> daily_signal(2026_05_24)

The federal AI deepfake-removal law turned on this week. The FTC sent warning letters to twelve nudify-AI sites Friday. Your face has a 48-hour clock now.

PickBits Daily Signal · Sunday, May 24, 2026

By Mark Pickering · 6 min read · May 24, 2026

// tl;dr

The week ran from a federal jury rejecting Elon Musk's OpenAI lawsuit on Monday to forty-eight thousand Samsung chip workers voting on a $26 billion AI bonus pool on Saturday. By Sunday morning four things had landed for ordinary Americans. The Federal Trade Commission began enforcing a law that lets anyone whose face was pasted onto a fake naked picture demand the platform take it down within 48 hours, with penalties already in writing. A leaked recording confirmed Meta scraped its own employees' Gmail and code to train AI before firing eight thousand of them. California signed a worker-protection order whose only requirement is that the state study what worker protections would look like. And OpenAI told every Mac user with ChatGPT installed that the app stops opening on June 12 unless you update it before then.

This week the federal government finally has a way to demand a deepfake of your face come down in 48 hours, Mark Zuckerberg got caught using Meta employees' Gmail and VSCode to train AI before firing eight thousand of them, California signed a paper-only worker-protection order, and every Mac with ChatGPT installed has 19 days to update or stop working.

1. The federal law that lets you demand a deepfake of your face come down in 48 hours turned on Tuesday. Friday the FTC sent letters to twelve sites that exist to make them.

The Federal Trade Commission began enforcing the TAKE IT DOWN Act on Tuesday, May 19. Signed into law by President Donald Trump on May 19, 2025, and championed by First Lady Melania Trump, the statute gave online platforms one calendar year to put a takedown process in place. That year ended Tuesday. Within 48 hours of receiving a valid removal request from someone who appears in a non-consensually shared intimate image or AI-generated deepfake, a covered platform must take the image down and any known identical copies. The FTC can pursue civil penalties of up to $53,088 per violation. The agency also launched takeitdown.ftc.gov on Tuesday, a complaint portal where a victim can report a platform that ignores a takedown request.

On Friday, May 22, the FTC sent warning letters to twelve websites that operate AI nudify tools, the services that take a clothed photo and generate a stripped version of the person in it. The letters said the sites appear to be violating the Act by not providing a removal process and ordered them to come into compliance immediately. Separately, FTC Chairman Andrew Ferguson sent compliance reminders to fifteen of the largest US online platforms: Alphabet, Amazon, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok, and X. These are read at face value as the platforms the FTC expects to enforce against first if a complaint shows the takedown was not honored. The TAKE IT DOWN Act is the first federal AI-specific statute with consumer enforcement teeth that the average American can use directly without going through a state attorney general.

FTC press release on warning letters to nudify AI websites
ftc.gov · May 22, 2026
Why this matters: If a deepfake of you (or your kid, or anyone in your family) shows up on a major platform, you now have a federal law that says the platform has 48 hours to take it down once you ask, and a website to file the complaint when they do not. That right did not exist a week ago. The hardest version of this problem (your 14-year-old comes home crying because a classmate ran her yearbook photo through a nudify site) just stopped being a problem you have to negotiate alone with a contact-form. Action this week: Open takeitdown.ftc.gov and save it to your phone home screen and your work browser bookmarks; that is the one URL to know. If you have a teenager, sit them down tonight and tell them two things: the law is on their side now, and if anyone runs an image of them through a nudify site, they tell you first and you go to that URL together. If you run IT or are the support engineer who fields the harassment escalation calls, write down a 3-step internal runbook that ends with the FTC URL so the next time this lands in a ticket you are not Googling.

ftc.gov: FTC Sends Warning Letters to Companies About Compliance with the TAKE IT DOWN Act

2. The leaked audio shows Mark Zuckerberg defending a program that scraped Meta employees' Gmail and VSCode to train AI. The next day, eight thousand of them got the email.

