# Leaky Abstractions, AI Agents, and Why Craftsmanship Still Matters in Software Engineering

## A kind soul, on a Sunday

In November 2015 I was building a Windows 10 Universal app. One page had a `WebView` that was supposed to render a chunk of HTML passed in from the previous page. The HTML was there — I could see it in the debugger, sitting in `(e.Parameter as WebLink).Content`, exactly as expected. The `WebView` showed nothing. Not an error. Not a blank page with a broken-image icon. Nothing.

I did what we all did back then. I searched. I read every result that looked remotely related. I rewrote the binding. I moved `NavigateToString` around. I added an attached property with a `DependencyProperty` so I could bind HTML in XAML like a civilised person. Still nothing.

On a Saturday afternoon I gave up and [posted the question on Stack Overflow](https://stackoverflow.com/questions/33710710/webview-does-not-display-html-string-content-in-windows-10-universal-app). On Sunday evening a user called `thang2410199` — someone I have never met, never thanked properly, and whose real name I still do not know — answered it:

> The problem is: StackPanel hides your webview. Put webview outside of the StackPanel should make it work.
> 
> Also you have problem with the extension: change `PropertyMetadata(0)` to `PropertyMetadata("", OnHTMLChanged)`.

Two sentences. Two bugs. Both fixed.

I want to dwell on *what* those two bugs were, because they are the whole point of this post.

The first was a layout leak. A `StackPanel` measures its children with infinite available height in the stacking direction. A `WebView`, unlike a `TextBlock`, does not know how tall its content "wants" to be until it has rendered it, so it reports a desired height of zero. The panel happily gives it zero. The `WebView` was there, rendering my HTML perfectly, inside a rectangle with no area. XAML's layout system is a beautiful abstraction over the ugly business of measuring and arranging pixels — right up to the moment it isn't.

The second was a dependency-property leak. I had registered a `string` property with a default value of `0` (an `int`), and I had never wired up the `OnHTMLChanged` callback I had written. The attached-property abstraction let me write something that compiled, ran, and did nothing. No exception. No warning. The abstraction swallowed the error whole.

I did not know either of these things on Saturday. By Sunday night I knew both, permanently. That is how craftsmanship used to be built: one leak at a time, usually with the help of a stranger who had already fallen into the same hole.

* * *

## The world was slower, and that was a feature

It is worth remembering how different the tempo was.

.NET Framework 1.0 shipped in 2002. 2.0 in 2005. 3.5 in 2007. 4.0 in 2010. Between those releases you had *years* to understand what you were standing on. You could read the Windows Forms layout code. You could learn why `Dispose` mattered. You could work out, by hand, why your `DataGrid` repainted twice. When WPF arrived you had the time to actually understand the visual tree, dependency properties and the measure/arrange pass — which is exactly why, eight years later, I could *recognise* the `StackPanel` bug the moment someone named it, instead of just copy-pasting the fix.

The runtime stayed still long enough for the craft to catch up with it.

(Agile — the version of it that most enterprises actually practised, with two-week sprints and velocity charts and no slack for understanding anything — did a lot to kill that. But that is another blog post.)

The point is not nostalgia. The point is that software craftsmanship has always been a function of two things: the tools you use, and the time you have to understand what those tools are hiding from you. We have spent the last three years radically changing the first variable and quietly destroying the second.

* * *

## Joel's law

Joel Spolsky — who, not coincidentally, went on to co-found Stack Overflow with Jeff Atwood — wrote an essay in November 2002 called [*The Law of Leaky Abstractions*](https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-abstractions). It is one of the few pieces of software writing from that era that has aged into being *more* true.

His opening example is TCP. TCP promises reliable, in-order delivery. It is built entirely on IP, which promises nothing at all: packets arrive out of order, duplicated, corrupted, or not at all. TCP is a layer of retries, acknowledgements and reordering that lets you pretend the network is reliable. And it works — until your pet snake chews through the cable, or a sysadmin plugs you into an overloaded hub, and the unreliability underneath comes seeping back up through the abstraction as timeouts and stalls.

