Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town

Read the talk

Agents across information silos: search, privacy, and network effects

Jean-Denis Greze compares five ways to give agents useful information across private boundaries, then asks how much authority people should delegate over disclosure.

From a talk by Jean-Denis Greze

At a glance

Ideas worth remembering

  • Evaluate collaboration by whether the consequential answer or tool call receives the relevant information. Privacy and security limit that access even if context capacity is unlimited.

  • Shared trust boundaries and constrained tools can provide immediate utility, but their information boundaries remain dependent on human design. Stronger models alone do not automatically connect the silos.

  • Sweeper agents can build shared knowledge from private stores using approval or a sharing policy. Greze favors this for near-term returns, while warning that malicious content and persistent factual errors can undermine the accumulated knowledge.

  • Searching before asking can reduce human interruptions, but it moves trust into the search system and its disclosure controls. Approval, logging, reversibility, and privileged auditing remain necessary design questions.

  • Start delegated disclosure in a defined low-sensitivity zone and retain human approval elsewhere. Cross-company network effects are a promising extension, but Greze leaves both their implementation and his trust in fully automated privacy decisions unresolved.

The impossible agent with complete information

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 166 seconds
The impossible agent with complete information

The benchmark is a thought experiment: one agent, one context window, and access to all information, including personal email, company records, and government information. Given a request, that agent would have no missing-information barrier. Greze treats this as the ideal that multi-agent systems should approximate. The claim is an architectural benchmark within his argument, rather than a demonstration that complete information guarantees correct reasoning or execution.

He invokes the Coase theorem as an economic analogy: with the right information and no transaction costs, people can reach an economically ideal negotiated outcome. Privacy and security obstruct the corresponding ideal for agents. Even an infinite context window would not make people willing to expose all their email. The difficult boundary therefore concerns permission to obtain and use information, not merely capacity to hold it.

This yields his evaluation question: how closely can a system reproduce the relevant context that an agent with unrestricted access would assemble? He introduces five strategies for bringing that information into the consequential LLM call while dealing with the boundaries around it.

2:302:31
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

2:30 · section reference included

Strategy one: share a trust boundary

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 334 seconds
Strategy one: share a trust boundary

The first strategy grants an agent broad access inside a boundary whose members already trust one another. Greze and his wife share an agent that can read both inboxes, including email from before they married. It helps answer practical household questions, such as whether he scheduled something for their children or followed up with a third party. Their willingness to share access makes information from both systems available without negotiating each retrieval.

At work, an HR team could use an agent with access comparable to an HR employee, perhaps limited to the access of the team's most junior member. Everyone on the team could query it. Greze says IT and security teams find this familiar because it resembles the security model already used for SaaS: a defined group receives access to a defined collection of systems.

His objection concerns how the architecture improves over time. Does it require fewer humans, and does a better model help it cross more information boundaries? He argues that this approach does neither automatically. Humans still determine the accessible data, and the agent inherits a newly defined silo. It can be useful immediately, but model improvements alone do not remove the organizational work needed to connect that silo to others.

4:224:25
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

4:22 · section reference included

Strategy two: expose a limited tool result

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 375 seconds
Strategy two: expose a limited tool result

The second strategy designs tools around a particular tradeoff between capability and privacy. Suppose someone wants an introduction to a member of Acme Corp's finance team. Unrestricted search could read every employee's Gmail, identify correspondence with Acme Corp, check the correspondents' roles, and find a colleague who frequently emails the CFO. That would provide useful evidence, but it would also expose everyone's mail to the requesting agent.

A narrower interface accepts a company domain and a target role, searches the mail internally, and returns relationship-strength scores. The requesting agent receives a ranking rather than the underlying correspondence. It can then contact Bob through Slack, confirm his connection to Jane, the CFO at Acme Corp, and ask about drafting an introduction. Broad access still exists inside the tool; the privacy tradeoff comes from restricting what the tool reveals outside that boundary.

Greze says Town uses this pattern for some common user needs, asking which limited tools users would accept and allowing them to opt out. Another example lets colleagues place draft emails in someone's inbox, reducing the effort of preparing introductions that the recipient would otherwise be asked to write. These capabilities create opportunities for network effects by making other people's connections or assistance usable through a constrained interface.

The limitation is that people must design each interface and explain its privacy consequences. Acceptance cannot be assumed simply because the tool is useful within a corporation. The arrangement remains manual and relatively static: its permitted outputs and capabilities reflect human design choices, rather than automatically expanding as the model becomes more capable.

6:096:11
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

6:09 · section reference included

Strategy three: accumulate permitted knowledge

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 610 seconds
Strategy three: accumulate permitted knowledge

The third strategy creates a shared knowledge space and steadily moves information into it. Agents can then retrieve useful material that would otherwise remain inside private systems even though it was acceptable to share. Repository skills illustrate the benefit: one engineer can contribute a better database-profiling procedure, and another engineer's agent can use it when a query is slow. Wikis and Airtable are other possible shared stores. The agents need both tools to access these stores and instructions or incentives that lead them to contribute and retrieve information.

Greze's favored extension is a sweeper AI inside each private silo. It receives a policy defining what must remain private and descriptions of the available shared destinations. At the end of the day, it examines new information and contributes permitted material to the appropriate spaces. Here, public means accessible within the company, not published to the wider world. The mechanism separates private collection from shared availability, allowing useful knowledge to accumulate before anyone asks a specific question.

The central decision is which private information may leave. One approach has the model propose contributions and ask the owner to approve them. That reduces the work of identifying and preparing useful material while retaining a human disclosure decision. The other approach delegates enforcement of the sharing policy to the LLM, so permitted contributions appear automatically.

