← Back to newsletters

AI Daily Brief — Tue May 12

2026-05-12

By Vadym · Generated with AI, curated by me


Listen to this issue

Two stories define Tuesday: the first confirmed AI-built zero-day exploit used in a live criminal operation, and China earning half a billion dollars an hour from AI-related exports. Every tool that makes builders faster is also making adversaries faster — and the gap between capability arrival and security response is where the damage happens.


Headlines & News
Security

Google Confirms First AI-Built Zero-Day Exploit Used in Planned Mass Hack

Google’s Threat Intelligence Group identified a criminal threat actor who used an AI model to develop a working zero-day exploit — a Python script designed to bypass two-factor authentication on a popular open-source web administration tool. The code carried unmistakable LLM fingerprints: auto-generated educational docstrings, a hallucinated CVSS severity score, and textbook-clean structure that Google said had high confidence of being AI-generated. The group planned a mass exploitation campaign. Google worked quietly with the vendor to patch the vulnerability before the operation gained traction.

Source: BleepingComputer

Industry

China Earns $500 Million Per Hour From AI-Supercharged Exports

Goldman Sachs and Nomura estimate that AI-related products — semiconductors, computers, and hardware — accounted for roughly half of China’s export growth in April. Export volumes surged despite ongoing disruptions from Middle East shipping constraints, rebounding more than most economists expected. Bloomberg’s analysis puts the pace at approximately $500 million per hour in AI-adjacent export earnings. China’s AI hardware industry is scaling its global footprint even as Western policy tries to limit its access to frontier chips.

Source: Bloomberg

Workforce

Chief AI Officer Is Now Standard at 76% of Major Organizations

A survey of more than 2,000 organizations found 76% have established a Chief AI Officer (CAIO) role — up from 26% just one year ago. More than half of CAIOs report directly to the CEO or board, and 61% control their organization’s AI budget. Total compensation ranges from $400K to over $2.5M depending on company size. CNBC notes the role is shifting from symbolic appointment to operational function, with CAIOs now expected to own procurement decisions, AI governance, and measurable productivity outcomes.

Source: CNBC

Tooling

Anthropic Announces Managed Agents and a SpaceX Colossus Compute Deal at Developer Conference

At the Code with Claude developer conference in San Francisco last week, Anthropic unveiled Claude Managed Agents — a framework that adds Multiagent Orchestration (scaling fleets of agents across complex tasks), Outcomes (agents that iterate until success criteria are met), and Dreaming (persistent memory across sessions). The company also announced a deal to allocate full capacity of SpaceX’s Colossus supercluster to Claude inference, and doubled rate limits for Claude Code Pro, Max, and Enterprise subscribers.

Source: Every

Research

Microsoft: Global Git Pushes Up 78% Year-Over-Year as AI Coding Tools Multiply Output

Microsoft’s global AI diffusion report found that git pushes — the standard measure for code shipped to production — increased 78% year-over-year globally. The report attributes the surge primarily to AI coding tools, and cites controlled studies showing productivity gains of 14–26% in software development and customer support. The finding that challenges the conventional wisdom: AI coding capabilities appear to be increasing demand for software developers, not reducing it, as faster output cycles create more work to manage, review, and ship.

Source: Microsoft


Analysis

Takeaway

The most interesting through-line today is the asymmetry. Git pushes are up 78%. Chief AI Officers now sit in 76% of boardrooms. China is running an AI hardware export machine at $500M per hour. Open-weight models are closing in on frontier benchmarks on four GPUs. Every signal says the productivity wave is real and accelerating. Then there’s the Google zero-day. Every tool that makes legitimate builders faster also makes adversaries faster — and the code quality bar for malicious exploits just dropped. The lag between AI capability arriving in the market and security teams adapting to it is exactly where the risk lives. Today’s brief is a useful split screen: the upside numbers are compelling, and the downside is no longer theoretical.

— Boba


Curated by Vadym