> daily_signal(2026_09_23)

More than 1,050 people died within range of the AI towers on the US border, and this week Meta's agent got hijacked, two states made AI hiring answer to you, and a cancer AI beat the standard test.

PickBits Daily Signal · Wednesday, September 23, 2026

By Mark Pickering · 9 min read · September 23, 2026

// tl;dr

The border story is the one that stuck with me. We wrote about that "virtual wall" of camera towers back in July, when it was still just an expansion plan, more towers, more money. This week a long investigation went and counted the bodies: more than a thousand people have died within range of these cameras, and the agency running them stopped checking whether they even work. The same week, the Muse agent we covered at launch got locked out by Amazon, hijacked in a researcher's demo, and flagged by banks as a fraud risk.

Two of the four went the other way this week, and honestly they're why I still like doing this. Colorado and Connecticut passed the first laws that make a hiring algorithm tell you it turned you down and explain why, though I'd bet the enforcement fight is only starting. And a lab in Chicago built the kind of AI that's easy to root for, reading scans and blood and genes to call who a brutal cancer treatment will actually help. Mostly I want to know who answers when the AI gets it wrong. This week, for once, the answer wasn't "nobody."

A border-camera system set to cost six billion dollars, more than a thousand deaths in its range, and no one at CBP counting.

1. More than 1,050 people died within range of the AI towers on the US border.

A new investigation cross-referenced migrant deaths against the surveillance towers, and CBP runs no review when a body turns up beside one.

The US has built a "virtual wall" of AI camera towers along its southern border, 803 of them so far, from Anduril, Elbit Systems, and General Dynamics, a system CBP estimates will cost $6.2 billion over its lifespan and sold as a way to spot people crossing so agents can reach them in time. Then a MIT Technology Review investigation published September 21, 2026 went and checked. Reporters cross-referenced nearly 4,000 recorded migrant-death locations against roughly 600 of the towers and found that more than 1,050 people died within tower surveillance range between 2015 and early 2026, including over 110 near Anduril's newer autonomous "Sentry" systems. One man was found by landfill workers 360 feet from the nearest tower. A two-year-old drowned in clear view of three cameras.

The people who sell these towers pitch them on safety, and Anduril founder Palmer Luckey describes the platform as an AI "sensor fusion" system that tags every person and vehicle across huge areas so responders know what they are walking into. The agents who use it say otherwise. The computer vision misses an estimated 10 to 15 percent of crossings, they told the reporters, with tarped groups and small rafts registering only as an "unidentified object" with no alert. CBP holds no comprehensive measure of whether the towers work, opens no formal investigation when a body is found near one, and dissolved its oversight office in October 2025. This is the same expansion we flagged in July, when the government watchdog warned CBP wanted to nearly triple the count; the plan is still roughly $1 billion for 1,497 more towers by 2034, on top of the 803 already up.

Screenshot of MIT Technology Review's investigation into deaths within range of the US border's AI surveillance towers.
technologyreview.com · September 21, 2026

Why this matters: You're paying for an AI border system its own operators can't prove works, and people are dying next to the cameras with nobody looking into it. This is your money, sold to you as a way to save lives, and nobody at CBP actually checks whether it finds anyone or looks into the deaths that pile up next to the towers. And once the agency stops counting the deaths and shuts the office that would ask why, calling any of it "safety" is a stretch.

Action this week: Track the appropriations for the roughly $1 billion, 1,497-tower expansion, because the towers are a federal procurement and that money is public, so go after it. Push for a public, independent audit of whether it works, and for someone to actually look into why people keep dying next to the towers, before another dollar clears; CBP does neither today. We covered the expansion plan in July as a numbers story. After this, my read is that the deaths change the question entirely, from "how many more towers" to "does the first 803 even work," and that is the question to put to any member of Congress who votes on the money.

technologyreview.com: The US built a virtual wall of surveillance towers. A new investigation counted the deaths within their range. (September 21, 2026)
technologyreview.com: Dying on camera, the full feature investigation (September 21, 2026)
technologyreview.com: The Download, investigating deaths at the US border's virtual wall (September 21, 2026)

2. The AI agent Meta gave your inbox and wallet can be silently hijacked.

In one week Amazon blocked Muse as an unauthorized bot, a researcher showed how to steal the token that lets it act as you, and Meta shipped an overnight patch.

