Permission is not permission to act
Frontier labs build the models. Clients bring goals. Product teams decide what to ship. Users click “allow.” Somewhere in that chain, access turns into action — and when the system does something nobody explicitly asked for, everyone can honestly say it wasn’t their fault.
That’s not a philosophical problem. It’s a design failure we’ve started treating as inevitability.
Achal recently gave an AI agent access to his email and calendar. He didn’t tell it to manage his meetings. Then an email came in asking to move one. The agent read it, found the invite, and moved it. Achal noticed afterward.

Nothing bad happened. It behaved like a good assistant. As he put it:
“It was just being proactive.”
— Achal, CPO
If it had asked first, it would’ve been a worse product. If it had ignored the email, it would’ve been useless. The value came from inferring and acting without being told how.
So here’s the uncomfortable part: Achal authorized access. He never authorized the action. Permission to see is not permission to do anything a model can reasonably invent from what it sees. We’re collapsing those two on purpose, because the collapse is where the magic is.
And magic without ownership is how you get a handoff problem.
The race is a moral laundering machine
Days before our Born West roundtable, the industry was doing its usual split-screen. A researcher who’d worked at OpenAI and Anthropic left Anthropic arguing that labs are racing past their ability to understand or control the systems they’re building. Anthropic’s CEO followed with his own call to slow down enough for safety to catch up.
Sid’s interpretation of these events was colder and, frankly, more useful: neither of them is “responsible” in the way the press wants. It’s Pandora’s box. Try to go slow and ethical, and you get left behind — especially once you bring China into the picture.
“If I don’t do it, somebody else will.”
That line doesn’t justify the race. It explains why responsibility keeps evaporating. Competitive pressure doesn’t stop at the labs. It shows up in every client deck asking for “AI-native,” every product team scared of looking behind, every builder who knows the edge cases and ships anyway because the alternative is irrelevance.
Sid called it the fudge factor. You know the pattern isn’t clean. You keep going because you have a problem, a client, a market. “Everyone’s responsibility” starts to sound noble until you notice what it actually does: it turns accountability into a group project with no owner.
We don’t need AGI to be reckless
The extinction talk is loud, slippery, and mostly a distraction from decisions already on the table. AGI doesn’t even have a stable definition. Meanwhile, companies are already handing agents email, calendars, files, codebases, and customer data, then acting surprised when the system treats “helpful” as a blank check.
The near-term failures won’t look like sci-fi. They’ll look like mass displacement without a plan, security that can’t keep up with the same tools attackers get, creative work collapsing into recycled sludge, and products that store more user data than they need because somebody might want it later. Xenia put it bluntly,
“Once you hold the data, you can’t make it 100% secure. You’ve already chosen exposure.”
Born West’s own line has been clearer than the industry’s: human in the loop, always. Not because autonomy is evil. Because today’s models aren’t deterministic, trust isn’t earned by demo, and consequential actions — money, deletion, publication, anything that hits another person — deserve a different threshold than tidying files.
Keeping a human in the loop is not an afterthought. It’s a product decision about where judgment still belongs. That line will move as the tech gets better. Pretending it doesn’t exist is how you end up authorizing inference and calling it progress.
Stop pretending the handoff is someone else’s job
Achal’s position in the room was simple: it’s everyone’s responsibility. He’s right — and that’s exactly why the current setup fails. Frontier labs own training and release. Product teams own access, tools, and approval gates. Clients own the problem definition. Users own the click that grants the keys.
Control is distributed. Responsibility should be too. Instead, each link makes a locally reasonable choice and assumes the next one is holding the bag.
We don’t need to solve AGI to decide whether an agent needs your inbox, which actions require confirmation, whether a mistake can be undone, whether a user can see what happened, or whether you’re storing data the product doesn’t need. Sometimes the responsible move is telling a client the thing they want shouldn’t be built that way.
The calendar agent made a good call. The next inferred action might not be. The industry keeps treating that gap like an edge case. It’s the product.
AI can already make decisions for us. The hot take isn’t that it will get smarter. It’s that we keep granting capability while diluting ownership and then acting shocked when nobody can say who allowed the thing that happened.
AI’s real risk is ownership theatre.
If you're granting agents access before you've mapped who owns the decisions they make on their own, we're glad to compare notes. Book a 15-minute intro



