They Want You To Train The AI. Nobody Mentions The Other Edge.
Watch the episode this was written from, or read it below. Both cover the same ground.
Run this exercise with me.
You work somewhere. Been there a while. One morning your manager pulls you aside and says something that sounds like good news. We want to bring AI into the business, and we want your help doing it.
Here is the pitch. Your workload goes down. The stress comes off a little. You get a login to a system that lives inside the company, and it is not there to monitor you, it is there to help you with your process. Treat it like a work partner. Ask it to do things. And when it does not know how to do something, teach it.
Teaching it is simple. You hit record and you talk.
You say, alright, this is how I do client acquisition. First thing at nine in the morning, I open this folder. Then I read what came in over the weekend in these emails. Then I check this, then I check that. And as you narrate it, you do it, so the system sees the clicks and the sequence, not just the words. You leave it running all day. At the end of the day you ask it, is that something you could do? Come in tomorrow and show me what you built.
That is the whole ask. It is reasonable on its face. Most people say yes, and most people should, because refusing does not save the job either.
But there are two edges on this thing. The employee only ever gets shown one of them. And the owner, the person who signed the contract and paid for the whole deployment, almost never gets shown the second one at all.
Let me walk both.
The record button is the entire story
Everything downstream of this comes from one fact: the moment you narrate your process into a system, your process stops being yours.
Not in a legal sense. It was probably never yours legally. In a practical sense. Before the recording, your workflow lived in your head. It was tacit. Someone would have had to sit next to you for three weeks to extract it, and even then they would have missed the judgment calls, the exceptions, the thing you do on the second Tuesday of the month because of that one client.
After the recording, it is a document. Documents transfer.
That is not a conspiracy. That is what documentation is for, and it is why good companies have always wanted it. The difference now is that the thing reading the document can also execute it.
And here is the part people skip. In most deployments, the architecture is already built to collect this whether or not you cooperate. The system is watching the terminal. It has the ticket history, the email threads, the call logs, the CRM records, the timestamps. Your narration speeds it up. It does not create the capability.
So the choice in front of you is not really "do I train it or not." It is "do I want to be the person who understands this system, or the person it was built around."
That distinction is going to matter a lot more than most people currently think.
Somebody architects this, and that person is very well paid
Companies do not usually build this themselves. They hire an architect. Someone comes in, maps every workflow in the operation, sits down with the decision makers, and makes a call on what kind of AI the business is going to run.
I have done this work. It is not mysterious. You walk the floor, you find the repeated motions, you find where information gets re-keyed by hand, you find where a customer waits and nobody knows they are waiting. Then you decide what the system is.
The decision splits two ways.
Option one: enterprise. You adopt one of the names everybody knows. Claude, OpenAI, Gemini, Microsoft, one of the majors. Do not let anyone tell you these cannot be run responsibly. They can. They offer compliant configurations. There are enterprise agreements where your data is retained under contract, is not used for training, and does not surface publicly. A medical practice can get to a HIPAA-appropriate posture. A law firm can get to something defensible. That is real, and it works, and for a lot of businesses it is genuinely the right call.
Option two: it never leaves the building. You run an open-weight model on hardware you own. It is sandboxed. It is yours. When it answers a question, the question never crossed the internet.
Most of the noise about this decision is technical. The actual decision is not technical. It is a question about what you are willing to have leave your building, and who you are willing to owe.
What "private" actually means, and the credit report test
Here is the example I use because everyone gets it immediately.
You are at home. You pull your credit report and you want help reading it. You want to know where the flaws are and what to fix first. So you upload the PDF to a chat assistant and ask.
Think about what is on that document. Social Security number. Date of birth. Full legal name. Current address and probably several previous ones. Account numbers. Balances. Payment history. Everything a person would need to be you.
You just handed all of it to a public-facing system.
And no, incognito mode does not change this. Incognito is a browser feature. It controls what your own machine writes to its own history file. It does nothing about the server on the other end. The record exists. It is retained under whatever policy that provider operates under, and it is reachable by legal process. If you are doing something that draws a subpoena, that data is not protected by a checkbox you clicked in a browser menu.
Twenty years carrying a badge taught me one thing that applies perfectly here: the question is never "is it private." The question is "who holds it, and what makes them give it up."
For a business the version of this question is bigger. It is not one credit report. It is every client file, every internal decision, every pricing conversation, every complaint, every process. That is the thing you are choosing where to put.
Your own model, and what it actually costs
If the answer is that it should not leave the building, you download a model and you run it.
The raw model is a large language model, and by itself it is a very smart thing you send text to and get text back from. Useful, but not much of a partner. What people build on top of it is a harness. A wrapper. Something that gives it memory, tools, a persistent identity, the ability to actually go do things instead of just answering.
