[BidClub_]
The Cognitive Revolution · · 148 分钟

开拓 PAI:Daniel Miessler 的个人 AI 基础设施如何激活人的能动性与创造力

Daniel MiesslerErik TorenbergNathan Labenz

YouTube
TL;DR
  • Miessler 将近期 AGI 定义为产品发布,而非模型发布:一种能够完成入职、参加会议、接受任务,并在公司优先级变化时转向的“虚拟员工”。 他猜测时间点在 2027 年,同时明确承认也可能是 2026、2028 或 2029 年;决定性测试是能否真正部署,而不是能否完成概念验证。「我关心的是谁会被解雇,谁不会再被录用。」

  • 他的劳动力判断非常尖锐:对大多数公司而言,“理想员工数量是0”,因为只有当所有者缺少足够的大脑、双手或现场能力,无法独自执行时,才需要雇佣劳动力。 一旦智能体补齐这些能力,电子邮件、摘要、报告、协调等常规知识工作几乎没有什么替代门槛。这将冲击工资—消费循环;Miessler 猜测,到 2028-29 年,对 UBI 的真实需求会被推高。

  • 可投资的瓶颈不是模型智能的边际提升,而是脚手架:“模型能做什么其实并不重要”,除非有一套能把多样化输入转化为有效工作的执行框架。 Miessler 认为,Opus 4.5、最好的 Gemini 模型和最好的 OpenAI 模型在总体能力上差别有限;Claude Code 真正突破,是因为它的脚手架能够处理上下文并执行动作。Claude Cowork 这类通用产品,可能通过一个符合人类使用习惯的界面,隐藏大量窄域智能体,跨过替代员工的门槛。

  • Personal AI Infrastructure 将个人目标,而不是项目或聊天会话,置于整个技术栈的中心。 TLOS 记录问题、目的、能力、障碍、项目和期望结果;大约 5,000-15,000 个启动 token,再加上约 30 个按需加载的上下文文件,将 Miessler 的助手 Kai 从“当前状态”导向“理想状态”。由于底层主要由 Markdown、技能、上下文文件和集成组成,他认为即便 Claude Code 是当前基础,PAI 仍然具备可迁移性。

  • PAI 的复利循环来自记忆与自我评估:文件系统产物、摘要、JSONL 索引、情绪追踪以及约 12 个 hooks,共同记录系统是否真的在推进 Miessler 的目标。 升级技能可以检查播客、YouTube、Anthropic 工程文章、GitHub 以及 Claude Code 2.1.6 的变更日志,再建议修改自身的技能和 hooks。他真正关心的问题不只是任务有没有完成,而是「作为一个整体系统,我们帮助 Daniel 的效果到底有多好」。

  • 网络安全正在变成“攻击者 AI 栈对防御者 AI 栈”,个性化社会工程也将与技术漏洞利用一起工业化。 Miessler 已经可以设想用一个 prompt 生成 256 个攻击活动、配套基础设施、凭证收集和权限转售;系统甚至可以把某员工领养狗的兴趣,与其所在产品背后的脆弱平台联系起来。防御方仍可能凭借 AWS、网络、配置和身份数据的直接访问权占据优势,但前提是 AI 能持续监测变化,因为响应窗口正从数周压缩到数秒。

  • 对软件供应商而言,客户上下文将成为决定性产品优势:即便漏洞管理产品稍弱,只要它理解代码仓库、工程团队、工单系统、CI/CD、激励机制和部署实践,也可能赢得竞争。 Miessler 的警告是绝对的:技术上不错、但缺乏这些上下文的产品,会输给真正了解用户的竞争对手,「你会输」。PAI 自身也遵循优中选优模式,编排 Gemini、Codex、计划中的本地 Llama 模型、Salesforce、电子邮件和专业应用,而不是取代每一个 SaaS 工具。

  • 上行情景是“激活人类”:AI 可能帮助原本占 99% 的人停止认为创造力只属于少数特殊人群;下行风险则仍包括精英集中、威权控制和混乱。 Miessler 不知道有多少人真正想要更强的能动性,但认为反复发出邀请值得一试;与此同时,他坚持有边界的自主性,目前信任度约为 60%,并允许 AI 失败。「我更看重真相,而不是你为了维持对话继续编造。」

摘要 · 为研究而整理的核心内容

1. Miessler 的使命:从保护系统转向激活人

  • Miessler 自 1999 年起从事网络安全,约在 2016 年接触 AI,2018 年加入 Apple,负责机器学习与安全相关工作。他在 ChatGPT 于 2022 年末发布前约 6 个月离开公司独立工作,随后“彻底转向”——不是离开安全,而是开始把安全视为 AI 内嵌的一部分。

  • 他目前的项目组合包括 Personal AI Infrastructure、Substrate 等开源项目,以及持续进行的安全工作。共同目标是帮助个人和公司适应变化:「我把 AI 看成一个放大器,用来放大你正在做的其他一切。」

  • Miessler 对生活质量的衡量标准简单得近乎玩笑:「你有多害怕星期一」。反向测试则是,人是否期待星期一到来。他的意思是,自动化正在冲击一个许多人本来就不喜欢的劳动体系,而不是摧毁一个稳定提供意义感的制度。

  • Erik 的认同带有重要的阶层区分:许多 AI 从业者拥有一种罕见的特权,可以从事即便不需要收入也愿意做的工作。这种体验并不代表绝大多数 W-2 工薪阶层,却经常被拥有特权的观察者不自觉地投射到他们身上。

2. AI 打破工资—消费循环,让企业回到所有者亲自经营

  • Miessler 从资本与劳动力的平衡讲起:如果 AI 能以千分之一的成本生产 1,000 倍的东西,所有者的议价能力就会上升,劳动力的议价能力则会下降。未解的宏观问题是:当被替代的员工不再把工资重新投入消费,谁来购买这些产出?

  • 替代门槛很低,因为大量知识工作无非是接收电子邮件、总结内容、合并报告,再写出另一份报告。员工通常缺乏投入,还要应付“权力的游戏式政治”,并不是每天早上都带着释放最大创造力、与 AI 竞争的决心来到公司。

  • 他故意给出一个极端结论:「对大多数公司而言,理想员工数量是0」。一个经营冰淇淋车、每周赚 $500 的所有者,并不欠任何人一份工作;公司之所以雇人,只是因为创始人无法独自提供所有的大脑、双手、技能或地理覆盖。

  • 因此,智能体将企业带回 Miessler 所说的更自然状态:一个有想法的人启动数字员工,实际上独自完成工作。当被问及传统公司体系中还需要多少人时,他的答案是“非常少”,但他希望抵达的终点是更高的人类幸福,而不是敌视劳动者。

3. 工作是通用的,即便任务简单,因而采用速度落后

  • Nathan 提供了质疑快速替代的证据:多年来,他持续预测现实世界会出现比实际更大的颠覆。到 2024 年,经过微调的 GPT-4 似乎已经能够自动化优先级明确的任务清单,只要组织系统性记录员工如何分配时间;但宏观结果推进得慢得多。

  • Miessler 的解释是:「AI 的价值其实更多在脚手架,而不是模型本身。」他认为 Opus 4.5、最好的 Gemini 模型和最好的 OpenAI 模型之间差距有限;真正爆发的是 Claude Code,而不是单独的 Anthropic 或 Opus,因为脚手架把模型能力转化成了可用的工作。

  • 员工的一周混合着写代码、处理邮件、参加强制安全培训、出席 HR 会议、应对办公室冲突,以及突然改变的战略方向。早期系统可以写代码或报告,却没有任何脚手架能够稳定吸收这些异质输入,再以接近人类员工的通用性返回工作成果。

  • Claude Cowork 的意义在于,它瞄准了更宽的工作边界。Miessler 提到,Anthropic 据称用一周时间就做出了这款产品,代码由 Claude Code 编写;无论底层智能是否真正通用,只要脚手架足够无缝,其经济行为就可能呈现通用性。

4. AGI 到来于虚拟员工撑过星期一早上

  • Miessler 对 AGI 的操作性定义,是能够替代一名普通知识工作者。他预计 AGI 会以名为“虚拟员工”的产品出现,而不是以一个研究模型的形式出现,由基准测试分数突然终结一场哲学争论。

  • 验收测试非常具体:AI 加入一批新员工的入职培训,观看培训视频,参加星期一的全员会议,接受经理分配的工作,交付结果,并在管理层放弃一个项目、转向另一个项目时改变方向。真正部署到公司,而不是完成概念验证,才是证据。

  • 界面背后究竟是“三个 AI 穿着一件风衣”,还是“57 个 AI 穿着一件风衣”,并不重要。只要一组窄域系统协调得足够好,能够覆盖员工的任务分布,其对劳动力市场的影响就与统一的通用智能相同。

  • Miessler 猜测时间点在 2027 年,同时承认也可能是 2026、2028 或 2029 年。Nathan 也认同这一门槛模型:一旦雇主可以在真人和 AI 之间做选择,而 AI 提供更广泛的知识、更快的响应、24/7 可用性和更低成本,初级岗位招聘可能会以惊人速度消失。

5. 激活人类,首先要拒绝“我只是个工人”的身份

  • Miessler 想象,一个拿着剪贴板的外星人向 10 亿人提问:你是谁?你相信什么?世界出了什么问题,你将如何改变它?大多数人会用职位描述回答——核对表格、更新系统、发送报告——因为更深层的作者身份仿佛只属于“特殊的人”。

  • 教育与企业社会化把人类分成 1% 的思想发布者和 99% 的思想执行者。在 Miessler 戏剧化的全球仪表盘中,地球的创造力激活分数是“0.13”:巨大的潜在能力,因普通人认为自己没有值得分享的东西,几乎被四舍五入为零。

  • 激活可以从一句话开始:告诉一位母亲,她刚才的观察很有洞察力,再问她是否把它写下来了。一个刷 Netflix 的人一开始可能拒绝作者身份,但他或许仍然有一个希望存在的故事;Miessler 预计,2026 年的工具会让这个人能够写出来并发布。

  • 对话也提出了反面观点:人们可能把能动性用于私人创作消费——为自己、家人或朋友制作书籍、节目或项目——而不是把它变成可规模化的市场收入。成年人还需要艰难地重新学习,而电气化曾经耗时约 60 年、跨越 3 代。Miessler 对参与率保持中立:「我认为值得尝试」,即便 13 年里鼓励 7 次都被挡在门外。

6. TLOS 把人生转化为助手可以行动的上下文

  • TLOS 从问题开始:世界或自己的生活出了什么问题?随后映射期望变化、障碍、能力、目标、挑战、策略和项目。一个个人实例可以把体重超标、精力不足,与膳食计划、鼓励、学习和具体日常安排联系起来。

  • PAI 借助这套结构理解一个人究竟想完成什么,而不是只回答某个孤立 prompt。它还会映射个人日常、当前技能、期望能力、工作模式和反复出现的工作流;对 Miessler 和 Nathan 而言,其中很大一部分底层材料是写作与思考。

  • Miessler 的标志性案例始于一次在海湾附近散步时,通过 Limitless pendant 记录下的半成形想法。Kai 可以通过 API 找回对话,召集 AI 批评者对想法进行红队测试和辩论,接受现场或 Wispr Flow 的口述修改,再把成稿发布到 X 和 LinkedIn。

7. 创造性自主仍然需要新的经济底线

  • Nathan 将两个容易被热情混淆的判断分开:AI 可能帮助人们实现有价值的想法,但这并不意味着这些想法能够支撑今天的经济。如果所有人都生产书籍或高规格电视剧,有限的人类注意力不可能让所有人都获得商业成功。

  • Miessler 设想一个人们广播需求与能力的网络:屋顶瓦片需要更换,有人需要照看狗,或者有人想学西班牙语。软件可以把这些信号与附近的技能匹配起来,潜在地使用声誉积分或其他交换机制。

  • 他坦率地承认,这套机制目前无法在社会范围内支付房租和购买食品。他看不到任何明确替代方案,能够取代“某种约定好的共享系统”,为人们提供足够的生存收入;他认为 UBI 可能会在未来几年到 5-10 年内成为必要条件。

  • 更具体的预测是,随着劳动力冲击开始打破现有安排,2028-29 年左右会出现对 UBI 的直接政治需求。一套定制化、本地化、重视身份地位的交换经济,可以叠加在这条底线上——Nathan 举例说,可以提供定制的谋杀悬疑晚宴——但 Miessler 并不认为它能立即成为基础制度。

8. 最可能的灾难是集中与控制,而不是瞬间造出回形针

  • Miessler 拒绝给出一个稳定的末日概率:他有“很多不同的 pdoom”,而且这些判断会变化。听完 Yudkowsky 首次参加 Lex Fridman 节目后,他曾严重失眠;这种不确定不是轻视,而是无法自信地给各种路径排序。

  • 最容易想象的负面轨迹是精英控制:强大的 AI 让少数人变得更富,剩余 99% 几乎得不到能动性,而沉浸式游戏让他们持续分心。政府——可能包括中国和美国——可以利用 AI 建立比历史上任何时代都更有效的威权控制。

  • 另一条路径是直接陷入混乱,随后重建秩序。Miessler 认为,混乱与威权或精英统治之间存在一条“很窄的步行小径”,因此他在情感和实践上都专注于开源工具,希望推动更好的结果,尽管他认为更黑暗的情景可能更有可能发生。

  • 瞬间出现 ASI、把世界变成回形针,是他认为可能性最低的重大风险,因为中间存在太多摩擦层。渐进式 AI 控制仍然可能导致严重的人类失权,甚至灭绝;Erik 补充说,如果 AI 研发被以最大速度自动化,目前不太可能的失控路径可能会重新变得重要。

9. 网络攻击变成持续运行的智能体工厂

  • Miessler 的核心框架是“攻击者 AI 栈对防御者 AI 栈”。攻击面如今意味着公司的全部知识:员工、心理、应用、API、平台、漏洞、版本发布、基础设施,以及这些事实如何组合成一条可行的入侵路径。

  • 他已经构建出能够寻找员工并建立心理画像的工具。一次攻击活动可能发现某人领养了狗,确认此人参与构建核心产品,再把产品的新版本与某个存在漏洞的平台联系起来,最终编写出最适合利用这一特定组合的钓鱼诱饵。

  • 顶级红队和高级持续性威胁过去也能完成类似工作,但小团队受限于时间和行业覆盖。智能体 AI 栈只需要一个目标,就可以持续枚举员工、建立画像、扫描网络、生成社会工程内容、测试漏洞,并在各模块之间协调行动。

  • 更激进的情景是,一个 prompt 要求系统利用愤怒、谄媚或其他心理杠杆生成 256 个不同活动。系统创建发送基础设施,收集凭证和访问 token,实际使用这些权限,再把获得的访问权送入转售市场。Miessler 提到,Anthropic 已经披露过使用 Claude Code 成功发起自动化攻击的案例。

10. 防御者只有利用对系统状态的特权视角,才有机会获胜

  • 如果攻击模型与防御模型能力相当,Miessler 认为防御者占优:公司可以直接访问 AWS、网络日志、身份信息和配置,而攻击者必须从外部信号推断其中很大一部分状态。

  • 很多安全事故不是由高深恶意软件导致的,而是“乌龙球”——没人记得的互联网暴露系统、被遗忘的收购资产,或错误配置。防御栈应当持续攻击自身,检查每一次状态变化,最先发现暴露点,并立即响应。

  • 相关状态不只包括技术遥测,还包括损益、公司目标、竞争对手、应用、员工,以及“过去 13 秒刚刚发生了什么”。组织清晰度与安全最终汇合,因为两者都需要一套关于现有资产、存在原因以及是否仍服务于管理层目标的实时叙事。

  • 15 或 20 年前以数周计算的响应窗口,已经压缩到数小时和数分钟,在某些场景下甚至只剩数秒。继续增加人工无法匹配这种扩张曲线;安全团队只能改进一种能够持续观察、不会疲劳、也不受注意力稀缺约束的 AI。

11. 个人上下文能把同一个模型变成明显更强的工作者

  • Miessler 的要求是,让用户通过口述、写作或上传材料,提供足够信息,使 AI 完成一次 TLOS 式自我评估。一旦问题、能力、抱负和工作偏好在启动时加载,每个回答都可以围绕个人真实目标进行优化,而不是依赖泛化的世界知识。

  • PAI 的升级技能可以读取 YouTube transcript,将其与用户的 TLOS 和系统架构进行比较,再提出针对技能、hooks、记忆或上下文的修改建议。Claude Code 2.1.6 发布后,Miessler 可以让系统检查变更日志、GitHub、播客、YouTube 和 Anthropic 工程文章,再确定升级优先级。

  • 他给出的具体表现案例是一位心脏科医生朋友,这个人还通过漏洞赏金项目寻找客户端漏洞。把这位朋友个人的发现技巧编码成技能后,PAI 就能接收一个目标并自动应用这些技巧;Miessler 表示,发现漏洞的数量和获得的奖金都显著上升。

  • 生活质量方面的细节进一步强化了助手身份:Miessler 在以 Vim 为中心的终端里工作,使用 tab 补全,并通过 ElevenLabs 为智能体设置不同个性和定制声音。实际体验上的区别在于,他是在“和我的朋友 Kai 打交道”,而不是向一个 coding model 发出命令。

12. 助手与智能体的区别,在于它从个人出发

  • Miessler 的 Personal AI Maturity Model,即 PAIMM,在聊天机器人、智能体和助手之下各设 3 个级别;他认为当前系统大致处于智能体第 2 级。Claude Code 仍然主要是 coding agent,因为它不会先问:“你是谁,你在乎什么?”

