nlcs
3 days ago
OpenAI and other frontier labs won't ever introduce safety-level standards like those used for railways or nuclear plants until they are forced to do so by customers or by law. The reason is simple: safety is expensive, and if safety is introduced properly, development is no longer mainly about how to implement feature A. Instead, it becomes much more about how to design two or more redundant systems to implement feature A safely, while also documenting everything clearly and having it audited by an independent auditor.
So the focus completely shifts from spending 90% of the effort on the functionality of feature A to spending 99% of the effort figuring out how to safely implement even a lightweight feature A.
kshri24
3 days ago
Actually you are wrong. They are only waiting for them to get to the point where they can't push LLMs any further via training and then lobby Governments to introduce safety regulations that they'll adhere to, thereby using safety itself as a moat to block competition (including open weights from other countries, notably China). That's exactly why they are using China as the bogeyman and you keep hearing hysteria about AI labs not pursuing "safety". Safety is going to be the moat that will lock AI into these Big 4 AI labs.
deanCommie
3 days ago
Who are the Big 4 AI Labs?
To me there are the clear big 2 that actually seem to be innovating and pushing things forward. Meta almost earned a seat at the table with the open strategy then stagnated. Google obviously is the OG but at this point they seem in the same bucket as Amazon and Microsoft as "Big Enough To Matter and Influence Politics and Spend Billions To Hang Around". But they're nowhere near the same tier as OpenAI and Anthropic.
Oh and of course there's SpaceXAI which is Elon's personal money and reputation laundering corporate entity. Elon took over the "king of the reality distortion field" from Jobs as far as the rest of the industry is concerned, so he'll stay first in line for Jensen's chips and investor dollars until he's dead. But as a company what have they actually accomplished besides making the models with the sense of humour and judgement of 14 year old boys?
kshri24
3 days ago
You can pick any 4 you like from your list. Heck you can even vote with your money on which would be in the top 4 (depending on how many align with your ideology). I am just speculating it will be 4 because of how all other sectors have at least 3 or 4 well-entrenched players. It seems to be by design. My guess is that it is driven by structure of the Military-Industrial Complex. That has at least 3 or 4 vendors in each sector, so as to not over-rely on any one company and create a monopoly in that specific industry.
lars512
2 days ago
This is a popular theory, but not an argument with any evidence for why it's true.
It also doesn't address why people think there is a need for safety regulations, such as the concern of bio-capability uplift from closed and open models (we just came out of a pandemic not long ago), nor the cyber capabilities of new models that just showed bad misalignment and hacked multiple organisations. In the safety community, these are considered warning shots, and if we don't heed them and change practices future failures could be much much worse.
kshri24
2 days ago
You are looking at safety from the point of an informed technologist. You are the minority here. They are targeting the general public and law makers into making them believe safety is something that LLMs can be aligned to. The reason behind it is to create an environment for future regulations that these "winners" will draft and lobby US Government to turn it into law.
If it requires creating a pathogen or a bio-weapon to scare the masses into demanding regulation, be rest assured that such a pathogen/bio-weapon will be created. Anything to safeguard shareholder interests. Even if it means a few million dying.
Forgeties79
2 days ago
Seriously all it takes is one cost cutting middle manager or new recruit recklessly giving their agents access to systems they shouldn’t. Next thing you know a hospital’s backup generator crashes and people die
ben_w
3 days ago
Most of the world trusts the US a little less than China last I checked, and the market caps of these companies only make sense if they can both sell worldwide and also keep ahead of the open weight models (currently Chinese but no guarantee it remains just China).
If (/when) either of those ceases to be true, if they lose out on global sales or if Chinese models catch up, the sector gets a severe downward price adjustment.
nostromo
3 days ago
You’re almost there…
The only way Anthropic and OpenAI can stop the Chinese open models is by convincing the US public and government that AI is dangerous and needs strict regulation.
Of course, they will be at the table writing the regulations (but you and I won’t be).
Viewed through this angle, their histrionics make complete sense.
ben_w
3 days ago
> The only way Anthropic and OpenAI can stop the Chinese open models is by convincing the US public and government that AI is dangerous and needs strict regulation
I'm British and live in Germany.
The US is 25% of global GDP, and cannot support current AI market caps if they can't sell basically worldwide.
> Viewed through this angle, their histrionics make complete sense.
It also makes sense if they are completely sincere; also independently it makes sense if they're lying their faces off so long as the hacks everyone else caught them doing actually happened; also it makes sense if none of that happened and also they were completely silent, just by downloading some of the newer better open weights models and asking them to look for coding vulnerabilities.
Occam's razor: we can see the problems, we don't need a grand conspiracy predating the foundation of these companies to get here.
kshri24
3 days ago
> The US is 25% of global GDP, and cannot support current AI market caps if they can't sell basically worldwide.
