> daily_signal(2026_09_15)
A Manhattan DA seized a dozen deepfake-porn sites, a leak exposed the humans grading your ChatGPT chats, a free Chinese model beat the paid ones, and the first AI-invented drug hit its final trial.
PickBits Daily Signal · Tuesday, September 15, 2026
// tl;dr
- Manhattan DA Alvin Bragg seized 12 websites that used AI to fabricate sexual images from roughly 1,200 real people's faces, including actors, athletes, politicians, and the first ladies of multiple countries, under New York's 2023 deepfake law. It's the first time a US prosecutor has taken a whole deepfake-porn marketplace offline rather than charging one defendant, and it lands two days after the first federal prison sentence in the same fight.
- A 404 Media leak revealed OpenAI's "Project Lily": hundreds of contractors paid over $50 an hour to read real ChatGPT conversations and grade the replies 1 to 7. Human review is disclosed only in a buried FAQ, the "Improve the model for everyone" setting is on by default for personal plans, and reviewers see sensitive data despite the scrubbing.
- AllSpark released Iris-mini and Iris-pro, open-weight search agents under Apache 2.0 that lead or tie their size classes across four web-research benchmarks. They're built on Alibaba's Qwen, free on Hugging Face, and a real self-hostable alternative to per-query closed search APIs, with the catch that the weights are China-origin.
- Insilico Medicine dosed the first patient in the world's first Phase 3 trial of a drug both discovered and designed by generative AI. The AI surfaced a target, TNIK, never before tied to lung fibrosis, then generated the molecule, rentosertib. Reaching the final trial is a world first, but it's a first dose, not a result.
The deepfake seizure is the one that stuck with me today. On Sunday I wrote about the first person ever sent to federal prison under the new deepfake law, one man, fifteen years. Two days later a Manhattan prosecutor stopped charging people one at a time and seized a dozen of the websites themselves, an entire storefront built from twelve hundred real faces. And in the same forty-eight hours, a leak turned that flat line in a privacy FAQ, "humans may review your content," into something you can picture: a paid stranger reading, word for word, whatever you typed into ChatGPT and grading it one to seven.
The other two are lighter on dread. A Chinese lab gave away search agents that top the benchmarks the closed labs charge you by the query to touch, the same "cheap open models eat the mid-tier" thread we've pulled since the summer, now with a China-origin governance string attached. And the good one: an AI didn't tweak a known drug, it picked a target nobody had tied to a disease and designed the molecule to hit it, and that molecule just reached its last human trial. And the thing I can't shake is how much of today just runs on trust. In three of these four you mostly have to take the company's word that it's safe, or that it works, and nobody outside has actually checked.
A prosecutor seized the sites instead of the suspect, a leak put a human on the other end of your chatbot, a free model outscored the paid ones, and an AI-designed drug reached its final trial.
1. A Manhattan prosecutor seized a dozen websites that fabricate deepfake porn from real people's faces.
It's the first time a US prosecutor has taken an entire deepfake-porn marketplace offline, two days after the first federal prison sentence in the same fight.
On September 14, Manhattan District Attorney Alvin Bragg's office seized 12 websites that used AI to fabricate non-consensual sexual imagery from roughly 1,200 people's likenesses. These weren't anonymous targets: the depicted were public figures, actors, athletes, musicians, social-media influencers, politicians, social-justice advocates, and the first ladies of multiple countries. The seizures cite New York's 2023 law criminalizing sexually explicit deepfakes, the investigation is ongoing, and Bragg declined to say whether images of minors were found. It arrives two days after the story I ran Sunday, the first federal prison sentence under the Take It Down Act, and it belongs to the same arc we've tracked all year, from Arizona folding AI fakes into its intimate-image law to xAI suing Minnesota over its deepfake statute.
What's different here is what got hit. Charge a person and you punish a person; seize the sites and the product is just gone, for everyone, at once, which is a much bigger blow to a business than to any one defendant. And 1,200 faces across a dozen sites isn't the whole thing, it's the part you can see, one node of a bigger commercial operation that stands a new site up the day you take one down. So you go after the storefronts, not the occasional creator. The storefronts are the business.
Why this matters: Most enforcement so far has gone after one person at a time, which makes a headline and leaves the business running. Seizing the sites takes the product down instead, and it hands every other prosecutor a playbook they can run under a law many states already have on the books. It's the first move in two years aimed at the market rather than at a single arrest.
Action this week: Find out whether your own state has a deepfake statute, and if it does, put one question to your district attorney's office or state legislator: will you use it to seize the sites, not just charge the occasional defendant. Most states passed these laws and then used them the slow way, one person at a time. Honestly, this is the first move I've seen that treats these sites as the business they are, and the states that copy Bragg this year will do more against this than the ones still writing press releases.
