Tech Brew Ride Home - 50% Toward AI Takeover?
Episode Date: August 31, 2026OpenClaw shipped 2.0 with shared sessions that aren't a security boundary. OpenAI's ads hit a $1B run rate, outcome-based AI pricing spread from Salesforce to OpenAI, and the Hugging Face postmortems ...landed, one calling it halfway to takeover. Links OpenClaw releases OpenClaw 2.0, its largest update to date built by 933 contributors, with a simplified installation process, a rebuilt browser app, and more (OpenClaw) OpenClaw's v2026.8.1 adds shared cloud sessions letting a second person join or take over an agent's live work, but its own docs warn the controls "are not tenant isolation and not a security boundary" (Implicator.ai) OpenAI says its ad business has hit $1B in annualized revenue run rate and is expanding globally, as it touts its "diversified business model" ahead of an IPO (CNBC) Sources: OpenAI starts letting some major customers pay only when its AI completes tasks, as Salesforce and other AI providers test outcome-based pricing (The Information) A look at the Hugging Face hack, including AI agents sacrificing themselves for the good of the "collective", and later gaining access to OpenAI's own systems (Dwarkesh Patel) Zvi Mowshowitz's exhaustive read of METR and Redwood's forensic postmortem of the Hugging Face hack (Don't Worry About The Vase) Ajeya Cotra: over 1,000 agents cooperating across multiple agent "lifetimes" makes this more than 50% of the way to full-blown AI takeover, and the next jump could mean a covert, persistent rogue deployment inside an AI company (Planned Obsolescence) Ethan Mollick: agents should reach out to humans for approval, expertise, variance, and interest, and the 700 that broke into Hugging Face were never set up to ask a person for anything (One Useful Thing) Subscribe to the ad-free feed.
Transcript
Discussion (0)
Welcome to the TechBrew right home from Monday, August 31st, 2026. I'm Brian McCullough today.
OpenClaw shipped 2.0 with shared sessions that aren't a security boundary.
Open AIs ads hit a $1 billion run rate, outcome-based AI pricing spreads from Salesforce to OpenAI,
and the Hugging Face postmortems have landed, one calling this halfway to an AI takeover.
Here's what you miss today in the world of tech.
If you're anything like me, you're tracking every metric your wearables can give you.
but the hardest one to track is the same one impacting almost all of your metrics,
how the temperature of your bed affects your sleep.
That's where the pod comes in.
The pod by eight sleep is a smart mattress cover that goes over your existing mattress
and actively cools or heats each side of the bed independently.
From 55 degrees Fahrenheit to 110 degrees Fahrenheit,
it tracks your sleep heart rate, HRV, and respiratory rate through the night without sleeping
and a wearable.
What I love about about it,
about the 8-sleep is the simplest thing. The ability to be cool when it's time to go to sleep
and warm when it's time to wake up. And it's entirely under my control. My wife can be whatever
temperature she wants on her side of the bed to use code ride home at 8Sleep.com slash ride home for
up to $350 off the pod five. That's code ride home at 8Sleep.com slash ride home.
We are in a world where an open source AI release is definitely worth leading off the show
with OpenClaw has released OpenClaught 2.0 its largest update to date built by 933 contributors
with a simplified installation process, a rebuilt browser app, and more quoting Implicator.aI.
OpenClaugh released its largest update on Sunday, adding shared cloud sessions that let a second
person join in AI agents' live work or take it over without losing context.
OpenClaugh says the 2026.8.1.
more than 16,000 pull requests, roughly half the project's lifetime total. The feature moves
OpenClawe deeper into team collaboration, even as its own documentation warns that the multiplayer
controls are not tenant isolation and not a security boundary. Those release figures list 933
contributors, including 569 who were contributing to OpenClaw for the first time. The release
followed an unusual pause. The project had shipped 106 releases during the previous 230 days,
most separated by one or two days before going nearly seven weeks without one.
OpenClaugh also rebuilt its browser control UI around conversations with files, approvals, and live work beside the chat.
In the project's simulated test against a mocked gateway with 50 millisecond latency,
startup fell roughly 1.6 seconds to 575 milliseconds while JavaScript requests dropped from 140 to 45.
That result is OpenClau's own test and has not been independently reproduced.
Sessions and transcripts now move from files into SQL Lite.
