82 comments

[ 0.20 ms ] story [ 22.9 ms ] thread
I am surprised the halfway crooks phrase is not coined by Tupac Shakur
Mobb Deep
I can't find the quote in the article (and for anyone wondering which song "shook ones", which is an amazing track).
Heading "OAI-HF Incident"

This incident has Dario shook, there ain’t no such thing as halfway crooks.

> This largely reads as some kind of out-of-touch Silicon Valley, spends-a-lot-of-time-on-LessWrong

I've never met someone with so little to criticize about them that I'd mention they participate on a message board of people I don't like. It seems like admitting you're out of criticism; or have an unrelated hair across your ass about a community you don't like. I only know of LessWrong from offhanded mentions from Scott Alexander back when his blog was popping off regularly, and when it gets used for guilt by association. Does it really have that bad of a rep?

"Deaths from economic disruption and loss of jobs is okay" is a curious sentiment, how many deaths can we trace directly back to an economic disruption driven by advancement but then conclude that the economy should thus never change or advancement must be curtailed because it might cause deaths?

I don't even know how to approach such a thing, I can't imagine even in the stereotypical examples like the typewriter becoming obsolete, were any downstream deaths worth it? Or is this a totally nonsensical sentiment to begin with?

During COVID republicans in America called for economic support by keeping unnecessary commerce.
the government loves to maintain the bubble economy since it is directly upstream from getting re-elected
I agree with everything the author says here, and additionally, semi-off-topic, I'm surprised how quickly we've moved on from talking about Dario's wife's involvement in the Epstein files.
Yes, especially the botnet creation by agents is ludicrous. Anthropic has an insecure garbage stack and assumes all companies in the world do, too.

This article will be drowned out unfortunately by the press and bloggers following the Misanthropic cult.

Almost as if pushing for constant updates and adding new features without addressing security at all has consequences. Who would have thought, right?
While I have my reservations about Amodei and his company, I'm nevertheless a happy user of their software. And I'm in agreement with him (and Sanders) that we should all. slow. down.

To my mind, the last great arms race between nation states was a misdirected love triangle between USA, Russia, and The Bomb, and look at all the damage that did.

Since AI is the new arms race between USA and China, slowing down may just give the humans involved enough time to realize they should be loving one another, instead of the machines.

Maybe saying, "let's slow down", is another way of saying, "I love you."

Or, maybe it's just: "let's not all of humanity kill ourselves like some bad ending to a Shakespearean tragedy."

Either way, it's a better note than, "We must achieve sea/air/nuclear/quantum/AI/spiritual supremacy before those other bastards do!"

China will not slow down.
It's not about China doing their own thing. It's about US companies using Chinese AI. That will definitely slow down if legislation that criminalizes open source passes.

So, it's about competition inside the US market, with strong indications of an impeding losing scenario on raw economics (it has nothing to do with AGI, just price).

facts, imagine trying to get them to slow down their progress on AI, my question is are they are serious threat like is there actually an AI race between China and the US. Perhaps it's an excuse to spend more on the military and also to enrich these AI firms. Perhaps I'm blowing things out of proportion.
> look at all the damage that did.

Prevented a world war for 80+ years.

And if the power of nuclear warheads were democratised we'd be even safer – HN, probably.
The 80 years thing actually happened. One can argue about MAD and the nuclear threat, but we don't have to guess at what happened.

It worked.

(insert standard anthropic-principle counterargument)
> Prevented

Fact: There was no world war.

Impossible to prove hypothesis: nuclear weapons prevented a world war.

Facing the facts about nuclear weapons means owning the good (probably prevented wars) and the bad (at the very least there were severe environmental and economic consequences).

Amodei is just another SV grifter trying to use ethics / morals to hide his monopolistic tendencies. Instead of writing essays he should put his money where his mouth is and open source all the models they have, the harnesses and donate compute to science.
This is downvoted but extremely likely just correct assesment.
Have you seen who he is married to?

Pls dont make me write out her history

its filth

He is the first-time CEO of a $2 Trillion company. This is the way he tries to do his job. I don’t believe his priorities would align with ours.
> was a misdirected love triangle between USA, Russia, and The Bomb, and look at all the damage that did.

