Back to the show

AI & Tech Daily

California Puts a Human Check on Workplace AI

19:07

California sets a human-review floor for workplace AI, while Google's latest security analysis shows why a rising vulnerability count is the wrong metric for patching. We also examine Google's Data Agent Kit, Reddit's retreat from RSS and its public API, Cohere's two-tier Embed 5 release, Apple's targeted CoreGraphics patch and Australia's six new quantum demonstrators. In What Changes for You, GitHub's dynamic Copilot workflows offer developers a code-defined way to run and review multi-agent work, with public-preview caveats.

Full transcript

Read the episode.

I'm Jesse Owen. This is AI and Tech Daily.

A Human Check on Workplace AI

In California, an employer can use AI to inform a decision about your job. It can no longer let that system make the final call on discipline or dismissal by itself.

Our main story today is California's new workplace AI package and what a practical floor for human accountability means for employers and workers. Governor Gavin Newsom signed the laws on 30 September 2026. Among the measures named in the official announcement are Senate Bills 947 and 951, and Assembly Bills 1331 and 1883.

The central rule is straightforward: an employer cannot rely solely on an automated decision system when making a disciplinary or termination decision. That word, solely, matters. The laws don't prohibit employers from using AI in employment processes, and they don't pretend that a person touching a decision automatically makes it fair. They do establish that a consequential decision about someone's livelihood cannot be handed entirely to software.

The package also requires notice when an AI system causes a mass layoff, relocation or termination. That brings automated decision-making into a process where timing, documentation and responsibility already carry legal weight. Employers need to know which systems are influencing those events, who reviews their output and how the required notice is issued. If an organisation can't answer those questions, the compliance problem begins well before the final decision.

Surveillance is part of the package too. The new measures restrict workplace technology that tries to infer a worker's emotional state from biometric data. The concern is that software can turn a biometric signal into an apparent measure of someone's internal state, then feed that judgement into the workplace. California is now placing a boundary around that use in employment.

For organisations operating in California, the practical work is an inventory. Which automated systems touch hiring, performance, discipline, termination, workforce planning or surveillance? What data do they use? Where does a person review the result, and is that review documented well enough to show it was meaningful? Then there is the notice process for AI-linked mass employment actions. A policy saying that a human is involved won't be much help if the operational record shows the software effectively made the decision.

There is a difference between a human review and a human rubber stamp. A defensible process needs a reviewer who can question the system's recommendation, consider the circumstances and reach a different decision. That makes the point of review, the person responsible and the path for overriding the system as important as the model's output.

My read is that California has set a useful minimum: someone remains accountable when AI affects a high-impact employment decision. The trade-off is more compliance work for employers using automated decision tools, particularly those that have grown across departments without a central register. This is a state framework, not a nationwide United States rule, and enforcement practice and court interpretation still have to develop. Even so, the direction for California employers is concrete now. Human review has to be part of the process, not a label added after the system has already decided.

The Vulnerability Queue Gets Faster

That closes the workplace story; the next pressure point is how security teams choose what to fix when the queue keeps growing.

Google's Threat Intelligence Group published its analysis on 30 September 2026. It says monthly vulnerability disclosures rose from 5,045 in January to 10,740 in August. Over the same January-to-August period, vulnerabilities observed being exploited averaged 18 a month, up from 10.5 a month in 2025. Those are two related increases, but they don't support the same response.

Zero-day exploitation rose more modestly, from an average of eight a month in 2025 to 11 a month during the first eight months of 2026. A zero-day is a flaw exploited before a fix is available or before defenders have had a reasonable chance to respond. Google's interpretation is that the bigger source of growth is rapid weaponisation after flaws are disclosed, rather than a comparable surge in previously unknown vulnerabilities. The gap between disclosure and attack is getting more important.

There is also a warning against treating the total CVE count as a risk score. Only 0.23 per cent of vulnerabilities disclosed in 2026 were observed in active exploitation. Google points to about 5,000 Linux kernel CVEs assigned from January through August with no exploited-in-the-wild zero-days observed among them. Automated discovery and assignment can make the list much longer without making every entry equally urgent.

AI's precise contribution is difficult to isolate. Public CVE records don't have standardised metadata saying that a flaw was discovered with AI, so Google used heuristics to identify some AI-assisted findings. Vendor disclosure cycles and automated CVE assignment also affect the totals. This is observational analysis, not a clean experiment showing how much of the increase belongs to AI.

The useful conclusion for security leaders is operational. Patch counts are a poor measure of progress when exposure and active exploitation are so uneven. Teams get more value from identifying exposed systems, watching evidence of exploitation and pushing high-risk fixes quickly than from treating ten thousand disclosures as ten thousand equal emergencies. AI-assisted analysis may be compressing time for defenders and attackers alike. That makes fast, threat-informed triage more valuable than an indiscriminate race to clear the largest possible number of tickets.

Agents Reach Live Cloud Data

Security triage is about narrowing access and attention. Google's next release puts that same discipline directly in front of developers using coding agents.