The labor-focused outlet More Perfect Union released audio Friday of an internal Meta all-hands held April 30. In the recording, Mark Zuckerberg defends a Meta program called the Model Capability Initiative, internal shorthand MCI, in response to a direct question from an employee about device monitoring. The program runs on what Meta calls an approved set of work applications: Gmail, GChat, VSCode, and Metamate, Meta's internal AI assistant. It collects keystrokes, mouse clicks, and periodic screenshots from employee devices. The data is used to train Meta's models on what skilled knowledge work actually looks like. In the audio, Zuckerberg justifies the program by saying Meta employees produce better training data than contractors: "the average intelligence of the people who are at this company is significantly higher than the average set of people that you can get to do tasks if you're working through these contractors."

When an employee asked whether opting out was possible, Meta CTO Andrew Bosworth responded that there is no option to opt out on a work-provided laptop. According to internal accounts in the same reporting, more than one thousand employees have signed a petition opposing the MCI program. The audio became public on Friday. Meta began cutting roughly eight thousand jobs on Wednesday, May 20, which is what the prior PickBits Daily on May 19 anticipated. The sequence in plain language: Meta surveilled the work product of its highest-skilled employees, used that surveillance to train its own AI, and then began firing those same employees about three weeks later. The leaked audio also shows Zuckerberg referring to certain employee categories as "lower-value human capital," a phrase that already surfaced in a separate Standard Chartered bank context on Tuesday and is now appearing in more than one CEO's recorded remarks.

The Register coverage of leaked Zuckerberg audio defending Meta employee monitoring
theregister.com · May 22, 2026
Why this matters: If you work somewhere that issued you a company laptop running standard productivity software (Gmail or Outlook, a chat app, an IDE, an internal assistant), the leaked Meta audio is the template for what your own employer is now allowed to do with what you type into those apps. There is no federal law that requires Meta to disclose this program, and there is no state law in most places that gives an employee the right to opt out. The MCI program is what AI training looks like when the cheapest, highest-quality training data is sitting on the work laptops your employer already owns. Action this week: Open your own employer's acceptable-use policy and your handbook and search for "monitoring," "training data," and "AI." If those words are not there or are vague, that is the gap. Then open chat.openai.com/policies/privacy-policy (or anthropic.com/privacy if your shop uses Claude) and search the same vendor pages for what happens to data your team types into the chat. If you are the architect or BA who picked an enterprise AI seat for your team, pull up your contract today and check whether "use of customer data for model training" is opted-out by default; on most enterprise plans you have to flip a switch, and the default is on.

theregister.com: Zuck defends monitoring employees to win AI race in purported leaked audio

PickBits Daily Signal is the working brief I file every morning at 6 a.m. ET. If a friend forwarded this to you and you want it in your inbox, you can subscribe at pickbitsai.substack.com. It is free.

3. California signed an AI worker-protection order Thursday. It directs the state to study protections that do not yet exist.

Federal-vs-state AI regulation, labor track. The other half of California's AI-labor response, the worker-protection bills now sitting on Newsom's desk, was last week's lede. Governor Gavin Newsom signed an executive order Thursday, May 21, titled in the press release as the first-of-its-kind state action on AI workforce displacement. The order does three concrete things. First, the Labor and Workforce Development Agency, the Governor's Office of Business and Economic Development, and the Department of Finance must deliver within 90 days an analysis of AI's workforce impact, including disproportionate effects on specific demographic groups. Second, the state must stand up a public dashboard tracking AI-driven hiring and payroll trends within 90 days. Third, LWDA must produce within 180 days recommendations to revise California's Worker Adjustment and Retraining Notification Act, the state's mass-layoff trigger, so it functions as an early-warning signal for AI-driven workforce disruption.

