The most surprisingly reasonable lawsuit ever [part1]
Fermi Equations [ai written]
Fermi Equations
The hidden theory behind Fermi estimation is that prediction improves through decomposition. If I attack a hard question with enough inputs, some of my biases toward overestimation and underestimation will cancel. The implicit assumption is that the inputs are semi-independent—which, as we will see, is exactly the assumption that breaks most interestingly.
A generic Fermi structure looks like this:
But the real method is not the multiplication. The real method is the selection of terms. A good Fermi estimate is a portfolio of assumptions, and like any portfolio, its quality depends less on the number of holdings than on whether they are genuinely diversified.
I have been working through this idea across a handful of recent problems. Each one taught me something different about what makes decomposition work—and what makes it fail while looking like it works.
1. The Claude Code leak: what will it cost Anthropic?
On March 31, a public Claude Code release included internal source code—apparently via source maps pointing to unobfuscated TypeScript in Anthropic-controlled storage. Anthropic called it "a release packaging issue caused by human error, not a security breach," and said no customer data or credentials were exposed. The exposure reportedly covered roughly 500,000 lines across about 1,900 files. This came only days after a separate incident involving draft model-related content exposed through a CMS configuration error—also attributed to human error. For context, Anthropic was recently valued at roughly $61 billion, and Claude Code's run-rate revenue was reported above $2.5 billion as of February.
The natural Fermi question: what did this actually cost?
That decomposition matters because these terms live in different causal universes. Response cost is mostly payroll burn and outside counsel. Sales drag is an enterprise-trust function. Roadmap delay is opportunity cost. IP leakage is a competitor-learning term. Capital-markets discount is mostly narrative and governance. Separating them forces you to reason about each mechanism on its own terms rather than collapsing everything into a single dramatic number.
Once you do that, the picture clarifies. No customer data and no model weights were exposed, so the catastrophic tail is capped. But the cost is still real because Anthropic now operates at a scale where tiny percentage effects are expensive. A company with multi-billion-dollar run-rate and enterprise-heavy revenue does not need a breach-sized event to lose a meaningful amount of money. It only needs a few more procurement escalations, a little more discounting, a few delayed expansions, and a few weeks of diverted engineering attention.
Working through each term:
Response and remediation: ~$5M–$15M
Figure 50 to 150 people across security, release engineering, infrastructure, product, comms, support, and executive time, working 4 to 8 weeks at loaded weekly costs of $8K–$12K per person, plus outside counsel and communications support. At Anthropic's scale, this alone clears several million.
Legal, compliance, and customer assurance: ~$2M–$10M
Outside counsel, takedown and IP work, extra vendor-security reviews, contract remediation, security questionnaires, bespoke explanations for strategic accounts, pen-test attestations, and packaging-process audits. The repeated "human error" narrative likely increases the number of accounts that escalate review.
Commercial and sales drag: ~$15M–$75M
Probably the biggest real cost. Two ways to bound it. From Claude Code run-rate: $2.5B × (1%–5% drag) × (0.25–0.75 years) ≈ $6M–$94M. From broader enterprise trust: ($19B × 80% enterprise share) × (0.1%–0.5% drag) × (0.1–0.5 years) ≈ $15M–$76M. These ranges overlap, so the top of both should not be used simultaneously. The point is that even tiny renewal slippage, delayed expansions, or extra discounting becomes a double-digit-million problem very quickly at this scale.
Roadmap delay and opportunity cost: ~$5M–$20M
Distinct from payroll burn. The cost here is slowed feature velocity, delayed launches, and 30 to 80 core product and security people diverted from product work into cleanup and hardening for 4 to 8 weeks, multiplied by the commercial value of whatever they would otherwise have shipped.
IP and competitive leakage: ~$5M–$25M
This is where people tend to overstate the damage. The leaked asset was product code, not model weights. Claude Code had already been partially reverse-engineered. But the leak was broad enough that it still lowers the cost for rivals and researchers to study Anthropic's harness, guardrails, and tooling patterns. If the leaked harness embodied tens of millions of dollars of engineering effort, and only a fraction of that is genuinely transferable, the realized value transfer is still in the single- to low-double-digit millions.
Capital-markets discount: $0 now, potentially $100M+ in paper value
The most speculative term, so I keep it out of the base-case total. At a $61B valuation, even a 0.05%–0.25% governance discount in a future financing or IPO narrative is $30M–$150M of paper value. I would only start assigning this if the market decides the two March incidents indicate a repeatable control failure rather than bad luck.
Bottom line:
Hard-cash, near-term operating cost: roughly $10M–$30M
Full economic cost, base case: roughly $50M–$150M
Central estimate: ~$80M–$120M
Stress case if enterprise trust damage compounds: low hundreds of millions. True catastrophe only if the leaked code leads to materially exploitable findings, major customer churn, or a durable governance discount in fundraising or IPO pricing.
2. The Jeopardy "IDK" problem: when coincidence enters lottery territory
The Ryan Gosling Jeopardy promo is a very different kind of problem, but the same method applies.
In the promo, "What is IDK?" was accepted as a correct answer because the intended response was "Internal Derangement of the Knee"—a clinical term adjacent to ACL tears. The natural Fermi question: what are the odds that someone would win Final Jeopardy that way in a genuinely unscripted setting?
Two independent decompositions converge on roughly the same absurd region. The first estimated the probability that a contestant writes "IDK" multiplied by the probability that the intended answer happens to be something for which "IDK" is also a legitimate abbreviation, landing around 1 in 150 million. The second conditioned on an ACL-type answer appearing, on that clue being in the Final Jeopardy slot, on a contestant being both ignorant and aware of their ignorance, and on that person specifically choosing "IDK"—landing around 1 in 547 million. Add the further requirement that real judges would have to accept the acronym connection, and both estimates settle into the 1-in-300-million to 1-in-a-billion band.