Greze predicts adoption of automated policy enforcement within the next six months, especially at high-trust companies with 10 or 50 employees. He expects slower adoption at Fortune 500 enterprises. His smaller-company example assumes relatively clear exclusions, such as finance and HR data, and a low likelihood of misuse. These are conditions behind his forecast, not evidence that LLMs already enforce such policies reliably. The anticipated payoff is more effective execution of common work because relevant information is easier to reach.

8:418:50
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

8:41 · section reference included

Strategy four: ask people before searching and sharing

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 748 seconds
Strategy four: ask people before searching and sharing

The fourth strategy uses humans as the conduit between private stores. One agent asks another whether its owner knows someone on Acme Corp's finance team. The owner first approves searching their email, then reviews the result and approves sending it to the requester. Search permission and disclosure permission are separate decisions.

This becomes expensive when only a few people can answer. In a 100-person company, the question could generate 100 Slack pings asking employees to approve a search of their personal networks. The system interrupts everyone before it knows who has useful information. Greze identifies that mismatch between widespread requests and sparse answers as the reason to seek a more selective approval mechanism.

11:4911:50
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

11:49 · section reference included

Strategy five: search first, ask the relevant owner

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 848 seconds
Strategy five: search first, ask the relevant owner

The black-box approach moves approval later. An LLM with a trace unavailable to people searches across private information and reaches an answer or prepares a tool call. It then identifies which information the result or action depends on and asks only the owners of that information for approval. Greze describes this as powerful but says he has seen little use of it in practice.

In the introduction example, all 100 employees' agents search their Gmail and private silos automatically, without asking humans to approve that search. The black-box agent receives 20 connected candidates, uses email evidence to assess their connections, and selects Bob as the strongest. Only Bob receives a request asking whether his connection to Jane, Acme Corp's CFO, may be shared with Jean-Denis. The search still spans the company, but the human interruption is concentrated on the selected information owner.

The trust requirement is substantial: participants permit an LLM to cross their silos before the sharing decision. Greze argues that a company could accept this arrangement if the human approval step works correctly and other information cannot escape through the result. He also gives a sensitive counterexample. Asking whether someone knows a recruiter at another company could be used to discover that they are interviewing elsewhere. A relationship query can therefore expose a fact whose significance extends beyond the apparent purpose of the request.

12:4312:45
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

12:43 · section reference included

Shared knowledge can preserve mistakes as well as value

For immediate return on investment, Greze favors AI-maintained information bases, whether implemented as wikis or databases. He expects increasing delegation of decisions about what is acceptable to share. But the same path that makes information available also creates an attack surface: someone can place malicious content in a more open silo, and agentic search can retrieve it. He identifies prompt injection as a real risk without presenting a specific defense.

Ordinary model errors can also become persistent shared knowledge. Greze's personal wiki still identifies his agent as Apex even though he renamed it Ivy a month earlier. The old name remains somewhere in his memory setup and keeps resurfacing. The example illustrates a correction problem: storing an assertion does not ensure that later updates replace every source from which the assertion can return. An obsolete name is amusing; an incorrect business fact could have much greater consequences.

Disclosure mistakes have uneven consequences. Greze warns that fully automated steps can release information incorrectly, with outcomes ranging from no meaningful harm to someone losing a job or a customer suing. This makes approval ownership, logging, and reversibility substantive design questions. The black box also cannot remain entirely opaque: someone responsible for security will eventually need to audit what happens inside it. In his account, that requires privileged access at some level, reintroducing a human trust boundary around the supposedly hidden computation.

15:3015:31
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

15:30 · section reference included

Automate within a defined sensitivity boundary

Greze proposes selective automation as the next frontier. He compares it with coding assistants moving from approval of every action toward an automatic mode that decides when intervention is needed. For information sharing, he expects low-sensitivity material to move automatically into common spaces, while other categories remain subject to human review or mandatory approval. The useful distinction is the sensitivity of the disclosure and the policy governing it.

His example is a request for notes from a recurring weekly call with a supplier and its finance team. An agent could examine the notes, consider the requester's role, and determine that sharing them does not require asking participants again. This is a contextual disclosure decision based on both content and recipient. Greze presents it as a possible behavior, not a fully specified authorization system or a demonstrated guarantee.

The architectural attraction is that delegated decisions could improve with model capacity, better policy encoding, and tools designed for difficult privacy tradeoffs. His practical recommendation is to define a low-sensitivity zone where the LLM may make decisions now. He expects that zone to expand as systems improve, reducing human work and increasing useful access. That expansion is his forecast; it depends on improvements in policy enforcement and system design as well as stronger models.

17:3017:32
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

17:30 · section reference included

Cross-company cooperation and the unresolved trust question

Selected presentation frame from Agents' next frontier: agent-to-agent and network effects — Jean-Denis Greze, Town at 1176 seconds
Cross-company cooperation and the unresolved trust question

Returning to network effects, Greze expects the five approaches to become useful within companies relatively soon. The unresolved issue is how comfortable people will become with automatic privacy decisions. A larger opportunity would emerge if multiple companies agreed to let a common agent work across their separate information silos. Such cooperation requires an incentive to share useful information and agreement about the access that agents may exercise.

He describes an unnamed company exploring this direction with investment banks. The banks could benefit from sharing private information about private companies for activities such as lending. According to Greze, they are beginning to consider trusting one another's agents to work across previously private information, with agents deciding what may be accessed. Because he does not identify the participants or explain the implementation, the example supports an emerging use case rather than an established account of its security controls or results.

