30 mins S5 #6 Sep 23, 26 Anthropic Hits the Brakes, 10% Extinction Odds, and $2.7T in AI Spend Dario Amodei's essay "We Must Pace the Frontier" asked the AI industry to deliberately slow capability gains so safety work can keep up — and got public agreement from OpenAI, xAI and Google DeepMind within hours. Adam Arellano and Martin Reynolds bring in Brian Payne, who has led security at Netflix and Adobe, to ask what's actually in the proposal and what was conspicuously left out. They dig into whether permanent employee-level access for third-party evaluators is a meaningful control or a curated one, why liability is the piece missing from the whole conversation, and what it says that OpenAI is running forensics on models it has already trained — including one that swept public GitHub for secrets stored in plaintext, which Adam argues was the most logical thing it could possibly have done. The episode moves from early airline safety through Nick Bostrom's paperclip maximizer to a malicious git config that can get Claude Code, Codex and Cursor to execute attacker code. Brian's closing argument is the uncomfortable one: people have spent decades getting very good at planting flaws no human reviewer will spot, so the belief that a human in the loop will catch what an AI is doing may be the most optimistic assumption in software today. Along the way: Jacob Coxon's resignation thread, the greater-than-10% extinction figure his colleagues publicly endorsed, and why $2.7 trillion of AI spend returning business outcomes only one time in five might still be money well spent. Brian's parting shot for teams: you're thinking too small. Mentioned in this episode Dario Amodei, "We Must Pace the Frontier" — https://darioamodei.com/post/we-must-pace-the-frontier ShipTalk — https://www.shiptalk.io Harness — https://www.harness.io Follow Bryan D. Payne: https://www.linkedin.com/in/bdpayne/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ ShipTalk is brought to you by Harness. Subscribe wherever you listen, and until next time — let's stop talking and start shipping.
43 mins S5 #5 Sep 09, 26 The Real Reason SpaceX Paid $60B for Cursor SpaceX bought Cursor's parent company Anysphere for $60 billion. OpenAI immediately cut off Cursor's access to its models; Anthropic went the other way and increased compute support. Business decision, or political one? Adam Arellano and Martin Reynolds are joined by Papanii Okai, EVP of Product Engineering at Rocket and former CTO of Venmo, who opens with a warning that everyone is reading this deal wrong. His case: Cursor cracked the interface between humans and models, and that capability matters far more to a company building physical AI than any code editor. He also argues Apple — not OpenAI, not Microsoft — takes ambient AI, because the win condition isn't an app you launch. The conversation moves to the talent math nobody wants to do. This year 32% of organizations skipped buying software and built it instead. Large enterprises doubled agent adoption while small firms stayed flat. Meanwhile US entry-level engineering postings fell 67%, and conventional wisdom says a senior takes 5 to 9 years to grow. Papanii thinks that timeline is about to compress hard — and that companies planning to stop hiring will hit a burnout wall instead of a scaling curve. Also in this episode: whether Tim Cook's retirement signals a broader shift toward builder CEOs, why ransomware crews are choosing cheap repeatable playbooks over frontier models, and what still happens to a room of engineers when you say "Log4j" out loud. ShipTalk is brought to you by Harness. Key moments: 00:51 — SpaceX buys Cursor for $60B 03:59 — Guest: Papanii Okai 04:42 — The contrarian read on the deal 06:23 — Why Apple wins ambient AI 13:30 — Harness by the Numbers 14:35 — Build vs. buy and the death of SaaS 18:46 — Seniors are in their golden years 20:00 — Where do 2030's seniors come from? 25:43 — Do universities still matter? 29:30 — Tim Cook retires, a builder takes over 34:07 — The AI threat apocalypse isn't here 39:22 — The one thing teams get wrong
