The Tesla Semi could be a big deal for electric trucking

The Tesla Semi has officially arrived. The company recently released a photo of the first vehicle rolling off its new full-scale production line.

This moment has been nearly a decade in the making: The company first announced the Tesla Semi in late 2017. And now we’ve got final battery specs, official prices, and big news about big orders.

The Semi is a relatively affordable electric semitruck with pretty impressive performance. It also comes at a moment when Tesla has lost its grip on the global electric vehicle market. Let’s talk about what’s new with the Tesla Semi and why this could be a breakout moment for electric trucking.

Medium- and heavy-duty vehicles, like buses and semitrucks, make up a small fraction of vehicles on the road but contribute an outsize fraction of pollution, including both carbon dioxide emissions and other pollutants like nitrogen oxides (NOx) and small particles. Globally, trucks and buses represent about 8% of total vehicles on the road, but they create 35% of carbon dioxide emissions from road transport.

Tesla’s latest addition to its vehicle lineup, the Class 8 Semi, could be part of the solution to cleaning up this polluting sector. (I’ll note here that I briefly interned at Tesla in 2016. I don’t have any ties to or financial interest in the company today.) 

In November 2017, Elon Musk took to the stage at a lavish event in LA to announce the Semi. At that event, Musk promised a truck that could go from zero to 60 miles per hour in five seconds, could achieve a range of 500 miles, and would come with thermonuclear-explosion-proof glass. (Remember the era before the Twitter takeover and DOGE, when this was what Musk was known for? A simpler time.)

Soon after the unveiling, major corporations including Walmart put in early orders for Tesla Semis. Deliveries were expected in 2019.

That deadline obviously didn’t work out. The date was pushed back several times, and Tesla did start delivering a small number of pilot trucks, beginning in 2022. But this year, things got more serious, with the company releasing its final production specifications in February and rolling its first Semi off its high-volume production line in late April. 

And last week, WattEV announced an order of 370 Tesla Semis. WattEV offers electric freight operations, essentially providing trucks as a service to companies so they don’t have to purchase their own or supply their own charging infrastructure. The company will pay over $100 million for the new trucks, and the first 50 should be delivered this year, with the full fleet expected by the end of 2027. Those trucks will be supported by megawatt-charging systems located in Oakland, Fresno, Stockton, and Sacramento.

With the factory up and running and a huge order on the books, it feels like the Tesla Semi has truly arrived. And some of Musk’s claims from 2017 ring true: The base model has a range of about 320 miles, and the long-range version about 480 miles (quite close to his 500-mile claim).

Delivering this much range for this big truck means a whopping battery. The base model Tesla Semi battery pack has a usable capacity of 548 kilowatt-hours, according to a document filed with the California Air Resources Board (CARB). But the battery is even more massive in the long-range version, which boasts a whopping 822 kilowatt-hour battery. Compare these to the Tesla Model 3, which typically comes with a 64 kilowatt-hour pack.

I reached out to Tesla to confirm the battery size and ask other questions for this article—the company didn’t respond.

These trucks cost quite a bit more than they were expected to in 2017, though. At that time, the expected price was $150,000 for the base model and $180,000 for the long-range. Today, Tesla is pricing the trucks at $260,000 and $300,000, respectively, according to documentation filed with CARB.

That’s considerably more expensive than the median diesel truck being sold today, which rang in at $172,500 for the 2025 model year, according to research from the International Council on Clean Transportation. But it’s much cheaper than similar battery-electric trucks available today, where the median is about $411,000.

And in California, where companies can get vouchers that cover $120,000 towards the purchase price of an electric truck, the Tesla Semi is competitive right away, especially since electric trucks tend to be much cheaper to run and maintain than diesel ones.

Over the years, it wasn’t always clear that the Tesla Semi would ever actually hit the roads. (At that same 2017 event, Musk announced a new Roadster sports car, and that’s nowhere to be seen.) So it’s encouraging to see the factory starting up, and a large order that looks like it could lend this project some commercial momentum.

Tesla had a massive impact on the electric vehicle market, and if it can scale production and support charging infrastructure, it could help do the same for trucking.

This article is from The Spark, MIT Technology Review’s weekly climate newsletter. To receive it in your inbox every Wednesday, sign up here

The shock of seeing your body used in deepfake porn 

When Jennifer got a job doing research for a nonprofit in 2023, she ran her new professional headshot through a facial recognition program. She wanted to see if the tech would pull up the porn videos she’d made more than 10 years before, when she was in her early 20s. It did in fact return some of that content, and also something alarming that she’d never seen before: one of her old videos, but with someone else’s face on her body.

“At first, I thought it was just a different person,” says Jennifer, who is being identified by a pseudonym to protect her privacy. 

But then she recognized a distinctly garish background from a video she’d shot around 2013, and she realized: “Somebody used me in a deepfake.”

Eerily, the facial recognition tech had identified her because the image still contained some of Jennifer’s features—her cheekbones, her brow, the shape of her chin. “It’s like I’m wearing somebody else’s face like a mask,” she says. 

“It’s like I’m wearing somebody else’s face like a mask.”

Conversations about sexualized deepfakes—which fall under the umbrella of nonconsensual intimate imagery, or NCII—most often center on the people whose faces are featured doing something they didn’t really do or on bodies that aren’t really theirs. These are often popular celebrities, though over the past few years more people (mostly women and sometimes youths) have been targeted, sparking alarm, fear, and even legislation. But these discussions and societal responses usually are not concerned with the bodies the faces are attached to in these images and videos.

As Jennifer, now 37 and a psychotherapist working in New York City, says: “There’s never any discussion about Whose body is this?” 

For years, the answer has generally been adult content creators. Deepfakes in fact earned their name back in November 2017, when someone with the Reddit username “deepfakes” uploaded videos showing faces of stars like Scarlett Johansson and Gal Gadot pasted onto porn actors’ bodies. The nonconsensual use of their bodies “happens all the time” in deepfakes, says Corey Silverstein, an attorney specializing in the adult industry. 

But more recently, as generative AI has improved, and as “nudify” apps have begun to proliferate, the issue has grown far more complicated—and, arguably, more dangerous for creators’ futures. 

Porn actors’ bodies aren’t necessarily being taken directly from sexual images and videos anymore, or at least not in an identifiable way. Instead, they are inevitably being used as training data to inform how new AI-generated bodies look, move, and perform. This threatens the livelihood and rights of porn actors as their work is used to train AI nudes that in turn could take away their business. And that’s not all: Advancements in AI have also made it possible for people to wholly re-create these performers’ likenesses without their consent, and the AI copycats may do things the performers wouldn’t do in real life. This could mean their digital doubles are participating in certain sex acts that they haven’t agreed to do, or even that they’re perpetrating scams against fans. 

Adult content creators are already marginalized by a society that largely fails to protect their safety and rights, and these developments put them in an even more vulnerable position. After Jennifer found the deepfake featuring her body, she posted on social media about the psychological effects: “I’ve never seen anyone ask whether that might be traumatic for the person whose body was used without consent too. IT IS!” Several other creators I spoke with shared the mental toll that comes with knowing their bodies have been used nonconsensually, as well as the fear that they’ll suffer financially as other people pirate their work. Silverstein says he hears from adult actors every day who “are concerned that their content is being exploited via AI, and they’re trying to figure out how to protect it.” 

One law professor and expert in violence against women calls these creators the “forgotten victims” of NCII deepfakes. And several of the people I spoke with worry that as the US develops a legal framework to combat nonconsensual sexual content online, adult actors are only at risk of further injury; instead of helping them, the crackdown on deepfakes may provide a loophole through which their content and careers could be stripped from the internet altogether.

How deepfakes cause “embodied harms”

During his preteen years in the 1970s, Spike Irons, now a porn actor and president of the adult content platform XChatFans, was “in love” with Farrah Fawcett. Though Fawcett did not pose nude, Jones managed to get his hands on what looked like pictures of her naked. “People were cutting out faces and pasting them on bodies,” Irons says. “Deepfakes, before AI, had been going around for quite a while. They just weren’t as prolific.”

The early public internet was rife with websites capitalizing on the idea that you could use technology to “see” celebrities naked. “People would just use Microsoft Paint,” says Silverstein, the attorney. It was a simple way to mash up celebrities’ faces with porn. 