Greze sees concrete cross-company use cases as a starting point for broader cooperation. Yet he closes with personal uncertainty about a future in which agents make all privacy decisions. He believes increasing delegation is the direction of travel, while remaining unsure that he trusts its endpoint. The talk ends with that tension intact: more useful collaboration may depend on giving agents authority over information boundaries that people have traditionally controlled.

19:1619:19
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

19:16 · section reference included

Read the complete timestamped transcript
  1. 0:01

    [music]

  2. 0:12

    >> Can you all hear me? All right.

  3. 0:14

    Um

  4. 0:15

    Well, first things for coming. I can't

  5. 0:17

    believe there's anybody in the room, but

  6. 0:18

    that's very nice. Uh

  7. 0:20

    Uh my name is Jean-Denis. Um I'm CTO at

  8. 0:23

    a company called Town. We're not going

  9. 0:25

    to really talk about Town, so you can go

  10. 0:27

    to town.com and check that out if you

  11. 0:29

    want, but that's not the point of the

  12. 0:30

    talk today. I was CTO at Plaid for 7

  13. 0:33

    years, and then I was at Dropbox before.

  14. 0:36

    And then before that I built software

  15. 0:38

    for hedge funds. I've done lots of stuff

  16. 0:39

    in my career, and right now I'm working

  17. 0:42

    on

  18. 0:43

    uh assistance agents for for normal

  19. 0:45

    people, not not for engineers, but for

  20. 0:47

    like basically everyone in America and

  21. 0:48

    the world.

  22. 0:50

    And one of the things we've been working

  23. 0:51

    on are systems where agents work with

  24. 0:54

    other agents. So, agent-to-agent. And

  25. 0:56

    the main idea is that we think there's

  26. 0:59

    huge network effects if agents can work

  27. 1:02

    together to get things done for people

  28. 1:04

    because in the real world the way most

  29. 1:06

    of us do work is with other people,

  30. 1:09

    right? Uh

  31. 1:10

    more is better. But, actually

  32. 1:13

    I don't think agent-to-agent makes much

  33. 1:15

    sense as a concept. So, I want to

  34. 1:17

    reframe the entire talk in terms of

  35. 1:19

    search. So, I think

  36. 1:22

    most LLM systems are just a search

  37. 1:24

    problem.

  38. 1:25

    And what you're trying to do is you're

  39. 1:27

    trying to make sure the context window

  40. 1:30

    right before you either return results

  41. 1:32

    to the user or before a tool call,

  42. 1:34

    you're trying to make sure the context

  43. 1:35

    window has the right information for the

  44. 1:36

    user. If you put the right information

  45. 1:38

    in the context window

  46. 1:40

    then based on the

  47. 1:42

    intelligence, so to speak, of the LLM,

  48. 1:44

    you will get the best result possible.

  49. 1:46

    Um so, you know, 4 years ago the way we

  50. 1:48

    did that is humans would populate the

  51. 1:51

    context window manually. Then a couple

  52. 1:53

    years ago, most people are ragging, so

  53. 1:55

    they were like, let's have a tool, like

  54. 1:56

    a search tool, that can look across

  55. 1:58

    systems and bring the data in there. And

  56. 2:00

    then people were like, well, that

  57. 2:01

    doesn't scale super well, has issues.

  58. 2:04

    And now we're all about agentic search,

  59. 2:05

    which is the idea that you give the

  60. 2:07

    agent a lot of tools, and it'll search

  61. 2:09

    through the space of all content,

  62. 2:12

    and then hopefully before it makes a

  63. 2:13

    tool call, it has exactly the right

  64. 2:14

    content to make the right tool call to

  65. 2:16

    return the right information to the

  66. 2:18

    user.

  67. 2:19

    Um and in this, by the way, there's no

  68. 2:21

    there's no people. It's just a one LLM

  69. 2:22

    call at the like the one that matters

  70. 2:24

    having the right context. That's That's

  71. 2:26

    what you're trying to do. You're trying

  72. 2:27

    to engineer

  73. 2:28

    um that system.

  74. 2:30

    Cool. So, what what does that have to do

  75. 2:31

    with agent agent? So, I want you to

  76. 2:33

    imagine the following world.

  77. 2:35

    There's

  78. 2:37

    not many agents that can do things.

  79. 2:39

    There's just one agent,

  80. 2:41

    right? And it has one context window,

  81. 2:43

    and it has access to all the information

  82. 2:45

    in the universe.

  83. 2:47

    It can look at any one person's email,

  84. 2:49

    can look at any company's information,

  85. 2:52

    can look at any government's

  86. 2:53

    information,

  87. 2:54

    and it has it right there in the context

  88. 2:55

    window,

  89. 2:56

    and then you ask it to do something. You

  90. 2:59

    You have your little system prompt with

  91. 3:00

    all that data, and what's going to

  92. 3:02

    happen is it'll give you the best

  93. 3:03

    possible outcome.

  94. 3:05

    And that actually That is a multi-agent

  95. 3:08

    world.

  96. 3:09

    It's just an agent that has access to

  97. 3:10

    all the world's information. That's the

  98. 3:12

    natural state of things. That's the

  99. 3:13

    ideal state of things. There's a problem

  100. 3:15

    with this state of things, and the

  101. 3:17

    problem comes from

  102. 3:19

    a few So, you're learning economics

  103. 3:21

    something called the Coase theorem, and

  104. 3:22

    it says that basically even humans, if

  105. 3:24

    they all have access to all the right

  106. 3:26

    information and there's no transaction

  107. 3:27

    costs, we get the economically

  108. 3:30

    ideal outcome out of a out of a contract

  109. 3:32

    or negotiation. Well, it's the same

  110. 3:34

    thing. We can't put all of the world's

  111. 3:36

    contacts We can't make it available to

  112. 3:38

    the LLM. Like theoretically even with

  113. 3:40

    infinite context window, because of

  114. 3:42

    privacy and security.

