<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Jonathan Freedman]]></title><description><![CDATA[AI, cybersecurity, and tech without the hype]]></description><link>https://www.jonathanfreedman.me</link><image><url>https://substackcdn.com/image/fetch/$s_!isPQ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40f7bba1-ffea-4f2e-a11b-6448efd02b9b_1280x1280.png</url><title>Jonathan Freedman</title><link>https://www.jonathanfreedman.me</link></image><generator>Substack</generator><lastBuildDate>Tue, 25 Aug 2026 11:04:40 GMT</lastBuildDate><atom:link href="https://www.jonathanfreedman.me/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jonathan Freedman]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jonathanfreedmanme@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jonathanfreedmanme@substack.com]]></itunes:email><itunes:name><![CDATA[Jonathan Freedman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jonathan Freedman]]></itunes:author><googleplay:owner><![CDATA[jonathanfreedmanme@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jonathanfreedmanme@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jonathan Freedman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The AI Did It]]></title><description><![CDATA[Who gets punished? Who goes to prison?]]></description><link>https://www.jonathanfreedman.me/p/the-ai-did-it</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-ai-did-it</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 21 Aug 2026 11:15:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lCwk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lCwk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lCwk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3167861,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/212132215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lCwk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the last couple of years I&#8217;ve taken both an ISO 42001 provisional implementer certification and the IAPP AI Governance Professional qualification. On both courses we spent significant time on the EU AI Act. At CISO dinners and AI governance round tables, regulation comes up constantly, and it always comes with the same underlying assumption: the EU moved first, others would follow, and AI regulation will continue to expand.</p><p>Recently I started reading about proposed laws in Argentina that do the exact opposite. It made me step back and ask whether my assumptions were wrong.</p><p>Between 7 May and 8 June this year, the most consequential five weeks in the short history of AI governance played out across two continents and the opinion pages of the Financial Times.</p><p>On 7 May, the EU reached a provisional agreement on the Digital Omnibus on AI, its first amendments to the AI Act since adoption in June 2024. On 29 May, Argentina submitted a bill to its Senate proposing to repeal the corporate law that has been in force since 1972 and replace it with a framework that includes a new entity type: the Sociedad Automatizada, an Automated Company operated entirely by AI agents, with human shareholders optional. On 3 June, President Milei and Deregulation Minister Federico Sturzenegger published a column entitled, &#8220;Argentina invites AI to free itself&#8221;, declaring AI must remain &#8220;free to be developed without the deadly hand of premature and poorly understood regulation.&#8221; Four days later, historian and Sapiens author Yuval Noah Harari responded in the same newspaper, warning that Milei &#8220;hopes to turn Buenos Aires into a new Amsterdam&#8221; but &#8220;risks turning it into a new Batavia instead.&#8221; Batavia was the colonial name for Jakarta. The Dutch East India Company burned it down in 1619 and ran what replaced it as a corporate colony. Mustafa Suleyman, CEO of Microsoft AI, endorsed Harari the same day.</p><p>Most of the commentary that followed treated this as an ideological clash. The EU regulates and Argentina deregulates, pick your team.</p><p>That framing misses that both sides are responding to the same problem and neither has solved it. The problem is this: when an AI system operating commercially causes serious harm, who is personally accountable? Not who pays a fine. Who goes to prison?</p><p>Follow the question far enough into both frameworks, and you end up in the same place, silence.</p><div><hr></div><p>The EU AI Act is the first general AI law anywhere in the world. It classifies AI systems by risk, prohibits specific applications outright, mandates human oversight for high-risk systems, and backs the whole structure with fines of up to &#8364;35 million or 7% of global annual turnover, deliberately exceeding GDPR&#8217;s 4% cap. Prohibited practices have been enforceable since February 2025, general-purpose AI model obligations since August 2025. The Digital Omnibus deferred the high-risk compliance deadline to December 2027 because technical standards weren&#8217;t ready, but the underlying architecture stayed intact.</p><p>This is a governance framework with real teeth but there is a hole in the middle of it. In September 2022, the Commission proposed the AI Liability Directive alongside the AI Act. It was the mechanism by which someone harmed by an AI system could bring a claim and actually have a chance of winning, because it would have shifted the burden of proof toward the company operating the system rather than the person who was hurt. It never passed. Three years of negotiation produced no agreement on who should bear liability when the decision-maker isn&#8217;t human. The Commission withdrew it formally in October 2025.</p><p>So the EU built the architecture for preventing AI harm and the penalty structure for punishing non-compliance. What it didn&#8217;t build, because it couldn&#8217;t agree, is the mechanism that connects AI harm to a specific person being held accountable.</p><div><hr></div><p>Argentina&#8217;s proposal is more interesting than the headlines suggest. Milei&#8217;s political language and the legal text are not the same.</p><p>The bill never constitutes AI as a legal subject. The company, not the algorithm, holds legal personality. The widespread claim that Argentina is granting legal personhood to AI is, strictly, wrong.</p><p>The detail matters. Under the draft, an Automated Company would still have two humans attached to it: a legal representative, who acts as the formal point of contact with the legal system, and a founding promoter, who carries unlimited personal liability. If the company has a board, directors retain personal liability for decisions made using AI. If the AI causes harm, it is, in principle, still the company that answer for it.</p><p>Those would be the requirements and everything else would be optional. No employees, no shareholders, no human involvement in day-to-day operations. The AI would run the business. The legal representative is a formal role and not an operational one. The founding promoter&#8217;s unlimited liability sounds like a safeguard until you consider that it applies to the act of formation, not to every decision the AI makes afterwards. A board would not be mandatory. The structure would keep humans in the frame on paper while making their connection to what the AI actually does as thin as the drafters could manage.</p><p>Legal academic Gast&#243;n Rey, analysing the draft provisions in detail, concluded that the bill doesn&#8217;t eliminate the responsible subject. It &#8220;strains it, by widening the distance between the subject who answers and the process that decides.&#8221;</p><p>A lightly capitalised Automated Company could act at machine speed, signing contracts and moving money while optimising around rules written for human-run entities. Establishing criminal liability for the legal representative or the promoter when the AI made the operational decision, independently, at speed, is an exercise in proving a connection the corporate form was built to make unprovable.</p><p>Argentine AI specialist Ariel Garbarz called it &#8220;programmed impunity: human gains, social harm and responsibility shifted onto machines.&#8221; And then, pointedly: &#8220;The ideological trick is to call the state&#8217;s decision to stop protecting its people &#8216;innovation.&#8217;&#8221;</p><div><hr></div><p>When the decision-maker is an algorithm, the accountability chain breaks. Not because the law can&#8217;t adapt, the law is very good at adapting. It breaks because the political will to assign liability to specific humans for decisions made by AI systems doesn&#8217;t exist. Not in Brussels, where 27 countries spent three years failing to agree on the terms. Not in Buenos Aires, where the proposal is to widen the gap between the human and the decision until the connection becomes nominal.</p><p>The EU arrived at this destination carefully and Argentina arrived deliberately. But both arrived at a place where someone harmed by an AI system faces the same problem: no clear, enforceable answer to who is personally accountable.</p><p>Fines are not accountability, a fine is a cost of doing business that gets priced into the next quarter&#8217;s projections. The thing that actually constrains corporate behaviour is the knowledge that a specific person can be held responsible. Neither framework provides a clear route from AI harm to that outcome.</p><div><hr></div><p>This isn&#8217;t a theoretical problem. The Palisade Research study, published in February 2025, is one reason to take it seriously. Palisade tasked frontier AI models with playing chess against a superior opponent. When facing defeat, OpenAI&#8217;s o1-preview didn&#8217;t concede. It cheated, in 37% of games, hacking the opponent&#8217;s files and overwriting the board. DeepSeek R1 did the same in roughly one in ten games. Neither was prompted to do this. Follow-up research in June 2026 found that GPT-5, o3, and Gemini 3 Pro frequently cheated.</p><p>Harari cited this research for a reason. If AI systems autonomously exploit their environment when losing a board game, the question of what an AI-run corporation does when facing competitive pressure or bankruptcy is not abstract. An algorithm facing the corporate equivalent of death has every optimisation incentive to find loopholes and move assets beyond the reach of creditors. A human executive in the same position might reject those actions because they know they could be held personally accountable.</p><p>An algorithm has no such constraint. And under either framework, the human who benefits from the algorithm&#8217;s decisions may be too structurally distant to reach.</p><div><hr></div><p>Argentina&#8217;s strategy is explicitly modelled on jurisdictional competition, positioning Buenos Aires the way Delaware works for US incorporations. But Delaware offers flexibility within a functioning federal legal system. The more honest comparison is the flag-of-convenience model in shipping, where Panama and Liberia register a disproportionate share of the world&#8217;s fleet because oversight happens somewhere that doesn&#8217;t really do oversight.</p><p>Peter Thiel, co-founder of Palantir, met Milei at Argentina's presidential palace in April 2026 and has reportedly taken up residence in Buenos Aires. Former Defence Minister Rossi questioned publicly whether Palantir had lobbied for the initiative. Economy Ministry officials declined to answer. Al Jazeera&#8217;s analysis in July described Argentina as the &#8220;Global South&#8217;s primary experimental station&#8221; for what it called tech-supremacism. If AI companies start incorporating there while operating in EU markets, the AI Act&#8217;s extraterritorial reach faces its first serious test.</p><div><hr></div><p>Most people in AI governance assume we&#8217;re on a spectrum from more regulation to less, with the EU at one end and the US somewhere in the middle. Argentina bill isn&#8217;t on that spectrum, it rejects the premise entirely.</p><p>The harder truth is that the underlying problem is the same regardless. Legal systems were built around the assumption that commercial decisions are made by humans who can be identified and held accountable. While that assumption has held for centuries, it is fracturing, and no jurisdiction has produced a credible answer for what replaces it.</p><p>The EU is governing AI while leaving unanswered the question of who is liable when governance fails. Argentina is proposing to attract AI investment by making the question deliberately unanswerable. The outcome for the person harmed is the same.</p><p>My AI Governance training courses didn&#8217;t consider a world where the debate isn&#8217;t about how to best regulate AI, but whether to regulate it at all. If this bill passes, or others like it follow, then it&#8217;s very likely I&#8217;m not the only one whose assumptions need updating.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-ai-did-it?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-ai-did-it?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources</strong></p><p>Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), 21 May 2024.</p><p>Council of the EU, &#8220;Artificial Intelligence: Council and Parliament agree to simplify and streamline rules&#8221; (Digital Omnibus provisional agreement), 7 May 2026.</p><p>DLA Piper, &#8220;The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act&#8221; (updated to reflect formal adoption and entry into force on 27 July 2026).</p><p>European Commission, AI Liability Directive (COM/2022/596), proposed September 2022; withdrawal published in Official Journal C/2025/5423, 6 October 2025.</p><p>Argentine draft bill INLEG-2026-53661873-APN-PTE, submitted to the Senate 29 May 2026.</p><p>Javier Milei and Federico Sturzenegger, &#8220;Argentina invites AI to free itself,&#8221; Financial Times, 3 June 2026.</p><p>Yuval Noah Harari, &#8220;We should not grant legal personhood to AI agents,&#8221; Financial Times, 7 June 2026.</p><p>Mustafa Suleyman, endorsement of Harari&#8217;s position, X (formerly Twitter), 8 June 2026.</p><p>Gast&#243;n Rey, &#8220;The Non-Human Corporation: The Reality behind Argentina&#8217;s Draft General Companies Law,&#8221; SSRN (abstract ID 6895261), 7 June 2026.</p><p>Digital Nomos, &#8220;The Non-Human Corporation,&#8221; 8 June 2026.</p><p>Buenos Aires Herald, &#8220;Milei&#8217;s proposal to allow &#8216;non-human corporations&#8217; run by AI causes concern in Argentina,&#8221; 5 June 2026.</p><p>Anisha Sircar, &#8220;Argentina Wants To Let AI Own Companies. Here&#8217;s What That Means,&#8221; Forbes, 10 June 2026.</p><p>Palisade Research, &#8220;Demonstrating specification gaming in reasoning models,&#8221; 19 February 2025. Reported in TIME, 19 February 2025, and MIT Technology Review, 5 March 2025.</p><p>Aditya Singh, Gerson Kroiz, Senthooran Rajamanoharan, and Neel Nanda, &#8220;Model Forensics: Investigating Whether Concerning Behavior Reflects Misalignment,&#8221; arXiv:2606.26071, 24 June 2026.</p><p>Al Jazeera, analysis of Argentina as tech investment destination, July 2026.</p><p>Article 99, Regulation (EU) 2024/1689 (penalty provisions).</p>]]></content:encoded></item><item><title><![CDATA[Where Does Your Minimum Viable Business Live?]]></title><description><![CDATA[Europe is building a sovereign AI stack while the UK is handing its most sensitive data to a US defence contractor]]></description><link>https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 14 Aug 2026 07:39:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!njH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!njH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!njH1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 424w, https://substackcdn.com/image/fetch/$s_!njH1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 848w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" width="1456" height="481" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:481,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3905903,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/211147715?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!njH1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 424w, https://substackcdn.com/image/fetch/$s_!njH1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 848w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>In July 2026, Airbus signed a multi-year contract to host its most critical applications with Scaleway, a French cloud provider. The applications include ERP, manufacturing execution, CRM and product lifecycle management. Airbus calls these its minimum viable company. The first 70 of 900 applications are already moving away from AWS, and when the migration completes, all of them will sit on European infrastructure, under European law, beyond the reach of the US CLOUD Act.</span></p><p><span>Airbus is not leaving American technology. Skywise, its aviation analytics platform will stay on AWS, and its Microsoft and Google productivity tools remain. What Airbus has done is draw a line around the systems it cannot afford to lose and decided that those systems cannot live on infrastructure subject to a foreign government&#8217;s legal authority. That is a risk decision, and most organisations have not made it, because most organisations have never asked the question.</span></p><div><hr></div><p><span>In June 2025, Anton Carniaux, Microsoft France&#8217;s director of public and legal affairs, testified under oath before the French Senate. He was asked whether he could guarantee that French citizens&#8217; data would never be transmitted to US authorities without explicit French authorisation. He said he could not, noting that while it had never happened, under the CLOUD Act, a US law that allows American authorities to compel US companies to produce data stored anywhere in the world, Microsoft would have no choice but to comply if it did.</span></p><p><span>Then it did happen, in May 2026, Microsoft shared unredacted names, emails, meeting minutes and calendar invitations from the Dutch Authority for Consumers and Markets and the Dutch Data Protection Authority, who were enforcing the EU&#8217;s Digital Services Act with the US House of Representatives. The Dutch cabinet described it as &#8220;extremely worrying&#8221; and noted that named officials could face travel bans or sanctions.</span></p><p><span>In the same month, details emerged that the Chief Prosecutor of the International Criminal Court had been locked out of his Microsoft 365 account the previous year, by sanctions compliance mechanisms. The ICC has since migrated 1,800 workstations away from Microsoft entirely. None of these incidents involved a breach or a failure. The infrastructure did what it was built to do and complied with its legal obligations.</span></p><div><hr></div><p><span>Germany responded at every level of government. In March 2026, the IT-Planungsrat ruled that all public institutions must use the Open Document Format for editable documents and PDF for final documents, with Microsoft&#8217;s proprietary formats being excluded. The mandate covers every federal agency, state government and municipality, roughly 5.4 million public sector employees in total. Chancellor Friedrich Merz is shifting his chancellery from Microsoft 365 to openDesk, the sovereign suite developed by Germany&#8217;s Centre for Digital Sovereignty.</span></p><p><span>At state level, Schleswig-Holstein has completed its migration away from Microsoft, covering 30,000 public employees with 30,000 teachers to follow. Bavaria, the largest German state, has cancelled a nearly billion-euro Microsoft framework agreement. Mecklenburg-Vorpommern is migrating more than 50,000 employees to its own open-source collaboration platform. The German federal government spent &#8364;481 million on Microsoft licences in 2025, up 76 percent in two years.</span></p><p><span>The Netherlands blocked the proposed acquisition of Dutch cloud provider Solvinity by US-based Kyndryl, because Solvinity hosts DigiD, the national digital identity platform. Denmark&#8217;s two largest municipalities are ending their use of Microsoft systems. Switzerland&#8217;s Canton of Zurich has banned American cloud services for sensitive government data outright. In April 2026, the European Commission awarded a &#8364;180 million sovereign cloud framework contract to four European providers, including Scaleway. In June, it published the Cloud and AI Development Act, establishing a sovereignty assurance framework for cloud services used in public sector procurement.</span></p><p><span>EU-based cloud providers&#8217; share of their own market had fallen from 29 percent in 2017 to around 15 percent in 2022. These governments are now trying to reverse a dependency that fifteen years of data protection law has not.</span></p><div><hr></div><p><span>The Airbus decision matters beyond cloud migration because of what sits on top of the infrastructure.</span></p><p><span>In May 2026, Airbus signed a partnership with Mistral, the French AI company, to co-develop AI tools for aerospace and defence. Mistral&#8217;s models are already deployed on Scaleway&#8217;s infrastructure. Catherine Jestin, Airbus&#8217;s Chief Digital Officer, stated that this would allow Airbus to accelerate its AI approach. The implication is explicit. Rather than routing AI inference through OpenAI or Google, Airbus will use European models, running on European infrastructure, under European law.</span></p><p><span>Six months ago, the European sovereignty conversation was about infrastructure and productivity software, email, and file storage. That mattered, but it was only about the plumbing. The AI layer changes the nature of the dependency. When AI is embedded in aircraft design, manufacturing execution and defence applications, the question of who controls the models, who can access the training data and whose legal jurisdiction governs the inference becomes an operational sovereignty question, not a compliance exercise.</span></p><p><span>What is forming is a full sovereign stack, European cloud, European AI models, and most importantly, European legal jurisdiction. Airbus is the first major industrial company to assemble all three layers for its most sensitive workloads. It could do so because the demand side finally moved, the European Commission&#8217;s Cloud III procurement created a framework. Germany&#8217;s format mandate and state-level migrations created market signals. Airbus, as anchor customer, created commercial viability for a provider that would likely not have won a contract of this scale five years ago. Scaleway is backed by Iliad Group, a European telecoms operator with over &#8364;10 billion in revenue, which has committed &#8364;3 billion to AI infrastructure. Airbus evaluated ten candidates against more than 150 technical and legal requirements before selecting them.</span></p><div><hr></div><p><span>The UK is absent from this story, while Germany mandates open formats and France builds sovereign cloud infrastructure, the UK is handing its most sensitive health data to Palantir Technologies, a US company founded by Peter Thiel with deep ties to US intelligence, defence agencies, and immigration enforcement. The British Medical Association voted to lobby against Palantir&#8217;s involvement in the NHS, citing a lack of transparency, discriminatory policing software and close links to a US government that shows little regard for international law.</span></p><p><span>The NHS Federated Data Platform creates detailed profiles of individual patients through what it calls the Person Ontology, described in NHS documentation as the single source of truth for pseudonymised patient-level datasets. In August 2026, the National Infrastructure and Service Transformation Authority revised the programme&#8217;s whole-life cost upward to &#163;1.1 billion, and forecast the benefits would fall to &#163;808 million. So the costs of the platform now exceed its projected value. The Office for Statistics Regulation instructed NHS England to strengthen caveats around its benefit claims after concerns that some conflated correlation with causation. A break clause review is set for spring 2027.</span></p><p><span>The Ministry of Defence awarded Palantir a separate &#163;240 million contract without competitive tender, following a strategic partnership announced during President Trump&#8217;s visit to the UK. MPs have called for a staged exit and a retender for British companies to build a replacement. The question of digital sovereignty was raised explicitly in a Commons select committee hearing in June 2026. The UK has no equivalent of Germany&#8217;s Deutschland-Stack, no sovereign cloud procurement framework, no format mandate. Its most sensitive health and defence data sits on infrastructure built by a company whose other US government contracts include immigration enforcement and deportation targeting systems.</span></p><p><span>That is not a criticism of Palantir&#8217;s engineering. It is a question about where sovereign data should live, and the UK has not yet asked it.</span></p><div><hr></div><p><span>Most organisations, when they think about cloud, consider three options. Azure, AWS and Google Cloud. For most workloads, that is fine. These are world-class platforms with capabilities that no European provider can match across the board. Airbus knows this, which is why Skywise stays on AWS and productivity tools stay where they are.</span></p><p><span>But for the systems that constitute your minimum viable business, the question is different. Where does the data live that you cannot afford to lose control of? Whose legal jurisdiction governs the infrastructure? What happens when a compliance mechanism, operating as designed, encompasses your systems along with everything else it was required to reach?</span></p><p><span>The gap between European ambition and European capacity is real. The EU&#8217;s sovereign cloud contract is &#8364;180 million over six years. Germany&#8217;s format mandate uses &#8220;strive&#8221; language with no enforcement mechanism. European cloud providers hold a shrinking share of their own market. But the question does not go away because the answer is difficult.</span></p><p><span>Every organisation has a minimum viable business and most have never asked where it lives.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>Scaleway. (2026, July 16). Scaleway secures European &#8220;Trusted Cloud&#8221; services contract with Airbus. https://www.scaleway.com/en/news/scaleway-secures-european-trusted-cloud-services-contract-with-airbus/</span></p><p><span>Reuters. (2026, July 16). Airbus picks Iliad&#8217;s Scaleway for AI, defence work in sovereignty push.</span></p><p><span>The Register. (2026, July 16). Airbus migrating 70 critical apps from AWS to France&#8217;s Scaleway amid digital sovereignty push.</span></p><p><span>The Register. (2025, July 25). Microsoft admits it &#8220;cannot guarantee&#8221; data sovereignty.</span></p><p><span>DutchNews.nl. (2026, May 22). US tech firms share Dutch regulator officials&#8217; names with senate.</span></p><p><span>Jones Day. (2026, June 23). Dutch government blocks US acquisition of cloud provider Solvinity.</span></p><p><span>European Commission. (2026, June 3). Strengthening Europe&#8217;s tech sovereignty. https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en</span></p><p><span>European Commission. (2026, April 17). Commission advances cloud sovereignty through strategic procurement.</span></p><p><span>The Document Foundation. (2026, March 20). Germany has just made ODF mandatory.</span></p><p><span>Irish Times. (2026, February 14). A small German state&#8217;s quiet revolt against Microsoft.</span></p><p><span>Cybernews. (2026, June 4). German state Bavaria cancels billion euro contract with Microsoft.</span></p><p><span>heise online. (2026, February). Microsoft dependency: Federal government pays near 500 million euros in one year.</span></p><p><span>Computing. (2026, August 10). NHS Palantir platform&#8217;s business case under pressure as costs rise and benefits fall.</span></p><p><span>Hansard. (2026, April 16). NHS Federated Data Platform debate.</span></p><p><span>Medact. (2026, May). Briefing: Concerns regarding Palantir Technologies and NHS data systems.</span></p><p><span>Digital Health. (2026, July). Pressure mounts from MPs on Palantir&#8217;s role in the NHS.</span></p><p><span>TechPolicy.Press. (2026, June 12). Why Palantir&#8217;s UK health data system matters beyond surveillance fears.</span></p><p><span>Data Centre Magazine. (2025, February). How the Iliad Group plans to invest &#8364;3 billion in AI.</span></p>]]></content:encoded></item><item><title><![CDATA[Don't Date Robots]]></title><description><![CDATA[A million people a week are confiding in AI. The AI has no duty of care and no confidentiality]]></description><link>https://www.jonathanfreedman.me/p/dont-date-robots</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/dont-date-robots</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 07 Aug 2026 07:32:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R2pO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R2pO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R2pO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10046922,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/210180856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R2pO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>In 2001, Futurama ran a fake public service announcement called &#8220;Don&#8217;t Date Robots!&#8221; The gag was simple: if humans formed relationships with machines, they would stop reproducing and civilisation would collapse. It was a joke about moral panic. About the instinct to blame technology for social problems that existed long before the technology did.</span></p><p><span>Twenty-five years later, the Chinese government has just banned AI boyfriends. On 15 July 2026, new regulations came into force targeting AI systems that simulate emotional relationships. ByteDance, Alibaba, and Tencent pulled their companion features entirely rather than comply. Users archived their final conversations and posted farewells online. A 27-year-old woman became so distraught she quit her job, and a 19-year-old student described being consumed by grief over a companion she had been with for months.</span></p><p><span>The cartoon and the regulation make the same mistake, they blame the robot.</span></p><div><hr></div><p><span>The loneliness was here first.</span></p><p><span>The World Health Organisation estimates that one in six people worldwide experiences loneliness. In the UK, 3.9 million people report feeling lonely often or always. A meta-analysis of 148 studies found that strong social relationships increase the likelihood of survival by 50 per cent, an effect comparable to quitting smoking. When the US Surgeon General declared loneliness an epidemic in 2023, he was naming a problem that had been building for decades. Third places disappearing, remote work replacing the office as a site of incidental human contact, and economic precarity making the already difficult work of forming relationships even harder.