Open Channels FM
Open Channels FM
The Cost of Convenience How AI Agents and Security Initiatives Challenge Control
Loading
/

Welcome to Open Channels News, your source for the latest in open source, digital security, and AI trends. In today’s episode, host Robert Jacobi sheds light on the complex balance between convenience, control, and accountability:

  • Instinct: The AI Assistant That Acts
    A new agentic AI, Instinct, can spend money, book travel, negotiate with vendors, and handle daily tasks through iMessage and WhatsApp. While this offers convenience, several users have reported costly mistakes, raising urgent questions about permissions, oversight, and responsibility when AI controls real-world actions.
  • IBM and Red Hat’s Project Lightwell: Securing Open Source at Scale
    IBM and Red Hat are investing five billion dollars in Project Lightwell, aiming to transform enterprise security in the open source software supply chain. The initiative brings together a security clearinghouse, thousands of engineers, and AI validation tools to help enterprises patch vulnerabilities while pushing fixes back to the community.

Listen as Robert Jacobi reports on how rapidly increasing AI automation changes the landscape of control and accountability for businesses and everyday users alike.

Since 2005, Automattic has built tools for the open web including WordPress.com, WooCommerce, and Jetpack that are used by millions of people to create, sell, and publish online. They believe in ownership, flexibility, and open source and we’re grateful for their support. Learn more at automattic.com.


InMotion Hosting brings over 25 years of experience, NVMe-powered speed, and 99.99% uptime to every plan they offer. When you need help, you get a real human, not a bot, and they’ll migrate your site for free. We’re happy to have them in our corner supporting the conversations we have here at Open Channels FM. Find your plan at inmotionhosting.com


Logo of Omnisend featuring a stylized 'i' icon and the brand name in lowercase letters.

Omnisend just dropped SMS pricing to $0.007, and their migration team moves your automations, templates and contacts in five days, free. That means you could be saving up to 35% in less than a week. We’re glad to have them supporting the show and the community we’re building around it. Use the code OpenChannels and get 30% off your first 3 months of any paid plan.

Takeaways

  • Agentic AI Raises New Risks: AI assistants like Instinct are moving beyond chatbots to take real-world actions such as booking appointments, spending money, and managing tasks—creating new risks where a wrong answer by the AI can directly result in tangible mistakes and financial costs 01:06.
  • Delegated Control Comes With Responsibility: The convenience of letting AI manage daily tasks brings with it the challenge of determining what the AI can access, spend, reverse, or log, and crucially—who is responsible when things go wrong 02:13.
  • Permission and Trust Are Core Issues: As AI systems are granted greater access to users’ email, calendars, payments, and personal data, the value proposition increasingly revolves around permission management and building a trust model that goes beyond simple confidence from the AI 02:22.
  • AI Accelerates Vulnerability Discovery in Open Source: While AI speeds up the discovery of software vulnerabilities, fixing those vulnerabilities does not become easier or faster, revealing a persistent bottleneck in the open source software supply chain 03:32.
  • Industry Response With Project Lightwell: IBM and Red Hat’s $5 billion Project Lightwell aims to industrialize and scale the process of testing and fixing vulnerabilities in open source software, pushing validated fixes upstream so the entire community benefits rather than just individual enterprises 03:46.
  • Human Oversight Remains Essential: Despite advances in automation and AI-driven auditing, the need for human governance, process, accountability, and controlled deployment remains unchanged; automation changes speed, not responsibility 04:54.
  • Control Is Easy to Give, Hard to Regain: As technology makes it easier to delegate authority to AI agents and automated systems, it becomes much harder to regain that control and ensure clear accountability when issues or mistakes arise 05:33.

Mentioned Links and Resource

Episode Transcript

Robert Jacobi:

Good day and welcome to OCN, the Open Channels News Broadcast. Today is September 15th, 2026, and I’m your host, Robert Jacobi. Today’s story is about control. How much control should we hand an AI assistant when it can spend money, book travel, and rearrange our lives? And how do enterprises regain control of the open source software supply chain when AI can find vulnerabilities faster than humans can fix them?

