October 2 through the morning of October 3, 2026, Eastern time. Microsoft’s October 1 security report is a dated late discovery.
Security has to keep pace with agents
Microsoft’s October 1 Digital Defense Report says AI is compressing parts of the attack chain from days to seconds, while helping defenders correlate signals and investigate continuously. It reports nearly 40,000 CVEs in the first half of 2026, putting the year on pace to roughly double. That is Microsoft’s synthesis, not a forecast guarantee.
The useful lesson: security must precede action. For experiments, separate credentials, minimize permissions, log tool use and test a containment path. Use synthetic data and disposable accounts rather than handing a prototype your ordinary work credentials.
A model change can break a repeatable test
GitHub deprecated Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code and Claude Opus 4.7 across Copilot features on October 2. Suggested replacements are Gemini 3.8 Flash, Kimi K3 and Claude Opus 5.5. Enterprise administrators may need to enable them in model policies.
Your interface can look unchanged while its underlying model disappears. Record the model, date, reasoning setting, tools and repository state alongside a small expected-output test. Rerun that test before accepting a replacement in a workflow that matters.
Megawatts are capacity, not results
Applied Digital said three additional 25 MW halls at Polaris Forge 1 reached “Ready for Service” October 2. Company-reported operational critical IT load is now 250 MW; the fully leased campus is contracted for 400 MW at full buildout.
Ready for Service does not prove that every megawatt is already running training jobs. Separate electrical capacity, installed chips, utilization and useful work delivered. Power capacity alone does not reveal model quality, energy per task, water use or local grid effects.

Useful AI gives people a better place to look
Google’s MTA case study describes Pixel phones gathering vibration, sound and location signals from subway cars. TrackInspect reportedly identified 92% of defect locations found by human inspectors, who physically confirm flagged sites. This is a vendor-reported pilot, not an independent audit.
The Houston Chronicle reports UT health institutions have 571 documented AI use cases and another 150 applications in production. One medical-student exam-grading tool assists faculty, who still decide pass or fail. UT’s $25 million oversight initiative aims to inventory tools and share safety signals; vendor access and retention remain concerns.
Google: TrackInspect · Houston Chronicle: UT oversight
Promises, inquiries and rules are different
Reuters reports the White House’s six-company frontier-safety accord has no stated consequence for noncompliance. It is voluntary, not a statute. A separate FTC industry inquiry and California subpoena to OpenAI seek information; neither establishes wrongdoing.
At an October 1 briefing, the European Commission said it expects enforcement from December 2 of the AI Act prohibition covering apps generating nonconsensual sexual imagery. That is a readiness statement, not a completed enforcement result. Its separate AI-and-copyright consultation closes November 3; consultation is evidence gathering, not a new copyright rule.
Reuters: accord · Reuters: inquiries · EU: briefing · EU: copyright
Three things to try with AI
Original proposals, not news or authorization to run tools or spend money. Time estimates are approximate; use existing access where possible.
Archive Scene Rebuilder
Choose a public-domain historical photograph. Ask AI to identify visible clues, build a dated evidence table from archives, maps and newspapers, and propose a modern re-photography angle. Allow 60–90 minutes. Mark uncertain identifications, avoid naming private people from weak clues and never present reconstruction as documentary fact.
Model Nutrition Label
Make a one-page label for today’s three Copilot replacements: access, price, benchmark owner, missing tests, safety evidence, deprecation risk and data handling. Highlight unknowns instead of guessing. About 40 minutes with vendor documentation and a document tool. Separate vendor claims from independent measurements; do not upload proprietary code.
Decision Rehearsal Deck
Pick a low-stakes choice and generate five cards: optimistic, ordinary, difficult, surprising and “do nothing.” Each gets an early warning sign and a reversible next move. About 30–45 minutes with chat and a document template. Omit sensitive health or financial details. Generated probabilities are not forecasts; high-stakes decisions need qualified advice.