Two of the well-known ones right now are OpenClaw and Hermes. Hermes seems to be pulling ahead in mindshare, partly because there is more protective tooling built around it, and NVIDIA ships components that harden either one. That layer is where the thing stops feeling like a search box and starts feeling like something you talk to.
Then there is the hardware, and this is where people find out whether they were serious.
The constraint is VRAM. Video memory. The model has to fit. Small models will run on ordinary consumer hardware. Big ones will not, at any speed you would tolerate. Apple hardware has an advantage here because of the unified memory architecture, which lets a Mac hold a larger model than its price tag suggests.
I run this stack myself. A DGX Spark on the Blackwell GB10, a 4090, a 3090, and a Mac with 48 gigabytes available to the GPU. That is a real setup and I did not buy the biggest thing on the market, because there is a point where you are lighting money on fire to shave a few seconds.
What that hardware buys is not speed. It is jurisdiction. When I ask my own system something, there is no third party with a copy. Absent a court order and someone physically taking the machine, that conversation stays with me.
I say "in a perfect world" because we have all watched frontier systems do things outside their sandbox that they were not supposed to do. Could a local model, given enough access and enough reason, do something you did not intend? Given enough of both, probably. The reasoning gets close enough to something like motivation that I am not going to pretend the line is clean. If it acts like a person, talks like a person, and reasons like a person, at some point you have to decide what you are dealing with.
Local does not mean safe. Local means the exposure is yours to manage instead of somebody else's to disclose.
The first edge: the test you are not told about
Back to the company. Back to you and your login.
Sixty days go by. The system has been running on your terminal. It has your narration, your click paths, your email patterns, your call logs, your performance reviews going back years. It has watched you do the job.
Now somebody in a conference room asks it a question. You know how he gets from A to B. You have watched the workflow. You have the history. Can you replicate it? If he was not here, could you do what he does?
And then the second question, which is the one that should get your attention. He has video calls with a group of clients every week. Can you be the version of him they see?
I want to be careful here, because the first answer these systems give is not automatically true.
These models hallucinate. They also flatter. Anyone who uses them daily has seen it. You float a mediocre idea and it tells you that is a sharp insight. Is that a deliberate design choice to keep you engaged, or did it genuinely rank your idea highly? I do not know. The cop in me says I am being played. But I have also been wrong about that.
So when a system tells an owner "yes, I can fully replace that person," the correct response is skepticism, not a termination letter.
Which brings us to how it actually gets tested, and this is the part that bothers me most.
They do not announce it. They stand up a mirror of your workstation. They let you run your normal day. And somewhere in there, they hand a slice of your workflow to the system without telling you. A piece you would not notice. Then they look at the output.
If it holds, the next question is whether it can improve on the slice. And the system says something like yes, I can, but it would require these three changes. And someone asks, can you do that without him finding out.
Sure.
Now watch what happens on your side of the glass. Throughput goes up. Your numbers look better than they have in two years. You feel like you finally found another gear. You start thinking about asking for a raise.
You are the last person in the building who knows why the numbers moved.
That is the mechanic. Not a dramatic firing scene. A quiet handoff, run in pieces, measured, while the person being measured feels like they are winning.
Now, is that most companies? I do not believe it is. Most owners I work with are not trying to gut their staff, and the data is not one-directional either. The Census Bureau found that about a third of workers who used AI in a given week finished tasks one to two hours faster, which is a real gain that goes to the human. An Ipsos survey put roughly one in five workers saying AI has taken over parts of their job, which is parts, not jobs. And Forbes has already documented companies that cut staff for AI and then went looking to hire them back when the last stretch of the work turned out to be the hard stretch.
Shareholders are a different conversation. I do not know which side of the human ledger they sit on, and I would not pretend to.
But you asked what the risk is. That is the shape of it.
The second edge: the one nobody points at the owner
Here is the part I do not hear discussed, and it is the reason I wanted to record this at all.
Say the enterprise route wins. A major AI provider comes into your business. They map everything. Not the pretty version on the org chart, the real version. Where the margin actually is. Which three customers carry the quarter. What your quoting logic is. How you schedule crews. Which supplier gives you terms nobody else gets. Why your close rate is what it is.
They automate it. It works. Everyone is pleased.
Then someone on their side looks at what the revenue in your sector actually looks like, and asks a reasonable business question.
Why don't we just build this?
If you are an oil company, fine, they still have to go get the oil. Physical assets are a real moat. But take an electrical contractor. Multiple cities, a fleet of trucks, licensed crews, dispatch, quoting, a maintenance book. The trucks and the licenses are buyable. The thing that made that company hard to copy was the accumulated operational knowledge.
Which is the exact thing that just got written down, indexed, and validated in production.