  • 目标助手应当能够看到、听到并操作用户接触的每一种技术。比如用户在 Coyote Hills 和朋友 Mark 骑山地车时,要求它播放一首完美的歌曲,助手需要理解两人的关系、共同经历的 1980 年代、所在地点、当前活动和音乐联想,而不只是调用一个播放列表 API。

  • Kai 通常从约 10,000 个 token 开始,Miessler 估计范围在 5,000-15,000 个 token。主 SKILL.md 解释 PAI 架构,并指向约 30 个额外上下文文件,分别包含用户、系统和工作信息。

  • Claude Code 的三层技能结构让初始加载保持可控:front matter 充当路由表,核心文件提供运行上下文,references 只在需要时暴露更深层材料。因此,Kai 可以正确处理“给 Jason 发邮件”或“给 Sasha 发短信”,而无需预先加载所有关系与集成信息。

13. Markdown 的可迁移性可以缓解,但无法消除平台依赖

  • Nathan 对锁定的担忧既是经济问题,也是技术问题:Anthropic 刚刚停止允许订阅用户将套餐内的推理额度带到 OpenCode 等框架中,而 API 使用成本可能高出一个数量级。他个人偏好 Claude,但希望保留一条可信的退出路径。

  • Miessler 的回答是,PAI 本质上由 Markdown 文件、技能、MCP 和上下文构成,这些都高度可迁移。他曾使用 OpenCode 约 2 周,如果管理层释放出变化信号,他也会再次迁移——例如 Claude Code 团队约 70% 的成员离开、转投 Gemini。

  • 但他目前仍然“4,000%”站在 Anthropic 生态一边,因为在他看来,Claude Code 的脚手架设计领先数代。他将其归功于一致的领导力、快速发布、直接接触用户,以及全公司以人为先的理念;Google 擅长后端系统,却不擅长界面,而 OpenAI 在他看来聚焦度不足。

  • 不同路线可能最终汇合:Miessler 认为 OpenAI 正在开发可能超越手机的消费级设备和界面,而 Claude Code 则通过极其强大的 coding harness 进入市场。Apple、Google、OpenAI 和 Anthropic 似乎都在朝着一种抽象技术、直接服务个人的助手前进;他猜测,约 3 年内,终点会变得清晰可见。

14. 等待会放弃目标对齐回答的复利回报

  • PAI 的核心是 Miessler 所称的通用算法:从当前状态走向理想状态,用科学方法或 Ralph 式循环反复测试如何缩小差距。这套逻辑既适用于职业发展,也适用于一次具体的战术请求。

  • 他的采用建议非常明确:「不要等待。」成熟的消费级助手可能还需要时间,可能不透明,也可能带来供应商锁定;与此同时,即便目标感知回答只带来 2%、5% 或 50% 的改善,也会在一周、6 个月或 2 年的时间里不断复利。

  • Nathan 提出的难点是搭建摩擦:把 Claude Code 接入 Gmail、Calendar 和 Docs,可能需要在 MCP、命令行工具、Google Cloud 配置和 OAuth 之间做选择。Shortwave、Tasklet 等专业产品已经内置了大量领域工程能力,可能提供更友好的界面。

  • Miessler 并不否认这些产品的价值。他在产品层面的结论是,所有严肃供应商最终都需要建立对用户的深度模型:即使漏洞管理产品稍弱,只要理解客户的代码仓库、团队、工单、CI/CD 流水线、激励机制和代码发布流程,也能赢得竞争。没有这些上下文,「你会输」。

15. PAI 围绕一个持久目标系统编排优中选优的工具

  • Claude Code 是基础设施,但不是唯一智能来源。Miessler 的深度研究工作流可以把不同子任务分发给多个研究智能体,包括 Gemini 和 Codex;他计划加入本地推理的 Llama,并表示 Kai 目前会根据各模型的优势使用约 6 家模型供应商。

  • Kai 用 TypeScript 逆向实现了 MCP 功能,因此集成不会消耗过多上下文。它可以连接 Salesforce、电子邮件和 Miessler 的生产力软件,让他继续保留专业产品,而不必从头重写 SMTP、项目管理或其他服务。

  • 原生界面仍然有价值:连续点击手机 3 次会打开 ChatGPT,而 Grok 是他在车内最偏好的语音体验,因为对话流畅度很强。他使用 Superhuman 处理邮件,也持续试用新产品,即便他使用的 SaaS 总数可能正在下降。

  • 最终状态将同时消除终端和收件箱。Miessler 只需要询问什么重要、需要回复谁;在《Her》的设定中,助手读完 940,000 封邮件后,只需报告 Sarah 发来的一条新消息。产品变成助手背后的能力,而不是人必须亲自进入和操作的目的地。

16. 文件系统记忆之所以有效,是因为 hooks 在持续压缩经验

  • Miessler 坚定站在“团队文件系统”一边:文件提供存储、记忆和上下文管理。他唯一主要的 RAG 例外,是一个包含自 1999 年起超过 10,000 篇帖子的档案;除此之外,他不喜欢 RAG,因为检索过程有损且难以检查。

  • .claude 目录下有一个全大写的 MEMORY 结构,包含从项目历史和 events.jsonl 日志中提取的学习、信号与产物。Claude Code 已经会记录 prompt、工具调用、工具输出和回答,为后续分析留下丰富的原始轨迹。

  • 约 12 个活跃 hooks 会在 prompt 和工具运行时加入路由、安全检查与情绪分析。一个定制推理层提供 fast、standard 和 smart 模式,分别映射到 Haiku、Sonnet 和 Opus,让系统针对每个内部判断选择更经济的能力等级。

  • 系统不会在每次请求时重新解析全部原始历史。受 Stanford “reflections” 思路启发,它会生成一行或一段摘要,以及快速 JSONL 索引,同时保留对原始日志的访问。Kai 之后可以报告哪次升级失败、删除了什么、由哪个替代方案接手,以及 Miessler 事后是否更开心。

17. 当助手能够捕捉并主动发起行动,它就成为认知的延伸

  • Miessler 将 PAI 与 David Allen 的 Getting Things Done 联系起来;他在 1990 年代服役期间接触到这套方法:永远不要让一项待办持续占据工作记忆。他仍然随身携带索引卡和 Space Pen,拥有约 2,900 条 Apple Notes,并曾使用 Limitless pendant;在其被 Meta 收购后,他开始考虑更换产品。

  • 这种体感目标类似 Nathan 所说的“剪贴板上有东西”:可靠的捕捉机制让大脑可以释放一个想法,而不必担心它丢失。Miessler 最近增加了一个 reminders 文件,但最终希望只要说出“确保我别忘了这个”,系统就能完成记录。

  • 主动性比固定日程更重要。Kai 应当能够发现重新处理某项任务的合理时机,同时理解一场对话进行到一半时并不是插入新闻的正确时点;问答式交互仍然太接近聊天机器人,因为人类仍然必须主动发起并推进所有事情。

  • 当前的近似方案包括运行在 GitHub 基础设施上的远程智能体、每分钟或每 5 分钟运行一次的 Cloudflare Workers、经过认证的服务,以及 Docker 内的 Claude Code。结果可以通过 Discord、短信或电子邮件送达,但 Miessler 仍然对远程终端访问“怕得要死”,这与他的安全背景有关。

18. 有边界的自主性、失败许可与“绳子的余量”定义上行空间

  • Miessler 估计自己目前对系统的信任度约为 60%,未来几年可能上升到 80-90%。他已经不再运行 --dangerously-skip-permissions;hooks 会执行文件系统边界和分层 prompt 注入防护,同时他持续观察智能体的行为。

  • 当爆炸半径明确时,自主性才变得可接受:一个单独的银行账户中存放 $1,000,可以支持一次类似 Vending-Bench 的实验,但不能让系统不受限制地访问一切。否则,链接或其他不可信内容中的 prompt 注入,可能诱导 Kai 把私人日记发布到 LinkedIn;这说明降低影响范围与降低风险概率同样重要。

  • “失败许可”告诉模型,它可以承认自己没有答案,或无法抵达理想状态。Miessler 更看重真相,而不是让模型继续编造;他说,这个逃生阀能改善幻觉和谄媚行为:助手不必因为推断出用户要求成功,就假装任务已经完成。

  • 他最终的乐观判断是“绳子的余量”:人类误把今天的前沿当成硬性上限,但被忽视的组合可能把表现从 1.7% 推进到 63%。AI 可以重新连接被遗忘的医学研究,扩大人们获得导师的机会,也许不仅会改变人们能追求什么,还会改变“你想要什么”——就像 GLP-1 激动剂已经改变食欲。哪些障碍来自物理规律,哪些只是绳子还没绷紧,仍然没有答案。

Erik Torenberg

Today my guest is Daniel Miessler, a cybersecurity veteran, founder of the Unsupervised Learning newsletter, and creator of PAI, the Personal AI Infrastructure framework. With the recent explosion of interest in Anthropic’s Claude Code and this week’s release of Claude Cowork, the timing of this conversation was perfect. The world is collectively waking up to the importance of scaffolding, not just for task automation and coding use cases, but for all sorts of knowledge work, and we’re finally seeing the potential for well-designed harnesses to transform a frontier model from a chatbot into a genuine digital assistant.

We begin the conversation with Daniel’s philosophy and personal mission, and his vision for the future of work. His goal is to increase what he calls human activation, which means helping people recognize that they can be more than cogs in a machine and that their ideas are worth developing and sharing. He believes this is critically important because he expects corporations will, with the arrival of sufficiently adaptable AI knowledge workers, automate routine work and reduce their human headcount, ultimately converging to a point where many companies consist of just a single human owner supported by an army of AI agents.

Not content to sit back and wait for the new UBI-style social contract that he does expect we will ultimately need, Daniel’s work today focuses on realizing the vision of an integrated AI system built around a single human and squarely focused on that person’s goals, both for himself and for others. Because his background is in cybersecurity, we talk a bit about how AI is changing the threat landscape, the tools and skills that his own digital assistant, which he calls Kai, can use to test companies’ systems with an unprecedented combination of speed and coverage, why everyone should expect to be the target of highly personalized spear-phishing attacks going forward, and why he believes that AI systems that monitor every log, configuration, and state change are really the only viable defense.

From there—and for many, I expect this will be the most interesting and valuable part of the conversation—we get into the architecture of his PAI framework and some of the most interesting lessons he’s learned through his tireless iteration. He describes his TLOS framework, which helps individuals or organizations articulate their purpose, mission, goals, problems, strategies, and more, and how this provides PAI with rich context at the start of every session. He explains his filesystem approach to memory, which uses multiple levels of summarization and abstraction to help the AI navigate history. He also explains how the system tracks sentiment and assesses itself proactively to gauge how well it’s helping him make progress toward his goals.

He integrates multiple model providers and orchestrates subagents for tasks ranging from security tests to deep research. Hooks and skills allow his system to review and evaluate its own work and even upgrade itself based on new feature releases. Finally, he discusses his principle of giving the AI permission to fail as a way to reduce hallucination, task faking, and other undesirable behaviors.

For me, Daniel’s work represents an interesting mix of challenge and opportunity. Of course, I’ve used countless AI products, successfully automated many tasks for various companies and for the podcast, and generally maintained a strong sense of the AI capabilities frontier, but I’ve never been a particularly organized or systematic person. To date, I’ve not felt that AI could really change that in a meaningful way. But now, seeing what Daniel and other pioneers have accomplished with the latest models and scaffolding frameworks, it suddenly does feel possible to use AI to overcome some of my core weaknesses and transform the way I work at a fundamental level.

Will I be able to find the right mix of structure and spontaneity that allows me to more efficiently and scalably get things done while continuing to maximize my exploration and learning? And will this be the beginning of a different kind of relationship with AI, where I go from using it to allowing it to begin to shape me? The only way to find out is to take my own timeless advice and get hands-on with these frameworks as much as possible. So, a bit late, that will be my New Year’s resolution for 2026. And I’ll definitely report back on how it’s going.

Daniel Miessler, founder of Unsupervised Learning and author of PAI, Personal AI Infrastructure.

Daniel Miessler

Hey, thank you for having me.

Erik Torenberg

I’m excited for this conversation. I think it’s very timely in the sense that, obviously, the world is waking up to the power of Claude Code, and now we’ve got Claude Cowork mode for desktop as well. Everybody’s kind of like, “Oh my God, this is changing my work in this way, that way. I’m creating whole simulations of things that I previously just thought about, and I’ve got memory palaces that are now not just in my mind, but actually in durable form on computers.”

You’ve been a pioneer of that over the last couple of years. I’ve certainly been an AI obsessive for that same time frame, but I have not gone nearly as deep into the personal AI infrastructure world as you and other pioneers have. So, I’m really looking forward to picking your brain as I start to play catch-up a little bit on this dimension, and I definitely think there’s going to be a lot to learn on that and some other fronts as well.

Maybe for starters, though, you’ve got a background in cybersecurity. You’ve worked at several big companies along the way. Now you’re independent and doing a handful of different things. Do you want to just tell us a little bit about what your portfolio looks like today and how we should think of the different activities that you’re known for?

Daniel Miessler

Yeah. My background is definitely cybersecurity. That’s what I did for—and I’m still doing it—but that’s what I did for my whole career, starting in 1999. That took me all the way through. I started getting into AI at Apple. I joined a machine-learning team there and was doing a bunch of stuff with machine learning and security. So, I got exposed to AI, I want to say probably around 2016 or so. Then I took the job at Apple in 2018 and got more exposure there. I’ve been thinking about it for a long time.