404media.co: New York District Attorney seizes 12 celebrity deepfake websites (September 14, 2026)
wired.com: New York seizes a dozen celebrity deepfake websites (September 2026)
2. A leak revealed that hundreds of contractors are paid to read and grade real ChatGPT conversations.
OpenAI calls it Project Lily; human review is disclosed only in a buried FAQ, and the setting that opts you in is on by default.
Right now, a person you'll never meet may be reading something you typed into ChatGPT, word for word. OpenAI runs a program it internally calls Project Lily, in which hundreds of contract workers, recruited through a firm called Crossing Hurdles and paid through the AI-training company Mercor at more than $50 an hour, read real ChatGPT prompts and score the replies on a scale of 1 to 7. That's the finding of a 404 Media investigation, built on leaked internal documents and published September 14, and the scoring it describes is training data. A "privacy filter" scrubs names first, but OpenAI's own page says it isn't an anonymization tool and sensitive details can still get through, and reviewers are shown a "user memory summary" that can reveal what you've used ChatGPT for and roughly where you live. It's the concrete edge of the ChatGPT-privacy thread we've followed for weeks, from the scrutiny of Temporary Chat to the risk in letting the model search years of your history.
To be fair to OpenAI, this isn't quite the horror movie it sounds like. It did disclose human review, buried in a consumer-data FAQ, and honestly every big chatbot maker does a version of it. The reviewers are even there to catch sycophancy, the flattery habit where a chatbot just agrees with everything, so scaring everyone into opting out would slow a fix people actually want. What bugs me is simpler than any of that. The word "human" appears nowhere on the setting itself, called "Improve the model for everyone," and nowhere on the page it lives on, under Settings, then Data Controls. It's on by default for the free, Plus, and Pro plans and off by default for Enterprise, Business, and Edu, the same company drawing opposite defaults for you and for its paying customers. Turn it off and it only covers new chats; give any reply a thumbs up or down and OpenAI can use that whole conversation anyway.
Why this matters: The problem isn't that humans help train the model, it's that the one label that would tell you a person might read what you wrote never says so, and it's switched on for you the moment you sign up. Disclosure buried in a FAQ you'd never open isn't the same as disclosure where the decision is actually made, on the toggle itself. When the same company sets that toggle off by default for the accounts it bills and on by default for the ones it doesn't, and that gap didn't happen by accident.
Action this week: Open ChatGPT, go to Settings, then Data Controls, and switch off "Improve the model for everyone," knowing it only affects chats from here on, not the ones already sent. Keep anything you'd never want a stranger reading out of a consumer chatbot account entirely, since the filter is explicitly not an anonymizer. What gets me is that this is a disclosure problem before it's a surveillance one. I don't mind that people teach the model what a good answer looks like; I mind that the one label built to tell me so is the single place the word "human" never appears.
the-decoder.com: OpenAI has hundreds of contract workers reading your ChatGPT conversations (September 14, 2026)
404media.co: Inside 'Project Lily', the humans reading your ChatGPT chats (September 14, 2026)
3. A Chinese lab gave away open-weight search agents that top the benchmarks and cost nothing to download.
Iris-mini and Iris-pro are Apache-2.0 and built on Alibaba's Qwen, which changes the build-versus-buy math for any team paying per query for a closed search API.
If your team pays for AI web search one query at a time, you have a build-versus-buy decision on your desk this week. On September 13, a lab called AllSpark released two open-weight search agents, Iris-mini (35B-A3B) and Iris-pro (397B-A17B), post-trained from Alibaba's Qwen3.5/3.6 and licensed under Apache 2.0, with the weights on Hugging Face and the Iris Harness, the agent loop, tools, and context-management code, on GitHub. They aren't toys. Iris-pro scores 88.6 on BrowseComp with its discard-all context management (72.6 without it), the pair leads or ties its size class across BrowseComp, BrowseComp-ZH, DeepSearchQA and Humanity's Last Exam, and Iris-mini beats the next-best in its class on BrowseComp by 3.4 points. This is the "mid-tier models die to cheap open systems" thread we've pulled since July, now landing squarely on the search-API line item, right after a benchmark that started ranking those APIs on cost as well as quality.
A self-hostable model that matches closed frontier systems on a public benchmark genuinely changes what "we need search" is allowed to cost, since the closed alternatives bill you per call. But a leaderboard win is a win on someone else's queries, not yours, and these weights are post-trained from Chinese models, which puts self-hosting them in front of your security team, not just your engineers. So the capability is free to download, and the decision to run it still needs someone to sign for it.