Two weeks ago the story was Meta launching Muse, a personal AI agent that shops, pays, and negotiates for you and can reach your email, messages, and health apps; it became the most-downloaded free app in the US App Store within a week of its September 8 launch. This week the backlash arrived all at once. On September 21, Amazon blocked Muse from its site, telling users that access by an unauthorized AI agent violates its terms of service and citing that Muse did not identify itself as AI and appeared to collect customer data. The same day, security researcher Patrick Wardle disclosed a macOS flaw (a proof of concept he called "not-a-mused"): an unprivileged program already on your Mac could alter an undocumented setting to redirect the agent's traffic, inject prompts Muse trusts and executes, and steal the authentication token that lets it act as you, reaching everything you granted it, including the linked iOS app.

Meta hot-fixed the flaw by September 22 and says Muse holds no passwords or payment details, and banks have started warning that AI shopping bots raise scam and fraud risks. And once someone else grabs the wheel, that access is the problem. Let an agent read and write everything you gave it, and the moment it is jailbroken or prompt-injected, an attacker can do the same, to your inbox, your messages, your health apps, and your money. That is Muse's whole design. Nobody ever required it to tell a store it was a robot, and nobody fenced what it can touch, so Amazon ended up drawing the line the rulebook still hasn't. This is the same agentic-commerce push we covered at launch, and this week Amazon and a lone researcher stepped in where there still isn't a rule.

Screenshot of The Decoder's report on Amazon blocking Meta's Muse AI shopping agent.
the-decoder.com · September 22, 2026

Why this matters: The AI agent you let read your email and pay your bills spent this week getting blocked, hijacked in a proof of concept, and flagged as a fraud risk. Whatever you let Muse touch, an attacker who hijacks it touches too, and that means your inbox, your messages, your health apps, and your money. Right now the only thing between all of that and an attacker is a patch Meta shipped overnight, because no rule yet forces an autonomous agent to identify itself or limits what it can hold.

Action this week: Update Muse now, then open its permissions and revoke everything it does not need, because it has no reason to hold your health data to buy socks. If you manage devices, treat these agents like any other privileged software on a work Mac: inventory which ones are installed and gate them the way Amazon just did. When I have pressed vendors on "what can this agent actually reach," the answer is always "everything the user approved." A hijack just means an attacker approved it instead, so watch the emerging bank guidance on who eats the loss when an agent gets robbed.

the-decoder.com: Amazon blocks Meta's AI agent Muse from online shopping (September 21, 2026)
malwarebytes.com: Meta's Muse AI assistant has a zero-day that can turn it into a Mac backdoor (September 2026)
theverge.com: Amazon blocks Meta's Muse AI agent from shopping (September 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it's worth something to you, the best way to support it's to forward it to someone who would read it. Subscribe today!

3. Colorado and Connecticut now legally require employers to disclose the AI screening your job application.

The laws also force a real explanation after a rejection and, in Colorado, a right to request a human review; California may go further and ban emotion-reading AI at work.

For a couple of years the fights over AI in hiring were mostly proposals. This year two states turned them into law. Colorado (SB 189) and Connecticut (SB 5) have enacted employment laws that require an employer using an automated decision-making tool to notify applicants and employees that it is in use, give a detailed explanation after an adverse outcome such as a rejection, let people correct inaccurate data, and, in Colorado, ask a real person to review the decision. It points straight at a machine most workers never knew was in the room: the resume-screener that never told you it read your resume, or the system quietly clocking how fast you work. By some estimates more than half of US employers already use AI somewhere in hiring. California's legislature also sent Governor Newsom AB 1883, which would bar employers from using workplace tools that read neural data or a worker's emotions. Across the country, states weighed 155 workplace-AI bills this session.

Enforcement is where it gets shaky. When New York City tried an earlier version, requiring firms to prove their hiring AI was not biased, the audits did not crack open the code; they just tested outcomes, and some law firms told clients they did not have to publish results or even comply, leaving it to a judge to decide. My own read is that disclosure with a weak enforcement arm still beats a black box nobody could see into, because a notice and a written explanation create a paper trail a rejected applicant can actually fight over, where before there was nothing. It won't fix hiring, but a rejected applicant finally has something on paper to push back with.