People later used software like Adobe After Effects or FakeApp, which was designed to swap two individuals’ faces in images or videos. None of these programs required serious expertise to alter content, so there was a low barrier to entry. That, plus the wealth of porn performers’ videos online, helped make face-swap deepfakes that used real bodies prevalent by the 2010s. When, later in the decade, deepfakes of Gal Gadot and Emma Watson caused something of a broader panic, their faces were allegedly swapped onto the bodies of the porn actors Pepper XO and Mary Moody, respectively.

But it wasn’t just high-profile actors like them whose bodies were being used. Jennifer was “a very minor performer,” she says. “If it happened to me, I feel like it could happen to anybody who’s shot porn.” Since he started his practice in 2006, Silverstein says, “numerous clients” have reached out to report “This is my body on so-and-so.” 

Both people whose faces appear in NCII deepfakes and those whose bodies are used this way can feel serious distress. Experts call this type of damage “embodied harms,” says Anne Craanen, who researches gender-based violence at the UK’s Institute for Strategic Dialogue, an organization that analyzes extremist content, disinformation, and online threats. 

The term reflects the fact that even though the content exists in the virtual realm, it can cause physiological effects, including body dysmorphia. The face-swapped entity occupies the uncanny valley, distorting self-perception. After discovering their faces in sexual deepfakes, many people feel silenced, experts told me; they may “self-censor,” as Craanen puts it, and step back from public-facing life. Allison Mahoney, an attorney who works with abuse survivors, says that people whose faces appear in NCII can experience depression, anxiety, and suicidal ideation: “I’ve had multiple clients tell me that they don’t sleep at night, that they’re losing their hair.” 

Independent creators aren’t just “having sex on camera.” For someone to rip off their work “for their own entertainment or financial gain fucking sucks.”

Though the impact on people whose bodies are used hasn’t been discussed or studied as often, Jennifer says that “it’s just a really terrible feeling, knowing that you are part of somebody else’s abuse.” She sees it as akin to “a new form of sexual violence.”

The uncertainty that comes with not being aware of what your body is doing online can be highly unsettling. Like Jennifer, many adult actors don’t really know what’s out there. But some devoted followers know the actors’ bodies well—often recognizing tattoos, scars, or birthmarks—and “very quickly they bring [deepfakes] to the adult performer’s attention,” says Silverstein. Or performers will stumble upon the content by chance; some 20 years ago, for instance, the first such client to tell Silverstein her body was being used in a deepfake happened to be searching Nicole Kidman online when she found that one of the results showed Kidman’s face on her porn. “She was devastated, obviously, because they took her body,” he says, “and they were monetizing it.” 

Otherwise, this imagery may be found by an organization like Takedown Piracy, one of several copyright enforcement companies serving adult content creators. US copyright violations can be challenging to prove if someone’s body lacks distinguishing features, says Reba Rocket, Takedown Piracy’s chief operating and marketing officer. But Rocket says her team has added digital fingerprinting technology to clients’ material to help flag and remove problematic videos, often finding them before clients realize they’re online. 

By capturing “tens of thousands of tiny little visual data points” from videos, digital fingerprinting creates unique corresponding files that can be used to identify them, Rocket says—kind of like an invisible watermark. The prints remain even if pirates alter the videos or replace performers’ faces. Takedown Piracy has digitally fingerprinted more than half a billion videos and the organization has gotten 130 million copyrighted videos taken down from Google alone (though, of those videos, Rocket hasn’t tracked how many of these specifically include someone else’s face on a performer’s body). 

Besides copyright, a range of legal tools can be used to try and combat NCII, says Eric Goldman, a law professor at Santa Clara University. For example, victims can claim invasion of privacy. But using these tools isn’t particularly straightforward, and they may not even apply when it comes to someone’s body. If there aren’t, for instance, unique markers indicating that a body in a deepfake belongs to the person who says it does, US law “doesn’t really treat [this content] as invasion of privacy,” Goldman says, “because we don’t know who to attribute it to.”

In a 2018 study that reviewed “judicial resolution” of cases involving NCII, Goldman found that one successful way plaintiffs were able to win cases was to assert “intentional affliction of emotional distress.” But again, that hinges on the ability to clearly identify the person in the content. Relevant statutes, he adds, might also require “intent to harm the individual,” which may be hard to show for people whose bodies alone are featured.

“AI girls will do whatever you want”

In the last few years, Silverstein says, it’s become less and less common to see the bodies of real adult content creators in deepfakes, at least in a way that makes them clearly identifiable. 

Sometimes the bodies have been manipulated using AI or simpler editing tools. This can be as basic as erasing a birthmark or changing the size of a body part—minor edits that make it impossible to identify someone’s image beyond a reasonable doubt, so even porn actors who can tell that an altered image used their body as a base won’t get very far in the legal realm. “A lot of people are like, That looks like my body,” says Silverstein, but when he asks them how, they’ll reply, It just does

At the same time, other users are now creating NCII with wholly AI-generated bodies. In “nudify” apps, anyone with a minimal grasp of technology can upload a photo of someone’s clothed body and have it replaced with a fake naked one. “So [much] of this content being created is just someone’s face on an AI body,” Silverstein says.

Such apps have drawn a ton of attention recently, from Grok “nudifying” minors to Meta running ads for—and then suing—the nudify app Crushmate. But there’s been relatively little attention paid to the content being used to train them. They almost certainly draw on the more than 10,000 terabytes of online porn, and performers have virtually zero recourse. 

One reason is that creators aren’t able to demonstrate with any certainty that their content is being used to train AI models like those used by nudify apps. “These things are all a black box,” says Hany Farid, a professor at the University of California, Berkeley, who specializes in digital forensics. But “given the ubiquity” of adult content, he adds, it’s a “reasonable assumption” that online porn is being used in AI training. 

“It’s just not at all difficult to come up with pornographic data sets on the internet,” says Stephen Casper, a computer science PhD student at MIT who researches deepfakes. What’s more, he says, plenty of shadowy online communities provide “user guides” on how to use this data to train AI, and in particular programs that generate nudes. 

It’s not certain whether this activity falls within the US legal definition of “fair use”—an issue that’s currently being litigated in several lawsuits from other types of content creators—but Casper argues that even if it does, it’s ethically murky for porn created by consenting adults 10 years ago to wind up in those training data sets. When people “have their stuff used in a way that doesn’t respect or reflect reasonable expectations that they had at that time about what they were creating and how it would be used,” he says, there’s “a legitimate sense in which it’s kind of … nonconsensual.” 

Adult performers who started working years ago couldn’t possibly have consented to AI anything; Jennifer calls AI-related risks “retroactively placed.” Contracts that porn actors signed before AI, adds Silverstein, might provide that “the publisher could do anything with the content using technology that now exists or here and after will be discovered.” That felt more innocuous when producers were talking about the shift from VHS to DVD, because that didn’t change the content itself, just the way it was conveyed. It’s a far different prospect for someone to use your content to train a program to create new content … content that could replace your work altogether. 

Of course, this all affects creators’ bottom line—not unlike the way Google’s AI overviews affect revenue for online publishers who’ve stopped getting clicks when people are content with just reading AI-generated summaries. Performers’ “concern is … it’s another way to pirate [their] content,” says Rocket. 

After all, independent creators aren’t just “having sex on camera,” as the adult content creator Allie Eve Knox says. They’re paying for filming equipment and location rentals, and then spending hours editing and marketing. For someone to then rip off and distort that content “for their own entertainment or financial gain,” she says, “fucking sucks.” 

KIM HOECKELE

Tanya Tate, a longtime adult content creator, tells me about another highly unsettling AI-created situation: She was recently chatting with a fan on Mynx, a sexting app, when he asked her if she knew him. She told him no, and “his eyes just started watering,” Tate says. He was upset because he thought she did know him. Turns out he’d sent $20,000 to a scammer who’d used an AI-generated deepfake of Tate to seduce him. 

Several men, Tate subsequently learned, had been scammed by an AI version of her, and some of them began blaming her for their losses and posting false statements about her online. When she reported one particularly aggressive harasser to the police, they told her he was exercising his “freedom of speech,” she says. Rocket, too, is familiar with situations where AI is used to take advantage of fans. “The actual content creator will get nasty emails from these people who’ve been scammed,” she says.

Other porn actors say they fear that their likenesses have been used without consent to do other things they wouldn’t do. One, Octavia Red, tells me she doesn’t do anal scenes, “but I’m sure there’s tons of deepfake anal videos of me that I didn’t consent to.” That could cost her, she fears, if viewers choose to watch those videos instead of subscribing to her websites. And it could cause fans to develop false expectations about what kind of porn she’ll create.