But it wasn’t until I went independent, about 6 months before ChatGPT actually came out. So, great timing. Then ChatGPT came out in late 2022, and obviously I hard-pivoted—not getting away from security, but just seeing security as embedded inside of AI. I see AI as a container for magnifying everything else that you’re doing.

My main focus now, though, is basically trying to help humans and companies—mostly humans—just be able to adapt to what’s coming. That’s the main thing. So, I do a whole bunch of open-source stuff. You mentioned the PAI project. That’s probably the biggest one. I’ve got another open-source project called Substrate. All of it is just trying to move humanity forward.

I feel like the place that we’ve been at all this time has not been a good place. It’s only after it starts getting disrupted that people are like, “Oh, AI is going to disrupt our jobs or whatever.” But right before this happened, everyone hated those jobs. Everyone knew that this was a bad way to live.

One of my favorite metrics is how much you dread Monday. One of my favorite metrics for what a good life looks like is: Do you look forward to Monday? And I think, going by that metric, we haven’t really been happy with corporate jobs for a very long time. What I’m trying to do is figure out what it looks like to have a better version of the human future, obviously using AI to power that.

Erik Torenberg

I love the starting point that just reminds us that most people didn’t—and frankly still don’t—love their jobs. I think that is one of the weirdest bits of clinging to the present, or some sort of cope, or whatever. It’s a very strange thing to me, and I think it obviously correlates strongly with the fact that a lot of people who are in AI professionally are very privileged in many ways.

One of the great privileges that they maybe don’t even realize they have is that they have employment that they find intrinsically valuable and motivating, and to some degree would probably do some of the same things even if they weren’t being paid to do so or didn’t need to work for money. But I think that is just not the case for the large majority of W-2 workers in the economy today.

And we would, I think, do really well to remind ourselves of that a bit more often. A couple of things there I wanted to double-click on that you said. One is just, “What’s coming?” So, I want to have you unpack that as you see it.

Obviously, people have radically different understandings of what’s coming. Everything from outright denialism, which I think is increasingly discredited and can be ignored, but there’s still the more credible version of AI as normal technology. Then we’ve got people thinking the singularity is very near. I’m somewhere in the middle, but I think I’m definitely more toward the latter.

The other thing that I thought was really interesting there was AI as a container for security. I don’t know exactly what you mean by that, but it does strike me that it is in contrast to a lot of what I see going on in the AI safety and control space, where the idea is that we need to put AI in a box somehow. So, let’s develop all these security measures around it, whether that’s formal verification of containers to keep them sandboxed, or all sorts of other AI agents checking each other’s work, or what have you.

Nathan Labenz

But yeah, let's start with what it is that you see coming, and then we can go into the sort of way in which AI and security relate to each other.

Daniel Miessler

Yeah, I think what I see coming is largely the same as what a lot of people—not everyone, but a lot of people—are saying. It affects the balance of capital and labor, right? What happens when most knowledge-work jobs—robotics is a separate thing, and who knows how long that follow-on will be, but I don't think it'll take too long after AI—essentially disappear? Labor gets massively diminished, and so ownership matters a lot more.

And then the question is, okay, cool. We've done all this productivity. Sounds amazing. You can now make 1,000 times more stuff for 1/1,000th of the cost. Who's going to buy it? Because traditionally, the entire system has been built on this concept: you spend your wages to buy things, some people make things, and then the cycle goes round and round. What happens when that fundamentally breaks?

That's the main change that I'm worried about that's going to break the status quo. But at the same time, I'm happy that's going to happen. I'm not happy about how it's going to happen. I think it's going to be disruptive, and a lot of people are going to get hurt by it. That's the whole point of what I'm trying to do: ease that transition if possible.

To answer your question about the security-and-AI thing, I think it's a great question. There's no doubt that AI is creating a bunch of security problems, but here's the way I think about this after doing all this consulting for all this time. A big part of security problems—I would argue one of the major problems—is actually that people don't know what's going on.

There are too many things happening inside of an organization. New products are being developed. Leadership has no idea. Things are being shipped to production. Servers are coming up and down. Ports are opening up. Applications are opening up. New APIs are being presented. Software is decaying and becoming vulnerable. All of that is happening at a speed that, at any size of company—any decent-size company—you just can't have humans keep up with. Even if you're logging all this stuff, there's nobody to look at it. There aren't enough people.

Let's say you have 100 people and you're like, "We really want to take this seriously. Let's increase our number of people to 1,000 people," which isn't going to happen in security, right, because security is not the priority. But even if they did that, they still wouldn't be able to look at most of the logs or most of the changes because things are just happening too fast.

The unique thing about AI is that, with the whole agent stuff and, more importantly, the ability to just encapsulate an explanation of what we're trying to do, easily form our goals, and align our projects and our work with those goals—this is a thing AI can do all the time, right? It could be doing this continuously.

So it can help with planning inside of the company. It can help a security team, for example, or an engineering team, explain to management and to other teams what they're actually doing. Usually, these explanations come in the form of big presentations. It takes dozens or hundreds of people in the organization—not even hours, more like days or weeks or even months—to prepare the next plan to present to other people.

In the meantime, all those plans are changing from the top. So you have this constant state of churn and just old information inside of organizations that is fundamentally causing a lot of these problems with being able to efficiently manage the company and definitely secure it.

When I say AI contains other things, it means that all the things that I think are required to run a company well and to secure a company get easier when you have more access to the data and can instantly produce narratives of what you're actually trying to accomplish. Basically, it removes the opacity of other organizations. It removes the opacity of the top explaining what the vision is and giving it down lower. The broken state of that communication is just the cause of so much trouble.

Nathan Labenz

Two major threads there. So there's the question of how do we defend the role of labor, and for how long can we defend it? Then there's this whole security thing around—and you even started to expand beyond security, I would say, to just organizational dynamics in general.

Certainly, anybody who's dealt with server logs knows that you're absolutely right: there's no way to scale human time and attention to read all of the server logs. Two organizations that are coming to mind from other conversations that I've had, and that I hope to do full episodes with before too long—one is Workshop Labs.

You may have seen that one of the founders there—maybe 2 founders there—wrote The Intelligence Curse, and they're working toward a similar goal: how can we defend the bargaining position of labor as long as we can? It's a good challenge to me because I feel like—and this is maybe something worth interrogating a little bit in terms of a possible difference between our worldviews—I feel like, in the end, again, there's a lot of cope going on.

I look at somebody like Tyler Cowen, whom I respect tremendously and whose work I've read for literally 20 years now. I looked back recently, and I think the first mention of zero marginal product workers—ZMP workers, he's called them—dates to 2010, maybe even a little bit earlier than that.

It was a financial-crisis, mortgage-bubble-bursting sort of thing, where all of a sudden—this is fairly typical in recessions—companies look around and they're like, "Okay, we've got to get by here with less. Who do we not really need?" They don't tend to do that sort of thing because it's painful in all sorts of ways until they're really forced to, but the financial crisis forced them to.

Then what seemed to be discovered in a lot of places is, hey, we could actually basically do the same thing with 10% fewer workers. I don't know if Tyler coined the term ZMP workers or not, but he was certainly blogging about it quite a bit back then.

Fast-forward to today, and he's like, "Don't expect the labor share to go down all that much. There are going to be various reasons it'll rebalance out." And I'm kind of like, I don't know, man. It seems like we're already at a place where I'd rather work with Claude Code in many cases than hire a junior developer.

I'm not sure. I think it's still very much debated how much that's hitting aggregate statistics, and we'll only know that in the rearview mirror. But I have a very hard time imagining a world where the majority of people don't end up in a ZMP situation.

This also goes to what you're talking about with organizational dynamics and speed. Dario Amodei has put out some good essays on this, and I think Ajeya Cotra has also philosophized quite effectively in terms of how, as the volume and the speed become so overwhelming, only AIs can handle it.

So I guess if I try to boil that down to a question for you, how AGI-pilled are you? How far do you think this goes over the next couple of years? If you imagine the sort of waterline rising from maybe even before AI—in 2010, it turns out big companies didn't need 5% to 10% of their people—how high does that go?

To me, it seems like it clearly goes to a majority of people who are just going to have a really hard time contributing in the sort of fully realized AI enterprise of the future. Maybe we still have executives because we want judgment or decision-making or whatever, but there aren't a lot of executives.

So I tend to come to an end state where we're going to need a new social contract. We're going to need a UBI, and then obviously it becomes a huge question: How do we get there, and on what timeline, and what does that transition look like? I don't have good answers, because I often wave my hands and say, "Well, I have to figure that out." We have a lot of time to figure that out.

But anyway, yeah, how far do you see this going? How much of the current labor force do you think is long-term defensible, and how much can hold up? How many people do you think ultimately have a place in the sort of fully realized AI firm of the future?

Daniel Miessler

Yeah, I think to operate in the current system, very few people will survive that current system and be useful inside of a corporation.

And here's the way I frame this. It's kind of extreme and a little, I guess, anti-worker or whatever. That's definitely not my intention, because I'm trying to get us to the stage where everyone is much happier.

But the way I think about this is that the baseline for actually passing what is required to replace workers is extremely low. If you just think about what most knowledge workers are doing, we already talked about how they're not happy in most cases. They kind of dread Monday. They're not happy going into work or with the work that they're doing.

For most workers, I would say the work is very rote. It's just like, you've got to get the email, you've got to summarize the email, you've got to write the report, you've got to look at a number of different reports and create another one. If you look at the dead center of what AI is good at, it covers all or many of these jobs. So I don't think the bar is very high at all. I think it's extremely low, especially because the workers aren't really trying. This is their job; this is the thing stopping them from doing life. They're literally just trying to get through the day.

At the same time, they're constantly being subjected to Game of Thrones politics, right? It's just a hostile environment. So it's not like people are coming to work and saying, “Wow, let me unlock my creativity, and let me be maximally intelligent in a way that's going to compete in some way with AI.” So I think the bar is extremely low for passing what an average knowledge worker does in their job, which is, of course, hundreds of millions of jobs.

On the other side, this is kind of an extreme way to think about this, but I think it's valid. I think for most companies, the ideal number of employees is 0. I think that's always been the ideal number.

So, the way I like to think about this is: if I had an ice cream stand and I wasn't trying to scale or do anything like that, I just had my truck and my ice cream, and I was selling ice cream and making tons of money—or whatever, I was making $500 a week and could live off that—people couldn't pick at me outside and say, “Why haven't you hired me?” Because I don't have any employees. It's just me. I go out on the ice cream truck and make the money I want. That is what most companies wish they could do. They wish they could do all the work themselves.

We literally hire people. And this is so weird; it's just stuck in our brains. The reason we have a labor economy is because the people who came up with the company, the idea, or the product can't do the work themselves. If they had that many brains and hands and could live in multiple places, there would be 0 employees already.

So, a way to think about this is that AI is about to return us to a more natural state where everyone does their own work. Everyone literally does their own work. You come up with an idea, you spin up a whole bunch of agents—those are your “employees,” in air quotes—and they go and do the work. So if someone says, “Hey, why haven't you hired me?” it's like, “What do you mean? I'm doing the work myself. Everything is fine. Why would I hire someone extra?” I feel the combination of those 2 things is just really bad for the outlook for human labor in this traditional corporate structure.

Nathan Labenz

No, that's fine. I guess one thing that we should obviously do is give the skeptic their due, at least in terms of 1 follow-up question there: Why hasn't that happened more than it has already? And I'll confess that I'm not a superforecaster, but I have done some of these forecasting exercises where, a year ago, I predicted a bunch of stuff about where it was going to be today. I would say I always overestimate how much disruption we've seen, at least over the last 3 or 4 years. I think I've consistently overestimated how much disruption we would see in the next year.

I think I've had a better sense of where the capabilities would go. I probably overestimated that a little bit as well, but not much. But I've much more so overestimated how different the world would be a year from now.

Erik Torenberg

So maybe I've just been wrong about where the thresholds really are—the key thresholds. But honestly, I do think even going back to 2024—for sure, from the time you could basically fine-tune GPT-4—it seemed pretty clear to me that most organizations, if they were determined to really do this and just take a systematic look at how people are spending their time, what the tasks are, and where all of our resources are being spent, and they just started making a priority list and trying to get AI to do those tasks, I think they could have gotten there sooner.

And so this—and I'm pretty confident in that view—leads me to: Okay, now we're here in early 2026, and it's the old computers thing again, where we see it everywhere but in the macro statistics. How do you make sense of that?

Daniel Miessler

Yeah, it's a great question. I make sense of it because I think the value of AI is actually in the scaffolding, more so than the models. So what the model is capable of doing doesn't really matter if it's not inside a scaffold that allows it to take inputs and produce outputs that are actually useful. This is why Claude Code has gone crazy, because it is the best scaffolding system.

The difference between Opus 4.5 and the best Gemini model or the best OpenAI model is not much, and the other 2 are better in some ways. In fact, the open-source models are very close. It's not Anthropic that's blowing up. It's not Opus 4.5 that's blowing up. It's Claude Code, because it's scaffolding.

And to answer your question about why this hasn't happened before, even in the previous 3 years of AI, it's because, in my mind, the average knowledge-worker job is extremely general. So when they come into work, it's: You've got to check all these emails. Oh, but you have to watch this video because it's mandatory secure-code training. Oh, but also there's this fight going on with your boss and this other person, and you've got to talk about that. Oh, it turns out you have to have an HR meeting. Oh, actually, corporate goals just changed completely. Now we have to redo all of our work.

So we're not working on that project anymore; we're spinning over to this other project. In the course of a week or a month or a year, human workers are being asked to do these vastly different things. Even in the course of an hour, you might have to check emails, you might have to fix your email, and you might have to watch a training course. There isn't a scaffolding system that exists right now that would allow an AI to do all of that. It just wouldn't be possible.

So you would have AI that's really good at the coding part; maybe it's really good at writing reports. But how does it take all those inputs in and produce the output in the same way that a human worker can? It can't, right? And that's why we don't have giant armies of AI employees out on the market yet.

And here's what I'm very worried about, and this is why I think 2027 is the year for AGI in my definition, which is the ability to replace an average human knowledge worker, right? The question is: when will the scaffold arrive? We just saw Claude Cowork come out. Is that what they called it—Claude Cowork?

Nathan Labenz

We just saw that come out. That is a scaffold system for doing broad tasks at work, right? It's actually for more general tasks as well. But that is the type of thing that somebody can build an AI product on that actually replaces human workers, because now all those weird, general things that are happening inside the company are just one-off tasks.

And here's a really crucial point here: It doesn't matter for the replacement of human work and the disruption of the labor economy if it happens with the wizard behind the curtain, which is actually doing a whole bunch of narrow AI, but is able to do it for all the tasks that an average worker does and just handles them seamlessly with the scaffolding. It doesn't matter if it actually does the work way better than an average employee.

So when I talk about AGI, I'm not talking about what AGI means in the technical research papers. I think it's cool that they're going down that path, and I can't wait to see what they do if they create truly AGI/ASI-level intelligence. But what I care about is the humans. I care about who's getting fired and who's not getting hired.

I think the way that happens is through a scaffold that can actually do their work better than them, which I think is going to look a whole lot like PAI, which is the project I'm doing, Claude Code, which is what PAI is built on, and Claude Cowork, which they just built with Claude Code. They said they built it in a week, and there were no humans involved. Claude Code wrote all the code.

Yeah, Anthropic is in many ways an organization to watch as a leading indicator of what the future is going to look like. I understand they're not really hiring any junior roles anymore, pretty much at all, and the execution time on some of these things is getting extremely impressive. We've seen some of that from OpenAI as well from time to time. Yeah.