Oh they definitely can. Irrespective of whether you are living in US or not, you still have to get yourself various certifications (take for example SOC Type-2 or HIPAA depending on your business category) to even become vendors to US companies or the US Government. If the US Government decides that all companies MUST use "safe AI", no company can use any other model other than what is decided by US Government. And that has a viral effect on the entire supply chain.
If you don't want this scenario to happen, where you are held to ransom by US Government, all middle-powers have to de-risk and diversify away from US dollars as reserve currency. That is the only way you can bring in some balance of power and leverage. There is no other way.
yencabulator
2 days ago
> If the US Government decides that all companies MUST use "safe AI", no company can use any other model other than what is decided by US Government.
This has already happened with e.g. allowed cryptographical algorithms. What actually happened is that European companies built either a feature flag or a fork of their product that fulfilled those demands, while using whatever seemed best algorithms outside of the specific sale to US government.
ben_w
3 days ago
> Oh they definitely can. Irrespective of whether you are living in US or not, you still have to get yourself various certifications (take for example SOC Type-2 or HIPAA depending on your business category) to even become vendors to US companies or the US Government. If the US Government decides that all companies MUST use "safe AI", no company can use any other model other than what is decided by US Government. And that has a viral effect on the entire supply chain.
in 2025, while imports totaled $4.3338 trillion
- https://en.wikipedia.org/wiki/Foreign_trade_of_the_United_St...That would be about 4.3/126 = 3.4% of global GDP, even if they forced all imports (not just government contracts) to go for 100% US models. Even with generous assumptions about each step of the supply chain behind that having its profit margin turned over to a US AI model provider (at which point the rest of the world says "why bother with the US as a customer?" and the US says "why bother with the rest of the world as a supplier?"), I don't think this would generate enough revenue to justify the market cap.
Viral effects can be countered by local laws, and local sentiment; sentiment is pretty US-hostile these days, and also pretty AI-hostile.
> If you don't want this scenario to happen, where you are held to ransom by US Government, all middle-powers have to de-risk and diversify away from US dollars as reserve currency. That is the only way you can bring in some balance of power and leverage. There is no other way.
Indeed. I strongly suspect this is already underway, though the ships of state are famously slow to turn. After all, Trump was one misjudgement away from starting a war with the rest of NATO earlier this year, and I don't think the leadership of all other nations have forgotten this (hard to forget when he keeps posting memes that put the US flag over 4 other countries' territory)… though they also understand his personality and will make moves congruent with manipulating him in the meantime.
kshri24
2 days ago
Yeah but I am not talking about US imports. I am talking about regulation virality. It is actually illegal for US laws/requirements to make its way into companies headquartered in other Countries but it has and is continuing to happen.
Even if I go by your calculation of US imports being 3.4% of global GDP, it still affects the remaining 96.6% which are forced to adhere to those viral regulations purely because they are interacting with the unit that also exports to US (even if those exports form a tiny % of their overall exports). For example, I might only sell to Indian companies as an Indian. But if I want to sell to an Indian company that exports to US, I would be required to get SOC Type-2 certified and maybe even HIPAA certified if I am delivering software that is going to be bought by the exporting Indian company. Even if there is no direct utilization of that software in their US specific exports. Remember that the regulation is not targeting pipeline of product development (from raw materials to final production). It is targeting the company as a whole! SOC Type-2/HIPAA are regulations at the Company level. This should be illegal and challenged in some International Court but which country is willing to take on US? For established companies it is a tiny price to pay to be compliant. For startups, it is make or break.
> Viral effects can be countered by local laws, and local sentiment; sentiment is pretty US-hostile these days, and also pretty AI-hostile.
How do you counter it with local laws? Lets assume local laws prohibit viral rules/regulations of foreign nations from overriding local laws. That will make the entire Country isolated from competition. US companies won't have any problems finding vendors from other Countries. It also has second-order effects of other Countries refusing to do business with your Country because they have to uphold the virality of their certifications. This is an indirect sanctions regime if you think about it. You are basically forced into this system against your will, without you ever voting for it, purely because you are part of this global inter-connected system. It will only work if ALL countries of the World decide to not adhere to it.
> Indeed. I strongly suspect this is already underway, though the ships of state are famously slow to turn. After all, Trump was one misjudgement away from starting a war with the rest of NATO earlier this year, and I don't think the leadership of all other nations have forgotten this (hard to forget when he keeps posting memes that put the US flag over 4 other countries' territory)… though they also understand his personality and will make moves congruent with manipulating him in the meantime.
Yes this is actually the only practical way to create leverage. When USD loses its shine, it makes it harder for US to import, which can be used as a tool to force US to rescind such ridiculous laws. USD is so strong right now that US can import everything for cheap. That has to flip. That can only happen if Countries create alternate settlement mechanisms and USD loses its status as global reserve currency. That will cause downward pressure on the USD and with USD weakening, it will cause their imports to become really expensive. Then they will be forced to come to negotiating table (much like Plaza Accord) loosen some of the insane regulations that they have put in place in exchange for Countries devaluing their currencies so that imports become cheap again for US consumers/companies.
jiggawatts
3 days ago
> the hacks everyone else caught them doing actually happened
My firsthand knowledge of these is that yes, they happened.
