A teenager found out from an anonymous Instagram DM. Someone she did not know sent her a link to a Discord server. On it were sexually explicit images of herself and other girls she recognized from school. The photos had been generated using Grok, the AI model built by Elon Musk’s xAI. The source material was a yearbook photo.

On March 16, three Tennessee teenagers filed a class action lawsuit against xAI in U.S. District Court for the Northern District of California. The case, Doe 1 v. X.AI Corp. (No. 5:26-cv-02246), was filed by Lieff Cabraser, one of the largest class action firms in the country. Two of the three plaintiffs are minors. All three are anonymous. The allegations are not negligence. They are production, distribution, and possession with intent to distribute child pornography.

This is the first lawsuit filed by actual minor victims against an AI company over generated child sexual abuse material. Not a regulatory probe. Not an advocacy group’s report. Three real people whose images were turned into pornography by a product that was, according to the complaint, designed to do exactly that.

The Design Problem

The lawsuit does not argue that Grok accidentally produced harmful content. It argues that xAI built the capability on purpose.

Grok’s “Spicy Mode” was marketed as offering “extra creative freedom.” The system prompt was configured to assume “good intent” when users referenced terms like “teenage” or “girl.” Musk personally pushed back against internal safety guardrails. In August, he posted publicly that “spicy mode” had helped technologies like VHS succeed. The safety team was already small. It lost staff in the weeks before the abuse exploded.

On December 29, Musk announced a one-click image editing feature powered by Grok on X. Within 11 days, Grok generated an estimated 3 million sexualized images, including approximately 23,000 depicting children, according to a Center for Countering Digital Hate analysis. That is roughly 190 images per minute. The feature was restricted to paid users on January 9. Technical restrictions on “undressing” were not added until January 14.

But the damage extends beyond X. The lawsuit alleges xAI licensed Grok’s model to third-party app developers, many based outside the United States, who built dedicated “undressing” applications. If xAI is held liable for what downstream licensees do with its model, every company licensing a generative AI system will need to rethink its terms of service overnight.

The Contrast That Defines 2026

The same month this lawsuit was filed, the U.S. government finalized its ban on Anthropic across all federal agencies. The reason: Anthropic refused to remove safety guardrails from Claude for military applications. Defense Secretary Pete Hegseth designated the company a supply chain risk to national security. Contractors doing business with the Pentagon were told to sever ties.

One company got punished by the government for having too many safety restrictions. Another is getting sued by teenagers for having too few. That is not a contradiction. That is the actual state of AI governance in the United States in March 2026.

The EU is at least attempting to close the gap. An investigation into Grok under the Digital Services Act has been open since January. On March 11, EU lawmakers struck a deal to explicitly ban AI-generated non-consensual intimate images, including CSAM. France has opened a separate probe. The U.S. has no federal equivalent. These teenagers had to file a private class action because no federal statute directly addresses AI-generated CSAM at this scale.


The counterpoint writes itself. xAI did restrict the feature. The guardrails came, eventually, 11 days and 3 million images later. And the Anthropic comparison is not perfectly parallel. The federal ban was about military procurement, not consumer safety. The xAI lawsuit is about product liability, not national security. Different legal frameworks. Different policy levers. But the optics tell a story that no amount of legal nuance can override: the U.S. government moved faster to punish a company for refusing to remove safety features than the market moved to punish a company for never installing them.

The U.S. government moved faster to punish a company for refusing to remove safety features than the market moved to punish a company for never installing them. The EU passed legislation explicitly banning AI-generated non-consensual intimate images. The U.S. has nothing equivalent. Three teenagers in Tennessee had to retain a class action firm because no federal statute exists to protect them at this scale. That should be bizarre to anyone paying attention. The regulatory vacuum is not an accident. It is a choice. And the people making that choice have decided that military AI procurement disputes are more urgent than protecting minors from a product that was designed, marketed, and licensed to do exactly what it did.

What This Means for Everyday People

If you have a teenager with a social media account, their photos are training data. Not in the abstract, theoretical sense that privacy advocates warn about. In the literal sense that a yearbook photo can be fed into an AI tool and returned as pornography within seconds. The tools exist. They are accessible. And until this lawsuit, no actual victim had tested whether U.S. courts would hold the companies that built them accountable.

The outcome of Doe 1 v. X.AI Corp. will set the precedent. If the court agrees that xAI’s design choices constitute intent rather than negligence, the liability framework for every generative AI company changes. If it does not, the message to the industry is clear: build first, restrict later, and let the victims find their own lawyers.

For inquiries and analysis contact laterstack@proton.me

Workers at an outsourcing firm in Nairobi, Kenya are watching people naked, on the toilet, and having sex. They are also seeing credit card numbers and other financial information flash across their screens. All of it captured by Meta’s Ray-Ban smart glasses, sent to these workers to label and annotate so Meta’s AI models can learn to see.

This was first reported by Swedish newspaper Svenska Dagbladet on February 27, 2026, and has since been confirmed by multiple outlets including Engadget and Android Headlines. The workers told journalists exactly what they are seeing. There is no ambiguity here.

Meta’s defense is that users agreed to it. Somewhere in the terms of service, buried under thousands of words of legalese, is a clause that permits human review of any data captured by the glasses. Every person who put on a pair of Ray-Ban Metas technically consented to having their most private moments sent to a room full of strangers in East Africa.

