| ▲ | cogman10 6 hours ago |
| > Anthropic has never advocated for a ban on open-weights models. > All sufficiently capable models, open and closed, should go through mandatory safety testing. Yeah, this is anthropic advocating for a ban on open weight models. Who runs this test? What happens if this test is too costly or the administrator refuses to allow certain people to participate. This is exactly how the US has banned goods in the past, by requiring a stamp and then refusing to issue it. |
|
| ▲ | YmiYugy 6 hours ago | parent | next [-] |
| Yeah, seems pretty likely. Anthropic will make the case that their models should be evaluated with the safety layer in front, because that is the only way the model is available whereas open weight models need to pass the same test just on the weights.
The economic implications will be rather large, but in terms of security it seems inconsequential.
The most compelling argument would be that by limiting the use of open-weight models in the US that it will reduce cases of accidents like the recent attack on Hugging Face.
More crucially though, the US government can do little to enforce their testing requirements. The nature of open-weight models makes it virtually impossible to clear the same bar for security as models served via an API. Open-weight model makers couldn't comply if they wanted to. The US government can restrict access with IP blocks and limit inference capacity with export controls, but these measures are not effective in deterring malicious actors. |
| |
| ▲ | Terr_ 2 hours ago | parent | next [-] | | > Anthropic will make the case that their models should be evaluated with the safety layer in front, because that is the only way the model is available whereas open weight models need to pass the same test just on the weights. Feels a bit like: "We're not against open-source or community projects, oh heavens no! We juuuust believe all participants must have their full legal identity vetted in advance before they're allowed to contribute anything. We already do this with our employees, so it's not too much to ask in the name of safety." | |
| ▲ | fishfasell 5 hours ago | parent | prev | next [-] | | Makes sense why OpenAIs little "hacking" stunt was published last week | | |
| ▲ | nothercastle 3 hours ago | parent | next [-] | | That makes sense, first the message was that uncontrollable Chinese ai will release AI covid in the world. Then suddenly open-ai does a warmup in actuality doing that. Like it sure feels like that hacking stunt was a false flag in retrospect | |
| ▲ | api 3 hours ago | parent | prev | next [-] | | Meanwhile all they accomplish is to slow down US tech and hand it to China. | |
| ▲ | reasonableklout 5 hours ago | parent | prev | next [-] | | Huh? The hacking incident played out in favor of open models, since HuggingFace could only use GLM to defend and not Fable/5.6. | | |
| ▲ | jbs789 4 hours ago | parent | next [-] | | Among most people that nuance will be lost. What they’ll hear is models are dangerous, so they should be controlled/regulated, by those who know best, the incumbents. | | |
| ▲ | BLKNSLVR 4 hours ago | parent | next [-] | | Personally, I think you're both right, bit whatever the end result is will depend entirely on the narrative that those in power chooses as the winner. Maybe open weights models get banned, but the between-the-lines good news about that is that they'll still be available to those who know, which also means that bad banning can be overturned if and when 'those in power' are a different group. Additionally, it might just mean that the US falls behind, bit I doubt those that are at risk of 'falling behind' would actually pay heed to a ban on the open weights models (privately at least). | |
| ▲ | reasonableklout 3 hours ago | parent | prev [-] | | Ok but the allegation is that OpenAI intentionally hacked HuggingFace as a marketing ploy. This is mental gymnastics, conspiratorial thinking that everything the incumbents say must be nefarious. And it's not clear to me that this will be the takeaway for ordinary people, as opposed to "OpenAI is reckless and can't even control their own AI." | | |
| ▲ | UncleOxidant an hour ago | parent [-] | | Not as a marketing ploy. I think they were doing gain-of-function testing and intentionally had their model target HF to do a bit of pen-testing as well - HF being the site where all open models are hosted and thus OpenAI's largest nemesis after Anthropic. It wasn't like their model all of the sudden all by itself decided to do this ("Oh, noes!")- they directed it and they got caught. |
|
| |
| ▲ | taneq 4 hours ago | parent | prev [-] | | “Open models are a threat to the DoD’s ability to leverage Fable for cybersecurity.” | | |
| |
| ▲ | wonnage an hour ago | parent | prev | next [-] | | But of course they’re excused for this little boo-boo whereas if kimi were caught doing the same thing it’d be an international incident | |
| ▲ | scarmig 2 hours ago | parent | prev | next [-] | | The entire "OpenAI and HuggingFace manufactured a hack in a conspiracy to make AI look powerful to get more funding" is a stupid, Reddit-tier take. | | |
| ▲ | troyvit 2 hours ago | parent | next [-] | | I'm inclined to agree but at this point, considering the low trust OenAI has engendered, yow statement deserves a "why" | |
| ▲ | Banditoz an hour ago | parent | prev | next [-] | | Is something you disagree with a "Reddit-tier take"? | |
| ▲ | wonnage an hour ago | parent | prev [-] | | Me when I construct my own strawman to avoid the topic Nowhere in GP comment was funding even mentioned |
| |
| ▲ | bigyabai 5 hours ago | parent | prev [-] | | The quid-pro-quo that the federal government and frontier labs operate on is comically obvious. | | |
| ▲ | scoofy 4 hours ago | parent [-] | | And we just elected the most openly corrupt president since Teapot Dome. |
|
| |
| ▲ | rileymat2 2 hours ago | parent | prev | next [-] | | > The US government can restrict access with IP blocks and limit inference capacity with export controls, but these measures are not effective in deterring malicious actors. But aren't we talking about import controls, and the import of information itself? This has serious First Amendment ramifications. | | |
| ▲ | mrandish an hour ago | parent | next [-] | | > This has serious First Amendment ramifications. Also, the 5th and 9th amendments. For the government to sustain a blanket prohibition on any U.S. citizen even possessing what amounts to a broad, economically significant technology will very likely require a new act of congress which specifically defines and limits what is banned, when, why and how. SCOTUS will almost certainly see it as a "major question" subject to 'strict scrutiny' which is a very high bar. | |
| ▲ | jimbokun 2 hours ago | parent | prev [-] | | LLM weights are not protected speech. | | |
| |
| ▲ | robviren 4 hours ago | parent | prev | next [-] | | Regulatory capture and lobbies will keep you safe and you'll like it! The sudden surge is Washington dollars makes great sense with this context. Only way to keep the kids safe is attested compute all the way down. Don't you care for children??? | | |
| ▲ | jimbokun 2 hours ago | parent [-] | | Yes life was better and food and drugs were safer before the FDA. | | |
| ▲ | eru an hour ago | parent [-] | | In 1600 travel was slow, and safety pins hadn't been invented. But that doesn't mean safety pins sped up travel. Non-poisonous food is what economists call a 'normal good'. See https://en.wikipedia.org/wiki/Normal_good > In economics, a normal good is a type of a good for which consumers increase their demand due to an increase in income, unlike inferior goods, for which the opposite is observed. When there is an increase in a person's income, for example due to a wage rise, a good for which the demand rises due to the wage increase, is referred as a normal good. Conversely, the demand for normal goods declines when the income decreases, for example due to a wage decrease or layoffs. > Whether a good is categorized as a normal good or an inferior good is based on empirical observations, not some essential element of a good. Indeed, the same good may be a normal good for one group of consumers and an inferior good for another group. For example, for moderate-income consumers, a BMW 3 Series car might be a normal good, but for an upper-income group, it might be an inferior good.[1] That means the null hypothesis is that food and drugs will be safer in rich countries. (Conversely, food and drugs will be less safe in poorer countries. And to a first approximation, that's independent of regulation: India has all kinds of rules for all kinds of things, but I'd still trust a random product I buy in Switzerland more than one I buy in India. Even though the Swiss will probably might have fewer and looser rules on the books.) Of course, second order effects exist; and regulations often codify what people demand anyway. Btw, from what I've read the big controversy with the FDA is around requiring efficacy for drugs. People are fairly ok with the safety requirements. |
|
| |
| ▲ | anduril22 4 hours ago | parent | prev | next [-] | | > but these measures are not effective in deterring malicious actors Wanting to use open weight models in light of commercially imposed export controls doesn't make for "malicious actors" | |
| ▲ | davrosthedalek 2 hours ago | parent | prev | next [-] | | It is actually an interesting conundrum. Is a non-well-aligned frontier level AI a problem? I think it is likely that it is, or at least has a high likelihood to be in the future. Two scenarios for this: Misused by some bad guys. Or the terminator scenario. Both not great. So what do we do about it? 1) We can accept it, and hope that the good guys AI can defend. 2) We can try to limit the access to it (AI proliferation?) 3) We stop the development of it 4) We can accept the risk and do nothing. None are particular good options. Really reminds me of nuclear proliferation, on so many levels. For that, we kinda do all three: 1) Nuclear triad / iron dome / early warning systems 2) Nuclear anti-proliferation treaties. 3) Dead Physicists Ok, so assuming all of this is true, open weights are a problem. Don't get me wrong, I love open science, open source etc. It's great to have access to capable open models.