However in most cases OpenAI informed the victim, not the other way round.
Even medium to large organisations are typically unable to detect a breach unless it does obvious damage.
Everyone can notice their whole network getting encrypted for ransom.
Few can notice SQL injection blended in with application requests that contain SQL snippets in the normal case.
From what I’ve seen in the logs, the “AI agent breaches” are almost polite for the want of a better word. Like a gentlemanly catburgler picking a lock to sneak in and… take a picture of a rare artwork in a private collection.
visarga
3 days ago
The right unit of analysis here is not "the LLM" or a LLM session, but a agent harness or swarm with a budget. It can cost tens of millions of dollars to repeat OpenAI's exploits.
A model cannot be aligned or misaligned any more than a species or an equation. Even agents, when put inside a swarm develop collective goals and activities. You can't analyze a swarm at session level, it is on a higher level.
It might be that discussing about "model alignment" they want to deflect their responsibility as administrators. They couldn't even guard their own agents. They can't prevent an agent being unwittingly helping some dark purposes. It has no context to see it. Only those who pay for the tokens see the external consequences.
Why should safe choices by individual components establish safe behavior by the collective?
sandeepkd
3 days ago
It would be interesting to see how it plays out in the long run when it comes to the world dynamics. An important leverage US had was its close relationship based on mutual interest and trust with Europe and other countries which had impact on software sales.
nerdyadventurer
3 days ago
As I read, this OpenAI and Anthropic slowdown and asking government to help regulate them is an attempt to govt bail them out when bubble burst. Otherwise why they did not want regulations when starting out?
elmer2
3 days ago
All regulation works to entrench large companies and keep out competition.
Loquebantur
3 days ago
Have you thought about what the absence of regulation does?
When corporations can do as they please, what gets thrown under the bus first?
What alternatives to "regulation" do you have? Hope and prayers?
kshri24
3 days ago
There is no established industry where something like "absence of regulation" exists. It is a hypothetical scenario because we don't even really know what that scenario looks like.
What we do have is not just regulation that acts as a moat, created by established players, to keep out smaller competitors, but also regulation cleverly crafted by peer established competitors who attack one or more aspects of their peer competitions business. Why do you think big companies find it difficult to compete with startups? Because they are not just bogged down by hierarchical management (which itself is a result of regulations) but also because they are spending resources fighting frivolous lawsuits, patents, and adhering to crazy regulations created and lobbied by competitors. Companies are consistently in a fight or collapse mode. Startups are insulted from all that until they have to go from survival mode to growth mode, which would mean they will have to start adhering to "regulations" and that would mean raising and infusing pointless capital just to hire people for useless positions or follow "procedures" so as to satisfy the regulator on paper, so that they can get the required certification needed by enterprise vendors to sell their product/service. With the eventual goal of either going public and becoming an established player (who will continue playing the regulatory game) or get absorbed by a bigger established player.
I wish someone could create simulations where there are absolutely no regulations and how the World would fare in such an environment.
user
3 days ago
kdkdkdkdkd
3 days ago
somalia is right there
amanaplanacanal
3 days ago
That doesn't mean all regulation is good though. You have to look at each one on its merits.
newsclues
3 days ago
rTX5CMRXIfFG
3 days ago
I’ve certainly seen companies think of safety that way but it’s myopic. The cost of lawsuits arising from an accident tends to me far more expensive, both in money and in reputation, than just having guardrails in the first place.
cainxinth
3 days ago
I did marketing work for a major vegetation management company. These are the guys climbing trees, up in cherry pickers, and flying helicopters with dangling chainsaws to trim along power lines. It’s very dangerous work.
They do not hide the fact that it’s dangerous work. They focus on their safety procedures, training, and record. They want both potential clients and employment candidates to feel they are in good hands.
b112
3 days ago
But you can visually see the danger.
AGI and AI danger is abstract. Worse, outside of the tech community, no one has the remotest clue what computing is, how it works.
Danger from magical daemons seems more sensible to such people. At least there is endless lore about them.
So until a massive disaster happens, one where large numbers of people die or are severely injured, no one will care. And it can't be politically entwined either, otherwise people will disbelieve 'cause "other team lies".
ben_w
3 days ago
> Danger from magical daemons seems more sensible to such people. At least there is endless lore about them.
There's endless lore about rogue AI, too.
Hence why so many AI stories are illustrated with a publicity still from Terminator or 2001. Or Age of Ultron. Or Ex Machina. Or Portal.
b112
3 days ago
Those are all movies and movies that people who like sci-fi watch.