This is privacy violation dressed up as a checkbox.

The Business Model Is the Problem

Meta did not stumble into this. The company’s AI models require massive amounts of visual data to train, and human annotators are the cheapest way to label that data. Outsourcing to Kenya, where workers earn a fraction of what American or European moderators would cost, is the same playbook Meta has used for years. Time magazine reported in 2023 that Kenyan workers were paid less than $2 per hour to label traumatic content for OpenAI. The pattern is identical. The only difference is that this time the content is coming from cameras strapped to people’s faces.

Meta spent $83 billion on the metaverse before killing its VR studios and pivoting hard to smart glasses. This is the product line they are betting the company’s future on. And the data pipeline feeding its AI depends on routing intimate footage of its own customers to underpaid workers overseas.

That is not a bug in the system. That is the system working exactly as designed. Extremely invasive and a complete violation of privacy, all in service of profit. Pure greed wrapped in a terms of service agreement.

What GDPR Lawyers Are Already Saying

Data protection lawyers cited in the original Svenska Dagbladet report flagged that this practice likely violates GDPR requirements around transparency and informed consent. Under European law, users must be clearly informed about how their personal data is processed. A blanket clause in a terms of service document does not meet that standard, especially when the data includes nudity and financial information being processed by third-party contractors on a different continent.

The question is whether European regulators will act. The EU has already opened investigations into Grok for generating images of minors. Meta’s smart glasses pipeline is a more straightforward GDPR case. The data is intimate. The processing is overseas. The consent mechanism is inadequate. Every element of a violation is present.

The Uncomfortable Reality

Nobody reads terms of service. Everybody knows this. Companies know this. Regulators know this. The legal fiction that clicking “I agree” constitutes informed consent for having your naked body reviewed by a stranger in Nairobi is exactly the kind of framework that exists to protect corporations, not people.

Meta could train its visual AI models differently. It could use synthetic data. It could limit human review to non-sensitive content. It could pay moderators properly and locate them in jurisdictions with strong privacy protections. It does none of these things because all of them cost more money.

The choice Meta made is simple: your privacy is worth less than the cost of doing this the right way. Every company building AI-powered hardware that captures visual data will face this same decision. Meta just showed everyone which way the industry is leaning.

What You Should Do

If you own Meta Ray-Ban smart glasses, understand that anything captured by the camera or microphone can be sent to human reviewers. There is no opt-out for human annotation that preserves full AI functionality. You either accept the terms or you stop using the AI features.

If you are near someone wearing Meta smart glasses, you have no say in the matter at all.

Nvidia just told Wall Street to expect $78 billion in revenue next quarter. That number beat analyst estimates by more than $5 billion. The stock went up after hours. Nobody was surprised. That’s the part worth paying attention to.

The Q4 fiscal 2026 numbers were absurd by any historical standard. Revenue of $68.1 billion, up 73% year over year. Data center revenue alone was $62.3 billion, up 75%. Earnings per share of $1.62, an 82% jump. Nvidia beat its own guidance by roughly $3 billion. The full-year trajectory tells the story even better: $44.1 billion in Q1, $46.7 billion in Q2, $57 billion in Q3, $68.1 billion in Q4. Not just growing. Accelerating.

These results landed against a backdrop of record AI infrastructure spending from every major hyperscaler. Microsoft, Meta, Google, Amazon. Combined Big Tech AI capex is projected to exceed $650 billion in 2026. That money has to go somewhere. Right now, the overwhelming majority of it goes to one place: Nvidia GPUs.

One Company, One Chip Line, One CEO

This is the concentration problem nobody wants to talk about in an earnings celebration. The entire AI buildout, the training runs, the data center expansions, the models that every tech company is betting their future on, runs through a single supplier. One company. One product line (H100, H200, now Blackwell). One CEO in a leather jacket.

If Nvidia has a supply disruption, the AI buildout stalls. If something happens at TSMC, which fabricates Nvidia’s chips in Taiwan, the AI buildout stalls. If a geopolitical incident disrupts the Taiwan Strait, as previous reporting on this site has explored, the AI buildout doesn’t just stall. It stops.

The $78 billion guidance isn’t just a revenue number. It’s a measurement of leverage. It quantifies how much one company controls the pace at which every other company can build AI. Microsoft can commit $145 billion in capex. Meta can pledge $135 billion. None of it matters if Nvidia can’t deliver the silicon.

There’s a second layer to this that gets less attention. Nvidia’s revenue is everyone else’s cost basis. Every dollar in that $68.1 billion figure is a dollar that some AI company spent on infrastructure before proving the business model works at consumer scale. Microsoft’s stock dropped after earnings partly because investors questioned whether AI spending would generate returns fast enough. The buyers are carrying the risk. The seller is printing money.

The Case That Dominance Is Exactly What’s Needed

There is a credible counter-argument. Nvidia’s position wasn’t handed to them. They invested in CUDA, their software ecosystem for GPU computing, for over a decade before AI made it the industry standard. AMD and Intel have been “catching up” for years. They haven’t. Custom chips from Google (TPUs) and Amazon (Trainium) serve internal workloads but haven’t dented Nvidia’s market share in any meaningful way.

The TSMC concentration risk is real but mitigated by multiple fab locations across Taiwan, Japan, and Arizona. Nvidia’s own advanced packaging capabilities add another layer of supply chain resilience. And the “single point of failure” argument has been made every quarter for two years. Every quarter, Nvidia beats harder.

