U.S. Proposes AI Incident Alerts With China, Plus 4 Stories
I’m starting with a proposal that sounds modest compared with “pause AI” or “regulate frontier models,” and may be more important precisely because it is modest.
The United States wants a way for Washington and Beijing to notify each other when an artificial-intelligence incident gets serious enough to become a national-security problem.
The U.S. wants AI incident alerts with China — but there is no agreement yet
Treasury Secretary Scott Bessent said Sunday that the U.S. proposed an AI “notification mechanism” during talks with Chinese Vice Premier He Lifeng in New York. The idea would sit inside a broader U.S.-China AI dialogue and cover incidents that rise to the national-security level. Bessent said the goal is more transparency between the world’s two leading AI powers.
That’s worth paying attention to, but let’s not turn a proposal into a treaty. China has not publicly agreed to the mechanism. Chinese state media described the talks as candid and constructive, and the proposal is expected to be considered around President Donald Trump’s meeting with Chinese President Xi Jinping this week.
It also isn’t an agreement to slow AI development. In fact, U.S. officials said AI export controls weren’t part of this discussion. Trump has publicly rejected calls to slow frontier development because he argues that doing so would help China catch up.
So what would this actually be?
The closest useful comparison is probably incident notification between two rivals that don’t particularly trust each other but can still recognize that some accidents are dangerous to both. If an advanced system caused a serious cyber incident or interacted with military systems unexpectedly, knowing whether the other side is looking at an accident, an attack or something in between could matter quite a lot.
That’s a long way from a shared AI regulator, and maybe it goes nowhere. But after a week of AI labs debating whether development itself should slow down, this is a more concrete question: can two competing governments at least agree that some incidents are dangerous enough that silence makes them worse?
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Another UK air-traffic failure disrupted flights this morning
If you’re flying through Scotland, Northern Ireland or northern England today, check with your airline before assuming the schedule on your phone is still the schedule at the airport.
NATS says a technical problem at its Prestwick control center in Scotland has now been resolved, but cancellations and delays are expected to continue through the day. Air-traffic restrictions were imposed while the fault was active to keep traffic within safe operating limits. NATS says airports south of Manchester were broadly unaffected and, importantly, says today’s problem was unrelated to the failure earlier this month.
That earlier incident is why this one deserves more than a shrug. On September 8, a separate software defect in the UK’s National Airspace System contributed to more than 2,000 flight cancellations. NATS’ preliminary report says an extremely specific sequence of events hit a legacy software defect within a millisecond, corrupted flight data and forced restrictions while the system was restarted.
We do not know that today’s failure had the same cause. NATS specifically says it didn’t. At this point, the useful information is simpler: this was an operational technical failure, not evidence of a cyberattack, and affected passengers should use airline channels for current flight status.
Amazon and Meta are fighting over whether an AI agent is allowed to shop for you
Meta launched Muse earlier this month as a personal AI agent that can browse the web, fill forms, connect to accounts and, with approval, make purchases. Meta says Muse runs in a dedicated virtual machine, keeps credentials in protected storage and asks before sensitive actions such as buying something.
Now Amazon has blocked it.
Amazon says Meta did not tell Amazon that Muse would access the store, the agent does not identify itself while browsing, and its behavior raises privacy and security concerns around account data and credentials. People trying to use Muse on Amazon are now seeing a warning that continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.
There are two different arguments tangled together here, and I don’t think we should pretend Amazon is a neutral referee.
One is a legitimate security and trust question. If I authorize an agent to use my account, does that automatically mean the service on the other end has agreed to let an unidentified third-party program operate inside that account? We already have an answer for APIs: services can define permissions, scopes and rules. Agents that imitate a browser make the boundary much fuzzier.
The other argument is commercial. Amazon makes a lot of money from controlling the shopping experience, including advertising, and it has its own agentic shopping tools. It has also fought Perplexity over outside agents accessing Amazon. So “privacy and security” can be true and still coexist with “we would prefer not to let somebody else own the customer interface.”