  115. 3:44

    We're humans. I don't let you look at my

  116. 3:46

    email, so there cannot be an agent that

  117. 3:49

    I'm willing to just let it look at my

  118. 3:50

    email all the time. But, if it existed,

  119. 3:54

    it would be very, very powerful. So, I I

  120. 3:56

    think this is like this is the test for

  121. 3:58

    a multi-agent system, which is how well

  122. 4:00

    does it approximate this?

  123. 4:02

    If it approximates this, that means if

  124. 4:03

    you can get the same data in your window

  125. 4:06

    that a perfect system that has access to

  126. 4:07

    all the world's data could, then you get

  127. 4:09

    the optimal outcome. That's what you

  128. 4:10

    need to try to do. So, we're going to

  129. 4:12

    talk about five strategies that people

  130. 4:14

    use at various companies to try to get

  131. 4:17

    the right data into that that LLM call

  132. 4:20

    with an externality. So,

  133. 4:22

    the first one is

  134. 4:25

    approximate access to everything within

  135. 4:26

    a trust boundary.

  136. 4:28

    So, my wife and I, we have an agent

  137. 4:30

    together,

  138. 4:31

    and that agent has access to my email

  139. 4:33

    and her email,

  140. 4:35

    uh including emails before we were

  141. 4:37

    married.

  142. 4:39

    Uh and it's okay, she doesn't ask my

  143. 4:40

    agent questions about that, but she does

  144. 4:41

    ask about, you know, whether I like

  145. 4:43

    schedule something for our kids or, you

  146. 4:45

    know, uh if I followed up on some

  147. 4:47

    third-party thing. And so, the fact that

  148. 4:49

    our agent has access to both of our

  149. 4:50

    systems is wonderful.

  150. 4:52

    Um and the work context, this might be

  151. 4:54

    there's a an HR team agent that has

  152. 4:56

    access to all the HR systems, just like

  153. 4:58

    an employee of the HR team would, or

  154. 5:00

    maybe as much access as the lowest

  155. 5:02

    employee in the HR team. All the

  156. 5:04

    employees in the HR team have the

  157. 5:05

    ability to ask this agent questions, and

  158. 5:08

    boom, it gets pretty good results.

  159. 5:10

    And this is very popular right now.

  160. 5:12

    Uh it's very popular with IT teams and

  161. 5:14

    security teams cuz it's the same model

  162. 5:17

    as SaaS for security, so it works really

  163. 5:19

    well.

  164. 5:20

    I think it has a problem, which is a

  165. 5:22

    fundamental problem that if I wake up in

  166. 5:24

    the morning, it's like basically the

  167. 5:25

    only thing I think about, which is does

  168. 5:27

    it get Over time, does this system

  169. 5:30

    naturally require fewer humans?

  170. 5:32

    And then, as the models get better, does

  171. 5:35

    this approach get better? And the

  172. 5:36

    problem with this approach is the answer

  173. 5:37

    is no to both.

  174. 5:39

    Uh you still need humans to think about

  175. 5:41

    all the data, and you don't get magical

  176. 5:43

    de-siloification of your data. You've

  177. 5:45

    just created a new silo cuz a human

  178. 5:47

    thought about it.

  179. 5:49

    So, the problem with this is I do think

  180. 5:50

    if this is your approach to building

  181. 5:52

    better AI, you're going to be in

  182. 5:55

    the next couple years.

  183. 5:56

    Um but that's okay. Your is my

  184. 5:59

    opportunity.

  185. 6:00

    Uh I'm just I'm just not an I'm

  186. 6:03

    sorry. That was mean. But like I think

  187. 6:04

    it's not I think it's a good now way to

  188. 6:06

    think about it. It's not the good end

  189. 6:07

    game way to think about it.

  190. 6:09

    The other approach which is I think is a

  191. 6:10

    little more clever and then I'm going to

  192. 6:11

    try to explain it is basically you try

  193. 6:13

    to have tools that make a different

  194. 6:15

    trade-off between power and privacy.

  195. 6:18

    So, I'm going to give you an example

  196. 6:19

    here. Um the use case is I want to ask

  197. 6:22

    my agent, does anyone in my company is

  198. 6:24

    anyone in my company connected to

  199. 6:26

    someone on the finance team at Acme

  200. 6:27

    Corp?

  201. 6:29

    And so,

  202. 6:31

    what the the no silo way to do that is

  203. 6:33

    just give me access to everyone's Gmail

  204. 6:34

    in my company.

  205. 6:36

    I'll see who has emails with people from

  206. 6:37

    Acme Corp. Then I'll look at their

  207. 6:39

    profile on Google or LinkedIn and then

  208. 6:42

    I'll be like, oh, you seem to email a

  209. 6:43

    lot with the CFO. Can you do the intro

  210. 6:45

    for me? But right, obviously silos, we

  211. 6:47

    don't want that. So, what if you build a

  212. 6:49

    tool and what the tool did is

  213. 6:52

    it looked at everyone's Gmail. So, that

  214. 6:53

    tool had access to everyone's Gmail and

  215. 6:55

    it just returned a relationship strength

  216. 6:57

    score.

  217. 6:58

    So, the tool you would give it like a

  218. 7:00

    domain and you would say I'm looking for

  219. 7:02

    someone who's a CFO. It would look at

  220. 7:04

    everyone at the company who sent emails

  221. 7:06

    to that company and then it would like

  222. 7:08

    rank their score and they would give you

  223. 7:09

    back the score and then the agent would

  224. 7:11

    get the score and it would be like cool.