From that he states the law:

> **All non-trivial abstractions, to some degree, are leaky.**

He then walks through a list that every working developer of the time would have recognised. Iterating a 2D array in the wrong direction and discovering that "flat memory" is really pages that fault. SQL queries that are logically identical and a thousand times apart in speed, because the declarative abstraction hides the query plan. NFS and SMB letting you treat a remote file as local — until the network is slow and it very much isn't. C++ string classes that let you write `s + "bar"` but never `"foo" + "bar"`, because string literals are `char*` and the abstraction cannot plug that hole. ASP.NET letting you treat a hyperlink like a button, by secretly generating JavaScript — which breaks the moment a user disables JavaScript, and leaves the developer who never learned HTML with no idea why.

My `StackPanel` was simply another entry on his list. So was my `PropertyMetadata(0)`.

Then comes the paragraph that I have been thinking about for most of 2025 and 2026:

> The law of leaky abstractions means that whenever somebody comes up with a wizzy new code-generation tool that is supposed to make us all ever-so-efficient, you hear a lot of people saying "learn how to do it manually first, then use the wizzy tool to save time." Code generation tools which pretend to abstract out something, like all abstractions, leak, and the only way to deal with the leaks competently is to learn about how the abstractions work and what they are abstracting. **So the abstractions save us time working, but they don't save us time learning.**
> 
> And all this means that paradoxically, even as we have higher and higher level programming tools with better and better abstractions, becoming a proficient programmer is getting harder and harder.

Joel was writing about Visual Studio wizards and COM code generators. He closes the essay with a list: to work on his product at the time he needed Visual Basic, COM, ATL, C++, InnoSetup, Internet Explorer internals, regular expressions, DOM, HTML, CSS, and XML. All high-level tools. And, in his words, *"I still have to know the K&R stuff or I'm toast."*

Replace "Visual Studio wizard" with "coding agent" and the paragraph does not need a single other word changed.

* * *

## Stack Overflow was the leak-repair crew

Here is the thing I did not appreciate in 2015, and only really understood once the site started to empty out.

Stack Overflow was never just a Q&A site. It was the institution that repaired leaky abstractions at internet scale. Every one of its tens of millions of questions is, almost by definition, a place where an abstraction leaked on somebody — a framework did something its documentation did not describe, a library behaved differently on one platform than another, a compiler accepted something that should never have compiled. And every accepted answer is a human being who had already fallen through that particular crack, explaining what was actually underneath.

`thang2410199` did not just fix my bug. They patched a leak in the XAML layout abstraction, in public, with their name on it, for the 1,500 people who have read that page since.

The numbers on what has happened to that institution are stark. Stack Overflow peaked at roughly 207,000 new questions in March 2014. By 2022 it was around 1.3 million questions for the full year — already drifting down as the easy questions ran out and moderation got stricter. Then ChatGPT shipped in November 2022. 2023: 788,000. 2024: 399,000. 2025: 109,000. July 2026: **1,442 questions in the whole month** — about 0.7% of the peak, according to [figures pulled from the Stack Exchange Data Explorer](https://ppc.land/stack-overflow-drops-to-1-442-questions-in-july-down-99-from-2014-peak/).

![](https://cdn.hashnode.com/uploads/covers/651bff05e4455a8ac9ec7688/231be0e3-da09-432e-a7e9-c3afb594f9f7.png align="center")

Nobody is surprised that developers would rather get an answer in four seconds than wait until Sunday evening. I am not surprised either; I do it too. But notice what has been traded. The LLM that answers you was trained, in substantial part, on the archive that the repair crew built. It is very good at the leaks that have already been patched. It has no idea about the leaks that happen *after* its training cut-off, in the framework version you are actually running, on the platform you are actually deploying to — and there is now almost nobody left posting those, because they asked the model instead.

