Podcast

Tommy Eastman: Own Your Intelligence Stack

Four months into running Hermes agent at TFTC, Marty Bent sits down with Noose Research's Tommy Eastman to make the case that the models are the least important leg of the stool, and that handing your company's IP to Anthropic or OpenAI is fast approaching a breach of fiduciary responsibility.

16 min read
Marty Bent and Tommy Eastman of Noose Research discussing Hermes agent and agentic AI on the TFTC podcast
Share

↓ Jump to the video and timestamps

You saw me when Tommy walked in here. I was on what looked like my phone. I was talking to my Hermes agent. That's where I am four to five months into this thing, and it's the reason I wanted to sit down with Tommy Eastman from Noose Research on tape and actually work through why most people are still sleeping on what's happening.

The conversation that exists right now around AI is almost entirely about the models. Which frontier lab is winning. What the new benchmark says. Whether GPT or Claude wrote the better email. That's the wrong frame.

Tommy and I spent the better part of two hours on what actually matters: the file system you feed your agent, the harness that makes it agentic, and why the model underneath is rapidly becoming the least important piece of the three. The models are commoditizing. The second brain and the harness are where the compounding value lives. Most people haven't figured that out yet, and the window to get ahead of it is closing.

There's also something darker going on that I don't think gets called out enough. The biggest frontier labs are actively lobbying against open source, and they're doing it while training on all of our data. I'm not going to be diplomatic about it.

Tommy agrees with me. We get into it.

Key takeaways

  • The models are commoditizing, own the harness and the second brain. The file system and the agentic layer are where value compounds. Models are becoming interchangeable, and being model agnostic is only going to matter more over time.
  • Feeding your company IP to frontier labs is approaching a fiduciary breach. Your training data is being used to build competing products. The enterprises that keep doing it are handing over the secret sauce to labs that will use it to undercut them.
  • Open-source Chinese models running on US infrastructure are not sending your data to China. The distinction is where the inference server lives, not where the model was trained. Connecting directly to DeepSeek servers is a different thing entirely from downloading the weights and running them on US soil.
  • The big-lab push against open source is a ladder-pulling exercise, not a safety argument. If existential AI risk were the real concern, compute consolidation, not open-source distillation, would be the target. The lobbying makes sense as business strategy. It does not make sense as a safety argument.
  • Your agent is only as good as the context you give it. The second brain, structured files, semantic search, a rich knowledge graph, is what separates a chatbot from something that actually moves the business.
  • High-agency individuals have never had more advantage. Whether AI can manufacture high agency in people who don't already have it is the defining question of the next decade, and I genuinely don't know the answer yet.

The Three-Legged Stool Nobody's Talking About

I laid this out on tape and I want to put it in writing because I don't think it's getting enough attention.

There are three legs to an agentic AI system, especially if you're building one for a business. First is the file system, what I call the second brain. That includes your raw files, but also things like semantic search layers, an Obsidian vault for knowledge graph associations, all of it bucketed into one concept: the structured context your agent can reach. Second is the harness, the agentic layer itself. In my case, Hermes.

Third is the model. The two most important legs are the second brain and the harness. The model is the one most people obsess over, and it's the one that matters least over time.

Tommy confirmed where the market is heading directly: nine months ago, by his read, open-source models basically weren't usable for real work. Now he figures about 90% of users can handle 90% of their work with open models. That gap is continuing to close.

I can already switch models mid-session in Hermes with a /model command, cheaper open model for routine tasks, heavier firepower when I need it, a privacy-first open-source model when I don't want the data leaving my stack. The harness makes the model a variable, not a dependency.

Tommy said it well: "The agents are only as good as the data that they are able to access. There's no magic." The file system is the moat. The harness is the executor. The model is increasingly just a commodity input you swap depending on the task and the budget.

What Agentic AI Actually Means, And Why Chatbots Are Not It

The jump from AI chatbot to agentic AI is autonomy. That's Tommy's framing and it's the right one. An agent can carry out tasks without you sitting there monitoring it every minute. A chatbot cannot.

The thing that makes Hermes specifically work for me, beyond the broader agentic framework, is what Tommy calls the self-evolving memory. Hermes stores what he describes as "the primitives of the path" to a solution. So if the agent figures out how to do something once, it can recall that path every subsequent time.

ChatGPT cannot do that. You ask it to do the same task two days in a row and you might get two completely different outcomes. That inconsistency is what kills adoption for real business workflows. You can't build a repeatable process on top of something that doesn't remember how it solved the problem last time.

