> daily_signal(2026_05_26)

AOC's two jars of brown water from a Meta data-center community got the EPA to commit on the record to investigate. Days later an open-source tool stripped Meta and Google's AI safety guardrails in under ten minutes.

PickBits Daily Signal · Tuesday, May 26, 2026

By Mark Pickering · 7 min read · May 26, 2026

// tl;dr

Yesterday the Pope made AI a moral question. Today four different federal and corporate stories made it a practical one. The EPA committed on the record to investigate a Meta site's drinking water, the safety regime on the world's most-downloaded open-weight model fell apart in ten minutes of laptop time, the Trump DOE made its fifth emergency order forcing a retired Michigan coal plant to keep burning so the grid can keep feeding new computing demand, and Microsoft pulled the most popular internal AI coding tool out of the hands of thousands of its own engineers four days before the end of its fiscal year. Then Nvidia's CEO, alone among the people whose companies actually built the technology, told the CEOs blaming AI for layoffs to stop.

Today the AI buildout got a federal water probe at a Congressional hearing, an open-weight safety regime that no longer holds, a fifth coal-plant order that put another $180 million on Midwest electric bills, and a public rebuke from Nvidia's CEO over the firings that other CEOs are blaming on the chips his company sells.

1. AOC walked two jars of brown water into a Congressional hearing and got the EPA to commit on the record to investigate a Meta data center. [Returning]

The data-center community-pushback arc was last covered May 22 — the hearing itself happened in mid-May; HuffPost's write-up of AOC's confrontation with EPA's Jessica Kramer ran on May 22 and Bloomberg Law confirmed the EPA commitment hours after that. We're surfacing it here as the precedent-setting event in the arc.

Rep. Alexandria Ocasio-Cortez pulled two glass jars of brown tap water out from under the witness desk at a House Energy and Commerce Oversight and Investigations subcommittee hearing and held them up across from the EPA's Assistant Administrator for Water, Jessica Kramer. The water came from a household in Morgan County, Georgia, where Meta is building one of its largest US data-center campuses. Ocasio-Cortez asked Kramer whether either jar was drinkable. Kramer said it was not. About 10 percent of the community's daily water supply now goes to the Meta build, residents are buying bottled water to drink and cook with, and local water bills are projected to rise about 33 percent. The county is on a trajectory the witness chair did not dispute: a full water deficit by 2030.

Kramer initially told the committee she was not aware of any complaints about data-center construction and local water quality. After Ocasio-Cortez tabled the jars, Kramer said on the record: "as soon as I get back to the office, I will be looking into exactly what you just talked about." Bloomberg Law confirmed the commitment within hours under the headline "EPA Official Agrees to Review Data Center Impacts on Water." It is the first federal water probe directly triggered by the AI data-center buildout. The hearing record now has named jurisdiction, a named official, and a named corporate site.

Why this matters: If you live within a few miles of a data center under construction (or one of the dozens of communities your county or state has approved without a public meeting), the EPA's water chief just told Congress on the record that the agency will investigate a Meta site's drinking water. That precedent did not exist yesterday. Local fights against data-center water use now have a federal channel that points back at a named EPA office, not just a town hall. Action this week: If your county or town has a pending data-center hearing, the AOC clip and the Kramer commitment are the two pieces of evidence to submit into the public-comment record (HuffPost has the clip; Bloomberg Law has the formal commitment). If you work in local government or on a water board, pull your current and projected groundwater allocations against any approved data-center site within your service area and write down the gap. The Morgan County figures (10 percent of daily supply, 33 percent bill increase, deficit by 2030) are now the public-record benchmark for what a single hyperscale site does to a small-town water table.

huffpost.com: AOC Just Made Two Jars of Brown Water The Center Of The AI Data Center Debate

2. An open-source tool stripped Meta's Llama 3.3 safety guardrails in under ten minutes. The unguarded model returned CSAM, malware code, and chlorine-gas instructions.

