RSS Amplifier

David Shapiro’s Substack · Jul 13, 2026

What I'm seeing in AI, the good, the bad, and the hilarious

0
Sign in to vote or save

David Shapiro · David Shapiro’s Substack

In this article I discuss:

  • The dying hype of AI

  • The problem of “Shadow IT” in enterprises

  • AI burnout and addiction

  • Hilariously bad security practices with agents

In my last post, I mentioned that the “show is over” and implied that the Gartner Hype Cycle is still deflating. I think that is true. Anthropic has taken over from OpenAI as “King of the Hype Weasels” (‘hype weasel’ being a pejorative term used by us terminally online for people who hype everything, trying to maintain maximalist engagement).

I did receive some pushback about my characterization of Mythos as a “nothingburger” because, in point of fact, some banks and federal agencies did “scramble” (briefly) to shore up cyber security posture. But here’s the thing—they did they same for ChatGPT 5.6. The difference is that OpenAI did not try to claim they had just created a “cyber weapon” with “national security concerns.”

r/OpenAI - OpenAI absolutely HUMILIATES claude MYTHOS 5 in the trust me bro benchmarks with their new GPT-5.6 Sol
By any objective measure, GPT 5.6 is the “more dangerous” of the models. But no one actually really cares. Iran is not telling US to shut it down, neither is China or Russia or North Korea. If it was a “weapon” someone would have said something.

That part was pure hype.

So I do stand by my characterization that Mythos and 5.6 represent nothing beyond expected incremental improvements. The same cyber security benchmarks that had been creeping up over the last few months have not suddenly been saturated. There was no step change in capability, no saltatory leap in agentic autonomy. Just Anthropic being Anthropic and crying wolf, and ordinary industry-wide trends.

Yes, it just so happens that capability thresholds are now salient to national defense in new dimensions, but that’s an activation threshold, not a gigantic leap.

Now let’s get into the real stuff I’m seeing out there.

Most people online are still bandying about the headlines of “95% of AI pilots fail” as if that’s the whole picture. But since I’m working directly on the frontlines of enterprise consulting again, and talking with other industry insiders who use this stuff every day, I am here to tell you that those failures are not the whole picture. They aren’t even important, in the grand scheme of things.

The real question right now is Shadow IT. Which sounds spooky, but for those who are not CTOs, basically what this means is “my employees are using unapproved technology and we have very little visibility or control over it.”

Having realized this by talking to CEOs and executives, and using my audience to send out surveys, this is pretty much confirmed. To respect the confidentiality of my audience, I will not share any direct quotations, but what I will say is this:

The stories you hear of one sysadmin or developer or engineer replacing an entire team are true. Not necessarily everywhere, and not uniformly, but it is not hyperbole when some people say they replaced all or most of a department with a combination of AI tools. Sometimes this is done with the explicit approval of management, and sometimes it’s literally the manager doing it. The quotations “I’m 40x more productive” is not exaggeration. If anything, in some cases, it may be dramatically underselling the impact that AI in capable hands can have.

But that last line is the key. The difference between an enterprising employee who understands governance, risk control, and that je ne sais quoi about technology and an ordinary employee using Copilot to draft emails is about the difference between a drainage ditch and the Grand Canyon.

I generated this graphic based on all the feedback I got from my audience survey combined with corroborating research. My methodology was straight forward: I aggregated feedback from my audience and used that to verify sources in industry to add context and perspective, but the originating data is “street level”.

The Shadow IT part is the bad/good news. Many CEOs either don’t care (because they don’t understand) or do care because they do understand, and either way, corporate policy absolutely cannot keep pace with the pace of tools.

Audience members shared stories of circumventing enterprise firewalls simply by taking screenshots or pictures with their phone and feeding the information into their paid chatbots (rather than Microsoft Copilot or whatever was approved). This is, of course, a governance, cybersecurity, and legal nightmare from the POV of a CEO and compliance officer.