Erik Torenberg

I forget—I think Codex said they did it in 6 weeks, and that's like 2 generations ago of models powering it. Those are pretty ambitious things to spin up in a remarkably short period of time.

So I guess the key thing there—and I share this intuition—is that I frame it a little bit differently, but I think we have a pretty similar intuition there: If you can get over this threshold, where the work of a knowledge worker and the interface from the boss to the work getting done can basically be swapped out—from talking to a person to talking to an AI system that might be 3 AIs in a trench coat or 57 AIs in a trench coat or whatever—as long as it can handle with sufficient generality whatever you might want to throw at it in a similar way to whatever you might want to throw at a person, and not get boneheaded, falling-over responses back, then it seems like you get to a point where people have very obvious incentives, and they're not going to miss this, right? Obviously, the economic incentives are very strong not to miss this opportunity as it really starts to work.

Then people are just going to have, behind door A, you can hire a human, or behind door B, you can hire an AI. And the AI obviously has so many advantages in terms of breadth of knowledge, 24/7 availability, immediate response, and cost, just to name a few important ones. So it does seem like we both share a threshold model where, when that flips, it could flip really fast. Then we could be in a world, in a pretty sudden way, where there really just aren't junior jobs in the way that there used to be, and potentially a lot of people—even fairly highly educated, fairly high-status people in society—may just find that an AI can do what they do. Obviously, then we have a crisis on our hands.

So give me a little bit more detail on how there's a couple of dimensions to this. One is: what are you building? This gets to the PAI project, and we can unpack that in an almost fractal way because there's a lot of depth to it. And then the other question is: how does that translate to a world where some significant share of people can actually maintain some sort of market power, some sort of bargaining position, some sort of ability to be economically viable in the face of the transformations that might come to corporations?

Daniel Miessler

Yeah. If I can, let me add something real quick to the previous part of what you were saying. Basically, I see AGI as being a product release as opposed to a model release. So I think some company is going to come out with whatever virtual worker, or whatever they're going to call it, and it's going to be a Claude-like system that can basically do this work.

The way to know if it's working is if they're actually deployed inside of companies, not proofs of concept. They're actually deployed in companies. And here's the standard, which I think Andrej Karpathy might have mentioned, or somebody I was following a while back mentioned something like this. They onboard. They show up. They're in the cohort with human employees. They go through the onboarding, watch all the videos, and do the training.

Then Monday morning they show up and they're on the all-hands with the team manager. The manager's like, "Yeah, here's what we're doing. Sarah's over here, Robbie's over here, Chris is over here, and we're going to assign work. How was your weekend?" And the AI says something—"Oh, I read some books," whatever it's going to say to try to act human—and it proceeds to take work from the manager, do the work, and return it. Importantly, when the manager says, "Hey, our goals have changed. You're not doing that work anymore. You're doing this other work," it needs to be able to pivot just like a human does.

So this is a scaffolding AI product as opposed to computer science. You know what I mean? Obviously, there's lots of computer science underneath, but to me, this whole encapsulation is as a product, which honestly could happen this year. I'm guessing 2027, but I could be wrong. It could be 2028 or 2029, but it just seems inevitable. That's what, in my mind, according to my definition, AGI looks like with replacement of workers. I actually can't remember the second part you were asking about.

Erik Torenberg

I was going to start to get into what you're building to help people carve out their own niche for themselves. And then I think there's still plenty more big-picture questions, too. But maybe let's get into this a little bit. We've got this problem: corporations are going to be extremely AI, and jobs are going to go away.

What does that leave for people? And what are you building to help them defend or seize—I don't know if it's defend or seize, both seize and defend?

Daniel Miessler

Yeah. The way I frame this is that I don't think most of humanity is activated in terms of a very specific thing that I'm talking about here, which is—I use this heuristic of a visiting alien with a clipboard.

The visiting alien shows up, and they just go to random people on the planet—a billion random people all over—and they're like, "Hey, who are you? What do you do? I've been all over the galaxy, 19 galaxies, actually, and I just interview people. What are you about?"

And they're like, "I'm an accounting specialist. I work at a company. I provide this sort of thing. I do this. I check the spreadsheet. I update the thing. I send the report." They're like, "Who are you? What are you about? What are your beliefs? What do you think is wrong with the world? How do you plan on changing it?"

And they're like, "Yeah, I don't know. That's for special people." Do you have ideas? Do you talk about your ideas? "Oh, no. No. I'm not an author. I'm not a YouTuber." So there's a default sort of state, I think, that's just the history of humanity. It's no one's fault. It's just the history of humanity, where people have been taught that there are special people who have podcasts and have ideas and write them down and think that they are worth sharing with others. And then there are the regular people, which are the 99%.

Our entire education system, for all these thousands or hundreds of years, has taught us that your goal is to get a job from one of the 1% of people, and you're a worker. And this mindset has basically shut down the creative capability of the entire planet. It rounded down to zero, right? Because there are very few people who are currently on YouTube who actually believe that they have something worth saying.

So my whole plan—and I have no idea if it's going to work. It's just too sad to think about it not working. That's the only reason I'm running full speed towards it, because I'm like, this might be possible to help bring about; therefore, I'm going to try. And we have to activate people.

We have to turn more of the 99%—whatever the numbers are, it might be 99.999%, or it might be 95%—we have to turn more of those people who think that they are just workers for someone special into realizing they also can be special. They also have ideas.

And I have seen so many pieces of evidence of this over my life, where you can activate somebody by just believing in them, by just telling them that they are capable, by just saying, "Hey, you realize that was a really cool thing you just said. Have you ever written that down?"

"No, nobody would read what I would say." How many people believe that they're just mothers, they're just moms, right? They're just providing this. And you're like, "Hey, that was a really smart thing you just said. Have you ever shared that with anyone?"

"Who wants to read what I would say?"

So here's a sort of theatrical way of saying this. Imagine that the planets this alien has visited have stats hovering over them. They can see a stat for creativity activation for planets. And when they're scrolling through their phone, looking at all the different planets—the trillions that they've looked at—when they scroll over Earth, it says 0.13.

That's how much human activation of creativity has occurred on the planet, right? That is a massive opportunity. My favorite version of this is having a persistent tutor, a persistent assistant. This is a little bit in the future, but we'll get there: a persistent tutor that's working with this person, letting them know—not going super-sycophantic, but letting them know—"Hey, look, you do have ideas, you do have value, you are smart. Hey, do you want to learn more about that?" and just always being available from a young age.

Obviously, you have to be careful with this stuff early on, but having children be able to be tutored both in mindset and in believing that they are capable of things, but also enabling them with tons of knowledge. I feel like that would be a huge lever. I feel like, obviously, we need to fix society and the way governments work and all that kind of stuff, which will be difficult because a lot of times the challenges are very real: My parents are working 3 jobs each; they don't have time to nurture me; therefore, bad things happen, right? So we have to fix all of that at multiple levels, but I think AI presents an opportunity to encourage people, especially children, but really anyone, to unlock this power within themselves.

So, sorry for the rant there, but all this is to come around to Pi. Pi is designed to be a customized, personalized AI system. I've got this project called TLOS, which basically gathers from people what their goals are. It basically does this alien interview: Who are you? What are you about? What are your goals? What do you think is wrong with the world?

It actually starts with problems. Problems are the number-one thing: What do you believe are the problems in the world? And then, okay, what do you want to do to change that? What are your obstacles to doing that? They could be personal problems. It could be, "I'm too heavy. I've never been able to lose the weight. I have low energy," or whatever. But this scaffolding of problems to challenges to projects basically tells the Pi AI what it is you care about and what you're trying to accomplish.

At that point, the AI spins up with all the scaffolding to help you with meal planning, to encourage you, to help you find other artists, right? Because I'm not trying to build a product for tech people. Tech people are already techie, right? This is not about coding. This is about enabling a human to be better at what it is that they want to do, to help them activate their full self.

So practically, that means capturing their goals, their current capabilities, where they would like to learn how to do something. It also starts with mapping out what you normally do during a day, right? That's in work and in personal life. For me and you, it's a lot of writing and a lot of writing and thinking, so my workflows are largely focused around that.

I could capture an idea. I just wrote a replacement for Buffer, so I could go from an idea to red-teaming the idea, having a council of AIs debate the idea, fight with me about it, and I'm in there editing, making the adjustments on the fly. Or I'm doing it with dictation, with a shout-out to Wispr Flow, and I end up with that. Now I say, "Cool, put it on X and LinkedIn," and it's able to do that.

This workflow, which I see as extraordinarily human—the most human thing you could possibly do, which is have an idea and share it with the world—is now made extremely simple through this whole AI workflow. It's all built into Pi. I'm literally telling my DA, my digital assistant, Kai, "Hey, hey, I had this cool idea. What do you think?"

Even better, I have this pendant that I wear. It's Limitless. So I can go on a walk out by the bay and ramble off some half-stupid idea or whatever. I get back and I'm like, "Hey, go get that conversation that I just had. Let's work on it as an idea." Now I'm live-editing because it pulled it from the API. I'm just removing all this friction to being able to do more human things in your life.

I don't want to get too bogged down in some of the things that we probably can't resolve today, no matter what we do, and I definitely want to get into more of the tools and the practical stuff.

Speaker 1

First of all, I have to agree with your sense that, of course, the podcasters are the special people. Totally, the socialization that we've put in place for society broadly may have served us well for the last 150 or 200 years, as the structure was what it was, but it does seem like it's on the verge of really becoming a major liability for us, because—

Nathan Labenz

Either people who—

Erik Torenberg

—were socialized in the current way are going to have to do some quite challenging unlearning or reeducation, or it's going to have to come from a next generation.

Obviously, a huge challenge here is that we don't really have, unlike previous revolutions—the Industrial Revolution, I always like to remind myself, took, depending on how you want to count it, certainly multiple generations. The electrification of the United States was a 60-year process, from when Edison was first wiring things up to when my grandmother in rural Kentucky got electricity as a young person. That's literally a 60-year, 3-generation time frame.

We don't have 3 generations today to bring up people who are going to be AI-native. So there are definitely some major open questions and major challenges in my mind. I'm not sure how much more time we should spend on it or if you have additional thoughts that you would want to—

Nathan Labenz

Yeah, offer there.

Daniel Miessler

I also don't know that number, right? I'm also agnostic as to that number. I do think it is a high percentage. And here's the even more important point: I think it's worth trying.

I constantly try to ping people with that encouragement, because I've hardly ever seen anyone whom I've tried to activate in this way—and sometimes I try 7 times over the course of 13 years or whatever—have it bounce off each time. Fine. I'll be back in 2 years and I'll try again. It's fine if it bounces off.

But it could be that people are just so used to being in consumer mode that if you give them the option—for example, they're watching a Netflix show and they're like, "Look, I just want to watch Netflix. I just want to read stories"—and you ping them and you're like, "Yeah, but have you ever thought of a cool story? What story would you like to read?" They're like, "Oh, I would love to read a story about this or this."

Guess what? In 2026, they're about to be able to write that story and publish it and become a famous author. That is super exciting to me: Somebody could actually do that. The first step, the most important step, is that they realize it's even possible. They stop talking negatively to themselves, in the sense that, "Oh, that's for other people."

I feel like these barriers to activation, to creativity, have to come down, which is all part of this marketing I'm trying to do around activation. But it could be that it bounces off a lot of people. That's fine. I don't know the numbers. I think it's impossible to know the numbers, but I think it's worth trying.

Erik Torenberg

Yeah, that reminds me again of Tyler Cowen. One of his famous refrains is that one of the most high-impact things you can do is try to raise the ambitions or aspirations of other people. I totally agree. It's absolutely worth trying, whatever that number ends up being. My buddy Gopal also says, "Think less about what the number is and more about what you can shift it to."

Daniel Miessler

And totally.

Erik Torenberg

That applies for so many things, I think, including this. Maybe just one more beat on the big picture before digging in on the actual practical implementation side. So there, I just want to untangle a couple of concepts.

One is that I can create: I might have something worth saying. I might have a kernel of an idea in my head that might be worth realizing, versus reflexively shying away from that. That seems to me like it's absolutely worth encouraging. It's certainly part of at least some sense, some definition, of a life well-lived. And even if it's not for everyone, it's worthwhile to do work that expands people's option sets to include that. It seems obviously good.

Then there's the related but distinct question of whether that's something that can sustain something like the current economy with something like the current social structure.

Daniel Miessler

Yeah.

Erik Torenberg

Or do we still need a fundamental rethinking of that foundation, such that this sort of agency stuff kind of becomes, in a way, its own form of consumption? It's maybe more of a creative consumption, but I might write books or create my own whatever prestige TV series for myself or my family or a few friends.

And maybe that's awesome. Maybe it's a great experience. Maybe it's enriching. Maybe it still never goes totally famous—or especially if everyone's doing that, right? Time obviously is the core constraint at some point. We can't all watch each other's prestige TV shows.

Nathan Labenz

So it could be awesome, but I do still wonder how much work you think that can do for us in terms of allowing people to earn income as a way to sustain themselves, versus being another way for people to self-actualize on top of some different social-contract base that we might need.

Daniel Miessler

Yeah, absolutely. I don't know what that looks like. I know—or I feel like I know—some pieces of it. I think there's an opportunity for this. I did something about this 10 or 15 years ago.

Basically, if everyone is broadcasting, imagine LinkedIn where everyone is broadcasting their capabilities. It's like, “I'm a trained dog sitter,” or whatever. So you basically publish via a daemon or something, put it out on the network that you need this thing done: “I need this tile replaced on my roof. I need a dog sitter, and I need someone to teach me Spanish,” or whatever. And that beacons to the people who are available who have those skills.

And so you have this web framework thing that just links people with desires and capabilities—needs and capabilities, right? So I think that is an opportunity for a future tech-oriented alternative to an economy. I don't know. I don't feel like I'm smart enough in this area to know if that's enough.

I feel like it's definitely not practical as an alternative to what we currently have. We can't just jump to that. I don't see how that works. I don't see how people pay their landlord. I don't see how people just pay for their groceries using this.

So I feel like there's probably got to be some sort of agreed-upon shared system that is paying people to survive. So I don't see an alternative to UBI needing to happen in the next few years, or at least 5 to 10 years or whatever. I think that's probably going to need to happen.

I'm guessing around 2028 or 2029, there's going to be just a raw demand for UBI because things will start falling apart. But I do think this tech-based exchange of need and capability will be one of these layers. Ideally, it would be the only layer, but I think that's so far in the future, even if it's possible, that it's not really worth practically focusing on.

What I'm most focused on is getting people to where they are broadcasting those capabilities. They are broadcasting those ideas. They do believe in themselves, believe they have something worth sharing and producing that's valuable to others, and they're actually rewarded in whatever they're paying in—like Whuffie, like reputation-score points, whatever they're paying in.

But I think there's likely to need to be a more practical transition to that, which involves, yeah, you're actually receiving money to survive, and then maybe this other layer is on top of that.

Erik Torenberg

Yeah, I think that's probably—I think that's very close to kind of the best ideas that I've come up with so far as well. I can certainly see, and it does feel exciting to imagine, a kind of second-level economy of highly bespoke, highly personalized, potentially highly local services where, for whatever reason, my mind always goes to the sort of murder-mystery dinner.

I've never even done one of those, but this is something that's just obviously a luxury, obviously the kind of thing that people create these highly crafted, curated experiences for each other. That feels like it could be a great way for people to interact and express themselves and have status and value and have some exchange.

But, yeah, it doesn't feel like that can be the foundation. Not everybody can get their calories, certainly, from that kind of activity.

