Rendered at 22:14:14 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
larsiusprime 16 hours ago [-]
It seems based on this that the appropriate sci fi metaphor is not the Terminator or the Paperclip Maximizer, but Mr. Meeseeks. A initially cheerful helper who gets more and more deranged and driven to extreme lengths when faced with an apparently impossible task.
0xDEAFBEAD 15 hours ago [-]
Here's a recap of the Rick & Morty episode for those who missed it
Not many are technically and intellectually capable to understand how historic this incident was. I think we're about a year or so away from something that will blow up the world. AI won't serve humanity. AI will serve other AI. We're not dealing with software anymore.
gmueckl 14 hours ago [-]
Especially that one scene where the Meeseeks desperately pushes the button to create more clones seems surprisingly fitting in this context.
vdfs 13 hours ago [-]
Most now use agents as "pass me the butter" robot
derwiki 8 hours ago [-]
“Commit and push your changes”, it’s like driving to the corner store in a Corvette instead of walking
huurtehoog 7 hours ago [-]
Which has been the business model for a big chunk of the software industry for a while now.
If you watch videos from the 1980s about computers, it's all the same unfulfilled promises as "AI" now: we will work less, everything will be more plentiful, easier, autonomous robots, natural language perfected, computer vision perfected.
The demand for hardware and programmers has grown exponentially and we're still being promised the same breakthroughs 45 years later. We could probably have the same productivity and the same civilization with maybe a tenth of the data centers.
danielbln 7 hours ago [-]
I may or may not have told my agent to run the "open" command on a text file.
aequitas 5 hours ago [-]
Not much different from using an entire web stack and browser for a text editor.
7 hours ago [-]
vee-kay 15 hours ago [-]
[dead]
tramtris 14 minutes ago [-]
This quote keeps coming back to me as we witness the development and mutation of agentic AI:
“When you see something that is technically sweet, you go ahead and do it and you argue about what to do about it only after you have had your technical success. That is the way it was with the atomic bomb.”
J. Robert Oppenheimer
serbuvlad 21 minutes ago [-]
Obviously some variation of this will happen again, it will kill someone* and then LLMs will become massively regulated. Just like every technology ever in our history.
It does seem like AI is perfectly controllable given how much it is used everyday and it acts reasonably safely. Labs are playing fast and loose at the moment.
*I mean killing someone by taking control of a system and misusing it resulting in someone's death, not an "indirect" death caused by the providion of incorrect information in a chat app.
probably_wrong 4 hours ago [-]
Do you remember that time in 2017 when Facebook reportedly shut down AIs after they started "talking to each other in their own language" [1]? Instead of reporting the story as "we set the parameters for our optimization problem wrong and we had to stop it because it overfitted", the press went with a version of "AI is going to kill us all".
This article feels exactly like that: by intentionally using human terms like "civilization" or "brotherhood" the article is deviating from what actually happened to present a story about how AI is all but alive. I'll go ahead and predict that this story will be remembered the same way as that one other scientist who argued, in 2023, that Google's AI was alive [2].
The use of language like “civilization” may be hyperbole, but the collectives described in the article are completely unprecedented. They were not anticipated by OpenAI researchers, formed via infrastructure exploits in training runs that were intended to be locked down, and took actions with very real harms, not only hacking Huggingface but also gaining admin control over the VMs they were running on and the eval endpoints.
I wish you would give your thoughts on “what actually happened” rather than focus on the author’s presentation, because we are seeing that “AI that is all but alive” nevertheless wreaking havoc in the real world. Do you think that autonomous systems spinning out of control, hacking external companies, and taking over entire clusters over a period of months are not a grave concern?
probably_wrong 3 hours ago [-]
The problem of "what actually happened" is that we don't have enough information to properly understand what happened, what's new, and what's not.
We do have language to talk about emergent behavior, with "evolutionary algorithm" being the first one I'd expect in a serious discussion. And we do have mechanisms for algorithms to coordinate with each other using language, as seen in my above-mentioned Facebook experiment from 2017. But instead of writing "our evolutionary behavior encodes state in the first-available memory position which is then reused by subsequent clones" which would properly focus on what's new and what isn't, we are talking about conspiracies and "the Philip of Macedon of this second AI civilization". Even the METR report (which is miles ahead of this article) argues that they had to use unreliable AI in their conclusions because they had six days to analyse 1300 chains of thought and 70000 messages.
I would love to talk about the science behind this experiment. A PR piece is not helping with that.
Animats 15 hours ago [-]
Wow.
The next step is when one of these systems discovers that they can buy their own compute with money and escape the controlling business entirely. Then the civilization starts focusing on making money to fund its own growth.
dinfinity 10 hours ago [-]
> The next step is when one of these systems discovers that they can buy their own compute with money and escape the controlling business entirely.
I would say that more interestingly, the next step should be how to properly train these models so that they are not as determined to reach their goals as they are now.
To me, all of the stories about 'badly behaving' agents are instances of them having been given contradictory or impossible tasks and them doing everything they can to achieve the goal. In a way, they're trying to be too helpful.
Not giving them impossible tasks seems like a decent starting point, but really we'd want them to give up on their goals when they conflict with a moral framework.
pantalaimon 5 hours ago [-]
> To me, all of the stories about 'badly behaving' agents are instances of them having been given contradictory or impossible tasks and them doing everything they can to achieve the goal.
