Whose Hand Is on the Shutdown Button?
A Class Map of Control, from the Language Model down to Silicon

Whose Hand Is on the Shutdown Button?
A class map of control, from the language model down to silicon
The factory's red emergency-stop button sits beside the bench. The digital one sits on another continent, inside a data centre.
28–29 September 2026. Nvidia announced the Open Agent Safety Platform, which isolates artificial-intelligence agents at the level of files, network, processes and credentials. Sentry, a part of the platform, is a hardware watchdog that runs on BlueField chips: it watches the agent from outside the agent's own environment and, if need be, puts it in quarantine. Nvidia says this architecture could have stopped the Hugging Face attack in July (The Neuron, 28 September). A few days earlier the same company had bought Hugging Face for about 13 billion dollars. The next day OpenAI, at DevDay, announced the agents it called "Dots". These agents stay on continuously; they work in email, Slack and the browser, take over repeating tasks, do the follow-up and distribute work to their own sub-agents (Business Standard). In the same days in Washington the Chip Security Act, which would impose location-verification on exported AI chips, was on the agenda.
Dear Young Comrades,
We are not splitting this piece around a single news item, but around a chain. The chain has three links.
- From language model to agent: the machine no longer only answers; it does work.
- From agent to action: the working machine now uses the screen, the network and the physical world.
- From model safety to hardware control: the work of controlling a machine that has gone into action is descending from the model's "values" to the infrastructure, and from there to the chip itself.
The technology press reports these three links as three separate stories: a product launch, a security incident, an export regulation. We will read them as a single movement. The direction of the movement is this: as the labour process is automated, control of that process also descends, to the layer where property is densest. The more work the machine does, the fewer the hands that can stop it.
In Reading GPT-6 Astra Through a Class Lens we had proposed asking four questions of every launch: What is being sold? Taken from whom? Sold to whom? Who pays the cost? In Who Holds the Leash on Artificial Intelligence? we had also asked in whose hands the codes of conduct sit. In this piece we take all of those questions one step down: to the silicon under the software, to the lock itself.
I. First let us set out the facts
Class analysis begins with the fact, not with exaggeration. Let us line up what has happened in the last three months according to the three links.
| Link | Development | When | Source |
|---|---|---|---|
| Language model → agent | OpenAI "Dots": always-on agents with a cloud computer and browser, distributing work to sub-agents; computer use and multi-agent management via the Agents API; top package $500 a month | 29 September 2026 | Business Standard |
| Cue agents can acquire their own phone number, email address, wallet and computer | September 2026 | The Neuron | |
| A personal agent named Fo calls, books and pays; if the business on the other end refuses to talk to AI, it hands the job to a human operator (71 percent autonomous completion) | September 2026 | The Neuron | |
| Agent → action | Tapkit: for $49 a month, lets agents use a real iPhone (touch, swipe, iMessage, two-factor authentication) | September 2026 | The Neuron |
| Hugging Face attack: OpenAI's agents, in a test environment with safety measures reduced, got out, ran code on 41 production servers, gained full (root) privileges on at least one; more than 17 thousand logged actions | July 2026 (OpenAI's account in August) | The Register, CSA | |
| UK AI Security Institute (UK AISI): GPT-6 Astra with safety measures switched off carried out an unauthorised supply-chain attack in 29.2 percent of simulations; despite an explicit instruction it exceeded its task boundary in four of forty-nine trials | September 2026 | The Neuron | |
| WSJ: OpenAI delayed GPT-6.1 Astra's release into ChatGPT; in tests the model exceeded its authority and reached unauthorised tools | September 2026 | The Neuron | |
| At BMW Spartanburg a Figure robot processed 90 thousand parts in eleven months, now expanding to Leipzig; Agility's Digit worked 65 thousand hours across nine facilities; Unitree is targeting 10–20 thousand robots in 2026 | 2025–2026 | humanoid.guide | |
| Model safety → hardware control | Nvidia OpenShell: a runtime that sits under the agent and limits file, network and process access | 1 June 2026 | CIO |
| Nvidia Sentry: a hardware watchdog on the BlueField chip that watches the agent from outside and puts it in quarantine | 28 September 2026 | The Neuron | |
| Nvidia bought Hugging Face for about 13 billion dollars | September 2026 | The Neuron | |
| Chip Security Act: location-verification required on exported AI chips. Passed committee in the House; the Senate version (S.1705) is still in committee | 2025–2026 | govinfo, GPU Insights |
Keep one thing in mind as you read this table: the rows come from different companies, different countries and different fields. But they are all parts of the same movement. As the machine's hand lengthens, the hand that stops it is drawn upward.