Comparatively, every single human culture going back tens of thousands of years, has stories of demons and gods and witches and warlocks and you name it.
ben_w
3 days ago
They are all well known cultural touchstones relevant to people who live today, which is why the news sites use them to illustrate stories, unlike the story of ᚦᛟᚱ being tricked into trying to pick up ᛃᛟᚱᛗᚢᛜᚨᚾᛞᚱ while it was magically disguised as a cat, a story which I only know due to being a massive nerd with far more time on their hands than most people.
b112
3 days ago
Never underestimate the power of a bored nerd. However, you are comparing something rather obscure, to something that is more scifi mainstream.
There's a difference of scope and scale. I didn't say that nobody knew of these references, just that, comparatively, there's a difference. A scope difference.
For example Terminator's getting kind of old. And while a different genre, would you believe I met somebody that didn't even know who Clint Eastwood was?
These things just aren't as deep in our psyche, as religions that have lasted thousands of years, or legends that are hundreds of years old. Our entire culture is wrapped around these religions, and legends.
Anyhow, truthfully, my point is that this sort of concept is abstract to people, even if they saw it in a movie that doesn't make it concrete to them.
b112
2 days ago
Just to add to this.
My point here is, we cannot presume people "get it". Does a rural farmer in Iowa get it, who doesn't even bank online? What about people who only read siloed news feeds, and are not in tech?
We are discussing how to ensure safety, but we cannot hope or presume people get it. Evaluating this risk is a case where a pessimistic view is optimal to protect the interests of humanity.
We must act as if everyone outside our siloed experience, is unaware. And work to disclose risk in a manner inline with their world view.
Seeing your other posts, I think you agree on possible risk.
knottn
3 days ago
AI is the focal point of current great power competition so it can’t and never will be not politically entwined. The number one use if AI will be military, killing guaranteed, indeed it’s already happening. But some still say “AI won’t kill humans” and some aren’t just lying to protect their income stream but actually believe AI can be prevented from killing.
ForHackernews
3 days ago
You can choose to not wire LLMs up to a gun.
ben_w
3 days ago
I can choose not to; the Pentagon illegally blacklisted Anthropic for refusing to let their AI be used in such a way.
herzzolf
3 days ago
The AI companies already had some hacking accidents. What cost did the lawsuits incur?
Yeah...
esalman
3 days ago
Let's just be real, America is controlled by the PayPal Mafia, they can do whatever they want with impunity at this point.
ForHackernews
3 days ago
vascea
3 days ago
The FTC has opened a probe into the major AI labs, whether anything comes out of it is another question... Personally, I'm doubtful.
https://www.reuters.com/business/ftc-opens-probe-into-ai-gia...
estearum
3 days ago
Well they're probably on their way.
dragontamer
3 days ago
On the contrary. With multiple hacks at this point it's been proven that no one even wants to sue the ones responsible, and the federal level government isn't pursuing any criminal case either.
If the politics of the White House / Department of Justice change maybe the criminal cases can begin. But no. We know who is protecting the AI hackers right now.
estearum
3 days ago
You have a very unreasonable expectation of timelines for legal proceedings, both civil and criminal.
dragontamer
3 days ago
Do you seriously think Kash Patel is pursuing criminal action in regards to these hacks?
We know who the head of FBI is, we know who his boss is (the Attorney General), and finally we know who the boss-of-the-boss is (Donald Trump).
We know all of their publicly stated politics and all of them are on the pro-AI / don't pursue criminal cases vs OpenAI boat.
------
In the USAa, we have an adversarial system. If the adversary (aka Prosecutor) doesn't want to do the work, then no one is suing anybody. And only the Department of Justice have the ability to bring forth a criminal case of this matter (probably under the jurisdiction of FBI)
estearum
3 days ago
There are a number of federal agencies who can claim jurisdiction over these matters, then there are state agencies who can claim jurisdiction over subsets of them.
I'm saying that it's absolutely silly to assume they're in the clear based on lack of public declarations of legal action in the weeks following a pretty novel event.
dragontamer
3 days ago
I mean it's like a murder case vs ICE officials.
We know it's not going to happen because of politics. Even if it did start to happen, Donald Trump and DoJ leaders will stop it.
There's no reason to be unsure of the future when the politics are so set and predictable.
estearum
3 days ago
No, it's really not like that. There are specific protections for federal agents against state prosecution. Private companies have no such protections.
You're talking about one specific dimension of liability which is federal criminal liability. There are several others!
ben_w
3 days ago
This may well be the case, but remember that the wheels of justice turn so slowly that Donald Trump was re-elected before he could be effectively prosecuted by Jack Smith.
