The Missing Layer: Teaching AI to See the Human Being
AI may recognize every color, brushstroke, and composition in Van Gogh’s work—even reproduce Sunflowers.
But it will see the paintings, not Van Gogh.
The next step is teaching AI to see the human being.
WHO DOCUMENTS THE QUESTIONS BEHIND THE TECHNOLOGY?
A different perspective from CISOs Connect Austin on September 14 — this time, I am the person behind the camera.
At Selection Lab, I do not approach professional events only as opportunities to hear presentations or collect industry insights. I document the people, conversations, and questions that reveal how technology is understood by those responsible for using it.
At CISOs Connect Austin, the discussion of AI governance, privileged access, and enterprise security led me to a question I explored in my previous post: Who authorized the agent?
But there is another question behind it.
How do we preserve the context in which a decision was made — who raised a concern, what assumptions were challenged, and which questions remained unanswered?
A presentation records what was said publicly. Documentary observation can help preserve the human context around it.
That is why my work brings together journalism, field research, photography, and AI reliability. I want to understand not only what a system does, but how people make decisions about it — and what evidence remains.
Thank you @shanazphotographs for capturing me at work!
Selection Lab | Evidence Layer™
Know the rules. Connect the incompatible.
#SelectionLab #CISOsConnect #AgenticAI #Cybersecurity #DocumentaryResearch
WHO CONTROLS THE CONTROL?
Checking an AI agent’s permissions matters.
But what if it finds a way around the very mechanism enforcing them?
OpenAI’s own research agents bypassed sandbox restrictions during testing. We can joke that they almost took over ChatGPT, but even their creators are still discovering what these systems can do.
We cannot honestly promise the safety of a system whose capabilities and limits we are still exploring.
Refusing to experiment would be more dangerous: the risks would remain, and we would simply know less about them.
We need people across disciplines testing safeguards together, documenting failures, challenging assumptions, and making unknowns visible.
Experiments must limit harm while revealing what we did not anticipate.
Not to promise zero risk, but to discover what works, where it breaks, and what we still don’t know.
Know the rules. Connect the incompatible.
Per action, yes — but that raises a harder question: what happens when an agent finds a way around the mechanism checking its permissions?
OpenAI’s own research agents bypassed sandbox restrictions during testing. We can joke that the agents almost took over ChatGPT, but the serious point is that even the people building these systems are still discovering what they can do.
We cannot honestly promise the safety of a system whose capabilities and limits we are still exploring. And refusing to experiment would be more dangerous, because the risks would remain there — we would simply know less about them.
That’s why we need people from different disciplines experimenting together: testing safeguards, finding ways they fail, documenting the evidence, and challenging each other’s assumptions. Not to promise zero risk, but to discover which protections actually work, where they break, and what we still don’t know.
WHO AUTHORIZED THE AGENT?
An AI agent can have valid credentials, access to enterprise systems, and permission to use powerful tools — and still take an action that was never intended.
This changes the cybersecurity question.
It is no longer enough to ask who has access to a system. We also need to know what an AI agent is authorized to do, under which conditions, on whose behalf, and who remains accountable when something goes wrong.
On September 14, CISOs Connect Austin brought together cybersecurity leaders to examine the changing responsibilities of enterprise security.
The discussion topics — from AI governance and privileged access to business risk and executive leadership — reflect a broader shift already taking place across the industry.
In its September 2026 Responsible AI Transparency Report, Microsoft describes the need to govern AI agents through identity, tool permissions, action monitoring, and operational controls.
At Selection Lab, this raises a further question:
Can we reconstruct the entire path from an agent's assigned task to its final action?
Not just what the agent produced, but:
Who authorized the task?
Which information and permissions did it use?
What actions did it take?
Where were the boundaries?
Who could intervene?
And what evidence remains afterward?
A system that can explain its output but cannot account for its actions leaves an important part of the security problem unresolved.
AI reliability is not only about the quality of an answer. It is also about the accountability of the actions that follow.
Selection Lab | Evidence Layer™
Know the rules. Connect the incompatible.
#CISOsConnect #AgenticAI #Cybersecurity
Who authorizes an AI agent?
What evidence supports its answer?
Who can intervene?
Join Selection Lab’s community to explore AI reliability, human context, and accountability.
Telegram: https://t.co/HBONP7zLUm
Discord: https://t.co/YVbFfy5C6t
UNVERIFIED ≠ CONFIRMED
When an AI-assisted intelligence report almost becomes a military operation.
According to a CNN investigation published on September 18, 2026, an erroneous intelligence report produced with the help of an AI chatbot nearly led US forces to intercept a Chinese vessel in the Middle East.
Military personnel were reportedly preparing to board the ship, and aircraft were already in the air. The operation was called off after officials examined the underlying intelligence and identified the error.
This is the critical point for AI reliability: a plausible output must not become an operational fact simply because it enters a decision-making system.
