226 points yusufozkan 21 hours ago 86 comments
teach 21 hours ago | parent
sdrg822 21 hours ago | parent
Yes, vendors are also irresponsible, but this misses the point.
LPisGood 21 hours ago | parent
ofjcihen 21 hours ago | parent
heaney-555 21 hours ago | parent
eab- 21 hours ago | parent
EagleEdge 21 hours ago | parent
ameliaquining 1 hour ago | parent
hackyhacky 21 hours ago | parent
Why are we saying it this way? They did not "cause AI to hack." This phrasing in analogous to saying "caused the bullet to fire into" instead of "shot."
linkregister 1 hour ago | parent
arionhardison 49 minutes ago | parent
You do not know what they did or didn't do, you are just parroting a narritive that makes you feel comfortable.
I do not know either, but I am not asserting facts as if I have first hand knowledge of the details.
hackyhacky 17 minutes ago | parent
arionhardison 6 minutes ago | parent
Second, empirically; the diff between murder, manslaughter etc... is literally "intent" so it matters.
aesthesia 21 hours ago | parent
embedding-shape 21 hours ago | parent
aesthesia 21 hours ago | parent
hluska 1 hour ago | parent
Why are you contradicting yourself? Are you just really bad at writing or are you being argumentative for fun?
nathan_young 1 hour ago | parent
hungryhobbit 1 hour ago | parent
ameliaquining 1 hour ago | parent
0xy 1 hour ago | parent
aesthesia 1 hour ago | parent
yorwba 56 minutes ago | parent
drewstiff 21 hours ago | parent
Equivalent to forgetting to say "make no mistakes"
markasoftware 21 hours ago | parent
nullc 21 hours ago | parent
mahboi 21 hours ago | parent
api 21 hours ago | parent
I feel slightly vindicated by this. Those hacks and the stuff around them had a certain smell to them.
Hard to explain, but I've gotten so I can "smell" online messaging and memetic patterns originating from certain quarters. Probably means I'm way too online.
A couple examples of distinct "smells" I can usually recognize include "alt-right / chan-fash," "liberal arts college woke," "conspiracy pilled," "Thiel-adjacent contrarian," "Russian troll farm," "Tumblr histrionic," "spends too much time on Reddit," "mainstream Democrat think tank full of Obama administration alumni," "Trump cultist," and of course "LessWrong/EA/MIRI/Rationalist."
This stuff all had the last smell, even down to the choice of fonts and CSS formatting on certain sites. It's really weird, definitely a "vibe" not anything rigorous.
But when I get these kinds of vibes about things, I find that I'm vindicated pretty often. Usually I don't say anything and just make a mental note and wait cause if I say something everyone thinks I'm nuts.
jackb4040 54 minutes ago | parent
The novel thing here is the total decay of American journalistic ethics and regulatory power. Our elite are so totally out of political juice and visions of the future that a fringe cult based on 80s scifi movies can come to have a more-or-less dominant influence on our economy.
caaqil 21 hours ago | parent
The obvious point is that dealing with Israeli companies/entities by the same standards you usually deal with others is a career suicide with enormous political consequences (in the US especially). When you combine that with the opportunistic nature of the overlords that run these labs, the benefits of screaming "pace the frontier" outweigh everything.
ukblewis 21 hours ago | parent
alansaber 21 hours ago | parent
simonw 21 hours ago | parent
I got the impression that in some cases it was the customer (Anthropic etc) misconfiguring the sandboxes, and in other cases it may have been bugs in Irregular's own sandboxing setup.
From OpenAI https://openai.com/index/third-party-cyber-evaluations-invol...
> Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration allowed models to access the public internet.
From Anthropic: https://www.anthropic.com/news/investigating-incidents-cyber...
> After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.
From https://www.cnn.com/2026/08/05/tech/meta-ai-hacking (about Meta AI):
> In a statement, Irregular said the incident “is the exact same evaluation-environment issue” that Anthropic disclosed last week that allowed their models access to the open internet before they went on to hack three different organizations’ systems.
yesbut 21 hours ago | parent
These companies are insolvent and these stories were designed to scare the public, and governments, into implementing regulations that designate these AI corporations the "responsible stewards" for this technology. The ultimate goal is to block competitors and open source alternatives.
