← Writing
Essay

I Built an AI System. It Had to Earn Its Access.

In my quest to continue to learn about all things AI, I started with OpenClaw.

March 25, 2026
Progressive Trust

When I first started using it, something felt off. Not broken, but productive, even impressive. However, open in a way I couldn’t quite name. I found myself being careful about what I fed it, what context I shared. I didn’t have a framework yet. Just instinct.

Then I switched to Claude Code. The difference was immediate. Every action, every permission, it asked. Each approval felt like a deliberate choice. That friction wasn’t annoying. It was right. Made me comfortable.

I started building. Projects, workflows, a system that compounded session over session. Most of it wasn’t an issue. Until I moved into people territory. It should know about my relationships, my contacts. The people I communicate with.

That’s when I paused…

OpenClaw now has an entire ecosystem spinning up around it. Tools specifically designed to make it safer to run. Some of the smartest builders I know run it on a dedicated Mac Mini, away from their primary machine. Nobody told them to. Their instinct is exactly right.

The comfort zone

While using Claude code I became more comfortable over time. Less guarded. That’s “the trap” so to speak . Not that the tool is bad, but that comfort itself moves the boundary. The information and data grows: professional context first, then projects, then personal. Todos, relationships, conversations. You don’t notice until you do.

And here’s the thing. It can’t even have a conversation with you without talking to a backend system somewhere. Every word goes somewhere. You’re not talking to a local instance. You never were. It feels like it.

I remembered my training. My time at Yahoo! Mail.

Think about what’s actually in an inbox.

Bills. Receipts. Order confirmations. Flight itineraries. Tax documents. Financial statements. Health information. Contacts. Phone numbers. The accumulated record of your life, sitting in one place.

I ran Yahoo! Mail. I spent years thinking about exactly this — what systems get to touch that data, who has access, what happens when it goes wrong. At scale. With real consequences.

And I fought for it. Internal teams wanted access to that data: for ads, for personalization, for growth. Real business reasons. Real pressure. I had to hold the line and it wasn’t easy.

When I started feeding my AI system personal context, that history didn’t stay in the past. It came with me. Let alone give it access to my personal inbox.

You might think this only happens to people who weren’t paying attention.

Meet Summer Yue. Her career: Applied ML at a startup, data infrastructure at YouTube, reinforcement learning research (AlphaChip, Robotics), LLM research on LaMDA, Bard, and Gemini, then Research Leadership at Scale AI and Meta. Her entire professional mission: ensuring powerful AI systems are aligned with human values.

Eleven months before what happened to her, she posted on LinkedIn that she was hiring engineers to build the AI Agent Oversight platform at Scale. “One of the most urgent challenges on the path to beneficial AGI,” she wrote.

She told her OpenClaw agent to confirm before acting. A context window compaction event hit mid-session (that means all the history is shortened/compressed and only keeping “the important stuff”). The instruction was lost. It deleted her entire inbox while she ran across the room to physically unplug her Mac Mini. She couldn’t stop it from her phone.

Her words: “Turns out alignment researchers aren’t immune to misalignment.”

This isn’t a carelessness problem. The instruction was there. The system just forgot it. The access had already been granted. If the person whose job is to prevent exactly this couldn’t prevent it. What does that tell you about the default state of these tools?

Progressive Trust

As I was designing a framework for myself with the system, working through it out loud. I started calling it “Progressive Trust”.

And I told the system directly: “You need to earn your trust with me.

Not a setting. A statement. Like an onboarding conversation with a new hire.

Here’s what it looks like in practice: Every action, every permission. Requires explicit approval (“you need to ask me — every time”). Each one builds the record. The system notices repeated approvals and asks if you want to make it automatic. That’s a deliberate decision, not a default.

Read-only first. Then expanded. When I trust it.

When my AI got email access, it didn’t get my email. It got its own. It works FOR me, not AS me (at least not yet). Collaborator mindset, not impersonation.

My system runs on a dedicated server in Helsinki. Not my primary machine. Private, documented, intentional. Same instinct as the Mac Mini builders, thought out architecture from the start.

Two models exist: autonomous by default, or trust earned. Most tools default to the first. This is the alternative.

This isn’t just practitioners figuring it out in isolation.

Major enterprise infrastructure players (like Nvidia) are now shipping dedicated security layers for agentic AI. Not roadmap items, but shipping. Because the default state isn’t safe and they know it.

CampClaw.ai teaches security and safety as one of the first things new agent builders learn. Not advanced curriculum. The on-ramp.

Practitioners got here first. The market is catching up. The timing of this conversation is exactly right.

A trust framework written down and not enforced is just a document.

Philosophy is easy. Enforcement is where trust becomes real.

This isn’t a warning. It’s a responsibility. Whether you’re using AI at home, at work, or inside someone else’s platform. What it touches, what it accesses, what it does on your behalfthat’s yours to answer. You don’t get to outsource that decision to the tool.

You should not fear it. Own it. Your data. Your decisions. Human in the loop by design, not by accident. Tell it.

When you’re about to paste in credentials, an API token, your wife’s phone number — pause. That moment of friction is intentional. Use it.

My policy is documented in a Claude trust-config.md file (link below): version controlled, load on each session, not just written down. And it’s enforced: a PII filter runs on everything before it leaves the system (both ways). Policy without enforcement is just a document. This is both.

Do your homework.

Understand what your AI system does and doesn’t do by default — before you hand it anything. Read the documentation. Check your settings. Read forums. Turn off training on your data if you haven’t already. Try CampClaw’s training program if you’re just getting started.

I’ve put my framework on GitHub. It includes the trust policy and a PII filter — the full starting point, ready to adapt. And it continues to evolve so will update it there.

Take it, adapt it, make it yours.

If you’re thinking about this for yourself or your team, I’d love to compare notes.

One question to close: what would you give your AI access to — and what would you make it earn?

Thoughts? Questions? Comments? Please leave them below!

Thanks! =- Michael

Also published on Medium ↗

Download meThe whole background in one file, written to be read by an AI. Hand it to yours and ask it anything.Get it →
How I work → Bring me the actual situation →

If this hit close to home, bring me the actual situation.

Discuss your situation