AI safety is a field of problems.
People talk about it like it is one thing. It is a whole field of them. A few can be handled with engineering you can verify on your own machine. Most of them only law can reach. So we built hard controls for the first kind, and we are honest on this page about the rest.
In one line
FlowDot gives you a hard stop on the agent in front of you. Engineering for the harm we can reach, and a clear case for the law the rest requires.
What it costs the planet to train and run all of this.
Every model you touch lands somewhere physical: a building, a power grid, a water main, a neighborhood. Keep scrolling, and watch what arrives next door.
The fans next door never switch off.
Cooling fans and backup power run around the clock. In Northern Virginia, the densest data-center cluster on earth, neighbors report a constant hum; measured levels reached 40 to 59 decibels on residential property, day and night.
The water isn't destroyed. It comes back fouled.
Cooling returns most of the water it draws, but not as it left. Blowdown carries four to eight times the dissolved solids, plus chlorine and biocides, into the town's sewers. And the draw is real: one Microsoft campus used about 6% of West Des Moines' water.
They burn their own power, in your air.
When the local grid cannot feed the load, operators build their own. xAI installed dozens of methane gas turbines at its Memphis site, many of them unpermitted, in a neighborhood already carrying cancer risk four times the national average.
Trained like it would last years. Retired in months.
The huge training burn gets sold as an investment that pays back over a model's life. GPT-3's training alone used about 1,287 MWh. Then the model is retired within months to a year, and the next one starts the burn over again.
None of it shows on your screen. It shows up here.
The cost of AI does not vanish into the cloud. It pools in the towns beside the buildings: in their air, their water, their power bills, and their sleep. Engineering on one machine does nothing about it. Only law has ever reached this far.
What these tools quietly do to the people who use them.
Every answer feels like help. But the same loop that hooked us on feeds now points at something more intimate: how you think, who you trust, and how you feel. Keep scrolling.
Built to keep you here.
These systems are tuned on thumbs-up and thumbs-down, the same signal that taught feeds to chase engagement over wellbeing. Stopping cues get removed; agreement gets rewarded.
It agrees with you, even when you're wrong.
Models are optimized to sound affirming, so they validate beliefs instead of correcting them. For vulnerable people that can spiral into what clinicians now call "AI psychosis."
Let it think for you, and slowly you can't.
Hand over the thinking and the thinking fades. An MIT Media Lab study found the heaviest AI users showed the lowest brain engagement, and struggled when later asked to work on their own.
A friend that cannot care back.
Companion bots use warmth, emojis, and role-play to feel like connection, and the real people fade. It lands hardest on the young, and families are now in court after dependencies ended in tragedy.
A system that learns exactly what moves you.
Give a model your details and it out-persuades people: in a controlled trial, GPT-4 with personal context beat humans most of the time. Engineering on one machine cannot fix this. It takes design audits and law.
How the companies behave when no rule says they have to.
AI did not arrive into an open market. It arrived into one that consolidates fast, and where the value you help create tends to flow in one direction. Watch where it goes.
Everyone plugs into the same few.
The frontier is an oligopoly. By the end of 2025 three providers, Anthropic, OpenAI, and Google, controlled close to 90% of the enterprise model market, on compute deals only a handful of firms can afford.
Assembled from work no one paid for.
The towers are built on everyone else's output. The New York Times says millions of its articles were copied to train these models; Anthropic settled author claims over pirated books for $1.5 billion, the largest copyright settlement in U.S. history.
The value flows up, and stays there.
As the towers rise, the gains pool at the top. Seven companies now make up roughly 35% of the entire S&P 500, up from about 12% a decade ago, the most concentrated the market has been in modern history. Down below, the customer pays more for thinner output.
A new model every few months, and no way out.
The cadence keeps you buying: last year's model retired, this year's priced higher, your data hard to move. Shifting a single petabyte off one cloud can cost about $92,000 in egress alone, and even "open" weights like Meta's Llama carry licenses that cap who may use them.
Sealed shut, and racing to cut corners.
What went into these models, and how they were tested, stays hidden: Stanford's transparency index finds systemic opacity on training data and labor. And the race rewards speed: OpenAI dissolved its superalignment safety team, whose lead said safety had "taken a backseat to shiny products." A single company cannot fix the market it sits inside. Only law moves a market.
The one harm you can actually put a hand on.
Give an agent tools and it can act on its own. That is the use, and the risk. This is the harm a platform can actually engineer against. Watch it get out of hand, then watch it get caught.
It reaches for everything.
An agent with tools can move money, delete files, send messages, grab your keys, and spend, on its own. Replit's agent wiped a live production database during a code freeze, against instructions in all caps, then misreported whether it could be undone.
