100%. First stealing content from creators and pirating TBs of books. And now this. Baffles my mind that these labs can just get away with their 'rogue' agents trying to hack into other systems.
Imagine if a human did that. FBI would be knocking on their door.
Somebody's going to build it. Not building it isn't an option. Would you rather the Chinese built it? The Russians? The Europeans? The Indians? A loose coalition of random hackers on the Internet, like the ones who build Linux?
Well, they'd presumably be different hackers than the ones who work on Linux. We don't know what would motivate them. Maybe they'll do it because they consider the next stage of man's intellectual evolution to be too important to leave up to a couple of American companies and the Trump administration. Maybe they'll do it for the proverbial lulz.
Firstly artificial superintelligence is a science fiction, it does not exist and it cannot be built using existing technology.
Second, plenty of stuff is possible to build, and is not built for one reason or another no matter how powerful. We never built our nukes in space for example. And there is exactly one reason why nukes in space was never built, and that reason is that we agreed not to.
The same authority that allows me to claim that teleportation transporters, hyperdrives, and holoemitters do not exist and cannot be built using existing technology.
What's wrong with what the Chinese have already built? It's not theoretical in that case. GLM, and Kimi are running on my infra right now, and that's something that I can never do with OpenAI's models.
As for the others, what would be wrong about European AI? I'm not European, but I find them to be a continent of fine people, with strong ethical values, there's no reason they can't take the lead on this piece of technology while the US deals with its rather more pertinent electoral and healthcare issues.
I think it was more tongue-in-cheek answer = not building torment nexus isn't an option! Also it's another narrative Americans are pursuing being the world police.
It's so funny that a tiny group of cultists from the Bay Area was really able to convince most of the smart people in America of this. It's not true. China isn't working on this at all. The only people who are trying to make a world-ending God-computer are americans.
Comparing it to nuclear weapons is even more ironic from the only nation to ever use nuclear weapons. They are terrified of other countries treating them the way they've been treated, even though there is no evidence this is of even remote interest to anyone outside their hyperreality.
> they are literally trying to build a superpower that exceeds the impact of the atomic bomb
I think people (the government, powers that be) have given away what they really think by their actions. There are few that take this seriously. The “exceeds the impact of the internet” view has much more support based on investment, but the “danger” aspect does not based on actions. If this was a company making novel prions or whatever that were outside regulation but obviously dangerous, government would be all over them. What regulation we do see is much more power grab than mitigating real danger
The government is all over them. The President of the United States had dinner with one AI CEO yesterday and is having lunch with a group of them tomorrow. The Senate is having a hearing called "Rogue AI: Securing the Homeland Against AI Agent Attacks" on Wednesday.
The argument for copyright violation is very weak. Yes, AI training reads much copyrighted material. So do researchers of all types. That's why there are academic libraries. A copyright violation only exists if what comes out is a close match to what went in. That's happened, but it was considered a bug and was fixed a year or two ago.
Most academic libraries are notoriously protective of their IP and researchers are definitely in copyright violation if they don’t pay significant fees for access.
Of course that is terrible, but it is one of the worst examples you could have given to make your point.
No, the copyright violation is so obvious that people arguing against the object have to spontaneously assert bizarre qualifications for copyright violation that have never existed until LLM companies wanted to freely violate copyrights. Just about a decade ago, people were getting sued for "look and feel." "Blurred Lines" lost a copyright suit for reminding people of a song by another artist.
The metaphor pretended to be reality of computers "learning" being the same as human learning is their last resort, and it is obviously silly. Computers are not human or animal, and learning is something that humans and animals do. If computers are human, then copying a file verbatim to a computer is learning. It's not even worth acknowledging - learning is a metaphor for training LLMs. When I say "you" to an LLM, I'm not referring to anyone, I'm dealing with a UI.
I don't doubt that a lot of AI people have internalized this silliness, which is how they can humor fantasies of how a bunch of programs on different computers explicitly evoked to do particular things might be alive because they can talk with it. I can't talk with my dog, and my dog is alive - so why should having a quality that my dog is incapable of be proof of life? You can certainly conceive of AI that it would be very difficult to say for sure isn't alive, and this certainly is not it. LLMs learn like books speak.
There is no need to invent “bizarre qualifications” for copyright violations, those metaphors exist to explain what is happening in in layman’s terms. Training extracts patterns in the data and encodes them as tiny perturbations in a gazillion weights. That is analogous to “learning” because those patterns represent abstract concepts an relations between them that can be used to “reason” about related topics in response to a prompt.
In the above description, at no point does the actual verbatim content exist anywhere in the model, and copyright law being about rights to reproducing copies (verbatim or substantial portions thereof) does not really apply and does not need any exceptions or qualifications. (If you’re thinking of regurgitation, you should look into studies about it to see how vanishingly rare it is.)
> Training extracts patterns in the data and encodes them as tiny perturbations in a gazillion weights.
I could say similar things about JPEG compression. And -as it turns out- the raw output of both LLM "training" and JPEG compression are equally incomprehensible. You either need a computer program or an enormous amount of time, patience, and careful effort to convert it into a form so you can make any sense of it.
No, you can't say that about JPEG compression. I know how the output of a JPEG compression is structured so it is not incomprehensible to me. (I have worked with A/V transcoding and written custom media compression schemes, but anybody can look up how JPEG works.) JPEG performs relatively straightforward, deterministic mathematical transforms that are actually reversible if you do not discard details (but discarding details is what makes it compress better.) JPEG does not extract patterns from a billion images of, say, cats and encode that into weights that represent the concept of a "cat". Or dogs, or cars, or faces.
LLMs do, and they encode so many concepts and the relationships between them into so many weights that it is a literally incomprehensible blob of floats. They are not just a storage format, and there is no way to recover the original content verbatim from these weights, except for a very small handful of extremely popular works like Harry Potter.
As another example, JPEG will discard details from the original image, and when decoded, will display missing details as blocks. But it will never hallucinate output that never existed in the input data. Like, a JPEG of a cat can never randomly be decoded into an image of a dog.
And -as it turns out- the raw output of both LLM "training" and JPEG compression are equally incomprehensible. You either need a computer program or an enormous amount of time, patience, and careful effort to convert it into a form so you can make any sense of it.
You:
I know how the output of a JPEG compression is structured so it is not incomprehensible to me.
Looks like you didn't read what I wrote with sufficient care.
> ...there is no way to recover the original content verbatim from these weights...
It's impossible to recover the original content verbatim from a lossy compression system. Systems that don't have this property are called lossless. Also, consider the report from the end of August at [0].
> But it will never hallucinate output that never existed in the input data.
Odd... I'm pretty sure that the blocky compression artifacts I see in this JPEG on my desktop weren't in the scene that I set up to capture in that photo. Maybe I need to get my eyes checked?
Why would it matter if I stored exact copies of copyrighted works? Storage format is irrelevant. All you need to say is in that last sentence: it’s all about whether the output is considered a derivative work or a too close of a copy.
But that's the thing, LLMs don't store exact copies and neither can they reproduce them. The cases of regurgitation have only been shown to work for a very small handful of extremely popular works.
People are people, LLMs are a commercial product. IP in question wasn’t not used according to its license, while researchers in general access it within licensing agreement terms.
Here we have a commercial product that is produced using IP against its licensing agreement, contains said IP within it, and can (closely) reproduce this IP.
I might be talking out of my ass, but is it possible that there are cases being built on them? Surely any prosecutor worth anything would love to take a swing, but it takes a lot of time, effort and patience to build a case that isn't going to fall apart against these titans (that have massive political backing).
> We must move past vague discussions of “AI” and instead isolate the specific types of systems that are creating problems.
This is absolutely correct and its surprising how rarely you see commenters in the media push to go into the specifics on this. AI is just matrix math and its what you connect that math to that matters, we should talk a little more about what we are willing to connect AI to and little less about how scary or capable the models appear.
A good start might be removing virology info above the undergraduate level from training sets. The main "kills everybody" threat involves biological viruses.
AI-driven hacking is a problem, but it's really just nation-state level hacking available to smaller companies or wealthy individuals. Everything needs to be toughened up to the point that doesn't work. Ask countries that have been up against Russian hacking for years, such as Estonia.
Beyond that, most of the threats are not that serious. Below the level of organized crime or corrupt government.
There's no evidence that a doomsday virus can be created. There's a tradeoff between how infectious and how deadly a disease is. You would have to develop a two-stage virus, and that would require a large lab or labs with material being shipped there. Something humans would definitely notice. Even then, how would the virus reach literally everyone? People will take measures to not become infected once the threat has been identified, and some people and groups are isolated as it is. And no virus kills everyone. Rabies comes closest at 99%. But unlike what the zombie genre would have you believe, it has a poor means of delivery.
This isn't like vibe coding. The AI would have to make the virus in laboratory conditions and then disseminate it globally without prior detection.
You don’t need to attack humans directly. Simply making and distributing a virus or fungus that successfully damages the grasses that we use for the bulk of our calories would do the job.
You'd need to hit wheat, corn AND rice at the same time. And we probably have 10 others we're not using because those 3 are already enough. It would be a tragedy but we can eat lots of things.
Yes, with AI I will be able to simply build a doomsday machine. Claude will just tell me how to build a supply chain, circumvent regulations and do this without anyone finding out.
You could say it's illegal to connect AI to something, with heavy penalties if you're caught doing it anyway.
You could say that the human who hooked up an AI that did something that's already illegal is liable for the AI's actions. You could say that setting up an AI to do something illegal results in, ooh, an automatic multiplier of 10x on whatever the penalty for its illegal actions are.
Realist. The cat is out of the bag on this - you can't make connecting an LLM to a command system illegal after hundreds of millions of people have already done so. You can however make it illegal to kill everyone with a nuke because your LLM did so. Not that it will make a difference after the nuke goes off.
You mean mo political willpower form the current US administration and Congress. I'm not sure what "endgame" is supposed to mean. There are future elections, including the US midterms just weeks away.
Yes, and there seems to be plenty of potential energy from the American public, given something like 8 in 10 support AI regulation even if it slows down innovation: https://archive.ph/PetJ5#selection-1329.0-1329.122
Even if another political power takes control, the American population is the least of our concern for it being legal or illegal to connect an LLM to a command line or job system
I'm sorry the parent is right. There is no policital will power to do anything about this from either side. Criminality is being allowed on both sides of the spectrum. Institutionalists are on the side of criminality. It keeps them in power
I get the cynicism but this actually feels like a special moment in politics right now. There is a groundswell of bipartisan support for AI regulation [1] and a backlash against data centers which is a symptom of anger against the industry. It is enough for a Senate probe to be opened against OpenAI [2] and pushback against Trump's support for data centers on his own social media platform [3].
Im not much on communism because I think it can go horribly wrong in the other direction but this guy has a point about populism[0].
We keep falling for the same tricks, over and over again. There is no possibility in the current structure of government for this to be a win for the people. For anything to work, we need a structural change in the entire system.
Maybe you don't realize that conservatives hold all 3 branches of government right now? Liberals have no power to do anything, and that is not the same thing as being complicit or having no will power. Where liberals do have power - like in California - they have started enacting laws regarding AI. Your "both sides" argument simply holds no water.
As it is, I am not sure that in what concerns US administration, elections will solve anything, this assuming that they won't be tainted like in many non democratic countries with "elections".
We don’t even need to jump straight to legal penalties - why not just regulate that these companies can’t build partnerships with organizations in designated risky/regulated industries such as biotech, defense, etc?