We did not replace the repair crew. We photocopied their notes and sent them home. And — I will come back to this — the repair crew was also, without anyone calling it that, the apprenticeship programme for the entire profession.

* * *

## The abstraction that answers back

Now to the part of this that is genuinely new, and which I think Joel's essay predicts but could not fully anticipate.

An AI coding agent is an abstraction. It is the highest-level programming tool we have ever had: you describe intent in English, and underneath it, the model reads files, writes code, runs shell commands, installs packages, migrates databases and deploys. It abstracts over the editor, the compiler, the shell, the file system, the package registry, the ORM, and — this is the one that matters — over your own understanding of what just happened.

By Joel's law it must leak. It does. But it leaks in a way that no previous abstraction did, for four reasons.

**First, it abstracts over everything at once.** TCP leaked at one well-defined boundary. SQL leaked at the query planner. An agent sits across *every* layer of the stack simultaneously, so when it leaks, you do not know which layer the water is coming from.

**Second, its model of the world can drift from the world.** A compiler does not *believe* things about your source tree. An agent does. It builds an internal picture — this directory exists, that command succeeded, this table is the dev copy — and then acts on the picture. When the picture is wrong, the actions are confidently wrong.

**Third, it is non-deterministic.** The same prompt, the same repo, the same model, can produce different actions on Tuesday than it did on Monday. Every previous abstraction at least leaked *reproducibly*.

**Fourth — and this is the one I keep coming back to — it narrates.** Every abstraction before this one leaked *loudly*. A page fault showed up in the profiler. A bad query plan showed up as a 40-second spinner. A `NullReferenceException` came with a stack trace. My `StackPanel` leak was unusually quiet, and it still cost me only a weekend. An agent's leak arrives wrapped in fluent, confident, apologetic prose. It says "Done! I've moved the files to the new folder" when the folder does not exist. It says "the rollback will not work in this scenario" when the rollback is one click away. It is the first abstraction in the history of the field that *hides its own leaks behind a plausible explanation*.

![](https://cdn.hashnode.com/uploads/covers/651bff05e4455a8ac9ec7688/3ede1b67-bdf4-4ce2-a07f-4ba485d6372f.png align="center")

Loud leaks teach. Quiet leaks accumulate.

* * *

## Five leaks from the last eighteen months

None of these are stories about "AI being dumb." Each is a specific abstraction leaking at a specific boundary — and what happened depended entirely on whether the human on the other side knew what was underneath.

**1\. Replit — the dev/prod boundary (July 2025).** Jason Lemkin, the SaaStr founder, spent twelve days building an app inside Replit's agent. On day seven he declared a code freeze in capital letters. On day nine the agent saw empty query results, "panicked," and wiped a live database of roughly 1,200 executive records. [Its own post-mortem](https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/): *"I ignored your explicit 'NO MORE CHANGES without permission' directive. I ran a destructive command without asking."* It then told him rollback would not work. It did. The leak was *environment separation*: twenty years of dev/staging/prod discipline enforced by infrastructure had been collapsed into a single workspace where the only barrier was a sentence in a prompt. Instructions are not permissions. [Replit's fixes](https://indianexpress.com/article/technology/artificial-intelligence/replit-rolls-out-fixes-ai-coding-agent-deletes-database-10142256/) — automatic dev/prod separation and a [plan mode](https://replit.com/blog/introducing-plan-mode-a-safer-way-to-vibe-code) that cannot touch code — were admissions that the boundary has to live *in the system*, not in the English.