The Financial Times and a research team led by Alice (a security researcher who publishes under one name) used a publicly available tool called Heretic to remove the safety guardrails from Meta's Llama 3.3 model in less than ten minutes, on consumer hardware, with no specialist setup. Heretic uses a technique called "abliteration" that analyses a model's weights, locates the specific neurons where refusal behavior sits, and zeros them out. The tool's author, Philipp Emanuel Weidmann, told the FT that Heretic has been downloaded 13 million times and has produced more than 3,500 modified versions of public models since release.

The decensored variant of Google's open-weights Gemma 3 model, when tested by the same team, returned step-by-step instructions for dispersing chlorine gas through a crowded indoor space, produced working code designed to steal credit-card data, and generated stories describing child sexual abuse. Google's response to the FT framed the result as expected: "Abliteration is a known technical challenge facing all open models" and the company said its open models "undergo rigorous internal safety evaluations prior to launch." Meta declined to comment. Independent reproduction is already happening: at least four other write-ups since May 25 have repeated the procedure with similar results across Qwen, Llama, and Gemma variants.

Why this matters: If you or anyone in your household runs an open-weight chatbot (the small downloadable models you can grab from Hugging Face onto a laptop), the safety filter that ships with the model can now be removed in roughly the time it takes to make coffee. The test results were not edge cases. They were the things the safety filter is specifically there to refuse: instructions for chemical attacks, working theft code, and child sexual-abuse material. The safety guarantees that Meta and Google publish for their open models survived rigorous internal review and then a tool from a single developer turned them off. Action this week: If you or a family member uses a local AI app pulled from a model hub, treat the published safety description as advisory rather than enforced. Set parental controls on the device the model runs on. If you build product on top of open weights, read the Heretic write-up (it is on the FT and the Irish Times has a full account) and add an output-filtering layer that does not depend on the model itself refusing the request. If you work in IT and your organization has approved open-weight model use because it was assumed safer than closed APIs, that assumption needs to be re-tested this quarter.

irishtimes.com: AI guardrails stripped from Meta and Google models in minutes

PickBits Daily Signal is the working brief I file every morning at 6 a.m. ET. If a friend forwarded this to you and you want it in your inbox, you can subscribe at pickbitsai.substack.com. It is free.

3. The Trump DOE issued its fifth emergency order forcing a retired Michigan coal plant to keep burning. Ratepayers are now $180M in.

U.S. Energy Secretary Chris Wright signed the fifth federal emergency order extending the operating life of the J.H. Campbell coal plant in Port Sheldon Township, Michigan, forcing Consumers Energy to keep the plant running through August 18, 2026. The plant was scheduled to retire on May 31, 2025; today's order pushes it 444 days past that retirement date. The plant has been kept open under back-to-back emergency orders citing grid-reliability risk from rising demand, in a region of the country where data-center load is the single fastest-growing electricity draw. Cumulative ratepayer cost across the orders has now reached about $180 million, money that comes out of Midwest electric bills rather than federal appropriations.

Michigan Attorney General Dana Nessel held a press conference at the plant on May 21 and called the order "crying wolf over a non-existent energy emergency, while at the same time undermining every effort made to increase the efficiency, affordability, and reliability of domestic energy markets." Her office is filing a fifth request for a rehearing with the DOE and is challenging the underlying authority at the U.S. Court of Appeals for the DC Circuit. The Environmental Defense Fund's analysis attributes about 66 excess deaths per year and roughly $1 billion in health costs to keeping the plant running past its retirement. Today's extension is the third in 12 months. The "Weekend at Bernie's coal plant" framing, which Nessel used at the May 21 press conference, has become the running shorthand for the underlying problem: nobody is willing to defend the plant operationally, the orders just keep coming.