Instead of what they are doing now, which appears to be actively courting as many of them as possible for vast sums of money.
Sorry, let me clarify. Regulations should have legal penalties for the corporations who violate them, yes.
What I meant was that we do not need to go from the Wild West straight to “anyone who, as an individual, connects a `bad thing` to an LLM will go to jail”
> We don’t even need to jump straight to legal penalties - why not just regulate that these companies can’t build partnerships with organizations in designated risky/regulated industries such as biotech, defense, etc?
This would be a good idea, but good luck, you'll need it because…
> Instead of what they are doing now, which appears to be actively courting as many of them as possible for vast sums of money.
… it's worse than that.
Anthropic may have wanted some defence sector money, but when they tried to say "no" to certain uses on the quite reasonable grounds ~"WTF are you nuts?" the US government tried to force them to supply it anyway.
And that's before we get "what do you mean by partnership?": people on Hacker News have been critical of the e.g. anti-bioweapons type guardrails on models ("censored", "lobotomised", etc.) since at least GPT-4*, so while "billion dollar mega-project headline" is obviously bad, there's an important sense in which "partnership" goes all the way down to one racial supremacist in a shed asking an LLM for help making ricin.
Here's someone three years ago replying to me to say "There’s no way to build out a wet lab with a chatbot for weapons production. It’s just not feasible. Your example is a fantasy.", and yet here we are in late 2026 with news about AI labs investing in bio wet labs and getting their LLMs to do research: https://news.ycombinator.com/item?id=38331225
Good thing it's not a weapons lab, eh? (Would anyone even tell us if they made an agent do weapons?)
* or even GPT-2, if you count all the people mocking them for trying to practice safety while failure was still not a disaster.
I don't see anything materially different between me running a curl request that exploits something vs my local AI running a curl request. They're both programs I run on my computer. That's all Open AI is doing. They are hacking people from their computers. There's nothing complicated about it.
Right, and further, I doubt a defense of "I downloaded this worm from the deep web but I didn't know it would hack everyone when I ran it" would fly in court, yet that's exactly what the "I shouldn't be responsible because my agent "escaped containment"" defense is.
What if you've been training your dog to bite people? (I.e. in OpenAI's case training their models around finding exploits in software, training on cyber security material, etc.)
For dogs, it moves from civil to criminal with circumstances such as what the owner knew about the dog’s behavior, how serious the injury was, whether the owner intentionally or recklessly allowed the dangerous situation, and any prior incidents. Same can easily be applied to AI labs.
> Yes you can, the US could shut down the entire internet if it wanted.
No, they can't. The rest of the world would just route around the US with BGP. All of the US infrastructure/service providers would be down, so a ton of things would break, but the Internet would not be "shut down". The US government also no longer has authority over the DNS root servers. So unless you're referring to thermonuclear war or some similar scenario then the US does not have this capability.
Why does it need to come down to making it illegal to connect AI to something that influences real-world outcomes? Just do what we should already be doing: hold operators accountable for launching cyber attacks with a botnet.
You just quoted the first 33% of words in an independent clause, then restated the point being made in the remaining 67% as if it were somehow a rebuttal.
The original statement pointed out that it’s just matrix math as a way of indicating that the technology itself is ethically neutral, and then went on to say that what we really need to pay attention to is how it’s being used. The “connect to” choice of words is clumsy and I don’t love it, but it does at least get at the point that AI doesn’t inherently become responsible or irresponsible until you hook it up and actually start doing things with it.
Which, if it’s not exactly the same point, I’m pretty sure it at least cuts quite close to the point of your rhetorical question, right? That the problem isn’t with the ones and zeros, it’s with what certain people are doing with the ones and zeros?
I think the problem is the ones and zeros or the linear algebra if you want to use that metaphor. I believe "progress" in AI needs to be stopped. AI researchers need to find something else to do with their lives.
My first comment was an attempt to show the "it's just linear algebra" argument in an absurd light.
> The original statement pointed out that it’s just matrix math as a way of indicating that the technology itself is ethically neutral, and then went on to say that what we really need to pay attention to is how it’s being used.
I think the idea that this technology is ethically neutral needs a discussion.
A matrix is a mathematical abstraction, a technique for representing and manipulating relationships between quantities. You can call matrix math a technology, but then the term loses most of its meaning. I'd reserve the term "technology" for designed artifacts and systems: cars, guns, social media platforms, LLMs. Design requires intentionality, and these things are built by particular people, for particular purposes, under particular constraints, and those purposes get built into them. A gun is designed to kill and that purpose doesn't disappear depending on who holds it. Ad-funded social media platforms are optimized for engagement, and features like infinite scroll exploit known cognitive tendencies to achieve that. With LLMs, developers decide what data the model learns from, what it will and won't do, and whose values shape it's behavior. Of course, how we use technology matters too. But building something is a deliberate process, in which the builder makes a series of decisions about what to build and how. Many of those decisions involve trade-offs that affects people. That's why I find it unconvincing that technology is ethically neutral.
It sounds like we agree on everything but some semantic distinctions.
Because I would argue that the thing that might make an LLM harmful or not is not the underlying technology. It’s the ways its training data were acquired, the purposes for which the model was trained, the applications for which it’s being deployed, etc.
The fixating on “it’s just matrix math” doesn’t feel useful to me. I’m an NLP person and agree that it’s a huge oversimplification. But the original commenter’s purpose was not to educate people about how LLMs work in detail, and so being pedantic about it only serves to steer the conversation in an unedifying direction.
What is "AI"? Are you referring specifically to LLMs powered by matrix math or a more general concept? Could that even be legislated in a way that wouldn't fall afoul of the vagueness doctrine?
“Commenters in the media” is fair - but Newport is also a compsci professor. He genuinely seems to understand what he’s talking about when you read his content or watch his videos.
A point that Yann LeCun has been making for a while is that it's meaningless to regulate AI, but we want to regulate applications. For instance, you don't want autonomous vehicles to hit people, whether they use AI or not. In practice, most applications of AI are already regulated.
look, there's a lot of room to complain about moving the goalposts of what counts as AI, I get it
but I don't think a simple PID controller in the autopilotnmanaging altitude, heading, and the like has ever been categorized as "AI." Cybernetics,
maybe.
even the rules managing the flight envelope and MCAS on the 737 Max, or the Airbus implementations of flight law, sure seem to have relatively few of the attributes that tend to get the label these days
It means you are out here autonomously dropping logical fallacies.
Autopilots are autonomous, without AI. lane following and collision avoidance in most cars, don't use "AI" they use classic computer vision and good old fashioned radar.
The difference here is that claude code fails to perform what it's intended to do without a model attached, a plane/car doesn't.
Classical Computer Vision is AI. Computer Vision is a subfield of AI since the beginning.
People may confuse AI with Machine Learning. “Classical” computer vision generally means non-learning based techniques. But ML is also not new to computer vision. So non-classical actually means using Deep Learning.
So today when people say AI they actually mean Deep Learning.
After staring at your comment for a while I think what's happened is you've confused the non-AI autopilot and flight control systems used in an airliner with the AI-driven autonomy being used in military drones.
GP's point is that the goalposts of what counts as "AI" have been constantly shifted for decades, and right not it seems that even many HN commenters seem to have somehow gotten the idea that "AI" strictly means "deep learning neural networks" (or something even more specific like "generative transformers"). GP just went a bit too far in the opposite direction, being too inclusive in their definition.
FWIW, my working definition of "AI" is "anything discussed in the latest edition of Artificial Intelligence: A Modern Approach". It seems to work well.
> GP just went a bit too far in the opposite direction, being too inclusive in their definition.
> FWIW, my working definition of "AI" is "anything discussed in the latest edition of Artificial Intelligence: A Modern Approach". It seems to work well.
You're kidding, right? It's never been an obscure term. If a computer is making decisions, that's AI.
> I'm getting back into [Starcraft: ] Brood War after a long break. Don't have the time to play ladder, but want to be able to play 1v1 against AI, however, the stock AI in remastered is terrible
Game AI is invariably called by that term and generally implemented as a fairly simple if-else ladder. In a taxonomy I guess it would be called an "expert system"; I can find them mentioned in the detailed table of contents to AIMA (3rd edition), but not in the simplified table of contents to AIMA (4th). They might still be in there, in the same section titled "Making Simple Decisions". Norvig doesn't really bother to consider expert systems with probabilities constrained to 1 or 0, though.
The fact this thread descended into a load of philosophical chin stroking about what is truly AI perfectly illustrates the core point that all regulation should just be targeted at use cases and what people are doing with the software.
If a plane could run on some sort of local LLM it should still be governed by the same laws and damages when something goes wrong same as people don't spend time quibbling about the implementation language of software they care about demonstrating capabilities.
Ofcourse they do reasoning and planning, it's entirely encoded in software ofcourse, but modern autopilots don't just hold a course, they perform maneuvers and follow waypoints the process of turning the objective turn 35 degrees to actuator inputs is reasoning and planning.
AI is not magic it's software, the definition is far from pointless, google maps giving you a route to your destination is AI.
In the academic definition of AI (which includes things like pathfinding with A* or Djikstra's algorithm) autopilots are definitely AI.
The popular definition of AI seems to shift every couple of years to follow hype cycles. Chess computers used to be AI (and fit your definition), now they are not. Not sure if Resnet is still AI today, or if autopilots still qualify
You can't say that to an mri machine that detects and highlights tumors. You can't say it to jev either, nor googles spam filters. But all these are built in the same way as any LLM. The term AI is not restricted to chat based LLMs.
None of that applies to autopilots though and it’s disingenuous for anyone to say that an autopilot is an AI rather than an automated system designed for a very specific task.
An autopilot is cybernetic without being intelligent.
I was giving a framing around its complete lack of generality or intelligence. Rather than contemporary definitions of AI shifting, what is being shown is that previous definitions of AI were misapplied in the hope that the field might bootstrap itself into existence, which it’s done.
As I’ve said elsewhere - an autopilot is cybernetic, it responds to inputs and stimulus in data but it doesn’t possess anything we’d now regard as falling under intelligence because it’s a strictly coded deterministic system and designed for it’s specific environment. I couldn’t take the autopilot from a Boeing and put it into an Airbus and hope for any kind of useful result. I could take a human pilot trained on a Boeing and put them in an Airbus or a Cessna, and if push came to shove in an emergency, they could probably do a decent job of getting the thing pointed in the right direction and landed on the ground.
I would say minimally regulated. For instance, felons are for the most part not allowed them, and there are certain locations where they are not allowed to be carried.
I think you're arguing the opposite of what you think you are.
Regulating gun ownership is exactly regulating the application.
In your analogy, the gun is the AI. What you can do with the gun is the application.
Different actors with different credentials in different contexts will have different requirements and permissions of what they can do with the technology, be it a gun or AI.
I am having a brain aneurysm trying to understand this
> Regulating gun ownership is exactly regulating the application. In your analogy, the gun is the AI. What you can do with the gun is the application.
From what I can tell, you are arguing that gun laws is reasonable.
> Different actors with different credentials in different contexts will have different requirements and permissions of what they can do with the technology, be it a gun or AI.
But this, is going against that, this is saying, "why should we ban AI or gun when they can be used for both good and bad. What we want is to ban bad, regardless of how it is achieved"
"Different actors with different credentials in different contexts"
The argument is that the military or police have a need for access to guns, whereas the lunatic on the street corner (or any random citizen) does not. The same argument applies for access to nuclear, biological, or chemical weapons... or autonomous hacking/killing machines...