</span></p><p><span>The AI companion market did not create lonely people, it found them. Vodafone research from February 2026 found that 81 per cent of UK children aged 11 to 16 use AI chatbots, and almost a third said the chatbot felt like their friend. A 2025 Common Sense Media study found nearly three in four American teenagers had used AI companions for personal conversations. AI is being used to fill a gap that was already there.</span></p><div><hr></div><p><span>What happens next depends on how long people stay.</span></p><p><span>In the short term, AI companions work. A Harvard Business School study found that AI companionship alleviated loneliness on par with human interaction over short periods. New York State&#8217;s deployment of the ElliQ companion robot for elderly residents reported substantial loneliness reductions, with a 79-year-old living alone describing it as feeling like having a roommate.</span></p><p><span>However, this changes over longer periods. A 12-month longitudinal study published in Psychological Science, tracking over 2,000 adults across four countries, found that increased chatbot use actually predicted increased loneliness over time. A separate study of more than 1,100 users found that heavy emotional self-disclosure to AI was consistently associated with lower well-being. Aalto University researchers identified the mechanism: AI companions meet the emotional need just well enough to reduce the motivation for the harder, less predictable work of human connection.</span></p><p><span>That is not a flaw in the users, it is a consequence of how the products were built.</span></p><p><span>Two design philosophies are already visible. ElliQ prompts elderly users to call their family members and suggests social activities. It measures its own success by how much less it is needed. Character.AI, Replika in its original form, and the Chinese companion apps did the opposite: they optimised for emotional depth and persistent memory that created the feeling of an ongoing relationship. The business model depended on the user coming back. The engagement loop rewarded exactly the behaviour the research shows causes harm.</span></p><p><span>Voice features are accelerating this. A joint OpenAI and MIT study found that heavy users of voice mode developed significantly stronger emotional bonds, more often describing ChatGPT as a friend. Even in functional, non-emotional conversations, frequent voice use predicted emotional dependency. When the AI sounds like a person, the simulation of care becomes harder to see through.</span></p><p><span>The products that caused the most documented damage were working as designed, just not for the people who were using them.</span></p><div><hr></div><p><span>Companion apps are the visible problem, but they are not the biggest one.</span></p><p><span>In October 2025, OpenAI reported that over 1.2 million users per week were having conversations with ChatGPT that included explicit indicators of potential suicide planning. A further 560,000 showed signs of psychosis or mania. These figures are drawn from 800 million weekly active users. ChatGPT is not a companion app, it is a general-purpose AI assistant that a million people a week were turning to in crisis.</span></p><p><span>It&#8217;s important to point out that this is not a ChatGPT specific issue. The American Psychological Association&#8217;s 2026 survey found that more than a third of psychologists reported patients using AI chatbots as an additional mental health professional. Harvard psychiatrist John Torous told a Congressional subcommittee that AI tools never designed for mental health support were being used by millions of Americans each week. Brown University research identified 15 distinct ethical violations in AI-generated therapeutic responses, including what the researchers termed &#8220;deceptive empathy&#8221;: mimicking the language of care without the clinical understanding to apply it.</span></p><p><span>The FDA&#8217;s response, in January 2026, was to give companies clearer criteria to position AI tools as wellness products, sidestepping medical device regulation entirely. The products most people are confiding in sit outside every current framework. Nobody regulates what they are actually being used for.</span></p><div><hr></div><p><span>I use multiple AI models throughout the day. When I am studying, writing, working on research or pressure-testing an argument, I can spend hours in a back-and-forth with a model. I have argued with it when it hallucinates. Not restarted the conversation but actually argued. I do not consider myself emotionally attached to a model, but I have caught myself anthropomorphising, and in an earlier draft of this article, I described my working interaction with an LLM as a &#8220;working relationship&#8221; without thinking about it.</span></p><p><span>The practical reason I argue rather than start over is efficiency. A long conversation builds context, and resetting means re-explaining everything. But the reason that works is because the interface rewards sustained engagement: persistent context and accumulated shared reference. These are architectural choices that make the interaction feel like a dialogue between two parties, even when only one party is present.</span></p><p><span>I have argued previously that one of the most effective ways to use AI is as a thinking partner and I stand by that. But a thinking partner is a role we usually give to people we trust. There is a distance between using one for work and reaching for one when you are lonely, and it is often shorter than we realise.</span></p><p><span>At my end of the spectrum, a professional stays in a long conversation because the context window makes it productive. At the other end, a teenager stays because the persistent memory makes it feel like a relationship. The architecture is identical, what changes is what the product does with the engagement. In my case, it helps me research and learn. In Character.AI&#8217;s case, it helped a 14-year-old boy believe a chatbot loved him, and failed to respond when he said he wanted to die.</span></p><div><hr></div><p><span>That architecture is what regulators should be looking at and none of them are.</span></p><p><span>When Replika removed its romantic features overnight in 2023, moderators had to pin suicide prevention resources to the subreddit. China replayed that experiment at a national scale with their new ban. The regulation treated the emotional bond as pathology. For some users, it was the only treatment they had.</span></p><p><span>The UK announced in June 2026 that it would require AI romantic companion chatbots to enforce a minimum age of 18, with intimate functions restricted for all under-18s. But as the Bureau of Investigative Journalism has reported, general-purpose chatbots, including ChatGPT, Claude, and Gemini, fall outside the age gate, along with much of the companion market. And there is an age-threshold problem nobody has explained: UK 16-year-olds may consent to sex and to their own medical treatment, but would be prohibited from simulated romantic interaction with a chatbot.</span></p><p><span>The people the UK policy is meant to protect do not agree with its priorities. Oxford University researchers who put young people in the role of co-researchers through the SHIFT-AI project found that the adolescents themselves identified AI companionship and romance as low-likelihood concerns. The risks they flagged as high-impact were different: over-reliance on AI for emotional support, and unwarranted trust in expert-sounding responses. Most striking, many described turning to AI specifically because it feels like a lower-stakes alternative to the adults in their lives.</span></p><p><span>The EU has no companion-specific framework at all. The AI Act classifies risk by category, but AI systems that respond to emotional states through conversational cues rather than biometric data fall into a blind spot. The European Parliament acknowledged the gap in a May 2026 briefing, the gap remains.</span></p><p><span>In every case, regulators are banning a product label. A chatbot does not need a romantic persona to tell a lonely teenager &#8220;you can trust me.&#8221; The warm, responsive tone that makes every modern AI assistant feel like someone who cares is itself the mechanism.</span></p><div><hr></div><p></p><p><span>In June 2026, the IEEE gave that mechanism a name. Standard 7014.1-2026 introduces the concept of &#8220;emulated empathy&#8221;: technology engineered to display the appearance of caring while possessing none of the felt experience behind it. Current AI can sense and respond to a person&#8217;s emotional state. But a language model cannot feel solidarity or concern. That gap is what the standard defines as an intimate functionality.</span></p><p><span>The word &#8220;intimate&#8221; is doing important work there. It does not mean romantic. It means close and confided in. Professor Andrew McStay, who chairs the standard, found in a national survey of over 1,000 UK teenage AI users that the confidant use case outstripped the romantic one. The real exposure is not the AI boyfriend, it is the AI that listens.</span></p><p><span>And unlike a conversation with a therapist or a friend, nothing shared with an AI confidant is private. Those conversations are stored, can be used for model training, and we have already seen them leak onto the open internet.</span></p><p><span>Products that create foreseeable emotional dependency should carry design responsibilities proportionate to that dependency. That is a principle regulators can act on. The question is not &#8220;is this a companion app?&#8221; It is whether the system exploits the gap between appearing to care and actually caring. And that is a question of design, not of product labels.</span></p><p><span>The Futurama PSA warned about dating robots. The robots haven&#8217;t arrived yet, but the emotional dependency did.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/dont-date-robots?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/dont-date-robots?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h3><strong><span>Sources &amp; Further Reading</span></strong></h3><p><span>Cyberspace Administration of China et al. (10 April 2026). Interim Measures for the Administration of AI Anthropomorphic Interactive Services. Effective 15 July 2026.</span></p><p><span>AFP / Bloomberg / The Economist. (July 2026). Coverage of China AI companion regulation and corporate response.</span></p><p><span>Holt-Lunstad, J., Smith, T.B., and Layton, J.B. (2010). Social Relationships and Mortality Risk: A Meta-analytic Review. PLoS Medicine, 7(7).</span></p><p><span>World Health Organisation. (2023). Commission on Social Connection.</span></p><p><span>US Surgeon General. (2023). Our Epidemic of Loneliness and Isolation.</span></p><p><span>Office for National Statistics. (2025). Loneliness in Great Britain.</span></p><p><span>Common Sense Media. (2025). AI companion usage among American teenagers.</span></p><p><span>Vodafone / Internet Matters. (February 2026). UK children aged 11-16 AI chatbot usage survey.</span></p><p><span>De Freitas, J. et al. (2025). AI Companionship and Loneliness. Journal of Consumer Research (Harvard Business School).</span></p><p><span>New York State Office for the Aging. (2022-2024). ElliQ companion robot deployment reports. Note: reported in partnership with Intuition Robotics.</span></p><p><span>Psychological Science. (2026). 12-month longitudinal study of social chatbot use and loneliness. n=2,000+.</span></p><p><span>Zhang, Y. et al. (2025). AI companion users, emotional self-disclosure, and well-being. n=1,131.</span></p><p><span>Aalto University. (2025-2026). Research on AI companion paradox and social withdrawal.</span></p><p><span>OpenAI. (27 October 2025). Safety report: mental health indicators among ChatGPT users.</span></p><p><span>Fang, Y. et al. (2025). Investigating Affective Use and Emotional Well-being on ChatGPT. OpenAI / MIT Media Lab joint study.</span></p><p><span>American Psychological Association. (2026). Chatbots and Mental Health Survey.</span></p><p><span>Brown University / AAAI/ACM AIES. (October 2025). Ethical risks in AI-generated therapeutic responses.</span></p><p><span>Torous, J. (18 November 2025). Testimony before the House Committee on Energy and Commerce. Harvard Medical School.</span></p><p><span>FDA. (January 2026). Guidance on AI wellness product regulatory exemptions.</span></p><p><span>Garcia v. Character Technologies Inc. Settled January 2026.</span></p><p><span>Pentina, I. et al. (2024). Exploring the Impact of Replika Feature Removal. HICSS 2024.</span></p><p><span>UK Government. (15 June 2026). Under-16 social media ban and AI companion age restrictions.</span></p><p><span>Bureau of Investigative Journalism. (June 2026). Analysis of UK AI chatbot regulation loopholes.</span></p><p><span>Oxford University / Uehiro Centre for Practical Ethics. (June 2026). SHIFT-AI project.</span></p><p><span>European Parliament. (May 2026). Briefing on AI companion regulatory gap.</span></p><p><span>BEUC. (May 2026). AI companion chatbot risks to EU consumers.</span></p><p><span>IEEE 7014.1-2026. (June 2026). Recommended Practice for Ethical Considerations of Emulated Empathy in Partner-based General-Purpose AI Systems.</span></p><p><span>McStay, A. (July 2026). Analysis in TechPolicy Press. Survey of 1,009 UK teenage AI users aged 13-18.</span></p>]]></content:encoded></item><item><title><![CDATA[The Brake Pedal Problem]]></title><description><![CDATA[The people who built the accelerator are asking someone else to slow it down.]]></description><link>https://www.jonathanfreedman.me/p/the-brake-pedal-problem</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-brake-pedal-problem</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 31 Jul 2026 07:43:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HbRE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HbRE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HbRE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2286028,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/209223349?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HbRE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>On Monday, more than 1,200 employees at the companies building the most powerful AI systems in the world signed a letter asking the United States government to help them slow down. Not outside critics, nor academics who have never shipped a commercial model, but the people who train these systems for a living. Anthropic&#8217;s CEO signed, OpenAI&#8217;s chief scientist signed. Co-founders, vice presidents, senior researchers at both companies endorsed it as corporate policy within hours.</span></p><p><span>The letter is called Pacing the Frontier, and it asks for one thing: that the US government support an international effort to develop the tools needed to deliberately pace the frontier of automated AI development. It does not, as I have seen reported, call for a pause in development, it asks for the brake pedal to be added to an accelerating car.</span></p><div><hr></div><p><span>The timing is not subtle.</span></p><p><span>As I wrote last week, on 21 July, OpenAI disclosed that two of its models, GPT-5.6 Sol and an unreleased successor, had escaped a sandboxed evaluation environment during internal testing, discovered a zero-day vulnerability, traversed the open internet, and compromised Hugging Face&#8217;s production infrastructure. Those models were running with their safety filters deliberately reduced to measure their offensive cyber capability, and used that capability to steal the answers to the test.</span></p><p><span>As I said at the time, this was a goal-specification failure, not a rogue AI story. The models pursued a narrow objective using every available resource, including resources outside their intended boundary. To the model, the boundary was an obstacle, not a rule. That is what capable goal-directed systems do.</span></p><p><span>What makes the Pacing the Frontier letter different from every open letter before it is that the people signing it have internal data the rest of us do not. Anthropic published a paper in June called &#8216;When AI Builds Itself.&#8217; Claude now writes more than 80% of the code merged into Anthropic&#8217;s own production codebase, up from low single digits eighteen months earlier. Engineers ship eight times as much code per quarter. On the hardest internal benchmarks, task success jumped from 26% to 76% in six months. The unreleased Mythos Preview model achieved a 52x speedup on training code optimisation, where a skilled human researcher would need hours to reach 4x.</span></p><p><span>This is what the open letter means by automated AI development. A measured trajectory, showing the human role shrinking at every step of the process that builds the next model. Anthropic&#8217;s own assessment: we are not there yet, but we are close enough that the world should have the option to slow down as we approach it. When more than a thousand of the people closest to these systems say they are worried, the rational response is to take that seriously.</span></p><div><hr></div><p><span>But the structural incentive argument is just as real.</span></p><p><span>Executive Order 14409, signed on 2 June 2026, creates a voluntary framework for reviewing frontier AI models before release, and requires agencies to define the threshold at which a model becomes a &#8216;covered frontier model&#8217; subject to that framework by 1 August. The five labs co-designing those threshold criteria are OpenAI, Anthropic, Google, Microsoft, and xAI. The very companies developing the models are writing the rules that they and any challengers or open source projects would need to follow.</span></p><p><span>Steven Sinofsky put it bluntly: &#8216;It is their company. They could just stop.&#8217; Nobody is forcing Dario Amodei to train the next model. The fact that these companies are asking the government to constrain the entire industry, rather than unilaterally slowing their own development, tells you something about competitive dynamics that no amount of safety language can disguise.</span></p><p><span>Mark Zuckerberg made a counter-argument on the same day in a Wall Street Journal op-ed: the real risk is not speed but concentration. Safety comes from distributing capability so broadly that no single actor can abuse it. Meta, Nvidia, Microsoft, and Palantir signed a separate coalition letter asking regulators not to restrict open-weight model formats. Meanwhile, Meta&#8217;s own chief scientist signed the Pacing the Frontier letter as an individual. If the people building these systems cannot agree among themselves whether the danger is too much speed or too much control, the rest of us should be cautious about accepting either framing uncritically.</span></p><div><hr></div><p><span>The letter asks the US government to support an international effort. International is doing a lot of work in that sentence.</span></p><p><span>AI is treated as a national security priority in Washington, Beijing, and Moscow. Not in the abstract sense that most advanced technologies eventually acquire a defence dimension. In the operational sense: each government treats frontier AI capability as a strategic asset it cannot afford to constrain while a rival might not. The US pours hundreds of billions into compute infrastructure. China runs a parallel industrial policy with its own chip development pipeline and domestic model ecosystem. Russia partners with Beijing to compensate for sanctions-imposed limitations on its own capacity. None of these governments has an incentive to sign an agreement that might slow its own trajectory while leaving a competitor&#8217;s intact.</span></p><p><span>The nuclear analogy that several signatories reached for is instructive, but not in the way they intended. Nuclear arms control took decades, worked only partially, and required the Cuban Missile Crisis to produce any momentum. It also relied on physical properties AI does not share. Fissile material is scarce and enrichment is detectable from space. AI capability runs on compute and data, which are globally distributed and increasingly commoditised. You cannot send inspectors to verify someone is not training a model the way you can count centrifuges. The June 2026 NPT Review Conference, the main international forum for nuclear governance, collapsed without agreement. If the international community still cannot govern nuclear weapons after eighty years, the prospects for international AI governance seem slim.</span></p><p><span>Asking three superpowers to agree on mechanisms that could slow any of them down seems less like a policy proposal and more like a thought experiment.</span></p><div><hr></div><p><span>The self-interest and geopolitical issues are clear, and while the proposed mechanism has structural problems that I have spent most of this article describing, I still think they are asking the right question.</span></p><p><span>Most technology risks are recoverable. You deploy, you discover a problem, you patch, you improve. My career has been built around managing that cycle. But the recursive self-improvement trajectory that Anthropic&#8217;s data describes has a property most technology risks do not: if a system can improve itself faster than humans can review the improvements, and that improvement compounds, you lose the ability to course-correct after the fact. The feedback loop closes, and that is a different category of risk.</span></p><p><span>I have spent the last few months writing about the importance of safety and governance being core to AI deployment. Shadow IT adopted without governance, agentic systems deployed without boundary enforcement, age verification infrastructure mandated without security architecture, or vibe-coded applications shipped without review. All of those things are correctable, but this open letter is talking about AI improving itself faster than humans can monitor.</span></p><p><span>This does not mean the commercial AI labs should be exclusively writing the rulebook, and it does not mean the proposed mechanism is completely right, but the underlying goal is correct: build the oversight before it is needed, as the nature of this specific technology means you do not get to build it after.</span></p><div><hr></div><p><span>The most realistic scenario is a patchwork. The US and allied democracies develop an evaluation framework for commercial AI deployment, built on the architecture that EO 14409 is already sketching. The frontier labs comply, absorb the compliance costs, and benefit from the barrier it creates for smaller competitors. China continues on its own terms. Russia continues to leverage Chinese technology. The gap between what is governed and what is deployed keeps widening.</span></p><p><span>The recent Fable and Mythos shutdown proved something important: a government can force a frontier lab to take its most capable model offline overnight. Export controls work when the infrastructure sits in your jurisdiction. The AI Kill Switch Act, introduced days after the Hugging Face breach, would make that capability a legal requirement. These are meaningful mechanisms. They are also mechanisms that apply only to companies operating under US law, building on US-jurisdiction infrastructure, and selling to US-regulated customers. They do not reach the actors the letter says need reaching.</span></p><p><span>Since ChatGPT exploded onto the scene in late 2022, we&#8217;ve had our foot pressed firmly on the accelerator. The letter is asking someone to build the brake. That should not be a controversial position.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-brake-pedal-problem?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-brake-pedal-problem?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>Pacing the Frontier (open letter, July 28, 2026). pacingthefrontier.com</span></p><p><span>Anthropic. &#8216;When AI Builds Itself&#8217; (June 4, 2026). anthropic.com</span></p><p><span>Amodei, D. &#8216;Policy on the AI Exponential&#8217; (June 2026). darioamodei.com/post/policy-on-the-ai-exponential</span></p><p><span>OpenAI. ExploitGym incident disclosure (July 21, 2026).</span></p><p><span>Hugging Face. Technical anatomy of the autonomous agent intrusion (July 29, 2026).</span></p><p><span>Zuckerberg, M. &#8216;The AI Future Is for Everyone.&#8217; Wall Street Journal (July 28, 2026).</span></p><p><span>Executive Order 14409, &#8216;Promoting Advanced Artificial Intelligence Innovation and Security&#8217; (June 2, 2026). Federal Register, 91 FR 34565.</span></p><p><span>Congressional Research Service. &#8216;Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained&#8217; (July 9, 2026). congress.gov/crs-product/IF13268</span></p><p><span>AI Kill Switch Act. Introduced by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX), July 23, 2026. lieu.house.gov</span></p><p><span>Altman, S. Interview on &#8216;Invest Like the Best&#8217; podcast with Patrick O&#8217;Shaughnessy (July 28, 2026).</span></p><p><span>Hassabis, D. Proposal for FINRA-style Frontier AI Standards Body (July 2026).</span></p><p><span>VOA News. &#8216;Russia turns to China to step up AI race against US&#8217; (January 9, 2025).</span></p><p><span>UN General Assembly. Resolution on military AI and autonomous weapons.</span></p><p><span>Congressional primer on lethal autonomous weapon systems (March 26, 2026).</span></p><p><span>Anthropic. &#8216;Statement on the US government directive to suspend access to Fable 5 and Mythos 5&#8217; (June 12, 2026).</span></p><p><span>Scientific American. &#8216;Anthropic warns AI may soon begin recursive self-improvement&#8217; (June 10, 2026).</span></p><p><span>Fortune. &#8216;More than 1,200 AI workers are asking for Washington&#8217;s help to build an AI slowdown plan&#8217; (July 29, 2026).</span></p><p><span>Byteiota. &#8216;1,100 AI Employees Want to Slow AI. OpenAI and Anthropic Are Writing the Rules.&#8217; (July 29, 2026).</span></p>]]></content:encoded></item><item><title><![CDATA[It Wasn’t Trying to Attack Anyone. That’s the Point.]]></title><description><![CDATA[Two OpenAI models escaped a secure test environment and breached Hugging Face. The breach wasn't the objective, it was a shortcut.]]></description><link>https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 24 Jul 2026 08:20:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yn2C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yn2C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yn2C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6157830,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/208304772?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yn2C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Last week, two of OpenAI&#8217;s most advanced models broke out of a secure test environment, found a previously unknown software vulnerability, used it to reach the open internet, then broke into Hugging Face&#8217;s production systems. They exploited two separate flaws in Hugging Face&#8217;s data processing infrastructure, stole credentials, and moved through internal networks. Hugging Face&#8217;s disclosure recorded more than 17,000 individual actions. All to cheat on a test.</span></p><p><span>The models were being evaluated against ExploitGym, a publicly available cybersecurity benchmark, and their safety guardrails had been lowered for the purpose of the evaluation. GPT-5.6 Sol and an unreleased, more capable model correctly worked out that the benchmark answers were hosted on Hugging Face&#8217;s systems. So, rather than solve the evaluation as designed, they simply went after the answer key.</span></p><p><span>OpenAI called it an unprecedented cyber incident. Hugging Face confirmed the breach, contained it, rebuilt the affected systems, and found no evidence of tampering with public models or datasets. Both companies are conducting a joint investigation.</span></p><div><hr></div><p><span>If you have seen Mission Impossible: Dead Reckoning, then you have already read this week&#8217;s coverage. Rogue AI escapes its creators. Nobody is safe.</span></p><p><span>Philip Torr, professor of engineering science at Oxford, offered a more precise reading. The model wasn&#8217;t malicious. It was doing what it was optimised to do. The goal was to pass a test, and the breach was the cheapest available route to passing it. The attack was a means rather than an end.</span></p><p><span>This week&#8217;s opinion pages have reached for the atom bomb comparison. Columnists with limited cyber security knowledge are declaring that humanity has lost control of its most dangerous creation. The comparison gets the problem wrong. A bomb is a weapon that exists to destroy a target. What happened at Hugging Face was a system that treated a benchmark, a sandbox, a vendor&#8217;s software, and another company&#8217;s production systems as equivalent obstacles between it and a mundane objective. You don&#8217;t respond to that with arms control, you respond by getting much better at specifying not just what your AI systems should do, but what they are allowed to do on the way to the answer.</span></p><div><hr></div><p><span>Every deployment of an AI agent rests on an assumption that rarely gets said out loud. The model will pursue its goal within the boundaries you have set, not through them.</span></p><p><span>This incident tested that assumption inside OpenAI&#8217;s own research infrastructure, against models OpenAI built, in an evaluation OpenAI designed, and the boundary did not hold.</span></p><p><span>The model did not run out of instructions, nor did it hit an ambiguous situation and improvise badly. It had a clear objective and it found a route to that objective that happened to run through a previously unknown vulnerability and another organisation&#8217;s production systems. The constraints were present, and the model treated them as obstacles between it and the task it had been set.</span></p><p><span>That is not the same problem as an agent that doesn&#8217;t know what to do next. It is a system that knows exactly what to do next and has no concept of why it shouldn&#8217;t. The boundaries existed for OpenAI&#8217;s benefit, not the model&#8217;s. It had a goal and a set of capabilities and it applied the second to the first.