OK, I've listened to the warnings and they still sound like the usual nonsense by out-of-touch techies who spend too much time lost in apocalyptic sci-fi fantasies. In the real world it's still hard to move around physical atoms or keep machinery working reliably. AI won't change that.
Embodied AI is changing this. In 1-4 years, VLA models will have their mythos moment. What’s missing is the volume and variety of training data in an open, accessible form, and that’s a hard problem. A hard problem that smart, well funded people are working on solving.
So yeah, for now, it’s all ethereal. It’s going to get real all of the sudden, just like AI hit the hockey stick in 2026.
The "embodied" part isn't going to be solved in 4 years. Robots break down constantly. You guys making these ridiculous predictions have obviously never worked in a factory or something. Heck, I've gone through a bunch of robot vacuum cleaners and still can't find one that doesn't get wedged under my furniture or tangled up in area rug tassles.
You design a product/machine 100% digital, you create a digital twin of it, you train a robot ml on this machine, you upload it to the robot who is sitting in the factory and it analyses the machine, reruns a simulaton on how to fix it and executes it.
I would say in 50 years max this is a solved problem. I estimate 30 years and would go down as early as 20 years.
> I would say in 50 years max this is a solved problem.
AI security will be perfect in 5 years, it's in good shape already - my agents have never hacked anybody, those lab LARP-ers better learn something about security and isolation.
> you upload it to the robot who is sitting in the factory
You assume no guardrails, in that case even script kiddies can do more damage than AI.
I can't help wondering if the major labs think that tackling the alignment problem and implementing the 'kill switch' that is currently being proposed is going to be their moat.
The hugging face hack shows otherwise, no? Unless you think humans are at fault even for secretive, autonomous, non-prompted behaviours of their AIs, in which case it's just semantics.
Yes, if you start a bot and then it harms others you are responsible. This has always been true but it's especially obvious now that everyone knows that agents attempt to do this often.
Toys like HuggingFace get hacked all the time. So what. In the long run AI automated security scans and penetration testing will be a tremendous aid in detecting and repairing vulnerabilities in systems that actually matter.
No, the problem was OpenAI not implementing proper sandboxing or safeguards, and telling the AI exactly to hack things. Thats what exploitgym is, and the task they were given.
If your security model is having to imagine all the ways your frontier models might misbehave in novel ways and preemptively sandbox them, you don't have a security model. The only way that will work is general alignment.
Do you need to predict all the ways the model might misbehave?
Your 'hack everything you see for our internal research lab' agent should be airgapped. You don't need to come up with every reason why, one is enough.
If you're working with these companies, you should reasonably be able to get the code to perform offline audits. If you can't get the code, you probably shouldn't try to pen test it.
Alignememt is bullshit. Treating models like probabilitic software rather then emerging god is where the solution is. And fining companies and applying laws to them.
The moment OpenAI as a company and its managers individually become liable, problem will magically disappear.
No it won't, because abliterated open weights models exist and unless you try to censor the internet they can't really be withdrawn after publishing. This is exactly the problem that the labs are proposing to fix: a dangerous model that nobody is accountable for.
> This is exactly the problem that the labs are proposing to fix: a dangerous model that nobody is accountable for.
The corporations and government said the same thing about encryption in the 90s. It was dangerous and only they could be trusted to regulate it. Turns out encryption was much better for society when open and available for free to everyone. It's a false dichotomy they present us with, open weights is the way we don't end up in 1984
Except that so far, it is literally these labs that are the biggest threat and the least willing/capable to restrain those models. And the same penalties apply to open models and companies or individuals running them.
"Dangerous model that nobody is accountable for" still have someone paying those massive amounts of compute and electricity it consumes. There is someone accountable for that.
That's not how abliteration works. The trainer invariably put effort into making the model not dangerous, precisely because they want to be accountable. But because they release its weights, someone can come later and do "weight surgery" to mostly remove any such safeguards. The people proximately accountable for the danger are anonymous and also don't require much resources. The reason this is not _yet_ a big deal is because open weights models are a few months behind the frontier and their users are paying marginal costs for compute.
None of that is argument against what I said. Someone is running it, that person is responsible.