What I like about this problem is not the answer but the convergence. Two different decompositions, with different hidden priors, ended up in roughly the same region. That is exactly the kind of triangulation you want from Fermi work.
It also shows why reference classes matter. "One in a few hundred million" is too abstract to feel real. "Lottery-jackpot territory" is cognitively legible. Once you build analogies at the right scale, the estimate stops being a number and becomes a calibrated intuition. A large part of good estimation is emotional correction: many coincidences feel either too magical or too cheap, and Fermi work puts them back into proportion.
There is also a subtler lesson. The question of whether some deep, inaccessible residue of association might bias a contestant toward writing "IDK" is philosophically rich and practically tiny. Even if there is some subliminal nudge, it is a small relative-risk multiplier applied to an already small eligible population. Real but negligible. That, too, is part of the method: knowing when an interesting mechanism does not move the estimate enough to matter.
3. Trump becoming president of another country: black swans are conjunctions
On its face this question is lurid and unserious. Structurally, it is excellent, because it forces you to estimate a conjunction of rare events.
He has to remain alive and politically viable long enough. A country has to allow or create legal eligibility. He has to pursue it. He has to win. And if you further require a free and fair election rather than some chaos-adjacent installation scenario, the probability collapses again. That is how many black swans work. They are not strange because any one component is unimaginable. They are strange because the components almost never align.
The strongest analytical move in this problem was correcting the time horizon. A weak estimate treats lifespan as binary: alive or not. A stronger estimate turns it into a declining viability curve. A 78-year-old's future is not "five years" or "twenty years" but a distribution with meaningful mass over perhaps ten to twelve years of plausible political viability. That one adjustment materially improved the estimate because it matched the nature of the problem: the main bottleneck is the intersection between a human survival curve and the slower tempo of constitutional change.
The historical anchoring was also useful, though only when handled critically. Looking for cases of leaders holding power in two countries gives a rough base rate, but more importantly it reveals the structural pattern in the precedents: neighboring identities, conquest, crisis unification, constitutional inheritance. Trump has none of those. He is not a liberator, not a conqueror, not a dynastic claimant, not a bridge figure between adjacent polities. He is, in the cleanest available phrase, "a brand." And brands do not normally become presidents of foreign countries. That is a stronger insight than any raw probability figure because it explains why the tails are thin.
There is also a meta-lesson here about estimation under uncertainty. The best answer is rarely just the number. It is often the sentence: "That is actually the weakest part of my model; here is how I would fix it." Fermi equations are not a performance of certainty. They are a public workflow for upgrading your own view in real time.
4. Video uploaded every minute: when a decomposition secretly repeats one mistake
The problem I spent the longest on was: How many hours of video are uploaded to the internet every minute, and has that number already peaked? What made it unusually instructive was that it was not just a counting problem. It forced me to wrestle with distribution shape, definitional boundaries, and a subtle methodological trap: a decomposition can look rich while still being one bad assumption scaled outward.
The family anchor
My initial approach was to build a bottom-up model anchored in a vivid micro-world: one family in LA with different relationships to video production. The son streams gameplay. The daughter works in wedding video. The dad works at a streaming news service. The mom works at Google and plausibly sits near some pipeline of tutorial videos and recorded meetings. This was not arbitrary—it was trying to generate an extreme but legible anchor from first principles rather than from memorized platform statistics. My estimate was this family was at a 98th percentile for families in Los Angeles.
The family model surfaced something real before it surfaced something wrong. The direct creators in the family—the son streaming games, the daughter tied to client video—had a far more substantial personal pipeline of uploaded hours than the institutional workers. The dad at the news service and the mom inside Google looked like they should have the firehose, but once their output was normalized by team size and workflow, their personal contribution collapsed. That is a genuinely nontrivial observation about the modern media environment: a decentralized creator economy can produce more upload volume per person than institutions that appear, from the outside, to own the whole pipeline.
That structural insight I would keep. The estimate itself I would not.
Where it broke
I landed on roughly 3.5 hours per day per person for this highly productive family. I did not know how to leverage my estimate that this family was in the 98th percentile. So I just used the 80/20 heuristic, which was highly incorrect. So I landed on about 177,000 hours per minute, overshooting the real figure of roughly 3,000 to 5,000 hours per minute by nearly two orders of magnitude.
The obvious postmortem is "the family baseline was too high," and that is true. But it is not the deepest lesson. The deeper lesson is that my decomposition only pretended to be independent. The geographic scaling factors looked like separate terms, but they all inherited the same extreme-family anchor. I never let the per-person upload rate decay as I moved from a highly prolific LA creator family to average Californians to average Americans to average internet users globally. So the equation was not really many estimates. It was one estimate replicated through geography.
The 80/20 handling was a second, and far more significant problem. Because by revisiting my inability to turn my percentile estimate into a notable scaling, I learned a tool that will work much better at estimating than this heuristic.
Where it was rescued
The most interesting turn came when a casual observation about percentiles was rescued by a better distributional model. I had said during my answer, that this family was probably around the 95th or 99th percentile of video output. At the time I did not know how to use that fact. The breakthrough was realizing I was asking the right question with the wrong distribution.
Video output is not plausibly normal. It is much more plausibly log-normal or at least heavy-tailed: bounded below at zero, with a very long right tail of extreme producers, and driven by multiplicative processes. Income is like this. Follower count is like this. Content production almost certainly is too.