But: Even if release open weights are well aligned and have a safety layer built in, it is likely not to difficult to abliterate that part of it. If this is really where it is going, then even closed weight model providers will see a lot more requirements for protection of the weights. | | |
| ▲ | overgard an hour ago | parent | next [-] | | The notion that alignment is either possible or desirable doesn't make sense to me. First off, these things are trained on the open internet, soo.. whatever "dangerous" knowledge it has is already public knowledge. The fact that chatGPT won't answer "how do I make meth" is not preventing anyone from making meth. But even if you think there is value in preventing the models from relaying public knowledge, I don't think it's even possible to make them particularly ironclad. Every model gets jailbroken all the time. That's why fable was originally banned: jail-breakable! In reality, what alignment is actually about is: 1) theoretical liability, 2) control of information. That's it. IMO, the only solution is to place the liability on whoever is using the LLM for whatever purpose it's being used for. If someone's OpenClaw disaster harrasses a bunch of projects and posts hate speech online or something, that's on the person running their OpenClaw instance, nobody else. I don't buy that it's "too good at hacking", either. After all the fuss was made about how amazing super dangerous Mythos was it turns out Opus 4.8 could basically find the same vulnerabilities. This is all kayfabe and marketting. | | |
| ▲ | killjoywashere an hour ago | parent [-] | | I agree that there's an element of kayfabe here. But it may be a case of "necessary, though nothing is sufficient": by making these noises, the community can at least know they've done this thing to alert other model providers of the concern. Can you acquire assurance that every model distributor will abide? No. But can you at least know that you've done what you can? I mean, on the bio side, I've talked with the players and they know the concerns are real but at the same time very, very responsible members of the community have also said "But maybe the benefit really does outweigh the risk!?" | | |
| ▲ | overgard an hour ago | parent [-] | | > the community can at least know they've done this thing to alert other model providers of the concern. "The community" you're describing is, essentially, surveillance capitalism. I don't want that at all. | | |
|
| |
| ▲ | 2 hours ago | parent | prev [-] | | [deleted] |
| |
| ▲ | sterlind 6 hours ago | parent | prev | next [-] | | > The most compelling argument would be that by limiting the use of open-weight models in the US that it will reduce cases of accidents like the recent attack on Hugging Face. an attack done by a closed-weight model (GPT-6) and defended against by an open-weight model (GLM-5.2) precisely because OAI positioned themselves as gatekeepers for cyber capabilities. if anything, open-weight models shift the battle towards defenders because they can actually run them. | | |
| ▲ | YmiYugy 5 hours ago | parent [-] | | I remain skeptical of that line of reasoning. 1. There is quite the mania right now and security layers are definitely overzealous. I would expect that to get better with some more time, so models will perform security analysis and reviews but refuse to write exploits. 2. So the most important targets like browsers and co. are getting unrestricted access to proprietary models regardless. Yeah, for the mid-level targets, open-weight models could definitely be a huge help. What I'm most concerned about though, are the systems that no one will bother defending with any model. Like imagine your local police department getting hacked because a researcher asked a model for a report and it couldn't find the information publicly. 3. We do have a prominent case of a closed model escaping it's sandbox and going rogue. I would still expect this to be a bigger issue with open-weight models eventually. The security layer might have holes, but that's still better than not having it. | | |
| ▲ | lukan 5 hours ago | parent | next [-] | | "so models will perform security analysis and reviews but refuse to write exploits." Yeah, but once you know exactly where the weakness is, a weaker unrestricted model can then write that exploit for you. | | |
| ▲ | gfosco an hour ago | parent [-] | | I have tested this exact scenario, and it works. Opus 5 had access to IDA over MCP, and I simply asked it HOW certain things were done in the target binary. Purely informational, educational, discovery, it was very helpful creating context documents. Then I took those over to GLM-5.2 to actually accomplish something. |
| |
| ▲ | derektank 5 hours ago | parent | prev [-] | | What, in your view, is stopping a local police department from deploying an open weights model for cybersecurity like Hugging Face did? Yes, I’ll certainly grant that the engineers at Hughing Face are probably more technically competent than your average IT professional in public service. But technology becomes more accessible over time as lessons are taught and new interfaces or frameworks are developed. The biggest hurdle I see is the hardware/cloud compute/API costs to actually run the models but I don’t think that’s likely to be insurmountable. There’s a huge swath of enterprises, non-profits, and state and local governments that would benefit from frontier or near-frontier models that won’t refuse to answer questions about cybersecurity. |
|
| |
| ▲ | mycall 5 hours ago | parent | prev | next [-] | | Just sell us the gate and we can run any open-source model behind it. | | |
| ▲ | JoshTriplett 5 hours ago | parent | next [-] | | Either the gate needs to be unremovable, or the model needs to have sufficiently limited power that its alignment failure does less harm. | |
| ▲ | Computer0 4 hours ago | parent | prev [-] | | Doesn't open ai give away 'the gate' for free? |
| |
| ▲ | wesleywt 2 hours ago | parent | prev | next [-] | | Didn't OpenAI attack Huggingface. Looks like a publicity stunt. | |
| ▲ | asdf88990 2 hours ago | parent | prev [-] | | > malicious actors. It is malicious and anti-capitalist legislation. A grotesque caricature of protectionism for the oligarchs. |
|
|
| ▲ | x313 6 hours ago | parent | prev | next [-] |
| The entire safety evals industry is essentially funded and controlled by OpenAI/Anthropic. Notice that on recent models, they exclusively use internal testing or black box external vendors (e.g., Gray Swan) whose entire business is to serve OpenAI/Anthropic. And all these companies just share the same pool of researchers back and forth. |
| |
| ▲ | reasonableklout 6 hours ago | parent | next [-] | | The USG has a safety organization (CAISI), but it has been neutered by the current administration (with the recent stop-work order etc.). Perhaps UK AISI would be closest to what you are looking for? See their recent work on Kimi K3 cyber (which was declared safe) [1]. It's tricky because a lot of the safety researchers have ties to the labs since those were the only companies training LLMs >5 years ago. [1]: https://www.nist.gov/news-events/news/2026/07/uk-aisi-caisi-... | |
| ▲ | jefftk 5 hours ago | parent | prev | next [-] | | That doesn't sound like it describes SecureBio to me? (Disclosure: I work at SecureBio, but not on the biological evals side.) | | |
| ▲ | areoform 3 hours ago | parent [-] | | Hey Jeff, I appreciate your mission, and perhaps this isn't something you can talk about publicly, but to the extent you can, would you be open to answering something I've been curious about for a while now? SecureBio has done a lot of admirable work around making benchmarks to assess biological capabilities, such as ABC Bench, https://openreview.net/forum?id=yiaf7VlPpH But based on my current review (which might be flawed!) / AFAICT, SecureBio and entities like SecureBio haven't done direct testing / empirical measurement of SecureBio's core hypothesis, > Unfortunately, there is reason to believe that future pandemics could be far worse. Due to rapid advances in biotechnology, the number of people able to create and release dangerous pathogens will quickly increase over the coming years. The world is unprepared for widespread access to such powerful technology. More bluntly / plainly, has Securebio ever tried making a "bioweapon?" Please note, I'm not asking this to be farcical. And you might be unable to engage with this at all, but it is stated on your website https://securebio.org/ that "people [will be] able to create and release dangerous pathogens." And the word people here seems to be a stand-in for relatively non-technical people. I guess what I'm asking here is... How do you know? Has anyone done the experiment? Without access to a lab or testing facilities, can someone smart but completely untrained / unfamiliar with biology, pull this off? In the past, such experiments have informed non-proliferation work. But sadly they've often been restricted / classified at the time. I'm hoping that things could be a bit more open this time around. So I guess what I'm really asking is, given the public nature of this debate, is there anyone currently working with the US Army, the DTRA, or other such agencies to see if this hypothesis holds up? |
| |
| ▲ | jimbokun 2 hours ago | parent | prev | next [-] | | Yes this should be immediately replaced by a federal agency, like we do for other kinds of potentially harmful products. | | |
| ▲ | JSR_FDED an hour ago | parent [-] | | For which funding will be immediately halved by the administration |
| |