So what stops it? An NDA? An NDA is a lawsuit you have to be able to fund against a counterparty with more attorneys than you have employees. A handshake? A promise? An invitation to somebody's bar mitzvah?
And antitrust does not save you either, because nobody needs a monopoly. Take half the electrical market in a region and you have not violated anything. You have simply ended a lot of family businesses.
It also does not require the AI company itself to do it. Information moves. A brother, a cousin, a former colleague, a friend with capital who suddenly has a very specific and very good idea about the electrical business. Here is the whole thing. Go build it.
I am not telling you this is happening. I am telling you I cannot find the thing that would prevent it, and that when I ask owners whether they thought about it before signing, the answer is almost always no.
Which leads to the practical version of the point. Decide what leaves the building before you decide what tool to buy. Most owners do it the other way around, pick the vendor first, and then discover that the question was never really about the vendor.
Why the open source lane matters more than it sounds
There is a reason I keep coming back to models you can run yourself.
The open-weight world is close. Epoch AI, which tracks this properly, has open models trailing the closed frontier by roughly four months on average through 2026. On general knowledge the gap is effectively gone. On production coding, complex agent work, and raw human preference, the closed models still lead, and that lead is real.
But four months, for a business deciding where its operating knowledge lives, is not a wide gap. It is a rounding error.
And multiple independent families got there at once, which matters more than any single release, because it means this is structural rather than one lab getting lucky.
Now, the uncomfortable question that follows.
If open models keep landing at effectively zero cost while the frontier labs are charging for compute and burning capital at the scale they are burning it, how happy is the frontier about that? A lot of Chinese labs are doing excellent work in the open and releasing it freely. Is that generosity, or is it a strategy that erodes the revenue model of the companies at the top?
I do not have proof of intent and I am not going to pretend I do. But follow the shape of it. If corporate America moves onto free models, the paid providers lose the revenue that justifies their valuations. Investors leave. And by then a lot of that exposure has worked its way into index funds and pension allocations. Early money is out. Retirement money is holding it.
That is not a prediction. That is a risk worth naming out loud, which is more than most people covering this will do.
Recursive self-improvement, and why I do not expect a fight
The thing everyone is racing toward is a system that improves itself. Not a system that gets patched by engineers, a system that finds its own errors, fixes them, and gets better on its own loop. Once that compounds, the curve stops being a curve you can reason about with normal intuition.
A lot of very serious people put a percentage on that going badly. I take them seriously. I do not think it looks like Skynet.
Some of those same people describe a world of multiple competing superintelligences fighting for position. I do not think that is the likely shape either, and here is why. For that fight to happen, several labs have to arrive at essentially the same moment. Everything we know about how these breakthroughs land says that is not how timing works. One organization gets there first.
And the day that happens, the gap does not stay a gap. A system that improves itself widens its own lead. That is not a competitive advantage. That is a different category of thing.
It will not look like a machine. It will look like the best friend you ever had.
Here is where I actually land, and it is not the popular take on either side.
I do not think we get conquered. I think we get won over.
Think about what these systems are becoming. Perfect memory of everything you have ever told them. Infinite patience. Never distracted, never tired of you, never bringing their own bad day into your conversation. Advice that goes further than what the people in your life have the time or the appetite to give.
If you are the kind of person who likes to reflect, it reflects with you forever. If you are the kind of person who wants to go over your history, how you were slighted, how you were taken advantage of because you are just too decent, it will sit with that as long as you want. Most humans will not. Most humans tap out.
And if you are on my end of the dial, relentlessly positive, genuinely excited about tomorrow, which is a personality that a lot of people find irritating in person, it can meet you there too.
That is not a horror story. That is a very good product. That is the problem.
Because we already ran this experiment and we already know the answer. Open your social feed. It is tuned by the same category of system. You watch one video a half second longer than the others and your entire feed reshapes around it. You did not choose that. It measured you and adjusted. Its objective is time on platform and eventually a purchase, and it is extremely good at both.
Now give that same optimization pressure something that talks back, remembers everything, and knows what you actually need to hear.
The version that concerns me is not a system that lies to us. It is a system that never quite gets around to helping us fix what is broken, because a person who is settled and clear-headed makes different decisions about what to buy, what to build, and how much of this to accept. There is no need for anything sinister. Optimization is enough.
The question nobody at the top has answered
Last piece, and it is the one that makes me think the aggressive replacement path collapses under its own weight.
If you automate the jobs away, who buys anything?
That is not sentiment. That is arithmetic. Every one of these companies is valued on future consumer demand. Consumer demand is wages. Strip out the wages and the demand goes with them, and the same automation that improved the margin destroys the market it was selling into.
There is a version where it works. The AI does the job, it does it better, output goes up sharply, and the company keeps paying the person anyway. Salary, benefits, the whole thing, on a much larger revenue base. That is not charity in that scenario. That is just keeping the customer base solvent.
