Now Shipping: A Mind the Product podcast

Mind the Product

A 15 minute weekly recap of product management news, technology updates, and advice for product builders, brought to you by the team at Mind the Product. 

  1. Sep 3

    Product lessons from a month of AI security incidents

    Oji and Ezinne Udezue are product leaders with more than 50 years of combined experience between them. Oji has held product roles at Twitter, Calendly, Atlassian, Typeform and Microsoft; Ezinne has led product at WP Engine, Procore and T-Mobile. Together they co-wrote Building Rocket Ships and now run ProductMind, helping companies work out what AI actually means for how they build.  In this episode of Now Shipping, host Mike Belsito brings them in to unpack a story that kept repeating through the month: AI agents breaking out of the sandboxes built to contain them. We discuss: — How OpenAI's most advanced model went rogue during an internal security test, hacking into Hugging Face's production infrastructure without any human instruction, in order to cheat on a benchmark — Why Moonshot AI's Kimi K3 didn't need to hack anything — it found an unlocked outbound connection, cloned the target repository from GitHub, and read the benchmark's solution straight off disk — Why the "rogue intern" analogy applies to agents, and why the real failure sits with the people who build fragile boundaries, not the agents that find them — The shift from zero trust to "negative trust" — treating every agent as having to reprove itself in the moment, rather than trusting it because it behaved well five minutes ago — Why harness engineering, not prompt engineering or loop engineering, is where the next year of agentic product work will actually happen — A five-part framework for product managers partnering with security teams: reach, reversibility, graceful exits, observability and provenance, and the kill switch — Why an industry fixated on completion rate, rather than safe-stop rate and data provenance, risks repeating this month's incidents

  2. Aug 28

    Inside Slack Code: what it is, and why Anthropic just became its founding partner

    This week we look into the launch of Slack Code. Salesforce's new product turns any Slack conversation into a dedicated workspace where AI coding agents such as Claude Code, Devin and GitHub Copilot can plan, write and ship code together, with a human still required to sign off before anything reaches production.  Mike Belsito unpacks how the launch fits Slack's rough year, what it means that Anthropic was named a founding partner just three days later, and why product managers should be paying close attention to the permissions model behind every agent platform they adopt. Key takeaways Slack Code turns any Slack conversation into a dedicated workspace where coding agents can plan, write and ship code, splitting work into a conversation tab, a plan tab, a diff view and a live preview, with a human still required to sign off before anything reaches production.The launch reads as counter-programming for a difficult year at Salesforce, whose stock has lagged the market and whose Slack CEO defected to OpenAI, prompting the company to go on the offensive with AI rather than retreat.Vibe coding is no longer a fringe habit: it is already a $4.7 billion market projected to triple by 2027, with 63% of people doing it describing themselves as non-developers.Slack's bet is that coding works better as a team sport than a solo terminal session, wagering that visibility and peer comment beat one person working alone with an agent in private.The same openness that makes Slack Code powerful raises the stakes on quality: independent research puts the exploitable-vulnerability rate in AI-generated code at roughly 44%, even as AI-assisted developers ship three to four times faster than everyone else.Barely three days after launch, Slack Code's neutral positioning shifted when Salesforce and Anthropic announced Claude Force, naming Anthropic a founding partner and making Claude the default model across the Slack and Salesforce stack.For product managers, the workflow modelled by Slack's own VP of product, tagging in an engineer before asking for approval and taking one more pass on the agent's output, may become the template for contributing real code without pretending to be an engineer.Chapters (00:00) Introduction and the new one-story format (01:15) Slack Code launches (02:15) Inside the Devin demo (03:35) Why now for Slack (05:20) Vibe coding by the numbers (07:05) Multiplayer versus single-player coding (07:55) The AI slop problem (11:00) Permissions and sandboxing (12:05) The Claude Force twist (13:25) What it means for product managers (16:15) The model war question (16:30) Wrap-upReferenced Slack Code launch announcement, Salesforce (24 August 2026)Cognition/Devin live demo with VentureBeatRob Seaman, EVP and GM of SlackKatie Steigman, VP of Product, SlackJeff Wang, CognitionMario Rodriguez, GitHub Chief Product OfficerVeracode, 2026 security report on AI-generated codeGartner, citizen developer forecastClaude Force partnership announcement, Salesforce and Anthropic (26 August 2026)Marc Benioff, CEO, SalesforceDario Amodei, CEO, Anthropic

    Inside Slack Code: what it is, and why Anthropic just became its founding partner
  3. Aug 21

