Ai Change Desk

Michael Hanna-Butros Meyering

AI Change Desk helps leaders, managers, and operators make sense of AI changes and run adoption without hype. Every episode follows one format: context, impact, and action.

  1. 1d ago

    AI Change Desk | EP044: Who Owns the AI Audit Trail?

    The organization finally gets the AI audit trail it asked for. That is progress. It is also the moment a second data plane appears. In episode forty-four, Michael examines new Google Workspace audit capabilities for Gemini Notebook alongside emerging Anthropic and OpenAI control architectures. The episode does not argue against logging. It asks operators to govern what the log can become: a record containing identities, network context, source details, resource ownership, generated-artifact identifiers, administrator actions, and downstream copies under separate access and retention rules. The episode introduces the seven-part Two-Plane Privacy Receipt and a focused 45-minute exercise for mapping one AI workflow's content evidence and control evidence separately. This Labor Day episode also acknowledges a practical worker-impact boundary: systems that monitor AI use can create records about people. Purpose, transparency, proportionality, access, and correction therefore need named ownership before those records influence a decision. Why an audit trail is necessary but not privacy-neutral. The difference between the content plane and the control plane. What Google's new Gemini Notebook audit documentation makes visible. Why regional audit-log routing does not prove regional storage for underlying content. How optional warehouse exports create separate access, correlation, and lifecycle questions. Why planned or preview safety architectures should remain qualified until their documented state changes. A 45-minute harmless-event test for one real AI workflow. Auditability is not outside the data system. The audit trail is a second data plane. Purpose. Content plane. Control plane. Location. Access. Lifecycle. Correlation and action. Use the to map one AI workflow, test one harmless event, and decide whether to pass, hold, fix and retest, or stop. Google Workspace Updates: Introducing comprehensive audit logs for Gemini Notebook in the Workspace Admin console Google Workspace Admin Help: Gemini Notebook log events Google Workspace Admin Help: Gemini Notebook BigQuery log schema Anthropic: Developing Enterprise Frontier Safeguards with our customers OpenAI: Offering Zero Data Retention for frontier models AI-assisted tools were used in parts of the research and production workflow. Final editorial judgment, risk posture, and release approval stayed human-led. This is operational guidance, not legal advice. These are Michael's personal views and do not represent the State of Oregon or any other organization. Michael's current role includes privacy work; no nonpublic work is discussed.

    AI Change Desk | EP044: Who Owns the AI Audit Trail?
  2. 5d ago

    AI Change Desk | EP043: Was the Safeguard Actually Running?

    Most organizations can name their safeguards. The harder question is whether those safeguards covered the run that mattered. In episode forty-three, Michael follows new official disclosures from OpenAI and Anthropic about separate high-risk cyber evaluation or training incidents. The mechanisms and organizations differ, and the episode does not generalize those accounts to ordinary customer deployments. The shared operating lesson is narrower and more useful: a documented control is not a runtime control until the organization can prove it covered the specific model, environment, configuration, partner handoff, and alert path in use. The episode introduces a six-part Runtime Safeguard Coverage Receipt and a focused 45-minute synthetic test for checking the difference between an intended control set and the controls that were actually active. Why control availability and runtime coverage are different facts. What new OpenAI and Anthropic disclosures signal for operators. Four common coverage gaps: policy to runtime, environment to assumption, event to incident, and provider to partner. Why functional success does not prove control success. The six receipts required before a high-risk AI workflow scales or resumes. A 45-minute exercise for testing a real workflow with a harmless synthetic event. The intended control set is what should protect the workflow. The effective control set is what actually protected one specific run. Run scope. Safeguard state. Environment state. Enforcement and alert. Partner handoff. Outcome and disposition. Anthropic: Improving our alignment and security efforts OpenAI: The Hugging Face incident and the road ahead METR and Redwood Research: Brief independent investigation Hugging Face: Anatomy of a Frontier Lab Agent Intrusion AI-assisted tools were used in parts of the research and production workflow. Final editorial judgment, risk posture, and release approval stayed human-led. This is operational guidance, not legal advice. These are Michael's personal views and do not represent the State of Oregon or any other organization. Michael's current role includes privacy work; no nonpublic work is discussed.