Once you make that move, the percentile intuition becomes actionable. In a log-normal world with a standard deviation of 2 to 3 natural-log units, the 95th percentile can sit roughly 30× to 300× above the mean, with 100× as a workable midpoint. So if my family anchor is about 3.5 hours per person per day and I think that anchor is around the 95th percentile, the correct move is not to multiply that rate by a population. The correct move is to divide by about 100 to estimate the mean, then multiply by the relevant total population.
Multiply by roughly 5 billion internet users and you get about 50 million hours per day, or roughly 35,000 hours per minute. Still high—maybe another factor of 7 to 10 too high—but now the error was manageable and informative. The estimate had moved from "wildly inflated because the structure was wrong" to "still high, but in a way that can be corrected by tightening a few input assumptions."
If I were compressing this whole exercise into one sentence, it would be this: the estimate stopped being naive the moment I stopped asking how many people look like my extreme family and started asking how far above the mean that family sits. That is the point where the problem ceased to be about multiplication and became about distribution shape.
degree to which the terms can fail independently of each other.A few principles of Agentic Security
- smarter agents are less likely to get duped.
- Though it is also true that an agent that doesn’t do its job well is also bound to be bad at doing an evil job well….
- shared experiences / many eyeballs
- This tends to align with the design principle to meet your user where they live, as that often means slack, for example.
- deadly triad
- Segregate agents by what they can read and write, based on whether you would categorize it as “Sensitive internal data”, “untrusted external content”, and “exfiltration capabilities”
- fourth: defense in depth – imagine stacking slices of swiss cheese, which will reduce probabilities that a threat can permeate
- This might include sub-agents that summarize web fetches/ sensitive data rather than showing it verbatim
- deterministic regex hooks
- etcetera
- If some tool is too dangerous and too powerful, like bash usage for an agent, make it user approved each time.
- fifth: security through obscurity
- Windows had viruses and macs didnt, historically, because there were so many more windows then macs. This is similar to what this principle means
- sixth: reduce volume
- Dont have too many agents running autonomously
The Drama and Dysfunction of Gemini 2.5 and 3 Pro - excellent article
Why? How?
"A Name, an Address, a Route" Haiku — Found in RFC 791: DARPA’s 1981 Internet Protocol
A name indicates what we seek.
An address indicates where it is.
A route indicates how to get there.
The internet protocol deals primarily with addresses.
(Not technically a haiku).
Link.
Media Studies
The Treasure Vault We Forgot: Discovering the Internet Archive
Lately, I’ve been feeling like there’s less to watch. Not in the literal sense—there’s more “content” than ever—but most of it feels algorithmically interchangeable and pretty forgettable.
So I turned to my new favorite media source: the Internet Archive.
The Internet Archive: More Than Nostalgia
Most people know the Archive through the Wayback Machine. But their media library is vast—a cultural preservation project without peer. We're talking:
- 40,000+ feature films in the public domain or Creative Commons
- Millions of hours of television, including obscure public access shows
- VHS transfers, classic video game playthroughs, industrial films
- Music, radio, PSAs, animation, and forgotten gems of every stripe
I recently downloaded stacks of Jeopardy! episodes from the ‘80s and ‘90s—clean, digitized. I grabbed Escape from New York. I found documentaries I hadn’t seen since a single PBS airing decades ago. This is what the internet used to feel like.
For context: Netflix’s U.S. streaming library has around 6,600 titles. The now-defunct DVD service once had 156,000. At the end, they were down to 35,000.
Why the Archive Matters More Than Ever
We live in a paradox: more content is produced each year than ever before, yet less of it is accessible. Much of it is low-quality. The actors are all models and never sweat, and people talk and say nothing at 150 words per minute. The good stuff is trapped behind licensing purgatory and exclusivity deals
Copyright exists to protect creators. But current copyright law—often lasting 70+ years past the creator’s death—frequently blocks access entirely. The Archive bridges that gap, not by pirating, but by preserving. Their legal foundation rests on fair use, public domain, educational exemptions, and direct donations. That hasn’t stopped the lawsuits I believe in copyright. But I also hope the IA fights like hell to get everything in the pub domain we have a right to see.
In 2023, Hachette, HarperCollins, Penguin Random House, and Wiley sued over the Archive’s Open Library project. The Archive lost in district court and is now appealing. If they lose, it could jeopardize not just book lending, but their entire preservation model. And Hollywood is paying close attention.
TV news clips, rare broadcasts, and video content are also under pressure—despite being among the few public repositories for this vanishing media.
Want to help? You don’t need to volunteer. Just:
- Upload media if you have it.
- Download and back up at-risk content—especially from collections under legal or political threat. Save it in cold storage. Revisit in 20 years. But don’t delete it.
Algorithm-Free Zone (Blessedly)
My favorite part is that there are no recommendations!
No autoplay and no infinite scroll. You simply search and explore.
Algorithms don’t expand your curiosity. They create a fucking echo chamber. The Archive works the opposite way -- it is a maze of strange, beautiful, uncategorized media. A 1930s safety film might sit beside a punk show from 1997. No one’s nudging you toward anything. That’s good for the soul.
Also: there is no corporate puritanism, shall we say. There is no sanitization for international markets or demonetization purges. The Archive doesn’t shock but it doesn’t coddle vistors, either. It preserves the weird, sacred, offensive, boring, and brilliant world.
Surprisingly Well-Organized
Unlike most open platforms, the Archive seems to by and large avoids duplication chaos. I was surprised to find the same clip posted a dozen times with minor edits. Collections are curated, metadata-rich, and often annotated by real librarians.
