Human in the Loop Episode 26 thumbnail: AI is getting its own POLICE FORCE??
EP 26October 6, 20267 min read

AI is getting its own POLICE FORCE??

PodcastAI AgentsAI SafetyPrivacy
MW
Matthew J. Wozniak
October 6, 2026 · 7 min read

OpenAI's Dots can lose access to an app and still remember what they learned. My take on that, the outside-watchdog and White House stories around it, and why memory is the product. Companion notes to Human in the Loop Episode 26.

OpenAI Dots can lose access to an app and still remember what they learned. Oscar tried one. Was it worth connecting?

That question opened Episode 26, and it turned into a longer argument than either of us expected about vendor dependence, who controls the brakes on an agent, and why a useful assistant can still leave you uneasy about the company behind it. The title's "kill the agent" is shorthand for delete or reset the Dot. Pause stops its work. Disconnecting an app does not erase information it already obtained. Keep those three straight and most of the confusion goes away.

Signal or Noise

Oscar and I run every story through the same filter: is this signal you should act on, or noise dressed up as news? Here's how the week looked from my side of the table.

OpenAI's Dots

Oscar's first-use reaction was underwhelming, and we spent real time on whether the subscription is worth it. The $500 a month Pro tier is the headline number, but $500 is not a standalone Dots fee, and Dots is also available on eligible lower Pro tiers. We also got into local AI as the alternative and the dot.com address that now redirects to Grok Bot. For me the interesting part isn't the price. It's what the product keeps after you stop using something. Signal.

Nvidia's outside watchdog

Nvidia is pitching a safety control that sits outside the agent. I like the idea. A prompt is not an access boundary, and a rule the agent can switch off isn't much of a rule. But we kept circling three questions: who controls the safety hardware, what happens if it fails, and whether a tool like this turns into a vendor restriction on what you're allowed to run. Signal.

The White House accord and the "Super Intelligence Force"

A voluntary accord, then a reported task force. We were skeptical about auditing: a commitment is not a completed audit. We also talked about government expansion and, I'll admit, wandered into a detour about the name. The useful question for builders is the same as always: who can actually stop a release, and what authority sits behind the promise? Signal.

Gemini 4 Argon

Restricted access, benchmark skepticism, model-release fatigue, and, naturally, name jokes. Argon is a noble gas. It barely reacts to anything. Neither Oscar nor I tested it, so I'm not going to tell you it's good or bad. I'll tell you not to rebuild your stack around a model you can't get yet. Noise.

No Jargon Required

This week's segment was two ideas behind the controls in the stories above.

Access revocation vs data deletion. I explained it with a key and a notebook. Take the key back and the assistant can't come in again, but the notes it already wrote are still in the notebook, and any copies that already left the building stay out there. Revoking access stops the next thing that can happen. Deleting data removes what already happened. Those are two different jobs, and a good product tells you which one a button does. The conversation then wandered into smart TVs, advertising and some surveillance speculation, which I'd call a feature of recording with Oscar.

Out-of-band control. Oscar covered this one with a lift brake, a referee and a blocked file transfer. A control that sits outside the system it's watching doesn't have to take the system's word for what happened. We argued about the verbs, too: watch, warn, block, or kill a process? Then came the second-agent critique, the dog "bonk" analogy, and my question about layered controls.

My unpopular opinion: memory is the product

Memory is the product. An assistant that forgets everything the second you unplug it is a worse assistant, so the controls that cut against the product are the ones that end up clunky.

I can't prove that's by design. OpenAI documents how this works on a public help page, and I'm not claiming anyone is hiding anything. But when a control is messy in exactly the place the business benefits, I stop assuming it's an accident. We've seen versions of this before. Google's location settings drew a settlement from 40 attorneys general. The FTC went after Twitter over phone numbers collected for security. It went after Facebook over privacy controls. Amazon Prime's cancellation flow became a $2.5 billion settlement. Those are other companies' past cases, not evidence about OpenAI. They're why I look at what a product is built to keep.

A Dot is built to keep context. The longer you use it, the better it knows you, and the harder it is to leave. If clearing the memory means deleting the assistant you've been teaching, that's a switching cost. I can't tell you it's deliberate. I can tell you which way the incentive points.

Oscar's take went the other direction: give agents a budget for being wrong, measure the failures, and improve their tools. I agreed, within limits. Scoped development environments, yes. Production boundaries, no. That's where we landed: give agents real access, and keep the brake.

Along the way

We also talked about getting an agent notification in the middle of a family visit, coding as a craft versus building solutions, and why clicking Approve all day can erase the benefit of delegation in the first place.

So here's my question for you: which agent action do you still approve by hand, and why?


Human in the Loop — Watch on YouTube · Listen on Spotify · Listen on Apple Podcasts

Every episode — full show notes, sources, and the archive — lives at podcast.vallyseed.com. The show is produced by VallySeed, where Oscar and I help organizations design, build, and deploy AI systems that create measurable competitive advantage.