specific Facebook IDs.

The legal theory is two California-and-federal statutes: the California Invasion of Privacy Act (CIPA), which carries statutory damages of up to $5,000 per violation, and the federal Electronic Communications Privacy Act. The proposed class is nationwide for federal claims with a California subclass for CIPA. OpenAI has not commented publicly on the filing as of Thursday. The structural part of the claim, the part that has implications beyond this one suit, is the framing: the complaint argues that a paid AI tool that integrates ad-tech trackers without explicit consumer consent is in the same bucket as a consumer website that does the same, and CIPA is the lever the California courts have already used in dozens of website-pixel class actions. If the theory survives a motion to dismiss, every AI tool with a hosted web interface (Anthropic's Claude.ai, Google's Gemini web, Microsoft Copilot for consumers, Perplexity) gets its web analytics stack audited by the same standard.

Cybernews coverage of OpenAI class action over Facebook Pixel and Google Analytics on ChatGPT
cybernews.com · May 14, 2026
Why this matters: If you have ever typed a question into ChatGPT.com that you would not have asked Facebook out loud, the complaint says the question's topic, your session, and a cookie tying you back to your Facebook ID went to Meta anyway. That is the allegation; OpenAI gets to answer. But the discovery process is now going to put every AI tool's web-tracker stack on the record. Action this week: open Settings, Data controls in ChatGPT and turn off "Improve the model for everyone" if it is on; if you mostly use ChatGPT in a browser, switch to the desktop or mobile app (the trackers are a web-interface issue, not an API one). If you handle privacy or compliance at work, open your AI tool list and check which of them are accessed primarily through a browser tab and which run inside a desktop or native app; the browser-tab tools are the ones inside the CIPA-pixel theory. If you are a small business owner whose customers' data passes through a ChatGPT-on-web prompt, this is the week to switch that workflow to the API or the desktop app instead of a shared web session.

cybernews.com/ai-news/openai-chatgpt-class-action-lawsuit-facebook-meta/

» What to watch this week

Tomorrow's signal lands here.