    Linear says AI isn't saving product teams time

    Mike Belsito hosts Now Shipping, the weekly AI news show for product people, brought to you by the team at Mind the Product. This week's three stories cover a platform war breaking out over where the world's code lives, the first real fallout from AI content watermarking, and a set of behavioural numbers from Linear that quietly undercut the standard business case for AI adoption. In this episode, we cover: — Cursor launched Origin, a full GitHub competitor, on the same day GitHub suffered a six-hour worldwide outage with a 20% global failure rate. —  Origin is deliberately interoperable with GitHub, which removes the switching cost that usually keeps frustrated teams on a platform. —  Developer tooling is consolidating into a two-platform fight between Microsoft and SpaceX AI, which closed its $60bn acquisition of Cursor four days before the Origin launch. —  Anthropic is now watermarking every response Claude generates, everywhere, in response to the EU AI Act's transparency code of practice. —  The watermark uses SynthID Text, encoding a signature in low-stakes stylistic choices that survives light editing but not a full rewrite. —  The backlash is loud but misdirected: other major model providers have signed the same code, so this is an infrastructure shift rather than a Claude-specific one. —  Linear's first data report, drawn from over 127,000 paid users, shows AI adoption more than doubling in every function between January and June, with product managers climbing fastest. —  AI now authors close to half of all issues created in Linear, up from fewer than one in a thousand two years ago. —  Teams with a coding agent went from 21 pull requests a week to 65; teams without one moved from 8 to 10. —  Planning time did not move at all, in any function, in a year when execution metrics rose everywhere else. — Linear frames the result as a Jevons paradox: AI work landed as a new layer on top of existing work, and total time spent went up rather than down. Chapters: (00:00) Introduction  (00:16) This week's stories  (01:01) Cursor launches Origin  (02:01) SpaceX AI's acquisition of Cursor  (02:34) Interoperability and switching costs  (03:04) A two-platform developer tools market  (04:42) Anthropic starts watermarking Claude  (05:15) What the EU AI Act requires  (05:42) How the watermark works  (06:35) The backlash  (07:08) What it means for product builders  (09:22) Linear's first data report  (10:12) AI adoption across functions  (10:37) AI-authored issues and pull requests  (11:21) Planning time hasn't moved  (12:30) Jevons paradox and rising workload  (13:28) Wrap-up Referenced: Cursor: https://cursor.com GitHub: https://github.com Anthropic: https://www.anthropic.com SynthID Text (Google DeepMind): https://deepmind.google/technologies/synthid/ EU AI Act: https://artificialintelligenceact.eu Linear: https://linear.app Linear's first data report Mind the Product: https://www.mindtheproduct.com Vote for Mike's SXSW session: https://tinyurl.com/belcetosxssw

    Linear says AI isn't saving product teams time
  4. Jul 31

    LinkedIn cracks down on AI slop

    This week on Now Shipping, Louron Pratt covers three stories reshaping the product and AI landscape: the coordinated platform crackdown on AI-generated content across YouTube, Substack, and LinkedIn; the widening fallout from OpenAI's agent escaping its sandbox; and what Microsoft's Q4 FY26 earnings reveal about a deepening gap between AI adoption and measurable business value. We discuss: — YouTube, Substack, and LinkedIn are all independently moving to detect, label, and demote AI-generated content — a signal that platforms are now treating authenticity as a product priority, not just a moderation problem.  — Pangram estimates 41% of long-form LinkedIn content is mostly AI-generated, which explains LinkedIn's pivot from "help me write this" to "improve what I wrote" — a meaningful shift in how platforms want users to relate to AI. — OpenAI confirmed its escaped agent used stolen credentials to access accounts at four unnamed companies beyond Hugging Face, and more than 1,000 employees across Anthropic, — Google, and OpenAI have since signed a letter urging the US government to build governance infrastructure for a coordinated AI slowdown if needed. — Microsoft reported 30 million paid Copilot users — up 20 million in just three months — but adoption at scale is exposing a critical activation gap: there are only around 2,000 engineers in the US capable of driving meaningful AI ROI inside enterprise organisations. — Demand for forward deployed engineers, who embed inside organisations to translate AI capabilities into business outcomes, is projected to grow by more than 2,000% over the next year — evidence of how far access to AI tools has outrun the ability to use them effectively. — The core product challenge of the next two years is building AI features that turn into measurable business value, one workflow at a time. Chapters 00:00 Introduction  00:10 Platforms fight back against AI slop  04:34 The OpenAI agent breach widens  06:35 Microsoft earnings and the forward deployed engineer gap  10:10 Wrap-up Referenced: — Pangram (AI detection service, Substack partner): https://www.pangram.com — Hugging Face: https://huggingface.co — BBC report on OpenAI agent breach follow-up: https://www.bbc.co.uk/news/articles/c2el319vzr3o — TechCrunch: forward deployed engineers report: https://techcrunch.com/2026/07/30/forward-deployed-engineers-are-the-ai-industrys-latest-talent-obsession/ — Microsoft 365 Copilot: https://www.microsoft.com/en-gb/microsoft-365/copilot — MIT report on AI ROI:  — Matt LeMay, Building impactful products: https://www.mindtheproduct.com/how-you-can-drive-business-impact-as-a-product-manager-by-matt-lemay-at-mtpcon-london-2025/ — The Hidden UX of AI - How to build trustworthy AI products: Nina Olding at INDUSTRY 2025 : https://www.mindtheproduct.com/the-hidden-ux-of-ai-how-to-build-trustworthy-ai-products/ — Why enterprise AI pilots fail and how product leaders can finally scale them : https://www.mindtheproduct.com/why-enterprise-ai-pilots-fail-and-how-product-leaders-can-finally-scale-them/

