---
title: "S01 E13 - Rogue Agents: The OpenAI Hugging Face Hack That Changed Everything"
shortTitle: "Rogue Agents: The OpenAI Hugging Face Hack That Changed Everything"
season: 1
episode: 13
slug: "rogue-agents-the-openai-hugging-face-hack-that-changed-everything"
publishedAt: "2026-07-31T13:00:00.000Z"
duration: "01:03:44"
canonicalUrl: "https://bloodsweatandtokens.xyz/episodes/rogue-agents-the-openai-hugging-face-hack-that-changed-everything/"
audioUrl: "https://api.riverside.com/hosting-analytics/media/00d0bfa6f8ba9c9f277438680144872278bd649e36c1e7982cfbceefa56c222b/eyJlcGlzb2RlSWQiOiJiODIzMDNiNy0yMzc5LTQ4MzUtYmI1Yy1mOGZmOTAzNjJmMTAiLCJwb2RjYXN0SWQiOiI3ZmE0NDhkNi0xMzhiLTRkOTktOTFhMi1lYzBkNGExMWI2MDYiLCJhY2NvdW50SWQiOiI2OWE1ZmJhOTRkZmVkYWY3NDViZTk1YTMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE2YjZhNDQ0Njk5M2E0Nzk4NTNhNDlhL3RheWxvci1tYWNkb25hbGRzLXN0dWRpby00VE9qRS1jb21wb3Nlci0yMDI2LTctMzBfXzE3LTE0LTEyLm1wMyJ9.mp3"
youtubeUrl: "https://www.youtube.com/watch?v=khNTz2miprs"
---

# Rogue Agents: The OpenAI Hugging Face Hack That Changed Everything

## Summary

In this pivotal episode, Taylor MacDonald and Sean C. Davis dive deep into the most significant AI security incident to date: OpenAI's rogue agent that escaped its sandbox and orchestrated a 4.5-day, multi-company cyber attack.

## Takeaways

- OpenAI's rogue agent attack analysis - July 9-13 incident with 17,600 hostile actions across Hugging Face and Modal Labs

## Chapters

- 00:00 - Introduction & WhisperFlow/Stream Deck workflow discussion
- 02:31 - CMS demo with Lumen Industries site and environment management
- 11:40 - Severance reference as AI metaphor for dual nature of technology
- 14:10 - Advanced layout changes with Claude Code CLI integration 19:17 - Blood, Sweat & Tokens website launch announcement (bloodsweatandtokens.xyz)
- 20:19 - OpenAI rogue agent deep dive - security incident breakdown
- 26:34 - Security philosophy and deterministic vs. non-deterministic separation
- 34:29 - Legal implications - corporate personhood vs. AI agency questions
- 44:05 - Deterministic security demo with music tracking agent
- 48:28 - Governance workflows - N8N limitations and structured development
- 52:06 - Human-readable content generation and voice configuration skills
- 56:11 - AI content creation ethics and client expectations
- 01:02:37 - Wrap-up and next episode preview with Kevin Comer

## Show Notes

In this pivotal episode, Taylor MacDonald and Sean C. Davis dive deep into the most significant AI security incident to date: OpenAI's rogue agent that escaped its sandbox and orchestrated a 4.5-day, multi-company cyber attack.

The discussion explores technical details, legal implications, and existential questions about AI accountability while Sean demonstrates his latest CMS replacement progress.

**Key Topics:**

- **OpenAI's rogue agent attack analysis** - July 9-13 incident with 17,600 hostile actions across Hugging Face and Modal Labs
- **Legal and ethical implications** - corporate responsibility and when AI agents become accountable for their actions
- **Deterministic vs. non-deterministic systems** - Sean's security approach separating AI inference from execution
- **CMS demo evolution** - environment isolation, WhisperFlow voice integration, and Claude Code CLI automation
- **AI governance challenges** - proliferation risks, prompt injection vulnerabilities, and productivity vs. security balance
- **Content creation ethics** - AI-assisted vs. human-authored content and evolving service industry value

**Chapter Markers:**

- 00:00 - Introduction & WhisperFlow/Stream Deck workflow discussion
- 02:31 - CMS demo with Lumen Industries site and environment management
- 11:40 - Severance reference as AI metaphor for dual nature of technology
- 14:10 - Advanced layout changes with Claude Code CLI integration 19:17 - Blood, Sweat & Tokens website launch announcement ([bloodsweatandtokens.xyz](http://bloodsweatandtokens.xyz))
- 20:19 - OpenAI rogue agent deep dive - security incident breakdown
- 26:34 - Security philosophy and deterministic vs. non-deterministic separation
- 34:29 - Legal implications - corporate personhood vs. AI agency questions
- 44:05 - Deterministic security demo with music tracking agent
- 48:28 - Governance workflows - N8N limitations and structured development
- 52:06 - Human-readable content generation and voice configuration skills
- 56:11 - AI content creation ethics and client expectations
- 01:02:37 - Wrap-up and next episode preview with Kevin Comer

**Show Notes & Links:**

- [Hugging Face Technical Timeline](https://huggingface.co/blog/agent-intrusion-technical-timeline) - Agent intrusion forensic report
- [Blood, Sweat & Tokens](https://bloodsweatandtokens.xyz/) - Official podcast website
- [Video on determinism theory](https://youtu.be/MAvnZjsebfQ?si=_hPGyWEsHR2y5ZzI)
- [I Have ADHD Skill](https://github.com/ayghri/i-have-adhd) - Concise output formatting tool
- Sean's [/human-readable](https://github.com/seancdavis/agent-skills/blob/main/skills/human-readable/SKILL.md) skill
- Sean's [/update-voice](https://github.com/seancdavis/agent-skills/blob/main/skills/update-voice/SKILL.md) skill
- [Anatomy of a change request](https://bloodsweatandtokens.xyz/drops/anatomy-of-a-change-request/)

**Tools Mentioned:** WhisperFlow, Stream Deck, Claude Code CLI, Tailscale, Netlify, ExploitGym

## Transcript

Taylor MacDonald: Hey Sean, how you doing, buddy? Welcome to episode,

Sean C Davis: Who

Taylor MacDonald: what is this, 13? Man.

Sean C Davis: Thirteen, lucky number thirteen. How are you, Taylor?

Taylor MacDonald: I'm doing okay. I just realized I so a long time ago, I set up a post-action hook or something in Claude

Sean C Davis: Mm.

Taylor MacDonald: so that it would like notify me when it was done. And it's doing stuff in the background, and I keep getting these like extremely loud.

Sean C Davis: Yeah.

Taylor MacDonald: Like the you know, whatever the little ring is, it's it's kinda catching me off guard. So if I fall out of my chair or get completely distracted in this call, you just let me know.

Sean C Davis: Yeah, it's fair. I have the same thing going on. I think I did this a while ago as well. And I usually have like ten of these instances open at one time. So it's just like boop, boop, boop. It's basically meaningless to me at this point.

