Yasir Qureshi
Menu

Writing

Seven essays about the trust problem around AI agents.

They started with a Chrome extension I decided not to build.

The argument moved from there. Agents have too much access. The people expected to control them are mostly given tools built for developers. And the institutional part keeps getting treated as something to solve later.

I do not have a complete answer. The essays are me trying to work one out.

The essays

  1. 01The Trust ParadoxAgents are hired for autonomy and distrusted for the same reason, and both instincts are right.5 min
  2. 02Agents Without an OSWe run powerful digital workers with nothing like user accounts or an audit log.4 min
  3. 03The Takeout ModelSeparate the order from the cooking and most of the threat surface disappears.5 min
  4. 04The Operator Is the BuyerThe person who runs the agent is the real customer, and almost nothing is built for her.6 min
  5. 05The Threat SurfaceEverything an agent reads is input, and most of it never came from the user.8 min
  6. 06Continuous EducationAn agent workforce needs drills and recertification the way pilots do.6 min
  7. 07The Institutional LayerTrust at scale looks like paperwork, and that in my humble opinion is a feature.7 min

Where Tanaka came from

Tanaka began in essay four. I needed a person to explain who agent infrastructure is actually for, so I imagined an IT administrator at a regional bank who had no interest in writing YAML at 2am.

Then I used AI to make a small version of the console I thought she would need. That project is here.