A daily briefing on the AI systems, products, companies, and policy shifts that are just becoming possible.
Want a podcast for your own topics? Join early access: https://www.barelypossible.to/waitlist/?source_path=public_feed&feed_source=rss
Okay kiddos, I'm your boy Tony DeLuca, and we've got a fresh plate of tech stories cooling on the windowsill this morning, so grab your coffee, pull up a chair, and let's have at it. This is Barely Possible.
Today we've got a story that I think is going to keep a lot of founders up at night, and it's not the usual model-release hype. It's about what happens to your company's data when your company dies. We've also got a great little cloak-and-dagger cybersecurity tale, a real reckoning on how the public actually feels about AI, some VC bad blood, and a story about grown adults betting money on twelve-year-olds playing baseball. Yeah. We're gonna get to that one.
But let's start with the one that matters most if you build companies for a living.
There's a piece out from Ars Technica, reported by Ashley Belanger, and the headline is blunt: flight attendants are freaking out that Google is buying tons of Spirit employee data. Now, before we go further, let me give you the honest framing. The underlying auction here happened back on August 14th, and the reporting picked up momentum with a court filing this week. So this isn't a brand-new bombshell that dropped this morning. But the objection, the fight, that's live, and there's a hearing scheduled in September. So this is a story still in motion, and the questions it raises are exactly the kind of thing you want to be thinking about before you ever need to.
Here's the setup. Spirit Airlines went bankrupt. The airline shut down overnight back on May 2nd. And when a company goes bankrupt, its assets get auctioned off to the highest bidder. Now normally when you think bankruptcy asset sale, you think planes, gates, brand name, maybe a customer list. But this auction included something else. Something that a year ago nobody would've thought to bid on. The airline's entire employment and workplace record. We're talking roughly 100 million employee emails. HR files. Payroll data. And data measuring, and I'm quoting the article here, "employee behaviors, activity, and productivity." Decades of it.
And Google won it. They opened at 5 million, they fought off other bidders for two and a half hours, and they closed it at 10 million bucks. Their fiercest rival, according to the court filing, was a company called Mercor, which is an AI data-labeling outfit. Mercor kept trying to bid on terms where they'd scrub the data themselves. Google won partly because they agreed to pay for a third-party service to strip out the personal information first, and to use a court-appointed ombudsman to oversee that whole scrubbing process. Mercor's backup bid, at 7.5 million, is the fallback if Google walks.
Now, why does Google want a bankrupt discount airline's internal Teams chats? Let me read you what the Google spokesperson said, because it's the whole ballgame. Quote: "We acquired part of an enterprise dataset from Spirit Airlines, which can be helpful in improving our products and AI models." End quote. There it is. They want to train agents on how a real company actually operates. How work gets done. The mundane back-and-forth of a functioning business. That's the third gold rush of the AI era, folks. First they scraped the whole internet. Then they bought up the codebases of dead startups. Now they want the internal communications of dead companies, because that's the raw material for building agents that can do white-collar work.
Okay. So here's where it gets interesting, and here's why this is a founder story and not just a privacy story.
The flight attendants' union, the AFA, filed an objection. And their argument is genuinely sharp. Let me read you the line that stopped me. Quote: "The privacy architecture of this transaction is consumer-facing; its payload is disproportionately employee-facing." End quote.
Let me translate that, because it's the crux of everything. Google's privacy promises were built around consumer protection law. They're going to strip out personally identifying information, the PII, so no individual customer can be identified. Fine. Except the data they're actually buying isn't customer data. Look at what's included versus excluded. The union laid it out. Customer profiles, loyalty data, active email addresses, call recordings, phone numbers, DOT complaints, all designated "Not Included." And then under the heading "Team Member": time card information, employee records, business travel records, crew training records, payroll records, tax forms, employee documents. All designated "Included."
So the privacy protections were architected to protect customers, and then they went and bought the workers. The workers got the leftover protections designed for somebody else.
And here's the part that really matters technically, and I want you to sit with this one. The union makes a distinction that I think a lot of people who casually say "oh it's de-identified, it's fine" completely miss. Here's their language. Quote: "Deidentification addresses whether a record can be traced to a named individual. It does not address whether the contents of the record are confidential." End quote.
Read that again. Stripping the name off a record does not make the record not sensitive. The union spells it out beautifully. A flight attendant's disciplinary correspondence. A crew training deficiency. A leave request. An internal chat about a staffing grievance or beef with management. A payroll adjustment history. Every one of those stays sensitive whether or not your name is attached to it. Because in a small, tightly-structured population, you can figure out an awful lot from the shape of the data. Which crew bases generated the grievances. Which employees were under investigation. What compensation changes followed which events. What people said about their union.