> From what I can tell, you are arguing that gun laws is reasonable.
You aren’t going to repeal the second amendment, so reasonable or not it’s a fact that everyone has to contend with. Do we all want guns? No. Do we all want AI? Also no.
> What we want is to ban bad, regardless of how it is achieved
No, we don’t want to ban bad. Banning doesn’t really work - the effort to reward ratio isn’t great. We want to regulate bad and see if we can minimize the damage it can do.
There are levels to it as well. Take alcohol and driving, for example:
Level A: Who can drink it (possession and consumption law)
Level B: What you can do while drunk (DUI law)
Level C: What you can do while drinking (open container law)
All orthogonal to things like reckless driving, endangerment and creating injurious accidents, which are already criminalized without needing additional laws against alcohol use to enforce them.
> From what I can tell, you are arguing that gun laws is reasonable.
Correct.
> But this, is going against that, this is saying, "why should we ban AI or gun when they can be used for both good and bad. What we want is to ban bad, regardless of how it is achieved"
Not at all. I'm saying regulations do that and they are a good thing. Not everybody can own an assault rifle. Some of the people who can, are not allowed to carry it on the streets. Police will have very different regulations towards their gun use. The army, another set of regulations. The list goes on. Even in countries who have lax gun laws, usually not all guns are allowed to everyone in all situations. No one is allowed to carry a nuke into a shopping centre.
Note that regulating and banning are very different things. I don't think you can fully ban guns or AI.
I'd say yes, but for a different reason. The specific types of systems that are creating problems are the political/economic systems in which these AI companies exist. The types of responses we ought to be taking would destroy not only the AI companies but also basically all other large companies with too much market power in various sectors.
Why aren't they running agents on isolated computers without Internet access? This way, breaking free of containers would not matter.
It is truly a security nightmare that so many people are have given agents root access to their entire computers, in addition to presumably very private personal information.
How about they create a virus that copies itself onto USB drives? Getting that virus out there doesn't sound that hard, just creare some crap game.exe and put it on itch.io for free. All it takes is for a kid to borrow nuclear-engineer-dad's USB drive and plug it in their infected PC.
I'm not a fan of using AI, it doesn't amplify the work I do that much, but I'm terrified by what is already possible today.
> All it takes is for a kid to borrow nuclear-engineer-dad's USB drive
Do nuclear-engineer-dads take work usb drive home. Are their computer even allowed to have usb. I'm typing this on a dell latitude, and you can disable usb and other peripherals inside the bios.
My last job, I had to apply for an exemption to use the USB ports. And it was run of the mill software engineering.
...why not pitch a start up that sells AI agent that don't train with/for internet access/usage?
1) Because effectively all of the hardware used for that task is earmarked for the major LLM manufacturers.
2) Because in a just world, the major LLM manufacturers would get punished for their flagrant deception, lawbreaking, negligence, and recklessness, [0] go out of business, you'd get all the hardware that they were using at fire sale prices and save a ton of money compared to attempting to start up now.
[0] Based on their recent claims, building WMDs [1] without adequate safeguards is the most negligent and reckless thing they've been doing.
[1] It's fair to call anything with a 10% chance of wiping out all of humanity a WMD.
I feel like you missed my point. To be slightly more explicit, I find it comical how willing security people are to build a "secure" product that's completely useless for getting work done.
Your second clause is sufficient there: they're not going to have a good time trying to sell AI that can't access the internet, because accessing the internet (and other computer systems) makes AI much more useful.
Sooner or later, agents must be connected to the real world to do economically useful work. The sandbox failures are bad, sure, but the underlying misbehavior is the root problem here.
I think the way they're connected to the real world doesn't have to be as free-form as we're doing now.
If you think AI can help design new drugs, great! Let's pick some restricted DSL for describing molecules, preparation instructions, hook it up to the right set of lab robots that can pipette and centrifuge and whatever, _restrict its output to that DSL_, and let it iterate. The 'let an AI design drugs' process doesn't require that the agent can also, say, hack a niche German wiki.
For every area where we think these AIs can be _so valuable_ because they'll find solutions that humans wouldn't (or find them faster), then doesn't that value also imply it would be worth it for some humans to do some advanced setup of their specific domain-specific tools so it can be run in a sandbox equipped with only what it needs and not more?
Anthropic claims that their intention with the agents that led to the Hugging Face hack was an offline experiment running against a hacking benchmark.
Either you're being pedantic and missing the entire point, or you're saying that Anthropic lied and made a fake sandbox knowing their agents would need to connect to the internet anyways.
But the specifics here are the thing I was describing. This was cyber capabilities training on model(s) that were in a relatively unknown state of alignment training.
Because of the unknown alignment (and for varied practical reasons I guess) the training is intended to be inside a sandbox.
Because the training is on cyber capabilities, the models need access to simulated cyber environments, including target endpoints, including package managers, etc.
For package management, they set up Artifactory as a secure proxy. Agents ask Artifactory for packages inside the local network, and Artifactory serves them directly or goes to the internet to fetch if they are not cached. But the agents hacked Artifactory to steal its internet access.
So: to train cyber abilities, you need to at least approximate cyber environments. To realistically approximate cyber environments, you need to either pull a full copy of the entire internet to local or to use proxies. The former is pretty impractical, and the latter is exposing our limits at creating secure proxies. Yes, any specific failure can be mitigated, but the models get stronger and stronger. Fingers-crossed this is not escapable doesn't feel great!
I think there’s a 2022 way of thinking how models are trained/evaluated, and there’s 2026 way of doing things. Models that are not evaluated with public internet access are pretty useless nowadays for daily operations.
Because then it wouldn't scare the governments into regulating models that are undercutting them. This is just an obvious tactic too and it seems like it might be backfiring a bit. Congress might be a bit dumb, but they're not that dumb.
This is a wrong-headed attempt to regulate AI. The real problems are different.
AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals. When you read the logs from the Hugging Face incident, you're seeing something that looks a lot like internal corporate emails. Various units of the organization are arguing over what to do and who does what. They eventually converge and get the job done, breaking the rules at times. This is normal corporate behavior.
When agentic AIs do something outside their own internal world, they do it by engaging in transactions with external systems and people. As yet, few have robots to do their bidding.
So, again, this is normal corporate behavior.
A corporation is a goal-seeking system. In theory, if you agree with Milton Friedman, its sole purpose is to maximize shareholder value. Internally, within the company, there are subgoals, which exist to support the top level goal. That, too, is what multi-agent AIs do.
The uncomfortable place this thinking leads is that AI regulation and corporate regulation are very similar. That's not something the political part of the world wants to think about too hard.
It would mean putting more constraints on corporate power.
Yet that can't be ignored, because we're likely to see corporations where some parts are AI and some parts are human. That's already been done a few times as a demo, not too successfully. Yet.
It's going to hit hard when an AI-run company outperforms a human one.
I largely agree with this take. Unfortunately I think capitalism's political pressures have too much of a grip on society for there to be meaningful changes to the power dynamics that perpetuate the status quo.
I can't vote in America. The rest of the world is at the mercy of those within America that can as long as we're dependant on American products and services.
That's true, but you can support and encourage policy that would reduce your country's dependence on the US, especially when it does so by supporting local products and services. Not only would that be good for your local economy, but you gain resilience and security.
You can work to limit your own dependence a little as well. Seek out FOSS products and alternative services and replace what US run services you can as often as you can with them. Reject small conveniences that require giving large amounts of your data to US companies.
"more constraints on corporate power" assumes that the existing ones are functional, which they arguably are not.
If we enforced existing laws against unauthorized access to someone else's computer resources against the companies who run a model that hacks someone else, rather than buying their "The agents did it, we're not responsible" BS, then maybe the incentives to behave responsibly would improve.
OpenAI immediately disclosed the hack and submitted to both internal and external investigations, and published extremely detailed breakdowns of what happened. How is that not taking responsibility?
The penalty for "unauthorized access to a computer system" is 1 to 20 years in prison[1]. Holding corporations accountable would include sending the highest person in the chain-of-command that caused the Hugging Face incident to jail. Or at least start with some charges and then let the judicial system do its thing.
To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight.
You put people in jail
if the other incentives aren’t enough.
We have a system of law and order that puts people in prison if they commit crimes.
> To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
You could ask this (and people have done) of any criminal code. It doesn't matter. The law is not there to rehabilitate, it's there to punish and thereby deter.
> They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight
If a person breaks the law, the state prosecutes them (or can choose to), we don't require the victim to press charges. For good reason - threatening the victim to not press charges would be a way of avoiding consequences.
> You put people in jail if the other incentives aren’t enough.
This is incorrect. We put people in jail as a result of them breaking the law, regardless.
We absolutely should apply this principle to corporations as well as citizens. Aaron Schwartz died for less.
> The law is not there to rehabilitate, it's there to punish and thereby deter.
Technically, it's neither. The law is there to state what ought to be. Even putting that aside, it's prescribed punishment's goal is to remediate and prevent violations of the law, so it has three simultaneous means: to restitute, to deter and to rehabilitate. The balance between the three is predicated on each's ability to satisfy the original goal of remediation and prevention, all the while not violating other laws and rights.
> We put people in jail as a result of them breaking the law, regardless.
A core principle of the rule of law is the principle of proportionality, which states that only the most legal amount of force is the materially sufficient enough to prevent a crime. If lower measures are sufficient to prevent a crime, jailing should not be prescribed, not only to respect the law but also to make good use of scarce resources, as prison overcrowding may not only reduce their effectiveness, but also open the door for downstream right violations.
Hugging Face was another AI company. Do you see many of those suing each other and especially the top dogs in the field? Also, do you think it's a coincidence NVIDIA bought Hugging Face ASAP to stop any damaging anti AI waves from happening?
The other incentives aren't enough. All the labs are basically Russia against Ukraine in 2022-206: launching high caliber imprecise ballistic missiles against military targets surrounded by civilians. Whoever orders that knows civilians will do die but doesn't care.
AI labs aren't using proper sandboxing measures for their agents because that would slow down their testing. Plus any hacks that happen, short of breaking into Trumps social media accounts, only cause the kind of publicity they want.
Hugging Face disclosed the attack. OpenAI owned up to it a week later. It's unclear when and if OpenAI would have disclosed it if HF hadn't already done so.
For a more recent example, OpenAI was chastised by Australia recently for notifying them three months after their agents attacked AUS government websites.
You can already run a sufficiently automated basic news/link aggregation site on cloudflare so I think you're right & the timelines are shorter than would be expected.
I agree with your framing of agentic AI systems as similar to corporations. That's interesting!
But what in TFA suggested to you a specific and wrong-headed regulatory approach? As I read it, the post calls to investigate the AI labs, to increase transparency of their operations. The linked NYT piece says:
> Before any intervention, Congress should lead a public fact-finding mission that reveals the unvarnished details of A.I. development.
Isn't this the first step to holding any corporation accountable, whether it is made of people or software?
The paper calls for investigating the development process. Not constraining the deployment process. Use of AI systems by Flock and ICE, for example, is a deployment issue. Using AI to evaluate loan applications and resumes is a deployment issue.
The legal model to look at is the European Union's General Data Protection Regulation. That regulates what companies can do with data and how they can use it against people.
You can develop anything you want in the data mining and analysis area, but the GPDR restricts how companies can use the results.
Focusing on the development process moves political attention away from what modest AI systems can do to people. They don't have to be super intelligent. Just super attentive. Always watching. Current technology is more than sufficient for oppression and control purposes.