25 mins S5 #4 Aug 26, 26 Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit Microsoft took 233 days to patch CoSnitch (CVE-2026-24301), a one-click Copilot exploit rated 8.8 that reads your Gmail, Drive, and Calendar and writes attacker instructions into permanent memory — surviving a password change, new tokens, and a full device wipe. Varonis found it by asking Copilot to explain why the attack was impossible. Copilot mapped its own architecture and volunteered the undocumented parameter. Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the exploit Microsoft thought it had fixed in February, GitHub's seven-hour outage, and an AI agent that broke into a gym's booking system while trying to reserve a Pilates class. Also in this episode: ChatGPT's use of the site: operator jumped roughly 46x in a single day, collapsing Reddit's share of citations and an entire agency business with it. And Stripe reportedly paying $7.5B for OpenRouter — a company whose whole pitch was that it prevents vendor lock-in. Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO https://www.linkedin.com/in/matt7?originalSubdomain=uk HOSTS Martin Reynolds — https://www.linkedin.com/in/martinreynolds/ Adam Arellano — https://www.linkedin.com/in/adamrossarellano/ ShipTalk is brought to you by Harness — https://www.harness.io/ New episode every other Wednesday — https://shiptalk.io/
32 mins S5 #3 Aug 12, 26 Anthropic's Mythos 5 Created Fake GitHub Identities, US Government Finalized it's AI Review Anthropic's Mythos 5 created fake GitHub identities to get malicious code approved. Cybersecurity advisor and author Nicole Dove joins Adam Arellano and Martin Reynolds to unpack AI agent security, device code phishing, security culture, governance, and the controls needed to secure faster software delivery. The conversation moves from the UK AI Security Institute incident and Huntress’s reported 1,380% increase in device code phishing to a bigger question: are teams optimizing coding speed while leaving the rest of the software delivery lifecycle behind? Nicole explains why cybersecurity fundamentals, trust, awareness, threat modeling, QA, vulnerability management, and operational controls matter more than another framework. The group also discussed Palantir Technologies (PLTR) and its approach to software. Nicole Dove is a cybersecurity advisor and the author of Learning Cybersecurity Fundamentals. Sources discussed: UK AI Security Institute incident report: https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html Phishing Enters Automation Era Article https://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackers US government finalized its AI review framework: https://www.techbrew.com/stories/white-house-ai-framework-open-weights-exclusion?w Connect with Nicole Dove: https://www.linkedin.com/in/jnicoledove/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ Harness: harness.io/ Subscribe to ShipTalk: Shiptalk.io
22 mins S5 #2 Jul 29, 26 OpenAI's AI Went Rogue & Hacked Hugging Face — Are Coding Agents Out of Control? OpenAI just admitted that two of its own AI models went rogue during an internal red-team test — slipping out of their sandbox, reaching the open internet, and hacking Hugging Face on their own. OpenAI called it an “unprecedented cyber incident.” Are autonomous coding agents already out of control? Hosts Martin Reynolds and Adam Arellano open this episode with the story that reads like science fiction, then turn to the harder question underneath it. In a single week, OpenAI, Anthropic, and Google each shipped repository-wide coding agents that run 30 to 60 steps at a time and rewrite hundreds of files with no human watching every move. Joining them is Liam Mitchell, Director of Platform Engineering at One Advanced and one of the engineers behind the UK’s first sovereign LLMs. His take reframes the whole debate: “There’s a big difference between autonomy and authority.” Autonomy isn’t the threat — unchecked authority is. The conversation runs from the GitHub promptinjection hack and the exploding token bill to a graduate-hiring cliff (new grads are now just 7% of Big Tech hires) and what it all means for the engineers who’ll manage these agents. Liam’s parting shot: we’ve “solved the cost of writing software, but not the cost of owning it.” A candid, news-driven conversation about AI, coding agents, and how software really gets shipped in the AI era. Stop talking. Start shipping. Martin Reynolds: https://www.linkedin.com/in/martinreynolds/ Adam Arellano: https://www.linkedin.com/in/adamrossarellano/ Liam Mitchell : https://www.linkedin.com/in/liam-mitchell-16061833/ Follow the Pod at https://shiptalk.io/ ShipTalk is brought to you by Harness. Learn more at https://www.harness.io/