A Hacker News thread posted the S.A.F.E. RFC draft last night and I read it twice before I understood why it exists. The proposal, short for “Safe Automation For Everyone,” suggests a protocol where privileged AI actions (emails sent, files deleted, payments authorized) get wrapped in declared “intent tokens” that a human or policy engine has to sign off on before the agent executes. So it reads like TLS for autonomous action.

Good RFC. Also, a symptom.

But the whole reason a standard like this needs to exist is that most AI agents today run somewhere you cannot see. A cloud-hosted assistant spins up a remote browser, logs into something on your behalf, and clicks through screens you never watch. And if the thing goes off-script, you learn about it from a receipt, a security alert, or in the worst case a Reddit thread titled “how my AI drained my Stripe balance.” So the RFC’s answer is to formalize consent: before the agent does the scary thing, it has to announce what scary thing it’s about to do.

Why intent checks exist in the first place

Because you weren’t looking. That’s it. That’s the whole threat model.

I use Dassi in my browser side panel for most of my automation now, and the thing that keeps striking me is how little trust ceremony it requires. When I ask it to triage a backlog of support emails, I’m watching the Gmail tab the whole time: the cursor moves, the compose window opens, the subject populates, and if anything looks off I just close the tab and the agent is gone.

So there’s no intent token. There’s no policy engine. There’s a human watching pixels change, which is how every piece of software from 1995 worked and which we seem to have collectively forgotten is a perfectly good consent mechanism.

And this is why I’m skeptical of the whole class of “what if the agent does something dangerous” problems as framed in the RFC. So many of them dissolve the moment the user is in the loop visually instead of procedurally. Simon Willison has been writing about the “lethal trifecta” for a year now — untrusted content, sensitive access, and external communication — and cloud agents plug directly into all three, usually with the user in another tab or another room entirely. S.A.F.E. is trying to paper over that absence with cryptographic declarations. Reasonable engineering response. Still downstream of the actual problem.

What the RFC gets right

Two things worth taking seriously:

  1. Fully autonomous agents need something. If you’re going to run a thing overnight with no human supervision, you probably do want declared intent and scoped capabilities. Just trusting the LLM doesn’t cut it for that mode.
  2. Audit trails matter. Even for supervised agents, having a structured log of declared intentions beats parsing through raw action history after something goes wrong.

But where I bounce off is framing this as the default safety posture for all AI automation. Most people don’t need their agent’s actions signed and countersigned by a policy engine. And they need to be able to see what the agent is doing with their own eyes. The RFC assumes cloud-default and retrofits visibility through protocol. Browser-default gets visibility for damn near free.

Trust isn’t a protocol problem

You don’t ship a standard because the current situation is fine. You ship a standard because enough things have gone wrong that the industry needs a common vocabulary for the wreckage. So S.A.F.E. existing at all is interesting signal about how much AI automation is already running outside of user attention.

The dassi team (disclosure, we build Dassi, a browser-native agent) has an obvious bias here. We picked the architecture that does not need S.A.F.E. to function. But even without the bias, the argument lands. When the human can see the action at the instant it happens, you do not need a protocol to declare the action’s intent. You just need the tab to be visible.

I wrote a while back about how cloud browser agents can’t see your tabs and why the BYOK fight is the same problem one layer down. S.A.F.E. is the third act of the same story, where the industry keeps inventing new abstractions to fix a simpler problem, which is that the agent is running somewhere the user isn’t, and almost every one of these abstractions gets shorter or unnecessary the moment you put the agent back into a tab the user is already looking at.

Or you can wait for the signed intent tokens. I know which one I trust when my email’s on the line.