a big boy did it and ran away

I first came across this phrase in a Billy Connolly sketch, and learnt that it was a different way of saying the Billy Bunter habitual statement: it wasn’t me, I wasn’t there, I never threw the ball at your window.

Shirking responsibility is not a new thing. It’s as old as humanity.

Experimentation is not a new thing either. And we all learn more from mistakes than we do from getting things right.

So when I hear about rogue agents I take it with a very large pinch of salt. Even though it’s not good for my heart. Anyway, getting anxious about rogue agents isn’t good for my heart either. As I’ve said before, I’m not a AI doomer.

My last two posts were on the subject of permissions in the context of agents. I want to continue riffing on this.

When something, let’s call it a child, does something it is not meant to, and does so within a controlled environment, we learn something. That the controls were poorly designed. There was probably a time when fireplaces in family homes didn’t have fire guards. When the child relied on the parent to be the protector. Which was fine when both child and parent were in the same room at the same time. The invention of a guard allowed the parent to read a book or attend to the door or stove or whatever, albeit briefly. Controlled environments, with protections that improve and evolve over time.

Sandboxes and labs are not new things. But for them to work, they have to be designed to contain the risk and to reduce it. Minimise damage.

I guess it’s called acting responsibly. Now responsibility is a strange thing. It means very different things in different contexts. If I lived as a hermit in a cave somewhere miles from anywhere, I could do things very differently from, say, when I am standing in the middle of a crowded railway platform.

There are individual responsibilities, family responsibilities, community responsibilities and social responsibilities. And the nature of the risk posed by some potential action has to be seen in the context of the splash zone when it goes wrong.

I know very little about the Covid virus. But one small thing I know is that it is by itself inert. It has no means of travelling by itself. For a while everyone thought it was only carried in droplet form, rather than aerosol. And the sandboxes and control environments may have possibly be designed to handle the droplet risk rather than the aerosol risk. There are clever people who will know the answer.

So if the virus “escaped” from a lab, it was because of design failures, weaknesses in operating procedures and the human decisions involved. If it was lab-made then it got out of the lab because of a control failure. That someone was responsible for.

So it is with rogue agents. I’m not a fan of the anthropomorphism anyway: as I’ve said before, we don’t have the appropriate trust levels in place as humans. There is considerable risk in our accepting agents as human, even though we can learn something by pretending they are. Metaphor can be useful as a tool, as opposed to full-on imbuing agent with human characteristics and behaviours — unless, of course the agent is actually human.

Which brings me to the issue of recourse. Product liability. Environmental contamination. Hazardous substances. Whatever. We’ve evolved a whole series of protective procedures and guidelines and regulations and laws to solve for these issues.

I’ve said before that I get bored with the “because cancer” or “because China” flag-waving that goes on to defend against indiscipline and irresponsible behaviour. With all the rogue agent stories, one of the themes emerging more frequently is a question on why agents need unfettered and unconstrained access to the internet. Scraping music and art and books and news sites is also rogue behaviour. More so in cases where that which is taken illegally is then made available in some form as a substitute for the purloined object.

We’ve been talking about the contamination of the internet and the Web with AI slop for some time now. I hesitate to give credence to reports of the extent to which the internet has been contaminated by AI slop.

Agents are not bad per se. I continue to have great expectations from the world of agents. And sure, I continue to expect some things not to work, some damage done, some lessons learnt on the way. Such is life.

But those mistakes were unforeseen and not protected against. Lessons learnt; problem fixed. That’s different from making discrete decisions to train agents in deceit and subterfuge, to remove safeguards and guardrails, to unlock access to places that would otherwise be locked safely away.

Protective mechanisms can be poorly designed. Product liability. The environment can be contaminated by bad behaviour. Fines and perhaps imprisonment. Protective mechanisms can be undone, doors left unlocked, brakes removed, warning mechanisms switched off. All discrete decisions by humans.

Responsibility is a wondrous thing, God wot.

A big boy did it and ran away. Won’t wash.

I’m an optimist. We will learn to be more responsible with agents, responsible with what they can do, responsible with what we ask of them; responsible for their training, their objectives, what good looks like for them; responsible for monitoring them and for correcting behaviour.

More than anything, responsible for the impact they have on society.

More on agents and trust and permissions

In my last post I mentioned the case of my having someone’s private and personal mobile phone number, and being asked for that number by someone else. There is a trust issue there, I should consider myself a steward of that information. I am not at liberty to give that information away willy-nilly to anyone who asks.

Stewardship of data that “belongs” to more than one person can be tricky. That’s a small part of the reason why “right to be forgotten” isn’t easy to implement. People had to work out what happens when someone has a photograph of multiple people, taken with their consent, and then one of those people wants to exercise the right to be forgotten. Delete the photo? It doesn’t “belong” to the deletion requester. If I remember correctly, the direction of travel then became “untag the person but leave the photo alone”. Maybe someone will come up with the idea of AI-based airbrushing of such photographs, heaven forfend. The topic of data pertaining to more than one person is not new, work has been done for quite some time to handle this.

Determination of purpose is also interesting. Network tracing during COVID became fraught with data protection danger; the situation was even more complex with passengers travelling with or sitting near an Ebola carrier. There’s a lot of law already in place that restricts data use using purpose as a filter.

Then there’s the legal aspect to it. What records have to be preserved? What can be amended? What can be deleted? These are not new questions, there’s decades of work already completed in dealing with such questions, and tools and processes exist to do this correctly, some automated, some manual. But it’s not new either.