Here's the concrete version of what this looks like in practice. I'm at a bar, we've just published an episode via Fountain. I voice-text my Hermes agent: find the section of this conversation where we discussed a specific topic, clip the most engaging moment, write a one-sentence description, tag the guest, draft a tweet. Within five minutes, Hermes had used the Fountain MCP, which gives the agent direct access to our published audio and transcripts, found exactly what I described, clipped it, drafted the tweet, and sent it to me for review.

I'm having a beer. That's real work getting done.

The ad deck story is the one that actually moved the revenue needle for us. I connected Hermes to our YouTube API, our Fountain API, and a market research layer for CPM pricing. Now when I want to pitch a potential ad partner, I describe who I want to target and what makes us a good fit, and five minutes later there's an HTML page on Vercel with a deck that can actually close. Accurate stats. Accurate pricing benchmarks. Our specific audience data surfaced and contextualized.

That workflow has led to more closed ad deals. That's the business case right there.

Then there's Martin. My wife was in the market for a car. Instead of her taking over my phone to dig through Telegram, I told her to just email Martin, that's the name I gave my Hermes agent, and that I'd given him permission to email her back. She's been going back and forth with Martin in an email thread, getting car research done.

She'll tell me, "I emailed Martin today and he did some good work for me." That's the form factor working exactly as it should.

And Ed on our team has his own agent. His agent and Martin email each other. If there's a business update Ed's side needs to surface, his agent emails Martin and tells him to update his second brain. We're doing this right now, and I still feel like I'm not utilizing this thing to its full potential.

Your Company's IP Is Being Fed to Labs That Will Compete With You

I brought this up unprompted in the conversation because it's been bothering me and I don't think enough people are connecting the dots.

Latham & Watkins, one of the biggest law firms in the world, recently announced they're buying their own GPUs and self-hosting their model rather than running through Anthropic or OpenAI. I called that a massive signal on tape, and I mean it. Not only does it mean the open-source models are good enough for serious enterprise work, it means the enterprises that are paying attention to their fiduciary obligations are starting to act on them.

Here's the argument I made: if you're running a company and you're feeding your workflows, your client data, your internal processes, your competitive intelligence into Anthropic or OpenAI, you are training the next version of their model on your secret sauce. Those labs are not neutral utilities. They are building competing products.

At some point, and I think that point is closer than most boards realize, shareholders and directors are going to say this is a breach of fiduciary responsibility. You're handing the secret codes to people who are going to use them to try to put you out of business.

Tommy's response was direct: "People are just throwing their trade secrets." He's seen it at the individual level and the enterprise level both. Alex Karp has been making a version of this argument publicly, and Tommy noted that ever since Karp started pushing on data sovereignty, the enterprises they talk to at Noose are much more attuned to where their data is flowing.

The general public is lagging. But businesses are waking up fast, and the signal from a firm like Latham & Watkins acting on it, not just talking about it, is about as clear as it gets.

Open Source Doesn't Mean Chinese Servers, The Distinction That Matters

I want to be clear about this because I see people conflating two very different things, and the confusion is costing them real money and potentially pushing them toward worse privacy outcomes.

If you connect directly to DeepSeek's servers, yes, your data is going to China. That's a real concern and a legitimate reason to avoid that specific setup.

If you download an open-weight model, even one trained in China, and run it on infrastructure owned by a US company in a US data center, your data does not go to China. The model's origin and the inference server's location are two completely different questions. Tommy put the numbers on it: open-source models running on US infrastructure can be 60%, 70%, 80%, 90% cheaper than US closed frontier labs, depending on the model and the task. The stigma around "Chinese model" is causing people to leave enormous cost savings on the table while also staying locked into exactly the data-sovereignty problem they think they're avoiding.

The education piece Tommy and his team are pushing is important: it's where the inference server lives, not where the model was trained, that determines where your data flows.

I'm also bullish on the next layer of this, which is running open-source models in trusted execution environments. The argument, which I've seen Mark Goodwin making clearly, is that even if you're using open source, it doesn't mean decentralized. There's still somebody hosting those servers.

Trusted execution environments, where inference runs in a secure enclave with end-to-end encryption from your device to the output, add a meaningful privacy layer on top. Venice and tools in that space are working on this, and I think it's a massive opportunity. Local models are getting good enough to handle sensitive workloads on consumer hardware too, which adds another option.

The Big Labs Are Pulling Up the Ladder

Tommy's most contrarian take in this conversation is actually the one I agree with most strongly, so I'll frame it as my take too.

The existential-risk argument being used to lobby against open source is disingenuous. Tommy made the logic explicit: if you actually believed that misaligned AI posed an existential threat to humanity, open-source distillation would be the last thing you'd be worried about. Distillation from open models definitionally cannot exceed what the closed frontier labs have already built.

The thing that would actually concern a genuine existential-risk believer is massive consolidation of compute in the hands of two or three companies. Which is exactly what the lobbying serves to protect.

