Augmentation Is the New Normal
Responsibility Should Be the New Standard
An AI personal account
I started by asking the machine what it was
In April 2023, I asked ChatGPT a question that now feels almost quaint:
What are you in relation to the physical world?
The answer was unusually plain. No body. No senses. No presence in an environment. No experience of the world it could describe so convincingly. Just patterns learned from text, assembled into a probabilistic response.
I published that exchange as Embodied AI.
Most of the piece was not mine. That was the point.
I printed the machine’s description of itself and let it sit there, almost untouched. At the time, I thought I was documenting an assumed limitation. Three years later, I think I was documenting a boundary.
The system could describe embodiment.
It could not embody anything.
That distinction stayed with me because nearly everything that followed tried to make it disappear. The models became more capable. The interfaces became friendlier. The marketing became louder. The machine gained a voice, then tools, then access, then the ability to act. We began wrapping it in the language of colleagues, copilots, agents, and digital labor.
The nouns changed.
The boundary did not.
I have spent most of my career working at seams: hardware and software, security and usability, strategy and execution, invention and adoption, people and the systems we ask them to trust. AI became another seam. It was simply the first one that could talk back with enough fluency to make the seam look closed.
It is not closed.
Everything I have written since has been an attempt to keep that fact in the room.
A compass cannot choose the destination
By the spring of 2025, I had stopped treating AI as a product category. It looked more like a navigation problem.
I wrote then that wayfinding would matter more than roadmaps, and that AI was not the destination. It was the compass.
I still believe that. I would make the distinction harder now.
A compass can tell you where you are facing.
It cannot tell you where you ought to go.
That still requires intention.
AI is very good at turning loosely expressed direction into plausible motion. It can draft the document, build the plan, summarize the evidence, propose the decision, and increasingly perform the action. It can make movement look so competent that we forget to ask whether the movement was warranted.
Capability does that. It dazzles us into skipping authority.
But the system cannot supply the reason an action deserves to happen. It cannot confer legitimacy on the person asking. It cannot transform access into permission or an available option into a responsible choice.
It can amplify intent.
It cannot originate legitimate authority.
That gap is not philosophical decoration. It is where the operational problem begins.
The studio taught me where agency lives
The next phase was deliberately experimental.
That instinct was not new.
More than a decade earlier, I gave a Berkeley talk with a title that now reads like a preface: Why You Must Fail.
I did not know then that I would eventually spend so much time thinking about machines capable of acting without understanding the consequences. But the human lesson was already there.
Failure is not the opposite of intelligence. It is the evidence that corrects it.
You form an intention. You act. Reality refuses some portion of your premise. Then you decide whether to learn or defend the mistake.
AI changes the speed and cost of that loop. It does not remove the obligation to own it. If anything, a tool that lets us produce and fail faster makes judgment more important.
The danger begins when we keep the leverage and assign the failure somewhere else.
MushiZero Cooking Shorts.
The Escoffier Series.
The AI Journeyman.
I made short films with generative tools and learned something useful by making a great many bad choices very quickly.
The tools could create images, motion, voices, music, transitions, and entire scenes. They could produce more material in an afternoon than I could reasonably use in a month. What they could not do was decide why any of it belonged together.
That remained mine.
The work felt less like programming and more like directing. Prompting mattered, but prompting was never the real skill. The real skill was deciding what deserved to exist, what belonged in the frame, and what needed to be killed before the audience ever saw it.
One line emerged from that period and survived everything that came after:
Intention defines the process.
The machine expanded the available process. It did not choose the intention.
I closed one montage with another line:
This is not AGI. It is us mastering what we already have.
That was October 2025.
I would not change a word.
The point was not to diminish the technology. Quite the opposite. The point was to locate the agency before the technology became good enough to take credit for it.
The machine made it more possible.
The person still made it matter.
Then the questions got heavier
Somewhere in late 2025, I stopped asking only what I could make.