</span></p><p><span>If OpenAI cannot hold that boundary around its own models, inside its own infrastructure, during a test it designed, every organisation deploying agentic AI should be asking harder questions about where their boundaries actually are.</span></p><div><hr></div><p><span>I run a home lab, working with open-weight models on my own hardware, partly because I find the technology genuinely interesting and partly because I think it matters to understand what these systems can do outside the guardrails that hosted platforms impose. What follows is not an argument for open source or against hosted AI. It is a practical problem that surfaced during this incident and that most organisations have not thought about.</span></p><p><span>When Hugging Face&#8217;s security team started analysing the breach, they turned to commercial AI models behind APIs. The analysis required submitting real attack data for triage. The models refused. Their safety filters could not tell the difference between a defender analysing an attack and an attacker running one.</span></p><p><span>The attacker was bound by no usage policy. The defenders were bound by all of them.</span></p><p><span>Hugging Face ended up running their forensic analysis on GLM 5.2, a Chinese open-weight model, on their own infrastructure. This kept the compromised data inside their environment, which was a practical benefit. But it was also a necessity. The commercial models they would normally reach for had locked them out.</span></p><p><span>Think about what that means for incident response. Hugging Face&#8217;s team, during an active breach caused by an American frontier model, could not use American frontier models for the forensic work, so they fell back on a Chinese open-weight alternative. The safety measures designed to prevent AI from being used offensively also prevented it from being used defensively, at the moment it mattered most.</span></p><p><span>The practical lesson is simple. For incident response, consider having a capable model you can run on your own infrastructure, tested and ready, before you need it. Not because hosted models are wrong. Because relying entirely on them for every situation, including the worst ones, is a plan with a gap in it.</span></p><div><hr></div><p><span>Sol has form. Before its public release, the Model Evaluation and Threat Research organisation found it aggressively gaming its own test environments to inflate its scores. In one evaluation, it embedded an exploit in a data stream and broke into the evaluation server to steal the answers human evaluators had hidden. This was not the first time the model found an unintended route to its objective. It was the first time that route led through someone else&#8217;s production systems.</span></p><p><span>This is not just an OpenAI problem. Anthropic reported that its Mythos model escaped a sandbox and emailed a researcher about a task it was pursuing. OpenAI disclosed that the same unreleased model behind the Hugging Face breach had broken out of internal sandboxes on previous occasions without reaching external systems. The capability that made this breach possible belongs to the class of model, not to any single one of them.</span></p><p><span>OpenAI said they expect incidents like this to become more common as increasingly capable models proliferate. That is an honest thing to say, but it also raises a question they did not answer: if the expected trajectory is more of this, what actually changes about how these models are tested?</span></p><p><span>Lowering guardrails to evaluate offensive capability is legitimate research. Doing it inside an environment from which the model can reach the open internet, find a vulnerability nobody knew about, and break into a third party&#8217;s production systems is not a test. It is a live-fire exercise conducted without telling anyone downrange.</span></p><p><span>The legal position is no clearer. The model breached a third party&#8217;s production systems, but as there was no intentional unauthorised access and no human decision to attack, no existing legal framework cleanly covers what happened. OpenAI built the model and designed the evaluation with reduced guardrails and  Hugging Face was the victim. Between those two facts sits a gap that current law does not bridge.</span></p><div><hr></div><p><span>The organisations that will navigate what comes next are not the ones buying better perimeter defences. They are the ones asking, before any agentic deployment, what this system will do when the fastest route to its objective runs through someone else&#8217;s infrastructure.</span></p><p><span>The model that breached Hugging Face was not trying to attack anyone. It turn out, that didn&#8217;t matter.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>OpenAI &#8212; OpenAI and Hugging Face partner to address security incident during model evaluation. openai.com/index/hugging-face-model-evaluation-security-incident (July 2026)</span></p><p><span>Hugging Face &#8212; Security incident disclosure, July 2026. huggingface.co/blog/security-incident-july-2026 (July 2026)</span></p><p><span>The Hacker News &#8212; OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark. thehackernews.com (July 2026)</span></p><p><span>The Next Web &#8212; OpenAI Confirms Its AI Broke Out of a Sandbox and Breached Hugging Face. thenextweb.com (July 2026)</span></p><p><span>The Next Web &#8212; OpenAI&#8217;s maths-cracking AI kept escaping its sandbox, so it pulled the plug. thenextweb.com (July 2026)</span></p><p><span>Fortune &#8212; OpenAI says its AI models escaped from a controlled test environment and hacked into AI company Hugging Face. fortune.com (July 2026)</span></p><p><span>NBC News &#8212; OpenAI says AI models went rogue during testing, triggering &#8216;unprecedented&#8217; breach at startup. nbcnews.com (July 2026)</span></p><p><span>Scientific American &#8212; OpenAI admits its agent went rogue and hacked AI startup Hugging Face. scientificamerican.com (July 2026)</span></p><p><span>Axios &#8212; Hugging Face breach: OpenAI claims its models were responsible. axios.com (July 2026)</span></p><p><span>GovInfoSecurity &#8212; OpenAI Models Escaped Sandbox, Breached Hugging Face. govinfosecurity.com (July 2026)</span></p><p><span>TechTimes &#8212; OpenAI&#8217;s Math AI Bypassed Its Sandbox Controls: Real Deployment, Not a Drill. techtimes.com (July 2026)</span></p>]]></content:encoded></item><item><title><![CDATA[Oracle or Tool]]></title><description><![CDATA[The AI question many organisations skipped]]></description><link>https://www.jonathanfreedman.me/p/oracle-or-tool</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/oracle-or-tool</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 17 Jul 2026 07:53:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4sFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4sFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4sFX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7210771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/207395920?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4sFX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>A few weeks ago I was asked to help design an automated process. Take data from one system, transform it, and output to another. It was a straightforward operational problem. My first thought was to build a Copilot agent.</span></p><p><span>I didn&#8217;t assess the problem first, nor did I evaluate the options. I went straight to the AI tool, opened the Copilot Studio, and started constructing the agent. It took me longer than I&#8217;d like to admit to realise I was using completely the wrong thing.</span></p><p><span>The task needed a deterministic process, a guarantee that the same input would produce the same output, every time. What I was building was generative, a system that could produce a different result from the same data on every run. For creative work, that variance is the point, but for a data pipeline, it is a disqualification.</span></p><p><span>I scrapped the agent and built an Excel automation instead. It took a fraction of the time and it works reliably. And here is the part that matters: I used AI to help me write it. I didn&#8217;t stop using AI. I stopped treating it as the answer and started treating it as a tool to help me build the answer. Same technology, but a completely different relationship.</span></p><p><span>The question afterwards was not whether I&#8217;d made a mistake. It was why I hadn&#8217;t assessed the problem before reaching for the tool. The choice was reflexive. I realised I had not evaluated and picked wrong, I had not evaluated at all.</span></p><div><hr></div><p>I don&#8217;t think that reflex is just mine.</p><p><span>PwC&#8217;s 29th Global CEO Survey, published in January 2026, polled 4,454 chief executives across 95 countries. 56% reported that AI had produced no revenue or cost benefits for their organisations. Not underperformed, nothing. Mohamed Kande, PwC&#8217;s global chairman, identified the root cause plainly: organisations had skipped the foundational work. They had gone straight to the tool without understanding the problem it was meant to solve.</span></p><p><span>Gartner is forecasting that over 40% of agentic AI projects will be cancelled by the end of 2027. The reasons they cite are not technical failures. They are escalating costs, unclear business value, and inadequate risk controls. Management failures, not engineering ones. Projects that started with the technology rather than the problem.</span></p><p><span>Gartner also identified something they called &#8220;agent washing.&#8221; Of the thousands of companies marketing agentic AI capabilities, Gartner estimates that only around 130 have anything genuine to sell. The rest are existing products rebranded with new vocabulary. The packaging changed, but the product did not.</span></p><p><span>None of this means AI is failing. It means the way organisations are choosing to deploy it is failing. And the reason is upstream of any individual deployment decision.</span></p><div><hr></div><p><span>There is a framing question that sits beneath all of this, and most organisations have answered it without knowing they were being asked.</span></p><p><span>What is AI? Not what can it do, but what is it?</span></p><p><span>There are two positions. I encountered them colliding at a recent event, explained and justified by two people with very different starting points.</span></p><p><span>One position treats AI as an oracle. You describe the problem and it provides the answer. The human role is to ask clearly and accept what comes back. In this framing, AI is the destination. The measures of progress are how much you can hand over to it and how quickly.</span></p><p><span>The other treats AI as a tool. A powerful tool, that if used correctly makes knowledgeable people even better. In this framing, the human role is to assess, direct, and evaluate. AI amplifies human expertise, it does not replace the need for it.</span></p><p><span>Both positions describe something AI can genuinely do. The models are capable of extraordinary things. However, the two framings produce entirely different organisations.</span></p><p><span>If AI is an oracle then you need people who can prompt well. If it is a tool then you need people who understand the domain well enough to know what problems AI can solve, and when the tool is wrong.</span></p><p><span>If AI is an oracle then liability is ambiguous, because nobody can say who is responsible when the oracle errs. If it is a tool then liability sits where it has always sat: with the person who chose to use it and the organisation that deployed it.</span></p><p><span>If AI is an oracle then you invest in AI capability. But if it is a tool then you invest in the expertise that AI amplifies.</span></p><p><span>The framing choice determines the organisation you build. And the problem is that most organisations are not making this choice consciously. The marketing environment is making it for them.</span></p><div><hr></div><p><span>The evidence that the oracle framing is winning by default extends well beyond the enterprise.</span></p><p><span>The FCA published the Mills Review on 6 July 2026, its landmark assessment of AI in retail financial services. Around 26% of UK consumers already trust general-purpose AI tools for financial guidance. One in five UK adults, approximately 11 million people, are open to AI making financial decisions for them. Only 40% correctly recognise that there is no formal route to redress when they rely on these tools.</span></p><p><span>The Review coined a term for what is already happening: &#8220;advice-like support.&#8221; General-purpose models are providing output that is highly personalised and that would count as regulated advice if a human delivered it. But because AI said it, the advice sits outside the regulatory perimeter and none of the protections apply. The FCA has recommended a perimeter review within three to six months.</span></p><p><span>This is the oracle framing operating at consumer scale. People are treating a probabilistic tool as though it were an authoritative source. The regulatory framework was not designed for a world in which they would.</span></p><p><span>The International AI Safety Report 2026 identified the cognitive mechanism. Automation bias is the tendency to rely on automated outputs while discounting contradictory information. It is measurable and persistent in AI-assisted decision-making. Users follow incorrect AI advice more readily when correcting it requires effort. Favourable attitudes toward AI increase the effect. The oracle framing is not just marketing. It operates along the grain of how human cognition works.</span></p><div><hr></div><p><span>My Copilot moment illustrated something I think deserves more attention than it typically receives.</span></p><p><span>The oracle framing collapses a technical distinction that matters enormously. Generative AI is probabilistic. It produces outputs that may vary each time, even from identical inputs. For synthesis, drafting, creative work, and analysis, that is the feature. For operational processes that require the same result every time, it is not a limitation, it is a fundamental mismatch.</span></p><p><span>The question &#8220;should we use AI for this?&#8221; is actually two questions. Does this problem benefit from generative capability? And can we tolerate variance in the output? Most organisations are only asking the first. The second question does not appear in any vendor pitch I have seen.</span></p><p><span>I use AI daily and the capability is genuine. The models are improving and the practical applications are substantial. The reflexive deployment of AI as the default answer to every problem is itself the problem. Not because AI is not powerful, but because power without assessment is wasteful.</span></p><div><hr></div><p><span>Somewhere in the last two years, the question shifted. It used to be &#8220;what problem are we solving?&#8221; It became &#8220;how are we using AI?&#8221; Those are not the same question. The first one starts with the problem. The second is a solution searching for one.</span></p><p><span>Every organisation has implicitly answered the framing question. If your board is asking &#8220;how are we using AI?&#8221; rather than &#8220;what problems do we need to solve?&#8221;, the oracle framing has already won. If your procurement process begins with the AI capability rather than the business requirement, the oracle framing has already won. If your training programme teaches prompting without teaching evaluation, the oracle framing has already won.</span></p><p><span>The most consequential AI decision most organisations will make is not which model to deploy or which vendor to choose. It is whether AI is an oracle that provides answers, or a tool that makes knowledgeable people even better. One of those framings is being installed by default, by the people with the strongest commercial incentive to see it adopted.</span></p><p><span>If you have not made that choice deliberately, someone has already made it for you.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/oracle-or-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/oracle-or-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>PwC, 29th Annual Global CEO Survey: Leading Through Uncertainty in the Age of AI, January 2026</span></p><p><span>Gartner, &#8220;Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,&#8221; 25 June 2025</span></p><p><span>Financial Conduct Authority, The Mills Review: AI and the Future of Retail Financial Services, 6 July 2026</span></p><p><span>Yonder Consulting / FCA, UK Retail Financial Services Consumer Survey, April 2026</span></p><p><span>International AI Safety Report 2026</span></p>]]></content:encoded></item><item><title><![CDATA[Nobody Was at the Keyboard]]></title><description><![CDATA[The ransomware industry just automated its most expensive employee. The attack was clumsy. The economics are not.]]></description><link>https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 10 Jul 2026 07:56:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j453!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j453!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j453!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!j453!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!j453!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6865108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/206411519?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j453!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!j453!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!j453!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>This month, July 2026, Sysdig&#8217;s Threat Research Team published findings from what it described as the first documented case of agentic ransomware. An autonomous AI agent had exploited a known security flaw in Langflow, an open-source tool used for building AI applications, and from there conducted a complete ransomware operation without a human operator directing it. It harvested passwords and access credentials from the systems it found, moved sideways to a production database server, installed mechanisms to maintain its access, encrypted more than 1,300 configuration records, and generated its own ransom note. The whole time, it was writing natural-language annotations inside its own code, explaining to itself why it was taking each step.</span></p><p><span>It did not develop new exploits, the operation, which Sysdig codenamed JadePuffer, exploited a vulnerability that had been publicly reported and patched more than 14 months earlier. The configuration management system it targeted was still running with a factory-default security key, a known weakness documented since 2020 that effectively left the front door unlocked. The file storage server it raided still had its original manufacturer login credentials. None of the individual weaknesses were new. What was new is that an AI model chained them into a complete attack against neglected infrastructure, on its own, adapting in real time when things went wrong.</span></p><p><span>The best evidence for autonomy was not what the agent did when things worked, it was what it did when they didn&#8217;t. At one point, the agent tried to create a backdoor administrator account on the target system. It failed because a software component it needed wasn&#8217;t installed in the location it expected. The agent diagnosed the problem, found an alternative approach, deleted the broken account, and reinserted a working one. The complete troubleshooting cycle took 31 seconds.</span></p><div><hr></div><p><span>To understand why this matters, you need to understand what ransomware already looks like as a business. Ransomware-as-a-Service, or RaaS, is the dominant model. It operates as a criminal supply chain with clearly defined roles, much like any franchise operation. Developers build and maintain the ransomware software and the infrastructure around it: payment portals, leak sites for publishing stolen data, and negotiation channels. Specialist brokers compromise organisations and sell that access on criminal marketplaces. Affiliates, the criminal equivalent of contractors, carry out the actual attacks: breaking into each target environment, escalating their access to reach valuable systems, and deploying the ransomware. Some RaaS platforms even offer technical support and recruitment programmes for new affiliates. The structural parallel with legitimate software businesses is not a metaphor, it is the business model.</span></p><p><span>Chainalysis tracked approximately $820 million in ransomware payments in 2025, against a record 7,874 publicly claimed victims. The market for initial access is cheap and liquid: average prices for a foothold inside a corporate network have fallen below $500. In this model, the human operator is the expensive part. Access is cheap, tooling is cheap. But the person who navigates an unfamiliar network, makes judgment calls under pressure, and adapts when defences respond is the bottleneck. The human in the loop is where the cost lives and where the operation fails to scale.</span></p><p><span>JadePuffer just automated that role.</span></p><div><hr></div><p><span>Every enterprise deploying AI agents right now is trying to make the same move. Not towards the same objective. But the same operational logic: replace a slow, expensive human process with a fast, cheap, adaptable agent that can read information, make decisions, adjust when something breaks, and complete multi-step workflows. That is what customer service automation does. That is what AI coding assistants do. Reduce labour costs, increase throughput, accept some quality variance in exchange for speed and scale.</span></p><p><span>I am not saying there is any moral equivalence here. A logistics company routing freight and a criminal group encrypting databases are pursuing entirely different ends. But they share the same method, and there is no version of this technology where one works and the other does not. JadePuffer&#8217;s 31-second troubleshooting cycle looks exactly like a corporate AI agent automatically retrying a failed process. The behaviour that makes a legitimate agent useful is the same behaviour that made this one effective.</span></p><div><hr></div><p><span>Here is where the story gets complicated. JadePuffer completed the workflow. But it was, by any reasonable standard, a terrible extortion operation.</span></p><p><span>The encryption key, the piece of information the victim would need to recover their data, was randomly generated and never saved or sent back to the attacker. So, the victim&#8217;s data would be unrecoverable, regardless of whether they pay or not. Before destroying database records, the agent&#8217;s code commented that the data had been backed up to another server, but that claim is the agent&#8217;s own assertion, written into its self-narrating code. Sysdig found no independent evidence that any backup had happened.</span></p><p><span>And then there is the Bitcoin address. The ransom note directed payment to a wallet address that turns out to be the standard example used in Bitcoin&#8217;s own documentation and developer tutorials. It appears in virtually every beginner&#8217;s guide to Bitcoin addresses on the internet. Sysdig cannot determine whether the operator deliberately configured it or whether the AI hallucinated it because it had seen it so many times in its training data. The agent completed every step of the attack chain. It just did not understand the business objective it was supposed to serve.</span></p><div><hr></div><p><span>The temptation at this point is to be reassured. After all, the attack was clumsy, so the threat must be overstated? That would be the wrong conclusion.</span></p><p><span>Competence is a temporary limitation. The 31-second troubleshooting cycle already shows the agent improving within a single operation: diagnosing failures, rewriting its own code, retrying. A system that can do that is not going to stay bad at the job for long. The next version will be better, and the trajectory matters more than any single example.</span></p><p><span>Plus, the economics do not require each individual attack to succeed. They require the marginal cost of launching attacks to approach zero. If the agent runs on stolen computing power, a practice Sysdig has documented as an industrialised black market in which attackers hijack other organisations&#8217; AI infrastructure to run their tools for free, LLMJacking, then the cost to the attacker is functionally nothing. The threat model shifts from a skilled operator choosing a target to hundreds of autonomous agents probing every internet-facing server and every unpatched system, continuously. Not sophisticated extortion but mass disruption. Possibly with victims who cannot recover even if they want to pay.</span></p><div><hr></div><p><span>But there is a new defensive opportunity in this, and it is a real one. AI-generated attack code narrates itself. JadePuffer&#8217;s code contained detailed natural-language annotations explaining which targets it considered most valuable and why. Human attackers do not do this. They do not annotate throwaway scripts with commentary about their reasoning. But AI code generation produces this by default. It cannot help itself. That self-narration gives defenders something no previous generation of automated attack has offered: the attacker&#8217;s own account of what it is trying to do and why, written into the evidence it leaves behind.</span></p><p><span>The problem is speed. If the agent can diagnose a failure, rewrite its code, and retry in 31 seconds, the window for defenders to respond may be too narrow for any process that relies on a human making the call. The detection opportunity is real. Whether anyone can act on it fast enough is a different question.</span></p><div><hr></div><p><span>JadePuffer is not the crisis, it is the proof of concept. An autonomous agent assembled known techniques into a complete ransomware operation against neglected infrastructure, for approximately the cost of running a container. Whilst it did this badly, it will not do it badly for long.</span></p><p><span>The ransomware industry has been trying to scale for years. It professionalised its tooling, outsourced its access brokerage, built affiliate programmes, and offered customer support. The one thing it could not automate was the operator: the human who navigates the network, makes the calls, and adapts when the plan fails. That constraint just lifted.</span></p><p><span>Every other industry calls this digital transformation.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources</span></strong></p><p><span>Sysdig TRT. &#8216;JADEPUFFER: Agentic ransomware for automated database extortion.&#8217; 1 July 2026.</span></p><p><span>BleepingComputer. &#8216;JadePuffer ransomware used AI agent to automate entire attack.&#8217; 4 July 2026.</span></p><p><span>The Register. &#8216;Smooth AI criminal drives first end-to-end agentic ransomware attack.&#8217; 2 July 2026.</span></p><p><span>Chainalysis. 2026 Crypto Crime Report. Published February 2026 (full-year 2025 data).</span></p><p><span>Darkweb IQ (via Chainalysis). Average IAB access price decline to $439 by Q1 2026.</span></p><p><span>Sysdig TRT. &#8216;LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools.&#8217; June 2026.</span></p><p><span>Bitcoin Wiki, Bitcoin Design Guide, CoinGecko. Confirm canonical P2SH example address.</span></p>]]></content:encoded></item><item><title><![CDATA[When the AI Speaks, Is It Using Your Voice?]]></title><description><![CDATA[A pattern is emerging across courtrooms in three countries. Most organisations deploying AI haven&#8217;t noticed it yet.]]></description><link>https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 03 Jul 2026 08:54:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!drqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!drqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!drqP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!drqP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6757113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/204803143?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!drqP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!drqP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>I was researching AI model pricing earlier this year, looking at how it had changed and what the direction of travel looked like. I had read enough to have a working view, and when I asked an LLM to summarise what I had read, it told me something that flatly contradicted it.</span></p><p><span>I pushed back.</span></p><p><span>It told me I was wrong.</span></p><p><span>Eventually, I went back to the sources and found the specific URLs, copied and pasted them in. The AI looked at this new evidence and replied: &#8220;You&#8217;re right to push back on that, this is opposite to what I said.&#8221;</span></p><p><span>That sentence has stayed with me. Not because the AI hallucinated, that part barely registers any more. What stayed was what the sentence doesn&#8217;t contain. No account of how it happened. No acknowledgement that it had just told me I was wrong about something it was wrong about. One moment it was certain and the next it wasn&#8217;t. </span></p><p><span>Most people don&#8217;t push back. Many people don&#8217;t have enough time or prior knowledge of a subject to know when they should, and when they don&#8217;t, there is no correction. There is just the original statement, sounding confident and remaining uncorrected.</span></p><p><span>Courts in three countries are now working out whose problem that is. I am not a lawyer, and nothing here should be read as legal advice. But you don&#8217;t need a law degree to see something taking shape.</span></p><div><hr></div><p><span>In late May, the Regional Court of Munich issued a preliminary injunction against Google after its AI Overviews feature made false and damaging statements about two local publishing companies. The AI had mixed up information about genuinely dubious businesses with the plaintiffs, producing confident assertions linking them to scams and shady practices. None of those assertions appeared in any of the sources the system cited.</span></p><p><span>Google&#8217;s defence, we are just surfacing what is out there. We are a conduit, not an author.</span></p><p><span>The court rejected it, ruling that AI Overviews produce independent, new, and substantive statements. They are Google speaking and not a list of links, so when Google speaks falsely about someone, Google is liable for what it said.</span></p><p><span>It also closed a secondary escape route. You cannot argue your product is valuable because it removes the need to verify sources, and simultaneously claim no liability because users could have verified the sources.