Šimon Podhajský, Head of AI at Waypoint, presents a counterintuitive argument at AI Engineer Europe 2026: that read-only AI systems are architecturally superior to agent-first approaches for personal intelligence use cases. He introduces the concept of "cognitive exhaust fumes" — the digital activity byproduct of human cognition (emails sent, browser tabs open, journal entries, task lists, CRM interactions, notes) — arguing that, like analyzing exhaust from a car engine, these traces can diagnose the underlying cognitive machine.
Podhajský built a personal AI system called Fulan with six data sources (email, journal, tasks, CRM, browser sessions, and notes) accessed in read-only mode. The system is organized into three zones: read-only sources, a workspace where analysis occurs, and a separate Obsidian vault for outputs the user reviews. Crucially, the AI never writes back to any source.
He identifies three high-value use cases that no single-source tool can surface: intention-action gaps (what you planned vs. what you did), attention drift (where focus actually went vs. where it should be), and relationship decay (contacts you've stopped engaging with). The cross-source signal is the core product — email clients don't know what you journaled, and task managers don't know what you're browsing.
The system runs entirely through Claude Code skills. A weekly reflection skill launches a Python script that ingests all read-only data, calls the Anthropic API to generate structured outputs from prepared prompts, and produces a markdown document. Podhajský demonstrates this live: the output surfaces weekly themes, tensions, commitment gaps, and reflection questions — framing it explicitly as a reflection on how you're thinking, not a productivity report.
A second demo shows a cross-source query: given recent reading (pulled from a Vivaldi SQLite browser database for most-visited and still-open tabs), the system queries a Clay MCP integration (acting as a friend relationship manager/CRM) to find contacts who might be interested in those articles — mapping specific people to specific articles. The system even identified the author of one article as a contact in his network. This synthesis spans four data sources none of which were designed to interoperate.
Podhajský makes a direct risk-asymmetry argument for the read-only constraint: a read error costs nothing (the user ignores it), while a write error in a personal AI context — involving relationships, career, and reputation — is potentially unbounded. Beyond safety, he argues read-only produces better analysis: once AI writes to your data sources, the exhaust is contaminated and you can no longer distinguish your cognitive patterns from AI-modified ones. The observer/agent distinction matters philosophically — you read the reflection and decide what to act on; that mediation is the point.
He addresses the "why not just use Claude on a read-only mount" objection directly: the observer surfaces insights like "you've avoided your most important project for two weeks," while an agent saves 30 seconds on a weather check. He frames observer and agent systems as different product categories, not stages on a maturity ladder.
On security, Podhajský flags two risks: the mosaic effect (cross-referenced data is a high-value target precisely because of its synthesis power) and Simon Willison's "lethal trifecta" (private data + untrusted content + external communications). He acknowledges the system doesn't fully break the trifecta since shell access preserves some external communication capability, and data is transmitted to Anthropic over open networks. His position: knowing your threat model and consciously accepting specific risks is categorically different from ignorance. He open-sourced a GitHub template — personal-intelligence-kit — so others can try the architecture. Context window usage is noted as a practical consideration, with Claude 4.6's one-million-token context making multi-source queries tractable.
Hi, my name is Shimon. Today, I'll talk about a personal AI system that knows you, but won't do anything instead of you or on your behalf, and won't blow up your life. So, that's good. In the process, I'll talk about the risks of personal AI and how read-only AI systems like this one mitigate them. Let's get started. The whole personal AI space is obsessed with agents that act on your behalf. I built something different. The starting point, six sources, read access only, no write permissions. Th...
Mario Zechner, creator of the LibGDX game framework, delivers a provocative three-act talk about building a minimal codi...