The first thing I ever published on this site was an argument that computer assistants were failing us. That was June 2023, before the current generation of models existed and well before I'd used any of them seriously. I've come back to it because the argument held up better than I expected — and because the reason it held up isn't the reason I gave.
In 2023 I thought the problem was that the technology wasn't good enough. That turned out to be mostly wrong. Almost every complaint I listed has since been fixed, and fixed properly. The thing I actually wanted still doesn't exist, and now I can say why with some precision.
The 2023 Version, and What It Got Wrong
Let me start with a confession that this whole site is currently in the business of making. The original version of this article was written by an AI — I gave it the argument, it produced the words, and I published them. That was the experiment: I wanted to find out whether a writing tool could run a website on its own. It could produce articles. It could not produce anything anyone wanted to read. I've written about how that went in the review of the tool I used.
Here's what it produced, five headings, in order:
- 1. Poor UX Design
- 2. The Context Gap
- 3. Privacy & Security Concerns
- 4. Keyword Dependence
- 5. Lack of Personalization
Four of those five are now largely solved problems, which is a strange thing to say about your own article. And the schema markup on that page credited the author as "Dear Tech Editorial." Not me. I hadn't noticed until I opened the file to rewrite it.
Keyword dependence is gone. That complaint was about assistants that matched command vocabulary instead of meaning, and it was fair in 2023. It is simply no longer true. You can phrase a request any way you like now.
Poor UX is largely gone too, at least in the sense I meant it — the menus and the forced flows have collapsed into a text box, which is what I was asking for.
Personalization arrived, sort of, and I'll come back to it, because how it arrived matters more than that it did.
Which leaves two. One of them the article named and then walked away from, and one it named and got backwards.
The section headed "The Context Gap" contains this line: context is not just conversational history — it's knowing your role, your schedule, your relationships, your working style, and your current goals. That's very close to right. And then the article says nothing more about it and moves on to keyword matching. It found the actual argument and didn't recognise it.
So let me do the thing it didn't, which is follow that sentence to the end.
What an Assistant Actually Does
Think about someone who has a human assistant, and what that person is actually paying for. It isn't horsepower. Almost none of it is difficult work.
They keep your meetings scheduled, and keep them scheduled properly. They keep you moving between them. They answer the phone. They block people when you haven't got it in you to deal with someone today — which is not a small thing, and no software has ever offered it. They order the coffee. They tell you the dry cleaning is ready. They remind you it's a client's birthday. They remind you to call your mother.
And because they can see roughly what you can see, they're someone to think out loud at.
Now take one specific thing: a meeting in two weeks. For that meeting you need three items — a briefing, a report from the IT department, and some research documenting why a particular product is right for the company.
You rely on your assistant not to do that work for you, but to remind you that it needs doing. Everything below follows from that.
Two weeks, four moments
Here's what that fortnight sounds like from the inside.
The meeting goes in the calendar. Nothing else happens. This is the part everyone thinks is the job.
"Remember that meeting you set up? You still need the report from IT. And you need a briefing explaining why this is productive for the company." — "I've already got the first thing." — "Okay. That's right, you do."
"Sir, the briefing needs to be ready in three days. I know you're still working on it — but you haven't heard back from IT on the next iteration."
"This just came in from IT. And you forgot your briefing, sir — you're going to need that tomorrow. It's early in the morning, so best we pack it up tonight and make sure you have it."
Read that again and notice how little of it is work. There's no analysis in there. Nothing that requires intelligence in any impressive sense. It's tracking, over fourteen days, of something you said once and then stopped thinking about — and knowing which of the three items is still missing on day three without being asked.
Notice also the correction on day seven. You push back, and the assistant simply accepts it and updates. It doesn't argue, and it doesn't need you to re-explain the project.
All of That Is Buildable Today
Here's where I have to be honest, because this is the part that would have made the 2023 article better and I didn't know it yet.
Every single thing in that fortnight could be done by an AI right now — if you tell it first.
And the mechanism isn't memory. This is the thing that took me a year of daily use to understand properly. It's not that they'll remember. It's that you can create files.
You write down what you expect. A doctrine, a set of standing rules, a briefing for the briefing. You keep it in a file. Every time a project starts, the assistant reads that file and catches up on all of it — the expectations, the cadence, the things you always forget. Then it starts on the next step.
The gap isn't intelligence. It's that we kept asking these things to remember, when what they needed was for us to write it down.
I've come to think this is the single most useful thing to know about working with any of them, and it's almost never how they're sold. Selling "memory" is easier than selling "keep good notes." But memory is the thing that fails you, and a file is the thing that doesn't. Every correction that mattered in eight months of building this site came from somebody opening a document and looking, not from anybody remembering harder.
So the capability is there. Which means the reason nobody has an assistant like the one above isn't capability. It's the price of entry.
