AI Is Helping Price Your Big Mac, Plus 3 Stories
Artificial intelligence is getting very good at answering questions. It is also getting increasingly comfortable sitting behind decisions that used to be made by people with spreadsheets, gut instinct, or both. Today’s lead is a pretty literal example: McDonald’s is using an AI-assisted pricing system to recommend what individual restaurants should charge.
McDonald’s AI pricing is getting much more specific
Reuters reports that McDonald’s has built a proprietary pricing engine that analyzes millions of transactions and recommends menu prices for individual U.S. restaurants. The system looks at things such as local competition and what customers in a particular market appear willing to pay. Franchise owners still technically set their own prices, but several told Reuters that McDonald’s closely tracks whether they follow the recommendations and can put pressure on operators whose pricing drifts too far from the model.
There are two things worth separating here because they are easy to mash together into one much scarier headline. This is algorithmic pricing: software is analyzing a market and recommending a price. Reuters’ reporting does not establish that McDonald’s is looking at your personal purchase history and charging you a different price from the person behind you in line. That would be personalized pricing, and it raises a different set of privacy and fairness questions.
But location-level pricing still matters. Anyone who has stopped at two highway exits and wondered why the same meal costs noticeably more at one of them already understands the basic idea. What’s changing is the precision. A pricing model can chew through far more transaction history, competitor data, traffic patterns, and demand signals than a restaurant manager ever could. It can also recommend changes much more often.
That doesn’t automatically make the system bad. A franchisee trying to keep a restaurant profitable has always had to answer the question, “What will this market bear?” The uncomfortable part is that software can make that question vastly more efficient. If the same technology that finds the lowest sustainable price can also find the exact point where customers grumble but still buy the fries, businesses have a very strong incentive to discover where that line is.
For consumers, the useful takeaway is simpler than the AI hype: menu prices may increasingly reflect what an algorithm thinks a specific local market will tolerate. For small businesses, this is also a preview. Pricing software that once made sense only for airlines, hotels, and enormous retailers is moving down-market quickly. The technology is becoming ordinary. The governance around it is not there yet.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
An appeals court just made an important AI copyright ruling
The Third U.S. Circuit Court of Appeals has upheld Thomson Reuters’ win against Ross Intelligence, a former legal-research competitor that used material derived from Westlaw to train an AI-powered legal search system. Reuters calls it the first U.S. appeals-court ruling in the current wave of copyright cases over AI training.
The detail that matters is what Ross actually copied. Westlaw includes “headnotes,” short summaries of legal points written by Thomson Reuters editors. Court opinions themselves are public law; those editorial summaries can contain copyrightable expression. The lower court concluded that Ross’ use of the headnotes to help build a competing legal-research product was not fair use, and the appeals court has now affirmed that result.
Do not turn that into “an appeals court ruled AI training is illegal.” It didn’t. Ross was building a directly competing legal-search product, and the system at issue was not a ChatGPT-style generative model. Fair use is intensely fact-specific. A model trained on books, photographs, source code, or public web pages can present different questions about purpose, transformation, amount copied, and market harm.
There is another limitation today: the appellate court’s reasoning is still under seal. We know the judgment was affirmed; we do not yet have a public opinion explaining how broadly the court framed that decision. That makes this important, but not permission to pretend every unanswered AI copyright case was quietly decided overnight.
Australia wants a closer look at how banks use AI on customers
Australia’s corporate regulator is opening a formal review of how banks are using artificial intelligence in customer interactions and decision-making. Reuters reports that the Australian Securities and Investments Commission is asking about current and proposed AI use cases and the potential impact on customers, including lending and other decisions that can materially affect people’s finances.
This follows months of broader work by ASIC and the Australian Prudential Regulation Authority on frontier-AI risk. Their recent roundtables with more than 600 people across the financial system kept coming back to some very unglamorous fundamentals: identity controls, patching, backups, third-party risk, recovery planning, and knowing which systems are actually critical.
That’s useful framing because “AI in banking” can sound abstract until the software helps decide whether someone gets a loan, flags an account as suspicious, talks a customer through a financial problem, or is trusted with enough access to move money. At that point, model quality is only part of the problem. You also need an answer for who reviews the decision, how errors are challenged, what data the model saw, and what happens when the automation moves faster than the people supervising it.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Orkes Conductor has a nasty unauthenticated RCE — and attackers are trying it
If your business runs Orkes Conductor or the open-source Conductor workflow engine, this one is actionable. CVE-2026-58138 affects versions from 3.21.21 through 3.30.1 and can let a remote attacker execute operating-system commands without authenticating first. Version 3.30.2 contains the fix.
The mechanism is worth understanding because it is exactly the kind of bug that hides inside “flexible” automation features. Conductor supports workflow tasks that evaluate JavaScript or Python using GraalVM. Vulnerable versions gave those evaluators unrestricted host access. In plain English, code that was supposed to calculate something inside a workflow could reach out into the underlying Java environment and, from there, the operating system. Combine that with an API that open-source deployments can expose without authentication and you have a very bad chain of assumptions.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Security reporting tied to Fortinet telemetry says exploitation attempts are occurring in the wild. One important qualification: this vulnerability is not currently in CISA’s Known Exploited Vulnerabilities catalog, so don’t cite CISA as confirmation of exploitation. The active-attack evidence is coming from vendor and security-research telemetry.
If you run Conductor, upgrade to 3.30.2 or newer now. Then check whether the workflow API was reachable from the internet, whether authentication was actually enforced in front of it, and whether the Conductor process spawned unexpected shells or processes. Patching closes the hole. It does not retroactively prove nobody used it while the door was open.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: Inside McDonald’s push to have AI price your Big Mac
- Reuters: U.S. appeals court upholds Thomson Reuters’ AI-training copyright win
- Third Circuit docket: Thomson Reuters v. Ross Intelligence
- Reuters: Australian regulator to review banking-sector AI use
- ASIC/APRA: Frontier AI awareness must turn to action
- GitHub Advisory Database: CVE-2026-58138
Photo by Ryan Collins on Unsplash.

FTC AI Agent Investigation Opens as Risks Grow
October 1, 2026 @ 8:28 am
[…] Yesterday I wrote about McDonald’s using AI-assisted pricing to recommend local menu prices. Today the algorithmic-pricing argument has moved from burgers to rent — and into federal court. […]