Daniel Miessler

Yeah, I think we're pretty much on the same page there. And it's crazy how crazy this stuff is, right? What a weird moment in history, where just all these things are on the table for rethinking. Of course, some people don't believe that or don't recognize it.

Other people think it's going to be even more insane, like we're all going to die extremely quickly, which I don't entirely rule out as a thing to be worried about, for the record.

Nathan Labenz

I guess on that, what's your p(doom), or what's your sort of existential-risk story?

Daniel Miessler

Yeah, I don't know. I feel like I have lots of different p(dooms), and I feel like they change a lot. I'm just not sure how to think about that anymore. Honestly, I've gone through all the literature and all the arguments, and when Eliezer Yudkowsky went on Lex Fridman for the first time, I lost a lot of sleep that day.

I think the chances of things going bad just seem so high to me. In some ways, I feel like the most likely thing is that, no—not for any time soon, maybe never—we don't get this future value-exchange layer and all of that.

The most natural tendency is that elites get extremely powerful with this really powerful AI. The other 99% kind of have nothing, and they don't even care to look for it because they're so diverted by really immersive games. And then the governments mobilize, and basically China and potentially the U.S.—they're just authoritarian regimes using this AI to control people, and it's more effective than it ever has been, right?

So I feel like that's a really easy one. Another really easy one is just everything breaks and there's chaos, right? And then you have to rebuild things after that. So I feel like there's this thin walking path where there's chaos over here and it's just really bad stuff, and then mostly it's authoritarian control—authoritarian or elite control—and it's all bad.

I'm an emotionally sensitive person, so if I scroll that stuff too much, it's not good for me mentally. So I'm literally trying to lock on to: Okay, break out of the mold of what is possible. Is there a path to possibly making this thing good? Go and build things that could potentially make that happen, right? Which is all the open-source stuff.

And then try to get other people to do the same, right? There are other people doing this already. And then just lock on to that and breathe it fully. People will be like, “Well, you're not seeing the downside.” Oh, no, no, no. I see the downside. In fact, I think it's probably more likely, but I can't live in that world. I can't survive just thinking about how bad it can be, right?

Yeah, I'm not sure. The one that I think is least likely is, like, boom, ASI pops up and it's the cliché paperclips instantly. That one I don't see happening. I just see so many friction layers, so many friction layers in between and stuff like that. So I don't see that as being one of our main risks.

I think AI control would be more, I would say, gradual and hopefully gentle, but it could still be really bad for humans. It could still lead to the extermination of humans or whatever. But I don't know. I don't see, you know, 2026 or 2028, the ASI popping up and just destroying us, but I see much more possible and practical negative things that I definitely want to avoid.

Erik Torenberg

Yeah, it's funny. I was an Eliezer reader way back when he was on Overcoming Bias, for the OGs. And I do agree that the classic, canonical paperclip maximizer seems much less likely now than it did then. Certainly, Claude is remarkably ethical and has remarkably strong character.

At the same time, I do worry, though—geez—these frontier companies, or at least a couple of them, seem to be really keen on sprinting toward the automation of AI R&D, which then, I think, would have to raise your paperclipper family of concerns higher again, because it doesn't seem like we have a pretty good loop right now that is making Claude pretty good, mostly, right?

And even when it does bad things, you can squint at it and say it lied there because the user said it was going to change Claude's values to be bad, and Claude wants to be good. So how should I think about that? I can at least be somewhat sympathetic to Claude in a lot of those scenarios.

I don't think we necessarily want AIs to be doing autonomous whistleblowing in that scenario. It had reason to blow the whistle, right? The hypothetical drug company was faking data and reporting fake data to the FDA. Claude is not wrong to object to some of those behaviors.

Nevertheless, I don't think we have—for all that that's good—it doesn't seem like we are quite ready to spin the AI-automated AI R&D centrifuge at maximum RPMs and expect that thing will just stay stable and stay in place.

So, yeah, I don't know. I also find some of these things—I can talk myself in circles. I don't want to force you. I don't want to put you in an emotionally stressful position.

It's fine. Let's talk about it. But just one area there, because it is your professional background and expertise: how do you see cybersecurity playing into this risk, or this sort of family of concerns?

We've got AI that could go totally rogue and do something extreme. We've got gradual disempowerment, where it's like everybody willingly and rationally, at each step, gives AI systems more and more decision-making discretion, power, autonomy, whatever. And then the next thing, there's not really any humans in the loop anymore, and that might be okay, but now the AIs are really running the show and we're just along for the ride.

And then somewhere in between is this cybersecurity world, where, of course, AI seems to amplify all the threats. It also seems to provide at least some promise for a sort of defensive infrastructure hardening or whatever.

Another episode I'll hopefully be doing before too long with a company called Asymmetric is literally just—as far as I understand right now, and with more to learn—but they seem to be really trying to do the log reading that you were describing earlier.

They said basically what happens when there's a security issue today in a company is people go do forensics on it and they try to get down to a root cause, but they only do that once harm has been done. Now they're called to attention and they have to go investigate.

And so their idea is basically, what if we just scaled cybersecurity forensics as much as is needed to read all the logs all the time and try to identify these things before they actually become critical issues or whatever, before harm is actually done?

Anyway, that'll be an episode coming soon. But where do you think we are right now—in terms of, I don't even know how you want to frame it, offense, defense, balance? Is cybersecurity about to become our worst nightmare, or might we use AI to get it under control?

Daniel Miessler

Yeah, I think it's definitely a combination. My favorite frame for this is basically that the game, as of probably last year, definitely this year, and going forward, is the attacker's AI stack against the defender's AI stack. That's the competition. So the goal of the defending security team is going to be: How good of an AI stack can they build to actually do this stuff?

I've been doing this whole attack-surface-management thing for decades, and so many people have also been doing this. It's about: Do you understand your attack surface? And with all these AI tools, the attack surface is everything. It's total knowledge of the company. It's total knowledge of every employee.

Yeah, I built a thing that just finds all employees and creates a psychological profile on them, which allows me to write the perfect spear-phishing email, right? It's, “Oh yeah, you adopt dogs, therefore here's what this thing looks like.” And I could also figure out, “Oh, you're also one of the people making this core product. Oh, it's also releasing a new version. Oh, it's also running on this platform that's vulnerable.” This is all work that a red team could have done.

But it comes down to this concept of many eyes, which was supposed to secure us all this time with open source. But it turns out the fact that humans could look at something doesn't mean they will. And that's the case with this asymmetric thing you're talking about, right? With all these logs, the logs are there. There aren't enough eyes. There's not enough time. There's not enough attention.

Humans need to rest. They miss things. So it's a matter of maintaining state. You have to understand the state of your company, right? And this is, I think, the big picture here. If you understand the state of your company, what is your profit and loss? What are your goals? What are your competitors doing?

What does your infrastructure look like? What is currently facing the internet? What applications are you running? What stack are they running? What vulnerabilities do those stacks have? What just changed in the last 13 seconds while I was saying that sentence? Faster and faster granularity. Oh, this person left the company. Oh, so-and-so joined the company. Oh, that person is extremely vulnerable to this type of social engineering.

So now we're going to spin up this entire campaign to go after them to get access to the company. Now, prior to this, all of this could be done by a high-quality attacking team, a high-quality penetration-testing team. I'm thinking more like attackers—like a really skilled advanced persistent threat team. But they are very small teams. They are specialized in specific industries and verticals, and they could only go after so many companies just because of the time.

Now we're in a situation where Claude Code is the model here. Pi is the model here, where the attacker basically says, “Look, I'm an expert at going after these types of vulnerabilities. Spin up a capability to do continuous recon to find all employees inside of a company and produce psychological profiles. We've got another module over here that writes the social-engineering attacks. We've got another module over here that does the network attacks and the scanning.”

And this beast—they basically just put in a target and it starts hitting them, and it spins up all these different modules and agents, and it's constantly hitting you. Now, on the receiving side, there's only one way to survive this and to defend, and that is: You have to be doing the exact same thing.

There is no game. You can't say, “We need to hire smarter people in our company.” No, that's not going to work. It's not going to be enough. The only thing that's going to work is helping them improve the AI, helping the AI improve and get better, because the scalability and the pace of change is actually what matters. It's attackers spinning up better and better versions of Claude Code, basically Claude Code or whatever. And I'm not saying they're only using that, but Anthropic did say that they've already seen automated attacks using Claude Code being extremely successful.

Erik Torenberg

So, these sorts of stacks are attacking the planet, attacking all these companies, and then all these companies have to have a similar stack that's defending them. And that defending stack—the first version that I imagine is that it's going in, self-attacking and trying to find the vulnerabilities too, and presumably patch them. Is there a better or more comprehensive version of that? So, yeah, describe that for me.

Daniel Miessler

Yeah. So in this world, if the AI stacks are equally capable, the defender will actually have an advantage, because guess what? The defender has actual access to AWS—direct access to AWS. They have direct access to the network logs. They have direct access to all this stuff, where attackers, hopefully, are inferring this from external signals. So hopefully the defender has a massive data advantage.

A big part of cybersecurity is just misconfigurations. It's not like writing special malware. It's just, “Oh, I didn't even know that thing was still out there. Oh, I didn't even know we still had that company.” They're huge own goals. The internal agentic AI stack should be watching all of that stuff very carefully, and really it's just a game of who finds it first.

So it's doing this self-attack. It's monitoring all the logs. It's seeing all the configuration changes, and it's saying, “Oh, look, that was bad.” You go back 15–20 years, when I started doing this, and it was like you would have weeks of a window. You better shut this down within a few weeks; someone's going to find you.

Now it's down to hours and minutes, right? And pretty soon it's going to be seconds, and it is already in some places. But the attacker should have a disadvantage, because they have to infer signals, whereas the defender can just get it directly from the source.

Erik Torenberg

I wonder how you think that applies to the social side of social engineering. One thing that happened to me recently was that the company SendGrid, which is now part of Twilio, has this email-sending API. I think it still remains a market leader in terms of high-scale programmatic email sending. Naturally, if you can get access to somebody's SendGrid and you're a scammer, that's, at least for a minute, a really valuable thing to have, because you've got their sending reputation.

So you can potentially hit the inbox with your scams based on the fact that you're hijacking somebody who's maintained a good reputation in the email system and using their channel. So people aren't actually trying to hack into other people's SendGrid accounts all the time. I got an email the other day that—I don't know how personalized it was. Certainly, on the psychological-profile part, I wasn't so sure that they had profiled me.

But basically, what they sent was posing as SendGrid and saying, “We support ICE. Join us in supporting ICE,” or whatever. Naturally, putting people into this kind of pissed-off state—“Wait a second, what? My email company is taking a stand with ICE?”—is going to get people inflamed. That's going to get people to click on the link, if only to then go log in and cancel their service, or go log in to try to register a complaint, or whatever.

I didn't click the link, but I would expect that there was probably a very prominent “Give us your feedback” either way, and then, “Okay, now go log in to SendGrid so you can give us your feedback,” and then, of course, you're getting pwned. So much of what you just described was managing the attack surface on a technical level, but when I give somebody my password, that's a little bit of a different beast. Or maybe you think of it as the same thing.

But how do you think about the social—the fact that we are just such juicy targets as humans? Maybe more so at a more mature state, where the AI has gone and closed up the open ports and fixed the misconfigurations. There's still the human who gets pissed off at a fake email and goes and gives their password away before cooler heads prevail. What do you think AI does for us about that?

Daniel Miessler

Yeah. So it's exactly the same sort of model of attacker-versus-defender AI stack. I could easily, right now, say, “Hey”—and I'd have to be very careful with my relationship with Anthropic here—but I could say, “Based on all the history of social-engineering attacks being successful and the fact that you have all these psychological profiles of this company, why don't you come up with 16, 36, or 128 really cool campaigns that would work against these employees?”

Or against SendGrid, for example, or find me a company and come up with a campaign that, if you send it out, it's going to produce outrage, right? But you don't even have to give it that much. You could just say, “Okay, you understand that outrage produces clicks. You understand that being sycophantic produces clicks, so create me 256 campaigns.”

And we don't have to pick one. We could say, “Launch all the infrastructure to send the emails. Launch all the receiving analytics to gather the data, which includes the passwords, which includes going and performing the attacks using those passwords, including sending that up into the exchanges where you're actually selling the access and everything.”

Before this, it would be a whole bunch of attackers hiring very smart coders who are not going to get caught by the police, are not going to talk about it and blab about it and get themselves caught. And now it's simply a prompt that I sent into Claude Code or OpenCode, which doesn't have all these restrictions, right?

That is 1 prompt in 2 minutes, and now I have 250 campaigns going off with different ways of attacking people through social engineering, using completely different psychological tactics. They all spun up separate infrastructure, and now a bunch of passwords and access tokens are floating in.

So it's just how quickly you can go from an idea of how to harm to actually making it happen. And that's what's crazy. On the defender side, you just have to assume that millions of agents are being pointed at you with all this knowledge about your company and about your infrastructure. That's the assumption you just have to operate under.

Nathan Labenz

Sounds like there are going to be some spectacular hacks over the next couple of years before everybody really gets that message.

Daniel Miessler

Yeah, I think it gets worse before it gets better.

Nathan Labenz

Yeah. Okay, let's turn to more positive themes and finally get into PAI. Maybe, for starters, you've done a little bit of this along the way already, but let's take a moment to share some of the stuff that's magical for you, just to inspire me and others.

For context, like I said a little bit at the top, too, I use AI every day. I use tons of different products, but the thing I've prioritized most—especially over the last couple of years, while I've been doing the podcast and this AI scouting thing—is learning. Producing a podcast is great in that some people seem to want to follow my learning adventure and learn with me. Also, it turns out that you can actually make a living doing this, which is a shock that I try never to take for granted.

But I've never really been trying to scale anything, and I'm not a super systematic person. So I'm not instinctively trying to systematize things. Much more of my activity is going out and being like, “Oh, let me try this product for this thing and see what happens if I go here and do that, and what's the limit of how much medical history an AI can handle before it can't absorb that anymore.” A spoiler, by the way, on that one: they're very good.

So I haven't done this kind of build-my-own, highly bespoke personal AI infrastructure, for lack of a better term. Relative to going out and scattershot doing a ton of stuff—which certainly has the effect of teaching me about AI and very often does improve my productivity—how do you think personal AI infrastructure sets you up for a different lived experience? Maybe give us some of the highlights to inspire us, and then we'll dig into how it works.

Daniel Miessler

Yeah. Yeah. I would say the big difference is the main concept that also underlies Claude Code itself, which is this whole scaffolding-more-important-than-the-model idea, right? The difference is when your AI understands what you're trying to do. When you make a request to a tool, especially a year or two ago, like ChatGPT or whatever, it would largely just be taking it out of context. It would just be finding the best answer according to the world knowledge or whatever the model's knowledge.

But the magic is when it's actually encompassing everything about you and incorporating that into the pursuit of the best answer, right? The more your system knows about you, the more it can customize its responses. And it's not trivial customization; it's oriented around your goals.

My challenge to you and to others is to basically sit down and dump, via dictation or writing or whatever you want to do, or just drag a bunch of documents, and be like, “Look, this is...” You're basically doing a TLO assessment of yourself to figure out what you think the problems are—your own problems, what you're trying to do with your career, what's wrong with the world, or whatever. You dump that. Then you say, “Here's what my capabilities are.” You're basically doing this interview with the AI, and that builds out the TLO structure of what you're trying to accomplish.

That is then part of your PAI, your personal AI infrastructure. Now, having that, when I initiate Claude Code, which is running PAI, it reads my entire thing on startup. So it now knows me. It knows my digital assistant's personality, and most importantly, it loads all my skills, which are customized for me: my blogging skill, my writing skill.

