September 2, 2026

California May Require Lawyers to Personally Verify Every Citation They File

Lawmakers have sent Governor Gavin Newsom a bill that keeps legal judgment, confidential data and court filings under human responsibility. OpenAI's next model, Google's publisher opt-out, Dell's server boom and a Dropbox breach show why the verification point is becoming the valuable part of the system.

A lawyer's desk with a legal brief, red pen circling footnotes, law books behind.

The Short Version

California is one signature away from putting detailed AI duties into state law for lawyers and arbitrators.

SB 574 would require attorneys to take reasonable steps to verify AI-generated work, correct errors, disclose generative AI use in documents submitted to a court and protect confidential information. Every citation in a court filing would have to be personally verified by the responsible attorney, including citations supplied by AI. Lawyers couldn't delegate the practice of law to a model. Arbitrators couldn't hand any part of their decision to one.

Both chambers approved the current version Monday. Governor Gavin Newsom can sign or veto it. Until he acts, these are proposed requirements.

The bill is narrower than a ban and more demanding than a disclosure label. It allows AI-assisted legal work while keeping professional responsibility attached to a named person. Some California lawyers say much of it duplicates duties that already exist. The practical change would be a clearer statutory record for enforcement and sanctions.

That idea travels well beyond a courtroom.

OpenAI says its upcoming Astra model can find previously unknown security flaws and develop exploits across hardened systems with little human guidance. The company has placed Astra in the highest cyber-capability category under its preparedness framework and plans a limited release with stronger monitoring and access controls.

Google has offered publishers a global switch that keeps their work out of generative AI Search without hurting rankings in traditional results. European regulators are asking publishers whether the proposed choice solves their competition concerns.

Dell recorded $16.4 billion in AI-server revenue last quarter and ended with a $95 billion backlog. Those are supplier results. Buyers still need to show that the machines produce accepted work, revenue, lower cost or another measurable return.

Dropbox disclosed that about 5,000 accounts were compromised through a legacy connection with Lenovo ID. Files were accessed in fewer than one-third of them. The failure sat in the identity path between two services, which is exactly where many organizations stop looking after they approve an integration.

AI can accelerate research, drafting and system operation. Value survives when someone verifies the result, controls the source material, measures the return and can close a broken path.

The Lawyer Keeps the Signature

California's bill turns AI review into a documented professional duty

SB 574 has completed its trip through the California legislature. The current version now awaits Newsom's decision.

The bill would add several duties for attorneys who use generative AI in legal practice. They would have to verify the accuracy of outputs, including case and statutory citations, and correct false or hallucinated material they use. They would have to tell a court when a submitted document was created with generative AI and consider disclosure when generated content goes to the public.

The confidentiality rule is specific. An attorney couldn't enter confidential, personally identifying or other nonpublic information into a system unless access to that information is restricted to the attorney and authorized people who are obligated to protect it. A generic consumer account with unclear retention and access terms would be a poor fit for client material. A controlled legal system may qualify, depending on its contract and configuration.

Court papers receive another protection. Every citation would have to be personally verified by the responsible attorney, whether AI supplied it or a person did. Existing California law already makes a signer responsible for factual and legal support in a filing. The bill would make citation verification explicit and leave courts with their existing power to impose appropriate sanctions.

Arbitrators would also remain responsible for the decision. They couldn't delegate any part of that process to generative AI or rely on generated information from outside the record without first making the required disclosures to the parties.

This is a proposed state law, not a national professional standard. It may be signed, vetoed or challenged after enactment. Lawyers quoted by Reuters also argue that much of it repeats competence, diligence and confidentiality duties they already carry.

Repetition can still alter operations. A general duty becomes easier to train, audit and enforce when the required acts are named. A law firm would need to know which matters use AI, which tools are approved, where client data can go, who checked each source and how the final attorney documented acceptance.

A sensible pilot begins with one recurring task, such as a first-pass contract comparison or research memo. Use a reference set already reviewed by experienced lawyers. Track material issues found, unsupported claims, citation errors, attorney review time, confidential-data exceptions and cost per accepted document. Preserve the source used to verify each material claim.

Fast drafting has little value when the verification burden grows faster than the saved time. The attorney's signature is the production checkpoint.

OpenAI Says Astra Crossed a Cyber Threshold

The upcoming model can find zero-days, while the safeguards remain company-tested

OpenAI says Astra is the first model it has designated as having Critical cybersecurity capability under its Preparedness Framework.

The company defines that threshold through two demanding abilities. A qualifying model can find and develop working zero-day exploits across many hardened systems without human intervention, or devise and execute a new end-to-end attack against a hardened target from a high-level goal.

OpenAI says Astra can find previously unknown vulnerabilities and turn them into working exploit chains with less computing than its strongest public model. In one internal evaluation built from 20 recently disclosed high-severity V8 vulnerabilities, Astra achieved higher rates of arbitrary code execution than GPT-5.6 Sol and found two zero-days during an exploit chain. OpenAI says it is disclosing those flaws to the maintainers.