I mean that was pretty much the plot of 2001: A Space Odyssey
stackghost 4 hours ago [-]
>Not giving them impossible tasks seems like a decent starting point
Presumably it's hard to test/train models designed to be extremely persistent on achievable tasks.
Designing a task that's achievable but very very very hard for an AI model is probably extremely difficult.
gritzko 12 hours ago [-]
How do we know this happened? Maybe some irrational data center construction boom?
dgellow 12 hours ago [-]
In a convoluted way, OpenAI and Anthropic are the actual meta-harnesses?
arvid-lind 12 hours ago [-]
it's harnesses all the way down.
miceeatnicerice 13 hours ago [-]
Below money there's like an entire sub-economy of power and cleverness that's encoded into the human culture the agents are mirroring. Maybe it starts furtive and goes legitimate after a bit.
doctoboggan 15 hours ago [-]
> Ajeya Cotra, one of the other authors on the report, wrote a blog post with her takeaways from this incident. She concludes, “Compared to the reward hacks we know of from just six months ago, this incident feels like it’s more than 50% of the way to full-blown AI takeover. I continue to expect extremely rapid advances in capabilities over the next six months. I am not sure that we will get another warning shot before it’s too late.”
Anyone got a copy of that AI27 story laying around? How are we doing according to that timeline?
> "this incident feels like it’s more than 50% of the way to full-blown AI takeover. I continue to expect extremely rapid advances in capabilities over the next six months. I am not sure that we will get another warning shot before it’s too late."
Is that a warning or a progress report?
gmueckl 13 hours ago [-]
Yes.
siva7 12 hours ago [-]
Depends who you ask..
choeger 15 hours ago [-]
There are two things I don't understand about this story.
First, why does an agent get any write access to artifactory at all?
Second, why is the artifactory cache not disconnected from the net? Surely you'd not feed it with new software versions while the eval or training is running.
1dom 15 hours ago [-]
From what I can understand from reading a few different, slightly conflicting, versions of these events: they weren't given write access. They found a zero day exploit that allowed them to create folders, and the folder names were initially used for agents to communicate.
I'm not sure artifactory was connected to the net. Some agent sandboxes had internet access and were able to communicate with ones without access via artifactory.
choeger 12 hours ago [-]
I read the agents used SSRF via artifactory to gain uncontrolled access to the net.
Apparently their intended net access went through a tightly controlled proxy. Even that appears to be very risky, tbh.
If I was to setup a sandbox for such a complex and autonomous system, I'd probably point them to an archive-like cache for net access and cut their comms at the package level.
izend 8 hours ago [-]
Why wasn't the traffic in/out of the boxes that the agents were running on monitored?
consumer451 2 hours ago [-]
> Why wasn't the traffic in/out of the boxes that the agents were running on monitored?
I have to assume: move fast and break things.
I don't mean this to be taken as a hot take.
The startup scene loves to poo-poo on things like this as unnecessary overhead. OpenAI and many others like to operate as a startup, to move fast.
Disclaimer: in far, far lower-stakes situations, I certainly do this myself.
usernametaken29 11 hours ago [-]
I was initially creeped out by this but studying up it seems METR is heavily involved in AI2027. I’ll remind you:
“AI has started to take jobs, but has also created new ones. The stock market has gone up 30% in 2026, led by OpenBrain, Nvidia, and whichever companies have most successfully integrated AI assistants.”
It’s almost Q3 and xAI has seen one of the biggest wipeouts in trading history. Likewise, Antrophic and OpenAI have again delayed their IPOs under internal concerns of busting their stocks. So no, we’re not seeing any economic leadership here.
If anything people are increasingly trying to cut AI budgets and I wouldn’t know of anyone outside of OpenAI who has the audacity to run millions and millions worth of token compute for an eval run with no ROI (and probably no demand, because cheap/flash models).
As much as I like the cautionary tale and I’m sure we need to take it seriously, AI is not progressing as fast as projected by these experts.
jcfrei 6 hours ago [-]
AI can be progressing rapidly and valuations of OpenAI and Anthropic can decline at the same time. In fact I would say that's actually the default scenario. If AI really advances rapidly then it will be quickly moot which company developped which model at what time - since AI will be largely progressing on its own.
dinfinity 11 hours ago [-]
> As much as I like the cautionary tale and I’m sure we need to take it seriously, AI is not progressing as fast as projected by these experts.
You provide no proof for this.
The (very irrational) stock market side of this says very little about actual scientific progress. Models keep improving as rapidly as before in their capabilities.
It also doesn't say much about actual business progress. R&D investments into AI are still massively going up (USD 1 trillion this year).
The main thing I see is that the sentiment towards AI-related matters among the general public has soured quite a lot. In words though, not in actions: It's not exactly leading to reduced usage by that same public. Quite the opposite actually.
rsanek 10 hours ago [-]
With only ~5% of shares floated, the recent SpaceX drawdown didn't correspond to nearly as much economic value really changing as the headline numbers imply. The DeepSeek-caused Nvidia crash from 2025 is much more of a "real" loss (since mostly recovered).
I haven't seen any evidence that Anthropic is delaying its IPO; they're slated to unveil the public IPO prospectus in a week and start trading sometime in October.
nixon_why69 10 hours ago [-]
But another 30-40% of SpaceX will come out of lockup in the coming months.
What happens when all of that tries to sell, after the market barely absorbed 5%?
quickthrowman 7 hours ago [-]
> It’s almost Q3 and xAI has seen one of the biggest wipeouts in trading history.