The pattern is not subtle. Raise enormous amounts of capital. Build the infrastructure. Reach a position of market dominance. Then lobby to close the door on open-source alternatives, wrapped in the language of safety.

I've seen this playbook run in every corner of the fiat establishment for years. It looks the same here.

Tommy pointed to the data origin question that makes this even more galling: "Where did all the data come in the first place? It's all of our data that trained it." The labs trained on publicly available human knowledge, a fact now being contested in court, including the ongoing NYT copyright litigation against OpenAI, and now want to use the regulatory state to lock in their position against any open alternative.

I said it on tape and I'll say it here: when you consider how profound of a shift this technology is for humanity, the fact that two or three companies are trying to pull up the ladder and control it all is evil. That's the word I used. I'm not walking it back.

The AI safety blind spot around closed-lab self-auditing is real, and compute consolidation is the actual threat worth worrying about, not open-source models that communities can inspect, fork, and run themselves.

How to Actually Build Your Intelligence Stack

My Hermes story starts at Christmas break. Thirty inches of snow in Philly, the kids are watching a movie, and I decided to finally try OpenClaw. First time I'd ever set up a VM, first time setting up a cloud server.

I went through a YouTube tutorial, got a Hetzner server running, set up OpenClaw, connected it to Anthropic via OAuth before they closed that off. Was immediately blown away.

I spent about four months building out that OpenClaw instance, integrating workflows, seeding the file system. Then around March or April, enough people had replied to my tweets saying to try Hermes that I sat down one Sunday and did it. I literally told my OpenClaw agent on Telegram: spin up a Hermes instance on the server and let me know when it's done.

Hooked up Telegram. Within 24 hours I was telling the Hermes agent to shut down the OpenClaw agent. Haven't looked back.

The form factor that vibes with me is Telegram voice-to-text. I have a group chat with the agent, just the two of us, but the group chat format lets you create topics. So there's an AdOps topic, a Bitcoin Brief topic, a BizOps topic, a newsletter builder topic. Each topic is essentially a persistent session.

I walk around the neighborhood and dictate. I'm in the studio and I talk through how I want to frame the newsletter before I sit down to write it. That's how it clicked for me.

Ed on our team uses the Hermes desktop app. My wife uses email. Noose supports WhatsApp, Telegram, email, and the platform is intentionally not prescriptive about where you interface with it.

What I'd push back on is building your workflow inside Claude Code or Codex Desktop specifically, because that's vendor lock-in, and vendor lock-in is what you're trying to avoid in the first place. Get yourself off that dependency as fast as you can.

The next frontier I'm actively trying to figure out, and I'm being honest that I don't have the skills yet, is post-training. I've got six months of Hermes context and TFTC's full corpus. I want to take an open-source small language model and fine-tune it on that specific data so it knows our business, our voice, our workflows cold.

Tommy confirmed this is actually in Hermes's DNA: Noose co-founder Technium originally built Hermes Agent to help a small AI research lab do exactly this kind of work. If anyone can help me figure out how to get there, let me know. That's where my head is for the next phase.

The High-Agency Question

Tommy said something early in the conversation that I've been turning over since. If you're a high-agency person right now, there's no better time in the history of the world to exist. He can't write code anymore, his words, but he manages compute clusters and pulls all the dashboards and visualizations he needs just by prompting Hermes in natural language. Work that would have required a data scientist and a front-end engineer is now one person interfacing with an agent.

That's the upside case. The question I keep sitting with is the one I raised on tape: is high agency a fixed natural distribution, or can AI tools engender it in people who don't already have it? Can the tools themselves pull someone toward higher agency behavior? Or is there a permanent ceiling set by disposition, and the tools just amplify whoever already has it?

I don't have an answer. I said that on tape and I mean it. I think that's what we're going to find out over the next decade.

The job-market question, permanent underclass or a billion flowers blooming, I think depends entirely on which way that answer falls. Tommy lands somewhere in between, which is probably the honest answer, but I'm not sure "somewhere in between" fully captures what's at stake if a large portion of people can't adapt.

What I'm more confident about is the specific opportunity Tommy described for enterprise: taking your top performers' prompting patterns and delivering them to every employee. Accelerating new-hire onboarding. Shaping agents to reflect how your best people think. That's a real capability Noose is building out, and it's one of the more concrete answers I've heard to the question of what you actually do with this at the organizational level, not just the individual one.

The agentic payments layer is another piece of this that I've been watching closely, agents that can actually transact, not just advise. And the broader question of Bitcoin as the savings layer for an agentic economy is one I think about a lot as these two worlds continue to converge. The sovereignty logic maps directly: own your keys, own your intelligence stack, own the rails your agents operate on.

