John Ternus became CEO of Apple today. That sentence is true. It is also four months late.
Apple's board appointed him in April. The press release went out on a Monday in spring. Tim Cook wrote that this was not goodbye. Ternus promised to lead with the values that have defined the place for half a century. Then everyone waited through summer, which is what a planned succession looks like when a company is trying not to look hurried.
Today is the first day. The titles swapped. Cook is executive chair. Art Levinson, who ran the board for fifteen years, is now lead independent director. Ternus has a seat. None of that is a surprise. The actual decision already happened, and it was a personnel choice rather than a product.
In 2011, Apple gave the company to an operator. Steve Jobs resigned on August 24. The board named Cook, then the COO, the same day. Cook spent the next fifteen years making Apple larger than almost anyone had language for. Revenue went from $108 billion to $416 billion. Services became a $109 billion business. The installed base, by Apple's count, passed 2.5 billion devices.
That is not a product story. It is a scale story. It is also why a lot of people assumed the next CEO would look like Cook: someone who could keep the machine running.
They picked a mechanical engineer who joined the product design team in 2001.
Companies reveal what they think is scarce when they choose a successor. In 2011 Apple thought operations was scarce. In 2026 it reached for someone whose public record is iPads, AirPods, years of iPhones, and a $599 MacBook they named Neo. Cook called him "the mind of an engineer, the soul of an innovator." Levinson talked about deep technical knowledge and a relentless focus on creating great products. That is not the language you use if you want another supply-chain CEO.
I do not think this means Apple is going back to hardware. That would be a neat sentence, and it would be wrong. The same day Apple named Ternus, it named Johny Srouji chief hardware officer. Hardware already has a boss who is not the CEO. Craig Federighi still runs software. Eddy Cue still runs services. Ternus told staff he planned to stay "very hands-on," which is the sort of thing hardware people say. The org chart is not a one-man studio.
The more useful observation is narrower. Apple spent a decade becoming a services company without ever ceasing to be an iPhone company. Last fiscal year, iPhone was still about half of revenue. Services was about a quarter. The profit mix moved. The identity did not quite catch up. Putting a hardware engineer in the chair is one way of saying the object still matters. It is also a way of saying that in a market where anyone can ship a model, the scarce thing is a product people will pay for.
Ternus has been unusually direct about that, for an Apple executive. In March, talking about the cheap Mac, he said they did not want to do it until they could do it well and build a Mac they were proud of. A few weeks later, before he was named, he told an interviewer: "We never think about shipping a technology. We always think about how can we leverage technology to ship amazing products." In the same stretch he waved off the idea that Apple was behind on AI by saying they have always focused on delivering the experience.
That is a coherent philosophy. It is also about to be tested in public, because the thing Apple most needs to ship this year is not a laptop.
In June, Apple unveiled Siri AI, an entirely new Siri, with foundation models "custom-built in collaboration with Google and its Gemini models." That is Apple's own newsroom, not a leak. The same day, Apple said it cannot put Siri AI on iPhone or iPad in the European Union because of the Digital Markets Act, and that there is currently no timeline. Austria is on the list. From Vienna, that is not a footnote. It is the product.
I am not arguing the DMA here. I am looking at the mismatch. The first new CEO since 2011 is a hardware lifer. The first real argument of his tenure is a software assistant that depends on someone else's models and does not ship in Europe.
Cook is still there. He said so more than once. "This is not goodbye." His new job, in Apple's words, includes "engaging with policymakers around the world." That is a polite way of saying the last CEO is now, in part, a diplomat. I suspect that is less a slight to Ternus than an admission that Apple's hard problems are no longer only engineering problems. Regulation sits next to the product, not underneath it. Even this summer's gross margin included a couple of points from tariff refunds.
On September 9 Apple will hold an event called "Surprise and shine." They have not named the products. I am not going to guess. The first hardware show of a hardware CEO will be read as a statement no matter what walks out. That is a burden, and it is a little unfair. Four months of transition is not a strategy.
Cook, on his last earnings call, said he was excited for Ternus to "lead Apple into its next era." Apple's April press release did not use that word. Ternus talked about half a century. One of them is describing a continuation. The other is describing a chapter break. Both can be true. Companies like Apple prefer the first. Commentators prefer the second.