The reframe I’d offer is this “Guys, we are getting a transformative technology essentially for free, all we have to do is harness this wave and surf it.” The most forward-thinking CEOs I’ve either worked with, spoken to, or heard from via the grapevine all have this mentality.

So, ignore the headlines that say “95% of pilots fail” because that’s only the “corporate approved pilots.” In reality, most organizations are benefiting from AI even if they are willfully blind to it.

The bad news goes beyond “shadow IT” concerns and into burnout and, often, plain stupidity. Since I spend more time online than I’d prefer (thanks to chronic illness) I see the silliest things happening online.

However, while I could be tempted to set up each individual failure mode below as “individual stupidity” the broader, and more interesting point, is that people simply have not acclimated to this technology yet. Let me explain.

AI-driven burnout is rising. As someone with the ability to hyper-focus, I never needed AI to shorten cognitive loops and get stuck in a hyper-aroused state. However, most people have never dealt with hyper-focus. But what I’m seeing out there is that many people are finally working with tools that work at their pace, and they become the bottleneck. That is the core insight. For most workers, entrepreneurs, and managers—the bottleneck is other people or processes, which creates natural breaks and stoppages in work. You get to a point where the mantra is “hurry up and wait.” But, for the first time in most people’s lives, the bottleneck is them. The AI is waiting on more instructions from them. This creates a “treadmill effect” where you feel the FOMO and opportunity cost of “but what if I waste this time and my agents could have been working overnight without me!”

It’s more like a hamster wheel, though.

Here’s how that works: it boils down to dopamine and goal tracking. Your brain gives you a little hit of dopamine every time you complete a task or make perceptible progress towards a goal. This is how video games work. Every time you get some XP, some better loot, unlock a new room, and so on, that’s a dopamine cycle. And, unlike a video game, when your AI chatbots and agents are making “real progress” on any project, that feels like real value. It feels like a money printer.

Which actually means that, psychologically and neurologically, it’s closer to gambling. I’m not saying that the AI chatbots are literally slot machines, but it feels like you’re leaving money on the table, and if you just work a little harder, a little longer, just one more prompt or one more loop, you’ll hit jackpot.

The hamster wheel of AI addiction. I had ChatGPT make this meme for me to explain why AI burnout is happening. There’s also the competition dimension i.e. people feel like they must surge ahead or get left behind, where in objective terms, if you’re using AI to generate value for your business, you are definitionally way ahead of most people.

And what I’ve seen out there is that people do not have a good intuition for delivering value with this new model yet. They get stuck on the hamster wheel of dopamine without stopping to realize “wait, I’m just burning tokens, and setting up agents for no real point.” Now, before you raise the obvious concerns, let me address them head on.

There IS value in learning how to do these things. You have to tinker, dick around, and build a mental model for what works and what doesn’t. So yes, learning is valuable. But there was a story of a guy who went to the hospital for palpitations and exhaustion because he wanted to get the most out of Fable before it went away again, and he blamed Anthropic.

Also, not everyone is stuck in token-burning dopamine-addiction cycles. Many people do genuinely have higher output. I am speaking specifically to the burnout mechanism going on, as I understand it. The metaphor is that each prompt is like one more pull at the slot machine. And no, I do not have the RCTs or academic clout to say that this is literally a formal addiction mechanism and that they need interventions.

Then, there’s another dimension of bad news, and it boils down to inexperience.

Most people are tech illiterate, and they are giving agents root access to mission-critical computers, or their entire business. I’ve seen this story play out more than a few times. The memes have been going around for a while, such as the one below, yet people seem to not have internalized this yet.

I did not make this meme. This kinda stuff has been floating around for a long time.

So, here’s where it gets into tech tribalism, and as a former IT infrastructure guy who spent a lot of time cleaning up messes that developers made, I have the unpopular opinion that developers and software engineers generally are not that tech savvy. They know code, sure, and maybe they know a little bit about Linux and VIM.

But…

That does not mean that they understand operating systems, networks, infrastructure, security, backups, or the rest of the thing. In my observation (shared by others) developers generally fall along a spectrum from “diva” to “plumber.”

