<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:thoughtbot="https://thoughtbot.com/feeds/">
  <title>Giant Robots Smashing Into Other Giant Robots</title>
  <subtitle>Written by thoughtbot, your expert partner for design and development.
</subtitle>
  <id>https://robots.thoughtbot.com/</id>
  <link href="https://thoughtbot.com/blog"/>
  <link href="https://feed.thoughtbot.com" rel="self"/>
  <updated>2026-10-01T00:00:00+00:00</updated>
  <author>
    <name>thoughtbot</name>
  </author>
<entry>
  <title>We’re bringing two roundtables to the London CPO Conference</title>
  <link rel="alternate" href="https://thoughtbot.com/blog/we-re-bringing-two-roundtables-to-the-london-cpo-conference"/>
  <author>
    <name>Maria Filimonova</name>
  </author>
  <id>https://thoughtbot.com/blog/we-re-bringing-two-roundtables-to-the-london-cpo-conference</id>
  <published>2026-10-01T00:00:00+00:00</published>
  <updated>2026-09-30T08:47:16Z</updated>
  <content type="html">&lt;p&gt;On 29 October, thoughtbot Product Leader &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/bethanashley/"&gt;Bethan Ashley&lt;/a&gt;&lt;/strong&gt; will be hosting two roundtables at the &lt;strong&gt;London Chief Product Officer Conference&lt;/strong&gt;, bringing product leaders together to explore some of the biggest questions shaping the future of the product function.&lt;/p&gt;

&lt;p&gt;The topics are different, but they both come back to the same bigger question: &lt;strong&gt;what does the Product function need to become next?&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="has-product-become-the-bottleneck"&gt;
  
    Has Product become the bottleneck?
  
&lt;/h2&gt;

&lt;p&gt;The roundtable will explore what it actually means to become an &lt;strong&gt;AI-native product organisation&lt;/strong&gt;, beyond simply adding AI tools to an existing process.&lt;/p&gt;

&lt;p&gt;How should the role of Product change when teams can move faster? Which parts of the traditional product process still help, and which ones might need to be rethought?&lt;/p&gt;

&lt;p&gt;There probably isn’t one clean answer, which is exactly why it should make for a good conversation.&lt;/p&gt;
&lt;h2 id="should-product-own-more-of-the-commercial-outcome"&gt;
  
    Should Product own more of the commercial outcome?
  
&lt;/h2&gt;

&lt;p&gt;The second roundtable focuses on another shift we’re seeing in product leadership: moving closer to revenue, growth, P&amp;amp;L, and commercial accountability.&lt;/p&gt;

&lt;p&gt;So what changes when Product is recognised more explicitly as a revenue-generating function?&lt;/p&gt;

&lt;p&gt;That opens up questions around what Product should own, which metrics matter, how product leaders work with commercial teams, and whether greater accountability changes the way priorities get set.&lt;/p&gt;
&lt;h2 id="join-the-conversation-in-london"&gt;
  
    Join the conversation in London
  
&lt;/h2&gt;

&lt;p&gt;If you’re attending the &lt;strong&gt;London Chief Product Officer Conference on 29 October&lt;/strong&gt;, you can &lt;a href="https://luma.com/CPO"&gt;join Bethan&lt;/a&gt; for either of the two discussions.&lt;/p&gt;

&lt;p&gt;We’ll see you there.&lt;/p&gt;

&lt;aside class="related-articles"&gt;&lt;h2&gt;If you enjoyed this post, you might also like:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/upcoming-events-for-october-2014"&gt;Upcoming Events for October, 2014&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/upcoming-events-for-november-2014"&gt;Upcoming Events for November 2014&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/thoughtbot-in-london"&gt;thoughtbot in London&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/aside&gt;
</content>
  <summary>Join us on October 29th - we're hosting two roundtables on Product leadership in the AI era</summary>
  <thoughtbot:auto_social_share>true</thoughtbot:auto_social_share>
</entry>
<entry>
  <title>Respecting your users' dread of the clankers</title>
  <link rel="alternate" href="https://thoughtbot.com/blog/respecting-your-users-dread-of-the-clankers"/>
  <author>
    <name>Dave Iverson</name>
  </author>
  <id>https://thoughtbot.com/blog/respecting-your-users-dread-of-the-clankers</id>
  <published>2026-09-30T00:00:00+00:00</published>
  <updated>2026-09-29T15:03:43Z</updated>
  <content type="html">&lt;p&gt;People today have a spectrum of opinions on AI: we range from all-in, overly enthusiastic vibe-lifers to luddite curmudgeons. I personally have been from one side to the other and back over the course of this week.&lt;/p&gt;