Google's Data Agent Kit reached general availability on 30 September 2026. It is a set of Model Context Protocol tools and agent skills that lets supported coding agents inspect and operate Google Cloud data services. Model Context Protocol, or MCP, is a standard way for an AI tool to connect to external systems through defined capabilities rather than bespoke prompt plumbing.

The kit works with environments including Codex, Claude Code, VS Code-compatible editors, Cloud Shell and Cloud Workstations. Google says it connects agents to more than 15 services. General availability adds BigQuery Graph, Bigtable and Managed Service for Apache Spark. In practical terms, a coding agent can receive live schema details, query context, job logs and resource information without a developer building a separate integration for each service.

The control boundary is Google Cloud Identity and Access Management. Operations run with the user's permissions, or with those of an impersonated service account. Existing row-level and column-level controls still apply. That is sensible, but it also means a broadly privileged identity gives the agent broad reach. A mistaken query or resource operation doesn't become harmless because it came from an assistant.

There is no additional charge for the kit itself. Standard charges still apply for the Google Cloud services it invokes, so an agent can generate real usage as it inspects data or runs work. Accuracy and operational safety will depend on the connected agent, the task and the permissions around it.

For developers already working in Google's data stack, the gain is less integration work and better context at the point of coding. My practical judgement is that the kit becomes more useful as permissions become more specific. A narrowly scoped service account can make live agent access productive and reviewable; an all-powerful account turns convenience into an avoidable production risk.

Reddit Closes Two Open Doors

Now for a change that removes access rather than adding it, with deadlines that arrive sooner than they may first appear.

Reddit has set dates to retire both RSS support and its remaining public Data API. RSS ends on 13 November 2026. New requests for public API access stop on 31 October, and access removal begins on 12 January 2027 for apps and users that haven't registered or engaged with Reddit. The remaining public API access ends in March 2027 as the company moves developers to its Developer Platform.

These changes affect different groups. Developers maintaining bots and integrations have a migration job. Researchers, social-listening services and AI products lose a familiar route to public Reddit data unless they can use the new platform or arrange another supported or commercial path. RSS users face the most abrupt shift because RSS is a simple open-web format that works outside a platform's own application environment.

Reddit says more than 14,000 apps and bots have registered for the Developer Platform. It is also offering a one-million-US-dollar migration program, including one-thousand-dollar payments for eligible apps that migrate successfully. That may help smaller developers cover some work, but money isn't the only question. An integration can migrate only if the new platform exposes the capabilities it needs.

For moderator alerts, Reddit has recommended a relay built on the Developer Platform in some cases. TechCrunch reports there is no replacement for RSS feeds consumed outside a moderator's own community. That distinction matters: a purpose-built moderation workflow is not equivalent to a general feed that a user, researcher or service can read with any compatible client.

Reddit gains more control over automated access, including the scraping and data use that have become commercially important during the AI boom. Developers gain a supported platform, but accept its permissions, runtime and future rules. It remains unclear how much existing bot, moderation and research functionality can be reproduced there.

My take is that maintainers shouldn't treat March 2027 as the only deadline. The registration cutoff and January access removals create earlier failure points. The larger consequence is another piece of the open web becoming platform-dependent: technically cleaner for the platform to govern, but harder for outside tools to use without ongoing permission.

One Vector Index, Two Retrieval Speeds

The access question looks different inside an AI stack, where the constraint is often the cost and speed of every search.

Cohere released Embed 5 Pro and Embed 5 Fast for general availability on 30 September 2026. Embedding models turn text or images into numerical vectors so a retrieval system can find material with similar meaning. Those vectors often sit behind enterprise search and retrieval-augmented generation, where an AI system looks up relevant source material before it answers.

The useful design choice is that Pro and Fast share an embedding space. A team can index its corpus with Pro, then query that index with either Pro or Fast without rebuilding it, provided the output dimensions match. That gives retrieval engineers a way to spend more compute on the less frequent indexing step, then choose quality, latency or cost at query time.

Both tiers support text, images and fused inputs, more than 100 languages, a 128,000-token context window and output dimensions from 256 to 2,048. Cohere prices text at 12 US cents per million tokens for Pro and eight cents for Fast. Image pricing is 40 US cents per million tokens for either tier. Availability includes Cohere's API and Model Vault, Microsoft Foundry, Amazon SageMaker and private self-hosting.

There are two cautions. Performance and throughput comparisons were run or presented by Cohere, and at least one evaluation set it cites is internal. Independent validation across real customer corpora isn't available yet. And a shared vector space is convenient partly because both models come from the same vendor family; that convenience creates coupling if a team later wants to switch providers.

For retrieval developers, the release makes a sensible architecture easier: build one index, then select the query tier for each workload. I would test the choice against the organisation's own documents and queries, because a small price difference means little if retrieval quality drops on the material people actually need. The flexibility is real, but the benchmark decision still belongs in your own corpus.

