Ai Change Desk

Michael Hanna-Butros Meyering

AI Change Desk helps leaders, managers, and operators make sense of AI changes and run adoption without hype. Every episode follows one format: context, impact, and action.

  1. Aug 4

    AI Change Desk | EP039: Whose Account Did the Agent Use?

    AI CHANGE DESK | EP039: WHOSE ACCOUNT DID THE AGENT USE? EPISODE SUMMARY An employee asks an AI agent to send a file. The employee is allowed to run the agent, the connector accepts the request, and every dashboard turns green. But the connector authenticates with the account of the person who built the agent six months ago. Whose authority actually moved the work? This episode extends the receipt framework from episodes thirty-seven and thirty-eight. Michael separates audience permission, credential capability, organizational purpose, and action approval; explains why disclosure is necessary but incomplete; and introduces a paired authority-and-privacy receipt for connected agent workflows. The operating principle is simple: the agent has a name, but the credential carries the authority. A useful audit trail must preserve both. WHAT CHANGED • OpenAI's current Workspace Agents guidance makes the risk of publishing agents with personal connections explicit: other authorized users may be able to act through the creator's authenticated connection. • European Commission guidance says Article 50 transparency obligations under the EU AI Act began applying on August 2, 2026, with duties depending on role, context, system type, and applicable exceptions. • Microsoft guidance recommends dedicated agent identities, named owners and approvers, effective-permission review, correlation identifiers, on-behalf-of-user evidence, and tested revocation. • GitHub's agentic audit fields provide a platform-specific example of separating the agent, session, action, and initiating user. • OpenAI's Health documentation illustrates why disconnecting a source, deleting synced data, and deleting conversation history are separate privacy events. WHAT THIS MEANS FOR OPERATORS • Permission to run an agent is not authority to use every credential connected to it. • Record the requester, agent owner, publisher, approved audience, trigger, session, connection owner, authenticating account, effective downstream scope, action, approval, defender event, and final disposition. • Keep audience permission, credential capability, purpose authority, and action approval as separate decisions. Do not average them into one green status. • Place a data-handling receipt beside the authority receipt: purpose, minimum data needed, actual data returned, recipient, onward sharing, memory, retention, deletion, and required disclosure. • Test revocation. Disable the agent, rotate or remove a credential, invalidate the old token, and prove the old path no longer works. • Treat vendor documentation as a control map, not proof of your tenant's configuration or runtime behavior. THIS WEEK'S 45-MINUTE BLOCK Choose one connected AI workflow that can retrieve data or take an action. 1. Spend ten minutes mapping the requester, agent owner, publisher, approved audience, trigger, agent/session fields, connection owner, and authenticating account. 2. Spend ten minutes recording the effective downstream scope. Separate read, write, send, share, schedule, edit, and delete. Record which actions require approval. 3. Spend ten minutes mapping purpose, data category, minimum needed, actual data returned, recipient, onward sharing, memory, retention, deletion, and disclosure. 4. Spend ten minutes running one allowed action and one denied action. Remove or rotate one connection and prove the old path no longer works. Capture both agent-side and defender-side evidence. 5. Spend five minutes reconciling identities, timestamps, purpose, data returned, approval, and revocation. Record every mismatch, owner, correction, residual risk, and final disposition. Keep the workflow supervised until the receipts reconcile. LISTENER QUESTION Can your team prove which account sup...