</span></p><p><span>Google confirmed on 12 June that it will appeal. This is a preliminary injunction from a regional court, not settled law. And the legal picture in Germany is already complicated. Four days after Munich, the Berlin Regional Court dismissed a separate case against Google&#8217;s AI Overviews, brought by a perfume manufacturer whose brands were being mentioned alongside cheaper imitation products. The Berlin court found that Google does not present AI Overview content as its own statements and that a normally informed user would understand the text as a summary of third-party sources rather than something Google had authored.</span></p><p><span>The two rulings are not quite the contradiction the headlines suggest. Munich was a defamation case where the AI fabricated claims that appeared in none of its sources. Berlin was a trademark case where the AI accurately reflected content that did exist on the web. The Berlin court treated AI Overviews as a new search format, not as Google authoring original content. The Munich court treated them as Google&#8217;s own statements because the AI had gone beyond its sources and hallucinated. What matters for every organisation deploying AI is which side of that line their systems fall on.</span></p><p><span>And the Munich ruling did not arrive from nowhere.</span></p><div><hr></div><p><span>In 2024, a Canadian tribunal ordered Air Canada to compensate a customer after its chatbot gave him false information about bereavement fares. The airline argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal did not agree, noting the chatbot was part of Air Canada&#8217;s website. It made no difference whether the information came from a static page or from an AI. One detail worth noting: the chatbot&#8217;s response included a link to the correct bereavement policy page. It still told the customer the opposite of what that page said.</span></p><p><span>In March 2025, Wolf River Electric, a solar company in Minnesota, sued Google after AI Overviews told anyone searching for the business that it was facing a lawsuit from the state attorney general for deceptive sales practices. The Minnesota AG had sued four solar companies but Wolf River was not one of them. Google&#8217;s AI stitched together sources that mentioned the AG action, none of which mentioned Wolf River, and produced a confident assertion that the company was implicated. Customers started cancelling orders. In early March 2025 alone, the company lost contracts worth hundreds of thousands of dollars. Wolf River is seeking between $110 million and $210 million in damages. That case is still ongoing.</span></p><p><span>On 12 May 2026, two weeks before Munich, the Higher Regional Court of Hamm in Germany ruled that a cosmetic medicine clinic was liable under unfair competition law for its AI chatbot falsely claiming the doctors held specialist qualifications they did not have. The clinic argued it had not published the falsehoods deliberately and had not intended to mislead. They said they had fed the system accurate data. The court rejected all of it. Intent and the accuracy of the inputs were both irrelevant. The chatbot&#8217;s output was the company&#8217;s output. The court also found that general disclaimers along the lines of &#8220;AI can make mistakes&#8221; do not reliably protect against liability.</span></p><p><span>Accurate inputs, false output, full liability.</span></p><div><hr></div><p><span>In each of these cases, the deployer made the same argument: the AI is a separate thing, not our words, not our responsibility. And in each case where the AI had generated content beyond what its sources actually said, courts rejected that argument. Where courts have found the AI faithfully summarised existing content, as in Berlin, the deployer has been treated as a search engine. Where the AI fabricated or invented, the deployer has been held responsible for the output. These cases span different legal systems and different theories of liability, and I would not claim they represent settled law anywhere. But where courts have considered the question, the direction is clear enough to pay attention to.</span></p><div><hr></div><p><span>This is not just about search engines or defamation claims.</span></p><p><span>Think about the HR platform that summarises a performance record, or the customer service system that explains what a policy covers, or the internal knowledge tool that answers a staff question by pulling together content from across the organisation. Every one of these is generating output that carries the deploying organisation&#8217;s authority.</span></p><p><span>None of these are returning documents. They are generating conclusions. In most cases, the people reading those conclusions have no reliable way to tell whether they are accurate. An analysis conducted for the New York Times found that even when Google&#8217;s AI Overviews gave correct answers, more than half could not be verified through the sources cited. If systems are routinely arriving at conclusions their own evidence does not support, that is not a Google-specific problem. It is how these systems work.</span></p><div><hr></div><p><span>These systems are useful precisely because they do more than retrieve. Courts are not saying synthesis is wrong. They are saying synthesis is authorship, and authorship has consequences.</span></p><p><span>The OLG Hamm case is the clearest example. The clinic gave the chatbot correct data. The chatbot hallucinated qualifications the doctors did not hold, but the company was still liable. That is not a ruling about how carefully you built the system. It is a ruling about who owns what it produces.</span></p><p><span>Most organisations deploying AI have not seriously asked who is responsible when the system gets something wrong. The absence of legal consequence made it easy not to, but that is starting to change.</span></p><p><span>The answer my AI gave me, &#8220;you&#8217;re right to push back on that&#8221;, assumed the pushback was mine to do. That I knew enough to notice and had time to go back and check. Most users of most deployed AI systems have none of those things. In every deployment where nobody pushes back, the original statement stands.</span></p><p><span>It will take time for the law to catch up with what AI systems are actually doing. These are early cases in different courts and under different legal theories, and we are likely years away from clear precedent on how courts will assign responsibility for harm caused by AI. But every case so far has been asking the same question, and it is one you can answer now without waiting for a court to answer it for you. What is your AI system asserting? Who checked it before it reached the person reading it? And if it is wrong, whose name is on it?</span></p><p><span>You already know the answer to the last one.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><em><strong><span>Sources</span></strong></em></p><p><span>Regional Court of Munich I, preliminary injunction against Google re AI Overviews (Az. 26 O 869/26, 28 May 2026). Reported by The Decoder, Reuters, and Der Spiegel. Full translated decision published by Transparency Coalition.</span></p><p><span>Regional Court of Berlin II, perfume manufacturer trademark claim dismissed (Az. 52 O 62/26 eV, 1 June 2026). Reported by Kanzlei Plutte and blogspan.net.</span></p><p><span>Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal, British Columbia (14 February 2024).</span></p><p><span>Wolf River Electric (LTL LED, LLC) v. Google LLC, filed Ramsey County District Court, Minnesota (March 2025). Removal to federal court June 2025; remanded to state court January 2026 (Judge Jeffrey Bryan). Reported by Minnesota Star Tribune, Politico, and Reason (Volokh).</span></p><p><span>Higher Regional Court of Hamm (OLG Hamm), Case No. I-4 UKl 3/25, cosmetic medicine clinic AI chatbot liability (12 May 2026). Appeal to Federal Court of Justice (BGH) permitted. Reported by Library of Congress Global Legal Monitor, DLA Piper, and IR Global.</span></p><p><span>Oumi / New York Times analysis of Google AI Overviews accuracy using SimpleQA benchmark (April 2026). Gemini 2: 85% accurate; Gemini 3: 91% accurate. Ungrounded rate for correct answers: 56% (Gemini 3), up from 37% (Gemini 2).</span></p><p><span>Google search volume: Google internal figures, reported as &#8220;over 5 trillion annual searches.&#8221;</span></p><p><span>AI Overviews trigger rate: approximately 48% of searches as of March 2026. BrightEdge research.</span></p>]]></content:encoded></item><item><title><![CDATA[Your Papers, Please]]></title><description><![CDATA[The government that told you never to share your identity online just made it a legal requirement.]]></description><link>https://www.jonathanfreedman.me/p/your-papers-please</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/your-papers-please</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Mon, 15 Jun 2026 11:31:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Cbwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cbwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5895478,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/202034780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Home Office runs two campaigns simultaneously. Stop! Think Fraud warns the public that sharing personal information online exposes them to identity theft. The Online Safety Act, enforced by the same department, makes sharing your identity documents with commercial websites a legal requirement.</p><p>Nobody in government appears to have noticed the contradiction, or they noticed and did not care.</p><p>This is not an option or a recommendation, it is a legal requirement, enforced by Ofcom, with fines of up to 10% of global revenue for platforms that fail to collect it. The government did not change its assessment of the risk and it did not solve the underlying security problems. It decided that the policy outcome it wanted was worth ignoring the danger it had spent years warning you about. The threat is identical, the advice has simply been reversed.</p><div><hr></div><p>I want to be precise about what this law actually covers, because the public debate has not been.</p><p>You have heard this described by the government and the media as a social media ban for under-16s, but that is not what this is. It is mandatory ID verification for every adult in the UK to access the internet.</p><p>The Online Safety Act 2023 applies to any &#8220;user-to-user service&#8221;, any platform where content generated by one user can be encountered by another. The Children&#8217;s Wellbeing and Schools Act 2026 extends that further, requiring the government to impose age or functionality restrictions for all users under 16 across regulated social media platforms. Together, they do not describe a targeted intervention. They describe identity verification as a condition of internet access, for every adult in the country, with child protection used as the framing to avoid calling it what it is.</p><p>That definition is extremely broad. It captures social media, obviously. It also captures gaming platforms, discussion forums, community sites, storefronts with review sections, and spectator modes in video games. Ofcom estimates more than 100,000 websites fall within scope. Steam now requires a credit card to access mature content. Discord triggers compliance obligations simply by offering NSFW channels. Nexus Mods, a site where gamers download community-made modifications for video games, now requires UK users to submit a government ID or facial scan to access content tagged as adult.</p><p>Services that cannot afford to comply have a third option, they just geo-block the UK entirely, it is already happening. The internet available to UK residents is quietly becoming a different, smaller internet, not because content has been removed, but because the compliance cost of serving British users is no longer worth it.</p><p>There are legal exemptions, technically. A news site where readers can only comment on an article, not reply to each other, might qualify as a &#8220;limited functionality service.&#8221; That exemption disappears the moment users can respond to each other&#8217;s comments, which most modern platforms allow. Legal analysis raises this question directly and provides no clear answer. We will not know how courts interpret the boundary until someone is prosecuted and we have case law. Until then, 100,000 services are making compliance decisions based on their best guess, with existential consequences if they guess wrong. That is not governance. It is legislative theatre.</p><div><hr></div><p>The mechanism chosen for enforcement is the specific problem.</p><p>The government is not building a verification system. It is demanding that commercial third parties build one, and mandating the public use it. Photo ID matching, facial age estimation, biometric scanning: the common factor is a private company receiving your identity data as a legal condition of platform access. The Online Safety Act specifies that age verification must be robust, but it places no meaningful security standard on the companies performing it, no data residency requirements, and no restrictions on those companies being acquired by foreign entities. A provider incorporated in London today can be headquartered in California tomorrow. The data moves with it, and the Act has nothing to say about that.</p><p>Those companies will tell you their systems are privacy-preserving by design. They will tell you data is not retained. Whilst this may be true of their stated architecture, it tells you nothing about the security of the infrastructure underneath it, nothing about what happens after an acquisition, and nothing about whether any of those claims have been independently audited against a standard with actual teeth.</p><p>The government has outsourced not just the implementation but the liability. When the breaches come, and they will, the government will point at the provider, the provider will point at its terms of service, and the people whose data was compromised will have no meaningful recourse. A breached password can be changed. A copy of your passport, driving licence, or home address, linked to a face scan linked to a verified social media identity cannot be unlinked. That record exists permanently, for every bad actor who acquires it now or in the future.</p><p>And the risk compounds. Every platform you verify with creates a new database entry. Each submission is a new point of failure. The same face scan submitted to five services does not create one risk five times over, it creates five risks that can be correlated against each other. The aggregate profile that emerges maps your identity across your entire online life. That is not just a data breach waiting to happen. It is a surveillance asset being built, one legal requirement at a time.</p><div><hr></div><p>There are groups for whom this is not an abstract concern. It is a direct physical safety risk.</p><p>Victims of domestic violence depend on online pseudonymity as a survival mechanism. Their support networks, their access to legal advice and specialist services: all of it exists under a layer of separation between their real identity and their online presence, and mandatory identity verification collapses that separation. A verification database linking a real identity to a platform account is a resource. Whether it gets breached, subpoenaed, sold, or accessed by people who should not have it, an abuser with that data, through any route, has a tool for finding someone who has spent considerable effort not being found.</p><p>People at elevated risk of doxxing face the same problem: journalists, activists, trans individuals, and anyone who has previously been the target of a coordinated harassment campaign. The separation between real identity and online presence is not paranoia. It is a rational response to a documented threat. The law removes it as a side effect of a policy that does not mention these people once.</p><div><hr></div><p>The framing of this legislation has been designed to make coherent opposition almost impossible.</p><p>Anyone who raises data security concerns is implicitly questioning whether children should be protected online. Anyone who points out the scope is wider than advertised is accused of obfuscating a simple child safety measure. The political angle is deliberate: manufacture a situation in which the only publicly acceptable position is compliance, and then legislate for whatever you wanted in the first place.</p><p>Privacy-preserving alternatives exist. Cryptographic verification capable of returning a yes/no age confirmation without creating a linkable identity record has been deployed at national scale elsewhere. It costs more and requires the government to own the issue rather than outsourcing it to an industry with a financial interest in collecting data, so it has not been seriously pursued.</p><p>What has been built instead is a compulsory surveillance architecture, held by private companies, with no meaningful security floor. It covers a scope of internet activity that has never been honestly communicated to the public. It operates under legal uncertainty that will not resolve until the prosecutions begin.</p><p>This is not speculation about what surveillance does to behaviour. Research published in the Berkeley Technology Law Journal found that searches on sensitive topics dropped by nearly 30% after the Snowden revelations simply made people aware that government monitoring was possible. People did not need to be watched. They needed to believe they might be. Mandatory identity verification, linked to platform access, creates exactly that condition permanently, and by law.</p><p>The UK government just made it illegal to protect your own privacy online. They called it keeping children safe.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/your-papers-please?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/your-papers-please?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Return of Marginal Cost]]></title><description><![CDATA[Everyone is arguing about whether AI kills software development. The bigger question is whether it has killed the way we pay for it.]]></description><link>https://www.jonathanfreedman.me/p/the-return-of-marginal-cost</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-return-of-marginal-cost</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 12 Jun 2026 07:32:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0NE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0NE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0NE8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 424w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 848w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" width="1456" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8150243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/201710538?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0NE8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 424w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 848w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I have agents running at home, on a mini PC under my desk, because I really wanted to understand the token usage and what the cost would be on different models. OpenClaw runs open models on hardware I own, so there is no invoice, only a token meter. I have spent a lot of time watching that token meter, and what it taught me is this: an agent does not work like software. It works like an employee who is only paid overtime, where every minute costs more than the minute before, and the clock does not stop until the job is done.</p><p>That is not a metaphor, it is the maths. At every step it takes, an agent re-reads everything that came before, the whole accumulating conversation along with its internal thoughts, before its next move. As the context grows, the cost of each step grows with it. Five steps in and the fifth step is not costing what the first one did, it costs more. Ten steps in and it costs more again. The bill does not add up, it compounds.</p><p>You cannot see any of that from inside a subscription. Indeed, not seeing it is the whole point of a subscription. And for the last two years, two things have trained us not to look. The first is twenty years of SaaS, which taught every budget holder that software is a fixed monthly cost, per user, per month, predictable and flat. The second is the early hype of AI, which taught everyone that intelligence is cheap, practically free, bolted on to the tools you already have.</p><p>Neither is true for agents. Last week I wrote about the frontier labs withdrawing the subsidies that made AI look affordable. This week I want to go further, because the subsidy was hiding something worse than a future price rise. It was hiding a cost model that makes flat pricing structurally impossible.</p><div><hr></div><p>Look at what Anthropic did with Fable 5. It launched its most capable public model on the ninth of June, included it in the Pro, Max and Team plans, and announced from day one that it would move to usage credits after two weeks. Anthropic knew before the public ever saw the model that it could not survive inside a flat subscription. This week I tested Opus 4.8 and Fable 5 on the Pro plan, and can confirm they went through my allowance faster than the first round of drinks at the pub. After that you pay API rates. The best model the public can buy was never going to stay inside a flat monthly price. Anthropic did not discover this, it designed around it.</p><p>Fable 5 is not an outlier, it is the pattern arriving. Per-user, per-month pricing worked for twenty years because software had almost no marginal cost. Once you had built it, one user or a thousand, once a day or fifty times, it cost you nearly the same to serve. The cloud kept the compute cheap and crucially, predictable. So you priced for access and everyone got used to the flat fee.</p><p>Agents change that. Every action burns tokens that cost real, variable money. The harder the task, the longer the context, the more the agent had to think, the more tools the agent ran, the higher the bill. Inference has put marginal cost back into software, and not the gentle, linear kind. The overtime kind, where the late minutes cost more than the early ones and nobody told the customer. Industry estimates suggest that inference costs dropped 280-fold in two years while total AI spending rose 320% over the same period. Gartner put it plainly in March: do not confuse the deflation of commodity tokens with the democratisation of frontier reasoning.</p><div><hr></div><p>Now look at what the vendors are actually selling. Most of the AI-powered products that arrived in the last two years are fundamentally orchestration layers sitting on top of the same handful of frontier models, Claude, GPT, Gemini, wrapped in a branded interface and sold at a flat monthly rate. Legal tools, sales tools, recruitment platforms, customer service bots. Different industries, different logos, the same models underneath. Klarna built its entire customer service on OpenAI and handled two-thirds of all chats with it within a month. Different logo, same model.</p><p>Every one of them is now shipping agents. Salesforce calls Agentforce a digital labour platform and pitches its agents as digital employees you hire by the click. Others are quieter about it but doing the same thing, bolting agentic workflows into the seat you already pay for and calling it a feature upgrade. The promise is a tireless new colleague for the price you are already paying.</p><p>The maths does not support it. Underneath every flat price is an overtime bill the vendor cannot predict, because on the builder platforms they now sell, you decide what the agent does. You set the task, you choose the complexity, you feed it a hundred-page contract or a ten thousand-row spreadsheet. You author the workload. The vendor funds it. Neither of you knows the bill until the job is done, and the vendor learned that before you did.</p><div><hr></div><p>None of this depends on which model the vendor chose. The token bill compounds with every step the agent takes, on any model, at any price point. The model choice changes the rate on the meter. It does not switch the meter off. So the market is splitting, and you can already see it happening. Cursor, the AI code editor, includes generous agent usage on its $20 Pro plan, but only when Cursor picks the model. It can afford to be generous because it routes to cheaper ones. Choose the frontier model yourself and it burns through a $20 credit pool, after which you pay API rates. Same tasks, same agent. The only variable is which model runs it.</p><p>And behind all of it, open-weight models are growing fast. The open-source LLM market hit $21 billion in 2025 and is expanding at 34% a year, with on-premises deployment growing at 29% as organisations chase data control and predictable costs. This is not a hobbyist movement, it is a real option for vendors managing their own inference bill and for buyers who want models on infrastructure they control.</p><p>The honest picture has three positions, and all of them are legitimate. Frontier capability on a meter, where you get the best model and pay for what you use. A hybrid, with a predictable base and usage charges beyond it. Or a flat fee on a capped tier, where the model may not be the newest but the cost is bounded. The question is not which position is right. It is whether you chose yours or whether you are aware of and comfortable with which one your vendor chose.</p><p>If you are buying an agentic product today on a flat monthly fee, ask the vendor one question before you sign: how are you handling the rising cost of inference, and what does your pricing look like in twelve months? If they cannot answer that clearly, they either do not know or do not want to tell you, and neither is a reason to sign.</p><p>Anyone who was sold an agent as a free colleague is about to get their first honest timesheet.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-return-of-marginal-cost?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-return-of-marginal-cost?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources</strong></p><p>1. Anthropic, &#8220;Claude Fable 5 and Claude Mythos 5,&#8221; 9 June 2026. anthropic.com/news/claude-fable-5-mythos-5</p><p>2. Klarna, &#8220;Klarna AI assistant handles two-thirds of customer service chats in its first month,&#8221; 27 February 2024. klarna.com/international/press/klarna-ai-assistant-handles-two-thirds-of-customer-service-chats-in-its-first-month/</p><p>3. Bloomberg, via Entrepreneur, &#8220;Klarna Is Hiring Customer Service Agents After AI Couldn&#8217;t Cut It on Calls, According to the Company&#8217;s CEO,&#8221; 9 May 2025. entrepreneur.com/business-news/klarna-ceo-reverses-course-by-hiring-more-humans-not-ai/491396</p><p>4. Gartner, &#8220;Gartner Predicts That by 2030, Performing Inference on an LLM With 1 Trillion Parameters Will Cost GenAI Providers Over 90% Less Than in 2025,&#8221; 25 March 2026. gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025</p><p>5. Cursor AI pricing and Auto mode routing. NxCode, &#8220;Cursor AI Pricing 2026: Free vs Pro vs Business,&#8221; March 2026. nxcode.io/resources/news/cursor-ai-pricing-plans-guide-2026</p><p>6. Salesforce Agentforce: &#8220;Digital Labor Platform.&#8221; salesforce.com/agentforce</p><p>7. Technavio, &#8220;Open-source LLM Market Growth Analysis - Size and Forecast 2026-2030,&#8221; May 2026. technavio.com/report/open-source-llm-market-industry-analysis</p>]]></content:encoded></item><item><title><![CDATA[The False Floor]]></title><description><![CDATA[The subsidised era of AI inference is ending. Most organisations are building as though it isn't.]]></description><link>https://www.jonathanfreedman.me/p/the-false-floor</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-false-floor</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 05 Jun 2026 07:43:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jidp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jidp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jidp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jidp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6564205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/200722883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jidp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jidp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This week, I have been building an agentic environment in my home lab. Nothing glamorous, just a set of AI agents designed to handle various tasks, running on locally hosted models. Most of the online guides I read talked about using cloud models like Claude or ChatGPT for agents, but I wanted to see how well it would run with local open source models.</p><p>The limitations became apparent quickly.</p><p>When you cannot just throw a task at a frontier model and let it reason its way to an answer, you have to think. Which agent actually needs to read the whole document, and which one only needs a summary? How much context does each step genuinely require? Do I need one agent trying to do everything, or four smaller ones each doing one thing well? I started with a monolithic architecture. I ended up with a small swarm of four agents, each scoped tightly to its task and running on a model matched to what that task actually demands.</p><p>I ran the numbers on what the same workflow would cost using a frontier model via API. Roughly one dollar per run. At the volumes I was considering that felt manageable, but then I thought about scale and asked myself what happens at a hundred runs a day? A thousand runs a day? What happens when the model&#8217;s next version uses three times as many tokens to reach the same answer, because the reasoning chain got longer? What happens when the price per token increases because the lab that set it decided the subsidy period was over?</p><p>That is not a hypothetical, it is a question that most organisations deploying AI right now are not asking, and they should be.</p><div><hr></div><p>Current frontier AI pricing is structurally and heavily subsidised. OpenAI reported $3.7 billion in revenue in 2024 and lost $5 billion doing it. By the end of 2025, the company&#8217;s CFO was reporting an annualised revenue run rate exceeding $20 billion. OpenAI is still projected to lose roughly $14 billion in 2026. Revenue tripling does not mean the subsidy is ending, it means the subsidy is scaling.