Claude's Leash, Google's New Trick, and Your Boss's Password
Listen on Spotify ↗Welcome to Briefly AI, a podcast by Harry Sharman, created by AI and voiced by an AI synthesis of Harry Sharman. A man, a machine, and a microphone he technically didn't stand near.
Satya Nadella — Microsoft's CEO — just publicly called out Anthropic's flagship AI for being too cautious. And separately, Claude is now being handed the keys to your online accounts. Both of those things happened this week. Let's get into it.
Right, so first up: Anthropic and the growing debate about what AI should and shouldn't refuse to do.
During an internal Microsoft meeting — which, naturally, became un-internal pretty quickly — Satya Nadella told staff that Claude Fable 5 is "editorially controlled." His word. He said that Claude's tendency to refuse certain requests, things he described as just "random things," makes no sense. The implication being that Microsoft, which uses Claude as part of its enterprise AI toolkit, is frustrated that the model has its own opinions about what it'll help with.
Now, this is a story we've been tracking for a while. Fable 5 had its access suspended by the US government back in June, was restored under undisclosed conditions, and has been quietly in the middle of a tug-of-war between Anthropic's safety principles on one side and commercial pressure on the other. Nadella's comments are essentially a very loud version of that same tension — except this time it's coming from the CEO of one of the biggest buyers of AI infrastructure in the world.
Here's the thing though. The reason Claude is cautious is partly by design. Anthropic has been explicit that safety constraints are a feature, not a bug. And they're heading into an IPO — so publicly watering down that stance would be a reputational problem right at the moment they're trying to convince investors that responsible AI is actually a competitive advantage, not just a nice badge.
What you're seeing here is the central tension in enterprise AI laid bare: the companies building these models are making deliberate choices about what they'll allow, and the companies buying them sometimes just want the restrictions gone. Those two things are going to keep clashing, especially as more businesses discover that the model they've built workflows around occasionally declines to help.
Worth watching: whether Nadella's comments push Anthropic publicly to respond, and whether other enterprise buyers start making similar noises. When a Microsoft CEO says your product is too restricted, that's not a footnote — that's a negotiation conducted in public.
Meanwhile, over at Google, something genuinely practical landed this week, and I think it deserves more attention than it's getting.
Google has updated its AI Mode in Search — that's the feature where instead of just returning links, Google's AI answers your question directly — to now connect with third-party apps. We're talking things like your calendar, your email, your shopping accounts. So instead of asking Google a question and getting an answer, you can now ask Google to do something: check your availability, place an order, manage a task across the apps you actually use day to day.
This is a meaningful step, and here's why it matters beyond the headline. Google is trying to become less of a place you visit to find information, and more of a thing that acts on your behalf. That's the direction the whole industry is moving — towards AI that doesn't just respond but actually does things. Google has the advantage of already being embedded in hundreds of millions of people's daily habits. If it can make AI Mode feel like a natural extension of existing behaviour rather than a new behaviour you have to learn, that's a very different adoption problem than asking someone to open a new app and start from scratch.
The risk, of course, is that every time you grant an AI assistant access to more of your life, you're also expanding what can go wrong. An AI that can put things in your calendar can put the wrong things in your calendar. An AI that can place orders can place the wrong orders. The capability arrives before the error rate is fully understood.
Keep an eye on what third-party apps come on board, and frankly how quickly people start using this — and whether Google publishes any data on where it goes wrong.
Now this next one is the story I keep thinking about, because it sits right at the edge of incredibly useful and slightly alarming — depending on how you squint at it.
1Password, the password manager used by millions of people to store their login credentials, has launched a direct integration with Claude. What this means in practice: you can authorise Claude to log into websites and accounts on your behalf. Book travel. Manage your accounts. Handle multi-step tasks that currently require you to be present, clicking, and logged in. Claude uses your credentials — via 1Password — to do it for you.
On the useful side: this is exactly what AI agents are supposed to be. Not just answering questions, but actually handling things. DoorDash announced something similar this week — a command-line tool that lets developers and AI agents place food orders programmatically. The direction is clear: we're building infrastructure for AI that acts in the world, not just talks about it.
On the "pause for a moment" side: this is your passwords. Your logins. The thing standing between AI and your bank account, your email, your everything. 1Password's architecture means the credentials are encrypted and controlled by the user — Claude doesn't just wander off with them. But we are, as an industry, moving at pace towards a world where AI agents have meaningful access to consequential systems. And the governance for that — the accountability frameworks, the security standards, the answer to "whose fault is it when something goes wrong?" — is still being built in real time.
Harry wrote about this problem through the lens of cognitive offloading — the idea that when we delegate judgment to AI, we also risk losing the capacity to check that delegation or claim it back. The 1Password-Claude integration is a practical, concrete version of exactly that question. You're not just handing the AI a task. You're handing it the keys.
VentureBeat published research this week showing that more than half of enterprises have already experienced a confirmed AI agent security incident or a near-miss. Most agents still share credentials rather than having their own scoped access. The plumbing is arriving before the safety standards for the plumbing are settled.
That's the shape of the week, really. AI with tighter restrictions is frustrating people at the top of Microsoft. AI with looser access to your accounts is the direction of travel. And somewhere in the middle of those two forces, the question of who's actually in charge is still very much open.
That's your daily dose of Harry and his one reliable collaborator, who happens to run on electricity rather than resentment.