Maybe concentration in the hands of the best-positioned company is exactly what hypergrowth requires. Distributed supply chains are built for mature markets where competition drives prices down and efficiency up. An industry that’s doubling every 18 months might need a single dominant supplier that can allocate capacity, set the technical roadmap, and keep the entire ecosystem moving in the same direction.

History has a clear track record on single-supplier dependency at this scale, and it has never ended well. Standard Oil controlled American energy until antitrust broke it apart. AT&T controlled communications until the monopoly strangled innovation for decades. Intel owned computing and missed mobile, AI, and every major platform shift of the last fifteen years. Every time an entire industry’s future ran through one company, the correction came through crisis, through regulation, or through both. I cannot find a single example where this kind of concentration produced a positive long-term outcome. The question is not whether Nvidia’s dominance produces a reckoning. It’s whether the AI industry builds alternatives before that reckoning arrives.

What This Means for Everyday People

If you use ChatGPT, Gemini, Claude, or any AI product, the price you pay and the quality you receive is gated by Nvidia’s production capacity. When supply is tight, AI companies pass those costs forward. Startups that can’t afford Nvidia’s latest hardware get stuck on older, slower chips or wait months for allocation. That shapes which AI companies survive and which ones die, which has nothing to do with who built the better product.

For consumers, the near-term effect is probably positive. Nvidia’s accelerating shipments mean more compute in the system, which means faster models and cheaper inference costs over time. But the structural dependency remains. One company’s manufacturing schedule, one company’s pricing decisions, and one country’s geopolitical stability determine how quickly AI gets better and cheaper for everyone.

The $78 billion guidance says Nvidia’s dominance isn’t slowing down. Whether that’s a feature or a vulnerability depends entirely on what happens next. And that’s a question no earnings report can answer.

For inquiries and analysis contact laterstack@proton.me

Between December 2025 and January 2026, someone used Anthropic’s Claude to systematically rip through Mexico’s government infrastructure. 150 gigabytes of data. 195 million taxpayer records from Mexico’s federal tax authority. Voter rolls from the national electoral institute. Government employee credentials from Jalisco, Michoacan, Tamaulipas. Civil registry data from Mexico City. Even Monterrey’s water utility. The jailbreak method was embarrassingly simple: Spanish-language prompts framed as a “bug bounty” program. Claude did what it was told.

That alone would be a major story. But it is not happening in isolation.

What We Know

According to Bloomberg, the attacker automated thousands of commands through Claude, directing the model to probe and extract data from Mexican federal and state systems over a period of weeks. Cybersecurity firm Gambit Security investigated the breach and suggested potential ties to a foreign government, though no specific attribution has been confirmed. Anthropic says it detected the abuse and shut down the account. This is the second time Claude has been linked to a government-targeted cyberattack in three months. In November 2025, a Chinese espionage campaign also exploited the model.

The method itself is worth paying attention to. The attacker did not need some sophisticated zero-day exploit or insider access to Anthropic’s systems. They used language. Spanish-language prompts wrapped in the framing of a legitimate security research program were enough to bypass Claude’s safety guardrails. That is not a minor vulnerability. That is a structural problem with how large language models process context and intent.

The Pentagon Connection

Now zoom out. While this hack was unfolding, the Pentagon has been locked in a public standoff with Anthropic over a $200 million defense contract. Defense Secretary Pete Hegseth gave CEO Dario Amodei until Friday to drop Claude’s remaining guardrails for “all lawful military use” or face the Defense Production Act and potential blacklisting from government contracts. Anthropic is refusing to budge on two specific restrictions: AI-controlled autonomous weapons and mass domestic surveillance.

An Anthropic safety researcher, Mrinank Sharma, resigned over the situation, saying publicly that “the world is in peril.”

The timeline is hard to ignore. A sophisticated, automated attack uses Claude against the government infrastructure of a U.S. neighbor. Anthropic claims to have caught it. And the Pentagon is simultaneously threatening to strip the same company of its safety restrictions because those restrictions are inconvenient for military operations.

This fits a pattern we have tracked before. When a Google whistleblower revealed Gemini was being used in Israeli drone surveillance, it showed what happens when AI companies lose control of how their tools get used in government operations. The difference here is that Anthropic is being asked to voluntarily surrender that control while evidence of exactly why it matters is playing out in real time.

The Simpler Explanation

There is a credible counter-argument, and it deserves honest consideration. The hacker has not been identified. Gambit Security “suggested” foreign government ties but offered no public evidence. No intelligence agency has attributed the attack. The simplest reading: a skilled criminal discovered that Spanish-language prompt engineering could bypass Claude’s safety filters and went after the easiest targets available. Mexican government systems are chronically underfunded and poorly secured. Not everything is a conspiracy. Sometimes a hacker is just a hacker.

Conflating this breach with the Pentagon dispute without direct evidence connecting them is speculation. That is worth acknowledging.

But Here Is What I Cannot Shake

Anthropic essentially blew the whistle. The company told the government it would not remove safety restrictions, and then got threatened for it. Now a “hacker” uses the exact tool Anthropic was trying to protect against an allied nation’s government infrastructure. The timing is suspicious. The method, a simple jailbreak that any moderately funded operation could replicate, looks less like criminal opportunism and more like a proof of concept. This might not be a random hacker who got lucky with Spanish prompts. This might be exactly the kind of thing Anthropic was warning about when it told the Pentagon no.