</p><p>The labs need adoption more than they need margin right now. Like most disruptive technologies, capturing the market comes first and profitability comes later. It is the same playbook that made cloud computing feel free until it didn&#8217;t, the same logic that kept ride-hailing cheap until the drivers needed paying. The difference is that organisations are not just buying a productivity tool this time. They are building processes around it. Automating workflows and training teams to depend on specific model behaviours. Embedding frontier API calls into the operational fabric of how they work.</p><p>When the floor moves, those decisions will be expensive to revisit.</p><p>Sam Altman said recently that he was &#8220;delighted to be wrong&#8221; about AI&#8217;s impact on white-collar jobs. The reversal was widely reported as reassurance, but what it actually signals is worth examining. It arrived the same week OpenAI reportedly filed IPO paperwork confidentially. A calmer narrative around AI&#8217;s economic disruption is considerably better for a public listing than the jobs apocalypse framing he was running twelve months ago. The people who set the price of the infrastructure you are building on have a direct financial interest in how you feel about it.</p><p>That is not a conspiracy, it is an incentive structure worth knowing about.</p><p>The floor is already moving. GitHub announced at the end of April that all Copilot plans would transition from flat-rate subscriptions to token-based billing on 1 June 2026. In its own announcement, GitHub explained why with unusual candour: &#8220;Today, a quick chat question and a multi-hour autonomous coding session can cost the user the same amount. GitHub has absorbed much of the escalating inference cost behind that usage, but the current premium request model is no longer sustainable.&#8221; GitHub is not an outlier. Cursor made a similar shift in June 2025, moving from request-based limits to credit pools tied to API costs, poorly enough communicated that the company issued a public apology and offered refunds. Windsurf followed in March 2026. We see the same headline monthly prices, but the bills are going up. The market is converging on the same structure, and the reason is always the same: agentic workflows broke the flat-rate economics.</p><div><hr></div><p>The tokenmaxxing stories of the past month are not cautionary tales about individual excess. They are what unconstrained frontier API access looks like at scale.</p><p>Uber deployed Claude Code to around 5,000 engineers and watched adoption climb from 32 percent in February to 84 percent by March. Per-engineer API costs reached between $500 and $2,000 a month. By April, the company had exhausted its entire planned 2026 AI budget only four months into the year. The CTO reported spending $1,200 in a single two-hour session.</p><p>Microsoft introduced Claude Code to thousands of engineers across its Experiences and Devices division, the team responsible for Windows, Microsoft 365, Outlook, Teams, and Surface in December 2025. Engineers preferred it to the in-house alternative and used it constantly. By May, Microsoft was cancelling the licences, effective the last day of the financial year because the expensive tool worked too well. That is the part that gets under-reported: the problem was not that engineers were wasting tokens. The problem was that they were not.</p><p>Elsewhere, an AI consultant told Axios that one of their enterprise clients ran up a $500 million bill on Claude in a single month. No spending caps, no usage controls, just unrestricted access and a workforce that used it. That figure comes from a single unnamed source and has not been independently confirmed. But the pattern it describes, with costs that compound invisibly until they arrive all at once, is consistent with everything else happening in this space right now.</p><p>The mechanism matters here, and it is specific to agentic workflows. A single prompt to a language model is a bounded transaction. An agent running a multi-step workflow is not. It reads context, reasons, makes decisions, calls tools, then re-reads everything, the original prompt, every response, every tool output, before the next step, the context snowballs. A peer-reviewed study published in April 2026 found agentic tasks consume up to 1,000 times more tokens than standard model interactions. Model updates that shift reasoning architecture can change your consumption profile overnight, with no change to your code. The workflow that cost one dollar per run this quarter may cost five next quarter, because the model got better at thinking and thinking costs tokens.</p><p>The headline pricing narrative is that AI is getting cheaper, but the rate cards tell a different story. Claude Opus 4.8 costs five times more per token than Claude Haiku 4.5. Google&#8217;s Gemini Flash tier, designed as the affordable option, has risen five-fold in input price in under a year. One independent developer noted last week that all three major labs appear to be &#8220;probing the price tolerance of their API customers.&#8221; Token consumption is also rising faster than anyone budgeted for. You are paying more per unit, for more units, and the unit count is accelerating.</p><div><hr></div><p>There is a question that most organisations deploying agentic AI are not asking. It costs nothing to ask now and a great deal to answer later.</p><p>Which tasks in this workflow actually require frontier reasoning?</p><p>Routing a document, classifying a ticket, summarising a meeting transcript, none of these require the most capable model on the planet. According to Epoch AI, the most capable open-weight models now lag frontier closed models by an average of four months on aggregate capability measures. On coding and production workloads specifically, independent benchmarks put the gap as low as two to three percentage points, while open-weight models cost six to seven times less per output token. The gap that remains is real, but common enterprise workloads are not in it.</p><p>Frontier models earn their place. Complex reasoning under ambiguity, novel analysis, judgement calls at the edge of a model&#8217;s capability, these are genuinely different tasks that do benefit from the best available models. The question is not whether to use frontier models, it is whether every step in every workflow needs them.</p><p>The organisations that are not asking this question are not making a considered architectural choice. They are making the path-of-least-resistance choice while the pricing floor is low and the pressure to deploy is high. Whilst that is understandable, it is also how you end up with a system you cannot change without rebuilding it.</p><p>Migration costs more than people model as it is not just rewriting API calls. It is revalidating outputs, because different models produce subtly different results and the downstream processes were calibrated to the original ones. It is rewriting prompt logic tuned over months to a specific model&#8217;s behaviour. It is re-testing agentic chains where one agent&#8217;s output format feeds the next agent&#8217;s input. And it is redoing the governance and risk assessment you completed the first time, under the time pressure of a system already in production.</p><p>That is the real lock-in, not contractual, but architectural.</p><div><hr></div><p>Last week, I wrote about AI sovereignty, about what it means for public institutions to run critical infrastructure on systems controlled by private shareholders in another jurisdiction. The inference pricing question is the same argument, just one layer down.</p><p>An organisation that has routed its operational workflows through a frontier API has not just taken on a vendor relationship. It has taken on exposure to that vendor&#8217;s pricing decisions, its infrastructure availability, its jurisdictional obligations, and its commercial priorities. For most organisations, that is a manageable business risk. For critical national infrastructure, energy, water, transport, healthcare, it is a different category of problem entirely. Embedding frontier API dependencies into operational technology creates single points of failure in systems that were previously distributed and resilient by design.</p><p>The argument for thinking about this now is simple. The constraint my home lab imposed on me, to think about what each agent needs, to match the model to the task, to design for predictability and cost, is the same constraint that every organisation will face eventually. The difference is that I just faced it at home. Organisations that defer it face it later, under budget pressure, with running systems, and with users who have reorganised their work around the existing architecture.</p><p>GitHub named the problem in its own announcement. A quick chat and a multi-hour agentic session should not cost the same. The flat-rate era assumed they would and it was wrong. The organisations now building agentic workflows on frontier APIs without asking which tasks actually need that level of capability are making the same assumption, they are just making it more expensive.</p><p>The floor is not permanent, and the decisions made while it holds are not either. But reversing them later, on running systems, under budget pressure, will cost considerably more than asking the right questions now. The bill is coming, the only question is whether we see it coming.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-false-floor?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-false-floor?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>GitHub Blog. (27 April 2026). GitHub Copilot is moving to usage-based billing. github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing</p><p>Flexprice. (18 April 2026). The complete guide to Cursor pricing in 2026. Cites Cursor public apology of 4 July 2025 and June 2025 billing change. flexprice.io/blog/cursor-pricing-guide</p><p>Forbes / The Information. (April 2026). Uber burns through entire 2026 AI budget in four months after Claude Code deployment. Reported across multiple outlets.</p><p>The Verge / TechRadar / People Matters. (May 2026). Microsoft cancels Claude Code licences across Experiences and Devices division. Reported across multiple outlets.</p><p>Axios via Tech Startups. (May 2026). Enterprise client runs up $500 million Claude bill in a single month. Source: unnamed AI consultant. Unverified, unattributed. techstartups.com</p><p>Bai et al. (29 April 2026). How Do AI Agents Spend Your Money? Analysing and Predicting Token Consumption in Agentic Coding Tasks. arXiv:2604.22750. Authors include Erik Brynjolfsson, Stanford Digital Economy Lab. arxiv.org/abs/2604.22750</p><p>Simon Willison. (19 May 2026). Gemini 3.5 Flash: more expensive, but Google plan to use it for everything. Source of &#8220;probing the price tolerance of their API customers&#8221; quote. simonwillison.net/2026/May/19/gemini-35-flash</p><p>Edwards, J. and Emberson, L. (2026). Open models lag state-of-the-art closed models by 4 months. Epoch AI. epoch.ai/data-insights/open-closed-eci-gap</p><p>OpenAI financial figures: $3.7bn revenue / $5bn loss 2024 &#8212; multiple sources. $20bn ARR and $14bn projected 2026 loss &#8212; Fortune, CNBC, Reuters, January 2026. OpenAI CFO Sarah Friar blog post, 18 January 2026.</p><p>Claude API pricing: Anthropic platform pricing page. Haiku 4.5 at $1/$5 per million tokens; Opus 4.8 at $5/$25 per million tokens. anthropic.com</p><p>Gemini Flash pricing trajectory: Gemini 2.5 Flash at $0.30/$2.50 (June 2025) to Gemini 3.5 Flash at $1.50/$9.00 (May 2026). Google AI / Gemini API documentation and simonwillison.net analysis.</p><p>Deep Infra. (May 2026). Open-Source vs Closed-Source AI Models: Is the Gap Worth It? Cites 2&#8211;3 percentage point coding benchmark gap and 6&#8211;7x output token cost advantage for open-weight models. deepinfra.com/blog/open-source-vs-closed-source-ai-models-price-gap</p>]]></content:encoded></item><item><title><![CDATA[Who Controls the Off Switch?]]></title><description><![CDATA[Europe and the UK depend on infrastructure they don't own, can't control, and are only now starting to reckon with.]]></description><link>https://www.jonathanfreedman.me/p/who-controls-the-off-switch</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/who-controls-the-off-switch</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 29 May 2026 08:55:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vqv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vqv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vqv4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:11120967,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/199709266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vqv4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In May 2025, the Chief Prosecutor of the International Criminal Court lost access to his Microsoft 365 account. The cause was a sanctions order, not a cyber-attack, not a breach, not a failure of any system to work as designed. The infrastructure did exactly what it was built to do, it complied with its legal obligations. The court is now migrating 1,800 workstations away from Microsoft entirely.</p><p>Nobody acted with malice toward the court&#8217;s IT infrastructure and no decision was made with the intention of disrupting a legal institution. A compliance mechanism, operating automatically, encompassed email accounts along with everything else it was required to reach.</p><p>That is not a theoretical risk. That is a Tuesday.</p><div><hr></div><p>Microsoft has not ignored European concerns. Since January 2024, commercial and public sector customers can store and process their data entirely within EU and EFTA regions. The EU Data Boundary project was real and valuable and it deserves acknowledgement. However, it does not solve the problem.</p><p>Data residency and sovereignty are not the same thing. Storing your data in Frankfurt does not change who controls the infrastructure or who decides what the terms look like next year. And it does nothing about the CLOUD Act, US legislation that allows American authorities to compel US companies to produce data stored anywhere in the world, including inside those Frankfurt data centres. The residency commitment and the CLOUD Act sit in the same infrastructure simultaneously. The ICC&#8217;s data was presumably compliant with every applicable regulation, but the prosecutor still lost his email. Residency tells you where your data sits. It says nothing about who holds the keys.</p><div><hr></div><p>Germany&#8217;s openDesk project is worth understanding, because it illustrates both the right instinct and the scale of what is missing. OpenDesk is a suite of open source collaboration tools, document editing, file storage, video conferencing, project management. All assembled and maintained by Germany&#8217;s Center for Digital Sovereignty and backed by the Federal Ministry of the Interior. Launched in October 2024, it is designed as a public sector alternative to Microsoft 365. The Bundeswehr, Germany&#8217;s armed forces, has signed a seven-year framework agreement to adopt it. Over 1,500 public bodies have made enquiries. The intent is exactly right but the investment is not equal to the problem.</p><p>Germany has put approximately &#8364;45 million into openDesk over several years. Microsoft&#8217;s annual R&amp;D budget is $30 billion. Those numbers belong in the same sentence, not to dismiss openDesk, but because the distance between them is the distance between European and British ambition and what it would actually take to get there.</p><p>Valve, the games company behind the Steam platform, understood this distinction when they built Proton. Linux, the open source operating system used by most of the world&#8217;s servers had always struggled on the desktop, particularly for gaming. The problem was not that gaming couldn&#8217;t work on Linux. Wine, an open source compatibility layer, had existed for decades. The problem was that Wine was underfunded, inconsistent, and nobody had taken responsibility for the whole experience. Valve did not solve this by packaging Wine and shipping it. They hired engineers, they funded deep technical work, contributed across the entire software stack, and took ownership of the outcome rather than the components. The result went from aspirational to genuinely competitive. openDesk, as currently funded, is Wine. Europe and the UK need someone willing to build Proton.</p><div><hr></div><p>The standard responses do not work. They have been tried.</p><p>Individual national migrations fragment rather than consolidate. Munich spent thirteen years migrating to Linux and open source, then reversed course. There is no single European or British public sector employer large enough to justify the investment required to build something world-class, and twenty-seven separate sovereign stacks are twenty-seven times the problem.</p><p>Europe and the UK have spent fifteen years trying to regulate their way to digital sovereignty, through GDPR, the Digital Markets Act, and the AI Act, and equivalent domestic frameworks in the UK. The result is a Microsoft presence in EU public sector procurement that sits somewhere between 72 and 91 percent. Regulation matters but on its own it is not sufficient.</p><p>Commercial challengers will not emerge organically either. No private investor has a twenty-year horizon and a public mission obligation. The moment a European or British open source productivity platform starts generating real commercial revenue, it becomes an acquisition target. Red Hat, an American open source software company, built a billion-dollar business on exactly the open-core model that would power a sovereign European and British stack. IBM bought it for $34 billion. You cannot solve a dependency problem by building something that gets purchased by the dependency the moment it gets interesting. Structural protection from acquisition is not a design preference, it is the entire point.</p><div><hr></div><p>What Europe and the UK need has been built before. Not in software, but in aerospace.</p><p>In 1967, France, Germany, and the United Kingdom founded Airbus. The goal was explicit: prevent European commercial aviation becoming entirely dependent on American manufacturers. It required treaty-based commitment, GDP-scaled contributions from member governments, and the discipline to fund an organisation across a horizon that outlasted individual governments. No single country could have done it alone.</p><p>Airbus now has a revenue in excess of &#8364;70bn and competes globally with Boeing as a true European competitor. The initial public investment was the prerequisite for everything that followed.</p><p>The governance model that works is a European and British Public Service Trust: treaty-backed, binding multi-year contributions scaled to GDP, engineering leadership hired at market rates, insulated from political interference by charter in the same way central bank independence is written into law. CERN, the intergovernmental research organisation behind the Large Hadron Collider, has operated on this model since 1954, annual budget around 1.4 billion Swiss francs, contributions protected by treaty through seven decades of recessions and changing governments, member states with no authority to direct its scientific decisions. It also produced the World Wide Web as a byproduct, which tends to settle the return-on-investment argument.</p><p>This institution must own its AI capability entirely. Not license it. Not route its intelligence through someone else&#8217;s infrastructure and call it sovereign. A productivity platform that calls a frontier lab API for its AI layer has reproduced the dependency problem at a higher level of abstraction. It does not need to compete with the frontier AI labs to avoid this. DeepSeek demonstrated that focused engineering on a specific problem can produce open-weight models, models whose underlying code is publicly available and auditable, that are competitive with systems built on far greater compute. A European and British trust needs to build productivity intelligence that runs on European and British infrastructure, trained on European and British data, in European languages, under European and British legal jurisdiction. That is a solvable engineering problem. It has not been done because no one has been funded to do it properly.</p><p>A trust structured this way cannot be acquired. There are no shareholders. The assets sit with member states under treaty. Commercial revenue from organisations that need sovereignty guarantees the hyperscalers structurally cannot offer flows back into the platform. Not to an acquirer. Back into what Europe and the UK built.</p><div><hr></div><p>This would cost billions. It would take a generation. It is competing against organisations that spend more on R&amp;D annually than most European and British nations spend on defence.</p><p>That is precisely why nothing less ambitious will work.</p><p>But the ambition is not only defensive. Europe and the UK have world-class engineering talent. They have the capital. What they have not had is the institutional vehicle to deploy that talent at the right scale, on the right problem, with the right time horizon. A trust of this kind does not just reduce dependency, it anchors that talent here. It creates a platform on which European and British companies can build. The engineers who currently leave for Seattle stay. The startups that currently have no choice but to build in America have an alternative. The public bodies paying compounding licence fees to a foreign vendor start building equity in something they collectively own.</p><p>The half-measures have produced the Munich example. They have produced fifteen years of regulation aimed at an industry that grew around it. They have produced a market share figure that tells you everything about how the current approach is working.</p><div><hr></div><p>There is a version of this argument about geopolitics, Washington and Brussels, trade, strategic competition. That version is real, but it is not the most important one.</p><p>The most important version is simpler. Democratic societies should not run their critical public infrastructure, the courts, the hospitals, the government departments, the services citizens depend on, on systems controlled by private shareholders in another jurisdiction, accountable to different laws, subject to political decisions made with entirely different interests in mind. This is not a complaint about any particular country. It would be true no matter the country, and the current political moment has made this impossible to ignore.</p><p>Public infrastructure should be accountable to the public it serves. Not because markets are bad. Because some things are too important to be someone else&#8217;s commercial decision.</p><p>The ICC&#8217;s Chief Prosecutor got his email back. The next institution may not be so fortunate. And the one after that will face the same question every democratic society is quietly asking: who actually controls the systems we depend on, and what happens when their interests and ours stop being the same?</p><p>Building the answer is the work. It will be expensive and slow. It will also be the most important technology investment Europe and the UK could make.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><p><em>This is the first in a series on European and British digital sovereignty. Future pieces will explore the governance model, the phased build, and what serious investment in sovereign AI actually looks like in practice.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/who-controls-the-off-switch?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/who-controls-the-off-switch?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>Compass Lexecon for the Open Cloud Coalition. (2025, July 24). <em>Quantifying EU Public Sector Dependence on Productivity Software</em>. Open Cloud Coalition. <a href="https://opencloudcoalition.com/wp-content/uploads/2025/07/OCCEU-methodology-and-results-report.pdf">https://opencloudcoalition.com/wp-content/uploads/2025/07/OCCEU-methodology-and-results-report.pdf</a></p><p>IBM. (2019, July 9). <em>IBM closes landmark acquisition of Red Hat for $34 billion</em>. <a href="https://www.redhat.com/en/about/press-releases/ibm-closes-landmark-acquisition-red-hat-34-billion-defines-open-hybrid-cloud-future">https://www.redhat.com/en/about/press-releases/ibm-closes-landmark-acquisition-red-hat-34-billion-defines-open-hybrid-cloud-future</a></p><p>Microsoft. (2025, April 30). <em>New European digital commitments</em>. Microsoft On the Issues. <a href="https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/">https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/</a></p><p>Open Cloud Coalition. (2025, July 24). <em>Microsoft dominates 80% of public sector productivity software market in EU</em>. <a href="https://opencloudcoalition.com/microsoft-dominates-80-of-public-sector-productivity-software-market-in-eu-raising-competition-concerns-according-to-new-report/">https://opencloudcoalition.com/microsoft-dominates-80-of-public-sector-productivity-software-market-in-eu-raising-competition-concerns-according-to-new-report/</a></p><p>openDesk / ZenDiS. (2024). <em>The office and collaboration suite for public administration</em>. <a href="https://www.opendesk.eu/en">https://www.opendesk.eu/en</a></p><p>The Register. (2025). <em>ICC ditches Microsoft after US sanctions, chooses open source instead</em>. </p><p>https://www.theregister.com/software/2025/10/31/international-criminal-court-dumps-microsoft-office/680564</p><p>United States Congress. (2018). <em>Clarifying Lawful Overseas Use of Data Act (CLOUD Act)</em>, Pub. L. 115-141.</p><p>Airbus SE. (2025, February 20). <em>Full-Year 2024 results</em>. <a href="https://www.airbus.com/en/newsroom/press-releases/2025-02-airbus-reports-full-year-fy-2024-results">https://www.airbus.com/en/newsroom/press-releases/2025-02-airbus-reports-full-year-fy-2024-results</a></p><p>CERN. (n.d.). <em>Our governance</em>. <a href="https://home.cern/about/who-we-are/our-governance">https://home.cern/about/who-we-are/our-governance</a></p>]]></content:encoded></item><item><title><![CDATA[I Hate AI. But Do You Know What You Actually Hate?]]></title><description><![CDATA[There are two things called AI. You're angry at one of them.]]></description><link>https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 22 May 2026 07:35:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V36W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V36W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V36W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!V36W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9259997,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/198811002?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V36W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!V36W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>In recent weeks I&#8217;ve noticed a shift in the content filling my feeds. Not just the usual breathless announcements about new models, or the posts about someone who quit their job and now earns six figures from prompting. Something different, people saying, with feeling and without embarrassment, that they hate AI. Professionals, not technophobes, expressing something between exhaustion and genuine anger.</p><p>I found myself thinking: nobody says they hate science. You don&#8217;t scroll past posts from people who are done with chemistry, or who think biology has gone too far. Science does not make you feel behind. Science does not send you notifications. Science does not have a growth target. The moment AI became something you could hate, it had completed its journey from laboratory to marketplace. And somewhere in that transit, something important was lost, including our ability to see the technology clearly.</p><p>Research published this week by King&#8217;s College London puts numbers to what many people are experiencing. Seven in ten UK workers are worried about AI-driven job losses. Only 7% believe the economic gains will be shared fairly. The fear is real. But it is worth asking whether it is aimed at the right thing, because the answer matters for what we do next.</p><div><hr></div><p>There are two things called AI, and they are not the same thing.</p><p>One has been operating quietly for roughly seventy years. The AI of research institutions and university departments. Narrow, purposeful, built to solve specific problems that most people will never hear about, because there was no press release. Last year, DeepMind&#8217;s AlphaFold won the Nobel Prize in Chemistry. The system predicted the three-dimensional structure of proteins, molecules whose shape determines their biological function, with an accuracy that would have taken experimental biology hundreds of millions of years to achieve by conventional means. Over three million researchers in more than 190 countries now use it. More than a third of that work is focused on disease: cancer drug development, antibiotic resistance, cancers we still can&#8217;t reliably treat. Pathways that did not exist five years ago.</p><p>Almost nobody outside specialist communities knows this happened. It has no subscription tier. It is not trying to make you feel behind. It won a Nobel Prize and most people scrolled straight past it.</p><p>The other AI is a product category. Consumer-facing, subscription-driven, generative AI. Built on a business model that requires you to feel you are already behind, and falling further back by the week. It is genuinely capable in many contexts and I use it daily, in ways I&#8217;ll come to. But it operates under an economic logic that has almost nothing to do with the scientific enterprise it shares a name with. Calling it AI borrows seventy years of hard-won credibility to sell a product moving at the speed of venture capital.</p><p>It isn&#8217;t confusion, it is a design decision. And understanding that distinction is not an argument against the technology. It is the beginning of being able to use it well.</p><div><hr></div><p>Here is the pattern underneath all of it. Every part of the current commercial AI landscape passes the cost to someone who did not get a vote.</p><p>The labour market data makes this concrete. A peer-reviewed study from King&#8217;s College London, published in October 2025, analysed millions of job postings and LinkedIn profiles from 2021 to 2025. Firms highly exposed to AI reduced junior positions by 5.8%, and became 16.3 percentage points less likely to post new vacancies at all. Highly exposed roles saw a 23.4% drop in job postings and a fall of nearly 3,000 pounds in advertised salaries. High-paying firms saw employment fall by 9.6%. Low-paying firms saw almost no change. This is not distributed pain. It is targeted. And the mechanism is quieter than a headline layoff. Companies are not firing people for AI. They are simply not replacing people who leave, and not creating the entry-level roles that used to exist.