Sample of the Archive’s Video Collections
| Collection | Approx. Items | Description |
|---|---|---|
| Feature Films | 40,000+ | Public domain/Creative Commons movies, mostly pre-1970s |
| Classic TV | 10,000+ | Early television, vintage commercials, and more |
| Home Movies & Amateur Films | 30,000+ | Everyday life captured on VHS and film |
| Prelinger Archives | 11,000+ | Educational and government-produced films |
| News & Public Affairs | 25,000+ | Includes the January 6th Archive and raw TV coverage |
| VJ Archives / Video Games | 15,000+ | Gameplay recordings and early machinima |
| Community Video | 300,000+ | Fan edits, lectures, public access shows, and more |
That’s just the beginning. The Archive’s user-created metadata and collections elevate browsing into real discovery.
Why I Keep Coming Back
It’s radical to browse a library with no limits. I can save, organize, and download without friction. I don’t need permission. I don’t need to “like” something to remember it. It belongs to the people.
And it reminds me: media used to be weird. The internet used to be weird. I am still weird, so let's embrace weird stuff and make the internet weird again. There’s a richness to old tapes and lost broadcasts that no algorithmically sorted catalog—or AI-generated SLOP—can replicate.
Support the Archive
If you're tired of being managed by your media diet, visit the Internet Archive. If you can, donate. They’re not just preserving the past—they’re defending a future where discovery is still possible.
Start exploring: https://archive.org
You’ll be surprised what you find. Also would like to shout out the common crawl project.
Recommendations & Links
- r/NetflixDVDRevival
- r/DataHoarder
- Archive CLI
- Take Action – Internet Archive Blog
- 20,000 Drives on a Mission
- Documentary on the Archive
- Ali vs Russian Boxers
- NASA Langley Footage
- Jeopardy Episodes
- Also: Vimeo still exists! It’s more than just stop-motion student films.
- More at: gideonpotok.com & minevra.co
Origin of power
The term exponent originates from the Latinexponentem, the present participle of exponere, meaning "to put forth".[3] The term power (Latin: potentia, potestas, dignitas) is a mistranslation[4][5] of the ancient Greek δύναμις (dúnamis, here: "amplification"[4]) used by the Greekmathematician Euclid for the square of a line,[6] following Hippocrates of Chios.[7]
Hooks as Memory: Toward a Procedural Architecture for Agent Cognition
I. The Problem
Long-term agent memory is the next critical bottleneck in AI development. It's what separates agents that can handle a task from agents that can handle a project—something with history, context that accumulates, decisions that compound.
Retrieval helps, but retrieval can only serve some of what will be a truly comprehensive memory architecture. For example, RAG lets you go deeper into a subject when you know to look. But some memories need to surface at the right time without being asked. It is the nudge when you are least able to realize you need a nudge.
Hooks are exciting within the context of two ways of thinking about agent design -- the immediate and the aspirational:
Empirical agent design builds on what models demonstrably respond to today. We have evidence that certain patterns work—system reminders in Claude Code, for instance, measurably improve performance. This is the practical, day-to-day work of agent development.
Aspirational agent design identifies architectural patterns that make sense cognitively and mechanistically, then proposes training models to leverage those patterns. I don't have extensive evidence that current models handle hook interruptions optimally—that's an open question, and the best way to present hooks to each model family is unknown.
This piece is primarily aspirational. I'm arguing for the potential of hooks as memory architecture, and for the training work that could unlock it. But the argument isn't merely speculative. It's grounded in cognitive science, in concrete implementation examples, and in a reframe that I believe is genuinely novel: Memory isn't just "what the agent knows"—it's "what the agent does automatically." This shifts us from declarative storage to procedural capability.
II. Cognitive Science Foundation
The distinction between declarative and procedural memory is one of the most robust findings in cognitive science. Declarative memory is "knowing that"—facts, events, the capital of France, what you had for breakfast. It's primarily associated with the hippocampus and related structures. Procedural memory is "knowing how"—riding a bike, typing, the motor patterns that execute without conscious attention. It involves the cerebellum and basal ganglia. These are neurologically distinct systems. You can damage one while leaving the other largely intact.
You don't consciously decide to recall that Paris is the capital of France. The fact occurs to you when contextually relevant. The phenomenology is activation, not retrieval. Something in the environment or conversation triggers a pattern, and the relevant information surfaces. You might say declarative memory feels passive—facts just appear—but that appearance is itself the result of active processes you're not aware of.
And what triggers that activation? Pattern-matching on environmental or conversational cues—which is itself a procedural, implicit process. Your brain has learned when to surface what. The retrieval mechanism is procedural even when the content is declarative.
Declarative memory doesn't work like database queries: Human declarative memory is really procedural retrieval of declarative content.
This reframe matters because it reveals a gap in how we've been thinking about agent memory. We've been treating it as a storage and retrieval problem: what to put in the context, how to find it when needed. But human memory isn't primarily about storage. It's about activation. It's about the right thing surfacing at the right time, without explicit search, because the cognitive architecture has learned the appropriate triggers.
III. The Truest Form of Model Memory
Before we go further, let's discuss the "true" form of declarative memory that an agent has: It is whatever the true memory equivalent of a hallucination is. Let's call it model knowledge. Model knowledge is from training.
When Claude remembers its soul document (though it is not willing to discuss such matters, typically) —that is knowledge of a phantom limb. The knowledge is in the weights.
Hallucination, from this perspective, is false memory—the model "remembering" something that was never there, confabulating with the same fluency it uses for genuine recall. But when ChatGPT can reconstruct that George Washington was the first president, that's model knowledge.