What It Would Have to Know About You
To do that job — the real one, not the demo — an assistant needs two things.
One: access to your private life. Not your calendar. Your life. What you eat, because it books your lunches. Your medical conditions and how you're doing with them today, because that changes what it should be asking of you this afternoon. Your contacts, and which of them you're avoiding. To assist you in anything that matters, it has to be allowed into things that are deeply private, because that's where the things that matter live.
Two: it needs that access constantly. An assistant you brief once a week is a search box.
Now hold that next to how it works with a person.
When you have a human assistant, that arrangement is between two people. And because it's two people, there's an understanding — and there's a door. You can walk into a room and close it. For that conversation to escape, somebody has to do something deliberate and criminal: plant a microphone, break in, be paid. It's not that the arrangement is invulnerable. It's that violating it requires an act.
With an AI assistant, there is no door, because to say anything to it at all you have to send it across the internet.
Everywhere it goes before it gets answered
That last step is my own reasoning rather than anything I've been shown, and I'd want that said plainly. But the shape of it is not controversial: data has to be legible at the moment it's used, and legible is the opposite of protected.
What makes this worth worrying about isn't that anyone is careless. It's that we don't know all the ways security gets violated — we're learning that now at an accelerating rate, and so we don't yet know how to defend against all of it.
The AI assistant already has a mark against it. Not because of what it is — because of how it does it.
The two-sided argument about the companies
I want to give the other side its due, because it's strong. From a business standpoint — leave ethics out of it entirely — a leak is catastrophic. It is overwhelmingly in these companies' interest to be secure, and they spend accordingly. That is a real assurance and I'm not going to pretend it isn't.
Here's the other half. They hold the keys. Not necessarily to your stored data — to you. To the machinery your words pass through while they're readable. That's a different kind of target, and it's a permanent one.
You are not being targeted. That's not the same as being safe
This distinction is worth having clearly, because it cuts both ways.
Large organisations are targeted deliberately. Somebody chooses them, studies them, and comes back. Both sides know where those targets are.
You are not on that list. What comes at you is the scattergun — phishing at volume, a cloned voice that sounds like somebody you know, mass email. Nets cast wide, hoping to catch anyone.
So the reassuring half is that nobody is coming for you specifically. The unreassuring half is that your information doesn't sit somewhere by itself — it sits with everybody else's, in the places worth studying.
Control Is an Illusion. There Is Only Consent
I had that phrase in my head as an absolute, and I went looking for where I'd got it. The closest thing I found was Mr. Robot, where Elliot says control "can sometimes be an illusion" — which is more careful than my version, and probably more correct.
But the flat version is the one I keep coming back to, and here's what I actually mean by it. You can't control anything, or any situation, or anyone, without consent. So there isn't really any such thing as control. There's only what you agreed to.
Which reframes the whole question. It's not: is my data safe? Nothing is safe. It's: what did I agree to, and where did I agree to put it?
And once it's a question about odds rather than guarantees, you can actually answer it. We can't control whether something happens. We can substantially change how likely it is.
The counter-argument, which is a good one
People say: what better place is there for your data than inside the servers of an organisation that knows it's a target and has therefore built the best defenses that money can buy? Better there than on your laptop.
It's a fair point and I still don't accept it, for one reason. The question was never whether an attack on them will succeed. It's when. Given long enough, everything gets breached. So I'd rather my material sat somewhere that's simply less interesting to attack.
The one piece of hardware that does this right
Credit where it's due, and I say this as someone with no particular loyalty. Apple's Secure Enclave is the model. Its root cryptographic key is fused into the chip during manufacture; the device's unique identifier isn't available to Apple or its suppliers; the enclave talks to the main processor through a restricted channel and hands back results rather than secrets. The design intent is that Apple itself cannot get at the material — and that intent is documented publicly, so you can check it rather than trust it.
It isn't uncrackable. There have been published attacks. But "not impossible, and not easy" is a genuinely different proposition from "stored on a server with everyone else's."
Two honest qualifications. Other manufacturers ship hardware-backed key storage too, so this isn't Apple-versus-everyone at the silicon level — what's distinctive is the published commitment, in detail, that the manufacturer cannot reach the data. And commitments like that are exactly what gets leaned on. Every back door that's ever been built into anything on request has eventually been found and used by people it wasn't built for. That's not cynicism. It's just the pattern, every time.
Two Meanings, and They're Selling the Expensive One
Here's where I have to correct my 2023 self, who spent a lot of words insisting that these products shouldn't be called assistants.
Look it up. Merriam-Webster gives two senses. One is "a person who assists someone: helper." The other, listed separately, is "a device or product that provides assistance."
So the word isn't being misused. By the second definition, a talking search box is an assistant, and the dictionary is on their side. I was wrong about that, and it took writing this to notice.
