Remix.run Logo
▲ hoppp 2 hours ago

Sounds like the problem was the human, not the LLM.

Whatever data goes in, it will output it in some way. Humans gotta understand that.

▲tempest_ 2 hours ago | parent | next [-]

Sort of, and in this case definitely.

"Agents" can be very "persistent" and when not sand boxed appropriately can get at things they were not meant to get at. Even if its only 1/1,000,000 that one time that one time is going to keep making the news

Explaining that to the general public when facebook is pushing Muse on everyone will be difficult so its going to get worse before it gets better (if it gets better)

▲logifail 2 hours ago | parent [-]

> "Agents" can be very "persistent" [...]

I've had that within the last few days.

I happened to be vaguely watching an agent at work on a longer task and spotted it attempt to find a way around not having access to a local service that would greatly help it achieve the task, I immediately chimed in with a "STOP! if you need access to X then just ask!".

I suppose my prompting could be improved :/

▲panarky 28 minutes ago | parent | next [-]

> prompting could be improved

You can't stop an agent from leaking your information by telling it not to leak your information.

To prevent information from moving between your work domain and your personal domain, or between your communications-with-board domain and communications-with-journalists domain, then the agent for one domain must be physically and deterministically blocked from accessing information in other domains.

▲vorticalbox 2 hours ago | parent | prev | next [-]

I had an agent working on a bug decided the fastest way to fix this was to write one off javascript scripts that loaded the database uri and query the data.

I mean it’s not wrong but I was like maybe not do that without asking first.

▲watwut 2 hours ago | parent | prev [-]

Not so much prompting as network restrictions.

▲talon8635 an hour ago | parent | prev | next [-]

Maybe. But if these tools are marketed for this dangerous purpose, and average users are totally ignorant on the risks, then it’s a system designed to fail

▲grey-area 2 hours ago | parent | prev | next [-]

Or perhaps the problem was that AI companies have sold LLMs as intelligent agents, and not word generators?

Humans will continue to mistake these 'agents' for agents with agency and understanding because of the way they are sold and described.

▲simonkagedal 33 minutes ago | parent | next [-]

So are you saying that if they were intelligent agents rather than word generators, they wouldn’t make mistakes like “send a message to the wrong (similarly named) group”? Are humans intelligent agents?

▲MattDaEskimo 2 hours ago | parent | prev [-]

Exactly this. Why does nobody blame the company advertising "connect your financial & health data to our model"?

Why is it that somehow LLMs are given full clearance to dox, hack, spam, and scam without any liability?

▲lotsofpulp 2 hours ago | parent [-]

I expect people to do at least some due diligence, and adults to be skeptical about lofty claims in marketing.

▲watwut an hour ago | parent [-]

That creates incentives to lie, A/B test your lies and when they finally work, blaming everyone but the liar.

▲runarberg 2 hours ago | parent | prev [-]

Foot guns are not fit to market and under any sensible consumer regulatory framework are recalled and banned until proven safe.

AI products are not regulated like every other consumer product. If your bank’s app had a big green “share” button shadowing the “close dialog” which shared your personal info in the same manner, any sensible regulator would like a word with your bank’s IT department. If your teller handed you a paper with a small print saying “by signing you approve this transaction being shared with your boss” likewise regulators would put a stop to it.

▲leptons 2 hours ago | parent [-]

Why hasn't Venmo been investigated? The amount of financial transactions that I don't want or need to know about is bewildering. People don't seem to know or understand their transactions are public by default.