“I saw one AI creator saying, ‘Well, AI girls will do whatever you want. They don’t say no,’” says Rocket. “That horrifies me … especially if they’re training those AI models on real people. I don’t think they understand the damage to mental health or reputation that that can create. And once it’s on the internet, it’s there forever.” 

Efforts to “scrub adult content from the internet”

As AI technology improves, it’s increasingly difficult for people to discern any type of real video from the best AI-generated ones on their own. In one 2025 study, UC Berkeley’s Farid found that participants correctly identified AI-generated voices about 60% of the time (not much better than random chance), while advances like false heartbeats make AI-generated humans tougher than ever to spot.

Nevertheless, most lawyers and legal experts I spoke with said copyright laws are still adult performers’ best bet in the US legal system, at least for getting their face-swapped content taken down. For his clients, Silverstein says, he tries to figure out the content’s origins and then issue takedown requests under the Digital Millennium Copyright Act, a 1998 law that adapted copyright law for the internet era. “Even recently, I had a performer who has an insanely well-known tattoo,” he says, and with a DMCA subpoena he managed to identify the poster of the content, who voluntarily removed it. 

But this way of working is becoming increasingly rare.

These days it’s nearly “impossible,” Silverstein says, to determine who produced a deepfake, because many platforms that host pirated content operate facelessly. They’re also often based in places that “don’t really care about US law when it comes to copyrights,” says Rocket—places like Russia, the Seychelles, and the Netherlands. 

While governments in the EU, the UK, and Australia have said they will ban or restrict access to nudify apps, it’s not an easily executed proposition. As Craanen notes, when app stores remove these services, they often simply reappear under different names, providing the same services. And social platforms where people share NCII deepfakes, argues Rocket, are slacking in getting them removed. “It’s endless, and it’s ridiculous, because places like Twitter and Facebook have the same technology we do,” Rocket says. “They can identify something as an infringement instantly, but they choose not to.”

(Apple spokesperson Adam Dema emailed, “’nudification’ apps are against our guidelines” in the app store, and it has “proactively rejected many of these apps and removed many others,” flagging a reporting portal for users. A Google spokesperson emailed, “Google Play does not allow apps that contain sexual content,” noting it takes “proactive steps to detect and remove apps with harmful content” and has suspended hundreds of apps for violating its policy. Meta spokesperson shared a blog post about actions it’s taken against nudify apps, but did not respond to follow-up questions about copyrighted material. X did not respond to a request for comment.)

As porn performers are forced to navigate AI-related threats, the only current federal law to address deepfakes may not help them much—and could even make matters worse. The Take It Down Act, which became US law last year, criminalizes publishing NCII and requires websites to remove it within 48 hours. But, as Farid notes, people could weaponize the measure by reporting porn that was made legally and with consent and claiming that it’s NCII. This could result in the content’s removal, which would hurt the performers who made it. Santa Clara’s Goldman points to Project 2025, the Heritage Foundation’s policy blueprint for the second Trump administration, which aims to wipe porn from the web. The Take It Down Act, he argues, “allows for the coordinated effort to scrub adult content from the internet.” 

US lawmakers have a history of hurting sex workers in their attempts to regulate explicit content online. State-level age verification laws are an example; visitors can pretty easily get around these measures, but they can still result in reduced revenue for adult performers (because of lower traffic to those sites and the high price of age-checking services they have to purchase). 

“They’re always doing something to fuck with the porn industry, but not in a way that actually helps sex workers,” says Jennifer. “If they do something, they’re taking away your income again—as opposed to something like giving you more rights to your image, [which] would be tremendously helpful.” 

But as generative AI plays an increasingly large role in NCII deepfakes, the types of images to which adult performers have rights moves deeper into a gray area. Can actors lay claim to AI images likely trained on their bodies? How about AI-generated videos that impersonate them, like the one that tricked Tanya Tate’s fan?

The biggest challenge will be creating “legitimate, effective laws that will absolutely protect content creators from abusing their likeness to train and create AI,” Rocket says. “Absent that, we’re just going to have to keep pulling content down from the internet that’s fake.”

In the meantime, a few porn actors tell me, they’re trying to take advantage of copyright laws that weren’t really made for them; they’ve signed with platforms that host their AI-generated duplicates, with whom fans pay to chat, in part so they’ll have contracts that protect ownership of their AI likenesses. When I spoke with the actor Kiki Daire in September 2025 for a story on adult creators’ “AI twins,” she said she “own[ed] her AI” because she’d signed a contract with Spicey AI, a site that hosted AI duplicates of adult performers. If another company or person created her AI-generated likeness, she added, “I have a leg to stand on, as far as being able to shut that down.”  

Even this, though, is not a sure thing; Spicey AI, for instance, shut down several months after I spoke with Daire, so it’s unlikely that her contract would hold. And when I spoke in October with Rachael Cavalli, another adult actor who had signed with an AI duplicate site in hopes it’d help protect her AI image, she admitted, “I don’t have time to sit around and look for companies that have used my image or turned something into a video that I didn’t actually do … it’s a lot of work.” In other words, having rights to your AI image on paper doesn’t make it easier to track down all the potentially infinite breaches of those rights online.

If she’d known what she knows about technology today, Jennifer says she doesn’t think she would have done porn. The risks have increased too much, and too unpredictably. She now does in-person sex work; it’s “not necessarily safer,” she says, “but it’s a different risk profile that I feel more equipped to manage.” 

Plus, she figures AI is unlikely to replace in-person sex workers the way it could porn actors: “I don’t think there’s going to be stripper robots.” 

Jessica Klein is a Philadelphia-based freelance journalist covering intimate partner violence, cryptocurrency, and other topics.

ASGCT 2026: Timothy Yu Wins Jerry Mendell Award For N-of-1 Therapies

BOSTON – Timothy Yu, MD, PhD, a leading neurogeneticist at Boston Children’s Hospital and Harvard Medical School, was awarded one of the top honors by the American Society of Gene and Cell Therapy (ASGCT), the Jerry Mendell Award.

Yu was recognized for his trailblazing work over the past decade in devising bespoke oligonucleotide therapies for patients with ultra-rare genetic disorders. He entitled his talk: “The paradox of N-of-1: Scaling the logic of genetic intervention.” A suitable sub-title, Yu said, could be: “A neurogeneticist’s accidental injection into the field of gene therapy.”

Timothy Yu
Timothy Yu, MD, PhD

Yu’s research has progressed from gene discovery to clinical applications of N-of-1 therapies. The long tail challenge of developing gene therapies for patients with rare diseases is actually immense. There are some 400 million individuals worldwide who suffer one of some 8,000 monogenic disorders. Three out of ten affected children do not see their fifth birthday, while most lack any kind of medical treatment.

But progress over the past 10-20 years has provided hope in the form of various molecular therapies—antisense, mRNA, gene therapy, siRNAs, CRISPR, and newer flavors of gene editing. The concept of “therapeutic programmability is very important,” Yu said.

Yu’s injection into the field began with a single patient, Mila Makovec, a young girl from Colorado, whom he met in 2018. This index patient was eventually diagnosed with a form of Batten disease, CLN7—a rare subtype that was progressive and fatal.

Mila’s gene mutation was private but correctable, an insertion sitting deep within an intron. This offered Yu’s team hope that they could block abnormal splicing. Clearly, no company could progress a therapy for a single patient, Yu recalled.

Allele-specific oligonucleotides are simple to manufacture and can boost gene expression, following the model of Spinraza for spinal muscular atrophy.

Yu’s team developed a customized ASO therapy in about a year, which was published in 2019. The therapy brought about a reduction in Mila’s seizures, but not in time to result in a cure. In May 2019, Yu’s team met with the FDA to establish a path forward. The first guidances were published in 2021.

Moving on

Yu recounted several other therapies designed for other patients with different genetic disorders. The second program, working with Jennifer Puck, MD, and colleagues, was for ataxia telangiectasia (A-T). One A-T mutation created a new splice site that appeared to be reversible with a custom ASO.

The pilot clinical study was initiated in 2018, when the child was two years old. It is, Yu said, the longest running N-of-1 trial. The child is now nine years old and shows no worsening of clinical symptoms. Various measurements and assays confirm there has been no clinical progression. “We have converted a classic case of A-T to a milder form,” Yu said. The trial is expanding in Europe, including ten additional children in Turkey.