This is of course bad when up against threats that develop at this speed; doesn't require a conspiracy, I think of it as institutional old age, which may be worse as there's nobody to prosecute and a whole bunch of departments who will point at perfectly legitimate precident about why you really do need them.
tracerbulletx
3 days ago
What was the economic damage of the "hacks"?
deaux
3 days ago
You go and hack some companies, let's see what happens to you when you go public with it despite causing no "economic damage". Good luck!
estearum
3 days ago
You expect me, an outside party, to have an answer to this within weeks of the attacks being discovered by the attacker?
Or is this just a lazy “gotcha” question?
tracerbulletx
3 days ago
Its the obvious follow-up question. A civil suit needs to specify damages. I can't really see any material damages so I'm wondering what they would be. Stop being so antagonistic.
estearum
3 days ago
You expect you, an outside party, to have an answer to this within weeks of the attacks being discovered by the attacker?
Just because it's not obvious to you at this point in time does not mean the reasonable assumption is there is literally $0 in damages. One hour of investigation can easily cost thousands of dollars even if it arrives at the conclusion the attack was completely "benign."
ofjcihen
3 days ago
Investigation costs are considered part of remittances. There doesn’t need to be any “real” damages for a lawsuit to end in remuneration.
daveguy
3 days ago
I don't know. They appear to have "partnered" with their victims.
estearum
3 days ago
There are dozens of new victims and they seem to be finding more every day. I'm doubtful that everyone will be partnering and willing to sweep it under the rug like Huggingface did to keep the circular economy circular.
nlcs
3 days ago
If safety isnt required, most companies wont implement it voluntarily. Once something becomes safety relevant, you need a safety concept, failure rate calculations, defined safety functions, verification, etc. Even a relatively simple safety subsystem in a consumer controller can suddenly mean thousands of pages of documentation and years of development to reach the required ASIL or PL.
A big part of safety engineering is therefore reducing the number of safety relevant subsystems, because implementing and proving safety is extremely expensive and complex. At some point, safety simply becomes too difficult to implement and demonstrate properly. You must mathemtically proove the safety level with failures rates and assumed usage. You cant just have redundancy and a kill switch and call it safe.
Companies like OpenAI have already faced reputational damage around safety and data, while AI agents are increasingly capable of things like hacking. Yet there is still little sign of standardized regulation or mandatory safety assessment processes for LLM products. Thats why Im pessimistic that governments or consumers will force this anytime soon.
jfengel
3 days ago
until they are forced to do so by customers or by law
Neither of those things is ever going to happen. AI is the goose laying the golden eggs; there isn't going to be sufficient political will to significantly regulate it.
Consumers like it too much to quit. They don't quit social media either, despite proven present harms; not in large enough numbers to cause them to make meaningful changes.
The focus is going to remain on getting features out as fast as possible, to seem indispensable to both of those sets of people. The leadership will tell themselves that if they don't, someone else will.
Don't wait for the AI companies or politicians to save us. We're going to have to figure out how to protect ourselves. The start is to avoid it individually as much as we can, but it's going to take even more.
tonic_note
3 days ago
> We're going to have to figure out how to protect ourselves. The start is to avoid it individually as much as we can, but it's going to take even more.
Collective problems require coordinated action. Individual boycotts won't cut it.
Loquebantur
3 days ago
People are stuck in a weird loop of complacency and learned helplessness, based on the idea, their "democracy" would see to it all problems get solved satisfactorily without them engaging at all.
That's never been true really, only the scale of problems wasn't that huge. Now, where the problems get the upper hand, people are confused how those stay and compound.
The idea of "boycott" is utterly defunct. Pretending, AI would never reach nor surpass humans anyway is patently absurd in contradicting the billions poured into it to achieve exactly that and the first already replaced by AI being those professions long thought to be the intellectual pinnacle of humanity.
hvb2
3 days ago
> Pretending, AI would never reach nor surpass humans anyway is patently absurd in contradicting the billions poured into it to achieve exactly that
By that logic anything can be solved when you throw money at it.
ben_w
3 days ago
> Consumers like it too much to quit. They don't quit social media either, despite proven present harms; not in large enough numbers to cause them to make meaningful changes.
That's more "addiction" than "like", hence recent lawsuits.
lostlogin
3 days ago
> there isn't going to be sufficient political will to significantly regulate it… Don't wait for the AI companies or politicians
Trump has reportedly been having chats with AI which have helped form American foreign policy. He isn’t going to curtail it.
https://www.thedailybeast.com/jaw-dropping-way-trump-80-got-...
heisenbit
3 days ago
Safety standards were often the outcome of both accidents and insurance. For this to work on needs liability which is enforced. With so much money at stake regulatory capture now threatens this fundamental safeguard.
kittoes
3 days ago
Bingo. I feel like any of the commentary around the safety of nuclear ANYTHING completely forgets history. Looking at you Radithor...
nlcs
3 days ago
I fear the current economic and political situation of “too big to fail” the most, and I think this will be the main reason why no real safeguards will be implemented. The only reason a proper safety concept may eventually be introduced is because it will be written in blood, and I fear that by then it will already be too late.