About Tommy Eastman

Tommy Eastman is a member of the team at Noose Research, the company behind Hermes Agent and Noose Portal. Before joining Noose, he worked at Foundry, where he focused on distributed and decentralized AI. At Noose Research, he works across product, enterprise onboarding, and compute relationships, including managing the inference infrastructure that powers Hermes Agent for hosted users.

Sources mentioned

Watch the conversation

Timestamps

  • 0:07 - Bitcoin and central bank debasement
  • 0:56 - Marty's Hermes origin story
  • 4:06 - What Hermes is and why chatbots aren't it
  • 10:41 - The three-legged stool: second brain, harness, models
  • 15:35 - Models are commoditizing
  • 21:14 - Enterprise IP and the fiduciary breach argument
  • 27:11 - The step-function moment: where AI was nine months ago vs. now
  • 31:35 - Who's using Hermes best and how
  • 38:48 - The ad deck workflow and closed deals
  • 48:47 - Open-source Chinese models vs. Chinese servers, the distinction
  • 50:54 - Post-training an SLM on your own data
  • 52:49 - Noose Research's roadmap and who they're building for
  • 58:25 - Martin, Ed's agent, and agents emailing each other
  • 1:03:27 - The job market: permanent underclass or a billion flowers
  • 1:05:16 - The contrarian take: big-lab lobbying against open source is disingenuous
  • 1:08:50 - Final thoughts on owning your AI stack

Sponsors

Frequently Asked Questions

What is Hermes Agent and how is it different from ChatGPT?

Hermes Agent is an agentic AI harness built by Noose Research that enables autonomous task execution, persistent memory, and full model agnosticism. Unlike ChatGPT, which resets context between sessions and cannot reliably reproduce results on repeated tasks, Hermes stores the path it found to a solution and recalls it every subsequent time. That reproducibility is what makes it usable for real business workflows rather than one-off queries.

What does "model agnostic" mean and why does it matter for my business?

A model-agnostic harness can connect to any AI model, open-source or closed, cheap or expensive, without locking you into a single provider. It matters because models are commoditizing rapidly: the gap between frontier closed models and capable open-source alternatives has closed dramatically in the past nine months. Being model agnostic means you can route tasks to cheaper or more private models as needed, and you're not dependent on any one lab's pricing, terms of service, or data practices.

Is it safe to use open-source AI models trained in China?

It depends entirely on how you run them. If you connect directly to a Chinese lab's servers, your data goes to those servers. If you download the open weights and run the model on US infrastructure in a US data center, your data stays on US soil.

The model's country of origin and the inference server's location are two separate questions. Running a Chinese-trained open-source model on US infrastructure is not the same as sending your data to China.

What is the three-legged stool of an agentic AI system?

The three legs are: the second brain (your file system, structured context, documents, knowledge graphs, semantic search layers your agent can access), the harness (the agentic layer that gives the system autonomy and memory, like Hermes), and the models (the AI models doing the inference). The second brain and the harness are where durable value compounds. The models are increasingly a commodity you swap based on task, cost, and privacy needs.

How do I build a second brain for my AI agent?

Start by collecting the files, documents, and structured data most relevant to your work and giving the agent access to them. For deeper capability, you can layer in semantic search so the agent can retrieve relevant context efficiently, or a knowledge graph tool like Obsidian to capture associations between concepts. The principle is simple: the agent is only as good as the context you give it. The richer and more organized the file system, the more useful the agent becomes over time.

Why are enterprises moving away from OpenAI and Anthropic to self-hosted models?

Two reasons converging at once. First, open-source models have reached a point where they can handle the vast majority of enterprise workloads, often at a fraction of the cost of closed frontier labs. Second, enterprises are increasingly aware that feeding internal workflows and proprietary data to external labs means that data may be used to train future competing products. Self-hosting eliminates both the cost problem and the IP exposure problem simultaneously.

What is a trusted execution environment (TEE) and how does it improve AI privacy?

A trusted execution environment is a secure computing enclave where code runs in isolation, encrypted from the hardware up. When AI inference runs inside a TEE, your prompts are encrypted in transit, processed in the secure enclave, and the output is encrypted before it leaves. This matters even with open-source models because someone is still hosting the server, a TEE adds a meaningful privacy guarantee on top of the open-source foundation, ensuring that even the infrastructure operator cannot read your queries or outputs.

Keep reading

All of TFTC

The Commoner

Truth for the Commoner, every weekday. Money, machines, and the people trying to control both.

Independent writing by Marty Bent at TFTC since 2017. Money, markets, AI, energy and privacy, delivered free to your inbox.

Free, every weekday. Unsubscribe anytime using the link in each newsletter. By subscribing you agree to our Terms and acknowledge our Privacy Policy. Read recent issues.