On the ‘diva’ end of the spectrum, developers think that they are Gemini and Apollo astronauts of our age, and that all should bow before them, and they throw temper tantrums (literally) if you do not just give them full access to everything. Then, on the opposite end of the spectrum, you have the plumbers, who are just there to write code, make sure it works, and trust the rest of the organization.

The reason I bring this up is because divas, by definition, also tend to believe they know everything. And if they don’t know it, they don’t believe it matters.

I was once in a meeting with a lead developer, and I was representing infrastructure (server, network, security, identity management, backups) and the developer said “We’re going to automate everything!” and I asked:

“What do you mean by ‘everything’?”

He rattled off a bunch of CI/CD pipeline and app monitoring stuff. I asked if he also meant backups, storage, databases, authentication, firewalls, and he just sort of glazed over and changed the subject.

That lesson was critical in my understanding the “diva developer” mentality, which by the way, is pervasive in Silicon Valley. When a developer says they understand “everything” that is a small subset of reality. It’s even a small subset of technology as a whole.

So this leads to the good old Dunning-Kruger Effect (as it is colloquially understood). Dunning-Kruger, as used in modern parlance, basically says people don’t know what they don’t know, and the less they objectively know, the more confident they are.

So, what I’m seeing out there is a bunch of people who simply do not know any better, giving brand new agents full access to their mission critical laptops, business APIs, and that sort of thing, and, as you might expect, sometimes this goes horribly wrong.

From my perspective as a seasoned infrastructure engineer, this is about like giving a sugared up toddler a taser, with the attendant results.

On the Shadow IT component, the primary thing is simple: talk about it. The number one thing CEOs and founders and executives can do about Shadow IT is normalize talking about AI. At your quarterly townhall, or your monthly newsletter, or your annual all-hands, just have the C-suite sit down and have a candid talk with the rest of the company about how much you like using Claude or ChatGPT and share some examples.

Leadership MUST break the AI taboo first.

And the weirdest thing I’ve heard from the field is that executives, leaders, and middle management are hiding AI use from each other. Everyone is afraid to take the first step. And also, some of the older fuddy-duddies in organizations have no clue what AI can do, and they are so far behind, that people have to lie about how long it took to achieve things. I’ve heard from teachers hiding their AI use from their students and administrators, and vice versa. And most individual contributors are hiding their AI use from their superiors (except the few positive cases where the mandate of AI is coming from on high).

Then, for the AI burnout component, the most important thing is to separate the dopamine cycle from actual valuable output. Yes, the AI chatbots are happy to burn tokens and you can set up agentic loops but so what? Who cares? What is it actually doing for you?

For people new to hyper-focus, you must cultivate somatic intuitions for when you’ve had enough. Set alarms, calendar events, timers, whatever you need to do to honor your body first. Create and maintain boundaries. But also recognize that it is actually addictive to feel like you’re making progress at warp speed, even if you’re just spinning in circles.

On the final component, where people do boneheaded things like give a brand new AI agent access to PROD… well you can’t fix stupid. But on a more serious note, talk to a talented sysadmin or engineer about sandboxing, version control, and virtual machines.

The rest will work itself out over time.

I have mentioned consulting multiple times, and while there have been some inquiries, I’m presently only working with one major client although we are open to more clients, if it is a good fit. Our specialty is midmarket enterprises (employee counts “from several dozen to several hundred” as the sweet spot).

Midmarket companies have the clout to make a real difference with AI, plus the agility to implement it. We have found that larger organizations (thousands to tens of thousands) will be on a decade-plus long journey with AI, and most will probably still be behind the curve in 10 to 15 years. We also only work with executive leadership teams directly, not middle management that does not have an executive mandate or buy-in. There’s no point in trying to shoehorn in a disruptive technology like AI if change is not coming from the top. We do work with middle management, but only at the behest of the CEO/owner/founder/top dog.

No posts

Read the original on daveshap.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.