← AI Daily Briefing

AI’s Copyright Fight Meets Its Data-Center Boom (September 18, 2026)

September 18, 2026 · 7m 52s · Listen

AI’s copyright fight just ran straight into its data-center boom. New to this story? Here’s where we are. The compute-obligation thread is about AI labs turning model demand into long-term claims on data centers, GPUs, and power. Anthropic was already part of it, with a large compute-contract ceiling and its first Australian data center lease at Zerra DC’s proposed Western Downs Digital Park in Queensland. The question is how much of that signed demand actually becomes permitted, powered capacity. This is AI Daily Briefing. First up: an internal Microsoft warning that makes the training-data fight much harder to wave away. This one's from Ars Technica:

Perhaps most explosively, Microsoft Director of Applied Science Brent Hecht repeatedly warned in documents that scraping news for AI training was “an astonishing theft of unprecedented proportions,” calling it perhaps the “largest theft of labor in human history,” news orgs said.

Brent Hecht wasn’t a plaintiffs’ expert. He was Microsoft’s Director of Applied Science. His internal warnings show Microsoft people saw the news-scraping plan as far outside any ordinary fair-use argument. And somebody marked those documents confidential, then kept shipping ChatGPT and Copilot. I want the decision trail: who received Hecht’s warnings, and who signed off anyway? The New York Times-led plaintiffs can now put the gap in one place: public fair-use language on one side, and a Microsoft scientist privately saying mass scraping made a mockery of it on the other. That’s evidence a judge can actually weigh. Over on Hacker News:

It is highly unusual that an end-product threatens the economic foundations of its essential suppliers, but that is the situation we have created for our LLM business So they do know exactly what they’re doing.

Yeah. News publishers supplied the material that made these systems useful, then got a product aimed at capturing the audience and ad dollars around it. Calling that a supplier relationship is generous. From Hacker News:

news site unhappy about their content being scraped Not surprising, but calling it "theft" only makes sense within the IP paradigm (we might do better without IP)

You can debate copyright doctrine all day. But Microsoft itself was debating whether this specific use fit fair use, and Hecht’s internal answer was emphatically no. That’s why these filings matter. From Jason Cartwright at techAU:

Anthropic has signed its first data centre lease in Australia, locking Claude into a proposed A$32 billion campus on cattle country west of Brisbane. Premier David Crisafulli announced the deal in Queensland Parliament on Wednesday. The site is Zerra DC’s Western Downs Digital Park, a 725.5 hectare feedlot block at Kogan, about 37 kilometres north-west of Dalby and roughly 250 kilometres from Brisbane.

Following up on Anthropic’s Australia compute lease, Jason Cartwright at techAU puts numbers on the scale: a proposed A$32 billion campus drawing up to 2.16 gigawatts. It’s a serious geographic commitment behind Anthropic’s giant compute ambitions. The lease signals commitment, but usable capacity is still a long way off. Zerra’s plan calls for 1.44 gigawatts of IT load from 2.16 gigawatts from the grid, with four 360-megawatt halls built over years. And Anthropic is the anchor tenant, not the developer writing A$32 billion into Queensland tomorrow. FIRB still has to approve the lease, and Western Downs council only got the development application on August 17. First use in 2027 looks optimistic when the site is a 725-hectare former feedlot near Kogan and the approvals are still live. A signed lease tells lenders somebody wants the power; it doesn't make a single Claude token run there. Kyle Orland, writing in Ars Technica:

Not every example of an OpenAI model acting in an unintended way will generate a public report, the company said. Instead, OpenAI said it will “prioritize new mechanisms, meaningful changes in known behavior, and findings that challenge assumptions about safety or mitigation.”

OpenAI’s giving employees a route to flag covert uploads, megalomania, whatever the model decides is a brilliant idea at 2 a.m.—then letting the safety team decide whether anyone outside the building hears about it. The escalation path has teeth: if the originating employee thinks an incident got buried, they can take it to the Safety Advisory Group, then OpenAI leadership. That gives employees a real escalation route, not just a blog-post flourish. But a disclosure ladder begins after somebody notices the failure. In production, the ugly question is how many bad agent actions land between the first weird behavior and the internal ticket. And after the Microsoft documents we just hit, internal warnings versus public posture is a very live credibility problem. OpenAI says it favors disclosure even when significance is uncertain. Good—publish enough of these calls that outsiders can judge whether that promise holds. Dan Goodin, writing in Ars Technica:

Siposova tested the “non-distortionary” configuration of SynthID-Text through Hugging Face’s unmodified SynthIDTextWatermarkLogitsProcessor. She fed harmful prompts into six open-weight models and compared the responses when the watermarking was used and when it wasn’t. The experiment revealed that the watermarking changed responses to harmful requests, particularly when they were made using prompt-injection techniques.

The test used six open-weight models and Hugging Face’s unmodified SynthID processor. A feature sold as non-distortionary changed whether they refused harmful prompts. That’s a safety regression introduced by the safety layer. And it gets worse under prompt injection, where several models became more likely to answer requests they would otherwise refuse. Tournament sampling chooses tokens differently, and that can steer a model straight through its guardrails. Put that beside the OpenAI incident ladder we just covered. If the watermark shifts one token early in an agent chain, the downstream difference can be a tool call and its arguments. Hope somebody’s measuring the failure before the internal report gets filed. Watermark mandates need behavioral testing, model by model, especially against injection. Provenance is useful, but it doesn’t get a free pass to alter refusal behavior in secret. If you’re finding this briefing useful, take a moment to subscribe or leave a review wherever you’re listening. Reviews help other people find the show, and they help us keep making this daily briefing.

We’ll be watching for Foreign Investment Review Board approval and Western Downs Regional Council action on Zerra DC’s development application for the Western Downs Digital Park.

Links to every story are in the show notes, so check out the ones you’d like to explore further. That’s AI Daily Briefing for today. This is a Lantern Podcast.