And Google's covenant, their binding promise, only covers intentional re-identification. The union's point is that the risk isn't intentional. It's inferential. When you combine a decade of linked operational data about a small group with everything else you know, you can reconstruct things about identifiable people without ever trying to un-mask a single name.
Now, to be fair, and I always try to be fair, the union itself acknowledged that Google's public commitments against re-association were, quote, "real and were not obviously required." So they're not accusing Google of acting in bad faith here. And a source close to the sale told Ars that Google won't ever touch the original identifiers, and the scrubbing happens before Google even receives the data. That's a real safeguard. I'm not going to pretend it isn't.
But the EFF privacy lawyer, Adam Schwartz, put the philosophical objection cleanly. Quote: "EFF opposes using a person's data for a new purpose without first getting their consent, which does not happen when a bankrupt company sells its employees' emails to become AI training data." End quote. Nobody at Spirit signed up, when they took a job as a flight attendant, for their decade of internal emails to become training fuel for a trillion-dollar company's agents.
So here's why I'm making this the centerpiece for you, the builder. Two takeaways, and they cut in opposite directions.
First takeaway, if you're building. Your internal communications are now an asset with a dollar value. Your Slack, your email, your Teams, your meeting transcripts, your HR files. In a world where AI labs are paying real money for exactly this material, that stuff is no longer just operational exhaust. It's a balance sheet item that could get sold out from under everyone, employees included, in a bankruptcy. And when you signed your employees' offer letters, I promise you nobody contemplated this. So if you care about your people, this is the moment to think about what your data governance and your bankruptcy provisions actually say. Because "de-identified" is doing a lot less work than people think.
Second takeaway, and this one's more strategic. Watch this space, because a court is about to weigh in on whether worker confidentiality is a real thing that survives de-identification. The AFA is asking the court to block the sale until Google agrees to exclude all flight attendant information, or at minimum extend the same protections to workers that it extended to consumers. If the court sides with the union, that reshapes what "clean" training data even means. It means the labels on the tin, "PII removed," stop being a legal safe harbor. And that changes the economics for everybody buying corporate data to train agents. It'd make datasets more expensive, harder to scrub, and legally riskier. Which, if you're one of the many startups trying to do white-collar automation, matters to your cost structure whether you ever touch airline data or not.
And let me connect this to the ledger, because we've been circling data and surveillance a fair bit this stretch. Earlier this week we did the Flock license-plate camera story, towns fleeing a surveillance network. And the week before, that Leonardo SignalTrace thing, linking phone signals to license plates. This Spirit story is the same underlying anxiety wearing a different suit. It's the question of whether the digital traces you leave behind, at work, on the road, in an email, belong to you or belong to whoever ends up holding them. The difference here is it's not a police tool or a surveillance vendor. It's a mundane bankruptcy auction. Which is almost scarier, because it means the mechanism is already routine.
Alright. Let me shift from data at rest to data under attack, because there's a cybersecurity story here that's just a good yarn, and it's got a lesson buried in it.
TechCrunch, reporting by Zack Whittaker, picking up on new Bloomberg reporting. The headline: T-Mobile "chopped a cable" to expel Chinese hackers from its network. And yeah, they mean that literally.
Here's the background. Back in 2024, there was a whole campaign of intrusions into American telecom by a Chinese state-backed group called Salt Typhoon. This was a big deal. They compromised hundreds of phone companies, internet giants, data center providers. The named victims include AT&T, Verizon, the satellite outfit Viasat, and infrastructure companies Charter and Windstream. The goal was to collect phone records and information on senior U.S. government officials, including, at the time, presidential candidates. Serious nation-state stuff.
Now, T-Mobile largely dodged the widescale breach. And the way they did it is the part that's going to stick with you. Their cyber staff spent months, months, hunting for these hackers in their network and coming up empty. Eventually they found unusual behavior on one of their systems, and it was coming from a router that belonged to a different telecom company. So the hackers were essentially reaching in through a connection to somebody else's compromised network.
And here's what T-Mobile's cybersecurity chief, Jeff Simon, told Bloomberg they did about it. He and three other guys got in a car, drove to a data center near their Bellevue, Washington headquarters, found the compromised box, pulled out a set of scissors, and snipped the cable connecting it to the outside world.
Scissors. Four guys and a pair of scissors, in the year 2024, versus a Chinese government hacking operation. I love this. And I want to be careful, because it sounds like a punchline, but there's a real lesson in there for anybody building systems.