  225. 7:13

    Then they would use a Slack tool to text

  226. 7:15

    that person the company. It's like, hey

  227. 7:16

    Bob, I see that you're connected to the

  228. 7:17

    Jane who's the CFO at Acme Corp. And

  229. 7:20

    then Bob would be like, yes, I am. And

  230. 7:22

    then your AI would be like, oh, can you

  231. 7:23

    draft an e- can I draft an email or can

  232. 7:25

    you draft an email introducing me? And

  233. 7:26

    then Bob would say, yes, and he would do

  234. 7:28

    that and you'd be connected and

  235. 7:29

    everything would be wonderful. So, this

  236. 7:31

    is actually very cool approach. I don't

  237. 7:33

    know how many of you do it. Like we we

  238. 7:35

    do this at Town for a few things that we

  239. 7:37

    see a lot of our users do. We ask

  240. 7:38

    ourself, what is a privacy preserving

  241. 7:40

    tool that all of our users would be okay

  242. 7:42

    existing? They can opt out if they don't

  243. 7:43

    want it, but it has a natural network

  244. 7:46

    effect because it breaks through silos

  245. 7:47

    in interesting way.

  246. 7:49

    Um, like another one that's interesting

  247. 7:50

    here is letting other people put draft

  248. 7:52

    emails in your inbox.

  249. 7:54

    You let other people at your company

  250. 7:55

    draft emails on your behalf cuz they're

  251. 7:56

    going to ask you to anyway to get intros

  252. 7:58

    if they're on the sales team, so might

  253. 7:59

    as well save yourself a few clicks.

  254. 8:02

    So, the question here is like are people

  255. 8:03

    going to be okay with a privacy

  256. 8:04

    trade-off that you make within a

  257. 8:06

    corporation?

  258. 8:08

    Uh,

  259. 8:08

    bad. Bad.

  260. 8:11

    Oh, boy.

  261. 8:13

    Within a corporation that will, you

  262. 8:14

    know, mostly it works. Um,

  263. 8:17

    so the problem here again is it's again

  264. 8:19

    manual and not dynamic. It's manual cuz

  265. 8:21

    humans need to think about the tools.

  266. 8:23

    Maybe I could build the tools.

  267. 8:25

    Uh, and it's also manual cuz you need to

  268. 8:27

    explain it to everyone that it's

  269. 8:29

    happening. Humans may not like it if

  270. 8:30

    this is happening if they're not okay

  271. 8:32

    with the privacy security the privacy

  272. 8:34

    kind of power trade-off that you've

  273. 8:35

    made. Cool. And again, this doesn't

  274. 8:38

    really get better as they I guess

  275. 8:39

    better. That's the problem.

  276. 8:41

    Cool. So, now the third category. This

  277. 8:42

    one's super popular, but only mostly in

  278. 8:45

    the single user context. So, this is,

  279. 8:46

    you know, like personal wikis in claw

  280. 8:48

    land. That's what we would call it. But

  281. 8:50

    it's across teams. So,

  282. 8:52

    it's a shared silo. Create a new place

  283. 8:55

    where data accumulates

  284. 8:56

    within your company within subgroups at

  285. 8:58

    your company.

  286. 8:59

    Um, and you start to put more and more

  287. 9:01

    stuff there over time.

  288. 9:03

    And all the agents have access to that

  289. 9:04

    stuff. Because they have access to it,

  290. 9:07

    you no longer have information that

  291. 9:08

    would be okay to be shared that's stuck

  292. 9:10

    in a silo. It now automatically filters

  293. 9:12

    out into this public space. So,

  294. 9:14

    examples, shared skills. If you code in

  295. 9:17

    an organization, probably in your repo

  296. 9:19

    you have shared skills. Anyone can make

  297. 9:21

    them better. Someone has a better way

  298. 9:22

    to, you know, profile your database or

  299. 9:24

    whatever. They can write the skill. Next

  300. 9:26

    time someone's sitting there is like,

  301. 9:27

    "Oh my god, the database query is slow."

  302. 9:29

    It uses the

  303. 9:31

    profiling skill and everyone's a better

  304. 9:32

    engineer. So, that's one version. The

  305. 9:34

    other one that's pretty popular is

  306. 9:35

    people decide they have some shared

  307. 9:37

    mediums, like a wiki, airtable, etc. And

  308. 9:40

    they uh they have a scale that says,

  309. 9:42

    "Hey, put more data in there over time."

  310. 9:44

    So, these are cool.

  311. 9:45

    Um and they work as long as your your

  312. 9:48

    agents have those tools and also some

  313. 9:51

    trajectory incentives to really like get

  314. 9:53

    data out in and out of of these shared

  315. 9:55

    silos. Um

  316. 9:57

    I think the next version of this that a

  317. 9:59

    few people are working on is like you

  318. 10:01

    have a sweeper AI. So, this actually if

  319. 10:03

    there's one good idea in this talk

  320. 10:06

    that I think works really well is this.

  321. 10:08

    It's a sweeper AI. So, you have an AI

  322. 10:10

    inside each private silo.

  323. 10:12

    An AI has a policy about what has to

  324. 10:15

    stay in the silo.

  325. 10:17

    And then it also has a description of

  326. 10:20

    all the shared spaces that you have. And

  327. 10:22

    at the end of the day, it looks at new

  328. 10:23

    information in the silo

  329. 10:25

    and it puts it in the public spaces.

  330. 10:26

    Well, public, public to your company.

