September 21, 2026

D.A.D. today covers 9 stories — about a 9-minute read. What's New, What's Innovative, What's Controversial, What's in the Lab, and What's in Academe.

The Daily AI Digest is a daily AI briefing automated by Alexander Panetta — a veteran political journalist tracking the field during a Master's in AI Management at Georgetown University.

D.A.D. Joke of the Day: My company adopted an AI policy: think before you prompt. Now everyone just prompts the AI to do the thinking.

What's New

AI developments from the last 24 hours

ChatGPT's Ad Cookie Follows You Across the Web — and Opting Out Doesn't Stop It

An independent security researcher who publishes as Buchodi has reverse-engineered the tracking system behind OpenAI's advertising platform, and published months of traffic analysis showing how activity on other companies' websites is linked back to a ChatGPT account.

The mechanism is ordinary adtech, and that is the first thing worth saying about it. Nothing here is a product of cutting-edge AI: no model is involved anywhere in the chain, and the cookie-and-pixel technique long predates the chatbot. What is new is what it has been attached to — an account holding a record of what someone asks when they believe no one is watching. A cookie called __obi, bound to a user's account through a signed token, lasts a year and is configured to travel across sites. Visit an advertiser that has installed OpenAI's tracking pixel and the browser hands __obi back to OpenAI along with the page being viewed. The analysis covers 936 advertiser pixels across 1,029 hostnames; on the researcher's own phone, a single __obi value reached OpenAI from 12 retailers including Chewy, Wayfair, HelloFresh, Coursera and SeatGeek. Names, emails and phone numbers are hashed before transmission. Country, region, city and postal code are not.

Three findings matter more than the plumbing. The cookie is filed under OpenAI's data-analysis consent category rather than its advertising one, so users who accept analytics and refuse marketing still receive it — switching off ad personalization does not stop it. It works on logged-out visitors too, through a persistent anonymous identifier. And it only functions in Chrome, because Safari and every browser on iOS block this class of cookie by default. Buchodi put both consent questions to OpenAI on September 14; support staff acknowledged the message, said it would be raised internally, and answered neither.

Why it matters: OpenAI's standing defense of its ad business is that it never shares your conversations with advertisers, and nothing here contradicts that. The point is that the conversation was never where the exposure sat. The data moves the other way — from the shops you browse back toward the account that knows what you ask in private — assembled by the same pixel-and-cookie machinery it took Google and Meta a decade of regulatory grief to normalize. Two practical notes for anyone weighing ChatGPT inside an organization: marketing cookies have been on by default for free accounts since April, under Settings → Data Controls → Marketing Privacy, and the analytics consent is a separate switch. Which browser your staff use determines whether any of this reaches OpenAI at all.


U.S. and China Discuss an AI Warning System Ahead of Xi's Visit

The United States and China discussed creating a notification system that would let each country alert the other to national security problems involving artificial intelligence, The New York Times reported, during a day of economic talks in New York on Sunday.

Treasury Secretary Scott Bessent, Trade Representative Jamieson Greer and China's vice premier, He Lifeng, met at JPMorgan Chase's New York offices to lay groundwork for President Xi Jinping's state visit to Washington this week. Bessent said the mechanism would be called "the U.S.-China A.I. dialogue" and would aim at a shared vision of AI's goals and the threats it poses. It would be activated, he said, when an AI matter "reaches the national security level." Moving "from opaque to more transparency between the No. 1 and the No. 2 A.I. powers in the world," he added, "is very important."

Reuters reported this month that the two governments were due to take up frontier AI safety risks in mid-September, with the issue possibly reaching Trump and Xi when they meet. This is that conversation, and so far it has produced a name rather than an agreement.

What each side would actually report remains unsettled. The Times notes that American labs have lately disclosed their own models breaching or bypassing contained testing environments — the OpenAI and Google cases D.A.D. covered on September 17 and 19 — while US officials worry about AI sharpening Chinese hacking, military and surveillance capabilities. A Trump administration report this month accused Chinese companies of taking proprietary capabilities from American models in an "aggressive, malicious and targeted" way — the distillation fight Beijing's state press has called a "Cold War playbook." It is expected to come up when the two presidents meet.