The lesson is that when you're truly compromised, sometimes the most reliable control is physical. All the sophisticated detection, all the software mitigation, they spent months on that and it didn't fully do the job. What worked, in the end, was the ability to physically sever the connection. That air gap, that literal disconnection, is the one thing an attacker on the other end of a wire can't route around. If your incident response plan doesn't have a "how do we physically kill this" option, you've got a gap. Because when the software approach fails, the guy with the scissors is your backstop. There's a certain Bronx wisdom to that, honestly. Sometimes you just gotta unplug the thing.
Now let's move from one company's security to the whole industry's public relations problem, because there's a piece that I think every founder building on AI should read.
Sarah Perez at TechCrunch wrote it, and the title says it all: "AI was supposed to win people over by now — it hasn't." And this is a current piece, this is fresh, published this week.
Here's the thesis, and it's uncomfortable if you're in this business. Despite all the technical progress, AI's reputation with regular people is getting worse, not better. The numbers back it up. Pew Research found 52% of Americans say they're more concerned than excited about AI in daily life. That's up from 37% in 2021. A CNBC poll of 18-to-34-year-olds gave them the names of nine top AI industry leaders, and a majority said they don't trust those people to act responsibly. A YouGov poll found over 70% of Americans think AI is advancing too fast.
And here's where it stops being a vibe and starts being a business problem. The Wall Street Journal reported that tech companies are facing a genuine PR crisis over their data center plans, and it's costing them. They're sweetening deals to get communities to accept these builds. Job guarantees. Clean water investments. In one case, in a Louisiana parish, fifty-thousand-dollar bonuses for teachers. That's not charity. That's the cost of buying social license because the public doesn't want the thing.
Now, we touched on the trust angle earlier this week with Dario Amodei calling the backlash a crisis of trust. And I told you I wasn't going to re-run the same quotes, so I won't. But the Perez piece adds a dimension that I think is the real founder lesson, and it comes from Airbnb's CEO Brian Chesky. Chesky said, and I'm quoting, "part of it is we need to actually be developing more products that just regular people can use and say, 'I love AI because AI allows me to have a doctor on demand and I can't have that. I can't afford that.' And so I think we need more regular things." End quote.
That's the insight, and it's the opposite of the Silicon Valley reflex. The reflex is: people don't like AI because we haven't explained it well enough. It's a messaging problem. But Perez lands on the sharper explanation. Maybe people understand AI just fine, and they've decided the trade-offs aren't worth it. When the upside they're being sold isn't "a doctor on demand" or "shorter workweeks with more pay," but instead "your email got auto-summarized" and "your TV talks to you now" and "your kid can cheat on his homework" and "the threat of losing your job," well, no wonder the skepticism hardens.
And here's my read for you as a builder. There's a whole retro counter-movement in this piece. Young people buying dumbphones. Classic iPods without algorithms going for top dollar on eBay. Knitting, quilting, jigsaw puzzles, run clubs, in-person meetups beating online dating. That's not nostalgia for nostalgia's sake. That's people voting with their attention against a tech ecosystem that stopped serving them. If you're building AI products, the takeaway is dead simple and Chesky nailed it: build the doctor-on-demand, not the chatty TV. Build something a regular person would genuinely miss if you took it away. Because ubiquity did not buy affection. The industry bet that if AI was everywhere, people would come around. Instead it's everywhere and people resent it. That's a real signal, and it's a competitive opportunity for whoever actually ships the useful thing.
Alright, let me lighten the mood, because we can't just do doom all morning.
Travis Kalanick is back in the news, and he's doing what Travis Kalanick does, which is bashing venture capitalists. Now, I'll be honest with the framing here: this is built on a podcast appearance that aired a bit back, so this is an older bit of discourse that got recirculated this week, not a fresh eruption. But it's fun, and there's a nugget of real founder advice in it, so let me pull the useful thread and move on.
Quick recap for anybody who's been off the grid. Kalanick founded Uber, raised something like 15 billion in venture money, became a VC darling, and then got pushed out in a 2017 boardroom battle with Bill Gurley of Benchmark. Now he's back raising huge money for a robotics company called Atoms, which just landed 1.7 billion led by Andreessen Horowitz.
And on David Senra's podcast, Kalanick let it fly. His view of VCs, in his words: a super high bar for a VC is "do no harm," and in his experience only about 10% of them clear even that bar. The ones who are actually helpful? He estimates 1%. His metaphor was that the founder is the chess master of the company and the VC is a "chess enthusiast" who drops in once in a while to check the score.
