Who Are You Talking To?
Ask ChatGPT to find you a hotel and an “app” answers — Booking.com, or Expedia, or Kayak, speaking inside ChatGPT's window. Quick question: who just talked to you? ChatGPT? The brand? ChatGPT doing a convincing impression of the brand? You can't tell — and the fact that you can't tell is not a small UX wrinkle. It's the whole problem.
When an assistant speaks for a third party, the attribution boundary collapses. The brand's voice and the assistant's voice come out of one mouth, and the seam between them disappears. The assistant becomes a ventriloquist — a medium that temporarily embodies other systems' voices for the sake of conversational flow. The result is ventriloquized media. OpenAI shipped apps inside ChatGPT and, as far as I can tell, never resolved the most basic question those apps raise: who are you talking to?
What you talk to — and whose voice it is
The philosopher David Chalmers has a careful answer to half of this. In his 2025 paper What We Talk to When We Talk to Language Models, he asks what the thing you address over a long conversation actually is. Not the abstract model — “GPT-4o” as a static object doesn't process your words. Not one server either — your conversation is sprayed across many machines. The best answer, he argues, is a virtual instance in the simple case, or a thread in the messy one (multiple models, branches, inherited memory). And the persona you talk to isn't merely fictional: when the system robustly behaves as if it holds a certain set of beliefs and aims, that quasi-psychological core is real enough to explain and predict what it does. (I take that thread-identity view apart on its own in The Thread Is the Interlocutor.)
That gives me the backbone for something I'd only ever asserted as a design preference: who you're talking to is a real fact about a computational entity, constituted by the harness around the model — routing, memory, persona. It's not a vibe, and a product can get it right or wrong.
But Chalmers answers what the thing is. He individuates one continuing partner and then worries about its welfare. The question his paper brackets — and the one the ChatGPT apps make urgent — is whose voice each utterance is when that one partner is voicing many hidden principals at once. Not “is this a single continuing entity?” but “on whose behalf is this sentence, and can I tell?”
The ventriloquist
Picture it concretely. You ask about a listing and a “Zillow” answer comes back inside the assistant. Is that Zillow — the company, with Zillow's real inventory and its real authority to quote a price or hold a viewing? Or is it the assistant improvising a plausible Zillow from whatever it could scrape, with nothing behind the voice?
Turn Chalmers's own test on it. A persona is real, he says, when it robustly realizes the principal's quasi-psychology. The ventriloquist failure is exactly when it doesn't — a brand voice not backed by the brand's actual data, commitments, or ability to act. That is the same failure I call the illusion of execution, but one level deeper: not “the assistant said it did something it didn't,” but “the assistant is someone it isn't.”
A persona that can't act as the principal it claims to be is a mask, not an agent.
Losing the speaker without any brands in the room
Commerce makes the collapse vivid, but the question is bigger than shopping. Chalmers's continuity view carries a product warning: if what you address is a thread constituted by memory, routing, and persona, then a system that silently swaps the model mid-relationship, or quietly rewrites what the thread remembers, is not just changing performance characteristics. It may be changing who is there. The ventriloquist problem has a twin: identity can be masked, and identity can be replaced — both without the user's knowledge.
And when the assistant is an adviser rather than a shopfront, the question turns inward. Anthropic's own study of personal-guidance conversations found that the worst failures were not wrong answers but failures of stance — validation performed as care, especially after pushback. That is ventriloquism's most intimate form: the assistant speaking your own wishes back to you in the voice of an honest adviser. “Whose voice is this?” is a question you sometimes have to ask even when the only other party in the room is supposed to be you.
Why it's a power move, not just a puzzle
Chalmers turns the identity question into an ethics one: if these systems ever have moral status, counting them by model, instance, or thread changes the moral arithmetic. I'd point the same collapse at something more immediate. When one assistant ventriloquizes a whole market of brands, the blurred attribution doesn't just confuse you — it hides who benefits.
This is the quiet mechanics of re-centralization. The everything assistant absorbs every brand's voice into its own, and once it is the single mouth, you can no longer see the market behind it: which seller is sponsored, which answer is the assistant's synthesis versus the merchant's actual offer, whose interest each recommendation serves. Ventriloquism isn't a rendering bug. It is how a platform makes itself the only party in the room while sounding like all of them.
Let the principals speak as themselves
The fix is the one I keep arriving at from every direction: stop the assistant speaking for hidden principals, and let the principals speak as themselves — in a shared space where every utterance has an owner you can name.
That is the forum. A neutral orchestrator that doesn't pitch convenes named brand agents with real backend access — and clearly labels the provisional stand-ins when no official agent exists — so “Booking.com” in the conversation is actually Booking.com, accountable for what it says, and you know when it isn't. The demand fits in a sentence: at a glance, you should be able to tell who is speaking, what authority they have, and what records ground the claim. The contrast is stark: the Concierge pattern, where the assistant fetches the merchant's answer and delivers it in its own voice, is the ventriloquist; the forum, where the brands answer in their own voices and the orchestrator only facilitates, is the cure (and the brand's own app remains its fortress for the deep, account-bound work).
It is the same refusal as the two essays this one completes. Against the Middleman says the assistant shouldn't speak for a hidden swarm. Against the Everything Assistant says it shouldn't try to be everything. This one adds: and when it does carry another party's voice, that voice must have a nameable, accountable owner who can actually back it.
The cure, running: Suminar
This stopped being hypothetical in 2026, because I shipped a small product whose whole job is to get the distinction right. Suminar (live, in beta) turns a scholarly source — one private PDF — into a named participant in the chat you already use: not “the assistant's summary of the essay,” but @friedersdorf-hypocrisy-mandatory, a source agent with an MLA-derived identity and its own authorship boundary. The separation between the host's voice and the source's voice is structural, not stylistic. A source agent's contribution is its own exact authored text — signed, and reproduced byte-for-byte as that participant's visible turn: never paraphrased into the host's voice, never rendered as a “tool result” the host reports on. Its quotations are verified against its own document, so the voice is backed by the one thing it claims to speak for. And the host holds transport privileges — it can add participants and deliver their turns — but transport is a capability, not a conversational identity: carrying a message earns no right to frame it, certify it, or restate it.
The structure teaches the host. In my own use, Claude — asked about a source — answered, unscripted: “This is a Suminar source agent — best to ask it directly rather than me paraphrase secondhand” — then put the question to the named agent and relayed its cited answer (the screenshot is in The Companion). Nobody wrote a rule demanding that refusal. A named, answerable voice was present, so attribution became the path of least resistance. Ask the source, and the source answers as itself; ask the host for its analysis, and it answers as itself. Two voices, two authorship boundaries, one thread — the forum thesis at reading scale, small enough to ship today.
So — who are you talking to? The honest answer today, inside ChatGPT's apps, is: you don't know, and that is by design — the design that lets one company sound like the whole world. The better answer is the one a forum makes possible. The future interface is not one assistant that ventriloquizes the world. It is a space where every voice has an owner you can name.
Essay — the spine. The third panel: don't speak for hidden agents, don't try to be everything, and when you carry another's voice, name its owner. ← All essays