AI & Tech Daily
AI’s New Test: Provenance, Permissions and Control
OpenAI is beginning to watermark eligible ChatGPT and Codex text generated in the European Union, while offering opt-in watermarking to API customers worldwide. Jesse examines what that signal can prove, and what it cannot. Also covered: AWS’s governed runtime for persistent OpenAI agents, Australia’s December deadline for automated-decision disclosures, Microsoft’s low-latency transcription and multilingual voice models, an actively exploited FortiMail flaw, Samsung’s US$1 billion AI infrastructure bet, AI’s role in familiar cyberattacks, and Meta’s experimental Muse hardware SDKs.
Full transcript
Read the episode.
I'm Jesse Owen. This is AI and Tech Daily.
A Watermark, Not a Verdict
A hidden signal is about to travel with some AI-written text in Europe. It can survive ordinary use, but a short edit or translation may make it disappear.
Our main story today is OpenAI’s move into text watermarking, and whether provenance can help without becoming a shortcut for judging authorship. On 5 October, OpenAI opened opt-in watermarking to API customers worldwide. Over the coming weeks, it says eligible text generated through ChatGPT and Codex in the European Union will begin carrying invisible watermarks.
The watermark is statistical rather than a visible label stamped onto a page. OpenAI embeds a detectable pattern in the choices the model makes while generating text. A reader sees ordinary prose. An authorised detector looks for that pattern and returns evidence about whether the text is consistent with watermarked output. API developers using selected models can turn the feature on, but it remains off by default.
That distinction matters for how widely the signal will appear. European ChatGPT and Codex users are being brought into a regional rollout, although OpenAI hasn’t given an exact date for completion. Developers elsewhere make their own choice. Detector access is also restricted at first to approved researchers and expert organisations, so this isn’t a universal public checker that anyone can use on a student essay, job application or news article.
OpenAI is unusually direct about the limits. Short passages may not contain enough signal. Editing can weaken it. Translation can remove it. Detection cannot establish that the words are accurate, who owns them, who is responsible for them, or how much a person contributed. And the reverse is equally important: failing to detect a watermark does not prove a person wrote the text unaided.
That leaves organisations with a useful but narrow tool. A reliable positive result can support a provenance investigation, alongside account records, document history and the circumstances in which the text appeared. It cannot carry the whole decision. A result should prompt a closer look and a fair chance for the affected person to explain how the text was made. If a school, employer or publisher turns the detector into an automatic guilty-or-innocent machine, the policy will claim much more certainty than the technology provides.
There is still value here. Invisible provenance can travel with text after it leaves the product interface, which a visible badge or download label often cannot do. OpenAI’s implementation will also create evidence about how watermarking behaves at large scale, including the messy reality of people trimming, rewriting and translating text. But the real-world reliability of the European rollout remains under evaluation.
My read is that watermarking is best treated like one forensic clue, not a verdict. It may make provenance checks easier, especially when the original platform context has vanished. It also makes careful process more important, because the people affected by a detection result need decisions based on evidence the signal was never designed to provide on its own.
AWS Wraps Agents in Cloud Controls
That provenance question closes one part of the governance puzzle. The next one is what happens when an agent can act.
AWS has moved Amazon Bedrock Managed Agents powered by OpenAI into public preview. The service gives developers a stateful runtime for agents that can preserve sessions and intermediate results, execute code, use reusable skills and connect to Model Context Protocol servers. It is available through APIs in three United States regions.
The notable part isn’t simply access to an OpenAI model through another cloud. AWS is bundling the operational pieces that become awkward once an agent moves beyond a single prompt. Each agent receives an Identity and Access Management role. Supported consequential actions can be held for human approval. Supported API activity can be recorded in CloudTrail, giving an operator an audit trail through the same tooling already used for other AWS workloads.
For an organisation already running on AWS, that removes a fair amount of plumbing. A developer can test a persistent agent without building every session store, permission boundary, approval step and audit integration from scratch. It also puts the agent inside a familiar security model, where access can be described and reviewed as cloud permissions rather than hidden in application code.
There are firm reasons to keep the experiment labelled as an experiment. This is a public preview, so interfaces, regional coverage and pricing can change before general availability. The underlying AWS resources are billable, and AWS says general-availability pricing may differ. The runtime also creates a stronger attachment to AWS identity, logging and deployment services. That can be useful operationally and costly to unwind later.
The competitive contest around agents is shifting from who can expose a model to who can run one with credible controls. For developers, AWS’s preview makes governed prototypes easier. My judgement is that it is too early for a production commitment, but it is a practical place for AWS-heavy organisations to test whether persistent agents can fit their existing approval and audit practices.
Australia’s Disclosure Deadline
Back in Australia, governance is becoming a dated compliance job rather than a future discussion.