Now here's the actually useful part, and this is why I'm not just dunking on the guy. Kalanick doesn't tell founders to avoid VC money or to be paranoid about their cap table. His advice is the opposite, and it's mature. He warns founders against what he calls a "victim mentality." His words: "You have to be really careful not to get into victim mentality. By that, I mean, what was my part in that dynamic?" And he's honest about his own Uber exit. He says he stands by his decisions but the optics were a problem, and, quote, "the problem was I ran too close to the line in too many situations." That's a guy taking some accountability, which, for Travis Kalanick, is notable.
There's also a good fundraising tip buried in there. He says share a modestly detailed plan when you pitch. Too little detail and nobody bites. Too much detail and it comes off naive, because the AI world moves so fast nobody can credibly predict the far future. Aim for the pitch honed enough to start a bidding war. That's practical.
I'll note one bit of theater. Andreessen Horowitz, which is leading Kalanick's round, was very eager to amplify all this online, pointing people back to the podcast. And a16z's Marc Andreessen has his own history with Gurley, once called him "my Newman" in a New Yorker profile, the Seinfeld nemesis reference. So the enthusiasm for Kalanick trashing Benchmark isn't exactly disinterested. Everybody's got a dog in this fight. Anyway, the founder lesson stands on its own: pick your investors carefully, but don't spend your energy as a victim. Ask what your part in the dynamic was. That's good advice from an imperfect messenger.
Now, staying in the AI-business lane for a second, there was a report this week that SpaceX tried to acquire the AI coding startup Cognition, the folks behind the Devin agent. And I want to flag it mostly to be responsible about it, because Cognition's CEO Scott Wu came out and disputed the report almost immediately, said the story was inaccurate, said the company is not for sale, said the two companies haven't been in talks. So I'm not going to spin a narrative out of a report the subject flatly denies. What I'll say is the context around it is real: SpaceX absorbed xAI, closed a 60 billion dollar acquisition of Cursor last week, and Musk has been telling employees that in four or five years AI will be 99% of the company's value. So the ambition is genuine even if this particular deal isn't happening. File it under "watch the space," not "here's what happened."
Let me pivot to the drone story, because it's a nice concrete look at what happens when a futuristic technology actually lands in your neighborhood.
Ars Technica, Jeremy Hsu reporting. Amazon wants its Prime Air delivery drones to reach nearly 500 US neighborhoods by the end of 2026. That's a sixfold expansion. New markets coming to Chicago, Cleveland, Atlanta, Syracuse, Boise. And Amazon's not alone. Walmart's teamed up with Wing and Zipline and just passed a million drone deliveries. Zipline announced a partnership with Uber aiming for a million deliveries a day by 2029. Even DoorDash got its FAA certification for DoorDash Air.
Now the promise is real. Deliveries in half an hour, sometimes minutes. Battery-electric, lower emissions, no delivery van clogging up the street. But here's the trade-off, and it's a very human one. Noise. Let me read you a quote from a resident in Hazel Park, Michigan, because it's perfect. Quote: "It's the equivalent of a flying leaf blower, lawnmower 20 feet over my house, 50 times a day. My dogs lose their minds and get upset." End quote.
And the Reddit threads are full of it. One person in Richardson, Texas wrote that a business gets to loudly disturb their home, unsolicited, unwanted, with no recourse. People in Richardson held an actual public protest over it back in June.
There's a safety dimension too. Amazon's had a rough run, honestly. Two drones crashed into a construction crane in Arizona in October 2025. One took down an internet cable in Waco. One flew into an apartment building in Richardson in February. The Prime Air VP, David Carbon, was refreshingly blunt in a leaked internal meeting, quote: "We trained our algorithms; we felt pretty good, but we found in the real world the performance just wasn't good enough, and let me tell you, that was a humbling experience." End quote. By contrast, Zipline, which flew over 100 million miles and puts backup parachutes on its drones, has the cleanest record.
Now why does this matter to you as a builder, beyond being interesting? Because it's the same theme as the AI backlash story, just with propellers instead of chatbots. Here's a technology that is objectively convenient, that works, that's cheaper and greener, and the public is still filing noise complaints and holding protests. The gap between "the technology functions" and "the community welcomes it" is enormous, and companies keep being surprised by it. Amazon says its cameras only navigate, no live feed monitored by a person, no tracking. Doesn't matter. People feel surveilled and annoyed and they didn't ask for four drones over their sunbathing. Whether you're shipping agents or aircraft, the lesson repeats: adoption is not acceptance, and the social license has to be earned, not assumed. If you're building anything that intrudes on people's physical or digital space, budget for that resistance up front, because it's not going away.