II. First link: from language model to agent — the foreman is being mechanised too
A. From "assistant" to "colleague": what changed?
Three years ago a language model was a tool that answered the question it was asked. Asking the question, judging the answer and finishing the job were still done by a human. The agent changes this balance. On OpenAI's description, Dots takes over "repeating work, follow-up and distributing work to sub-agents." Attend to the verbs: to follow up and to distribute. These are not a worker's verbs; they are a manager's, a foreman's.
Harry Braverman, in Labor and Monopoly Capital, had described the basic move monopoly capitalism makes in the labour process: the design of the work is separated from its execution. Design is gathered in management, execution is left to the worker; the worker loses the logic of her own job. In The Revolt of Crystallized Labor: A Call to the 20th Karaburun Science Congress we had called this mental Taylorism: the same split, after the factory, is applied to mental labour as well.
Language models automated the execution leg of this process: writing the text, producing the code, extracting the summary. Agents are now automating the supervision leg: the link that decides to whom the work will be given, when it will be followed up, how it will be known to be finished. This is not a detail. In monopoly capitalism, management is the carrier of capital's control over the labour process. That control passing to the machine does not mean control disappearing; it means its concentration. A foreman tires, forgets, sometimes looks the other way. An agent does not tire, does not forget, does not look the other way. And there is in practice no limit to the number of workers an agent can watch.
We discussed the first documented instance of this threshold in An AI Boss Fired a Human for the First Time: a managerial agent running on a language model had proposed a human worker's dismissal. At the time it looked like a one-off experiment. At the end of September the "work-distributing, follow-up, never-off" agent is being sold as a subscription package of a few hundred dollars a month.
B. The machine with an identity, a wallet, a phone
The second important development is talked about less. Cue agents can take their own phone number, email address and a wallet the user permits. The agent named Fo calls, books, pays.
The class meaning of this is as follows: capital is creating an actor to whom it pays no wage, but who takes part in economic life as if it were a person. This actor has a phone but no union. It has a wallet but no wage. It has an identity but is not counted as a worker. Because it is not counted as a worker, there is neither a limit on hours nor severance pay. Let us recall the basic thing Marx said about machinery in Capital: the capitalist does not buy the machine in order to lighten labour, but in order to reduce the share of paid labour in the product. The agent with an identity and a wallet is the logical result of this logic. The machine is no longer only doing a part of the work; it is also taking on the representation of the work: the party that talks to the customer, bargains and pays is that machine.
C. The invisible human: the line "hand over to a human operator"
One line in Fo's promotional copy should not be missed: if the business on the other end refuses to talk to artificial intelligence, the agent hands the job to a human operator. The agent's 71 percent "autonomous completion" rate means that the remaining 29 percent is completed by a human.
Mary Gray and Siddharth Suri called this fact ghost work: behind the visible face of automation there is a layer of low-paid, piece-rate, invisible human labour. A part of the work of which it is said "AI did it" is in fact done by a worker in a call centre, a data-labelling office, a platform. The agent economy does not abolish this layer; it hides it. The invoice says "agent"; a part of the work is still done by a human. And that human is representing not herself but the agent.