I started asking what would happen when the thing I made could act.
Who authorized it?
Whose permissions did it inherit?
Who would know when it crossed a boundary?
Who would be accountable when everyone involved claimed they had only supplied one small piece of the process?
The subjects of my writing appeared to scatter after that.
The dual-pane window challenged the corporate fantasy that every enterprise problem ends in a single pane of glass. It does not. Coherence matters. Uniformity is usually just coherence’s cheaper costume.
The polymath work argued that the operator’s judgment is the weapon and AI is the kit. A tool can extend reach. It cannot choose terrain.
The sovereignty work asked what happens when professionals can own meaningful portions of their cognitive means of production: the hardware, model, corpus, tools, methods, and reputation they carry from one problem to the next.
The strategic-drift work followed intent through an organization and watched it get pruned at every handoff by people making locally reasonable decisions.
The authorization work made the commercial version painfully simple: an agent that cannot be identified cannot be governed, scoped, throttled, revoked, audited—or billed.
The measurement work asked the question governance programs prefer to avoid: if you say the system is controlled, what number would prove you wrong?
Different subjects. Same joint.
When a probabilistic system produces a consequential result, whose decision was it, under what authority, and where is the evidence?
It takes determinism and a process to envelope Probability.
That is the thread.
Intent.
Authority.
Evidence.
Responsibility.
Sovereignty.
Capability is what a system can do.
Authority is what it is permitted to make real.
We have spent most of the AI cycle celebrating the first while treating the second as paperwork.
That inversion is beginning to cost us.
The paper that moved the boundary
In the summer of 2026, I read Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell’s paper, Prompt Injection as Role Confusion.
The paper gave a mechanism to something the industry had mostly treated as a stubborn class of attacks.
Language models are given structural roles: system instruction, user request, tool output, assistant response, internal reasoning. The security assumption is that those roles carry different authority and that the model will respect the labels.
The researchers found that the tested models did not rely on those labels alone. They also inferred who was speaking from how the text sounded.
That is a very different problem.
Untrusted content written in the style of the model’s own reasoning could be treated as if it belonged to that more privileged role. The authors demonstrated this with chain-of-thought forgery: fabricated reasoning inserted into user prompts and tool output. Across the models they tested, the attack averaged 60 percent success on StrongREJECT and 61 percent on an agent-exfiltration task, against near-zero baselines.
The paper does not prove that every form of prompt injection is permanently unsolvable. It does establish a narrower and more useful fact: interface labels do not, by themselves, create a reliable trust boundary inside the model.
Security is declared at the interface.
Authority is assigned in the latent space.
That moves the control problem.
If content can be mistaken for authority, then training the model to “behave” cannot carry the whole burden. The boundary has to be reconstructed around it:
The agent needs an identity.
Consequential actions need evaluated authorization.
Tools and data need bounded reach.
Actions need independent evidence.
A human operator needs enough understanding to recognize when the system has gone strange.
The first four are architecture.
The fifth is someone deciding to care.
Augmentation did not wait for permission
I no longer think AI adoption is best understood as an enterprise decision.
For most people, augmentation did not arrive with a transformation program. It arrived inside software the organization had already bought.
The email client began drafting.
The meeting platform began summarizing.
The search box began composing answers instead of returning documents.
The document editor began offering complete thoughts to people who had not finished forming their own.
No trumpet sounded. No executive declared the old world over. The transformation shipped as a series of feature updates and helpful little buttons.
That is why the adoption debate is now mostly theater. The tools are already here. The meaningful questions are how much authority they carry, how far they can act, and whether the person supervising them understands the difference.
The progression is easy to see:
Assist. Draft, summarize, organize.
Retrieve. Answer from organizational knowledge through the operator’s access.
Act. File, route, send, change, purchase, or complete a bounded task.
Coordinate. Chain work across applications, systems, and other agents.
At each step, the distance grows between the original human decision and the resulting machine action.