For ecommerce businesses, this is the part to watch. AI agents are becoming customers, or at least customer representatives. Sites are going to need policies for whether agents are allowed, how they identify themselves, what they can access, what actions require confirmation and what gets logged. “It works in a browser” is not going to be enough of a governance model.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
A forum image bug reached an OpenAI employee’s coding agent
The easiest headline here is “Claude hacked OpenAI.” That’s memorable. It’s also not a very good description of what happened.
Security researchers at Hacktron disclosed how they chained an image-processing vulnerability on OpenAI’s Discourse forum with an OpenAI sign-in problem. The first flaw involved libheif, a library used to process HEIC and HEIF images. A specially crafted image could reach vulnerable native code through the forum’s image-processing path and produce remote code execution.
That was bad enough, but the second step is the part I care about for ordinary businesses. The forum used OpenAI sign-in, and the researchers found that the resulting trust extended too far. They were able to take over ChatGPT and Codex sessions belonging to forum users, including employees.
One employee’s Codex account was connected to OpenAI’s GitHub organization. The researchers say they proved the impact by prompting that compromised Codex account to open a harmless pull request in an internal repository, then stopped without reading sensitive source code.
OpenAI fixed its side of the sign-in issue within roughly 14 hours of disclosure and later paid a $6,500 bounty for that finding. Discourse also patched the image-processing vulnerability; its advisory lists the issue as CVE-2026-32882 and tells self-hosted operators to rebuild the application so the Docker image actually picks up the patched libheif package.
There are two lessons here. The first is ordinary patch management: if you self-host Discourse, make sure you’re actually on a fixed build, not merely assuming an application update replaced every library underneath it.
The second is more interesting. When an AI agent is connected to GitHub, email, Slack, customer data or production systems, compromising the account that controls the agent can inherit the agent’s reach. SSO convenience and agent connectors can quietly turn one account into a very large blast radius.
That isn’t an argument against connecting agents to useful tools. It is an argument for narrow scopes, approval gates, separate trust boundaries and regular inventories of what each agent can actually touch.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Humanoid robots are real. The market is still much smaller than the hype.
The International Federation of Robotics has started counting humanoid robots separately, and Reuters reports that about 7,000 were sold globally in 2025 for industrial and professional-service uses.
Seven thousand is a market. It is not a robot workforce.
For perspective, IFR says 542,000 conventional industrial robots were installed in 2024, while nearly 200,000 professional service robots were sold. Many of the humanoids sold last year went to research organizations and companies working on AI development rather than into ordinary production jobs. Automakers are experimenting with them, but mostly in pilots and small deployments.
Forecasts get much larger very quickly. Bank of America Global Research estimates shipments could reach 90,000 this year and 1.2 million by 2030. Those are forecasts, not robots already walking around factories.
China is showing signs that even regulators inside the country most aggressively pushing “embodied intelligence” want some evidence underneath the enthusiasm. Reuters reports that Chinese regulators are raising scrutiny around humanoid-robot IPOs, particularly where valuations depend heavily on state-backed projects or revenue that may not demonstrate real commercial demand. Unitree’s shares, for example, have fallen sharply from their post-IPO peak.
I’m not dismissing humanoid robotics. A machine designed to work in spaces built for human bodies has obvious appeal. But this is one of those moments where counting deployed machines is more useful than counting impressive demo videos.
The robot future may be coming. It just hasn’t hired millions of people’s replacements yet.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters — Bessent proposes U.S.-China AI safety notifications
- Associated Press — U.S. proposes AI incident alert system in talks with China
- USTR — Ambassador Greer to travel to New York for U.S.-China talks
- Associated Press — Technical issue disrupts flights across northern UK
- NATS — Preliminary report on September 8 technical incident
- Meta — Introducing Muse personal AI agent
- GeekWire — Amazon blocks Meta’s Muse AI assistant
- SecurityWeek — AI-built exploit and sign-in flaw opened path to OpenAI code
- Discourse / GitHub — GHSA-vhm9-85gw-x335: RCE via malformed HEIF file
- Reuters — Humanoid robot sales tally hit 7,000 globally last year
- Reuters — China slows humanoid robot IPO rush as hype outruns reality
- International Federation of Robotics — World Robotics statistics