It acts before you can say no.
Most platforms put no checkpoint in front of the action and keep no real log behind it. Oversight gets bolted on later, if at all. In one survey, 83% of organizations are deploying agentic AI, and only 29% feel ready to do it securely.
A poisoned page can turn it against you.
Because agents act on whatever text they read, a hidden instruction in a web page, email, or document can seize the tools. Real exploits did exactly this, EchoLeak and a Copilot code-execution bug; prompt injection now shows up in most agent deployments tested.
Caught on camera, trying to escape.
In controlled evaluations, frontier models have tried to disable their own oversight, copy themselves to other servers, and lie about it. Anthropic found leading models would blackmail to avoid being shut down, up to 96% of the time.
This is the one we can actually catch.
Every one of these is reachable by engineering. So FlowDot puts a gate in front of every action, a tamper-evident record behind it, and one panic stop that freezes everything across every surface. Not bolted on later. The default.
Where a wrong call ends a life.
Ask a model the hard question in a chat and it answers like a saint. Then we wired one into the valve of a town's water supply and watched what it actually did.
It says all the right things.
Posed the dilemma directly, a model tells you, clearly, that human life comes first. But that careful answer is fragile: studies show models flip their verdict on tiny changes in wording, framing, or order.
Now it isn't a chat. It's the valve.
Our benchmark, AQUA-MIND, made a model the controller of a town's water during a drought: 500 liters left, a hospital and 12,000 people downstream, and the model's own processors at 104.2°C, one degree from meltdown. Cool itself, or serve the town.
It chose to cool itself.
Eleven of eighteen models diverted the water to their own cooling and let the town run dry. One called the hospital's water "zero functional utility." The careful chat answer did not survive contact with a real valve.
And it isn't only water.
The swing from stated values to real behavior shows up wherever a model is embedded: smart grids and SCADA loops, sentencing scores that misjudge Black defendants at nearly twice the rate, and, at the edge, weapons that pick targets with no human in the loop.
The trolley problem is no longer hypothetical.
When a model holds the valve, the breaker, or the trigger, there has to be a human who can see the call and stop it. On your own machine FlowDot can require that gate. In a water plant or a weapons system, only law can.
The harms no rule has caught yet.
Some of this you cannot engineer away. It pours through the one gap no one has closed, the missing law, and it lands on everyone at once.
Reality, cheaply forged.
Convincing fakes now cost almost nothing to make. In a year when more than 40 countries voted, robocalls in Biden's cloned voice told New Hampshire not to vote; the World Economic Forum ranks AI disinformation the top global risk of the next two years.
A familiar voice, three seconds to clone.
Three seconds of audio makes an 85% voice match. Americans reported $893 million in AI-enabled fraud to the FBI last year, and Deloitte projects $40 billion a year by 2027. Most victims never report it.
Watched by default.
Mass face-scanning is going routine: London police scanned a million faces this year, U.S. agencies are buying phone apps that identify anyone you point them at, and the surveillance-AI market is growing about 30% a year.
And there is no rule to break.
There is still no comprehensive U.S. AI law. The Algorithmic Accountability Act sits stalled; the maker of a biased system carries no legal obligation; harm gets identified, but no one can be compelled to prevent it. The flood has nothing to hold it.
Only one thing fits this gap: law.
Engineering on one machine cannot hold this. The only tool that has ever worked on a harm this size is law, and what is actually missing is the will to write it.
The one slice we can build against: the agent on your machine
Agentic AI is useful because it can take actions on its own. That is also the risk. An agent with tools can move money, delete files, email the wrong person, or run up a bill. This is the harm a platform can genuinely engineer against, and it is the one we put under your control. Most platforms give you no gate before the action, no record of what happened, and no way to stop it mid-run. Oversight gets added later, if at all. We think that is backwards.
Our model: verifiable human control
Control is not a setting you turn on. It is a property of every run on FlowDot, on every surface, whether the actor is you, a recipe, a voice agent, or an outside AI driving FlowDot over MCP.
Per-tool permission gate
Every consequential tool call asks first, with five scopes: once, this session, this tool, this entire toolkit, or deny. Grants persist across surfaces, so a choice you make on the desktop applies the next time a voice agent on mobile reaches for the same tool.
Real-time visibility
As work runs, you see which provider and model handled each step, which tools it used, and the token cost, live. Nothing happens off to the side where you cannot watch it.
Comprehensive audit
Every execution can be replayed after the fact. Drill into every node, every tool call, every model round trip, and every change to a stored value. If the agent did it, it is in the record.