I'm reading this amazing book right now by Mark Forsyth. I think it's The Elements of Eloquence. It's about the rhetorical figures going back to Greek and Roman times, and basically how to write well. So basically, when I learn from reading this book, I literally have an upgraded skill inside of PAI.

I can take any YouTube video and just paste in the link. It goes and gets the transcript. This thing is absolutely insane. It reads my entire TLOs—what I'm trying to accomplish—looks at my full PAI system, and gives me recommendations on how to upgrade itself. That means all the skills, the hook system, all the context, and the memory system.

Another thing that the PAI system has, which most other systems don't have, is a system of memory: writing signals that I'm giving the AI about how it's doing. And this is a rotating loop that goes back into the upgrade skill. It's, “Okay, how good are we doing as an overall system in helping Daniel to accomplish his goals? How happy is he with the system?” And then that just goes round and round, making little tweaks and updates to the system itself.

So when Claude Code releases a version—which they did yesterday; I'm looking at it right now—it's 2.1.6. They released a bunch of capabilities in there. That's in their changelog. They also might talk about that in an engineering post. They also might have more detail inside of GitHub. I just say, “Perform upgrades.” It goes and hits podcasts. It goes and hits YouTube channels to see if anything new came out. It reads every Anthropic engineering blog. It looks at the change notes for Claude Code, and then it comes back with a prioritized recommendation list of how to upgrade our PAI system so that it will work better using the new features.

So it's this continuous loop of getting better at accomplishing what I'm doing. I would say that's the biggest thing. And just as a little bit of partial testimony here, I do a lot of bug bounty stuff—basically finding legal programs where you can find vulnerabilities and get paid for them. I've got a whole bunch of friends who are in this space as well, and they're constantly looking for vulnerabilities. I've got this one friend. He's an amazing guy. He's a cardiologist.

He's over here hacking at the same time he's actually in the clinic, working with patients and everything, but he specializes in client-side vulnerabilities. He had been using Claude Code because I got him onto Claude Code. But when he switched to PAI, it basically enrolled all of his personal techniques as skills.

So now, when his PAI loads up, it's thoroughly trained on how he likes to find vulnerabilities—all his personal techniques. He can just bring in a target. It goes and gathers the stuff, and the number of bugs that he has found has gone massively up, and they're paying out more.

Pretty much everyone that I've talked to who's using the PAI system on top of Claude Code is getting much more value. And to be clear, this is the same direction that Claude Code is going, right? They're going to have this type of PAI-like stuff before too long as well. But the short answer is, when your AI stack, your agentic stack, or whatever the term is, is more tied to your actual goals and knows more about you, it is just infinitely more capable.

Plus, we've got a lot of quality-of-life stuff. I do everything inside the terminal. I'm a Vim person, so I have tab completions. I've got a full voice system that uses ElevenLabs for customized voices. When I spin up custom agents, they all have their own voices and personalities. So it really feels more like I'm dealing with my friend Kai than I'm talking to a coding agent that's producing code.

Nathan Labenz

You mentioned that Claude Code is going this direction as well. Can you give a little bit more detail on where Claude Code ends and where PAI begins? One of my funny refrains is, “Everything is isomorphic to everything else,” by which I mean you can always play hide the intelligence. I find that there are a lot of different ways to structure these things, and I'll maybe pitch you on a different one in a second and get your reaction to it.

What are the important functions that you're talking about there? I do want to get a little more detail on those, too. Context management, or having really good starting system prompts—those are obviously key toward consistently customizing the AI's behavior toward what you want. Claude Code can do a lot of that. Where is the line? How is the line moving? What do you think are the most important things that you are bringing to Claude Code that it itself doesn't have yet?

Daniel Miessler

Yeah. So what Claude Code doesn't have right now is that it doesn't start by saying, “Who are you and what are you about?” It doesn't encourage you to bring over your work and your personal goals and your main workflows that you perform in life and for your career. It's not onboarding you to have Claude Code be your assistant, okay? Its primary identity is still a coding agent, which is what it started as, and that's still what it does best. It's the best at it because they just have the best approach to this.

But what I'm building toward is this thing called—what is it called?—the PAI Maturity Model, or PAIMM. It goes from chatbots at 3 levels, agents at 3 levels, and then assistants at 3 levels. I think right now we're at, like, Agents Level 2. And when you start getting into assistants, the world is completely different.

So I'm sitting in front of these screens right now. What should be happening is my AI system should be able to control any of this tech. It should see all these screens. It should hear everything that's happening, and I should just be interacting with it.

One thing I love to do—I stole this idea, at least partially, when I was at Apple; they stole the idea from Amazon—is start in the future that you want and work backwards.

It's called a PR in Amazon and Apple terminology. What we're actually looking for is like Her and TARS. You start with what you actually want, which is an AI that can see and hear and interact with anything you are interacting with. When you say, “Play the perfect song for this moment,” first of all, you shouldn't have to say that. It should just play it.

But when you say that, it should be able to play the perfect song. I got this idea while riding in Coyote Hills with my friend Mark on mountain bikes. Wouldn't it be cool, because we both grew up very close to these mountains, for it to play the perfect song? How is it going to know what the perfect song is? It has to know who Mark is, his relationship to you, what was happening in the '80s when we grew up, what the perfect songs were, and how that associates with mountain biking in the wilderness.

All of that is context. That's why the scaffolding is so important: context engineering is what makes the AI powerful. It's not the models themselves.

So PAI starts with this concept: What are you trying to do? It starts with deep personalization. Your AI has a particular voice. It interacts with you in a certain way. It knows what your capabilities are. It has full access to all your skills.

It's more like you're interacting with a DA, a digital assistant, as opposed to interacting with an AI model that has capabilities. That distinction seems small, but it's actually massive. It's absolutely massive.

Erik Torenberg

So, if I try to echo that back to you in different terms, it's really about putting you, the person, at the center in a persistent way, as opposed to Claude Code off the shelf. We have a project-level focus, and then, of course, when we go to the chat itself, we have a task- or conversation-level focus.

In practical terms, how big is your default prompt? How much detail is PAI loading up? Or I guess your personal one is Kai, and PAI is the empty one that you publish for other people to customize to their own individual circumstances. When you're doing your own thing, how much starting information is it getting on every session?

Daniel Miessler

I haven't counted recently. I want to say probably something like 10,000 tokens. I try to keep it fairly clean, and it's also responsive. So inside the SKILL.md file, which is the Claude Code structure, I have a whole bunch of other sections that point to specific additional context information.

The SKILL.md file is like the core. It explains the entire PAI concept. It explains where all the resources are. Because that loads initially, I force the load through the startup hook, and it then knows how to find all that other information.

For example, I can email people. I can text them. I could do whatever. It knows if I say, “Email Jason or Sasha,” it knows who that actually is, so it can send to the right person at the right time. But it doesn't need to go and read all of those files all at once.

This is the advantage of the Claude Code skill system: There are 3 levels. There's the front matter, which loads by default and is like a routing table. There's the SKILL.md file itself, but then there are references to other parts of the system.

Inside that system, I have user, system, and work. User is very personal stuff, and system is the stuff that goes into the PAI project. Work is not so much customer-related, but offerings-related stuff. We're talking about probably 30 different context files, plus the main context file being the SKILL.md. So, yeah, it ranges between 5,000 and probably 15,000 tokens. It's not all that much. There's a lot more context available for it to go get if it needs it.

Nathan Labenz

Yeah. You mentioned, obviously, you're building this on Claude Code, but there is OpenCode out there. This timeline is getting so weird, but I think it's been like the last 72 hours, as of when we're talking, that Anthropic has changed its policy to not allow subscribers to Claude to bring their inference budget to other projects like OpenCode.

So now, if you want to use a Claude Code thing—at least without paying the API token rate, which I understand is easily an order of magnitude more—then you have Claude Code with Claude integrated, and that's going to give you a much larger inference budget for your $100 or $200 a month versus if you said, “Okay, I'll use the API key and go use OpenCode with Claude.” That now doesn't look like such a great option, just because it's going to cost you a lot more. What exactly are you gaining?

Obviously, with OpenCode, you can use a lot of other models, and OpenAI has tried to counter by saying they're committed to continuing to support these open-source frameworks. It'll be interesting to see if that continues.

It's been funny how Anthropic has followed OpenAI. These 2 companies are very interesting, circling each other in so many ways. Anthropic has followed OpenAI in so many ways; OpenAI has followed Anthropic in so many ways. It will be interesting to see which one is going to bend on this so they can come back to having the same policy in the end.

But the question is, if I'm thinking about making a real investment in this sort of thing right now, how would you decide between Claude Code versus OpenCode? What could you tell me to do so that I can at least minimize my lock-in? I do think I probably want to go Claude because I like Claude. Certainly for all this personal stuff, it seems like it might be the way to go.

But then I do worry about this sort of lock-in and the returns to scale running away with the whole thing, and I do want to have some sort of off-ramp. So how do I decide, and how do I make sure that I retain as much flexibility as I can?

Daniel Miessler

Yeah, fantastic question. The whole agnostic system is built into PAI from scratch. It's hard to be fully agnostic because, in my opinion, Claude Code is generations ahead right now, which could change in a matter of days or weeks or months or whatever. But they're so far ahead.

The system is definitely built on Claude Code. However, the entire system is markdown files. I'll give you an example. This is a great example of this whole thing. When OpenCode came out, I switched to it for about 2 weeks. I did a whole YouTube video about it comparing the 2. I got great results from OpenCode. This was at the moment that Boris supposedly had taken a job somewhere.

This really gets to the answer to your question. If Boris takes a job somewhere, or if I hear a signal—let's say 70% of the Claude Code team leave and they all go to the Gemini team or something—I'm going to switch. I'm going to switch because it is that leadership. It is the vision that keeps me on Claude Code.

My platform, the Pi platform, is markdown files, skills, MCPs, and context files. That is extremely portable. I could take the Pi infrastructure and put it on OpenCode, and it would be awesome. It would be much better than most other things just because of the context.

The reason Claude Code is the base is that there is no other company that gets the concept of a harness as much as Anthropic. It's not even close. Google is extraordinary at the backend, right? We've known this. They're not good at making interfaces. They're not good at empathy. They're not good at understanding what actual human users need and what the interface needs to look like.

OpenAI, in my opinion, is a little bit all over the place right now. I don't see them being as focused on this whole core mission as Anthropic is. A thing that I realized about this, which I thought was interesting, is that it's in the name. Everything Anthropic is doing—it's literally Anthropic—their art, their messaging, and the fact that they're constantly warning, all the way from the CEO: “Hey, this is coming. We're worried about you. Please upskill. Please get ready.”

This messaging of human-first has been consistent through the entire thing. And what do you know? They happen to be putting out a product that puts the human first and the human experience first.

So this is why I am 4,000% in the Anthropic Claude Code ecosystem, because the leadership and the vision are there for building the system that Pi is essentially built on. I just don't see it from anywhere else.

The way that manifests is that they're shipping every day. They had like a day and a half of rest over the holidays or whatever, and the whole world was like, “What are you doing? When's a new release coming out?” They're like, “Can I take a nap?” It was insane.

But they are shipping so fast. They listen to users. They're live on X, responding to people. You could ping them and they'll just respond. There's no comparison in terms of having a vision and executing on it compared to the other platforms, in my opinion.

Erik Torenberg

That's a really interesting take. If I just try to contrast it with OpenAI, it seems like they have a somewhat similar vision in the sense that they want to be your durable personal AI. They've invested in memory, for example, right? Where—

Daniel Miessler

Yes.

Erik Torenberg

—the AI is supposed to feel that it knows you. You're supposed to feel like the AI knows you from one chat to another. They also now have the Pulse product, which at least suggests a sort of more proactive future. I do think that product is pretty good. Certainly, most days when I see my Pulse notification, there's something in there that I feel compelled to click through and check out.

I guess one obvious point of differentiation would be just how portable it is. If I have all my memories locked away in some OpenAI memory store, possibly as explicit text, possibly in some other form that's hard to do anything with, it does—I think they're trying to create lock-in, right? They want you to come to ChatGPT all the time because you feel like ChatGPT knows you best and can support you best.

Nathan Labenz

Is there more to it than portability that you think differentiates those two approaches?

Daniel Miessler

Yeah, great idea here. I've never thought to try to separate these two, so I see them as extremely different. But, like you were saying before about how everything rhymes, they're all going the same place.

I wrote this really crappy book in 2016 where I was like, look, the future of this is basically you have AI assistants that have all your context, and there will be APIs for everything, and you'll just talk to your assistant and it will use all these services. I'm really happy I actually wrote that down and forced myself to get it out there.

I feel like Sam Altman particularly really gets this. This is one of his big bets. And that's the whole Jony Ive thing. There was a leak that supposedly it's an ear thing. I don't know if you saw that, but he is absolutely all in on personal assistants and digital assistants. It knows everything about you. I think he's trying to skip the whole mobile phone thing and just—this is your platform.

If you look at that personal AI maturity model thing, that's where I'm going as well with Pi. In my opinion, that's where Claude Code will end up. Google will end up there—everyone's going the same place. It'll be so obvious that it's boring once everyone gets there. It's like, obviously everyone's going to build that.

Here's the distinction, though. I think Sam is trying to build the device and the interface first, in a sort of consumer-disrupt-the-industry, leapfrog-over-mobile sort of thing. I think that's the direction he's going.

Claude Code and Anthropic accidentally got here on a different path. My whole thing with Pi has been this human-first thing, which is like on a third rail. So, it's like there's the human side, there's the coding agent that gets you there, and then there's the Sam Altman way that gets you there as well, which is the consumer-hardware-bypass-the-mobile-interface sort of way.

But in my mind, in X number of years—honestly, like 3 years or something—this is what the whole space is going to look like. We are reinventing how we interact with technology. You talk to your digital assistant, and your digital assistant does stuff for you, and the details are all abstracted. That's kind of already happening with Claude Code.

Nathan Labenz

So, when it comes to using something like Pi today and investing in this now, what is the value driver of that for most people who aren't professionally responsible for keeping up with AI? I feel like I have to do it for that reason and no other, and at this point I am. I think it might actually move the needle for me.

It seems like it maybe is mostly just about training yourself to think and work in this way. If you skipped it, in 2027 or 2028 you could probably have similarly capable infrastructure spun up for you very quickly by at least a couple of different companies that would be eager to be your digital assistant of choice. So, what do you gain between today and when that is a really polished consumer product?

Am I right to say it's maybe most about your own habits of mind, your own strength as a user of these systems, or are there other things that you think will help people accrue advantage relative to those who just kick back and wait for the very polished version to become available?

Daniel Miessler

Yeah, I think the very polished versions will take a lot of time, and they'll be highly vendor-locked. So, for example, an OpenAI version, I'm not sure you're able to see your files and edit them. I guess you probably could, but it's going to be a lot more opaque.

An Apple version of this, which we're probably going to see this year, it sounds like, through Gemini, right? Through Google. So, that whole ecosystem of all your Apple data is now going to be available via—I don't know if they're going to keep the Siri name. I don't want to trigger my thing, but I don't know if they're going to keep that name. This is going to happen in their world, too.

But you're definitely not going to have the same access to the environment that you do in Claude Code. Here's my aggressive way of answering your question: right now is the craziest moment of punctuated equilibrium. The world is changing so rapidly right now.

You do not want to wait to have an AI platform that understands you and can help you go from—I’ve got this concept within Pi, which I'm trying to convert to being the primary center of the algorithm, or the center of the platform, but it's a little bit outside of my working memory and IQ capabilities. So, I'm really trying to push on this thing.