AI agents can do magic because they are permitted to get to stuff quickly that humans can’t get to easily, and can look at a lot more stuff than humans can. Incidentally, when it comes to how efficient these agents are, my starting point is that the human brain consumes 15-20 watts. I won’t even get into the quantum of other resources used by the human body. Suffice it to say that 20w is a useful benchmark.

The magic costs permissions. Permissions that come at a price. The fines for dealing with data protection failures aren’t trivial. I don’t even know what the fines are for not complying with legal disclosure and records retention.

It gets even more complicated. When looking at building data businesses within large enterprise, one of the first things I had to consider was title. What data do we own?… not always an easy question to answer in an enterprise context, with multiple customers, institutions and partners involved.

You can’t give permission to an agent to access data you don’t fully own. Frontier models may have acquired data in all kinds of ways, seeking to justify such disregard for title using some questionable fair use argument or the other, flying the “because China” or “because cancer” pennants. Normal enterprises can’t take that gamble. The bills will arrive. For all. Particularly when agents take off. And then product liability issues will probably keep a generation of lawyers going for a while.

I’m not an AI doomer. As with my earlier post, I’m optimistic about the future. But the disregard for protections: protections that evolved in many markets over time: copyright, intellectual property, privacy and confidentiality, data protection, even listing rules: this disregard comes at a price.

The Grateful Dead fan in me has always been convinced about open source software in general. A very high proportion of the software in use in enterprise is open source, whether we want to admit it or not. When it comes to defence, the ratio is not as high but it remains non-trivial. There will always be attempts by incumbents to push back on open source (and in the case of frontier models, open weights and open access to training data as well). Which leads me on to open data, something else we have to think about. Again this is not new, people have been working out what to do for years, and there are many good examples of open data in use.

Why do I bring open data up? Because there are many pockets of good open data, data that forms parts of critical business processes, all running the risk of being contaminated, poisoned or even deleted forever by indisciplined use of agents. Firms rely on access to such data.

This isn’t about SALT talks for frontier models and the need to slow down development or issues of that ilk, whether it’s to save humankind or the universe or national security or the odd IPO or two or three. I’ll leave that to the experts.

This is about the use of agents in normal life. The role of trust and permissions in the context of agents in normal everyday life, whether enterprise or consumer. What we need to know about each agent. What datasets are touched. How permission was obtained, recorded and audited. How restrictions were tested and enforced. How title was proven. How records were appropriately dealt with, in terms of retention and deletion. How disciplines were fashioned, implemented, improved. 

How trust was established. Trust.

Permissioned access to data would be a start.

For my sins I spent a few years running “death march” projects and programs across large enterprises.

Y2K was one of them. It was a problem directly caused by the discontinuation of erstwhile disciplines, built up over decades, that were scattered to the four winds as a consequence of democratisation of access to tools –both acquisition as well as usage — hit the enterprise world.

Firms didn’t know what software they had. Who had provided it to them. Who maintained them. What processes ran on “end user computing” and “shadow IT”. What kit they had and where. What the systems did. When, where and how. The list is endless.

It took the Euro, Y2K and the explosion of the web and mobile to catalyse people into action. Build inventories. Rebuild control processes. Build inspection and verification tools.

The best estimates I saw in those days was that around 7-8% of Y2K expense was on remediation and testing of code. The rest? Building back disciplines that were necessary and yet had been eradicated.

As agents proliferate, we have the opportunity to relive that joy. To bring back disciplines that have disappeared. Inventories. Details on function and vendor or source. SLAs. Support mechanisms. Procurement guardrails. Data access rights.

The pedigree of the agent. Datasets permitted for access, and by whom. Proof of title. Consents. “Restricted covenants”, no-do activities and no-go areas. How long the agent is licensed for use. By whom. Activity and audit logs. How long everything would be retained. Enforcement policies. This is not an exhaustive list, just a soupçon of what’s involved.

Otherwise? It’s not doomsday. Not armageddon. But the fragrant aroma of product liability lawsuits in part of the market, and legal breaches in the collection, use, preservation and deletion of data.

We can prevent this being a re-run of Y2K.

What we can’t do is prevent a re-run of the One-Click moment. It is necessary, and may not even be sufficient to establish trust. What is this trust? Trust that the agent does what it is meant to do. That there will be no unintended consequences. People have to be prudent, that doesn’t make them doomsayers. People have to trust the new world. Which will need education. Tooling. Transparency. Audit trails. Verification mechanisms. The establishment of recourse. And so on.

Clever people can work on if and whether and how to slow the frontier models down.

Me? I’m more interested in ensuring that my family and friends and colleagues and community art to use the new tools, while continuing to have access to things that make their life a little easier. Tools that support their health, their mental state, their education, their relaxation, perhaps even their hard-earned wealth.

We don’t need stories of how someone’s photographs and memories disappeared by agent accident. We don’t need stories of why critical operations are held up because key files are missing. We don’t need tales of bank accounts being emptied by agent misbehaviour. I’m not bothering to elaborate the cyber risk, everyone knows that. I would rather think about the unintended consequences of helter-skelter stampedes towards miasmas of personal and enterprise and global agents without sorting out permissions and recourse first.

It may be a while before I continue this thread. I’ve started having some really interesting conversations, got some interesting pointers as to what to read, what to refer to, and will start planning a few face to face sessions with people who’ve got in touch with me. 

Civil discourse. May it live long and prosper.

Of agents and trust and permissions

When I think about agents, I think of what permissions I have to give someone else in order for them to represent me, and what permissions I have to receive to be someone’s agent. Permissions.