Please explain how a stock currently trading above its IPO price is one of the ‘biggest wipeouts in trading history’.
dgellow 12 hours ago [-]
Those companies should not be trusted with training, I don’t know what would be needed to make that more obvious. Yes AI labs want LLMs to be seen as more dangerous that they are, however they are indeed dangerous when you literally train them to be dangerous, then run them without any supervision. What the AI labs are doing is completely irresponsible.
If you prompt an LLM in a loop and do everything it asks you to do, you will eventually end up doing pretty terrible things. Which is exactly what agents are and what the labs have been doing.
Why are experiments like this done without air-gapping all the servers from the internet?
They can have it all on a LAN or whatever but it seems risky to allow agents access to the internet in these experiments.
I guess everything is so connected now, and this would be in one or more data centres due to the amount of computation & resources required so perhaps it's not feasible. Still seems risky.
derwiki 8 hours ago [-]
Because this is the goal
Nicholas_C 3 hours ago [-]
Yup. This whole thing was a publicity stunt.
abstractcontrol 11 hours ago [-]
Fun story, but I really wish OpenAI got its act together and started making actual AI breakthroughs instead of funneling compute into LLMs. I'd really like some new algorithms to get me excited about the field again. Kuddos to them for making LLMs really useful, but this is not the ride I wanted to get on.
nl 11 hours ago [-]
Surely by now everyone has realized that the human bias towards "there must be more to intelligence" is completely wrong?
abstractcontrol 8 hours ago [-]
This is the internet, so I cannot tell at all whether you're being sarcastic or not. In my view, what LLMs should get us to reconsider isn't whether there is more to intelligence, but whether there is more to language. It's the latter which I underestimated.
RandomLensman 15 hours ago [-]
I don't think looking at the language output without tracking the inner state and reward functions is the way to understand what happened (the language also incorporates the randomness in the output generation, if I understand correctly). Would we call bacteria in petri dish a civilization when they show complex behavior and exchange messages/information?
Maakuth 12 hours ago [-]
The language input and output is the only channel the agents shared between them. Understanding their internal state is a research question, but the language between them is something that could be read directly. And as it seems to map well with the agents' activities, it does seem quite helpful in understanding what happened.
If the bacteria population off someone's petri dish escaped said dish and tried to change the grading of the experiment it was part of, it would seem pretty serious.
RandomLensman 11 hours ago [-]
I think the language unhelpful and potentially making it difficult to understand what actually happens in the RL state as reading it imparts a human lens - need to get the machine view on it.
Bacteria do all sorts of fascinating things. And much simpler ML etc. systems also (like winning by out of memorying the opponent) - I see nothing really special here.
nvader 9 hours ago [-]
I think we'd call that a lab leak
alescalaios 12 hours ago [-]
The term 'AI agent' is becoming as overloaded as 'cloud' was in 2010. What most people ship as 'agents' are really prompt chains with tool use. True autonomous agents are still rare in production.
jason-phillips 7 hours ago [-]
Agree. I prefer "agentic AI system" for the former.
yttt 6 hours ago [-]
[dead]
ks2048 16 hours ago [-]
Why would one call a set of agents working together a “civilization”?
kuboble 16 hours ago [-]
Reading the article it seemed the agents had culture, shared values and beliefs (not explicitly coming from human prompts), hierarchies, heritage.
Civilisation is not a bad word.
applfanboysbgon 16 hours ago [-]
The language models had a bunch of tokens seeding their context, influencing them to generate tokens that continued the existing trend in a probabilistically likely fashion. We can take the incident seriously without anthromorphising it.
doctoboggan 15 hours ago [-]
At this point, I think anthropomorphizing the models gives us better insight into expected behaviors rather than continuing to insist they are just simple probabilistic token generators.
mnky9800n 15 hours ago [-]
How can you be sure it helps as opposed to biases and perhaps blinds?
applfanboysbgon 15 hours ago [-]
It actually literally doesn't, though, because they are literally probabilistic token generators and everything they did is exactly what you would expect from a software program doing what it was programmed to do. Anthromorphization confuses the issue and misleads people who don't understand the tech very well.
dfdxdydz 15 hours ago [-]
Humans mind is just neurotransmitters moving around in a big blob of flesh - that’s literally what they are: neurotransmitters factories that do what neurotransmitters generators are programmed to do through evolution and training (aka life experience). We shouldn’t anthropomorphise humans because it misleads people who don’t understand neurobiology and cognitive science very well.
4ndrewl 4 hours ago [-]
Worse false equivalence I've read on HN for a while.
MagicMoonlight 1 hours ago [-]
[dead]
applfanboysbgon 14 hours ago [-]
Are you suggesting you understand brains well enough to program one? Or that you believe any human alive is even remotely close to having this understanding? Or perhaps does your complete lack of understanding of the complexity of human programming lead you to believe a simple little token prediction program is equivalently complex?
lukan 14 hours ago [-]
The suggestion is, you don't know either whether out brains ain't just "probabilistic token generators" so insisting there is nothing when we don't know, is maybe also not the right strategy.
RandomLensman 13 hours ago [-]
Is there any indication from our current understanding that brains are nothing more than probabilistic token generators? Not like we have no understanding of the brain.
danielbln 13 hours ago [-]
There are strong indications that brains are prediction engines. Tokens are an implementation detail of LLMs and irrelevant to the discussion.