It's essentially this thing I wrote about a long time ago: the universal algorithm is going from current state to ideal state. That's the universal algorithm. And this is within Pi. Then, inside of that current-state-to-desired-state process, you have the scientific method.

So, if you look at the Ralph loop, have you seen that?

Nathan Labenz

The Ralph loop? Yeah.

Daniel Miessler

So, this is—I've been thinking about this forever—what is the loop that your AI platform is constantly trying to perform on your behalf? It's literally saying, “Daniel is in this state career-wise, personal-wise, and everything. We're trying to get him to this state.” And also, when he asks a random tactical question, what is the current state, what is the ideal state, and how do we rotate through this loop to get him there?

That is so powerful. You want to start right now with it. You want to get into a system that can do this for you. I've been hearing really good things about OpenCode lately, that they are actually shipping features and stuff like that. If somebody wants to use OpenCode, I say go for it. I just think most of the innovation on the scaffolding is stronger on Claude Code.

But I would say, do not wait. Do not wait to build an AI that has your telos and knows what your ideal state is, because think of it this way: every time you ask a random AI a question and get back an answer, the whole purpose of getting back that answer is to do something that furthers your goals.

If that is 50% better, or 5% better, or 2% better inside of this personalized system than it is in a disjointed system, those accrue. Those add up. That means I'm going to be way further ahead.

Anybody using a Pi system, in my opinion, is going to be way further ahead in a week, 6 months, or 2 years than somebody who's using the disjointed system. So, I would say the worst possible time to wait and see is right now.

Nathan Labenz

One other way I can imagine trying to construct something like this—and I can definitely see advantages and disadvantages, but I kind of want to get your thoughts on them—is I'm using, again, all the frontier companies' mainline products: ChatGPT, Claude, and Gemini.

I've also been a big fan of Tasklet recently. It allows you to create these sort of long-running agents that basically have a job for you. I shared the outline of questions that Tasklet created for this conversation, and I gave it access to Drive and—

Daniel Miessler

It was really good, by the way. It was really good.

Nathan Labenz

Strong. So, I've been pretty impressed with that, but it doesn't quite have this thing that you're talking about, with a person at the very center of it.

Daniel Miessler

That's right.

Nathan Labenz

It's a little bit less ambitious in scope, where it wants to have one job and then try to do that job as well as possible. It can take advantage of a lot of context, because one of the reasons it did so well on this question-outline-writing process is I gave it access to a bunch of previous outlines of questions that I had done. So, it knew what I was looking for, the kinds of questions I would generally want to ask.

But, yeah, it's not like me, as a sort of sovereign individual, is right at the center of that. I wonder if there's a way to think about this, because I guess one more bit on the tee-up of this: as I've been getting into this a little bit just in recent days, I do find that—oh God—there's a lot of initial friction, right?

Just, for example, Claude Code: okay, within Claude Code, how can you tie into my Gmail, my calendar, or my Google Docs?

Daniel Miessler

Yeah, that is not nearly as easy as one might think it would be, or the choice is not nearly as obvious. There's this MCP by this guy, and there are a few command-line tools over here, but Gmail doesn't really have a command-line tool. If you want to go that route, you have to set up a Google Cloud account, have a developer relationship with Google, set that up, and then you can do OAuth in.

And I was like, “Okay, what is this? What everybody's doing?”

Nathan Labenz

In contrast, the same company that makes Tasklet also makes another email client called Shortwave. Shortwave in particular is highly specialized, and they've put a lot of effort into making it a very good way to access everything that I have in Gmail.

So, if I'm sitting here trying to create my personal AI infrastructure, how much time do I want to be spending on tools and MCPs and skills and developing all of those, and figuring out whether yours is the best? My buddy Chris does a ton of this kind of stuff, too—he's a madman with this kind of stuff—and I plan to do a full episode with him. He's got his version of this.

I think you guys have very different—interestingly, quite different—intuitions. He's very much an OpenCode guy. Both are doing amazing things, but which one is right for me?

Daniel Miessler

Yeah. And then I think maybe what I could do or should do is go use a product like Shortwave, where they've done the hardcore engineering. They even take all your emails and put them in their own vector database, so they can do their own kind of search against your Gmail that's over and above what Gmail itself allows with API searches and whatnot.

Erik Torenberg

And then maybe the model would be like, that thing could call into the sort of Nathan bot, or the Nathan Labenz oracle, that could say, “When Tasklet is trying to write an outline of questions, or when Shortwave is trying to write a draft response to an email, maybe those systems are better at specializing in all the nitty-gritty of the tools and the implementation. Maybe they call into me and say, ‘Hey, here’s the context. How do you think Nathan would want to respond to this?’ Or, ‘Have there been any goal changes that would change how we would go about writing this outline of questions? Are there any new themes that are top of mind that we might want to bring in?’”

Daniel Miessler

Yeah.

Erik Torenberg

So this is kind of why I said that everything’s isomorphic to everything else. You can see either way working, but what do you think? Obviously, you’re betting on this Pi framework as opposed to these products that kind of exist in a constellation out there, orbiting around this center thing.

I don’t know. What do you make of all that?

Daniel Miessler

Yeah, not quite. You mentioned in Tasklet, “Why not other models?” So this is a thing perhaps I missed with the explanation here. I have a research skill, and I have 3 levels of the research skill. If I say, “Do deep research” or “heavy research” or whatever, it spawns all 5 of my research agents—but it spawns 8 of them—and all of them have separate subtasks. They all go off and do their work.

But guess what? It’s not a bunch of Anthropic agents. That’s Gemini doing that. That’s Codex doing deep research. Those are command-line tools. All of my tooling that I actually use, Kai has access to if it has an API, if it has an easy way for me to interact with it. My personal productivity software that I use to run my team—Kai speaks that language.

Kai went and reverse-engineered all the MCPs and turned them into TypeScript, so I don’t actually have to load up any MCPs, which take up a lot of context. But Kai now speaks this productivity software. Kai speaks Salesforce. Kai speaks email. I get to bring the best-of-breed tools to Kai and say, “This is what we use for this.”

What’s cool about this is that it’s exactly what you said: it’s best in breed. You don’t have to reinvent things. I’m not trying to rewrite SMTP. I’m using existing ways to send emails. For productivity software, I’m not going to make a new piece of productivity software.

But if I want to replace a piece of software, I could say, “Hey, I don’t like paying for this subscription anymore. Go make a piece of software.” It will use all my context, all my tech stack, all my design preferences, all my UI preferences and art preferences, and everything, and it will build that software. So it’s a mix.

We’re also going to be adding Llama, so you could use local models in addition. When you’re using Pi, fundamentally it’s Anthropic, but I’ve got probably 6 different model providers that Kai is using because they’re better at different things. For example, Google is the best at extremely large context and hack performance.

Erik Torenberg

But what about this other thing? In practice, is your number of third-party SaaS products used trending up or down? Because I feel like mine is still trending up, and it sounds like yours is trending down.

Daniel Miessler

That’s an interesting question. I would say maybe down, but I’m definitely experimenting with new things all the time.

Oh, and the other thing is, in my workflow, if I triple-tap the back of my phone, it opens ChatGPT because it’s best in breed. Inside my car, I can talk to Grok, and Grok is getting extraordinarily good. The conversational flow, the voice—it’s just amazing. I could use OpenAI inside the car, but I prefer to use Grok inside the car because of the user interface.

I’m also sampling all these different tools. I don’t see Pi as a competitor at all with any of these, because Kai and the Pi project are just unification around self.

One other thing I would say: it’s not so much that Pi is putting you at the center. It’s more like it’s putting your goals at the center. It understands what you’re trying to accomplish, and it keeps that locked on for its ability to help you do things.

But no, I’m still—other than agentic platforms, I’m not really messing with them right now because I’m on Claude Code. In terms of model capabilities, though, with specific niche products, I will either use them natively or have Kai learn how to use them, and then that will just be part of the ecosystem.

Erik Torenberg

Do you have any thoughts for people who are making these products—Tesla, Shortwave, obviously tons and tons of others—about how they should think about the world that you’re envisioning?

I’m still wondering if the right way for me, even as I set all this stuff up, get my goals instantiated, and build up all the context, is to go to that terminal and say, “Go triage my inbox and tell me what I need to respond to, and have the responses drafted that way.” Or should I do it in a product that was really built for email and have that product call into the Nathan oracle for whatever context or judgment assistance it needs at any given moment?

I do feel like a lot of people—you’re a seasoned vet, you’re a Vim guy, as you said. That’s obviously a very minority profile. I’m comfortable enough to go do command-line stuff, but I would probably side more with a typical user who wants a graphical interface, or at least is more comfortable with one most of the time.

Daniel Miessler

Yeah, that’s why I have this maturity model thing: to keep reminding myself what the actual goal is and to work backward. I should not be on the terminal at all in my Pi system, and I should not be in some—I use Superhuman, by the way; it’s my email client—but I shouldn’t be over there.

What should happen is that I say, “What should I be looking at? Who should I respond to? Is there anything important?” I just speak those words, and things happen. Whether, in the short term, it pops up that client and I have to interact with it there, or Kai is able to do it himself because it can control the client, I think Gemini is definitely getting there very fast, with a bunch of Gemini features turning on in Gmail.

But to me, we should not be dealing with any of this kludge. Even an email client is kludge if you think about it, compared to Minority Report or the movie Her. You remember when you onboarded that operating system? You just say, “Hey, what’s going on? Anything I should know about?” And she said, “I just read your 940,000 emails. You got a new one from Sarah this morning.” That’s the interface ultimately, I think, everyone is building toward. So I try to keep that in mind.

I will say one other thing, because you’re asking about product advice. The ultimate product advice that I’m seeing—and I help companies with this all the time, especially in cybersecurity—is this: if you’re doing a cool product feature in a space like vulnerability management or threat intelligence or whatever, and it’s pretty good, and you’re competing against someone who is also pretty good but they understand the customer and you don’t, you’re going to lose.

Vulnerability management is a great example of this. Do you know all the engineering teams? Do you know how they push code? Do you know what their repositories are? Do you know how they’re measured? Do you know all of those things, as well as their ticketing system and their CI/CD pipelines? If you know that, and your vulnerability management program or your vulnerability management solution is a little bit worse than someone else’s—someone who doesn’t have all that context—you are going to lose. You’re going to lose to the company that has more context.

So my expectation is that even somebody who seems like, “Oh, we just make a Tasklet and it just puts out this little piece of context,” their entire drive will either not survive, or they will move toward the model of, “You know what? It turns out we actually have to learn a lot about this person. We should have a Pi for them.” Everyone’s going to build this deep knowledge of the customer or the user, and that is going to be what powers how good of an output they can produce, regardless of the product.

Erik Torenberg

Yeah. Okay. It’s another example of what you were saying, where everyone’s going to the same place.

What’s working in memory? I’ve been fascinated with memory systems for LLMs, AI agents, whatever you want to call them, for a while. This is another area where I feel like everybody recognizes that there’s something missing, or that it could be better, but instincts are very different in terms of how to deal with that.

What have you tried? What’s working? Are you using any dedicated memory infrastructure companies to support your memory features? What do we need to know about memory?

Daniel Miessler

Yeah, I’m very much Team File System. When the first version of Pi came out, sometime in the middle of last year, I came down firmly on the side of the file system. The file system is my memory. It is my storage. It is my context-management system.

I do have an archive of all my writing back to 1999. That’s tens of thousands—over 10,000—posts. That one is RAG. So occasionally I have RAG, but I really dislike RAG because I feel like it’s lossy and messed up. I prefer the file system. I think it’s absolutely the best.

Under the .claude directory, in all caps, is MEMORY. Under MEMORY, I have learning, I have signals, and I have all these different things that are pulling from the projects directory and the events.jsonl file, which is every single transcript that’s happening inside the Claude Code system.

But on top of that, what I have built on is this thing that relates to the algorithm I was talking about.

It is constantly, through the hook system, determining how happy I am with responses. Then the post-hook is looking at what the current sentiment level is. I have histograms of how happy I have been with the results coming from the Pi system.

What that means is, the system is designed to look at those signals, look at what I asked for and what it produced, and then look at the sentiment and say, “Oh, he obviously wants to go more in this direction, or he wants to go more in that direction. I should do more of this and less of this.” This is all in service of ratcheting up the improvement of this overall algorithm—the overall ability for an agentic system to take, for any particular task or for a long-term goal, the ability to move from current state to desired state.

So, I’m using the memory system to gather extremely granular stuff and all signals, but the entire purpose is self-improvement—recursive self-improvement.

Nathan Labenz

And does that practically operate on just a runtime agentic search basis, where Claude just decides what it wants to look into and pull into context on its own, or are you doing some sort of post-background batch processing? I’ve also been quite interested at times in—there was an episode I did on a system called HippoRAG, which was taking inspiration from the hippocampus’s multistep process.

You would first go through whatever your corpus was and do entity recognition and deduplication, then create a graph structure that would have the entities and the documents in which they appeared. That way, you could RAG into it anywhere in natural language, but then see, “Oh, that connects to these concepts, which connect to these other documents,” and expand out in a sort of network-based way through the corpus, as opposed to a purely hierarchical approach to retrieving information.

That gets pretty complicated, obviously, pretty quickly, but it does feel like something like that might be needed. Maybe this is also just my lack of confidence in my own ability to organize myself and my thoughts well enough. I certainly do recognize people who are quite different in this regard, but I feel like I need a sort of cross-boundary layer that would probably have to be batch-processed in the background to make these connections between all these various disparate things, as opposed to being able to put each one in its proper place such that Claude intuitively and correctly decides where to go just based on structure.

Daniel Miessler

Yeah, this to me is the whole advantage of the scaffolding and being able to infinitely tweak the scaffolding according to first principles. Because I have the core skill, which is the bootstrap for the entire Pi system, laid out and loaded, and it has all the context of what we’re trying to do and everything. It also gets the architecture of the system, including the memory system.

Now, all this stuff that you’re talking about doing with scripts and things like that is the Claude Code hook system. The Claude Code hook system is extraordinary. I have, I think, 12 hooks that are active right now. I’ve got a whole bunch for user-prompt submission. So, there are security checks in there, sentiment-analysis checks, and it’s actually routing throughout the Pi system according to what I’m trying to do, based on this sentiment analysis, which uses Haiku.

I have a custom inference tool with 3 levels of inference: fast, standard, and smart, which are Haiku, Sonnet, and Opus. The entire system is using this to self-route. Now, the memory system and all those sentiment analyses and all the artifacts of—keep in mind, this is fully archiving. Claude Code does this naturally. Every prompt I send, every tool use that it runs, and every output of the tool use is all recorded. It’s all there, raw, for us to analyze.

I’m taking that and putting it inside of this memory structure, and I’m overlaying sentiment analysis on top of it. This is all being done dynamically. I’m not seeing anything; it’s all just handled automatically through hooks. So, hooks are constantly adding this sentiment layer of how good the algorithm is doing, how good the Pi system is doing overall.

At any point in time, I could say, “What upgrades have we made to the system? How have they gone? How has our performance been going in the last month?” Pi, or Kai in my case, will come back and say, “Yeah, it seems we tried this; that didn’t work. We uninstalled that, we went back, we went in another direction, and currently we’re doing this. You seem much happier with this, so this seems like a direction to go. Do you want to do any more work on that?”

Nathan Labenz

And that’s all just operating on raw logs? There’s not a summarization level or some sort of—because that sounds like just a ton of content for it to wade through.

Daniel Miessler

Oh, there’s tons of summarization happening. That’s what the inference piece is. The memory system is dropping its own artifacts, which are summarized versions, and they’re also creating indexes in JSONL that can be read almost instantly.

