USA Today and 18 Gannett papers sue OpenAI for $250M+ over scraped training data
Good morning ๐ The number everyone's leading with is $250M. The actual ask, buried a few paragraphs into the complaint, is that OpenAI destroy every model trained on the data.
In today's issue:
- ๐ญ USA Today and 18 Gannett papers sue OpenAI for $250M+ over scraped training data
- ๐ง Microsoft's classifier that skips text generation entirely
- ๐ฌ Three papers on models that know they're wrong and say nothing anyway
- ๐ Runtime guardrails for AI agents, and robots building gene therapies
- ๐ ๏ธ Lifting AWS's human-approval gate for your own agent's fixes
- ๐ Nvidia eyeing a Reflection AI buyout, plus OpenAI, Ai2, and Hugging Face
Get tomorrow's issue in your inbox.
One concise AI brief, sent after the signal clears the noise.
๐ญ THE ONE THING
๐ฐ USA Today and 18 Gannett papers sue OpenAI for $250M+ over scraped training data
USA Today, the Detroit Free Press, the Arizona Republic and 16 more Gannett mastheads filed suit against seven OpenAI entities in the Southern District of New York on Oct. 8, case 1:26-cv-08892. The complaint gets specific: more than 160,000 entries scraped into OpenAI's WebText training sets, 83,266 of them from usatoday.com and 12,994 from freep.com alone, plus over 122 million tokens pulled into C4. Gannett wants $250M+ in damages, an injunction, and destruction of any model trained on the data. That last ask is the tell: courts have let similar suits settle into licensing checks, not model rebuilds, and I'd bet this one follows the same path. Despite the splashy number, trade press is already filing this as one more entry in a two-year pile of publisher suits against OpenAI, not the landmark it's being sold as.
๐ง MODELS & RELEASES
- ๐ฏ Microsoft shipped Decision-1, a Qwen3.5-9B model that scores a fixed set of answers instead of generating text, priced at $0.042 per million input tokens with output free, and claims 35x the speed of GPT-6 Sol at P50 for the routing, labeling, and judging calls you're currently burning a frontier model on. It's running on Qwen for now; Microsoft says it'll rebase onto MAI or OpenAI tech later, so this reads less like a model launch and more like Microsoft staking out the cheap-classification layer before it's picked the permanent engine underneath. Microsoft-Decision-1
๐ฌ RESEARCH HIGHLIGHTS
- Epistemic humility Researchers ran four agents through tasks where retrieved evidence contradicts what the model already "knows," then measured something nobody usually checks: does it say so. The agents with the best task accuracy were often the ones that quietly dropped the contradiction and shipped a confident wrong answer anyway. They noticed the conflict early, then lost the thread. Nudging models to flag uncertainty worked, but it cost accuracy every time. arxiv.org/abs/2610.12360
- Legal citations Seven open-weight models, four legal benchmarks, one swap: replace the cited statute or precedent with an unrelated one, keep the facts fixed, see if the verdict moves. On CaseHOLD it barely does, 0 to 21.7% of the time, even though the same models name the "correct" authority 67 to 100% of the time. The citation is decoration, not the reasoning. The same models complied with an adversarial instruction hidden in the case facts 73 to 96% of the time. The authority you can point to isn't the one doing the work. arxiv.org/abs/2610.12361
- Safety benchmarks A construct-validity audit of HarmBench, one of the standard safety evals, finds it isn't measuring one thing. Item response theory modeling says "harmful refusal" doesn't behave like a single, coherent trait, and models from different labs with matching aggregate scores diverge item by item. One tidy number is covering for a messier reality underneath. If you're picking models off a safety leaderboard, that leaderboard is flatter than the models actually are. arxiv.org/abs/2610.12409
๐ AI STARTUPS
- Rein Security raised a $25M Series A (Glilot and Sienna Venture Capital leading, Corner Ventures joining), pushing total funding to $35M. The pitch: watch every AI agent at runtime and kill bad actions before they execute, no gateway or proxy in the data path. Lemonade and Dun & Bradstreet are already customers, and Rein claims 8x revenue growth since a January launch. Gartner's betting the "secure AI" market hits $7.7B by 2028, so the category's about to get crowded. Source
- Multiply Labs closed a $75M Series B led by NantWorks, with AstraZeneca and Lux Capital among the names in the round. The company builds robotic clusters that manufacture cell and gene therapies, antibodies, and mRNA treatments in-house, GMP-compliant, instead of outsourcing to a CDMO. Their numbers: 100x the throughput of manual production and a 74% cut in cost per dose. Co-founder Fred Parietti's framing is the interesting part: AI is now designing more therapies than anyone can physically make. That's the bottleneck this round is betting on. Source
๐ ๏ธ TRY THIS
Gate your agent's fixes behind a human, not its own judgment
Publishers suing OpenAI over scraped content are arguing a version of the same thing ops teams have wanted for a year: don't let an autonomous system act on what it touched without a person signing off first. AWS just shipped that pattern for its own DevOps Agent. It investigates incidents and stays strictly observe-and-report; a separate pipeline turns its findings into a pre-validated fix a human has to approve before anything runs. AWS Machine Learning blog
1. Let your diagnostic agent produce a root-cause summary only. No write access, no remediation calls.
2. Pipe that summary into a second stage that drafts the actual fix as a candidate, not an action. AWS does this with Lambda Durable Functions and EventBridge.
3. Validate the candidate fix against your runbook (AWS routes this through Bedrock) before it ever reaches a human queue.
4. Require an explicit approve-and-run click from on-call. The agent diagnoses. A person pulls the trigger.
Prompt: Given this incident summary and the current runbook, draft a remediation step as a candidate only. Flag anything outside documented procedure, and do not assume approval to execute.๐ QUICK LINKS
- Nvidia is reportedly weighing a full buyout of Reflection AI, the coding-agent startup it already backed with $800 million, after Reflection pitched a $25 billion valuation back in April. FT
- OpenAI added a College Planner to ChatGPT for Teens, bundled with flashcards, quizzes, and a new teen advisory council. OpenAI
- Ai2 swapped priority queues for time-budget scheduling across its GPU clusters, holding occupancy at 98% while cutting median wait times from 5 minutes to 24 seconds. Hugging Face
- Hugging Face engineers used an agent called ML Intern to train six custom models for about $103 total, among them a 0.8B rewriter distilled down for $16. Hugging Face
See you tomorrow.
Pradeep Perugu