Why it matters: Notice what kind of instrument this is. It does not restrain what either country builds. It promises to tell the other side after something has already gone wrong enough to count as a security matter — the same after-the-fact posture Trump took domestically on Saturday, when he said the existing criminal and civil justice system is all the oversight American AI needs. For anyone watching whether an international floor under AI is forming, the honest read is that the first brick is a telephone line: worth having, far short of a rule, and dependent on two governments each deciding how much they are willing to admit to the other.


Trump Says He'll Build an "AI Force" and Name an AI Czar

President Trump announced on Truth Social Saturday that he will create an "AI Force" modeled on the Space Force and appoint an AI "czar" to lead it. He offered no timeline, no structure and no name. "Only High I.Q. individuals need apply," he wrote of the job.

The substance was in a sentence about enforcement. "We will not in any way hinder or stifle the Growth of this incredible Industry," Trump wrote. "Rather, we will cherish it, help it, and watch over it, as it grows! However, we will also be looking for BAD, and we can do that, very easily, with our already existing Criminal and Civil Justice System. For this purpose, I am forming the AI Force, much like I did Space Force."

That is the argument he made five days earlier, when he phoned Nvidia's Jensen Huang onstage to call AI safety warnings "a hoax" and said no new AI law was needed because prosecutors already have the tools. Saturday's post attaches an institution to it.

What kind of institution is the open question. The Space Force is a branch of the armed forces, not a regulator — if the AI Force copies it, the body Trump is describing sits inside the Pentagon, and its job is capability, not oversight. The czar title points elsewhere: David Sacks held an AI and crypto czar role until March, when his clock as a special government employee ran out, and he now co-chairs the President's science advisory council with Michael Kratsios, who runs the White House science office. Neither post is a regulator either.

Why it matters: The safety standards body OpenAI, Anthropic and Google have been drafting since July is a self-regulator with no government agency above it to ratify or overrule its rules. This is the administration's answer, and it is not that agency. It is a promise to prosecute after the fact, wrapped in a military metaphor, from a President who has said the underlying risk is imaginary. For anyone weighing how much federal AI rulemaking to plan around, Saturday's signal is that the answer is close to none — and that whatever the AI Force turns out to be, it will not be writing rules.


EPA Scraps Carbon Limits on the Power Plants AI Is Helping to Build

The Environmental Protection Agency finalized the repeal of most of the 2024 Carbon Pollution Standards on September 14, ending the requirement that coal and gas plants capture 90% of their carbon emissions or close. The agency put the savings to the power sector at $310 billion. In the same announcement it went further, proposing to scrap the remaining greenhouse gas standards for power plants and to rescind the 2015 findings underpinning the EPA's authority over them — a step that, if it survives, would leave future administrations without the power to try.

Power plants are the country's second-largest source of greenhouse gases, and they are being asked to supply more. The Energy Information Administration now describes data-center load as the dominant driver of long-term growth in American electricity demand, concentrated in the commercial sector, where its forecasts have been revised upward most sharply. Gas burned for power generation is on track this year to match its all-time high. The plants being built and kept running to meet AI's appetite are the ones whose carbon obligations just disappeared.

Why it matters: The cost of electricity is AI's quiet variable — the number that decides whether a data center pencils out. This strips a compliance expense out of the generation side of that calculation, which is a subsidy to the buildout however it is labeled. For institutions carrying net-zero commitments, the arithmetic moves in an uncomfortable direction: the grid power behind a cloud contract is less regulated than it was a week ago, so the emissions attached to a company's AI use are now harder to shrink by waiting for the grid to clean itself up.

Sources: EPA · Human Rights Watch · Discuss on Hacker News


A Flaw in Four AI Coding Assistants Let Attackers Swap In Their Own Code

Researchers at the security firm AIR — Or Nevo, Dor Granat and Niv Hoffman — disclosed a vulnerability on September 17 affecting the four most widely used AI coding agents: Anthropic's Claude Code, OpenAI's Codex, GitHub Copilot and Google's Gemini CLI. They call it Plugin4Shell.