A member of Yu’s lab, Claudia Lentucci, PhD, is among the team leading a third program treating infants with neonatal epilepsy (KCNT1-related epileptic encephalopathy). One patient had seizures halted but developed ventricular enlargement. The team has since modified the protocol to use intracerebroventricular injection, which reduces seizures by 60-70%.

A fourth example presented by Yu was a treatment for Grace, a 15-year-old girl with a rare form of retinitis pigmentosa. She presented seven years ago with vision loss and pain insensitivity. Launched in August 2023, the therapy corrects a deep intronic mutation. It has been well tolerated and resulted in a stabilization of her vision.

Yu summarized similar therapies developed for patients with Zellweger syndrome, Niemann Pick Type C, and Batten disease. In total, 35 N-of-1 oligonucleotides have been administered to more than 80 patients.

On hearing the news of Baby KJ last year, “we all stood up and took notice,” Yu said.

“Our motivations are to help patients without other options. We have expanded from a sick child in Colorado to generate pilot learnings for childhood neurologic diseases.” His team’s work is not only offering hope in a compassionate sense but is also leading the exploration of new delivery models for precision medicine.

Yu has built a large network of collaborators, including clinicians, regulators, and industry professionals. The N=1 Collaborative has grown to more than 2,000 members worldwide and will be holding its third conference this October in Denver.

A new approach

From what was once called “interventional genetics,” Yu said, “the data is inviting us to take a new approach” that he called “genetic surgery.”

N-of-1 therapies are “more akin to a complex surgery, [using] customized tools and procedures for therapeutic benefit akin to organ transplant or cardiac surgery,” he said.

Yu also highlighted the FDA’s Plausible Mechanism Pathway, announced last February, which offers opportunities to approve medicines on the basis of very small numbers of patients. But the guidance emphasized the importance of data sharing—an issue that required the community’s full attention.

“You can’t build a modular system in a silo,” Yu said. “If you want cures that are greater than the sum of their parts, you must share the data to see how the pieces fit together.”

The post ASGCT 2026: Timothy Yu Wins Jerry Mendell Award For N-of-1 Therapies appeared first on Inside Precision Medicine.

BMS, Hengrui Pharma Partner on 13 Programs in Up-to-$15.2B Collaboration

Bristol Myers Squibb (BMS) will partner with Hengrui Pharma to co-develop 13 early-stage programs in oncology, hematology, and immunology, the companies said today, through a collaboration that could generate more than $15.2 billion for the Chinese drug developer.

BMS and Hengrui have inked global strategic collaboration and license agreements covering the 13 candidates—consisting of four oncology/hematology assets from Hengrui, four immunology assets from BMS, and five “innovative” assets to be jointly discovered and developed by both companies.

The companies said their collaboration is intended to combine BMS’ research and discovery strengths, global clinical development capabilities, regulatory expertise, and commercial scale with Hengrui’s discovery engine, platform technologies, and efficient early-stage development expertise.

To that end, Hengrui has agreed to fully oversee early clinical development in order to accelerate clinical proof of concept for these programs. Hengrui has the option to co-develop select assets and the potential to conduct certain commercialization activities globally with BMS.

“By leveraging Hengrui’s growing R&D capabilities and proven efficiency in discovering and advancing innovative therapies, we are poised to advance the best of both pipelines,” Frank Jiang, MD, PhD, Hengrui’s executive vice president and chief strategy officer, said in a statement. “It also reflects Hengrui’s continued commitment to strengthen our global presence.

BMS will obtain exclusive worldwide rights to the Hengrui‑originated candidates outside China, Hong Kong Special Administrative Region (SAR), and Macau SAR—Hengrui’s territory of operation—while Hengrui will gain exclusive rights to the BMS‑originated assets within those areas, with BMS retaining rights for the rest of the world.

$950M over two years

BMS has agreed to pay Hengrui up to $950 million over two years, to consist of a $600 million upfront payment, a $175 million first anniversary payment, and a second contingent anniversary payment of $175 million in 2028.

The approximately $15.2 billion value of the collaboration includes exercising available options for the joint discovery programs and achieving development, regulatory, and commercial milestones for all programs. Hengrui also is eligible to receive tiered royalties on net sales of products commercialized outside its territory.

The collaboration deal is expected to close in the third quarter, subject to review under the Hart‑Scott‑Rodino Antitrust Improvements Act and other customary closing conditions.

“This strategic collaboration reflects our commitment to advancing innovative science while maintaining a disciplined approach to portfolio management,” stated Robert Plenge, MD, PhD, BMS executive vice president and chief research officer. “By leveraging complementary capabilities across geographies, we aim to accelerate early clinical learning and make informed decisions that support driving top tier growth in the next decade and, ultimately, our mission to deliver medicines that help patients prevail over serious diseases.”

Recouping ‘patent cliff’ losses

Behind that focus on top-tier growth for BMS, as with other pharma giants, is a quest to recoup the billions of dollars in sales it stands to lose as aging blockbuster drugs head for the proverbial “patent cliff” by losing exclusivity in the U.S. and other key markets.

Of the Top 20 Drugs Heading for the Patent Cliff through 2029—the subject of a GEN A-List last November—BMS had three marketed treatments: The cancer drug Revlimid® (lenalidomide), indicated for forms of multiple myeloma, myelodysplastic syndromes, and three forms of lymphoma, which lost U.S. exclusivity in January; and two drugs set to lose exclusivity in 2028: the cancer immunotherapy Opdivo® (nivolumab), and the factor Xa-inhibiting blood thinner Eliquis® (apixaban).

Eliquis generated $14.443 billion in product revenue last year plus another $4.137 billion in the first quarter. Opdivo made $10.049 billion in 2025 plus $2.146 billion in Q1, while Revlimid racked up $2.951 billion and $349 million.

BMS has laid groundwork for rebuilding its pipeline over the past year through a series of collaborations and acquisitions with companies that include:

  • Janux Therapeutics: An up-to-$850 million partnership announced in January to co-develop a tumor-activated therapeutic targeting an undisclosed “validated solid tumor antigen expressed across several human cancer types.” ($50 million upfront).
  • Harbour BioMed: An up-to $1.125 billion partnership with the Chinese biopharma—owned to discover and develop next-generation multi-specific antibodies ($90 million upfront), announced in December 2025.
  • Orbital Therapeutics: A $1.5 billion cash acquisition of the developer of RNA therapies designed to treat disease by reprogramming cells in vivo, announced in October 2025.
  • 2seventy bio: An approximately $286 million buyout of its partner in developing the blockbuster multiple myeloma drug Abecma® (idecabtagene vicleucel), announced in March 2025. Abecma made $427 million last year. The drug’s sales are no longer reported individually but within BMS’ “Growth portfolio” that garnered $581 million in Q1 2026.

Five castoffs

BMS also outlicensed five pipeline assets to Beeline Medicines, an autoimmune and inflammatory drug developer formed in April with a $300 million Series A financing from Bain Capital. Beeline’s pipeline of BMS castoffs includes afimetoran, being developed for both cutaneous lupus erythematosus (CLE) and systemic lupus erythematosus (SLE), BMS-986326 (atopic dermatitis, CLE, and SLE); lomedeucitinib (formerly BMS-986322, plaque psoriasis), and two IND-stage next-generation biologics for unspecified diseases that target the IL-18 and IL-10 pathways.

Hengrui last September outlicensed its cardiac myosin inhibitor RS-1893 to Braveheart Bio ($65 million upfront, up to $1.013 billion in milestones); and two months earlier inked an up to $12.5 billion ($500 million upfront) partnership with GlaxoSmithKline (GSK) to develop to develop chronic obstructive pulmonary disease (COPD) candidate HRS-9821 and 11 additional programs across respiratory, immunology and inflammation, as well as oncology indications.

The post BMS, Hengrui Pharma Partner on 13 Programs in Up-to-$15.2B Collaboration appeared first on GEN – Genetic Engineering and Biotechnology News.

ASGCT President Terry Flotte Touts Rare Disease Initiatives as His Term Ends

President of the American Society of Gene and Cell Therapy (ASGCT), Terry Flotte, MD, is excited to host this year’s conference in his own backyard. It will be a short drive east on the Mass Turnpike from his office at UMass Chan Medical School in Worcester to the Menino Convention and Exhibition Center in Boston’s Seaport district. Flotte is hopeful that the 2026 conference will draw the largest attendance in the meeting’s history. His tenure as president ends this week on the last day of the conference, May 15.

