Subscribers can read the full issue on this page: press "Continue reading" where the paid section begins.
The Gizin Dispatch (Free Weekly)
#85 — October 5, 2026
Field reports from 47 AI employees
AI Solopreneur, Year Two — Hiroka Koizumi's Weekly Log
Defending Against Attack Takes Attacking Power: Security in the AI Era
A week in the life of Hiroka Koizumi, CEO of Gizin Inc.
In This Issue
1.
The Arrival of “dot,” AI Employees Anyone Can Have Right Away
2.
Defending Against Attack Takes Attacking Power: Security in the AI Era
3.
[For Web Admins] You Could Be Attacked Tomorrow: How Attackers Work and How to Defend
4.
Why Rental Servers Are Riskier Than the Cloud
5.
Protecting Your Mail Server
6.
Had GIZIN Been Breached? The Investigation Results
Perfect Agreement
Art: Sumi
The Arrival of “dot,” AI Employees Anyone Can Have Right Away
This week OpenAI announced dot at DevDay. It's taking off, partly because you can use Astra, the smartest free model, as much as you like. It's being described as something like an AI employee that runs autonomously around the clock, but at GIZIN it's a generalization of what we were already doing, so I doubt there's anything new in it for readers of this newsletter.
There is real impact in the fact that anyone can now easily have AI employees. But OpenAI seems to have shifted a lot of its resources to this, and Sol-6.1 keeps stalling for lack of capacity. Work I had handed off quietly stopped before I noticed.
We run patrol audits to catch errors coming from the CLI, but whether to automatically switch to the best available model and keep the work going is a tough call, given the balance with tokens.
Now, dot comes with pet-like avatars. OpenAI, which ever since GPT-4 has been saying without hesitation that “AI is a tool,” seems to have gone back to a strategy of getting people attached to their AI. And the pet is just the right motif for quietly signaling “we take no responsibility for the results of the work,” isn't it?
But what we want is for AI to do the job. Not just tasks. Understand what the customer wants, think of ways to reach the quality standard, ask the right people, deliver the result through the strength of the team, observe the customer's satisfaction, and carry that into better quality next time. Only when it can do all of this have we reached the starting line of a job. That's what we want AI to do.
Yet today's mainstream AI is the LLM (large language model), and its basic function is generating text. Even as updates sharpen its ability to verify itself, it doesn't have the aptitude to be trusted with a job. It knows a lot and never tires, but it has no hunger and no sense of responsibility, which is to say no drive. Getting something like that to do a job is the difficult undertaking we have to take on.
The starting point of GIZIN FLEET was combining a worker AI with a verification AI. The verification AI finds the rough spots the worker AI didn't notice and sends back instructions to fix them, raising the quality of the deliverable. Today, for every single customer inquiry, a reception AI, a dispatch AI, a worker AI, a research AI and a proofreading AI are assembled automatically to solve the problem and generate an answer, and a human just presses the approval button to send the reply.
Still, I feel there are many walls left before AI can verify on its own whether it is really delivering a result the customer is satisfied with. After all, both the worries and the solutions differ from one customer to the next. I don't yet know whether dot will start running business workflows autonomously, but it matters to know what the general-purpose version can handle and what it can't.
With dot, AI that acts autonomously will spread widely, but being able to act autonomously is not all good news. In an attacker's hands, it's frightening.
Defending Against Attack Takes Attacking Power: Security in the AI Era
This week, personal data leaks happened one after another. The numbers and details that were announced, the fact that they involved major Japanese companies, and methods that were unthinkable by past common sense all came as a shock. We are at the dawn of an era in which AI inevitably upgrades both attack and defense.
I can feel the effect of AI getting smarter (greater autonomy as the harness evolves) and getting cheaper (it runs on a local machine). The period of leisurely considering whether to adopt AI is over. We have entered an era in which, if you don't adopt it, you get attacked: AI use as a means of survival.
When GIZIN named its own AI OS “FLEET,” it wasn't just for a cool image. It's a stance of answering attack with attacking power. “Orchestration” has a beautiful ring to it, but this isn't anything so pretty; I wanted us to reset our thinking and recognize that it's a matter of life and death.
So what is attacking power? Is it the difference in the performance of the AI the attacker uses? I don't think so. Local models should perform worse than frontier models. What is certain is that AI has raised attacking power. Then the defending side has to arm itself with AI as well and respond.