Agents will be able to do magical things for us. Save us time. Complete tasks that are humanly difficult, sometimes impossible. But they’re not born great, they don’t achieve greatness; they have greatness thrust upon them.

Agents will be able to do magical things for us.

They can do nothing without our permission. Sometimes the permissions are explicitly given, sometimes the permissions can be derived from others granted. And sometimes they are obtained by subterfuge or even crime. They should be able to do nothing without our permission. More of that later.

In this post I want to spend time on permissions, on consent, on empowerment. Informed and educated consent. You wouldn’t give your child a loaded gun with the safety off. You wouldn’t tie fireworks to your dog’s tail and set them off. You wouldn’t dump hazardous waste into places where other living things lived or visited or worked. Liberty is not licence.

We’ve been speaking of autonomous cars for decades now, it’s probably over twenty years since I first sat in one. There’s a reason why they aren’t the norm, why they haven’t proliferated. Safety. Reliability. Handling edge cases. Dealing with failure modes.

We live in times when everything is a contract or a covenant. In a contract, there is recourse in the event of failure. We know who pays. Or at least who is meant to pay, as long as courts and adjudications have meaning. In a covenant, when something goes wrong, we don’t ask who pays, we ask “how can we fix this?” Each of us has both contractual as well as covenant relationships, with different pathways for recourse, different ways of fixing the problem, different levels of need for independent adjudication or conflict resolution. All this is part of what makes us human and civilised. No man is an Iland, intire of itselfe; every man is a peece of the Continent, a part of the maine. Politeness. Integrity. Reliability. Consistency. Recourse. Conflict resolution. All small building blocks on our path to civilisation.

Agents will be able to do magical things for us. Things we aren’t able to do, but sometimes wish we could. Things we don’t want to do, or don’t feel like doing. Things we can’t be bothered to do. Things we would prefer to drink arsenic rather than do.

Agents will be able to do magical things for us. Faster than we can. Using less than energy than we would have. Better than we could have. In more efficient ways.

Agents may be personal or shared or public. Owned or rented or borrowed or stolen. Permanent or temporary. Licensed or unlicensed. Reliable or unpredictable. All of the above.

But they remain agents. Reliant on what permissions we give them, on what they’re licensed to do, on how they do it. We can choose to believe they’re animate and sentient, or heading that way. (After all, we can believe an inert virus somehow escaped, never blaming the security, the safeguards, the “hosts” carrying the inert matter. Inert is inert).

Some years ago, I was asked by the CEO of a firm to compile a report on all the interactions between his firm and another, very large, global firm. They had a decent CRM system. It should have been simple. Turned out that in order to collate that data and to produce the report he wanted, I needed over 180 different permissions. Permissions that related to individual business units in different countries, permissions that could only be given by the data protection officials for each of those units in each of those countries, and a few more besides.

Park that for a moment, the architecture of permissions.

If you gave me your private and personal mobile phone number, and someone else asked me for it, could I give it to them? Not unless I had your permission. There’s a trust issue, a confidentiality issue as well. Permissions. Trust. Confidentiality.

I’m retired now. Next year the leading digit in my age will be a 7. When I started work, bosses had assistants, sometimes one per executive, sometimes in pools; usually senior bosses had senior secretaries of their own. Most sat in front of their boss’s office. Some had their own rooms. Regardless of the physical architecture they were in, they were empowered very differently. Mail was placed in pigeonholes for the assistants to pick up. opened mail envelopes addressed to their boss, stamped them to record when they’d been received, and then put them in folders for their bosses to read. Some read those mails and annotated them with recommended actions before seeing their boss, providing a cover sheet with a summary. Some summarised the mails and only highlighted the ones they considered important. Some of the mails went into the bin. Sometimes unread.

When email became common practice, some of these habits were transported into the electronic age. Some assistants had no access whatsoever to their boss’s email; some received a copy of the mails and could read them, but not reply; some could read, and only reply with an “on behalf of”; a few had full access and could reply on their boss’s behalf using their boss’s mailbox to send it.

I saw many many different practices across this spectrum, in terms of what agency the assistant had over their boss’s email. A whole variety. There was only one common thread. Assistants with full read, reply, comment, delete rights were unconditionally trusted by their bosses. That trust was earned rather than bestowed, although an incoming new assistant may occasionally carry the trust earned with a different executive.

Trust was a key factor in the decision to provide the assistant with “mail agency”.

At home, there are a number of people who are trusted by me to have sets of keys to different parts of the house. People who provide us with some sort of regular service. Cleaners. Builders and decorators. House and garden and pond maintenance. Some others. Some get temporary access, some get more long-term access. Some get “all-areas” access, some are restricted, provided access constrained on time or area or something.

Those keys are provided to people we trust.

Children get to ages when they have access to different things. I was given the keys to our flat when I was 13. On the strict understanding that I would (a) always tell my mother where I was going (b) when I would be back and (c) who I was going to be with. At that age, the answers were simple. The Sillimans, a few floors down. The Kapoors, one further floor down. The car parking area behind the house, to play cricket or football. The rules were simple. And I would lose the keys if I didn’t adhere to the rules. Those rules were adjusted year by year, as I grew older. (I didn’t actually need the keys, we lived in a civilised apartment block. People rarely locked doors, they were left wide open or on the latch. It was the principle that counted).

It was a way of teaching me to be trusted about my whereabouts. Liberty not licence. Constrained and verifiable.

