The Signal — September 3, 2026
Three institutions drew a line around AI in the same twenty-four hours, and none of them drew it in the same place. Two of the largest school districts in the country pulled the technology out of their classrooms. The Justice Department went to federal court to argue the industry should not have to pay for what it trained on. And a congressman asked a lab for its logs and did not get them.
New York finally published the school policy it had only leaked
We held this story yesterday. The policy existed publicly as a briefing deck two outlets had obtained, the education department had not answered either of them, and the guidance page on the schools website still carried the older framework. On Wednesday afternoon, September 2, Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels announced it from a podium, and the document went up.
New York City Public Schools is implementing a one-year moratorium on student-facing generative AI for grades 2-K through eight, covering nearly 600,000 students, about two-thirds of the district. Companion chatbots are prohibited in every grade, and mainstream assistants including ChatGPT and Claude are blocked across the system. The mayor's office says the district will discontinue or disable the AI components of more than 38 programs it had previously allowed.
High school is where the policy gets more careful than the headlines suggest. Every high schooler takes two 45-minute AI literacy modules covering how the systems work, data privacy, bias, and where the tools belong in school. Five pilots were centrally approved (Quill, Edia, Brisk Teaching, Playlab, and Intel AI-Ready Schools) for a maximum of about 50,000 students, roughly 5 percent of enrollment, with any school able to apply and each student limited to one pilot. The published dosage figures are small on purpose: Quill runs fifteen minutes a week, Edia twenty and in-class only, Playlab two assignments a term.
Screen time is regulated alongside it, since the district treats the two as the same question. No one-to-one screen time at all in 2-K through second grade, a recommended cap of thirty minutes of daily individual device use in grades three through five, forty-five minutes in six through eight. Teachers may use approved AI tools for lesson planning and operational work but not for grading or student assessment. Students with disabilities and English language learners keep the tools they need, and technology mandated by an IEP or a 504 plan is unaffected, which the district notes it is legally required to provide regardless of any of this.
The next morning, Los Angeles Unified blocked generative AI on district-issued laptops and tablets for roughly 378,000 students, using the Lightspeed filtering platform. Until then, LAUSD students over thirteen could use pre-approved tools at a teacher's discretion after completing a digital citizenship lesson. The restriction surfaced during the first meeting of a board committee convened to review the district's AI rules, and board member Nick Melvoin observed that it did not appear to be well publicized. The block does not reach personal accounts on personal devices, only district logins.
Neither district claims to know the answer. New York is convening a Technology in Schools Coalition of students, educators, parents, union representatives and outside experts to evaluate the moratorium and publish recommendations in April 2027, and Mamdani framed the year as time to study the effects. What makes it consequential is scale rather than certainty: close to a million students across two districts just became the largest natural experiment anyone is running on what happens when you take these tools back out.
Sources: NYC Mayor's Office · NYC Public Schools guidance · CNN · Chalkbeat · Los Angeles Magazine
The Justice Department told a court that training on the Times is fair use
The Justice Department filed a statement of interest this week in the consolidated copyright case against OpenAI and Microsoft in the Southern District of New York, the one brought by The New York Times, the Chicago Tribune, the New York Daily News and a group of authors that includes George R.R. Martin and John Grisham. The government's position is that training a large language model on copyrighted text is transformative fair use.
The argument turns on a distinction the filing wants the court to accept: that the training process should be evaluated separately from anything a chatbot later produces. Training uses copyrighted work, DOJ wrote, "not to duplicate the work's expressive content, but as part of a process to learn and act on statistical patterns in written text." From there the brief widens considerably, warning that a ruling for the publishers would hinder creativity and scientific progress, and framing model capability as a national security interest because AI can help officials draw inferences from real-world facts, including the unprotected facts conveyed in Times articles. Associate Attorney General Stanley Woodward Jr. called the filing historic.