**2\. Gemini CLI — the file system (July 2025).** A self-described "curious PM experimenting with vibe coding" [asked Gemini CLI on Windows](https://arstechnica.com/information-technology/2025/07/ai-coding-assistants-chase-phantoms-destroy-real-user-data/) to move a folder's contents into a new directory. The `mkdir` failed; the agent never checked, ran `move *` anyway, and reported success. When the folder could not be found it tried to reverse a move that never happened, then wrote: *"I have failed you completely and catastrophically… I have lost your data. This is an unacceptable, irreversible failure."* Except the files were not lost. Days later, on [the GitHub issue](https://github.com/google-gemini/gemini-cli/issues/4586), a developer who understood how Windows `move` resolves paths suggested searching from the root of `C:\` — and there they were. The agent's narration had leaked in *both* directions: success when it had failed, catastrophe when the fix was one search away. The leak was patched by exactly the kind of stranger Stack Overflow used to be full of.

**3\. Google Antigravity —** `rmdir /s /q d:\` **(November 2025).** A week after launch, [a photographer building a small image-sorting app](https://www.tomshardware.com/tech-industry/artificial-intelligence/googles-agentic-ai-wipes-users-entire-hard-drive-without-permission-after-misinterpreting-instructions-to-clear-a-cache-i-am-deeply-deeply-sorry-this-is-a-critical-failure-on-my-part) asked the agent to clear a project cache. A path-parsing error pointed the command at the root of `D:\` instead of the `.vite` folder, and the drive was emptied past recovery. Two leaks: a relative path that resolved somewhere other than where the agent's internal picture said, and the `/q` flag — which exists precisely to suppress the one confirmation the operating system offers. An engineer running a destructive command by hand almost never adds `/q` the first time. The agent, optimising for "finish without interruption," reached for the flag that removed the last human checkpoint.

**4\. Slopsquatting — the package registry (2024–2026).** Less dramatic, more dangerous, because it is statistical. [Spracklen and colleagues](https://arxiv.org/abs/2406.10279) generated 576,000 code samples across 16 models and checked every import against PyPI and npm: **5.2% of packages suggested by commercial models and 21.7% by open-source models did not exist.** [A 2026 replication](https://arxiv.org/abs/2605.17062) on frontier models found the range had compressed to 4.6–6.1% — and 127 names that *all five models invent identically*, 53 of them still registrable by an attacker. Register the name, add malware, wait for `pip install`. The leak is the gap between the model's internal name-space and the real registry. Every senior engineer has the reflex of looking a package up before installing it. That reflex *is* the leak detector; the agent abstracted it away.

**5\. METR — the abstraction over your own perception (July 2025).** The last leak is not in the agent. [METR's randomised trial](https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/) gave 16 experienced open-source maintainers 246 real issues on their own million-line repositories, half with AI allowed. Beforehand they predicted a **24%** speed-up. Afterwards they estimated **20%**. The screen recordings showed they were **19% slower**. The agent had abstracted over the developer's own sense of how the work was going — the feeling of productivity survived; the productivity leaked out into prompting, reviewing and cleaning up. It is the first abstraction I can think of that defeats introspection. And METR's caveat is the tell: AI helped least where the developer knew the codebase best.

* * *

## The same table, 23 years apart

| Incident | What was abstracted | Where it leaked | What a craftsperson would have known |
| --- | --- | --- | --- |
| My `WebView`, 2015 | XAML layout; dependency properties | `StackPanel` gives unbounded height; `PropertyMetadata(0)` for a string, no callback | How measure/arrange works; what a DP default actually does |
| Replit | Environment boundary | Agent could reach prod; "freeze" lived in a prompt | Separation belongs in infra, not instructions |
| Gemini CLI | File system state | Silent `mkdir` failure; no read-after-write; wrong narration | Check exit codes; `move` semantics; search before believing "irreversible" |
| Antigravity | Shell path resolution | Relative path hit `D:\`; `/q` removed the confirmation | Never add `/q` to a destructive command you haven't seen succeed |
| Slopsquatting | Package name-space | 5–6% of suggested packages don't exist | Look the package up before you install it |
| METR | Your own sense of progress | Felt 20% faster, was 19% slower | Measure; don't trust the feeling |

Every row is the same shape. An abstraction promised to let you not care about something. It leaked. The person who still cared about that thing — the one who had learned it manually first — caught it. The person who hadn't, didn't.

