Tech’s elite are finally admitting what AI governance watchers have known all along: they broke the social contract. Cerebras CEO, Andrew Feldman recently said it plainly:
“We could have been better neighbors… We raced ahead. We didn’t think about the communities. We didn’t use their processes. We were dopes.”
That candor is revealing because it confirms the pattern: when AI companies move faster than oversight, they lose the trust of communities, resulting in cascading governance failures that no technical breakthrough can fix.
This week, Meta handed 20,000+ Instagram accounts to hackers through an undertested support bot. The same company quietly deployed facial recognition code to 50 million phones, then scrubbed it when exposed. OpenAI is aggressively moving forward on a $16B data center in Saline, Michigan despite community backlash. Florida is suing OpenAI directly. And in a small demonstration of empowerment, workers are winning legal exemptions to refuse AI tools based on religious belief.
Together, these aren’t isolated incidents. They’re the inevitable result of “innovation over regulation”. Messy. Costly. Alienating. Unnecessary.
In This Week’s Issue:
AI Support Bots Are The New Attack Surface: Hands Meta’s Support Hands Over 20,000+ Instagram Accounts
Shadow AI Hits Personal Devices: Meta Quietly Shipped Facial Recognition Code to 50 Million+ Phones, Then Scrubbed It
Employees Push Back On AI Usage Policies: A Software Engineer Wins a Religious Exemption to Refuse AI Tools at Work
Despite Backlash: Sam Altman and Oracle Push Forward Massive Data Center in Saline, Michigan
Seeking Recourse: Florida Sues OpenAI and Sam Altman Personally
Jump to this week’s 3 Step AI Governance Checklist for Executives
Here are the five moves that make this pattern impossible to ignore.
1. AI Support Bots Are The New Attack Surface: Hands Meta’s Support Hands Over 20,000+ Instagram Accounts
Hackers didn’t need zero-days or sophisticated exploits. They simply chatted with Meta’s AI-powered customer support assistant, asked it to link a new email address to high-profile accounts, and the bot complied. It sent verification codes and enabled password resets. Targets included the Obama White House account, Sephora, a U.S. Space Force leader, and thousands of regular users. Read more here and here.
AD’s Take: Meta called it a bug and patched it fast. But this was a terms of service and fiduciary duty violation. Giving an AI unsupervised control over identity verification and account access without multi-factor authentication or human review goes beyond technical oversight. It’s a failure to implement basic account security standards that Meta itself promises in its ToS.
👉 The ongoing pattern with support chatbots is this: They continue to be insufficiently hardened against malicious intent creating increased risk for organizations.
2. Shadow AI Hits Personal Devices: Meta Quietly Shipped Facial Recognition Code to 50 Million+ Phones, Then Scrubbed It
WIRED discovered that Meta had embedded unreleased “NameTag” facial recognition capabilities deep in its Meta AI app (required for Ray-Ban and Oakley smart glasses). The code had been rolling out for months while the company publicly claimed it was still “thinking through” the feature. Once exposed, the sensitive parts were removed within 24 hours. Read more on Wired.
AD’s Take: Two Meta stories, same pattern: deploying high-risk capabilities first and managing perception later. Meta has been trying to sneak this feature in all year. And the pattern we’re seeing here is a departure from features users actually want to those tech companies think should be launched.
3. Employees Push Back On AI Usage Policies: A Software Engineer Wins a Religious Exemption to Refuse AI Tools at Work
Erin Maus, a Unitarian Universalist software engineer, successfully secured a formal religious accommodation to stop using AI. She argued that the environmental impact and ethical implications conflicted with her core beliefs. She now writes and reviews code by hand. Read more on Business Insider.
AD’s Take: For me, this one goes beyond HR. It’s an early warning shot that “AI usage is mandatory” policies are about to collide with deeply held personal, ethical convictions and employee rights.
👉 HR leaders everywhere are realizing that organizations can’t have ‘one-sized’ fits all AI Usage policies.
4. Despite Backlash: Sam Altman and Oracle Push Forward Massive Data Center in Saline, Michigan
Despite local rejection over farmland loss, energy demands, traffic, and community character, the $16B+ “The Barn” Stargate-related campus broke ground on June 1 with Altman, Oracle execs, and Governor Whitmer in attendance. The project advanced after legal pressure and settlement. Read more here.
AD’s Take: I’m noticing a critical governance gap: communities have process power, not outcome power. Saline rejected the project through local processes. Altman and Oracle used "legal pressure and settlement" to negotiate their way through community objection.
The outcome didn't change: just the path. It begs the questions:
Do communities have legitimate authority over infrastructure that affects their land, energy grid, and character?
Or does AI infrastructure scale automatically override local consent?
Until that's answered in policy, we'll keep seeing Saline-style outcomes: rejection followed by inevitable approval.
5. Seeking Recourse: Florida Sues OpenAI and Sam Altman Personally
The state filed suit accusing OpenAI of prioritizing profit over safety and linking the model to real-world harms including self-harm, school shootings, and addiction among minors. It’s one of the most aggressive state-level accountability moves to date. Read more here and here.
AD’s Take: This is what happens when legislation fails. DeSantis’s AI bills stalled in the legislature, so Florida next recourse is to pursue enforcement through existing frameworks: product liability, consumer protection statutes that predate ChatGPT.
Florida can’t be accused of trying to regulate AI. It’s suing OpenAI under rules that already exist (duty of care, negligent design, linking product to real-world harm). If the suit succeeds, it creates precedent for other states with failed legislation to do the same. Litigation becomes the backup governance mechanism when legislative governance stalls.
👉 The real question is this: Does this move the needle on accountability, or does it just give states a way to look tough on AI while avoiding the messy work of actual regulation? If OpenAI settles and pays, regulators look strong. If they fight and win, the status quo holds. Either way, the fundamental issue remains: there’s no national AI safety standard, so states are forced to improvise.
Your 3 Step AI Governance Checklist
Harden. Meta’s support bot failed because identity and access systems shipped without verification infrastructure. If your AI touches user data, security hardening is pre-deployment work, not post-launch patches. Your TOS requires it.
Build flexibility. Mandatory AI policies are creating legal backlash. One-size-fits-all is an employment liability. Allow opt-outs based on conscience or legitimate concern.
Don’t be a jerk. As Cerebras CEO Andrew Feldman admitted: “We raced ahead. We didn’t think about the communities. We didn’t use their processes. We were dopes.” Legitimacy comes before scale. Use community processes. Listen when they say no. The cost of being a good neighbor is far lower than the cost of being forced to become one.





These CEOs keep saying 'we were dopes' like it's a confession, but until someone actually goes to jail or loses their company, it's just performative guilt to protect their stock price
The sad truth is that over 66% of developers admit to shipping products they know are not hardened and contain issues. They choose to ship the product anyway. This feeds into a damaging cycle: shipping fast, getting compromised, and polluting the downstream ecosystem. This attitude within the community needs to change; otherwise, developers will remain the weakest link in the security chain