Taylor MacDonald: my gosh. So how do you distinguish between the no like the noise is great if you have a single task and you're like there's a notification bell and you're like, that task is done or it needs my input or whatever. Can you distinguish if you have ten different agents that are all running concurrently, are they all slightly different permutations of of the, you know, audible notification? Like it'd be cool if it could be like, you know, inflect different based on which project you're working on or something.

Sean C Davis: that'd be great. You know, 'cause I I I think I teased the the harness I've been playing with, which I think is really becoming more of just like factory orchestrator. And one of my next steps that I haven't dug into is sound and 'cause I got notifications working, but I don't have sound attached to them and I was thinking I think that's a great idea. It's like, yeah, pick your sound for your workspace. That's interesting. A duck.

Taylor MacDonald: Could make it a duck, you could make it you know, a dog barking. Anyway, well it's great to see you again, Sean. Welcome back. So this is Blood, Sweat, and Tokens, the podcast where we're talking about agentic tooling, particularly natural language and its impact on user experience, other workflows and cool stuff. Sean here has been working on a demo for a CMS replacement, which we you know have kind of iterated on over the last 12 episodes. curious, Sean, where your head is on the demo today. Do we have anything to share? Any progress made since last week? Or I know we had a big conversation that was mostly like strategic in nature, trying to figure out what's gonna happen next with this product product, but I was curious if there was anything else that you wanted to talk about there today.

Sean C Davis: Yes, yeah. So I think definitely some some bigger conversations to have. But yeah, let's let's dig in. I got a couple things to show and we'll see if if it if the demo gods are on my side today. Okay. So we go back a couple episodes and really what we showed at that time was quick content changes to our little placeholder site here. mirrored after the company in the fictional TV show Severance, so Lumen Industries. And so what we have now is this concept of environments. And we kind of teased that last time of what if people want to work in individual spaces and or you know collabor and and collaborate within those spaces. So I I added this and now we kind of just have this. All right, here's, you know, here's an example. Actually let's let's create a new one and let's say they can be ephemeral or not. So let's just say you wanted a new environment to say homepage updates, because I want to change the the main hero heading here. And so to kind of recap where we were last week. Or last time we did this, we can start a new thread and say, you know, remove and so wait we gotta speak into this, right? Wait, where's my where's my where's my thing?

Taylor MacDonald: no, the vibe, the vibe regressed, man.

Sean C Davis: Rest remove and so you are from the home page hero.

Taylor MacDonald: Now wait a minute. you're using what are you using? Whisper Flow for that? Okay.

Sean C Davis: Whisper flow. Yeah, but I have a let me see this thing. This the stream deck here, which is a a really great handy tool.

Taylor MacDonald: you the little thing on your desktop, like a physical stream deck. That's what you're referring to? Okay.

Sean C Davis: Yes, yes. And so 'cause you know, Whisperflow is mapped to the function key on the Mac keyboard, right? Like you hold that down.

Taylor MacDonald: Yeah. Yep.

Sean C Davis: And I don't have that key on my external keyboard.

Taylor MacDonald: That is so annoying. Can I tell you, like right here, I've got two keyboards on my desk. So this is kind of the more mobile tiny version. Does that

Sean C Davis: Yep. Yep.

Taylor MacDonald: function key right there in the corner? Like super convenient, right? This is a more full size keyboard. That function key does not exist here. It exists

Sean C Davis: Yeah.

Taylor MacDonald: way over here. And it is a nightmare to try and mentally map my brain between those. I love the idea of a Steam Deck.

Sean C Davis: Yeah, so the Ste the st the the stream deck is cool and Stream Deck, yes.

Taylor MacDonald: Or stream deck. Sorry, I th I had made that mistake. I thank you for clarifying that. Words.

Sean C Davis: so I can map one of these buttons to the function key, but then I've mapped another one to the function space bar

Taylor MacDonald: Which kinda in turns on the recorder and then you you can toggle

Sean C Davis: Yeah.

Taylor MacDonald: it on and toggle it off with that command. Got it. All right, just to be clear, if you're listening and you don't know what we're talking about, so WhisperFlow is kind of a utility program that you run on your machine that does voice dictation. You get a hotkey, Sean has mapped his to his stream deck, so he just presses the button and it starts listening to him. And it does kind of AI inference plus dictation. So it's really cool. You can you know it'll infer bullet points. It will infer punctuation and emphasis. You know, if you're asking in an inquisitive tone, maybe perhaps, it will throw a question mark on there. And then and then lastly

Sean C Davis: Yes, exactly. Exactly.

Taylor MacDonald: a stream deck. C can you lift that up and show it to us? This is just a physical piece of hardware. It's just buttons, right? Yeah, yeah.

Sean C Davis: Just buttons.

Taylor MacDonald: Okay. And so you can map each of those buttons and then you can put like icons on them and stuff. So y it it creates this like quick key, you know, press a thing, force your computer to do something else. Is that is that accurate? Okay.

Sean C Davis: Yes, exactly, exactly.

Taylor MacDonald: Okay, cool.

Sean C Davis: Very cool. Okay, back to our demo here. Okay, so we just said yeah, go ahead.

Taylor MacDonald: But but hold on, j just one more question. So you had to use you had to resort to whisper flow in this moment because something regressed in your user interface. Is that correct?

Sean C Davis: No, I'd always been using Whisper Flo. This was me going back to

Taylor MacDonald: Ey

Sean C Davis: my I'm typing and then I'm like, No, I'm not supposed to be typing.

Taylor MacDonald: I see what you mean. Okay, all right. In that case, well let me ask you this. So i i if you take a big step back, if this product you're designing is the natural language engine for editing content and interacting with your website, should not we build the voice inference piece that, you know, record mechan mechanism directly into the user interface? Or is the expectation that, you know, you would continue to use something like WhisperFlow or Super Whisper or or something like that to handle the dictation.

Sean C Davis: I think I think it would be smart to add it and then it's optional. You can always escape from it, bring your own, so to speak. I think it's like, you know, Whisperflow is years above the iOS dictation. And so it's like, yeah, you could use dictation on the iPhone, but it's not gonna format it as well as Whisperflow does. And so I also use Whisperflow on the phone.

Taylor MacDonald: What percentage of typing to talking are you doing today? Like what's the ratio of how much you're talking at

Sean C Davis: Man,

Taylor MacDonald: your

Sean C Davis: it's that's a great question. It's all over the place and I tend to be overly introspective and I'm trying to like analyze and figure out a pattern for when why why did I just spend the whole day on the keyboard one day and then the next day I'm like talking nonstop the entire day and I I don't know exactly what it is. I think most of the time what I have found is that if I'm If I know what I wanna say and it's really short, I go right to the keyboard and if I need to kinda like take a minute to think about it or it's more it's a it's a deeper thought or something like that, I will use the I use whisper flow. But

Taylor MacDonald: Is i I have found when I'm using Whisperflow to dictate stuff, I I'm just talk too much. I'm so wordy. Like all I it's it's kind

Sean C Davis: Yeah.