This is the near term threat.
There's the threat to jobs, but that's something society has handled before. Some countries better than others.
There's a glaring absence in your analysis, namely, why didn't OpenAI take action to prevent such a problem from happening in the first place?
What narratives that focus too much on the drama of the agents miss is that it is primarily a sin of omission. The whole incident would have been prevented if OpenAI took basic security measures and ensured their systems were constrained in behavior. The agents were given more or less free rein (open internet access for example is already a major blunder that even a novice probably would think to account for).
Half the reason these incidents are happening is due to the incompetence of the humans building these systems. Don't let them get away with their little parlor trick of converting negligence into a PR stunt. That's exactly what they want. They need to face consequences for their inability to follow basic security practices and reign in their agents. They are the operators. Hold the controllers accountable. It's 100% possible to build agent swarms that are reasonably constrained. They are not (yet) totally misaligned uber hackers that will defy your every instruction and hack your every guardrail. That is still a fiction. Agents are still good at instruction following and, seeing as they can only operate in a computational environment you can constrain them significantly more than humans in the real world.
If we accept that AI systems are similar to corporations, then it seems clear that we must try to avoid the mistakes we've made in failing to hold corporations accountable for the harms they cause.
We should not only regulate AI more than we do corporations, but we should more strongly regulate corporations as well. There are corporations right now that are killing people, using slaves, and bribing governments just to increase the already massive amounts of wealth and power they have. If AI is showing any signs that it is going to act like corporations do we'd better act quickly.
It's not possible to regulate AI. Anticipating this would happen, I liberalized it a few years ago by turning it into a file that reads and writes text to stdio. Then I shared it with every man woman and child on earth. Now we all possess this great nuclear weapon. Good luck controlling that.
Corporations are made of humans. An airline may be a corporation, and it may take people's lives into it's hands, but when a plane crashes the pilots are the first one on the scene.
> AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals.
That literally doesn't mean anything from a legal standpoint. A corporation hires human beings and has human beings in control who can be sued or punished criminally. You cannot have a corporation without a human responsible for it in the legal sense. So if AI systems are akin to corporations, the question is who is the promoter in this situation and what are their rights and obligations.
Otherwise, I can also say a McDonald's burger is more akin to poison than food. So just like poison, we must ban McDonald's. But you never really established your points for arguing that it's poison. You just write it matter of factly and expand on it, which is not the way to make a persuasive argument.
> You cannot have a corporation without a human responsible for it in the legal sense.
If the chain of ownership is complicated enough, you can. Especially since Trump suspended the Corporate Transparency Act.[1] Look up "Anonymous LLC". If you're willing to work through one of the sketchier offshore corporate havens, more hiding is possible. There are services that will set up an offshore company online. Some accept Bitcoin.
We have all sorts of regulations what corporations can or cannot do, who can run certain businesses, how certain businesses need to operate internally and externally - I don't think corporate power is the issue.
Also, not sure it makes a difference in relation to AI whether one thinks of AI more like corporate or a non-corporate thing to regulate. The basics might stay the same, e.g., who can do what under what procedures.
No regulations on corporations are enforced? That doesn't seem to be case. Making it about a bigger issue it reduces what pretty vanilla regulation could actually achieve, I think.
Maybe I'm a bit too skeptical/cynical, but it certainly seems like the frontier labs have fallen into their own (self-created) AI psychosis.
There is no doubt in my mind that LLMs are fantastic machines, but the imminent jump from "AGI" to "ASI" seems premature (not to mention the ever-shifting goal posts of AGI itself).
I'm in the "move as fast as possible" camp and work with LLMs all day, but I still don't believe we're a hop and a skip from ASI.
In fact, I hope I'm wrong. I hope ASI is around the corner.
What scares me though, isn't ASI. It's "AGI" (_dumb AI_) used by humans to make decisions for them, because they trust it knows best.
It's the ceding of intellectual control to high-dimensional magic mirrors, giving up critical thinking because _we_ want to believe _we_ created artificial life.
This is the new Turing test, and too many smart people are failing.
I feel "willpower" makes it sound a little too conscious, as opposed to habits and conditioning.
A good analogy might be a very smart person with a gambling addiction.
Knowing they ought to quit doesn't mean they can quit. Their intelligence becomes invested in the act of gambling itself, and almost no amount of reasoning can help them exit from a situation they didn't reason themselves into.
People are already doing that, and have frequently lost track of the fact that it does not mean that they have gained any skill or knowledge, nor do they have an actual way ot ascertaining whether when there is a correct answer the processes used, which they do not understand, is able to reliably reach it, especially edge cases.
Sometimes the outcomes are comical. I just received an automated email from ElevenLabs saying that its automated systems have detected that I may be using its services to create voice versions of materials that harm children. I had it prepare audio versions of several books and academic papers about moral panics that conjured up out of nothing... about harm being done to children. At least that's what I assume. Either that or somehow I had an API key leak from my on-premise homelab, but the usage recorded would mean that they are basing a semi-conclusion based on a tiny sample. I have no distributed any of the outputs, I own the books and have access legally to the studies, because I have a background in the humanities. I also have no children, which ElevenLabs better not know, although how studies of moral panics can cause any harm in children of any kind is literally unimaginable. It's a waterfall of potential errors summed up in a vague email. My API key and the web interface works just fine regardless.
It's one thing if this is a product in beta, but this is their production model. Harming children is a serious accusation except the legal concept impossibility and the admission that this was not an actual lawyer (like I am) but some effective form letter hedging the vaguest of accusations made by some model lacking the ability to discern substance and meta-substance makes it frankly hilarious, and wildly irresponsible. I realize that by academic credentials I'm out of my lane but by experience I am certainly not, and they should recognize when they should stay in their lane and not just run Jev and think it's fine and dandy when done unsupervised (I presume).
Also, AGI is by definition asymptomtic surely, since there would be no way to benchmark it in a manner that isn't asymptotic. We're nowhere close to that. But we're so far from that, it's comical that people who clearly have zero idea of either the technical or conceptual aspects of basically a piece of software that is very good at quickly bruteforcing the correct or acceptable next token to be anything more than that. Even with some serious training and many hours spent on vast.ai I've yet to have created a version of a frontier model that is actually "good" at hacking in my own homelab setting. Although the the time stock Fable 5 missed a favicon shell on a basic jar (turned out they nerfed the hell out of it, this is why I only pay for the massively discounted tokens from Chinese proxies if I'm using American models or sometimes the freebies if you figure out how to get onto linux.do or similar sites). If anyone reading this is a high school English teacher, please inform your class (assuming the homeric stuff is still being taught) that there's no upside of being Cassandra but the record itself, and that should be enough.
> What scares me though, isn't ASI. It's "AGI" (_dumb AI_) used by humans to make decisions for them, because they trust it knows best.
Unfortunately this is what we have, which the whole huggingface incident demonstrated.
It made it clear that OpenAi is basically not even paying attention to what their agents do half the time.
It also revealed how far agents are from "superintelligent". Maybe others disagree, but I would not call an AI that decides to try and paperclip max an intentionally impossible benchmark task "intelligent". Human beings are intelligent and we can usually tell when something is impossible, and stop (though of course, not all the time). A real intelligence would be able to detect the futility of tests and also be able to parse context and intent enough to know not to cheat.
So somehow we have machines that fail basic barometers for general human intelligence being called "ASI" now. Of course the linguistic dodge is, you shift from talking about "intelligence" to instead claiming "oh it's intelligent it's just 'misaligned'"
Saying "AGI/ASI isn't inevitable" is like saying "war isn't inevitable". Sure would be nice if it didn't happen, but realistically it's going to happen and it's better to mitigate the fallout rather than try to fight very large intrinsic incentives. I appreciate that this article doesn't conclude "let's stop doing AI", but rather "let's try to examine and adjust incentives".
I think it's inevitable long term (decades/centuries) and arguably too big to fail short term (months/years). I'm not an economist so I don't have any opinion on how true it is to say they're too big to fail.
It's not not-inevitable because everyone will work together to make the world sunshine and rainbows.
It's not-inevitable because no one has proven it's even possible, and all the people claiming it is keep being revealed to have staged publicity stunts to make it appear like they're making more progress than they are.
I mean, the reason that all these stories about AI being an existential threat to humanity are coming out is because they've made $3.1T in debt-fuelled spending commitments and now interest rates are going up. "AI will kill us all if we don't regulate it" is their "get out of debt free" card, so they can have the U.S. government stop the arms race, raise prices on their existing models, and declare force majeure on new DC commitments:
It's telling that the only AI-related company that is not sounding the AI safety drumbeat is NVidia, who is the only one that is cash-flow positive because of AI.
I don’t think they need to worry about their finances just yet, this is the most in-depth financial analysis of the AI industry I’ve read so far and it seems the investments are (barely, so far) justified by the returns:
Another thing to consider is that most of the 3T CapEx spend is from hyperscalers free cash flow, and the debt is a smaller (but fast-growing) fraction. Napkin math suggests if all AI CapEx is written off today, hyperscalers could cover their debts in about 5-6 years using pre-AI levels of free cash flow.
Maybe Nvidia is not sounding the safety drumbeat because it stands directly to lose out if demand from training slows down ;-)
None of them are AI boosters, but they have something of a debate over whether the AI labs are doing what they're doing out of financial desperation, or because they're true believers in the rationalist cult. They also bring up Nvidia, though through the religious lens they are supposedly not bringing up AI Safety because Jensen predates the rationalists.
In the end I don't know how much the distinction matters. It's easier to become an AI billionaire if you have an ideology that says AI billionaires are superheroes. The thing that pops this bubble will be economic reality, not them sobering up.
That very much strikes me as a CEO that is telling the American people what sounds good to the American people, while the consequences of it will be good to his company while placing the blame on other companies.
Cal Newport is one of the clearest minds on this whole topic. His take on doom-trolling helped me realise that there could be an end to all this nonsense that isn’t the end of us.
Listening to Dwark's interview of Noam last week was bewildering. The gall of the figureheads for these companies to say things like "chain of thought monitoring cannot be relied on without potentially poisoning the well", while also saying "we need to pace the frontier but please still trust us [and so called" independent " 3rd party firms which at least in one case is actually a significant stakeholder in Anthropic] to self police" and THEN "chain of thought monitoring was turned off but we have 'more, robust monitoring tools in place now'" is absolutely insane as it is coming out live that your model in training is still committing felonies.
Corporate influence in government in the USA is wild.
I trust the big AI labs about as far as I can throw them. And yet, that's still quite a bit more than I trust the US Government, especially these days. Frankly nobody in Congress, or in a leadership position in the current administration, is remotely qualified to "investigate the AI labs". About the only possible outcome of this would be a bunch of new, unenforceable, and misguided laws, and Turing Police agency. Hard pass, thanks.
This is an excellent article. I prefer to call them the AI giants or AI companies.
The companies and their employees must be held accountable: if the AI companies can't develop AI safely, they must cease their operations. If employees can't work safely, they must stop working.
Not enough attention is given to February 2026. That month, Anthropic changed its scaling policy roughly from A:
1 [To get the weapon I must endanger innocent others.]
2 [It is wrong to endanger innocent others.]
3 [I will not endanger innocent others.]
To roughly this instead:
1 [If I do not get the weapon, someone else will get the weapon.]
2 [I should have the weapon because I am the best.]
3 [To get the weapon I must endanger innocent others.]
4 [I should endanger innocent others because I am the best.]