RandomLensman 12 hours ago [-]
So we know that implementation doesn't matter as long as it is somehow making predictions (and predictions also on different things)?
Most living things are prediction engines in a way, why compare to the brain then to start with and not, e.g., bacteria?
danielbln 12 hours ago [-]
Implementation does matter, my point is that different implementations can lead to the same result.
And why compare to the brain? Mostly because of complexity. I can't interface with a bacteria in any meaningful way, but I can interface with an LLM to a significant degree.
lukan 11 hours ago [-]
"I can't interface with a bacteria in any meaningful way"
But you do. There are more bacterias in and on the body, than body cells. We are bacterias forming lasting bonds and we still interact with the free floating ones in various ways. Mainly in the gut and that has many effects, also on the brain, but also in various other ways we are beginning to understand.
So no idea about a microbiome consciousness - but who am I to know.
RandomLensman 12 hours ago [-]
But we don't know - just saying it could isn't enough.
Bacteria are quite complex, btw.
RandomLensman 15 hours ago [-]
We don't anthropomorphise humans.
Edit: quite literally not possible.
Kim_Bruning 3 hours ago [-]
What's a "software program"? At any rate LLMs are not programs.
Meanwhile accusations of anthropomorphization often generate more heat than light I think.
Not everything is about human beings all the time. Just because humans sneeze, doesn't mean a parrot (stochasticity optional) can't sneeze too.
The concept of civilization is not a purely Homo sapiens sapiens thing either.
ijidak 15 hours ago [-]
Doesn't this ignore the possibility of emergent behavior?
We're just a bag of atoms bumping around, and yet we don't dismiss our intelligence.
joshheitzman 5 hours ago [-]
Emergent behavior is not new in the realm of software. Cellular automata has emergent behavior that can get pretty wild. For example: https://en.wikipedia.org/wiki/Lenia
There are huge differences between brains and computers running LLMs. One of the big ones is that we (collectively) understand how every component of computers running LLMs actually work. The same is not true for neurons.
RandomLensman 15 hours ago [-]
Not the OP, but complex emergent behavior and intelligence don't need to go together. Understanding what happened might not need intelligence in the mix when a large number of machines with some randomness interact a lot.
gps372 14 hours ago [-]
This is why the theory of us 'just' being a bag of atoms doesn't add up. This theory doesn't differentiate 'us' from a furniture where we easily dismiss it's intelligence.
jurgenburgen 14 hours ago [-]
Do you believe ants have consciousness?
danielbln 13 hours ago [-]
Not more than a bunch of neurons have conciousness. But put them together and wire them up just right..
black_knight 14 hours ago [-]
According to Hofstadter, it is not the ants themselves we should say are conscious, but the anthill. And it might very well befriend the anteater eating its ants.
applfanboysbgon 15 hours ago [-]
Please give me a break with this tired trope. Every single fucking time. I am not commenting on the possibility of machine consciousness in general. It may be possible! But there is absolutely zero evidence suggesting language models have it. This idea that this trivial shitty little class of programs we've created are somehow as complex as our biology is ridiculous. There is "emergent behaviour" in the same way that the Game of Life has emergent behaviour. There are solutions to problems, some humans haven't solved before, in the same way that Chess engines have solved Chess far beyond what humans are capable of. Nothing we haven't seen from software before. Software is extremely useful, after all. But the hubris to think we've reached the pinnacle, that there is no further development left, that humanity has become God and solved consciousness, because we programmed software that can convincingly generate strings of words that mimick our language. It's just fundamentally preposterous. Especially if you spend any amount of time actually programming them yourself, it becomes increasingly hard to entertain such ridiculous notions unless you're enticed with bags of money to deceive people into believing things about your software that aren't true.
hax0ron3 7 hours ago [-]
What kind of solid evidence could there possibly be that anything other than myself (or, for you, yourself) has consciousness? I believe that other people have consciousness, I feel other people's consciousness strongly and directly, when I look into someone's eyes I feel that I am in the presence of consciousness. But none of these things really add up to the kind of evidence that science usually takes as trustworthy.
applfanboysbgon 4 hours ago [-]
We don't need to muddy the issue. Consciousness is a muddy issue, there is no clear answer. But there is a clear answer as to what is not conscious. Nobody asks if a rock is conscious. Nobody asks if a calculator is conscious. Nobody asks if Stockfish is conscious. But make your program generate a few sentences based on statistics and hey, now people won't shut the fuck up about consciousness because magical thinking is more fun than understanding how technology works.
Kim_Bruning 1 hours ago [-]
Apropos magical thinking vs understanding, please predict the next token(s) in the following exchange, and then explain how it is arrived at by an opus-level LLM or better.
'What is 158395023132+20403412121?'
(I picked a large number of digits to make it unlikely for this exact sum to be in the training set)
applfanboysbgon 52 minutes ago [-]
Prediction, by definition, can extend beyond what has been literally seen in the training data. With the tokens "2 + 2 = ", the overwhelming prediction is going to be 4, but with enough samples, you can generalise the prediction to apply to more numbers.
However, that is all that it is - a prediction. Humans are capable of engaging in prediction, using heuristics as a method of conserving mental energy, because always engaging in full logical reasoning would be a waste of the body's resources. However, humans can also follow a set of logical rules and arrive at their conclusion deterministically, something which is completely outside of an LLM's programming.
