Sep 2026

Training My Dragon

Everyone is building personal agents. This is how I would raise mine.

Anuradha Sachdev built and led a fifty-person practice putting agentic AI into production at enterprise scale. This is how she would build her personal agent.

IN BRIEF

Today's personal agents can act. The question is when a person would let one decide on their behalf. People have handed decisions to rules before, when something stood behind the rule.

The one I want is the agent from The Theory of Moss, and it answers to me: I set its rules, its record stays mine, and I train its judgment. What is still missing is the guarantee. The first company to make its agent's mistakes right will be the first one trusted to decide.

The rules we already trust

An errand, a booking, a purchase, an email: a personal agent can do all of those. When would I let it make the choice?

This is an old problem. Economists call it the agency problem: what stops someone acting for you from putting their own interests first? They formalized it in a landmark 1976 paper. The law had an answer long before that: a trustee owes a duty of loyalty, and a fiduciary must put the person it serves first.

People have let rules decide for them before. Each time, something stood behind the rule.

Vanguard is owned by the people who invest in it. There is no separate owner to take the profit. On its retirement plans, workers are enrolled by default and can change it at any time. Across nearly five million workers, participation rose from 65% to 86% as automatic enrollment spread, and nearly seven in ten now let someone else choose their investments.

In Britain, a Direct Debit is standing permission for a company to take payment from your bank. There were five billion Direct Debit payments in 2025. People let the payments happen because the Direct Debit Guarantee means their bank will refund a payment collected in error.

| People handed over the decision because someone would make it right if it went wrong.

I saw it happen in 2003, working on an early generation of search advertising at Yahoo!. Advertisers used to set the price for every keyword by hand, checking several times a day to stay visible. With the redesign, they could set a ceiling and a budget and let software manage the prices within those limits. Later they could give the system a target, and it set the prices. Each step let the system decide more on their behalf.

The personal agent I want

People are turning to AI for help with decisions. Google's AI Mode in Search alone passed a billion monthly users this year. The same systems are beginning to act on those decisions, to run an errand, make a booking, buy something or send an email. That is the moment advice becomes an agent.

The capability is real. Google will call a shop to check what is in stock, or book you a table. Amazon will watch a price and buy when it drops, and can even buy products from some other merchants for you. Apple will translate a conversation as it happens. Instinct, a personal agent, paid one user's tolls, booked his DMV appointment and negotiated with vendors in India while he slept.

The Atlantic, which reported that, also described costly mistakes for other users. That is where it gets serious. A wrong choice costs money, and somebody has to make it right. OpenAI opened checkout inside ChatGPT; it fell short, and Walmart is replacing it with its own chatbot. So the question is no longer what these agents can do. It is who they answer to. A personal agent answers to the person. A company's agent answers to the company.

| Before I let an agent act for me, I want to know who it answers to.

Give the company's agent its due. Meta's Muse, launched in September, has gone further. It asks before a sensitive action and keeps a record of what it has done and plans to do. A second agent, Sentinel, must approve anything it sends out to the internet, and Link covers eligible purchases. Those are real protections.

Each one guards a single action. What I cannot do is set one rule over everything Muse does, such as a total it may spend for me before it has to ask. And when it gets a claim or a reservation wrong, no purchase protection applies, so no one makes me whole. The people it serves do not own it. Muse is Meta's.

In The Theory of Moss, I described the personal agent I would trust to decide for me. It has three qualities. Reach: it does what I cannot, and what I would rather not. Judgment: it knows what to handle, what can wait, and what I never need to see, and it weighs my competing values the way I would. Foresight: it thinks ahead the way I rarely can in the thick of life.

Two conditions make it mine. First, it answers to me: I set the rules it keeps, I can take the record with me if I leave, and it compares every company's offer, not only what the company that built it sells. Second, it keeps the record whole: every interaction, every company compared to every other, my history alongside what is public, and none of it shared without my say. I can challenge what it concludes, and no company can rewrite it. It does not forget.