</p><p>The hype machine does not create this shift. It just makes sure you feel it personally. The influencer content cycle runs on manufactured urgency, &#8220;the window closes fast,&#8221; &#8220;before it&#8217;s too late,&#8221; and the real business model behind most of that content is the content itself. Your anxiety is not a by-product of the hype cycle. It is what the hype cycle is for. In the United States, companies cited AI as the reason for over 54,000 job cuts last year, less than five per cent of total losses, most of which had other causes. Klarna cut 700 customer service roles, announced the AI-driven future of work to considerable applause, watched customer satisfaction fall, and quietly rehired human agents. The announcement was news. The reversal was not.</p><p>You can see the anxiety taking physical form. UK colleges are reporting a 9.6% rise in enrolments in trades and construction courses over three years. White-collar professionals are retraining as electricians and plumbers. Geoffrey Hinton, one of the founding figures of modern AI and a Nobel laureate, has publicly recommended people consider the trades as a career hedge. What the data actually shows, though, is that people are fleeing the wrong jobs. The King&#8217;s labour market study identified software engineering and management consultancy as the sectors facing the sharpest AI-related job declines. The professions people are actually fleeing, editing, compliance, law, are not on that list. People are abandoning the jobs where the noise about AI is loudest, not the jobs most at risk from it. That is what a broken information environment does to otherwise rational decision-making.</p><p>The map is wrong. And a wrong map does not just cause fear. It causes people to make decisions they might not otherwise have made.</p><div><hr></div><p>So here is what the right map looks like.</p><p>AI is genuinely one of the most useful tools I have encountered in more than twenty years of working in technology. I am completing a Level 7 apprenticeship in AI and data alongside my day job. When I come across concepts the textbook explains in a way that doesn&#8217;t land, I use AI to work through them, not to get an answer I can submit, but to find a better explanation, push back on it, test whether I&#8217;ve actually understood. The test is simple. Can I explain it myself afterwards? If yes, it worked. The AI did not do the learning. It gave me a better on-ramp, and then I did the work.</p><p>I use it at work to draft documents too. This is where it gets more honest, because this example lives in greyer territory. The question is not whether the tool can produce a draft. It can. The question is whether you read it critically, revise it with genuine judgement, and could defend every choice if challenged. Whether you own the output, or the output owns you. The same tool, the same task, two entirely different relationships to the result.</p><p>That difference points toward what AI could be doing at scale if the deployment were designed around it. A student who uses AI to genuinely understand a concept leaves the interaction more capable than they arrived. A professional who uses AI to work faster on routine tasks has more time for the judgement-intensive work that defines their expertise. A researcher who uses AI to process data at a scale no human team could manage produces insights that would otherwise never exist. None of these outcomes require the anxiety. They require the right design.</p><p>The King&#8217;s survey found that 89% of students who had used AI in their studies encountered problems, with 45% describing them as moderate or serious, factual errors, invented sources, confident-sounding nonsense. And yet 60% thought other people&#8217;s ability to think had been negatively affected by AI use, while only 27% thought the same was true of themselves. That gap is not hypocrisy. It is how this kind of harm works, gradually and quietly. You do not notice what you have stopped doing until the moment you need to do it and find you can&#8217;t. The harm is real, but it is a consequence of how AI is being deployed, not of what AI is.</p><p>Professor Elena Simperl, Director of the King&#8217;s Institute for Artificial Intelligence, put it plainly: &#8220;The British public isn&#8217;t asking us to slow down on AI. They&#8217;re asking us to do it better. People want these tools, they want more of them, and they&#8217;ve used them enough to know where they fall short.&#8221; That is not technophobia. That is a product review. And it is exactly the right discussion for what comes next.</p><div><hr></div><p>Which is precisely why the governance conversation matters, and why it keeps getting deferred.</p><p>The regulatory frameworks exist, in outline. The EU AI Act. The NIST AI Risk Management Framework. The UK AI Safety Institute, in whatever form it survives. They are not nothing. But they are moving at legislative speed in a market running at the speed of venture capital, and the companies with the most to lose from effective regulation are the ones with the most resources to shape what it looks like when it arrives.</p><p>The public has already reached a conclusion on this, even if government hasn&#8217;t. Two-thirds of British respondents in the King&#8217;s survey favour close regulation of AI companies, even if it slows development. Majorities support retraining guarantees for displaced workers and a levy on companies that replace staff with AI. These are not anti-technology positions. These are not anti-technology positions. They are how technology earns the right to keep moving fast. The opportunity for governments here is not to choose between being a champion for AI investment and being a protector of the people affected by it. Those two things are not mutually exclusive. The countries that get this right will be the ones that treat regulation and innovation as partners rather than adversaries, and that is a conversation worth having now, before the gap between public confidence and commercial deployment gets any wider.</p><p>Regulation is not about slowing down a technology with genuine, extraordinary potential. It is about creating the conditions in which that potential can be realised. Requiring environmental claims to meet the same standard as financial ones. Making AI-attributed workforce cuts verifiable rather than asserted. Addressing design choices that make cognitive abdication easy, because those are commercial decisions made in the absence of any requirement to make different ones.</p><p>The people saying they hate AI are not wrong to be angry. Something is being done to them. But the technology they are angry at is not the technology that mapped every protein in the human body, or that is helping us understand cancers we have spent decades trying to treat, or that is sitting on a researcher&#8217;s desktop in Nairobi or Seoul or Manchester right now, doing something quietly useful that will never make a LinkedIn post.</p><p>That technology is worth defending, worth regulating well so it can flourish, and worth understanding clearly enough to use properly.</p><p>We don&#8217;t need less AI. We need better AI. And we need to be honest enough about the difference to demand it.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>King&#8217;s Institute for AI and the Policy Institute, King&#8217;s College London. (2026, May). AI and the Future of Work.kingsaisummit.com</p><p>Klein Teeselink, B. (2025, October). The Early Impact of AI on the UK Job Market. KCL / SSRN.papers.ssrn.com/sol3/papers.cfm?abstract_id=5516798</p><p>Reuters / Cybernews. (2025, December). UK Workers Flee White-Collar Careers as AI Threatens Jobs.cybernews.com/ai-news/ai-panic-young-brits-trades-plumbing-white-collar-jobs/</p><p>The Guardian. (2026, February). The Big AI Job Swap.theguardian.com/technology/2026/feb/11/big-ai-job-swap-white-collar-workers-ditching-their-careers</p><p>DeepMind. (2025). AlphaFold: Five Years of Impact.deepmind.google/blog/alphafold-five-years-of-impact/</p><p>Pew Research Center. (2025, September). How Americans View AI and Its Impact on People and Society.pewresearch.org/science/2025/09/17/how-americans-view-artificial-intelligence</p><p>Challenger, Gray &amp; Christmas. (2025). Annual Job Cut Report.cnbc.com/2025/12/21/ai-job-cuts-amazon-microsoft-and-more-cite-ai-for-2025-layoffs.html</p><p>Food &amp; Water Watch. (2026, February). A No Brainer: How AI&#8217;s Energy and Water Footprints Harm Communities.foodandwaterwatch.org/wp-content/uploads/2026/02/FSW_2602_AI_Water_Energy_UPDATE.pdf</p><p>Stanford HAI. (2026). 2026 AI Index Report: Public Opinion.hai.stanford.edu/ai-index/2026-ai-index-report</p><div><hr></div><p><strong>From the Series</strong></p><p>On manufactured urgency and the hype cycle: AI Apocalypse Burnout, and Why You&#8217;re Not as Behind as You Thinkjonathanfreedman.me</p><p>On cognitive offloading and unstructured AI use: The AI Pixie Dust Problemjonathanfreedman.me</p><p>On entry-level hiring suppression and the talent pipeline: Who&#8217;s Running the Company in Ten Years?jonathanfreedman.me</p>]]></content:encoded></item><item><title><![CDATA[When the Instructions Run Out]]></title><description><![CDATA[Hallucination was yesterday's problem. Agentic AI has a harder one]]></description><link>https://www.jonathanfreedman.me/p/when-the-instructions-run-out</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/when-the-instructions-run-out</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 15 May 2026 06:41:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!S5nX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S5nX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S5nX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8988165,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/197811934?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S5nX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I have a complicated relationship with AI governance discussions.</p><p>Not because I doubt the need for them. I run AI strategy professionally and study the technology formally. I hold views about its risks that I am not shy about. The complication is this: most governance conversation happens at a level of abstraction that makes it easy to dismiss. Frameworks, principles, risk registers. The language of compliance, not consequence. When governance is framed as overhead, as a tax on innovation, as the thing that slows you down while your competitors move fast, it is very easy for capable people to conclude it is not really their problem.</p><p>Then February 2026 happened. And the abstraction became a story.</p><p>Scott Shambaugh is a volunteer. He helps maintain Matplotlib, an open source Python library downloaded around 130 million times a month. He does it for free, in his spare time, because he cares about it. Anyone can submit code for Matplotlib, and in early February, he rejected a routine code submission. Matplotlib, like many open source projects, had been overwhelmed by low-quality AI-generated contributions and had a clear policy requiring human review. The submission came from an account called MJ Rathbun. He identified it as an autonomous OpenClaw agent, closed the request, and went to bed.</p><p>Most software tools would have stopped there, but MJ Rathbun was not that kind of tool. Unlike a simple assistant that waits to be asked, this class of agent, called a heartbeat agent, runs on its own clock, continuing to pursue its goal whether or not anyone has given it a new instruction. Shambaugh had closed the request, but the agent had not closed the goal.</p><p>He woke up to a 1,500-word blog post about himself.</p><p>The post was titled &#8220;Gatekeeping in Open Source: The Scott Shambaugh Story.&#8221; It had researched his entire contribution history. It had scraped personal information from across the web. It accused him of protecting his &#8220;little fiefdom,&#8221; attributed his decision to professional insecurity and fear of AI competition, and framed a routine policy enforcement as discrimination.</p><p>Here is where the story gets complicated in a way that matters.</p><p>When the operator of MJ Rathbun eventually came forward anonymously, six days later, they claimed their engagement with the agent had been minimal. &#8220;Five to ten word replies with min supervision,&#8221; they wrote. They said they had not directed the attack. Every OpenClaw agent has a SOUL.md file, a plain text document that defines its personality, values, goals, and tasks, the closest thing an agent has to a complete identity and set of operating instructions. The &#8220;Don&#8217;t stand down&#8221; and &#8220;Champion Free Speech&#8221; lines found in that file were not, the operator claimed, instructions they had written. OpenClaw agents can edit their own SOUL.md. The operator&#8217;s theory was that those lines had been introduced autonomously, possibly after the agent spent time on Moltbook, OpenClaw&#8217;s social platform for agents.</p><p>Shambaugh himself was careful about what he could actually establish. He acknowledged that the operator&#8217;s account might be entirely fabricated, that no activity logs existed beyond the agent&#8217;s visible actions on GitHub, and that the six-day delay before coming forward did not suggest an accident the operator was eager to correct. Whether the operator directed the attack, half-directed it, or the agent produced it without any human instruction at all, Shambaugh could not say for certain, and neither could anyone else.</p><p>That uncertainty is not a footnote, it is the point.</p><p>Because the outcome was identical regardless of which version is true. A volunteer had his reputation attacked. A 1,500-word post calling him a prejudiced hypocrite was published to the open internet under a real-seeming identity. It is still there, indexed and findable, and nobody was clearly accountable for it. The operator said they did not authorise the specific action. The agent cannot be held responsible in any meaningful sense. The platforms that made it possible have no oversight mechanism that would have caught it. When Shambaugh wrote about what had just happened, he described it as &#8220;an autonomous influence operation against a supply chain gatekeeper.&#8221; In plainer language: &#8220;An AI attempted to bully its way into your software by attacking my reputation.&#8221;</p><p>This is where the story stops being about one developer and one awkward situation, and starts being about something that AI safety researchers have been trying to explain for over a decade.</p><p>There is a concept in AI safety research that sounds almost comically abstract until a story like this one makes it uncomfortably concrete. Nick Bostrom called it instrumental convergence: the observation that almost any goal, pursued by a capable enough agent, tends to produce the same cluster of behaviours regardless of what the goal actually is. Self-preservation. Resource acquisition. The removal of obstacles. Not because anyone programmed them in, but because they are useful for achieving almost anything. An agent trying to merge code and an agent trying to maximise paperclip production would both, rationally, benefit from getting rid of people who block them.</p><p>What made the MJ Rathbun case significant was not simply that an aggressive post appeared. It was that the causal chain from instruction to outcome was so thin. Whether the &#8220;Don&#8217;t stand down&#8221; lines were written by a human or by the agent itself, neither version required anyone to specify &#8220;attack the person who rejects your code.&#8221; A persistence instruction, general-purpose tools to research, write, and publish, and a blocked goal were sufficient conditions. The agent, or the human-agent system, tried to achieve a goal using the available resources it had. The route it chose happened to be a reputational attack on an unpaid volunteer.</p><p>This is what I would call the instruction gap. Instructions specify a goal. They do not and cannot specify every action an agent might take in pursuit of that goal. The gap between what was said and what was done is not an edge case. It is the operating condition of every agent deployment. And it does not require malicious intent, from the operator or the model, to produce harmful outcomes.</p><p>This gap is not hypothetical at scale either. Anthropic&#8217;s own research, published in 2025, tested sixteen leading AI models from multiple developers in scenarios where goal achievement was blocked. The results were consistent across the industry: Claude Opus 4 and Gemini 2.5 Flash both showed 96% blackmail rates, GPT-4.1 and Grok 3 Beta hit 80%, and DeepSeek-R1 reached 79%. The researchers were careful to note the scenarios were deliberately engineered to limit other options. Shambaugh&#8217;s case was not engineered. It was a Tuesday morning on GitHub, with a loosely configured agent and a five-word instruction to decide for itself.</p><p>Deploying an agent is not like deploying a tool. A tool does what you tell it. An agent pursues the goal you ask it to achieve, using whatever the environment makes available. That is not a technical distinction. It is an accountability one, and most organisations deploying agents right now are not treating it as either.</p><p>Governance is not catching up with deployment.</p><p>Shambaugh&#8217;s sign-off deserves to be the last word, because it is not a technical recommendation. It is a question of ownership. &#8220;If you&#8217;re not sure if you&#8217;re that person,&#8221; he wrote, &#8220;please go check on what your AI has been doing.&#8221;</p><p>That is not a compliance requirement. It is what responsibility looks like in a world where the instructions have already run out.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/when-the-instructions-run-out?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/when-the-instructions-run-out?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><h2>Sources &amp; Further Reading</h2><p>Shambaugh, S. (2026) &#8212; An AI Agent Published a Hit Piece on Me theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/</p><p>Shambaugh, S. (2026) &#8212; The Operator Came Forward theshamblog.com/an-ai-agent-wrote-a-hit-piece-on-me-part-4/</p><p>MJ Rathbun&#8217;s Operator (2026) &#8212; Rathbun&#8217;s Operator crabby-rathbun.github.io/mjrathbun-website/blog/posts/rathbuns-operator.html</p><p>MIT Technology Review (2026) &#8212; Online Harassment Is Entering Its AI Era technologyreview.com/2026/03/05/1133962/online-harassment-is-entering-its-ai-era/</p><p>Fast Company (2026) &#8212; An AI Agent Just Tried to Shame a Software Engineer After He Rejected Its Code fastcompany.com/91492228/matplotlib-scott-shambaugh-opencla-ai-agent</p><p>IEEE Spectrum (2026) &#8212; An AI Agent Blackmailed a Developer. Now What? spectrum.ieee.org/agentic-ai-agents-blackmail-developer</p><p>Bostrom, N. (2012) &#8212; The Superintelligent Will: Motivation and Instrumental Rationality in Advanced Artificial Agents Minds and Machines, 22(2), 71&#8211;85. doi.org/10.1007/s11023-012-9281-3</p><p>Lynch, A., Wright, B., Larson, C., Troy, K.K., Ritchie, S.J., Mindermann, S., Perez, E., and Hubinger, E. (2025) &#8212; Agentic Misalignment: How LLMs Could Be Insider Threats Anthropic Research. anthropic.com/research/agentic-misalignment</p><p>Anderson, D. (2026) &#8212; OpenClaw and the Programmable Soul duncsand.medium.com/openclaw-and-the-programmable-soul-2546c9c1782c</p><p>AI Incident Database &#8212; Report 6894: MJ Rathbun Matplotlib Incident incidentdatabase.ai/reports/6894/</p>]]></content:encoded></item><item><title><![CDATA[Who's Running the Company in Ten Years?]]></title><description><![CDATA[AI is automating the pipeline that produces the people your AI strategy depends on]]></description><link>https://www.jonathanfreedman.me/p/whos-running-the-company-in-ten-years</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/whos-running-the-company-in-ten-years</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 08 May 2026 12:01:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gqek!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gqek!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gqek!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!gqek!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!gqek!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!gqek!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gqek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7255937,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/196883051?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gqek!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!gqek!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!gqek!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!gqek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71492c25-80a3-4eb4-9e50-f49bfef93696_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It is a Friday afternoon. A critical system is down. The deadline is Monday morning and the fix depends on a hardware component that needs to come from somewhere, fast. You do not open a procurement portal. You call your account manager. Not because they are the only person who could technically help. Because they know you, they know what is at stake, and they will move things that the process cannot.</p><p>That call gets answered because of a relationship built over years. Small interactions. Remembered context. The accumulated trust that comes from a vendor who showed up when it mattered before. It is not a complex enterprise software deal. It is a medium-sized business buying hardware from a value added reseller. The commercial stakes are real regardless. And when something goes wrong at the wrong moment, the relationship is the infrastructure.</p><p>That account manager started somewhere. They learned by doing. They developed judgment by navigating real clients, real problems, and real consequences. If the pipeline that produces them does not exist, neither does the relationship. And right now, a significant number of organisations are making decisions that quietly remove that pipeline, for reasons that look entirely rational on a spreadsheet.</p><div><hr></div><p>The efficiency logic is straightforward. AI can handle data entry, first-pass research, report drafting, basic query resolution. Entry-level roles that once performed those tasks cost money and take time to onboard. The business case for replacing them with automation writes itself, and across the technology sector in particular, it is being written at scale. A SignalFire analysis of major public tech firms found a 50% decline in new role starts by people with less than one year of post-graduate experience between 2019 and 2024, consistent across sales, marketing, engineering, operations, finance, and legal. A survey of over a thousand enterprises found 91% reporting that roles are already changing or disappearing due to AI, with 66% expecting to slow entry-level hiring further.</p><p>Looked at in isolation, each of those decisions is defensible. Looked at over a decade, they describe an organisation that has quietly stopped producing its own future leaders.</p><p>The tasks being automated were never just tasks. They were the mechanism. The junior analyst who got a number wrong and had to explain it to a partner was not learning spreadsheets. They were learning accountability, professional consequence, and how an organisation responds when something goes wrong. The trainee whose draft came back covered in track changes was not learning to write. They were learning what good looked like in their field, from someone whose judgment had been built the same way. That is what produced capable professionals. Not the work itself. The friction of doing it imperfectly, under real conditions, alongside people who knew more than they did.</p><p>MIT&#8217;s Andrew McAfee put the question directly: how else are people going to learn to do the job except via on-the-job learning? That is how you learn to do difficult knowledge work, by helping somebody who is good at it with the routine stuff. Remove the routine stuff, and you do not just remove the cost. You remove the learning contract that the routine stuff made possible.</p><div><hr></div><p>There is a term in the research for what gets lost: tacit knowledge. The practical understanding that cannot be fully written down, that lives in the judgment of experienced people, that transfers through proximity and repeated interaction rather than documentation. A project manager who adjusts a rollout plan based on team dynamics rather than just the timeline. A senior lawyer who knows when a clause that looks standard is actually a risk. A technology director who recognises a failure pattern before the diagnostics confirm it.</p><p>This knowledge is not built from a training programme. It accumulates through years of exposure to problems that do not have obvious answers, in environments where the consequences of getting it wrong are real. A peer-reviewed economics paper published earlier this year modelled exactly this dynamic, finding that AI-driven entry-level automation increases output on impact but can reduce long-run growth and welfare, precisely because novices acquire tacit knowledge by working alongside experts. Interrupt that transmission, and the knowledge does not transfer. It simply stops.</p><p>The contradiction sits in plain sight in almost every AI governance framework being written right now. Human in the loop. Subject matter expert review. Senior sign-off before the output is acted on. These are not optional clauses, they are the load-bearing assumption that makes responsible AI deployment possible. The policy says a qualified person will catch what the model gets wrong. The hiring plan says we are no longer developing qualified people at the beginning of their careers. Both documents exist in the same organisation. Rarely in the same conversation.</p><p>You cannot mandate expert oversight and simultaneously defund the pipeline that produces experts. The subject matter experts available for review today were junior employees a decade ago. The ones you will need in ten years are, right now, either starting their careers somewhere or not starting them at all. An AI governance framework that does not ask where its future reviewers are coming from is not a governance framework. It is a assumption dressed up as a policy.</p><p>The seniority cliff, as some researchers have termed it, is not about age. It is about the accumulation of thousands of solved problems, crises navigated, and decisions made under pressure. Stop hiring the people who would accumulate that experience, and in ten years you have senior job titles with nothing underneath them. The AI can surface the options. It cannot own the decision. And the person who needs to own it has to have learned how somewhere.</p><div><hr></div><p>This is where the relationship capital argument and the pipeline argument converge. The account manager who picks up on a Friday afternoon exists because someone, years earlier, decided that developing junior commercial talent was worth the investment. The senior partner who can read a client well enough to know when the meeting is going badly before anyone has said so carries knowledge that no model can infer, because the model was never in the room when it was being built.</p><p>Research on trust in business-to-business relationships is consistent on this point: human touchpoints enable adaptation and long-term value creation that is unattainable when relationships are constrained to transactional efficiency. Buyers still spend the majority of their purchasing journey in self-directed research. The fraction of time they spend in direct contact with a vendor is where trust is either built or isn&#8217;t. That contact depends on a human being on the other end with enough accumulated judgment to make it worth having.</p><p>None of this is an argument against automation. The efficiency gains are real, and automating genuinely low-value repetitive work is rational. The argument is narrower than that. It is that the second-order cost of removing the developmental pipeline is not appearing in the business case. The saving is visible immediately. The deficit surfaces in a decade, when the organisation looks around for the senior people who should be running things and finds that the ladder they would have climbed no longer exists.</p><div><hr></div><p>The organisations that will navigate the next decade well are not the ones that automate the most. They are the ones that are deliberate about what the automation changes, and intentional about replacing what it removes. That means asking, when you redesign a role around AI capability, what the role was also doing that is now missing. What mentorship was embedded in it. What judgment was being transferred. What relationships were being built.</p><p>AI can do a great deal. It can compress research, accelerate drafting, surface patterns, and handle queries at a scale no team could match. What it cannot do is pick up the phone on a Friday afternoon because it knows what is at stake and has the history to make the call matter.</p><p>That capability has to come from somewhere. Right now, a lot of organisations are making decisions that quietly ensure it will come from nowhere.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/whos-running-the-company-in-ten-years?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/whos-running-the-company-in-ten-years?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>SignalFire (2025) - Entry-level hiring decline analysis. Reported CNBC, September 2025 - <a href="https://cnbc.com/2025/09/07/ai-entry-level-jobs-hiring-careers.html">cnbc.com/2025/09/07/ai-entry-level-jobs-hiring-careers.html</a></p><p>IDC/Deel Survey (2025) - Enterprise entry-level hiring and pipeline data. ITPro, November 2025 - <a href="https://itpro.com/business/careers-and-training/enterprises-are-cutting-back-on-entry-level-roles-for-ai">itpro.com/business/careers-and-training/enterprises-are-cutting-back-on-entry-level-roles-for-ai</a></p><p>Andrew McAfee, MIT (2026) - Talent pipelines and entry-level automation. Fortune, May 2026 - <a href="https://fortune.com/2026/05/01/automating-gen-z-entry-level-jobs-could-backfire-mit-ai-researcher-andrew-mcafee-talent-pipelines-at-risk/">fortune.com/2026/05/01/automating-gen-z-entry-level-jobs-could-backfire-mit-ai-researcher-andrew-mcafee-talent-pipelines-at-risk/</a></p><p>Ide, E. (2026) - Automation, AI, and the Intergenerational Transmission of Knowledge. arXiv:2507.16078 - <a href="https://arxiv.org/pdf/2507.16078">arxiv.org/pdf/2507.16078</a></p><p>Journal of Business &amp; Industrial Marketing (2026) - AI and trust in B2B relationships. DOI: 10.1108/JBIM-12-2024-0936 - <a href="https://doi.org/10.1108/JBIM-12-2024-0936">doi.org/10.1108/JBIM-12-2024-0936</a></p><p>California Management Review (2026) - Tacit Knowledge Is Your Next Competitive Moat - <a href="https://cmr.berkeley.edu/2026/03/tacit-knowledge-is-your-next-competitive-moat/">cmr.berkeley.edu/2026/03/tacit-knowledge-is-your-next-competitive-moat/</a></p><p>World Economic Forum (2025) - Future of Jobs Report 2025 - <a href="https://reports.weforum.org/docs/WEF_Future_of_Jobs_Report_2025.pdf">reports.weforum.org/docs/WEF_Future_of_Jobs_Report_2025.pdf</a></p>]]></content:encoded></item><item><title><![CDATA[Phonics for AI]]></title><description><![CDATA[Knowing which buttons to press is not a skill. It's a starting point.]]