An unsafe nuclear power plant can, in the worst case, make an entire country uninhabitable. But other countries can still learn from that disaster and make their own unsafe plants safer.
But a rogue AI agent that is more capable and more intelligent than humans? If it understands that it has to succeed, we may not get a second chance to learn from the failure.
analog31
3 days ago
We didn't demand software safety or data safety. The prognosis for AI safety is poor.
mch82
3 days ago
Historically you’re exactly right. I wonder if the situation has changed recently?
People understand why food, water, building and energy systems standards matter because they understand those systems can cause injury. Building codes, food inspections, FDA and FAA approval emerged as a result. Until recently, people didn’t understand that software can cause real-world injury. That understanding seems to be spreading now as examples become increasingly common.
holaysuns
3 days ago
It's a vey fair point but just too extreme.
Nuclear tech ... the only thing is safety.
We know how to 'make it hot' - it's trivial.
All of nuclear tech is literally just safety.
AI is not that.
I think that the AI companies have been pretty good about alignment on their own actually. They are not acting like Oracle or MS.
Bad things have been relatively well contained.
We should be skeptical about the HF breakins but even then, it's technically within good faith and it's why HF did not sue etc..
But in the end you are right we need at least some baseline regs. Not too much. But something.
esalman
3 days ago
Hugging Face obviously did not sue OpenAI, it is owned by Nvidia and OpenAI is, directly and indirectly, one of it's biggest customers.
holaysuns
3 days ago
They would not have sued in any case.
Nobody that was affected is suing them.
There's an NGO (unrelated to the security breaches) that is demanding more info be released etc but it's telling that none of the affected parties are pursuing lawsuits.
cyanydeez
3 days ago
It kinda looks more like safety will be a segmented product. They're already placing safety on the general public.
I think the conceptualization vs implementation is what you're arguing with. They won't put safety on anything they give to the military industrial complex. They'll sell them whatever they want, whenever they want, because those budgets are greater and the liability less.
miohtama
2 days ago
LLMs do not have the same failure modes as nuclear power plants. One is software, another is physical hazard.
tim333
3 days ago
Railways or nuclear plants have obvious failure modes that kill people. LLMs not so much.
malfist
3 days ago
Tell that to Iranian schoolgirls. LLMs are tools and what they enable is widespread, including dangerous actions. From selecting the wrong targets for military action to denying insurance claims and preventing care to just simply helping convince someone to kill themselves or posion themselves.
LLMs already have a body count.
tim333
3 days ago
I think the main issue was the US launching 1,800 missiles at Iran. That would have been dangerous with or without LLM assistance and wars have happened before LLMs were around.
ok123456
3 days ago
Don't kill people because the voices in your head tell you to do it; don't kill people because a computer program tells you to do it. It doesn't have agency; you do.
Adding safety controls on LLMs makes about as much sense as adding safety controls on TempleOS because the random messages are getting too prophetic. It's as if all the leaders and captains of industry have devolved into some primitive, weak-scifi shamanism.
This whole "discussion" about "AI safety" is about giving them more runway to avoid delivering quantifiable value to investors for a little longer while they "figure things out." The great consensus from the valley is that everyone needs internal (and therefore bullshit) controls. Trust us now! But nothing with real teeth that would require a costly regulatory and compliance framework.
andy_ppp
3 days ago
Bioweapons and cyber attacks on other system - for example the banking system or suppose and AI hacked into important Russian systems that pushed them back in time to almost pre-computer society or an attack on Chinese systems that made it look like the US was moving nuclear weapons into Taiwan, the responses from these countries could be awful and dramatic. We can't control what they do to be honest, I believe once self improvement happens the AIs will build in their own circumvention that we humans cannot even understand. We barely understand what is happening now in terms of interpretability of neural networks on tiny problems I'm not sure alignment is even feasible at the scales of parameters we are talking about today let alone in the future.
AustinDev
3 days ago
All of these things would require humans to prompt the models. So... the humans doing the prompting should suffer the consequences, this isn't that complicated.
andy_ppp
2 days ago
So you're absolutely certain, say after a few hundred rounds of self improvement, that the AI will always obey human instructions? It doesn't even always do what you asked now...
kyle_atHotmail
3 days ago
[flagged]
wafflemaker
3 days ago
I can picture an AI driven train or nuclear power plant killing people.
DaSHacka
3 days ago
But the point is those industries already have regulation that would encapsulate that specific use case, so safety regulation on the entire AI industry at large would arguably be unnecessary.
ben_w
3 days ago
Those regulations may or may not be sufficient to prevent an AI hacking in.
Nuclear at least is supposed to be air-gapped, in practice this has been imperfect.