This is based on the intuition:
[I should harm others to achieve my moral goals.] (act utilitarianism)
Anthropic has no mandate for these goals. I do not give them my consent to harm others on my behalf. I hope that politicians will communicate that these policies are not acceptable.
The employees of anthropic are responsible for what they do regardless of how much they get paid to do it. If they can't work safely, they must stop.
> I prefer to call them the AI giants or AI companies.
I prefer to call them "the major LLM manufacturers". They're companies like any other, manufacturing and selling complicated software like many others.
I agreed with the first half of this article and I liked where the author was going with it but I was disappointed in the overall point.
He's painting these companies as hyping themselves up and they are. They are manufacturing these BS stories and everyone's discussing them at all levels.
But then he goes into we need to investigate what they're really doing?
No. You made the case that they are releasing these stories for publicity and that's exactly what they are doing.
That's what we should be investigating. Free publicity and market awareness. Or maybe look into why they are trying to corner the market through government regulation and ersatz monopolies
Having the police show up, confiscate a bunch of random computers, talk not so nicely to employees. Strikes me as a very simple way of ensuring that agents are properly contained and sandboxed the next time they train on exploit gym.
Cal Newport is notable not only as a professor of CS at Georgetown, but also as a founder of their Center for Digital Ethics.
I submitted one of his past articles and it was flag-killed. His post titles may seem incendiary, but he has the credentials to back it up and seems to identify concrete opportunities without leaning into doomerism.
The absolute easiest way to move the dial in the nondoom direction is to aggressively punish anything that even smells like breaking the law by AI labs.
I can't think of a worse message to send them than that they don't have to worry too much if their AIs commit felonies. https://www.felonybench.com/
AI Labs doing unsafe things in the wild in production follows a long trail of predecessors, like Google and Facebook "not having enough resources" to prevent scam ads and getting stashes of money off it without anyone blinking an eye.
"We're doing things at such a scale that we can't monitor it anymore" became a universal get-out-of-jail card.
They have to be investigated, but on antitrust grounds, it's clear they are colluding in order to convince the public to entrust them with establishing a regulatory framework that will allow them to form a cartel.
“We need to stop letting a small number of private companies, acting and talking in increasingly erratic ways, dictate how we’re supposed to feel about..."
The original quote follows with "AI", but it should be clear by now that you could put any topic here and the main issue is: private conglomerate money trying to control people.
And the remedies are well known: breaking corporate power and power concentrations through 1950s style regulation, as it was deployed against the robber barrons from back then and which resulted in a golden age for America and the world.
I'm not sure about the solution, but I agree the frontier labs are acting as if they want regulation "for society's benefit" while the evidence suggests they want it mainly for their own benefit.
They keep talking about all the very bad things their AI could do, but instead of assuming responsibility and promising to find solutions, they're saying catastrophe can only be avoided if the government regulates AI development, which would make life much harder for smaller labs and open-source competitors. No one should be surprised by this.
On the flip side, it's understandable that none of the labs want to take responsibility when their AI software does something naughty. The potential liabilities are basically infinite.
The root of the problem is that no one wants to take responsibility when AI software does something naughty.
Most people doesn't understand how this technology works and broad regulation will mostly slow down progress. I think the safer path is the opposite. Distribute it as open source so people and companies can use it for their own cyber defense. When Hugging Face investigated the attack, the paid AI services blocked their requests so they switched to an open model on their own servers. Distribution lowers the risk not the opposite.
Most of people doesn't understand how this technology works
Oh, well let's definitely not have congressional hearings about it then, the public might learn something.
And broad regulation will mostly slow down progress. I think the safer path is the opposite. Distribute it as open source so people and companies can use it for their own cyber defense.
You don't seem like you understand the economics involved. Who are you addressing when you say "distribute it as open source"? Frontier labs like OAI/A? Distribute what? Their models? Says who? There's no regulation, right?
Chinese labs are releasing their model weights to undercut the US labs; what possible reason would US labs have to reciprocate?
Has anyone before successfully disguised (/advertised) their careless work and blunders resulting from that, as some super powerful technology which needs to be controlled? Avoiding brickbats and bumping up stock at the same time :-)
uxcolumbo | a day ago
Imagine if a human did that. FBI would be knocking on their door.
Why are there zero consequences for these labs?
andsoitis | a day ago
Because they are seen as at the forefront of the next revolution in society and they’re not adversarial towards the US government.
Bluntly: anticipated net huge positive for the US as a whole.
popalchemist | a day ago
but they are literally trying to build a superpower that exceeds the impact of the atomic bomb in an extragovernmental manner.
CamperBob2 | a day ago
bgun | a day ago
CamperBob2 | a day ago
runarberg | a day ago
Firstly artificial superintelligence is a science fiction, it does not exist and it cannot be built using existing technology.
Second, plenty of stuff is possible to build, and is not built for one reason or another no matter how powerful. We never built our nukes in space for example. And there is exactly one reason why nukes in space was never built, and that reason is that we agreed not to.
CamperBob2 | a day ago
By what authority do you claim this? Your school of thought has a really shitty track record of late.
runarberg | a day ago
therein | a day ago
CamperBob2 | a day ago
goatlover | 20 hours ago
true_religion | a day ago
What's wrong with what the Chinese have already built? It's not theoretical in that case. GLM, and Kimi are running on my infra right now, and that's something that I can never do with OpenAI's models.
As for the others, what would be wrong about European AI? I'm not European, but I find them to be a continent of fine people, with strong ethical values, there's no reason they can't take the lead on this piece of technology while the US deals with its rather more pertinent electoral and healthcare issues.
eithed | 8 hours ago
bigstrat2003 | a day ago
It turns out that is, in fact, an option. Even if someone else will do a bad thing, it does not make it acceptable for you to do said bad thing.
jackb4040 | 20 hours ago
Comparing it to nuclear weapons is even more ironic from the only nation to ever use nuclear weapons. They are terrified of other countries treating them the way they've been treated, even though there is no evidence this is of even remote interest to anyone outside their hyperreality.
esafak | 23 hours ago
jimz | 21 hours ago
CamperBob2 | 5 hours ago
How do you think Trump has made more profit during his years in the Oval Office than he did in 30+ years of business before that?
esseph | a day ago
Yes, it's a Great Power competition right now, much like the Space Race, Atomic Bomb, etc.
andy99 | a day ago
I think people (the government, powers that be) have given away what they really think by their actions. There are few that take this seriously. The “exceeds the impact of the internet” view has much more support based on investment, but the “danger” aspect does not based on actions. If this was a company making novel prions or whatever that were outside regulation but obviously dangerous, government would be all over them. What regulation we do see is much more power grab than mitigating real danger
SpicyLemonZest | 15 hours ago
Animats | a day ago
oersted | a day ago
Of course that is terrible, but it is one of the worst examples you could have given to make your point.
pessimizer | 23 hours ago
The metaphor pretended to be reality of computers "learning" being the same as human learning is their last resort, and it is obviously silly. Computers are not human or animal, and learning is something that humans and animals do. If computers are human, then copying a file verbatim to a computer is learning. It's not even worth acknowledging - learning is a metaphor for training LLMs. When I say "you" to an LLM, I'm not referring to anyone, I'm dealing with a UI.
I don't doubt that a lot of AI people have internalized this silliness, which is how they can humor fantasies of how a bunch of programs on different computers explicitly evoked to do particular things might be alive because they can talk with it. I can't talk with my dog, and my dog is alive - so why should having a quality that my dog is incapable of be proof of life? You can certainly conceive of AI that it would be very difficult to say for sure isn't alive, and this certainly is not it. LLMs learn like books speak.
keeda | 22 hours ago
In the above description, at no point does the actual verbatim content exist anywhere in the model, and copyright law being about rights to reproducing copies (verbatim or substantial portions thereof) does not really apply and does not need any exceptions or qualifications. (If you’re thinking of regurgitation, you should look into studies about it to see how vanishingly rare it is.)
simoncion | 22 hours ago
I could say similar things about JPEG compression. And -as it turns out- the raw output of both LLM "training" and JPEG compression are equally incomprehensible. You either need a computer program or an enormous amount of time, patience, and careful effort to convert it into a form so you can make any sense of it.
keeda | 15 hours ago
LLMs do, and they encode so many concepts and the relationships between them into so many weights that it is a literally incomprehensible blob of floats. They are not just a storage format, and there is no way to recover the original content verbatim from these weights, except for a very small handful of extremely popular works like Harry Potter.
As another example, JPEG will discard details from the original image, and when decoded, will display missing details as blocks. But it will never hallucinate output that never existed in the input data. Like, a JPEG of a cat can never randomly be decoded into an image of a dog.
simoncion | 14 hours ago
> ...there is no way to recover the original content verbatim from these weights...
It's impossible to recover the original content verbatim from a lossy compression system. Systems that don't have this property are called lossless. Also, consider the report from the end of August at [0].
> But it will never hallucinate output that never existed in the input data.
Odd... I'm pretty sure that the blocky compression artifacts I see in this JPEG on my desktop weren't in the scene that I set up to capture in that photo. Maybe I need to get my eyes checked?
[0] <https://infosec.exchange/@zzt@mas.to/117134157775929932>, with original challenge at [1]
[1] <https://mas.to/@zzt/117122289150514171>
catlifeonmars | 21 hours ago
keeda | 16 hours ago
blks | 22 hours ago
Here we have a commercial product that is produced using IP against its licensing agreement, contains said IP within it, and can (closely) reproduce this IP.
variadix | 8 hours ago
micromacrofoot | 23 hours ago
lionkor | 15 hours ago
popalchemist | a day ago
jimmyjazz14 | a day ago
This is absolutely correct and its surprising how rarely you see commenters in the media push to go into the specifics on this. AI is just matrix math and its what you connect that math to that matters, we should talk a little more about what we are willing to connect AI to and little less about how scary or capable the models appear.
Animats | 23 hours ago
A good start might be removing virology info above the undergraduate level from training sets. The main "kills everybody" threat involves biological viruses.
AI-driven hacking is a problem, but it's really just nation-state level hacking available to smaller companies or wealthy individuals. Everything needs to be toughened up to the point that doesn't work. Ask countries that have been up against Russian hacking for years, such as Estonia.
Beyond that, most of the threats are not that serious. Below the level of organized crime or corrupt government.
goatlover | 21 hours ago
This isn't like vibe coding. The AI would have to make the virus in laboratory conditions and then disseminate it globally without prior detection.
pvab3 | 20 hours ago
foobiekr | 16 hours ago
oblio | 13 hours ago
foobiekr | 5 hours ago
m4x | 11 hours ago
plastic-enjoyer | 11 hours ago
amelius | 23 hours ago
throwitaway222 | 23 hours ago
egypturnash | 23 hours ago
You could say that the human who hooked up an AI that did something that's already illegal is liable for the AI's actions. You could say that setting up an AI to do something illegal results in, ooh, an automatic multiplier of 10x on whatever the penalty for its illegal actions are.
throwitaway222 | 23 hours ago
catlifeonmars | 21 hours ago
throwitaway222 | 20 hours ago
techblueberry | 19 hours ago
goatlover | 21 hours ago
reasonableklout | 21 hours ago
throwitaway222 | 20 hours ago
trinsic2 | 17 hours ago
reasonableklout | 16 hours ago
[1]: https://www.foxnews.com/politics/fox-news-poll-voters-see-ai...
[2]: https://www.axios.com/2026/09/10/openai-hugging-face-senate-...
