All Posts

You Are the Man in the Middle: How We Quietly Handed Over the Conversation

July 19, 2026    6 min read

You Are the Man in the Middle

We spent a decade bracing for the dramatic version of the AI takeover — the one with red eyes, a server farm, and a machine that decides humanity is inefficient. It didn't arrive that way. The takeover was quieter, and it went straight through you. It looks like a person at 4 p.m. copying an answer out of a chat window, pasting it into a Teams thread with "hope this helps," and moving on to the next ticket. No red eyes. Just Ctrl-C, Ctrl-V.

The question we keep asking has already been answered

"Will the robots ever govern us?" is the wrong question, because it assumes control changes hands by force — a takeover, a threshold, a single line crossed. It never does. In organizations, authority changes hands the way it always has: through delegation. Nobody schedules the meeting where you hand over your judgment, which is exactly why you don't notice it happening. There was no meeting. There were a thousand small pastes.

Let's be honest about what most "AI adoption" actually looks like day to day. It isn't autonomous agents rewiring the business. It's a human receiving a question, forwarding it to a model, and forwarding the model's answer back — a courier who has stopped opening the envelopes.

You are the man in the middle

Borrow a term from security. A man-in-the-middle attack is when something slips between two parties and relays their messages while both sides still believe they are talking directly to each other. It's dangerous for one specific reason: it's invisible. The trust between the two people stays intact. The channel does not.

Now look at your own week with that definition in hand. A colleague asks you something in Slack. You pass it to an LLM. You pass the LLM's answer back. Your colleague believes they are getting you — your experience, your read on their situation, your judgment about the thing they can't see but you can. What they are actually getting is a model's output, relayed by a person who has been quietly reduced to a transport layer.

That is the whole picture. You are the man in the middle of your own conversation. The trust is intact. The channel is compromised. And the compromise is invisible precisely because the packet still has your name on it.

The tell is that nobody reads the reply

Here's where it stops being a clever metaphor and starts being the actual problem.

There is a version of this that is fine — good, even. You ask a model to draft something, you read it, you catch the two things it got wrong about your context, you rewrite the tone, you add the caveat only you know about, and you send it as yours because it is yours now. That's augmentation. That's a human in the loop.

Then there's the version I see everywhere: the reply gets pasted without being read. The model wrote it, the human transported it, and nobody in the chain actually decided anything. That's not augmentation. That's abdication wearing a human's name badge.

The man-in-the-middle who doesn't inspect the packet isn't a participant in the conversation. He's a wire. And the difference between the two versions — the one that helps and the one that hollows you out — is not the model. It's whether you read the reply.

We got here one paste at a time

The uncomfortable part is that no single paste was wrong. Each one was reasonable. It's faster. It's probably more polished than what you'd have typed. You're busy, the queue is long, and the answer looks right.

But delegation compounds. Hand over how you phrase things, then what you recommend, then how you answer the routine ticket, then how you answer the not-so-routine one — and stack enough of those, across enough people, and the model is effectively steering the organization's decisions, its tone, its institutional memory. Not because it seized anything. Because we kept handing it the next small thing, and Teams and Slack turned out to be a very efficient delivery mechanism for output nobody owns.

This is the mundane mechanics of "the robots govern us." It was never going to look like a coup. It looks like autocomplete for your professional judgment, accepted one keystroke at a time.

Who owns the unread answer?

Now put an enterprise hat on, because this is where it gets expensive.

When you paste an unread LLM answer into a work channel as your professional response, you have created an accountability vacuum. The organization believes a competent human vetted that answer — that's the entire reason your name carries weight. Nobody did. If it's wrong, who's responsible? The model has no accountability. You've outsourced the judgment but kept the liability. And in any regulated context — anything touching compliance, customer commitments, or the sort of decisions the EU AI Act cares about — "a human was nominally in the loop but didn't read it" is not a defense. It's the finding.

The value a human was supposed to add was never the typing. It was the judgment, the verification, and the accountability. Strip those out and you haven't made a human more productive. You've removed the human and left the signature.

Be a human in the loop, not a man in the middle

I'm not arguing you should stop using these tools. I use them constantly, and anyone selling you the Luddite position is wasting your time. I'm arguing for one small, non-negotiable discipline that separates the two roles:

  1. Read the reply. All of it. If you don't have time to read it, you don't have time to send it under your name.
  2. Add the thing only you know. Your context, the caveat, the "actually, in our case." That's the part the model structurally cannot have.
  3. Own it. Send it as your words because you've made them your words. The test: if it were read aloud in the room as your professional opinion, would you stand behind every line? If not, don't send it.

That's the entire difference between a human in the loop and a man in the middle. The loop is the point — it's judgment, verification, and ownership closing back on the output. Remove the loop and you're not augmented; you're bypassed, in your own chair.

I've spent years arguing that the model is the easy 20% and the discipline around it — the verification, the oversight, the willingness to be responsible for the output — is the 80% that actually decides whether a system is trustworthy. That's true for production AI systems. It turns out it's just as true for a Slack reply. The person who pastes without reading has done to themselves exactly what a badly-built AI product does to its users: shipped an unverified answer and hoped.


The Bottom Line: The robots don't need to seize control while we're handing it over one message at a time. The line between augmentation and abdication is a single, boring act of will — whether you read the reply before you send it as your own.