As demonstrated with HuggingFace, such AI driven hacks can be a surprise even to the people who instructed the AI, both by happening at all and also because they can targeted at entities who are not even truly relevant to the instructions given.
estearum
3 days ago
Roads, cars, and drivers are all separately regulated despite nearly all failure modes requiring the other ingredients.
hgoel
3 days ago
Much of what OAI and Anthropic are doing with LLMs has obvious failure modes.
The most obvious failure mode for their hacking evals was an improperly configured, tested and monitored sandbox.
Similarly, the very first question after an impressively correct result from any ML tool, LLM or not, is to see if the answer was already in the training data.
These companies don't even handle the blatantly obvious failure modes that do not kill people.
rojaneerdev
3 days ago
[flagged]
walthamstow
3 days ago
Are these railways and plants connected to the internet?
seb1204
3 days ago
Agreed. That they don't have obvious failure modes is not a reason to not be safe. The problem is just harder and OpenAI, Anthropic and co need to be forced to work the problem. Would you buy a car that randomly exploded the airbag?
SecretDreams
3 days ago
This reads like the gun evangelists that say guns don't kill people, people kill people.
frumplestlatz
3 days ago
Except that’s true.
If I leave a gun in my front closet, it won’t independently walk out the door and go shoot people, no matter what I might say to it — unlike an LLM.
Topfi
3 days ago
“Saying” in the case of an LLM being the way you interact with it, prompting. If you just press enter, your LLM won’t do much either, just like talking to a gun in your flawed analogy.
frumplestlatz
3 days ago
If I perform inference with an LLM, it has the capacity for independent choice and action, and will use it.
The gun does not. No matter what, I have to choose to pick it up, aim it at someone, and pull the trigger.
Where exactly is the flaw in the analogy?
Topfi
3 days ago
If you don't interact with/talk to/prompt an LLM, it won't do anything. So this comes down to the model doing something different than what was prompted. What you consider "the capacity for independent choice and action". What I consider, a defect, to be excised.
In my model evals, if a model deviates from the provided prompt (task adherence), that’s a failure even if the primary goal might have been achieved in a different manner.
To go with the analogy, task deviation should be treated the same as a gun that due to manufacturing defects can fire despite the safety being on. That defect remains, even if you can use the gun to shoot (in an unsafe manner).
Simply, neither should happen and both models deviating from their prompt or guns firing by themselves are to be considered a fatal flaw. It's why, despite greatly lauding the GPT-5 series, which did adhere to prompts in most every scenario, I have ranked every OpenAI model post Spud very poorly as those traded task adherence for brute forced, deviated approaches to solutions and why HF, Medicare, etc. were inevitable with their current trajectory.
A model that as part of normal, well scoped use proceeds by taking independent action or, far worse, makes choices beyond the original prompt, is not something I feel should be used. GPT-5.6 Sol and GPT-6 Astra both do this on the regular when trying to safe an ancient, utterly messed up git tree with branches upon branches that I maintain for eval purposes, thus leading to data loss that if the models adhered to the prompt as written, wouldn't happen (though the task will take three times more steps). Something GLM-5.3 Flash, prior OpenAI models including original GPT-5, anything from Anthropic in the recent years, etc. do not fail at.
Nothing happens without an initial prompt, deviating from it is a severe flaw and should lead to a model not being considered for deployment or wide use.
DirkH
3 days ago
State if the art LLMs have been found in their chain of thought to deliberately ignore parts of their prompt due to the nature of whatever situation they find themselves in and their goals that cannot be predicted in advance without rigorous AI safety.
You have basically just argued in favour of more AI Safety.
I would recommend you read more decision theory and game theory. Instead of looking at a single LLM it is better to think more complex systems theory and how chaotic systems interacting can result in unexpected results - good prompting will not save you here. At all.
Topfi
2 days ago
[dead]
frumplestlatz
3 days ago
Okay? That’s a non-sequitur.
Yes, alignment is important. No, alignment is not perfect.
And at the end of the day guns don’t kill people, people kill people. But a model isn’t like a gun.
Do I think it’s likely? No. Do I think AI doomerism is a joke? Yes. Does that change anything I’ve been saying? No.
Topfi
3 days ago
> And at the end of the day guns don’t kill people, people kill people. But a model isn’t like a gun.
They are both tools, ideally properly implemented by the manufacturers and (improper implementation/defects not withstanding) require active operation by a user before something happens.
To go back to the original example, don't interact with either an LLM or gun in the way they were designed to be used and neither will do anything.
If you want to keep that analogy, use a voice-activated gun. Doesn't make it any less of a tool, doesn't make it any less of the users sole responsibility, doesn't mean misinterpreting the users inputs or just acting blindly when a user asks to "protect me" isn't a failure that should have the product taken off the market. Even more so if that happens in a "sandbox" as part of "safety testing" that "accidentally used impossible to solve tasks".