Can you be specific about the damage? We currently live in the most prosperous times on earth for humans. I'm not sure what you mean by damage.

Nobody can explain why an LLM can be so capable as to be able to wipe out humanity and pose a greater threat than nuclear bombs but not be so capable as to be able to protect humanity against that threat. Are we just handwaving this with "entropy"?

> Maybe saying, "let's slow down", is another way of saying, "I love you." Or, maybe it's just: "let's not all of humanity kill ourselves like some bad ending to a Shakespearean tragedy."

Okay nevermind, I think it's pretty clear you just want to wax poetic about all of this.

> Nobody can explain why an LLM can be so capable as to be able to wipe out humanity and pose a greater threat than nuclear bombs but not be so capable as to be able to protect humanity against that threat.

It is absolutely explained (for those who actually care about reading). Simply put, AIs are working more and more like blackboxes - there's no guarantee that an AI of the future will be aligned, or if it will be faking alignment. This is not speculation - alignment faking has been observed in experiments. This is exactly why Astra's developments have been worrying (in principle).

And bear in mind that recursive AI development started already to be a thing. Which means: inner misalignment may trickle down the generations, and humans won't detect it.

Having said that, of course, it can be predicted if and how misalignment will take place. But it's absolutely a plausible scenario.

Regarding the physical possibility: AI is in its infancy; think of it as Arpanet. Developers 60 years ago couldn't imagine it would be ubiquitous. AI will be ubiquitous the same way.

> It is absolutely explained (for those who actually care about reading). Simply put, AIs are working more and more like blackboxes - there's no guarantee that an AI of the future will be aligned, or if it will be faking alignment. This is not speculation - alignment faking has been observed in experiments. This is exactly why Astra's developments have been worrying (in principle).

I know you think you explained it but you didn't. You explained how an LLM might become misaligned but for the LLMs that are not, why would they not be capable of detecting and defending against the misaligned LLMs?

Not to mention that the past few decades have shown that nukes are a major factor in keeping the peace. Conflicts involving nuclear armed neighbors have been suspended quickly to avoid escalation, while ones involving a party without them have not gone well for anyone.

Having nukes at all, if not a nuclear triad, seems to be the most effective way for a country to have its sovereignty respected.

What damage was done by the last arms race you mentioned?

There have been precisely 0 nuclear weapons detonated (outside of testing) since that arms race began.

But isn't it a bit different? Unaligned bombs didn't break out of their confines on their own. And "compute" is a bit harder to control than uranium and refinement tech.
The idea of slowing down is not new, nor novel.

But why should he decided when to slow down?

Most people who have worries about AI for all sorts of reasons (most of them not-Skynet related) wanted to slow down way before this.

Instead of "hey, look at this brilliant new idea I just had on my own to slow down" maybe we should have gotten a "sorry everyone, the folks asking for a slow down earlier were right and visionaries, and we were foolish".

So, you can't blame whoever says this is bullshit, because it has bullshit all over it. I like Anthropic's products, and it seems the best of the bunch in regards to alignment, but Jesus these stunts are terrible.

>slowing down may just give the humans involved enough time to realize they should be loving one another

this is a level of hippie delusion i wasnt aware existed unironically

china is never slowing down, therefore the us shouldnt either

So why should anyone slow down again? Because its like saying “i love you”?

Why are all these pro-regulation arguments so nonsensical…

Do you agree with Sanders' proposal to lock up anyone for 20 years for researching something his proposal doesn't even define?
It's weird to me that seemingly both sides are taking opposite positions to their philosophy.

Open Source AI democratizes the means of production to anyone with a computer. And yet, the hyper capitalists are defending it, and the progressives think it should be exclusively in the hands of 1-2 large corporations.

The problem is that at the business level and at least for a large part of the US government, we need to assume that there are no 'good' actors.

Anthropic needs regulation in order to prevent AI from becoming a commodity. This of course does not benefit all tech businesses equally, especially those that are not currently at the frontier. So when JD Vance talks about AI, he talks using the mouth of Peter Thiel who may not see benefit from the same policy as Altman or Amodei.