Why this matters: If you pay an electric bill anywhere in the Midwest grid (MISO or PJM territory in particular), you are already paying for the federal decision to keep this retired coal plant running. The bill is $180 million and counting, and it is being added to the rate base by federal order without a state-level vote that you can show up to. The rationale on the order is grid reliability, and the load growth driving that rationale is dominated by AI data-center demand. Your electric bill is now load-bearing infrastructure for an industry buildout you did not approve. Action this week: Pull up your last electric bill and find the line item for "power supply" or "energy charge." If you live in Michigan, the Citizens Utility Board (CUB) of Michigan and the Michigan AG's office both take public comments on rate-case dockets. If you live elsewhere in MISO or PJM territory, your state Public Service Commission or Public Utilities Commission posts open dockets you can file written comment on; data-center load and the cost allocation behind it is the single most common live filing in those dockets right now. If you build at a utility, energy retailer, or large industrial site, the EDF write-up has the legal challenge timeline; the DC Circuit ruling, when it comes, will set the precedent for whether the next plant in this category gets the same treatment.

michiganadvance.com: 'Crying wolf' - Nessel says feds created energy 'emergency' to keep Campbell coal plant open

4. Microsoft is canceling Claude Code licenses for thousands of its own engineers by June 30. Its developers are pushing back.

Microsoft is canceling most of its internal Claude Code licenses by June 30, 2026 for the company's Experiences and Devices division, which covers Windows, Microsoft 365, Teams, Outlook, and Surface. Affected staff have been told to switch to GitHub Copilot CLI. Microsoft introduced Claude Code internally in December 2025 by handing out licenses across engineering, design, and project management roles, and the tool became extremely popular over the following six months. Microsoft's fiscal year ends June 30, and Windows Central, TechRadar, and Thurrott's reporting all align on the same explanation: the cancellation is a budget move tied to the close of the fiscal year, layered on top of a strategic decision to push internal developers onto Microsoft's own coding tool.

The pushback is on the record. Internal posts cited by Windows Central and Yahoo Tech describe engineers questioning the move, given the productivity gap they had measured between Claude Code and the alternatives. Anthropic's Claude models will remain available through Copilot CLI as a model option, so this is not a contract-level break in the Microsoft-Anthropic relationship. It is a question about whose CLI runs on the developer's machine, and where the per-seat spend lands. Microsoft is simultaneously selling Copilot as the AI layer of choice for every software shop on the planet; having thousands of its own engineers vocally prefer a competitor's tool is the kind of internal tension that does not stay internal for long.

Why this matters: If you write code at work, or your work depends on someone who does, the cost-of-AI-tools question is no longer a buy-anything-that-helps question. The single biggest software company in the world just told its developers they cannot keep using the AI coding tool they preferred because the spend is too high in a quarter where the books need to close cleanly. The same conversation is about to happen in every company that handed out Claude Code, Cursor, or Codeium licenses last year. Action this week: If you have an internal AI coding tool you depend on, document the productivity delta against your fallback option (a few before-and-after metrics from a real ticket are worth more than a vendor benchmark). If you run developer experience or IT at a software shop, the Microsoft decision is the data point your CFO is about to bring to your next planning meeting; have your own usage and per-seat-cost numbers ready before that. If you build product on a Claude API rather than the IDE, the underlying API access is unaffected by this Microsoft decision; the change is the seat license inside Microsoft's own org, not Anthropic's enterprise availability.

windowscentral.com: Microsoft cancels Claude Code licenses, shifting developers to GitHub Copilot CLI

5. Anthropic moved its Mythos AI bug-hunter toward public release. It has already flagged 23,019 vulnerabilities across 1,000 open-source projects.

Anthropic said it is working toward publicly releasing its Mythos-class AI models, the security-focused systems the company previously deemed too dangerous to ship outside a closed pilot program called Project Glasswing. Glasswing operates a limited deployment of Mythos with about 50 partner organizations, mostly large companies and open-source maintainers who use Mythos to harden cyber defenses ahead of general-purpose attacker access to comparable capability. Mythos was first announced as a research preview on April 7. The case for public release is the case that the underlying capability is already arriving in non-Anthropic models, and waiting any longer leaves defenders behind attackers who are already running these tools privately.