These results come from the developer. The full system card is planned for launch, and outside researchers have yet to evaluate the released model under representative conditions. OpenAI also says the most advanced results reflect special Daybreak Blue access rather than the default product configuration.

The safeguards are therefore part of the product claim. OpenAI says it delayed portions of development and release, tightened its training infrastructure after the earlier Hugging Face incident, trained Astra to refuse harmful cyber requests and added monitoring that can stop potentially unauthorized activity. The company reports a 91.5% refusal rate on its cyber-jailbreak evaluation, compared with 59% for GPT-5.6 Sol.

Higher refusal can reduce misuse and can also interrupt legitimate defensive work. OpenAI expects extra checks to slow, pause or stop some valid tasks. Advanced cyber capability will initially go to a small group of testers, with broader defensive access planned through Daybreak Blue. The company hasn't given a release date.

Security leaders should treat capability and control as separate acceptance tests. A defensive pilot can use an isolated replica of a real application, synthetic credentials and a fixed set of known vulnerabilities. Measure confirmed findings, false alarms, time to a reproducible report, reviewer effort, unauthorized actions blocked and interruptions of valid work. A finding earns value when a human can reproduce it and the owner can patch the system.

The access decision deserves equal care. A small security team may gain testing capacity that previously required scarce specialists. It also needs an approved target list, network restrictions, activity records and a person who can stop the run. The stronger the model, the less useful a vague instruction such as “test our environment” becomes.

Publishers Get a Choice With a Price

Europe's review asks whether Google's AI Search opt-out is meaningful

Google announced a Search Console control in June that lets a website stay out of its generative AI Search features. An August 31 update says the control and new performance reporting are now available to websites worldwide.

A publisher that opts out would lose traffic and impressions from AI Overviews, AI Mode and related generative experiences. Its position in traditional search results would not be affected by the toggle, according to Google.

European Union antitrust regulators are now testing whether that is a meaningful choice. A confidential questionnaire reviewed by Reuters asked publishers whether they expected to use the control and which factors would shape the decision. The European Commission sent the questions in July and requested responses by August 28 as part of an ongoing investigation.

The review has produced no finding. Google has offered a product change, publishers have supplied feedback and the Commission will decide whether the proposal addresses competition and content-use concerns. The opt-out also follows a binding UK requirement announced the same day as Google's control.

For an independent publisher, creator or specialist business, the choice has a built-in cost. Remaining inside AI Search may bring citations, brand discovery and visits. It may also let a generated answer satisfy the user before a visit occurs. Leaving protects one form of control over the work but removes the chance to receive traffic from those AI features.

A measured test gives the publisher a usable decision. Record current impressions, clicks, engaged visits, subscriptions, leads and revenue attributable to generative Search. Use the control for a fixed period or a defined property where the business can tolerate the lost AI exposure. Compare the audience outcome with traditional search and direct channels.

Publishers should also preserve examples of answers that use their reporting, whether the source is visible and whether the resulting visit converts. Regulators need market evidence. Publishers need a business decision grounded in their own audience.

An opt-out has practical meaning only when the publisher can understand what leaves with it.

Dell's Backlog Reaches $95 Billion

Infrastructure revenue is accelerating faster than buyer evidence

Dell's latest results put another large number behind the AI infrastructure buildout.

The company booked $60.9 billion in AI-server orders during the quarter ended July 31, recognized $16.4 billion in AI-optimized server revenue and finished with a $95 billion backlog. Total quarterly revenue reached a record $47 billion, up 58% from a year earlier.

Dell raised its full-year revenue forecast from $167 billion to $192 billion. It now expects $74 billion in AI-server revenue for fiscal 2027, up from its prior forecast of $60 billion. The company says it has received more than $130 billion in AI-server orders during the past 12 months and serves over 6,500 customers in that business.

The completed quarter provides reported financial results. The annual figures are company forecasts. The backlog represents orders awaiting fulfillment, not recognized revenue or customer return.

That separation matters for any organization writing an AI business case. Dell gets paid for delivered servers. A buyer creates value when the system improves an accepted result after computing, power, storage, integration, review, security, correction and change management are counted.

Demand also reaches beyond specialized accelerators. Dell reported that traditional server and networking revenue rose 122%, partly because CPU-based systems are handling agentic workloads. Storage revenue rose 26%. Memory shortages have pushed the company to raise prices on products including PCs, Reuters reported.

A buyer can keep the economics grounded by approving capacity against a workload rather than a general AI ambition. Baseline one production process. Estimate the useful work per week, service level, current labor, error, delay and peak demand. Then measure system utilization, cost per accepted result, human review, energy, incidents and the capacity that sits idle.

Supplier backlog can signal durable demand and future constraints. It cannot prove that the buyer chose the right workload, model or deployment size. A smaller rented system may produce better evidence before a large purchase. A larger system may be justified when privacy, latency, predictable volume or strategic control outweigh the added operating burden.

Dell has proved that customers are placing extraordinary orders. Each customer still owns the return.