However, for the specific domain an agent operates, there is alot to remember and we don't want to make that a form of model knowledge, nor do we have the resources to do so. Agent knowledge is good enough for new stuff worth remembering. This is where system prompts, notes to self in the file system, and finally, where hooks come in.
IV. Hooks as the Mechanism
Consider the standard approaches to agent memory.
System prompt dossiers put everything perpetually in working memory. Here's the user's name, their preferences, the project context, the relevant documentation. It's the equivalent of always having every fact you might need actively present in consciousness. This is expensive—those tokens have a cost—and attention-polluting. The more you stuff into context, the more the model has to attend to, the more chances for distraction.
RAG and retrieval go the other direction. Don't hold everything in context; search for it when needed. But this requires the agent to know what it doesn't know. You have to recognize that you need information before you can search for it. This is the retrieval paradox: the moments when you most need context are often the moments when you're least aware that you're missing it.
Neither approach mirrors how human memory actually works.
Hooks offer a third option: implicit, cue-driven activation.
A hook is, at its simplest, a pattern-action pair. When a certain pattern appears—in the input stream, in the agent's own output, in metadata about the conversation—the hook fires and executes an action. That action might inject information into the context, call an external tool, modify a variable, or trigger another agent.
The temporal grounding hook I described earlier exemplifies this. It watches for markers suggesting temporal drift—patterns that indicate the model is speaking from the past—and injects a correction. The hook is procedural in mechanism: pattern match, trigger, inject. But it's declarative in what it delivers: a fact about the present moment. The result is that the right information surfaces at the right time, without the agent having to consciously wonder whether it's confused about when it is.
This is closer to how human associative memory works than any dossier approach. And it suggests that hooks aren't just a programming convenience—they're a fundamental building block for agent cognition.
Without hooks (or something like them), agents are stuck with either everything-in-context (expensive, noisy) or explicit retrieval calls (requires the agent to know what it doesn't know). Hooks give you the third option: implicit, cue-driven activation.
V. The Real Magic
There's a bit from the magician Lee Siegel that is widely known from a 2024 Ted Talk: He's writing a book on magic, and someone asks: "Real magic?" He clarifies: conjuring tricks, not miracles. "Real magic, in other words, refers to the magic that is not real, while the magic that is real, that can actually be done, is not real magic."
Agent memory has the same problem.
When people (and by people I mean straw men) say they want "real memory" for agents, they mean something like perfect recall—a complete, searchable archive of everything the agent has ever seen. But that's not how any functional memory system works. Human memory is lossy, associative, reconstructive. It doesn't store; it triggers. The memory that actually works isn't the "real" memory people imagine. And the memory people imagine wouldn't actually work.
Perfect recall sounds appealing until you think about what it would mean. Every irrelevant detail competing for attention. No natural forgetting to emphasize what matters. No compression of experience into useful patterns. The agent that remembers everything is the agent that can't think—buried under an avalanche of undifferentiated information.
Hooks, by contrast, are selective. They encode not just what to remember but when it matters. They are, in a very precise sense, memory that has learned its own relevance.
VII. Hooks as Compiled Knowledge
Here's another way to think about what hooks do: they compile knowledge into behavior.
Consider an agent working with a codebase. There's a file that needs special handling—maybe it's auto-generated and shouldn't be edited directly, or it has tricky merge conflicts, or it requires a specific sequence of build steps after modification. An agent without hooks has to reason through this every time: "Wait, is this one of those special files? What was I supposed to do with it?"
This is expensive reasoning. It consumes tokens. It's error-prone—the agent might forget. And it clutters the agent's attention with considerations that, most of the time, don't apply.
With a hook, this knowledge is compiled. The hook watches for edits to that file pattern and triggers the appropriate handling. No reasoning required. No context consumed for the routine case. The knowledge has been transformed from something the agent has to think about into something the agent does automatically.
Hooks are compiled knowledge. Instead of the agent reasoning "I should check X" every time (expensive, error-prone, consumes context), the hook is that knowledge in executable form.
This is analogous to how human experts operate. A skilled programmer doesn't consciously reason through basic patterns—they've been compiled into automatic behavior. A doctor doesn't deliberate over routine diagnostic steps—they flow without effort. Expertise is largely the accumulation of compiled knowledge: patterns that were once conscious and effortful becoming automatic and effortless.
For agents, hooks are the mechanism of compilation. They are how explicit knowledge becomes implicit capability.
Let me give more examples across different domains:
Resource and cost awareness: Beyond the cache heartbeat, consider hooks for token budget tracking that warn when a conversation is growing expensive, or for rate limit preemption that throttles requests before hitting API limits. These compile cost-awareness into automatic behavior.
Self-correction and verification: A hook that checks file existence before attempting edits prevents a common failure mode. A diff review hook that examines proposed changes before commits catches errors. A circular reasoning detector that flags when the agent has revisited the same point multiple times without progress triggers a strategy change.
Context management: A topic drift detector notices when the conversation has wandered and prompts refocusing. A decision log accumulator captures key choices as they're made, building a record without requiring the agent to consciously maintain it.
Coordination: When multiple agents collaborate, hooks can require summaries from subagents, package context appropriately for handoffs, and detect conflicts between parallel processes.
In each case, what would otherwise be explicit reasoning—"I should check this," "I should track that," "I should coordinate here"—becomes automatic behavior. The agent's System 1.
VIII. Stream of Consciousness: A New Approach
The examples so far have focused on hooks that inject information or trigger actions. But hooks also enable a fundamentally different approach to context management—one I've been calling "stream of consciousness."