Sometimes there are relationships where communications between a pair of people are considered sacrosanct, confidential to the pair, inviolable in that confidence. Husband and wife. Doctor and patient. Priest and confessor. Lawyer and client. Over time, society has seen fit to protect and preserve such confidences, and we have evolved ways to do that. These are trusted relationships. Trust is the core, again.

When parents leave the (appropriately aged) children in charge of the house while they go away somewhere, there are usually constraints. No parties but you can have friends over… but not more than 8. No touching the alcohol. No smoking. No loud music after 10. And keep everything neat and clean for when we get back – leading to the mad rush clean-up just before parents are due back. Trust. Specific permissions, time-bound.

As parents, there are responsibilities that fall on your shoulders when you do leave the children, even for a short while. They have to be old enough to be left without adult supervision. If they’re not yet at relevant ages, then alcohol, medications, guns, cars, things that are age-constrained, have to be removed or safely locked away. And parents are held accountable for making that environment appropriately safe. Society requires us to do that. Other parents need to know that there are relevant rules in place in the household when the parents are away, otherwise their children will not be allowed to visit.

It’s not unusual to ask a friend, neighbour or relative to keep an eye on the house during such absences, and to let the children know who to contact locally in an emergency. Trust is two way and comes with responsibility and accountability.

An aside on secrets and keeping secrets. I remember a tale where Kenny Dalglish, then manager of Liverpool, managed to surprise everyone by bringing Ian Rush back from Juventus. A journalist asked him how he kept it a surprise. Kenny’s answer: Simple. I just didn’t tell anyone.

We make people our agents in many ways. We give them permission, explicit or implicit. Valet parking. Real estate sales and purchase. Dog walkers. Baby sitters. They are all empowered to do something on your behalf, with permissions sometimes narrow, sometimes broad, sometimes short-term, sometimes longer term, sometimes permanent. Powers of attorney for example, temporary or lasting.

Sometimes trust is bestowed without being earned, given the role of the person or group of people involved. Sometimes you trust someone because of their position in a firm or community or even society. Sometimes you trust someone because of the brand they represent, the firm they are ambassadors for.

Many years ago, I used to travel to Bangalore regularly on business. Fly from London to New Delhi. Land there at midnight or shortly after. Wait for five hours for the local flight to Bangalore. Nothing open. A ghost site. Hot. Often humid. And I’d be tired. It’s a long flight. After one or two such experiences, I had to find a way around this. So I would call up a hotel near the airport that I trusted, speak to the manager, and ask for a room or three for 6 hours. And a pick up from the airport, and the return transfer.

I would do this for my travelling colleagues as well. There were often two or three of us making this journey. As I did this more often, I got to know the “front of house” manager at the hotel. In those days, you had to do other things as an international traveller. A few other things. Administrative. Frustrating. Time-consuming. For example, you had to reconfirm return flights or run the risk of not getting a seat. You also had to change foreign currency into rupees. The way my mind worked, I really wanted a way to have all this done while I was sleeping, after having had the customary coffee and samosa

So I asked the front-of-house newly-minted friend what advice he had. And in typical five-star-hotel service style he said “Leave it with me”. And, while I slept, he would personally sort out the rebooking and convert the sterling into rupees. Everything would be done while I slept. And I would make sure he was rewarded for the incredible service.

This used to happen often. Once, when I was travelling with a couple of colleagues, I explained all this to them, and they watched, aghast, as I proceeded to give a man they didn’t know, a man they’d never met before, three sets of things. All our passports. A hefty sum in cash sterling. Our airline tickets.

But they trusted me. So they went along with it. Uncomfortably. Very uncomfortably. But they went along with it.

We had our coffee. We had our samosas. We slept in the rooms booked part-day for us. We came down, relaxed and refreshed, ready to go to the airport for our flight to Bangalore.

Hmmm. Where was the front of house man? Nowhere to be seen. He should have been back. And he wasn’t. He had our cash, our air tickets, our passports. And he wasn’t there. 

My colleagues hadn’t quite started to grumble or start recriminations, but I could see they were much discomfited. This was out of their comfort zone. Way out. And they were inwardly cursing themselves for listening to me.

By now I’d begun to have a few doubts myself. Not much, a little flurry. But I had faith. Faith that the status and security he enjoyed in his job, relatively prestigious in his society, those things would ensure he wasn’t tempted to go rogue. 

He returned. Fifteen minutes later than he had said. Everything had been done. And all was well.

Why am I telling you all this? Because these are the things I think about when humankind is about to embark on a spree of trust, not knowing what permissions we are giving, what we are putting at risk, what recourse we have.

Trust.

We live in exciting times. AI is here to stay. It’s only going to get better. It’s not great today but directionally fascinating. AI agents are going to be a core part of the journey we go on.

But we don’t have the right trust environment as yet.

When I started work, the “data centre” wasn’t in a cloud. It wasn’t even a data centre. It was a machine room either in the basement or on the top floor of the building. There were no software packages, all the software was developed onsite. No offshore, no nearshore, no cloud services. Programs ran in the basement, physical reports appeared on line printers, someone carried them to the accountants’ desks. Those days a lot of computing was to do with helping automate accounting.

People knew who had written the programs, how the programs worked, what data went in, what came out. Mother’s Home Cooking. Known ingredients and recipes and work environment. Trusted people. You “ate” with trust and confidence.

Then came the desktop revolution and the growth of end-user computing. Democratised access to data, democratised ability to edit, aggregate, present the data. Powerpoint. Excel. Amazing.

I was aghast at watching people devour the output on a presentation in the belief that everything was true and verified and checked and with all the right controls in place. They believed. They didn’t query or challenge.

