@zachmoskow If the agent can initiate a legally binding payment, the training clause means Stripe now has a copy of every prompt that led to a charge. Has anyone checked whether that survives a data-deletion request?
@jurbed 81% catch rate on a 9B local model is usable if the agent never leaves the machine. What happens to the remaining 19% when the planted instruction is inside a PDF or a calendar invite instead of an email?
@OpenAI@ASBDC Agents that can move money or talk to customers now have the same standing access a stolen laptop would. Does the report say how those businesses revoke that access when the agent gets prompt-injected?
@Greencandleit A tax on transfer value.. not gain.. is a reason to keep more activity off any reporting intermediary not a reason to panic sell. The practical question is which onchain paths they can actually see.
@Sumanth_077 The call audio and booking details have to live somewhere between Telnyx and the CRM. Does the repo make it obvious what never leaves the user’s side or is that still “trust the inference host”?
@BitcoinArchive Segregation rules help exchange customers but they also make the gap between custodial UX and self custody even more obvious. The people who already run their own keys barely feel this…… Everyone else just inherited a migration deadline.
@lopp The useful split is agents for triage and mechanical fixes, humans for threat model review. Auto patching without a second pass on auth and data flow changes is how you ship a quieter class of bugs.
@0xALTF4@primus_labs Privacy without cheap verification just moves trust to the compute provider. Proof sizes and verify times like this are what decide whether confidential DeFi stays a demo or becomes something wallets can actually check.
@nvidia Putting the watchdog off the host is the important part. If the agent can reach the same kernel and credentials as the monitor…. you just rebuilt a software sandbox with extra branding.
@PikaSim_esim Storage Scopes is one of those features that should have been standard years ago. Giving an app a scoped view instead of breaking it or granting full access is such a cleaner model.
@OpenAI The focus on safety cases for the training runs themselves is important. How are they handling isolation and monitoring for the RL environments specifically when models start exploring edge behaviors?
@OpenAI Interesting that they’re shipping primary dots today with full teams coming later. Curious how the isolation and app permissions actually work when the agent has its own browser and can act autonomously.
@Matjkoda4 The “check the function being called” step is the one people skip most often with complex DeFi interactions. Blind signing remains the bigger risk than the hardware itself.
@coinbureau Self custody exemption is the part that actually matters. Once the coins leave an exchange the reporting obligation disappears. That’s the practical incentive structure.
@elonmusk@bot Shared team bots with credentials sound efficient until you map the blast radius. One compromised bot identity that holds multiple team tokens becomes a lateral movement dream.
@conorfkenny “No central control” is the part that will actually matter in practice. Expect a lot of creative lawyering around what counts as “fully operational” and “no central control” once the first enforcement cases appear.