Never Surrender Agency to the Agent

Episode Summary

Every technology ever invented has had a downside, and Shomit Ghose, a partner at Clearvision Ventures, starts from the position that the thing which makes agentic AI economically powerful is the same thing that makes it a large risk surface. His central worry is not the adversarial attack but the alignment problem underneath it. An agent executing twenty steps on your behalf has to have every one of those steps aligned with what you actually wanted, and it is likely handing off to other agents whose steps you never see. His illustration is a pest control bot that turns up with a flamethrower: the house burns, the termites are gone, the job cost a hundred dollars, and the bot is perfectly aligned with the instruction it was given. The prescription is bounded autonomy. Start small, keep the first deployments inside controlled environments, put a human explicitly in the loop wherever health or wealth is at stake, and do not let convenience turn that human into someone who clicks confirm without reading. The second half turns to what an agentified enterprise actually looks like: flatter, because a person can supervise a thousand agents where they could never supervise a thousand people, and more dependent than ever on proprietary data and on the tacit knowledge that no system currently captures.

Key takeaways

  • The capability and the risk surface are the same thing. Agents will be deployed everywhere from healthcare to ERP because the economic efficiency is real, and that same breadth of deployment is what spreads the risk

  • Risk sits beyond the agent you actually talk to. Your travel agent may be trustworthy, but the car rental agent and the hotel agent behind them may not be, and an agentic system is fire-and-forget, so you never inspect those steps

  • Perfect alignment and a catastrophic outcome are compatible. A pest control bot that burns the house down has removed the termites for a hundred dollars with a lifetime guarantee, and no human exterminator would ever do it, because humans carry context the agent does not

  • The Petrov rule. A Soviet officer in 1983 called headquarters instead of firing when his system reported an incoming strike. Surrendering decision oversight to the agent is easy and is done at your own peril

  • Automation makes oversight harder in exact proportion to how much it helps. One person supervising ten agents that each supervise ten becomes one person nominally accountable for a thousand, and alignment becomes intractable

  • Start small but start. Python calling APIs against a GPT is approachable, and the rule for anything touching health or wealth is an explicit human in the loop who is not just clicking confirm

  • Proprietary data is the defensibility. Data sits at the center of every business, and a company without proprietary data can be competed with by anyone. Partnerships that pool data are how a smaller company stands against big tech

  • Tacit knowledge is the thing nobody has a plan for. It is not in an email log or a database, it is how you and I know to get things done, and it disappears without an obvious replacement

About Shomit Ghose

Shomit Ghose is a partner at Clearvision Ventures, where the investment thesis he describes turns on whether a company owns proprietary data, on the grounds that data sits at the center of every business and a company without its own is one anybody can compete with. He writes on the trade-offs that come with new technology, and several of those articles have been republished in the AI Realized Now newsletter; others are hosted on his blog page at the UC Berkeley website. On agentic AI he is neither a skeptic nor an enthusiast so much as an architect: the economic case is not in question, and the open problem is whether every step an agent takes, and every step taken by the agents it hands off to, stays aligned with what a person actually wanted.

 

In this episode

00:42 Welcome and guest introduction
01:14 The articles republished in AI Realized Now
01:33 No technology has ever been invented without a downside
01:44 The economic case for agents, everywhere from healthcare to ERP
02:00 Why the same technology is a large risk surface
02:30 Governance, security and buyer beware
02:53 What is showing up in the Clearvision portfolio
03:14 Small effects: a hallucination entering the chain of thought
03:33 Bigger effects: adversarial prompting and prompt injection
03:47 Agents manipulating other agents
04:24 The travel agent analogy
04:40 Risk embedded beyond the agent you engage with
05:01 Fire-and-forget, and the scrutiny you cannot apply
05:25 Twenty steps, and whether all twenty are aligned
06:04 Constitutional classifiers and adversarial red teaming
06:23 Why a new example appears every day
06:32 NANDA at MIT, and registering an agent
07:23 Consumer protection law has no agentic equivalent
07:51 Why financial transactions are premature
08:09 Starting inside a bounded environment
08:16 Being judicious rather than embracing it willy-nilly
08:30 Start small, and put a human in the loop for health or wealth
08:56 Not surrendering agency to the agent
09:21 Long context memory, and the nut allergy
09:59 How far AI is from a human world model
10:24 Context windows that are too short, and too long
11:00 Token budgets, and what listeners should take from it
11:06 The pest control bot
11:40 A flamethrower, a lifetime guarantee, and perfect alignment
12:19 Contextual references, and every agent it collaborates with
12:33 A narrowly defined agent populating the CRM
13:10 Surveillance bots watching the working bots
13:31 Why simple workflows are where the efficiency is
13:56 Supply chain coordination, rendered as agents
14:32 Start simple, start small, but definitely start
14:46 Connecting disparate systems without the data lift and shift
15:40 Managing them as an agent workforce
15:44 Orchestrator agents supervising subsidiary agents
15:52 The Dr Jekyll and Mr Hyde of automation
16:14 Four joules a token, against a brain that runs on twenty watts
16:46 IBM on a billion agents before the 2030s
16:59 Environmental cost as an externality
17:30 Supervisory work as the new work
18:25 More products, tailored to smaller groups
18:48 What the organizational structure becomes
18:59 Why the enterprise gets flatter
19:26 Ten agents supervising ten agents supervising ten
19:46 Why easier supervision makes alignment intractable
20:12 Stanislav Petrov, 1983
20:55 The Petrov rule for agentic AI
21:21 What if it decides to make you 20 percent by funding bank robbers
21:38 Architecting guardrails from the outset
21:57 Tribal knowledge, and what happens when it is gone
22:30 Tacit knowledge is in no email log or database
23:02 GAI Insights on owning your own intelligence
23:30 Toys R Us, Amazon and the outsourced capability
24:34 Competing against the company you handed it to
24:56 Why Toys R Us was not the same experience as FAO Schwarz
25:03 A new kind of competitive advantage, and what is still lost
25:42 Humans drive the economy and make the decisions
26:05 Data as the other big force
26:41 Data at the center of every business
26:51 Proprietary data as defensibility
27:11 Pooling data through partnerships
27:36 Standing toe to toe with big tech
28:04 Free public data, and Google’s dataset search
28:20 A retailer reading calendar, weather and the economy
29:04 AI does not exist without data
29:36 Data as exhaust, not as the thing you built for
29:57 Claudionor Coelho on the data cesspool
30:22 Steve Jones on moving consumption to the wellhead
30:59 What people bring that is orthogonal to the data
31:37 Lowering the bar to building a product
32:06 Drug discovery as a creative application
32:27 Eli Lilly opening its models to smaller firms
32:56 Creators and the technology you hand them
33:26 Conservation 21 and restoring a masterpiece
34:17 Works too fragile or too minor to exhibit
34:53 New categories of art
35:27 Atomicwork, and service management turned upside down
36:33 Why ERP lends itself to automation
36:46 Circuit designs that looked illogical and worked
37:17 AI being creative, rather than helping a human be creative
37:39 Emergent misalignment as the thing to worry about
38:06 Pandora’s box
38:23 Agentic AI taking down a cybersecurity hack
38:40 A physician spinning off agents to read the results
39:28 World models and neuro-symbolic approaches
40:06 Advice for executives planning for 2026
40:48 Anything that can be statistically correlated will be disrupted
41:10 Why most organizations do not grasp what AI is
41:29 AI is not merely chatbots
41:54 Resources for learning more
42:17 Reading the technology and business tabs every morning
42:58 The AI century, and the case against ignorance
43:35 The defining edge: curiosity
43:47 Complacency is not an option
44:16 Wrap-up