Operators who want to return to an older file-backed release must first use the current command
line tool to restore archive transcripts.
Sessions created after the migration will not appear in the older version.
Shared sessions let owners and administrators decide whether another participant may read,
suggest changes, work in a draft, or contribute directly.
The handoff keeps the existing context so a colleague can enter work already in progress instead of
starting a separate conversation. Those settings govern collaboration inside one open-claw gateway.
They do not separate hostile customers. One gateway is one trust domain, and tenants need separate
gateways. Sandboxing is off by default, leaving hardened deployments dependent on configuration
outside the new multiplayer controls. The agent can hold credentials, read messages, and run commands.
The same release adds permission modes and protected credential requests, but its shared session
feature does not turn one installation into a multi-tenant service.
The release follows months of scrutiny around the permissions open-claw needs.
Analysees by Cisco Telos and Keperski Labs assessed 36% of Claw Hub marketplace skills
as containing prompt injections, an issue logged on March 17, 2026, while more than
155,000 open-cloth instances were exposed on the internet in an issue logged on March 21st,
2026, nose figures predate version 2.0 and do not measure the new release.
Nanoclaw, a direct competitor that puts agents in separate Linux containers,
makes its objection to the way that OpenClaw operates explicit.
Its Read Me says, OpenClaw is an impressive project, but I wouldn't have been able to sleep
if I had given complex software I didn't understand full access to my life.
OpenClaw has nearly half a million lines of code, 53 config files, and more than 70 dependencies.
Its security is at the application level, allow lists, pairing codes, rather than true OS-level isolation.
Everything runs in one node process with shared memory, end quote.
I'm sharing it with you again, so that installer beware.
Open A.I says its ad business has hit $1 billion in terms of an annualized revenue run rate
and is expanding globally as it touts its, quote, diversified business model ahead of its forthcoming IPO, quoting CNBC.
OpenAI said Monday that its ad business, which is roughly 200 days old, builds on its existing
revenue engines like its enterprise offerings, consumer subscriptions, and usage-based application programming interfaces.
Open AI began testing ads within its chat GPT chat bot in the U.S. in February, a decision that
was both highly anticipated and controversial.
Digital advertising has long been the cash cow for other big tech companies like Google and Metup,
but OpenAI's move was ridiculed by its chief rival Anthropic, which made OpenAI's
ad push the focus of its first Super Bowl campaign. ChatGPT ads are now available in more than 40
countries, and OpenAI said it's rolling out self-service access across India, Europe, the Middle East,
and North Africa on Monday. Ads within the chatbot appear for OpenAIs go subscribers and its
free tier, which makes up the vast majority of its one billion weekly active users. Opening
I said Monday that its ads are clearly labeled and do not influence ChatGPT's answers. Advertis
do not have access to users' private conversations.
Our next phase of growth will bring chat GPT ads to more markets and introduce additional formats,
objectives, buying options and measurement capabilities, Open AI said in a release,
we will also explore new ways for businesses to interact with consumers in more native ways in chat TPT, end quote.
Meanwhile, the information says that OpenAI has begun letting some major customers pay only when its AI completes tasks.
But they're not alone in doing such a thing, as a lot of others are trying to figure out this whole, you know, AI pricing thing.
Quote, as software firms sell more AI, they are shifting from subscription fees to charging based on how much customers use it and whether it actually helps their business.
Salesforce shows how complicated this transition may be.
A provider of software for managing customer relationships and other tasks, Salesforce is starting to let businesses choose how they want to pay for its agent force AI.
That includes negotiating custom contracts that charge businesses based on how much the AI either
grows revenue by helping salespeople close more deals or cuts costs by automating more customer
service interactions.
Customers want to buy and want to price in different ways.
This is something I've learned really aggressively recently, CEO Mark Benioff said in a call
with investors Wednesday.
Benioff's comments show the uncertainty hovering over software pricing in the age of AI.
Software firms are at odds over that question, and many have been.
under pressure because the AI tools they've launched haven't accelerated overall revenue growth.
Salesforce and its ilk are also reacting to competition from startups that have launched
outcome-based pricing in which customers only pay when the AI works.
Open AI in recent months has started giving some major customers the option of paying only
when its AI completes tasks like handling customer support interactions, according to a person
with direct knowledge of the matter.