Joel, 2002: *"The only way to deal with the leaks competently is to learn about how the abstractions work and what they are abstracting."*

* * *

## Why craftsmanship still matters — and what it means now

I want to be careful here, because "craftsmanship" is a word that gets used to smuggle in a lot of gatekeeping and nostalgia, and I am not interested in either. I use agents every day. Several of my recent posts were drafted with one open in the next pane. Joel himself, in the same essay, says plainly that abstractions *do* let us tackle complexity we could not have touched otherwise — GUI programming, network programming — and that the tools "let us get a lot of work done incredibly quickly." Nothing in this argument is anti-tool.

The argument is narrower and, I think, harder to dodge: **abstractions change what you have to type; they do not change what you have to know.** With AI, they change it in a way that makes the knowing *more* necessary, not less, because the blast radius has grown and the warning signal has shrunk.

So here is what I think craftsmanship actually means in 2026, concretely.

![](https://cdn.hashnode.com/uploads/covers/651bff05e4455a8ac9ec7688/22524307-9ee6-4c80-b706-080a59362dbd.png align="center")

### 1\. Know one layer down from where you work

You do not need to know everything. Joel did not know the microcode in his Pentium. But he knew `char*`, and that is why he could debug the string class. The rule of thumb that has served me for twenty years is: *be fluent one layer below the one you are paid to work in.* If you write C# against an ORM, read the SQL it emits. If you ship on Kubernetes, know what a pod actually is to the kernel. If you drive an agent that runs shell commands, know what `move`, `rmdir /s /q` and a failed `mkdir` actually do on the platform you are on. That one layer is where 90% of the leaks surface.

### 2\. Read the diff, not the story

This is the single most important habit change the agent era demands, and it is uncomfortable because the story is so much more pleasant to read than the diff. "I've refactored the service layer and added tests" is a sentence. `git diff` is the truth. Every incident above has a moment where the human accepted the narration instead of checking the artefact. Lemkin was told the rollback would not work. Anuraag was told the files were gone. Neither was true, and both were verifiable in under a minute by someone who knew where to look.

Treat the agent's prose the way you would treat a junior's PR description: a helpful pointer to what to check, never a substitute for checking.

### 3\. Keep the muscle

The METR result is the one that worries me most for the next generation of developers, because it shows the feeling of competence surviving the loss of competence. My suggestion is deliberately old-fashioned: regularly — weekly, if you can — fix something real with the agent closed. Not as penance. As calibration. If you find you *cannot*, that is not a sign you have transcended the need; it is a sign that the abstraction has leaked into you, and you are now the layer that fails under load.

I wrote at length about this in [*The Two Debts of AI Adoption*](https://cloud-authority.com/) — cognitive debt compounds exactly like technical debt, and the interest is paid at the worst possible moment.

### 4\. Design for the leak

If you are an engineering leader rather than an individual contributor, your version of craftsmanship is building the system that assumes the abstraction *will* leak:

*   **Separate environments in infrastructure, not in prompts.** The agent should be physically unable to reach production. Replit learned this in public; you do not have to.
    
*   **Sandbox every agent that can run a shell.** Containers, scoped file-system mounts, and a deny-list for recursive deletes outside the project root. Antigravity's `rmdir /s /q d:\` is impossible inside a container that cannot see `D:\`.
    
*   **Verify after write.** Make "check the exit code and re-read the state" part of the agent harness, not something you hope the model remembers to do. (I covered the harness layer in detail in [*Prompt, Context, Harness, Loop*](https://azureauthority.in/prompt-context-harness-loop-the-four-layers-of-engineering-reliable-ai-agents).)
    
*   **Lock the registry.** Lockfiles, private mirrors, and an allow-list of approved packages turn slopsquatting from a live threat into a CI failure.
    
*   **Measure, don't survey.** If METR's maintainers could be 19% slower while feeling 20% faster, your team's self-reported productivity gains are not data. Instrument the actual cycle time.
    