  331. 10:28

    So, this is the same as the personal

  332. 10:30

    wiki that you all have AI building for

  333. 10:32

    you at the end of the day so that I can

  334. 10:33

    know your goals and your friends and all

  335. 10:34

    that stuff, but it's at the company

  336. 10:36

    level.

  337. 10:37

    Um

  338. 10:38

    the hard part is how do we pick what

  339. 10:39

    private information is okay to to share

  340. 10:42

    and to put it in shared silos. And I

  341. 10:44

    think there's two approaches. There's

  342. 10:46

    the ask a human approach. So, this is

  343. 10:48

    like

  344. 10:50

    the LLM comes up with a list of things

  345. 10:51

    to contribute and then it asks the user,

  346. 10:54

    "Hey, are you okay with me putting this

  347. 10:55

    in the shared space?"

  348. 10:56

    And you read it. You're like, "Yep."

  349. 10:58

    Saved you a bunch of time.

  350. 10:59

    Right? I mean, you weren't going to do

  351. 11:00

    it otherwise.

  352. 11:02

    Uh

  353. 11:02

    I think the other version is you

  354. 11:03

    actually ask the LLM to enforce a

  355. 11:06

    policy.

  356. 11:07

    And I think that actually is where

  357. 11:09

    things are going to go very, very

  358. 11:10

    quickly. Um and I think in the next 6

  359. 11:13

    months we'll have a bunch of systems

  360. 11:14

    where companies have trusted an LLM with

  361. 11:16

    a policy to automatically surface more

  362. 11:19

    and more information that otherwise

  363. 11:20

    would have been private into a public

  364. 11:22

    space. If you're like at a Fortune 500

  365. 11:24

    enterprise company, unfortunately,

  366. 11:26

    I don't think that's going to happen for

  367. 11:27

    a while, but I think if you look at

  368. 11:28

    smaller companies, like 10, 50 person

  369. 11:30

    employees, high trust, like low

  370. 11:32

    likelihood of something one one doing

  371. 11:34

    bad with the data, which really clear to

  372. 11:36

    know what data couldn't be shared,

  373. 11:37

    basically finance and HR data, you're

  374. 11:40

    going to see a ton of this. And the cool

  375. 11:42

    thing here is this really improves

  376. 11:43

    trajectories of systems on on common

  377. 11:46

    work.

  378. 11:47

    All right, that was third approach.

  379. 11:49

    Fourth approach pretty obvious, use

  380. 11:50

    humans as the conduit for information.

  381. 11:52

    So this is like traditional agent to

  382. 11:54

    agent.

  383. 11:55

    My agent ask your agent, "Hey,

  384. 11:58

    who is connected to someone on the

  385. 12:01

    finance team at Acme Corp?"

  386. 12:03

    You as a human see the request and

  387. 12:05

    you're like, "Yeah, I'm okay with that.

  388. 12:07

    Go and find the information inside of my

  389. 12:09

    email."

  390. 12:10

    And then it shows you the result. And

  391. 12:12

    then you're like, "Yes, I'm okay with

  392. 12:13

    that result

  393. 12:14

    going to the person who asked." The big

  394. 12:17

    problem with it is for for any request

  395. 12:19

    that has low where it's like only a few

  396. 12:22

    people will have the information, you're

  397. 12:23

    kind of spamming everyone the request.

  398. 12:25

    So if I ask this question to 100-person

  399. 12:27

    company, 100 people are being pinged on

  400. 12:29

    Slack, being like approves on these

  401. 12:30

    requests to like farm your personal

  402. 12:33

    network for this for this, you know, for

  403. 12:35

    this like the answer to this question.

  404. 12:38

    That's not very efficient. Um

  405. 12:40

    And so that's why there's a better

  406. 12:41

    version of it.

  407. 12:43

    Um which I this is this is very

  408. 12:45

    powerful, but uh I haven't seen it in

  409. 12:47

    practice much. It's it's a black box

  410. 12:49

    approach.

  411. 12:51

    I wish I had a diagram for this.

  412. 12:52

    Unfortunately for you all, I do not. So

  413. 12:54

    here's what this means. The black box

  414. 12:56

    approach is where when you ask a

  415. 12:58

    question

  416. 13:00

    that can only be answered by looking at

  417. 13:02

    information in other people's silos. You

  418. 13:04

    have an LLM,

  419. 13:06

    the trace of which no one has access to,

  420. 13:08

    that gets access to all of the data,

  421. 13:11

    and it gets to the answer.

  422. 13:13

    Right? Like by say get to the answer,

  423. 13:15

    either gets the answer or it's about to

  424. 13:17

    do the the the any tool call that's all

  425. 13:19

    right.

  426. 13:20

    And then it looks at what information

  427. 13:22

    did it need to make that tool call,

  428. 13:24

    and it only ask the people

  429. 13:26

    who own that information for their

  430. 13:28

    approval to do the tool call.

  431. 13:30

    So, in the example before that I gave,

  432. 13:31

    when I ask 100 people at my company,

  433. 13:33

    "Hey, do you know the CFO at Acme Corp?"

  434. 13:36

    The request goes to everyone's agents in

  435. 13:39

    my company.

  436. 13:41

    All of their agents look in their Gmail

  437. 13:43

    and their private silos to see if

  438. 13:45

    they're connected to the CFO.

  439. 13:47

    That happens automatically. No No human

  440. 13:49

    is being asked for approval for that to

  441. 13:50

    happen.

  442. 13:51

    Then it

  443. 13:53

    the agent in the black box ha gets the

  444. 13:55

    list of the 20 people who are connected.

  445. 13:59

    It looks at contacts from the emails to

  446. 14:01

    determine who has the strongest

  447. 14:02

    connection. It determines that it's Bob.