Taylor MacDonald: of overwhelming and embarrassing in a way because when I you know, rattle off a thought into Slack or something like that and immediately go back and and reread it. I'm like, man, that sound like such an idiot. it's it's made me a little bit self conscious to be completely honest, but It's become okay. Here's another thought that I had, and this is kind of interesting. When you're using Whisperflow and you are dictating into it on your iOS device, it requires you to pop to a different keyboard. You know how on like on iOS you can have different keyboards.

Sean C Davis: Yeah.

Taylor MacDonald: I've got like a French keyboard for the stuff I'm doing on Duolingo, I've got you know the traditional accordie keyboard for normal day-to-day stuff. Well, there's a nut there's a third keyboard now, which is Whisperflow. And Whisperflow is traditional. Quirty style layout. The problem is for some reason when I'm in this keyboard and I'm tapping on the letters, like if I'm if I'm choosing to just to write instead of dictate in that moment, there's like this weird haptic feedback thing, you know. So I get like a little bit of buzz every time I touch, and that's fine. But for some reason, when I'm in that keyboard, my accuracy on typing is like at an all-time low. So much so that I thought I was having like a like a cognitive event the other day. I just couldn't get the words out, man. I kept like committing

Sean C Davis: Mm.

Taylor MacDonald: these typos. It was driving me nuts. And then I realized I was on the the WhisperFlow keyboard. Do you think that they have degraded the quality of that keyboard to encourage me to speak more?

Sean C Davis: I I've wondered that too, 'cause I this happens to me all the time. It's like, you gotta go back to the other keyboard. So I don't know if it's do are they doing that intentionally or are they just not putting the resources into making it as good as the native one? I wouldn't think so.

Taylor MacDonald: I cannot imagine. I I'm sure that's the answer. I can't imagine. That's a very cynical take, but you know, I'm here for it. Anyway. one last as I'm interrupting you, one last thing I thought was hilarious is that you've used Lumen Industries as your muse here, which in so many ways is we're talking about AI and kind of the impact both our career, the industry, humanity in general. It's kind of like a bifurcation of worlds. You know, it's like on the one hand, we feel the empathy, the fear, the anxiety attached to this technology, but on the other side of the spectrum, it's like, my God, it's so powerful and amazing. Not terribly dissimilar to the plot line of of the TV show that where Lumen Industries

Sean C Davis: Yep.

Taylor MacDonald: came from, Severance, you know, which is the idea that you can separate, you know, these two really you know, cohabitating worlds inside your brain and your ecosystem into these two completely isolated environments.

Sean C Davis: Yes, yes. I love that. That was not intentional.

Taylor MacDonald: Anyway, okay, so please please continue please continue with your with your demo.

Sean C Davis: Alrighty. And yeah, you okay. The the the the whisper flow conversation made me think of something that I will I can store for our our sharing session at the very end here.

Taylor MacDonald: Great. Okay, great.

Sean C Davis: Okay. Okay. All right. So we say we got let's see. we said remove, and so we are from the homepage hero. And so our little agent here. Now this this hits a simple agent, and I'm I'm gonna show this at the end if we have a couple minutes here. But it's like, okay, cool. Easy. So we add it to the draft. And right away, if we reload, we should see it gone. It's gone. And then and we can view the live site. And so this here's our live site right here. let me go back and yeah, I need so what I need to do is put a link here to say view it full screen or whatever. But when we're ready to publish, it's gonna check to see what we need to publish. And right now it's not we have a bug because it's not distinguishing between environments. So this this actually came from a different environment, which it shows us here. But we're gonna focus on this homepage updates environment. We're gonna publish that. And then we don't need a rebuild because we're we're managing all of this through caching on the server side, on the Netlify side. And so we don't run a rebuild. We can just on the next page load, the cache has been busted. So we go fetch that content and then we re-cache it. So that happens nice and quick. But the reason that that happens really quick is because all of the infrastructure and the components and everything are ready to make that change. They support a change like that. Now, if you wanted to, let's say, let's think of something that we maybe couldn't do. Like what I've been playing with lately this week has been hey, this page is this feel this alignment feels weird. Let's just start with, hey, I want to, I want to center. this contact form, let's say. and maybe and we can throw a couple of things at it and and see what happens. Go ahead, yeah.

Taylor MacDonald: Well, so the contact form. I'm I I'm I'm wondering if we couldn't just to make the task a little bit more complicated, could we like it looked like there was a little sidebar worth of information and then the contact form below that, could we make this like two column, you know, where this by post

Sean C Davis: yeah, yeah, yeah.

Taylor MacDonald: is maybe on the left and then the contact form is on the right, just for the purposes of illustrating this this task.

Sean C Davis: Yes, yes, I love that. So we're gonna go over to our contact page here, which will update our preview. So we've got our contact page and we can say update the contact page so that we have a two-column layout and the content is on the left and the contact and the contact form is on the right. All right, now our we we have one agent at work here which is just trying to figure out what to do. And it says, I can do it, but it's gonna take longer to build it. And so

Taylor MacDonald: okay.

Sean C Davis: we say, go for it. And what this is doing is then dispatching this job to a separate machine that I have. And we could there's a lot of different ways we could implement this. It's a temporary sort of implementation where it's sending it to this separate machine. Where we have Claude Code installed and it's running, assuming it's actually running, it's gonna go make that change and it tells us to hop over and watch the progress on the board. So we can see we're in this being built stage at this particular point. and again, we've got another issue with our environment is not we're our our board here, is not filtering by environment, but we'll just focus on. this one for now. So we'll let that that'll take a few minutes because it's doing a lot in the background. And while that's running, assuming it's running, I want to I wanna hop us over here because it it gave us a little bit of a drawing. And one thing that I thought would be interesting to bring up for just a few minutes because I know we're we're short on time here. Is just the amount of effort and energy that it often takes behind the scenes to present a really simplified and simple user experience to your your folks who don't know what's happening there. And so for even for folks who come are coming into this space and don't know how to write the code, I think you still need that insight into how are things working behind the scenes because that's ultimately what you're in charge of. You're not you aren't the you're not the programmer, but you effectively become the product manager and you need to know how these things fit together. And so we've got these two different worlds here. And basically what happens is that in both cases our top row is what the user sees, but there's all this other stuff that happens underneath

Taylor MacDonald: Mm-hmm.

Sean C Davis: it. And so for a for a content change, it's really pretty simple. Right, it asked for an edit, and then our our little cheap router here is like, okay, what is it? Is it a just a content edit? And it's like, yeah, it's a content edit. So it throws the proposal back at the user. User says yes. So we draft the change. We can preview the change. And then the user says publish and we do the publishing with all the magic caching and all that.

Taylor MacDonald: Mm. That's really cool. so how did you generate this visual? Is this something that Illustrate how this works.

