Today’s news is about what happens once AI is deployed in places where mistakes are expensive: patient records, hospital shifts, power grids, and the legal system. The tools work. The consequences are what’s catching up.
1. OpenAI gets a California subpoena and shows three staff the door
The Register ran two OpenAI stories on the same day: one says its wandering AI agents earned it a California subpoena, the other that three staff were dismissed over alleged information misuse. We only have the headlines, so who issued the subpoena, what it demands, and who the three people were remain unclear. Nothing in the supplied text says the firings were about safety dissent.
The timing still matters. A WIRED column from the day before argued that AI safety is being left to self-policing, and noted that AI agents themselves are not the ones being served subpoenas. In California’s case, the legal process lands on the company, not the software.
That is the real test of autonomous agents: whether their makers can say what the agents did and why. Until the details surface, the subpoena shows only that someone is asking, and the dismissals show OpenAI is policing its own information, not what the dispute is about.
The Register · The Register · WIRED
2. Oracle’s Wisconsin AI datacenter waits on a power approval
Oracle’s planned Wisconsin AI datacenter may miss its 2027 customer delivery date because its grid connection is still awaiting regulatory approval, according to The Register. The supplied text is only the headline and subhead, so the size of the delay and the reasons behind it are unknown.
Even so, it’s a useful reminder for anyone who assumes compute is purely a purchasing problem. A site can have the buildings and the customers, and still sit idle without a power connection. If regulators and utilities set the pace, delivery dates become promises that depend on parties outside the cloud provider’s control. Founders planning around 2027 capacity should treat vendor schedules as conditional.
3. Nurses say Palantir’s scheduler ignores them, and nobody can audit it
HCA says its Palantir-built Timpani scheduler gives nurses their requested days off 1 percent of the time. Nurses told WIRED that figure undersells the change: at one Missouri facility, being scheduled on a day off was once unheard of, and now nearly everyone has had it happen.
WIRED’s reporting, based on interviews with six nurses, describes understaffed shifts, too few senior nurses on a floor, and an appeals process that runs through a central team in Nashville with no room for explanation. HCA counters that nursing leaders, not Timpani, make final decisions, and its innovation chief has credited the tool with less manager time on scheduling and better retention. Palantir says customers own the data and the decisions.
Both claims can be true, and that’s the problem. If the software drafts the schedule and humans only approve it, ‘a human decided’ is weak comfort. A former HCA data science manager’s lawsuit alleges the data the tool uses was routinely deleted, which would make independent auditing impossible. HCA hasn’t responded in court. A scheduler that can’t be checked is hard to defend whatever its averages say.
4. Epic freezes development after an AI model finds MyChart flaws
Epic, whose MyChart software sits behind more than 320 million patient records, has paused most product development for about six weeks, CEO Judy Faulkner told Modern Healthcare. The trigger was a deployment of Anthropic’s Mythos cybersecurity model, which turned up flaws that could expose patient data. TechCrunch reports the company hasn’t said what the bugs are.
The one concrete detail came from security chief Stirling Martin, who told The New York Times that some customer configurations of MyChart could let outsiders read records without leaving a trace in the logs. Mythos reportedly didn’t say whether records could be altered undetected, but Epic judged the risk big enough to stop shipping features.
The notable part is how it was found. Freezing a roadmap is rare, and TechCrunch ties the move to worry that AI makes finding and exploiting vulnerabilities cheaper for attackers too. If defenders can run a model like Mythos, so can everyone else, which makes security debt a deadline instead of a backlog item. Epic also says hospitals, not Epic, hold the data, and the bug involves customer configurations. So the fix may depend on how many of those customers actually apply it.
5. Cloudflare’s web search API is really a pitch to control agent traffic
Cloudflare says agents often just guess a URL and curl it, which is why so many fetches return a 404. Its answer is a Web Search API, launched through AI Gateway with Ceramic.ai, Exa, and Linkup, that injects fresh web snippets into model context.
The search is the easy part. The product is the wrapper: queries draw from AI Gateway credits, show up in the same logs, and are billed at partners’ list API pricing with no markup. Cloudflare also lets you bring your own keys and will flag providers that support zero data retention. Server tools are promised for later.
The more strategic move is the rule on crawlers. Partners must meet Cloudflare’s Verified bot requirements, respect robots.txt, and include a link to the source of crawled content. For Cloudflare, which sits in front of much of the web, that positions it as both the agent’s gateway and the publisher’s gatekeeper. Whether site owners see a benefit from those source links is not yet shown.