>gabes/the letter
// the weekly letter · issue 10 · aug 31 to sep 4

five signals.
one week.
nobody ran
the test._

three large employers who cut roles on a business case and hired them back without a release. a hundred thousand complaints about a bot with no exit. a regulator whose whole standard is did you test what you sold. an ad product that listened to nothing and billed for years. and three in ten dead pilots whose credentials are still live. five stories where the only evidence in the room came from the person selling.
01shiftmonday

ford, ibm and commonwealth bank all cut roles on an automation case, then hired people back into them. none of them put out a release about the second part.

the systems did the tasks. the role was never a list of tasks.

reporting from july put three large employers in the same position: reductions made on an ai business case, followed by quiet rehiring once the systems could not carry the work end to end.

the condition underneath it is a category error made at the budgeting stage. a role gets priced as the sum of its visible tasks, and everything else in it, judgment about exceptions, context nobody wrote down, the call to the customer who is halfway out the door, is valued at zero because it never appeared in a process map. the cost is not the salary you saved and then gave back. it is the rehire at market rate, the institutional memory that left with the first round, and a team that now reads every efficiency project as a layoff with a project plan attached.

the fake fix is a better assessment of which jobs ai can do, which is the same question that produced the first answer. ask a different one. take the role you are tempted to automate and write down what happens in it when something goes wrong, who decides, and what they need to know that is written down nowhere. automate the documented part, keep the person on the undocumented part, and you get the savings without paying a recruiting fee to find out what the job was.

dowrite down what happens in the role when something goes wrong, who decides, and what they know that is written down nowhere. automate the documented part only.
not thisdo not commission a better assessment of which jobs ai can do. that is the same question that produced the answer you are now unwinding.
the process map is not the job. it is the part of the job somebody had time to write down.
receiptjuly 2026 reporting: ford, ibm and commonwealth bank each reduced roles on an automation business case and subsequently rehired into those functions, without public announcement of the rehiring
shipped monday · read it as it shipped →
02prooftuesday

the bbb read more than 100,000 complaints filed since 2023. over 90 percent of the reviews mentioning ai customer service describe a bad experience.

almost nobody is complaining that the bot is stupid. they are complaining that there is no way out of it.

that is not a sample of opinion. it is a hundred thousand people who took the time to file, and the pattern in it is consistent enough to plan around.

the condition is a containment design rather than a model problem. deflection rate is the number the vendor sells against, so every handoff to a person scores as a failure and the exit gets buried on purpose. the cost lands on exactly the customers you can least afford to lose, because the ones who escalate are the ones with money at stake or a problem worth fixing, and they leave with a screenshot and a review.

the fake fix is a better bot, more training data, a warmer script, which makes the trap more comfortable without making it shorter. do the version that holds: put a visible route to a human on every step, cap the loop at two failed attempts before it hands off with the full transcript attached, and change the number your team watches from containment rate to resolved on first contact. then call ten customers who used it last month and ask what happened, because the vendor dashboard is not going to volunteer it.

doput a visible route to a human on every step, cap the loop at two failures, and watch resolved on first contact instead of containment rate.
not thisdo not buy a better bot. more training data and a warmer script make the trap more comfortable without making it shorter.
the number the vendor optimises is the number that measures how long you kept the customer away from you.
receiptbbb analysis of more than 100,000 complaints and reviews filed since 2023: over 90 percent of reviews mentioning ai customer service describe a negative experience
shipped tuesday · read it as it shipped →
03movewednesday

every ftc case against an ai vendor comes down to one question: did you test the capability you sold. most of them could not answer it.

that is not a regulator's question. it is a buyer's question, it takes one email, and it costs nothing.

operation ai comply runs on a standard that is lower than it sounds. a company claiming an ai capability has to have tested that capability and kept the results. in the donotpay matter the ftc alleged the product was never tested against the work of a real lawyer, which is the entire case in one sentence.

the condition on your side of the table is that ai purchases get decided on a demo and a reference call, both supplied by the seller, so the only evidence in the room is the evidence they chose to bring. the cost is not the licence fee. it is eight months of a live process running on output nobody measured, plus the rework when somebody finally checks.

the fake fix is a longer diligence questionnaire, which mostly produces marketing copy arranged in a spreadsheet. run the regulator's question instead. before you sign, ask for the test they ran, the sample it ran on, the failure rate it produced, and the name of the person who signed off. a vendor holding that answer sends it the same day. a vendor who stalls has told you what you needed to know, for free, before the money moved.