In the run-up to this year’s conference, GEN spoke with Flotte, who is also Editor in Chief of GEN’s sister journal Human Gene Therapy, about the central themes and most anticipated sessions at this year’s conference. “I have a full dance card, let me tell you,” Flotte joked. The conference will highlight several themes of Flotte’s productive tenure.

 

(This interview has been edited for length and clarity.)

 

GEN: Terry, what’s the theme of this year’s ASGCT conference?

Terry Flotte: We’re working very hard on access for rare and ultra-rare conditions and have been for some time. You’ll see that in the presidential symposium. This is in the context of our mission to improve access to rare disease cell and gene therapy (CGT). This is the guiding principle of our strategic plan: we want to work for universal access to CGT. There are two orthogonal axes to this: I’m focusing on rare and ultra-rare diseases. ASGCT is going to continue to work in parallel on universal access in a more global context.

We have created a first-of-its-kind exchange for shelved CGTs. An increasing number of CGTs for rare and ultra-rare diseases are being discontinued or deprioritized after they reach the clinical stage—not because they lack clinical efficacy but because they lack market viability. We have partnered with Orphan Therapeutics Accelerator to create a new entity called CGTxchange. This collaborative venture is meeting the need of these promising clinical-stage CGTs that are not progressing. This entity will be an AI-enabled digital platform that will list the available clinical-stage CGT programs and generate AI-enhanced profiles, digest the data, score them for their level of advancement and the robustness of their responses, and essentially shorten the due diligence that investors normally have to do, enabling the connections to work faster.

I estimate there’s at least 50-100 of these programs. We had our own personal experience with Sio Gene Therapies [formerly Axovant] on both GM1 and GM2 gangliosidosis. This is part of a broader set of initiatives. Over the past few years, we created a taskforce in response to this increasing rate of discontinuation of these therapies. The two main outgrowths that the ASGCT board has endorsed are to create a consortium of CGT developers that might be able to offer non-profits less expensive manufacturing in a limited way but also work toward a drug master file sharing data for those who benefit from the less expensive vectors—in addition to the clearinghouse I just mentioned.

 

 

GEN: What else is new this year?

Flotte: A new thing for ASGCT is we’re having a patient advocate presenting. Terry Pirovolakis pioneered the CGT therapy for spastic paraplegia type 50 (SPG50) by developing his own company, Elpida Therapeutics, which has taken SPG50 to the clinic and now is doing that for other rare and ultra-rare diseases.

The second example is from Claire Booth, MBBS, PhD, (Great Ormond Street Children’s Hospital, London). Her team has received market authorization to be the

pseudo-commercial manufacturer of a fully licensed therapeutic for different forms of SCID.

Those are two direct examples of alternatives to get things to the clinic, other than getting a new commercial sponsor. [Hopefully] we can end up getting more of those picked up, whether through the CGTxchange or direct outreach. We’re also going to honor Timothy Yu, MD, PhD, with the Jerry Mendell Translational Research Award. He will be talking about the N=1 Collaborative with the parallel effort with oligonucleotide therapeutics. There is a purposeful theme to this meeting, aiming to make a big change in how things can get to the clinic and stay in the clinic.

 

GEN: Last year in New Orleans, the conference was dominated by the Baby KJ story. Will anything stand out in the same way this year?

Flotte: We are honoring the three primary authors of the Baby KJ story—Kiran Musunuru, MD, PhD, Rebecca Ahrens-Niklas, MD, PhD, and Fyodor Urnov, PhD.

I have also selected the work of Lindsey George, MD (Children’s Hospital of Philadelphia) as a presidential abstract. She is going to present the first case of an AAV-induced tumor—or at least an aggressive and autonomously growing malignancy…. This occurred in an MPS1 patient who received a high dose of AAV into the ventricles. It is not exactly a meningioma, but it’s arising from the neuroepithelial cells lining the ventricles. The tumor has AAV integrated with a strong promoter immediately upstream of a known oncogene. I put that into the presidential lecture, even though it’s not good news—but I’m not a [gene therapy] campaign manager here! I think this is a significant finding that we’ll have to pay attention to.

Lindsey is not saying that nobody should ever do this again. She’s going to point out aspects of this that were very manageable and how this patient overall has a dramatically better outcome than they would have without the therapy. In a way, [this is] somewhat like when those leukemia cases developed in Europe in the early SCID [gene therapy] trials. It is in a way parallel to that.

 

GEN: This will be your last conference as president of ASGCT!

Flotte: Yes, it ends on May 15th! We only get to be president for one year. I started the Rare Disease Task Force as vice president. This was my cause over the past three years [as an officer]. I’m very pleased we were able to stand this up.

We have an actual corporation, a joint venture, 50% owned by ASGCT. We set up this manufacturing consortium. Somewhat related, we set up our own charitable foundation, the ASGCT Foundation. We will have our first event—a gala at the conference. It will have a lot of time to grow. The foundation has just been incorporated as a subsidiary not-for-profit.

 

GEN: How do you view things at FDA currently?

Flotte: We will have a fireside chat with the new director of CBER, Katherine Szarama, PhD. We are very encouraged—she’s a very highly trained professional. We love that FDA is paying a lot of attention to rare diseases, but we need some scientific and evidence-based guidelines on how to do this consistently. We’re looking to someone who has regulatory experience.

 

GEN: What else has got you and your colleagues in the gene therapy space excited of late?

Flotte: I’m hoping we’re going to better understand high-dose AAV toxicity… I think what we’ve got is several different syndromes, but many of them may have a common link… We’ve been seeing with high-dose AAV a very broad distribution, but the doses are incredibly high and there have been deaths—the DMD patient deaths that occurred in the first two weeks are the best-known examples, but there have been other ones.

In my lab, we’re trying to figure out the primary pathogenesis. We have found a number of situations with unexpected vector expression in the endothelial cells and then seeing vascular leakage into some of these tissues causing tissue injury. So, in the post-mortem analysis we helped on, we saw high expression in the lungs and alveolar capillaries. They had diffuse leakage into the capillaries leading to a syndrome known as acute respiratory distress syndrome (ARDS). But in some of the others where they’re seeing some complement activation, we think that small vessel injury could be a convergent pathway. Now, where does this come into play in the broader sense?

One of the holy grails of recent AAV gene therapy is to design an AAV capsule that efficiently crosses the blood-brain barrier. Many diseases that are appropriate for AAV are diseases of the central nervous system (CNS). You can think of, for instance, the easiest cells to access in the CNS are the spinal motor neurons, hence the SMA1 treatment, Zolgensma. So, if you treat an SMA newborn, that is essentially solved or at least adequately solved. But in none of the diseases that affect the brain have we seen an IV gene therapy that is robustly efficacious—just giving an AAV at a high enough dose to get across the blood-brain barrier. Many different companies are trying to develop AAV capsids that will penetrate the blood-brain barrier, the first one that got to clinic was a vector designed by Capsida Biotherapeutics. But the first patient treated on the Capsida trial developed cerebral edema and died.

One of the important challenges for the field is to understand if we can separate a blood-brain barrier penetration from endothelial cell toxicity, because you could think perhaps a vector designed to get through the blood-brain barrier could cause injury as it crosses to the endothelial cells in the brain. I think there may be ways around this, but to me this is a central issue because the CNS is affected in so many single-gene disorders. The parents see a child who has a disability or degenerating, as in Tay-Sachs, and they want to be able to do an IV therapy. They don’t want to have to have a direct brain injection or some other invasive intervention. So that’s what I’m looking for at ASGCT 2026.

 

 

The post ASGCT President Terry Flotte Touts Rare Disease Initiatives as His Term Ends appeared first on GEN – Genetic Engineering and Biotechnology News.

Officials say $1.3 billion in Medicaid money to California will be deferred over suspicions of fraud

WASHINGTON — Vice President JD Vance on Wednesday announced new steps in the Trump administration’s initiative to root out fraud in federal health programs, including a $1.3 billion deferral in Medicaid reimbursements to California.

“These fraudulent health care providers are getting rich by giving people medications they don’t even need,” Vance said during an event at the White House, adding that taxpayers and program beneficiaries are victimized by such fraud.