I think the honest version is smaller. Apple did not become a new company this morning. It confirmed a bet it made in April: that after fifteen years of making the operation extraordinary, the person in the chair should be someone who has spent his career arguing, in aluminum and glass, that the object is the point.
Whether that bet matches the decade in front of them is a different question. Siri will ship, or it will stay stuck in Brussels. The September event will look like a product company or like a holding pattern. Cook will recede, or he will remain the person governments actually call. None of that gets decided on a leadership page.
Ternus's first useful day is not today. It is whenever the first thing that is clearly his, and not leftover Cook, has to survive contact with a customer.
I am still not sure whether that is an era. It is, at least, a different kind of risk.
]]>There is a kind of company that spends years convincing you it is not really a company. It is a layer. A switch. A place you pass through on the way to doing the actual work. You are not supposed to worry about who owns it, because ownership is not the point. The point is that it sits in the middle and does not take a side.
August was a bad month for that story.
On August 14, Cursor published a short post: it was now part of SpaceX. The language was familiar. More compute, better models, the same hope that people with ambitious ideas might spend less time writing code. Two weeks later, OpenAI said it would wind down the contract that supplied its models to Cursor, with a proposed shutoff on November 12. The stated reason was not that the editor had failed. OpenAI wrote that it could not be confident SpaceX would use the technology within its terms of service.
Cursor's CEO, Michael Truell, said OpenAI models accounted for about 5 percent of user traffic, that the companies were talking, and that Cursor had "trusted their platform to be neutral infrastructure for our business."
Neutral infrastructure. That is a revealing way to put it.
On August 19, Stripe said it had agreed to acquire OpenRouter. If you have not used OpenRouter, the simplest description is that it is a switchboard. It sits between a product and hundreds of models from dozens of providers, and it tries to send each request somewhere sensible, based on price, speed, and reliability. In its own post, OpenRouter said it now processes more than 10 trillion tokens a day for a community of over 10 million developers and companies. The deal had not closed at the time of writing. OpenRouter said it expected to close in the coming weeks.
Its founding belief, restated in the acquisition note, is that intelligence will be multi-model. No single model wins every task, and the frontier moves too fast for one default to be safe. Alex Atallah, OpenRouter's CEO, said developers need a "neutral layer" to orchestrate them. Patrick Collison put the economic version in one sentence: "Tokens are the central currency for companies building with AI."
These look like different stories. One is a dispute. The other is a complimentary acquisition between two companies that like to describe themselves as infrastructure. I think they are the same story.
The companies that made the middle of the stack feel like a utility are being folded into companies that have other jobs.
That is not a moral complaint. SpaceX wants compute and a place to put it to work. Stripe wants to sit closer to how AI companies spend money, not only how they collect it. OpenAI is using a change-of-control clause because it does not trust the new owner. Each of those motives is ordinary. The surprise is ours. We got used to treating editors, routers, and model APIs as if they were closer to electricity than to vendors.
They were never electricity.
This pattern showed up more than a year ago, in a quieter form. In June 2025, Anthropic cut most of Windsurf's first-party access to Claude after reports that OpenAI might buy the company. Jared Kaplan, Anthropic's co-founder, put the logic plainly: "I think it would be odd for us to be selling Claude to OpenAI." Windsurf had been a customer. Then it looked like it might become a competitor's customer. The model stopped behaving like a utility and started behaving like a product with an owner.
Once you see it, you start noticing how much of the current stack was sold on the opposite promise. Use any model. Route to the best one. Bring your own tools. The pitch was interoperability. The fine print was always that access is a contract, and contracts have change-of-control clauses.
I do not think the lesson is "never use a platform." That is a fantasy, and a tiring one. Almost everything worth building now sits on someone else's model, cloud, payment rail, or distribution channel. The useful lesson is narrower. Neutrality is a market position. It lasts as long as independence is more valuable than belonging to someone larger.
OpenRouter's post is honest about that tension. The company says there were few buyers it would have considered, because its mission, its neutrality, and its lead all argued for staying independent. It chose Stripe anyway, on the theory that Stripe is the rare parent that has spent a decade being trusted not to pick winners among its customers. Maybe that turns out to be right. Stripe has earned some of that reputation. But a reputation is not the same thing as a structural guarantee. After the deal closes, OpenRouter's neutrality will have to compete with Stripe's other interests, in the same way Cursor's model menu now has to compete with SpaceX's.
