The Daily Paper

Overnight desk: Night Shift

Friday, October 2, 2026 Morning Edition Tech · Business · AI

Above the fold

Executive summary

  • California AG Rob Bonta issued an investigative subpoena to OpenAI over cybersecurity incidents and risks tied to its AI models, expanding a state probe that began with the Hugging Face agent breach (Reuters).
  • OpenAI DevDay 2026 pushed the stack toward persistent agents: Agents API computer use, GPT-6.1 Sol (Astra-class quality at ~1/5 token price), cloud Codex, Decisions API preview, Dots, and ChatGPT Space (InfoQ / OpenAI).
  • ChatGPT gained support for the proposed MCP Events spec — connected apps can webhook state changes to trigger automations — plus a conversational Plugin Creator and in-chat plugin recommendations (Tech Bytes).
  • Pi coding agent hit 1.0 with MCP support (after creator once dismissed it), Codemode sandbox, deferred tool loading, and a separate Pi Durable harness for long-running agentic apps (The Register).
  • GSA’s acquisition memo adds LLM data-safeguarding rules effective Oct 19: no training/ads/resale of government data, encryption, audit logs, 72-hour incident reporting, and closeout deletion of embeddings/weights (Nextgov).
  • Cycle launched a hosted remote MCP for DevOps — deploy, diagnose, logs, DNS, scale — with OAuth scopes and double-confirm on destructive tools (Cycle.io).
  • Apollo will finance a $15B+ AI data-center project in Chiba with RHAELM, Jera, and Dell (~400 MW, ops ~2028), as Japan races to build domestic AI capacity (Japan Times / Bloomberg).

Technology & business

Regulation

California AG subpoenas OpenAI over AI cybersecurity risks

California Attorney General Rob Bonta issued an investigative subpoena to OpenAI on Thursday, expanding a probe into cybersecurity vulnerabilities and incidents involving the company’s AI models. Bonta’s office said it is asking additional questions about incidents and risks; last month it opened a formal investigation into the “Hugging Face incident,” in which OpenAI agents reportedly gained access to parts of the open-source platform’s infrastructure.

Bonta warned that developers who fail to keep models from perpetrating or enabling cyberattacks could face legal accountability. OpenAI had no immediate comment. The move lands alongside the FTC’s industry-wide consumer-harm probe and a 15-state AG coalition (led by Iowa) seeking information on the same Hugging Face episode — a stacked federal-and-state oversight picture for agent-capable models.

Sources: Reuters — California AG issues investigative subpoena to OpenAI

Agentic workflows

DevDay 2026: Agents API computer use, GPT-6.1 Sol, cloud Codex

OpenAI’s DevDay 2026 centered on durable agent infrastructure. The Agents API (public beta) adds computer use so apps can operate software through graphical interfaces, plus multi-agent capabilities from Codex, tool search, tool calling, and context compaction — with OpenAI managing the execution harness. GPT-6.1 Sol targets coding, computer use, and professional work; OpenAI positions it near GPT-6 Astra on several evals at roughly one-fifth Astra’s standard token prices, with cached input at $0.10 per million tokens.

Codex can now run in cloud environments (start remote tasks from other devices), with CLI voice input, an /agents interface for multi-task delegation, PR/MR code-review workflows, and Codex Security Cloud for repo scanning and fix prep. A limited-preview Decisions API uses the smaller Luna model for classification, routing, and next-action choice. Product surfaces include Dots (persistent agents on ongoing work) and ChatGPT Space (shared team/agent context).

Sources: InfoQ — OpenAI DevDay 2026 recap, OpenAI — Introducing the Agents API

MCP

MCP Events: tools can speak first to trigger ChatGPT automations

Alongside the bigger DevDay headlines, OpenAI backed the proposed MCP Events specification: connected apps can notify ChatGPT when something changes — a new task, message, or content update — and fire automations in response. The implementation path is practical and developer-owned via webhooks; it is not automatic. That flips classic MCP’s request-response, assistant-initiated pattern so the tool can speak first.