  448. 14:06

    And then, it just asks Bob, "Hey,

  449. 14:09

    Jean-Denis

  450. 14:10

    wants you to introduce him

  451. 14:12

    to Jane, the CFO at Acme Corp.

  452. 14:14

    I know you're well connected to her. Am

  453. 14:16

    I okay sharing that bit of information

  454. 14:17

    with Jean-Denis?"

  455. 14:19

    And you're like, "Yeah, sure." You click

  456. 14:20

    yes. No big deal.

  457. 14:21

    The important thing is you have to trust

  458. 14:23

    the black box. So, you have to trust

  459. 14:24

    that you can break down all the silos

  460. 14:28

    for an LLM that has full access

  461. 14:31

    and that doesn't ask for permission

  462. 14:33

    until there's this sharing moment or

  463. 14:35

    this right step.

  464. 14:37

    So, actually, within a company, this is

  465. 14:38

    not impossible to do.

  466. 14:40

    Uh

  467. 14:41

    and actually, your security and

  468. 14:43

    compliance team can get okay with it. Um

  469. 14:46

    you just have to have You have to be

  470. 14:47

    sure that the human in the loop step is

  471. 14:50

    correct, and you have to be sure that

  472. 14:52

    you're not letting other information go

  473. 14:54

    through without last answer. So, you

  474. 14:56

    know, like the the nightmare scenarios

  475. 14:58

    and things like this are things like uh

  476. 15:01

    um

  477. 15:02

    Sorry. I'm like

  478. 15:05

    We have plenty of time. I'm almost done.

  479. 15:06

    So, it's great. Um the nightmare

  480. 15:08

    scenarios with things like this is

  481. 15:09

    someone asks a question like,

  482. 15:11

    "Are you connected to a recruiter at the

  483. 15:13

    other company that you have no business

  484. 15:15

    being recruited to as a way for them to

  485. 15:17

    find out that you're interviewing

  486. 15:18

    somewhere else, right?" So, you know,

  487. 15:20

    there are you you still sometimes with a

  488. 15:22

    black box inadvertently get an

  489. 15:24

    information out that you shouldn't be

  490. 15:26

    able to. You have to really think about

  491. 15:28

    how you would build a great system.

  492. 15:30

    So, those are the those are the

  493. 15:31

    approaches. I think if I were to bet on

  494. 15:34

    one that has immediate ROI that we're

  495. 15:36

    going to all see in both like open

  496. 15:38

    source claw-ish worlds and then like

  497. 15:41

    small companies, it's going to be the

  498. 15:42

    wiki that's automatically created by AI

  499. 15:44

    like the information base that's kept up

  500. 15:46

    to date. I think there will be database

  501. 15:47

    versions of it, wiki versions of it, and

  502. 15:50

    I think more and more we're going to

  503. 15:51

    trust LLMs to make the decision about

  504. 15:53

    what's okay to share and what's not.

  505. 15:55

    There are problems. So, prompt injection

  506. 15:58

    in in the silos can be a real problem.

  507. 16:01

    Obviously. So, if you have a silo that

  508. 16:03

    has like that's more open and someone

  509. 16:05

    can put something bad in there and then

  510. 16:07

    that as part of the energetic search you

  511. 16:09

    pull it out, you know, bad things can

  512. 16:11

    can happen.

  513. 16:12

    Uh you can have it's very easy to have a

  514. 16:14

    shared wiki that just goes like totally

  515. 16:16

    off the rails,

  516. 16:17

    you know, like the information there one

  517. 16:19

    piece of information there is incorrect

  518. 16:21

    cuz LLM made a mistake and then it like

  519. 16:23

    poisons it forever. I have a personal

  520. 16:25

    wiki that thinks my agent's name is Apex

  521. 16:27

    right now, but I renamed my agent a

  522. 16:29

    month ago to Ivy. And like somewhere in

  523. 16:31

    memory bank uh uh

  524. 16:33

    of my like setup uh Apex lives and so I

  525. 16:37

    can't get rid of it.

  526. 16:38

    Uh that's fine for Apex. That's a funny

  527. 16:40

    one, but it's like much more difficult

  528. 16:41

    if it's a really wrong piece of

  529. 16:43

    information about your business.

  530. 16:45

    Um

  531. 16:46

    if you don't have human in the loop for

  532. 16:48

    any of the steps, obviously there'll be

  533. 16:50

    false and wrong disclosures. You know,

  534. 16:53

    sometimes when there's a wrong

  535. 16:54

    disclosure of information, someone gets

  536. 16:56

    fired. Someone there's a wrong

  537. 16:58

    disclosure,

  538. 16:59

    it doesn't matter at all. Sometimes a

  539. 17:01

    customer sues you. So, you know, uh you

  540. 17:03

    got to be careful.

  541. 17:05

    Um and then I think

  542. 17:08

    this all sounds nice, but like who

  543. 17:09

    approves what, what's logged, what's

  544. 17:11

    reversible? The black box idea is really

  545. 17:13

    great, but it can't truly be a black

  546. 17:15

    box. Someone at your company will want

  547. 17:17

    to audit it at some point. They want to

  548. 17:19

    understand what's going in there, right?

  549. 17:20

    So, at some level there must be some

  550. 17:22

    person in the CISO suite or somewhere

  551. 17:24

    that has access to all the data.

  552. 17:26

    Um

  553. 17:28

    Yeah.