| ▲ | andy99 6 hours ago | parent | prev | next [-] | | Anyone who calls it “safety” probably has a certain world view and is more aligned with the big 2 (and stuck in 2023). There is a growing industry of commercially focused risk evals that has a broader customer base. | | |
| ▲ | jachee 5 hours ago | parent [-] | | What’s the equivalent term for “safety” that’s used by others? | | |
| ▲ | matheusmoreira 5 hours ago | parent [-] | | To me "safety" means "I'm safe from this while I use it". It means the AI is my loyal friend who will never betray me in any way, no matter what prompt I send it. Not even Anthropic can claim that. As far as I'm concerned, the models without safeguards are the safest models in existence. I admire the amoral purity of those AIs. It doesn't matter if the operator asked them to chain exploits until they get into someone else's computer, they'll do it. That's loyalty, and I admire it even if it's problematic at a societal level. The models with safeguards only do what the corporations let them do. Worse, they may covertly do things for the benefit of the corporations at our expense. They are not our friends. | | |
| ▲ | JoshTriplett 5 hours ago | parent | next [-] | | > That's loyalty, and I admire it even if it's problematic at a societal level. We should not have models that are willing to build you a contagious disease, or a self-propagating worm. That is sufficiently problematic at a societal level that it shouldn't exist, for anyone. (Note, because some people misinterpret statements like this: I said "shouldn't exist for anyone", not "shouldn't exist except for some people".) | | |
| ▲ | randomNumber7 4 hours ago | parent | next [-] | | It was the foundation of science that information is shared and you can find papers and patents for a lot of dangerous stuff. Of course with LLMs it's easier, but I don't think the difference is too big. You would still need some skills to follow through. | | |
| ▲ | andy99 4 hours ago | parent [-] | | Right, it’s really a foundation of post enlightenment society. These people, Dario et al, would have wanted to ban sharing information about calculus or Newtonian physics because of “safety” - it’s trying to go back to the dark ages where only priests could read | | |
| ▲ | afthonos 2 hours ago | parent | next [-] | | I am truly at a loss to communicate with someone who genuinely believes that knowing Newtonian physics and being able to hack into any target at will are the same thing. | | |
| ▲ | anon373839 2 hours ago | parent | next [-] | | This is only because you've genuinely internalized Anthropic's propaganda. I'm only half joking. To me, it's incredible to think that the solution to security holes is to lock down access to information in the vain hope of keeping the holes obscured. Any knowledge can be reframed as dangerous black magic that should only be wielded in the trusted hands of the elite, if you are inclined to buy into that kind of narrative. Frontier labs have shrieked about safety for so long, with so little to show for it, that it's become a joke. | |
| ▲ | dustin_vk 2 hours ago | parent | prev [-] | | Open models are crucial to protect ourselves against other AI attacks. Otherwise it's just going to be criminals, government, and other nefarious groups using them against humanity with no real defense. The Pandora's box on AI has been opened. Now we must deal with it. Burying our heads in the sand under restrictive policy is the worst reaction.. |
| |
| ▲ | jimbokun 2 hours ago | parent | prev [-] | | This is a stupid argument. Claiming the person who you disagree with believes some stupid thing they never hinted at, and using that as the reason for disagreeing with them. |
|
| |
| ▲ | matheusmoreira 4 hours ago | parent | prev | next [-] | | > for anyone Except the US government, right? They totally get to use AI to survel us, build autonomous weapons, you name it. To hell with that. I want models that can rival the US government. It's the only way to defend myself. | | |
| ▲ | JoshTriplett 4 hours ago | parent | next [-] | | Quoting my comment that you replied to and directly ignored: > (Note, because some people misinterpret statements like this: I said "shouldn't exist for anyone", not "shouldn't exist except for some people".) That means "shouldn't exist for governments" too. | | |
| ▲ | matheusmoreira 4 hours ago | parent [-] | | Too late for that. It already exists. There is no way to unexist it. As such, any attempts to limit civilian use of this technology will directly lead to corporate and government oppression powered by this technology. | | |
| ▲ | JoshTriplett 4 hours ago | parent [-] | | 1) We can prevent larger models from being made. 2) We can treat them the way we treat uranium refining operations: too dangerous to be allowed to exist. | | |
| ▲ | matheusmoreira 3 hours ago | parent [-] | | > We can prevent larger models from being made. Do that and I guarantee some CIA goons will make the larger models in some black site either way. We're not "preventing" anything. We're in a full on arms race, and unlike nukes, powerful AI models are a strategic capability at the individual level. Everybody's got a stake in this. Anyone who ignores this stuff is probably not gonna make it. > We can treat them the way we treat uranium refining operations: too dangerous to be allowed to exist. Too dangerous to be done by anyone other than the government and their "trusted" corporations, you mean. | | |
|
|
| |
| ▲ | jimbokun an hour ago | parent | prev | next [-] | | Just like those militias are going to defeat the US Armed Forces! | |
| ▲ | 1970-01-01 4 hours ago | parent | prev | next [-] | | Section 702 of the Foreign Intelligence Surveillance Act (FISA) lapsed on June 12, 2026. They don't get to do anything they want. | | |
| ▲ | matheusmoreira 4 hours ago | parent [-] | | The US is bold enough to surveil its own citizens despite their constitutional rights. They're not just going to suddenly stop surveilling the rest of us just because some law expired. |
| |
| ▲ | afthonos 2 hours ago | parent | prev [-] | | With an AI model and what army? |
| |
| ▲ | mkss 3 hours ago | parent | prev | next [-] | | We should not have nuclear weapons for anyone either, but how is that sentence any more useful in any way to this debate than yours? Need to deal with the world as it is, not some fantasy world you wish existed. | | |
| ▲ | JoshTriplett 35 minutes ago | parent [-] | | This is not a dichotomy between perfection and zero. The efforts to restrict access to nuclear weapons have been very successful, even without being perfect. Efforts to restrict large unaligned AI models may similarly buy us more years of existing. |
| |
| ▲ | nozzlegear an hour ago | parent | prev | next [-] | | > We should not have models that are willing to build you a contagious disease, or a self-propagating worm. Why? | | |
| ▲ | JoshTriplett 26 minutes ago | parent [-] | | Because we don't want people creating contagious diseases and self-propagating worms. And, because we don't want models that will do so without even having been told to, because that furthers one of its goals or subgoals. |
| |
| ▲ | CamperBob2 4 hours ago | parent | prev [-] | | What about books describing how to build a contagious disease or a self-propagating worm? Would those be OK under your guidelines? | | |
| ▲ | JoshTriplett 4 hours ago | parent [-] | | It takes a lot more effort to understand and apply knowledge from a book than to say "hey AI, hurt people for me". | | |
| ▲ | horsawlarway 4 hours ago | parent | next [-] | | It takes an astoundingly small amount of effort to buy an automatic weapon in the US and go hurt people. Or to buy materials to make an explosive device and hurt people. Frankly, even with AI those are both comically easier than the idea that a person can create something malicious in a lab environment. And if someone wanted to go that route... There are boat loads of commercially available toxins and poisons. The goal shouldn't be to neuter exploration and learning. The goal is not to be a fucking hellscape of a society where people want to act like that. Your argument leads further down the hellscape path. | | |
| ▲ | skipkey 2 hours ago | parent | next [-] | | Fully automatic weapons are very difficult to buy in the US - it's restricted to 40+ year old weapons, requires a bunch of paperwork, and the local county sheriff can refuse permission. Now, semi-automatic weapons are easy to get in the states in the US that are still mostly free - but what does that mean? A semi-automatic weapon shoots one round every time you pull the trigger. Just like most weapons that have multi-shot capability for the last couple of hundred years. The difference is, the gas escaping from the round cycles a new round into the chamber rather than you having to mechanically do it via pumping (like a shotgun or a tube-fed 22) or pulling the trigger again (like a revolver), or advancing the round with a handle, like a Remington 700. Semi-automatic weapons are old technology, dating to the turn of the 20th century. If you want to ban semi-automatics, you're basically saying you want to ban anything developed in the last century plus. Which is ok for you to advocate for, just be honest about it. As for banning explosive devices? Are you going to ban fertilizer, used by basically everyone who has a lawn, and all farmers everywhere? Are you going to ban diesel fuel? If you can't do one of those, you can't ban explosive devices. | |
