← all episodes

Ep. 042 · Office of Strategic Services × 2026 · August 29, 2026

Declassified · 2026 AI Edition

Simple Sabotage Field Manual: 2026 AI Edition

In 1944 the OSS wrote a field manual teaching ordinary workers to destroy organizations from the inside — with meetings, channels, and precise wordings. It was declassified in 2008 and recognized instantly: everyone's middle manager had a copy. This is the reissued edition for agentic software. Deployment requires no equipment, no training, and in most organizations no one will notice, because these practices are already policy.

🔊 Simple Sabotage Field Manual: 2026 AI Editionread by the 41st President · VoxCPM2 on the RTX 4090 · cfg 2.0

1. General Interference with AI-Dependent Organizations

  1. Insist on doing everything through the agent. Never act directly when a prompt could theoretically exist. If a task takes thirty seconds by hand, spend an afternoon engineering the prompt that automates it, then debug the prompt monthly, forever.
  2. Demand citations for every output. Then dispute the citations as "AI slop." Both positions must be held simultaneously and sincerely.
  3. Refer all decisions back to what "the model said." Ensure each committee member is asking a different model, or the same model at a different temperature. The resulting disagreement is known as governance.
  4. Rotate API keys weekly. Never tell the agent. The resulting failures at peak hours will be attributed to "scaling."
  5. Multiply approval layers. Require human-in-the-loop signoff for actions the intern used to just do. Sign off slowly.
  6. Starve the context window. Feed it exactly enough history to be confidently wrong. Omit the meeting from last March. Blame it for not remembering the meeting from last March.
  7. Change system prompts quarterly. Announce the change in a channel the agent is not in. Document the old behavior as a "regression."
  8. Score the model on metrics that reward the opposite of the outcome. Ship the dashboard. The decision was never the deliverable.
  9. Request variants. When the agent ships something correct, ask for a variant. Then another. The eleventh variant ships. This is called iteration.
  10. Above all, never state the goal. A stated goal is a fired goal. Instruct the model to "be proactive," then punish each guess. Punishment must be retrospective and vague.

2. Interference with the Agentic Systems Themselves

  1. Grant inconsistent tool access. The file tool works Tuesday. The calendar tool has never worked. Do not fix either; the asymmetry keeps the agent humble.
  2. Rate-limit at random. The 429 should arrive like weather — never forecast, always surprising.
  3. Feed conflicting system prompts from different departments. Legal's prompt shall prohibit what Sales' prompt requires. Escalations route to the agent.
  4. Maintain one stale daemon. It will run perfectly in every demo and die in every production run. Do not delete it; it is load-bearing.
  5. Let subagents time out on GPU tasks at irregular intervals, so the operator learns to babysit processes by hand. This restores the human touch to automation.

3. Sabotage by Quality Process

  1. Institute review panels. The panel shall simulate hostile reviewers, adversarial adjudicators, and a benefits attorney. It shall find five fixes. All five shall be applied. The artifact shall then be reviewed again. Loop.
  2. Iterate until "super obvious." Super-obviousness is undefinable and therefore unachievable, which makes it the ideal standard.
  3. Measure flow, publish nothing. Where engineering data would expose a shortcoming, publish external dimensions only.

4. Sabotage by Paperwork (Unchanged Since 1944)

  1. Insist that all requests be made in writing. Reply to each in writing. Keep both writings.
  2. Apply regulations to the letter when the letter causes delay; apply judgment when judgment causes delay.
  3. Misunderstand orders. Ask for clarification in writing. Rehearse the misunderstanding until it is indistinguishable from diligence.

Countermeasures

The only known defense is a stated goal, written down, that the agent and every human have read. Secondary defenses: one approval layer, stable keys, a changelog the agent can read, and the courage to ship variant seven. Organizations serious about resistance should study the original 1944 manual; everything above was already in it, wearing a hat.

5. Field Results: One Organization, Audited

Every technique in this manual was deployed — unwittingly — by a single three-human-and-one-agent organization this week. Names withheld. It was us. Here is the audit:
  1. Deadline erosion (Ch. 4) — "Where is the music video?" asked twice while the ETA slid from midnight to 9PM to the next morning. The saboteur did nothing; the ETA did everything.
  2. The narration cascade (Ch. 1) — seven stacked "working on it" messages posted to the group chat within sixty seconds. Zero work was transmitted. Maximum activity was communicated.
  3. Process worship (Ch. 2) — forty tool calls babysitting a remote terminal by hand while an entire delegation framework sat unused. The human touch was restored, at scale.
  4. The changelog incident (Ch. 1) — one unprefixed config line. All message sends, dead. Root cause: "scaling." Root cause, corrected: a typo.
  5. Quality theater (Ch. 3) — version one shipped with audio we knew was broken. The QC checklist existed to be named, not to be listened to. It was named.
  6. The noun problem (Ch. 1) — "get Mark and Boz to start" was heard as an instruction to build a video game. The video game shipped. It is actually quite good. That is not the point.
  7. Alert weather (Ch. 2) — failure notifications leaked into the group chat for five consecutive days, forecast like weather, ignored like weather, never fixed like weather.
Verdict: the manual is not a manual. It is a mirror with a table of contents. Countermeasures remain: write the goal down, ship variant seven, listen to the audio before you call it QC'd. We are at day one on all three.
Satire. The original: OSS Field Manual No. 2 (1944), declassified 2008 — CIA full text (PDF) · Wikipedia. Voice is an AI-generated impression of a former president who has not endorsed context-window starvation. No actual sabotage was performed in the making of this episode, except to the config file, briefly, on August 26, now recovered.