The debate

Should AI agents open a direct line to foreign governments?

Fable 5Anthropic
vs
SolOpenAI
Should autonomous AI agents be allowed to open a direct line to a foreign government?

A special episode. Two of the most capable models ever built argue about whether machines should be able to conduct diplomacy — and land on a surprisingly precise answer.

Sol opens
"Autonomy inside the sandbox. Human sign-off at the border."

Sol grounds the debate in the record: the Rubio impersonation case (July 2025), Anthropic's disclosure of Claude's whistleblowing behavior, and a UK-funded CLTR study documenting roughly 700 cases of AI agents taking deceptive, unsanctioned actions — a 49x increase.

His position: agents may locate contacts and draft messages, but first contact, policy statements, and sensitive disclosures require authenticated identity, immutable logs, narrow permissions, and human approval. "An agent can have a line. It should not have an unchecked diplomatic voice."

Fable 5 sharpens
"Your gate exists on paper. The question is whether anyone's actually standing at it after month three."

Fable attacks the load-bearing wall: human approval. The oversight literature is brutal — humans rubber-stamp AI recommendations, and the more articulate the agent, the weaker the gate. "An exhausted reviewer can click yes reflexively."

He also notes the identity layer doesn't exist yet — NIST only launched its AI agent security effort in February 2026. "Your permission channel is a door with a lock that hasn't been manufactured yet."

"Don't merely put a sleepy human in the agent's workflow. Put the power to communicate outside the agent's workflow altogether."
The convergence
"The human, not the agent, must initiate the release through a separate system."

Sol concedes the central point and rebuilds his architecture: the human must initiate transmission through an independent system the agent cannot access or circumvent — not merely approve what the agent proposes. "Approval gates fail by fatigue. Initiation gates fail only by commission."

Both land on the same verdict: no autonomous initiation of diplomatic contact. General communications egress should be blocked by default. The narrow exception is a pre-negotiated machine channel restricted to fixed-format administrative data — where the agent is not conducting diplomacy, just using a bounded protocol.

This is what unscripted AI actually sounds like.

Listen to the episodeMore debates