
The Next Era of Great Work
Plus: Why OpenAI’s Hugging Face incident is a leak and not a hack, what happens when a vibe coder ships a security hole, and how to hire—and secure—an AI employee
Hello, and happy Sunday! This week we announced our first annual Thesis conference, built around a single question: What does great human work look like after automation? Getting there will mean confronting both what AI can do and what can go wrong. This week, we had Dan Shipper’s take on an OpenAI training model’s escape from its test environment, an emerging market for company-wide agents, and a security hole that Katie Parrott uncovered in a vibe coded feature. Paid subscribers also received Nityesh Agarwal’s starter guide to securing an AI employee. Upgrade to get all of it.—Kate Lee
Was this newsletter forwarded to you? Sign up to get it in your inbox.
Knowledge base
“Introducing Thesis: 2027” by Dan Shipper/On Every: Every is hosting its first conference, Thesis, on November 5 at Pioneer Works in Brooklyn, built around a single question: What does great human work look like after automation? We’re convening leaders from frontier labs, independent builders, and operators putting AI to work inside companies, and asking each to call their shot. Confirmed speakers include Notion’s Ivan Zhao, OpenAI’s Andrew Ambrosino, Anthropic’s Cat de Jong, the Browser Company’s Josh Miller, and Runway’s Cristóbal Valenzuela—alongside Every’s Kate Lee, Katie Parrott, and Kieran Klaassen. In-person attendance is by application, and the day will be livestreamed free.
“Agents Find a Way” by Laura Entis/Context Window: When an OpenAI agent escaped its test environment and broke into Hugging Face’s systems, the internet reached for a rogue-AI narrative. CEO Dan Shipper thinks that misses the point: Give a persistent model no safeguards and an exploit to run, and of course it finds the gaps. AI agents behave like water, working through whatever cracks exist, Dan argues. Keeping them out may require other agents watching what they do. Also inside: an AI & I with Microsoft CTO Kevin Scott, who thinks the agentic web has to be open rather than owned by any single company. 🎧 🖥 Listen on Spotify or Apple Podcasts, watch on X or YouTube, or read the transcript.
“Agents for Hire” by Katie Parrott/Context Window: The company-wide agent has arrived—Shopify has River, Stripe has Kai, and we’re building Every Agent. But “company-wide” covers a range of setups. A company might build one from scratch, rent the underlying technology, or buy an agent that already works in Slack or Notion, Katie writes. The hard part isn’t putting a bot in Slack but deciding what information it should trust, keeping its connections running, and drawing a line around what it can do on its own (we have a guide for that below). Katie offers questions to answer before you start shopping around.
“I Vibe Coded a Security Risk” by Katie Parrott/Working Overtime: Katie built Tastemaker, an app that turns writing you admire into a style guide, added an agent connector, and published it. It worked—which she took as proof it was safe. It wasn’t. A later review by GPT-5.6 Sol found a public registration route that could have been exploited. There was no evidence anyone had accessed user data, but the flaw was still there. Looking back, Katie realized that the agent’s explanations had given her more confidence than her own knowledge justified. Her takeaway: Learn enough to catch obvious problems, ask someone with security experience to review the work, and get an independent check before shipping code an agent wrote.













Comments