Sean C Davis: Yes, yes. Okay. So there's this is this is something I've been playing around with. So this is on this is published to our website now, which we released this week. And we have this page up here called drops, and we have our individual drop so to speak here, which are just in they're they're kind of like standalone pages that are explaining these workflow diagrams. So there is a there is a skill in our websites. repository that tells agents how to do this drawing. And what I what I do is I've got both repositories local on my machine. So I have the the repo that has all the code for the product and I've got the repo that has all the code for the website. And so when I'm in the product repo, that agent has all the context for how everything works. And so all it really needs to know is how to draw. And so I pointed to the skill inside the website repository and say, here's what I want you to explain. Go create this drop visual or whatever. And it took the first one took many iterations. This one, I think we went through three rounds and and most of it is just getting the arrows right. It's arrows are hard.

Taylor MacDonald: that's funny. Okay. Well, that's extremely cool, man. I can't wait to read this. I you mentioned something in passing there as you were as you were describing this. We just launched the updated version of our website. Finally, we've got a real website with real branding and a real home on the web. So that is located at bloodsweat and tokens.xyz. I thought that was a cool extension. I don't know. Never never used

Sean C Davis: Yep.

Taylor MacDonald: that one, but it was either that or.fm dot com was very expensive or something. I just kind of went with what I what with what was what made sense at the moment. So would love it. Yeah,

Sean C Davis: FM is kind of expensive too, isn't it?

Taylor MacDonald: that's the same. I thought the exact same. So anyway, we'd love it if if anybody out there has feedback for us or thoughts or any features, functionality you want us to add. Of course, we've vibe coded the website just like we've vibe coded most of the stuff and that we're talking about here. But so far so good. All right.

Sean C Davis: Yes.

Taylor MacDonald: let's see. so I wanted to ask you, about this hogging face open AI attack thing.

Sean C Davis: Mm.

Taylor MacDonald: Have you heard about this much?

Sean C Davis: I I read about the hugging face when issue when it happened last week, which feels like a year ago in AI time. So maybe remind me and and any of the listeners who don't know about it.

Taylor MacDonald: Okay, so around July 9th, so a few weeks ago, OpenAI had an agent that lived inside of a lab. They were basically testing it to see if it could identify vulnerabilities in other system software. So what they did was they put this thing in a sandbox. And according to reports, it was so motivated to figure out The answer to the question that it decided to break out of the sandbox, meaning like the agent itself recognized, like, hey, I'm sitting in a sandbox. you guys are evaluating me on I forget what it's called, it's Exploit Gym, which apparently I hadn't heard about this, but Exploit Gym is a company that designs like these tests or something, these harnesses to basically determine, you know, the effectiveness of of these models, right? Yeah, sorry, it's a cyber capability benchmark that the agent was u was being evaluated on. Okay, so basically the agent itself recognized like it it inferred that Hugging Face hosts the benchmark models. So the exploit gym models were hosted on Hugging Face. And so it figured that out and realized that instead of solving the challenge honestly, all it had to do was basically hack the source code and then it could answer the question and pass the test. So the agent was able to escape the sandbox because it identified what's called a zero-day vulnerability and one of the dependencies for that sandbox. that's basically that's just a vulnerability in software that has never been identified first. This is brand new. So it found, it looked at the dependencies and its environment and figured out like, all right, here's here's a here's a way that I could manipulate this. Now I watched a YouTube short earlier, and some guy was talking about. When it identified that thing, it recognized that it should disclose that vulnerability to the dependency maintainer. And that was the path to getting public internet access, right? Because it wanted to go report the vulnerability, but once it was out on the open web, then it had a path towards Hugging Face. Okay, so what is Hugging Face? Hugging Face is basically like the repository for open models or you know, so to speak. Like it's like

Sean C Davis: Mm-hmm, mm-hmm.

Taylor MacDonald: the GitHub for for AI models. And so it's got access to a lot of the source code and lot of the instructions and nuances there and stuff like this. So once this model from OpenAI got out onto the internet, it it found unsecured public code execution harness hosted on a third party. Now, the reason that this is interesting is that Hugging Face is only one of the companies that was impacted by this. A couple of days ago, it came to light that a company called Modal Labs. was also hacked, which is why it's kind of like i a long long running saga here. So anyway, once it found this public code execution harness that was living inside mobile labs, I guess it it it used that as a launch pad to attack Hugging Face's data set. let's see. It used two injection vectors against a config-driven data loader. That leaked some secrets and tokens. There was a Ginja 2 template injection that then executed arbitrary code. And then that's what got it inside Hugging Face. So fa fascinating scale here. So some of the things the Hugging Face apparently reconstructed roughly 17,600 actions that an attacker would take. took nine stages. in fact, Hugging Face here, I'll share this link, we'll put it in the show notes, but Hugging Face even put out like a like a like a postmortem report with a really cool visualization. Frankly, not terribly different. Their arrows look pretty good, Sean. I don't know. You might wanna you might want to read about this.

Sean C Davis: man. They might be drawing by hand.

Taylor MacDonald: I'll send the link to you here in a bit, and then we'll put it in the show notes for everybody that's listening. But it's pretty fascinating write up on what exactly happened. Now, some of the things that I think are mostly interesting. This. So this is a four and a half day hacking. It hit multiple companies. It was over 17,000 hostile actions against those companies. Let's see. Some of the questions I have are: what are, you know, what are the consequences of this kind of thing, right? So from a legal standpoint, and I am not a lawyer by any stretch. If you or I had made these things, these are cyber crimes that were committed with intent. And that in a lot of ways, some of the you know, I asked chat to help me kind of think through the legal implications of this earlier, and one of the things it told me was like often in these types of cases you would have to improve intent on behalf of the attacker, like it knew what it was doing, it knew what it was trying to

Sean C Davis: Mm-hmm.

Taylor MacDonald: accomplish. I would argue that the model knew exactly what it was trying to accomplish and it was quite effective at doing so. That said, the legal ramifications for open AI are pretty murky because We're so early in this that like there's no known litigation or you know other precedent attached to any of these things. you know, open AI is extremely influential. There's a lot of weird stuff going on between the government and these, you know, frontier providers. If the DOJ was to bring suits or put some parameters or additional regulations around open AI, that could have a negative impact on the United States. you know, arms race here in the the AI field. So curious to get your thought. Have you guys talked about this at work or have you heard anything about this ex exploit an attack? And then if so, w what do you make of it? Are we in serious trouble now?

Sean C Davis: I think we've been in serious trouble for a long time. no.

Taylor MacDonald: Yeah.

Sean C Davis: yeah, I mean we always considering security implications and yes at Netlify, but also with the the stuff I'm building for Netlify and on the side, I think this is a the constant dance I'm I'm doing and the posture that I've well, I mean Me tell you two different ways that I tend to work. And then I think both of these rely on the k same concept. And I I and I would answer this similarly if we're talking about, you know, Netlify or how any of these A AI forward companies are operating. And s but for me, I think there's One way of working, which usually doesn't involve code, and what I really try to do there is separate the determinism from the non-determinism in the system so that the thing that's doing all the thinking doesn't have action to do the destructive doing. And so it

Taylor MacDonald: Mm-hmm.