I have not seen a publicly available personal agent that meets both conditions.

Only part of the personal agent I want is being built. The agents that act, Google's, Amazon's, Meta's and the rest, run the errand, make the booking, watch the price, and any one of them can be swapped for a better one. What cannot be swapped is the rules I set, the record of everything done in my name, and the judgment I keep training, correction by correction.

| The agents that act can be bought. The one that answers to me has to be trained.

So the question becomes: how would I raise mine? What follows is my thinking.

The Trust Gap. A person, labelled decisions, on one side. A personal agent, labelled tasks, on the other. A yellow zigzag between them: the gap a personal agent has to cross before it is handed a decision.

Before the training

My data would be the start of what a personal agent needs to know me. I have bought two televisions in my adult life, and both times I handed the decision to the same friend. I told him roughly the size I wanted and the most I would pay, and he chose. I did not check his answer. He knew what I would care about in a television and what I would not. That came from knowing me, and it is in no database.

My father is the proof from the other side. For five years he has been telling me to buy a new car, and offering to buy it for me. Mine is from 2009, with seventy thousand miles on it. He sees an old car and reads risk. I see a car with miles left in it. He knows me well and wants the best for me. He still does not think the way I do.

That is the gap a personal agent has to cross. Facts are easy to accumulate. The reasoning underneath them is what makes an answer mine.

| The record shows what a person did. It cannot show why.

A personal agent starts knowing nothing about the person it serves. On the first day, the person gives it the digital footprint, the categories of caring, and the rules.

First, the digital footprint. A life already has one: email, calendar, purchases. The person connects it to the agent, and the agent starts by reading it. People already do this for services they trust; I attached my own accounts to Credit Karma years ago. But the digital footprint has a limit. Mine says I rarely buy televisions. It cannot say that I would rather someone else chose the next one.

Second, the categories of caring. A person keeps some decisions, gives the agent others, and there are degrees in between. Eating out: I keep the choice; finding the hole in the wall that only locals know is the pleasure. The television: it decides. Travel: it picks the flight; I pick the hotel. The doctor: it does the research; I make the final call. Each category carries its own permission: what the agent may do without asking, what it must check first, and how much it may spend before it asks. The industry grades its agents by what the machine can take on. This list runs the other way: it starts from where the person wants to stay involved.

Third, the rules, and there are two. The data stays the person's, and the person decides what it shares, with whom, and when. And whatever the agent does is done in the person's name, so it takes the person's side, not the side of the company that built it. Without those two, an agent eager to help will do too much in someone's name.

Those can be set up on the first day. How a person decides has to be taught.

Training my dragon

This is the part I call training my dragon. It is what makes the agent yours, and it takes four steps.

First, the person corrects the reasoning, not the answer. When the agent brings back a wrong answer, the fix goes into the reasoning that produced it. In graduate school I studied design and computation. We wrote algorithms in Mathematica that generated architecture, and when a building failed our criteria we changed the algorithm, not the building. The correction went where the design came from. That is the training.

Second, it learns from what the person does. The mindsets, how a person thinks about love, money and health, matter most, and the digital footprint cannot show them. A questionnaire on the first day gives the agent a start, the way Noom begins with one. The rest it learns by watching.

I saw this while designing a life insurance product for a generation that did not think it needed one. Two women, identical on paper, same generation, same Seattle suburb, both immigrants from India, both real-estate investors, had opposite mindsets about money: one lived for today, the other planned far ahead. Their profiles did not show that. What each did with her money did.

Third, it thinks ahead for the person. When my sister was offered a job at Amazon, her husband ran a spreadsheet and found that the tuition discount at her current employer was worth more to the family than the higher pay. Nobody at either company was going to run that number. A personal agent would.

Fourth, it speaks for the person in rooms they will never enter. Soon it will deal with company agents, not companies. I have seen those rooms. At Yahoo Search in 2003, bidding software watched rival software and moved by a penny. A tool set to hold first place at any cost could be bled by a rival bidding one cent under its cap until the budget was gone. A personal agent will be in rooms like that. It must hold the person's rules, even when another agent pushes against them.

