> daily_signal(2026_08_22)
AI got pointed at the water grid and the classroom this week, and also put to work for you: catching a California wildfire and moving your company's data back home.
PickBits Daily Signal · Saturday, August 22, 2026
// tl;dr
- A joint NSA, FBI, and CISA advisory says attackers are now using AI to auto-write the exploit code for the Siemens S7 controllers that run US power, water, and farms. The AI-written scripts are disguised as legitimate monitoring tools, and the agencies say the trick sharply lowers the skill and time it takes to attack industrial systems.
- US schools are rolling out AI-literacy classes whose core lesson is distrust. A live demo had an AI misspell countries on a world map (Mali as "Mail," Egypt as "Sopth"); the curriculum tells students to verify every AI-sourced fact and to keep personal data out of chatbots that can store, train on, and leak it.
- After enterprise pushback, Anthropic will move the 30-day copy of enterprise Claude data it keeps for cyberattack detection off its own servers and into customers' own clouds. It built the change with more than 100 regulated-industry customers, and it arrives this fall.
- Amid the worst US wildfire year in at least a decade, AI is catching fires early. Cal Fire's 1,200-plus ALERTCalifornia cameras have flagged fires before any 911 call about half the time, Pano AI runs 1,400-plus cameras across 17 states, and the first 3 of a planned 50 FireSat satellites reached orbit in July.
The thing I flagged back in June just got specific. When five governments warned that AI-powered hacking was months away rather than years, it was still theoretical; this week the NSA, FBI, and CISA named the target, the Siemens controllers that run US water and power, and said attackers are already using AI to write the break-in code. Schools, meanwhile, have started teaching kids to assume the chatbot is lying, which beats the bans they tried first. Anthropic, pushed by its biggest customers, is handing companies back the data it keeps to hunt those same AI attacks. And out in fire country, the same cameras that would unsettle me anywhere else are catching wildfires before anyone smells smoke. I notice only one of this week's four had to ask anybody's permission first.
This week attackers turned AI on the Siemens controllers running US water and power, schools began teaching students to catch the chatbot fabricating, and Anthropic moved its 30-day copy of enterprise Claude data into customers' clouds, while in fire country AI cameras keep catching California wildfires before the first 911 call.
1. A federal advisory says attackers are now using AI to write the attack code for the controllers running US water and power.
The public warning is out; the boring fix is still yours to do.
If you keep anything running on a Siemens S7 controller, a federal advisory this week says the skill and time it takes to attack it just collapsed, because attackers are now using AI to write the exploit code itself. The joint alert comes from the NSA, the FBI, and CISA, and it describes an active threat: adversaries using AI-assisted development to generate exploitation scripts against S7-series programmable logic controllers, the small computers that run equipment in the energy, water, and agriculture sectors. The agencies call it "an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working exploitation scripts."
The AI-written scripts are disguised as legitimate monitoring tools, so they are built to slide past whoever is watching the control network. And the skill bar the technique removes is the one that used to protect this gear: attacking industrial systems has always required a rare specialist who understood the hardware, and that scarcity was itself a defense. We wrote about this in June, when five governments warned that AI-powered hacking was months away rather than years, and now it has a specific target attached.
2. Schools started teaching a generation to assume the chatbot is lying, and to stop feeding it their data.
Schools tried banning it, then ignoring it; now they are teaching kids to fact-check it.
Before your kid trusts a chatbot with their homework, look at the world map an AI drew in one class: Mali spelled "Mail," Egypt labeled "Sopth," and Libya wiped out and relabeled simply "Africa," all delivered with total confidence. That demo is the centerpiece of a wave of AI-literacy classes US schools are standing up this year, and the surprise is the framing. The core lesson is not how to use generative AI. It is how to distrust it, and to verify what it hands you before it goes anywhere near a grade.
