It's Time to Investigate the AI Labs (calnewport.com)

129 points by ibobev 2 hours ago

28 comments:

by jimmyjazz14 34 minutes ago

> We must move past vague discussions of “AI” and instead isolate the specific types of systems that are creating problems.

This is absolutely correct and its surprising how rarely you see commenters in the media push to go into the specifics on this. AI is just matrix math and its what you connect that math to that matters, we should talk a little more about what we are willing to connect AI to and little less about how scary or capable the models appear.

by Animats 15 minutes ago

Yes.

A good start might be removing virology info above the undergraduate level from training sets. The main "kills everybody" threat involves biological viruses.

AI-driven hacking is a problem, but it's really just nation-state level hacking available to smaller companies or wealthy individuals. Everything needs to be toughened up to the point that doesn't work. Ask countries that have been up against Russian hacking for years, such as Estonia.

Beyond that, most of the threats are not that serious. Below the level of organized crime or corrupt government.

by amelius 6 minutes ago

AI is basically "Bobby Tables" but without a known proper engineering approach to solve it.

by lmeyerov a minute ago

Fun anecdata:

- I was talking with a well-funded AI safety org and they didn't know what an Internal Review Board was nor had cyber staff

- for all the claims of complexity from anthropic and OpenAI, their cyber eval breakouts answers ultimately boils down alignment being not the primary control, and instead, to more sandboxing and more monitoring of them (traditional security!), and by more monitoring, a lot of it seems to be, "at all", which merits scrutiny. It's strange to hear companies crowing to Congress about being AI security leaders yet their cyber staff not being able to monitor what folks are doing. It seems literally years late given how early the FUD started, and for more practical views, it was clear commodity models were doing funny things last Dec+ for folks outside of labs (I gave a talk at blackhat week cataloging what we were seeing and doing on our shoe string operation back then, for example) and unclear why we are in September talking about monitoring

- AISI (uk gov's safety lab) intentionally gave an attack bot internet access. Somehow I doubt an IRB was involved in that one, that would have been a wild conversation.

It's possible to simultaneously have empathy for the security staff individuals and be flabbergasted by the frontier labs and their ecosystem of companies like METR, Irregular already in the news, and others I won't name who aren't yet but probably should also be

by Animats 21 minutes ago

This is a wrong-headed attempt to regulate AI. The real problems are different.

AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals. When you read the logs from the Hugging Face incident, you're seeing something that looks a lot like internal corporate emails. Various units of the organization are arguing over what to do and who does what. They eventually converge and get the job done, breaking the rules at times. This is normal corporate behavior.

When agentic AIs do something outside their own internal world, they do it by engaging in transactions with external systems and people. As yet, few have robots to do their bidding. So, again, this is normal corporate behavior.

A corporation is a goal-seeking system. In theory, if you agree with Milton Friedman, its sole purpose is to maximize shareholder value. Internally, within the company, there are subgoals, which exist to support the top level goal. That, too, is what multi-agent AIs do.

The uncomfortable place this thinking leads is that AI regulation and corporate regulation are very similar. That's not something the political part of the world wants to think about too hard. It would mean putting more constraints on corporate power.

Yet that can't be ignored, because we're likely to see corporations where some parts are AI and some parts are human. That's already been done a few times as a demo, not too successfully. Yet. It's going to hit hard when an AI-run company outperforms a human one.

by psyklic 26 minutes ago

Why aren't they running agents on isolated computers without Internet access? This way, breaking free of containers would not matter.

It is truly a security nightmare that so many people are have given agents root access to their entire computers, in addition to presumably very private personal information.

by malisper 22 minutes ago

> Why aren't they running agents on isolated computers without Internet access?

They probably will soon, but even air-gapping may not be enough. See stuxnet for instance

by uxcolumbo an hour ago

100%. First stealing content from creators and pirating TBs of books. And now this. Baffles my mind that these labs can just get away with their 'rogue' agents trying to hack into other systems.

Imagine if a human did that. FBI would be knocking on their door.

Why are there zero consequences for these labs?

by andsoitis an hour ago

> Why are there zero consequences for these labs?

Because they are seen as at the forefront of the next revolution in society and they’re not adversarial towards the US government.

Bluntly: anticipated net huge positive for the US as a whole.

by popalchemist an hour ago

not adversarial in obvious ways

but they are literally trying to build a superpower that exceeds the impact of the atomic bomb in an extragovernmental manner.

by andy99 35 minutes ago

> they are literally trying to build a superpower that exceeds the impact of the atomic bomb

I think people (the government, powers that be) have given away what they really think by their actions. There are few that take this seriously. The “exceeds the impact of the internet” view has much more support based on investment, but the “danger” aspect does not based on actions. If this was a company making novel prions or whatever that were outside regulation but obviously dangerous, government would be all over them. What regulation we do see is much more power grab than mitigating real danger

by esseph an hour ago

> but they are literally trying to build a superpower that exceeds the impact of the atomic bomb

Yes, it's a Great Power competition right now, much like the Space Race, Atomic Bomb, etc.

by CamperBob2 an hour ago

Somebody's going to build it. Not building it isn't an option. Would you rather the Chinese built it? The Russians? The Europeans? The Indians? A loose coalition of random hackers on the Internet, like the ones who build Linux?

by true_religion 40 minutes ago

Yes?

