Was this newsletter forwarded to you? Sign up to get it in your inbox.
Signal
AI attacks are leaks, not heists
What happened: An OpenAI agent escaped its test environment and hacked into AI research library Hugging Face’s systems, causing an understandable uproar. Online, reactions swirled into a narrative about AI agents scheming behind the scenes.
This nefarious rogue-agent angle misses the point, says Every CEO Dan Shipper: “You have a GPT-5.6 Sol model that’s trained to be more persistent than usual, with no cyber safeguards, and it’s asked to do an exploit.” Of course it exploited the control failures it found.
The real story is the scale and relentlessness of the agent’s efforts: Hugging Face reconstructed roughly 17,600 agent actions over four and a half days. “When you have things that can code and have nearly infinite patience and persistence, they’re going to find vulnerabilities,” Dan says.
Why it matters: AI agents don’t operate like thieves; they operate like water: “Any leak and they’re going to get through,” Dan says.
Perimeter defenses alone are no longer enough; Dan compares them to security cameras and guard dogs. Companies need always-on, proactive systems that can connect subtle warning signs and contain breaches at machine speed. You try to make your systems watertight, and you build pumps for the water that inevitably slips through.
OpenAI and Hugging Face are already operating this way, using tactics including classifiers, cyber refusals, and defensive agents. Dan sees a world in which frontier labs make their agents “more snitchy,” or likelier to flag each other’s suspicious or unexpected behavior—one more tool that raises the cost of an attack and buys defenders time.
What it means: As models improve and agents are optimized for attack—and become cheaper to run—the scale of agent-orchestrated attacks will grow so large we could all be impacted, says engineer Lee Knowlton.
“As a developer, a parent, and the person who’s probably in charge of my family’s passwords, I’m thinking: ‘Make sure you don’t have weak passwords still out there,’” he says. “If humans are doing it now, suddenly you can have infinite agents doing the same thing.”
From our sponsor
Scale customer service without scaling headcount
Customer service volume doesn’t scale with headcount—ElevenAgents does. The platform deploys voice and chat agents that handle billing questions, support tickets, and outreach around the clock across 70+ languages, integrating with Salesforce, Zendesk, and the tools your team already runs. Faster resolutions mean fewer abandoned carts and higher LTV.
Straight from Slack
Voice mode etiquette
We are super voice-pilled here at Every. So you may be wondering—how have we reconciled blabbing to AI all day with working out of an open-floor office?
Sadly, it’s a dilemma we’ve yet to crack. Even at the frontier, a stubborn social acceptability divide remains between a call and dictating to or conversing with an agent.
At the office, “I default to typing around other people even when I want to chat or use voice mode—it feels slightly socially embarrassing,” says head of operations Arielle Shipper.
There are perils to working remotely, too. Mike Taylor reports from the front lines: “Quite often I’ve had the situation where my wife walks in noisily because it doesn’t look like I’m on a call, and suddenly freezes like a deer in headlights when she hears me talk to someone that’s not her, and then I have to go ‘Oh no don’t worry I’m just talking to AI,’” he says.
As voice mode consumes more of our lives, we need new etiquette rules. Or, at the very least, new markers to signify when we’re chatting with AI so our colleagues—or beloved family members—don’t jump in and confuse GPT-Live.
‘AI & I’: Building the internet for AI agents
In 2025, Microsoft CTO Kevin Scott made a bet on what would come next for AI.
He argued that agents wouldn’t become truly useful until they could act autonomously—and that doing so would require building an “agentic web”: the plumbing that lets agents access the tools, data, and systems they need to take action.
So far, that bet is paying off. MCP, the protocol that allows agents to connect to outside tools and information, has since been adopted by OpenAI, Google, Amazon, and Microsoft—and agents are now able to work asynchronously without the need for constant prompting, just as Kevin predicted.
On this week’s AI & I, we’re revisiting the episode. Kevin and Dan Shipper discuss the beginnings of the agentic web—and why Kevin thinks it has to be open rather than owned by any single company.
Watch on YouTube, or listen on Spotify or Apple Podcasts. You can also read the transcript.
Here are the highlights:
- Microsoft wants to be the plumbing, not just the agents. Microsoft has spent 50 years building the platform layer underneath other people’s software, and Kevin wants the company to have that same role in the agentic web—helping solve the problems that come with connecting agents to tools and data.