The curriculum is blunt in a way the marketing around these tools never is. It tells students to "always verify any factual information you get from GenAI, especially for your classwork," and it warns that AI conversations "can be stored, used for data training, and potentially leaked." As Rebecca Winthrop of the Brookings Institution puts it, good AI literacy includes knowing when not to use it. We have watched schools lurch from banning these tools outright to pretending they were not already in every backpack, and this straight talk is showing up a couple of years later than it should have.
news4jax.com (AP): Schools are starting to teach AI literacy; for many, that means helping kids see chatbots' flaws (August 21, 2026)
oann.com (AP): Schools are starting to teach AI literacy (August 2026)
3. Anthropic is moving the 30-day copy of your company's Claude data off its servers and into your own cloud.
It took angry enterprise customers, not a privacy update, to move where the data actually sits.
If you own your company's Claude contract, the 30-day copy of everything your team types into it is moving off Anthropic's servers and into your own cloud this fall. Anthropic keeps that copy to scan for a specific problem, novel AI-enabled cyberattacks, and it has now admitted the retention rule was unpopular and a business risk. After months of work with more than 100 customers from regulated industries, it will hold the 30-day copy inside the customer's own cloud instead of on its own servers, handing control of that copy back to the company paying for it.
That worry is not made up. As today's lead story shows, AI is already good enough to help attackers find and write working exploits for serious security holes, and my own read is that a company shipping models this capable has real reason to watch its own traffic for abuse. What changed is not the scanning but the location, and in a regulated industry the location is the thing your auditors care about. A competitor is testing a different approach with Databricks and Microsoft, which means you want to nail down where your prompts are held while you are still negotiating the contract.
the-decoder.com: Anthropic changes data retention policy after enterprise pushback (August 21, 2026)
4. AI cameras caught a California wildfire about 20 minutes before anyone called 911.
For once the cameras are pointed at a fire nobody has seen yet, not at a person.
AI cameras caught a California wildfire about 20 minutes before anyone called 911, in what is shaping up as the worst US fire year in at least a decade. The camera belongs to ALERTCalifornia, Cal Fire's network of more than 1,200 AI-enabled cameras, which has flagged fires before any 911 call about half the time; the one near Fresno gave crews a head start while the fire was still small enough to stop. In a year with more fires and more acreage burned than any of the last ten, those minutes are the difference between a fire crews can contain and one they cannot.
It is not only California, and it is not only cameras. Pano AI, a San Francisco startup, runs more than 1,400 high-resolution detection cameras across 17 states, and in July a SpaceX launch carried the first three of a planned 50 FireSat satellites to orbit, built to spot a new fire anywhere within about 20 minutes of ignition, even one as small as a beach bonfire. The fifty-percent figure is Cal Fire's own read on its own data, and more cameras watching more of the country is still more cameras. But this time I do not mind the extra ones, because they are scanning an empty ridge for smoke, not watching people.
pbs.org: How satellites and AI cameras are detecting wildfires before they get out of control (August 4, 2026)
pbs.org (classroom): How AI cameras are detecting wildfires (August 2026)
pano.ai: Pano AI wildfire detection network
» What to watch this week
- Whether CISA follows the advisory with named indicators or a specific S7 firmware fix, and whether any operator publicly confirms an AI-written intrusion. The alert describes the technique. What actually helps a defender is a specific signature they can load, and that is the part still missing.
- Whether the data-privacy half of AI literacy survives as it scales from a few districts to a state standard. Teaching that the chatbot makes mistakes is the easy part; districts keep dropping the harder half, telling students to stop feeding it their data.
- Anthropic's fall rollout, and whether the competing Databricks-and-Microsoft approach lands somewhere similar. Once one big vendor hands custody back, the others start getting asked why they have not.
- How far the coverage actually reaches: past the West for ALERTCalifornia and Pano, and from three FireSat satellites toward the planned fifty. Right now it is thickest where the fires already are.
Tomorrow's signal lands here.