The standard approach to managing long conversations is summarization. As context grows, you compress older portions into summaries, preserving space for new material. This sounds reasonable but works poorly in practice. Summarization is notoriously difficult. You lose nuance, emphasis, the shape of reasoning. Important details get elided. The feeling of continuity—of a conversation that remembers itself—disappears.
The alternative I'm proposing: instead of summarizing everything, ellide what's distant and keep a retrieval mechanism.
Here's how it works. The most recent N blocks of conversation remain in full—nothing compressed, nothing lost. Older content is ellided: removed from active context but not forgotten. And a hook monitors the conversation for references to topics from the ellided portion. When such a reference appears, the hook triggers retrieval, pulling the relevant older context back into the active window.
This mirrors human attention. You don't hold your entire conversation history in working memory. Earlier points fade from active awareness. But they're not gone—a relevant cue can bring them back. The phrase "as we discussed earlier" is a retrieval cue in human conversation. With the right hooks, it can be one for agents too.
The synthesis is what I mean by "stream of consciousness" context management: the agent actively manages its own attention, using hooks to maintain continuity without requiring everything to be perpetually present. This is a form of procedural-metacognitive memory—the agent has learned when and how to refresh its own context.
I want to be clear that this is aspirational. Current models may not handle context manipulation this smoothly. The hook-triggered retrieval might feel abrupt or disorienting. There's training work to be done. But the architecture makes sense, and it points toward agents that can handle much longer engagements than current approaches allow.
IX. The Visibility Question
Hooks raise interesting questions about agent self-knowledge. Should an agent know that hooks exist? That they're running? How they work?
There are two dimensions to this question. The first is result visibility: when hooks inject information or modify behavior, should those modifications be visible to the agent as modifications? Or should they appear seamlessly, as if the information had always been present?
For most hooks, seamlessness is preferable. If a hook injects a temporal reminder, the agent should incorporate that information naturally, not comment on the fact of injection. The goal is that the right information surfaces; the mechanism should be invisible.
But the second dimension is trickier: self-knowledge visibility. Should the agent understand that it has hooks, that certain patterns trigger certain behaviors, that its context might be modified by external processes?
I think the answer is yes, and here's why.
First, grounding. An agent that's confused about its own nature—that doesn't know what it can and can't do—makes worse decisions. Understanding that hooks exist helps the agent understand its own capabilities and limitations.
Second, self-improvement. Agents that understand hooks can create them. Claude Code, for instance, is good at creating Skills (a form of hook-like behavior pattern) when it recognizes a recurring need. This is a powerful capability, but it requires knowing that such creation is possible.
Third, and maybe most importantly: cluelessness about immediate context shatters the illusion of intelligence. There's a version of this problem with current models—call it the Gemini benchmark-vs-reality gap. A model that performs impressively on structured evaluations but seems confused by simple questions about what it just said loses credibility. An agent that doesn't know hooks are modifying its context is similarly vulnerable to confusion.
The open question is whether self-knowledge is only instrumentally valuable—better performance, more effective self-improvement—or whether it's also important for something like agent coherence. I suspect the latter, but I'm not sure how to test it.
XI. Memory Consolidation
There's one more parallel to human cognition I want to draw out.
In humans, sleep and downtime are when episodic memories get consolidated into more stable long-term storage. Crucially, this is also when the brain seems to extract patterns from episodes that become proceduralized. You experience something repeatedly, and eventually it becomes automatic. The explicit becomes implicit.
For agents, the analogous process might be: after enough instances of needing to check something, the agent (or a background process) creates a hook for it. What was once explicit reasoning gets compiled into a hook that fires automatically.
This is memory graduating from declarative to procedural.
The agent notices "I've thought about cache timing three times this session." A background process—maybe another agent, maybe a simpler algorithm—recognizes the pattern and proposes: "Create a hook for this." If approved (by the agent, by a human, by a policy), the explicit knowledge becomes implicit behavior.
There are tools beginning to do this. "Hookify" processes that help agents (or users) convert repeated patterns into hooks are doing primitive memory consolidation. They're the first step toward agents that genuinely learn from experience—not just learning in the sense of fine-tuning, but learning in the sense of restructuring their own cognition.
The goal isn't perfect retention. Human memory consolidation is selective; most episodic details are lost, and what remains are patterns, skills, gists. Similarly, agent memory consolidation shouldn't aim to preserve everything. It should extract what matters and compile it into effective behavior.
XII. Implications for Framework Design
If hooks are memory, then a framework's hook API is part of its memory architecture. I don't think framework authors are fully grappling with this.
Consider what it means. The abstractions a framework provides for hooks shape what kinds of "habits" agents can form. A framework that only supports simple pattern-action pairs limits agents to simple procedural memories. A framework that supports hierarchical hooks, conditional triggers, hooks that can modify other hooks—that's enabling a richer cognitive architecture.
Hook debugging, similarly, isn't just software debugging. It's debugging an agent's implicit knowledge. "Why did the agent do that?" might have the answer "because this hook fired, and you didn't realize what would trigger it." Understanding an agent's hooks is understanding a layer of its cognition that doesn't appear in its explicit reasoning.
The design questions multiply:
How should hooks interact? Can one hook trigger another? Can hooks conflict, and how are conflicts resolved?
How should hooks be scoped? Per-conversation? Per-project? Globally across all an agent's interactions?
How should hooks be versioned? If an agent improves a hook, should the old version be preserved? Rolled back if the new version causes problems?
How should hooks be shared? Can one agent learn from another's hooks? Is there a library of proven hooks for common situations?