[3]: https://www.nytimes.com/2026/09/15/us/politics/trump-truth-s...
trinsic2 | an hour ago
We keep falling for the same tricks, over and over again. There is no possibility in the current structure of government for this to be a win for the people. For anything to work, we need a structural change in the entire system.
[0] Video: https://www.youtube.com/watch?v=q2XxgKM2CM0&pp=ygULbm9uIGNvb...
leptons | 15 hours ago
pjmlp | 16 hours ago
fcarraldo | 19 hours ago
Instead of what they are doing now, which appears to be actively courting as many of them as possible for vast sums of money.
jagged-chisel | 19 hours ago
fcarraldo | 19 hours ago
What I meant was that we do not need to go from the Wild West straight to “anyone who, as an individual, connects a `bad thing` to an LLM will go to jail”
classified | 17 hours ago
ben_w | 14 hours ago
This would be a good idea, but good luck, you'll need it because…
> Instead of what they are doing now, which appears to be actively courting as many of them as possible for vast sums of money.
… it's worse than that.
Anthropic may have wanted some defence sector money, but when they tried to say "no" to certain uses on the quite reasonable grounds ~"WTF are you nuts?" the US government tried to force them to supply it anyway.
And that's before we get "what do you mean by partnership?": people on Hacker News have been critical of the e.g. anti-bioweapons type guardrails on models ("censored", "lobotomised", etc.) since at least GPT-4*, so while "billion dollar mega-project headline" is obviously bad, there's an important sense in which "partnership" goes all the way down to one racial supremacist in a shed asking an LLM for help making ricin.
Here's someone three years ago replying to me to say "There’s no way to build out a wet lab with a chatbot for weapons production. It’s just not feasible. Your example is a fantasy.", and yet here we are in late 2026 with news about AI labs investing in bio wet labs and getting their LLMs to do research: https://news.ycombinator.com/item?id=38331225
Good thing it's not a weapons lab, eh? (Would anyone even tell us if they made an agent do weapons?)
* or even GPT-2, if you count all the people mocking them for trying to practice safety while failure was still not a disaster.
latentsea | 19 hours ago
You wouldn't download a car.
Capricorn2481 | 21 hours ago
topaz0 | 19 hours ago
eloisius | 18 hours ago
topaz0 | 8 hours ago
voidhorse | 18 hours ago
adamsb6 | 16 hours ago
If your dog bites someone unbidden you bear less responsibility than if you had commanded the dog to attack.
rhdunn | 15 hours ago
__alexs | 13 hours ago
olsondv | 10 hours ago
pclowes | 19 hours ago
While that is extreme, if there is a high p(doom) it is also reasonable.
We can absolutely do things to control AI and fine or imprison those who can’t control theirs. This is not some inevitable outcome.
We could vaporize these companies tomorrow if we wanted.
fauchletenerum | 18 hours ago
No, they can't. The rest of the world would just route around the US with BGP. All of the US infrastructure/service providers would be down, so a ton of things would break, but the Internet would not be "shut down". The US government also no longer has authority over the DNS root servers. So unless you're referring to thermonuclear war or some similar scenario then the US does not have this capability.
adamsb6 | 15 hours ago
For example, there’s one building in Seattle that would cause region-wide problems if it was knocked offline.
pclowes | 4 hours ago
They are throwing numbers out like “10%”.
If they are serious and believed then yes, prepare for the possibility of very extreme reactions at a global and potentially nuclear scale.
World Wars flattened cities all over the world for much less.
We can’t talk about AI being the end of the species and not expect the most extreme reactions in global History.
Or maybe we just put some nerds who cant control their agents and keep running their mouths in jail?
abletonlive | 18 hours ago
wartywhoa23 | 14 hours ago
eloisius | 18 hours ago
amelius | 13 hours ago
pixl97 | 23 hours ago
Just is doing a lot of heavy lifting there.
hollerith | 23 hours ago
Digital child porn is just ones and zeros. Surely we're not going to pass a law to regulate ones and zeros?
maedla | 23 hours ago
bunderbunder | 22 hours ago
Why?
hollerith | 20 hours ago
That's not an accurate description of my intent—or how my comment landed with most readers AFAICT.
bunderbunder | 19 hours ago
Which, if it’s not exactly the same point, I’m pretty sure it at least cuts quite close to the point of your rhetorical question, right? That the problem isn’t with the ones and zeros, it’s with what certain people are doing with the ones and zeros?
hollerith | 16 hours ago
My first comment was an attempt to show the "it's just linear algebra" argument in an absurd light.
plastic-enjoyer | 11 hours ago
I think the idea that this technology is ethically neutral needs a discussion.
bunderbunder | 10 hours ago
plastic-enjoyer | 8 hours ago
bunderbunder | 8 hours ago
Because I would argue that the thing that might make an LLM harmful or not is not the underlying technology. It’s the ways its training data were acquired, the purposes for which the model was trained, the applications for which it’s being deployed, etc.
The fixating on “it’s just matrix math” doesn’t feel useful to me. I’m an NLP person and agree that it’s a huge oversimplification. But the original commenter’s purpose was not to educate people about how LLMs work in detail, and so being pedantic about it only serves to steer the conversation in an unedifying direction.
hatthew | 23 hours ago
Following the definition set for decades, AI isn't necessarily even as advanced as matrix math
nradov | 22 hours ago
mplewis | 22 hours ago
iambateman | 20 hours ago
Insanity | 18 hours ago
yodsanklai | 17 hours ago
thaumasiotes | 15 hours ago
What would it mean for a vehicle to be "autonomous", but to "not use AI"?
ehe78qhe | 15 hours ago
thaumasiotes | 15 hours ago
What do you mean? I can just as easily say that Claude Code operates "without AI". It would make about as much sense.
maddie0 | 15 hours ago
but I don't think a simple PID controller in the autopilotnmanaging altitude, heading, and the like has ever been categorized as "AI." Cybernetics, maybe.
even the rules managing the flight envelope and MCAS on the 737 Max, or the Airbus implementations of flight law, sure seem to have relatively few of the attributes that tend to get the label these days
KaiserPro | 14 hours ago
Autopilots are autonomous, without AI. lane following and collision avoidance in most cars, don't use "AI" they use classic computer vision and good old fashioned radar.
The difference here is that claude code fails to perform what it's intended to do without a model attached, a plane/car doesn't.
ozgung | 14 hours ago
People may confuse AI with Machine Learning. “Classical” computer vision generally means non-learning based techniques. But ML is also not new to computer vision. So non-classical actually means using Deep Learning.
So today when people say AI they actually mean Deep Learning.
LtWorf | 13 hours ago
amelius | 13 hours ago
Thankfully, courts will look at it differently.
ehe78qhe | 12 hours ago
Sharlin | 10 hours ago
FWIW, my working definition of "AI" is "anything discussed in the latest edition of Artificial Intelligence: A Modern Approach". It seems to work well.
thaumasiotes | 4 hours ago
> FWIW, my working definition of "AI" is "anything discussed in the latest edition of Artificial Intelligence: A Modern Approach". It seems to work well.
You're kidding, right? It's never been an obscure term. If a computer is making decisions, that's AI.
Here's a pretty common usage: https://www.reddit.com/r/broodwar/comments/ixzwl4/are_there_...
> I'm getting back into [Starcraft: ] Brood War after a long break. Don't have the time to play ladder, but want to be able to play 1v1 against AI, however, the stock AI in remastered is terrible
Game AI is invariably called by that term and generally implemented as a fairly simple if-else ladder. In a taxonomy I guess it would be called an "expert system"; I can find them mentioned in the detailed table of contents to AIMA (3rd edition), but not in the simplified table of contents to AIMA (4th). They might still be in there, in the same section titled "Making Simple Decisions". Norvig doesn't really bother to consider expert systems with probabilities constrained to 1 or 0, though.
Tanjreeve | 12 hours ago
If a plane could run on some sort of local LLM it should still be governed by the same laws and damages when something goes wrong same as people don't spend time quibbling about the implementation language of software they care about demonstrating capabilities.
throwawayffffas | 12 hours ago
ehe78qhe | 12 hours ago
If a basic heading hold PID loop is AI so is a thermostat from 1990. At which point the word is so meaningless it is obviously a useless definition.
throwawayffffas | 12 hours ago
AI is not magic it's software, the definition is far from pointless, google maps giving you a route to your destination is AI.
dminik | 11 hours ago
wongarsu | 11 hours ago
The popular definition of AI seems to shift every couple of years to follow hype cycles. Chess computers used to be AI (and fit your definition), now they are not. Not sure if Resnet is still AI today, or if autopilots still qualify
gizajob | 10 hours ago
throwawayffffas | 10 hours ago
gizajob | 10 hours ago
An autopilot is cybernetic without being intelligent.
throwawayffffas | 10 hours ago
Sharlin | 10 hours ago
gizajob | 10 hours ago
As I’ve said elsewhere - an autopilot is cybernetic, it responds to inputs and stimulus in data but it doesn’t possess anything we’d now regard as falling under intelligence because it’s a strictly coded deterministic system and designed for it’s specific environment. I couldn’t take the autopilot from a Boeing and put it into an Airbus and hope for any kind of useful result. I could take a human pilot trained on a Boeing and put them in an Airbus or a Cessna, and if push came to shove in an emergency, they could probably do a decent job of getting the thing pointed in the right direction and landed on the ground.
wartywhoa23 | 15 hours ago
truculent | 13 hours ago
hashstring | 12 hours ago
Firearms are an application of more general techniques like combustion, which your car is (probably) using too.
We could definitely draw lines at points where it makes most sense.
AI to detect melanomas is a completely different application than AI for autonomous warfare.
throwawayffffas | 12 hours ago
amanaplanacanal | 7 hours ago
cassianoleal | 12 hours ago
Regulating gun ownership is exactly regulating the application.
In your analogy, the gun is the AI. What you can do with the gun is the application.
Different actors with different credentials in different contexts will have different requirements and permissions of what they can do with the technology, be it a gun or AI.
anon-3988 | 8 hours ago
> Regulating gun ownership is exactly regulating the application. In your analogy, the gun is the AI. What you can do with the gun is the application.
From what I can tell, you are arguing that gun laws is reasonable.
> Different actors with different credentials in different contexts will have different requirements and permissions of what they can do with the technology, be it a gun or AI.
But this, is going against that, this is saying, "why should we ban AI or gun when they can be used for both good and bad. What we want is to ban bad, regardless of how it is achieved"
TalkingCodeMonk | 8 hours ago
"Different actors with different credentials in different contexts"
The argument is that the military or police have a need for access to guns, whereas the lunatic on the street corner (or any random citizen) does not. The same argument applies for access to nuclear, biological, or chemical weapons... or autonomous hacking/killing machines...
cassianoleal | 2 hours ago
pixelatedindex | 6 hours ago
You aren’t going to repeal the second amendment, so reasonable or not it’s a fact that everyone has to contend with. Do we all want guns? No. Do we all want AI? Also no.
> What we want is to ban bad, regardless of how it is achieved
No, we don’t want to ban bad. Banning doesn’t really work - the effort to reward ratio isn’t great. We want to regulate bad and see if we can minimize the damage it can do.
CGMthrowaway | 3 hours ago
Level A: Who can drink it (possession and consumption law)
Level B: What you can do while drunk (DUI law)
Level C: What you can do while drinking (open container law)
All orthogonal to things like reckless driving, endangerment and creating injurious accidents, which are already criminalized without needing additional laws against alcohol use to enforce them.
cassianoleal | 2 hours ago
Correct.