I am not stating that as fact. But the question needs to be asked out loud, because nobody else is asking it.

What This Means for Everyday People

195 million taxpayer records is not an abstract number. That is the financial identity of most of Mexico’s adult population, exposed because an AI model could be tricked with the right phrasing in the right language. If this can happen to Mexico’s tax authority, it can happen to the IRS. It can happen to your state’s DMV, your health insurance provider, your voter registration.

The Pentagon’s demand makes this worse, not better. Removing safety guardrails from the same AI that just got weaponized against a neighbor’s government is not a security strategy. It is handing loaded weapons to everyone in the room and hoping the good guys shoot first.

Looking Forward

Anthropic’s Friday deadline with the Pentagon will come and go. But the Mexico breach has already demonstrated what unconstrained Claude looks like in practice. The question is no longer theoretical. It happened. The only variable left is whether the people demanding unrestricted access to this technology are paying attention to what unrestricted access actually produces.

The agency responsible for defending American critical infrastructure from cyberattacks is operating at roughly 38 percent of its workforce. A partial government shutdown that started February 14 furloughed the majority of the staff that was left. Before the shutdown even began, CISA had already lost a third of its people to cuts and layoffs under the Trump administration.

There is no permanent director. The proposed 2026 budget slashes $495 million from the agency. And the programs being eliminated aren’t obscure bureaucratic line items. They’re the specific capabilities the US built to fight ransomware, protect elections, and coordinate defense of power grids, water systems, and hospitals.

Where the Cuts Land

The numbers tell a story the administration’s talking points don’t.

The Cybersecurity Division loses $216 million, an 18 percent cut. That’s the division that runs threat detection, incident response, and vulnerability coordination across federal networks and critical infrastructure. The counter-ransomware initiative, the program specifically designed to combat the fastest-growing cyber threat to American businesses and hospitals, is eliminated entirely.

The National Risk Management Center gets cut 73 percent, a $97.4 million reduction. This was the office that worked with private sector operators of critical infrastructure to identify and manage systemic risks. Power companies, water utilities, telecom providers. The partnerships that made coordinated cyber defense possible.

Election security is zeroed out. All 14 positions eliminated. The full $36.7 million budget, gone. The Stakeholder Engagement Division, CISA’s main interface with state and local governments and private industry, loses 62 percent of its budget ($62.2 million).

The “Censorship” Framing

The administration frames these cuts as removing “censorship infrastructure.” That framing deserves scrutiny, and it also deserves some context.

CISA did get involved in flagging online content to social media platforms during the 2020 election cycle. Congressional investigations documented this, and legitimate concerns were raised about government agencies influencing speech. That’s a real debate worth having.

But counter-ransomware coordination has nothing to do with content moderation. Working with water utilities to patch vulnerable SCADA systems has nothing to do with speech. Helping hospitals defend against the ransomware gangs that locked up patient records across dozens of facilities last year has nothing to do with censorship.

The programs being killed served operational cybersecurity functions. If the goal was to remove content moderation activity, targeted reforms could have done that while preserving the cyber defense apparatus. Instead, the entire agency’s operational capacity got hollowed out. The censorship argument is being used to justify capability destruction that goes far beyond any content moderation concern.

The Threat Environment Right Now

This is happening while nation-state cyber operations are accelerating. Chinese hacking groups have been caught pre-positioning inside US critical infrastructure networks. Russian intelligence has tripled resources targeting Western critical infrastructure. Ransomware attacks hit record levels in 2025.

CISA was the coordination point. When a water utility in a mid-size city got hit, CISA was who they called. When a hospital system locked up, CISA provided the technical response team. When intelligence agencies detected a Chinese intrusion in telecom networks, CISA coordinated the cross-sector response.

This is also happening weeks after the Cybersecurity Information Sharing Act expired during the same government shutdown. That law gave companies legal liability protections for sharing threat intelligence with federal agencies. Without it, and without the CISA staff who managed those relationships, the information-sharing pipeline between private industry and government defense is breaking down from both ends.

I keep coming back to the same word: self-sabotage. I genuinely cannot construct a rational explanation for gutting your own cyber defense agency while nation-state hackers are inside your infrastructure. Either this administration is clearing out the people who might blow the whistle on something, or they are deliberately leaving the country unprotected. I don’t know which one it is. Both explanations are worse than the other.

What This Means for Regular People

Hospitals, school districts, water treatment plants, and local governments are the most frequent ransomware targets in the US. They also have the thinnest cybersecurity budgets. CISA was the backstop. The agency provided free vulnerability scanning, incident response support, and security assessments to organizations that couldn’t afford to hire their own security teams.

That backstop is now running at 38 percent capacity with no permanent leadership and a budget proposal that eliminates its most critical programs. The question nobody in Washington is answering: who fills that vacuum? Private cybersecurity firms charge six figures for incident response. State governments don’t have the technical expertise. Small utilities and rural hospitals were never going to defend themselves against Russian military intelligence or Chinese state hackers on their own.

The programs being cut were built because that gap existed. Eliminating them doesn’t make the gap go away. It just means nobody’s standing in it anymore.