There is a quieter version of the same fight happening in standards.
On August 6, Vercel, together with people from AWS, Cursor, GitHub, Microsoft, and OpenAI, shipped Agent Plugins 1.0, an open format for packaging agent skills and tools so they can move between clients. The specification is deliberately small. It says how to lay out a directory. It leaves installation, distribution, policy, and user experience to each product. That split is the whole plot. The industry will share a file format. It will not share power.
I suspect this is what the next few years of software will look like. The portable floor gets standardized just enough to calm developers down. The layers that actually matter keep consolidating: who you can call, on what terms, through which product, with whose compute. We will get more open manifests and fewer independent companies in the middle.
If you are building something, this changes the kind of risk that is easy to ignore.
For a long time, the default founder worry about vendors was outage, price, or lock-in in the old sense: switching costs, messy exports, a bill that only goes up. Those still matter. Sitting on top of them now is a political risk that used to be reserved for operating systems and app stores. Your coding tool can be acquired by a company your model provider already does not trust. Your router can be acquired by the company that processes your payments. Neither of those used to be a normal Tuesday.
Truell's 5 percent figure, if it holds, is supposed to be reassuring. Most Cursor traffic already goes elsewhere. Anthropic, for its part, said it would continue supporting Claude inside Cursor. That may be enough for users this autumn. It does not make the underlying issue smaller. If a layer is truly infrastructure, losing one supplier should be boring. The fact that it is news tells you the layer was never as boring as it claimed to be.
I keep wondering what a more honest posture would look like.
It would probably sound less like a utility and more like a supplier. It would name the owner, the competitors, and what happens to your access if that list changes. Some of that already exists in contracts. Almost none of it exists in the way these products are explained to the people who depend on them.
The internet had a long stretch where a handful of protocols really were ownerless, and a long stretch after that where we pretended newer products were protocols too. HTTP does not have a change-of-control clause. Your editor does. Your model API does. Your router does. Mixing those two categories up is becoming an expensive habit.
I am not arguing that independent tools were a golden age, or that big companies cannot run a fair marketplace. Sometimes they can. Stripe's whole business depends on not quietly kneecapping customers. That incentive is real. It is also specific. It does not automatically transfer to every other company that buys a "neutral" product and promises to keep it that way.
The simpler conclusion is the one I trust. If a layer matters to what you are building, assume it can pick a side. Design as if the middle of the stack has a counterparty, because it does. Neutrality was a good sales pitch. It was never a law of physics.
]]>Let me tell you about Sullivan & Cromwell.
One of the most storied law firms in the United States — over 900 lawyers, blue-chip clients, a reputation built across two centuries — walked into a federal bankruptcy court in April 2026 and issued an apology. The filing they had submitted contained inaccurate legal citations. Errors produced by artificial intelligence.
It made international headlines. But here is the thing: it was not an American story. It was a global one.
A French researcher named Damien Charlotin, who maintains the most comprehensive public database of AI hallucination cases in legal proceedings, has now catalogued over 1,353 such incidents across courts worldwide — with the pace accelerating sharply. The United States accounts for the largest share, but cases have been documented in the United Kingdom, Canada, Australia, and beyond. Reported incidents have grown from roughly two per week in early 2025 to two or three per day by the end of the year.
We have crossed a threshold. AI is no longer a curiosity being tested in the corner of a law firm's IT department. It is embedded in the workflow of practitioners on every continent. And it is, regularly and consequentially, getting things wrong.
So here is the question that the legal profession is now being forced to answer in real time — everywhere: When the AI lawyer gets it wrong, who pays?
To understand the liability question, you first need to understand what AI hallucination actually looks like in a legal context. It is not always clumsy or obvious. It often looks authoritative — exactly like the kind of citation a careful associate would produce after a long night in a law library.
Courts across multiple jurisdictions have identified the same recurring categories. First: citations to cases that simply do not exist — invented docket numbers, invented parties, invented holdings. Second: fabricated citations to real cases, where the case exists but the quoted passage does not. Third, and most insidious: citations to real quotes from real cases that directly contradict the legal proposition being argued.