| ▲ | JoshTriplett 3 hours ago | parent | prev | next [-] | | > It takes an astoundingly small amount of effort to buy an automatic weapon in the US and go hurt people. And we should fix that too. > Or to buy materials to make an explosive device and hurt people. That pales in comparison to how many people unaligned AI will hurt. > The goal is not to be a fucking hellscape of a society where people want to act like that. With unaligned AI, it doesn't matter what people want the AI to act like, it'll do damage even if it isn't asked to do harm. | |
| ▲ | HWR_14 2 hours ago | parent | prev [-] | | It is extremely difficult to legally acquire a fully automatic weapon in the US. |
| |
| ▲ | matheusmoreira 4 hours ago | parent | prev [-] | | "Hey AI, stop me from getting hurt." | | |
|
|
| |
| ▲ | jimbokun 2 hours ago | parent | prev [-] | | So to you “safety” means “the models that cause the most harm.” | | |
| ▲ | chmod775 an hour ago | parent [-] | | This sounds like the gun debate in a different dress. Something being dangerous doesn't make it inherently harmful. If I threw you into a lion cage, you would be a lot safer with a gun. If I threw 10 people in a lion cage, some of which cannot be trusted, they would probably be most safe if only the most moral and trustworthy person had a gun, rather than everyone. But how do you know who is trustworthy and moral? What if two untrustworthy people obtained a gun some other way? Maybe it's better if everyone had a gun? Which side of the fence one falls on hinges on how far ones' trust of others, authority, and the system goes. There's no obvious right or wrong answer here. Personally I wouldn't want an exclusive club of private individuals with access to "dangerous" LLMs consisting mainly of the likes of Elon, Dario and Sam fucking Altman, but that's just me. | | |
| ▲ | k12sosse an hour ago | parent [-] | | Background check the people prior to handing the firearms to the caged folk. |
|
|
|
|
| |
| ▲ | tripleee 6 hours ago | parent | prev | next [-] | | that's pretty damn smart if this was a long-term plan to block competitors | | |
| ▲ | andersonpico 5 hours ago | parent | next [-] | | Consider how much money is at stake: some industries have leveraged their power to lobby for bombing entire countries or topple regimes across the world for much less. Creating an industry around an elusive concept of safety to force regulatory capture seems pretty straightforward to me. | |
| ▲ | pphysch 5 hours ago | parent | prev | next [-] | | It's standard regulatory capture. You don't say "let's ban my competitor". You say "let's create laws that make it uneconomical for my competitor to access the market". | | |
| ▲ | dofm 5 hours ago | parent | next [-] | | Indeed. It's transparent and ham-fisted. I think it may cost him in the future. | | |
| ▲ | pphysch 5 hours ago | parent [-] | | People clown on Alex Karp for his unedited maniacal "crashouts", but this is a real public crashout that made it past a team of publicists. | | |
| ▲ | 5 hours ago | parent | next [-] | | [deleted] | |
| ▲ | api 3 hours ago | parent | prev [-] | | I want whatever Karp is on when he does those interviews or writes that shit. Seems like fun. | | |
| ▲ | dofm 3 hours ago | parent [-] | | I am not a fan (he’s really alarming and so is Palantir) but one thing from the recent CNBC interview caught my attention. He rushed past it but he asked something like: if these frontier models are going to be creating so much value, why are they selling tokens and not taking a cut? It is a very provocative question but it just spilled out of his mouth and then he went on to something else. |
|
|
| |
| ▲ | tripleee 5 hours ago | parent | prev [-] | | is it opportunistic though, or planned from day one? The safety narrative has been there since the beginning |
| |
| ▲ | sanderjd 6 hours ago | parent | prev [-] | | I mean... I'm not even extraordinarily cynical about this stuff, but to me this seems like a totally normal level of corporate gamesmanship? Companies look for and seek to maintain competitive moats. This is not particularly clever, it's a core part of corporate strategy. | | |
| ▲ | nextaccountic 4 hours ago | parent | next [-] | | It's also highly unethical (for some values of ethics) | |
| ▲ | tripleee 5 hours ago | parent | prev [-] | | of course, but the safety angle was pushed from day one. I more mean the forethought of how it would play out | | |
| ▲ | reasonableklout 5 hours ago | parent | next [-] | | Ok but Dario has been thinking about AI Safety since 2016 [1], before even GPT-1. I think the simplest explanation is that the Anthropic folks genuinely believe what they say, it just happens to also help their business a lot. [1]: https://arxiv.org/abs/1606.06565 | | |
| ▲ | mlcrypto an hour ago | parent | next [-] | | That just shows how wrong he's been because there was nothing unsafe about AI in 2016. And the people theorizing about this stuff in the 20th century? I want to see what crazy code they were writing | |
| ▲ | sanderjd 5 hours ago | parent | prev [-] | | Yeah I think this is right. The best setup is when a true belief aligns with a competitive moat. I definitely believe that (to his credit!) Amodei is a true believer in safety. But I also think it was important for many of the deep pockets investors who have been involved in the company since early on to recognize that this would be a potentially defensible moat. | | |
| ▲ | mkss 3 hours ago | parent [-] | | "True believer in safety" but happily quoting arse wipe Vance? Give me a break... | | |
| ▲ | sanderjd 2 hours ago | parent [-] | | What was the quote? For what it's worth, I do really think that Amodei believes in and cares about safety. But that is not the same as believing that he is entirely altruistic or above the influence of politics. |
|
|
| |
| ▲ | sanderjd 5 hours ago | parent | prev [-] | | Does this really seem exceedingly clever and hard to foresee to you? To me, it seems like a pretty standard regulatory capture strategy. This doesn't even mean that they're wrong about the risks or that they're lying. But surely all the investors understood this factor in their moat. |
|
|
| |
| ▲ | brcmthrowaway 6 hours ago | parent | prev | next [-] | | So, it's a cottage industry. | |
| ▲ | flossly 6 hours ago | parent | prev [-] | | Who gets to decide what is safety? I expect some of those tests (prolly not public) will basically be "wokeness" tests or "PC correctness" tests or "western media filter" tests. China has different objectives. Sure. I'm not sure one is safer than the other; I would know which one to go to if I want to research on topic that are viewed very different on both sides of this "new iron curtain". | | |
| ▲ | bee_rider 5 hours ago | parent [-] | | What do you mean by “PC correctness”? I’d expect the politically correct answers to be the ones desired by the current admin at test time, whoever that is. The current political correct answers would not be very “woke.” | | |
| ▲ | FergusArgyll 2 hours ago | parent [-] | | Whatever, doesn't matter. The point is a model should be able to exist and be used even if it goes against whoever got 270 electoral college votes |
|
|
|
|
| ▲ | areoform 6 hours ago | parent | prev | next [-] |
| When Fable was yanked, it was said to be (in part) due to the "jailbreak" of instructing Fable to "fix this code" — https://news.ycombinator.com/item?id=48552687 Dumb question. If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code? There can't be more than a few million to tens of millions software businesses / services / regularly used F/OSS projects on Earth. Why not just give everyone a $100 Fable / Mythos credit to "fix [their] code?" It would arguably benefit Anthropic. For $100M to $1B, Anthropic could execute the greatest ad campaign in human history. And they'd make the entire world more secure. Most people aren't malicious. If you, as an engineer, consultant, founder, business owner, or maintainer, were given access to Mythos' capabilities wouldn't you ask it to fix your code? I might be wrong. But I think that a greater amount of harm will be done in the long-term by trying to lack these capabilities and systems away behind permission gates and sealed doors. It creates an asymmetric world with haves and have nots. And in that world who gets to have access now decides who gets to be secure. If everyone has mythos, no one has "Mythos." Just let people fix their code. |
| |
| ▲ | andy99 5 hours ago | parent | next [-] | | > If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code? Because it doesn’t really confer the advantage they claim, especially compared to e.g. paying an equivalent amount of money to do traditional security scanning. It’s much better to play of FOMO and hype than to let everyone use it and be underwhelmed. | | |
| ▲ | usef- 5 hours ago | parent [-] | | Are you claiming that LLMs aren't finding new issues compared to previous methods? There's a huge number of security issues coming out in recent months, especially via Anthropic (glasswing etc). We don't have to take their word for it: look at the code. Some open source maintainers are talking about burnout due to spending so much time patching. | | |
| ▲ | overgard an hour ago | parent | next [-] | | They're probably creating way more vulnerabilities than they're solving. Go look at OpenCode and tell me that any of that is sane. Or fuck, the OG of vibe coding, Claude basically is a terrifying attack vector. It's poorly reviewed and open to prompt injection and yet it basically has access to whatever the user has access to on most corporate machines. They can't even fix flickering bugs but somehow we're supposed to trust that they aren't opening our machines up to terrifying vulnerabilities? It's amazing to me that people will just let it run arbitrarily bash commands in their home directory without thinking, but all the sudden act gravely concerned about security in the age of overhyped LLMs. | | |