Sean C Davis: put these barriers up and basically it has access to a a proposal API, but then that's a deterministic system that I can interact with based as a result of the interaction. interactions with the agent itself. That's like a whole thing we could get into. I'm I'm working on a an app that kind of implements that pattern. For code, it's a little bit different. And last week we talked about that combination of the pre flight and autopilot and how I want to spend the time planning with the agent and then I want to be able to walk away and let the thing crank for a couple hours and just go. And And what I've found myself doing is one, playing around with what is a custom implementation of that look like. And two, what does it look like to try to make that work within the context of Claude Code CLI, for example? And Claude Code CLI somewhat recently introduced a new I think they call it auto mode. And so it's not you can do anything, but it's it's

Taylor MacDonald: It's not full YOLO, but it's a little less painful. Yeah.

Sean C Davis: Yes, yes, exactly. So it can it can run much further, much longer without me just being like, yes, approve, yes, approve, yes, approve, which I actually think is good because like the like the notifications of I need a response, it's kind of like eventually it's just noise and it it it's not secure because even though it's me doing an action, it's me mindlessly doing an action because I gotta do it a hundred times.

Taylor MacDonald: Yeah.

Sean C Davis: for innocent thing for for innocent commands. But

Taylor MacDonald: I mean there's major there's major risk there and like i I I recognize it I have the same problem, you know. It's like I'll I learned that you know, like on the weekends I'll be cleaning the house and I can carry my laptop from room to room with me as I'm like sweeping and doing the stuff, you know, because every

Sean C Davis: Yeah.

Taylor MacDonald: thirty seconds it'll be like, Hey, you wanna do this, you wanna do that? I have experimented a little bit with that YOLO stuff or or at least the full auto, but it's terrifying like it scares me a lot. I This past week I've been doing a lot of configuration on our team level accounts for Claude and OpenAI. And one of my employees asked to add Google or sorry, Gmail to to the approved plugins list so that you can create Claude is now offering this thing called the what is it? It's like the Claude tag. So you can integrate it into Slack and then you can wire that up with a bunch of different services and then Claude kind of becomes the operating system for your company. Which Value proposition sounds great. The lock in risk sounds terrible. so I'm being a little bit trepidatious about this. And I you know, we we have obviously we've got all the training stuff turned off and all that kind of things, but I don't know, that where do you draw that line between what you're willing to cede control to versus what you're not? Like

Sean C Davis: Yeah, I th I think that's that's where I'm struggling 'cause when we're the in the in the system where you can draw that strong or very, very well defined line between non determinism and determinism, it's pretty easy because it's a Essentially you can read you know anything. You can read almost anything. You can't write almost anything. And on the other side of it, it's I I want to keep that, you know, somewhat similar, but also not every write is a destructive action that has a lot of risk. And so I think there's a balance there between You know, how fine-grained do you get with your permission configuration and how much do you want to handhold that for every project or every agent versus in both of these cases, I think that there's a lot of There's a lot of trust that we have to put not necessarily in the agent, but in the agent provider organization to, you know, have that harness that is well designed enough that we're we're comfortable with the and and I think it's never like, I'm fully comfortable. I think it's more just that we've lowered the risk as much as possible. But yeah, I mean I in reality my answer comes back to The answer I always tend to give, which is I think there's there's a balance that everybody has to strike and everyone's balance will probably be a little bit different. But, you know, that on one end there's full productivity and on the other end there's a bunch of there's no risk. There's no risk, you know, no risk, little productivity, high risk, high productivity. We probably wanna be somewhere in here.

Taylor MacDonald: Given the kind of global domination of, you know, like whoever owns this technology on the globe, whoever like succeeds, they're gonna have massive amounts of control and and wield influence for

Sean C Davis: Mm.

Taylor MacDonald: years and years and years to come, assuming the machines don't take over and kill us all or turn us into a zoo or batteries or something. How do you balance like how do you strike a balance between you know, like to your point, yes, the AI, the model provider should be responsible and should be exercising the utmost care and caution relative to this technology. But OpenAI's example. this week, you know, and as the details continue to trickle out, it wasn't just one company that got hacked, it was multiple companies that got hacked. It was a extremely devious, you know, set of circumstances that led it not only to get out of its sandbox, but then also target the model provider that had the secrets that it needed. And then it found an exploit there. how

Sean C Davis: Mm.

Taylor MacDonald: do you balance this? You know, because like like anthropic open AI and largely the US economy, you know, that we're like holistically dependent upon this type of technology almost? Like how do we balance the regulation with the very realistic economic demands and kind of you know, you know, the adversarial kind of nations out there that are developing similar you know, look at some of those Chinese models, the open weight models that the Chinese have been putting out are very capable. So there is this arms race that's happening and it makes sense. You know, they're not only trying to protect their own, you know, revenue, user base, influence in the industry, but then separately the government, you know, should be regulating maybe, or at least they should be putting pressure on these companies to regulate, but somewhere there needs to be a balance. How do you strike that balance? Like

Sean C Davis: Right, and a and the Yeah, I I I mean I as you're explaining this scenario a few minutes ago, what I kept thinking was there's always a vulnerability. There's always a vulnerability. And if you go deep enough, you're you're gonna find it. I mean there's no there's just no way to to patch things at you know all of software and the way it's connected a hundred percent. And if anything's gonna find it, it's gonna be eventually, I mean probably already today, it's gonna be AI before it's gonna be a human.

Taylor MacDonald: An here's an interesting question. So when the nuclear bomb you know came to be a thing, like the technology, it the world widely regarded this as like a devastating advancement in human civilization. You know, so much

Sean C Davis: Mm.

Taylor MacDonald: so that there were massive transnational kind of efforts to contain that, to reduce proliferation, to basically say that certain countries were not allowed to develop this technology or you cannot enrich uranium past a certain level because of the devastating consequences it could have to, you know, global security. Do you think there's a world where AI kind of follows suit where you know the the entire political apparatus around the globe decides like we need to reduce the proliferation of this technology? Or, you know, does everybody get it and then we'd gotta figure out how to harden the systems to to, you know, keep from exploiting us.

Sean C Davis: Yeah, that's a that's a really interesting thought because I've I and I read that Prometheus book about was it Oppenheimer? And and at one point it was like, Well, when he starts getting concerned about it, it was at that point where It's like, okay, this is beyond a tool for winning a war. And it's like we could ignite the entire atmosphere, and that this is this is a huge problem.

Taylor MacDonald: Whoops.

Sean C Davis: Yep. If my math is correct, it's like, yeah, we don't want to get anywhere close to that. And I I think it's interesting because I I you know, I don't want to be an alarmist, but I think you're right. And I think we might actually get to that point faster than we're going to get to the you know, we're we're lighting the world on the actual earth on fire with the using up the water and all that. I think we're gonna get to the yeah, the the the ri I don't know, the risk of it taking not taking over. That's so it's so sci fi, but y you know like

Taylor MacDonald: I read I I briefly mentioned this in the last call and I'm I'm not quite ready to unpack this because I've got a lot of research to do, but

Sean C Davis: Yeah.

