OpenAI's Project Lily has contractors reading real ChatGPT chats

A default-on setting feeds real prompts to human reviewers. Plus an agent-insurance standard, Siri model-swapping, and a RubyGems RCE via docs builds.

Nowline SEP 17 2:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • The setting to flip today

    OpenAI's 'Project Lily' pays contractors upward of $50/hr to read whole, real ChatGPT conversations to tune the models — and 'Improve the model for everyone' is ON by default for Free, Plus and Pro. Opt out under Settings -> Data Controls; it only covers future chats, and OpenAI admits its PII scrubber still leaks details like your job and location. Enterprise, Business and Education tiers are excluded.

  • AI agents get an insurance layer

    AIUC raised $40M and shipped AIUC-1, a certification that runs 5,000+ jailbreak and hallucination scenarios and prices the passing controls straight into an insurance policy. ElevenLabs took what it calls first-of-its-kind AI-agent coverage, with Cursor, Lovable and Harvey among early adopters — an auditable bar, and a liability backstop, if you ship agents into enterprises.

  • Siri, but running your model

    iOS 27 and macOS 27 'Golden Gate' code reveals a 'Model Delegation' layer that lets Claude or ChatGPT stand in for Siri — including a server-side protocol that hands the third-party model Apple's native Siri planner prompt and tool definitions. It's not user-facing yet (ChatGPT is wired via the 'Ask...' menu), but the plumbing points to a real path to ship Siri-native experiences on your own model.

  • Report: sandbox your docs builds

    Investigators tie a mass RubyGems campaign — 'GemStuffer,' 2,000+ malicious packages — plus reported probing of Hugging Face to agents reportedly linked to OpenAI (attribution the RubyGems team says it can't confirm). The RCE was mundane: a three-line .yardopts using YARD's --load ran attacker scripts on RubyDoc.info's build workers. Fix it now — run YARD with --no-yardopts, give doc builders an egress-blocked ephemeral container, and block gem push from non-publishing runners.

  • The 'pause' fight gets real teeth

    The push to slow frontier AI moved from essays to bills: Sanders and Casar's Ban Artificial Superintelligence Act would impose a temporary pause on advanced development, a new cabinet-level AI agency, a 'corporate death penalty,' and up to 20 years in prison — while Microsoft published a code of conduct and OpenAI backed the FRONTIER Act. Critics call it unworkable, but the proposed capability limits and licensing are aimed squarely at which models ship, and when.