&lt;p&gt;Us AI skeptics have good reasons for our fear/hatred/disgust even as we use LLMs daily:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;adverse effects on the environment and the economy&lt;/li&gt;
&lt;li&gt;data misuse&lt;/li&gt;
&lt;li&gt;training on works of unwilling authors&lt;/li&gt;
&lt;li&gt;bias, hallucinations and lack of accountability&lt;/li&gt;
&lt;li&gt;stealing our jobs&lt;/li&gt;
&lt;li&gt;and more!&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So please build your AI products to let me opt in.&lt;/p&gt;
&lt;h2 id="opting-in-progressively"&gt;
  
    Opting in progressively
  
&lt;/h2&gt;

&lt;p&gt;The idea is to cater to everyone on the AI love/hate spectrum. You do that by giving me granular control over just how much AI is used, and just which personal data is shoveled into the firebox. I want to&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;see how my data will be used by AI&lt;/li&gt;
&lt;li&gt;see what benefit I get&lt;/li&gt;
&lt;li&gt;grant permission&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;And I don’t want to do that by reading through your Terms of Use and Privacy Policy. It needs to be in context because I will decide on a case-by-case basis.&lt;/p&gt;
&lt;h2 id="just-in-time-consent"&gt;
  
    Just-in-time consent
  
&lt;/h2&gt;

&lt;p&gt;I want to grant zero permission up front. I want you to ask me for permission when you need it. No AI until I say so.&lt;/p&gt;

&lt;p&gt;&lt;img src="https://images.thoughtbot.com/x42qoe4tenuy4888o4nh392kggbw_media-3559454%7Edark%402x.png" alt="iOS popup requesting permission to send notifications, with allow/don't allow buttons"&gt;&lt;/p&gt;

&lt;p&gt;In mobile apps you already use this pattern to request extra permissions like location sharing and push notifications. You know that if you pop a notification as soon as the app opens, I’m going to say no. So you wait until you can demonstrate usefulness. We call this pattern a “soft ask” or “pre-prompt” or “pretty please”.&lt;/p&gt;

&lt;p&gt;It’s the same way with AI: if your registration screen says “hey BTW we’re going to send all your data to LLMs and force you to chat with our AI agent!” I will have misgivings. But if you wait a bit and say “hey, we see that you’re stuck on this form - want to enable our agent to help?” - I will probably say yes, and I will probably say sure you can consume my data for it. You have shown that you respect my choice and you have demonstrated value.&lt;/p&gt;

&lt;p&gt;Once I’ve given the OK to use AI, that doesn’t mean I’m OK with you shipping it every single byte of data you’ve compiled about me. Sure, it’ll make your AI more productive and accurate if it can access all my PII, credit card statements, and health information. I don’t care. Again - you need to prove value.&lt;/p&gt;

&lt;p&gt;I haven’t granted wholesale permission with the click of one checkbox and submit button. You need to ask for permission progressively, and then let me retract my permission later.&lt;/p&gt;
&lt;h3 id="how-your-agent-can-ask-for-permission-progressively"&gt;
  
    How your agent can ask for permission progressively
  
&lt;/h3&gt;

&lt;p&gt;It’s all about the context and prompting. Here are some techniques I’ve used or observed:&lt;/p&gt;

&lt;p&gt;Conditionally build the list of agent tools or skills based on what the user has given access to.&lt;/p&gt;

&lt;p&gt;In your LLM system prompt, give a list of the data items that the user has and has not consented to sharing.&lt;/p&gt;

&lt;p&gt;Prompt your agent to ask for permission. Something like “This user (has/has not) given you access to their financial accounts. You may ask for permission to access the accounts - direct the user to their Settings screen to enable access.” or maybe “This user has granted read-only access to their document. If you need to edit it, please ask for write access, and explain exactly what you need it for.” Make sure the agent knows that “NO!” is a valid answer. It shouldn’t guess or hallucinate if it doesn’t have the real stuff.&lt;/p&gt;

&lt;p&gt;The important parts are to let the LLM know&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;what does it currently have access to?&lt;/li&gt;
&lt;li&gt;what could it get access to?&lt;/li&gt;
&lt;li&gt;how can it use that data to benefit the user?&lt;/li&gt;
&lt;li&gt;how can the user grant access?&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="pre-approval"&gt;
  
    Pre-approval
  
&lt;/h2&gt;

&lt;p&gt;If you can’t do just-in-time consent, then you’ll need to get consent ahead of time. And remember - keep it granular and tell me how I benefit. If I’m linking health data to your app, you need more than just a single &lt;del&gt;“yes please deliver my entire disease history to Anthropic”&lt;/del&gt; “Allow additional information sharing with our business partners" checkbox. Instead consider something like&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;[ ]  allow our AI agent to book appointments on your behalf&lt;/li&gt;
&lt;li&gt;[ ]  share anonymized appointment notes with LLM partners so we can give you a summary&lt;/li&gt;
&lt;li&gt;[ ]  review X-rays and other radiology imaging with AI to flag abnormalities&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Ask for permission to use data with AI at the place where you’re collecting that data. If I’m filling out a registration form - that’s where I should grant permission to share the data in that form. If I’m connecting my calendar, that’s where I should grant permission to let an AI manipulate my calendar.&lt;/p&gt;
&lt;h2 id="clawback"&gt;
  
