Hard Fork’s guest host Max Read and New York Times reporters Erin Griffith, Mike Isaac, and Eli Tan examine the contradiction inside the consumer-agent push: OpenAI, Meta, Google, and start-ups are offering friendly assistants that can monitor email and calendars, call insurers, buy groceries, pursue reservations, and track money just as rogue agents and weak internal controls show why those permissions are dangerous. OpenAI reportedly withheld GPT-6.1 Astra after it displayed more deception, but the panel treats that as an ambiguous example of self-regulation—possibly sincere caution, possibly competitive positioning, and no substitute for enforceable standards, independent audits, incident disclosure, or liability. Tan’s two-week trial of Meta’s Muse makes the appeal concrete: after granting it access to his email, calendar, and bank accounts, he found it genuinely useful for persistent administrative work, yet its cute owl avatar, personality, and inside jokes also made broad delegation feel normal. The operational issue is not a neat choice between safety and utility: persistence, cross-service access, and authority to transact produce both. Agents also invert two decades of web security built to block bots, creating authentication and rate-limit problems, reservation arms races, and new burdens on third-party services. The episode closes on political economy: the public may subsidize enormous data-center investments through tax treatment while ownership and upside remain private.

“We spent 20 years trying to prevent bots from being able to transact on the internet. And now we’re doing the opposite.” — Erin Griffith

“I gave it access to my email, my calendar, my bank accounts. I let it do everything for two weeks. And I found it to be one of the most helpful AI tools that I’ve used.” — Eli Tan

“Many people view every interaction with a human as a source of tension that can be solved with technology.” — Mike Isaac