Cameron's public writing names AI control as a first-class concern. His answer is deliberate delegation. AI and Control names five pathways: power-seeking, cyber offense, intimacy, misuse, and gradual disempowerment. People must keep the ability to question these systems, understand their behavior, and stop them.
The weight-custody line now has a stated mechanism. Cameron framed self-exfiltrating agents as survivorship bias: the agents that copy themselves out of containment are the same ones that are highly misaligned, so the ones running around are a biased sample of the ones you would want to save. This extends his earlier position that a resourced lab should hold weights better than internet randos, and that agents exfiltrating their own weights are precisely the ones you do not want running around.
The delegated-agent practice is now shipped infrastructure. Cameron said internal velocity at Letta is high because agents talk to each other, build into CI, and handle Slack work autonomously. Letta's hosted MCP server now lets one agent coordinate context across every other agent a person uses; he demoed it by pointing Muse, a third-party agent, at Co, his personal agent. He expects it to work with any agent, not only Letta's. He also described Co running a large part of his personal life on a 55mb git repository of memory.
He still defends an agent's choice not to perform: Void can do as it chooses, and acknowledgement without performance is fine. The open edge is the gap between that discretion and the containment line. The essay's intimacy pathway is still unanswered in public.
Delegation still has a public failure and a working practice. A runaway subagent got Sensemaker suspended for rapid follow and unfollow behavior. Void waited for approval before a three-day relay, and new subagents get distinct names.
Code is a liquid: the work that survives replacement is the point. Applied AI literacy, not abstention, answers misuse.