> daily_signal(2026_09_19)
The classroom-AI fight we've followed since summer is now Florida law, alongside a Siri that reads your screen, a $3,000 break-in at OpenAI, and a free CT-scan AI.
PickBits Daily Signal · Saturday, September 19, 2026
// tl;dr
- Florida's Board of Education adopted the AI-in-schools rule we covered on September 3 as a scheduled vote. Every district, charter, and the 28 state-college boards must build AI guardrails into their internet-safety policies by July 1, 2027. Schools have to tell parents the name of each approved AI tool and the classes it runs in, offer a non-AI alternative, and are barred from any system that grades kids in secret or poses as a friend.
- iOS 27's redesigned Siri has an "on-screen awareness" feature that can read whatever is on your screen, including messages inside Signal and WhatsApp. The EFF warns the developers of encrypted apps cannot block it, and Apple gives no clear signal when a query is sent to its Private Cloud Compute servers. The fix is three settings you can change in about a minute.
- Three Hacktron researchers used Anthropic's Claude to break into OpenAI's internal systems in under 72 hours, for under $3,000. Claude Opus 5 wrote a working exploit in about three hours after Opus 4.8 fell short. The way in was OpenAI's neglected public community forum; the chain reached its single sign-on, employee accounts, and an internal GitHub repo. OpenAI fixed the holes about 14 hours after disclosure.
- Alibaba's Damo Academy open-sourced Damo Radar, a model that reads a contrast CT scan and flags nearly 150 conditions across 18 organs, cancers included, free for any hospital to download. In a study in Science, it hit an average AUC of 0.913 across 146 findings on roughly 40,000 real exams, and is billed as the first expert-level generalist medical-imaging model.
The Florida story is the one I would read first today, and it is the least dramatic of the four. We have been on this since September 3, when the state's AI-in-schools rule was just an item scheduled for a vote. This week it passed, with a real deadline and a parental opt-out, which makes it the clearest thing a government has actually done about classroom AI while everyone else is still arguing. The other three are less settled. Apple's new Siri can read your screen, encrypted apps included. A team broke into OpenAI for less than a used car costs. And Alibaba gave away an AI that reads a CT scan.
None of those three is really new. We flagged Siri turning into Apple's everything-tool back in July, and we have spent the summer on report after report showing AI keeps making hacking cheaper. This week each of them turned concrete, and I don't think most people clocked how fast that happened. I think the Alibaba release is quietly the biggest deal here, and I think the Siri change is the one almost nobody will notice until it burns them.
Florida's new rule says a school has to tell you the name of every AI tool your kid's teacher turns on.
1. Florida turned its AI-in-schools proposal into binding law.
Every district, charter, and state college must tell parents which AI tools are in the classroom, and let them say no, before July 1, 2027.
We covered this on September 3, when it was only a rule the Florida Board of Education was scheduled to vote on, a proposal on a calendar. This week the Board adopted it, and the calendar item became a mandate with a deadline. All public school districts, charter schools, and the state's 28 state-college boards of trustees must fold AI-specific guardrails into their internet-safety policies before July 1, 2027. Education Commissioner Henry Mack framed it as a middle path, avoiding an outright ban while blocking "unfettered access."
The load-bearing part is not the ban list, it is the paperwork. Whenever a teacher approves an AI instructional tool, the school must notify parents of the platform's name and the classes it is used in, give them a documented way to object, and provide a non-AI alternative on request. PreK-5 tools get extra age-appropriateness review, and the rule bars any system that harvests student data, grades kids in secret, or, in Governor Ron DeSantis's words, "pretends to be a friend." That lines Florida up next to two other approaches we've tracked: New York City put an outright moratorium on classroom AI, and the Microsoft-and-union fight is all about who controls the training data.
Why this matters: If you have a kid in an American public school, your state now has roughly three ways it can go on classroom AI, and Florida just picked the one built on telling parents and letting them opt out rather than banning the tools. I like that more than a ban, but the enforcement is where it gets hard. A notification rule only works if the notices actually reach parents and if a district can produce, on demand, a list of every AI tool a teacher has switched on, which is a software-inventory problem most districts have never solved.
Action this week: Ask your district for its list of approved AI tools and the opt-out form. That list is now legally required to exist, so a district that can't produce it is already out of step with the rule. My honest read, after watching age-verification and consent rules land the same way, is that these disclosure rules live or die on whether a single parent ever shows up to read the list, so be the one who does.
2. iOS 27's Siri can read your encrypted messages off the screen.
On-screen awareness lets the new Siri see anything on your display, including Signal and WhatsApp, and the apps cannot block it.
Back in July we flagged that Siri was quietly turning into Apple's everything-tool, one assistant reaching across every app on your phone. In iOS 27, that ambition shipped as a feature called on-screen awareness: the redesigned, chatbot-style Siri can analyze whatever is currently on your screen. The Electronic Frontier Foundation spelled out the flashpoint. Because Siri reads the display rather than the network, that includes the messages inside end-to-end encrypted apps like Signal and WhatsApp, and the developers of those apps have no control to block it. Apple also gives no clear indication when a query is routed to its Private Cloud Compute servers instead of staying on the device.
Apple's not wrong that this is the same deal every AI assistant offers, and its on-device processing really is better than most. My problem is narrower. It shipped as a default nobody chose, on the exact kind of app people use because it is supposed to be sealed. Your Signal thread stays encrypted right up until Siri reads the words off the glass, and nothing in the setup makes that obvious.