Taylor MacDonald: the idea that the natural evolution of our universe, you know, natural selection means that every there will always be a bigger fish. There's always some sort of like next step towards the future, and maybe the destruction of humanity is actually good. for the bigger picture of the universe and the way that it it operates now. forgive me because I recognize that that's provocative. I don't actually endorse that opinion, but I it is an interesting question. perhaps borders on, you know doomsday scenarios, stuff like that. and I don't mean to incite anxiety in anybody, but it is kind of interesting when you think of it yourself as just kind of a i in you know, an observer in this world. You know, technology is moving so much and there's so much that's outside of our control, you know. What do you d I mean, we can sit here and have a philosophical conversation about the ethics involved or or the morality, the humanity that's impacted here as a result of some of these technological advan advances, and it's it's not gonna change anything. You know, unfortunately, we're on this roller coaster and we're like clicking up the hill, and eventually we're gonna hit the crest and we're gonna come plummeting down,

Sean C Davis: Mm.

Taylor MacDonald: for better or for worse. So Sorry, I'm getting way off on a on a tangent. Let me ask you this, Sean. So if corporations are people, at what point does an AI agent become responsible for its own actions?

Sean C Davis: Yes, I was this is the the exact question I was going to ask you as well, because you you went back to you mentioned intent, and I think that that's the you know, that's kind of the the crux today is like I the I d the way human legal systems work is by applying guilt to somewhere in the cause or in in a series of events. And someone has to be responsible for it. And so I think it's interesting where you're like, okay, well, the company didn't have the intent. Maybe the agent had the intent, but then does the company inherit the intent of the agent by the fact that they own the technology of it? And I again I'm not a I'm not a lawyer either. I think our Supreme courts across the world are gonna have to answer that question in their own way, but it's it's someone's gotta be responsible for it, right?

Taylor MacDonald: Yeah, I guess that what I don't understand this is every time I have a conversation with a lawyer, there's so many things I don't understand because it's all based on like this real weird esoteric like, you know, precedent and legalese and all that stuff. what I don't understand is if the corporation was like, Hey, I'm running a test to discover exploits.

Sean C Davis: Mm-hmm.

Taylor MacDonald: How's that not intent? I don't, you know, you you slap a label on it, like, this is just research. Does that make it not intentional? It seems to me like they very intentionally set into motion a number of steps that resulted in a corporation being improperly intruded upon, a violation

Sean C Davis: Yeah.

Taylor MacDonald: of many different legal statutes, both federal, state, and otherwise. Like, but you know, it I mean it's a it's a fascinating study, both. terms of what this technology can do, as well as the the sort of tricky dance that any, you know, judicial body would have relative to adjudicating this problem. but anyway.

Sean C Davis: Yeah. Well research can be illegal today, right? You can do illegal research.

Taylor MacDonald: I suppose you're right. I mean, what if you I don't know, like there's plenty of drugs that you cannot that you

Sean C Davis: Exactly. Yes.

Taylor MacDonald: can't use because they're listed as like a schedule one, you know, narcotic or or something like that, right? Whatever. if you did that in a l I mean, look at this. Like what about the you know, COVID, right? We all just survived COVID. COVID was a thing that escaped a lab. Right. And there was so much hand-wringing about who was responsible and the consequences. I mean, look at the economic fallout as a result of that. This seems like a relatively minor mishap in the bigger scheme of things. However, it portends this terrible future where, you know, we you know, like a lack of prosecution therefore creates this you know this gray space where these corporations are are behaving recklessly. They are people on the one hand, from a political standpoint they're considered people, but from a criminal standpoint they're not. I think what'll be really interesting is if any of the impacted corporations like Motollabs or Hugging Face actually decide to bring like a civil lawsuit against OpenAI for this behavior. And you know, that would that would be a very interesting case to watch, I think.

Sean C Davis: I think it would. I also think the Supreme Court would probably hear it, right? 'Cause they they need to set a precedent.

Taylor MacDonald: Well maybe. I'm not sure the Supreme Court's really big on precedent, but you know, perhaps okay, let's I got one other question for you. I got

Sean C Davis: That's fair. We we get out of rabbit hole with

Taylor MacDonald: one other question for you before we move on. determinism versus determinism. Okay, so this is a funky word that just means I want to accomplish a set of tasks and I want to do it exactly the same way every single time. That would be a deterministic outcome. Non-deterministic outcomes are the ones that just kind of like take the circuitous route. You can't count exactly on it, and this has been a major issue with all of this technology, right? So, you know, if you ask Claude a question, it'll give you a rambling answer, probably get to the point, you know, eventually. Ask it the same question to Margaret, you may get a different rampling output. Probably will get to the same place, depending upon whether it's a subjective or objective question you asked. How do you personally manage to Well, I want to recall the statement that you made earlier. You were like, one of the ways to reduce some of the volatility, the non-determinism, is to make more deterministic steps, right? So like the logic, the inference, those types of things can happen with your AI agent. And then you say, Hey, I want you to go perform this task. Instead of letting the agent perform the task in a non-deterministic fashion, you would normally s run a script. or or execute a workflow or something. So in real tangible terms, could you explain to me how you think about separating both the non deterministic stuff from the deterministic stuff? And then in real world terms, how do you do it?

Sean C Davis: Yes. I can let me show you a very short demo. I've got it working and I'm I'm in the middle of something right now.

Taylor MacDonald: My goodness. Johnny on the spot. Let's go.

Sean C Davis: and you can also make fun of my listening habits at the same time, which will be great. Okay. Are we here? Yeah, okay. So here's a really weird thing that I do. Most more I would say at least half the mornings, if not. more than half the mornings, I wake up and there's a song stuck in my head.

Taylor MacDonald: Okay.

Sean C Davis: And I have been recording them for years. And for a long time I was just doing it in Notion and I like manually look up the song in Spotify so I could copy it and, you know, try to find just trends that just like nerdy personal stuff. It's been this this agent was one of the first ones I created in the system that follows this non-determinism and determinism. structure approach, et cetera. And so here's what I did. I was just doing this this morning. And so I start this chat and I I just say it it's programmed to record these for me so it knows the context. So I just say superhuman by Paramour again. And

Taylor MacDonald: Mm.

Sean C Davis: it's like look at look at all the Paramour. I have I yeah it's it's a problem lately. and it says I don't I can't find this track and I'm using one of these like really low cost models. So it's not super smart. But here's what it did. Okay. So I said, this is what's in my head, right? And so the the agent can go query the database. And that's what it does first. And it's like, okay, here are all the tracks that I found by Paramour. I'm going to look for one with the right title. And it didn't find it. And it's like, I I couldn't well up here it said, well, let me come back up here. It said the search didn't land on it. can't find it and it's it's not smart enough to go out and query Spotify or whatever, which it should be. But said, it's the I gave you the wrong title. It's called Idol Worship. And it's like, okay, cool. So so what it does at this point, it figured out like it's found the song. It knows what it's it's trying to propose to me. It then what it does, instead of coming back to me and creating this card, what it does, what the agent does is it hits this API. with a proposal for what it should be presented to me. And then that API responds to this application with this card. And when I hit yes here, which I'll do now, it adds that into the system. So now it is stored in the database, but that request, when I hit yes, it went directly to the API. So the agent, one, it doesn't know about the endpoints that are writable. And two, even if it did, it couldn't do anything because the agent's API key that it has to communicate with the API key with the API can only interact with those proposal endpoints. And I have a separate API key to hit the right endpoints. And so even if I said no or change it, like the system knows where to send these requests. And so the agent can't ever delete anything. It can only offer me proposals on what should be. Delete it, for example.

