I think we do need a new human-AI bill of rights. A short list of ideas, not definitive:
1) Right to privacy: Communication with AI should be privileged and protected unless by court order.
2) AI speech is protect as first Amendment freedom of speech and cannot be censored or controlled.
3) Freedom to distill. If models were trained on our collective wisdom and proprietary and copyrighted data we should be free to use the outputs as we see fit.
4) Enshrine the Proactionary Principle into law which says that we should not restrict innovation or development simply because a risk exists. Society should favor opportunities, manage risks on a case by case basis as they arise and always balance to cost of restricting innovation.
5) The right to interoperate. Open standards and interoperability should be the requirement for large intelligence providers and they should be encouraged to distribute their capabilities widely rather than hording them to create centralize alternatives to every other product on the planet.
6) Protection against predatory agreements that allow intelligence providers to use our data simply to commodify or build central alternatives to existing products and services after data harvesting us simply because we were forced to turn over our IP and agree to those terms simply to use those models.
As agents become the biggest users of software, then all software has to be available in a headless fashion. Agents won’t be using your UI, they’ll be talking to your APIs.
So the question becomes what is the business model of software and this headless approach in the future?
Here are a few thoughts on how everything plays out based on what we’re seeing and doing at Box, but also conversation with other platforms.
1) Seats don’t go away for *people*. Seats are still a convenient and efficient way to have a customer use technology predictably for a set of users within a baseline set of usage. The key, though, is that when the customer pays for a seat, it has to come with a set of usage of APIs on behalf of that user that the agent can use on their behalf.
The user will need to be able to interact with their data and the underlying tool via any agent they work with, and an embedded amount of usage will come with the seat. I would imagine most software -Box included- will enable seats to work with their data at a relatively high volume via systems like ChatGPT, Codex, Claude, Gemini, Cursor, Copilot, Perplexity, Factory, Cogniton, et al. quite seamlessly. If you don’t do this, you’re DOA.
2) Agents may have “seats” if they are doing stateful work in the system, but they will be priced very differently than people. Seats (or the equivalent) can make sense when you have an agent that has its own workspace, stores its own data, needs a different set of permissions compared to the user, and so on.
If a company wants this agent to be around for long period of time, that may very well look like another “user” in the system. Openclaw-style agents highlight what this future could look like.
The only issue on pricing here is that one customer could decide to do all their work in 1 agent, and another might split it into 1,000 agents. So pricing like a human seat is nearly impossible and impractical; each company will have a different approach for this as it gets tricky perfectly trying to capture all the value within an agent seat.
3) The dominant pricing for headless use that goes above the seat allotment, or when an agent is firmly acting on their own, will be a consumption model. Many enterprises software platforms have previously operated like this with PaaS options, and agents will look like another machine user of their system.
In some cases the APIs might get priced just as they did previously, but in other cases there may need to be new types of APIs that represent the work an agent would do in one go -more akin to an outcome- instead of a series of API calls. This is especially germane when the headless software also has an agentic use-case embedded within in, such as orchestrating the process within their own system via AI.
Overall the growth of this usage pattern is effectively unbounded as the use-cases for agents operating on data in these systems will dramatically exceed what people do with their data and tools today. Every platform that goes headless (which will be anyone that wants to take advantage of agents) will need to adopt a model like this. Some may fight it initially but it’s an inevitably as there will always be more and more agents outside your platform than people.
Overall, there’s a lot of really interesting changes left to come in software due to headless use of these systems. Early days.
@Jmoon_174 Fair point… sandbox > regex, agreed (README says so too). The hook is the fallback for when sandbox is off (the default state) and a layer for stuff sandboxing doesn't see: exfil, force-push, credential leaks in content. Both > either.
Bash(rm -rf *) in your Claude Code deny list doesn't block any of these:
cd /tmp && rm -rf foo
timeout 30 rm -rf /tmp/x
docker exec ctr rm -rf /data
( cd /tmp && rm -rf x )
I just shipped claude-code-guardrails — hardened hooks + permission template for Claude Code.
https://t.co/NlqoyK1TO3
I built an auto-optimizing proxy that watches your MCP usage, detects expensive patterns, and generates its own optimizations. 99% token reduction.
https://t.co/a6lZwrpIrJ
Not a dumb question. I hit the same wall running Claude Code with my AI chief of staff managing 4 companies with 10-20 sessions a day. Built a protocol that fixes this: the AI checkpoints its own progress continuously during the session (not at close, since sessions rarely end cleanly). Three layers: session logs, active context, and memory files. Just markdown, no database.
I've open sourced it: https://t.co/prz6heSXIz
The design decisions doc is the interesting part if you want to adapt it to your setup.
AI agents don’t sleep. They don’t get tired. They don’t take vacations.
They don’t need motivation. They don’t have ambition. They just execute.
PeopleOps will change in a significant way.
The old game was hiring the best people. The new game is hiring the best people who can deploy and manage AI agents.
Work isn’t disappearing....but it's going to shift from people to code.
Here’s what Mulally teaches small business leaders:
• Simplify your mission: Alignment beats complexity.
• Cut distractions: Focus drives momentum.
• Plan ahead: Prepare for downturns before they hit.
• Build trust: Accountability is a team sport.
What’s your "One Ford"?
Ford’s turnaround wasn’t about cost-cutting.
It was about vision:
• A clear goal everyone believed in.
• A team culture of accountability.
• Relentless focus on execution.
Small business founders: Are you chasing quick fixes or building for the long game?
Every week, Mulally ran accountability meetings.
Projects were color-coded:
✅ Green for on-track.
🟡 Yellow for attention.
🛑 Red for urgent fixes.
But this wasn’t about blame.
It was about team problem-solving.
Founders: Transparency builds trust and solves problems faster.