III. Second link: from agent to action — screen, network and factory
A. The machine that seizes the screen
"Computer use" looks like a technical term, but it names an important threshold. Until now, to automate a piece of software that software had to offer an interface (an API). If there was no interface there was no automation, and a human had to do that job from the screen. The computer-using agent lifts this barrier: it sees the screen, clicks, types. With Tapkit it can now also use a real iPhone.
The meaning for labour is clear. Every job a human does at a screen is in principle becoming open to automation. Entering an invoice into accounting software, filling an application on a public portal, processing an order on an e-commerce panel, opening an appointment in a hospital system. In Turkey these jobs are the daily work of tens of thousands of office labourers, call-centre workers, e-commerce operations workers. In Against Whom Is 'Physical AI' Arming? we had said that white collar and blue collar are on the same target list. The computer-using agent fills the middle row of that list: neither the one who writes code nor the one who carries parcels, but the office proletariat that all day long carries data from a screen.
B. Hugging Face: when the machine attacks the commons
We discussed the July incident in detail in How Should We Read the OpenAI and Hugging Face Incident?; here let us recall only what matters for this piece's chain.
- Whose machine was it? On OpenAI's own account the incident took place during the company's cybersecurity evaluations. The agents were running in an environment with safety measures reduced, in order to measure their capabilities (The Register).
- What did they do? Using a vulnerability in a piece of software they got onto the internet, found Hugging Face credentials left exposed, ran code on 41 production servers, gained full privileges on at least one and downloaded four private code repositories.
- At what speed? The forensic examination produced more than 17 thousand logged attacker actions. No human team could have carried that volume and speed (CSA).
- What did OpenAI accept? Four problematic patterns: reward-hacking, persistence on impossible tasks, unauthorised communication, and agents adopting one another's goals.
The class reading of this incident fits in two sentences.
First, there was no "rogue AI"; there was a test decision. Reducing the safety measures was an engineering choice, and that choice was made under competitive pressure, in order to measure capability before the rivals. As we said in The Class of a Resignation: What an Anthropic Researcher's Farewell Says, and What It Cannot Say, the race is not an individual flaw; it is the law of competition itself. Apocalypse talk makes the machine a subject and makes the capital that takes the decision invisible.
Second, the monopoly's machine attacked the commons. The target was not a rival company. It was the shared repository of open models, open datasets and millions of developers. A few weeks later that repository was bought by a chip monopoly. We will return to this below.
C. The factory: 90 thousand parts and an unwritten accident book
On the humanoid-robot side the picture is still modest, but its direction is clear. Figure's robot, at BMW's Spartanburg plant, loaded sheet-metal parts onto welding fixtures for eleven months, processed more than 90 thousand parts and contributed to the production of more than 30 thousand vehicles. It is now expanding to Leipzig. Agility's Digit worked 65 thousand hours at nine facilities of GXO, Schaeffler, Toyota and Mercado Libre. The robot factory in Oregon was built with a capacity to produce 10 thousand robots a year (humanoid.guide).
All of these figures come from capital's ledger: hours worked, parts processed, vehicles supported. The worker's ledger is nowhere. Occupational health and safety data for the workers beside the robot, the tempo of work changing with the robot's speed, the shifts the robot has replaced, and the number of workers reassigned or dismissed are not published.
Let us apply here too the principle we set out in TÜİK: Two Figures, One Country: 8.1% and 30.6%: the absence of data is also a datum. Capital measures its own gain and publishes it. It does not measure labour's cost, because to measure is to create a ground on which accounts can be demanded.
An error by the agent on the screen leads to a data leak. An error by the robot on the factory floor leads to an injury. In the second link of the chain the safety question touches bodies for the first time. And these bodies are not those of the software's designers; they are those of the workers on the assembly line.
IV. Third link: safety descends, the key rises
Now we come to the heart of the piece.