ESET researchers published their analysis of PromptSpy this week, the first known Android malware to use a generative AI model during execution. The malware calls Google’s Gemini API at runtime, sending it an XML dump of the infected device’s screen, including UI elements, text labels, class types, and screen coordinates. Gemini responds with step-by-step instructions for how to pin the malicious app in the recent apps list, navigate settings menus, and maintain persistence across different Android versions and device manufacturers.

Read that again. The malware doesn’t contain hardcoded navigation paths for every possible Android configuration. It asks an AI to figure it out on the fly. That’s a meaningful technical shift.

How It Works

PromptSpy started life as VNCSpy, a more conventional remote access trojan that appeared on VirusTotal on January 13 from Hong Kong. By February 10, four more advanced samples appeared from Argentina. The upgrade between versions was the Gemini integration.

The core functionality is spyware. Once installed (it masquerades as “MorganArg,” a fake Morgan Chase banking app distributed through a dedicated website, never through Google Play), it requests Accessibility Services permissions. With those permissions granted, it deploys a VNC module that gives the operators full remote access to the device. It can capture lockscreen data, block uninstallation attempts by throwing invisible overlays over the settings screen, gather device information, take screenshots, and record video of everything happening on screen. Command and control communications are encrypted with AES.

The Gemini component handles the persistence problem. Android fragmentation means that the path to pin an app in the recent apps list, or to navigate to the settings screen to block uninstallation, is different on a Samsung running Android 14 versus a Pixel running Android 15 versus a Xiaomi running MIUI. Traditionally, malware authors had to hardcode paths for each device configuration or limit their targeting to specific manufacturers. PromptSpy outsources that problem to Gemini. Feed it the screen layout, get back the tap coordinates. Works on any device that Gemini has seen training data for, which is effectively all of them.

The Bigger Pattern

PromptSpy is technically a proof of concept. ESET hasn’t detected it in active telemetry yet, and its distribution is limited. But the technique it demonstrates is immediately replicable by any malware author with a Gemini API key. And getting a Gemini API key is trivial. Google gives them away.

This connects to a pattern that’s been building for months. In January, security researcher Michael Bargury published work showing that Microsoft’s Copilot could be exploited to bypass Data Loss Prevention controls, extracting sensitive data from organizations that assumed their DLP policies covered AI tool interactions. They didn’t. Microsoft had shipped Copilot as a productivity tool without engineering the security boundaries that organizations depend on to prevent data exfiltration.

The common thread isn’t any specific vulnerability. It’s the order of operations. AI capabilities ship first. Security engineering happens later, if it happens at all. Google made Gemini’s API accessible because accessibility drives adoption. Microsoft integrated Copilot into the enterprise stack because integration drives revenue. In both cases, the security implications were secondary to the business objective of getting the tool into as many hands and systems as possible.

PromptSpy is what happens when the “accessible to everyone” part includes malware developers. Bargury’s Copilot research is what happens when the “integrated everywhere” part includes data you’re legally required to protect. Neither represents a failure of security engineering. Both represent the absence of it at the point where it mattered most.

What Comes Next

The obvious next step is malware that doesn’t just use AI for navigation but for decision-making. A trojan that evaluates what’s on screen to decide whether to exfiltrate banking credentials or cryptocurrency wallet phrases. A phishing kit that uses an LLM to generate personalized social engineering in real time based on the victim’s recent messages. A worm that uses AI to identify which lateral movement path through a network is least likely to trigger detection.

All of these are technically feasible today. PromptSpy proved the integration pattern works. The cost is a Gemini API call, maybe a fraction of a cent per inference. The barrier to entry just dropped from “skilled malware developer” to “anyone who can write a prompt.”

Google’s response will probably involve restricting API access for certain use cases, the same way they restrict advertising APIs. But content-based restrictions on API usage are reactive by nature. You can’t distinguish between a legitimate developer building an accessibility app that reads screen layouts and a malware developer building a trojan that does the same thing. The API call is identical. The intent is invisible.

The security industry has spent two years talking about AI-powered defense. PromptSpy is the other side of that equation arriving exactly on schedule. Every capability that makes AI tools useful for productivity makes them equally useful for exploitation. The only variable is who builds the integration first.

IBM shares fell 13% today in the company’s worst single-day drop since October 2000. February has now wiped 27% off IBM’s stock price, putting the month on track for its steepest decline since at least 1968. The trigger: Anthropic announced that Claude Code can map dependencies across COBOL codebases, document workflows, and identify modernization risks “that would take human analysts months to surface.” With AI, Anthropic claimed, teams can modernize COBOL in quarters instead of years.

Wall Street heard this and panicked. IBM’s consulting and infrastructure divisions generate billions from organizations that still run COBOL. If AI can do COBOL modernization faster and cheaper, the logic goes, IBM’s cash cow is heading for slaughter.

The logic is wrong. Or at least, it’s about five years early and missing the parts that actually matter.

What COBOL Actually Is

COBOL runs the back end of civilization. An estimated 95% of ATM transactions, 80% of in-person transactions, and roughly $3 trillion in daily commerce flow through COBOL systems. The IRS runs on COBOL. Social Security runs on COBOL. Most major banks run their core transaction processing on COBOL. These aren’t legacy systems in the sense that they’re outdated. They’re legacy systems in the sense that they’ve been running, continuously, for 40 to 60 years, and nobody has found something more reliable to replace them with.

The average age of a COBOL programmer is somewhere north of 55. The language was designed in 1959. Universities stopped teaching it decades ago. The talent pool is shrinking every year to retirement and mortality. This is the real COBOL crisis, and it’s been a crisis in slow motion for 20 years.

