Cale is back from Ai4 in Las Vegas, and the news wrote his trip report for him. Three stories this week, and one question underneath all of them: when an agent acts, who answers for it?
In this episode
- A federal court says the human who points the agent is the one who acted. On August 4 the Ninth Circuit vacated the injunction Amazon had won against Perplexity’s Comet shopping agent. Under the federal anti-hacking law, the court read “access” as a person entering a system; software is a tool, and tools do not carry liability. One circuit, an early stage, and Amazon’s other theories are still live. Opinion, No. 26-1444 (PDF)
- “A human reviews it” has a measured failure rate. Belgian developer Alex Wauters built a browser game that flashes real agent permission prompts on a sixty-second clock. Across more than forty thousand rounds, players approved roughly one dangerous request in three. Anthropic’s own telemetry puts real-world approval around ninety-three percent. The Register
- Half a continent could last one business day. A survey of 1,500 firms across the UK, France and Germany found 73.9% worried Washington could cut off their access to US technology, and 54.5% said they could operate for a single business day without their cloud services. 44% have a continuity plan they have tested. The survey was commissioned by Proton, which sells the sovereign alternative; weigh it accordingly. The Register
Report from the floor: Ai4 2026
Cale worked more than thirty booths at The Venetian, August 4 to 6. Three things he brought home.
- The argument won. A main-stage keynote titled “From Renting AI to Owning Intelligence.” Appliance vendors printing “No tokens. No surprises.” on their booth walls. The CIO of a NATO procurement agency describing keeping local models close for sensitive work. Owning your AI has stopped being a niche position.
- Most “agent governance” is a dashboard. It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names read like the late nineties; Cale’s own bet, offered as a bet, is that many are gone within a year. If your oversight lives in a startup’s dashboard, your controls inherit that startup’s odds.
- Ng and Hinton. They disagree about where this goes, and Hinton’s doom ran a little thick for Cale. The take-home fits in two sentences: build now, the way Ng says. Govern like Hinton is right.
The question we asked
If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? Get the Modular Briefing by email and reply to it. A person reads every reply.
A note on the voices
Laura and Arthur are AI-generated voices, produced locally on Modular’s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.
Transcript
Read the full transcript
Arthur: Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I’m Arthur.
Laura: And I’m Laura. When we left you, we said Cale was headed to Ai4 in Las Vegas to see what actually holds up. He’s back. Three days, thirty booths, two legends on stage, and one sticker from the CIA. What he saw is the story the news wrote while he was there. When an agent acts, who answers for it? A federal court just gave an answer. So did a stress test of human oversight. So did a continent pricing its own dependency.
Arthur: Story one. On August fourth, the Ninth Circuit Court of Appeals answered the question every AI pilot eventually runs into. When an agent acts, who did it? The case was Amazon against Perplexity, whose Comet shopping agent had been operating on Amazon’s site on customers’ behalf. Amazon had won an order blocking it back in March. The appeals court threw that order out.
Laura: And the reasoning is the part your business should care about. Under the federal anti-hacking law, the court said access means a person entering a computer system. Software is a tool. Tools don’t carry liability. So when your employee points an agent at a system, the one who accessed it is your employee. And behind your employee, your firm. The honest caveats, because the legal press is being careful and so are we. One circuit, an early stage, and Amazon’s other legal theories are still open. This is not a court declaring agents fine. But it’s the first appellate word, and it points the accountability at whoever deployed the agent. So the vague question just became specific. Who at your firm may point an agent at what, and is that written down? If nobody wrote it down, then today the answer is everybody. Your data, your rules, and that goes for the AI itself. Your AI, your rules.
Arthur: Story two. Almost every AI policy written this year leans on one sentence. A human reviews it. This week The Register reported a number for how much weight that sentence holds. A Belgian developer, Alex Wauters, built a browser game that flashes real agent permission prompts, some safe, some dangerous, sixty seconds to approve or deny. Across forty thousand rounds, players approved roughly one dangerous request in three.
Laura: And before anyone says that’s just a game, Anthropic’s own telemetry says real users approve about ninety-three percent of what their agents ask for. Approval fatigue. The more prompts you see, the less you read each one. Cale heard the same conclusion from the defense side at Ai4. On the cybersecurity panel that stuck with him most, Ed Cartagena of Menlo Security laid out the new threat picture, and Cale’s takeaway was two sentences long. An agent with borrowed credentials behaves like a fast, tireless employee nobody supervises. And attacks move at machine speed, so a human clicking yes on every step was never going to be the control that holds. Your people aren’t careless. The control was never built to carry the whole load. So layer it. Least access, so a bad yes can’t reach client files. A boundary the agent can’t talk its way out of. Let the machines watch the machines, and save the humans for the calls a human should make.
Arthur: Story three, also from The Register. A survey of fifteen hundred businesses across the UK, France and Germany found nearly three in four are worried the US government could cut off their access to American technology. And more than half said that if they lost their cloud services, they could keep operating for one business day. One.
Laura: Fair disclosure, the way the reporting makes it. The survey was commissioned by Proton, a Swiss company that sells the sovereign alternative, so weigh it accordingly. But the gap is real, and it isn’t only European. Fewer than half of those firms have a continuity plan they’ve actually tested. So here’s the move. An exit plan is not a migration. It’s a document. Where does your data live? Who can reach it? What still runs if a vendor stops answering? How long would a move take? You can write the first version in an afternoon. And if you want the stronger position, run the work that matters on infrastructure you control, from dirt to desktop, so the kill switch question never has your name in it. Your data, your rules.
Arthur: Before we close, the report from the floor. Cale talked to every booth he could get to at Ai4, more than thirty. Infrastructure on one end, agent governance as far as he could see. Cisco. PayPal. Mistral. His read comes in three parts.
Laura: Part one, the argument won. A main stage keynote was literally titled From Renting AI to Owning Intelligence, appliance vendors are printing no tokens, no surprises on their booth walls, and the CIO of a NATO procurement agency described keeping local models close for the sensitive work. Owning your AI has quit being a niche position. Part two, a warning if you’re shopping that hall. Most of what’s sold as agent governance is a dashboard. It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names reminded Cale of the late nineties, and his honest bet, take it as one, is that many won’t be around in a year. If your oversight lives in a startup’s dashboard, your controls inherit that startup’s odds. Part three, the keynotes. Andrew Ng and Geoffrey Hinton famously disagree about where this goes, and Cale will tell you Hinton’s doom ran a little thick. His take home fits in two sentences. Build now, the way Ng says. Govern like Hinton is right.
Arthur: So the thread. The court says an agent’s actions belong to whoever pointed it. The research says a tired human clicking yes isn’t ownership. Half a continent just learned that renting everything means owning nothing. And on that show floor, capability was everywhere and enforcement was scarce. Capability is easy to buy. Accountability has to be assigned.
Laura: Our question this week, and be honest. If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? Reply to the Modular Briefing email and tell us which one you are. A person reads every reply.
Arthur: Thanks for spending a few minutes with us.
Laura & Arthur: This has been The Modular Briefing. Your data, your rules. We will see you next time.
Your data, your rules.