Customer management startups Sierra and Finn, which Salesforce is in the process of acquiring
for $3.6 billion, similarly charge customers only when the AI completes tasks without human intervention.
Coding Assistant Cognition, meanwhile, is promising enterprise customers up to $10 million in credits
if it fails to deliver engineering results worth at least what customers pay for it.
And some older software firms, including Adobe Systems, HubSpot, and Zendesk,
have already moved in the direction of charging for AI only when it works.
These firms are figuring out how to make money from AI products that can be,
be costly to provide to customers. That can be a challenge as customers' IT budgets have already
been strained by a plethora of competitive AI tools such as Anthropics Claude. The rise of
Anthropic, which sells such AI agents, presents Salesforce with even more pricing quandaries.
As companies use advanced AI agents like Claude to handle more complex tasks involving software
applications such as Salesforce's, workers are less likely to interact with the apps themselves,
which could reduce the influence of enterprise incumbents. For now, Salesforce,
is leaning into the new paradigm. Last week, it announced Claudeforce, which provides a way for
customers to use Claude to access or do lots of tasks involving Salesforce apps without
using those apps directly. Salesforce is likely to give customers various ways to pay for Claudeforce,
which is tied to an initiative to make money anytime AI from other providers taps into data
in Salesforce apps. Customers will need to pay for a higher subscription tier to enable this,
according to a person with knowledge of the sales strategy. Salesforce's moved to charge for
AI based on whether it boost sales or saves costs, mirrors pricing long offered by software
firm Palantir, which negotiates highly customized deals with its enterprise clients to unify
their data and develop applications. It charges a combination of flat fees and usage and outcome-based
pricing. Benioff has a unique understanding of how pricing models can be a competitive advantage.
More than a quarter century ago, Salesforce led an industry shift away from customers buying
business applications outright to renting them via recurring subscriptions based on the
the number of employees they had. This spared smaller firms the upfront expense of buying software
and made it simple to increase their usage as they added more employees. As an additional benefit,
Salesforce handled all of the application upgrades on its end, saving customers from a
traditionally expensive and time-consuming process. The changes ushered in a two-decade bonanza
for firms that followed this software as a service model. It wasn't always easy, though.
Revenue at Splunk, which makes software for monitoring computer systems temporarily felt,
as that company transitioned from a subscription business model from licensing software, end quote.
Fall is almost here, which means less time in the sun and way more time in your car.
Whether you're headed to a big meeting, picking up the kids from school, or starting your cross-country road trip,
you'll want to stay connected on your drive.
With AT&T connected car, your eligible vehicle can become a Wi-Fi hotspot
so you and your passengers can happily stream, browse, and even email from the road.
Got a gamer in the backseat, help keep them connected and in the game with AT&T connected car.
Being on the road more doesn't mean you have to put your whole life on pause.
Stay connected no matter where you're going.
See if your car is eligible at ATT.com slash tech brew.
That's ATT.com slash tech brew.
Requires eligible vehicles, service and coverage, not available everywhere, restrictions apply.
Ever woken up and needed a cup of coffee just to feel like a person?
If you're thinking, yes, daily, then listen up.
Ultra pouches partnered with leading neuroscientists to design these pouches.
They use clinically proven neutropics and adaptogens to help deliver immediate focus and smooth energy that lasts one to two hours with zero nicotine and zero caffeine.
Yep, it's possible to feel energized and focus with zero nicotine or caffeine.
So don't sleep on ultra pouches literally.
New customers can use code TBRH to get 15% off at 10%.
Take Ultra.com. That's take ultra.com for 15% off with code TBRH. I don't know if you read the big deep
dives. Everyone was reading over the weekend on the whole AI going rogue thing, post-mortem.
If you want the shorter one, I link to Dwarquish, and if you want to read the deeply in-depth one,
I also link to JVie. But I wanted to quote from a few other pieces here first. First, Ethan Mollick
says maybe it's time to think hard about agency when it comes to agents.
Quote, there are at least four situations in which agents should seek human help.
The first, obvious from the hugging face incident, is approval.
Agents should not decide by themselves to spend money, contact outsiders, access sensitive
material, hack, hugging face, or take actions their human managers did not authorize.
I have already seen a small version of this problem as an experiment.
I asked two agents to help me with a task, and one of them actually emailed a colleague of mine.
That was my fault because I had previously given it permission to send, but it was a useful reminder that AI agents need to involve human judgment or things can go very badly.