Apple Fixes an Exploited Graphics Flaw

A quick but important security note now, especially for anyone handling sensitive files or communications on Apple devices.

Apple released iOS 26.7.1 and iPadOS 26.7.1 on 28 September 2026 to fix CVE-2026-86950. The flaw is an out-of-bounds write in CoreGraphics, the system framework involved in drawing and processing graphics. A maliciously crafted file could trigger arbitrary code execution, meaning the attacker may be able to run code on the device.

Apple says the vulnerability may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27. The company hasn't disclosed how many people were affected or described the wider exploit chain. Canada's Cyber Centre says the United States Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue on 29 September. It also lists patched releases across iOS, iPadOS, macOS, watchOS and visionOS.

The affected mobile range includes iPhone 11 and later, along with specified generations of iPad Pro, iPad Air, the standard iPad and iPad mini. Narrow targeting can make a flaw sound remote, but it also tells us this vulnerability class has moved beyond a theoretical proof. For users and administrators, the judgement is easy: install the available operating-system updates, with particular urgency on devices exposed to sensitive documents, messages or media. It is a low-cost response to a flaw linked to real exploitation.

Quantum Projects Move to Demonstration

From a patch you can apply now to technology that still has to prove itself outside the lab.

The Australian Government announced 12.3 million Australian dollars on 2 October 2026 for six projects moving from feasibility studies into the demonstrator phase of the Critical Technologies Challenge Program. Demonstrator is the important word. These projects now have backing to build and test application-focused prototypes; the announcement doesn't establish that any of them is ready for production or commercially viable.

Silicon Quantum Computing will receive 3.6 million dollars. It plans to integrate its quantum hardware with Schneider Electric AI models for energy forecasting and better use of renewable energy. The other demonstrators cover grid timing, health diagnostics, border inspection, livestock monitoring and transport planning. That spread gives the program several operational settings in which to test whether the underlying technology can deliver a measurable advantage.

For Australian quantum researchers and companies, the funding creates a bridge from a feasibility result to something a prospective user can examine. Energy, health and biosecurity organisations may get evidence from working demonstrations rather than another set of broad claims. They are not receiving deployable systems yet, and the announcement provides no results on technical performance, scalability or commercial cost.

I think that is the right standard for reading the news. Quantum combined with AI can attract more expectation than evidence. The public value here is the chance to test local research against concrete problems such as forecasting and grid operation. Success should be judged by what the demonstrators show: whether they work reliably, whether they outperform practical alternatives and whether anyone can afford to operate them at useful scale.

What Changes for You

One release from 1 October 2026 is available to working developers now, and it changes how recurring agent jobs can be put together.

GitHub has launched dynamic workflows in public preview for Copilot CLI, the GitHub Copilot app and the Copilot SDK. The feature lets an extension combine deterministic code with one or more agent-driven stages. Those stages can run in sequence or in parallel, pass structured outputs, ask subagents to verify findings and pause when a person needs to provide input or review a result.

That opens a practical middle ground between a conventional script and a long prompt. A release check could keep its fixed commands in code, give an agent the judgement-heavy review step, then require approval before anything consequential proceeds. The same pattern could be used for incident response or repeated research. Because the stages and outputs are explicit, a developer has a better chance of seeing where a run failed than when everything is buried in one conversational request.

Dynamic workflows are available on all Copilot plans. The Copilot app requires no setup. Copilot CLI users need the latest version and must enable experimental features. The major limitation is maturity: GitHub labels the release a public preview and says it is subject to change. Production stability and long-term API compatibility haven't been established. There is also platform dependence because these workflows run inside GitHub's extension environment.

For developers already using Copilot, the immediate opportunity is to encode a recurring procedure as a reusable program with observable stages. My view is that the best early candidates are workflows where deterministic checks already exist and agent judgement fills a clearly bounded gap. You get repeatability and review without pretending every part of the job belongs in an agent, while accepting that a preview workflow may need maintenance as GitHub changes it.

You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.

Sources

Reporting behind this episode.

  1. gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more
  2. apnews.com/article/1aa4935e3ee79519ae8b2458b2b9ebc1
  3. cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era
  4. itpro.com/security/hacking/vulnerability-disclosures-are-rocketing-but-ai-is-changing-the-types-of-flaw-being-discovered
  5. cloud.google.com/blog/topics/developers-practitioners/data-agent-kit-is-now-ga-bring-google-data-cloud-to-any-coding-agent
  6. reddit.com/r/redditdev/comments/1wubcvf/moving_data_api_apps_to_the_developer_platform
  7. techcrunch.com/2026/09/30/reddit-is-killing-rss-feeds-ending-public-api-access-because-of-ai-bots
  8. cohere.com/blog/embed-5
  9. support.apple.com/en-us/149226
  10. cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-971
  11. minister.industry.gov.au/charlton/media/albanese-government-backs-aussie-quantum-projects-12-million
  12. github.blog/changelog/2026-10-01-dynamic-workflows-in-copilot-cli-and-the-copilot-app