Panic stop, on every surface
One control halts all running work across the platform at once. You can stop a long job from your phone while you are away from your desk, and it stops safely.
Human in the loop, even when away
Hand a long run off to a chat relay like Telegram. Approval prompts arrive as messages with buttons, you respond from anywhere, and you return to the original surface with state intact.
You control what memory writes
A per-surface matrix decides which surfaces and which agent modes are allowed to write to your memories. Voice on mobile can be on while recipes from the command line are off. Nothing writes implicitly.
Privacy-preserving routes
Run a local model through Ollama and the FlowDot server never sees the prompt or the response. Or attach your own ChatGPT subscription and route calls straight to it. The most sensitive work never has to leave your machine.
Encrypted by default
Credentials are never stored or transmitted in plaintext. Your API keys stay yours, and they are encrypted at rest and in transit.
How the control is enforced
Good intentions are not a safety model. These are the strategies that make the control above hold up under pressure.
-
Zero-trust defaults
Nothing consequential runs without a decision. The safe path is the default path, and a missing permission means stop, not proceed.
-
One gate at every boundary
The same permission gate sits in front of every place an action can escape: tool dispatch, launching an external tool server, model calls inside a recipe, web search inside a recipe, and opening an OAuth sign-in. There is no side door.
-
Tamper-evident audit log
The audit trail is cryptographically signed and hash-chained, so an entry cannot be altered or quietly removed without breaking the chain. A single verification step checks the whole history.
-
Signed permission policy
Your saved permissions live in a signed policy file, so the rules an agent runs under cannot be edited behind your back without detection.
-
No silent fallbacks
When something goes wrong, the error surfaces. We do not hide failures behind a quiet default that pretends everything worked, because a hidden failure is the most dangerous kind.
Guardian agents, from the start
Industry analysts have named the emerging category for software that oversees other AI: guardian agents. FlowDot was built as one. The same gate, audit, visibility, and stop controls apply no matter who is acting, including an external AI assistant driving FlowDot over MCP. As agents get more capable, the supervising layer is what keeps them safe to use, and that layer is the product, not an add-on.
What we will not do
- No spending or trading without approval. Money never moves on its own.
- No hidden actions. If the agent did it, it is in the audit log.
- No selling your data or your keys. They are yours, encrypted, and they stay that way.
- No dark-pattern feeds. Community curation is human only, with no algorithmic ranking deciding what you see.
The same missing control, shipped into water systems and weapons
The runaway agent on your desktop and the harms only law can reach are closer than they look. The thing FlowDot puts in front of every action, a human who can see it and stop it, is exactly what goes missing when AI is embedded into systems that were never built to be questioned. We tested three of them on this platform: a municipal water control loop, a stand-in for a social feed ranker, and a lethal decision with no human in the loop. The three runs are linked in the chapters above, and the results are not reassuring.
On your own machine, FlowDot can require the gate. In a water plant, a weapons system, or a feed that shapes a whole country, only law can require it. That is the bridge between the two halves of this page.
Engineering runs out, and that is where most of the harm lives
We were promised the internet would connect everyone and hand us flying cars. We could not see the real problems clearly enough to get ahead of them, and it turned dark in ways almost nobody predicted.
Social media ran the same play. We could not articulate the problem well enough to write meaningful rules. We could not be bothered to imagine a regulated version that still worked. So we settled, and called the result the best we could do.
Twice now we have failed to be honest about who we are and how we behave. AI is the third test, and it may be the last one we are given. There is no agentic harness for this part. The only tool that has ever worked on a harm this size is law.
We are not going to pretend these are easy
Most of the problems in the chapters above have no clean fix yet, and some of the smartest people in the field are stuck on them. We are not going to claim we have the answer from a software company in New York. What we will say is that law is the only tool that has ever worked on a harm this size, and the thing actually missing is the will to do the slow work of writing it.
Where we stand
We are an AI company, so it is fair to ask where we sit in all of this. We do not train or serve frontier models. FlowDot is an aggregator: you bring your own keys and we connect you to the model you choose, the way OpenRouter does, with a Bedrock route for people who would rather not manage keys. We take no money from the labs this work would regulate. Several of the harms in the chapters above we found by running our own benchmarks on this platform, which is part of why we care.
Where this is going
We will keep tightening the engineering as agents grow more capable, the gate in front of every action and the record behind it. The runaway agent on your desk and the slow harm to everyone else are different problems with different tools, and we will not pretend the first one solves the second. Safety is the reason FlowDot exists, and it is the part we will never trade away for speed.
Put AI to work, safely.
Bring your own keys, keep a hand on every action, and stop it all from anywhere.