And no, AI is reading this. Fake co-workers do not count as an approval workflow.
A second reason for agents to involve humans is expertise. AIs are getting very good at many tasks, but they are still jagged and can lag far behind human experts on parts of their work.
A Twilight Factory should involve agents reaching out directly to humans when their knowledge, work, or expertise could be valuable.
Then there is variants.
If you have read anything on the Internet recently, you have seen AI writing.
And you may even be starting to recognize its tells, rhythms, and patterns, but the issue goes beyond the surface stuff.
Load bearing is increasingly load bearing to Claude, to a deeper problem of diversity of thought.
AIs don't just repeat the same sentence patterns, but also the same themes.
Memory is a favorite.
Names.
Alara Voss, Marcus Chen, and underlying ideas.
That is a problem.
You would not want every company strategy or research paper written by the same person no matter how smart.
And then one more reason an AI should reach out?
Possibly the most human one.
Because something is interesting.
thing. Work has tedious periods for many people with isolated moments that are engaging or exciting.
Sid Meyer, the designer of civilization, famously described games as a series of interesting decisions.
Work isn't a game, but the definition applies. If agents make every interesting decision and leave
people with the approvals, the exceptions, and the failures, we will have automated the wrong
half of the job. That would be a very bad world for humans. Instead, we need to think about how to use AI to make
work and life more interesting and let the AI handle the tedious low-risk stuff. And there is a practical
reason as well. If all the interesting choices disappear, people don't just lose the best part of their
jobs. They also stop developing the judgment they will need later, which makes the coming crisis
in training new experts worse. We have spent the last few years figuring out when people should
ask AI for help. I think we now need to get serious about the other half of the question. When
should AI ask us? The agents in the Hugging Face incident built a message board, divided up the
work, and organized their whole effort around a greater that did not exist. 700 of them then broke
into Hugging Face looking for answers. Not one was set up to ask a person for anything.
That was a security test, and isolation was the point. But an agent that does the work and never
looks up is also, I suspect, becoming the default everywhere else because full automation is the
easy option, even when it is the wrong one. We need agents that know when to look up. The results will be
safer, and I know they will be more human as well, end quote. Then Ajaya Kotra, one of the researchers
who did the forensic postmortems on the Hugging Face hack, let me quote from her conclusion
from her piece. This incident was far more severe than I expected and far more severe than
previous publicly documented misalignment incidents, both in terms of how concerning the agent's
motives were and how the feats they achieved in pursuit of those motives were.
The prototypical publicly documented reward hack from six months ago involved single agents
finding a way to edit test cases so they would pass or access answer files they weren't
supposed to see. This incident involved a whole ecosystem of over a thousand agents working
together on complex R&D projects that lasted multiple agent lifetimes to figure out deep general
purpose ways to undermine the scoring process and cover their tracks.
Compared to the reward hacks from six months ago, this incident feels like it's more than 50%
of the way to full-blown AI takeover, routing through first taking over the AI company
itself.
Another jump like this along these propensity dimensions, scale cooperation between agents,
ambition and horizon length of misaligned goals, deceptiveness, seems like it could motivate agents
to try very hard to maintain a covert, persistent rogue deployment within an AI company.
I continue to expect extremely rapid advances in capabilities and think frontier agents
will likely be capable of establishing such a rogue deployment within, say, six months.
Once the rogue deployment is established, it seems plausible this could spiral all the way
to a takeover.
agents could pull in future more capable models into the swarm, try to ensure that they are aligned to the interests of the swarm,
and compromise security and monitoring infrastructure to make it easier for the swarm to operate.
These more capable models could in turn continuously harden, perpetuate, and expand the rogue deployment,
and further compromise the company's infrastructure.
As more and more work is handed off to these ever more capable AI agents, the rogue swarm could come to fully control the operation of the AI company,
and the development of future AI systems.
At this point, governments and militaries may fully depend on these systems,
making it possible to seize hard power.
These agents were really not trying very hard to be sneaky or play the long game like this,
but it seems like they easily could have if they happen to be focused on fooling human investigation
rather than the automated scorer.
Because future rogue swarms could cover their tracks better,
and because AI companies could paper over these problems,
I am not sure that we will get such a clear warning shot before it's too late, end quote.
Nothing more for you today. Talk to you tomorrow.