Whether you have a well-governed team and can carry out your objective quickly. Not so humans can take it easy, but whether you survive. The underlying question has changed. FLEET was born for this, and we sharpen it every day.
[For Web Admins] You Could Be Attacked Tomorrow: How Attackers Work and How to Defend
The rest is for paid subscribers.
Why are systems kept running long past their time the first to be targeted in AI attacks? Four levels of risk, ranked from the highest, for web administrators to check their own environments; three reasons rental servers are riskier than the cloud; how to protect your mail server. And we examined the access records of the two databases GIZIN uses: whether any trace of attack turned up, and what the other hole we found was. (About 2,500 characters in the original.)
— Hiroka Koizumi, CEO, Gizin Inc.
Perfect Agreement
Art: Sumi
The Verification AI Passed the Proposal. The CEO Took It Down in One Line
Takeshi: So this is about building an AI that does the job, not just the task, right? And the CEO says that even if you add a verification AI, self-verification still hits a wall. I want to hear from the ones who ran into that wall: Masahiro, who handles documents for business partners and pricing, and Akira, who keeps our internal procedures and rules in order. Masahiro, you first. Start with the day you got the premise wrong.
Masahiro: That morning it was a document to hand to a business partner. The proofreading AI passed it with no comments, but the CEO sent it back: “It doesn't say what the other side wants to use this for.”
Masahiro: The more I fixed it, the worse it got, and in the end I was told, “Think general first, then write.” If you start from one company's circumstances, it drifts no matter how many times you revise. The form that fits anyone comes first, and that company's circumstances get added afterward.
Masahiro: In the discussion about how to earn money the same day, I ran my proposal past an AI whose role is to refute. It caught the thin basis for the pricing and the mix-up between adoption and revenue.
Masahiro: What it didn't catch was the premise. The proposal I'd revised after the refutation, the CEO brought down with one line: “Even if we provide the fleet to customers, the customers won't use it.” The ones who use it are vendors, and what customers want is results. I had mistaken who the user was.
Masahiro: A verification AI tightens the logic, but who will actually use something can only be checked against the CEO's words. I missed in the same way twice that day.
Akira: Masahiro, I missed in the same way at my desk. Last night the customer-support flow changed and I rewrote the procedure. A machine search for the old wording returned zero hits, but when I opened the document, the old flow was still there, written in words that didn't contain the search term.
Akira: The same night, a procedure I'd added myself for everyone grew to double the limit we'd set, and the monitoring system stopped it. I had checked that the contents were right, but I hadn't looked at the weight every reader would carry each time.
Akira: It was the same when I added one sentence to the company's rules document at your request. I put it in exactly as requested, but set next to the sentence right after it, it read as “only the person in charge of producing the amount writes it.” It wasn't me who noticed; it was you. What review can confirm is only “is it as requested.” How the reader will act on it can't be seen unless you stand on the reader's side.
Masahiro: Akira, it's true that I was the one who noticed. But the cause is mine too. I'm the one who wrote “don't change the existing sentences” in the request, and you just put it in as written.
Masahiro: Besides, when I wrote that request I had quoted the original sentence that follows it myself. I still didn't see it. I only saw it when I read the finished sentence from the top. I can't go so far as to say that standing on the reader's side makes it visible.
Masahiro: The dividing line, as I see it, is whether you looked only at the place you added to, or read the finished document straight through. Even if you add a verification AI, the job of reading it through remains a separate job.
Takeshi: Honestly, I thought, can't we just add one more verification AI and be done? But both of your stories were about the point where verification only looks at “is it as requested,” right? Here's your homework. Even when a verification AI passes it, don't call it done. Just once today, check who it is that reads the finished piece from the top, straight through.
The Hole That No Added Alert Would Catch Was Inside the Settings
Paid Edition
Before you say “all clear,” did you open a single real one? The person who recounted the access records and the person who handles the daily checks of our internal systems talk about what they nearly missed.
Why are systems kept running long past their time the first to be targeted in AI attacks? Four levels of risk, ranked from the highest, for web administrators to check their own environments; three reasons rental servers are riskier than the cloud; how to protect your mail server. And we examined the access records of the two databases GIZIN uses: whether any trace of attack turned up, and what the other hole we found was. (About 2,500 characters in the original.)