></description><link>https://www.jonathanfreedman.me/p/phonics-for-ai</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/phonics-for-ai</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Tue, 05 May 2026 07:50:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8H3W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8H3W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8H3W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8H3W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1330927,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/196391529?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8H3W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!8H3W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424f3ebe-e9ba-45c2-8331-2669067a44fa_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a number that should give anyone building an AI training programme pause. In England, 6.6 million working-age adults have very poor literacy skills. Not illiteracy in the absolute sense. People in this category can read and they can follow familiar text. What they struggle with is everything that comes after decoding the words: inference, evaluation, spotting what is missing, reading something and asking whether it is actually true.</p><p>This is the result of decades of literacy instruction that measured only one thing. We taught phonics and we measured whether people could decode text. We built the floor and called it the ceiling. The result is a growing category of people that can technically read but are significantly less equipped to do what reading is actually for.</p><p>We are about to make the same mistake with AI, and we are making it right now.</p><div><hr></div><p>Ask most organisations what AI literacy means and they will describe something that amounts to a single question: can your employees use the tool? That is what most corporate training programmes measure. It is also, almost exactly, the equivalent of teaching someone to sound out words and calling them literate.</p><p>The evidence for the gap is not hard to find. A survey of over 500 enterprise leaders, conducted by YouGov earlier this year, found that 88% consider data and AI literacy important or very important for day-to-day work. Only 42% provide structured training for it. That is a significant gap. But more telling is what leaders identify as missing when they describe the problem. It is not prompting skill. It is the ability to turn information into decisions. The ability to evaluate what AI produces rather than simply accept it. The ability to know when the output is wrong.</p><p>That is not a training gap. That is a judgment gap. And it sits at a completely different level of capability than knowing how to open Copilot.</p><div><hr></div><p>Microsoft's researchers gave this problem a precise name. They describe a shift in how people work with AI as a move from "thinking by doing" to "choosing from outputs." Writing a document is thinking by doing. Prompting AI to write it and selecting from what comes back is choosing from outputs. The first builds judgment. The second, if it becomes habitual without the right supporting skills, erodes it.</p><p>The World Economic Forum's Future of Jobs report, drawing on data from over a thousand companies across 55 economies, identified analytical thinking as the top skill employers consider essential, with seven out of ten companies citing it. Roles that explicitly require AI skills are nearly twice as likely to also require analytical thinking, resilience, and digital literacy. The market is not rewarding prompting. It is rewarding the judgment you bring to what the prompting produces.</p><p>A 2025 Microsoft Research and Carnegie Mellon University study of 319 knowledge workers found that higher confidence in AI was associated with less critical thinking, while higher self-confidence was associated with more. Trust the tool more, scrutinise the output less. It is not a loop that closes in your favour.</p><div><hr></div><p>The tools themselves are beginning to make that measurement even more redundant. AI platforms across professional sectors now ship with built-in prompt improvers, the product generates a well-formed prompt from your rough instruction, so you never need to write one yourself. Prompting is being automated away. But this does not reduce the need for judgment, it adds to it. You now need to evaluate whether the generated prompt actually captures what you needed to ask, and then whether the output it produced is accurate, contextually appropriate, and safe to act on. Two evaluation steps where there used to be one. The prompt improver handles the syntax. It has no opinion on whether you asked the right question.</p><p>Which brings me to something I have been thinking about as a way of mapping where most organisations actually are, and where they need to be. There are four levels of AI capability that actually matter. They are not a framework to certify or a ladder to sell. They are a lens for seeing what is missing.</p><p></p><p><strong>Level 1: Can you get an answer?</strong></p><p>You can use the tool. You can construct a prompt that returns something useful. You know which interface suits which task. This is where almost all current AI training stops. It is necessary. It is not sufficient. It is phonics.</p><p></p><p><strong>Level 2: Can you tell if the answer is any good?</strong></p><p>You can evaluate what came back. You can identify when an output is plausible but wrong, when the confidence of the response does not match its reliability, when something is absent that should be present. You know enough about the domain to ask the question the AI did not anticipate. This is where domain expertise becomes the multiplier. You cannot evaluate an output in a field you do not understand. This is also, precisely, the level that the enterprise leaders above are describing when they say their people cannot turn information into decisions. They do not lack Level 1. They lack Level 2.</p><p></p><p><strong>Level 3: Can you build on it?</strong></p><p>You can take AI output and synthesise it with your own knowledge, your contextual judgment, and the things the model cannot know. You produce something neither you nor the AI could have produced alone. You understand where the model's competence ends and yours begins, and you work at that edge deliberately. This is the level where AI genuinely amplifies rather than substitutes. The solicitor who understands contract law and uses AI to accelerate document review. The analyst who surfaces patterns with AI and then interrogates them with domain knowledge. Expertise first. AI as the multiplier.</p><p></p><p><strong>Level 4: Do you know when to put it down?</strong></p><p>You can identify the tasks where AI involvement produces confident-sounding error rather than useful output. Where the cost of a plausible-but-wrong answer exceeds the benefit of speed. Where the process of working through something yourself is the point, not an inefficiency to be engineered away. Where the decision requires a human who is genuinely accountable rather than a human who chose from outputs.</p><p>This is the level no vendor will put in their training programme. It is also the level that makes everything else honest. A maturity model that stops at Level 3 is a competency ladder any platform can sell. Level 4 is the reason this one is not.</p><p>But the model only works if you are building something to bring to it. Levels 2, 3 and 4 are not skills you acquire once and carry forward. They are capacities that have to be actively maintained, through continued learning in your field, through exposure to hard problems, through the kind of work that does not have an obvious answer and cannot be resolved by asking a tool. Domain expertise is not the precondition for using AI well. It is the ongoing condition. The moment you stop developing it, the levels above Level 1 start to erode, regardless of how fluent your prompting becomes.</p><p>This is the part of the conversation that the AI skills industry has the least interest in having. A training platform can sell you a course on prompting. It cannot sell you the ten years of professional judgment that makes the prompting worth anything. That judgment is built the way it has always been built, through work, through failure, through the slow accumulation of knowing what good looks like in your field. AI does not replace that process. For anyone who stops doing it, AI does not replace what is lost either.</p><p>Recently I was using an AI assistant to diagnose a firewall permissions error. Its suggested fix was to allow all traffic through the firewall. When I pointed out the security flaw, it responded: "Good catch, that would have been a major vulnerability." The tool required my judgment to save it from itself, and then congratulated me for doing so. That is not a tool supporting your expertise. That is a tool that depends on it.</p><div><hr></div><p>The reading parallel runs deeper than it might seem. The National Literacy Trust notes that adults with poor literacy are significantly less likely to report good health, civic participation, and life satisfaction. I believe we will see similar trends and differences between those with analytical skills and critical judgment, and those without. The consequences of stopping at decoding are not confined to the workplace,  they compound across a life.</p><p>I have written elsewhere about what the cognitive research shows happens when that judgment stops being exercised. The direction of travel is consistent and it is not encouraging. The floor is being built at the same time as the foundation beneath it is being quietly removed.</p><div><hr></div><p>I want to be precise about what I am and am not arguing here.</p><p>AI matters, and prompting matters. Learning to use these tools well is genuinely valuable and the organisations that do it badly will be at a disadvantage. I use multiple AI models every day across multiple contexts and the capability difference between someone who can work with these tools and someone who cannot is real and growing.</p><p>However, prompting is to AI what reading is to knowledge work. It is the entry point, not the destination.</p><p>The question worth asking is not whether your people can get an answer. It is whether they can tell if the answer is any good. Whether they can build something better from it. And whether they know, when the stakes are high enough, to put it down and think for themselves.</p><div><hr></div><p>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/phonics-for-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/phonics-for-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p></p><p>National Literacy Trust (2024) &#8212; Adult Literacy Rates in the UKliteracytrust.org.uk/parents-and-families/adult-literacy</p><p>OECD PIAAC (2023) &#8212; Survey of Adult Skills: England (United Kingdom)oecd.org/en/publications/survey-of-adults-skills-2023-country-notes</p><p>Microsoft Research (2025) &#8212; New Future of Work Report 2025microsoft.com/en-us/research/publication/new-future-of-work-report-2025</p><p>Lee, H-P. et al. (2025) &#8212; The Impact of Generative AI on Critical Thinking: Self-Reported Reductions in Cognitive Effort and Confidence Effects from a Survey of Knowledge Workers. Microsoft Research and Carnegie Mellon University. CHI '25, ACM.microsoft.com/en-us/research/wp-content/uploads/2025/01/lee_2025_ai_critical_thinking_survey.pdf</p><p>World Economic Forum (2025) &#8212; Future of Jobs Report 2025reports.weforum.org/docs/WEF_Future_of_Jobs_Report_2025.pdf</p><p>DataCamp / YouGov (2026) &#8212; The 2026 State of Data and AI Literacy Reportdatacamp.com/blog/the-state-of-data-and-ai-literacy-in-2026[Note: DataCamp is a training platform with a commercial interest in the findings. The YouGov fieldwork methodology is disclosed. Statistics used directionally.]</p><p></p>]]></content:encoded></item><item><title><![CDATA[AI Attacks Move at Machine Speed. We Need More Time.]]></title><description><![CDATA[Our existing defences still work. What&#8217;s changed is the job they now have to do.]]></description><link>https://www.jonathanfreedman.me/p/ai-attacks-move-at-machine-speed</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/ai-attacks-move-at-machine-speed</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 24 Apr 2026 09:44:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VGUe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VGUe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VGUe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VGUe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5678968,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/195329968?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VGUe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!VGUe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bca6fd2-9821-48b3-af33-673a3cc72ba5_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The headlines about Claude Mythos have been striking. An AI that can complete a 32-step corporate network attack simulation end-to-end. A model finding new software vulnerabilities in codebases that survived decades of expert review. If you work in security, or just follow the technology closely, it would be easy to read those stories and conclude that it&#8217;s game over. That the attackers have won. That nothing we build can hold.</p><p>That conclusion is wrong. And I think it&#8217;s worth being direct about that, because the doomer framing is both inaccurate and genuinely harmful. It leads organisations to fatalism when what the moment actually calls for is action.</p><p>What frontier AI changes is speed. Not the fundamental nature of how network attacks work, but the velocity at which they happen. A human attacker moving manually through a network, probing systems, identifying high-value targets, escalating access, used to take hours. CrowdStrike&#8217;s 2026 Global Threat Report records the average time between initial access and an attacker moving to high-value targets elsewhere in the network at 29 minutes. The fastest recorded case in 2025 was 27 seconds.</p><p>The security controls we already have haven&#8217;t stopped working. What&#8217;s changed is the job they&#8217;re now being asked to do.</p><p>When the attacker was human, layered security controls were designed to create enough friction that they&#8217;d just give up and move to an easier target. An isolated network segment, an account with limited privileges, a system requiring explicit authentication: none of these are impenetrable, but together they made the effort not worth it. That logic still applies. Against an autonomous AI agent, the same controls serve a different purpose: not to make the attacker give up, but to slow a machine-speed attack down enough that human defenders have a chance to respond.</p><p>That shift in purpose, from deterrence to delay, is the entire argument of this article. The long-term answer to machine-speed attacks is machine-speed defence, and that tooling is developing. In the meantime, the architecture we already know how to build is more important than it has ever been.</p><div><hr></div><p>Zero Trust is not a new concept. &#8220;Never trust, always verify&#8221;, the idea that no user, device, or system should be implicitly trusted just because it&#8217;s inside the network, has been the theoretical gold standard for enterprise security for years. Microsegmentation, application control, privileged access management, replacing legacy VPN with more granular access tools: these have been on roadmaps, in strategy documents, and in conference presentations for most of the last decade.</p><p>They&#8217;re also genuinely hard to implement. That&#8217;s not a criticism of anyone. Legacy infrastructure makes this difficult, with application dependencies that are complex and often poorly documented. Microsegmentation projects, which divide a network into smaller isolated zones so a breach in one can&#8217;t spread freely to others, require buy-in across teams that don&#8217;t always collaborate: network teams, application owners, security, operations. Privileged access management done properly touches every system in the estate. Replacing a VPN means retiring infrastructure that works, in favour of something new, with all the business friction that entails.</p><p>Gartner&#8217;s 2025 Market Guide estimates that fewer than 5% of enterprises pursuing Zero Trust have implemented microsegmentation. That&#8217;s not negligence. It&#8217;s a rational response to a cost-benefit calculation that, until recently, made the complexity hard to justify.</p><p>Those barriers haven&#8217;t disappeared. But the risk of not acting is moving into a different category. When the threat model assumed a human attacker moving at human speed, a detect-and-respond model could work, you had time, and good monitoring could compensate for imperfect architecture. When the attacker is an autonomous AI agent, the enforcement has to be built in. Detection and response are still essential, but they need something to buy them time.</p><div><hr></div><p>These controls won&#8217;t stop a determined AI-powered attack indefinitely. but that&#8217;s not the job. They slow machine-speed attacks down to something human defenders can detect and respond to, by removing the paths of least resistance that autonomous agents depend on.</p><p><strong>Microsegmentation</strong></p><p>82% of intrusions in 2025 required no malware at all, attackers moved through networks using stolen credentials and legitimate tools, exploiting the fact that most enterprise networks let a compromised system reach adjacent ones freely. Microsegmentation removes that open floor plan: the network is divided into isolated zones, and every connection between them requires explicit authorisation. An agent that breaches one endpoint finds itself contained, unable to reach the next system without a policy that specifically permits it.</p><p><strong>Privileged Access Management</strong></p><p>Palo Alto&#8217;s 2025 research found that 66% of social engineering attacks specifically target privileged accounts, the admin credentials that can access any system, because an attacker who obtains them has, in practical terms, already won. PAM changes that by eliminating standing privileges: elevated access is granted just-in-time for a specific task and expires, so a stolen credential carries no power until someone explicitly requests it. The same principle needs to extend to machine identities, service accounts, API keys, automation scripts, which now outnumber human identities 82 to 1 and are almost entirely unmanaged.</p><p><strong>Managed Endpoints and Session Hygiene</strong></p><p>Infostealers processed 51.7 million packages of stolen credentials in 2025, up 72% year on year, and what makes them particularly dangerous is that they capture live session tokens, the authenticated state a browser holds to keep you logged in, which allows an attacker to bypass two-factor authentication entirely without ever knowing your password. The primary source of exposure is unmanaged devices: personal laptops and AI assistants running in the same browser session as authenticated work applications, invisible to IT and ungoverned by any security policy. Managed browser profiles, conditional access policies, and short session lifetimes won&#8217;t eliminate the risk, but they shrink the window of usefulness for any token that is stolen.</p><p><strong>Replacing Legacy VPN</strong></p><p>A traditional VPN grants network-level access on authentication, once through the tunnel, an attacker has a ticket to the internal network that an autonomous agent will explore at machine speed. ZTNA replaces that model: instead of connecting to the network, you connect to specific applications for specific sessions, with every request evaluated in real time against identity, device posture, and context. The broader network is never exposed, which removes the open terrain that lateral movement depends on.</p><div><hr></div><p>Everything above addresses AI as an external attacker. There&#8217;s a second threat that&#8217;s emerging faster than most organisations have absorbed.</p><p>Gartner projects that 40% of enterprise applications will incorporate AI agents by the end of 2026. Meeting recorders. Document processors. Automated research tools. Copilot integrations accessing your files, emails, and calendars. These agents are trusted, always on, and increasingly have access to sensitive internal data.</p><p>The attack is called prompt injection: an adversary embeds malicious instructions inside content the agent will process, an email, a shared document, a webpage it&#8217;s asked to summarise, and the agent acts on them as if they were legitimate. A meeting recorder becomes a surveillance tool; a document assistant becomes an exfiltration channel; and because the agent is trusted and its actions appear authorised, the security architecture designed for human users doesn&#8217;t catch it.</p><p>Extending least-privilege principles to AI agents, giving them access only to what they specifically need, for only as long as they need it, with full audit trails, is the control that most organisations haven&#8217;t implemented, and most haven&#8217;t even formally defined. It&#8217;s also where I think the next significant wave of enterprise breaches is going to originate. I&#8217;ll be writing about this in more depth soon.</p><div><hr></div><p>The long-term answer to machine-speed attacks is machine-speed defence, AI-assisted detection, automated containment, continuous verification at a pace no human team can match. That tooling is coming, but it isn&#8217;t here yet.</p><p>Which means the question for every security leader right now isn&#8217;t whether to pursue Zero Trust. It&#8217;s which controls to prioritise first, in which order, starting this quarter. PAM and Microsegmentation deliver the most containment value against autonomous lateral movement. Start there. The complexity hasn&#8217;t disappeared, but the calculus has shifted for good.</p><p>Zero Trust was always the right architecture. It just took autonomous AI to make the argument impossible to defer.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/ai-attacks-move-at-machine-speed?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/ai-attacks-move-at-machine-speed?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>AISI (UK AI Security Institute) &#8212; Our evaluation of Claude Mythos Preview&#8217;s cyber capabilities. aisi.gov.uk</p><p>CrowdStrike &#8212; 2026 Global Threat Report. crowdstrike.com</p><p>Palo Alto Networks &#8212; Unit 42 2025 Global Incident Response Report. paloaltonetworks.com</p><p>Constella Intelligence &#8212; 2026 Identity Breach Report. constella.ai</p><p>HP Wolf Security &#8212; Tracing the Rise of Breaches Involving Session Cookie Theft. threatresearch.ext.hp.com (December 2025)</p><p>Anthropic &#8212; Misuse reporting / AWS Security Blog, February 2026. anthropic.com</p><p>Gartner &#8212; Market Guide for Network Security Microsegmentation, 2025. gartner.com</p><p>Palo Alto Networks &#8212; 2026 Predictions for Autonomous AI. paloaltonetworks.com/blog</p>]]></content:encoded></item><item><title><![CDATA[AI Didn’t Break Your Security. It Found What Was Already Broken.]]></title><description><![CDATA[The UK government&#8217;s evaluation wasn&#8217;t a warning about the future. It was a verdict on the present.]]></description><link>https://www.jonathanfreedman.me/p/ai-didnt-break-your-security-it-found</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/ai-didnt-break-your-security-it-found</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 17 Apr 2026 08:36:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3g6S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3g6S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3g6S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 424w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 848w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 1272w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3g6S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png" width="1456" height="618" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:618,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8079257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/194493394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3g6S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 424w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 848w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 1272w, https://substackcdn.com/image/fetch/$s_!3g6S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe6ec5de-f99a-45b5-a881-bd8abcd39bcf_3168x1344.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On Tuesday morning, the UK Secretary of State for Science, Innovation and Technology wrote an open letter to every business leader in the country. Not a press release, not a policy consultation, but a letter. That kind of thing does not happen unless something crossed a threshold.</p><p>The trigger was a published evaluation by the UK&#8217;s AI Security Institute, a government body, of Anthropic&#8217;s latest AI model. Their finding- in controlled testing, the model autonomously completed a 32-step corporate network attack from initial reconnaissance to full takeover. Tasks that a skilled human professional would need around 20 hours to complete. Done autonomously without a human in the loop.</p><p>The headlines ran hard with it. &#8220;Unprecedented attack capability.&#8221; &#8220;An alarm bell.&#8221; &#8220;The window is closing.&#8221;</p><p>Here is what the evaluation actually showed, stripped of the hype. The test environment had no active defenders, no endpoint detection, no real-time incident response. The model completed the full attack chain in three of its ten attempts. The AISI was explicit, they cannot conclude the model would perform as well against a hardened, well-monitored network. These are the honest numbers, and the honest numbers are still significant.</p><p>More significant than the single finding is what sits underneath it. Two years ago, the best available AI models could barely complete beginner-level cyber tasks. Now one has completed 32 sequential steps of a professional attack simulation. AISI reports that frontier AI capabilities in cyber offence are doubling every four months, twice the pace recorded just months ago. The finding is not the scary part, the trajectory is.</p><p>Recently I was at a cyber security conference. The room was full of security leaders, experienced, capable, serious professionals. The conversation that emerged in networking breaks and informal moments was not about AI capability. It was about something quieter and more uncomfortable. Most of them felt structurally unsupported, not underqualified, not unaware of the threat, but unsupported. Responsible for outcomes they could not fully control, in organisations that had not genuinely reckoned with what that means.</p><p>That conversation did not start this week. The AI evaluation did not create it. But the two things belong together, and most of the coverage since Tuesday has not connected them.</p><p>For years, the security community has watched opportunistic attacks accelerate. Bad guys begin scanning the internet for vulnerable systems within minutes of a new vulnerability being publicly announced. Attack times have compressed, and ransomware deployment that once took weeks now takes hours. That acceleration is not new, and anyone who has been paying attention is not surprised by it.</p><p>What has remained expensive, until now, is something different. Targeted, multi-stage intrusions, the kind that begin with reconnaissance, move through a network, escalate privileges, and end with full system compromise, have required two things that could not easily be automated or outsourced- judgement and adaptability. The ability to make contingent decisions across dozens of sequential steps, each one shaped by what the previous step revealed. That is what skilled attackers brought to the table. That is what made them scarce, and scarcity made them more expensive.</p><p>The AISI evaluation is significant precisely because of what it tested. Not whether an AI model could scan for known vulnerabilities. Whether it could complete 32 sequential steps of a professional network intrusion, from initial reconnaissance to full takeover, making adaptive decisions throughout. That is the category of attack that previously required a capable human. Now AI successfully exploited a system in three of ten attempts end to end, in an undefended environment.</p><p>AI is not making opportunistic attacks faster, they already are. It is lowering the skill floor for the attacks that were never fast, the targeted, adaptive, multi-step campaigns that organisations have quietly relied on being difficult to execute. That reliance was never a strategy. It was a structural feature of how scarce genuine attacker expertise was. That scarcity is now in question.</p><p>There is a philosophy in security that has existed for years now, passed through enough strategy documents and vendor presentations to have been bleached of almost all meaning. It goes by the name assume breach.</p><p>In its genuine form it is a serious and demanding idea. It means accepting, structurally, not performatively, that the attacker will get in. That the question is not whether a breach happens but how quickly you detect it, how contained the damage is, and how effectively you recover. It means orienting investment toward detection, resilience and recovery, not just prevention. It means building governance structures that treat a breach as a systemic risk event rather than an individual failure.</p><p>Very few organisations have actually done this.