Control over identity, data, and distribution set the day's agenda. OpenAI traded recoverability for phishing resistance while enabling off-platform marketing measurement for free accounts. Italy challenged Google's answer-first search, Musk disclosed xAI's use of OpenAI outputs, and Legora's financing showed capital moving into domain-specific workflow ownership.
1. OpenAI adds phishing-resistant protection for ChatGPT and Codex
OpenAI introduced an opt-in Advanced Account Security mode that requires passkeys or physical security keys, disables password login and email or SMS recovery, shortens sessions, and excludes account conversations from model training. The same controls cover Codex when it uses the protected ChatGPT login.
The stronger recovery model has a hard tradeoff: OpenAI Support cannot restore an enrolled account after every approved credential is lost. Redundant authenticators, separately stored recovery keys, and departure procedures become prerequisites for enrollment because the support channel is intentionally removed from the recovery path.
Sources: Introducing Advanced Account Security
2. Italy asks Brussels to examine Google's AI search features
Italy's communications regulator referred Google's AI Overviews and AI Mode to the European Commission for assessment under the Digital Services Act. The referral followed a publisher complaint that generated summaries reduce referral traffic, threaten smaller outlets, and can present claims without easily verifiable sourcing.
This is a formal request for assessment, not a finding that Google violated the DSA. Even so, it moves publisher attribution, traffic diversion, hallucination risk, and algorithmic transparency into the same regulatory proceeding, raising the compliance stakes for answer-first search products in Europe.
Sources: Italy's media regulator asks EU to investigate Google AI search tools
3. Musk says xAI distilled OpenAI outputs while training Grok
Elon Musk testified that xAI partly used distillation from OpenAI model outputs while training Grok. He characterized the method as common across AI labs, but his testimony addressed xAI's conduct rather than the contractual or legal status of any particular extraction run.
The admission turns output provenance into a two-sided commercial problem. Providers can compare account telemetry with high-volume teacher-model queries, while downstream buyers can trace whether a training recipe carries usage-term or intellectual-property exposure. The trial established a claimed method, not a general legal rule for model distillation.
Sources: TechCrunch on Musk's testimony · The Verge on the distillation admission
4. Legora's extension prices legal workflow distribution at $5.6 billion
Legal AI company Legora added $50 million to its $550 million Series D, bringing in Nvidia's NVentures and Atlassian at a reported $5.6 billion post-money valuation. TechCrunch also reported that annual recurring revenue had passed $100 million.
The figures come from company statements and unnamed sources rather than audited filings. The investor mix is more revealing than the valuation alone: a chip supplier and a collaboration platform are backing an application vendor whose differentiation sits in legal workflows, integrations, and distribution as foundation-model providers move into the same domain.
Sources: TechCrunch on Legora's extension · CNBC on Nvidia's investment
5. Free ChatGPT accounts default into off-platform marketing measurement
OpenAI revised its US privacy policy to permit limited identifiers, including cookie or device IDs, to be shared with marketing partners for promotion and conversion measurement outside ChatGPT. WIRED found the controls enabled on two free accounts but not on the paid accounts it checked.
OpenAI says conversations and private content remain excluded, and users can opt out through Marketing Privacy settings or recognized privacy signals. That preserves a content boundary while opening an identity boundary: account and device events can still connect product use with activity elsewhere, particularly when work experiments occur in consumer accounts.
Sources: WIRED's account-level checks · OpenAI's marketing privacy explanation