> daily_signal(2026_08_28)
The Labor Department can't measure AI's hit to your job, so it asked the companies building AI to, the same week Australia jailed a supply-chain crew and Ring rewrote your doorbell's defaults.
PickBits Daily Signal · Thursday, August 28, 2026
// tl;dr
- The Labor Department says it does not have the data on how fast AI is displacing workers, so it is signing data-sharing agreements with the tech giants to get it. Acting Secretary Keith Sonderling named the plan, the partners include OpenAI, Google, Meta and Amazon, and the numbers will feed a public DOL workforce hub. The companies building the AI would be the ones measuring what it does to jobs.
- Australian Federal Police charged two Perth men as the alleged principals behind TeamPCP, the crew that poisoned updates to Trivy, Checkmarx KICS and the AI gateway LiteLLM in March. Police put the campaign at more than 1,000 organizations, 500,000-plus stolen credentials and 300GB of data, with OpenAI, GitHub and European Commission systems among the targets. The arrest ends the operation, not the exposure: any build that pulled a poisoned version still needs a credential rotation.
- Amazon made TAKE, "Throw Away the Key" encryption, the default for Ring's cloud features, rotating keys that delete within 24 hours so even Ring and police can't pull your clips. It is a real privacy step, built on the open MLS standard. But the same account still runs Familiar Faces face-scanning and Search Party neighborhood-camera search, both on by default, amid a June class-action and congressional alarm over Ring's AI surveillance.
- An NYU Langone lab led by Dr. John-Ross Rizzo, who is legally blind, built AI navigation tools for blind and low-vision people, and testers using its transit app finished trips 33% faster. Shopscout guides grocery shopping by audio, Commute Booster reads subway signage, and Unav navigates indoors with no cell signal. The tools are still pilot-stage, built by the people who actually live the problem, not yet something you can buy.
The Labor one is the story that stuck with me this week. Washington admitted, out loud, that it cannot see what AI is doing to the job market, and its fix is to ask the four companies building the AI to hand over the numbers. We have tracked this arc since spring, when Meta and Microsoft cut twenty thousand jobs and the fight was whether AI was the reason or the alibi, and the government's answer back then was a shrug. Now that shrug is turning into policy, and the companies doing the automating get to keep the score.
The tech in the other three is already live, and in each one whoever is supposed to be watching it keeps handing the keys to somebody inside the machine. Australia caught the crew behind a supply-chain hack we have been covering since a similar poisoning hit thirty-two Red Hat packages in June, but catching them does nothing for the credentials their code already walked out with. Ring shipped genuinely better encryption on your doorbell and, in the same update, left its AI face-scanning switched on. The last one is the exception, and it is the best thing here: a lab where the lead scientist is himself blind built the tool he needs, and it works.
Washington cannot measure the automation, so it asked the automators for the number, and called it a workforce hub.
1. The Labor Department admits it can't see what AI is doing to jobs.
Its fix is to sign data-sharing deals with OpenAI, Google, Meta and Amazon, so the companies building the AI become the ones measuring its effect on your paycheck.
The admission is the part that matters. Acting Labor Secretary Keith Sonderling said the U.S. Department of Labor "does not have the data" on how fast AI is being adopted or whether it is displacing workers, and that its own Bureau of Labor Statistics figures lag by months. So the department is signing data-sharing agreements with major technology and Fortune 500 firms to obtain private-sector numbers, and the named partners include OpenAI, Google, Meta and Amazon. The data is meant to supplement the lagging federal figures and go public through a forthcoming DOL AI workforce hub.
The problem is right there in the setup: the companies building and selling the AI would supply the official record of what the AI is doing to employment. Ask people entering the job market how they see it and the fear is right there in the numbers, a Marist poll this year found just 27% of 18-to-29-year-olds think AI will increase the number of jobs, against 73% who think it will cut them. A public hub sounds like transparency, and it might even produce useful numbers. But you cannot trust a number without knowing the terms behind it, and nobody has published those: which data flows, on what cadence, filtered by whom, audited by whom.
Why this matters: If you lost a tech job this year, the official federal record of whether AI did it now runs through the same companies that automated it. Call it what it is, a conflict of interest sitting in plain sight: the people measuring AI's effect on jobs are the ones who built the AI, and they have every reason to want the number to look fine. A workforce hub built on terms nobody outside has seen is just a screen showing you what its owners decided to put there.