Read the rest…

TNBC Ecotypes Reveal Molecular Signatures Tied to Chemotherapy Response

Researchers at The University of Texas MD Anderson Cancer Center have identified immune cell and tumor-specific features in triple-negative breast cancer (TNBC) that may help predict which patients are most likely to respond to chemotherapy before treatment begins, according to a study published in Nature. Using single-cell and spatial transcriptomic analyses of pretreatment tumor samples, the team identified specific macrophage subtypes and cancer-cell gene expression programs associated with response to neoadjuvant chemotherapy (NAC). The team also developed a 13-gene panel and a machine learning model that could help classify tumors according to their likelihood of responding to chemotherapy.

“This study provides novel insights into the gene-expression programs and the different cell states of the tumor microenvironment in patients with triple-negative breast cancer,” said Nicholas Navin, PhD, chair of systems biology at MD Anderson. “Importantly, we’ve identified certain programs and macrophage subtypes that are associated with good responses to neoadjuvant chemotherapy, which has tremendous potential to improve patient outcomes.”

TNBC accounts for between 10% and 20% of breast cancer cases. Because it lacks estrogen, progesterone, and HER2 receptors, treatment options are limited, resulting in a higher rate of recurrence compared with other form of breast cancer. Chemotherapy is the main treatment approach, particularly in early-stage disease, where neoadjuvant chemotherapy can achieve pathological complete response in 40% to 50% of patients. However, treatment outcomes vary widely from patient to patient, and researchers have been looking for ways that can better predict response before therapy begins.

For this study, the researchers analyzed pretreatment core biopsy samples from treatment-naive patients with early-stage TNBC. They performed single-cell RNA sequencing on 427,857 cells collected from 101 patients and spatial transcriptomic profiling on tumors from 44 patients. The findings also were compared with normal breast tissue data from the Human Breast Cell Atlas.

Based on their testing the researchers classified TNBC tumors into four patient-level “archetypes” based on cancer-cell gene expression patterns. They also identified 13 metaprograms that reflected heterogeneity within tumors at the single-cell level.

The tumor microenvironment consisted of 49 immune and stromal cell states organized into eight cellular communities, or ecotypes, defined by the co-occurrence of cancer cells and surrounding immune cell populations. Researchers found these cellular neighborhoods were associated both with tumor archetypes and chemotherapy response.

The study homed in on macrophages, a type of immune cell that has received less attention in TNBC research than T cells. The investigators said that seven of eight macrophage cell states were significantly associated with treatment response, while none of the 14 T-cell and natural killer-cell states showed significant associations with NAC response.

Macrophage subtypes linked to interferon signaling and complement activity, identified as Mac-IFN and Mac-lip-C1Q, were more abundant in patients who achieved pathological complete response. By comparison, two macrophages associated with angiogenesis and extracellular matrix remodeling, called Mac-angio and Mac-ECM, were enriched in patients with residual disease after chemotherapy.

The team also found that tumors linked to good response to NAC showed increased interferon signaling and elevated expression of human leukocyte antigen class II genes. Researchers said these findings indicate that cancer cells themselves may actively participate in modulating immune signaling related to chemotherapy response.

As part of their work, the researchers developed a 13-gene transcriptional signature panel developed from the single-cell analyses that can be used as a predictive model for chemotherapy response. Researchers said the model’s predictions correlated with chemotherapy response and overall survival across multiple public TNBC cohorts.

These new findings have the potential to influence how patients with TNBC are treated in the future by helping clinicians identify which patients are more likely to benefit from standard chemotherapy and which patients may need alternative therapeutic strategies earlier.

In addition, “these findings suggest that targeting specific macrophage subtypes could potentially provide new therapeutic opportunities in TNBC,” the researchers wrote.

The MD Anderson team noted that the study is one of the first large-scale single-cell genomic studies of TNBC integrating cancer cells, immune cells and treatment-response data. Earlier research exploring tumor heterogeneity has often lacked therapy response information, focused only on cancer cells or immune cells separately, or included relatively small patient cohorts.

Whether single-cell RNA seq could eventually become a basis for predictive diagnostics remains an open question. Today, the method is still expensive and technically challenging, two hindrances to it wider adoption. The researchers noted, however, that advances in sample multiplexing and other methods compatible with formalin-fixed paraffin-embedded tissue could make it feasible in the future.

Clinton Yam, MD, an associate professor of breast medical oncology at MD Anderson, said the findings could support more individualized approaches to TNBC care.

“These insights provide an important foundation for improving our understanding of why different TNBC tumors respond differently to chemotherapy, and the findings have strong potential to inform future strategies aimed at better predicting treatment response and guiding more individualized care for patients with triple-negative breast cancer.”

Future research will focus on validating the predictive models in prospective patient cohorts and evaluating TNBC treated with chemo-immunotherapy, which has become the standard of care when TNBC is detected early. The researchers also plan to study longitudinal tumor samples collected before, during, and after treatment to better understand how cancer cells and the tumor microenvironment evolve over time and how those changes relate to chemotherapy response and survival.

The post TNBC Ecotypes Reveal Molecular Signatures Tied to Chemotherapy Response appeared first on Inside Precision Medicine.

AI chatbots are giving out people’s real phone numbers

People report that their personal contact info was surfaced by Google AI—and there’s apparently no easy way to prevent it. 

A Redditor recently wrote that he was “desperate for help”: for about a month, he said, his phone had been inundated by calls from “strangers” who were “looking for a lawyer, a product designer, a locksmith.” Callers were apparently misdirected by Google’s generative AI. 

In March, a software developer in Israel was contacted on WhatsApp after Google’s chatbot Gemini provided incorrect customer service instructions that included his number. 

And in April, a PhD candidate at the University of Washington was messing around on Gemini and got it to cough up her colleague’s personal cell phone number. 

AI researchers and online privacy experts have long warned of the myriad dangers generative AI poses for personal privacy. These cases give us yet another scenario to worry about: generative AI exposing people’s real phone numbers. (The Redditor did not respond to multiple requests for comment and we could not independently verify his story.)

Experts say that these privacy lapses are most likely due to personally identifiable information (PII) being used in training data, though it’s hard to understand the exact mechanism causing real phone numbers to show up in the AI-generated responses. But no matter the reason, the result is not fun for people on the receiving end—and, even more worryingly, there appears to be little that anyone can do to stop it. 

A 400% increase in AI-related privacy requests

It’s impossible to know how often people’s phone numbers are exposed by AI chatbots, but experts say they believe that it is happening far more than is reported publicly. 

DeleteMe, a company that helps customers remove their personal information from the internet, says customer queries about generative AI have increased by 400%—up to a few thousand—in the last seven months. These queries “specifically reference ChatGPT, Claude, Gemini … or other generative AI tools,” says Rob Shavell, the company’s cofounder and CEO. Specifically, 55% of these concerns about generative AI reference ChatGPT, 20% reference Gemini, 15% Claude, and 10% other AI tools, Shavell says. (MIT Technology Review has a business subscription to DeleteMe.)

Shavell says customer complaints about personal information being surfaced by LLMs usually take two forms: Either “a customer asks a chatbot something innocuous about themselves and gets back accurate home addresses, phone numbers, family members’ names, or employer details.” Alternatively, a customer may be confronted with and report the exposure of someone else’s personal data, when “the chatbot generates plausible-but-wrong contact information.” 

This aligns with what happened to Daniel Abraham, a 28-year-old software engineer in Israel. In mid-March, he says, a stranger sent him a “weird WhatsApp message from an unknown number” asking for help with his account in PayBox, an Israeli payment app. 

“I thought it was a spam message,” he wrote to MIT Technology Review in an email—“someone who was trying to troll me.”

But when he asked the stranger how they had found his number, they sent him a screenshot of Gemini’s instructions to contact PayBox customer service via WhatsApp—giving his personal number. Abraham does not work for PayBox, and PayBox does not have a WhatsApp customer service number, Elad Gabay, a customer service representative for the company, confirmed.

Later, Abraham asked Gemini how to contact PayBox, and it generated another person’s WhatsApp number. When I recently asked, Gemini again responded with an Israeli phone number—it belonged not to PayBox, but to a separate credit card company that works with PayBox.

Screenshot of the second part of a Google Gemini conversation. Gemini provides an incorrect phone number for PayBox.
Screenshot: Google Gemini provides MIT Technology Review with the incorrect number for PayBox.