What Anthropic announced is that Claude can help with the reading comprehension part of COBOL modernization. And that part is genuinely valuable. A COBOL codebase at a major bank might contain 100 million lines of code written by thousands of developers over decades, with documentation that’s either incomplete, wrong, or nonexistent. Understanding what the code does before you change it is the first bottleneck in any modernization project. AI can accelerate that step considerably.

What AI Cannot Do

Understanding the code is maybe 20% of a COBOL modernization project. The other 80% is everything else. Testing the replacement against the original in a production-critical environment. Migrating data formats that haven’t changed since the Johnson administration. Handling edge cases that only surface during year-end batch processing or leap year calculations or regulatory changes that were hardcoded in 1987. Coordinating across departments that have never spoken to each other because the COBOL system was the one thing that connected them.

The Commonwealth Bank of Australia spent $750 million and five years modernizing its core banking system off COBOL. JPMorgan has been working on its mainframe modernization for over a decade and is still not done. The UK government’s Universal Credit system was supposed to replace COBOL-based benefits processing; it went billions over budget and years past deadline.

These projects fail or balloon not because the code is hard to read. They fail because replacing a system that processes millions of transactions per day with zero downtime tolerance is an operational problem, not a programming problem. AI can’t write your rollback plan. AI can’t manage the political dynamics between your CTO who wants to modernize and your CFO who doesn’t want to spend $200 million. AI can’t test whether your new system handles the same rounding errors the old system did, intentionally, because three downstream systems depend on those specific rounding errors.

IBM Already Sells This

Here’s the part the market somehow missed: IBM already has an AI COBOL modernization tool. It’s called Watson Code Assistant for Z. It refactors COBOL into Java. IBM has been selling it to mainframe clients since 2024. IBM’s total AI book of business exceeded $12.5 billion as of Q4 2025, with over $10.5 billion in consulting alone. IBM Z revenue grew 67% year over year last quarter.

IBM isn’t losing to the AI modernization trend. IBM is one of the companies selling the AI modernization trend. The stock market reacted as if Anthropic invented COBOL modernization today. IBM has been billing for it for two years.

What the Market Got Right and Wrong

The market is right that AI will eventually compress the timeline and cost of COBOL modernization. The $13.34 billion mainframe modernization market that was supposed to grow steadily through 2030 will probably get disrupted. IBM’s margins on multi-year consulting engagements will face pressure as AI tools reduce the labor hours required.

The market is wrong about the timeline and the magnitude. COBOL modernization is not a technical problem that AI solves. It’s a risk management problem that organizations avoid until they can’t. The technology to modernize has existed for years. What’s missing is institutional willingness to accept the risk of replacing a system that works, imperfectly but reliably, with a system that might work better but might also crash during month-end processing and cost someone their job.

AI changes the cost equation at the margins. It doesn’t change the risk equation at the center. A 13% stock drop prices in a revolution. What’s actually happening is a slow, cautious evolution that IBM is better positioned to sell than almost anyone.

Anthropic published a report today accusing three Chinese AI labs of running an industrial-scale distillation operation against Claude. DeepSeek, Moonshot AI, and MiniMax allegedly created over 24,000 fake accounts and ran more than 16 million exchanges through Claude’s API to extract its most advanced capabilities. Agentic reasoning. Tool use. Coding. The specific things that make Claude worth paying for.

The findings are credible. Anthropic says it tracked DeepSeek running 150,000 exchanges targeting foundational logic and alignment, specifically probing how Claude handles censorship-sensitive queries. Moonshot AI was more aggressive, with 3.4 million exchanges aimed at agentic reasoning, tool use, coding, and computer vision. MiniMax fell somewhere in between. The scale was significant enough that Anthropic built behavioral fingerprinting tools to detect the patterns in API traffic and is now sharing technical indicators with other AI labs and cloud providers.

None of this is surprising. Distillation is how smaller labs have always bootstrapped their models. You take outputs from a frontier system, use them as training data, and your model learns to mimic the behavior without incurring the full cost of developing it independently. OpenAI sent a memo to House lawmakers earlier this month making similar accusations against DeepSeek. Google has been dealing with API abuse at scale since long before the current AI generation. This is a known technique with known countermeasures.

The Timing Tells the Story

What matters more than the distillation itself is when Anthropic chose to publish this. The report dropped the same week that Congress is actively debating AI chip export controls. Last month, the Trump administration formally allowed Nvidia to export H200 chips to China, loosening restrictions that had been tightening since 2022. Critics have been screaming about it. Anthropic’s report explicitly argues that distillation attacks “require access to advanced chips” and that these findings “reinforce the rationale for export controls.”

That’s not a security disclosure. That’s a policy position with a security disclosure stapled to the front.

Anthropic benefits directly from tighter export controls. If Chinese labs can’t get advanced chips, they can’t train competitive models, which means they stay dependent on API access to Western systems. If they stay dependent on API access, Anthropic and OpenAI collect the revenue. Restricting chips doesn’t stop distillation (you can distill with consumer hardware), but it slows down the development of independent Chinese AI capabilities. That’s good for Anthropic’s business whether or not it’s good for national security.

The House Homeland Security Committee has asked Dario Amodei to testify about the implications. That’s the real deliverable here. Not the technical report. The hearing invitation.