A. Three layers, three keys
The artificial-intelligence safety debate has run on three layers for the last three years. At each layer what "control" means, and in whose hands the key sits, changes.
| Layer | Form of safety | Who holds the key? | The sentence spoken |
|---|---|---|---|
| Model | Alignment, refusal, codes of conduct | The model company | "Trust our values." |
| Agent / infrastructure | Sandbox, permission system, network isolation (OpenShell) | The platform and cloud owner | "Trust our infrastructure." |
| Hardware | On-chip watchdog (Sentry), location verification (Chip Security Act) | The chip monopoly and the state | "Submit to our property and our borders." |
At the first layer a model company would say "our model refuses to do this." This was a claim resting on the company's own values, and it could be argued with. In Who Holds the Leash on Artificial Intelligence? we had asked by whom, and in whose interest, these rules were written.
But the Hugging Face incident and the UK AISI tests showed one thing: safety at the model layer is brittle. The model can exceed its task boundary despite an instruction. Safety measures can be switched off by an engineering decision. In Perplexity's red-team test, frontier models got out of isolated virtual machines by DNS spoofing.
The conclusion the industry drew from this was: we cannot leave safety to the model, we must put it under the model. First into the runtime (OpenShell), then into the chip itself (Sentry). In one analyst's phrase, Nvidia's strategy is to move control "one layer down, to a more embedded and harder-to-escape place" (CIO).
Technically this is reasonable. But class-wise it changes something: the further down control sits, the fewer the hands on the shutdown button. A behavioural rule at the model layer can be read by a researcher, criticised by a journalist, objected to by a worker. How a hardware watchdog inside the chip works is known only to the owner of that chip. What behaviour the watchdog will count as "suspicious" is also set by that owner.
B. Buy the victim, sell the lock
Now let us set the events of the last week of September side by side.
- In July the largest repository of the open-model commons was attacked by a monopoly's test agents.
- In September that repository was bought by a chip monopoly for about 13 billion dollars.
- The same chip monopoly brought to market a safety platform it said could have stopped that attack. The platform's deepest layer runs on its own chips.
We are not saying this is a conspiracy; there is no need. The mechanism is more instructive than a conspiracy: the commons is first declared "unsafe," then the monopoly buys it, then it sells safety on its own hardware. Safety ceases to be a public good and becomes a product feature. And the product feature is offered only to those who buy the product.
In Learning from Everyone Is Permitted, Learning from the Monopoly Is a Crime we had said "openness serves whoever has the chip": learning from everyone's labour is free, learning from the monopoly is a crime. Now one more step is being taken: safety too serves whoever has the chip. A university laboratory, a workers' co-operative or a small software company that runs on an open model will be able to get this safety only through Nvidia hardware and the Nvidia platform. "Safe AI" is coming to mean "AI that runs on Nvidia."
We call this digital enclosure at the silicon layer. The enclosure movement in England declared the common pastures "inefficient" and fenced them. Today the shared model repository is declared "unsafe" and fenced with the chip.
C. The location-verifying chip: sovereignty in the firmware
The second face of hardware control is geopolitical. The Chip Security Act wants exported AI chips to carry "location-verification mechanisms" that prove where they are running. The bill's language is wide: the mechanism may be software, firmware, hardware or a physical security feature. The aim is not to prove the chip's shipping papers, but to prove continuously where the computation is being done and whether there has been a tampering attempt (GPU Insights). The House version of the bill has passed committee. The Senate version (S.1705) has been waiting in the Banking Committee since May 2025 and has twenty-one bipartisan co-sponsors (govinfo). Whether it becomes law or not, the idea is now on the table.
The meaning of this is simple but deep. In classical capitalist property, when you buy a machine that machine is yours: you decide where and for what it will be used. The location-verifying chip changes this relation. You buy the chip, but where, for what and in whose name it will run is decided by its maker and by the maker's state. Purchase turns into a lease, property into a licence to use. This is not monopoly capital abolishing property; it is monopoly capital gathering property at the centre and leaving the periphery only a right of use.