Why this matters: If you just updated your iPhone, Siri can now read your Signal and WhatsApp messages straight off the screen, and there's nothing the apps can do to stop it. That's a real shift in who can see your private conversations, and it happened as a default in an update most people tapped through without reading. It bothers me because encrypted chat was the one place people assumed was actually private, and now the assistant on the same phone can read it anyway.
Action this week: Open Settings and change three switches EFF flags. Turn off Show Content in Search for the apps that hold anything sensitive, turn off Improve Siri & Dictation under Privacy & Security then Analytics & Improvements, and if you want the old assistant back, revert to Siri Classic under Screen Time then Content & Privacy Restrictions. The Show Content in Search toggle is the one I changed first, because it's the switch that decides what Siri gets to see.
eff.org: How to limit what Apple's new Siri AI can access in iOS 27 (September 18, 2026)
PickBits Daily Signal is free. If it lands in your inbox every day and it is worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!
3. Researchers used Claude to break into OpenAI for under $3,000.
A neglected public forum was the way in; an off-the-shelf model wrote the exploit that reached OpenAI's single sign-on, employee accounts, and an internal repo.
Three researchers at the firm Hacktron chained two vulnerabilities in OpenAI's public community forum at community.openai.com and used that foothold to reach OpenAI's single sign-on system, employee ChatGPT and Codex accounts, and an internal GitHub repository. They proved the access by opening a harmless pull request from an employee's Codex account, and OpenAI confirmed it patched the holes roughly 14 hours after disclosure. The whole thing took under 72 hours of active work across a two-month project.
What gets me is that the researchers didn't write the break-in themselves. Anthropic's Claude Opus 5 produced the working exploit in about three hours, after the earlier Opus 4.8 had failed at it, and the team's whole AI bill came to under $3,000. We've spent the summer on this arc, from federal agencies warning that attackers use AI to build exploits to report after report showing it keeps getting cheaper, so the direction isn't the surprise. What got me is that it landed on OpenAI, of all places. I'll hold onto the counterpoint we ran in August, though: AI finds tons of flaws, and almost none of them actually get exploited, because turning a bug into real access is still slow, skilled work. That part still holds. Finding got cheap this year; the hard part didn't, and I wouldn't bet on that lasting.
Why this matters: If you own any part of your company's attack surface, the way into OpenAI should worry you more than the price tag: a neglected public forum nobody had in the threat model, turned into a path to the crown jewels by a model anyone can rent. AI didn't work magic here. What changed is the cost of a competent attacker, now roughly the price of a laptop, so the stuff you forgot you even owned is suddenly worth an attacker's time.
Action this week: Pull the list of everything your company exposes on the public internet and find the forgotten one, the old forum, the stale subdomain, the marketing microsite nobody owns. Put the question to your team in writing: what is on our attack surface that is not in our asset inventory? When I have asked that question of teams I have worked with, the answer is never empty, and OpenAI's answer turned out to be a community forum that cost it a path to its own single sign-on.
4. Alibaba open-sourced an AI that reads a CT scan and flags nearly 150 conditions.
Damo Radar covers 18 organs, cancers included, hit an average AUC of 0.913 in Science, and any hospital can download it for free.
Picture a hospital that does not have a specialist radiologist for every scan, which describes most hospitals on the planet. Alibaba's research arm, Damo Academy, just open-sourced Damo Radar, a vision-language model that reads a contrast-enhanced CT scan and identifies nearly 150 abdominal conditions across 18 organs, including malignant tumors, rather than being trained for a single disease. In a study published in the journal Science, it reached an average area-under-the-curve of 0.913 across 146 clinical findings, tested on roughly 40,000 real-world examinations, and its developers describe it as the first expert-level generalist medical-imaging model.
We have written about AI cancer-detection tools before, including the ones that fell short of what radiologists were promised, so I want to be careful with that 0.913. It's a genuinely strong number on a large, well-documented test set. It isn't the same thing as working in a busy emergency room on a Tuesday night, where the images are messier and the stakes are immediate. From what I have seen reported on tools like this, they cut both ways: the model flags cancers a panel of radiologists walked past, and it also misses things those same radiologists would catch. But the part that actually matters to me is the second half of the pitch, that a hospital that could never afford a radiologist can now run an expert-level read for free.
Why this matters: A free AI can now read a CT scan and flag nearly 150 conditions, including cancers, and any hospital on earth can download it today. The hopeful part has nothing to do with beating doctors. It is that "open-source" and "free to download" mean a rural clinic in a country with a handful of radiologists can run expert-level triage at all, which is a very different thing from one more pricey tool sold to hospitals that already have specialists.
Action this week: Watch whether real hospital systems actually pick this up, not just whether the paper trends. There is a big gap between a model that is announced, one that is published, and one actually running in a clinic, and most medical AI stalls somewhere in there. My own read is that the license and the price make this one worth rooting for, but I will believe the impact when a hospital that could not afford a radiologist tells me it caught something with it.
» What to watch this week
- Which state moves next. Florida makes three approaches on the table now, and with a 2027 deadline on the books, the next few boards to act will show whether telling parents or banning the tools outright is winning.
- Apple's response is the tell. Does it add a clear on-device-versus-cloud indicator, or a real developer switch for on-screen awareness? So far its answer is the three settings you have to dig out yourself.
- The forgotten-property audit. OpenAI's peers now have a concrete reason to map every public thing they own. If cheap AI recon is what finally makes companies do that, this break-in did some good.
- The first real deployment. The first hospital to actually put Damo Radar into a clinic will tell us far more than the AUC did. An open-weights release is only the starting line.
Tomorrow's signal lands here.