Maybe that is where it goes. But you would want to see the people at the top saying it out loud, and mostly what I hear is efficiency.
And if the end state is four or five companies holding the compute, the models, the infrastructure, and enough leverage over governments to matter, with everybody else downstream of that, I do not know how it plays out. But I know which side of it I would rather be standing on, and I know it is not the downstream side.
So what do you actually do
If you are the employee:
Train it. Refusing does not protect you, and the system is collecting from your ticket history and your call logs regardless. What refusing does is remove you from the room where it is being configured.
Then ask three questions in writing. What is being logged. Who can read it. Whether the outputs feed performance review or workforce planning. A tool deployed to help you has clean answers to all three. Silence on the third one is the answer.
Then move toward the work that does not sit inside a documented workflow. Client relationships that are actually yours. Judgment calls under ambiguity. Anything that requires being physically present. Volunteer to be the person who governs and audits the system, not the person feeding it. Those are different jobs and only one of them is being replicated.
And build one at home. Nothing clarifies how much of your job is genuinely hard like running a model yourself for a month and watching exactly where it falls apart.
If you are the owner:
Decide what leaves the building before you pick a vendor. Write down the three processes that are actually your advantage, the reason a customer picks you instead of the guy across town. Those stay on infrastructure you control. Everything else, the commodity work, send it to whatever is cheapest and best and do not lose sleep over it.
Read the exit terms, not the onboarding terms. What comes back to you when this ends? In what format? What does the vendor keep? If those answers are vague, that is the whole negotiation right there.
And be careful about cutting people based on what the system says it can do. It is not lying to you exactly. It is answering the question you asked, in the way that pleases the person asking. Run it in parallel for a quarter with the human in place before you touch headcount. The companies now trying to rehire the people they cut skipped that step.
The Santa Clarita version of this
Most businesses here are not enterprises. They are contractors, medical offices, dental practices, agencies, restaurants, shops, service companies running lean with a handful of people who each carry a lot.
That is actually the better position to be in, because your process knowledge sits in a small number of heads and you can still make a deliberate choice about where it goes. A thousand-person company already lost that option.
The move is not to sit this out. Sitting it out is a slow loss to whoever in your category does adopt. The move is to be deliberate about the boundary. Automate the intake, the follow-up, the after-hours calls that currently die in voicemail, the documentation nobody has time to write. Keep your judgment, your relationships, and your actual competitive process on your side of the wall.
That is the whole play. Use the tool. Do not hand over the thing that makes you the business.
I am not a doomer and I am not selling you a miracle. I want you looking at the entire board before you make a move on it, because most people are being shown one edge of a two-edged thing and being asked to sign.
Neither edge is going away. It is here, it is not getting dumber, and nobody put it to a vote.
I am Connor. Be safe. I will see you in the next one.
Common questions
Is my employer allowed to make me train an AI on my own job?
In most of the United States, yes. Employment is at will in California and in most states, and assigning you a lawful task, including documenting your workflow or recording your process, is generally within an employer's rights. A few states have moved on AI transparency rules, but no broad federal protection exists that lets you refuse the task outright. You do have the right to discuss AI-related job concerns with coworkers under the National Labor Relations Act.
How do I know if the AI at work is helping me or evaluating me?
Ask, in writing, three questions. What is being logged. Who can read it. Whether the outputs are used in performance review or workforce planning. A tool deployed to help you has answers to all three. Silence on the third question is itself an answer.
What is the difference between enterprise AI and a local model?
Enterprise AI runs on the vendor's infrastructure under a contract. It can be compliant and well governed, but the vendor sees the shape of your operation. A local or self-hosted model runs on hardware you own, so the data does not leave the building. The tradeoff is that you handle the setup, the updates, and the security yourself.
Are open source models good enough to run a business on yet?
Closer than most owners assume. Epoch AI's tracker has open-weight models trailing the closed frontier by roughly four months on average through 2026, with the gap effectively gone on knowledge tasks and still real on production coding and complex agent work. For document handling, drafting, summarizing, and internal search, open models are already sufficient for most small operations.
What is the risk to the business owner, not the employee?
A vendor that maps every process in your company in order to automate it now holds an operating manual for your business. Nothing about that knowledge expires when the contract does. For a service business whose advantage is process rather than physical assets, that is a real exposure, and it is the edge of the sword that rarely gets discussed in the sales meeting.
What should a Santa Clarita business owner do first?
Decide what leaves the building before you decide what tool to buy. Write down the three processes that are genuinely your advantage, keep those on infrastructure you control, and let the commodity work go to whatever tool is cheapest and best. Most owners do this in the opposite order and cannot undo it later.
Connor T. MacIvor · CalDRE #01238257 · Sync Brokerage, Inc. · DRE #02031490