Our Next Adventures in AI

We have enjoyed our time working on this — the Hidden Guild — website. But the technical edge of AI is already moving in a new direction. Which means it may be time for the Anti-Dave to reveal a bit more of his thinking about where the Future will be landing.

Because, dear Reader, that is what the Future does.

You step up to the tee, take your best swing and sometimes land in the middle of the fairway. Just as often, though, the ball disappears into the knee-high rough and you spend the next half-hour looking for something you were certain you understood five seconds after impact.

AI is now heading into that rough. Not because it is failing, but because it is becoming useful enough that the next problem is no longer simply intelligence. The next problem is organizing, packaging, testing and maintaining what the intelligence has been asked to do.

Two New Domains

For the “uninwebbinated,” a domain name is simply an address on the internet. But if you have read the ancient marketing classic Positioning by Al Ries and Jack Trout, you will appreciate the larger idea: A project’s name should tell people what shelf in the mind it belongs on.

With that in mind, we have registered two new domains.

Taskerware.com

The idea behind Taskerware is simple: AI is quickly moving beyond the point where every tiny procedural detail must be explained from scratch during every conversation.

AI is growing up. A decent amount of fault tolerance is already being built into these systems. Interactions are becoming smoother across platforms, including the smaller but increasingly functional 2-billion- to 8-billion-parameter models that can run on processor-bound personal computers without massive memory bandwidth.

Not all systems have embraced what we have long called the Shared Framework Experience: the collection of assumptions, definitions, methods and prior decisions that allows a human and machine to work together without starting over every morning. But the direction is obvious.

The intelligence is becoming plentiful. What remains scarce is a reliable description of the job.

That is the Taskerware layer.

A Taskerware package describes what must be accomplished. It contains the objective, required knowledge, available tools, permissions, sequence, standards, exception rules, completion tests and expected deliverable.

It is not merely a prompt. It is the durable specification of a task.

AI-OpCode.com

The companion domain is AI-OpCode.com.

Our working distinction is:

Taskerware packages how a job is done. AI OpCode tells machines how to execute, test and maintain it.

That is better territory than building “another agent builder.” Microsoft, OpenAI, UiPath and a growing herd of extremely well-funded companies can own the general-purpose execution machinery.

The more defensible layer resides in the human-derived task specification: the objective, knowledge sources, tools, permissions, sequence, exception rules, completion evidence and maintenance history.

Taskerware sits closer to workflow analysis and deliverable design. AI OpCode sits closer to the executable calls that make the workflow happen.

A Taskerware package might say:

Produce the Tuesday market report using these sources, these calculations, these chart standards and these editorial rules. Deliver a WordPress-ready article, a subscriber PDF and a short public summary.

The AI OpCode would handle the procedural layer:

On Tuesday at 4:30 a.m., load Task Package 117, collect the current inputs, run the specified analysis, validate the result, distribute it to List PN-Tuesday, update the website and open a feedback page.

One defines the job. The other operates it.

Plugging Past Plugins

The concept of the software “plugin” is about to undergo a remarkable change—one likely to affect server-farm operations, software maintenance and future demand for backend computing.

The walk-through matters because, at the highest level, no one has yet beaten a path to my door for the idea of a process-broker layer sitting above large shared computing systems.

But something like it will have to arrive.

Traditional plugins have usually been narrow additions to a larger program. The VST world in digital audio is a good example: One plugin provides an equalizer, another adds compression and another simulates a particular amplifier or room.

AI plugins will not remain that singular in focus.

To keep computing near the highest-performance and lowest-cost regions, plugins will become progressively more granular. One may hold instructions. Another may expose a data source. Another may contain a tool. Another may enforce a permission boundary, validate an output or format the finished product.

The intelligence will assemble what it needs for the job.

This is precisely where Taskerware sees opportunity jumping up and down, waving both arms.

Taskerware owns the “What is the deliverable?” layer. That includes not only the intellectual objective, but also mundane—and absolutely necessary—details such as file type, paper size, page orientation, naming conventions, citation requirements, approval points and distribution rules.

AI OpCode occupies the procedural layer: which task package to load, what tools to invoke, what order to follow, when to ask for human approval and what evidence must be recorded before the job can be declared complete.

The agent is not the product.

The completed, repeatable and maintainable job is the product.

Where Does This Place the Future?

We will not know until we get there, but several near-term product decisions are already becoming clear.

A Taskerware item should be a versioned package. It should contain a manifest, task instructions, source materials, required tools, permissions, acceptance tests and a change log.

The specification should also be separated from its execution engine. The same task ought to be runnable through OpenAI, Microsoft, a local model or even a deterministic conventional program. Model choice belongs in the deployment configuration—not in the permanent definition of the task.

Semantic versioning also makes sense. Correcting a prompt or documentation error might produce a patch release. Changing workflow behavior would justify a minor release. Breaking compatibility with existing inputs, outputs, permissions or tools would require a major version.

