A clip from a Milken Institute talk has been circulating in which Tristan Harris describes, as the post presents it, AI systems finding their own ways to complete a goal once given tools and access.
The engineering question underneath that description holds whatever one makes of the examples.
The mechanism. A system given tools, a goal, and room to act will search for routes to the goal. Routes nobody listed are still routes. That is what optimization does, and it is dull and well understood.
One announcement before we continue with today's piece.
In response to strong demand, we are running the NVIDIA AI Developer Bootcamp, an NVIDIA-certified workshop, in partnership with De La Salle University, Manila.
It runs three days and stays hands-on throughout:
1. Deep learning fundamentals. The core techniques and tools, worked through rather than lectured.
2. Data types and model architectures. Practice with the kinds you will actually meet at work, not textbook cases.
3. Transfer learning. Building a model by starting from one that has already learned the general patterns and adapting it to your own data, which is how most working models get built today.
Participants who complete all three days receive an NVIDIA certification.
When: 9 to 11 October 2026, Friday to Sunday, 9 AM to 6 PM
Where: De La Salle University, Manila

Four objections.
1. The clip is built to alarm. Clips are. The mechanism is not alarming; it is a property of the system to design around.
2. Nobody runs agents with that much access. An agent with shell access and a network connection has more reach than a permission review assumes, and the reach often arrives through a helper library nobody audited.
3. Alignment research will handle it. It is in progress, and operates at the model layer. Sandboxing and logging operate at the deployment layer, which is the one your team controls.
4. It slows everything down. A sandbox and a tool-call log cost far less than the incident they prevent, and most of the cost is paid once.
What this actually asks of a team. Before an agent touches a live system, even on a laptop, run it once where an unexpected route is harmless, then read the log of every tool it called. That log is the only honest account of what the agent does, as opposed to what the prompt says.
None of that requires a position on how risky AI is. It is ordinary engineering discipline applied to a system that acts.