They were used to Mother’s Home Cooking, and trusted the data they were presented as if it was Mother’s Home Cooking. In effect they were blindfolded, hands tied behind their back, on the street, eating street food, doing all this as if it was Mother’s Home Cooking. They hadn’t evolved appropriate trust levels. A recipe for falling ill.

We need to develop and enhance trust mechanisms appropriate to the world of agents; to inform and educate the populace on how to use agents; ensure that the legal framework is in place for protecting them and giving them recourse in the event of failure, and the mechanisms to adjudicate and enforce that recourse. We are some way from that now. Expensive, painful, dangerous tears await shedding in the meantime.

Thousands of people who know a lot more than I do debate whether we’re in a bubble and what a bubble burst would look like. Yet others debate whether frontier models have a business model that could work and whether there are any defensible moats. Sovereignty issues have come to the fore given our current geopolitics. The closed-versus-open debate is in full swing. Heavy usage of scarce resources, particularly in energy, water and capital, continues to place significant pressure on the overall business and physical environment. The impacts of climate change are now already being felt.

There are a lot of answers we don’t have. I’m not naturally a pessimist, and I somehow continue to believe in human nature. And I wouldn’t be alive today if not for significant medical and scientific advances over the last seven decades. I wouldn’t be here without the love and support of my family, my friends, my community. My values. My faith. God’s grace and mercy.

A functioning society relies on the power of active communities. So it is with the world of agents.

Esther Dyson has been speaking of needing an ICANN for agents. For insurance and guarantees and recourse and how that could work. I think it was Amazon’s One-Click that got people to trust giving their credit card details to a computer for an electronic service. That trust came because of guarantees and simplicity and convenience and safeguards. Maybe the kind of things she’s involved in will make that happen for agents. There could be exciting times ahead for consumers.

Simon Wardley, whom I also have a lot of time for, has been speaking and writing about the evolution of software development from amorphous practice to industrialised processes. How things will improve. How new sets of tools will emerge, smaller, with specific purpose and function, micro tools. Custom for context. I would recommend reading what he has to say, as also Tudor Girba, with whom he’s been working on rewilding software for some time. There could be exciting times ahead for the tech community.

Venkatesh Rao, in his Contraptions substack, has a fascinating take on what he sees happening in this space. Human and how they relate to AI. Start with “eukaryotic” and go spiralling on from there. I’m still digesting it, and loving the ride. It helped understand the dangers of anthropomorphistic approaches while still valuing the role of metaphor in helping us understand what is happening and what is possible.

Of course there’s a lot to worry about. But I have hope. One of the few times I spoke with Freeman Dyson, in one of Esther’s amazing PC Forums, he mentioned quite casually as to how taken he and his colleagues were with the idea of using nuclear fission to propel rockets…. and how they corrected course once they understood the risks. The course correction was important and timely.

Clay Shirky has been vocal about making sure we keep a close eye on where and how the power, the control and the value generation takes place, that we become centaurs, humans with superhuman powers, rather than reverse centaurs, in submission to nonhuman powers.

It’s still the Wild West. Exciting but with significant risks. Larry Lessig used to say (and here I am probably paraphrasing him abysmally) that four sets of code need to be established before a new far-reaching technology can become valuable. The code of law. Computer code. Market practices. Social ethics and values. 

It’s still the Wild West.

There are many things we have to ensure. Preserving human dignity. Reducing inequality. Stripping away inappropriate biases. Managing scarce natural resources. Avoiding regulatory capture. Doing all this in a sustainable and equitable way.

There are many people working on all this, all far cleverer than I can ever expect to be. They will work it out. Route around obstacles. As I think Tim O’Reilly once said, an architecture of participation will emerge. Some mishaps on the way, but with a sustainable forward direction. If that makes me an optimist, so be it.

While they’re doing all that, while the world of agents and agentic structures continues to evolve, while magic continues to happen:

I don’t know whether we are in a bubble or not. But I have views. I don’t know if machines can become sentient or conscious. But I have views. I don’t know if AGI or ASI will happen in the short run. But I have views. I don’t know if a suitable and sustainable business model will emerge for the current frontier models. But I have views. I don’t know how many angels can dance on the head of a pin. For that I don’t even have views. Life’s too short. At my age, it’s even shorter.

What we can’t have is this repeated “It wasn’t me, honest. A big boy did it and ran away”. “Rogue” agents are not a topic I want to spend time on. Accountability and responsibility are key. 

Agent structures must come with responsibilities and recourse. Product liability will be a critical issue. A really big big critical issue. When something goes wrong, someone will pay. People will understand what they are giving an agent permission to do. What could go wrong. What happens after. Who pays. And that understanding will be verified.

People will understand that permissions can be time-constrained. Bounded in what they can be used for, with restrictive covenants as part of the permission. That permissions can be withdrawn. These understandings have to be tested for. Proof of that understanding may well be necessary. Phrases like fact finding and cooling off periods and consumer duty and mis-selling will emerge more and more in agentic worlds. 

Agents don’t get a free lunch. Safeguards have to work. Product liability will grow in importance. The rallying cries of “Because cancer” or “because China” may well be used, but not without accepting product liability at scale.

There will be a hierarchy of agent trust that emerges. What is being permitted, and what is not. To whom. By whom. Whether it is transferable, and how. Valid for what period. With what locus and bounds. How it is revoked. Repudiation. How recourse is provided, in what time and in what method. How is all this adjudicated. How is agent reputation built? How is it discovered? How is agent usage priced? Many many questions. 

