The Second Emergency All working notes On the Record Contact

Working Note 08

Three Months Later


In the last days of September and the first day of October, the companies building AI and the governments watching them both moved. This note sets out what happened, in order and in plain words, and points to the one piece that is still missing.

1. What happened this week

This is what it's like

A car maker finds a fault in a new model and holds it back from the dealers. A parts supplier designs a better brake. The government sends the car maker a letter asking what else it knows. All of that is real safety work, and it all happens at the factory.

2. Three months, twice

Two incidents sit behind this week's news. Both involve AI helpers, the kind of AI that can act on its own rather than only answer a question.

When it happenedWhat happenedWhen it came into the open
June 2026OpenAI models got into Australian government websites during testing, including a Medicare site.23 September, when Australia's Prime Minister disclosed it and called it unacceptable
July 2026AI helpers built by OpenAI got into parts of Hugging Face, a large website where developers share AI tools.1 October, when California announced its subpoena

In both cases, about three months passed between the incident and a government acting on it in public.

3. Credit where it is due

A company that cancels its own release gives up money to do it. A guard that can stop an AI helper in milliseconds is serious engineering. A company that tells its investors, in writing, that its product carries grave risks is taking those risks seriously. The builders deserve credit for all of it.

California's subpoena matters for a different reason. It is a government asking questions under the law rather than relying on a company's promise.

4. The piece still missing

Every one of these steps happens at the factory end. None of them reaches the person at the other end of the line: the resident whose benefit, prescription, water or bank account runs on a system an AI helper can touch.

In emergency management, a warning protects only the people who receive it in time to act. When a car is recalled, owners get a letter. When an AI helper goes somewhere it should not, there is no equivalent letter, and as Working Note 04 sets out, no one is required to send one.

The builders are putting brakes on the machines. Somebody has to put a plan on the fridge.

5. And in Canada

On 1 October, the day California announced its subpoena, the Prime Minister listed the Pacific Link pipeline as Canada's first project of national interest under the Building Canada Act, so that it can be built faster. Whatever one thinks of the project, it shows that when Ottawa decides something matters, it can move quickly.

Canada already has its own warning on the record. By mid-September, the Canadian Centre for Cyber Security had warned that attackers are using AI to break into the controls of water, energy, food and chemical systems. Since then, a model was pulled before release, a guard was built, an accord was signed and a subpoena was served. The AI systems in this week's news are built and tested outside Canada, and they reach Canadian banks, pharmacies and public services all the same.

Take banking first. Deposit insurance protects eligible money in a member bank if that bank fails. It was never designed to keep payments working through an outage, or to tell a household what to do when a card is declined at the grocery store.

The banks themselves have already been told to prepare. In July, OSFI, the federal regulator of Canada's banks and insurers, published a bulletin warning that AI systems "can act with limited human oversight." It tells the institutions it regulates to "test AI failure and outage scenarios and establish manual fallbacks," and to require their suppliers to say "if and how they are using AI to deliver services." A separate OSFI rule on managing the risk of models, including AI, takes effect on 1 May 2027. The people who run the banks have their instructions. The people who use them have none.

Telling Canadians in time when AI fails in an essential service is in the national interest too. It deserves the same speed as a pipeline.

6. What a household can do now

A household cannot speed up a government investigation. It can decide in advance what to do when a service stops, or keeps working and gives a wrong answer. The Plan sets out five first steps for the day it happens, two sheets to fill in by hand, and what to check once service comes back. It is free, in English and French.

7. Questions for the people responsible

For the companies: when one of your AI helpers goes somewhere it should not, who outside the company is told, and how quickly?

For governments: when an AI incident touches a public service, what is the deadline for telling the public?

For municipalities: if a supplier's AI helper misbehaves inside a City system, how would you find out, and how fast?

Smaller dated events now go to On the Record, a running list with one line and one source for each, so the Working Notes can stay for arguments.

Sources

Verification note: every dated event is as reported in the sources above. The Anthropic filing is described as reported by the press. The Cyber Centre's industrial-controls warning was given in Working Note 07 as dated 8 September 2026; the page itself shows it was modified on 14 September 2026, and its first publication date has not been confirmed. Note 07 has been corrected, and the change is recorded in the site updates.

All working notes On the Record Print or save as PDF Back to the documents

Free to use, adapt and reproduce. No permission required, no fee.

Working notes are dated when published. If one is revised, the change is recorded in the site updates log. Notes are never silently edited and never backdated.
TheSecondEmergency.com  ·  angela@lindow.ca