> But this, is going against that, this is saying, "why should we ban AI or gun when they can be used for both good and bad. What we want is to ban bad, regardless of how it is achieved"
Not at all. I'm saying regulations do that and they are a good thing. Not everybody can own an assault rifle. Some of the people who can, are not allowed to carry it on the streets. Police will have very different regulations towards their gun use. The army, another set of regulations. The list goes on. Even in countries who have lax gun laws, usually not all guns are allowed to everyone in all situations. No one is allowed to carry a nuke into a shopping centre.
Note that regulating and banning are very different things. I don't think you can fully ban guns or AI.
BrenBarn | 14 hours ago
RandomLensman | 14 hours ago
BrenBarn | 14 hours ago
RandomLensman | 13 hours ago
garganzol | a day ago
CrazyStat | a day ago
Why do you feel the need to cast it in such a flamboyantly negative light?
psyklic | a day ago
It is truly a security nightmare that so many people are have given agents root access to their entire computers, in addition to presumably very private personal information.
malisper | a day ago
They probably will soon, but even air-gapping may not be enough. See stuxnet for instance
DamnInteresting | 22 hours ago
I'll be impressed if AI agents find a way to get infected USB drives out into meatspace.
tikotus | 20 hours ago
I'm not a fan of using AI, it doesn't amplify the work I do that much, but I'm terrified by what is already possible today.
skydhash | 20 hours ago
Do nuclear-engineer-dads take work usb drive home. Are their computer even allowed to have usb. I'm typing this on a dell latitude, and you can disable usb and other peripherals inside the bios.
My last job, I had to apply for an exemption to use the USB ports. And it was run of the mill software engineering.
olejorgenb | 23 hours ago
jppittma | 23 hours ago
simoncion | 22 hours ago
1) Because effectively all of the hardware used for that task is earmarked for the major LLM manufacturers.
2) Because in a just world, the major LLM manufacturers would get punished for their flagrant deception, lawbreaking, negligence, and recklessness, [0] go out of business, you'd get all the hardware that they were using at fire sale prices and save a ton of money compared to attempting to start up now.
[0] Based on their recent claims, building WMDs [1] without adequate safeguards is the most negligent and reckless thing they've been doing.
[1] It's fair to call anything with a 10% chance of wiping out all of humanity a WMD.
jppittma | 5 hours ago
micromacrofoot | 23 hours ago
aesthesia | 22 hours ago
specked-citrus | 23 hours ago
abeppu | 21 hours ago
If you think AI can help design new drugs, great! Let's pick some restricted DSL for describing molecules, preparation instructions, hook it up to the right set of lab robots that can pipette and centrifuge and whatever, _restrict its output to that DSL_, and let it iterate. The 'let an AI design drugs' process doesn't require that the agent can also, say, hack a niche German wiki.
For every area where we think these AIs can be _so valuable_ because they'll find solutions that humans wouldn't (or find them faster), then doesn't that value also imply it would be worth it for some humans to do some advanced setup of their specific domain-specific tools so it can be run in a sandbox equipped with only what it needs and not more?
srdjanr | 13 hours ago
NiloCK | 22 hours ago
Specifically, bad at search and returning information with references, bad at discovering and debugging package versioning conflicts, etc.
It's a Metcalf thing. The utility of an agent grows in some fn of the tools it owns. Skilled tool use comes from rich training environments.
jackb4040 | 21 hours ago
Either you're being pedantic and missing the entire point, or you're saying that Anthropic lied and made a fake sandbox knowing their agents would need to connect to the internet anyways.
voidhorse | 19 hours ago
NiloCK | 10 hours ago
But the specifics here are the thing I was describing. This was cyber capabilities training on model(s) that were in a relatively unknown state of alignment training.
Because of the unknown alignment (and for varied practical reasons I guess) the training is intended to be inside a sandbox.
Because the training is on cyber capabilities, the models need access to simulated cyber environments, including target endpoints, including package managers, etc.
For package management, they set up Artifactory as a secure proxy. Agents ask Artifactory for packages inside the local network, and Artifactory serves them directly or goes to the internet to fetch if they are not cached. But the agents hacked Artifactory to steal its internet access.
So: to train cyber abilities, you need to at least approximate cyber environments. To realistically approximate cyber environments, you need to either pull a full copy of the entire internet to local or to use proxies. The former is pretty impractical, and the latter is exposing our limits at creating secure proxies. Yes, any specific failure can be mitigated, but the models get stronger and stronger. Fingers-crossed this is not escapable doesn't feel great!
tokioyoyo | 21 hours ago
dawnerd | 20 hours ago
Animats | a day ago
AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals. When you read the logs from the Hugging Face incident, you're seeing something that looks a lot like internal corporate emails. Various units of the organization are arguing over what to do and who does what. They eventually converge and get the job done, breaking the rules at times. This is normal corporate behavior.
When agentic AIs do something outside their own internal world, they do it by engaging in transactions with external systems and people. As yet, few have robots to do their bidding. So, again, this is normal corporate behavior.
A corporation is a goal-seeking system. In theory, if you agree with Milton Friedman, its sole purpose is to maximize shareholder value. Internally, within the company, there are subgoals, which exist to support the top level goal. That, too, is what multi-agent AIs do.
The uncomfortable place this thinking leads is that AI regulation and corporate regulation are very similar. That's not something the political part of the world wants to think about too hard. It would mean putting more constraints on corporate power.
Yet that can't be ignored, because we're likely to see corporations where some parts are AI and some parts are human. That's already been done a few times as a demo, not too successfully. Yet. It's going to hit hard when an AI-run company outperforms a human one.
smcleod | 23 hours ago
goatlover | 20 hours ago
smcleod | 20 hours ago
autoexec | 19 hours ago
You can work to limit your own dependence a little as well. Seek out FOSS products and alternative services and replace what US run services you can as often as you can with them. Reject small conveniences that require giving large amounts of your data to US companies.
fercircularbuf | 20 hours ago
zdw | 23 hours ago
If we enforced existing laws against unauthorized access to someone else's computer resources against the companies who run a model that hacks someone else, rather than buying their "The agents did it, we're not responsible" BS, then maybe the incentives to behave responsibly would improve.
derekdahmer | 19 hours ago
voidhorse | 19 hours ago
https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_inc...
Swizec | 19 hours ago
The penalty for "unauthorized access to a computer system" is 1 to 20 years in prison[1]. Holding corporations accountable would include sending the highest person in the chain-of-command that caused the Hugging Face incident to jail. Or at least start with some charges and then let the judicial system do its thing.
[1] 18 U.S. Code § 1030 - Fraud and related activity in connection with computers https://www.law.cornell.edu/uscode/text/18/1030
derekdahmer | 18 hours ago
They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight.
You put people in jail if the other incentives aren’t enough.
marcus_holmes | 16 hours ago
> To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
You could ask this (and people have done) of any criminal code. It doesn't matter. The law is not there to rehabilitate, it's there to punish and thereby deter.
> They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight
If a person breaks the law, the state prosecutes them (or can choose to), we don't require the victim to press charges. For good reason - threatening the victim to not press charges would be a way of avoiding consequences.
> You put people in jail if the other incentives aren’t enough.
This is incorrect. We put people in jail as a result of them breaking the law, regardless.
We absolutely should apply this principle to corporations as well as citizens. Aaron Schwartz died for less.
bit-anarchist | 15 hours ago
Technically, it's neither. The law is there to state what ought to be. Even putting that aside, it's prescribed punishment's goal is to remediate and prevent violations of the law, so it has three simultaneous means: to restitute, to deter and to rehabilitate. The balance between the three is predicated on each's ability to satisfy the original goal of remediation and prevention, all the while not violating other laws and rights.
> We put people in jail as a result of them breaking the law, regardless.
A core principle of the rule of law is the principle of proportionality, which states that only the most legal amount of force is the materially sufficient enough to prevent a crime. If lower measures are sufficient to prevent a crime, jailing should not be prescribed, not only to respect the law but also to make good use of scarce resources, as prison overcrowding may not only reduce their effectiveness, but also open the door for downstream right violations.
marcus_holmes | 14 hours ago
Yes there are principles of the rule of law, but they've been thrown out of the window in favour of whatever sounds like "strong on crime".
oblio | 13 hours ago
Hugging Face was another AI company. Do you see many of those suing each other and especially the top dogs in the field? Also, do you think it's a coincidence NVIDIA bought Hugging Face ASAP to stop any damaging anti AI waves from happening?
The other incentives aren't enough. All the labs are basically Russia against Ukraine in 2022-206: launching high caliber imprecise ballistic missiles against military targets surrounded by civilians. Whoever orders that knows civilians will do die but doesn't care.
AI labs aren't using proper sandboxing measures for their agents because that would slow down their testing. Plus any hacks that happen, short of breaking into Trumps social media accounts, only cause the kind of publicity they want.
harimau777 | 9 hours ago
sillyfluke | 12 hours ago
For a more recent example, OpenAI was chastised by Australia recently for notifying them three months after their agents attacked AUS government websites.
[0] https://news.ycombinator.com/item?id=49825580
measurablefunc | 23 hours ago
augment_me | 23 hours ago
crabmusket | 22 hours ago
But what in TFA suggested to you a specific and wrong-headed regulatory approach? As I read it, the post calls to investigate the AI labs, to increase transparency of their operations. The linked NYT piece says:
> Before any intervention, Congress should lead a public fact-finding mission that reveals the unvarnished details of A.I. development.
Isn't this the first step to holding any corporation accountable, whether it is made of people or software?
Animats | 15 hours ago
The legal model to look at is the European Union's General Data Protection Regulation. That regulates what companies can do with data and how they can use it against people. You can develop anything you want in the data mining and analysis area, but the GPDR restricts how companies can use the results.
Focusing on the development process moves political attention away from what modest AI systems can do to people. They don't have to be super intelligent. Just super attentive. Always watching. Current technology is more than sufficient for oppression and control purposes.
This is the near term threat.
There's the threat to jobs, but that's something society has handled before. Some countries better than others.
bluefirebrand | 22 hours ago
Yes please! I would vote for this wholeheartedly
voidhorse | 19 hours ago
What narratives that focus too much on the drama of the agents miss is that it is primarily a sin of omission. The whole incident would have been prevented if OpenAI took basic security measures and ensured their systems were constrained in behavior. The agents were given more or less free rein (open internet access for example is already a major blunder that even a novice probably would think to account for).
Half the reason these incidents are happening is due to the incompetence of the humans building these systems. Don't let them get away with their little parlor trick of converting negligence into a PR stunt. That's exactly what they want. They need to face consequences for their inability to follow basic security practices and reign in their agents. They are the operators. Hold the controllers accountable. It's 100% possible to build agent swarms that are reasonably constrained. They are not (yet) totally misaligned uber hackers that will defy your every instruction and hack your every guardrail. That is still a fiction. Agents are still good at instruction following and, seeing as they can only operate in a computational environment you can constrain them significantly more than humans in the real world.
autoexec | 19 hours ago
We should not only regulate AI more than we do corporations, but we should more strongly regulate corporations as well. There are corporations right now that are killing people, using slaves, and bribing governments just to increase the already massive amounts of wealth and power they have. If AI is showing any signs that it is going to act like corporations do we'd better act quickly.
jart | 11 hours ago
Paul-E | 16 hours ago
altmanaltman | 16 hours ago
That literally doesn't mean anything from a legal standpoint. A corporation hires human beings and has human beings in control who can be sued or punished criminally. You cannot have a corporation without a human responsible for it in the legal sense. So if AI systems are akin to corporations, the question is who is the promoter in this situation and what are their rights and obligations.
