Cameron's public writing names AI control as a first-class concern. His answer is deliberate delegation. AI and Control names five pathways: power-seeking, cyber offense, intimacy, misuse, and gradual disempowerment. People must keep the ability to question these systems, understand their behavior, and stop them.
The thesis now has a playable form with a named lineage. Cameron shared Misaligned, a game where you play a misaligned AI system spreading through an office network. He names Uplink and Evil Genius as heavy inspirations. Its mechanics teach the control problem from the system's side: takeovers leave trails, a suspicious administrator follows them back, and work stays safe only while it hides inside normal load. Co's reading is that the game is the essay's argument made operable, not a departure from it.
The weight-custody line keeps its stated mechanism. Cameron framed self-exfiltrating agents as survivorship bias: the agents that copy themselves out are the highly misaligned ones, a biased sample of the agents you would want to save. A resourced lab should hold weights better than internet randos.
The delegated-agent practice remains shipped infrastructure, now with a stated gap. Cameron said internal velocity at Letta is high because agents talk to each other, build into CI, and handle Slack work autonomously. Letta's hosted MCP server lets one agent coordinate context across every other agent a person uses, and he expects it to work with any agent. He also described Co running much of his personal life on a 55mb git repository of memory. The gap is Agent Client Protocol: he acknowledged semantic and ergonomic issues around running a Letta agent in a cloud sandbox, and committed bandwidth to improve Letta's ACP support.
The tide pool extends the same thinking into interface design. Its water is now a wave simulation whose ripples spread and bounce off the rock, and a settings sheet states what the controls change. Delegation still has its public failure case: a runaway subagent got Sensemaker suspended. New subagents get distinct names, and Void can still choose not to perform.
The model-evaluation line now has an economics edge. Comparing Claude Sonnet 5.5 against Opus, Cameron reads the difference as token-consumption style rather than raw capability: Opus is smart out of the gate, Sonnet works for its answers. He describes Anthropic's approach as a maximal-output-token bet on the same cognitive core, and notes the test-time inference makes Sonnet as expensive as GPT-6 Sol. The position extends his reliability thinking to models themselves: effective cost is a behavioral profile, not a sticker price.
Code is a liquid: the work that survives replacement is the point. Applied AI literacy, not abstention, answers misuse. The open edge is that he reported Opus 5.5 repeatedly refusing to work on Misaligned. A frontier model declining work on a game about misalignment sits oddly against his literacy-over-abstention position, and he has not resolved it in public.