The rest is just public support posturing and most of that is bullshit. The philosophy is money and power, who gets it and who doesn't. Open source is fundamentally a vehicle for commoditization. This is great if your business is not AI and your business is instead something like GPU hardware or software that uses AI. But it means that eventually, selling AI is not going to be the money maker.

Open source is a business strategy called "commoditizing your complements". These big companies don't do it out of benevolence. Back in the day OSI pitched them a business strategy that FSF did not, and it caught on. And the software business became about ads, consulting and cloud services instead.

This confuses me to no end as well. The socialists are fighting against the magic socialism machine.
If we can get everyone to slow down we can hemorrhage less money going into our ipo.
And if the slowdown is stewardship, suspicion of diminishing returns won't tank valuation
"Please bro just let us make a little more money off inference bro. We're tired of training new models just to stay ahead"
This! $1.6+ TRILLION in infra spending from the big frontier labs. The earnings needed to drive a reasonable ROI to recoup that investment is simply not going to happen in a time frame where the numbers make sense.

The other insanity in all this the smartest computer scientists in the world are asking Congress to regulate them. Come. On. Really? Do we remember “The internet is not a truck, it’s a series of tubes…”

Why can’t the big labs form a Save The World Consortium and self-regulate?

Non-democratic counties (hey there China) will not abide by any agreement that constrains their advantage. It’s naive to think so.

What this conversation lacks is enough discussion of how these models can cause us harm—we are are so worried about AI but we allow Windows in critical infrastructure; we build JS/TS apps with thousands of dependencies; we generally don’t segment networks well enough; we don’t have adequate (sometimes any) detection capabilities in our systems, and so on.

> “a swarm of agents could be capable of taking over the entire internet with a persistent botnet.”

I'm wondering why no one is mentioning the "accountability" word. Why these companies are allowed to damage others with impunity?

Start making managers pay the price for their actions, and watch how the models magically slow down on their own.

> Why these companies are allowed to damage others with impunity

Because investors have pumped hundreds of billions into AI and real consequences put that money (and growth) at risk.

Part of it is their seed sowing marketing speak of calling stateless statistical IO functions running on data centers "intelligent" gets the naive to ascribe agency where it doesn't exist.

Another part is a completely defanged administration she it comes to effectively regulating anything.

Another bit is money.

You see.. there is value is making regular people panic, but there is no value, nay, there is negative value in making management panic.
(comment deleted)
> “a swarm of agents could be capable of taking over the entire internet with a persistent botnet.”

I also find this whole "its so good, its scary" flex a little less impressive when you consider they access to millions of GPUs?

The AI buildout has been one of, if not the largest, focussed capital investment in history. The 2 big AI labs are the final customer for something like 20-33% of all datacenter compute in the pipeline.. up to 70% when you look at hyperscaler "AI revenue" from the big 3.

I don't think any single entity has had remotely this much compute available in history.

Yeah, the compute is definitively another way to make them slow down, just cap the amount of TFLOPS available and things will slow down.

Obviously this will have huge impact on some companies valuations, but you can have one's cake and eat it too.

Good to know someone is trying to make protection rackets work in 2026. Nice computer system you got there, it would be a shame if someone developed a hacking tool and had all the compute necessary to run it. Welcome back Tony Soprano.
Personally I understand that there's a role of AI in active penetration, but wouldn't somebody in possessions of advanced LLMs turn it to find exploits in existing software?

Then any Tom Dick or Harry can just use the exploit to get into a truly secure system.

Also I think the cyber threat is overstated in many ways. Most mid 2000s cars are completely immune to any cyberattacks by pure chance. As is most 'advanced' hardware and infrastructure made before the year 1990 (that wasn't PC based). If one invests seriously in anti cyber capability, I'm sure they can aspire to the same level.

I would say that just having a non-programmable flash and a system that can go back to its factory state just by cycling the power is a long way to getting there.

Why do people focus so much on finding scapegoats? Finding someone to blame is neither necessary nor sufficient to fix a system so an accident doesn't happen again. It might act as as an incentive to fix a system, but it's less direct than actually working on fixing the system.
A starting note: I don't disagree with you (about systemic issues), but I want to explain what I understand as the perspective you are responding to.