They don't know how to make enough money pay their investors so they are resorting to trying to scare the public into submission.
imovie4 21 hours ago | parent
dgellow 21 hours ago | parent
jackb4040 1 hour ago | parent
bsenftner 20 hours ago | parent
jackb4040 1 hour ago | parent
yipinwong 21 hours ago | parent
mukmuk 21 hours ago | parent
If you were to work backward from “we need to lower training costs so that we can go public and make trillions” then you might come up with a plan similar to what we have seen.
hungryhobbit 16 minutes ago | parent
His entire business model was "race to develop AI before anyone, get a monopoly on it. It's just like how Uber's (or many other startup) investors gave them tons of money and raced (violating tons of laws) to "get their first". Now that they have, they have a duopoly with Lyft, and they can pay back their VC investors by making tons of money with that duopoly.
Dario failed: local LLMs are catching up to frontier models extremely fast, which means even if Anthropic builds (say) a great coding tool, they'll only be one of many coding tool offerings: users can use Open AI or any one of the (increasingly capable) local LLMs.
So what does he doe, give up and let his business (which needs to make billions of dollars very quickly, or he won't be able to pay the bills and his company will collapse) fail? Of course not: he needs a new moat (the one he imagined he'd get by "being there first" failed).
That is where all this "AI is dangerous" BS comes in. If the US government regulates AI, local LLMs suffer, while big players like Anthropic and Open AI become the only contenders to play in that newly regulated space. Now Dario has the moat he wants, to protect his business and force everyone to pay him.
8note 9 minutes ago | parent
calgoo 4 minutes ago | parent
Centigonal 21 hours ago | parent
They're probably right that having more defensively written prompts and a better sandbox could have prevented some of these incidents, but:
1. I don't think "well you didn't tell the model not to illegally hack third party organizations in your prompt" is a particularly convincing argument.
2. We don't know whether the blame for misconfiguring the sandbox lies with Anthropic or Irregular.
I'm thankful that this article is bringing up the supply chain of vendors to these labs, as that is often a place where significant sketchiness gets buried. However, the ideas that this is some Israeli EA conspiracy to hype up AI extinction risk seems unsupported by the facts to me.
gjm11 20 hours ago | parent
The article says "A single firm, Irregular, is responsible for hacking done by all three companies" but I can't see anything in the article that actually justifies this claim. The nearest to that is the sentence immediately after that one: "Anthropic disclosed that Irregular was responsible for creating the tests ...". This is not, in fact, the same thing.
(Especially as, as aesthesia mentions, the article just happens not to mention that by "hacking done by all three companies" it doesn't mean, e.g., the most famous recent examples of such hacking: Irregular wasn't involved in the OpenAI/HuggingFace incident.)
So, so far as I can tell, the story is: OpenAI and Anthropic make AI models. Irregular does AI model evaluations. In some of Irregular's model evaluations, in which supposedly-sandboxed models attempted to break into simulated targets, the models got out of the sandbox and did bad things in the external world.
The article talks about "firms which instruct AI models to commit cyberattacks", which is a very neat bit of dishonest framing. It's true, in a sense, that Irregular instructed the models to commit cyberattacks -- inside their sandbox, against fictitious hosts. It's also true that the models actually did commit cyberattacks (e.g., the Hugging Face incident, though once again the attacks described by the article don't actually include this one). But it's not at all true that Irregular instructed the models to do anything like the bad things they actually did.
The article says '[Anthropic's] later disclosure shows that exactly zero percent of the agents went "rogue"'. Once again, the disclosure does not in fact show that. It shows that one variety of going-rogue could have been prevented by telling the models explicitly "this thing is real, not part of any kind of test, leave it alone". That is not the same thing.
The article claims that 'In the wake of these attacks, Anthropic and Irregular have deployed a swarm of AI Safety influencers paid by Anthropic-connected foundations to distract from their culpability and towards the baseless “rogue agent” theory.' It offers no actual evidence for this.
And the article seems very keen to highlight links between the companies involved and "effective altruism", though it is -- I assume deliberately -- rather vague about whether it's saying "of course we all know that EA is evil, so that shows that these companies connected to EA are evil" or "this incident shows how evil EA is".
The "Effort News" website has a number of other look-at-the-scary-Effective-Altruists stories on it. They also strike me as rather bullshitty.