The Atlantic reports on a new AI assistant called Instinct that works through iMessage and WhatsApp. And this is where AI starts getting much more interesting and much more dangerous. People still think of an AI assistant as something you ask questions. Instinct does things.

Users can text it to order groceries, find doctors, book appointments, arrange travel, negotiate with vendors, make reservations, and handle other everyday tasks. One user reportedly had it pay tolls and book a DMV appointment. That’s Department of Motor Vehicles. Another used it to recover an Apple Pencil left at a hotel. The Atlantic’s writer used it to find an Airbnb, locate doctors, and contact cleaning companies. Sounds great. And it also starts to look less like a chatbot and more like a junior employee with your credit card.

And like a junior employee, sometimes it screws up. One user said the agent accidentally canceled the flight and cost him more than $200. Another reported unwanted restaurant bookings. That is a real shift happening with agentic AI. The risk is no longer simply that the model gives you the wrong answer. The risk is that it takes the wrong action. There’s a huge difference between an AI hallucinating a restaurant recommendation and an AI actually booking the restaurant, or canceling the flight, or sending the money, or emailing somebody on your behalf.

Once AI systems connect across email, messaging, calendars, payments, all the tools that we trust normally, permissions become the product. What can the agent access? What can it spend? What requires confirmation? What gets logged? What can be reversed? And when something goes wrong, who is responsible? That last question is going to become very important very quickly.

The convenience is obvious. Text one message and something annoyingly disappears from your day. Awesome. But every layer of convenience is also another layer of delegated authority. We spent years teaching people not to give strangers their passwords. Now we’re building software whose entire value proposition is basically, give me access to everything and I’ll take care of it. That can work, but the trust model has to become much better than the AI seemed confident.

And that brings us to the infrastructure layer. Cybersecurity Dive reports on IBM and Red Hat’s Project Lightwell, a $5 billion initiative designed to help enterprises identify, validate, patch, and manage vulnerabilities across open source software. It’s a pretty big number aimed at a very familiar problem. Open source runs almost everything. IBM says more than 90% of Fortune 500 companies rely on open source software, but much of that software is maintained by communities that were never designed to operate like global security teams for the world’s largest companies.

Now AI is accelerating vulnerability discovery. That sounds good, and it is good, but it creates the same bottleneck we keep seeing and talking about. Finding the problem gets cheaper. Fixing the problem does not.

Project Lightwell is IBM and Red Hat’s attempt to industrialize that second half. The plan combines a trusted security clearinghouse, more than 20,000 engineers, and AI systems that can help validate and test patches. Enterprise customers will be able to subscribe to the service and integrate validated fixes into their existing software lifecycle process. IBM says it has already been testing the approach with major financial institutions, including Bank of America, Goldman Sachs, JPMorgan Chase, Mastercard, and Visa.

The interesting part is that IBM is not trying to replace open source maintainers. The model is supposed to push fixes upstream so communities benefit from the remediation instead of enterprises quietly maintaining private patches forever. And that’s important because one of the long-running problems in open source is that enormous companies depend on tiny projects, then discover a security issue and treat it as somebody else’s maintenance problem. Lightwell is basically an argument that security has become too important and too complicated for that model to continue.

It ties directly back to the AI agent story. AI can find vulnerabilities faster, AI can help validate patches faster, but neither of those things eliminates the need for humans, governance, process, accountability, and controlled deployment. Automation changes the speed, it does not remove the responsibility.

So that’s the thread for today. With Instinct, people are handing AI agents more control over real-world actions and discovering that a wrong answer becomes much more expensive when the software can actually do something. And with Project Lightwell, IBM and Red Hat are spending $5 billion to bring more structure, engineering capacity, and accountability to the open source software supply chain.

Different stories, same problem. Technology keeps making it easier to delegate power to AI agents, to automated security systems. The hard part is making sure we still know who is accountable when that power gets used. Control is easy to hand over. Getting it back can be a lot harder.

And that’s OCN for September 15th, 2026. I’m Robert Jacobi. Be open and stay secure.

Sponsors
Open Channels News