transcribe

Where Does Your AI Code REALLY Run?

Boundary · 1m · transcribed May 2026
More from Boundary Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Transcript

0:00 So imagine you're in this world that we're talking about. I'm I'm like, I'm going to go back to like this drawing that I had. I'm going to copy and paste it and then like bring it over to the side and then and then clean it up a little bit. The The thing is uh when you're doing this over here, um this is an open air response. There's no way for the model to prevent you from recognizing what this API call is. You can observe this. Now someone might say, uh and why is this true? Because if you're building a coding agent, this coding agent's typically running on a user-owned machine.

0:28 But someone might say that, "Hey, no, actually this is going to run on the labs' machine. The labs will not let you run their run their coding agents on your machine. You have to go into a cloud computer that that ends up running this." So now this is >> Yeah, this is how like Devin was doing it. >> machine. Exactly. Yeah. But it's still even though it's a lab-owned machine, it's user-owned code. If the user is running code, you can't prevent them from doing this because at some point they're going to make an API call and they will go do this. If you're billing them on their API usage, at some point you're going to expose what API call you're making to the end user cuz that's what they're being billed on.

1:06 I mean at some I mean like if you Okay, let's say you're making some API usage over here and you're being billed for this. How are they going to ban you from seeing your own API calls to what what the models are assuming that you're using an API key to go process [music] it?

Summary

The discussion revolves around the implications of using coding agents and API calls in a user-owned versus lab-owned environment. It highlights the challenges of preventing users from recognizing and accessing their API calls, especially when they are billed based on usage.

- Users can observe API calls made by coding agents, regardless of whether they run on their own machines or lab-owned machines.
- The inability to hide API calls stems from the nature of billing users based on their API usage.
- Even in a controlled lab environment, user-owned code can lead to exposure of API calls.
- The conversation emphasizes the transparency required when users are charged for API usage.
- Concerns are raised about the limitations of restricting user access to their own API data.
© transcribe · For agents Built with care and craft by Gokul Rajaram