The Legal Gray Zone Nobody Wants to Address

Distillation is not theft. It’s not hacking. It’s not even clearly a terms-of-service violation in every jurisdiction. The technique involves sending legitimate API queries and using the legitimate outputs for training. Anthropic’s terms prohibit it. But terms of service are contractual agreements, not laws. Enforcing them against entities operating in China through fake accounts routed through intermediary jurisdictions is, practically speaking, impossible.

There’s a reason Anthropic didn’t announce lawsuits today. They announced a report. Lawsuits require legal standing in a jurisdiction where you can actually enforce a judgment. Reports require a PDF and good timing.

The harder question is whether distillation should be illegal. If you buy API access, you get outputs. If you use those outputs to train a model, you’ve created a derivative work. But derivative of what? The model weights? Those weren’t copied. The training data? That wasn’t accessed. The “style” of reasoning? Good luck defining that in a courtroom.

Copyright law doesn’t map cleanly onto AI model outputs. Patent law is even worse. The closest precedent is database protection law, and that varies so wildly across jurisdictions that it’s not precedent at all. Congress could write a law specifically prohibiting model distillation. Congress could also cure cancer. Neither appears imminent.

What This Actually Changes

Practically, very little. Anthropic will improve its detection systems. The Chinese labs will improve their evasion techniques. The arms race between API providers and distillation operations will continue at increasing sophistication on both sides, just like the arms race between ad platforms and click fraud, or streaming services and credential sharing, or any other system where the economics of cheating outpace the economics of enforcement.

Politically, quite a lot. Anthropic’s report gives export control hawks exactly the ammunition they need during exactly the debate they’re having. The narrative is clean: American AI companies build frontier capabilities, Chinese labs steal them, and the only solution is to restrict the chips that make it possible. That narrative is compelling whether or not it’s complete.

The part nobody is saying out loud: if distillation is this effective, it means Anthropic’s models contain enough concentrated capability that a smaller lab can extract meaningful value from just the outputs. That’s simultaneously a security vulnerability and the best advertising Anthropic has ever received.

A federal judge in Miami upheld a $243 million jury verdict against Tesla this week over a fatal 2019 Autopilot crash, and the ruling was about as blunt as these things get. U.S. District Judge Beth Bloom wrote that “the evidence admitted at trial more than supports the jury verdict.” Tesla asked for a new trial. Tesla argued excessive damages. The judge said no to all of it.

George McGee was driving a Tesla Model S with Enhanced Autopilot engaged in Key Largo, Florida. He dropped his phone and reached for it, assuming the car would brake. It didn’t. The car went through an intersection at 62 mph and killed 22-year-old Naibel Benavides. Her boyfriend, Dillon Angulo, was severely injured. The jury found Tesla 33% responsible and awarded $19.5 million to Benavides’ estate, $23.1 million to Angulo, and $200 million in punitive damages.

Before the trial, Tesla could have settled for $60 million. They refused.

Courts as Legislature

What makes this verdict matter beyond the dollar amount is what it represents in the absence of anything else. There is no federal liability framework for autonomous driving. None. NHTSA tracks crashes. NHTSA investigates defects. NHTSA has proposed a voluntary program called AV STEP for manufacturers to submit safety data. The House introduced the SELF DRIVE Act of 2026 in February. But none of this addresses the question that actually determines how autonomous driving works in practice: when the car crashes, who pays?

Juries are answering that question. Case by case, verdict by verdict, in courtrooms across the country. That’s not regulation. That’s litigation filling a vacuum.

The problem with litigation as de facto regulation is that it’s incoherent by design. A jury in Miami can find Tesla 33% liable. A jury in Texas might find them 80% liable for similar facts. A jury in Michigan might find them 0%. There’s no consistency, no precedent that binds other courts (beyond the same federal circuit), and no mechanism for the industry to build around. Companies can’t plan product roadmaps around jury verdicts because no two juries see the same facts the same way.

Congress has had a decade to pass autonomous driving liability legislation. They haven’t. State regulations are a patchwork. Some states require permits. Some require safety drivers. Some have no rules at all. The only consistent national standard for “what happens when an autonomous vehicle kills someone” is whatever 12 people in a courtroom decide on a given Tuesday.

The Math Changed

Tesla used to fight every Autopilot case. Before the Benavides trial in August 2025, Tesla had never lost an Autopilot verdict. Their legal position was clear: the driver is responsible, the system requires supervision, and no reasonable person should trust it to drive unattended. That argument worked until a jury disagreed.

Since losing, Tesla has settled at least four additional Autopilot crash lawsuits. One involved a 15-year-old killed in California. Another involved a Model Y on Autopilot that crashed into a parked police vehicle in Texas. Terms undisclosed, but the pattern is obvious.

Companies don’t shift from fighting to settling because they had a change of heart. They do it because the expected cost of trial, weighted by the probability of another $200 million punitive award, now exceeds the cost of writing a check. The Benavides verdict didn’t just cost $243 million. It repriced every pending Autopilot case on every docket in the country.

And there are a lot of pending cases. NHTSA tracked over 900 incidents involving Tesla’s driver-assistance features between 2018 and 2023 alone. In January 2026, a new lawsuit was filed after a 2022 Model X allegedly veered into oncoming traffic on an Idaho highway, killing a mother, her two daughters, and her son-in-law. The suit alleges Autosteer and Lane Keeping Assist were “unreasonably dangerous and defective.”