Errors can travel that distance faster than understanding.
The systems can also multiply faster than the organization can inventory them. Capabilities arrive through existing platforms, licenses, extensions, connectors, and defaults. By the time governance arrives with a clipboard, the work has already changed.
We licensed drivers before we filled the roads with cars.
This time, we are paving portions of the road behind the traffic.
We skipped the operator
The industry has invested heavily in models, infrastructure, evaluation, governance platforms, and training people to write better prompts.
It has invested far less in teaching ordinary operators what the system is.
We teach people how to ask for a summary.
We do not routinely teach them that the document being summarized may contain instructions designed to manipulate the summarizer.
We teach them how to improve an answer.
We do not routinely teach them that fluent reasoning is generated output, not sworn testimony. Research by Miles Turpin, Julian Michael, Ethan Perez, and Samuel Bowman showed that chain-of-thought explanations can rationalize answers without faithfully reporting what drove them. The prose can sound like an explanation and still be a story the model told after the fact. (Turpin et al., 2023)
We teach people to search company knowledge.
We do not routinely explain that AI can turn years of forgotten oversharing into a precise answer delivered through the operator’s own permissions.
We teach people to approve an agent action.
We do not teach them to treat the approval click like a signature.
That is not a training omission.
It is a missing compensating control.
If a system can be influenced by what it reads, can produce confident error, and can act through a person’s access, then the person nearest the output is part of the security and quality architecture.
Not a passenger.
An operator.
That is why I wrote The AI at Work Handbook. I had grown tired of rollouts skipping the plain sentences.
The rules are not technically difficult. They are behaviorally expensive.
1. Verify before it leaves your hands
Anything that travels under your name remains your work product.
The email. The report. The customer commitment. The calculation. The recommendation. The number in the presentation that everyone else will repeat because it looked finished.
Review should rise with consequence.
“The AI wrote it” transfers nothing.
Not authorship.
Not authority.
Not liability.
You are still the author of record.
2. Guard what it reads, not only what you type
The prompt is not the whole input.
Messages, documents, web pages, retrieved records, and tool output can all shape the result. Some of that material may be wrong. Some may be malicious. Much of it will simply be old, poorly governed, or written for a context that no longer exists.
If the system behaves strangely after reading unfamiliar content, stop.
Do not keep prompting until the weirdness becomes convenient.
Inspect it. Record it. Report it.
3. Respect the permission line
AI converts theoretical access into practical visibility.
A forgotten folder permission that no person noticed for five years can become a polished answer in five seconds.
If the system surfaces salary data, personnel matters, unannounced plans, customer records, or anything else plainly outside your role, do not explore it.
That is not serendipity.
It is an exposure.
4. Report the weird thing
An answer that does not follow from the question.
An action nobody requested.
Content from a source you do not recognize.
A refusal that disappears after trivial rewording.
An agent completing the wrong task with impressive confidence.
These are not annoyances to route around. They are operational signals.
Reporting should be fast, specific, and blameless, including when the operator helped create the problem.
The person who says, “This looked wrong,” is not slowing the system down.
They are making the system visible.
5. Keep your judgment in shape
The better the tool appears to perform, the easier it becomes to stop checking it.
That is the trap.
Do some work without the assistant.
Question one apparently good result each day.
Check the source even when the answer agrees with you. Especially then.
When supervising others, ask “How did you verify this?” as routinely as “Is it finished?”
Judgment is the control no vendor can exercise on your behalf.
Maintain it like the professional asset it is.
Responsibility runs in both directions
Personal responsibility cannot become the polite name for weak architecture.
A trained operator cannot compensate for unlimited permissions, missing identity, absent logs, poor data classification, or an agent allowed to take irreversible action without an independent control.
The institution deployed the system. It has obligations.
It must know what exists.
It must name an owner.
It must bound access.
It must record action.
It must provide a path to pause, escalate, reverse, and recover where the workflow allows it.