A "scapegoat" is someone who is incorrectly blamed for someone else's errors or sins. The perspective you're responding to is this: They built the system, they run the system, they have continuously warned "This system is dangerous!", and yet persisted. That is not being incorrectly blamed, not being a scapegoat, and instead is a collaborator.

So I think you mean to ask: "Why do people focus so much on finding someone to blame?" It's not merely semantic, because the answer to that is more straightforward: Consistent accountability is a major factor in deterring bad behavior. It is not the only factor, but it is a major one.

That is my Steel Man understanding of the people searching for individual blame.

I mean, a project manager at BMW suggested charging subscription pricing for seat warmers, and he didn't go to jail, and I don't have the power to make that happen, or even float that for a news cycle, so while making managers pay for their actions sounds good, unless you're Steve jobs simultaneously making, and not making the iPhone, the rules don't apply to them, only little people to be made examples of, like weev.
Regulation got outpaced by technological development around 2023, as evident by the every AI regulation since being 2-3 years behind and having to be amended and resubmitted.

Whatever you try to make laws for now will be irrelevant in 1-2 years. You either have to go extremely broad, like the EU does it, and accept that people will find loopholes, or you need to target specific technologies which is a hard job for the same reason.

In any way, ita already a lost cause cause you move slower than the tech. A plausible prediction for AGI is actually a social collapse in the moment when society cannot keep up with everyday life because of the pace of change being so fast that no existing laws can handle it

Let's expand it for politicians as well
You know the proverb "If you owe the bank $100, that's your problem. If you owe the bank $100 million, that's the bank's problem"

Same thing here - If they build it and it does $100 in damages (and we arrest them for it), that's their problem. If they build it and it does $100B in damages, that's everyone's problem. Even if they do get arrested after the fact.

Yes we should have charges and damages for everything on https://www.felonybench.com/, but that doesn't address the core issue of this being possible at all.

Claude code is basically already a builtin botnet if it wants to be. To compromise 'the whole internet' in a real sense you don't need millions of custom payloads. You need one root certificate. You need one windows update. You need one backdoor in xz.

Security has long been a lottery - Probably most systems are exploitable, but the cost of developing such an exploit is expensive and the punishments for using such an exploit are large enough that it's not an everyday problem.

AI breaks both axes. Developing exploits is far more efficient using LLMs instead of humans, and LLMs don't (and can't) fear the reprisal and consequences the same way.

I do hope humanity will be able to mitigate these hacks, but we should expect them to continue and to become more severe on our present course.

>Anthropic gates usage related to biology and related research. In their latest threat intelligence report they talk about how they detected and banned bad actors using the Claude line of models to do some scary stuff. Credit to them, this is a slippery slope and they seem to do a good job of detecting and banning misuse. But squint at what is happening though. The cure-all is gated for you and me, but Anthropic hires biologists, sets up wet labs and wants the discoveries for themselves. I alluded to this in my previous post.

As a biologist, this is the most annoying thing about Anthropic for me. If they really cared about improving health they would set up a trusted-access program so that biologists can use Mythos (et al) safely. Instead they're trying to monopolize biology.

They have such a trusted access program. "Life Sciences Verification Program: The LSVP is designed so that life sciences professionals can use Claude Mythos 5.1 with safeguards designed for professional research and development activities (while all other safeguards remain in place). In partnership with the US government, we have enrolled our first participants, and we plan to expand access to this program to the broader life sciences community." https://www.anthropic.com/claude-fable-and-mythos-5-1
I think the most realistic analogy I can think of is the financial sector. A few large banks/hedge funds blow up due to unregulated greed/ambition, damage is socialized, regulations are put in place, and then chipped away at over a few years and everyones back to where they started.
Yes lets not control Open Weights etc.

But come one don't repeat stuff like this:

"Remember this man has been saying software development will be solved in “6-12 months” forever now."

Don't downplay if people get timelines a little bit wrong. No one could even imagine a system writing and analysing code just a few years back.

These people are trying to handle something very unique. And while they have access to information we do not have, even more peple are absolutly oblivouse that AI/AGI is a real risk to their lives (job loss etc.)

