> daily_signal(2026_08_22)

AI got pointed at the water grid and the classroom this week, and also put to work for you: catching a California wildfire and moving your company's data back home.

PickBits Daily Signal · Saturday, August 22, 2026

By Mark Pickering · 8 min read · August 22, 2026

// tl;dr

The thing I flagged back in June just got specific. When five governments warned that AI-powered hacking was months away rather than years, it was still theoretical; this week the NSA, FBI, and CISA named the target, the Siemens controllers that run US water and power, and said attackers are already using AI to write the break-in code. Schools, meanwhile, have started teaching kids to assume the chatbot is lying, which beats the bans they tried first. Anthropic, pushed by its biggest customers, is handing companies back the data it keeps to hunt those same AI attacks. And out in fire country, the same cameras that would unsettle me anywhere else are catching wildfires before anyone smells smoke. I notice only one of this week's four had to ask anybody's permission first.

This week attackers turned AI on the Siemens controllers running US water and power, schools began teaching students to catch the chatbot fabricating, and Anthropic moved its 30-day copy of enterprise Claude data into customers' clouds, while in fire country AI cameras keep catching California wildfires before the first 911 call.

1. A federal advisory says attackers are now using AI to write the attack code for the controllers running US water and power.

The public warning is out; the boring fix is still yours to do.

If you keep anything running on a Siemens S7 controller, a federal advisory this week says the skill and time it takes to attack it just collapsed, because attackers are now using AI to write the exploit code itself. The joint alert comes from the NSA, the FBI, and CISA, and it describes an active threat: adversaries using AI-assisted development to generate exploitation scripts against S7-series programmable logic controllers, the small computers that run equipment in the energy, water, and agriculture sectors. The agencies call it "an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working exploitation scripts."

The AI-written scripts are disguised as legitimate monitoring tools, so they are built to slide past whoever is watching the control network. And the skill bar the technique removes is the one that used to protect this gear: attacking industrial systems has always required a rare specialist who understood the hardware, and that scarcity was itself a defense. We wrote about this in June, when five governments warned that AI-powered hacking was months away rather than years, and now it has a specific target attached.

Screenshot of The Record's August 19, 2026 report on the NSA, FBI, and CISA advisory about AI-written exploit code targeting critical infrastructure.
therecord.media · August 19, 2026
Why this matters: The advisory names specific hardware, Siemens S7 controllers, and a specific technique, AI-generated scripts disguised as monitoring tools. That combination is what worries me, because the attacker no longer needs to be the rare person who understands industrial systems. Action this week: Pull the advisory and inventory which S7 controllers you actually run and which of them touch the open internet, because the fix here is the unglamorous one, isolation and patching, and it works whether or not the code was written by a model. I have sat in enough security reviews to know the internet-facing controller nobody remembers installing is the one that gets you. And if your town runs on this equipment and you do not operate it, the advisory is public record, so you can put a pointed question to whoever runs your utility: have you read it, and what did you change because of it?

therecord.media: NSA, FBI warn of hackers using AI-generated tools in attacks on critical infrastructure (August 19, 2026)

2. Schools started teaching a generation to assume the chatbot is lying, and to stop feeding it their data.

Schools tried banning it, then ignoring it; now they are teaching kids to fact-check it.

Before your kid trusts a chatbot with their homework, look at the world map an AI drew in one class: Mali spelled "Mail," Egypt labeled "Sopth," and Libya wiped out and relabeled simply "Africa," all delivered with total confidence. That demo is the centerpiece of a wave of AI-literacy classes US schools are standing up this year, and the surprise is the framing. The core lesson is not how to use generative AI. It is how to distrust it, and to verify what it hands you before it goes anywhere near a grade.

The curriculum is blunt in a way the marketing around these tools never is. It tells students to "always verify any factual information you get from GenAI, especially for your classwork," and it warns that AI conversations "can be stored, used for data training, and potentially leaked." As Rebecca Winthrop of the Brookings Institution puts it, good AI literacy includes knowing when not to use it. We have watched schools lurch from banning these tools outright to pretending they were not already in every backpack, and this straight talk is showing up a couple of years later than it should have.