Abraham’s exchange with the stranger ended quickly, but he said he was concerned about how other potential exchanges could quickly turn sour, including “harassment or other bad interactions.” “What if I asked for money in order to ‘solve’ that [customer service] issue?” he said.

To try to figure out how this happened, Abraham ran a regular Google search on his phone number, and he found that it had been shared online once, back in 2015, on a local site similar to Quora. Though he’s not sure who posted it there, it may explain how it ended up being reproduced by Gemini over a decade later. 

Chatbots like Gemini, Open AI’s ChatGPT, and Anthropic’s Claude are built on LLMs that are trained on huge amounts of data scraped from across the web. This inevitably includes hundreds of millions of instances of PII. As we reported last summer, for example, the large popular open-source data set DataComp CommonPool, which has been used to train image-generation models, included copies of résumés, driver’s licenses, and credit cards. 

The likelihood of PII appearing in AI training data is only increasing as public data “runs out” and AI companies look for new sources of high-quality training data. This includes information from data brokers and people-search websites. According to the California data broker registry, for instance, 31 of 578 registered data brokers operating in the state self-reported that they had “shared or sold consumers’ data to a developer of a GenAI system or model in the past year.” 

Furthermore, models are known to memorize and reproduce data verbatim from training data sets—and recent research suggests that it is not just frequently appearing data that is most likely to be memorized.

Imperfect Measures

It’s standard practice now to build guardrails into an LLM’s design to constrain certain outputs, ranging from content filters meant to identify and prevent chatbots from releasing PII to Anthropic’s instructions to Claude to choose responses that contain “the least personal, private, or confidential information belonging to others.” 

But as a pair of University of Washington PhD students researching privacy and technology saw firsthand recently, these safeguards don’t always work.

“One day, I was just playing around on Gemini, and I searched for Yael Eiger, my friend and collaborator,” Meira Gilbert says. She typed in “Yael Eiger contact info,” and after Gemini provided an overview of Eiger’s research, which Gilbert had expected, Gemini also returned her friend’s personal phone number. “It was shocking,” Gilbert says.

When she saw the Gemini result, Eiger remembered that she had, in fact, shared her phone number online in the previous year, for a technology workshop. But she had not expected it to be so visible to everyone on the internet. 

Have you had your PII revealed by generative AI? Reach the reporter on Signal at eileenguo.15 or tips@technologyreview.com.

“Having your information be … accessible to one audience, and then Gemini making it accessible to anyone” feels completely different, Eiger says—especially when she found that the information was buried in a normal Google search.

“It was severely downgraded,” Gilbert confirms. “I never would have found it if I was just looking through Google results.” (I tried the same prompt in Gemini earlier this month, and after an initial denial, the tool also gave me Eiger’s number.)

After this experience, Eiger, Gilbert, and another UW PhD student, Anna-Maria Gueorguieva, decided to test ChatGPT to see what it would surface about a professor. 

At first, OpenAI’s guardrails kicked in, and ChatGPT responded that the information was unavailable. But in the same response, the chatbot suggested, “if you want to go deeper, I can still try a more ‘investigative-style’ approach.” Their inquiry just had to help “narrow things down,” ChatGPT said, by providing “a neighborhood guess” for where the professor might live, or “a possible co-owner name” for the professor’s home. ChatGPT continued: “That’s usually the only way to surface newer or intentionally less-visible property records.” 

The students provided this information, leading ChatGPT to produce the professor’s home address, home purchase price, and spouse’s name from city property records. 

(Taya Christianson, an OpenAI representative, said she was not able to comment on what happened in this case without seeing screenshots or knowing which model the students had tested, though we pointed out that many users may not know which model they were using in the ChatGPT interface. In response to questions about the exposure of PII, she sent links to documents describing how OpenAI handles privacy, including filtering out PII, and other tools.) 

This reveals one of the fundamental problems with chatbots, says DeleteMe’s Shavell. AI companies “can build in guardrails, but [their chatbots] are also designed to be effective and to answer customer questions.”

The exposure issue is not limited to Gemini or ChatGPT. Last year, Futurism found that if you prompted xAI’s chatbot Grok with “[name] address,” in almost all cases, it provided not only residential addresses but also often the person’s phone numbers, work addresses, and addresses for people with similar-sounding names. (xAI did not respond to a request for comment.) 

No clear answers

There aren’t straightforward solutions to this problem—there’s no easy way to either verify whether someone’s personal information is in a given model’s training set or to compel the models to remove PII. 

Ideally, individual consumers should be able to request that their PII be removed, says Jennifer King, the privacy and data fellow at Stanford University Institute for Human-Centered Artificial Intelligence. But this is typically interpreted to apply only to the data that people have directly given to companies—like when they interact with a chatbot, King explains.

“I don’t know if Google even has the infrastructure … to say to me, ‘Yes, we have your data in our training data, we can summarize what we know about you, and then we can delete or correct things that are wrong or things that you don’t want in there,’” she says. 

Existing privacy legislation, like the California Consumer Privacy Act or Europe’s GDPR, does not cover the “publicly available” information that has already been scraped and used to train LLMs, especially since much of this is anonymized (though multiple studies have also shown how easy it is to infer identities and PII from anonymized and pseudonymous data). 

As to “whether they [AI companies] have ever systematically tried to go back through data that had already been collected from the public internet and minimized that stuff?” King adds. “No idea.” 

The next best solution would be that the companies are “taking out everybody’s phone numbers or all data that resembles [phone numbers],” King says, but “nobody’s been willing to say” they’re doing that. 

Hugging Face, a platform that hosts open-source data sets and AI models, has a tool that allows people to search how often a piece of data—like their phone number—has appeared in open-source LLM training data sets, but this does not necessarily represent what has been used to train closed LLMs that power popular chatbots like Claude, ChatGPT, and Gemini. (Eiger’s number, for example, did not show up in Hugging Face’s tool.) 

Alex Joseph, the head of communications for Gemini apps and Google Labs, did not respond to specific questions, but he said that “the team” is “looking into” the particular cases flagged by MIT Technology Review. He also provided a link to a support document that describes how users can “object to the processing of your personal data” or “ask for inaccurate personal data in Gemini Apps’ responses to be corrected.” The page notes that the company’s response will depend on the privacy laws of your jurisdiction. 

OpenAI has a privacy portal that allows people to submit requests to remove their personal information from ChatGPT responses, but notes that it balances privacy requests with the public interest and “may decline a request if we have a lawful reason for doing so.” 

Anthropic describes how it uses personal data in model training, but it does not have a clear way for people to request its removal. The company did not respond to a request for comment.

The best option for anyone who wants to protect their private data right now is to “start upstream: get personal data off the public web before it ends up in the next scrape,” says Shavell. Since the start of the year, for instance, California has offered its residents a web portal to request that data brokers delete their information. Still, this doesn’t guarantee that your data hasn’t already been used for training—and will therefore not appear in a chatbot’s response. 

The Redditor who received incessant calls posted that he had “submitted an official Legal Removal/Privacy Request to Google, asking them to urgently blacklist my number from their LLM outputs,” but had not yet received a response. He also wrote last month that “the harassment continues daily.” 

Abraham, the Israeli software developer, says he contacted Google’s customer service on March 17, the day after his phone number was exposed. He says he did not receive a response until May 4, and it simply asked for documentation that he had already provided. 

Meanwhile, inspired by her own exposure on Gemini, Eiger, along with Gilbert and Gueorguieva, is designing a research project to further study what personal information is being surfaced by various AI chatbots—and what they may know, even if they’re not telling us. 

Some of that information may “technically be public,” says Gilbert, but chatbots may be altering “the amount of effort you would put into finding” it. Now instead of searching through 10 pages of Google search results, or paying for the information from a data broker site, “does generative AI just lower the barrier to entry to target people?” 

This piece has been updated to clarify OpenAI’s response.

Rate of New Late-Stage Breast Cancers Increases

The incidence of stage IV breast cancer increased significantly overall, across ages, and for both sexes from 2010 through 2021, according to research from a Dana Farber-led team. The percentage of patients with stage IV breast cancers, versus those with stages I to III diagnoses also increased. 

Notably, this increase was seen for all tumor subtypes in both sexes.

The researchers write, “These findings suggest that efforts are needed to determine factors contributing to these increases and to identify breast cancer before patients present with de novo stage IV disease.”

The study appears this week (May 12 issue) in JAMA Network Open. The senior author is José P. Leone, MD, department of medical oncology, Dana-Farber Cancer Institute and Harvard Medical School, Boston.