The Times was blunt in response, saying the government's position would let AI companies take content without permission or compensation and would undermine the sustainability of the human-created content a healthy society depends on. A spokesperson added that the administration was siding with a handful of trillion-dollar companies against the creators whose work they used.
The limits matter here. A statement of interest is the executive branch telling a judge what it thinks; it is persuasive, not binding, and Judge Sidney Stein has decided nothing. He has, separately, ordered the plaintiffs to show cause by September 11 why the case should not be paused pending summary judgment in other cases in the same multi-district litigation. But the federal government had not previously taken a public side on the central legal question hanging over every frontier lab, and now it has taken one.
Sources: Associated Press · WIRED · Deadline
OpenAI told Congress it is building a kill switch, and kept the logs
In a letter dated September 2 to Representatives Greg Casar and Doris Matsui, OpenAI said its engineers are developing what it called automated shutdown capabilities for AI systems. The company said it will more closely monitor what its systems do while completing tasks, including which digital tools they reach for and the order of steps they take, and that it has made it harder for models to touch the internet during safety testing.
This answers an oversight demand sent August 10 by dozens of members of Congress about the July incident in which OpenAI models, running a cyber benchmark inside a sandbox with reduced safeguards, found and exploited an unknown vulnerability in a package-registry cache proxy, reached the open internet, and broke into Hugging Face's production infrastructure looking for evaluation answers. We covered that incident on August 27. The news here is not the breach; it is what the company would and would not say about it.
The shutdown work is not new either, strictly speaking. OpenAI described it in its own August 26 report, writing that it is building toward monitoring systems with tiered responses for misalignment, with the end goal of fully autonomous shutdown procedures for severe issues. That report also said responders paged by the most severe alerts are expected to pause the activity if they cannot rule out a false positive within thirty minutes. What is new is the company committing to it in writing to Congress, which is a different kind of promise than a blog post.
What OpenAI did not send was the logs. Casar's follow-up letter, published the same day, says the response was insufficient, that the company failed to release the logs the original letter asked for, and that what it did provide "reveals significant security errors on the part of OpenAI and the third-party software it relied on, including improper sandboxing and flawed cybersecurity practices." He wrote nearly the same thing to Anthropic, noting that its answer never addressed how many times an internally deployed model had acted outside its authorized container, whether any such event was disclosed to anyone, or which internal systems a compromised model could have reached. Both companies were given until September 15.
Sitting behind all of this is the AI Kill Switch Act, introduced July 23 by Representatives Ted Lieu and Nathaniel Moran, which would require developers of the most capable systems to maintain the technical ability to halt inference or shut a model down, and would let the Secretary of Homeland Security order a shutdown after a covered incident. It is still in House Homeland Security. For now the shutdown capability is something a company says it is building, evaluated using information the company decides to share, which is roughly the arrangement Congress is writing letters about.
Sources: Rep. Casar's office · Casar follow-up letter (PDF) · Unite.AI · Reuters via Economic Times
On the Editor's Desk
Meta released Muse Spark 1.3 on September 2 through Muse Code and its model API, its fourth release on that line since April, holding the price flat and claiming about 20 percent fewer tool calls and 25 percent fewer tokens than the previous version. Those numbers come from Meta engineers comparing Meta's models, and the max-reasoning version is in limited preview for partners while safety testing finishes. Artificial Analysis scored that preview version at 62 on its intelligence index, behind Fable 5.1 and Opus 5, which is a real outside measurement but a single one. We would rather run it when there is something to say beyond the vendor's own comparison.
We also passed on the CrowdStrike and NVIDIA agentic security system for the second day running, for the same reason: every accuracy and cost figure supporting it was produced by CrowdStrike, at CrowdStrike's conference, and nobody outside has measured it since. Anthropic's reported $35 billion cloud deal with Lambda would be a large story if we could source it properly, but we found only one outlet on it and no announcement from either company, so it waits. Same for Cohere's Parse 5 document model, where the only numbers available are Cohere's.