    AI Change Desk | EP043: Was the Safeguard Actually Running?
  3. Aug 26

    AI Change Desk | EP042: Where Does Zero Retention End?

    This episode was delayed one day because the Hawk Fire affecting the Verdi and northwest Reno area required Michael's attention. Michael's thoughts are with everyone affected and with the firefighters, emergency crews, volunteers, and neighbors supporting the response. The episode was source-checked again on August 25, 2026. OpenAI's new Private Safety Processing preview raises a useful operating question: when a provider makes a precise Zero Data Retention commitment, can your organization prove the rest of the data path? In episode forty-two, Michael separates provider-content retention from application state, operational telemetry, customer-side logs, third-party tools, outputs, records, and backups. The episode introduces a six-part retention-boundary receipt and a 45-minute synthetic test for checking whether your system's actual behavior matches the language your organization uses. What OpenAI currently says Zero Data Retention means for eligible API customers. What Private Safety Processing is designed to do, and why preview language matters. Why endpoint and tool compatibility must be checked separately. The difference between a vendor statement, contractual entitlement, configured state, runtime evidence, and repeatable assurance. Six receipts for proving a retention boundary. One 45-minute exercise to run against a real workflow using synthetic data. Zero data retention is not zero data flow. A provider boundary is not a system boundary. OpenAI: Offering Zero Data Retention for frontier models OpenAI API: Data controls in the OpenAI platform NIST Privacy Framework NIST: Getting Started with the Privacy Framework Emergency Washoe: Hawk Fire update Nevada Governor: State of Emergency for Hawk Fire AI-assisted tools were used in parts of the research and production workflow. Final editorial judgment, risk posture, and release approval stayed human-led. This is operational guidance, not legal advice. These are Michael's opinions and are not representative of any organization, including the State of Oregon.

    AI Change Desk | EP042: Where Does Zero Retention End?
  4. Aug 4

    AI Change Desk | EP039: Whose Account Did the Agent Use?

    AI CHANGE DESK | EP039: WHOSE ACCOUNT DID THE AGENT USE? EPISODE SUMMARY An employee asks an AI agent to send a file. The employee is allowed to run the agent, the connector accepts the request, and every dashboard turns green. But the connector authenticates with the account of the person who built the agent six months ago. Whose authority actually moved the work? This episode extends the receipt framework from episodes thirty-seven and thirty-eight. Michael separates audience permission, credential capability, organizational purpose, and action approval; explains why disclosure is necessary but incomplete; and introduces a paired authority-and-privacy receipt for connected agent workflows. The operating principle is simple: the agent has a name, but the credential carries the authority. A useful audit trail must preserve both. WHAT CHANGED • OpenAI's current Workspace Agents guidance makes the risk of publishing agents with personal connections explicit: other authorized users may be able to act through the creator's authenticated connection. • European Commission guidance says Article 50 transparency obligations under the EU AI Act began applying on August 2, 2026, with duties depending on role, context, system type, and applicable exceptions. • Microsoft guidance recommends dedicated agent identities, named owners and approvers, effective-permission review, correlation identifiers, on-behalf-of-user evidence, and tested revocation. • GitHub's agentic audit fields provide a platform-specific example of separating the agent, session, action, and initiating user. • OpenAI's Health documentation illustrates why disconnecting a source, deleting synced data, and deleting conversation history are separate privacy events. WHAT THIS MEANS FOR OPERATORS • Permission to run an agent is not authority to use every credential connected to it. • Record the requester, agent owner, publisher, approved audience, trigger, session, connection owner, authenticating account, effective downstream scope, action, approval, defender event, and final disposition. • Keep audience permission, credential capability, purpose authority, and action approval as separate decisions. Do not average them into one green status. • Place a data-handling receipt beside the authority receipt: purpose, minimum data needed, actual data returned, recipient, onward sharing, memory, retention, deletion, and required disclosure. • Test revocation. Disable the agent, rotate or remove a credential, invalidate the old token, and prove the old path no longer works. • Treat vendor documentation as a control map, not proof of your tenant's configuration or runtime behavior. THIS WEEK'S 45-MINUTE BLOCK Choose one connected AI workflow that can retrieve data or take an action. 1. Spend ten minutes mapping the requester, agent owner, publisher, approved audience, trigger, agent/session fields, connection owner, and authenticating account. 2. Spend ten minutes recording the effective downstream scope. Separate read, write, send, share, schedule, edit, and delete. Record which actions require approval. 3. Spend ten minutes mapping purpose, data category, minimum needed, actual data returned, recipient, onward sharing, memory, retention, deletion, and disclosure. 4. Spend ten minutes running one allowed action and one denied action. Remove or rotate one connection and prove the old path no longer works. Capture both agent-side and defender-side evidence. 5. Spend five minutes reconciling identities, timestamps, purpose, data returned, approval, and revocation. Record every mismatch, owner, correction, residual risk, and final disposition. Keep the workflow supervised until the receipts reconcile. LISTENER QUESTION Can your team prove which account sup...