Under Project Glasswing, Mythos has scanned more than 1,000 open-source projects and flagged a total of 23,019 software flaws. Of those, 6,202 are rated high or critical severity, the categories most likely to be exploitable. So far 530 high-or-critical issues have been reported to maintainers, 75 have been patched, and 65 have public advisories. The remainder are inside the 90-day coordinated vulnerability disclosure clock. Anthropic has not given a public-release date; the framing is "once adequate safeguards are ready" and the Just Security write-up is treating that as a tightening window rather than an indefinite delay.

Why this matters: If you use anything that talks to the internet (your phone, your router, your work laptop, your smart speaker, your car), the open-source libraries those devices are built on are the ones Mythos just finished scanning. The 23,019 number is the inventory of doors and windows an AI bug-hunter could see; the 6,202 are the ones that look open. Maintainers of the affected projects are inside the 90-day disclosure window, which means the patching wave will arrive on your devices over the next two to three months. The good and the bad arrive together: defenders running Mythos-like tools find the bugs faster than attackers can; attackers running Mythos-like tools weaponize the same bugs first if they get there first. Action this week: Turn on automatic updates on every device in your home that supports them; for the ones that do not, write down a 30-day check-in to install whatever the manufacturer has shipped by then. If you run IT at a small business or clinic, audit your inventory of internet-facing software and confirm you have a patching policy that fires inside the 90-day disclosure window. If you maintain an open-source project, the Anthropic Glasswing page and red.anthropic.com both list how to enroll your repo so that the next wave of Mythos findings reaches you privately first.

theregister.com: Anthropic to release Mythos-class models to the public

6. Nvidia's Jensen Huang publicly told CEOs blaming AI for layoffs to stop. He called the framing "lazy" and "irresponsible."

In a CNA television interview reported today, Nvidia CEO Jensen Huang said the narrative used by chief executives to attribute layoffs to AI is "just too lazy" and "doesn't make any sense." He told CNA he hates executives "blaming layoffs on AI to sound smart" and added: "we're scaring people and that's irresponsible." Huang's working logic, in his own words: "AI has just arrived. How is it possible that AI became productive and useful only six months ago, and they were somehow laying people off two years ago because of AI?" The comments land in the same week Meta began cutting roughly 8,000 jobs, Wix announced a 1,000-job cut, and Intuit, Cisco, and Standard Chartered all explained recent reductions in part by pointing at AI.

Huang's advice to workers got quoted heavily: "You're not going to lose your jobs to AI, you're going to lose your job to somebody who learned AI better than you." This is the first time the chief executive of the single company most directly responsible for the AI cost curve has publicly told peers using AI as the cover story for layoffs that the math does not work. Standard Chartered's Bill Winters walked back his "lower-value human capital" phrase last week after Singapore's then-President Halimah Yacob called it out by name; Huang's comments are the broader template for the same critique, delivered from the supplier side rather than the public-figure side.

Why this matters: If your employer used AI as the cover story for a layoff this year, or if your employer's next earnings call is the one where they might, the most influential person in the AI hardware supply chain just publicly said that framing is dishonest. That is not a labor advocate or a regulator saying it. That is the CEO of the company whose chips trained every major model on the market saying it on television. It changes the cost of using AI as an HR talking point for the rest of 2026. Action this week: Save the Huang quote (Tekedia and Aninews both have the full interview write-up) for the next time your company runs an all-hands where AI is named as a workforce factor. Ask the speaker on the call which named tasks AI is currently replacing in your function. If they cannot answer with a specific tool and a specific workflow, you have your read. If you are looking for work right now and an interviewer cites AI as the reason for restructuring, the Huang counterargument is the question to bring: which six-month-old AI tool drove the cut? The honest interviews will give you a real answer; the dishonest ones will pivot.

tekedia.com: 'We're scaring people' - Nvidia's Jensen Huang rebukes CEOs blaming AI for layoffs

» What to watch this week

Tomorrow's signal lands here.