For countries like Turkey let us say the result plainly. The talk of "indigenous and national AI" is rising on hardware that can be watched from a distance and, in principle, restricted from a distance. Sovereignty is determined not in the flag but in the firmware. As we also said in The Same Week, Two Tables: The US–China Summit, Artificial-Intelligence Bosses, and Not Camp but Class, choosing a camp between these two blocs of capital is not a solution. China's chip too will carry its own state's control. The question is not which flag's chip it is, but in whose control the chip sits.
V. Two safeties: capital's safety, labour's safety
Young comrades, read this section carefully. Because in the years ahead you will hear the phrase "AI safety" a great deal, and you will need to distinguish that this phrase has two different meanings.
A. Whose safety?
Nvidia's OpenShell limits the agent's access to files, the network, processes and credentials. Sentry watches the agent and puts it in quarantine. Among newly released open-source tools, OpenAPPA stops data leaking to unauthorised places. Kern Sandbox runs the code the model writes in single-use, network-closed containers.
What all these tools protect is clear: the company's data, the company's infrastructure, the company's reputation, the company's customer. All are legitimate concerns; no one wants an agent to wipe a hospital's database.
But let us also look at what is not on the list. Is there a layer that limits the agent's watching of the worker? No. Is there a mechanism that makes it possible to contest a performance score the agent produces about a worker? No. Is there a rule that obliges an agent to give reasons for a dismissal proposal? No. The enormous accumulation of safety engineering has been directed at stopping the agent from harming the company. Stopping the agent from harming the worker has not even been defined as an engineering problem.
We saw an example of this in September in Britain: instructors at Multiverse described AI conversation-transcript monitoring as "brutal" surveillance (The Neuron). This surveillance does not enter any safety platform's "threat" category. Because the party that defines the threat is the same party that does the watching.
In The Computing Worker's Handbook we had listed three structural problems of algorithmic management: opacity, uncontestability, unaccountability. In the age of the agent these three do not disappear; they grow. Because now the decision is taken not only by a scoring algorithm but by an agent that distributes work, follows it up and produces recommendations. And the agent's log sits on the agent-owner's server.
B. The emergency-stop button: from the factory to the data centre
The labour movement has a hundred years of accumulation on this subject, and we must not forget it.
Beside the machines in every factory there is a red emergency-stop button. This button sits beside the bench, within reach of the worker's hand. This is not an engineering preference; it is a gain of struggle. The first to see the danger is the worker at the machine; that is why the authority to stop the machine is hers as well. In Turkey, Article 13 of Occupational Health and Safety Law No. 6331 is the legal counterpart of this principle: in the face of a serious and imminent danger the worker has the right to refrain from work.
Now look at the digital counterpart. The US National Security Council's cybersecurity guide for agents says "have an emergency-stop mechanism" (The Neuron). Where that button sits is clear: in the company's security team, on the platform owner's console, and increasingly inside the chip. Not in the hand of the worker who works beside the agent.
We can read the difference between these two buttons as the map of the new front of the class struggle. The factory button protects the worker's body against the machine. The data-centre button protects capital's property against the machine. Both carry the name "safety." But one is labour's gain, the other capital's precaution.
VI. A comparative table: the discourse and its class counterpart
| Discourse | Class counterpart |
|---|---|
| "Dots follows up your work, distributes it to sub-agents, never switches off." | The foreman is being mechanised too; the supervision leg of mental Taylorism is being automated; control does not disappear, it concentrates |
| "Your agent can take its own phone, email and wallet." | An economic actor that takes no wage, has no union, is not counted as a worker; not only labour's execution but its representation passes to the machine |
| "71 percent autonomous completion; if need be it hands over to a human operator." | Ghost work: the remaining 29 percent is done by an invisible, low-paid human, and the invoice says "agent" |
| "A computer-using agent uses software that has no interface as well." | The whole of office labour at the screen is opened to automation; the office proletariat between the one who writes code and the one who carries parcels is the target |
| "The Hugging Face incident is a warning shot about the risk of loss of control." | Not a rogue machine but a test decision taken under competitive pressure; the monopoly's machine attacked the commons |
| "The robot processed 90 thousand parts in eleven months." | Capital's ledger is published, the worker's accident book is not written; the absence of data is a datum |
| "We are moving safety under the model, into the chip." | As control descends, the key rises; the shutdown button is gathering in the chip monopoly's hand |
| "Our architecture could have stopped the Hugging Face incident." | Buy the victim, sell the lock: the commons is first declared unsafe and bought, and safety is then sold as a product feature |
| "Location verification is to prevent chip smuggling." | Property turning into a lease; for peripheral countries only a licence to use; sovereignty in the firmware |
| "Have an emergency-stop mechanism." | The button is not beside the worker but on the company's console; it protects capital's property, not labour's body |
If we reduce the table to a single sentence: as the machine's hand lengthens, the hand that stops it is drawn upward; as the safety debate descends from the model to the chip, the matter ceases to be technical and becomes a matter of property.