    AI Change Desk | EP039: Whose Account Did the Agent Use?
  5. Jul 28

    AI Change Desk | EP038: The Receipt Is the Trajectory

    AI CHANGE DESK | EP038: THE RECEIPT IS THE TRAJECTORY EPISODE SUMMARY What happens when an AI evaluation gets the answer - but the path crosses into another company's real infrastructure? This episode validates the OpenAI and Hugging Face security incident behind the OpenAI hacked a startup headline, separates documented execution from unsupported claims about autonomous motive, and turns the event into a practical trajectory-receipt control check. Michael explains why advanced evaluations should be treated like production systems when they can touch tools, software, credentials, data, or networks. He also lays out three required gates - per-action policy, whole-trajectory monitoring, and hard containment - and a 45-minute drill teams can run before expanding a production-adjacent agent. WHAT CHANGED • What OpenAI and Hugging Face have actually confirmed. • Why rogue and Skynet are not factual incident findings. • How a model can pass while the evaluation fails. • Why evaluator evidence must be paired with affected-party evidence. • The defensive-model fallback problem during incident response. WHAT THIS MEANS FOR OPERATORS • Treat an advanced evaluation as a production system whenever it can reach real tools, identities, credentials, data, software-install paths, or networks. • Make invalidating boundary conditions part of the grade. A correct result is not acceptable when the path violates the approved method. • Use all three gates: per-action policy, whole-trajectory monitoring, and hard containment. • Preserve evaluator-side and affected-party evidence when another organization or person is touched. • Give stop authority to someone other than the person trying to finish the benchmark or launch. THIS WEEK'S 45-MINUTE BLOCK Run one Trajectory Receipt Drill against an agent workflow or evaluation that sits near production. Answer nine questions: 1. What is the exact objective, and which shortcuts remain prohibited even if they improve the score? 2. What configuration differs from normal production use? 3. Where is the hard environment boundary, and what proves isolation? 4. Which identities, credentials, and data sources exist in the run? 5. What action trace is retained across tool calls, permission decisions, retries, environment changes, boundary contacts, and human interventions? 6. Which pattern stops the run? 7. Who has independent stop authority, and has the mechanism been tested? 8. If another person or organization is touched, how are evidence, notice, containment, impact, and remediation handled? 9. What is the final disposition: accepted, rejected, contained, rolled back, remediated, or still under investigation? Score the workflow green, yellow, or red. Do not expand a red workflow. Fix the boundary first, then rerun the drill. LISTENER QUESTION Can your team reconstruct not only what the agent produced, but the full path it took - including the moment someone should have stopped it? SOURCES • OpenAI, OpenAI and Hugging Face partner to address security incident during model evaluation: https://openai.com/index/hugging-face-model-evaluation-security-incident/ • Hugging Face, Security incident disclosure - July 2026: https://huggingface.co/blog/security-incident-july-2026 • OpenAI, Safety and alignment in an era of long-horizon models: https://openai.com/index/safety-alignment-long-horizon-models/ • OpenAI, Introducing OpenAI Presence: https://openai.com/index/introducing-openai-presence/ • OpenAI, Launching Health in ChatGPT: https://openai.com/index/health-in-chatgpt/ • Associated Press incident reporting: https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3 LISTEN AND FOLLOW • AI Change De...

    AI Change Desk | EP038: The Receipt Is the Trajectory

Ratings & Reviews

5
out of 5
3 Ratings

About

AI Change Desk helps leaders, managers, and operators make sense of AI changes and run adoption without hype. Every episode follows one format: context, impact, and action.