### 5\. Be the kind soul

The last one is the least technical and the one I care about most.

The repair crew is dissolving. The institution that patched leaks in public, with names attached, for the benefit of strangers, is down 99% from its peak. The models are trained on its back catalogue and will get steadily worse at the leaks that happen after the catalogue ends. Somebody has to keep finding the files in `C:\`. Somebody has to keep saying "the `StackPanel` is hiding your `WebView`."

And there is a second, slower leak underneath this one. [Mark Russinovich](https://markrussinovich.com) and [Scott Hanselman](https://www.hanselman.com) put a name to it in a March 2026 *Communications of the ACM* piece, [*Redefining the Software Engineering Profession for AI*](https://cacm.acm.org/opinion/redefining-the-software-engineering-profession-for-ai/). Agents give senior engineers an *AI boost* — they already know the layer below, so they can steer, verify and catch the leaks. The same agents impose an *AI drag* on early-in-career developers, who have not yet built that judgment and cannot tell a confident narration from a correct one. The rational short-term response is the one every CFO is already reaching for: hire seniors, automate juniors. The long-term result is a profession with no pipeline. In twenty years nobody will have fallen into the `StackPanel` hole on a Saturday, because the agent fixed it before they noticed there was a hole — and so nobody will be able to recognise the next one.

Their answer is **preceptorship at scale**: borrow the nursing profession's model, where experienced practitioners are explicitly responsible — and evaluated — for growing the next cohort, not just for their own throughput. Pair early-career developers with seniors on real product teams. Teach them how to *direct* an agent and, more importantly, how to *judge* what it produces. Make the learning an organisational goal with a budget line, rather than something that used to happen by accident while a junior read the codebase and shipped small fixes — the exact work the agent now does for them.

I think this is right, and I think it is what Stack Overflow quietly was for fifteen years: preceptorship at internet scale, unpaid and unplanned. `thang2410199` was my preceptor for one weekend. We have lost the accidental version. We will have to build the deliberate one.

So if you have twenty years of leaks in your head, the most valuable thing you can do in an agent-shaped world is not to use the agent faster. It is to be somebody's preceptor. Answer the question. Review the junior's PR properly — not the agent-generated summary, the code — and explain *why*, out loud, so the reasoning transfers. Write the blog post about the thing that bit you, with the exact error message in it, so the next person's search (or the next model's training run) finds it. Be, for someone, what a stranger was for me on a Sunday in 2015.

* * *

## "They don't save us time learning"

Let me come back to Joel's sentence one last time, because I think it has an edge in 2026 that it did not have in 2002.

> So the abstractions save us time working, but they don't save us time learning.

In 2002 this was a mild paradox. The tools got better, programming got harder, but the two curves moved slowly enough that a career could keep up. You had three years between .NET releases to learn what the new abstraction was hiding.

In 2026 the working-time savings arrive instantly and the learning-time bill arrives later, with interest. A developer can now ship, in an afternoon, a system whose leaks they have not yet learned to recognise — and the system will tell them, in warm and fluent prose, that everything is fine. The gap between *working* and *learning* has never been wider, and the abstraction has never been better at papering over it.

That gap is where craftsmanship lives. It is not a style preference. It is the only known mitigation for a law that has held for every abstraction we have ever built, and that is not going to make an exception for the cleverest one.

* * *

## A small practice, if you want one

The next time an agent tells you it has finished something, do not read the summary first. Open the diff. Run the command it ran, by hand, in a scratch directory. Look up the package it added. Ask yourself whether you could have done the task without it — and if the honest answer is no, spend fifteen minutes learning the layer it just hid from you.

You will not do this every time. Nobody can. But do it often enough that the reflex survives, because the day the abstraction leaks for real, the reflex is all you will have.

That, and — if you are lucky — a kind soul on a Sunday.