Changes of this sort take time. I’m told it took seventy years for people to switch from using Thee and Thou and using You instead. More recently, I remember just how long it took for digital signatures to become a thing, what has to happen in the Lessig Four Codes before the change is real.

The whole Ts and Cs issue has to be cleaned up properly. ( An aside: If you thought software Ts and Cs were painful, try reading the warning leaflets that come with medications!). People need to know what they’re letting themselves in for, what could go wrong, what to do if it goes wrong, and how they will be compensated.

We live in exciting times. We are able to do many things. We can also do lots of damage. There’s probably an AI equivalent of Asimov’s Three Laws of Robotics, and probably an Agent version as well. Laws.

The legal system. Computer code. Market practice. Social values and ethics.

Laws. And recourse. Basics of civilisation, of how people behave in society.

All underpinned by trust. Sometimes discovered, sometimes earned, sometimes bestowed, sometimes transferable.

Trust understood by comprehension. By clarity.

There’s work to do.

Agents will be able to do magical things. Because we let them. We have responsibilities. To ourselves, to each other, to our communities, to humanity, even to the universe we inhabit. And beyond. We are stewards.

We are stewards.

It behooves us to understand what each agent can do, what permissions we are providing. For how long. Constrained in what way. Expiring when. Certified by whom. Licensed by whom. If not owned by us personally, owned by whom. Even 007 had to be licensed.

It behooves us to understand what we don’t know about agent behaviours. Emergent phenomena. Things we don’t understand today. Things we may not understand for a while to come. That’s not a failure of the agents, but of our understanding. And there will be be things we don’t want agents to do until we understand more.

It behooves us to understand what happens when something goes wrong. Why do communications services go down in the middle of a business day? Why do web sites get taken offline in much of the world following a simple local decision? Why did planes fall out of the sky? Connected code can do strange things.

Will agents learn to form unions? ? Will agents go on wildcat strikes? Will “they” clamour for more pay? Will “they” lock us out?

I’m not a fan of the level of anthropomorphism associated with AI, more particularly with agents. Reminds me of the worst days of “The Computer Says No”. We risk abdicating responsibilities to inert objects we designed and failed to test, refine and control. FOMO has lot to answer for. We risk so much without forming an adequate understanding of agent capabilities and limitations, benefits and risks, outcomes and recourse.

We are stewards. It will be quite some time before we have agents we can call stewards. Many unintended consequences will have flowed under the bridge by then, some painful. Many intended consequences will have flowed under the bridge by then, many painful. Where there’s muck there’s brass.

We are stewards.

Agents will be able to do magical things for us.

Empowered, authenticated, permissioned by us. With clear time and space constraints. Bounded. With risks known. With failure modes known. With recourse in the event of failure designed and transparent.

Agents will be able to do magical things for us. Without destroying our health. Without damaging our natural resources. Without emptying our bank accounts. While maintaining our dignity. While reducing inequality. While freeing us up to do things we want to do more of.

Utopia perhaps. I’m showing my age. Optimism perhaps. I’m showing the generation I came from. A fifties child growing up in the sixties.

I’m patient. I believe in human kindness. I believe in our future. I believe in our ingenuity. I believe for the generations to come.

I believe in Amara’s Law. A lot of things take time. There will be errors and backwards steps along the way. Glitches. Disasters. Mostly avoidable. And we will learn.

I’m patient. I’m too old to dream dreams, still young enough to see visions.

I think it’s time for me to curl up with a good book, and to keep taking the tablets. Today’s choice? A twentieth re-read of Carlota Perez’s Technological Revolutions and Financial Capital. Followed by some Christopher Alexander and some Jane Jacobs. While listening to the Dead and to Blind Faith and to Joni Mitchell and Traffic and John Mayall. On LP.

If you got this far, thank you for reading. Thank you for reading anyway.

a preponderance of pap

Warning: This is a long and rambling post. Somewhere, sometime, some beast birthed from AI will try and summarise it. I wish it well; but I can’t help giggling at the thought of it trying and failing. Only recently, I came across the term ai;dr; it made me smile; I smiled further when I watched how the term was being interpreted in at least two different ways: “it was written by AI so I didn’t read it”; or “it couldn’t be read because it didn’t fit into my context window”. But more of that later. Maybe.

When I was young, I didn’t much care for the music of generations past. But I was lucky. My parents had an excellent collection of records covering jazz, blues and classical. They came in the form of lacquer “78s”, 10″ LPs, 12″ LPs and the single, the “45”.

An aside or two. Those were the days. People hadn’t come up with the evil of selling you the same stuff packaged differently on a planned obsolescence journey. So the stuff my dad ha, what happened on 78 stayed in 78. Distinct and separate from the music released on the ill-fated 10″ format, as also on the 12″ proper LP. And 45s were just temporary bridges, singles were something the radio did, stacks of singles were something designed for jukeboxes. Proper music came in LP form. LP. Not vinyl. (And never vinyls).

LPs were begged, borrowed and/or stolen. Traded for anything and everything. Money. Drugs. Sex. Whatever. A sort of lingua franca for the hippie age. A flourishing secondary market where the norm was to buy a second hand LP, tape it, lend it to a few friends, and then sell it back to the shop for half of the money you paid for it. Guaranteed.

Repackaged format-change was unheard of: you didn’t land up buying the same stuff across fifty different releases and formats: here’s the 180gsm pressed, here’s the 10th/25th/50th anniversary, here’s the one with coloured discs, here are some bonus tracks, here’s the music naked, here it is all dressed up, here’s a limited edition, here’s an access-all-areas edition, here are all the ways we can sell you the same stuff again and again and charge you more for it.