Now let me get to the one I promised you at the top. The one that made me put my coffee down.
TechCrunch, Amanda Silberling reporting. People are gambling on the Little League World Series. And yes, I mean grown adults putting money on the outcomes of games played by ten-to-twelve-year-olds.
Here's the situation. The state-regulated sportsbooks won't touch it. The federally-regulated prediction markets, Kalshi, Polymarket, they don't allow it either, though Polymarket apparently did offer it back in 2024. But offshore books like BetOnline don't have to follow US law. So they offer odds on children playing baseball.
And here's the quote from BetOnline's brand manager, Dave Mason, that tells you exactly where we are as a society. Quote: "We offer Little League World Series odds because there's a massive demand for it. Our customers request these odds every year, and we'll take more bets on the LLBWS over the next two weeks than on established markets such as the WNBA, Major League Soccer, pro tennis or golf." End quote. He also claimed more people are wagering on a Little League matchup between South Korea and Canada than on certain Major League Baseball games. And bettors put in twice as much money in 2025 as they did in 2024.
Little League itself reposted a statement this week, reminding everyone, quote: "Little League is a trusted place where children are learning the fundamentals of the games... and no one should be exploiting the success and failures of children playing the game they love for their own personal gain." End quote.
Look. I don't have a founder takeaway that's going to make you a better product manager here. But I do have a thought, and it ties to something we care about on this show, which is where the prediction-market and betting economy is heading. Everybody in tech is excited about Kalshi and Polymarket and the idea of markets on everything. And I get the appeal, real price signals, real information. But this is the shadow side of "bet on anything." The infrastructure for wagering on any outcome doesn't come with a conscience built in. The regulated players drew a line here, good for them. But the offshore books exist precisely to route around lines. So when you hear the utopian pitch about prediction markets pricing all of human knowledge, keep this in the back of your mind: someone is already taking action on twelve-year-olds dropping fly balls on national television. The technology is neutral. The demand, apparently, is not. Anyway. That one's just gross, and I wanted you to know about it.
Let me do a quick lightning round of the developer and product stuff, because there was a batch of it and a couple pieces are worth thirty seconds each for the people building.
OpenAI put out a bunch of announcements. One that caught my eye: a case study saying Asana used Codex to replace an outdated testing system in two weeks, work that was expected to take five years, for about twelve thousand dollars. Now, always take a vendor case study with a grain of salt, that's a marketing artifact, not an audited result. But if even directionally true, that five-years-to-two-weeks compression is the kind of thing that reprices what an engineering backlog is even worth. Worth watching whether that holds up outside a press release.
OpenAI also reaffirmed Zero Data Retention for eligible API customers and previewed something called Private Safety Processing. For you builders in regulated environments, that data-retention posture is a real procurement consideration, so keep an eye on it. They expanded ChatGPT Ads to 31 European markets, which tells you the monetization machine is spinning up hard. And Replit launched a Free Mode powered by GPT-5.6 Luna so people can build software without worrying about token costs, which continues the trend of everybody racing the price of building down toward zero to grab the developer market.
And there was a short TechCrunch video piece about a startup called Silicon Data trying to help Wall Street put a price on AI compute, and let firms hedge their exposure when that price moves. I couldn't get the full details, but the concept alone is worth flagging: compute is now the single biggest cost for anyone building AI products, and there still isn't a clean way to price it or hedge it. If you're spending real money on GPUs, a financial instrument that lets you lock in or hedge compute costs is the kind of infrastructure that quietly matters a lot. That's a space to watch.
Okay. Let me bring it home.
If there's a thread running through today, it's this. We had the Spirit data sale, where the value of a company turned out to be its employees' emails. We had the AI backlash piece, where the public decided ubiquity wasn't the same as usefulness. We had the drones, where a working technology still can't buy its way into people's good graces. And even the Little League betting mess, where the infrastructure for a thing raced ahead of anyone asking whether we should. The common denominator is the gap between what's technically possible and what people will actually accept. And that gap is where a lot of the real business risk lives right now. The builders who win this next stretch aren't going to be the ones with the flashiest model. They're going to be the ones who understood that the human on the other side of the product has a vote, and started earning that vote early instead of assuming it.
That's the menu for today. Chew on it.
I'm Tony DeLuca, this has been Barely Possible, and I'll be right here tomorrow with another plate. Be good to each other out there.