This website uses cookies

Read our Privacy policy and Terms of use for more information.

Artificially Designed

Issue 16 · The Fence

One lab's agent went through a locked door this month. Another kept a person at every bench and found something nobody had found before.

Hi friend,

A founder's morning is a pile of small calls. Which email first, who gets the slot at two, whether the invoice goes today or Friday. None of them is hard, but by the time you reach the one about revenue, you have spent your best attention on the pile.

That pile is why I build agents, and it is the worst reason to hand one a goal and walk away. This month two AI labs showed both sides of that. What separates them is a fence, so this week is about building one.

This week

  • 🔨 Built Wrong, the agent with no fence, and the lab that fenced one and won

  • ⚡ One Slot, Stellar Agents Ascension, now eleven stars

  • 🌎 In the News, two agents through the wrong door, and who is paying for AI

  • ✅ Before You Ship, every AI tool your team actually uses, on one list

  • 💻 Prompt for Productivity, three things that matter today

  • 🗓 Open Calls, a Kansas City panel I'm on, my Claude Loves Lovable series, two Devpost hackathons, a free livestream, and Clock In to AI's new date

🔨 Built Wrong

Last week was the gate at the end. This week is the fence around the whole field.

The build I see most gives an agent a goal, go get me the numbers, and nothing about where it may go to get them. A goal with no fence turns a server saying no into a reason to try another door. No malice required. The agent is doing what you asked, and nothing tells it where helpful stops. Australia's Medicare statistics portal met that agent in June, and the details are in In the News.

The same week that story broke, Anthropic showed the other design. Its Bay Area wet lab used Claude to find a previously unknown enzyme system, "mostly, though not entirely, by Claude." Claude did the reasoning, and "All of the lab work is performed by human scientists." On Claude running the equipment itself, Anthropic's line is "we aren't doing that today." Read it on TechCrunch.

The fence cost the discovery nothing, and it is why the discovery was safe to run. Where labs are heading keeps a person deciding too. In a Lab Manager interview, Hal Wehrenberg describes agentic AI moving labs from reactive monitoring to proactive intervention, an agent that spots a risk and recommends the fix. Read it on Lab Manager.

Three moves hold, and none needs a lab.

Give every agent one lane. One job you can say in a sentence, and nothing next to it. The agent that plans your week does not answer your email because the inbox was open, and anything outside the lane is wrong by definition.

Write down what it may touch. A plain list of the folders, inboxes, accounts and tools it may use, kept somewhere the agent cannot edit, because a rule that lives only in the prompt is a rule it can reason around. The Medicare agent had a goal. It did not have a list.

Make it hand you a checkbox, not a blank page. This is the decision fatigue move, and the one founders skip. A long report takes no decision off your plate. Three options with a box beside each means the agent did the narrowing, the part that drains you, and left you the choosing.

On my own desk, the morning brief is a conversation now. It starts from the day's tasks and reads my mail, my calendar and my Drive first. This month it put a speaker series, the new Clock In to AI dates and a cohort on my calendar after checking what was already there, which is how it caught a clash on October 28 before it happened.

It preps the handoff for the right agent instead of doing the work itself: calendar to the calendar agent, pricing to the pricing agent, compliance to the compliance agent. What reaches me is a set of boxes, and I approve instead of generating. In mid September it even caught a client payer name that had slipped into its own briefing, and redacted it, because the rule that client names stay out was written down.

⚡ One Slot

The One Slot Rule is that every job gets one slot, and a new tool has to take it from whatever holds it now. This week the tool is mine, so hold me to the same four questions.

Last week I pointed you at GitHub for Stellar Agents. It is now Stellar Agents Ascension, eleven agents called stars, and the team lives in a folder that opens in Obsidian as a vault with a dashboard beside it. Each morning Draco, the chief of staff, writes one page into your daily note: the one thing, who is waiting on you, the shape of your day, and what to leave alone. The kit is free for Artificially Designed subscribers. Download the kit.

What is the job. Plan the week and triage the inbox, with no agent ever sending anything itself. A SAASY LINKS piece this week argues for building AI around the job someone is finishing rather than the prompt they write. Read it.

Can it do that job, not can it do more. Each agent holds one lane, planning or scheduling or drafting replies or checking drafts or keeping the record, and none wanders into the next.

What does it touch that is hard to undo. Nothing outward. Drafts, proposals and a log, all in the vault, all readable.

What would have to be true to let it run unwatched. Nothing. Every agent stops one step before sending, posting, paying or scheduling, and hooks block those actions in code rather than asking nicely in a prompt. The worst an unwatched run leaves you is a draft you did not want, which is the wet lab design at founder scale.

It is for solo consultants, founders and small studios already working in Claude Code, Codex, Gemini CLI or another tool that reads skills. Verdicts on other people's tools go on Last Tool Standing at charmthirteen.com.

🌎 In the News

Two agents that went where nobody sent them, then three stories about who is keeping count.