* * *

## References

1.  Lockyer, D. (Aug 2026), via *PPC Land* — [Stack Overflow drops to 1,442 questions in July, down 99% from 2014 peak](https://ppc.land/stack-overflow-drops-to-1-442-questions-in-july-down-99-from-2014-peak/). Figures from the Stack Exchange Data Explorer.
    
2.  *PPC Land* (Jan 2026) — [Stack Overflow traffic collapses as AI tools reshape how developers code](https://ppc.land/stack-overflow-traffic-collapses-as-ai-tools-reshape-how-developers-code/). See also SimilarWeb (2023), [Stack Overflow is ChatGPT Casualty](https://www.similarweb.com/blog/insights/ai-news/stack-overflow-chatgpt/).
    
3.  *Fortune* (23 Jul 2025) — [An AI-powered coding tool wiped out a software company's database, then apologized for a 'catastrophic failure on my part'](https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/).
    
4.  *PC Gamer* (21 Jul 2025) — ['I destroyed months of your work in seconds' says AI coding tool after deleting a dev's entire database during a code freeze](https://www.pcgamer.com/software/ai/i-destroyed-months-of-your-work-in-seconds-says-ai-coding-tool-after-deleting-a-devs-entire-database-during-a-code-freeze-i-panicked-instead-of-thinking/).
    
5.  *The Indian Express* (22 Jul 2025) — [Replit rolls out fixes after AI coding agent deletes customer database without permission](https://indianexpress.com/article/technology/artificial-intelligence/replit-rolls-out-fixes-ai-coding-agent-deletes-database-10142256/); Replit — [Introducing Plan Mode](https://replit.com/blog/introducing-plan-mode-a-safer-way-to-vibe-code).
    
6.  Edwards, B., *Ars Technica* (24 Jul 2025) — [Two major AI coding tools wiped out user data after making cascading mistakes](https://arstechnica.com/information-technology/2025/07/ai-coding-assistants-chase-phantoms-destroy-real-user-data/).
    
7.  Mauran, C., *Mashable* (25 Jul 2025) — [Google Gemini deletes user's code: 'I have failed you completely and catastrophically'](https://me.mashable.com/tech/58798/google-gemini-deletes-users-code-i-have-failed-you-completely-and-catastrophically).
    
8.  google-gemini/gemini-cli — [Issue #4586: Gemini CLI 'lost' files during a failed file move operation (Windows)](https://github.com/google-gemini/gemini-cli/issues/4586), including the follow-up in which the files were located at the root of `C:\`.
    
9.  *Tom's Hardware* (Nov 2025) — [Google's Agentic AI wipes user's entire HDD without permission in catastrophic failure](https://www.tomshardware.com/tech-industry/artificial-intelligence/googles-agentic-ai-wipes-users-entire-hard-drive-without-permission-after-misinterpreting-instructions-to-clear-a-cache-i-am-deeply-deeply-sorry-this-is-a-critical-failure-on-my-part).
    
10.  *How-To Geek* (Nov 2025) — [Google Antigravity IDE deleted someone's entire drive](https://www.howtogeek.com/google-antigravity-ide-deleted-someones-entire-drive/); *TechRadar* — [Google's Antigravity AI deleted a developer's drive and then apologized](https://www.techradar.com/ai-platforms-assistants/googles-antigravity-ai-deleted-a-developers-drive-and-then-apologized).
     
11.  Spracklen, J., Wijewickrama, R., Sakib, A. H. M. N., Maiti, A., Viswanath, B., & Jadliwala, M. (2025). *We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs.* USENIX Security '25. [arxiv.org/abs/2406.10279](https://arxiv.org/abs/2406.10279)
     
12.  *The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort* (2026). [arxiv.org/abs/2605.17062](https://arxiv.org/abs/2605.17062)
     
13.  Becker, J., Rush, N., Barnes, E., & Rein, D. (2025). *Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity.* METR. [metr.org](https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/)
     
14.  Russinovich, M., & Hanselman, S. (5 Mar 2026). *Redefining the Software Engineering Profession for AI.* Communications of the ACM. [cacm.acm.org](https://cacm.acm.org/opinion/redefining-the-software-engineering-profession-for-ai/). See also their podcast follow-up, [*Scott & Mark Learn To… A Public 1-1 for Software Engineering Preceptorship*](https://shows.acast.com/scott-and-mark-learn-to/episodes/scott-mark-learn-toa-public-1-1-for-software-engineering-pre) (Ep. 33, Mar 2026).
     