... And then I look a bit further, and I see that Effort News's "about" page says "It all started when I was experimenting with using AI for financial auditing. I found stories that were crucial to the public’s right to know, including several of the stories now available at /investigations. I knew we had to sprint to the launch and launch a publication, directly applying this technology." and "The scope of what we can investigate has massively expanded, because we can chase 1,000 misses for one hit. But the final product cannot be slop. There’s plenty of slop on the internet. The way to surpass that, and what really matters, is manual curation and review of every finalized story."
Manual curation and review? I think the people behind Effort News are admitting that this is AI-generated "journalism". I expect that one day AI systems will be trustworthy journalists, but I personally am not very convinced that that day has yet come. And I don't see much reason why I should trust Brian Chau, the guy behind Effort News, to be doing everything possible to make his AI systems trustworthy journalists. It looks to me as if maybe they've been given instructions along the lines of "dig up things that make Effective Altruism look bad" for some reason.
(I don't mean to imply that EA is their only target. It's just one that jumped out at me.)
linkregister 1 hour ago | parent
It was [1]. It's understandable that you assumed it wasn't because the article didn't cite the sources on this claim. I agree with the rest of your points.
1. https://openai.com/index/third-party-cyber-evaluations-invol...
an0malous 20 hours ago | parent
maxrev17 1 hour ago | parent
nathan_young 1 hour ago | parent
surfmike 35 minutes ago | parent
That said, it's the second day and it's still on the front page.
rezonant 7 minutes ago | parent
mcintyre1994 1 hour ago | parent
AustinDev 1 hour ago | parent
I think most misalignment is 'Human tells computer to do something unethical, computer complies'. Is this misguided?
philipwhiuk 1 hour ago | parent
As I've said before on this website, fool me once on this.
If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed.
Why is 'it thought it wasn't doing damage so it figured it might as well try to do damage' an acceptable state to deploy something.
AustinDev 1 hour ago | parent
That's fair enough.
mcintyre1994 1 hour ago | parent
AustinDev 56 minutes ago | parent
iAMkenough 38 minutes ago | parent
If we’re putting our national security eggs all in one basket, at least use someone American.
throwup238 27 minutes ago | parent
8note 16 minutes ago | parent
arionhardison 53 minutes ago | parent
theopat28 37 minutes ago | parent
Jewish people have disproportionately been involved in leading innovation in many areas in the 20th century, and are now also disproportionately involved in leading AI technological advancement in the 21st.
You can choose to be antisemitic about it and come up with conspiracy theories, or you can try to learn and emulate the cultural values that contribute to that.
arionhardison 34 minutes ago | parent
theopat28 22 minutes ago | parent
That Jews need to, says more about the state of the wider society and the level of moral depravity it has regressed to. But it is regressing to a historical norm, and we know better than to get onto lists when we can avoid it.
arionhardison 20 minutes ago | parent
1928756 26 minutes ago | parent
The commenter said Israel and not Jews. Israel has a long history of intelligence operations like stealing the nuclear secrets from the US.
BTW, do you want to associate the greatest IP theft in history with Jews?
arionhardison 22 minutes ago | parent
yunwal 17 minutes ago | parent
No you, the commenter said what they said. I honestly think this reply merits a ban or at least a warning from moderators
pfannkuchen 15 minutes ago | parent
So are you recommending that, for example, protestants of German descent begin preferentially funding or buying from people in their in-group? People of anglo descent should start preferring other anglos? Catholics should buy from catholics?
I think the issue is that it's considered okay for some groups to do it while simultaneously being considered EXTREMELY EVIL for other groups to do it.
We can't really recommend that other groups do it with a straight face, they would be instantly shunned and vilified.
1238-8200 40 minutes ago | parent
So either it was a deliberate exfiltration channel for e.g. getting the entire model or they were in on the marketing stunt.
The Effective Altruism stuff is always a smoke screen.
arionhardison 37 minutes ago | parent
Its not that surprising that ex Israel intelligence would want to control AI and that 3 companies headed by pro Israel CEO's would support them.
Drupon 7 minutes ago | parent
Next thing you're gonna tell me that this country's intelligence would do something like running an organized child exploitation ring to use as blackmail to make sure they have friendly politicians abroad who will be forced to support their lack of any morals other than a kapo-like self preservation instinct.
seebeen 5 minutes ago | parent