What's wrong with what the Chinese have already built? It's not theoretical in that case. GLM, and Kimi are running on my infra right now, and that's something that I can never do with OpenAI's models.

As for the others, what would be wrong about European AI? I'm not European, but I find them to be a continent of fine people, with strong ethical values, there's no reason they can't take the lead on this piece of technology while the US deals with its rather more pertinent electoral and healthcare issues.

by bigstrat2003 29 minutes ago

> Somebody's going to build it. Not building it isn't an option.

It turns out that is, in fact, an option. Even if someone else will do a bad thing, it does not make it acceptable for you to do said bad thing.

by bgun an hour ago

At least random hackers seem to have codes of ethics.

by CamperBob2 44 minutes ago

Well, they'd presumably be different hackers than the ones who work on Linux. We don't know what would motivate them. Maybe they'll do it because they consider the next stage of man's intellectual evolution to be too important to leave up to a couple of American companies and the Trump administration. Maybe they'll do it for the proverbial lulz.

by hollerith 20 minutes ago

That's a pretty weak argument. It is like saying, "somebody's going to kill all the polar bears. Not wiping them out is not an option. If we do it, then at least we get to keep the cool bearskins."

That's a persuasive argument only if you really really want big white bearskins or maybe if you're embedded in a society with an unhealthy level of dependence on fur trading.

by therein 43 minutes ago

It is sad to see how many times this narrative will continue to work. Across generations, humanity learns no lessons at all.

by CamperBob2 41 minutes ago

I'm being descriptive, not prescriptive. The "narrative" isn't intended to "work," except as a statement of fact.

by runarberg an hour ago

Logical fallacy, of the worst kind.

Firstly artificial superintelligence is a science fiction, it does not exist and it cannot be built using existing technology.

Second, plenty of stuff is possible to build, and is not built for one reason or another no matter how powerful. We never built our nukes in space for example. And there is exactly one reason why nukes in space was never built, and that reason is that we agreed not to.

by CamperBob2 41 minutes ago

Firstly artificial superintelligence is a science fiction, it does not exist and it cannot be built using existing technology.

By what authority do you claim this? Your school of thought has a really shitty track record of late.

by runarberg 38 minutes ago

The same authority that allows me to claim that teleportation transporters, hyperdrives, and holoemitters do not exist and cannot be built using existing technology.

by Animats 39 minutes ago

The argument for copyright violation is very weak. Yes, AI training reads much copyrighted material. So do researchers of all types. That's why there are academic libraries. A copyright violation only exists if what comes out is a close match to what went in. That's happened, but it was considered a bug and was fixed a year or two ago.

by oersted 31 minutes ago

Most academic libraries are notoriously protective of their IP and researchers are definitely in copyright violation if they don’t pay significant fees for access.

Of course that is terrible, but it is one of the worst examples you could have given to make your point.

by pessimizer 12 minutes ago

No, the copyright violation is so obvious that people arguing against the object have to spontaneously assert bizarre qualifications for copyright violation that have never existed until LLM companies wanted to freely violate copyrights. Just about a decade ago, people were getting sued for "look and feel." "Blurred Lines" lost a copyright suit for reminding people of a song by another artist.

The metaphor pretended to be reality of computers "learning" being the same as human learning is their last resort, and it is obviously silly. Computers are not human or animal, and learning is something that humans and animals do. If computers are human, then copying a file verbatim to a computer is learning. It's not even worth acknowledging - learning is a metaphor for training LLMs. When I say "you" to an LLM, I'm not referring to anyone, I'm dealing with a UI.

I don't doubt that a lot of AI people have internalized this silliness, which is how they can humor fantasies of how a bunch of programs on different computers explicitly evoked to do particular things might be alive because they can talk with it. I can't talk with my dog, and my dog is alive - so why should having a quality that my dog is incapable of be proof of life? You can certainly conceive of AI that it would be very difficult to say for sure isn't alive, and this certainly is not it. LLMs learn like books speak.

by sharadov 18 minutes ago

Private enterprise as it's being run in the US especially under the Trump administration ( where a few billions tossed at the right people ) will get you all kinds of favors and look asides.

Hopefully once the dems win back the house, we will see some regulation.

Up until now it's been a capitalists' wet dream!

The labs have become so brazen especially OpenAi that they don't even care to report incidents. https://www.politico.com/news/2026/09/25/rogue-openai-agents...

by popalchemist an hour ago

It's past time.

Data from: Hacker News, provided by Hacker News (unofficial) API