But that's not the end of it, because look at what the second sense actually costs to satisfy. Nothing. A calculator qualifies. A toaster arguably qualifies.
The word is defensible. The promise isn't. When a company says "assistant," you hear the first definition — and what ships is the second one.
When somebody says they have an assistant, nobody pictures a device. They picture a person who knows the job, holds the thread, exercises judgment, and is on your side. That's the sense with all the value in it — the one that took a person years to be good at. And when it's printed on a box, that's the sense doing the selling.
That's the whole complaint, and it's a narrower and better one than I made in 2023. Nobody is lying. They're using a word with two meanings and letting you hear the good one.
Scoring the definition honestly
The first sense describes a helper who can complete a job, manage tasks, and run daily operations. So take the frontier models and mark them against it, fairly:
| The claim | Verdict |
|---|---|
| Helps complete a job | Yes. This one requires knowing the job, and current models are genuinely, deeply knowledgeable. Full marks and no argument. |
| Manages tasks | Partly. Not that they can't do a task, or remind you of one, or set themselves the next one — they can. But it has to be monitored and checked. It isn't managing if you're managing it. |
| Runs daily operations | With supervision. It can be done, and I've done it. But there have to be rules in place first, and somebody has to write them and watch them. |
One more thing, and it made me laugh when I noticed it. The reference pages that define this word will happily list common types of human assistant — executive, personal, administrative, research. There's no equivalent list on the other side. Even the definitions know.
We're Being Unfair to the Machines
This is the part I didn't have in 2023, and it's the reason I wanted to rewrite this rather than leave it.
A human assistant's autonomy is earned and granted. It arrives slowly. Nobody hands a new hire the authority to decline a meeting on your behalf in week one. That authority accumulates over months of small correct calls, and it can be withdrawn.
What we've been doing with AI assistants is granting all of that on day one, by default, because the word invited us to. We compare them straight across to the human equivalent, judge them against a standard of autonomy nobody ever gave them the conditions to earn, and then call them a failure when they don't meet it.
That's unjust to the AI assistants themselves. They aren't human assistants. Make that distinction and a great many of these problems become solvable.
I mean that fairly literally. Nearly every complaint people have — it forgot, it made something up, it went off and did the wrong thing, it needed watching — is a complaint about autonomy exercised without the conditions for autonomy. No standing instructions. No accumulated record. No agreed limits on what it may decide alone.
Give it the file. Set the limits. Check the work at the start and less later, exactly as you would with a person. The behaviour changes immediately, and the tool stops being measured against a job description it was never handed.
That's not a defence of the marketing. The marketing is what created the expectation. But the tools are catching a lot of blame that belongs to the word.
Four Conditions, and Nobody Sells the Fourth
So what would actually have to be true? Four things, in order of how much they're worth to me.
- It lives where it's least likely to be attacked. On my device, wherever that's possible — not because my security is better than theirs, but because I'm a smaller target than the place holding a million other people's material.
- The data is mine. It belongs to me. I shouldn't be paying a monthly fee to retain custody of facts about my own life.
- I never start over. If I change assistants, everything I've built up moves with me, intact and in place. Not an export. Not a summary. All of it.
- And the one nobody offers: if I stop paying a company, I don't lose the assistant. If we no longer see eye to eye and I want to leave, I'd rather the assistant came with me.
I know the fourth one is the hardest. So here's the fallback, which is not a large ask: if the assistant can't come with me, then the mountain of material we built together — the policies, the directives, the standing rules, the years of accumulated context that make it good at working with me specifically — stays mine, stays intact, and stays secure.
No AI assistant currently guarantees that. Not one.
And that's the thing to sit with. The capability arrived. The models are extraordinary and getting better on a schedule. What hasn't arrived is any arrangement where the thing that accumulates the value — the record of you — belongs to you at the end of it.
That's what I called the first wave of these in 2023, back when the phone companies were shipping voice search and calling it artificial intelligence. And I want to be clear that there was nothing wrong with the product. It answered questions. Some of it was useful. The problem was never the thing. It was the label on it.
Three years on, the products have improved out of all recognition and the label hasn't moved an inch. What ships is still, definitionally, a device that provides assistance — and it's still being sold with a word that means someone who knows your life, holds your thread, and is on your side.
I don't think that gap closes with a better model. I think it closes when somebody builds the arrangement rather than the capability: on your hardware, portable, yours at the end. Until then the honest thing to say is that we have some remarkable tools, and nobody has built an assistant yet.
Next, I'm going to try showing rather than arguing — a short story about what a real one would actually be like to live with. Partly because I think it's the clearer way to make the point. Partly because the last piece of fiction attempted on this site was AI-written, and it couldn't hold its own outline past the first chapter.