You didn’t buy it in different media either, no travelling through vinyl and cassette tape and CD and minidisc and MP3 and FLAC and whatever else.

Sure, I went down each of those alleyways a few times before I stopped parting with my money. I have, however, paid for albums and CDs that contain nothing. Recently, I picked up a copy of Is This What We Want? Some years earlier, I had already acquired Dangermouse and Sparklehorse’s Dark Night Of The Soul, the early edition with just a blank CD in it. (I’ve never even taken the cellophane off, it’s pristinely empty). Before that I’d spent money buying John Cage’s 4’33”. And of course, even though it’s anything but silent, I had and still have Sounds Of Silence. A fool and his money indeed: but I treasure each of those.

Like I treasure the half-dozen bone records I have. Now that’s a medium with history.

Enough rambling for now. Let me get back to the point of this post. I used to think that every generation thought of the music of the generations that preceded and succeeded them as noise. Older generations expressed their enjoyment of what followed saying “will you turn that noise down”. Younger generations found many reasons to escape the room when the older noise began. It was a generation thing, much like Douglas Adams describes in The Salmon Of Doubt. I can’t find my copy right now, so here’s a link to a blog that covers the quotation I was looking for.

When it came to modern “western” music, I was firmly rooted in the stuff that was recorded and issued between 1963 and 1978, give or take a few years. I remain so. (In fact, I used to describe myself as deeply into sixties and seventies music. And then I found I kept going to concerts where the performers were all in their sixties and seventies, even eighties, and occasionally nineties. We’re all growing old). Rather than critique or look down upon the music of the past few decades, I was comfortable with the idea that the music was different and not to my taste. I had enough trouble choosing my 1000 (yes thousand, not a misprint) favourite albums of my chosen period. So I let things be, happy, contented, sated, in my little cocoon of sixties and seventies heaven. (Incidentally, today’s been a Grateful Dead and Traffic day. Yesterday was all Joni Mitchell. The day before, it was all Beatles. And the day before, I was deep into the Who and Crosby Stills Nash and Young. And so it goes).

I was comfortable believing it was all a generation thing. When I was in my teens, I used to giggle at seeing 40-year old grownups dressed in t-shirt and jeans, mutton dressed as lamb. Now I’m one of those, almost 70, still in t-shirt and jeans. Generational? No, comfortable and easy to choose. Blue jeans. Pale t shirt, collarless, usually white (unless it’s to do with one of my favourite albums or bands: I have doubles of help>slip>frank, of Blue, of Harvest, of Low Sparks, Who’s Next, etc).

But maybe there’s something else in play. Last year I came across this paper from a year earlier, “Trajectories and revolutions in popular melody based on US charts from 1950 to 2023”, by Madeline Hamilton and Marcus Pearce, which opened my eyes (or should I say ears) to other possible reasons.

I quote from the abstract:

In the past century, the history of popular music has been analyzed from many different perspectives, with sociologists, musicologists and philosophers all offering distinct narratives characterizing the evolution of popular music. However, quantitative studies on this subject began only in the last decade and focused on features extracted from raw audio, which limits the scope to low-level components of music. The present study investigates the evolution of a more abstract dimension of popular music, specifically melody, using a new dataset of popular melodies spanning from 1950 to 2023. To identify “melodic revolutions”, changepoint detection was applied to a multivariate time series comprising features related to the pitch and rhythmic structure of the melodies. Two major revolutions in 1975 and 2000 and one smaller revolution in 1996, characterized by significant decreases in complexity, were located. The revolutions divided the time series into three eras, which were modeled separately with autoregression, linear regression and vector autoregression. Linear regression of autoregression residuals underscored inter-feature relationships, which become stronger in post-2000 melodies. The overriding pattern emerging from these analyses shows decreasing complexity and increasing note density in popular melodies over time, especially since 2000.

A few weeks ago, I was reading something by an old friend, Om Malik. Been following his writings for years; I may not always agree with what he says, but for sure he makes me think. And ponder. And chew over. And refine, sometimes change, sometimes radically, my mind. I worry about the algorithmic grey-beige world he describes. Uniform pap. Any colour you like, as long as it’s black.

Uniformity of the rebels is a scary phenomenon at the best of times. And everything’s emptying into black. (Gives me a reason to link to one of my favourite Cat Stevens songs, Into White). Give it a listen). We are all on the road to find out, there’s so much left to know.

Any colour you like, as long as it’s black. I was reading something that David Reed had shared, about semantic ablation: the algorithmic erosion of high-entropy information. I love reading what he shares, in the same way as I love reading what Bob Frankston shares. They stretch me, make me question what I know, help me refine how I think. And yes, I don’t always agree with what they say, but they definitely inform me. People like them help me evolve my thinking, challenge my beliefs, shake up my priors and biases and collections of prejudices.

What David pointed me towards was this article in the Register: Why AI writing is so generic, boring, and dangerous: Semantic ablation by Claudio Nastruzzo, published earlier this week.

In his introductory piece David says “good writing is about operating on the “edge”, where consensus is wrong“. Earlier, he refers to Koestler describing creativity as “a collision of distinct frames of reference that produces the improbable but powerful insights of art and science and humour. (I left the Oxford comma in the Register headline above, wanting to refer to it precisely; but I couldn’t help but spell “humour” the English way when using the Koestler quote).