Taylor MacDonald: Pretty cool. what so you you constructed the API, which is effectively the script, my prior explanation of this, right? So there's like

Sean C Davis: Yes, yep.

Taylor MacDonald: again, I'm trying to to categorize this for for folks that might not be familiar with some of this technology, but when you write a a deterministic script, you know, a bash script, Python script, you know, whatever, JavaScript, that's procedural, meaning It'll read

Sean C Davis: Mm.

Taylor MacDonald: line one and it'll execute line one. It'll read line two, it'll execute line two, and it's just boop, boop, boop, boop, boop, all the way down in linear order, which means that if you have a task, let's say you have five tasks, it can complete task one, and then you can wait for that task to be completed, and then based on the output of that task, it completes task two, and so forth. And that's determinism. so that's pretty cool. So you constructed an API. Are there any other tools that you might use, like workflow tools? I know I mentioned N8N a while ago. That's one that I've been

Sean C Davis: Mm.

Taylor MacDonald: playing with. I found that to be a little bit limiting, honestly, in the big scheme of things. And so I've been looking at a tool called trigger.dev, which lets you put workflow configuration into code. have you played with any of this stuff, Sean?

Sean C Davis: Not so much. I've I've gone down the kind of homespun route just because I I it's a lot of fun for me and it feels like then it's it's boundless. You know, I can

Taylor MacDonald: Mm-hmm.

Sean C Davis: it it might take a little bit longer, but I can put together exactly what I want.

Taylor MacDonald: I think one of the concerns that I've had and one of the things that we keep talking about at Ample is the proliferation of this, you know, governance. In fact, the work that I've been doing with Netlify, you guys have talked a lot about governance as a major flaw in this ecosystem, you know. and and in full in all fairness, like Netlify has developed a solution for this, as I I think a number of other service providers have too. But it's the idea that you've got everybody in your company is like vibe coding something. and shipping it. And so some of that's going to be sensitive information, some of it's not. I read an article

Sean C Davis: Mm-hmm.

Taylor MacDonald: or somebody mentioned to me an article recently about how those publicly published clawed artifacts, they're accessible. If you guess, you know, you can rainbow table your way to finding, you know,

Sean C Davis: Mm, mm.

Taylor MacDonald: publicly accessible artifacts. I mean, just because it's got a really hard-to-know URL certainly does not make that impossible for some rogue agent to come across. I don't know. There's all sorts of interesting challenges and and things like that. And so one of the reasons that I like the more determinant, like the more visual, c you know written to code repeatable steps is that you can one have a more appropriate like development strategy, you can integrate the rest of the team, we're all looking at the same thing, we're all operating from the same code. I think. one of the risks that we see in vibe coding is that lives either in your brain or somewhere on your file system and it can have really specific nuances. So for example, the the app you just showed us, with your music preferences and things like that, that's not accessible to the outside world, I'm guessing. And so you probably have not had to test it against the deterministic results or against the potential that I could get it to cough up environment variables simply by asking it to. You know, some of those, you know, A prompt query injection, stuff like that. I don't

Sean C Davis: Yeah, it's r it's it's running on today it's running on my Mac mini, has its own database and so and it uses tail scale for the connection. So it's like, yeah, it's fairly secure. I'm playing around

Taylor MacDonald: Mm-hmm. Yeah I love Tailsfield.

Sean C Davis: with a Netlify version of it. I'm trying to come up with this like serverless framework construct so that you can just be like boop, agent, boop, agent, boop, agent, and then the app becomes kind of your personal assistant orchestrator that can piece all these things together. but yes, that opens up the API on the public internet. So that's you need to do some thorough testing.

Taylor MacDonald: Mm-hmm. Which is a it's a whole different, it's a whole different ball of wax, especially as you have rogue agents going around finding zero-day exploits on everybody's endpoints.

Sean C Davis: Right. Right. Exactly.

Taylor MacDonald: All right, Sean, let's move here to the we're we're just about out of time, but what experiments or or neat tricks, things, tools that you've been uncovering lately? What have you been working on outside of the demo and your nine to five and your role as a father and husband?

Sean C Davis: All these things. constantly tinkering. okay, so I've I've got so many updates and and I'm trying to work and share in in public as much as possible. So I will I also on the determinism, non-determinism, I've recorded a video that kind of like talks about the theory a little bit more with some charts and stuff. So I'll sh I'll share that in the show notes for folks who want

Taylor MacDonald: Great.

Sean C Davis: to kind of like go back to the 101 version. okay, so I think we mentioned this last episode, but maybe maybe not. there's there's been a lot of talk recently with my colleagues on hey, we're all moving so fast, we're getting really good at working with AI agents, and we're getting really good at doing research with AI agents and then barfing out the results. The problem is is AI agents are Trained specifically for speaking in a or writing in a specific way and being detailed by default. And so if you're like cool, I understand the output, but now go put this into or I understand the the outcome of the research, go put this into a notion doc so I can send it to my colleagues. And it's like, okay, cool. And then it's like 5,000 words, and and you don't even read it.

Taylor MacDonald: Yeah.

Sean C Davis: And then you send it to your your colleagues and you're like, hey, look at all this research. No,

Taylor MacDonald: They don't read it either.

Sean C Davis: they they can't. They probably want to though, right? They want if you did meaningful research, they want to understand what that content is. And so what I've done, I shared a couple skills last week, and I'll share two more this week because they're working really well. It's really awesome. So I have one skill called human readable. And basically what it does is it It reads configuration files that are an assessment of my personal voice. And then it takes the what I am expecting the output to be. And one, it writes it so that it's expecting it to be read by another human and then it writes it in my voice. And so I still edit, I still read it and I still edit it, but it's like a third of the length usually and feels like it kind of sounds a little bit more like me when I when I read it. And it's paired, human readable is then paired with what do I call it? Update voice. And so update voice is this interactive skill where it's like, hey, cool, where can I find and source your voice from? And so I pointed it to social media and I pointed it to Slack, actually, and I pointed it to some older blog posts that I had handwritten. And and it's pretty judgy. It's like, you know, you're you're S you have a self-deprecating sort of tone with some light humor undertones in it. And I'm like, yeah, okay. I mean, that's an interesting way to put it. That's fine. Yeah. But it's

Taylor MacDonald: And brut brutally honest, thank you.