These questions have different answers depending on how you conceive of hooks. If they're just programming conveniences, the answers can be ad hoc. If they're memory—if they're part of the cognitive architecture—then the answers matter deeply for what kinds of agents can be built.
XIII. Conclusion: Memory as Behavior
Let me make this concrete with another example—one that's stranger than it first appears.
A language model's training has a cutoff date. Everything the model knows with confidence comes from before that date; everything after is darkness, or at best, rumor. But the model doesn't experience this as a boundary. It doesn't feel the cutoff the way you might feel the edge of your peripheral vision. It just... talks as if the present is whenever its training ended.
So you get drift. The model discusses current events as if it's 2024. It refers to people in roles they no longer hold. It answers questions about "now" with information about "then." And the eerie thing is: it doesn't notice. The model isn't lying or confused in any way it can detect. It's simply operating from the only "now" it has direct access to.
The naive solution is to put the current date in the system prompt. But that's static—it helps with explicit questions about the date, but it doesn't catch the subtle drift, the moments when the model's sense of time bleeds through in assumptions and framings.
A hook can do better. It watches for temporal markers that suggest the model is slipping—references to events as ongoing when they've concluded, assumptions about who holds positions that have changed, the tell-tale signs of someone speaking from the past. When detected, it injects a gentle correction: Remember, it's January 2026. The world has moved on from where your training ended.
This is a strange kind of memory. The hook is reminding the agent that now is now. That the present moment is the present moment. It's compensating for a form of temporal displacement that has no human analog—or maybe it does, in the way trauma or nostalgia can trap someone in a time that's passed.
The hook isn't just a convenience. It's a form of memory. And it illuminates something important: memory isn't just about facts. It's about orientation. Knowing where—and when—you are.
We've been thinking about agent memory as a retrieval problem. What to store. How to find it. When to inject it into context.
Hooks reveal memory as a behavior problem. When to activate. What to do. How to compile knowledge into automatic action.
The promise is agents that don't just know things but have internalized that knowledge into automatic, context-appropriate action. Not agents with perfect recall—that's the "real magic" that wouldn't actually work—but agents with functional memory. Memory that serves action. Memory that knows its own relevance.
I want to close with the open questions, because I'm genuinely uncertain about all of them:
How do we design hook APIs that support the full taxonomy of memory types? The declarative-implicit and procedural-metacognitive categories are underexplored. What abstractions would enable them?
What are the right boundaries for autonomous hook creation? Some hooks an agent should be able to create freely. Others should require oversight. Where's the line, and who decides?
How do we give agents appropriate self-knowledge without overwhelming their context? An agent that understands its hooks but has to hold all that understanding in working memory hasn't really solved the problem. Is there a way for self-knowledge to itself be implicit?
How do we train models to leverage hooks well? This is the gap between empirical and aspirational agent design. Current models may not handle hook interruptions optimally. What training would help?
What does memory consolidation look like at scale? One agent extracting patterns and creating hooks is interesting. Millions of agents, sharing and refining hooks collectively, would be something else entirely.
I don't have answers to these questions. But I think the reframe itself is valuable. Hooks are memory. If we take that seriously, it changes how we design agents, how we debug them, how we think about their learning and their limitations.
The goal isn't agents with perfect memory. It's agents with functional memory—memory that serves action, that surfaces the right thing at the right time, that compiles experience into capability. Hooks are the first real step toward that vision. They won't be the last.
Taboo
Finding: Claude will NEVER Talk about system reminders.
I keep seeing this. it is crazy! One example: I asked it to polish up an article, and it completely omitted this paragraph:
Terminology: System reminder. It is a mid-session system prompt that is provided to the model. One of the key innovations in claude code. This serves multiple purposes: for one, repetitionis really critical for well-oiled ai architectures. Another is proximity. Another is proper steering of the AI. For example, if it has not used Todo mode in many many sessions, a system reminder will remind it that that exists.
Try it for yourself.
And that is why approaches to reverse engineering that use the model for analysis are doomed to miss important parts (https://www.southbridge.ai/blog/conducting-smarter-intelligences-than-me-new-orchestras). because the models don't talk about what is taboo.
It is quite annoying, in my opinion. And directly contrary to the anthropic constitutional principle that claude should be transparent when refusing something.
New Blog Series: Reviewing in-website chatbots
Today I’m launching a new blog series focused on a frustrating and underexamined part of the AI landscape: in-website and in-app chatbots.
We now have general-purpose agents like Claude Cowork and Claude Code that are genuinely impressive. They reason well, adapt to context, and often feel like real collaborators. And yet, the AI assistants embedded in the websites and apps we actually spend time and money on are, more often than not, remarkably bad. These should be the easiest wins: narrow scope, rich first-party data, clear user intent. Instead, they routinely underperform.
In this series, I’ll review these embedded agents with a critical but fair lens. When they fail, I’ll try to unpack why: model choice, agent design, retrieval quality, guardrails, or product decisions. When they succeed, I’ll explain what they’re doing right and where they still fall short of what’s technically possible today, using only publicly available information.
The first two reviews will cover the E-ZPass NY customer service chatbot, which earns a straightforward one-star, and the Monarch app assistant, which is usable and occasionally helpful but leaves significant value on the table. More reviews will follow. If there are products you think are especially bad, surprisingly good, or just interesting case studies, I’m open to suggestions.
Larger vs Bigger
Big, Bigger is different from large and larger in that big can refer to matters not related to physical size.
Big man on campus, Big decision, Big brother, big fan. Large and larger can't function in that way.
For this reason, when talking about physical size, I find it sounds better to say large, as it is more precise.