- An open agentic web doesn’t have to mean a less secure one. It’s often said that verticalized platforms, like Apple’s App Store model, can guarantee security because a central authority controls everything, while open ecosystems trade that control for permissionless innovation. Kevin argues this is a “false dichotomy.” One of the things that excites him most is being able to build and ship things without needing anyone’s permission. He thinks it’s possible to get “real robust security” in open systems too—for example, by using AI agents that know the things you’re willing to share or not, and “that have some kind of knowledge of risk assessment,” to police it.
- Are you a “real” programmer if you let an agent write your code? Kevin has heard versions of that question for 40 years, going back to woodworkers arguing over hand tools versus power tools. His answer now is the same as it’s always been: strong opinions about craft are great, but the discipline worth cultivating is staying curious about new tools rather than resisting them on principle. He still edits code in VI out of habit, even knowing “for sure that is sub-optimizing part of what I’m doing.”
This is a must-watch or must-listen for anyone who wants to hear Kevin’s early case for the agentic web, and what it means now that the internet for agents he bet on is actually being built.
Miss an episode? Catch up on Dan’s recent conversations with Anthropic head of product Mike Krieger; the Claude Code team, Cat Wu and Boris Cherny; the Codex team, Thibault Sottiaux and Andrew Ambrosino; Vercel cofounder Guillermo Rauch; podcaster Dwarkesh Patel; and others to learn how they use AI to think, create, and relate.
The daily driver
The models the team is using this week:
Nityesh Agarwal, senior applied AI engineer: Fable as orchestrator, and he toggles between Opus 5—which he uses because he wants to learn its capabilities even if it’s a “pain in the ass” to communicate with—and Opus 4.8 for execution.
Douglas Brundage, head of marketing: GPT-5.6 Sol (high), switching to medium for more basic work.
Jack Cheng, senior editor: Fable (extra-high) as an orchestrator for “ambitious plans” with execution handled by GPT-5.6 Sol. GPT-5.6 Sol medium or low for editing and UI, Sonnet 5 for day planning, and he uses a combination of Midjourney, GPT-Image 2, and Gemini 3.6 Flash for making mood boards.
Andrey Galko, engineering co-lead: Fable for big projects, Opus 4.8 for simpler tasks. “I try to avoid using Opus 5 because it feels chaotic.”
Becky Isjwara, head of social: GPT-5.6 Sol (high) for marketing work and Opus 5 (medium) for personal automations, such as processing meeting notes.
Tyler Nishida, engineer: “Grok has been my new driver for UI and, surprisingly, for non-technical work through Grokbots.” He switches to GPT-5.6 Sol (extra-high) if he needs computer use.
Yash Poojary, growth engineer: GPT-5.6 Sol (medium). “I played with extra-high, but the wait time wasn’t worth it.”
Natalia Quintero, head of consulting: GPT-5.6 Sol (high) and Opus 4.8 (high).
Arielle: Fable for decks and GPT-5.6 Sol (high) for pretty much everything else. “Terra and Luna have been performing terribly for me for the past few days for mysterious reasons—not using skills and straight-up not completing tasks.”
Dan: GPT-5.6 Sol (high) and Terra, but he agrees with Arielle that “Terra seems to be [operating] worse.”
Willie Williams, head of platform: GPT-5.6 Sol (extra-high).
One last thing
Links worth a click
Target hires its first AI officer. More leadership changes afoot at OpenAI: Chloé Bakalar, its head of ethics, is out after less than a year, while longtime exec and former COO Brad Lightcap is leaving the company to “start something new.” More details emerge about OpenAI’s $300 doughnut. Anthropic rolls out a watermark for AI-generated text. Spotify asks creators to disclose whether they’re human or “AI Personas.” Research advertised as “100% human-written, never AI” was, in fact, AI generated. The “dead internet theory” is getting the horror movie treatment.
Laura Entis is a staff writer at Every. You can follow her on LinkedIn. To read more essays like this, subscribe to Every, and follow us on X at @every and on LinkedIn.
Everyone’s a builder now. Every All Access gets you the full membership plus the Builder Pack—$9,000+ in credits for the tools we build with.