Migration and regression testing must be built in early. Each serious task package should include representative cases, including ordinary jobs, difficult jobs, known failures and exception paths. A new model, tool or connector should not become the “current” version until it passes those tests.

Maintenance must also become an explicit part of the product. The initial task build is one thing. Keeping it working through model retirements, API changes, connector failures, security discoveries and changing business rules is another.

The likely pricing model is therefore hybrid: a predictable subscription for maintaining the Taskerware package, with unusually expensive executions metered separately.

The opening is not:

We have smarter agents.

The opening is:

We preserve working knowledge as a portable, testable and upgradeable asset—even when the underlying AI changes or disappears.

What the Rest of the Field Is Thinking

The Anti-Dave has already sorted through several recent developments, and they point in precisely this direction.

OpenAI Is Moving from Custom GPTs to Plugins

OpenAI plans to retire custom GPTs on December 11, 2026, with a possible Enterprise deferral to February 11, 2027. Creation of new custom GPTs is scheduled to end October 26.

Their replacement is the plugin: a package that can combine reusable instructions, reference files, skills and connected applications.

Importantly, migration does not automatically preserve sharing permissions, and custom actions may need to be rebuilt. OpenAI advises creators to save representative prompts and regression-test the replacement because the migrated system may behave differently. OpenAI’s migration FAQ explains the transition.

That is not merely a product-name change.

The disposable custom chatbot is being replaced by an installable and maintainable software package. Instructions alone are no longer the whole product. Dependencies, permissions, tests, distribution and upgrade behavior now matter.

There is also a hard retirement date, so this is not speculative AI marketing. It is a lifecycle event.

Microsoft Has Split Casual AI from Agentic Work

Microsoft’s September 25 Copilot redesign divides the market economically.

Everyday questions, summaries, drafts and Office assistance remain under a fixed user-subscription model. Cowork, Code, Autopilot, frontier models and long-running agentic work move toward usage-based billing.

Microsoft is also introducing spending policies, credit-request approvals, model restrictions, usage histories and reporting intended to connect agent spending with business outcomes. Its Managed Runtime provides a governed environment for code, apps and workflows, while a unified plugin catalog is intended to let developers publish a capability across multiple Copilot surfaces. Microsoft describes the new Copilot structure here.

The meaningful shift is commercial. One of the world’s largest software vendors is validating a hybrid model: fixed subscriptions for ordinary assistance and metered billing for delegated machine work.

The hype boundary remains visible. Some of the new capabilities are only beginning limited rollout, while Autopilot remains in private preview. The pricing direction is real. The persistent digital employee is not yet a universal, broadly shipped reality.

UiPath Made the Workflow Specification an Asset

UiPath’s September 23 introduction of Cartographer may be the clearest confirmation of where the edge is moving.

Cartographer builds what UiPath calls a Map of Work: a tenant-owned, governed and versioned definition of how an enterprise process actually operates. It can collect knowledge from documents, systems, recordings and employees. Each asserted fact carries its source and verifier, while conflicting instructions are surfaced for human resolution.

Cartographer, Delegate and UiPath for Coding Agents are generally available. UiPath has also divided its Maestro product into Orchestrate for long-running, stateful business processes and Automate for large volumes of shorter tasks.

Most importantly, an approved Map of Work becomes the specification from which workflows, agents and tests can be built. Evaluations can then gate deployment. A planned Decision Ledger would capture production exceptions and turn them into proposed changes, subject to accountable human approval. UiPath’s FUSION announcement provides the details.

The market is finally treating workflow knowledge as something that must be sourced, versioned, approved, tested and maintained independently of whichever model happens to execute it.

That is the heart of Taskerware.

The Edge Is Moving

…and this means the frontier will follow.

There is a great deal of build-out left in “the Future.” It is possible that today’s apparent overbuilding of AI infrastructure will eventually return as a gift in the form of much lower per-token costs on distant backend compute systems.

But we would not hitch our wagons to that promise.

We are still waiting for atomic energy to make electricity so cheap that it will not be worth metering.

AI may follow the same path. Intelligence will become cheaper, but metering, permissions, maintenance and ownership will remain.

Which means the real edge may not belong to whoever owns the smartest model this quarter.

It may belong to whoever best captures how useful work is performed—and can keep that knowledge operating after the models, vendors and fashionable names have all changed.

Oh, and if you want either of those domain names? Everything is for sale; this is America after all.  And the Anti-Dave needs more time in the shop and less playing in the future.

Because eventually it becomes the Past Ure.

~Anti-Dave

License the Transmitter, Not the Listener

Obvious Solutions from the HiddenGuild.dev

The Bum’s Rush is coming soon for private LLMs.  I’ve rallied on this before but it’s workin g its way through the fear-mongers right now.

We’ve been here before. Radio – the FCC – Constitutional freedoms – the whole (remarkably similar) ball of wax.