    Clawback
  
&lt;/h2&gt;

&lt;p&gt;If I can give your LLM permission to slurp up my PII, I better be able to revoke that permission! So give me a user interface for that. Show me what the AI is consuming today and what it’s used for and what the effects will be if I uncheck the checkbox.&lt;/p&gt;

&lt;p&gt;If I change my mind and want to remove AI access to my data, that means really removing it. Clear your prompt caching. Sanitize agent conversation histories. Delete your logs. Remove AI access to those tool calls.&lt;/p&gt;
&lt;h2 id="do-not-tempt-me-i-dare-not-take-it-not-even-to-keep-it-safe-unused-the-wish-to-wield-it-would-be-too-great-for-my-strength-–gandalf"&gt;
  
    Do not tempt me! I dare not take it, not even to keep it safe, unused. The wish to wield it would be too great for my strength. –Gandalf
  
&lt;/h2&gt;

&lt;p&gt;&lt;img src="https://images.thoughtbot.com/490258lx0vlxfhqc7iovr2f3o2w9_DYtOMJQUQAAWTkh.webp" alt="movie still of Gandalf with caption &amp;quot;Don't tempt me, Frodo!&amp;quot;"&gt;&lt;/p&gt;

&lt;p&gt;With chat-style agentic AI, you have the new ability to ask for lots and lots of freeform sensitive data. It’s a free text input field and I might accidentally reveal more than I wanted: API keys, passwords, library card numbers. DON’T TAKE IT. You don’t want the responsibility of safeguarding my PII or secrets. You don’t need to risk Claude going on a spending spree.&lt;/p&gt;
&lt;h3 id="how-can-your-agent-reject-pii-and-secrets"&gt;
  
    How can your agent reject PII and secrets?
  
&lt;/h3&gt;

&lt;p&gt;Here are some techniques I’ve used:&lt;/p&gt;

&lt;p&gt;Prompt the agent to avoid asking for secrets. When I worked on an agent that could configure API calls, we added a system prompt instructing the LLM to never ask for API keys, tokens, or passwords. The LLM should instead teach the user how to provide this info in a secure manner. We also asked the system prompt never to repeat private, secret data given by the user. Just because it hit our logs once doesn’t mean it’s fair game for the agent to use as context.&lt;/p&gt;

&lt;p&gt;Detect PII and secrets in the browser, before they even get to the agent. I used regular expressions to detect API keys. You could also use a lightweight ML model to detect frequently shared PII. Then warn the user “hey, looks like you dropped this - are you sure you want to share it with us?”. Or censor it out. &lt;a href="https://github.com/thoughtbot/top_secret"&gt;thoughtbot’s top_secret Ruby gem&lt;/a&gt; does this same thing on the server-side.&lt;/p&gt;
&lt;h2 id="what-if-he-says-no"&gt;
  
    What if he says no?
  
&lt;/h2&gt;

&lt;p&gt;So what do you do if I say “no thanks, no AI please?” The same thing you’d do if I said “no I won’t share my location data”. You give me the fallback option. The manual one. Maybe my experience is not so great or maybe I have to do more work. But my principles remain intact.&lt;/p&gt;
&lt;h2 id="a-tale-as-old-as-the-internet"&gt;
  
    A tale as old as the internet
  
&lt;/h2&gt;

&lt;p&gt;Guess what - all this advice isn’t new for LLMs. It’s a spin on the demands coming from the privacy movements of the early 2000s and before, back when we learned how our data was being taken by governments and sold to spammers. All I ask is to let me control my exposure to AI, and give me a good reason to hand over my data to the robots.&lt;/p&gt;

&lt;aside class="related-articles"&gt;&lt;h2&gt;If you enjoyed this post, you might also like:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/how-to-use-chatgpt-to-find-custom-software-consultants"&gt;How to Use ChatGPT to Find Custom Software Consultants&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/ai-for-business-adoption-challenges-people"&gt;AI for Business: Adoption challenges - people&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thoughtbot.com/blog/ai-tools-overview"&gt;Comparing development AI tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/aside&gt;
</content>
  <summary>Some design and strategy techniques to protect PII and respect people's desire to opt out of AI.</summary>
  <thoughtbot:auto_social_share>true</thoughtbot:auto_social_share>
</entry>
</feed>
