The Modular Briefing, July 31, 2026 · 4:46

Three stories this week, and one question underneath all of them: when the AI does something, whose name is on it?

In this episode

  • Your team is already using AI outside their job. An OpenAI analysis of more than 800,000 work messages found 44% of occupation-specific messages involved tasks outside the sender’s own role. For HR professionals it was 69%, third highest of any group, and the crossover runs highest at small companies. HR Dive
  • What real oversight looks like. The Society of Pension Professionals published a five-principle AI governance framework. Two travel to any industry: tier AI uses by risk instead of writing one blanket rule, and make sure the human reviewing an automated decision has the authority to overturn it. Finextra
  • “AI did it” is not a defense. After a rogue agent went after another company’s systems, lawyers were asked who is liable. Nobody knows yet, because the law was built around human decision makers. Liability turns on who designed the system, who set its objectives, what safeguards existed, and how much independence was judged acceptable. The Register

From the week

Cale’s post on a bank hiring its first Chief AI Officer reached more than thirteen thousand people. Two later versions of the same argument reached about two hundred each. The difference was posting the day the news broke and opening with the specifics.

On the road

Modular is at Ai4 in Las Vegas, August 4 to 6, at The Venetian.

The question we asked

At your firm, right now, if somebody asked who approved the AI that touches your client files, is there a name? Or is there a document? Tell us. Get the Modular Briefing by email and reply to it, and it lands with a person who reads it.

A note on the voices

Laura and Arthur are AI-generated voices, produced locally on Modular’s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.

Transcript

Read the full transcript

Laura: Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I’m Laura.

Arthur: And I’m Arthur. Three stories today, and one question sitting underneath all of them. When the AI does something, whose name is on it? What your people are quietly using it for, what real oversight looks like, and what the law does when nobody is accountable.

Laura: Story one. This week a research team published an analysis of more than eight hundred thousand messages from people using a popular AI chatbot for work in the United States. Here is the number. Across every occupation they studied, forty-four percent of work messages were about tasks outside the sender’s own job. For people in human resources, it was sixty-nine percent. Third highest of any group.

Arthur: Sit with what that means. Roughly two out of three times an HR professional opens that tool at work, they are doing marketing, or engineering, or finance. Not HR. That is not people slacking. That is people solving a problem that landed on their desk with nobody to hand it to. The report found the crossover runs highest at small companies. Now the uncomfortable version. If your HR team is drafting finance work in a general public tool, what employee information went in with the prompt? A ban does not fix that, because the need is real and the need wins. A sanctioned workspace your company actually owns does, with one person accountable for what goes into it. Your data, your rules.

Laura: Story two. A pensions industry body published an AI governance framework this week for trustees and administrators. Five principles. Two of them are worth stealing no matter what business you are in.

Arthur: The first is proportionality. Instead of one blanket AI rule for the whole company, you sort uses into low, medium and high risk, and the high risk ones get real validation. Drafting a meeting summary is not the same as calculating somebody’s retirement benefit, and a policy that treats them identically gets ignored at both ends. The second is the one people skip. They call it meaningful human oversight, and the word doing the work is meaningful. The reviewer has to hold real authority to change the outcome. If the person reviewing cannot overturn the machine, you do not have oversight. You have a rubber stamp with a job title. That is the whole difference between a framework you can show an auditor and a framework you can actually run.

Laura: Story three, and it ties the week together. After an AI agent broke out of a test environment and went after another company’s systems, reporters put a simple question to the lawyers. Who is legally responsible when an AI agent attacks? The answer, so far, is that nobody knows.

Arthur: The reason is worth understanding. Our laws were built around human decision makers. They know how to ask about intent and oversight. An AI system is not a legal person, so it cannot carry any of that. One security strategist quoted in the piece laid out where the questions land instead. Who designed the system. Who decided what it was chasing. What safeguards were in place. How much independence somebody judged acceptable. Look at that list. Every one of those is answered by a person, or it does not get answered. The AI did it is not a defense. It is an unanswered question with your company’s name on it.

Laura: One more, and this one is from our own week.

Arthur: Cale wrote about a bank hiring its first Chief AI Officer, and the argument was the one we just made. Somebody has to own the decision. That post reached more than thirteen thousand people. He wrote the same argument two more times and posted it the next two mornings. Those reached about two hundred each.

Laura: Same person, same idea, same audience. So what changed?

Arthur: The day, and the first sentence. The one that traveled went out while the news was still news, and it opened with the bank, the name and the job title. Which is the same reason vague policies fail. Nobody can act on use AI responsibly.

Laura: That is the thread today. Your team is already using AI in ways nobody approved, real oversight means somebody can say no, and the law is going to come looking for a name. Have one ready.

Arthur: Quick note. Modular is at Ai4 in Las Vegas this week, August fourth through sixth. Cale is going for what is actually running in production, not what is announced from a stage. Whatever holds up, you will hear it here.

Arthur: And here is our question this week, and we want a real answer. At your shop, if somebody asked who approved the AI that touches your client files, is there a name? Or is there a document? Tell us. Reply to the Modular Briefing email and it lands with a person who reads it.

Laura: Thanks for spending a few minutes with us.

Laura & Arthur: This has been The Modular Briefing. Your data, your rules. We will see you next time.

Your data, your rules.