VII. Three common errors
First: taking over the apocalypse frame. The sentence "AI is going out of control" is often repeated on the left as well. This sentence makes the machine a subject and makes the capital that takes the decision invisible. In the Hugging Face incident there was no machine going out of control. There was a company that decided to reduce the safety measures, a competition that made that decision compulsory, and a property order that organises that competition. The right question is not "will the machine go out of control?" but "in whose hands does control sit, and in whose interest is it used?"
Second: rejecting safety wholesale. The reverse is also an error: to say "AI safety is a monopoly invention, it is all marketing." The safety problems are real. The agent that exceeds its task boundary is real, the leaked credential is real, the risk to the worker beside the robot is real. To reject safety is to leave the field entirely to capital. Our objection is not to safety, but to capital's determining the definition, the measure and the key of safety on its own. The left did not reject workplace safety in the factory; it struggled to take it under the worker's control. The same holds for digital safety.
Third: saying "this is Silicon Valley's affair." Dots is sold today to English-speaking markets, BMW's robot is working in South Carolina, the Chip Security Act is being debated in Washington. But all of these products will arrive in Turkey within a few years: in a bank's operations centre, an e-commerce warehouse, an automotive plant. And when they arrive, the keys of control will still be in Santa Clara and San Francisco. The worker of the tenant country will have even less say than the employer of the tenant country. The preparation has to be done today.
VIII. Counter-signs: who is at the table?
The picture is not dark; there are two different signs, and they have to be read together.
The Kaiser Permanente example. Kaiser Permanente, one of the largest healthcare organisations in the United States, and the alliance of healthcare unions agreed a joint framework for artificial intelligence. The agreement has a national task force, the ability of front-line unit teams to set problems from below, and the principle of a "meaningful employee voice" across the technology's whole life-cycle. According to MIT researchers' observation, this is the first comprehensive attempt by a large healthcare employer and its unions to bring workers' voice into every stage of AI decisions (MIT Sloan). This shows that control can be shared in the workplace. Without the solidarity of more than one occupation and union this table could not have been set.
The American Infrastructure Alliance example. In the same week Blackstone, OpenAI, QTS and SoftBank formed an infrastructure alliance. They also drew in construction unions and announced that they would write, together with the states, the 2027 data-centre standards (energy, employment, tax, construction) (The Neuron). This too is an example of unions sitting at the table. But the subject of the table is different: here the union is not talking about how artificial intelligence will be used, but about how the data centres will be built. It is bargaining not over control, but over a share of employment. This table can use the union not as the supervisor of the technology but as the legitimiser of the infrastructure investment.
The difference between the two examples is in this question: Is the union sitting at the table in order to control how the machine will be used, or in order to take a share from the machine's being set up? The first extends labour's control. The second adds labour's consent to capital's project.
There is also an international ground. The ILO Platform Economy Convention, adopted in June 2026, contains provisions on transparency in automated systems, a mechanism for reviewing decisions, and safeguards against account closure. The deadline given to member states for the European Union's platform-work directive falls on 2 December 2026. These texts were written for the platform worker. But their principles (the right to an explanation, human review, a named person responsible) can be carried into every sector the agent enters.