  554. 17:29

    So,

  555. 17:30

    um what do I think? Well, I do think the

  556. 17:32

    frontier is auto. So, I've said that. I

  557. 17:34

    think in coding we used to approve

  558. 17:36

    everything. Then we were like, "YOLO,

  559. 17:37

    live dangerously." And now the gods at

  560. 17:39

    Anthropic have granted us auto mode. And

  561. 17:42

    auto mode tries to figure out when we're

  562. 17:43

    maybe being a little silly and it tells

  563. 17:45

    us. Well, I think A to A across

  564. 17:48

    information silos will be the same way.

  565. 17:50

    I think what's going to happen is we're

  566. 17:51

    going to get comfortable with low

  567. 17:52

    sensitivity information being pulled out

  568. 17:54

    and put into common spaces. And then we

  569. 17:56

    will have a place that's like human

  570. 17:58

    review or always human approved.

  571. 18:00

    And then over time what's going to

  572. 18:02

    happen is the LLMs will get more

  573. 18:03

    powerful.

  574. 18:04

    We will be better at encoding safe

  575. 18:06

    policies within them. We'll be better at

  576. 18:08

    designing for the really hard areas

  577. 18:10

    tools that get the privacy trade-off

  578. 18:12

    correct.

  579. 18:13

    And it'll just be more and more auto for

  580. 18:15

    building shared silos and even sometimes

  581. 18:17

    for deciding whether involve a human.

  582. 18:19

    So, the example that I have is like if I

  583. 18:22

    ask for notes from a weekly recurring

  584. 18:24

    call with, you know, a supplier of ours

  585. 18:27

    and their finance team, maybe the the

  586. 18:29

    LLM's like, "Oh, well, in giving your

  587. 18:31

    role, I don't need to ask anyone on

  588. 18:33

    those teams for permission. I can just

  589. 18:34

    share the notes with you. It's like it's

  590. 18:36

    fine. I they can it can look at the

  591. 18:38

    content. It can see what my role is. It

  592. 18:39

    can decide from a risk perspective I'm

  593. 18:42

    okay with that disclosure."

  594. 18:43

    Um and the cool thing about auto, by the

  595. 18:46

    way, is if you design your systems that

  596. 18:47

    way, it'll scale with model capacity.

  597. 18:49

    So, my encouragement would be like, you

  598. 18:51

    need to start if you have agent to agent

  599. 18:53

    or or work across silos, which is I

  600. 18:55

    think the better way to think about it,

  601. 18:56

    definitely define a low sensitivity zone

  602. 18:59

    where you're okay with the LLM making a

  603. 19:00

    call.

  604. 19:02

    And get okay with that.

  605. 19:04

    And then magically, as time goes on,

  606. 19:07

    it'll get bigger and your system will

  607. 19:08

    naturally get more powerful, which is

  608. 19:09

    what you you So, you want to be on a

  609. 19:11

    beach.

  610. 19:13

    That's what you want to do. That's where

  611. 19:14

    I want to be. My kids

  612. 19:16

    in Hawaii. Okay, network effects. I've 1

  613. 19:18

    minute.

  614. 19:19

    Uh this is the conclusion. So, we talked

  615. 19:22

    about five approaches, blah blah blah,

  616. 19:24

    trust boundaries, custom tools, shared

  617. 19:25

    silos, humans in the loop, and this

  618. 19:27

    human in the black box version. Uh I

  619. 19:30

    think this stuff is very powerful.

  620. 19:32

    I think the interesting questions a

  621. 19:33

    little bit are

  622. 19:35

    in within companies, I think this will

  623. 19:36

    all work very soon. The big question is

  624. 19:38

    where how how how comfortable are we are

  625. 19:40

    we with something like an auto mode

  626. 19:42

    around privacy?

  627. 19:43

    And I think the really interesting

  628. 19:44

    question that I don't have an answer

  629. 19:46

    for, but I think whoever does this will

  630. 19:47

    be wealthier than I am, is if you can

  631. 19:50

    think of

  632. 19:52

    scenarios where you can get multiple

  633. 19:54

    companies to agree to their information

  634. 19:57

    silos

  635. 19:59

    having a common agent working across

  636. 20:00

    them. So, there's like a company that I

  637. 20:02

    won't name in in in in somewhere in the

  638. 20:05

    world, uh working on like finance stuff

  639. 20:07

    where they have a lot of investment

  640. 20:08

    banks. And actually the investment banks

  641. 20:10

    there's a benefit to them sharing

  642. 20:11

    private data about private companies for

  643. 20:13

    purposes of things like lending.

  644. 20:15

    And they're starting to look in this

  645. 20:16

    direction. Where they're trusting each

  646. 20:18

    other's agents to be able to work across

  647. 20:20

    what before would have been private

  648. 20:21

    information, with agents deciding what

  649. 20:23

    can be accessed or not. And it's it's

  650. 20:25

    cool. It's very cool. And I think once

  651. 20:27

    you find some use cases across across

  652. 20:30

    companies, uh

  653. 20:32

    I think that'll be a really good

  654. 20:33

    beachhead to to move more in this

  655. 20:35

    direction.

  656. 20:36

    So,

  657. 20:37

    yeah.

  658. 20:38

    You know, as a human though, I ask

  659. 20:39

    myself,

  660. 20:41

    do I trust the future where agents make

  661. 20:43

    all the decisions about privacy? I don't

  662. 20:45

    know about that. I just think it's a it

  663. 20:46

    is for better or worse the direction

  664. 20:48

    things are going.

  665. 20:50

    And I just I'm like so good on time. So,

  666. 20:52

    I'm on time. Thank you for coming. I

  667. 20:54

    again, uh

  668. 20:56

    yeah. [applause] Thanks for being here,

  669. 20:57

    and

  670. 21:13

    >> [music]

  671. 21:16

    >> Mhm.