Action this week: Ask the one question that actually decides this, in writing if you are anywhere near the policy side: what data are these firms handing over, who audits it, and does the public get the raw feed or only the approved view. My own read is that the data-sharing terms are the entire story here, and until they are public this is a measurement designed by the thing being measured. If you are a worker, treat any company memo that credits or blames "the AI" for a headcount decision as a claim to check, not a fact, because the people writing the national number have the same incentive your employer does.
axios.com: Labor Department turns to tech giants for AI jobs data (August 26, 2026)
fedscoop.com: Labor Department to launch AI workforce hub (August 2026)
govciomedia.com: Labor Department's new hub aims to prepare the workforce for AI (August 2026)
2. Australia arrested the two men behind the LiteLLM supply-chain hack.
The crew that poisoned Trivy, Checkmarx KICS and LiteLLM is in custody, but every build that pulled a compromised version still has credentials to rotate.
The Australian Federal Police charged two Western Australian men, Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, as alleged principal participants in TeamPCP, the group behind the March 2026 software-supply-chain attack that poisoned updates to the open-source scanner Trivy, Checkmarx KICS, and the AI gateway LiteLLM. Police say the campaign hit more than 1,000 organizations, exposed 500,000-plus credentials, and stole over 300GB of data, with targets including OpenAI, GitHub, Mercor and European Commission cloud systems. The two appeared in Perth Magistrates Court on August 27 facing more than a dozen offences.
An arrest is the satisfying end of a story, and it leaves your exposure exactly where it was. A poisoned dependency is a landmine that stays armed long after whoever planted it is in a courtroom: any credential, key or token that was live on a machine that pulled a compromised Trivy, KICS or LiteLLM build is still, today, potentially in someone else's hands. This is the same lesson we drew in June, when an attacker poisoned thirty-two Red Hat packages and the only safe assumption was that the secrets were already gone. The fix then was the rotation, and it is the rotation now.
Why this matters: If your team ships software, the arrest that made this week's headlines does nothing for the credentials a poisoned build already exposed. This is the kind of breach where you can do everything right on your own machines and still get burned, because the compromise rides in through a dependency you were correct to trust. "The attackers are caught" reads like closure, and it is exactly the moment people stop rotating.
Action this week: Pull your dependency history for the compromised window and rotate every credential those builds could have touched, arrest or no arrest. When I have cleaned up after one of these, the thing that bites is the service token nobody remembered was sitting on the build box, so reissue anything signed on a machine that was exposed and do not trust a "we're probably fine." Then get a written yes or no from whoever owns your pipeline: are we certain nothing pulled a poisoned LiteLLM, Trivy or KICS build, and if we cannot be certain, we rotate anyway.
techcrunch.com: Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI and others (August 27, 2026)
thehackernews.com: Alleged TeamPCP hackers charged in Australia (August 2026)
therecord.media: Australia arrests alleged TeamPCP supply-chain hackers (August 2026)
PickBits Daily Signal is free, and it is the fastest daily read on where AI's real costs and capabilities are landing. If it is worth something to you, the best support is to forward it to one person who would read it. Subscribe today!
3. Ring made better encryption your doorbell's new default.
TAKE locks your video so even Ring and police can't pull it, but Familiar Faces and Search Party stay switched on by default in the same account.
On August 26, Amazon's Ring made TAKE, "Throw Away the Key" encryption, the default for its cloud features, rolling out from September. It uses rotating keys held only briefly in the cloud, so AI features like Smart Alerts and video search keep working, then deletes each key within 24 hours, built on the IETF's open MLS standard. Founder Jamie Siminoff went on CBS to describe it as giving you "literally the key to your video," a variant of the end-to-end encryption you already have on WhatsApp or an iPhone. On its own, that is a genuine, credit-worthy privacy step.
What Ring did not put in front of you is that the same account still runs Familiar Faces, the AI that scans and names the people at your door, currently blocked by biometric law in Illinois, Texas and Portland, and Search Party, which lets neighbors sweep the block's cameras, flagged by Rep. Raja Krishnamoorthi and on by default for cloud-saving devices. All of this lands amid a June class-action over Ring's facial recognition. Better encryption sitting on top of face-scanning that is still switched on just puts a stronger lock on a door you are still broadcasting through. This is the arc we have tracked all year, from Flock's camera networks to the point we made in June, that a $300 camera plus a database puts any neighbor, ex, or landlord in the surveillance business.