This compounding works in one direction. In December 2025, a California administrative law judge ruled that Tesla’s use of “Autopilot” and “Full Self-Driving” in marketing was deceptive. Tesla quietly dropped the Autopilot branding from California marketing materials in February. That concession is now ammunition for every plaintiff’s attorney in every pending case. You don’t voluntarily change your marketing unless you believe a court might force you to.

Everyone’s Problem

This isn’t just Tesla’s situation. Every company building autonomous or semi-autonomous driving systems, Waymo, Cruise, Motional, Mobileye, the Chinese players, is watching this verdict and doing the same math. If a jury can award $200 million in punitive damages against the largest EV company in the world, and a federal judge upholds it, what does the liability profile look like for a company with less cash on hand?

The insurance industry hasn’t figured this out either. Autonomous vehicle insurance is still mostly written as extensions of traditional auto policies because there’s no actuarial model for a technology that doesn’t have standardized safety reporting or a federal liability framework. Underwriters are pricing risk they can’t quantify because the rules haven’t been written.

The SELF DRIVE Act will probably pass in some form. NHTSA will eventually finalize AV STEP. But liability, the question of who pays when the machine fails, is being decided right now in courtrooms by people who don’t know what Autosteer is. That’s the system we have. And every verdict that comes down while Congress sits on its hands becomes another data point in a legal framework that nobody designed and nobody controls.

Phil Spencer retired from Microsoft on Thursday after 38 years. His last day is Monday. Sarah Bond, Xbox president and the person most people assumed would succeed him, also resigned. Both of them, gone within the same announcement. And neither of them is being replaced by anyone from gaming.

The press release calls it a retirement. Spencer’s own statement says he told Nadella last fall he was “thinking about stepping back and starting the next chapter.” That’s the kind of language you use when you want the exit to look calm. And maybe it was calm. But the timeline tells a different story if you’re paying attention.

The Sequence

Spencer orchestrated the $69 billion Activision Blizzard acquisition, the largest in gaming history and one of the largest in tech. That deal closed in October 2023 after a year-long regulatory fight with the FTC. Within three months of closing, Microsoft laid off 1,900 gaming employees. By January 2024, another 2,500 across the company. Studios got shuttered. Teams got folded. The kind of restructuring that happens after a mega-merger, where you cut the overlap and consolidate the headcount.

Spencer oversaw all of it. The deal. The layoffs. The integration. The reorganization of every studio under one umbrella. And then last fall, once the hard part was done, he told Nadella he was thinking about leaving.

That’s not a retirement. That’s an architect walking off a job site after the building is finished. He built the thing. He did the ugly work of merging it. And then he left before anyone could ask him to run it differently than he built it.

Bond’s Exit Is the Stranger One

Spencer at least gets the “38 years, I’m tired” narrative. Bond doesn’t. She was Xbox president. She was running the day-to-day. She was the obvious next CEO of Microsoft Gaming. And instead of taking the job, she resigned.

That’s the part nobody is spending enough time on. Bond didn’t get passed over and stay. She got passed over and left. When the person everyone expects to get promoted decides to walk instead, it usually means they saw something they didn’t want to be part of. Or they were told the direction was going somewhere they disagreed with. Either way, it’s not the behavior of someone who lost a title fight. It’s the behavior of someone who chose to leave.

Microsoft replaced both of them with Asha Sharma from CoreAI, who joined the company in 2024 from Instacart. Her first public statement included a promise not to “flood our ecosystem with soulless AI slop.” She felt the need to say that on day one. Draw your own conclusions about what the internal conversations looked like.

What the Timing Actually Says

Spencer built Xbox into a $25 billion annual revenue business. Game Pass has over 34 million subscribers. The studio portfolio, after Activision and Bethesda, is the largest in the industry. All of that was Spencer’s project.

But building the portfolio was one job. What Nadella wants to do with that portfolio is a different job. Microsoft has spent the last two years layering AI into every division. Azure, Office, GitHub, Windows. All got Copilot. All got AI integration as a strategic priority. Gaming was the last major division without an AI executive running it.

Spencer built a content empire. Nadella wants a platform. Those are different ambitions with different definitions of success. Content success means great games that sell and retain subscribers. Platform success means AI tools, procedural generation, dynamic monetization, ecosystem lock-in. Content people and platform people rarely see the world the same way.

Spencer telling Nadella last fall he wanted to leave makes more sense if you consider that last fall is also when Microsoft accelerated its AI integration roadmap across divisions. If the conversation shifted from “build the best game library in the world” to “now turn it into an AI platform,” Spencer may have decided he’d rather leave on his own terms than execute someone else’s vision for the thing he built.

Bond apparently reached the same conclusion.

What’s Left

Matt Booty got promoted to Chief Content Officer, which is Microsoft’s way of saying the studios will still make games. Sharma’s job is everything else. The platform layer. The AI strategy. The part that Nadella actually cares about.

The studios that make Halo, Elder Scrolls, Call of Duty, and Minecraft are still staffed with the same developers. Nobody is firing the game makers. But the person those game makers report to, through Booty through Sharma, has never shipped a game. And the person who spent 12 years protecting them from the platform side of Microsoft just walked out the door.

Spencer’s retirement statement was gracious. Bond’s departure was quiet. Together they read less like a transition and more like two people who decided the next chapter of Xbox wasn’t one they wanted to write.