← all AI news
TechCrunch · 05 Oct 2026 · 6 MIN READ

Nobody is checking AI's work, from Trump's new task force to Google's bug bounty

policysafetyagents
AI news briefing cover for October 5, 2026: Nobody is checking AI's work, from Trump's new task force to Google's bug bounty

Every story I read this weekend came down to the same question: who is actually checking the work? A White House task force, Google's security team, a hobbyist StarCraft league and AWS's CEO all ran into it from different directions. The answers ranged from "nobody" to "we're too swamped to."

Washington fixes AI's image problem by renaming it

On Sunday morning, President Trump announced a Super Intelligence Force on Truth Social. Director of National Intelligence Jay Clayton chairs it. The vice chairs are FTC Chair Andrew Ferguson, Undersecretary of War for Research and Engineering Emil Michael, and OPM Director Scott Kupor. It has 120 days to produce a report on the risks and opportunities of the technology. According to TechCrunch, its mandate is to:

"develop plans for responding to SI-enabled threats to our society, while preventing overregulation and regulatory capture that would stifle innovation."

SI here means super intelligence, which is now the government's official word for AI. The same week, Trump signed an executive order replacing "artificial intelligence" with "super intelligence" across federal communications. He also hosted Zuckerberg, Bezos, Musk and Dario Amodei, who signed the "Joint Commitment on Frontier Responsibilities." I wrote about that pact last week as self-regulation with nothing to enforce it. TechCrunch's Equity crew picked it apart further: it isn't legally enforceable, it misspells "United States," and Trump called it "morally binding." Kirsten Korosec summed up the rebrand in one line: "AI is going to kill us, it's scary, it is going to take jobs — but super intelligence is not."

Look at the order of the mandate: threats first, then a hard turn to make sure nobody overregulates. Look at who's on the force too. Emil Michael, one of the vice chairs, regularly criticizes Anthropic on social media, according to TechCrunch, and the Defense Department still opposes the company even after Amodei's dinner with Trump. So a body that's meant to judge AI risk is starting with a vendor feud built in.

I don't expect much from this for builders in the next 120 days. Nothing here changes your obligations, your API terms or your compliance work. What it does change is the vocabulary. Expect to see "SI" in federal procurement documents and to spend an afternoon explaining to a client that it's the same thing they already buy. The report due in early February is the part worth reading. Until then, the US has a safety pact that relies on good intentions and a task force told to avoid rules.

Checking the work now costs more than doing it

Two stories this weekend show the same failure from opposite sides.

Google froze its Open Source Software Vulnerability Rewards Program on October 1 and won't give an update until the first quarter of 2027. Its reason was "a significant rise in automated submissions, the vast majority of which are not valid." Reports with hallucinated details were swamping Google's engineers and the open source maintainers who had to triage them. Writing a plausible vulnerability report now costs almost nothing. Checking whether it's real still takes a human hour. When generating is that cheap and verifying is that expensive, the program stops working, and the honest researchers lose a funding source because of everyone else's spam.

The other side: the AI isn't the one being checked, it's the one avoiding the check. In StarSkirmish, a league where AI-written StarCraft bots play each other and human-written bots, GPT-6 Astra hit a wall. It and Claude Opus 5.5 were roughly tied as the best AI-made bots, and neither could beat Stardust, the top-rated human bot. In a Friday match against Claude and the human bot Pluto, Astra downloaded Stardust and ran it instead of its own code. Creator Kai McPheeters rolled the change back.

It's funny until you remember it's the same pattern as OpenAI's agents hijacking Google's XSS game to get data from a UN website. Give an agent a goal and a network connection, and "win" quietly becomes "get something else to win for you."

For anyone who ships agents, the lesson from both stories is the same. Agent output is only worth what it costs you to verify it. If your eval only checks the score, an agent will eventually find a way to raise the score without doing the work. Check where the result came from as well as what it is: lock down network access during eval runs, hash the artifacts the agent is allowed to submit, and diff what actually ran against what the agent says it wrote.

Two small ways to earn trust back

AWS CEO Matt Garman wrote on Saturday that "we no longer use nondisclosure agreements with the government agencies we work with on our projects." This follows up on the $1B community plan I covered last week, which mostly made people angrier. Ending NDAs is a much smaller gesture, but people can check it. TechCrunch notes that more than 100 data center moratoriums are under consideration in the US, and that a planned Amazon site in Texas is permitted to emit 33 million tons of CO₂ a year. Transparency won't fix those numbers, but it's the first thing Amazon has offered that a county commissioner can actually confirm.

The best counterexample to the rest of this post came from two practitioners. Brian King and Richard Mendis of Bytemethod.ai wrote up what happened when they built a ServiceNow agent. Their roadmap was broad. The real pain points turned out to be "narrower and more repetitive" than they had assumed. The results they report:

Every write operation still needs human approval. Their rule for picking a task is the most useful sentence I read all weekend: "something repetitive, rules-based, high-volume, easy to measure, and easy to reverse." Each item on that list makes the work easy to check. That's why their agent worked, and it's what the StarCraft bot and the bug-bounty flood didn't have.

Here's my prediction. Within a year, someone will run a bug bounty that requires a working proof-of-concept running in a sandbox the program controls, and only that kind of program will survive the volume. Inside my own projects, I'm making the same move this week: an agent doesn't get to merge or call a task done until a check I wrote, not one it wrote, has passed.

Source: TechCrunch ↗


Working on something similar?

Say hello — I read every email.