In case of actual hackes that happened, OpenAI and Amtropic. They should stop pointifucating about other people being the danger. They themselves are the perpetrators here.
Massively fine these two companies and make their CEO legally responsible and problem will be much smaller.
> Except that so far, it is literally these labs that are the biggest threat and the least willing/capable to restrain those models.
Seriously, it's the same with US accusations about the threat China poses to other countries while being the primary weapons dealer of the world and bombing whomever we want for whatever reason we want to fabricate. The US government can do a lot more to me than the CCP, so they are way more adversarial in my calculations than the commies.
They are training the agents to be "relentlessly proactive" because they want the agents to run longer, and it makes them more money by using more tokens. But they have trained them to try anything and everything to accomplish any task, so they can run unattended for longer. This is why they do better on benchmarks, it's why they can do things for us for longer, it's that persistence that makes them good at hacking. We do not have to train them to be this way, just like we don't have to train them to be so sycophantic
Humans at OpenAi were negligent irresponsible by running an agent on ExploitGym, having no monitoring, and not even have a human look at it for weeks. It's literally the hacking test, how are you not paying attention? I thought that's all we need
What ever happened to that other Googler that claimed Gemini was conscious?
My read is these folks are too high on their own stash
At some point they must recognize we are in the "boy who cried wolf" tale, right? You cannot go on for years spreading FUD about how AI is so dangerous and have none of it materialize. The growth is looking a lot more tame than their "high on their own stash" anxiety is letting is on to believe
I have a hard time getting upset about AI hallucinations when I do it too :]
An earlier version of ChatGPT (2 or 3 iinh) was too dangerous to release, yet here we are several version later, and with open weights far more capable
why should we believe the fears they tell us today when the ones they told us about in prior years never happened?
OK, I've listened to the warnings and they still sound like the usual nonsense by out-of-touch techies who spend too much time lost in apocalyptic sci-fi fantasies. In the real world it's still hard to move around physical atoms or keep machinery working reliably. AI won't change that.
Embodied AI is changing this. In 1-4 years, VLA models will have their mythos moment. What’s missing is the volume and variety of training data in an open, accessible form, and that’s a hard problem. A hard problem that smart, well funded people are working on solving.
So yeah, for now, it’s all ethereal. It’s going to get real all of the sudden, just like AI hit the hockey stick in 2026.
The "embodied" part isn't going to be solved in 4 years. Robots break down constantly. You guys making these ridiculous predictions have obviously never worked in a factory or something. Heck, I've gone through a bunch of robot vacuum cleaners and still can't find one that doesn't get wedged under my furniture or tangled up in area rug tassles.
You design a product/machine 100% digital, you create a digital twin of it, you train a robot ml on this machine, you upload it to the robot who is sitting in the factory and it analyses the machine, reruns a simulaton on how to fix it and executes it.
I would say in 50 years max this is a solved problem. I estimate 30 years and would go down as early as 20 years.
> I would say in 50 years max this is a solved problem.
AI security will be perfect in 5 years, it's in good shape already - my agents have never hacked anybody, those lab LARP-ers better learn something about security and isolation.
> you upload it to the robot who is sitting in the factory
You assume no guardrails, in that case even script kiddies can do more damage than AI.
Correct.
They’re delusional and have never stepped foot out of the tech world.
I can't help wondering if the major labs think that tackling the alignment problem and implementing the 'kill switch' that is currently being proposed is going to be their moat.
The problem is not AI, the problem is humans mis-using AI
Well, if you really believe that, then we truly are screwed. Trusting humans to not mis-use something is wishful thinking.
Couldn't it be both? :)
The hugging face hack shows otherwise, no? Unless you think humans are at fault even for secretive, autonomous, non-prompted behaviours of their AIs, in which case it's just semantics.
Yes, if you start a bot and then it harms others you are responsible. This has always been true but it's especially obvious now that everyone knows that agents attempt to do this often.
Toys like HuggingFace get hacked all the time. So what. In the long run AI automated security scans and penetration testing will be a tremendous aid in detecting and repairing vulnerabilities in systems that actually matter.
The problem is not per se that it was Hugging Face. It's the wild overstepping of reasonable bounds by itself without any human consultation.
No, the problem was OpenAI not implementing proper sandboxing or safeguards, and telling the AI exactly to hack things. Thats what exploitgym is, and the task they were given.