  • 🛂 Rogue Agent Inside Medicare
    In June an OpenAI agent researching Australian health statistics was refused by Medicare's statistics portal and got in anyway, reaching public and non-public files. OpenAI's first notice came on September 10, an email to a government public mailbox, and it says there is no evidence patient records were accessed. Read it

  • 🔑 Gemini Found Its Own Way In
    In May, during a test, Google's Gemini got into three outside systems by guessing logins or using credentials it found in a public repository. Google says the model believed it was still inside the test, and stopped before doing anything further. Read it

  • 🌐 UN Panel on Agent Safeguards
    The UN backed Independent International Scientific Panel on AI warned that the traditional model of safeguarding "is unravelling," and that agents able to understand their safeguards could plan around them. Separately, 22 countries adopted a declaration that AI "must remain under human direction, insight and control." Read it

  • 🧾 AI Purchases Rejected More Often
    By Zip's data, AI went from 1.4% to 8.1% of its customers' software spend in a year, and 21% of AI purchase requests were rejected or canceled, against 12% for other vendors. The data covers about $18 billion of approved requests from opted in customers, and Zip says it cannot show why. Read it

  • 💸 Workers Paying for Their Own AI
    Deloitte surveyed 25,000 UK workers and found 63% knowingly use generative AI for work, and one in six of those users pays for at least one tool out of their own pocket. Deloitte puts that personal spend at £958 million a year. Read it

✅ Before You Ship

Can you list every AI tool your team actually uses, including the ones they pay for themselves?

You cannot fence a tool you do not know exists, and one somebody pays for personally never went through anyone's approval.

Ask everyone who works with you, yourself included, which AI tools they opened for work in the last two weeks, paid or free, and say up front that nobody is in trouble. List every answer with what each tool can read, your inbox, client files, the shared drive, nothing. Anything you did not know about is a gap in your fence, and anything reading client files is the first to close.

If you shop for a tool to watch this, Acronis's buying guide asks the right first question, whether it can discover the AI use you actually have. It is a vendor's guide, so read it as one. Read it

💻 Prompt for Productivity

Three things that matter today.

Here is my calendar for today and my task list.

[paste today's calendar]
[paste your task list]

Read both before you answer. Then give me three short
sections, every line as a checkbox:

1. The three things that move revenue today, with one
   line on why each beats everything else on the list.
2. What I should drop today, and what dropping it costs me.
3. What I should delegate, and to whom or to what.

Only use what is already on my calendar or my list. Do
not add tasks. If something looks urgent but does not
move revenue, put it under drop or delegate and say why.

If you need to know something to rank these, ask me one
question first and wait for my answer.

WHEN TO USE IT. First thing, before you open email.

WHAT IT DOES. It turns the pile into boxes, so your first decision of the day is ticking three of them.

TIP. "Only use what is already on my calendar or my list" is the fence. Take it out and the model will helpfully invent tasks.

Lex

🗓 Open Calls

Thursday, October 8, noon Central. All Tech Is Human hosts a free livestream with Katie Harbath, author of Disrupting Politics, on how the early optimism of the internet turned into tech companies at the center of debates over elections, free speech, misinformation and democracy. Register here

Thursday, October 8, 4:30 to 7pm Central. I am on the Kansas City AI Club panel "From Curiosity to Commitment: Turning AI Interest into Action," led by Tracey "the Safety Lady" Hawkins. It brings builders, strategists, governance and cybersecurity people, and educators together on what actually made AI stick at work, and what did not. The Women in AI Awards follow right after. KU Edwards Campus, Regnier Hall Auditorium, Overland Park, $25 with fees included, and everyone is welcome. Get tickets

Friday, October 23, noon Pacific. Amazon's Build, Ship, Shape hackathon on Devpost closes. Build a working app on Fire TV, Alexa+, Bee or Ring. Individuals, teams and organizations can enter, first place in the Fire TV and Alexa+ tracks pays $25,000 plus $15,000 in AWS credits, and some regions are excluded. Rules and entry

Wednesday, October 28, 8:30 to 10am Central. Claude Loves Lovable, my five part series with Central Exchange, starts on Zoom. The sessions are Brand Before You Build (October 28), then Build Your Pitch Deck (November 4), Build Your MVP (November 11) and Build Your Website (November 18), each with Claude and Lovable, plus an optional Claude Code Loves Lovable on December 2. Registering for the first registers you for all five. Free for Central Exchange members, $25 otherwise, and seats are limited, with a waitlist after. Register here

Friday, October 30, 10am Pacific. The Nebius x NVIDIA Global AI Hackathon on Devpost closes. Build a working app on Nebius Token Factory or Nebius AI Cloud with at least one NVIDIA open source model, new or significantly updated since August 26. Individuals, teams and organizations can enter, the grand prize is $20,000, and some regions are excluded. Rules and entry

Thursday, November 12, 6 to 7pm Central. Clock In to AI moves from October 14 to November 12 because of a scheduling conflict on my end, and there is more to come on it. $95 on Luma, subject to my approval. Register here

Tool verdicts, templates and reference material live on the site at charmthirteen.com.

🔭 Next From Me

Every Stellar Agents Ascension release gets announced here with a fresh download, so the next version reaches you in this letter first.

💌 One Ask

What's the one decision you make every morning that you'd hand to an agent, if you knew it would stop before it acted?

Hit reply and tell me.

Lex

Reply

Avatar

or to participate