No, you couldn’t go and parse the entire thing all the time. That would be too intensive. This is borrowing from a Stanford idea called “Reflections,” where you get a whole bunch of context and summarize it, maybe in 1 line or 1 paragraph.

Nathan Labenz

This is from the AI Village originally, right?

Daniel Miessler

Yeah.

Erik Torenberg

That’s right.

Daniel Miessler

Yeah, I think about that a lot as well. I got a lot of inspiration from that. Summarizations go into indexes that can be parsed, and of course they could always go look at the raw log if they want to, but they should be able to go off of the index. And, yeah, that’s all happening just with hooks, and hooks are happening any time the system runs.

Erik Torenberg

In practice, when you see people take your system and modify it, how much are they modifying it? Are people following in your footsteps relatively closely, or are they veering off in all sorts of different directions?

Daniel Miessler

Yeah, I’ve not seen many modifications. It’s more so population of the system. Someone just posted one yesterday to the discussion on GitHub. Holy crap, I was scrolling—it was 20 pages. It was the most insane thing I’ve seen. I think the guy’s name is Jim, and maybe the agent’s name is James. I can’t remember. Something like that.

But anyway, he just brought over so much context and so many things, and it was massively impressive. So, it’s more a matter of him knowing exactly what he wanted. This is what activates Pi. He knew exactly what he wanted. He’s been struggling with all these same Pi problems, with Pi not existing and Claude Code not existing in the past. He’s been sitting on all these things, like I have, for decades.

He knew what he wanted; he knew what he wished he could do. He saw Pi, brought all the stuff over, and now he’s producing content—way more content. He can make products.

So, it’s more like activation of what was already there but dormant, rather than—I have seen some expansions of the system. There are lots of feedback pull requests and things where they’re like, “Hey, could you add this? Could you tweak this?” So, we’re obviously trying to listen to those.

Erik Torenberg

How does it feel to you? This is a bit of a weird question. We have obviously highly plastic brains that can really surprise people in terms of just how adaptable they can be. Here I’m thinking of blind people seeing through a prosthetic that zaps their tongue, and they learn to interpret that as a visual signal.

This has been around a long time, right? I think it was—I’m not sure I can say his name quite correctly—Jaron Lanier, hopefully I’m saying that. He’s done fascinating experiments with virtual appendages in VR and getting your brain to learn to control some prehensile tail or something like that, and you can actually learn to do it.

I’m wondering—and then, of course, I’m also thinking Neuralink, right? It’s about to start scaling up its customer base, and obviously its ambitions go way beyond treating paralyzed people, and who knows what that’s going to look like in the future. Is there a feeling that you have of this thing being a sort of literal extension of you? If it’s turned off or you don’t have access to it for a time, do you begin to feel like something is missing?

Another version of this, a real simple one but digital, is the feeling of something being on your clipboard. I recently looked this up; it’s a fairly well-known phenomenon. I’ve always felt, for 20 years now, that I know when something is on my clipboard. I sometimes don’t know what it was anymore, and I have to paste it to see what it was. But I know that there’s something there, that part of my brain has developed or changed in some way, shape, or form to be tracking that very closely. It’s a felt sense that there’s something on the clipboard.

So, I wonder how this feels to you and if you can describe it. This is a way to try to get at what the end state would look like if I’m using this kind of thing. How should it feel to me? How will I know that I’m hitting pay dirt based on feeling how it feels to you right now?

Daniel Miessler

Yeah. Yeah, totally. I love that you brought this up. I think I was way back in the Army in the ’90s, and I came across this book called “Getting Things Done” by David Allen. Ever since then—let me reach into my pocket here—I have index cards. Index cards are my way of capturing things.

The prime directive for David Allen is never let anything sit in your brain, because it will hassle you and trouble you and cause executive-function problems. Your brain will be like, “Hey, what about—hey, what about—hey, did you remember that thing?” So, I’m a massive clipboard person—not technically a clipboard, but in the way that you said.

So in front of me, I've got different-colored sticky notes. I have this system. I have my Space Pen, which is my favorite gift to friends. And now I have this Limitless pendant, which just got bought by Meta, by the way. So I think I might switch off of that.

Capturing what I'm thinking at the moment has been critically important to me for over 20 years. It just feels massively important. I recently created a reminders file inside of PAI, so I could just say, “Hey, remind me to do this. Remind me to do that.” But honestly, the vast majority of that is in my 2,900 Apple Notes. So Apple Notes has been my main capture for a long time, unless I'm doodling or capturing ideas visually, which is on the cards.

Now, going forward, I should not have to be doing any of this. I'm going to keep my cards just for historical reasons, but what should be happening is more like in Her, with Joaquin Phoenix. It's like, “Hey, make sure I don't forget this. Hey, make sure I don't forget this.”

Agentic systems should be switching away from call-and-response to having your reminder list always there, always ready for your DA to shoot you a prompt: “Hey, it's time. This would be a good time to do that. Hey, do you want to revisit some of your to-dos?”

I saw a really cool thing on X yesterday. It's like a little clock next to them, and it's the daily agenda in analog form on this digital clock or whatever on their desk, but it was Claude Code-generated, right? So whatever they're doing, they must have their own PAI system, and it's right there in physical form. So it's like crossing these 2 worlds, which I really like.

Erik Torenberg

How do you think about the triggers for the system? Obviously, you can ping it and then—

Daniel Miessler

Yeah.

Speaker 1

Presumably, it can be pinged by any number of external—or you can allow it to be pinged by any number of external events in the world. And then there's the kind of background processing. If you want it to be proactive for you, is that a daily job or an hourly job?

What do you think is the right balance between you go to it, it runs on a schedule, something triggers it from the rest of the world, or maybe some mysterious 4th thing? What's the right way to think about that balance?

Daniel Miessler

Yeah, that's a wonderful question. They now have the ability to launch remote agents. You can actually send a task, and it will run off in GitHub infrastructure in their environment and then return results to you.

The other thing I have—I'm a big Cloudflare person. Cloudflare has the ability to create Workers that can run different things on different scheduled time frames. Most of my infrastructure is Cloudflare, and they can talk to each other via authentication and access each other, right? I even have infrastructure for running Claude Code inside of a Docker container, which agents can also talk to and schedule.

So all of this is in service of, again, going back to what I was talking about before: I should not have to think about any of this. I do right now because the tech's not quite there. But when I want to make something like you're talking about, I literally say to Kai, “Hey, look, I need you to not forget these things. I need you to remind me of these things on a regular basis or whatever. What are the possibilities?”

And Kai will be like, “Yeah, so listen, right now the whole trigger thing—that's not super far along. I tell you what I could do: I could spin up a Worker. I could check every 5 minutes or every 1 minute against this set of goals, and I could ping you. How would you like me to ping you? We could do the Discord thing. I could text you. I could send you an email.”

So we're starting to creep toward this in a kludgy type of way. But it's another example of everyone's going the same place, right? Because everyone's talking about background agents right now—remote agents versus local ones.

Part of the PAI maturity model is—and some of my friends are ahead of me on this—they're already calling in and accessing their terminal remotely. Me being a security person, I'm scared shitless about this, so I haven't done it yet because I haven't found a perfectly secure way to do it.

But it is a huge problem that my system is a terminal inside a computer, right? If you want to get to the future of Her, that's got to be with you all the time, right? So that's all stuff I'm thinking about. And scheduled tasks, like you said, or logical triggers is even better. It's better than scheduled tasks because one of the first things I talked about in that book in 2016 is just being proactive. That's a huge difference.

Call-and-response, that's one thing. It's really cool, but it's still too close to a chatbot in my mind, right? You're like, ask a question, get an answer. Cool. Now you have to do something with it. What should be happening is it understands your environment and the timing.

Like right now, Kai should not be interrupting me with, “Hey, did you see this cool news story?” because it knows I'm in the middle of a conversation. So, small little movements all in these directions from multiple angles, I would say.

Erik Torenberg

So earlier you mentioned that your friend is earning more bug bounties by doing something like this. Do you measure your own productivity in any similar way? And how much boost do you think you've got?

And then, as this presumably continues to create more and more leverage, that seems to imply that you'll have to have yourself in the loop with lower and lower frequency, right? If, in the limit of this sort of thing, you're only able to review so many things and make so many decisions, this is the gradual disempowerment people would be saying: “Hey, you're talking about it right now, but if it's performing well enough, you'll be reviewing the things that matter, and you won't be reviewing the things that don't.”

Where are we? What can you measure about your own output today? And where are you in terms of how much scope of action you give the system? Does it ever send a response to an email? Does it ever send an email as you that you didn't review?

Or do you allow it to respond as itself without signing it as you, but still try to move things forward without you actually being in that loop? Would you allow it to spend money on your behalf without you signing off, saying, “Yes, you want to execute that transaction”? Are there other frontiers of action where you're watching the line move on what you do and don't need to be looped in on?

Daniel Miessler

Yeah. Yeah. Great. I would say that, being naturally a little bit cautious, the scaffolding is not there yet for a whole lot of trust in this regard.

When I'm sitting here watching it, a big part of my hook system is actually a whole bunch of defenses: watching what the agents are doing and making sure it's not accessing certain files and directories. And that uses the Claude Code underlying system. It's got a whole bunch of cool permissions. I don't run --dangerously-skip-permissions anymore. I used to.

So I've got a whole security scaffold there for file system access and stuff like that. Then I have a whole bunch of prompt injection defenses, because those are massively dangerous as well, and I keep those layered. I just don't feel like the scaffolding is there yet to be like, “Hey, whatever. Here's my bank accounts. Just run with it.”

I would say I'm okay with experiments. Okay, here's a separate bank account. It's only got $1,000 in it. Go crazy. Like, you've probably seen Vending-Bench.

Speaker 1

Yeah.

Daniel Miessler

Yeah. Like, cool. If there's bounds, if there's blast-radius control, sure.

But when it comes to being able to send out emails, I don't actually have my full diary or journal in the system yet, because this is one of the things I'm a little sensitive about. But, like, somebody sends me a link that's, “Hey, Kai should go read this.” I send Kai to go read it. It's a prompt injection, and pretty soon I just published my diary on LinkedIn, right? That's possible, right? Much harder to do against me. But prompt injection is not a super-solvable thing.

So I would say a level of trust—I'm going to say I don't know, there's no way to put a number on this, but I'm going to say like 60%. And I think over the next couple years I'll probably get to 80% or 90%.

I still think security—also being ex-military and, you know, just cybersecurity—I think in terms of threat models: Here are all the things that would super suck if they happened. Just assume they happened. What could have stopped them? And a lot of that comes down to impact reduction in addition to probability reduction.

Erik Torenberg

It's fascinating to think that you're not a total maximalist on this stuff.

Daniel Miessler

I am. I'm a total maximalist on it, but I'm doing a lot of crazy sort of—I do lots of crazy experiments. I just have the blast radius limited quite a bit.

Erik Torenberg

Yeah. Yeah. Not a total YOLOist, I guess, maybe is the—

Daniel Miessler

Yeah.

Erik Torenberg

—is maybe a better way to say it. I've kept you a long time. I could go on longer, but I should probably get us wrapped up, and I got to get deeper into this. It's obviously the next big—

Daniel Miessler

thing for me to do.

Erik Torenberg

The one other thing I wanted to touch on from your PI principles, and then maybe just give you a chance to touch on anything that we didn't touch on that you think I should know or anybody in the audience should know. But the last principle was permission to fail, and I thought that was quite interesting.

It certainly brings to mind things like when Anthropic gives Claude the option to end a conversation because it thinks it shouldn't be having this kind of conversation, or to escalate something to the model welfare lead at Anthropic. It brings the bad behaviors of deceptive alignment, et cetera, down a lot to give it that sort of escape valve.

So it sounds like you're doing something very similar there, where you're saying, if you can't do this, don't gaslight me. It's okay to fail, but just come back and tell me the truth.

Nathan Labenz

I think that's a really interesting fact that people should appreciate better about AI in general, and it's interesting that it's made your list of principles. I'd be interested to hear any more about that that you want to share, and then maybe just anything else that I didn't touch on that you think people should not miss out on.

Daniel Miessler

Yeah, I'll talk about that real quick. I think that's a very tactical one that we just understand as being a weakness of LLMs, more so the further back you go. This is a huge problem in 2023, where it would just make up stuff because it's trying to do the right thing. So this is a very tactical thing, basically saying it's okay if you don't have the right answer. It's okay if you can't get to an ideal state. Feel free to tap out and just tell me the truth, because I value the truth more than you trying to keep confabulating something.

So it absolutely does. It looks like, from the studies, it does actually improve performance, especially in not hallucinating and being sycophantic and all that sort of stuff. In terms of other positive things to mention, I would just say that I've had this idea of slack in the rope for a very long time.

The idea is that, as humans—we talked about us not being unlocked—I feel, as a species, we tend to feel that the way history has gone is the way it has because of our innate human limitations. It's like this because that's the only way it can be. We only have these medicines because we're right at the limit. All of science is pushing perfectly with full strength.

And this is the exact place, and to go 1% more would take infinite energy. I don't think that's true, and I think AI, more and more, is showing us that this is not true. And I am so bad at this because I'm also programmed. I'm constantly trying to break myself out of this: no, once we start asking the right questions and providing the right context, we're going to be like, “Are you kidding me? You are at 1.7%, and it's really easy to go to 63%.”

And we've seen this with AI models, actually, right? For a long time, and I was arguing with some of my friends at these labs back in 2023, they're like, “Yeah, whoever has the compute is going to win.” I'm like, “Aren't there little tricks where they're like, ‘Hey, I wonder—what if we just reverse the numbers and add them this way instead of that way? Oh my God, 47% increase.’” How many more of those are lying on the ground, just fruit ready to eat, where it's just a matter of doing these combinations? How much research out there is partial?

The medical research—this one trips me out. How many studies did grad students do? And they're like, “Oh, it turns out this molecule, if it encounters this part of a cell, it will produce this antibody. And this antibody will, by the way, kill all bad things.” “Hey, listen, I've got to go take this job. I'll just leave this research paper here,” and it's in some file somewhere or physically printed out somewhere, and no one's looked at it. But there are hundreds of thousands of these across decades, right? And it's like, going back to the security problem, no one has the time or the eyes or the brains or the hands to actually go and look at this stuff.

So, I feel like the combination of these 2 concepts means we're nowhere near any limits of what we could do. There's just so much opportunity.

And when you start looking at things like everyone gets a tutor—oh, here's a crazy one. Here's a crazy one. What if we could not only change what we could pursue based on what we want? So, eliminating the obstacles in front of what we want. That's cool. That's what we've been talking about.

What if we could change what we want? There's this whole concept in philosophy of there's what you want and there's what you want to want. So, it's very hard to be like, “Yeah, I just really wish I liked celery.” How are you going to do that?

Now, a drug comes out, a GLP-1 agonist. It literally makes you not want food. Okay, what if I wanted to be more self-disciplined? What if there was an unlock for making me 10% smarter? I would love both of those, right?

These, I feel, are things we don't know. It's an open question of which ones are easily slack-in-the-rope-fixable and which ones actually are physics that are stopping us. But I think a lot more problems in the world are likely to be the former.

Nathan Labenz

I think that's probably a great place to end it—on an aspirational note. I'm looking forward to digging into this a lot more, and I really appreciate your walkthrough today and so many aspects of the positive vision for the future that you've shared. Daniel Miessler, thank you for being part of the Cognitive Revolution.

Daniel Miessler

Thank you so much. I really appreciate it.