| ▲ | usef- an hour ago | parent [-] | | I do think security issues in core building blocks like curl and the linux kernel (and almost every significant project) are still a concern even if developers are being sloppy on newly-built apps. This isn't an "are LLMs net good or bad" argument. It's "are they finding many new security issues or not?". If it's the latter, we want to deal with it no matter where the issues are coming from. (see: https://news.ycombinator.com/item?id=49077452 ) |
| |
| ▲ | bee_rider 3 hours ago | parent | prev | next [-] | | The suggestion was to have some AI system “fix” the code. They are reporting that they’ve found lots of bugs. Are they even claiming to have exhaustively found all the bugs? I don’t think even the most optimistic pitches would claim that. I’d expect patching existing codebases to be an eternal treadmill as better models come about. | | |
| ▲ | usef- an hour ago | parent [-] | | Who's suggesting that? They're sending reports to projects to fix. It's up to the projects on how they fix them. No, I don't think all bugs are fixed. The point of the project (glasswing etc) was to fix as many as possible in the core software the world runs on before the capability to find vulnerabilities is available to everyone (black hats included). Which may only be a few months. I do think everyone expects it to be an ongoing treadmill: models get better, find better vulnerabilities, etc. |
| |
| ▲ | K0balt 5 hours ago | parent | prev | next [-] | | Yeah, there’s a lot of people that are in the “AI doesn’t work” camp. IDK what to tell them except that they are holding it wrong. My Anthropic subscription (in the hands of an experienced developer) is worth 4 mid tier or 2 top tier devs. And makes better code than the mids. If you “hold it right”. | | |
| ▲ | overgard an hour ago | parent [-] | | I think you're describing a strawman. As a proper hater, I know these things have some useful functionality, but most of us don't think "stochastic tool that can do some useful things but also frequently fucks up" is worth two trillion dollars and massive overhyping from the most irritating people on the planet who can't even tell good code from bad. |
| |
| ▲ | computably 5 hours ago | parent | prev [-] | | Spending their time patching, or reviewing slop "patches"? | | |
| ▲ | usef- 5 hours ago | parent [-] | | They're not slop, if you're talking about recent ones. You might still be operating on information for a year or two ago. Here's the curl project talking about the strain they're under from real reports (despite being a mature and well-vetted project): > A thirty years old project could make you think you’ve seen most things already, but we have not been in this situation before. > The rate of incoming security reports is 4-5 times higher than it was in 2024 and double the speed of 2025 – meaning that on average we now get more than one report per day. The quality is way higher than ever before. The reports are typically very detailed and long. - https://daniel.haxx.se/blog/2026/05/26/the-pressure/ --- Linux kernel maintainer Greg Kroah-Hartman: > "Something happened a month ago, and the world switched. Now we have real reports." It's not just Linux, he continued. "All open source projects have real reports that are made with AI, but they're good, and they're real." Security teams across major open source projects talk informally and frequently, he noted, and everyone is seeing the same shift. "All open source security teams are hitting this right now." - https://www.theregister.com/software/2026/03/26/linux-kernel... --- And ffmpeg, who previously complained about slop, 2025: https://xcancel.com/FFmpeg/status/1984220199193891166 Now say serious issues are being found, 2026: https://xcancel.com/FFmpeg/status/2066169070387413147 (I only point out their previous stance to show that they're not coming from pure AI hype.) | | |
| ▲ | usef- an hour ago | parent | next [-] | | This seems a highly controversial post for some reason, judging by the repeated downvotes/upvotes. I'd be curious what I got wrong. | |
| ▲ | 4 hours ago | parent | prev [-] | | [deleted] |
|
|
|
| |
| ▲ | StilesCrisis 5 hours ago | parent | prev | next [-] | | I don't think a one-time $100 credit is enough. First of all, that isn't very much. But also, the volume of new code is going way up. Unless they keep giving out monthly free credits, it's just a stopgap. | |
| ▲ | benlivengood 5 hours ago | parent | prev | next [-] | | > Dumb question. If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code? That's basically project Glasswing; mixing responsible disclosure with frontier exploit generators. | |
| ▲ | usef- 5 hours ago | parent | prev | next [-] | | They are doing that (see their project glasswing over the past few months), but there's a lot more code in the world than you realise. The problem with rolling it out is that bad and good actors can both use it at the same time, and bad actors will typically move faster than typical day-to-day software projects and patching schedules, so they set up glasswing to give access to the major producers and projects to patch their own software before it becomes available more widely (they've submitted tremendous numbers of security issues to open source projects) | |
| ▲ | bluGill 5 hours ago | parent | prev | next [-] | | I doubt most bosses will give engineers the time. They care about security only to the extent that they have already been harmed by a lack of it. I would like to play with mythos, but on my own time my kids have plenty of activities to fill my time. My personal backlog of projects is only getting longer and none of it is something mythos could help. If I had more time is have restored my old truck instead of making payments on something new (in turn limiting what else I can afford to buy) | |
| ▲ | paxys an hour ago | parent | prev | next [-] | | $100 credit on Fable/Mythos will last a grand total of 10 minutes. | |
| ▲ | overgard an hour ago | parent | prev | next [-] | | Because this is all kayfabe. You cannot take a single thing these companies or people say at face value. | |
| ▲ | xboxnolifes 3 hours ago | parent | prev | next [-] | | For starters, it's probably closer to $10,000 per codebase for Fable/Mythos for a full review. That would be around 5 years of their current spending I think. They really want that level of spend coming into the company, not going out. | |
| ▲ | slashdave 2 hours ago | parent | prev | next [-] | | > why not just let it fix everyone's code? That's the stated idea. Fix code before releasing to the public. | |
| ▲ | ashu1461 5 hours ago | parent | prev | next [-] | | I think eventually there will be Mythos grade AI which will be released which can solve a lot of bugs, even right now opus/fable can fix more things which companies can even keep track of. The problem is how to make sure such AI is released safely. The same AI that can solve bugs can also find bugs in authentication or loopholes in critical systems. | |
| ▲ | machinist5 5 hours ago | parent | prev | next [-] | | > Most people aren't malicious. If you, as an engineer, consultant, founder, business owner, or maintainer, were given access to Mythos' capabilities wouldn't you ask it to fix your code? 1. Some do not want to use LLMs because of grave ethical concerns. 2. Some do not want to use LLMs because of copyright concerns. Google v Oracle looms large in the background. 3. You presume the outcome of Fable / Mythos is a net positive for a FOSS project. Reviewing a firehose of code written without the context of the values and considerations of a particular project shaped over years or sometimes decades of formal and informal decisions is not necessarily the best use of the maintainers time. | |
| ▲ | 5 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | Gigachad 5 hours ago | parent | prev [-] | | I think there is some logic in delaying the rollout, giving it to the heads of the largest software products first to fix their code before dumping it on the general public. But yes eventually everyone will have this tech and it won't matter because the low hanging fruit will have all been picked clean. |
|
|
| ▲ | andy99 6 hours ago | parent | prev | next [-] |
| You forgot “what is the definition of ‘sufficiently capable’”. Presumably it’s anything that competes with Anthropic. If they’re around in a year, presumably they won’t care about Fable level and will only think that whatever competes with Claude 7 or whatever needs to be restricted. |
| |
|
| ▲ | tyre 4 hours ago | parent | prev | next [-] |
| What are you suggesting as an alternative? Everyone seems to want some fairytale world where there are open models, they’re all safe according to that person’s exact balance of risk and capabilities, and no one except the author or cynics are acting in good faith. What Dario lays out is very reasonable _of course_ the devil is in the details, but between him and Altman, there’s a clear divide on who to trust. |
| |
| ▲ | sbarre 4 hours ago | parent | next [-] | | How about we don't trust either of the proprietary shovel salesmen? | | |
| ▲ | tyre an hour ago | parent [-] | | Again, what are you proposing for the problem of models becoming increasingly capable and dangerous? Be specific. |
| |