dobefore you sign, ask for the test, the sample it ran on, the failure rate, and the name of the person who signed it off.
not thisdo not send a longer diligence questionnaire. it produces marketing copy arranged in a spreadsheet and nobody reads it twice.
the answer arrives the same day or it does not arrive. either way you learn the thing you were trying to learn.
receiptftc operation ai comply: the standard requires a company claiming an ai capability to have tested it and retained the results · in the donotpay matter the ftc alleged the product was never tested against the work of a real lawyer
shipped wednesday · read it as it shipped →
// the week's argument

ask for the test.
ask what it ran on.
ask who signed it.

every signal this week turns on evidence that was never produced and never demanded. the business case nobody checked against the job. the containment number the vendor chose. the capability nobody tested. the mechanism nobody could inspect. the access nobody audited. in each one the confidence was real and the test was missing, and the confidence is what did the damage.
04trapthursday

advertisers spent years paying for an ai that listened to customers through their smart devices. there was no voice data in it, the targeting ran on purchased email lists, and the orders came to $930,000.

nobody caught it because the mechanism was the product, and the mechanism was the one part a buyer could never inspect.

cox media group and two marketing firms sold a service they said used a special algorithm to detect relevant conversations near a phone and put local ads in front of the people having them. the ftc says it used no voice data at all, consumers never opted into anything, and the location results did not match the claim. the orders were finalized last week at $930,000 across three settlements.

the condition is not that a vendor lied. it is that the story about how the system worked was doing all of the selling, and any result that came back could be read as proof of the story, because there was no way to test it. that shape is in your budget right now anywhere you are paying for a capability rather than an outcome, and a capability you cannot audit keeps billing long after it stops existing.

the fake fix is asking the vendor to explain the technology in more detail, which gets you a better story from the same people. buy the number instead. name the p&l line the spend is supposed to move, agree how it gets measured before you sign, and hold back a slice of the audience or the accounts that gets none of it. a vendor who will not sell against a number is selling you the explanation.

doname the p&l line the spend must move, agree the measurement before signing, and hold back a slice that gets none of it.
not thisdo not ask the vendor to explain the technology in more detail. that gets you a better story from the same people.
if the only evidence is the explanation, you are not buying a capability. you are subscribing to a narrative.
receiptftc, orders finalized august 2026: cox media group and two marketing firms, $930,000 across three related settlements · ftc found the advertised voice detection used no voice data, consumers did not opt in, and location claims did not match results
shipped thursday · read it as it shipped →
05warningfriday

three in ten agentic pilots have been paused or killed. the accounts those pilots were given are mostly still open, still credentialed, still able to act.

the pilot ended in a meeting. the access ended nowhere.

survey work across 202 enterprise technology and security leaders puts 65 percent of them in a position where an ai agent has already acted outside its intended scope, 29 percent with measurable impact, and 47 percent without a reliable inventory of the agents running in production.

the condition is that agents get provisioned like software and retired like meetings. somebody grants a service account and production access to get the pilot moving, the pilot stalls, and nobody owns the revocation because nobody owned the grant. the cost is a standing credential attached to a project with no budget, no sponsor and nobody watching, which is the exact profile of the access an attacker wants. 46 percent of these organizations could not produce a complete audit trail of one agent's activity over the last thirty days if you asked today.

the fake fix is an ai governance policy, and the researcher's own line on that is worth keeping: most organizations have policies and real confidence in them, and the gap is between what is written down and what is enforced. do the boring version this week. list every agent by name with the credential it holds and the person accountable for it, kill the credentials on anything paused or discontinued, and make decommissioning a named step in the pilot plan rather than an afterthought.

dolist every agent with its credential and its accountable person, kill the credentials on anything paused, and make decommissioning a named step in the pilot plan.
not thisdo not write an ai governance policy. the gap is not between you and a document, it is between what is written down and what is enforced.
94 percent were confident their agents held no more access than they needed. 32.7 percent had actually provisioned least privilege. treat your own confidence as untested until you have run the list.
receiptsurvey of 202 enterprise technology and security leaders: 65 percent report an ai agent acting outside intended scope, 29 percent with measurable impact, 47 percent lack a reliable production agent inventory, 46 percent could not produce a complete thirty day audit trail for one agent · 94 percent confident on least privilege against 32.7 percent who had provisioned it · three in ten agentic pilots paused or discontinued
shipped friday · read it as it shipped →
// the signal daily, the letter weekly

five claims.
five tests.
none of them run.

one signal a day, monday to friday, public. the letter every friday, the same hour the fifth signal lands: the week compiled, connected, and pointed at what to do. no quizzes, no funnels, no webinar.
good. fridays, then. bring us the part that keeps breaking.
>gabes · operating systems for companies done improvising · issue 10 · past signals →