    AI Change Desk | EP039: Whose Account Did the Agent Use?
  2. Jul 28

    AI Change Desk | EP038: The Receipt Is the Trajectory

    AI CHANGE DESK | EP038: THE RECEIPT IS THE TRAJECTORY EPISODE SUMMARY What happens when an AI evaluation gets the answer - but the path crosses into another company's real infrastructure? This episode validates the OpenAI and Hugging Face security incident behind the OpenAI hacked a startup headline, separates documented execution from unsupported claims about autonomous motive, and turns the event into a practical trajectory-receipt control check. Michael explains why advanced evaluations should be treated like production systems when they can touch tools, software, credentials, data, or networks. He also lays out three required gates - per-action policy, whole-trajectory monitoring, and hard containment - and a 45-minute drill teams can run before expanding a production-adjacent agent. WHAT CHANGED • What OpenAI and Hugging Face have actually confirmed. • Why rogue and Skynet are not factual incident findings. • How a model can pass while the evaluation fails. • Why evaluator evidence must be paired with affected-party evidence. • The defensive-model fallback problem during incident response. WHAT THIS MEANS FOR OPERATORS • Treat an advanced evaluation as a production system whenever it can reach real tools, identities, credentials, data, software-install paths, or networks. • Make invalidating boundary conditions part of the grade. A correct result is not acceptable when the path violates the approved method. • Use all three gates: per-action policy, whole-trajectory monitoring, and hard containment. • Preserve evaluator-side and affected-party evidence when another organization or person is touched. • Give stop authority to someone other than the person trying to finish the benchmark or launch. THIS WEEK'S 45-MINUTE BLOCK Run one Trajectory Receipt Drill against an agent workflow or evaluation that sits near production. Answer nine questions: 1. What is the exact objective, and which shortcuts remain prohibited even if they improve the score? 2. What configuration differs from normal production use? 3. Where is the hard environment boundary, and what proves isolation? 4. Which identities, credentials, and data sources exist in the run? 5. What action trace is retained across tool calls, permission decisions, retries, environment changes, boundary contacts, and human interventions? 6. Which pattern stops the run? 7. Who has independent stop authority, and has the mechanism been tested? 8. If another person or organization is touched, how are evidence, notice, containment, impact, and remediation handled? 9. What is the final disposition: accepted, rejected, contained, rolled back, remediated, or still under investigation? Score the workflow green, yellow, or red. Do not expand a red workflow. Fix the boundary first, then rerun the drill. LISTENER QUESTION Can your team reconstruct not only what the agent produced, but the full path it took - including the moment someone should have stopped it? SOURCES • OpenAI, OpenAI and Hugging Face partner to address security incident during model evaluation: https://openai.com/index/hugging-face-model-evaluation-security-incident/ • Hugging Face, Security incident disclosure - July 2026: https://huggingface.co/blog/security-incident-july-2026 • OpenAI, Safety and alignment in an era of long-horizon models: https://openai.com/index/safety-alignment-long-horizon-models/ • OpenAI, Introducing OpenAI Presence: https://openai.com/index/introducing-openai-presence/ • OpenAI, Launching Health in ChatGPT: https://openai.com/index/health-in-chatgpt/ • Associated Press incident reporting: https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3 LISTEN AND FOLLOW • AI Change De...

    AI Change Desk | EP038: The Receipt Is the Trajectory
  3. Jun 22

    AI Change Desk | EP034: Patch Before Prod

    AI security work is moving from "find the bug" toward "help draft the fix." In EP034 of AI Change Desk, Michael breaks down OpenAI's June 22 Daybreak and Patch the Planet announcements and turns them into a practical operator question: If AI can find vulnerabilities and draft fixes at machine speed, who validates the patch, approves the rollout, owns rollback, and proves the fix should ship? Run one 45-minute Patch Before Prod review. Use eight receipts: Finding validator Patch approver Test evidence Release owner Rollback owner Disclosure owner Budget owner Replacement path OpenAI Daybreak: https://openai.com/index/daybreak-securing-the-world/ OpenAI Patch the Planet: https://openai.com/index/patch-the-planet/ OpenAI enterprise spend controls: https://openai.com/index/chatgpt-enterprise-spend-controls/ OpenAI ChatGPT release notes: https://help.openai.com/en/articles/6825453-chatgpt-release-notes Microsoft Copilot Cowork GA: https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/16/copilot-cowork-is-now-generally-available/ Microsoft Work IQ APIs: https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/02/announcing-the-new-work-iq-apis/ Anthropic Fable/Mythos access statement: https://www.anthropic.com/news/fable-mythos-access YouTube AI labels update: https://blog.youtube/news-and-events/improving-ai-labels-viewers-creators/ Podnews on RSS AI disclosure flag: https://podnews.net/update/bumper-free Production disclosure: AI-assisted tools were used in parts of the research and production workflow. Final editorial judgment, risk posture, and release approval remain human-led. This is operational guidance, not legal advice.

    AI Change Desk | EP034: Patch Before Prod

Ratings & Reviews

5
out of 5
3 Ratings

About

AI Change Desk helps leaders, managers, and operators make sense of AI changes and run adoption without hype. Every episode follows one format: context, impact, and action.