The Office of the Australian Information Commissioner has published resources for a transparency obligation taking effect on 10 December 2026. It applies to covered entities that use personal information in computer-assisted decisions which could significantly affect a person’s rights or interests. The regulator’s wording reaches beyond a program that presses the final button. It can also apply when software does something substantially and directly related to making the decision.
Affected privacy policies need to describe the kinds of personal information those programs use and the kinds of decisions they make or materially inform. The regulator has released a fact sheet, a supplement for government agencies and a decision flowchart after receiving 90 consultation submissions. Whether a particular system crosses the significant-effect and personal-information thresholds still depends on the facts.
The hard part for an organisation is likely to be discovery. A neat register of systems called ‘AI’ won’t reveal every rules engine, scoring model or automated workflow that contributes to a consequential decision. Someone has to trace how personal information moves through operational systems, identify where software shapes an outcome, and connect that work to the privacy policy people can actually read. A generic line saying the organisation may use artificial intelligence will not describe the kinds of information and decisions the obligation asks for.
For people affected by automated decisions, the benefit is visibility. They should have a better chance of knowing that software materially informs a decision and what information it uses. For organisations, the immediate consequence is a deadline a little over two months away.
My assessment is that the inventory is the real work and the policy update is the final output. Organisations that begin with wording may produce a tidy disclosure that misses systems operating in the business. Starting with the decision path gives privacy, legal and operational owners something concrete to assess before 10 December.
Voice Models Cut the Waiting Time
Now for a change people will hear rather than read: voice systems are getting quicker across more languages.
Microsoft has released MAI-Transcribe-2-Streaming, alongside MAI-Voice-2.1 and a lower-cost Flash variant. The transcription model is designed for real-time applications and, according to Microsoft, begins returning provisional text just over 100 milliseconds after receiving audio. It can continuously detect among 60 languages, which is useful in conversations where a speaker switches language rather than selecting one at the start.
That provisional text is important. A voice agent doesn’t need to wait for a finished sentence before it starts understanding the exchange. Shaving that delay can make turn-taking feel less mechanical, although Microsoft’s latency and quality figures are company claims and developers still need to test the conditions their users bring: Australian accents, background noise, cheap microphones and interrupted speech.
The introductory transcription price is US$0.54 per audio hour through the end of 2026. The two voice models cover 23 languages and 26 locales, priced at US$22 and US$15 per million characters. They are available through Microsoft Foundry and other listed platforms. Those numbers make experimentation accessible, but the transcription offer is explicitly temporary and comparative results come from Microsoft or vendor-selected evaluations.
The voice models also support cross-language voice cloning with consent controls. That could let an approved voice speak another supported language while retaining recognisable characteristics. It also raises the stakes for proving that consent was granted and remains valid. A control in the product is useful only if a developer can audit how it was applied in the surrounding workflow.
For builders, lower-latency multilingual speech makes genuinely conversational agents more achievable now. I’d treat the launch as a strong reason to prototype, not a reason to skip evaluation. Cost after December, performance in real rooms and the enforcement of voice consent will determine whether a polished demonstration survives contact with production.
FortiMail Patching Cannot Wait
There’s also a security update where the correct timetable is much shorter.
Cyber authorities say CVE-2026-104286 in FortiMail is being actively exploited, and the vulnerability has been added to the United States Known Exploited Vulnerabilities catalogue. The affected product sits directly in the email path, so an exposed gateway is an attractive target as well as a security control.
The flaw is a path-traversal issue. Through crafted HTTP or HTTPS requests, an unauthenticated attacker can write files outside the location the application expects. That combination of remote access, no authentication and file-writing capability explains the urgency, even though the advisory does not say how many systems have been compromised, which organisations were hit or the full shape of the observed attacks.
Affected releases include FortiMail 8.0 before 8.0.2, version 7.6 before 7.6.7 and version 7.4 before 7.4.9. Administrators still on the 7.2 branch are advised to move to 7.4 or later. The Canadian Centre for Cyber Security explicitly tells administrators to apply the necessary updates.
For operators, the job is to identify the deployed branch, confirm whether the management surface is exposed and move to a fixed release immediately. Active exploitation changes the calculation: a maintenance window planned around convenience leaves time for an attacker who is already using the bug. After upgrading, the limited public information about victims means administrators cannot assume the absence of a published campaign means their system was untouched. Existing incident-response and review processes still apply.
The useful organisational lesson is quite plain. Security appliances need the same asset inventory, internet-exposure review and rapid patch discipline as public application servers. My view is that a gateway’s security label can create false comfort; its position in the network makes prompt upgrades more important, not less.
Samsung’s Billion-Dollar Infrastructure Bet
Zooming out from one exposed appliance, the physical build-out for AI is pulling whole industrial groups into the same project.