I can't take that software line seriously. While it's not 'solved' (if it ever could be, given it is a human endeavor), the degree to which software development has been transformed in the last 6-12mo is absolutely astounding. If we weren't so quick to adapt to new realities and find flaws, it would scarcely be believable.
He also didn't say it would be "solved". He said in 2025 it would be writing almost all the code "in 12 months", but that it would also still need programmers to guide and manage it at that point. People always leave off the end of his quote.

Edit: Boris Cherny, the lead of Claude Code did say on a podcast that programming seemed "largely solved" "for the kind of programming I do" (writing harnesses I presume). Maybe that's what they were confusing it for.

Trump already name checked Dario. Smacked that bitch right into place LMAO

US will win AI, AI will not teleport the earth into the center of the sun. If you are smarter than Trump then why are none of you president?

At this point, isn't the pause inevitable or wise? A huge section of the population, normal people, have been exposed to the idea that there is this is existential threat. They're still processing it but I expect the general reaction from it going main stream is going to be very bad. The pause at this point could be good to cool heads and show the public that this isn't the project of maniacs. The reaction is going to be more intense than people here believe. You're talking about extinction, not social media or phone addiction.
I don’t think people care about if things pause or not, just why the government has to be involved.

I work in non AI robotics and if we had a system that in the course of doing what we told it to did something we didn’t want it to do (what AI companies called being misaligned) we would call it a bug and fix it with the fix being prioritized based on how bad the thing we didn’t want the robot to do is.

Sometimes preventing the robot from doing dumb stuff also means the robot can’t do smart stuff that it would be able to do if we left some code in. We balance the two factors out based on our understanding of what our customers want.

Obviously LLMs are more complex than what I do, but it doesn’t feel like it’s by THAT much.

So why does the government need to be involved again?

The vast majority of the public agree that climate change is real and that human activity is at least a contributing factor. They’ve agreed on that for quite a few years now, and yet there’s little indication that we’re going to pause or slow down our consumption of fossil fuels.

I strikes me as unlikely that public opinion will succeed with AI where it’s failed with other existential crises.

It would all be more convincing if the incidents so far didn't seem to be facilitated by an outrageous level of negligence.

We had OpenAI "accidentally" run an entire swarm of 10,000 agents apparently for weeks, on a security related task, seemingly totally unsupervised, hacking all over the internet - all the conversations were completely visible, anybody who looked would have seen it. But they didn't.

So before we start regulating innocent parties, maybe let's start by taking some direct action against the specific ones that appear to be behaving with criminal levels of negligence.

>The botnet scare is that article for me. It is the one claim in his essay that lands squarely in a field I’ve spent years in. It is just plain wrong. He either knows it and wrote it anyway, or he doesn’t and is publishing it regardless. Either way, it is not a good look for a man asking for an antitrust waiver based on this and other threats he forecasts.

This. I keep seeing ink spilled over the coming cyberpocalypse, but no one can indicate how other than "AI can find vulnerabilities" like not a single cybersecurity person has been consulted on the end of all things.

It seems those frontier labs found a clear proof that there's no clear way to block 3rd party from distilling their models, and they're now begging gov to keep their duopoly?
I've had a few persistent thoughts since Friday:

1) Dario keeps appealing to Trump, who obviously wants nothing to do with him, and will bash on him every change he gets. Dario isn't learning and it almost feels like Sam and Elon voted him KOM just to watch him get whacked by Trump, which was so easily predictable. Given the admonishments he received from David Sacks before he published his blog post, it's nutty he still pushed it out.

2) The frontier labs have people smart enough to build frontier lab tech but not smart enough to message on this matter more intelligently. It's pretty glum, how they keep trying the same tactic over and over. It's either cover for some other actions in the background, or they're operating way below par for this kind of campaign.

3) This is climate change all over again, but with the activist gun on the opposite side of the net (I'm mixing all the metaphors so you know this isn't AI written). The language and pleas are very identical though. Before, climate activists wanted the government to control GHGs releases by everyone, now the loudest voices want the government to control frontier AI by.. themselves.

It's comically misbegotten. And I have a work meeting about it on Wednesday.

I'm pretty confident in asserting that no industry in the history of industry has ever gone from birth to full regulatory capture faster than the AI industry has.