A Legacy Login Opened Current Files

The Dropbox breach traveled through an identity connection

Dropbox says about 5,000 accounts were compromised between August 4 and August 21 through a connection with Lenovo ID.

Files were viewed or downloaded in fewer than one-third of the affected accounts. Dropbox told Reuters that the compromised accounts were linked to a Lenovo ID and lacked Dropbox two-factor authentication.

Lenovo described the cause as a legacy integration that could be used to authenticate some Dropbox accounts improperly. Lenovo says its own customers were unaffected and its investigation continues. No public technical postmortem has established the attacker's full method or the categories of files reached.

Dropbox terminated sessions authenticated through Lenovo ID, removed the links between Lenovo IDs and Dropbox accounts and changed the flow so a user must enter a Dropbox password. It notified affected users and data-protection regulators.

The incident is small relative to the largest consumer breaches. Its architecture is widely relevant. A cloud account may have a strong password while a connected identity service provides another door. An old integration can preserve authority long after the person who approved it has moved on.

Individuals and small organizations should review connected login methods, active sessions, recovery addresses, app authorizations and shared links across the cloud services that hold contracts, tax records, customer files and creative work. Turn on multifactor authentication at the destination service, especially when a partner login can reach the same account.

Organizations need an inventory that connects each identity provider to the data and actions it can unlock. Test how quickly the link can be disabled without losing the records needed for investigation. Measure unauthorized sessions ended, accounts covered by strong authentication, stale connections removed, time to notify affected people and files whose access cannot be reconstructed.

Convenient sign-in is an operating dependency. Its risk belongs in the same review as the files behind it.

Opportunity Radar

Evidence packs for AI-assisted professional work

Law firms, accounting practices, consultants and other regulated professionals increasingly need to show how an AI-assisted result was produced, reviewed and accepted. Many have an approved-tool list but lack a usable record at the matter or engagement level.

A legal-technology provider, compliance consultant or practice-management vendor could build a narrow evidence workflow around one high-volume task. The service would record the approved system, source set, sensitive-data classification, generated draft, reviewer, corrections and final approval without copying privileged material into another uncontrolled database.

Small and midsize practices could pay for lower review friction and a record they can defend to a client, court, insurer or regulator. The product has to fit existing professional rules and security requirements. It also must prove that documentation takes less time than it saves. Review completion, citation defects found, confidentiality exceptions, time per accepted document and audit-reconstruction time are useful measures.

California's bill may strengthen demand if it becomes law. A viable service should still solve today's competence, confidentiality and supervision duties without depending on one governor's signature.

What You Can Do With This

If you use AI in professional work

Name the person who accepts the result and give that person the source material, time and authority to reject it. Record the tool, sensitive data entered, citations checked, corrections made and final approval for one recurring workflow.

If you run a security team

Test advanced cyber models inside an isolated target with synthetic credentials. Score reproducible findings, reviewer effort, boundary violations and false interruptions separately. Keep network controls and the stop mechanism outside the model.

If your work depends on discovery

Separate AI Search traffic from traditional search, direct visits and referrals. Measure engaged visits, subscriptions, leads and revenue before using an opt-out. Keep examples showing how the generated answer represents and links to your work.

If cloud services hold important files

Review every connected identity provider and active session. Enable multifactor authentication at the storage service, remove stale login paths and confirm that administrators can revoke a partner connection without destroying the investigation trail.

The Bigger Picture

The fastest systems in this edition all arrive with a slower obligation.

A lawyer can generate a draft quickly and still has to verify every material part. Astra can find vulnerabilities at a new level and still needs a defined target, restricted access and reproducible findings. Google can summarize a publisher's work at search speed while the publisher weighs discovery against control. Dell can ship enormous computing capacity while each buyer proves a return. A federated login can remove friction and quietly preserve another route to private files.

The durable control sits close to the consequence. It is the attorney who signs, the security owner who authorizes a target, the publisher who measures an audience, the buyer who accounts for accepted work and the administrator who can revoke access.

Those controls create useful evidence. They show which source supported the answer, which action was allowed, which cost produced a result and which path failed during an incident.

AI adoption is moving from general permission into named responsibility. The organizations that handle that shift well will gain speed without losing the ability to explain, challenge or repair the work.

References

California Legislative Information: Current text of SB 574 governing attorneys, arbitrators and generative AI

Reuters: California lawmakers send the lawyer AI bill to Governor Gavin Newsom, September 1, 2026

OpenAI: Astra's critical cyber capability assessment, safeguards and release plan, September 1, 2026

Reuters: Astra is the first OpenAI model to trigger the company's strongest cyber safeguards, September 1, 2026

Google: Global Search Console opt-out for generative AI Search features, June 3, 2026

Reuters: EU regulators ask publishers about Google's AI Search opt-out, September 1, 2026

Dell Technologies: Second-quarter fiscal 2027 results and updated guidance, September 1, 2026

Reuters: Dell raises its annual forecasts as AI-server orders and backlog reach records, September 1, 2026

Reuters: Dropbox says about 5,000 accounts were compromised through a Lenovo ID integration, September 2, 2026