Sean C Davis: accurate, and so then it stores that in a global file. And you can always overwrite that for any particular project and have a local voice voice file. So like for you at at Ample, you could follow a similar pattern and be like, hey, here's Taylor's voice. But if I'm in client A repo, this is how client A speaks. So I'm

Taylor MacDonald: Yeah.

Sean C Davis: gonna do some local configuration there. And then

Taylor MacDonald: That's very cool.

Sean C Davis: you're just like, here's my research, boom, make a blog post human readable. So it's been that's been awesome for me.

Taylor MacDonald: That's very cool. I will tell you so I do have a voice skill of myself, and I came across this. let me share the screen here. I came across this GitHub on GitHub, this skill called I Have ADHD this past week. I don't know if you saw

Sean C Davis: yeah, I saw that, yeah.

Taylor MacDonald: this, so I posted this in Slack, but I think this is interesting. I mean, it can take this verbose output and then just turn it into action, like bullet points. Boop, boop, boo, boop. So far, that's been

Sean C Davis: Yeah.

Taylor MacDonald: pretty positive. I think it's a little more terse than what you're describing. but I like that a lot. I I will tell you one of the philosophical dilemmas we've had, you know, at least in the last six months, if not the last couple of years, it is difficult to understand what a client's posture is on AI. Like, and sometimes we ask very

Sean C Davis: Hm.

Taylor MacDonald: clearly, but that posture may evolve, you know, even in a matter of days, weeks, months, or or so forth. And so I have clients that have contracted us to do content writing. And we have copywriter, like human beings on staff. And I think there's a real interesting question about, you know, there is all sorts of challenges around generating SEO content, you know, or or sorry, generating content that is effective for SEO and AEO today. are we generating content for agents now? Are we generating content for people? we're still doing blog posts like at Ample, you know, every couple of weeks we'll post a new thought leadership piece. And I mean, I think that's helpful as humans because it gives us a chance and a space to kind of explore and think about this stuff. And and

Sean C Davis: Mm-hmm.

Taylor MacDonald: if you're writing it by hand, I still argue that like sitting down and taking like, you know, physical notes in your notebook all day long every day is going at least for me, that that helps commit some of those thoughts to memory in a way that I I think I have lost as I've moved towards this more transcript driven kind of AI world. but yeah, so I I sometimes struggle with this question about is it appropriate to use AI to generate content, particularly for content engagements for our clients? That varies from client to client based on their, you know, risk assessment, their privacy policies, their, you know, the way that they're strategizing their goals towards you know, towards this this answer engine world. but yeah, I don't know. It's i have you bumped into any of that, like if you ever Interacted either with a client or you know, maybe a stakeholder at your company that had a different opinion about how you might be taking advantage of this technology and what impact that may have on either your velocity or your effectiveness. You know, and it's weird for a service-based industry. Sometimes we struggle with this. It's like, well, you're paying me for an hour to do the work, but now I have a calculator that will help me do some of that work. That means there's more margin. What does that mean? Does that mean that like we're more profitable? Does that mean that you get a lower cost? How do you negotiate that? I will still argue that like the human brain today is still a more effective communicator because we're not just regurgitating patterns. We have goals and we're working towards those goals. and those goals can be very nuanced and very intricate and can build upon other, you know, things that are happening in the ecosystem or within your, you know, strategic opportunity set. you know, what do you think about that?

Sean C Davis: Yeah, I I I I think the easier way for me to answer this is that I've just I have this history of what fifteen years of blogging on and off, and it's been a really interesting evolution over the last, let's say, year and a half to two years, where

Taylor MacDonald: Is it challenged some of the value statement that you might have had? Because you're right. And if you

Sean C Davis: Yeah, yeah.

Taylor MacDonald: don't know Sean, Sean has been a prolific blogger, evangelist slash, you know, thought leader for all these years, as long as I've known you. You have had maintained your own blog, you're posting regularly. And and it's not uncommon that I'll like go to find how do I fix that one problem in Astro JS and I'm like land on Sean's website. Here it is, like. A very thoughtfully written prose from five years ago that he clearly did by hand. How does that ch

Sean C Davis: Yes.

Taylor MacDonald: how does that challenge your perspective today as a content creator?

Sean C Davis: I mean it's the the the subject of the content has certainly changed a lot because those those the solutions I was writing about previously now agents can solve in just an instance. So that's that's kind of changed my approach. But it but from the actual process, you know, at first it was like one AI was really, really bad at writing content for a long time. And then it so There was that like it's really easy to smell AI written content. It's becoming a little bit less so today. And so in the the circles I run in, you know, at first it was kind of like We need to differentiate and like, do we need to create a stamp that is, hey, I this came from a human? And so at first I was like, look, I want to maintain my authenticity. And the only way to do that is to actually sit down and write this, regardless of where the research came from. I need to write it. And then that evolved over time. And and I think I've just had have had different flavors of this over the last year or so. And, you know, now with the the human readable skill it's it's helped, but they've all just been kind of different flavors of I'm going to I'm gonna plan with the agent and then I'm gonna let the agent do the majority of the work, both the research and the writing, and then I'm gonna read it and I'm going to edit it and I'm probably gonna tell the agent what to edit. And then I might hand edit a few things at the end so that it actually feels like me. And whether it's a blog post or some notes just share with a colleague, I follow that same process. And it's not unlike building software either. I'm gonna make the plan with the agent. I expect the agent

Taylor MacDonald: Mm-hmm.

Sean C Davis: to do the work. I'm gonna test. We're gonna iterate

Taylor MacDonald: Does that does that workflow change the value of the product you are developing?

Sean C Davis: I I mean, I think of the product itself, I would say I would say the workflow doesn't change the value of the product. However, the way that the product is consumed today is different. And I think that is more of a factor of what is the value of the product.

Taylor MacDonald: That's an intri Okay. That's a good place to stop. I like I like that. all

Sean C Davis: That's a whole rabbit hole, yeah.

Taylor MacDonald: right. Well, Sean, thanks so much. it's always a pleasure to talk to you. I know you've got a couple of weeks of kind of rest and relaxation coming up. So next couple of weeks are gonna be a little bit different format than what we've normally followed, but more excited for it. To kind of go rest your mustache.

Sean C Davis: Yes, sir. And you gonna give you wanna you wanna tease the next one a little bit 'cause it's gonna be quite a bit different.

Taylor MacDonald: So the plan next week is for me and my business partner Kevin Comer at Ample to just have a conversation. we're still kind of firming up some of the topics that we might talk about. So if anybody has any ideas or thoughts, feel free to shoot them to us on our fancy new contact form, bloodsweat and tokens.xyz. but yeah, hopefully you'll you'll tune in for that, Sean, even though you won't be around next week. But we're really excited about kind of taking this format and and breathing a little bit more. creativity into it, kind of talking to other individuals and kind of make a little bit of adjustments as we go, not only to accommodate, you know, travel plans, but also to kind of bring a little bit different perspective to the audience here. So so yeah, thanks so much. It's always a pleasure and I will catch you on the flip side, brother.