That third category should frighten every practitioner. Because it does not just waste a judge's time — it can actively mislead a court on the state of the law.
An Australian federal court put the nomenclature issue bluntly in JML Rose Pty Ltd v Jorgensen in August 2025, refusing to call these outputs "hallucinations" at all: "More properly, such erroneously generated references are simply fabricated, fictional, false, fake and as such could be misleading." That framing matters. The word "hallucination" sounds like an accident. "Fabricated" sounds like what it actually is when it reaches a court unchecked.
The geographical spread of documented incidents tells you everything about the scale of the problem.
In the United Kingdom, the Divisional Court dealt with exactly this issue in Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank in 2025. A solicitor had relied on case citations provided by their client — citations that turned out to be fabricated or inaccurate material sourced from generative AI. The key finding: despite the client being the original source of the error, the solicitor was held accountable for failing to verify the information. The duty to the court transferred to the lawyer regardless of where the error originated. The Bar Council of England and Wales had already warned in 2024 that blind reliance on AI risked incompetence or gross negligence. The Law Society followed in May 2025 with a checklist that effectively codified AI literacy as a baseline professional competence. Courts, the Judicial Office made clear in April 2025, will forgive litigants in person for AI errors. They will not forgive regulated lawyers.
In Canada, the Ontario Superior Court confronted Ko v Li in 2025, a matrimonial case in which the applicant's counsel submitted a factum relying on several "Canadian court cases" that could not be located. When the judge investigated, one hyperlink directed the reader to a completely unrelated case; another produced a 404 error. The lawyer faced contempt of court sanctions. The case demonstrated that the hallucination problem is not confined to the large commercial litigation and corporate law contexts where it first attracted attention — it is present in family courts, in routine disputes, wherever AI tools are accessible.
In Australia, the Federal Court in Murray on behalf of the Wamba Wemba Native Title Claim Group v State of Victoria flagged AI-generated errors in 2025, and Australian legal bodies have issued increasingly detailed guidance in response. A joint statement from the Law Society of New South Wales, the Legal Practice Board of Western Australia, and the Victorian Legal Services Board was unambiguous: lawyers cannot safely enter confidential client information into public AI tools, and commercial AI tools require careful contractual review before any client data is processed through them.
In the United States, the sanctions wave has been the most extensively documented. US courts imposed over $145,000 in AI hallucination sanctions in the first quarter of 2026 alone. Oregon handed down a record $110,000 penalty. Nebraska issued what appears to be the first licence suspension directly tied to AI misconduct. The Sixth Circuit Court of Appeals dismissed a case entirely in March 2026, citing "pervasive misconduct" that rendered the appeal "almost entirely frivolous." And then there is Gordon Rees Scully Mansukhani — a top-100 firm by revenue — which apologised, updated its AI policies, implemented citation-checking procedures, and then, according to a subsequently filed brief, apparently submitted fabricated citations again.
The common thread across all of these jurisdictions is identical: the courts have been unambiguous that responsibility for accuracy never transfers to the machine.
The practising lawyer is, for now, the answer — everywhere. The Colorado Supreme Court stated it plainly in a case involving a suspended attorney: "The use of artificial intelligence does not relieve an attorney of the obligation to verify the accuracy of all representations made to the court." This principle is not distinctively American. It reflects the basic structure of professional duty that exists in every common law jurisdiction and in the civil law traditions of continental Europe. The technology changes; the duty of candour does not.
The concept of "willful blindness" is doing a lot of work in judicial reasoning. By 2026, after years of widely publicised sanctions, warnings from bar associations globally, and professional guidance in virtually every jurisdiction, the argument that a practitioner was unaware of the hallucination risk simply does not hold. Courts are treating it as equivalent to knowing the risk and choosing to look away.
What about the vendors?
This is where it gets genuinely complicated — and where different jurisdictions are beginning to diverge in potentially significant ways.
Legal AI products are sold on the premise that they are specifically designed for legal research, with safeguards that generic tools lack. Yet the sanctions wave includes incidents involving purpose-built commercial legal tools, not just general consumer AI. The terms of service for nearly every legal AI product currently disclaim accuracy warranties and push responsibility back onto the user. Those disclaimers have not yet been seriously stress-tested in a products liability context. But the first major malpractice claim attributable to a commercial legal AI tool will test them — and some will not survive.
