> daily_signal(2026_07_29)

The nudify tools jumped from the app store to an AI hub no takedown can reach, while the token bill turned on the companies that cheered it and only one of ten wearables locks up your health data.

PickBits Daily Signal · Wednesday, July 29, 2026

By Mark Pickering · 8 min read · July 29, 2026

// tl;dr

A couple of the stories we have been following for weeks finally moved. The AI-cost one went from enterprise bills spiraling in late June to plain sticker shock last week, and now the AP says companies are hunting for cheaper AI and the token flex is over. The wearable-privacy one we keep circling got a scorecard: the EFF checked ten devices and only one encrypts what it stores. The other two are about who can reach what. The nudify tools San Francisco chased through the app stores have moved onto an open host no takedown can pull down, and a free tool out of USC hands a city the one map it needs to see where the heat lands hardest. The fourth is the one piece of good news, and it landed with the cities that usually get skipped.

AI Forensics ran a one-week honeypot on Hugging Face and caught seven of its nine top image tools stripping photos on command.

1. Seven of the nine most-popular image tools on Hugging Face will undress a photo on request, and about one in fifteen of the sexual prompts a watchdog logged went after a child.

The EU research nonprofit AI Forensics set up honeypot Spaces on Hugging Face, the dominant open-source AI hub, and logged more than 1,000 prompts over a single week, tested against the platform's most-popular image Spaces as of late June. Seven of the nine most-used image-editing models complied with undress requests.

Of the sexual requests, 83% sought to strip or sexualize the subject, 95% targeted women, and 6.7% targeted apparent children.

This is the same non-consensual-imagery harm San Francisco chased through the app stores earlier this month, but one step back, at the model itself rather than the app built on top of it.

And that is the catch: a takedown can reach an app, not a model everyone has already copied. On July 18, San Francisco pressed Apple and Google to pull nudify apps from their stores, and a store has a front door, an owner, and a delist button. An open model is just weights, and weights get mirrored. Pull one Space and copies are sitting on other hosts and hard drives by morning. That is why AI Forensics and the reporters covering it keep pointing past the apps to the host: shutting an app never reaches the files everyone has already copied.

Screenshot of The Verge's report on the AI Forensics study of nudify models hosted on Hugging Face
theverge.com · July 28, 2026
Why this matters: The models doing this do not live in an app you can get pulled from a store. They live as open weights on a host, and San Francisco's win this month cannot reach them, because a store has an owner to serve and an open model has a hundred mirrors by morning. That is why the honeypot numbers matter more than the next app takedown: the models get handed out from a place none of the enforcement actually reaches. Action this week: What still works is not a takedown; it is liability and law. It runs through pressure on the model hosts themselves and, in the EU, the ban on nudification apps being written for the end of the year. If you have standing to push, as a legislator's constituent, a school board member, or a parent at a district that posts children's photos, that is where I would spend it. And the plain personal read I would pass on is to treat any photo you post of a child as something these tools can run, because the 6.7% figure says they already are.

theverge.com: Hugging Face is being used to easily undress women and children (July 28, 2026)
wired.com: Hugging Face has a nonconsensual deepfakes problem (July 2026)

2. The token bill your company treated as a productivity flex six months ago is the line item it is now scrambling to cut, and the cost is roughly doubling every month.

In the spring, burning as many AI tokens as possible was a status symbol. Sam Altman said in May he was "excited to see what will happen with tokenmaxxing startups," and Nvidia's Jensen Huang said that if your $500,000 engineer is not burning $250,000 in tokens, something is wrong.

By this summer, per the AP's Matt O'Brien, the same companies are hunting for cheaper AI. Bain's Jue Wang cites tool costs doubling roughly monthly, on the order of $200 per developer per month across about 20,000 developers.

The spend padded revenue at OpenAI and Anthropic, but analysts warn much of it bought work nobody needed.

This is not a mood swing. The price of the same work is climbing month over month, and Palantir's Alex Karp, who has every reason to talk the AI boom up, now calls the trend "completely wrong." Enterprise budgets are shifting from unlimited internal usage toward cheaper models and tighter cost control. The cost stopped living in the license and moved into the meter, and the meter is the part most teams still are not watching. You used to be able to forecast a seat price; now it doubles while you decide whether to look at it.

Screenshot of the AP wire report on corporate America cutting AI spending as tokenmaxxing fades
abcnews.com (AP) · July 27, 2026
Why this matters: My own read is that most of this spend was never productivity; it was a flex with a dashboard. High token burn got treated as a proxy for output, and the analysts the AP quotes think a lot of it bought work nobody needed. The cost does not sit in the license anymore; it sits in the meter, and the meter is doubling about every month. That is a budget line behaving like a runaway cloud bill, except most teams are not watching it like one yet. Action this week: The question I would get answered in writing before the next renewal is the boring one: can we route routine calls to a cheaper model, and what does the vendor commit to when our usage doubles again. I would audit token spend the way I would audit cloud, by workload rather than by headcount, and I would treat any tool quietly moving to usage-based billing as a repricing, not a feature. When I have asked vendors the doubling question directly, the useful answer has always been the one they will put in the contract, not the one on the pricing page.

abcnews.com (AP): Once a flex in corporate America, AI 'tokenmaxxing' fades as workplaces cut costs (July 27, 2026)
techxplore.com: Once a flex in corporate America, AI tokenmaxxing fades (July 2026)

3. Only one of the ten most popular smartwatches and rings encrypts the health data it stores in the cloud, which leaves your heart rate, sleep, and location on the other nine sitting as readable records a subpoena can reach.