Why this matters: A capability a team may be renting by the query is now a free download that leads its class on the public benchmarks. That doesn't retire the closed search APIs overnight, but it moves the ceiling: the honest reason to keep paying can't be raw capability anymore. It has to be integration, or support, or the governance headache you'd rather someone else carry. And you're going to keep seeing "open weights, but China-origin" on decisions like this one.
Action this week: Before you swap a paid search API for Iris, run it against your own real queries rather than the leaderboard, because a benchmark win is not a win on your traffic. Then get one thing answered in writing from whoever owns security: are China-origin open weights allowed to run in our stack, and under what isolation. When I've priced per-query search APIs against a model I host myself, the math flips hard once volume climbs, but the sign-off, not the accuracy, is almost always the real gate, and it's the part teams discover last.
the-decoder.com: Iris-mini and Iris-pro are the strongest open-weight search agents in their class (September 13, 2026)
github.com: AllSpark-Research/Iris (Iris Harness, open source)
huggingface.co: AllSpark-Research/Iris-pro (open weights)
PickBits Daily Signal is free. If it lands in your inbox every day and it's worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!
4. The first drug an AI both invented and chose the target for just entered its final human trial.
Insilico's rentosertib, aimed at a lung-scarring disease with few options, is the first Phase 3 trial of a molecule and target both generated by AI, a milestone, not yet a cure.
Picture someone whose lungs are slowly hardening into scar tissue. That's idiopathic pulmonary fibrosis: breath lost a little more each year, causes that stay unclear, and treatments that barely slow it down. On September 9-10, Insilico Medicine dosed the first patient in GENESIS-IPF-3, described as the world's first Phase 3 trial of a drug whose target and molecule were both discovered and designed by generative AI. Insilico's system surfaced the target, a protein called TNIK that had never previously been linked to fibrosis, then generated the molecule, rentosertib (ISM001-055), to hit it. The trial is a randomized, double-blind, placebo-controlled study of once-daily rentosertib over 52 weeks in 320 patients across 47 centers in China, with annual forced-vital-capacity decline as the primary endpoint; an earlier 12-week Phase 2a showed lung-function improvement. It's the arc of AI drug design we've tracked from a cancer molecule built from scratch in August to AI-designed CAR-T binders this month, and this is the one that reached the last stage of human testing.
Reaching Phase 3 with a molecule and a target both machine-generated is a world first, and the target is the part that got my attention. Most AI drug work starts from a protein scientists already suspect and just draws a better molecule for it; here the system proposed a protein nobody had tied to the disease, and a Phase 2a suggests it was onto something. But this is still a first dose, not a finding. There's no efficacy readout, 320 patients have a year of dosing ahead of them, and plenty of drugs look promising at this point and fail. The milestone is that the AI picked the target. Whether the medicine actually works is up to the trial now.
Why this matters: For someone living with IPF, the options today are thin, and a genuinely new mechanism is worth more than another incremental tweak. The part that matters beyond this one drug is that the AI didn't just design a molecule against a target a human handed it, it proposed the target, TNIK, that nobody had tied to the disease. If an AI can keep finding targets like that, and they keep panning out, it changes where new medicines even come from, not just how fast we draw them.
Action this week: Read this as a milestone, not a cure, and hold the "an AI invented a drug" headline against the one number that will actually decide it: whether patients on rentosertib lose less lung function over the 52 weeks than patients on placebo. Watch for that readout rather than the launch. The way I see it, the real result is already banked, the AI found the target, and the efficacy question is wide open, which is exactly the honest place a first-in-class Phase 3 should sit.
news-medical.net: Generative-AI-driven drug rentosertib enters Phase III trial for idiopathic pulmonary fibrosis (September 10, 2026)
insilico.com: Insilico Medicine doses first patient in GENESIS-IPF-3 (September 2026)
biospace.com: Insilico doses first patient in GENESIS-IPF-3, the world's first Phase III trial of a generative-AI-driven drug (September 2026)
» What to watch this week
- The next prosecutor to copy the seizure, not just the charge. Bragg handed every DA with a state deepfake law a playbook. The tell is whether a second office seizes sites in the next few weeks, or whether this stays a one-city move.
- Whether OpenAI puts the word "human" on the toggle. Right now the disclosure lives only in a FAQ most people never open. The fix that would matter is saying it on the setting itself, not deeper in the help pages.
- Whether Iris holds up off the leaderboard, and clears governance. The number to watch is a team publishing results on their own queries, and separately, whether security functions start writing an explicit yes-or-no on China-origin open weights.
- Insilico's first efficacy signal. GENESIS-IPF-3 won't read out for a while, but any interim word on forced-vital-capacity decline is the moment "AI picked the target" becomes "the drug works," or doesn't.
Tomorrow's signal lands here.