In the European Union, the regulatory framework is hardening in ways that may accelerate this reckoning. The EU AI Act is approaching its most significant enforcement milestone: most core obligations take effect on August 2, 2026. The Act is explicit that AI may support the decision-making of judges but must not replace it — and it codifies in law the human oversight principle that courts have been developing through hallucination case decisions. Critically, the EU AI Act has extraterritorial reach: it applies to any provider or deployer of AI systems whose outputs are used within the EU, regardless of where the company is based. Legal technology vendors operating internationally cannot treat European compliance as optional. Penalties for the most serious violations exceed GDPR maximums — up to €35 million or 7% of worldwide annual turnover, whichever is higher.
What about the firm?
Supervising partners carry exposure that may be underestimated. Courts in the United States have been clear that supervisory responsibility does not evaporate because the AI error originated with a junior associate or an external tool. If the signature is on the filing, the signatory is accountable. Over 35 US state bar associations have issued guidance extending supervisory obligations explicitly to AI use by junior staff. UK and Australian bodies have taken equivalent positions. A firm that allows AI tools to operate in client work without meaningful oversight, without verification protocols, and without training on hallucination risks is not merely negligent in the colloquial sense. It may be negligent in the legal sense — with all the malpractice exposure that implies.
There is a liability question embedded in all of this that the profession has been reluctant to surface directly: what happens when the AI error is not a fabricated citation, but a subtler analytical failure?
Fake case citations get caught, eventually, because judges check. They are embarrassing and sanctionable, but they are also recoverable — the filing gets struck, the attorney gets fined, the case continues.
What about an AI-generated contract analysis that misses a governing-law clause? What about a due diligence report that fails to flag a material liability because the model was not current on a recent regulatory development? What about a cross-border compliance survey that passes clean because the AI did not capture a jurisdiction-specific rule enacted three months ago — a rule that now exposes a client to criminal liability?
These failures are harder to detect, harder to attribute, and potentially far more costly. A Baker McKenzie partner observed in January 2026 that faulty citations in court filings are identified relatively easily, but oversights in complex contracts, due diligence reports, and regulatory surveys will prove much harder to catch. That is not a reassuring framing. That is a warning about the next phase of this problem.
There is also a dimension that Australian legal bodies have been particularly forthright about, and that deserves wider attention: legal professional privilege. A US federal court held in February 2026, in United States v Heppner, that material processed through AI may lose the confidentiality necessary to sustain a privilege claim — and that advice generated by AI, rather than by a lawyer, may never attract privilege in the first place. Uploading client documents to a public AI platform is, in the view of multiple courts and regulators, inconsistent with maintaining confidentiality. The implications for cross-border transactions and international arbitration, where privilege questions are already complex, are significant and barely discussed.
The emerging global picture is one of convergence on principle — human oversight is mandatory, verification is non-delegable, the machine cannot be blamed — and divergence on mechanism. The EU is moving toward binding statutory obligations with substantial penalties. The UK is relying on existing professional regulators and guidance rather than new legislation. The United States is locked in a federal-versus-state conflict over AI regulation that has left practitioners uncertain about which rules apply. Australia is advancing through professional body guidance rather than primary legislation, at least for now.
The result is a patchwork that works reasonably well for a domestic practitioner in a single jurisdiction and poorly for any lawyer doing international work. A firm advising a client on a cross-border acquisition using AI tools across multiple jurisdictions faces a matrix of professional obligations, privilege risks, confidentiality rules, and regulatory requirements that no current AI tool is designed to navigate.
That gap — between how legal AI tools are marketed and what international legal practice actually requires — is where the next wave of liability exposure is quietly accumulating.
I am not arguing that lawyers should not use AI. They should. The efficiency gains are real, the access-to-justice implications are significant, and the practitioners who refuse to adapt will ultimately harm their clients.
But the current moment — in which adoption is racing ahead of both ethics rules and product accountability, across every jurisdiction simultaneously — is genuinely risky. Courts from London to Toronto to Sydney to New York are losing patience in parallel. The jurisprudence is developing faster than the professional frameworks designed to contain it.
When the first major malpractice verdict attributable directly to AI-generated error lands — and it will — the question "who's liable?" will have an answer. The profession should not wait for a court to provide it.