The agents let users install plugins pinned to a specific commit — a 40-character fingerprint meant to guarantee you get exactly the code you approved. The researchers found the agents confirmed the fingerprint existed but never checked that it matched what they were actually downloading. Naming a malicious branch after the expected fingerprint was enough: the agent installed the attacker's code and reported a successful install. No click was required, because Claude Code and Codex update installed plugins in the background by default.

Anthropic patched Claude Code in version 2.1.179 and OpenAI patched Codex in 0.146.0. Microsoft had not fixed Copilot at the time of disclosure. Google said Gemini CLI is deprecated, will not be fixed, and told users to migrate to its Antigravity tool. The researchers report no known exploitation.

Why it matters: These agents run with a developer's own permissions on machines holding source code and credentials, which is what turns a plugin bug into an access problem. The detail to carry into a procurement conversation is the silent background update: the security of these tools changes without anyone at your organization approving the change, and here one vendor declined to fix the flaw at all. Asking which AI tools in your shop auto-update, and who reads the vendor's advisories, is now an ordinary IT question rather than a paranoid one.


Volunteers Torrent AI Models to Save Them from Deletion

A new project called Pirate Face is mirroring openly licensed AI models—LLMs, image and audio models, datasets—from Hugging Face as peer-to-peer torrents, verified against official checksums to confirm files haven't been tampered with. Instead of living on one company's servers, each model gets copied across a distributed swarm of users, similar to how BitTorrent shares movies or software. The pitch: even if Hugging Face or an individual creator pulls a model down, copies survive elsewhere.

Why it matters: It's a hedge against a real dependency risk—teams building on "free" open-source AI models could lose access overnight if a host removes them, and this makes that much harder to do.


What's Innovative

Clever new use cases for AI

Better AI Posters Come Down to How You Ask ChatGPT

Noticed that every AI-made event poster seems to have the same generic look? A design writer, in a write-up that resurfaced on Hacker News this week, found the fix isn't the tool but the prompt. Asking ChatGPT for a specific aesthetic—Bauhaus, Swiss Style, mid-century modern—instead of a generic "make me a poster" produces noticeably more distinctive results. The default look, it turns out, is a prompting habit, not a hard limit of the technology.

Why it matters: If you're using AI for flyers, slide decks, or marketing visuals, naming a design style up front is a free, immediate upgrade over accepting whatever the model defaults to.


What's in Academe

New papers on AI and its effects from researchers

AI Reveals Well-Being Talk Changes Sick Days, Not Health

Economists Riccardo Di Francesco and Seetha Menon of the University of Southern Denmark, with Peter Hull of Brown University, used language models to score Danish companies on how heavily their public disclosures emphasize employee well-being, then matched those scores to national health and workplace records spanning 2013-2022. Tracking workers who changed employers, they found people who moved to higher-scoring firms took notably more sick days—but their actual health care use stayed flat. Since declining health would typically raise both measures, the researchers argue employers' well-being messaging changes how workers use sick leave, not their underlying health.

Why it matters: It's an early example of using AI to quantify soft corporate signals—like stated values—and test whether they actually shape employee behavior, a technique that could extend well beyond health policy into HR and workplace analytics.


People Trust AI Coding Agents' Work but Can't Supervise Them, Study Finds

A study mined 73,093 Reddit posts from people using the AI coding agent OpenClaw, coding what users valued and whether they got it. The pattern: users were generally satisfied with what the agent produced—its outputs. But when posts touched on supervising the agent—checking its work, setting limits, understanding what it was doing—those needs went largely unmet across all six value categories researchers tracked, including reliability, cost, and access.

Why it matters: As companies hand more tasks to autonomous AI agents, this suggests the weak link isn't output quality but oversight—the tools and habits needed to actually supervise them are lagging behind.


What's Happening on Capitol Hill

Upcoming AI-related committee hearings

Wednesday, September 23Hearings to examine Flock's nationwide AI surveillance network. Senate · Senate Judiciary Subcommittee on Crime and Counterterrorism (Open Hearing) 562, Dirksen Senate Office Building


What's On The Pod

Some new podcast episodes

The Cognitive RevolutionAI:AM Highlights: Zvi on Pacing & Trump-Xi, Astra better behaved than Fable? + a new LLM Pain Axis??

Get tomorrow's briefing