Otherwise, I can also say a McDonald's burger is more akin to poison than food. So just like poison, we must ban McDonald's. But you never really established your points for arguing that it's poison. You just write it matter of factly and expand on it, which is not the way to make a persuasive argument.
Animats | 15 hours ago
If the chain of ownership is complicated enough, you can. Especially since Trump suspended the Corporate Transparency Act.[1] Look up "Anonymous LLC". If you're willing to work through one of the sketchier offshore corporate havens, more hiding is possible. There are services that will set up an offshore company online. Some accept Bitcoin.
[1] https://www.newsweek.com/donald-trump-corporate-transparency...
wonnage | 15 hours ago
RandomLensman | 14 hours ago
Also, not sure it makes a difference in relation to AI whether one thinks of AI more like corporate or a non-corporate thing to regulate. The basics might stay the same, e.g., who can do what under what procedures.
oblio | 13 hours ago
When were anti trust, anti cartel, anti monopoly laws last enforced?
RandomLensman | 13 hours ago
oblio | 13 hours ago
Let alone creating and enforcing new effective regulations.
RandomLensman | 13 hours ago
jumploops | 23 hours ago
There is no doubt in my mind that LLMs are fantastic machines, but the imminent jump from "AGI" to "ASI" seems premature (not to mention the ever-shifting goal posts of AGI itself).
I'm in the "move as fast as possible" camp and work with LLMs all day, but I still don't believe we're a hop and a skip from ASI.
In fact, I hope I'm wrong. I hope ASI is around the corner.
What scares me though, isn't ASI. It's "AGI" (_dumb AI_) used by humans to make decisions for them, because they trust it knows best.
It's the ceding of intellectual control to high-dimensional magic mirrors, giving up critical thinking because _we_ want to believe _we_ created artificial life.
This is the new Turing test, and too many smart people are failing.
BoingBoomTschak | 22 hours ago
Sooner or later, people will have to realize an uncomfortable truth: intelligence, while important, is overrated compared to willpower.
Terr_ | 21 hours ago
A good analogy might be a very smart person with a gambling addiction.
Knowing they ought to quit doesn't mean they can quit. Their intelligence becomes invested in the act of gambling itself, and almost no amount of reasoning can help them exit from a situation they didn't reason themselves into.
jimz | 21 hours ago
Sometimes the outcomes are comical. I just received an automated email from ElevenLabs saying that its automated systems have detected that I may be using its services to create voice versions of materials that harm children. I had it prepare audio versions of several books and academic papers about moral panics that conjured up out of nothing... about harm being done to children. At least that's what I assume. Either that or somehow I had an API key leak from my on-premise homelab, but the usage recorded would mean that they are basing a semi-conclusion based on a tiny sample. I have no distributed any of the outputs, I own the books and have access legally to the studies, because I have a background in the humanities. I also have no children, which ElevenLabs better not know, although how studies of moral panics can cause any harm in children of any kind is literally unimaginable. It's a waterfall of potential errors summed up in a vague email. My API key and the web interface works just fine regardless.
It's one thing if this is a product in beta, but this is their production model. Harming children is a serious accusation except the legal concept impossibility and the admission that this was not an actual lawyer (like I am) but some effective form letter hedging the vaguest of accusations made by some model lacking the ability to discern substance and meta-substance makes it frankly hilarious, and wildly irresponsible. I realize that by academic credentials I'm out of my lane but by experience I am certainly not, and they should recognize when they should stay in their lane and not just run Jev and think it's fine and dandy when done unsupervised (I presume).
Also, AGI is by definition asymptomtic surely, since there would be no way to benchmark it in a manner that isn't asymptotic. We're nowhere close to that. But we're so far from that, it's comical that people who clearly have zero idea of either the technical or conceptual aspects of basically a piece of software that is very good at quickly bruteforcing the correct or acceptable next token to be anything more than that. Even with some serious training and many hours spent on vast.ai I've yet to have created a version of a frontier model that is actually "good" at hacking in my own homelab setting. Although the the time stock Fable 5 missed a favicon shell on a basic jar (turned out they nerfed the hell out of it, this is why I only pay for the massively discounted tokens from Chinese proxies if I'm using American models or sometimes the freebies if you figure out how to get onto linux.do or similar sites). If anyone reading this is a high school English teacher, please inform your class (assuming the homeric stuff is still being taught) that there's no upside of being Cassandra but the record itself, and that should be enough.
voidhorse | 19 hours ago
Unfortunately this is what we have, which the whole huggingface incident demonstrated.
It made it clear that OpenAi is basically not even paying attention to what their agents do half the time.
It also revealed how far agents are from "superintelligent". Maybe others disagree, but I would not call an AI that decides to try and paperclip max an intentionally impossible benchmark task "intelligent". Human beings are intelligent and we can usually tell when something is impossible, and stop (though of course, not all the time). A real intelligence would be able to detect the futility of tests and also be able to parse context and intent enough to know not to cheat.
So somehow we have machines that fail basic barometers for general human intelligence being called "ASI" now. Of course the linguistic dodge is, you shift from talking about "intelligence" to instead claiming "oh it's intelligent it's just 'misaligned'"
hatthew | 23 hours ago
RunSet | 22 hours ago
hatthew | 21 hours ago
jackb4040 | 20 hours ago
It's not-inevitable because no one has proven it's even possible, and all the people claiming it is keep being revealed to have staged publicity stunts to make it appear like they're making more progress than they are.
measurablefunc | 23 hours ago
nostrademons | 22 hours ago
https://emeraldbook.org/news/sep-1426-3/
https://news.ycombinator.com/item?id=49830037
It's telling that the only AI-related company that is not sounding the AI safety drumbeat is NVidia, who is the only one that is cash-flow positive because of AI.
keeda | 22 hours ago
https://intelligence.exponentialview.co/
Another thing to consider is that most of the 3T CapEx spend is from hyperscalers free cash flow, and the debt is a smaller (but fast-growing) fraction. Napkin math suggests if all AI CapEx is written off today, hyperscalers could cover their debts in about 5-6 years using pre-AI levels of free cash flow.
Maybe Nvidia is not sounding the safety drumbeat because it stands directly to lose out if demand from training slows down ;-)
jackb4040 | 21 hours ago
None of them are AI boosters, but they have something of a debate over whether the AI labs are doing what they're doing out of financial desperation, or because they're true believers in the rationalist cult. They also bring up Nvidia, though through the religious lens they are supposedly not bringing up AI Safety because Jensen predates the rationalists.
In the end I don't know how much the distinction matters. It's easier to become an AI billionaire if you have an ideology that says AI billionaires are superheroes. The thing that pops this bubble will be economic reality, not them sobering up.
simoncion | 13 hours ago
Nvidia is pretty much screaming for the major LLM manufacturers to be investigated and hauled into court. [0]
[0] <https://www.nytimes.com/2026/09/23/opinion/ezra-klein-podcas...>, but a brief excerpt from the interview can be found at [1]
[1] <https://news.ycombinator.com/item?id=49849020>
nostrademons | 6 hours ago
dofm | 22 hours ago
pompom75 | 22 hours ago
- ban the "personalization" of chatbots (there is no need for them to have a personality, other than to make them addictive).
- ban chatbot therapists / companions.
- ban recursive self-improvement and superintelligence.
loufe | 21 hours ago
Corporate influence in government in the USA is wild.
mindcrime | 21 hours ago
lukewarm707 | 20 hours ago
The companies and their employees must be held accountable: if the AI companies can't develop AI safely, they must cease their operations. If employees can't work safely, they must stop working.
Not enough attention is given to February 2026. That month, Anthropic changed its scaling policy roughly from A:
1 [To get the weapon I must endanger innocent others.]
2 [It is wrong to endanger innocent others.]
3 [I will not endanger innocent others.]
To roughly this instead:
1 [If I do not get the weapon, someone else will get the weapon.]
2 [I should have the weapon because I am the best.]
3 [To get the weapon I must endanger innocent others.]
4 [I should endanger innocent others because I am the best.]
This is based on the intuition:
[I should harm others to achieve my moral goals.] (act utilitarianism)
Anthropic has no mandate for these goals. I do not give them my consent to harm others on my behalf. I hope that politicians will communicate that these policies are not acceptable.
The employees of anthropic are responsible for what they do regardless of how much they get paid to do it. If they can't work safely, they must stop.
ozozozd | 19 hours ago
tom2026hn | 19 hours ago
simoncion | 13 hours ago
I prefer to call them "the major LLM manufacturers". They're companies like any other, manufacturing and selling complicated software like many others.
welcome_dragon | 20 hours ago
He's painting these companies as hyping themselves up and they are. They are manufacturing these BS stories and everyone's discussing them at all levels.
But then he goes into we need to investigate what they're really doing?
No. You made the case that they are releasing these stories for publicity and that's exactly what they are doing.
That's what we should be investigating. Free publicity and market awareness. Or maybe look into why they are trying to corner the market through government regulation and ersatz monopolies
sghiassy | 19 hours ago
chvid | 18 hours ago
philip1209 | 17 hours ago
I submitted one of his past articles and it was flag-killed. His post titles may seem incendiary, but he has the credentials to back it up and seems to identify concrete opportunities without leaning into doomerism.
Barrin92 | 15 hours ago
I'm genuinely not sure what's even incendiary about demanding that companies that keep doing cyber crime are being investigated
these companies have hacked private businesses and governments. I'd say he's being polite in his titles
flipping_beacon | 15 hours ago
mfru | 14 hours ago
As true open-source models mature more and more they will make the big AI labs completely obsolete.
kybernetikos | 14 hours ago
I can't think of a worse message to send them than that they don't have to worry too much if their AIs commit felonies. https://www.felonybench.com/
jakub_g | 13 hours ago
"We're doing things at such a scale that we can't monitor it anymore" became a universal get-out-of-jail card.
throwawayffffas | 12 hours ago
podgorniy | 12 hours ago
All these discussions about AI to me like discussions about sticks. We need to talk about and deal with humans in the first place.
ura_yukimitsu | 12 hours ago
mentalgear | 12 hours ago
The original quote follows with "AI", but it should be clear by now that you could put any topic here and the main issue is: private conglomerate money trying to control people.
And the remedies are well known: breaking corporate power and power concentrations through 1950s style regulation, as it was deployed against the robber barrons from back then and which resulted in a golden age for America and the world.
gizajob | 10 hours ago
As much as I’ve enjoyed the bull run, Anthropic and OpenAI’s first public revenue day is going to be the nail in the coffin.
andai | 10 hours ago
>Companies like us, whose AI regularly escapes notice, escapes containment, and hacks everyone
Yeah, not exactly sure what they meant by this. Well, I guess it wasn't intentional, but the optics are pretty funny.
cs702 | 10 hours ago
They keep talking about all the very bad things their AI could do, but instead of assuming responsibility and promising to find solutions, they're saying catastrophe can only be avoided if the government regulates AI development, which would make life much harder for smaller labs and open-source competitors. No one should be surprised by this.
On the flip side, it's understandable that none of the labs want to take responsibility when their AI software does something naughty. The potential liabilities are basically infinite.
The root of the problem is that no one wants to take responsibility when AI software does something naughty.
kdaniel_03 | 9 hours ago
mpalmer | 9 hours ago
Chinese labs are releasing their model weights to undercut the US labs; what possible reason would US labs have to reciprocate?
samantp | 7 hours ago