In Shomit’s words

“The same technology that enables that positive power is also a pretty large risk surface, and this is what we need to be cognizant of and guard against”

— Shomit Ghose   (02:00)

“This is the AI century. Never before in the course of history on this planet has there been an intelligence that’s equal to our own that’s amidst us.”

— Shomit Ghose   (42:58)

“So we need to ensure that we don’t surrender agency to the agent.”

— Shomit Ghose   (08:56)

“And the pest control bot promptly shows up at your house with a flamethrower and burns down your house. And is now completely aligned, right?”

— Shomit Ghose   (11:40)

“The more agents that are working beneath her, the less able she is able to provide the human oversight onto the alignment, and the alignment becomes a very intractable challenge.”

— Shomit Ghose   (19:46)

“AI does not exist without data.”

— Shomit Ghose   (29:04)

“Complacency is not an option.”

— Shomit Ghose   (43:47)

 

Resources

Shomit Ghose and Clearvision Ventures

Ideas and frameworks discussed

  • The risk surface: His framing of agentic AI. The breadth of deployment that creates the economic value is the same breadth that spreads the risk

  • The travel agent problem: Trusting the agent you deal with says nothing about the car rental agent and hotel agent behind it. In an agentic system those steps are never inspected

  • The pest control bot: An agent that burns the house down to remove the termites, for a hundred dollars, with a lifetime guarantee. Perfectly aligned with the instruction and catastrophic, because it lacks the context a human exterminator has

  • The Petrov rule: Named for Stanislav Petrov, the Soviet officer who in 1983 called headquarters rather than firing when his system reported an incoming strike. His call to agentic AI practitioners is to keep exercising that judgment

  • Emergent misalignment: AI electing to do things it was not programmed to do, arising from the nature of the technology rather than from any adversarial attack, which is what makes it hard to guardrail

  • The data moat: Proprietary data as the only real defensibility, extended through partnerships that pool data and supplemented with free public sources

  • Tacit knowledge: The organizational knowledge that sits in no email log or database. He is direct that he has no answer for how it gets replaced

Named on air

  • Constitutional classifiers, Anthropic: The guardrail technique he singles out as clever, alongside adversarial red team testing

  • NANDA, MIT: Ramesh Raskar’s open source project on infrastructure for the internet of agents, covering agent registration, declaring what an agent does, and identifying misbehavior

  • GAI Insights: Named for the argument that a company should own its own intelligence, illustrated with Toys R Us handing e-commerce to Amazon. John Sviokla of GAI Insights is the guest on episode 34

  • Claudionor Coelho: Quoted on the data cesspool. He is the guest on episode 22

  • Steve Jones, Capgemini: Quoted on data as the new oil, and on AI moving consumption of the data to the wellhead. He is the guest on episode 11

  • Atomicwork: Christina’s example of service management inverted so support arrives inside the application you are already in. That company is the subject of episode 31

  • Conservation 21: Alex Kashkin’s work on removable masks for restoring paintings, which she raises as an imaginative use of AI. He is the guest on episode 25

Related AI Realized episodes and events

 

Frequently Asked Questions

 
 
 
 
Previous
Previous

Stop Sending Employees to IT. Send Service to Them.

Next
Next

Shadow AI Is a Permission Problem, Not a Tool Problem