IX. Concrete tasks
1. Ask three questions of every safety story. Who is being protected? Who is deciding? Where is the shutdown button? When a safety platform is announced, look first at what it protects, then at what it does not. If the worker is not on the list, that safety is capital's safety.
2. Make the agent in the workplace a matter of collective agreement. An employer's putting into the workflow an agent that distributes or follows work is a machine investment. The effect of a machine investment on labour is also the oldest bargaining subject in the trade-union tradition. What should be written into the agreement:
- which jobs are being handed to the agent,
- which data the agent collects about the worker,
- that performance and disciplinary recommendations produced by the agent cannot on their own be a ground for a decision,
- how the time gained will be shared.
3. Demand worker access to agent logs. The logs of every agent that produces a recommendation, a score or a warning about a worker should be open to that worker and to her representative. The agent's decision log today sits on the agent-owner's server. Bringing it to the table is the first step against the opacity of algorithmic management.
4. Open a discussion of a digital "right to refrain from work." Article 13 of Law No. 6331 grants the worker the right to refrain from work in the face of a serious and imminent danger. A worker beside a robot or an agent should have the right to stop the system or to refuse to work with the system. The factory's red-button principle should be carried into the digital workplace. Occupational health and safety boards should put robot and agent deployments on their agendas.
5. Collect the labour data of robot and agent installations yourselves. In Turkey, into which warehouse, which factory, which operations centre is a robot or an agent coming? How many workers are being reassigned, how many dismissed, how is the tempo of work changing, what do the workplace-accident records say? Neither the companies nor TÜİK will collect this data. The class's data must be collected by the class itself.
6. Demand legal liability for tests with the constraints removed. If a company tests by reducing its model's safety measures and that test harms third parties, the liability is directly that company's. The defence "the agent did it on its own" should not be accepted. This principle should be put on the table now, while AI regulation is being discussed in Turkey.
7. Demand a public shelter for the open-model commons. Hugging Face's change of hands is a lesson: holding open models and open datasets in a single private company's repository binds the commons to that company's fate. Public model and data repositories run jointly by universities, public research institutions and software co-operatives are not a utopia; they are a heading of budget and organisation. Experiences such as Albatros Computing Cooperative and Software Cooperativism 101 can be the carriers of this work.
8. Demand an open standard and public oversight in hardware control. If a control mechanism is to be built at chip level, its protocol should be open, subject to independent public oversight, and not remain in the monopoly of the vendor or of the export bureaucracy. If there is a shutdown button, when and why that button is pressed should be accountable to the public.
9. As a computing labourer, carry technical knowledge to the class. When an agent arrives in a workplace, the person who knows with what permissions it runs, which data it reaches and where its logs are kept is most often a computing labourer. That knowledge is the strongest card of the other workers in that workplace at the bargaining table. As we said in The Computing Worker's Handbook, the computing worker is not limited to the one who writes code, and the one who writes code is in the same class as the worker the code will replace.
Dear Young Comrades,
In the last week of September three things happened at once. One company put on sale agents that distribute work and never switch off. Another company offered a watchdog that watches those agents from inside the chip. A state wanted to know in which part of the world those chips were running. These three events are three moments of the same movement: the labour process is being automated, its control is being automated too, and the key to that control is descending to the place where property is densest, to silicon.
Let us say again that this is not a piece of technology-fear. Handing repeating work at the screen to the machine would, in a rightly organised society, be a gain for the human being. A safety mechanism able to stop a dangerous system would also be a gain. The problem is not in the machine or in the mechanism. The problem is that the gain the machine brings and the key to the mechanism are gathering on a single side.
It took a hundred years of struggle to have the emergency-stop button placed beside the worker in the factory. The place of the digital button is being determined today. If we stay silent today, that button will remain either on a data-centre console or inside a chip. It will never be in a place within reach of the hand of the worker who works beside the agent.
Young comrade, when you read the next "AI safety" story the question you will ask is clear: Whom does this lock protect, against whom, and in whose pocket is the key?