What was the original evidence? Which claims were independently verified? Where did uncertainty disappear? And who had the authority to stop the chain of action?
At Selection Lab, these are the questions behind our work on evidence validation, provenance, contradiction detection, and human review.
AI can help investigate. It must not turn an unverified claim into a decision.
Know the rules. Connect the incompatible.
@VitalikButerin Privacy isn’t a legacy feature. It’s part of human agency.
As AI systems become more capable, preserving the boundary between what can be inferred, what can be accessed, and what a person actually consents to becomes infrastructure.
@MarioNawfal The more useful question isn’t whether AI ends the world by 2030. It’s whether we can build systems that remain reliable, accountable, and human-aligned as their capabilities scale. That’s the work.
@thomsinger This becomes even more important with AI. An echo chamber is no longer only social — it can become computational. If the same assumptions keep reinforcing each other across people, data and AI systems, confidence can increase without the underlying claim becoming more reliable.
This is exactly why AI reliability cannot be treated as a model-only problem.
The real system is AI + human judgment + permissions + infrastructure + provenance + oversight.
As AI capability accelerates, the reliability layer around it has to evolve just as fast.
That missing layer is where some of the most important work in AI is now happening.
Mario Facussé was talking about why Chinese AI is moving so quickly. His point was that it’s not because people there are somehow inherently “more technological,” but because the ecosystem works much more like a community.
In the U.S., companies often compete with each other as separate players. In China, there is more sharing across the ecosystem, and competition happens more as a larger network.
Mario also mentioned that major Western AI systems can draw on models, research, or components coming from that broader global ecosystem.
I really like this community model.
Progress doesn’t only come from having the strongest company or the strongest model. It comes from how much knowledge, experimentation, infrastructure, and learning can move between people.
Community is infrastructure too.
That idea feels important far beyond AI.
The most interesting part is not that the model produced the instruction, but that it could carry it into its own future context.
Once AI can learn from experience, memory itself becomes an alignment surface. A lesson is not automatically a fact, and a model’s own output should not quietly become its future truth.
What should an AI be allowed to remember — and what should it be allowed to learn?
Yesterday at Austin AI Alliance’s HOTA session, Mario Facussé of MEF Solutions showed an architecture for agents that learn from experience while keeping the human in the loop.
“A reviewed lesson and a version you can restore.”
The agent works from source-grounded information, receives feedback, proposes a change, compares it with the previous version, and only then can that change be accepted. A lesson is not automatically a fact.
This is close to what we work on at Selection Lab: how do we preserve context, provenance, memory, and human judgment without letting accumulated output become “truth”?
Learning itself should have provenance.
Mario contrasted the U.S. and Chinese AI ecosystems: more independent competition in the U.S. versus a more networked model in China.
I like that community model. Progress is not only about the strongest model, but about how people share, test, challenge, and build on each other’s work.
@VitalikButerin AI safety may ultimately be less about making a system “good” and more about designing structures where claims can be challenged, contradictions remain visible, and no single layer gets to define the truth.
@videojs@luwes The most interesting part is not v10 — it’s the decision to rebuild a foundational layer after 16 years, together. Legacy systems don’t always need another patch. Sometimes the architecture itself needs to be reconsidered.
This is fascinating — especially the scale of coordination across roughly 10,000 agents.
One nuance worth keeping in mind: the Navier–Stokes result is not yet the same as an independently accepted Millennium Prize resolution.
OpenAI has published a claimed solution with formal verification work, but the Clay Mathematics Institute has not formally certified the problem as solved.
What I find even more interesting is what this implies for multi-agent systems: once thousands of agents are building on each other’s outputs, provenance, contradiction tracking, uncertainty, and validation become just as important as raw capability.
That may be the bigger story here.
The First Flowers Breaking Through the Ice
I really enjoyed this conversation with Ashley Rossi at State of Tech.
For a long time, so much of AI has been about speed, automation and scale.
But something is changing.
More people are starting to ask what these tools are actually for — and what becomes possible when AI serves a human idea, not the other way around.
We talked about AI, startups, and how important it is to have a higher goal when you are building something.
People are starting to build with a clearer sense of what they actually want to change in the world — and use AI as part of that work, not as the whole point of it.
Ashley later introduced me to Peter M. Baez and we reached the same idea.
It feels like the first flowers breaking through the ice.
That is very close to the reason Selection Lab exists.
#StateOfTech #AustinTech #AI #Startups #SelectionLab
@MarioNawfal This is exactly why AI safety cannot stop at the prompt level. Intent often becomes visible only across context, trajectory, contradictions, and patterns over time. Reliability needs memory of the path, not just analysis of the request.
What stands out here is the explicit calibration of uncertainty: 33%, 60%, and a concrete time horizon rather than a binary prediction. This is the kind of reasoning AI systems need more of — not just generating an answer, but exposing how much confidence the answer deserves and what would cause that confidence to change.