> daily_signal(2026_09_16)

Three of four AI stories today turn on who checks the system: the labs want to police themselves, Clearview hid a dossier tool, an AI wrote your invoice scam. Gates bet a billion on AI for the poor.

PickBits Daily Signal · Wednesday, September 16, 2026

By Mark Pickering · 8 min read · September 16, 2026

// tl;dr

The antitrust story is the one that turned over on me today. Back in August, the government was the side worried about concentration in AI: the Justice Department had opened a probe into whether Andreessen Horowitz's partners, sitting on the boards of competing labs, held too much control over the sector. This week the biggest labs themselves walked into Washington and asked for the opposite. Let us coordinate, exempt us from antitrust, so we can slow frontier AI down together in the name of safety. Whether you read that as caution or as a moat depends on who you trust, and that's the whole problem, because the people who would write the rule are the people it would protect.

The other three come back to the same question. WIRED found a Clearview tool, built to auto-assemble a dossier the moment a camera knows your face, sitting in the company's own login page with no filing or announcement to be found. Microsoft caught a million-email invoice scam so clean that the tell of AI is in the tidy templates, not in the typos. And the good one, the Gates Foundation putting a billion dollars into AI for the world's poorest, arrives stapled to Gates's own warning that the same tools could skip those people entirely. And so much of today comes down to trust, taking a company's word that a tool is safe and that it isn't being misused, while the only party able to check is the company itself.

Dario Amodei asked for an antitrust exemption, WIRED found Clearview's dossier tool in a login page, Microsoft traced a million fake invoices, and Gates wired a billion dollars toward the people AI usually skips.

1. The biggest AI labs asked Washington for permission to slow AI down together.

A rival CEO calls it a cartel by another name and the White House calls it regulatory capture, which flips the antitrust fight we tracked in August clean on its head.

Over the weekend, Anthropic's Dario Amodei called for a coordinated, deliberate slowdown of frontier AI, enforced by shared global standards, with antitrust exemptions so the dominant labs could legally work together. Sam Altman and Elon Musk backed the push to regulate. The reaction split hard and fast. Cohere's Aidan Gomez called it "a cartel by another name," arguing that only the largest players could afford the compute, the monitoring infrastructure, and the safety organizations the plan would mandate. White House AI czar David Sacks pointed at OpenAI and Anthropic's "duopoly in frontier intelligence" and framed the ask as regulatory capture, while President Trump dismissed AI-takeover fears as a "hoax" and the effort as a "scam." Obama, Bernie Sanders, and Kamala Harris separately backed plain transparency measures instead. It belongs to the same arc we followed in August, when the Justice Department opened an antitrust probe into Andreessen Horowitz over its partners' seats on competing AI boards, only now the sector is asking Washington for the room to coordinate that the DOJ was worried about in the first place.

A coordinated slowdown is also a wall, and it happens to be a wall only the companies asking for it can afford to build, since the compliance, the monitoring, and the safety bureaucracy all cost more than a challenger has. That doesn't make the underlying risk fake. Plenty of serious people think fast, unchecked frontier development is genuinely dangerous. It just makes the messenger hard to trust, because the same handful of firms would write the rule and would be the ones it shields.

Screenshot of The Decoder's September 15 report on the AI labs' proposed slowdown and the backlash to it
the-decoder.com · September 15, 2026

Why this matters: When the firms that would gain the most from a rule are the ones drafting it, an outsider can no longer tell the safety argument from the competitive one, because they are worded identically. A rule that only the incumbents can afford to comply with doesn't slow AI so much as it freezes the current leaders in place. And this isn't a niche fight over corporate structure. It's a decision about whether powerful AI gets governed in public or negotiated privately between a handful of labs and the agencies meant to check them.

Action this week: Watch who carries the counter-offer, not the headline about a slowdown. Obama, Sanders, and Harris all backed transparency, telling the public what these systems can actually do, without handing the incumbents a coordination exemption, and that's the version an ordinary citizen has standing to push for. My own read is that a coordinated slowdown priced beyond any challenger is a moat wearing a safety badge, so the lever worth pressing your representative on is disclosure, not exemption. It's the one that survives whether or not the labs are sincere.

the-decoder.com: Not everyone is convinced big AI's proposed development slowdown is really about safety (September 15, 2026)

2. Clearview built a tool that auto-assembles your online life from a single face match.

It runs on a model from Elon Musk's xAI, reporters found it hidden in the code Clearview's login page ships to every visitor, and there's no public record of it anywhere.

Reporters at WIRED found an unreleased Clearview prototype called InquiryIQ by reading the code the company's own login page sends to every visitor's browser before anyone signs in. After a face match identifies someone, InquiryIQ uses a model from Elon Musk's xAI, the company behind Grok, to fan out across the web on its own and assemble a profile of that person's likely employers, aliases, associates, and physical characteristics. There are no public records, no announcement, and no regulatory filing about the tool anywhere; WIRED found it in a login page. Clearview told WIRED that police have never used InquiryIQ and that it has no plans to release the current version, and two other outlets independently corroborated the reporting. We have tracked this surveillance arc all summer, from consumer face-recognition gear that puts a database in anyone's hands to the fight over whether police get to run these searches at all, and this moves the line one more notch.

Clearview's existing business is what makes this a leap. It scraped billions of photos off the open web, our Facebook and Instagram posts included, and built a searchable database it sells to police, so that any face can be matched against nearly everything a person has ever posted. The old product was the match itself; the new one turns a single hit into an automatic file.