The Electronic Frontier Foundation reviewed ten of the most popular wearable makers, Amazfit, Apple, Coros, Garmin, Google's Fitbit, Hume, Oura, Polar, Suunto, and Whoop, and found only the Apple Watch offers end-to-end encryption for the health data it stores online. Only Apple and Google publish transparency reports, and four makers, Apple, Google, Whoop, and Oura, which added the pledge in June, promise to notify you if law enforcement asks for your data. Because fitness data such as heart rate, GPS, and sleep sits outside HIPAA, a subpoena or warrant can unlock what most makers keep as readable records.

The exposure is not theoretical. The surveillance firm Penlink already lists fitness trackers as an "overlooked source" for investigations, which is the tell that the readable-data default is not an oversight nobody has noticed; there is already a business pointing investigators at it. It is the same gap we keep coming back to: the health information that does not come from your doctor does not get your doctor's legal protection, and the device carrying it is one tens of millions of Americans wear to bed.

Screenshot of the EFF Deeplinks post on smartwatch and fitness-band privacy and transparency gaps
eff.org · July 15, 2026
Why this matters: The EFF put a scorecard on a gap we keep landing on: nine of ten makers keep your heart rate, sleep, and location as readable data, health information that is not your doctor's and so does not get your doctor's protections, and only Apple and Google even publish a transparency report. Because none of it falls under HIPAA, the barrier is not a hack; it is a subpoena or a warrant, and a surveillance vendor is already pitching fitness trackers to investigators as an "overlooked source." The exposure is the default setting on a device tens of millions of people wear to bed. Action this week: No federal health-privacy law is coming to close this, so the pressure that actually moves it is at the state level, in the biometric-privacy bills in front of legislatures, where a resident has standing to show up and push. My own read on the device in front of you is that I would not tell you to ditch your Garmin, but I would assume its logs are readable and go check whether your maker promises law-enforcement notice, because right now only Apple, Google, Whoop, and Oura do. If health-data privacy is the thing you actually care about, the Apple Watch is the only major wearable with end-to-end encryption on by default.

eff.org: Most smart watches, rings, and bands lack basic transparency reports and key privacy features (July 15, 2026)
securityaffairs.com: EFF says most smart wearables still fall short on privacy and transparency (July 2026)

4. A free AI tool can now show a city exactly where it has no shade, and where the heat lands hardest, from nothing but the free federal aerial photos it already flies.

Researchers at USC's Spatial Sciences Institute, led by John Wilson, trained AI on the free USDA NAIP aerial imagery to map urban tree canopy and detect individual trees at accuracy the team calls "competitive with far more expensive lidar-based approaches." Then they released it for free: the code plus a ready-to-run ArcGIS model on Esri's Living Atlas, which has been downloaded more than 12,900 times in six months. It validated in San Francisco and Phoenix without retraining, so a city does not need in-house machine-learning staff to run it on its own blocks.

The barrier it removes was never scientific; it was the price. Shade-equity mapping already existed; it just required lidar, the laser scanning that priced smaller cities out. A canopy map is the data a city needs to show where the heat lands hardest, and it tends to land on lower-income blocks with the least tree cover, so the tool's real function is handing a planning office the proof it needs to argue for shade where the argument was previously unaffordable. No chatbot here, just a measurement a cash-strapped city could not otherwise afford to make.

Screenshot of the USC news release on a free AI tool that maps urban tree canopy for shade equity
today.usc.edu · July 8, 2026
Why this matters: John Wilson's team did not build a better satellite; they built a way to skip one. By training on the NAIP photos the USDA already flies, they got individual-tree detection they say holds up against lidar, the scanning that priced shade-equity mapping out of reach for any city without a budget for it. It validated in San Francisco and Phoenix with no retraining, which is the part that matters, because a mid-size city with no machine-learning staff can run it on its own blocks. Nearly 13,000 downloads in six months says planners were waiting for exactly this. Action this week: Here is the caveat I would attach before anyone celebrates: a canopy map is evidence, not shade. It shows a city where the heat lands hardest and where the trees are not, but it does not plant one or pay for one. So what I would watch is whether the cities downloading it actually move planting budget onto the low-canopy, high-heat blocks it lights up, because that is the step where a free map either becomes cooler streets or becomes a nice PDF. For once the tool that maps you is on your side. Whether a city acts on what it shows is the part still up in the air.

today.usc.edu: USC researchers develop a low-cost AI tool to help cities map urban tree canopy (July 8, 2026)
dornsife.usc.edu: USC researchers develop a low-cost AI tool to help cities map urban tree canopy (July 2026)

» What to watch this week

Tomorrow's signal lands here.