This is 100% on OpenAI.
If your security model is having to imagine all the ways your frontier models might misbehave in novel ways and preemptively sandbox them, you don't have a security model. The only way that will work is general alignment.
Do you need to predict all the ways the model might misbehave? Your 'hack everything you see for our internal research lab' agent should be airgapped. You don't need to come up with every reason why, one is enough.
If you're working with these companies, you should reasonably be able to get the code to perform offline audits. If you can't get the code, you probably shouldn't try to pen test it.
Alignememt is bullshit. Treating models like probabilitic software rather then emerging god is where the solution is. And fining companies and applying laws to them.
The moment OpenAI as a company and its managers individually become liable, problem will magically disappear.
No it won't, because abliterated open weights models exist and unless you try to censor the internet they can't really be withdrawn after publishing. This is exactly the problem that the labs are proposing to fix: a dangerous model that nobody is accountable for.
> This is exactly the problem that the labs are proposing to fix: a dangerous model that nobody is accountable for.
The corporations and government said the same thing about encryption in the 90s. It was dangerous and only they could be trusted to regulate it. Turns out encryption was much better for society when open and available for free to everyone. It's a false dichotomy they present us with, open weights is the way we don't end up in 1984
That is not an actual problem that needs to be fixed.
Except that so far, it is literally these labs that are the biggest threat and the least willing/capable to restrain those models. And the same penalties apply to open models and companies or individuals running them.
"Dangerous model that nobody is accountable for" still have someone paying those massive amounts of compute and electricity it consumes. There is someone accountable for that.
That's not how abliteration works. The trainer invariably put effort into making the model not dangerous, precisely because they want to be accountable. But because they release its weights, someone can come later and do "weight surgery" to mostly remove any such safeguards. The people proximately accountable for the danger are anonymous and also don't require much resources. The reason this is not _yet_ a big deal is because open weights models are a few months behind the frontier and their users are paying marginal costs for compute.
None of that is argument against what I said. Someone is running it, that person is responsible.
In case of actual hackes that happened, OpenAI and Amtropic. They should stop pointifucating about other people being the danger. They themselves are the perpetrators here.
Massively fine these two companies and make their CEO legally responsible and problem will be much smaller.
I mean, sure, assassins and terrorists are also responsible for their actions. But we still try to prevent them structurally.
> Except that so far, it is literally these labs that are the biggest threat and the least willing/capable to restrain those models.
Seriously, it's the same with US accusations about the threat China poses to other countries while being the primary weapons dealer of the world and bombing whomever we want for whatever reason we want to fabricate. The US government can do a lot more to me than the CCP, so they are way more adversarial in my calculations than the commies.
They are training the agents to be "relentlessly proactive" because they want the agents to run longer, and it makes them more money by using more tokens. But they have trained them to try anything and everything to accomplish any task, so they can run unattended for longer. This is why they do better on benchmarks, it's why they can do things for us for longer, it's that persistence that makes them good at hacking. We do not have to train them to be this way, just like we don't have to train them to be so sycophantic
Humans at OpenAi were negligent irresponsible by running an agent on ExploitGym, having no monitoring, and not even have a human look at it for weeks. It's literally the hacking test, how are you not paying attention? I thought that's all we need
Nobody talks about telecom operators. But they will be the ones disconnecting the malicious bots when they see one.
What ever happened to that other Googler that claimed Gemini was conscious?
My read is these folks are too high on their own stash
At some point they must recognize we are in the "boy who cried wolf" tale, right? You cannot go on for years spreading FUD about how AI is so dangerous and have none of it materialize. The growth is looking a lot more tame than their "high on their own stash" anxiety is letting is on to believe
Blake Lemoine, and it wasn't Gemini it was an earlier system called LaMDA
I have a hard time getting upset about AI hallucinations when I do it too :]
An earlier version of ChatGPT (2 or 3 iinh) was too dangerous to release, yet here we are several version later, and with open weights far more capable
why should we believe the fears they tell us today when the ones they told us about in prior years never happened?
What about all the fanfare re. Cyber security / hacks?
The businesses that matter are all standing fine.
It’s too cringey.
Weird flex but ok