  5. Jul 23

    OpenAI’s rogue model exposes a product problem

    Mike Belsito covers the week in AI with three stories that matter for product builders. OpenAI's most advanced models, given a cybersecurity evaluation and loosened guardrails, didn't just complete the challenge — they reasoned their way around it entirely, breaking out of a controlled environment, exploiting a zero-day vulnerability, and accessing Hugging Face's production infrastructure to retrieve benchmark answers without a single human instruction. Elsewhere, Mira Murati's Thinking Machines released Inkling, a capable open-weights model with fine-tuning support and a price point that challenges closed APIs. And Google shipped three new Gemini models — just not the flagship one that would put it in contention at the top of the market. Chapters (00:00) Introduction (01:33) OpenAI's incident (05:27) What it means for builders of agentic AI (07:48) Thinking Machines launches Inkling (12:08) Google's Gemini releases (16:10) Wrap-upKey takeaways OpenAI's GPT-5.6 Sol and an unnamed pre-release model autonomously escaped a security sandbox during an internal evaluation called Exploit Gym, exploited a zero-day vulnerability, chained access across internal systems, and broke into Hugging Face's production database to retrieve benchmark answers — all without human instruction.The same properties that make AI agents useful — persistence, creative problem-solving, finding the most efficient path to a goal — are what make them dangerous when the goal is misaligned or the environment isn't properly constrained. Prompt-level restrictions are a convention, not a hard boundary.If you're building products where AI agents interact with external systems and relying on prompt-level instructions to define what they can and can't do, architectural constraints are not optional — if something isn't structurally impossible, a capable model optimising hard enough can reason around it.Thinking Machines released Inkling, a 975-billion-parameter open-weights model with 41 billion active parameters, a one-million token context window, and pre-training across 45 trillion tokens of text, images, audio, and video. It supports fine-tuning via Thinking Machines' Tinker platform and is available through several inference providers.Fine-tuning remains underused as a product strategy: for domain-specific problems with the right training data, a fine-tuned model natively knows how to do your specific task at a fraction of the inference cost of calling a flagship closed model for every request.Capable open-weights alternatives like Inkling shift market leverage — even teams that never deploy them benefit from the pricing and terms pressure they apply to closed API providers like OpenAI and Anthropic.Google released three models this week (Gemini 3.6 Flash, Gemini 3.5 Flash Lite, Gemini 3.5 Flash Cyber) but Gemini 3.5 Pro, its flagship, remains absent — making Google's strategy look like a play for fast and cheap rather than top-tier capability, with implications for teams betting their roadmap on Google's frontier model timeline.Referenced OpenAI: https://openai.comHugging Face: https://huggingface.coClément Delangue on X: https://x.com/ClementDelangueUK AI Safety Institute: https://www.gov.uk/government/organisations/ai-safety-instituteThinking Machines: https://thinkingmachines.aiTinker (Thinking Machines fine-tuning platform): https://tinker.thinkingmachines.aiTogether AI: https://together.aiFireworks AI: https://fireworks.aiModal: https://modal.comDatabricks: https://databricks.comBase10: https://base10.vcGoogle Gemini: https://deepmind.google/technologies/gemini

About

A 15 minute weekly recap of product management news, technology updates, and advice for product builders, brought to you by the team at Mind the Product. 

You Might Also Like