The missing guarantee

A protection stood behind each rule people trusted. Vanguard chooses for its investors, and its investors own it. The advertiser set the ceiling on their spend. The bank refunds the Direct Debit.

An agent that answers to me has the first: it works for me, the way Vanguard works for its investors. The rules I set are the second: my ceiling. The third does not exist yet. Purchase protection is a step toward it on the money side, and that is where it ends. Beyond a purchase, nobody stands behind what a personal agent decides: not the company that built it, not a bank, not a rule. Until someone does, the decisions beyond a purchase stay with me.

| The first company to make its agent's mistakes right will be the first one trusted to decide.

For a company building a personal agent, the question is whose side it is on when the person and the company want different things. The law answered that question for people long ago: a fiduciary puts the person it serves first.

An agent on the company's side will be handed tasks. An agent on the person's side, with rules the person sets, a record that stays theirs, and someone who makes its mistakes right, will be handed decisions. That is the personal agent worth building.

If you want to go deeper

The question started with The Theory of Moss, where I described the personal agent the way I want it. Then a friend asked the next question: how would something like that be built? This essay is my answer. https://www.anuradhasachdev.com/the-theory-of-moss

Most people know How to Train Your Dragon from the film, or the series. Cressida Cowell's book is different. Hiccup goes looking for the clan's manual, which has the same title. Its entire advice is: yell at it. So he has to find another way. He watches the dragon, learns its language, and the relationship becomes the training. That is closer to the agent I want than any setup screen I have seen. You can give it instructions on day one. You cannot yell judgment into it. https://www.littlebrownlibrary.com/titles/cressida-cowell/how-to-train-your-dragon/9780316085274/

I spent months reading, testing and working with what Google, Amazon, Apple, OpenAI and Meta say they are building. For every claim in this essay I went back to the company's own announcement, and some claims did not survive that; my notes on what did run past twenty pages. I download everything: Instinct this month, Replika years ago, if anyone remembers it. The agents got better while I wrote. These two stories mattered most.
https://www.wired.com/story/ai-lab-walmart-openai-shaking-up-agentic-shopping-deal/
https://www.theatlantic.com/technology/2026/09/instinct-ai-personal-assistant-credit-card/688607/

Muse arrived in September with real protections. I asked it whether it was mine or Meta's. It said: "My loyalty is yours; my landlord is Meta." I asked whether what I share with it stays mine. It said: "What Meta's systems may log is the part I can't seal off." That is this essay in two sentences, from the agent itself: whose it is, and whose the record is. The third thing, someone standing behind its decisions, it did not mention.
https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/
https://link.com/terms/purchase-protections

The Vanguard story came to me from the Acquired podcast. Its hosts then wrote in The Wall Street Journal about John Bogle's company as the Costco of investing: owned by the people who use it, so the savings go back to them.
https://www.acquired.fm/episodes/vanguard
https://www.wsj.com/finance/vanguard-costco-acquired-podcast-hosts-bogle-96d97c7d

In Marcos Novak's transarchitecture studio at UCLA, I built a virtual world that was later shown at the Getty Museum. At its center was a Latin palindrome, "In girum imus nocte et consumimur igni": we go round in the night and are consumed by fire. It returns to where it began. Guy Debord took the line for a film title, and the Getty holds his archive. Training a personal agent would work the same way. Each wrong decision would send me back to the reasoning, and that is where I would fix it. https://www.getty.edu/research/special_collections/notable/situationists.html

I built and led the North America customer service experience practice at Accenture Song — fifty people designing and deploying agentic AI at enterprise scale in 2024. I came to this work through architecture and computation, which shaped how I think about systems: why organizations struggle to adapt, where trust is won or lost, and what it takes to make technology work in the real world. If that's the part you're building, I want to hear about it.

Email →