Why this matters: Your Ring doorbell just got better encryption by default, and left its AI face-scanning switched on in the same update. The company wants you looking at the encryption; the thing that actually affects you is what it left on, because a feature that stays on unless you go find and disable it is a feature most people will keep. TAKE genuinely narrows who can pull your footage. It changes nothing about the AI reading and naming everyone who walks up to your door.
Action this week: Open the Ring app tonight and do three things: confirm TAKE is on, turn off Familiar Faces, and opt out of Search Party. And if you live in Illinois, Texas or Portland, know that biometric law already gives you standing to push back that the rest of us are still fighting for. I keep coming back to the same thing with Ring: judge it by the switch it quietly left flipped, not the one it put in a press release.
techcrunch.com: Ring introduces a new encryption standard and makes it the default for cloud features (August 26, 2026)
techcrunch.com: Amazon faces class-action over Ring's facial recognition feature (June 2, 2026)
eff.org: Ring's surveillance nightmare (February 2026)
4. A blind doctor's lab built the AI navigation tool he needed.
NYU Langone's Shopscout, Commute Booster and Unav guide blind and low-vision people through stores and subways, and testers finished their trips 33% faster.
Picture a blind shopper walking into a grocery store and choosing their own fruit, guided by a small wearable camera that reads the aisle out loud. That tool is real. It is called Shopscout, and it comes from an NYU Langone Health lab led by Dr. John-Ross Rizzo, who is himself legally blind. His team built three of them: Shopscout for the grocery run, Commute Booster, an app that reads the transit and MTA signage most navigation apps skip past, and Unav, which guides you indoors where there is no cell signal. In testing, blind and low-vision travelers using Commute Booster completed journeys 33% faster, the standout figure from the team's Dr. Giles Hamilton-Fletcher.
That number is the whole point, and it is worth being honest about what it is and isn't. This is lab and pilot work, led by the people who actually live the problem, not a product sitting on a shelf you can buy tomorrow, and the researchers say so plainly. But that is also exactly why it reads as the good story. When the person building the tool is the person who needs it, the design tends to solve the real problem, the one an able-bodied product manager would never think to name, instead of the demo. The market skipped these problems for decades, mostly because the people who had them were never in the room when the tools got built. This time one of them was running the lab.
Why this matters: A blind shopper can now walk into a grocery store and pick their own fruit, guided by an AI that reads the aisle out loud, and blind commuters got through their trips a third faster. This is the version of "AI for good" that comes with a real number attached, on a problem the market skipped for decades, built by the people it is for. When the guy running the lab rides the subway blind, the thing gets built for the actual trip, and it shows.
Action this week: Watch whether a transit agency, an MTA, actually picks up Commute Booster and runs it at scale, because that is the line between a study and a commute. My own read, after a year of assistive-tech demos that never ship, is that the lead researcher being blind himself is the single best reason to bet this one does. And if you know someone navigating vision loss, this is the rare tech story worth forwarding not as a warning but as something to try.
cbsnews.com (CBS New York): New AI tools help visually impaired people navigate (August 18, 2026)
» What to watch this week
- Whether the Labor Department publishes the actual data-sharing terms, or just the workforce hub built on top of them. The dashboard is the announcement; the audit rights, the filtering, and who gets the raw feed are the story, and a hub that ships without them is Big Tech grading its own homework.
- Whether anyone can confirm no build in your dependency chain pulled a poisoned LiteLLM, Trivy or KICS version. The arrests close the case, not the exposure; the open question for every affected org is whether it rotated credentials during the March window or is still trusting a compromised token today.
- Whether Ring ever flips Familiar Faces and Search Party to off-by-default, and whether the June class-action forces it. TAKE shows Ring can make the pro-privacy choice the default when it wants to; the tell is whether it makes the same choice for the AI surveillance features it profits from.
- Whether a transit agency runs an NYU Langone tool like Commute Booster on live infrastructure. A 33% improvement in a study becomes real the day an MTA puts it on an actual line; that pilot is the moment this research actually reaches the people it was built for.
Tomorrow's signal lands here.