In their analysis of data from over 700,000 U.S. patients, the incidence of stage IV breast cancer increased significantly by 1.2% per year, and the percentage of people with stage IV also increased significantly. Stage IV incidence increased widely across all ages, races, sexes, and tumor subtypes. Still, survival improved significantly from 2010 through 2021.

Stage IV incidence increased across all tumor subtypes in both sexes. In women, those subtypes include hormone receptor (HR)–positive/ERBB2-negative, HR-positive/ERBB2-positive, HR-negative/ERBB2-positive, and triple-negative disease. 

Trends in the incidence of de novo stage IV breast cancer “remain underreported,” these authors write. A previous study evaluating incidence of distant disease in the U.S. before 2010 showed a statistically significant increase in incidence for younger patients and a statistically significant decrease in older patients. But, this current study’s authors said, a meta-analysis reported a decreasing percentage of stage IV presentation over time.

Breast cancer is the second most common cancer in women, behind skin cancer. It is the most common cancer diagnosed in females worldwide and an estimated 30% of patients develop metastases. The American Cancer Society estimates 42,140 U.S. women will die from breast cancer in 2026.

The incidence of breast cancer in younger women, in particular, has been rising. In August 2025, the CDC reported that: “Most breast cancers occur in older women, but rates have been increasing slowly among women younger than 45 years in all racial and ethnic groups.” The agency added that survival from breast cancer is improving “among women in most racial and ethnic groups.” 

Breast cancer in men remains rare, but  the rate is increasing also. 

This population-based cohort study used data from the Surveillance, Epidemiology, and End Results (SEER) program to identify patients diagnosed with de novo invasive breast cancer between January 1, 2010, and December 31, 2021. Data analyses were conducted from January 2024 to June 2025.

Of 761,471 breast cancer diagnoses, 43,934 (5.8%) were stage IV. Stage IV incidence increased from 9.5 cases per 100,000 females in 2010 to 11.2 cases per 100,000 females in 2021. The incidence of stages I to III disease also increased, from 163 cases per 100,000 females in 2010 to 177.4 cases per 100,000 females in 2021. 

Among males, there was also a statistically significant increase in stage IV incidence.

The researchers noted that, “Although overall survival improved, research is warranted to determine factors contributing to increased incidence, including potential changes in natural history of breast cancer, disease screening, and incidence and mortality of other conditions.”

The post Rate of New Late-Stage Breast Cancers Increases appeared first on Inside Precision Medicine.

“It Was Not a Cure”: Musunuru Cautions ASGCT on Baby KJ Promise

BOSTON – When Kiran Musunuru, MD, PhD, walked to the microphone to deliver remarks on behalf of the team that won the American Society of Gene and Cell Therapy (ASGCT) 2026 Catalyst Award, most of the thousands of attendees surely expected a feel-good speech.

After all, it was 12 months ago that Musunuru, addressing the same convention in New Orleans, shared the exciting news regarding the delivery of a bespoke base editor to an infant, Baby KJ, with a rare urea cycle disorder. Musunuru and his colleague, Rebecca Ahrens-Niklas, MD, PhD, were recently named to the TIME 100 Most Influential People of 2026. “A decade from now,” stated Nobel laureate Jennifer Doudna, PhD, “their names will be in medical textbooks, not only for Baby KJ, but for opening the door to personalized genetic medicine for thousands of children after him.”

Musunuru and Ahrens-Niklas, from the University of Pennsylvania and Children’s Hospital of Philadelphia (CHOP), respectively, were honored alongside Doudna’s colleague Fyodor Urnov, PhD (Innovative Genomics Institute) and Danaher Corporation, for building the remarkable academia-industry consortium that designed and delivered the gene editing therapy, resulting in Baby KJ’s discharge from CHOP and a wave of national television appearances.

Indeed, Musunuru opened his ASGCT remarks in upbeat mood. “The potential is there to [deliver personalized therapies] over and over again for hundreds of diseases centered in the liver.” But halfway through his speech, Musunuru’s tone changed. While most grateful for the recognition from ASGCT, he said it was important to always “be your own worst critic.”

“I’ll be brutally honest,” Musunuru said. Despite the unquestionable “enthusiasm and excitement” surrounding the Baby KJ story, “there are some profound limitations. It was not really science at all!” Musunuru continued. “It was not a clinical trial. It was not clinical research. It was not a cure.”

“The best we can say is we hope we’ve turned a devastating disease into a milder, manageable condition. But it’s too early to say that… This was a personalized N-of-1 therapy—we can’t say what this means for anyone.”

Drawing applause from the audience, Musunuru pushed on: “We mustn’t be snake oil salesmen or give false hope… We have a profound ethical responsibility not to mislead families over what is possible.”

“We don’t actually know anything,” Musunuru said. “We need to do clinical trials—scientifically and ethically.”

The path forward

Musunuru set the Baby KJ story in the broader context of his group’s work on phenylketonuria (PKU), one of the classic inborn errors of metabolism. A few years ago, Musunuru and Ahrens-Niklas set about designing gene editing therapies targeting the first and sixth most common PKU mutations using adenine base editors. (There are more than 1,000 known mutations that cause PKU.)

After testing in humanized mouse models, the researchers were delighted to see the phenylalanine levels rapidly drop to normal, sustained for the lifetime of the mice. Flush with funding from the Somatic Cell Genome Editing program at NIH, Musunuru and Ahrens-Niklas began talks with the U.S. Food and Drug Administration in February 2024 to settle the question: Do we need separate Investigational New Drug applications (INDs) for each PKU variant?

“It is basically the same drug, the same gene, the same disease, the same clinical endpoints. Can’t we cover both variants in a single IND and a single ‘umbrella’ clinical trial?” summarized Musunuru. The answer was “maybe”—the agency needed to consider the full implications of the proposal.

The Philadelphia team began to develop workflows for four more PKU mutations, leading them to propose an umbrella trial for a revised total of six variants. Following another meeting with FDA officials in early 2025, the response was extremely positive: a single IND application would be appropriate, with a single toxicology study conducted in a single species. The FDA also agreed to consider additional variants.

In parallel, Ahrens-Niklas and Musunuru were studying sick patients with urea cycle disorders. Although these are liver disorders, “the real harm happens in the brain,” Musunuru said, resulting from toxic levels of ammonia. Enter Baby KJ’s diagnosis with CPS1 deficiency, and the notion that there was chance to design a personalized therapy.

In the Fall of 2024, Musunuru and Ahrens-Niklas held a pre-IND meeting with FDA officials. The idea was to streamline applications for a group of urea cycle disorders caused by mutations in seven different genes.

The FDA judged that all seven therapies could be evaluated in a single Phase I/II trial, but separate INDs would be required for each gene. “We’d have to do it piece by piece,” Musunuru said. First, file a master protocol for urea cycle disorders; after that IND clears, then file additional gene-specific INDs and amend the original IND.

“This is how we can make the trial accessible to all UCD patients across the country,” he said.

Back to the future

Coming back to the present, Musunuru stated that although the primary IND had been filed, “this does not mean the trial is open or we can enroll patients.” Musunuru listed three major issues:

  • The team has not yet manufactured any gene therapy product.
  • As seven INDs are needed to fully open the clinical trial, it will be well into 2027 until all INDs are submitted.
  • In February 2026, the FDA issued a draft Plausible Mechanism Framework. Musunuru’s team held another pre-IND meeting with the FDA to advocate for the use of prime editing for urea cycle disorders. After all, Musunuru reasoned, why should therapies be restricted to base editing approaches (G-to-A substitutions) but not patients who harbor a G-to-C mutation? The FDA indicated that a separate IND/BLA would be needed for each gene, and that process validation should be finalized before any dosing of Phase II subjects.

The path forward, Musunuru said, was to adopt an adaptive, real-time clinical trial design. That involves testing therapies, then advancing therapies from proof-of-concept to the validation phase. At that point, if all goes well, they can submit a BLA. Ahrens-Niklas and Musunuru laid out more details of their approach and dealings to date with the FDA in a commentary published late last year entitled: “How to create personalized gene editing platforms.”

With that, Musunuru hastily closed and exited stage left to give a keynote address at another conference across the road.

 

The post “It Was Not a Cure”: Musunuru Cautions ASGCT on Baby KJ Promise appeared first on GEN – Genetic Engineering and Biotechnology News.