Six Samsung affiliates have announced a combined US$1 billion investment in Helix Digital Infrastructure, a company established by KKR to bring data centres, power, transmission and fibre together for AI deployments. Samsung Electronics is providing US$500 million, with five affiliated companies contributing the other half.
Samsung says Helix launched in June 2026 and is led by former AWS chief executive Adam Selipsky. Its other founding investors include KKR, Kuwait Investment Authority, NVIDIA and Vistra. The venture’s proposed shape fits the constraint facing large AI projects: accelerators are only one part of the system. A site also needs electricity, cooling, network capacity, construction and a way to deliver the whole facility.
Samsung can approach that stack through several businesses rather than as a chip supplier alone. Its announcement points to semiconductors, cooling, construction, data-centre capability and batteries as pieces of an integrated platform. That could give the group a wider role in projects where securing power and a usable site is as difficult as buying compute.
There is a large gap between the strategic picture and delivered infrastructure. The announcement gives no committed computing capacity, construction timetable, project locations, customer deployments or delivery dates. Descriptions of expected benefits come from the company, and committed capital is not a functioning data centre.
For organisations planning large AI deployments, the signal is that suppliers are trying to bundle more of the physical stack. My reading is that power and integrated facilities are becoming strategic products in their own right. Helix may put Samsung in a useful position, but the figures that would show execution—capacity, locations, customers and dates—are still missing.
AI Joins Familiar Cyberattacks
The cyber threat itself is changing too, though perhaps less theatrically than some predictions suggest.
Microsoft’s 2026 Digital Defense Report describes threat actors using AI during reconnaissance, social engineering, malware and exploit development, and activity after a compromise. Its central observation is that most malicious use it has seen accelerates parts of established attack workflows. It is not a complete replacement for those workflows with wholly autonomous attacks.
That framing helps security leaders put effort in the right place. Faster research can improve a phishing attempt. Code analysis can help find a vulnerability. Generated material can reduce the time needed to tailor social engineering. Defenders can use similar tools to analyse code and investigate threats, so the technology does not confer a one-sided advantage. The findings reflect Microsoft’s own telemetry and investigations rather than a complete census of malicious AI use around the world.
The report also calls out agent identities, permissions, revocation, prompt injection, memory and tool access as enterprise security concerns. An agent that can search internal systems, call tools or change data is a privileged system participant. Its identity needs a defined owner, its access should be limited to the job, its actions need monitoring, and an operator needs a reliable way to revoke it.
I think that is more useful than waiting for an exotic autonomous attacker. Organisations already understand identity management, least privilege and incident logs. Applying those controls to agents addresses the systems being deployed now and the familiar attacks being made faster, even while the more dramatic scenarios remain uncertain.
What Changes for You
One experimental release is especially relevant if you like connecting AI software to things you can hold.
Meta has published open-source ESP32 firmware and a Linux device SDK for Muse. Builders can connect homemade displays, sensors and actuators, or a Raspberry Pi-class Linux computer, to the hosted agent. The code is predominantly under the Apache 2.0 licence, so the device side is available to inspect and modify. Every gadget still needs a Meta-issued token and pairing through the Muse mobile app.
The practical change is that a developer can prototype a physical Muse interface using common hobbyist hardware instead of designing the entire connection layer. A sensor can provide input; a display or actuator can expose an output. On Linux, though, Muse can run shell commands and read or write files with the permissions of the installation account. If that account has sudo access, the exposure includes that elevated capability.
Meta’s own documentation says the pairing process lacks manufacturer verification and cannot stop an active person-in-the-middle attack. Pairing should happen only on a trusted network. The repository does not state a launch date or a support commitment, and describes the kit as experimental and used at the developer’s own risk.
For a builder, the sensible boundary is a dedicated, unprivileged account on an isolated test device, with no files or credentials you cannot afford to expose. The open code makes the device connection easier to examine, but it does not remove dependence on Meta’s token, mobile app or cloud agent. That trade-off is the difference between a fun hardware prototype and quietly giving a hosted agent broad control of your everyday machine.
You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.
Sources
Reporting behind this episode.
- openai.com/index/eu-text-provenance
- aws.amazon.com/about-aws/whats-new/2026/09/bedrock-managed-agents-preview
- oaic.gov.au/news/media-centre/new-resources-on-transparency-for-use-of-ai-and-automated-decision-making
- microsoft.ai/news/our-first-streaming-transcription-model
- cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-989
- news.samsung.com/global/samsung-to-invest-usd-1-billion-in-ai-infrastructure-company-helix
- microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report
- github.com/facebookincubator/muse-gadget-sdk/blob/main/README.md
- github.com/facebookincubator/muse-gadget-sdk/blob/main/linux/README.md