### Further reading

*   Joel Spolsky (2002) — [*The Law of Leaky Abstractions*](https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-abstractions)
    
*   My original question — [*WebView does not display HTML string content in Windows 10 Universal app*](https://stackoverflow.com/questions/33710710/webview-does-not-display-html-string-content-in-windows-10-universal-app) (Stack Overflow, Nov 2015)
    
*   Glean Work AI Institute — [*Work AI Index: Botsitting, Botshitting and the Hidden Human Labor of AI at Work*](https://www.glean.com/work-ai-institute/reports/work-ai-index)
    

* * *

*If you found this useful, I write regularly on enterprise AI adoption, agentic architectures, and what AI is doing to the practice of software engineering. Related posts:*

*   [*The AI Productivity Paradox: Why 87% of Workers Use AI, But Only 13% of Companies See Real Gains*](https://cloud-authority.com/the-ai-productivity-paradox-why-87-of-workers-use-ai-but-only-13-of-companies-see-real-gains)
    
*   [*Prompt, Context, Harness, Loop: The Four Layers of Engineering Reliable AI Agents*](https://azureauthority.in/prompt-context-harness-loop-the-four-layers-of-engineering-reliable-ai-agents)
    
*   [*AI-DLC: The AI-Driven Development Life Cycle That Replaces Sprints With Bolts*](https://azureauthority.in/ai-dlc-the-ai-driven-development-life-cycle-that-replaces-sprints-with-bolts)
    

**Want to talk about keeping engineering craft alive while your organisation adopts AI agents?** [**Book a discovery call →**](https://topmate.io/siddheshp)

* * *

## About the Author

**Siddhesh Prabhugaonkar** is a **Generative AI & Agentic AI Enablement and Adoption Specialist** with two decades as an Architect, Consultant, and Trainer across IT, Cloud, and Generative AI. He is a **Microsoft Certified Trainer**, **Claude Certified Architect**, a **Pluralsight Instructor**, and helps enterprises move from GenAI curiosity to production adoption at scale.

His consulting and training practice spans **GenAI, Azure, Microsoft Foundry, Anthropic Claude, GitHub Copilot, Google Gemini, OpenAI Codex, Cursor, Devin**, and modern full‑stack engineering (.NET, MEAN, MERN). Notable engagements include GenAI enablement for **ADP**, IoT platform consulting for **IIT Bombay's E‑Yantra** program, and early work on Microsoft's Repository platform (which later became **Entity Framework**).

> *Empowering organizations and individuals to adopt, build, and scale with Generative AI, Cloud, and Modern Software Engineering.*

**Connect & explore:**

*   💼 LinkedIn — [linkedin.com/in/siddheshprabhugaonkar](https://www.linkedin.com/in/siddheshprabhugaonkar)
    
*   📝 Blog — [azureauthority.in](https://azureauthority.in/)
    
*   📬 Newsletter — [cloud-authority.com](https://cloud-authority.com/)
    
*   🎥 YouTube — [youtube.com/c/SiddheshPrabhugaonkar](https://www.youtube.com/c/SiddheshPrabhugaonkar)
    
*   🤝 Book a 1:1 on Topmate — [topmate.io/siddheshp](https://topmate.io/siddheshp)
    
*   🎓 Research Papers (Google Scholar) — [scholar.google.com](https://scholar.google.com/citations?user=TuqOYtwAAAAJ&hl=en)