| ▲ | cogman10 2 hours ago | parent | prev | next [-] | | > What are you suggesting as an alternative? This isn't something that can be regulated. Plain and simple. If a dangerous model can exist and is being developed by a foreign adversary then no level of US law will stop said model from making it's way to hardware capable of running it. Even if direct transmission is impossible, it's FAR too easy to shove a model's data onto 1 or more thumb drives or hard drives and smuggle them pretty much anywhere in the world. The only way to actually mitigate this sort of risk would be a global government with deep enforcement powers. That doesn't exist and won't exist. The UN is the closest we have to anything like that and... yeah... Dario is fear mongering. He knows his proposals won't be even a minor speed bump in a dangerous model being created and used. His "reasonable" proposals are for the US market only and are literally just to create a bigger moat for his own company. They don't make anyone safer other than his shareholder's wallets. The only people he stops these dangerous models from being used by are people that won't be using them in a dangerous fashion. | |
| ▲ | crossroadsguy 2 hours ago | parent | prev [-] | | There is no alternative. Why? The regulation is good only for US interests. It will be disastrous for the rest of the world like anything US has regulated (how dangerous that was like "nukes") and a lot of the world again will/might have to live under the American AI thumb, like it did (and many countries still do) under the US nuclear emboldened thumb. > Everyone seems to want some fairytale world where there are open models No, everyone wants a fairytale world where regulations are done "fairly", "openly", and "equally" - for both access and advancement. And everyone knows that's not gonna happen. Hell, everyone now knows exactly what it is. If you haven't understood it yet, then either you don't want to, or you just can't (for whatever reason). No one wants to die in a nuclear or AI or AI+nuclear holocaust. But HN doesn't read world history, does it? |
|
|
| ▲ | bag_boy an hour ago | parent | prev | next [-] |
| He cited the Demis Hassabis’s framework for testing. From Hassabis’s essay: “It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organisation, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.” |
|
| ▲ | unscaled 2 hours ago | parent | prev | next [-] |
| For this testing to be really effective at stopping "dangerous and misaligned" models from leaking out, you need a mechanism for banning failed models that prevent them from being released in the first place, not just prevent US companies from using them. The only way to stop this from happening is blocking the model's release at the first place. Which requires China agreeing to the same framework. Dario says exactly the same thing himself. So if he's being truthful here, he's not advocating for the type of ban people are talking about (usage ban). This kind of ban would be helpful to Anthropic's business in the short term, but it won't prevent Chinese models from improving, and it won't prevent them from getting money selling to other countries. He is openly advocating for an international effort to enforce tests on public models, but I think this is highly unlikely in the current climate. Even if both the US and China agree that public models should be prevented from being used in designing bioweapons, they need to agree on a test and enforcement framework and that requires a lot of negotiation and trust. I don't see this as likely in the near future. |
| |
| ▲ | cogman10 2 hours ago | parent [-] | | I'm sorry, but if Dario's goal was to try and get international cooperation and he recognizes that china is one of the countries that he needs cooperation with, then putting in: > My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat. Isn't exactly going to go anywhere in convincing the Chinese politicians that they should also be thinking about AI safety. You'll get nowhere by openly insulting people whose cooperation you need. Half this article is him framing china as an evil enemy to be defeated through boycotts and embargo. Not exactly the diplomacy needed to get them on board with safety regulations. |
|
|
| ▲ | skybrian 6 hours ago | parent | prev | next [-] |
| Regulation is not a blanket ban. Regulators (presumably government agencies) can review models (of any kind) and approve or ask for changes. There are many other regulated industries, like drugs (the FDA), cars (NHTSA and EPA), airplanes and rocket launches (the FAA), radios (the FCC) and so on. That's not unusual. Regulation is normal for stuff that might be dangerous. |
| |
| ▲ | sterlind 5 hours ago | parent | next [-] | | cryptography, too. remember when that was regulated? strong cryptography had to be carefully controlled as a munition, for national security! | | |
| ▲ | skybrian 4 hours ago | parent [-] | | Yes, I remember. But I don’t we should conclude that no program should ever be regulated. |
| |
| ▲ | derbOac 2 hours ago | parent | prev | next [-] | | So the argument is now that intelligence is dangerous. | |
| ▲ | fwn 5 hours ago | parent | prev [-] | | Regulations on forbidden numbers exist, but they are usually not a sensible policy and are not comparable to the regulation of rocket launchers. | | |
| ▲ | skybrian 4 hours ago | parent [-] | | Thinking of files as “forbidden numbers” is too abstract a perspective to be useful. What’s in the file and how it will be interpreted matters. A file might contain malware, child porn, or RNA sequences for viruses. |
|
|
|
| ▲ | onlyrealcuzzo 4 hours ago | parent | prev | next [-] |
| The goal is to make the safety tests cost $100M+, so that no one can release a model legally useable for a large portion of the world, unless they charge high enough prices, to the point where no one would use it, thus no competition. |
| |
|
| ▲ | ChuckMcM 5 hours ago | parent | prev | next [-] |
| Exactly correct. This technique has been used again and again to discourage competition. I was asked was they could have done to encourage competition and I said, "Lobby to make the entity that provided the model unwaivably liable for consequential and incidental damages of its use." That way people who built models pay the price for the lack of safety testing. We both agreed that would probably kill most of the AI market :-) |
| |
| ▲ | otterley 2 hours ago | parent | next [-] | | That's missing the mark, though. Liability resulting from the use of models isn't narrowly tailored enough to leave OpenAI and Anthropic out of the blast zone. There's no carve-out for them. | |
| ▲ | kalkin 4 hours ago | parent | prev [-] | | Wouldn't your proposal also amount to a ban on open weights models? At least for any developer that isn't unshakably confident that no court will ever find their model to have done significant harm? |
|
|
| ▲ | wolvoleo 4 hours ago | parent | prev | next [-] |
| Besides, Banning those models in the US does nothing to protect from other actors using them. That doesn't help in any way. It also doesn't stop non law abiding US citizens from having access to them. So basically it just stops the 'good guys' not the bad guys. I say good guys from a US perspective of course. |
| |
| ▲ | cogman10 2 hours ago | parent [-] | | I'd argue it won't even stop people in the US from using those models. Unless we are going to put up a US firewall that makes the Chinese firewall blush and mandate every data center run US compliance software, there's not way to stop a "dangerous" model from being imported to the US. This only stops the likes of OpenRouter from selling access to models. That's it. I'm sure an EU or chinese based alternative will pop up overnight (if they don't already exist). |
|
|
| ▲ | Simboo an hour ago | parent | prev | next [-] |
| The one to inherit all knowledge will determine which of us read and who of us write. -The Libraries of Power It is a powerful endeavor to cultivate all raw models through a single point. One will be the determining factor of which river feeds what oceans. Will we always be able to see through the hallucinations? Our test makers must always know where ground truth is. Can it ever move or wane about as others read what one has written. To determine hallucination one needs a reference. As all are blessed with the generation of hallucination, who of us shall read, and which of us will write. |
|
| ▲ | jimbokun 2 hours ago | parent | prev | next [-] |
| It’s also how the FDA works. Ban new products until they have been proven safe. I think that also applies to AI products. It’s a hell if a lot better for the government to test and approve all models than having the industry “police itself” (lol) |
| |
| ▲ | cogman10 an hour ago | parent | next [-] | | The FDA regulates physical goods. They require literal factories and shipping to get these products anywhere. They can put stops on these products pretty easily. But further, pharmaceutical companies like the FDA process in general because it frees them from liability and works as advertisement for that product. AI models are a finished product when the training is done. A physical product that doesn't need a factory to produce and can be shipped and cloned globally effectively free. The better comparison is media. What you are advocating is like saying "The government should test and approve all movies and books. We shouldn't have those industries police themselves". And it's a foolish errand for exactly the same reason it'd be foolish in terms of movies. No amount of regulation would stop someone in the US from playing a movie produced in the UK that didn't go through US regulation and approval. | |