What the order does not do is set any worker right that can be enforced today. There is no severance standard in the order. There is no requirement that an employer disclose whether AI was a factor in a layoff. There is no obligation on a California employer to do anything different on Monday than they did on Friday. The order arrived one day after Meta began firing 8,000 workers, several thousand of them California residents. The two bills that would create enforceable rights, the AI worker bills the California Senate passed last week, are still sitting on Newsom's desk. The order tells the state to measure AI-driven layoffs; it does not tell employers to stop them, and it does not give a fired worker a new lever to pull.

CalMatters coverage of Newsom AI workforce executive order
calmatters.org · May 21, 2026
Why this matters: If you work in California for any company that has been talking about AI productivity, the order your governor signed Thursday is the news your employer will read into the next layoff plan. The state is going to start counting AI-driven layoffs, and no rule yet requires anyone to tell you AI was the reason yours happened. Outside California, this executive order is the template every other governor with an AI-driven layoff problem (which is now most of them) will reach for next: a study order in May with the actual rules coming in November at the earliest, if at all. Action this week: Open the executive order at gov.ca.gov/2026/05/21 and read the press release. If your employer has had AI-related layoffs in the last six months, write down the date and the reason given in any public communication; that is the data point WARN Act revisions will eventually be triggered by. If you are an HR or compliance lead for a California employer, calendar August 19 (90 days from May 21) for the LWDA dashboard, and February 17, 2027 for the WARN Act recommendation; those are the two dates that will determine whether the rule-making catches up to the layoffs.

calmatters.org: After AI layoffs, Newsom orders state government to find ways to ease the pain

4. If you have ChatGPT, Codex, or Atlas installed on a Mac, you have 19 days to update or it stops working.

On May 11, the threat group TeamPCP pushed 84 malicious artifacts across 42 npm packages in what is now being called the TanStack supply-chain attack. Two OpenAI employee devices were compromised during the campaign, and credential material was exfiltrated from a subset of OpenAI's internal source code repositories. The compromised credentials included access to OpenAI's macOS code-signing certificate, the cryptographic key Apple uses to verify that a piece of Mac software came from OpenAI and was not modified by anyone else. OpenAI disclosed the incident on May 14 and confirmed a fuller response on May 22: every OpenAI Mac, Windows, iOS, and Android app is being re-signed with new certificates, and the old macOS certificate will be fully revoked on June 12, 2026.

After June 12, macOS will refuse to launch or update any OpenAI app signed with the old certificate. The specific versions affected are ChatGPT Desktop 1.2026.125, Codex App 26.506.31421, Codex CLI 0.130.0, and Atlas 1.2026.119.1. If a user has one of those versions installed on a Mac and does not update before June 12, the app will not open on June 13. There is no public estimate yet of how many users are running affected versions, but ChatGPT Desktop alone has been the top productivity app in the Mac App Store on multiple weeks this year. June 12 is the first time an AI lab has had to revoke a signing certificate that ships installed on millions of consumer devices, and the way OpenAI handles the rollover (clear notification in the apps, an update prompt before the deadline, no surprise breakage) will set the precedent for what every other AI app vendor does the next time this happens.

The Hacker News coverage of OpenAI TanStack supply chain attack and macOS certificate
thehackernews.com · May 15, 2026
Why this matters: If you (or anyone in your household) installed ChatGPT, Codex, or the Atlas browser on a Mac, those apps stop opening on June 13 unless you click update before June 12. The fix takes about 30 seconds; the surprise of waking up to a productivity app you actually use refusing to launch on a Friday morning is the part this section exists to spare you. Action this week: Open ChatGPT on your Mac, click the menu bar, choose "Check for Updates," and let it update; do the same for Codex CLI in Terminal (codex --version, then codex update if you have it installed via Homebrew or npm). If you run a Mac at home for a parent or kid who uses ChatGPT, do the update for them. If you are the support engineer or DBA who fields the laptop questions at your shop, send a one-line note to your team Sunday night so the first ticket Monday morning is not "ChatGPT will not open." Mark June 12 on the calendar.

thehackernews.com: TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

» What to watch this week

Tomorrow's signal lands here.