Screenshot of a News4Jax August 21, 2026 AP report on schools teaching AI literacy by showing students how chatbots fabricate facts.
news4jax.com · August 21, 2026
Why this matters: This is not new ground for us. We have tracked schools swinging from outright bans to quiet acceptance, and this one finally tells kids to check the tool instead of just banning or ignoring it. Action this week: Sit down with your kid, have them show you one chatbot answer, and fact-check it together against a primary source, because the habit of verifying is the actual skill, not any single fact. Then ask your district whether AI literacy, including when not to use it, is in the curriculum this year. My own read is that the data half of the lesson matters more than the accuracy half: a wrong map is obvious, but a kid pasting a name, a school, and a schedule into a system that stores and trains on it is the harm nobody sees.

news4jax.com (AP): Schools are starting to teach AI literacy; for many, that means helping kids see chatbots' flaws (August 21, 2026)
oann.com (AP): Schools are starting to teach AI literacy (August 2026)

3. Anthropic is moving the 30-day copy of your company's Claude data off its servers and into your own cloud.

It took angry enterprise customers, not a privacy update, to move where the data actually sits.

If you own your company's Claude contract, the 30-day copy of everything your team types into it is moving off Anthropic's servers and into your own cloud this fall. Anthropic keeps that copy to scan for a specific problem, novel AI-enabled cyberattacks, and it has now admitted the retention rule was unpopular and a business risk. After months of work with more than 100 customers from regulated industries, it will hold the 30-day copy inside the customer's own cloud instead of on its own servers, handing control of that copy back to the company paying for it.

That worry is not made up. As today's lead story shows, AI is already good enough to help attackers find and write working exploits for serious security holes, and my own read is that a company shipping models this capable has real reason to watch its own traffic for abuse. What changed is not the scanning but the location, and in a regulated industry the location is the thing your auditors care about. A competitor is testing a different approach with Databricks and Microsoft, which means you want to nail down where your prompts are held while you are still negotiating the contract.

Screenshot of The Decoder's August 21, 2026 report on Anthropic changing its enterprise data-retention policy after customer pushback.
the-decoder.com · August 21, 2026
Why this matters: My own read is that this is a real concession, not a press release, because moving where data lives is expensive and Anthropic only did it after the customers with the most leverage refused the old terms. The retention itself is not going away. What moves is where the copy sits, and for anyone in a regulated industry that is the entire audit. Action this week: Get the answer in writing before the fall rollout, specifically where the 30-day security copy will sit, who can reach it, and how you export it, because "you own your data" has never once produced an actual file when I have asked a vendor to hand one over. Then put the same question to every other AI vendor you pay, since Anthropic just made data custody a fair thing to demand an answer on. If this is your call to make, it is worth forwarding to whoever signs your AI contracts.

the-decoder.com: Anthropic changes data retention policy after enterprise pushback (August 21, 2026)

4. AI cameras caught a California wildfire about 20 minutes before anyone called 911.

For once the cameras are pointed at a fire nobody has seen yet, not at a person.

AI cameras caught a California wildfire about 20 minutes before anyone called 911, in what is shaping up as the worst US fire year in at least a decade. The camera belongs to ALERTCalifornia, Cal Fire's network of more than 1,200 AI-enabled cameras, which has flagged fires before any 911 call about half the time; the one near Fresno gave crews a head start while the fire was still small enough to stop. In a year with more fires and more acreage burned than any of the last ten, those minutes are the difference between a fire crews can contain and one they cannot.

It is not only California, and it is not only cameras. Pano AI, a San Francisco startup, runs more than 1,400 high-resolution detection cameras across 17 states, and in July a SpaceX launch carried the first three of a planned 50 FireSat satellites to orbit, built to spot a new fire anywhere within about 20 minutes of ignition, even one as small as a beach bonfire. The fifty-percent figure is Cal Fire's own read on its own data, and more cameras watching more of the country is still more cameras. But this time I do not mind the extra ones, because they are scanning an empty ridge for smoke, not watching people.

Screenshot of PBS NewsHour's August 4, 2026 segment on AI cameras and satellites detecting wildfires early.
pbs.org · August 4, 2026
Why this matters: Cal Fire says its cameras have caught fires before any 911 call about half the time, and near Fresno one was spotted a full 20 minutes before the first call, which at the start of a fire is the whole ballgame. For once the thing the AI is watching is not a person; it is a fire that has not started spreading. Action this week: Check whether ALERTCalifornia or a Pano AI network covers your area, and if you are in fire country, sign up for your county's evacuation alerts now, because the head start only helps if you are ready to move on it. I will hold one caveat next to the good news: these are the agencies' own numbers on their own data, and more cameras aimed at the horizon are still more cameras, even when smoke is all they are watching for.

pbs.org: How satellites and AI cameras are detecting wildfires before they get out of control (August 4, 2026)
pbs.org (classroom): How AI cameras are detecting wildfires (August 2026)
pano.ai: Pano AI wildfire detection network

» What to watch this week

Tomorrow's signal lands here.