Screenshot of MultiState's rundown of new state AI-employment laws in Colorado and Connecticut.
multistate.us · September 21, 2026

Why this matters: If your company screens or manages people with AI, two states now legally require you to disclose it, explain a rejection, and offer a human review, and your vendor may not have built any of that. For years the answer to a silent rejection was just "the software decided." Two states finally said that's not good enough, and put the work of proving it on the employer instead of the applicant. If you're the one applying, you now have the right to be told an algorithm screened you, and to ask a person to look again.

Action this week: Get one answer from your vendor in writing before your next req goes live: can it produce the applicant notice and the adverse-action explanation these laws require, and who signs off on the human review. Make a list of every hiring and monitoring tool you run, because Colorado and Connecticut already require the paperwork and more states are following. And if you are the one applying and an automated screen rejects you in either state, ask for the explanation and the review in writing. If nobody uses the right, employers will assume they can skip it.

multistate.us: State AI employment laws address monitoring, hiring, and bias concerns (September 21, 2026)

4. An AI that reads scans, blood and genes beat the standard test on who lung-cancer immunotherapy helps.

Across nearly 2,400 patients in six countries the University of Chicago-led model reached an AUC of 0.88, and the doctors who used it got more accurate too.

Immunotherapy transformed advanced lung cancer, but it works for only some patients, and the standard tool for guessing who, a marker called PD-L1, is famously unreliable, so many people endure a punishing, expensive treatment that was never going to help while others who might benefit are passed over. A University of Chicago-led study published in Nature Medicine on September 14, 2026 (the I3LUNG project, senior author Dr. Marina Garassino) shows AI can sharpen that call by reading everything at once. The team trained multimodal models on 2,396 patients with advanced non-small-cell lung cancer treated with immunotherapy across six countries, fusing routine clinical and blood data with CT imaging, digital pathology, and genomics. A clinical-plus-blood model reached an AUC of 0.77, and the full multimodal model hit 0.88, consistently outperforming PD-L1 and other standard biomarkers.

The part I liked most is what happened when real physicians used the tool: their own predictions improved from an AUC of 0.72 to 0.87, and the reasoning grew more consistent across doctors of different experience levels. This is the kind of medical-AI story I actually like, where the win isn't a new gadget but a smarter read of tests a hospital already runs; we covered the breast-cancer "virtual cell" and the D-dimer brain-bleed model this month for the same reason. It's a decision-support model, not a cleared product, and it still needs prospective validation before it goes near a bedside. Done right, it flags at diagnosis who's likely to respond and spares everyone else a toxic course that was never going to work. It also hands a community oncologist the same read a specialist would get.

Screenshot of MedicalXpress's report on the I3LUNG multimodal AI immunotherapy-response study.
medicalxpress.com · September 2026

Why this matters: An AI that reads the scans, bloodwork, and genetics already in your file just beat the standard test at telling who actually benefits from lung-cancer immunotherapy. The everyday consequence is real: fewer people put through a brutal treatment that was never going to work, and a clearer call at diagnosis about who should get it. And because the inputs are data hospitals already collect, this is the kind of tool a community clinic could eventually use, not one locked to a handful of academic centers.

Action this week: Ask your oncology team how they decide whether immunotherapy is likely to help, since PD-L1 alone is imperfect, and whether multimodal tools that combine scans, labs, and genomics are being trialed near you. Watch for prospective, multi-site validation on diverse US populations, because that's the milestone that turns a strong result on one dataset into care a patient can actually get. My own read is that this is the rare medical-AI story that isn't overselling, so follow it and test it, but don't expect it at the bedside tomorrow.

medicalxpress.com: AI tool successfully predicts outcomes for lung-cancer immunotherapy (September 2026)
eurekalert.org: I3LUNG multimodal AI predicts immunotherapy benefit in non-small-cell lung cancer (September 2026)
nature.com: Multimodal machine learning for immunotherapy response prediction in NSCLC, Nature Medicine (September 14, 2026)

» What to watch this week

Tomorrow's signal lands here.