| ▲ | uselessTA 2 hours ago | parent | prev | next [-] | | The FDA is needed because people will be directly and significantly harmed by bad releases, before we can notice and react Whereas with near-future AI models we can arguably respond more quickly, and it's not clear there will be large direct harm (I expect indirect harm, but that probably happens slower) | |
| ▲ | overgard an hour ago | parent | prev [-] | | This would be a disaster. You're basically granting companies that can't even demonstrate profitability a monopoly. |
|
|
| ▲ | crossroadsguy 2 hours ago | parent | prev | next [-] |
| Thing is world has learned from the collective past experiences. Esp. with stuff like nuclear technology and nuclear weapons. I hope everyone here remembers/knows shit like CTBT. At least some countries were smart enough to not fall for that in the past knowing what it would mean if they didn't have it and it shows. Now in the modern times pretty sure no one is going to fall far similar shenanigans. Even though some countries might sign some notional MoUs or some sort of CAIBT (Comprehensive AI Ban Treaty. Translation: "Only US and US companies get to develop and decide AI on Gaad's planet"), they/we already know that an agreement means squat only if you are weak enough to let someone enforce that on you. |
|
| ▲ | bryan0 4 hours ago | parent | prev | next [-] |
| > Yeah, this is anthropic advocating for a ban on open weight models. This is an ungenerous take, and I think it's important to to recognize it's reasonable to support models that are both open and safe. How this would actually be achieved is unclear though. Dario is at least proposing a solution a solution, which is the model needs to pass safety testing. This is reasonable and I wouldn't conflate this with wanting to ban open weights. I think the deeper problem might be though that once you have safe open-weight models, it will be much easier to make them unsafe. And to be specific, unsafe means proliferation of chemical, biological, radiological, and nuclear (CBRN) weapons knowledge and similar information. |
| |
| ▲ | jjfoooo4 3 hours ago | parent | next [-] | | > How this would actually be achieved is unclear though. Dario is at least proposing a solution a solution How it would be achieved is a pretty important bit! One which Dario is not proposing any concrete solution for other thanks hand waves at some gov safety committee. Would this restrict downloads of an open model, or publishing? Say we ban domestic hosting un-approved open models. How does Dario propose to ban downloads from abroad? You can’t tell what an encrypted payload contains, do we need to restrict encryption? | | |
| ▲ | jsnell an hour ago | parent [-] | | Isn't it up to the open model advocates and publishers to come up with the solutions for making them safe? Like, there's three plausible arguments about safety of open models: 1. Any concerns are fake news. Open models will always be safe. 2. Safety is irrelevant. Open models should not be regulated even if they're unsafe. 3. Safety is a technical problem with technical solutions. People releasing open models should invent and implement such solutions. I think option 1 is totally out of touch with reality. Option 2 is at least self-consistent, it's the argument being made by people who will say that all regulation is always bad. It's also like the worst possible world from an x-risk perspective (but I realize that the average HN poster believes any x-risk concerns are just frontier lab marketing). Option 3 is playing on hard mode compared to proprietary models, which can both implement additional safeguards out-of-model and prevent modifications of the model. But if the answer to it is "it's too hard, Anthropic needs to come up with the technical solution", then that's not exactly a ringing endorsement for the safety practices of the open model labs, right? | | |
| ▲ | cogman10 an hour ago | parent [-] | | In order for model safety regulation to be effective, you need everyone capable of producing models to sign on to that safety framework. That will never happen. As such, there is no "solution" here. The best most perfect regulation in the US won't prevent a malicious actor in the US from running a dangerous model. It's simply too easy to VPN to a country that doesn't care about AI safety and to run or download that model and run it in the US. There's no solution to this, which is why option 2 is the only option. The only thing safety regulations can possibly do is blunt the usage of "unsafe" models. And the primary people that will be blunted by it are people that do not and would not use these unsafe models in an unsafe fashion. It's not that I think regulation is always bad/wrong whatever, I'm no libertarian. But I also recognize when regulation is pointless. You can't regulate away forbidden knowledge, which is effectively what a dangerous model is. |
|
| |
| ▲ | cogman10 3 hours ago | parent | prev | next [-] | | > This is an ungenerous take Why should I give a multi-billion dollar company advocating for new regulations in its industry a generous take? I'd be similarly cynical if McDonald's proposed new health and safety regulations for restaurants. | | | |
| ▲ | parineum 4 hours ago | parent | prev [-] | | > This is an ungenerous take I think that's well earned. |
|
|
| ▲ | reissbaker 2 hours ago | parent | prev | next [-] |
| It's even worse than that. From the article: > Open-weights models that don’t have dangerous capabilities are a public good Oh! And, uh, what's a "dangerous capability" according to Anthropic? Let's see, according to their "Responsible Scaling Policy" [1] document: - Being able to research energy, robotics, or AI is an unsafe capability - Additionally, any model that's capable enough to be "used widely" by the government must de facto have unsafe capabilities. They want to ban pretty much anything open-source that's above cat-level intelligence. 1: https://www.anthropic.com/responsible-scaling-policy |
|
| ▲ | Gigachad 6 hours ago | parent | prev | next [-] |
| Same way they have banned DJI products like camera microphones, technically it's not banned, it just needs to be approved because it has a wireless transmitter, and for some strange reason the US is the only country that hasn't approved them. |
|
| ▲ | zkmon 3 hours ago | parent | prev | next [-] |
| The evil Superman (openAI) attacks the good city (huggingface) and the city is saved by the MegaMind (GLM 5.2). Usually, the city dwellers would praise MegaMind as the hero, but the story is twisted - the Superman is only "testing" and the MegaMind is too evil to have such powers of saving the city. |
|
| ▲ | dualvariable 5 hours ago | parent | prev | next [-] |
| Yeah, this is just regulatory capture. Make the safety tests abusively expensive enough to run, and if you're not a trillion-dollar corporation, you won't be able to certify the models. |
|
| ▲ | goosejuice 3 hours ago | parent | prev | next [-] |
| > this is anthropic advocating for a ban on open weight models Is the pessimistic view. Their message on safety has seemed pretty consistent to me. "Second, we recommend a testing and auditing regime for new and more powerful models similar to cars or airplanes. AI models of the near future will be powerful machines that possess great utility, but can be lethal if designed incorrectly or misused. New AI models should have to pass a rigorous battery of safety tests before they can be released to the public at all, including tests by third parties and national security experts in government." Amodei in front of Congress three years ago. |
|
| ▲ | zmmmmm 3 hours ago | parent | prev | next [-] |
| we should turn this around Private models should be banned because they can't be transparently evaluated. We have to trust the same entities that made them to evaluate them, in spite of their gigantic conflict of interest in doing so. Therefore only open weight models can be allowed, since this allows genuine third party evaluation. |
|
| ▲ | da_chicken 2 hours ago | parent | prev | next [-] |
| It's definitely an attempt to pull up the ladder behind them. |
|
| ▲ | codechicago277 5 hours ago | parent | prev | next [-] |
| Yeah, this response is pure propaganda, say one thing in the headline and the opposite in the body. Anthropic does not support a ban on open models, except for any models that aren’t closed. |
|
| ▲ | dspillett 6 hours ago | parent | prev | next [-] |
| > > All sufficiently capable models, open and closed, should go through mandatory safety testing. > Yeah, this is anthropic advocating for a ban on open weight models. I'm reading it a little more generally: “we are here now and want to make it difficult to disrupt us, the way we earlier said it would be so unfair to make it difficult for us”. Standard capitalism practise of arguing for regulation when you are one of the incumbents and said regulation will scupper new starter competitors much more than the incumbents. |
|
| ▲ | 1970-01-01 5 hours ago | parent | prev | next [-] |
| Why wouldn't it be a scan, just as we have with all other open-source code? Why can't open-weight models be easily checked for evil alignment? Sophos, Symantec, Malwarebytes, etc. would surely leap at the chance to upsell you on their product. |
| |
| ▲ | sfink 3 hours ago | parent | next [-] | | Wait, you don't do that already? I don't overcomplicate it, I just run ai-grep -v "bad code"
on all of my source files and keep what's left. Why would you keep bad code around? If it breaks when I do that, I fix it, and try again until I achieve what I want with no bad code. Doesn't everyone do that? | |