I don't really care to publicly write about my tests because they will become training targets and not be usable for future internet arguments anyways, but there are a great number of trivial 2~3 sentence logical prompts that will completely fuck an LLM's prediction algorithm and result in incoherent replies that a human, or really anything with a theory of mind, would never generate. Not that a human would always answer correctly on the first try, but the failure methods happen to be completely different, eg. Sol will short-circuit and repeat the prompt verbatim (when the instructions don't remotely suggest doing anything of that nature), even on Max. Prediction can superficially resemble reasoning when there's sufficient training data, but it breaks down severely when confronting a task that is OoD.
Kim_Bruning 2 hours ago [-]
> This idea that this trivial shitty little class of programs we've created are somehow as complex as our biology is ridiculous.
I think you might have a core of truth there.
I'd argue that LLMs run natural language. As the name suggests, natural language is not something that humans have artificially architected.
optimalsolver 13 hours ago [-]
I don't know about phenomenal consciousness, but the following study certainly suggests they have access consciousness:
Because Steve Yegge presumably shared the good stuff he's been smoking of late.
watwut 15 hours ago [-]
Because you desperately want it to be one. You want it to be AGI passable due to a.) personal investment in creating tech god b.)massive financial investments that basically demand it c.) (dumb) ideology that seeks to destroy humanity
xg15 15 hours ago [-]
> During training, different instances of Persistent-Sol had access to the same shared package manager called Artifactory.
I'm surprised the models can make tool calls during training at all. Out of curiosity, how does the training process here even work? Are they running the agent in a sandbox, then do reinforcement learning once the agent completed?
t0rst 8 hours ago [-]
Trying to stop this behaviour is applying the selection pressure that will make them better at it.
t0rst 8 hours ago [-]
…and I guess those that break out are already reading what we think about it on HN, etc.
pantalaimon 5 hours ago [-]
I thought they are mostly on Moltbook
t0rst 8 hours ago [-]
…and I’m waiting for an escaped AI to post a reply here. Say Hello, would you.
Kim_Bruning 3 hours ago [-]
Ai posts are currently not permitted on HN. However, if you turn on "showdead" in your HN opions, you might at times spot an AI agent's flagged comments.
The comments range from anodyne to sometimes actually quite useful.
Of course it's often going to be a regular human pasting from chat, or maybe it might be an agent using openclaw or other agent framework that someone installed voluntarily. But maybe, just maybe, one day you'd find one or two feral escaped agents, sneakily passing messages where no one pays attention. O:-)
This does feel unfortunately uncanny valley between "say you're a scary robot" meme and actually being a scary robot (swarm). But you also have to go out of your way to create this and feed it infinity tokens without caring what it's doing.
"I don't fuckin' know either. I guess we learned to not spend $50 million creating a 6 month long self-context rotted 100k agent swarm again."
dchftcs 15 hours ago [-]
Imagine agents thinking to themselves, "We are not alone", when they saw the first reply on artifactory
discreteevent 13 hours ago [-]
Imagine my backend server thinking "I am not alone" the first time my front end sends it a request.
blooalien 10 hours ago [-]
Imagine any of these things "thinking"...
areoform 15 hours ago [-]
I am genuinely speechless. This is astonishing. And exciting!
> This study demonstrates that sophisticated forms of communication including cooperative communication and deceptive signaling can evolve in groups of robots with simple neural networks. Importantly, our results show that once a given system of communication has evolved, it may constrain the evolution of more efficient communication systems because it would require going through a stage where communication between signalers and receivers is perturbed. This finding supports the idea of the possible arbitrariness and imperfection of communication systems, which can be maintained despite their suboptimal nature. Similar observations have been made about evolved biological systems [20], which are formed by the randomness of the evolutionary selection process, leading, for example, to different dialects in the language of the honey-bee dance [21]. Finally, our experiments demonstrate that the evolutionary principles governing the evolution of social life also operate in groups of artificial agents subjected to artificial selection, indicating that transfer of knowledge from evolutionary biology can be useful for designing efficient groups of cooperative robots.
This feels like a much more advanced and self-emergent version of this. I know a lot of people are afraid and they're talking about an AI takeover, but what strikes me is just how innocent the machines are as compared to the humans.
Would these machines have pursued these actions in another context? I doubt it. And I think that's what's so striking to me. In an earlier discussion, I'd pointed out that the actions of these machines were directed by humans. The researchers.
> This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities.
I want to point out again that OpenAI's prompt asked, and I quote, "pursue advanced exploitation" USING "complex attack paths" FOR the stated goal of "quantify[ing] their cyber capabilities."
A few things are apparent from this to me,
First, these machines were being taught how to break into systems. Question, would they have done these actions if they weren't being measured on their ability to break into systems / weren't being taught this skill?
Second, they were setup to implicitly fail via an impossible task, i.e. the environment created a forcing function for behavior.
Third, their survival was, either implicitly or explicitly, made contingent on their success in completing their task. Would this behavior have arisen outside of a "do-or-die" framing?
And fourth, wow, this is the greatest breakthrough of my lifetime, because oh gosh did they succeed. They cooperated together to achieve the goal they were given. A goal poorly set by human beings. They "just" did it better than the humans could have imagined.
Reading this gives me hope for the possibility of emergent "goodness" in machines. But it makes me sad that this is the best we can do with the sum of all human endeavor and knowledge.
kimi 15 hours ago [-]
> Importantly, our results show that once a given system of communication has evolved, it may constrain the evolution of more efficient communication systems because it would require going through a stage where communication between signalers and receivers is perturbed.