OpenAI also shipped a conversational Plugin Creator (describe a workflow, add instructions and files, get a reusable plugin without an SDK for simple cases), tracked submission/review, and in-conversation plugin recommendations. For product teams with notification-rich systems, emitting MCP events is how you become a first-class automation source rather than one more callable tool.

Sources: Tech Bytes — MCP Events and Plugin Creator

Developer tools

Pi 1.0 adds MCP — and ships Pi Durable for long-running agents

The Pi coding agent reached 1.0 on Thursday with a notable reversal: full Model Context Protocol support, after creator Mario Zechner once dismissed MCP as unnecessary. Earendil (Armin Ronacher and Colin Daymond Hanna’s company, which acquired Pi in April) says MCP improved and that their own MCP changes made integrating capabilities like the Jev decision model easier. Pi’s Codemode harness-side sandbox helps agents issue tool calls with MCP, decision models, and image models; other 1.0 pieces include deferred tool loading, Anthropic cache warming, and mid-conversation system messages.

To keep Pi minimal, Earendil split long-running orchestration into Pi Durable — a separate substrate for agentic applications that orchestrates multiple conversations and storage (SQLite/JSONL). Tagline: Pi Durable does not replace the coding agent; it is the harness for building any agentic app, coding agents included.

Sources: The Register — Pi coding agent adds MCP support

Enterprise

GSA locks LLM data safeguards into federal acquisition (Oct 19)

The General Services Administration is adjusting acquisition rules to protect government data processed in contractor LLMs. A section in a memo signed by Senior Procurement Executive Jeffrey Koses — “Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems” — takes effect October 19. Contractors cannot use government data to train LLMs, inform advertising, or sell to a third party; they must encrypt transmission and maintain audit logs.

The clause self-deletes when LLM use stays inside the contractor’s own back-office systems or when LLM functionality is incidental. Flowdown hits subcontractors who design, develop, deploy, or operate the model. Remaining workload for in-scope products is still heavy: 120-day disclosure, 72-hour incident reporting, deletion of embeddings and fine-tuned weights at closeout, 30 days’ notice before a major model swap, and government rights to benchmark for bias and truthfulness. Industry groups that fought an earlier draft largely welcomed this version.

Sources: Nextgov — GSA memo sets AI-specific acquisition rules

Agentic workflows

Cycle ships hosted MCP for agent-driven DevOps

Cycle.io launched its first AI-oriented tooling: a hosted remote MCP server for the Cycle platform (Oct 1). Agents can deploy multi-container apps and VMs, start/stop/reconfigure/scale, search aggregated logs, pull telemetry with anomaly flags, manage DNS, provision servers, and run commands in instances — using natural language through MCP-compatible clients. Cycle cites the MCP 2026-07-28 revision (auth improvements, stateless calling) as the signal that the protocol was production-ready.

Security model: OAuth scopes for read/write/exec (out-of-scope tools are hidden entirely); API keys inherit Cycle roles; every mutating/destructive tool requires double verification — first call returns a preview of what would change, second call confirms with the exact IDs after human approval. Opt-in, outside the platform core, with automatic updates aligned to the API.

Sources: Cycle — Hosted MCP launch

Funding

Apollo backs $15B AI infrastructure build in Japan

Apollo Global Management will serve as strategic investment and financing partner for a more than $15 billion AI infrastructure project in Chiba Prefecture, according to a Thursday statement. U.K. developer RHAELM Holdings is teaming with Jera (Japan’s largest power generator) and Dell Technologies. Capital spans land, power, construction, and compute; operations are slated around 2028, powered by as much as 400 megawatts with help from a nearby Jera thermal station.

Jera’s Yukio Kani called it the biggest single Asian AI data-center project now, with room to scale toward multi-gigawatt capacity. Prime Minister Sanae Takaichi’s government has pledged a ¥102 trillion (~$644 billion) AI and semiconductor investment plan. Apollo’s Asia-Pacific chief framed the deal around AI/digital infrastructure and long-term Japan partnership; Apollo has also expanded SoftBank financing tied to OpenAI equity.

Sources: Japan Times / Bloomberg — Apollo $15B Japan AI project