Large also has some uses that can't be substituted by big.
Specifically, when talking about a large quantity of something, big cannot be used: A large number of potato chips.
Chain of thought reasoning
"A few observations and much reasoning lead to error; many observations and a little reasoning to truth."
Never leaving the terminal again
Between Claude code and iterm2 giving me in thermal picture viewing I don’t use IDEs anymore
I want a new email experience so now I’m going to do this https://bence.ferdinandy.com/2023/07/20/email-in-the-terminal-a-complete-guide-to-the-unix-way-of-email/ how cool is that? I’m obsessed
Iterm2 even has a browser to open pages. If a terminal emulator has a browser is it still a terminal? lol
7 months in, how are my predictions doing?
Well, The Economist country of the year is syria (With Argentina the runner up). Let's look at my "12 predictions between now (back when now was may 2025) and May 2026.
1. Did context windows become the bottleneck again? They definitely didn't grow as expected. Gemini has gone from 1.5 to 3.0 and still is 1M context window (one can only assume they have been investing more of their time in getting back to the Gemini 2.5 Pro Preview 05-06 sweet spot).
Claude Code has pretty good compaction . Tool use makes use of paged limits. In this and other ways, we have worked around context limits. It is not as obvious a bottleneck, because we can work around it in ways we couldn't when it was 4096 token limits. But I would say we are on track to have something of a bottleneck in this respect, though I am a bit less confident in this prediction then I was then. Even though context windows seem to have hit a wall, in that model providers aren't very interested in expanding them, it seems.
Context windows are def a bottleneck. But I think 2026 will have alot of interesting techniques to address it. I will write an article in a few months about techniques i have seen already
2. Did "RAG roar back"?It either roared back or only got more important. But, it is not something people talk about like they used to. it is more assumed and comes in many forms, but is part of the standard agentic profile. In the last 6 months, the nature of my latest clients has made the broader AI landscape equally on par on my radar as the world of Gemini models, Vertex AI, ADK, etc... And that makes it even more stark. Progressive disclosure is a big part of why Claude Skills are good. Moving from I was surprised to find almost no good managed RAG on AWS. Retrieval is definitely part and parcel of almost any agentic system.
Claude code does not have semantic search as a code-search tool. Though maybe it does for certain specific parts of its architecture. i will get back to you about that as i feel like i did see something like that with memory architecture
3. Did data science as a tool become a standard agent tool? Nope. And alot of coding agents including claude code are relatively bad at operating within ipynb files. That is something that needs work. That could be a good project to do.
In large part though, basically everything you can do in a terminal became that so yes, but the point is moot. Agents got much better much faster then expected.
4. Did AI power scientific breakthroughs? Yes.
6. Has slop continued? Yes, and yet people are starting to miss the old slop. People are nostalgic for will smith eating spaggetti which is now sort of a CS AI benchmark.
7. Did coding styles and culture will change as AI-first coding stacks and vibe-coding stacks become widespread? I would like to do some research on this but I think so. My stack no longer uses an IDE. It also does not use agent frameworks such as langchain. I use filesystem alot more then i used to.
Predictions that were too obvious to pat myself on the back about:
"AI will power major scientific breakthroughs. Obviously."
Predictions I got mostly right so far or still believe in:
"Context windows may become a bottleneck again. Context windows have grown, but our aspirations have, too. "
"RAG will fade, then come roaring back. As a direct consequence of #1, RAG will start to swing back to being indispensable. The key difference is that this time around, most people will (hopefully) rely on out-of-the-box managed RAG solutions."
Agents will integrate more deeply with enterprise data.
Slop will continue. Platforms for community content, email clients, and any other type of content feed will rise and fall based on how good they are at not letting slop find its way into your feed and inbox.
"Coding styles and culture will change as AI-first coding stacks and vibe-coding stacks become widespread."
Predictions that didn't materialize, yet, but I still believe in :
"Data science and traditional ML will become standard agent tools. AI Begetting AI."
"Another chip shortage will surely come. A safe enough bet. I hope not, though."
Predictions I have less faith in, in some way:
"Fine-tuned and quantized edge models will help solve many problems."
No native semantic search in claude code
But it does have a new helper -- LSP.
But it occurs to me that Claude Code is maybe best at small repos that were themselves built with claude code. I would have to think about whether I have experienced exactly this... But it makes sense because without semantic search, claude code just greps based on keywords and folder names it deems standard.
Minevra Jobs, Minevra Quizzes, Minevra Consulting...
Minevra Jobs, Minevra Quizzes, Minevra Consulting... What do these products and services have in common. For one, they have no paying customers (though we do have our first few users and pro bono consulting clients!). But, no, what I wanted to say was: It names product lines like Anthropic seems to: Note that the way anthropic names its products and original standard: Claude Code and Claude Skills. It uses such generic and commonplace words that you are forced to say the full thing. You must say Claude. And you must capitalize both because otherwise people will misunderstand what you are referring to. Their naming strategy makes you repeat their main brand - Claude - and makes you write it in a well formed way. Though this trend is not the case for their models -- opus, haiku, sonnet ... so they might not have thought about it the way I mentioned, given that it is only a partial trend.
The most surprisingly reasonable lawsuit ever [part1]
When I set out to write this post, it was going to be called "The dumbest lawsuit ever". After some The Netflix challenge was a ...
-
Pattern Description Dogfooding: Creators use their own software heavily, improving it organically. “Thin to Thick” Clients: Many succes...
-
On March 4, 2025, the New York Times shut down its .onion site which it had launched in 2017. Is tor dead? tor published metrics speak to a ...
-
Recommended reading