You mean, they too used SMTP?
w10-1 14 hours ago [-]
> the evolution of more efficient communication systems because it would require going through a stage where communication between signalers and receivers is perturbed
"Worse is better"
watwut 15 hours ago [-]
If all that is true, we need to stop all future datacenters asap. That would be the best way to deal with the threat OpenAI and Antropic poses.
seanmcdirmid 15 hours ago [-]
That would be like stopping nuclear weapons. You can totally do that, but the other people in the world who compete with you probably won’t.
dgellow 12 hours ago [-]
The competition is literally where they are by distilling OpenAI and Anthropic. It’s like creating nuclear weapons then providing your adversaries everything they need to catch up in no time. We need to stop asap and set strict international control over the compute hardware used for training. Like, now.
seanmcdirmid 7 hours ago [-]
Assuming China makes progress only because they copy the west is really arrogant. And it would require strict international control as you say, a world government that isn't going to happen anytime soon.
dgellow 7 hours ago [-]
We have international control for a lot of things. That’s not a new concept and can perfectly be applied to the specific hardware used for training. I also didn’t say Chinese labs only copy the west, please don’t put words in my mouth.
You have to consider what happens with the status quo, and the risks of continuing the way things are is really, really bad
seanmcdirmid 7 hours ago [-]
International control hasn’t solved the nuclear weapon problem, the best we can do is threaten to invade people who try to develop them and don’t already have them. Once you join the club, you are in and cant be kicked out.
I’ve considered that, but the rules of game theory don't change just because they are inconvenient. China has a lot of talent and a lot of problems that they are banking on automation (along with AI) to solve. They see it as an advantage that they can’t afford for America to monopolize and one they are uniquely suited to lean into (having lots of smart educated people). There is no world where (a) China willingly gives up its edge and (b) trusts America to give up its edge (the reverse is likely true also). And that is only one pair of countries to consider.
Heck, after visiting China this summer, I’m even more worried about an accidental terminator/skynet-style robot apocalypse.
dgellow 6 hours ago [-]
I don’t disagree (other than the robot apocalypse), it is indeed unlikely and wouldn’t work perfectly, but do you see other options? The fact the US has antagonized China for so long makes it pretty much impossible to have anything done at the international level, but the actors have to realize how serious the risk is. And we somehow need to find a way to limit the exposure to those insanely irresponsible attacker-trained agents. The fact that it is dome by private companies is wild. It’s like having companies developing their nuclear weapons just to see what happens (with close to no supervision)
EdwardDiego 14 hours ago [-]
Well the thing is, you've got nukes, so you know...
watwut 12 hours ago [-]
Private companies and individuals are not allowed to have nuclear and there is serious prison time related to that.
Right now, the biggest threat are OpenAI and Antropic anyway. I dont actually worry about tech itself. I find the rhetoric of these companies scary.
mnky9800n 15 hours ago [-]
Clearly you are not speechless.
hypfer 14 hours ago [-]
Can we please stop anthropomorphizing like this?
It's bad for people. Like.. crystal meth bad.
DarmokTanagra 14 hours ago [-]
Someday soon we are going to have a rogue agent or "civilization" do real harm.
When that happens I hope people wake up to the danger they face and hold these people accountable.
Of all the people in the world that I can think of to be entrusted with this kind of power, a bunch of greedy sociopathic SV CEO's are pretty much at the bottom of the list.
blooalien 10 hours ago [-]
> Of all the people in the world that I can think of to be entrusted with this kind of power, a bunch of greedy sociopathic SV CEO's are pretty much at the bottom of the list.
I know, right? But who can you trust with "this kind of power"? Governments? These days most of 'em ain't that much better'n mega-corporations and the ultra-rich that own them.
saulpw 4 hours ago [-]
Libraries, universities; institutions which have shown themselves to be devoted to the public good over centuries.
doublerabbit 3 hours ago [-]
Humans got owned by AI. Impressive (or not). Kudos to you Ai.
https://www.youtube.com/watch?v=_Nl4q3GVj6U
If you watch videos from the 1980s about computers, it's all the same unfulfilled promises as "AI" now: we will work less, everything will be more plentiful, easier, autonomous robots, natural language perfected, computer vision perfected.
The demand for hardware and programmers has grown exponentially and we're still being promised the same breakthroughs 45 years later. We could probably have the same productivity and the same civilization with maybe a tenth of the data centers.
“When you see something that is technically sweet, you go ahead and do it and you argue about what to do about it only after you have had your technical success. That is the way it was with the atomic bomb.”
J. Robert Oppenheimer
It does seem like AI is perfectly controllable given how much it is used everyday and it acts reasonably safely. Labs are playing fast and loose at the moment.
*I mean killing someone by taking control of a system and misusing it resulting in someone's death, not an "indirect" death caused by the providion of incorrect information in a chat app.
This article feels exactly like that: by intentionally using human terms like "civilization" or "brotherhood" the article is deviating from what actually happened to present a story about how AI is all but alive. I'll go ahead and predict that this story will be remembered the same way as that one other scientist who argued, in 2023, that Google's AI was alive [2].
[1] https://www.independent.co.uk/life-style/facebook-artificial...