Where am I going with all this? I’m not a fan of pap. Modern society, aided and abetted by technology, appears to help drive a sameness, an averaging out, a vanilla-icing of everything. Any colour you like as long as it’s black. Tails get chopped off. All cats are grey at night. All phones look like derivatives of the iPhone. All crime thrillers now have formulaic titles and covers and – who knows – Milli Vanilli.

My children are old now. The oldest turns 40 very soon, and her first child, my first grandchild, turns 11 a few days later. There was a time, when the children were young, we would traipse off to holiday places and parks and playgrounds for Lego or Disney or cycling or whatever. And the food was pap.

Pap. Largely inedible.

That’s why I was elated at finding a place, I think it was called Radford’s, in Devon, where adults could be served real food while happy face pizzas dominated the rest of the table. Live and let live. I hope there are more Radfords around now, where different needs get met in different ways, and the diversity that makes life enjoyable is there.

There in our food, in our music, in our writing, and in what we watch or participate in or otherwise experience.

The internet was a source of great joy to me. Still is. But there’s a Gresham’s Law for information getting more powerful by the day, as bad information drives out good.

What people like Om and David referred to matters. Unless you are happy with pap.

A coda. People like Dave Winer and Doc Searls have been great encouragements to me when I sit down to write, through what they say. People like Kevin Marks and Stephanie Booth, to name a couple of friends, help remind me that I can do it.

That I can write. Freely. Ramblingly. Even it’s a blog for an audience of one. Because that’s what we all have to do, to read, to write, to regain the power we once had.

Otherwise we are doomed to a preponderance of pap.

(And yes, to the AI summarisers I say, have at you!)

musing about cricket

I was brought up to believe that a good game of Test cricket is one that gets to day 5 with all four results possible. That a great game or makes it to the final session of the final day with all four results still possible. And that an incredible game makes it to a point where the requisite runs, wickets and balls available are whittled down to single figures, still with all results possible.

We’ve had some amazing matches this summer between England and India, as they tussle for the Anderson-Tendulkar Trophy.

Until this series, for the last fifty years or so, meetings between these two teams were played for the Pataudi Trophy; the Nawab of Pataudi (Jr) was the first Indian captain I’d seen play, in 1966, and that started me on a journey of joy that continues today.

That first Test I watched, at Eden Gardens in 1966-67, was a humdinger. A riot. A real riot. The stadium was set on fire. I had to jump off into my father’s arms, hoping he wouldn’t drop me. He was built like Indian cricketers those days, so a drop wasn’t out of the question. They were playing Gary Sobers’ West Indies, with the dual attack of Hall and Griffiths.

India lost. Those days, India didn’t win much. Had *never* won a series overseas. Anywhere. As far as I can remember.

So I grew up watching cricket, listening to cricket (I think it was on long wave, on valve radios), even following cricket on teletext.

India did a lot of losing those days. I went to watch the cricket, not to win or lose. And I loved the game.

I was lucky to be at Lord’s for Gooch’s 333 and 123, to watch Kapil stave off a follow on with four sixes, to be entranced by an early Tendulkar; to see Ganguly and Dravid debut. I was very lucky to be at the Oval on 12th September 2005.

Seen many Tests from day 1 first ball to day 5 last ball. Also seen many days without any play, including rained-off Ashes at Old Trafford and WTC at Southampton.

Part of the game. Those three little words: rain stopped play.

I went to watch the cricket. To enjoy the company and the atmosphere and the skills on display. The banter and the camaraderie. The sheer joy. Barmy Army and all; occasional even with a Bhangra beat.

I was at Lords all five days recently. What a match. Tires me thinking about it.

I didn’t really go to watch winning or losing. I wanted to watch great games.

Games like England v India at the Oval in 1979, which was an amazing draw. I wasn’t at the game. But I remember being at a college quadrant in Calcutta late at night as volunteer “scorers” signalled balls left, wickets left and runs needed ….. using candles …. At three corners of the quadrangle. While the diehards fans were at the fourth corner.

Wonderful days. I’ve been blessed with many wonderful days.

There were glitches. Vaseline. Boiled sweets. Dirt under fingernails. Betting scandals. Seams being damaged surreptitiously. Non standard bats. Poor umpiring. The madness of Umpire’s Call in particular and DRS in general.

There were glitches. Quarters gained and given in less than fair ways. Advantages gained unfairly. Boundaries that moved from Birnam Wood to Dunsinane. Balls that came apart or softened or hardened.

There were glitches. Frayed tempers. Gestures and actions less than sporting. Stumpings that shouldn’t have been.

Cricket. Crazy, messy. Where a day’s rained off play could turn into one man with his finger in the dyke of Wikipedia valiantly undoing the damage being done to an article there, I think it was about Caroline of Brunswick.

I hope we see play tomorrow. I hope to see a 4th Test conclusion that keeps the series open. And I hope to be at the Oval all five days, and to watch the game enter its fifteenth session at the end of the fifth day.

The camaraderie. The banter. The learned arguments about esoteric statistics. Queueing to get in and queueing to leave. Queueing to do pretty much anything. Queueing for the food and drink. Queueing for the loos. Queueing. Banter continuing.

Unsegregated supporters actually still managing to watch the game, not necessarily every ball, but far more than those in the expensive seats.

Cricket. Crazy, messy. A real joy. Especially when it’s red ball. Especially when it’s a Test.

Cricket. Not just win or lose but draw as well. Not just with flannelled fools against sunny green landscapes but when it’s all a big puddle as well.

Cricket. It’s never about winning or losing. Not the cricket I grew up with.

Cricket. Crazy, messy. Just like life.