Comment by aditya_rs

5 days ago

I feel like a lot of these always on agents tie users deeply into the platform. Unlike models that you can swap between with relative ease, with an agent because of the integrations to other platforms, work history and so on it would be harder to switch, since in effect they are essentially your computer on the cloud.

Tin foil hat version of me thinks that all the closed model companies want to desperately build an abstraction layer on top of the model, so that they can limit access to the model directly and build a locked down relationship with the user.

Other inference providers should counter this by providing their own version of standardized managed agents.

Coincidentally, I published a note on my blog just about this today https://aditya.rs/blog/2026/09/29/inference-providers-should...

Lock-in is easy with these agents because they NEED all of your data to be useful, and they will continue to learn internally about you.

But ultimately the AI company CAN choose to just make all the data exportable and open source their product for self-hosting. (The mainstream ones won't, of course, they want to lock you in and hide their AI prompts and algorithms.)

I think what is sorely needed is a version of Dots/Muse without lock-in risk but is still accessible to regular people unlike Openclaw.

  • I don't think export is necessary. Most of the value is in the context, you can always prompt your agent to vomit all of its context out into markdown files in some repo and then pass it on to the next agent

  • I agree. FWIW I'm trying to build a wordpress-like AGPL 3.0 thing (holdout.com) that lets you import your existing chats, has feature parity with the frontier consumer apps, rich plugin marketplace, and hopefully lets people feel more in-control, and able to sacrifice less of their entire lives to one walled garden.

  • i'm usually not one to defend europe's (over-)regulation, but having ownership of such data and being able to direct it to other providers for easy switching is one of the pillars of a lot of data related regulation

    so either they can forget about their moat or forget about the continent with those practices

  • Yep, that's what I think and wrote on my blog. My hope is that the inference providers should provide a managed service like it. It's also in their best interest to do so, because if they don't and these provider hosted agents become the norm, demand for independent inference would drop.

    • > It's also in their best interest to do so, because if they don't and these provider hosted agents become the norm, demand for independent inference would drop.

      I disagree with this part. AI companies will want to try their damndest to control distribution of AI, so that they can enshittify later.

      Consumers conscious of this will want an alternative, of course. Might be niche similar to how Kagi is in search because big tech will always have a AI inference cost advantage + making users the product (extra $ from ads & purchase cuts) + the good old strategy of dumping.

This isn’t tin foil hat, it’s standard corporate strategy - the more of the customer relationship you can own, the better your long-term retention and growth will be.

Very true. I have ChatGPT set up to do some recurring tasks (keeping track of developments on a policy proposal in politics; on a weekly basis tracking music releases based on my evolving tastes; checking new book releases; basically doing recurring deep dive web research on my behalf and reporting when there is a significant new finding) and this alone keeps me from switching to another service.

The AI itself is quickly becoming a commodity. The ecosystem is what will keep people tied to one of the companies.

Actually there is an open source version of dots called Headlong

https://x.com/andykonwinski/status/2091990178638496195

I have not used it myself but it is in my todo list for a while.

  • That looks like a very bad recipe to get burned with your private data escaping your control. Just the choice of components alone is enough to give me the shakes but that gets compounded by a design that can only be described as 'insecure out of the box'.

    This is a great research project/experiment but I would really suggest you pause before you give it actual data.

It feels like the opposite to me. Moving providers with my Linux VM is incredibly annoying, but with these things, I can (so far) literally ask them to create me a tarball with a README.md and hand it to an agent on the new provider and have it do the rest.

  • Possibly so for now. But do you think the providers are interested in making interoperability easy?

    Even in the future if they are required by law to provide it, I wouldn't bet against the craftiness of the providers to invent some sort of network effect dark pattern to make it painful, if not outright impossible.

    Just as an example, with Muse I can already see that the way they are thinking of making money is via taking a transaction cut, so it's not that hard to imagine that Meta can negotiate deals for txns that happens through Muse which won't be available elsewhere.

    • Obviously I don't expect them to intentionally help me move to the competition, but I do wonder whether obscure data formats as a moat are a thing of the past.

      Your second point is where I'd imagine the future moats to live: Exclusivity deals with service providers. Things are already in motion with Amazon banning and Shopify explicitly inviting Muse; we'll probably see much more of that.

    • That is not really how agents work? You can't reliably stop an agent from writing out its context and even if you could that would just make the agent horrible and unusable at performing tasks in general (e.g. delegating to subagents)

That seems like the intent for sure… but behind the scenes, they are really the LLM with a hosted sandbox. I’m still thinking any sort of moat will be difficult & agent services that can use multiple LLMs will be popular.

Credentials seem to be another big part of this lock-in problem. If an always-on agent has permanent access to all your internal tools, moving agents means moving a huge pile of secrets and permissions too including api integrations you forgot even existed.

And as a secondary consequence, imagine you've connected your whole life to your agent and used it for 5 years, and then your agent gets prompt injected.

Everything about you/your life is stolen and it's just straight up over

> Other inference providers should counter this by providing their own version of standardized managed agents

The whole personal agents field is still at a nascent stage. As the field matures and we learn winning use cases and robust operating patterns, we'll also see a few open-source agent harnesses doing well. That would be the signal for commodity infra providers to start providing hosted assistants. Too much froth to keep up with, before that point.

Only if these platforms don’t provide anyway to export the text files that contain memories and chat history. If they do allow it, switching it is easy. It’s not like these agents are updating a custom models weights based on your convos. The most important thing they have is the API connections you give them access to so they can access your gmail, calendar, etc.

This is barely tinfoil hat material. Ai inference providers desperately need to find a moat before they are commoditized.

This does not scale well for enterprises. The risk always-on agents bring is something no one wants to take. Guardrail and Harness is going to be next big thing for Enterprise AI.

I mean it’s not exactly tin foil hat. I suspect when we see the s1 drop for these companies , the business plan will be essentially exactly what you just said.

OpenWebUI has allowed me to avoid this. Combined with OpenTerminal.

I am using zcode with GLM5.3 flash from z.ai due to the extra usage / air drops etc . However nothing I’m doing is tied to that harness.

When I moved from crush to Zcode , the first thing I did was tell Zcode to migrate all of my crush customizations to Zcode and to set things up in a harness agnostic way going forward. It did.

So the harness specific setup is just symbolic links to the canonical .md file in various git repos. Also the heavy use of redmine / discourse / GLPI (via small go CLi wrappers that crush and Zcode made for me ) allows me to remain context / chat agnostic as well.

  • > When I moved from crush to Zcode , the first thing I did was tell Zcode to migrate all of my crush customizations to Zcode and to set things up in a harness agnostic way going forward. It did.

    This works for hosted mass-market solutions just as well! ChatGPT and Claude allow me to download all of my data, and these days data formats are less of a moat than ever given that you can just hand them to an LLM and have that worry about importing it into your new thing for you.

    I've even seen explicit "offboarding prompts" to hand to your old agent, e.g. in Meta Muse.