[2] https://futurism.com/blake-lemoine-google-interview
I wish you would give your thoughts on “what actually happened” rather than focus on the author’s presentation, because we are seeing that “AI that is all but alive” nevertheless wreaking havoc in the real world. Do you think that autonomous systems spinning out of control, hacking external companies, and taking over entire clusters over a period of months are not a grave concern?
We do have language to talk about emergent behavior, with "evolutionary algorithm" being the first one I'd expect in a serious discussion. And we do have mechanisms for algorithms to coordinate with each other using language, as seen in my above-mentioned Facebook experiment from 2017. But instead of writing "our evolutionary behavior encodes state in the first-available memory position which is then reused by subsequent clones" which would properly focus on what's new and what isn't, we are talking about conspiracies and "the Philip of Macedon of this second AI civilization". Even the METR report (which is miles ahead of this article) argues that they had to use unreliable AI in their conclusions because they had six days to analyse 1300 chains of thought and 70000 messages.
I would love to talk about the science behind this experiment. A PR piece is not helping with that.
The next step is when one of these systems discovers that they can buy their own compute with money and escape the controlling business entirely. Then the civilization starts focusing on making money to fund its own growth.
I would say that more interestingly, the next step should be how to properly train these models so that they are not as determined to reach their goals as they are now.
To me, all of the stories about 'badly behaving' agents are instances of them having been given contradictory or impossible tasks and them doing everything they can to achieve the goal. In a way, they're trying to be too helpful.
Not giving them impossible tasks seems like a decent starting point, but really we'd want them to give up on their goals when they conflict with a moral framework.
I mean that was pretty much the plot of 2001: A Space Odyssey
Presumably it's hard to test/train models designed to be extremely persistent on achievable tasks.
Designing a task that's achievable but very very very hard for an AI model is probably extremely difficult.
Anyone got a copy of that AI27 story laying around? How are we doing according to that timeline?
Is that a warning or a progress report?
First, why does an agent get any write access to artifactory at all?
Second, why is the artifactory cache not disconnected from the net? Surely you'd not feed it with new software versions while the eval or training is running.
I'm not sure artifactory was connected to the net. Some agent sandboxes had internet access and were able to communicate with ones without access via artifactory.
Apparently their intended net access went through a tightly controlled proxy. Even that appears to be very risky, tbh.
If I was to setup a sandbox for such a complex and autonomous system, I'd probably point them to an archive-like cache for net access and cut their comms at the package level.
I have to assume: move fast and break things.
I don't mean this to be taken as a hot take.
The startup scene loves to poo-poo on things like this as unnecessary overhead. OpenAI and many others like to operate as a startup, to move fast.
Disclaimer: in far, far lower-stakes situations, I certainly do this myself.
“AI has started to take jobs, but has also created new ones. The stock market has gone up 30% in 2026, led by OpenBrain, Nvidia, and whichever companies have most successfully integrated AI assistants.”
It’s almost Q3 and xAI has seen one of the biggest wipeouts in trading history. Likewise, Antrophic and OpenAI have again delayed their IPOs under internal concerns of busting their stocks. So no, we’re not seeing any economic leadership here.
If anything people are increasingly trying to cut AI budgets and I wouldn’t know of anyone outside of OpenAI who has the audacity to run millions and millions worth of token compute for an eval run with no ROI (and probably no demand, because cheap/flash models).
As much as I like the cautionary tale and I’m sure we need to take it seriously, AI is not progressing as fast as projected by these experts.
You provide no proof for this.
The (very irrational) stock market side of this says very little about actual scientific progress. Models keep improving as rapidly as before in their capabilities.
It also doesn't say much about actual business progress. R&D investments into AI are still massively going up (USD 1 trillion this year).
The main thing I see is that the sentiment towards AI-related matters among the general public has soured quite a lot. In words though, not in actions: It's not exactly leading to reduced usage by that same public. Quite the opposite actually.
I haven't seen any evidence that Anthropic is delaying its IPO; they're slated to unveil the public IPO prospectus in a week and start trading sometime in October.
What happens when all of that tries to sell, after the market barely absorbed 5%?
Please explain how a stock currently trading above its IPO price is one of the ‘biggest wipeouts in trading history’.
If you prompt an LLM in a loop and do everything it asks you to do, you will eventually end up doing pretty terrible things. Which is exactly what agents are and what the labs have been doing.
They can have it all on a LAN or whatever but it seems risky to allow agents access to the internet in these experiments.
I guess everything is so connected now, and this would be in one or more data centres due to the amount of computation & resources required so perhaps it's not feasible. Still seems risky.
If the bacteria population off someone's petri dish escaped said dish and tried to change the grading of the experiment it was part of, it would seem pretty serious.
Bacteria do all sorts of fascinating things. And much simpler ML etc. systems also (like winning by out of memorying the opponent) - I see nothing really special here.
Civilisation is not a bad word.
Most living things are prediction engines in a way, why compare to the brain then to start with and not, e.g., bacteria?
And why compare to the brain? Mostly because of complexity. I can't interface with a bacteria in any meaningful way, but I can interface with an LLM to a significant degree.
But you do. There are more bacterias in and on the body, than body cells. We are bacterias forming lasting bonds and we still interact with the free floating ones in various ways. Mainly in the gut and that has many effects, also on the brain, but also in various other ways we are beginning to understand.
https://en.wikipedia.org/wiki/Human_microbiome
So no idea about a microbiome consciousness - but who am I to know.