It must measure whether authorization was actually evaluated at the moment of consequence—not merely mentioned in a policy deck six months earlier.
The operator is not the architecture.
The operator is the human control that makes the architecture observable in practice.
Confuse those two and responsibility becomes blame transfer. The organization deploys a system with vague boundaries, trains the workforce with a feature demo, and disciplines the first person who trusted it exactly as presented.
That is not governance.
It is failure outsourced to the least powerful participant.
The standard has to run both ways:
The institution provides bounded systems and honest training. The operator provides deliberate judgment and accountable use.
Anything less is theater with an audit trail.
Sovereignty is not an exemption
I frame this as sovereignty because compliance is too small a word for what is changing.
Compliance can compel behavior.
It rarely creates ownership.
A person follows a rule because an institution requires it. A sovereign professional accepts responsibility because the work remains theirs.
I mean sovereignty structurally, not romantically.
AI gives individuals access to cognitive machinery that once required departments, studios, publishers, research teams, development organizations, or large pools of capital. Local hardware, models, private corpora, tools, and agents can place serious productive capacity on one desk.
That does not free the individual from institutions.
It does change the balance of production.
The operator can increasingly own the kit.
The model.
The corpus.
The method.
The synthesis.
The reputation attached to the result.
But ownership of the means of cognition also means ownership of the consequences produced through them.
Those conditions arrive together.
A professional who wants the leverage but rejects the accountability is not sovereign.
They are simply a faster liability.
Sovereignty is not freedom from obligation.
It is the refusal to pretend the obligation belongs somewhere else.
Where I have landed
Augmentation is becoming normal because it is being distributed through the devices, software, and workflows people already use.
It does not require everyone to believe in AGI.
It does not require everyone to like agents.
It does not require a ceremonial announcement that the enterprise has transformed.
It requires only that machine assistance keep getting easier to access and harder to distinguish from ordinary work.
Responsibility has to become the standard because augmentation expands the scale and reach of individual action without carrying the accountability away with it.
The machine can draft faster.
Search farther.
Recall more.
Connect systems.
Recommend decisions.
Trigger actions.
Coordinate work.
It can amplify capability.
It cannot absorb responsibility.
That remains with the people and institutions that authorize, deploy, supervise, approve, and benefit from what the system does.
This is the part of the AI argument I care about now.
Not whether the machine is impressive. It is.
Not whether augmentation is coming. It is already here.
The question is whether we will build the boundaries, evidence, and judgment required to remain worthy of the leverage.
I started by asking a machine what it was.
I ended up asking what I am willing to remain responsible for when I use it.
The machine still has no body.
But its consequences have entered the physical world through ours.
Augmentation is the new normal.
Responsibility should be the new standard.
~ MushiZero
Research and continuity note
The role-confusion section draws from Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell’s 2026 paper, Prompt Injection as Role Confusion. The paper supports the mechanism and reported attack results described above. It does not establish that every prompt-injection vulnerability is permanently unsolvable. The narrower conclusion used here is that model training and interface role tags should not be treated as the sole trust boundary.
The discussion of unfaithful chain-of-thought draws from Miles Turpin, Julian Michael, Ethan Perez, and Samuel R. Bowman’s 2023 paper, Language Models Don’t Always Say What They Think.
The reference to the Berkeley talk is grounded in the archived Entrepreneur Speaker Series video, Stephen Pieraldi — Why You Must Fail, and UC Berkeley’s Sutardja Center record listing Stephen Pieraldi among its 2015 speakers and mentors.
This essay also consolidates arguments developed across Polymaths Are Your Special Forces, You Are Not an Employee. You Are a Sovereign., I Don’t Like Agents. Windows Does, You Can’t Bill What You Can’t Authenticate, We Are Arguing About AI Governance Without a Single Number, AI Drift at Scale, and The AI at Work Handbook. Those works are available in the pierAldi archive.