Screenshot of WIRED's September 10 report on Clearview's hidden InquiryIQ face-to-dossier tool
wired.com · September 10, 2026

Why this matters: The debate over facial recognition has always been about being identified in a crowd. InquiryIQ moves the line to being automatically dossiered the instant you are identified, by a private company, with no law telling it to stop and no filing telling anyone it exists. That a working version was discovered in shipped login-page code, rather than disclosed, is the whole tell: the reassurance that police have never used it only exists because a reporter went looking.

Action this week: Find out whether your state has a biometric privacy law, the kind Illinois has, that gives an ordinary person the right to sue over the use of their own faceprint. That standing is the only lever that has actually forced Clearview to change its behavior before. When I have watched these fights play out, the states with a private right of action are the ones where the company negotiates, and the states without one are where it simply operates. If your state has no such law, that absence isn't a gap in the story, it's the story.

wired.com: Clearview AI is testing an AI tool that lets cops instantly unearth your online activity (September 10, 2026)

3. Microsoft caught a million-email invoice scam aimed mostly at US companies.

Each message asked for about $50,000, wrapped in fake ServiceNow invoices and forged executive threads, and Microsoft reads the AI fingerprints in the templates rather than the typos.

In early August, Microsoft's security team detected a single business email compromise campaign of more than 1 million fraudulent emails, with roughly 88% aimed at American organizations and each message requesting close to $50,000. What makes it different from the phishing everyone has been trained to spot is that the tell is gone. The operators stitched together executive impersonation, real ServiceNow vendor branding, a fabricated invoice, and a fake supporting email chain into one coherent narrative that reads exactly like a company's own accounts-payable workflow. Microsoft flagged the construction as AI-assisted, pointing to extensive HTML comments, structured section labeling, and templates too uniform to be handmade at that scale, while cautioning that it can't independently establish how much of the content a model actually generated. We have watched AI keep turning up on the attacker's side, and this is the version aimed straight at your finance team.

The mechanics are old, and the FBI mapped them years ago: a phishing email gets one finance person to click, the criminals quietly alter the bank routing number on a real-looking invoice, and the payment goes out to them instead of the vendor. What is new is that the bait no longer looks wrong. The grammar is clean, the branding is real, the thread above it's fabricated but plausible, so the defenses built to catch sloppy fakes catch nothing.

Screenshot of The Record's September 11 report on Microsoft's million-email invoice-scam campaign
therecord.media · September 11, 2026

Why this matters: The advice that carried corporate security for a decade, teach people to spot the typos and the odd sender address, is now dead, because a model removes exactly those tells. Detection was always the weaker control; it just looked good enough while the fakes were bad. When the fake reads like your own paperwork, the only thing left that works is verification, a step that doesn't depend on a human noticing something feels off.

Action this week: Put one rule in writing for your finance team and get it signed off: no change to a vendor's bank details, and no wire over a set threshold, goes out on the strength of an email alone. It gets confirmed by a phone call to a number you already had on file, never a number from the message itself. When I have watched these losses happen, the companies that paid all shared one gap, a single person able to move funds off a single email, and closing that gap is what makes the fanciest AI-written invoice bounce. Ask your controller today which of those two controls you actually have.

therecord.media: Invoice scam emails gain new features, Microsoft researchers say (September 11, 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it's worth something to you, the best way to support it's to forward it to someone who would read it. Subscribe today!

4. The Gates Foundation is putting a billion dollars into AI for the world's poorest.

A Kenyan clinic's AI already cut diagnostic errors and a Sierra Leone tutor moved students up to 1.7 years in eight weeks, but Gates warns the same tools could skip the people they are meant for.

Picture a mother walking into a clinic in rural Kenya, describing her child's symptoms in her own language, to a health worker whose AI assistant is quietly catching what a rushed visit might miss. That's not a pitch: at Kenya's Penda Health network, a clinical-AI tool raised diagnostic accuracy by 16 percentage points. This week the Gates Foundation said it will invest at least $1 billion over two years to widen access to AI in health, education, and agriculture, released alongside its 2026 Goalkeepers report. The early results it pointed to are concrete. In Sierra Leone, an AI tutor called "Gemini Guided Learning" drove student gains of up to 1.7 years in eight weeks. It lands on the AI-in-medicine arc we have tracked from AI-designed drugs reaching trials to the harder question of whether these tools survive contact with a real clinic, and here the answer is being tested in the places with the least slack to absorb a failure.

Here is the honest part, and Gates said it himself: the billion dollars is the easy part. The same technology could leave the poorest behind, because the tools are built where the data is. More than 90% of the early data these large language models learned from came from English sources, and speech recognition still fails about 60% of the time in Yoruba versus under 6% in English. A diagnostic assistant that only works well in English isn't help for most of the planet. It's help for the part that already had options.

Screenshot of The Decoder's September 15 report on the Gates Foundation's $1 billion AI commitment
the-decoder.com · September 15, 2026

Why this matters: For a health worker in a rural clinic, a tool that catches a missed diagnosis is worth more than any frontier benchmark, and the Penda result suggests that's already happening in the real world, not a demo. The part that could still go wrong is the part Gates named. Announced money isn't funded money, funded pilots aren't running programs, and a program that only performs in English quietly redraws the map of who AI is for. The measure of this billion dollars isn't how it's announced but whether it closes that language gap or widens it.

Action this week: Watch the language, not the dollar figure. The number that will tell you whether this reaches the people it's for is how these tools perform in Yoruba, Krio, and Swahili, not in English, and whether the foundation reports the gap closing over the next year. Treat "announced" as a starting line, not a result, and track which of these three pilots is actually running a year from now versus still being described in a press release. My own read is that the diagnostic win is real and already banked, and the open question is whether the tools speak the languages of the people they were built to serve.

the-decoder.com: After warning AI is too dangerous, Bill Gates bets a billion on its upside (September 15, 2026)

» What to watch this week

Tomorrow's signal lands here.