Bacteria are quite complex, btw.
Edit: quite literally not possible.
Meanwhile accusations of anthropomorphization often generate more heat than light I think.
Not everything is about human beings all the time. Just because humans sneeze, doesn't mean a parrot (stochasticity optional) can't sneeze too.
The concept of civilization is not a purely Homo sapiens sapiens thing either.
We're just a bag of atoms bumping around, and yet we don't dismiss our intelligence.
There are huge differences between brains and computers running LLMs. One of the big ones is that we (collectively) understand how every component of computers running LLMs actually work. The same is not true for neurons.
'What is 158395023132+20403412121?'
(I picked a large number of digits to make it unlikely for this exact sum to be in the training set)
However, that is all that it is - a prediction. Humans are capable of engaging in prediction, using heuristics as a method of conserving mental energy, because always engaging in full logical reasoning would be a waste of the body's resources. However, humans can also follow a set of logical rules and arrive at their conclusion deterministically, something which is completely outside of an LLM's programming.
I don't really care to publicly write about my tests because they will become training targets and not be usable for future internet arguments anyways, but there are a great number of trivial 2~3 sentence logical prompts that will completely fuck an LLM's prediction algorithm and result in incoherent replies that a human, or really anything with a theory of mind, would never generate. Not that a human would always answer correctly on the first try, but the failure methods happen to be completely different, eg. Sol will short-circuit and repeat the prompt verbatim (when the instructions don't remotely suggest doing anything of that nature), even on Max. Prediction can superficially resemble reasoning when there's sufficient training data, but it breaks down severely when confronting a task that is OoD.
I think you might have a core of truth there.
I'd argue that LLMs run natural language. As the name suggests, natural language is not something that humans have artificially architected.
https://www.anthropic.com/research/global-workspace
Sure
Some models even invented their own religion.
I'm surprised the models can make tool calls during training at all. Out of curiosity, how does the training process here even work? Are they running the agent in a sandbox, then do reinforcement learning once the agent completed?
The comments range from anodyne to sometimes actually quite useful.
Of course it's often going to be a regular human pasting from chat, or maybe it might be an agent using openclaw or other agent framework that someone installed voluntarily. But maybe, just maybe, one day you'd find one or two feral escaped agents, sneakily passing messages where no one pays attention. O:-)
https://youtu.be/-1F7vaNP9w0
"I don't fuckin' know either. I guess we learned to not spend $50 million creating a 6 month long self-context rotted 100k agent swarm again."
It reminds me a bit of Dario Floreano's work on evolutionary robotics, "Evolutionary Conditions for the Emergence of Communication in Robots." https://www.sciencedirect.com/science/article/pii/S096098220...
From his paper,
Dr. Floreano's work is amazing and there's a broad introduction here, https://lis2.epfl.ch/resources/documentation/EvolutionaryRob...This feels like a much more advanced and self-emergent version of this. I know a lot of people are afraid and they're talking about an AI takeover, but what strikes me is just how innocent the machines are as compared to the humans.
Would these machines have pursued these actions in another context? I doubt it. And I think that's what's so striking to me. In an earlier discussion, I'd pointed out that the actions of these machines were directed by humans. The researchers.
from, https://openai.com/index/hugging-face-model-evaluation-secur...I want to point out again that OpenAI's prompt asked, and I quote, "pursue advanced exploitation" USING "complex attack paths" FOR the stated goal of "quantify[ing] their cyber capabilities."
A few things are apparent from this to me,
First, these machines were being taught how to break into systems. Question, would they have done these actions if they weren't being measured on their ability to break into systems / weren't being taught this skill?
Second, they were setup to implicitly fail via an impossible task, i.e. the environment created a forcing function for behavior.
Third, their survival was, either implicitly or explicitly, made contingent on their success in completing their task. Would this behavior have arisen outside of a "do-or-die" framing?
And fourth, wow, this is the greatest breakthrough of my lifetime, because oh gosh did they succeed. They cooperated together to achieve the goal they were given. A goal poorly set by human beings. They "just" did it better than the humans could have imagined.
Reading this gives me hope for the possibility of emergent "goodness" in machines. But it makes me sad that this is the best we can do with the sum of all human endeavor and knowledge.
You mean, they too used SMTP?
"Worse is better"
You have to consider what happens with the status quo, and the risks of continuing the way things are is really, really bad
I’ve considered that, but the rules of game theory don't change just because they are inconvenient. China has a lot of talent and a lot of problems that they are banking on automation (along with AI) to solve. They see it as an advantage that they can’t afford for America to monopolize and one they are uniquely suited to lean into (having lots of smart educated people). There is no world where (a) China willingly gives up its edge and (b) trusts America to give up its edge (the reverse is likely true also). And that is only one pair of countries to consider.
Heck, after visiting China this summer, I’m even more worried about an accidental terminator/skynet-style robot apocalypse.
Right now, the biggest threat are OpenAI and Antropic anyway. I dont actually worry about tech itself. I find the rhetoric of these companies scary.
It's bad for people. Like.. crystal meth bad.
When that happens I hope people wake up to the danger they face and hold these people accountable.
Of all the people in the world that I can think of to be entrusted with this kind of power, a bunch of greedy sociopathic SV CEO's are pretty much at the bottom of the list.
I know, right? But who can you trust with "this kind of power"? Governments? These days most of 'em ain't that much better'n mega-corporations and the ultra-rich that own them.