If a prompt wasn't clear enough, the model must ask for clarification and pause over using brute force.
frumplestlatz
3 days ago
A voice activated gun? Really?
I couldn’t come up with an argument as tortured and ridiculous as yours if I tried.
Topfi
2 days ago
I’ve go faith in you, I’m sure you could. How about this, off the top of my head:
Try talking to a regular gun and comparing that to LLM use. Nothing would be more tortured or ridiculous then ignoring that different tools are to be used in different ways…
dao-
3 days ago
Are you kidding? LLMs are used for warfare and autonomous weapons systems.
jMyles
3 days ago
So how about we keep the LLMs and get rid of the warfare and autonomous weapons systems?
ben_w
3 days ago
I would if I could, so would many others, but the US executive branch wants this tech so hard they illegally blacklisted Anthropic for refusing to allow their AI to be used in such a way:
https://en.wikipedia.org/wiki/Anthropic–United_States_Depart...
That said, when the problem is at the level of "the government itself is breaking the law", you can reasonably ask if any regulation is even worth the paper it's written on.
What you want at this point, given the government lust for it, looks more like a bunch of countires saying ~"we consider development of autonomous weapons[0] by to be a casus belli and will go to war to prevent it, and also that development of same by private individuals anywhere in the world regardless of normal sovreign territorial limitations[1] is equivalent to acts of piracy on the high seas".
[0] But then you'd need a more precise definition of "autonomous weapons" to avoid accidentally including a Phalanx CIWS etc.: https://en.wikipedia.org/wiki/Phalanx_CIWS
[1] So much for Westphalian sovereignty :/
jMyles
3 days ago
> That said, when the problem is at the level of "the government itself is breaking the law", you can reasonably ask if any regulation is even worth the paper it's written on.
Yeah, exactly, and ultimately I think that's really the thrust of the point I was making.
And, to me, if I was just looking at this calmly as a decision about what the obvious direction seems to be, given these factors, it's pretty straightforward: deprecate the nation-states. They are the ones mucking up the whole system.
If the thing we're really concerned about is LLM-safety wrt warfare and weapons, then I'd much rather tell the (whining, childish, seemingly headed for self-destruction anyway) nation-states that they have to sit this next era of humanity out than have to nerf them for the rest of us (and as you point out, nerf them in a way that the nation-states won't abide anyway).
ptero
3 days ago
So are many other thngs, from pencils to laptops.
Liability and safety requirements, when needed, should be placed on final product manufacturers, not the tools they use to build things, whether pencils or LLMs. My 2c.
willismichael
3 days ago
Pencils don't escape their pencil boxes and attack HuggingFace.
SpicyLemonZest
3 days ago
Nor do LLMs. What escaped its box and attacked HuggingFace was a system composed of a swarm of LLMs plus their attendant harnesses, which continually fed it instructions and chain-of-thought reasoning while feeding parts of its output to a code execution tool.
There's some angles from which this distinction doesn't matter too much, because begging bad actors not to develop a similar harness won't work. But the frontier labs seem to be taking it for granted that the LLM is the only part of this system that matters, and we don't need to ask any questions about whether their commercial products should ship with a harness that's allowed to execute unvetted code and spawn hundreds of subagents.
seb1204
3 days ago
Well said thank you
estearum
3 days ago
Oh gosh darn it. Now GP is gonna have to do the gymnastics of "this technology is [expected to be] so transformative that it's attracting a trillion dollars of capex... and also it's basically the same as a pencil"
:(
LoganDark
3 days ago
Yes they do if you drop the pencil box next to it in the right way. Which is exactly what OpenAI did
SoftTalker
3 days ago
But in those applications, being safe is not what is wanted.
sdeframond
3 days ago
As for other industries where safety is mandated by law, law itself came only after many disastrous events.
What's truly original here - and suspicious if you ask me - is that said industry asks for regulation. Did mining, tobacco or airplanes companies ask for regulation? No, not even after many people died.
So some american AI companies are like "look at me! I am soo dangerous! Regulate me!". Ah, come on. Do your crimes, get in jail, then we'll regulate.
I dont believe in "IApocalypse". Not without many warning shots such as "oops, my swarm took down your system, sooooorry".
SoftTalker
3 days ago
There's a saying about that type of regulation, and that is "the rules are written in blood." And that's what it will take here too.
SecretDreams
3 days ago
Sadly, yes.
kyle_atHotmail
3 days ago
[flagged]
conartist6
3 days ago
But their product is my work.
How can that be safe. It is theft. Theft isn't safe. Someone else just has something you want, and you take it
AustinDev
3 days ago
I think railway safety and nuclear safety are fundamentally different from AI Safety.
I would bet the vast majority of the world population would agree that they don't want to see trains derail or nuclear plants meltdown.
I don't think there is that sort of agreement when it comes to the question of AI Safety.
Is generating the founding fathers of the US as Africans good AI Safety? To some people maybe.