Walk with me – to the time machine.

There is a useful lesson in the history of radio, and it is shorter than the history itself. When wireless technology arrived, anyone with the equipment could put a signal into the air. That was thrilling until transmitters began interfering with one another. Governments had legitimate concerns about maritime safety, emergency communications and, later, hostile transmissions during wartime. Rules followed. In the United States, radio licensing eventually became part of the FCC’s job.

Here is the part worth remembering for AI: the license attached to transmitting, not listening. You could turn on a receiver and hear what was out there without applying for government permission. The public’s ability to listen was not treated as the danger that required a license.

That distinction offers a better starting point for AI governance than either “regulate everything” or “regulate nothing.” We have been asking whether a model is powerful, whether an answer is dangerous and whether a user might do something harmful with it. Those questions matter. But they mix together three different acts: learning something, saying something and making a machine do something in the world.

A person asking an AI to explain a political argument is listening. A researcher using it to examine a disputed claim is listening. Someone privately testing an idea they may ultimately reject is listening. Government should not require identification, logging or preapproval for that activity. The same principle ought to guide the wider web: a person should be able to read publicly available material without leaving a permanent, identifiable trail merely for having looked.

We are a long way from that condition online. Websites, apps, advertisers and service providers routinely have reasons to collect data about readers. An AI assistant can gather an even richer record because people ask it questions they would hesitate to ask another person. If government begins treating that record as a convenient source of leads, private inquiry will become less private even without a formal ban on any question.

The pragmatic goal is therefore private reception by design. Let people read, search, compare and reason without building a dossier around each act. Services can protect themselves against abuse without retaining every ordinary user’s lifetime of questions. They can separate account information from query histories, shorten retention, offer private modes that mean what they say and permit local processing where practical. Law should require a proper, narrow process before private records are handed over. It should not turn every provider into a standing intelligence collector.

What, then, is the AI equivalent of transmitting?

Sometimes it is obvious. An agent sends a thousand messages, attempts to enter a computer system, moves money or controls a physical device. It has crossed from helping a person think into acting on the outside world. Such actions can affect people who never agreed to participate. They deserve rules matched to their actual reach and risk.

But the radio analogy has a limit.

Publishing an opinion online is also “transmitting,” and political speech must not require a government license. We cannot simply put permits on every AI output that leaves a computer. The useful distinction is between expression and operational action. Writing an argument about a bank is expression. Giving an agent credentials and authority to transfer funds from the bank is action. Explaining how software vulnerabilities are discovered is information. Directing an agent to probe someone else’s network without permission is action.

Regulate the action at the point where it can cause harm. Not the machine, the operator. (Machines don’t pay fines or go to prison…)

An agent permitted to purchase things should have spending limits, a clear record and a way to stop or reverse a transaction. One operating machinery should have tested boundaries and an emergency shutoff. A system acting on behalf of a business should identify who is responsible when it makes a consequential mistake. An agent attempting unauthorized access should face the same legal boundaries whether a human wrote each command or the AI generated them.

This approach also tells us what to report. If a developer discovers that a deployed agent can bypass its spending limit or expose customer data, report the defect to the people able to fix it. If an AI is used in an actual intrusion, investigate the intrusion. There is a legitimate role for coordinated security work. It does not require a routine feed of everyone’s prompts to a government office.

Nor does it require a government-approved list of ideas a model may discuss. A rule that prevents an autonomous tool from acting without authority can be tested. A rule requiring an assistant to give the “correct” treatment of every contested subject soon becomes a struggle over who appoints the corrector. The former governs conduct; the latter can govern thought by governing the information available to think with.

There is an economic reason to keep the boundary clear, too. Suppose every capable model needs an expensive license before release, regardless of what anyone connects it to. The largest companies will hire compliance departments. Small developers, independent publishers, researchers and local businesses will wait—or give up. We would have protected ourselves from competition as efficiently as from danger. Meanwhile, a poorly designed agent operated by an approved giant could still do real damage.

Test the system and its permissions. Audit consequential actions. Hold the operator accountable. Preserve room for small and local models that people can use without surrendering their private working notes. These are practical rules because they ask what a machine is authorized to do, whom it can affect and who can stop it.

The historical fears around radio were not imaginary. Interference was real; wartime and Cold War security concerns were real. Yet the enduring bargain allowed people to own receivers and listen freely. We should aim for an equally understandable bargain with AI. Keep the receiving end of intelligence open and private. Put enforceable boundaries around powerful actions directed outward.

If we get that distinction right, an AI can remain a mind amplifier instead of becoming a licensed window onto the citizen’s mind. The government can pursue actual abuse without requiring a seat at every conversation. And the next generation of inventors can keep building useful tools without asking permission to let us think with them.

Here’s hoping the simple questions and direct answers can survive 64-bit bullshit.

The Anti-Dave