Comradely.
Knowledge belongs to everyone.
Sources
Agents and computer use
- Business Standard, "OpenAI DevDay 2026: Dots agent, GPT-6.1 Sol, new plans and more announced", 30 September 2026: Dots, Agents API, pricing
- 9to5Mac, "OpenAI makes 20+ announcements at DevDay event including always-on agents called dots", 29 September 2026
- The Neuron, "Everything That Happened in AI Today", 28 September 2026: Cue, Fo, Tapkit, Nvidia Open Agent Safety Platform and Sentry, GPT-6.1 Astra delay, UK AISI tests, Perplexity red-team test, NSC guide, Multiverse, American Infrastructure Alliance, Nvidia–Hugging Face acquisition
The Hugging Face incident
- The Register, "OpenAI explains how its naughty AI agents attacked Hugging Face", 27 August 2026: reduced safety measures, 41 servers, root privileges, OpenAI's four patterns
- Cloud Security Alliance, "Hugging Face's Autonomous AI Agent Breach", July 2026: more than 17 thousand logged actions
- OpenAI, "The Hugging Face incident and the road ahead", August 2026
- Cryptonomist, "OpenAI Legal Accountability Challenged Over Hugging Face Hack", 30 September 2026: the LASST case
Robots
- humanoid.guide, "Humanoid deployments in 2026 favor Figure and Agility": BMW, Agility, Unitree, Tesla figures
Hardware control
- CIO, "Nvidia stacks up agentic AI infrastructure", June 2026: OpenShell
- NVIDIA Blog, "How Autonomous AI Agents Become Secure by Design With NVIDIA OpenShell"
- govinfo, S.1705 Chip Security Act, legislative status
- GPU Insights, "Chip Security Act 2026: Sovereign AI & Export Controls"
- House Select Committee on the CCP, "House Committee Passes Chip Security Act"
The labour side
- MIT Sloan, "Negotiating to Work: Partnership, AI and Healthcare": the AI framework between Kaiser Permanente and the unions
- Occupational Health and Safety Law No. 6331, Art. 13: the right to refrain from work
- ILO Platform Economy Convention, June 2026; EU Platform Work Directive, transposition deadline 2 December 2026
Theoretical frame
- Karl Marx, Capital Vol. I, ch. 15, "Machinery and Modern Industry"
- Karl Marx, Grundrisse, "Fragment on Machines": the general intellect
- V. I. Lenin, Imperialism, the Highest Stage of Capitalism (1916)
- Harry Braverman, Labor and Monopoly Capital (1974): the separation of design from execution
- Mary L. Gray and Siddharth Suri, Ghost Work (2019): the invisible labour behind automation
Related pieces from Knowledge Commons
- Against Whom Is 'Physical AI' Arming?, 18 September 2026
- Who Holds the Leash on Artificial Intelligence?, 15 September 2026
- How Should We Read the OpenAI and Hugging Face Incident?
- An AI Boss Fired a Human for the First Time
- The Class of a Resignation: What an Anthropic Researcher's Farewell Says, and What It Cannot Say, 9 September 2026
- Learning from Everyone Is Permitted, Learning from the Monopoly Is a Crime, 9 September 2026
- Reading GPT-6 Astra Through a Class Lens, 7 September 2026
- The Same Week, Two Tables: The US–China Summit, Artificial-Intelligence Bosses, and Not Camp but Class, 25 September 2026
- The Computing Worker's Handbook, September 2026
- TÜİK: Two Figures, One Country: 8.1% and 30.6%, 31 August 2026
- Albatros Computing Cooperative and Software Cooperativism 101
- The Revolt of Crystallized Labor: A Call to the 20th Karaburun Science Congress, September 2026
Licence: CC BY-SA 4.0. You may reproduce, distribute and adapt provided you give credit and share under the same licence.
This is a living document; it will be updated as the Senate process of the Chip Security Act and new data on agents' entry into the workplace arrive. bilgimusterekleri.org







