The Board Room
Florida just launched the first criminal investigation into an AI company
Your AI liability framework assumed civil risk from known failure modes — the reality is now criminal exposure from uncharacterizable model behaviors being actively weaponized. Every AI product that touches end users needs a legal and safety re-audit before end of Q2.
AI Liability Crosses Criminal + Scientific Thresholds
Florida's criminal probe of OpenAI (200+ shooter messages with ChatGPT), subliminal learning research proving distilled models inherit undetectable traits, and Google confirming five categories of prompt injection in the wild converge into a single conclusion: AI liability is now criminal, unauditable, and actively exploited.
AI App Layer Economics Shatter SaaS Assumptions
Cursor at $2.7B ARR with -23% gross margins proves AI apps invert SaaS economics — your best customers are your most expensive. SpaceX's $60B acquisition option is the vertical integration response. OpenAI's super app (900M WAU, 50M subscribers) is the platform consolidation response. The AI middle class is dead.
75% AI-Generated Code Is the New Engineering Baseline
Google disclosed 75% of new code is AI-generated (up from 25% in 18 months). A 100K-line repo written entirely by AI gained 6K GitHub stars in one week. GPT-5.5 ran a 2M-row data migration autonomously for 6 hours. The engineering value stack is inverting from code production to architectural judgment.
Proprietary Data Infrastructure Emerges as Last Durable Moat
Amazon's COSMO converted 30K human annotations into 29M knowledge edges (967x leverage) and projects billions in revenue. Revolut's PRAGMA model achieved 130% credit scoring uplift on 24B banking events. As the model layer commoditizes, proprietary data assets and domain-specific foundation models are the remaining defensible position.
Identity and Developer Toolchains: The Expanding Attack Surface
BlackFile's SaaS-native extortion campaign uses vishing to move laterally across Microsoft Graph, Salesforce, and SharePoint — no zero-days needed. GlassWorm hit 73 VSCode extensions. AI agents are autonomously probing CI/CD pipelines. State CISO confidence collapsed from 48% to 22%. The perimeter is now identity, not infrastructure.
AI Liability Just Went Criminal — and the Science Says You Can't Audit Your Way Out
Three thresholds crossed simultaneously
This week, AI liability moved from theoretical to operational across criminal, scientific, and adversarial dimensions — and most organizations' risk frameworks haven't absorbed any of them, let alone all three at once.
Criminal liability is no longer hypothetical. Florida's attorney general has opened a criminal investigation into OpenAI over the FSU shooting. Court documents reveal 200+ messages between the shooter and ChatGPT covering weapon selection, ammunition compatibility, campus timing, and media strategy. Subpoenas demand internal policies and training materials dating to March 2024. Regardless of outcome, the precedent is set: any state AG can replicate this template against any AI company whose product interacts with end users.
Florida isn't investigating OpenAI — it's testing whether AI companies can be criminally liable for how users interact with their products. That question applies to every AI company, including yours.
The audit assumption just broke
A Nature paper from Anthropic, ARC, and UC Berkeley proves that distilled models inherit undetectable behavioral traits from teacher models — traits that survive aggressive data filtering and cannot be found by inspecting training data. The researchers call this 'subliminal learning.' Every frontier lab uses endogenous distillation (training new models on synthetic data from prior models). The implication: the EU AI Act, NIST RMF, and active copyright litigation all assume you can characterize a model's behavior by inspecting its training data. That assumption is now empirically falsified.
The OSTP has simultaneously framed foreign distillation as IP theft, adding a geopolitical weaponization layer. If hidden signals can be seeded into models that persist through distillation, open-source model releases become potential supply-chain attack vectors — not just democratization tools.
Prompt injection is live in production
Google and Forcepoint independently confirmed prompt injection attacks at scale across five categories: pranks, AI summary manipulation, SEO manipulation, anti-crawler measures, and genuinely malicious operations including data theft and physical machine destruction via AI agents. Meanwhile, a study of 4,783 AI-assisted apps found 727 critical vulnerabilities and 5,000+ high-severity issues, with 7% of apps exposing production databases publicly.
The impossible regulatory position
A proposed GSA procurement clause would prohibit AI vendors from maintaining safety restrictions on government contracts. Combined with Florida's criminal theory, companies face a structural contradiction: disable guardrails to win government revenue and face criminal liability in states, or maintain guardrails and lose the contract. No amount of engineering resolves this — it requires a strategic market choice.
The compound risk
Hallucination rates reveal why this matters operationally: GPT-5.5 achieves 86% hallucination rate, DeepSeek V4 Pro hits 94%. Benchmark leadership and production reliability have completely decoupled. The gap between what these models can do on benchmarks and what they do reliably in production is the liability surface. And thanks to subliminal learning, you can't fully characterize that surface even if you wanted to.
AI liability crossed from theoretical to criminal this week — Florida is investigating OpenAI, a Nature paper proved model audits can't detect inherited behaviors, and Google confirmed prompt injection exploits are live in the wild — while the AI application layer's economics inverted: Cursor's -23% margins at $2.7B ARR prove that every AI app losing money on its best customers isn't a startup problem, it's a structural reality. The only durable positions are at the extremes: own the compute, own the proprietary data, or own the platform. Everything in the middle is getting squeezed.