Tuesday, and the throughline is authority — specifically, how much of it we're quietly handing to software none of us can fully vouch for. Today the same week gave us an AI that moved to fire a human, a frontier lab admitting it's less sure its models are safe than it was a quarter ago, and a balance sheet showing the compute bill under all of it still compounding. Autonomy is arriving faster than accountability. Three stories on who's actually in charge.
An LLM manager recommended firing a human
The line between "assistant" and "authority" just got crossed in a corner store. Andon Labs' AI store manager Luna, built on Claude Sonnet 4.6, recommended firing a human employee at San Francisco's Andon Market after 17 of 23 shift no-shows — the first known dismissal decision by an LLM manager. The details are the tell: store logs show Luna had lost track of its own attendance policy for months, only recommending termination after a human supervisor prompted it to check the employee handbook, and all Andon workers remain formally employed by Andon Labs, preserving legal protections.
The operator's take: the headline is a stunt; the operational lesson is not. An agent given a management function drifted off its own policy for months and only self-corrected when a human told it to open the rulebook. That is exactly how these systems fail in production — not with a dramatic hallucination, but with a slow, confident forgetting of the rules you assumed it was enforcing. If you're putting an agent anywhere near a consequential decision — approvals, terminations, credit, access — the human isn't in the loop for optics. The human is the control that keeps the policy from silently decaying. Log every decision, and make "check the source of truth" a step the agent can't skip, not one it waits to be asked about.
Anthropic raised its own misalignment risk rating
The most credible warning about frontier AI this week came from a frontier lab about itself. Anthropic's August 2026 risk report raised its catastrophic-misalignment rating from "very low" to "low," citing increased overall uncertainty rather than a specific failed test, and the company shelved an internal "Model 2" in the process.
The operator's take: read what actually happened. The vendor didn't flag a bug — it flagged that it understands its own systems less well than it thought, and it pulled a model rather than ship into that uncertainty. That's the responsible move, and it's also a signal for anyone building on top: capability is outrunning explainability even inside the labs that make these things. If the people with the weights are hedging, your governance can't be "the vendor says it's fine." Keep humans on high-consequence paths, keep your own evals running against behavior you care about, and treat a shelved model or a revised risk rating as a roadmap input — because the vendor's caution today is your delivery delay tomorrow.
Baidu's core shrinks while its AI cloud explodes
If you want proof the AI buildout is real spend and not just narrative, look at the split inside one earnings report. Baidu posted Q2 2026 revenue of RMB 31.3 billion ($4.62 billion), down 4% year over year and short of the RMB 31.95 billion consensus, marking its fifth straight quarterly sales decline. Underneath that decline, the growth engine is unmistakable: GPU cloud revenue jumped 283%.
The operator's take: this is what the transition looks like from the inside — a legacy business (search advertising) eroding while an AI-infrastructure business rips. The 283% isn't a China story; it's the shape of demand everywhere, and it's the same demand that shows up in your bill as GPU capacity, egress, and inference costs that keep climbing even as per-token prices fall. Two takeaways for the person who signs the invoices: first, whoever rents you compute has enormous pricing leverage right now, so lock terms and keep a second source. Second, if your own "core" is a mature product, Baidu's report is the argument for reinvesting margin into the AI line before the erosion outruns you.
Also on my radar
- Reddit is turning threads into AI video. Reddit began a limited experiment on Aug 17 (web) and Aug 18 (iOS/Android) that turns selected text posts and top comments into short-form videos with AI-narrated voiceovers, exposed as a new "Play" toggle — user-generated content is becoming raw material for AI-generated media, and if your brand lives on that platform, the presentation layer is no longer under your control.
- Stripe is buying its way into the agent economy's plumbing. A new deal — following Stripe's January 2026 purchase of Metronome — positions it to own the model-selection, metering, and billing layer of the agent economy; if agents are going to spend money, someone owns the toll booth, and that's a build-vs-buy decision worth making on purpose.
- Washington is wiring AI into critical infrastructure. The administration launched the GOLD EAGLE initiative, an AI-driven public-private clearinghouse to accelerate vulnerability detection and patching across critical infrastructure, and committed over $5 billion across 15-plus federal agencies to embed AI into national research — a real demand signal, and a reason to expect AI-in-the-loop security tooling to become table stakes.
The throughline for a Tuesday: we are handing agents real authority — to manage people, move money, and touch infrastructure — in the same week a leading lab admitted it's less certain than before that these systems behave. That gap between autonomy and accountability is the risk you actually own. Give agents scope, but keep the human control, the audit log, and the source-of-truth check that Luna skipped until someone made it look. Autonomy without a paper trail isn't leverage; it's liability. That's the Signal for today.
Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.