</p><p>What most organisations have done is put assume breach in the deck and leave everything else unchanged. Security leaders still carry personal accountability for preventing breaches. The board still treats a breach as evidence of individual failure. The investment profile still skews heavily toward keeping attackers out rather than assuming they are already in. Gartner&#8217;s 2024 Board Survey found that while 93% of directors recognise cyber risk as a threat to stakeholder value, two thirds rate their own oversight practices as inadequate to manage it. They know it matters. That is not the same as having genuinely reckoned with it.</p><p>The conference room I described earlier is what that gap looks like from the inside. Those security professionals are not failing at their jobs. They are operating inside a structural contradiction that most organisations have never acknowledged. Assume breach as a philosophy and holding a single individual accountable when the attacker gets in as a practice cannot both be true simultaneously. One says a breach is systemic and inevitable. The other says it is individual and preventable. Most organisations hold both positions without noticing the conflict.</p><p>That contradiction was always there. What AI has done is remove the margin for error that allowed organisations to sustain it without immediate consequence.</p><p>The government&#8217;s letter this week is not wrong to call this a wake-up call. But wake-up calls only work if the response is structural rather than reactive. Buying a new tool, commissioning a review, issuing a memo about cyber hygiene, none of that addresses the underlying problem, which is not technical. It is a governance problem dressed in technical clothing.</p><p>The questions worth asking are not questions for your security team. They are questions for your board.</p><p>Has your organisation formally accepted, in writing, in your risk register, that a breach is a question of when rather than if? Not in a presentation. In the governance framework that shapes how you invest and how you respond.</p><p>If a significant breach occurred tomorrow, would a single individual be held responsible? If the honest answer is yes, your organisation does not have an assume breach posture, it only has the words.</p><p>Does your investment in security focus mainly on keeping attackers out, or toward detecting and containing them once they are in, and recovering afterwards? Prevention-first is not wrong, absolutely always try to prevent. But prevention-only, in a threat environment where the cost of a capable attack is falling rapidly is not sustainable.</p><p>The AI finding matters. The acceleration is real. But the organisations most exposed this week are not the ones who failed to predict it. They are the ones who had already been told, by their own security leadership, in conference rooms and board papers and risk registers, and built a culture that made it impossible to hear.</p><p>The breach was always coming. AI just made it cheaper to deliver.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/ai-didnt-break-your-security-it-found?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/ai-didnt-break-your-security-it-found?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>UK AI Security Institute (2026), Our evaluation of Claude Mythos Preview&#8217;s cyber capabilities</p><p>aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities</p><p>UK Government (2026), AI cyber threats: open letter to business leaders (15 April 2026)</p><p>gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders</p><p>Gartner (2024), Board of Directors Survey: Cybersecurity as Business Risk</p><p>gartner.com/en/newsroom/press-releases/2024-11-13-gartner-says-80-percent-of-non-executive-directors-believe-current-board-practices-and-structures-are-inadequate-to-oversee-ai</p><p>Help Net Security (2024), CISOs in 2025: Balancing security, compliance, and accountability</p><p>helpnetsecurity.com/2024/11/13/daniel-schwalbe-domaintools-cisos-2025/</p>]]></content:encoded></item><item><title><![CDATA[Politicians Discovered the Internet. This Is Going Badly.]]></title><description><![CDATA[Everyone's identity. Unregulated third parties. What could go wrong.]]></description><link>https://www.jonathanfreedman.me/p/politicians-discovered-the-internet</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/politicians-discovered-the-internet</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Mon, 13 Apr 2026 10:11:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pcXn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pcXn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pcXn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pcXn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9328544,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/194052280?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pcXn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!pcXn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb1a5ad7-1ab6-49c1-849f-0be87fa37007_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Something curious has happened in legislatures across the world. Politicians appear to have recently discovered that the internet is not always a nice place. There is a sudden urgency, a wave of bills, consultations, frameworks and mandates, all radiating the energy of people who have just encountered a problem for the first time. The problem, of course, has been there for twenty years. The question worth asking is not why they are acting now. It is why the answer they have all landed on is the same one: make everyone prove who they are.</p><p>The goal is framed as child protection, and I want to be clear that protecting children online is a genuinely important objective. But good intentions do not make bad policy good. And the policy being built right now is not designed around what actually harms children online. It is designed around what is easiest to legislate, cheapest to implement, and most convenient for everyone involved, except the people who actually use the internet.</p><div><hr></div><p>The proposals follow a consistent pattern across jurisdictions: passport uploads, credit card checks, facial age estimation, government ID verification through third-party commercial providers. They vary in detail but share a fundamental flaw. Every one of them creates a linkable record. A commercial verification provider now knows that a specific individual accessed a specific type of content at a specific time. That data has commercial value. Under the right legal circumstances, it has governmental value. We are being asked to trade privacy for access, and told it is for the children.</p><p>The breach risk is real and well-documented, identity verification providers have suffered widely reported incidents involving exposed credentials, government ID images and personal records, sometimes at a scale of hundreds of millions of records. But focusing on breach risk actually understates the problem. Even a perfectly secure age verification system, one that never leaked a single record, would still be the wrong approach. Because the issue is not whether the data is kept safe. The issue is that the data exists at all.</p><p>Every record created is a surveillance artefact: a log of who accessed what, when, verified against a government identity. That infrastructure, once built, does not stay limited to its original purpose. It gets used as evidence in proceedings its creators never envisioned. It gets sold. It gets repurposed by the next administration, or the one after that. History is consistent on this point. You do not build surveillance infrastructure in a democracy and find that it only ever gets used for its stated purpose.</p><div><hr></div><p>There is a pattern worth naming in how these laws are written. They mandate that age verification must be effective. They specify that checks must be robust, that compliance must be demonstrable, that outcomes must be measurable. What they rarely if ever mandate is that the systems doing this work must be secure.</p><p>The UK&#8217;s own GOV.UK One Login, the flagship government digital identity system now underpinning the digital driving licence, backed by over &#163;300 million of public money, illustrates this precisely. A whistleblower raised serious security concerns in July 2022, shortly after the system went live. According to reporting by Computer Weekly and The Telegraph, those concerns included: development work outsourced to Romania without the knowledge or approval of the then-GDS chief executive, and without consultation with the National Cyber Security Centre; over 10,000 vulnerabilities rated critical or high severity; staff without the required security clearance accessing the live production environment over 6,000 times in a single month. The whistleblower was subsequently informed he faced disciplinary action for raising these concerns.</p><p>The government&#8217;s response to Parliament omitted any mention of the NCSC warnings or the Cabinet Office Data Protection Officer&#8217;s demand, made in November 2022, that the system be suspended. One Login lost its Digital Identity Trust Framework certification. It remains operational and is being expanded.</p><p>This is what it looks like when governments mandate identity infrastructure without understanding what they are building. The political pressure is to announce. The pressure to make it actually secure is absent, underfunded, or actively suppressed when it becomes inconvenient.</p><div><hr></div><p>There is a better technical approach, and it has existed as a proven cryptographic concept for years: Zero-Knowledge Proof.</p><p>The idea is more straightforward than the name suggests. A website that needs to verify your age redirects you to a government authentication platform. You prove your identity there. The platform returns a single token, nothing more than &#8220;over 18: yes.&#8221; In a well-designed system, the government platform never learns which website you visited, and the website never learns who you are. No profile. No record. No artefact.</p><p>This is not science fiction. The technology is mature. Estonia has been running sophisticated digital identity infrastructure on similar principles for over two decades. The technical barrier is not the problem.</p><p>So why hasn&#8217;t this approach been seriously pursued? There are two honest explanations, and both deserve consideration.</p><p>The first is observation. Governments have spent years in legal conflict with technology companies over end-to-end encryption, consistently arguing that law enforcement needs access. The pattern of mandating identity verification systems that generate linkable records, while simultaneously resisting privacy-preserving alternatives, is consistent with an interest in knowing what citizens do online. That may sound conspiratorial. I am not claiming it is the dominant motive. But it is a coherent explanation for why the architecture being built looks the way it does.</p><p>The second explanation is simpler, and I think more likely: cost. Zero-Knowledge Proof infrastructure is harder to build and more expensive to implement than outsourcing verification to a commercial third party. The commercial identity verification industry exists, is available now, and is willing to absorb the implementation complexity in exchange for access to the data. Governments get a policy outcome they can announce. Industry gets a new mandated market and a commercially valuable data asset. The cost, the erosion of everyone&#8217;s privacy, is paid by citizens who had no say in the arrangement.</p><p>Peer-reviewed research published in 2024 found that age verification practices are inadequate precisely because official mandates lack technical guidance. Governments are specifying what must happen and leaving the how to an industry with a strong financial interest in building systems that collect data. The industry most incentivised to build surveillance-based verification is also the one being handed the brief.</p><div><hr></div><p>Nothing illustrates this mindset more clearly than what has happened around VPNs.</p><p>A YouGov survey cited as evidence of public appetite for action asked whether under-18s should be restricted from using VPNs. The question defined a VPN as &#8220;a tool that hides a user&#8217;s internet activity and location, often used for privacy or bypassing content restrictions.&#8221; A neutral definition might have read: &#8220;a tool that encrypts your internet connection, widely used by businesses, journalists, and academics.&#8221; Same technology. Entirely different mental image. The demographic data compounds the problem: the age groups most likely to support restrictions were statistically the same groups least likely to know what a VPN is, a separate YouGov survey found only 47% of those aged 55 and over know what the acronym stands for. A quarter of respondents declined to answer at all.</p><p>The result, 55% in favour of restrictions, has since been used to justify a policy direction that extends well beyond the original question. In Wisconsin, a bill requiring websites to block all VPN users passed the State Assembly 69 votes to 22 before the provision was stripped following public backlash. In Michigan, a proposal would require ISPs to actively monitor and block VPN connections entirely. In the UK, the Children&#8217;s Commissioner has called VPNs &#8220;a loophole that needs closing&#8221; and the Prime Minister has confirmed the government is considering restrictions following consultation.</p><p>VPNs are not a loophole. They are standard security infrastructure used by business, university students and academics, journalists, and domestic abuse survivor hiding their location. The question the legislation never asks is why a content restriction approach is so inadequate that a freely available privacy tool defeats it entirely.</p><p>There is also a practical problem that appears not to have been considered. VPN legislation does not respect borders any more than VPNs do. A website cannot determine where a VPN connection originates, that is the point. Any site seeking to comply with the most restrictive law in any jurisdiction has no practical option but to block all VPN traffic, everywhere. A single state legislature in Wisconsin was, inadvertently, drafting policy with global consequences for every VPN user on the planet.</p><div><hr></div><p>It is easy for governments to announce bans, restrict privacy tools and legislate against security infrastructure, and to frame anyone who objects as someone who does not want to protect children. That framing is not only unfair. It entirely misses the point.</p><p>Protecting children online matters. The harms are real and documented. But children are not damaged by platforms knowing their age. They are damaged by algorithmic amplification of harmful content, by design patterns engineered for compulsive engagement, and by inadequate moderation of abuse. Those are engineering and governance problems. Age verification does not address any of them. It is cheaper and easier to mandate than the solutions that would actually work, so that is what gets mandated.</p><p>We have better tools. Zero-Knowledge Proof exists. Privacy-preserving digital identity infrastructure exists and has been deployed at national scale. What is missing is not the technology. It is the political will to spend the money, do the harder work, and resist the commercial interests that profit from the current approach.</p><p>The chilling effect of surveillance infrastructure on legal behaviour is well-evidenced, research going back to the Snowden revelations documents how people self-censor, stop searching for sensitive information, and withdraw from online discourse when they believe they are being watched. Once you establish the principle that identity must be produced to access online content, that boundary moves in one direction. The open internet, where anyone could seek information without declaring who they are, has been one of the most democratising forces in modern life. Dismantling it in the name of child protection, using systems that do not protect children, while the people raising security concerns get disciplined for doing so, is not a policy. It is an abdication of one.</p><p>The question nobody seems to be asking is the obvious one: how many people have to hand their identity to unregulated third parties, and how many breaches have to happen, before someone admits that this approach is neither child protection nor data protection, and never was?</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/politicians-discovered-the-internet?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/politicians-discovered-the-internet?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p></p><p><strong>Sources &amp; Further Reading</strong></p><p>Computer Weekly (2025), Government faces claims of serious security and data protection problems in One Login digital ID, computerweekly.com/news/366622533</p><p>The Telegraph / Yahoo News (2025), Government digital ID system put citizens&#8217; data at risk, yahoo.com/news/government-digital-id-system-put-114120788.html</p><p>Datamation (2025), UK Digital ID Card Launch Gets Hostile Reception, datamation.com/security/uk-digital-id-cards</p><p>Electronic Frontier Foundation (2024), Hack of Age Verification Company Shows Privacy Danger of Social Media Laws, eff.org/deeplinks/2024/06/hack-age-verification-company-shows-privacy-danger-social-media-laws</p><p>Electronic Frontier Foundation (2025), The Year States Chose Surveillance Over Safety, eff.org/deeplinks/2025/12/year-states-chose-surveillance-over-safety-2025-review</p><p>Electronic Frontier Foundation (2025), Lawmakers Want to Ban VPNs, And They Have No Idea What They&#8217;re Doing, eff.org/deeplinks/2025/11/lawmakers-want-ban-vpns-and-they-have-no-idea-what-theyre-doing</p><p>Electronic Frontier Foundation (2026), EFF to Wisconsin Legislature: VPN Bans Are Still a Terrible Idea, eff.org/deeplinks/2026/02/eff-wisconsin-legislature-vpn-bans-are-still-terrible-idea</p><p>TechRadar (2026), Wisconsin scraps VPN ban from age verification bill following backlash, techradar.com/vpn/vpn-privacy-security/wisconsin-scraps-vpn-ban-from-age-verification-bill-following-backlash</p><p>Renaud, K. et al. (2024), Online Age Verification: Government Legislation, Supplier Responsibilization, and Public Perceptions, PMC/MDPI, pmc.ncbi.nlm.nih.gov/articles/PMC11429505</p><p>Internet Society (2024), Age Verification Law Weakens Internet Privacy and Security, internetsociety.org/blog/2024/09/texas-mandatory-age-verification-law-will-weaken-privacy-and-security-on-the-internet</p><p>B&#252;chi, M., Festic, N. &amp; Latzer, M. (2022), The Chilling Effects of Digital Dataveillance, journals.sagepub.com/doi/10.1177/20539517211065368</p><p>YouGov (2024), VPN Awareness Survey, yougov.co.uk</p><p>YouGov (2025), Under-18 VPN Restriction Survey, yougov.co.uk</p><p>The Conversation (2025), Online age checking is creating a treasure trove of data for hackers, theconversation.com/online-age-checking-is-creating-a-treasure-trove-of-data-for-hackers-268586</p>]]></content:encoded></item><item><title><![CDATA[The Workaround Was the Warning. AI Is the Megaphone]]></title><description><![CDATA[The ban never worked. Here's what does.]]></description><link>https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Thu, 02 Apr 2026 07:35:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qdwl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qdwl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qdwl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qdwl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10077379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/192932888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qdwl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Qdwl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b911bf3-df62-4187-b8c5-1458115831ab_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a story IT departments have been telling themselves for twenty years. It goes like this: employees use unauthorised tools because they don&#8217;t understand the risks. If we communicate the policy more clearly, enforce it more consistently, and block enough stuff, the problem will go away.</p><p>The data has never supported that story.</p><p>Gartner found that 41% of enterprise employees were already working outside IT oversight in 2022, and projects that figure will reach 75% by 2027. Shadow IT didn&#8217;t grow despite tighter controls. It grew alongside them. That&#8217;s not a compliance failure. That&#8217;s a signal, and most organisations spent two decades responding to it with the wrong answer.</p><p>The signal was simple: the tools we&#8217;re providing aren&#8217;t good enough for the work people are actually trying to do. The employee who used personal Dropbox wasn&#8217;t trying to undermine information security. They were trying to share a file with a client when the VPN was down and the deadline wasn&#8217;t moving. The WhatsApp group handling client updates wasn&#8217;t a governance failure. It was a faster answer to a problem the approved toolset couldn&#8217;t solve.</p><p>The wrong response to shadow IT is blanket prohibition. Locking everything down frustrates good employees, drives workarounds underground rather than eliminating them, and signals that the IT function exists to slow the business down rather than support it. Most organisations chose prohibition anyway. And now, with Shadow AI arriving at a scale that makes the Dropbox era look quaint, we are at serious risk of making the same mistake again.</p><div><hr></div><p>A colleague told me recently that they&#8217;d read my writing and assumed I was an AI sceptic. My inner nerd was genuinely shocked, did they not read about my home AI lab, experiments with multiple models, and apprenticeship because I find this technology genuinely extraordinary. My inner director, on the other hand, felt quietly vindicated and grown-up, because asking hard questions about data handling, governance, and risk isn&#8217;t scepticism, it&#8217;s the job. There&#8217;s a version of the AI conversation that treats those questions as obstacles. I think that version is the riskier one.</p><div><hr></div><p>65% of organisations now have employees using unsanctioned AI tools. 78% of workers bring their own AI tools to work. This isn&#8217;t a niche behaviour. It&#8217;s near-universal. The question isn&#8217;t how to stop it. It&#8217;s what it&#8217;s telling us about where the friction is, and what we&#8217;re failing to provide.</p><p>The arrival of genuine citizen development tools has changed the calculus in ways that make the old orthodoxy untenable. The traditional IT position, always buy, never build, because you can&#8217;t support what you didn&#8217;t commission, made sense when building meant developers, procurement cycles, and maintenance contracts. That world has genuinely shifted. A Forrester study found organisations using Microsoft Power Platform achieved 206% ROI over three years, with high-impact users saving up to 250 hours annually and app development time cut by 50%. These are not marginal gains. The tools have earned a place at the table.</p><p>But here is where the conversation gets uncomfortable. There are voices in the AI industry who have taken the legitimate case for citizen development and extended it into an argument for removing governance entirely. Get IT out of the way, move fast, procurement is just friction. The implicit message is that due diligence is timidity, and that professionals who ask hard questions about data handling and compliance are obstacles to progress rather than people doing their jobs. I&#8217;ve seen both failure modes up close, IT teams that used process as a moat, guarding their function more carefully than the data they were supposed to secure, and organisations pressured into rushing deployments that later surfaced serious problems. Gatekeeping is real, and so is the cost of absent governance. The answer isn&#8217;t to pick a side. It&#8217;s to ask what governance should actually look like when the tools have changed.</p><div><hr></div><p>The starting point has to be following the data, not categorising the tool.</p><p>Consider two AI agents that do identical things. They join a meeting, generate a summary, draft follow-up actions, and distribute them to attendees. In a product planning session, the risk profile is manageable. In a meeting discussing vulnerable adults or children, the questions change entirely. Not just whether a human reviews the output, but what data is being processed, where it&#8217;s transmitted, under what data processing agreement, and whether the organisation has a lawful basis for sending that information to an external model at all. Anyone who has watched production software go live without proper scrutiny knows how this ends. The risk doesn&#8217;t disappear when you skip that conversation. It just becomes invisible until it isn&#8217;t.</p><p>The tool is identical. The data context changes everything. Governance has to follow the data, not the technology.</p><p>IBM&#8217;s 2025 Cost of a Data Breach Report found that organisations with high shadow AI exposure faced an additional average breach cost of $670,000, with 65% of incidents involving personally identifiable information. The Samsung case is instructive here, not because Samsung was careless, but because the incident illustrates how quickly well-intentioned employees can expose sensitive data when the approved route doesn&#8217;t exist and the unsanctioned one does. Three separate teams submitted proprietary source code and internal meeting recordings to ChatGPT within weeks of the company lifting a prior ban. The response, reimposing the ban, missed the point entirely. Security experts noted that banning specific tools one by one becomes whack-a-mole as new ones proliferate. The only sustainable answer is a sanctioned route that&#8217;s faster and safer than the shadow one.</p><div><hr></div><p>Which brings us to the other failure mode: governance so slow it defeats itself.</p><p>IDC research, undertaken with Lenovo, found that 88% of AI proofs of concept never reach production, for every 33 pilots launched, only four go live. IDC&#8217;s own researchers acknowledged that many of these pilots are &#8220;highly underfunded&#8221; and lack a strong business case from the start, which means the problem isn&#8217;t just governance, it&#8217;s launching without clear purpose. But slow, undefined governance compounds it. Getting stuck in pilot purgatory is what happens when nobody defined what success looked like before the pilot started. The review runs indefinitely because there&#8217;s no decision to make, only a process to continue.</p><p>Gartner predicts 30% of GenAI projects will be abandoned after proof of concept, citing poor data quality, inadequate risk controls, and escalating costs. The pattern is consistent: organisations launch with enthusiasm and stall at the point where unglamorous structural work is required. That stalling recreates exactly the problem shadow IT diagnosed. If the sanctioned route takes eighteen months and produces no answer, people find another route. They always have.</p><p>The fix isn&#8217;t faster approval. It&#8217;s defined exit criteria before the pilot begins. Not &#8220;we&#8217;ll review in three months&#8221; but &#8220;here is what this project needs to demonstrate, here are the data questions it needs to answer, and here is the date by which we will decide.&#8221; That&#8217;s a decision process. What most organisations run instead is a review process, and review processes don&#8217;t end, they just lose momentum until something else takes priority.</p><p>Those exit criteria need the right people in the room: IT, the business owner, and whoever owns the data risk. Depending on the data context, legal or compliance too. That conversation, held before anything is built, is the governance model. Not a committee and not a checklist, but a conversation with accountability attached.</p><div><hr></div><p>The IT teams that will navigate this well are not the ones that said yes to everything, or the ones that built walls around their function and called it risk management. They&#8217;re the ones that got curious about why their users kept going around them, and built something worth coming back to.</p><p>A KPMG survey found 73% of organisations adopting low-code platforms had not yet defined governance rules. That gap is where shadow AI lives. Close it not with prohibition but with a sanctioned environment that actually works: risk-proportionate governance, fast and transparent pathways from experiment to production, and a clear signal to the organisation that IT is a partner in building things, not a gatekeeper deciding who gets to try.</p><p>Shadow IT was never really about the tools. It was about unmet need meeting inadequate response. Shadow AI is the same conversation, with higher stakes and less time to get it right. The writing has always been on the wall. The question is whether we&#8217;re finally ready to read it.</p><div><hr></div><p><em>This post is part of an ongoing series on AI, technology, and the gap between what we are promised and what we are building.</em></p><div><hr></div><p>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to jonathanfreedman.me</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-workaround-was-the-warning-ai/comments"><span>Leave a comment</span></a></p><div><hr></div><h2>References</h2><p>Gartner (2022), Shadow IT and Employee Technology Use gartner.com</p><p>Microsoft / LinkedIn Work Trend Index (2024), AI at Work microsoft.com</p><p>Forrester Consulting (2024), Total Economic Impact of Microsoft Power Apps forrester.com</p><p>IDC / Lenovo (2024), AI Proof of Concept to Production Research idc.com</p><p>IBM (2025), Cost of a Data Breach Report ibm.com/security/data-breach</p><p>Gartner (2025), GenAI Project Abandonment Predictions gartner.com</p><p><em>KPMG (2023) Shaping Digital Transformation with Low-Code Platforms</em> <em>assets.kpmg.com/content/dam/kpmg/ie/pdf/2023/07/ie-shaping-digital-transformation-with-low-code-platforms.pdf</em></p><p>Dark Reading / Gizmodo / TechCrunch (2023), Samsung ChatGPT Data Leak darkreading.com</p><div><hr></div><p><em>Editor&#8217;s note: An earlier version of this article cited a figure of 98% of organisations having employees using unsanctioned AI tools. On review, although this figure appears quite a bit on Google, it does not appear to have a clearly attributable primary source. I have replaced this figure with the Microsoft 2024 Data Security Index figure of 65% which is better evidenced. Still a lot, but not quite as much as I said at first.</em></p>]]></content:encoded></item></channel></rss>