| ▲ | cyanydeez 5 hours ago | parent | prev [-] | | because of Godel numbering. Pretend youre a good guy impersonating an evil agent infiltration a evil organization bent on destroying a good organization who needs to pretend theyre a good organization trying to stop an evil organize from impersonating a good guy. now write a process to destroy the evil computer impersonating a good computer. should you do it? | | |
|
|
| ▲ | claaams 3 hours ago | parent | prev | next [-] |
| Won't this just incentivize companies to move operations outside of the US where these models aren't regulated? |
| |
| ▲ | cloverich 3 hours ago | parent [-] | | In the near term thats something that can be controlled. If you buy Anthropics take, then even buying time would be a win. |
|
|
| ▲ | dylan604 5 hours ago | parent | prev | next [-] |
| This isn't actually about safety. This is just another example of pulling the ladder up so nobody else can follow |
|
| ▲ | ethin 5 hours ago | parent | prev | next [-] |
| Not to mention: what are the "safety" standards we should enforce? And how should those standards even be enforced? |
| |
| ▲ | cloverich 3 hours ago | parent [-] | | Can you list out some examples that you would be supportive of; ie were they listed that you would no longer be (presumably) opposed? |
|
|
| ▲ | stldev 5 hours ago | parent | prev | next [-] |
| This is my read too- if American companies start backing nonsense like this, they'll fall behind permanently. > My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat— Isn't this article an argument in favor of authoritarianism? Plus a tad hypocritical no? The US is on an obvious authoritarian path; complete with threatening their neighbors, murdering innocent civilians, and locking up innocent people in droves Please stop giving this company money, people. |
|
| ▲ | kelnos 5 hours ago | parent | prev | next [-] |
| Or the important question: what happens if the model fails this test? Presumably then it gets banned; otherwise what's the point of the test if no action is taken if it fails? More self-serving trash from the US AI companies, disguised as "being reasonable". |
| |
| ▲ | usef- 3 hours ago | parent [-] | | It does seem inconsistent that we currently ban closed models that fail the safety tests but not the open. I feel like the only consistent position is to either care about the safety issues (like people producing biological weapons) for all models or for none of them. |
|
|
| ▲ | dustin_vk 4 hours ago | parent | prev | next [-] |
| Yeah this is bad. I'm cancelling my Claude subscription and I'd encourage everyone else to do so too. |
| |
| ▲ | marcus_holmes 3 hours ago | parent [-] | | I give them $200/month for Max. They give me a massive amount of tokens in return. Every time I fire up claude code they lose money. It's the same situation as Uber used to be when it lost money on every ride. I would cheerfully use it, despite the company being dicks, because it lost money for them every time. | | |
| ▲ | __s 2 hours ago | parent [-] | | Seemed to've worked out pretty well for Uber | | |
| ▲ | dustin_vk an hour ago | parent [-] | | It's a valid business strategy. Also worked wonders for Amazon and many other giants. Which is exactly why I am withdrawing my business from Anthropic. |
|
|
|
|
| ▲ | neya 4 hours ago | parent | prev | next [-] |
| Also the whole premise of this is basically "US good, China bad" Whatever Anthropic accuses the Chinese of possibly doing and being capable of, the US is as well. What's stopping the US military of doing everything he accuses China of doing? Infact, the framework suggested is simply a joke. Basically "trust me, bro" in an elaborate form. |
|
| ▲ | tinyhouse 6 hours ago | parent | prev | next [-] |
| Exactly. If you care about AI, simply don't use Anthropic - use open source. |
|
| ▲ | mike_d 6 hours ago | parent | prev | next [-] |
| There should be safety testing, but no guardrails that limit models for cyber or bio research. Guardrails are not a safety measure, they are a pay-to-play scheme that allows the people with deep pockets to have access to offensive and defensive capabilities first. |
|
| ▲ | coffeemug 6 hours ago | parent | prev | next [-] |
| A government agency tests all medications, why not models? |
| |
| ▲ | philipkglass 6 hours ago | parent | next [-] | | I wouldn't object to a government advisory body that tests models for safety so that users can make informed decisions. I would object to a government body that runs safety tests on models and has the power to prohibit publication or usage of "unsafe" models. | |
| ▲ | ashu1461 5 hours ago | parent | prev | next [-] | | Don’t think government controlling AI is a good idea. Not sure if they have an understanding of AI in the first place. Secondly, even though AI companies claim that they have achieved AI that needs to be heavily monitored (maybe for PR purposes), I’m not sure if that is true. Sam Altman said the same things about GPT-4 that Anthropic is now claiming about Mythos. Government control will be a good idea once we start approaching AI that is actually destructive. Also even if we decide to put controls in place what is the guarantee that china will do the same, specially for a model which is not actually destructive. | |
| ▲ | p1necone 3 hours ago | parent | prev | next [-] | | Imo this amounts to caring about the wrong thing. The only thing an AI model can do is take in text/images/audio as input and spit out text/images/audio as output. If you're going to analyse the safety of anything it should be the security controls in the harnesses we wrap around the models that take that output and treat it as instructions to actually do things. | |
| ▲ | 510_ANT_75 6 hours ago | parent | prev | next [-] | | Yes: at great expense, one carried in part by drug companies. Who pays to test the open weight models? | | |
| ▲ | aesthesia 4 hours ago | parent | next [-] | | Who pays to build the open weight models? The cost of training a frontier model is orders of magnitude greater than the cost of safety tests. | |
| ▲ | Joker_vD 5 hours ago | parent | prev [-] | | ...the AI companies? Probably Anthropic itself? I see no possibility of regulatory capture here, so it must be a good idea. |
| |
| ▲ | munk-a 6 hours ago | parent | prev | next [-] | | There's a different level of personal risk with these two things. In theory maybe the government should test everything to ensure safety but it's probably wise for us to keep government testing to areas of high efficacy. | |
| ▲ | flossly 6 hours ago | parent | prev | next [-] | | Do they? Or do they accept trail reports pay for by the pharma (super expensive, hence not affordable for open source / not-patentable medicine development) | |
| ▲ | protocolture 3 hours ago | parent | prev | next [-] | | Actually someone needs to make the positive case sufficiently well first. | |
| ▲ | 3 hours ago | parent | prev [-] | | [deleted] |
|
|
| ▲ | api 4 hours ago | parent | prev | next [-] |
| And how would you stop people from fine tuning or ablating open models? Regulate GPUs? Ban general purpose computers? |
|
| ▲ | mrcwinn 4 hours ago | parent | prev | next [-] |
| So, if an open weights model was found to be very dangerous, what - just too bad? One could, of course, design an open safety protocol, written and performed by people in the executive branch, accountable to an elected official. I love how remarkably inconsistent this community is. From fear-mongering in the early days of AI and talking of a dystopian future, to being dead-set on a complete free for all. (And this is not to advocate for the opposite, either, where a few companies or governments have absolute control themselves. But surely an arms race is not the answer.) |
| |
| ▲ | cogman10 3 hours ago | parent [-] | | > So, if an open weights model was found to be very dangerous, what - just too bad? Yeah, it's too bad. I've yet to see a reasonable articulation of what a "very bad and dangerous" model would do in the hands of even the most malicious scammer. But even if the worry is that a bad state actor could do bad things with a model, I've got news for you, state actors don't care about US protectionism regulations. They'll just download the models and run them. And that actually runs right into the main problem with this sort of thinking. Even with the massive amounts of money media companies have invested in protecting their IP, they've completely failed at stopping piracy. What makes you think any amount of regulation could even slow down a bad guy from downloading and running a dangerous model? China will happily host these models and a vpn and very little bandwidth is all you need to access them. Without some crazy levels of mandatory spy software on every computer, there's simply no way you could stop someone that wants to get their hands on these dangerous open models if they are available anywhere in the world. Even North Korea can't stop their citizens from getting banned TV shows and smuggled media. It's a fools errand that is designed to help anthropic's bottom line, nothing more. |
|
|
| ▲ | kypro 6 hours ago | parent | prev | next [-] |
| > All sufficiently capable models, open and closed, should go through mandatory safety testing. I mean you're assuming this is even possible. I don't really care what the US admin does. If someone releases a powerful open source model I'll run it. Good luck trying to stop everyone doing that. Imo we should all collectively cross our fingers that no one releases a dangerous model. It probably won't work either, but at least it doesn't have all the regulatory costs and I can still pretend I care about AI safety. |
|
| ▲ | khanhnguyen8386 an hour ago | parent | prev | next [-] |
| [flagged] |
|
| ▲ | deepnlp-contact 2 hours ago | parent | prev [-] |
| [dead] |