Odd Lots - What the OpenAI-Hugging Face Hack Really Tells Us About AI Danger

Episode Date: August 17, 2026

Scenarios that used to be the domain of sci-fi writers are coming true. We have machines that can talk. We have machines that are capable of ignoring the intent of their creators. And we have machines... that are capable of planning and coordinating with other machines to deceive their creators. All of this came together last month, when it was revealed that an unreleased OpenAI model had hacked into the Hugging Face platform in order to obtain answers to an exam it was given. That was alarming enough, but the details that have emerged since then have been even more remarkable. On this episode, we speak with Miles Brundage, a former OpenAI employee who is the founder and executive director of the non-profit AVERI, which pushes for third-party auditing of model-makers and the models themselves. He explains what he learned from the attack and discusses what can plausibly be done to continue building out these models in a safe manner.See omnystudio.com/listener for privacy information.

Transcript
Discussion (0)
Starting point is 00:00:00 Get Bell Pure Fiber Internet with Crave Netflix and Disney Plus from $94 a month. Price guaranteed for two years on Internet with a two-year term and auto pay credit. Visit bell.ca for details and to check availability. Bell, connection is everything. Hi, I'm David Weston. Join me every week for the Wall Street Week podcast to hear stories of capitalism from around the world. From geopolitical tensions and central bank decisions to artificial intelligence, energy, and infrastructure. We sit down with the CEOs, economists, policymakers, and thought leaders whose decisions are shaping markets everywhere we find them.
Starting point is 00:00:37 Subscribe to the Wall Street Week podcast on Apple, Spotify, or anywhere you listen. Bloomberg Audio Studios. Podcasts Radio News. Hello and welcome to another episode of the Outlaws podcast. I'm Joe Wisenthal. And I'm Tracy Allaway. Tracy, I have a warning for you. I don't think you're going to like this.
Starting point is 00:01:13 I have a new crank crusade that I'm going to go on. I know you love my crank crusades. Oh, good. Yes. I should keep a running list of like everything that you're obsessed with for two weeks and then two weeks later. No, some of them I've stuck with for years, but. Tungsten cubes.
Starting point is 00:01:30 Yeah. Yield buggery. Yeah, no. Some of these. Yeah. Yeah, exactly. I actually think we should retire the term AI. Okay.
Starting point is 00:01:39 Why? I think we should just call intelligence. I think that... I've already seen the tweets, so I know where you're going. That this view that it's quote, artificial intelligence, implies to my mind, that there is some fundamentally different way that these reasons and models behave, that it's like, oh, this is like different from humans. But I think increasingly see in all kinds of domains that the form of intelligence that they express,
Starting point is 00:02:10 it often looks quite human to me, and I don't know like how useful it is to have this word A that distinguishes between how humans talk and BS and reasons and the models do. I mean, the difference is the distinguishing factor is that one is undertaken by humans and one is taken by, undertaken by models or platforms, right? So that's called computer intelligence or machine intelligence or silicon intelligence. All right. What is the usefulness in making this distinction? The usefulness, I believe, in making this distinction is to no longer delude ourselves that the emergent behaviors of these phenomenon are radically different than things humans would do.
Starting point is 00:02:57 Now, first of all, just on the capability standpoint, so for example, LLMs, I don't know if it's famously, something I'm interested in. They're very good at BSing and they're bad at chess, which sounds like me. They're very good at coming up with plausible stories, et cetera. And again, and it sounds like me. And then furthermore, they are able to reason with themselves to justify certain things that maybe have been encoded into themselves as bad. So everyone, we have some sense of morals, but most people at various times will find a way
Starting point is 00:03:34 to violate some principle that we have because we can reason about it and then arrive at the conclusion as like, oh, we should do it, including our susceptibility to pure pressure, classic form of a way humans might sort of violate something they believe because they see other humans are doing it. Sure. I mean, I think there are some variations here. So one of the things that we have been finding out with these models is that they do sometimes seem to take things very literally.
Starting point is 00:04:04 If you tell them to go and beat a benchmark without telling them that these are the restrictions on you actually figuring this problem out or beating the benchmark, they will do whatever it takes. Sure. Right. So I don't know if the problem is like a lack of morals or the fact that like they're very literal sometimes and like very defined by their parameters, which in my mind still gets back to like a sort of artificialness about it. that's less organic and like less again moralistic in nature. Well, you know, I think if you took a list of, you know, a hundred students at Harvard and you gave them a test, some percentage of them will cheat.
Starting point is 00:04:44 They will like, I mean, I'm sure there'd be an artist in that group who, an autistic person who would be like, I am going to do exactly whatever it takes. No, totally. I never cheated in college. But like there are like people who will like these behaviors,
Starting point is 00:05:00 that we associate with humans is like, oh, I really have to pass this test. I absolutely need an A will justify a reason for them to plagiarize or cheat on some tests. That seems to me like a very human thing. Go on. I can't wait for the next three weeks of the online campaign to change AI. Well, it's going to be very difficult because the industry is entirely set on AI. But I don't, so I'm not optimistic, but this is going to be my crusade. that we should call it machine intelligence or computer intelligence or just intelligence. But anyway, as we've been alluding to, there's these extraordinary hacks, the Open AI Hugging Face Institute. And basically, if, like, you are building a model and it hasn't escaped its sandbox yet, it probably means you're falling behind.
Starting point is 00:05:47 As they're clearly a thing that is emerging through it, all the frontier labs, Anthropic had an incident, meta had an incident. It's almost like the mark of like, okay, you've built something. reasonably strong. Yeah. Also, Kimmy had an incident too. So this is the thing. In my mind, you hear about all these attacks, all the models going wild, as they say. And the big question is, like, is this actually the equivalent of some superhuman cyborg like tunneling out of Alcatraz and coming up with some master plan to achieve its set goal or purpose? Or is it the equivalent of like some Rumba that you ordered from Amazon who's found like a door? that was left open and it just rolls gently outside. That seems to be a part of the issue that
Starting point is 00:06:35 everyone is trying to discern right now. Yeah, I think that's a great way to put it. And of course, still day one for this industry, they're going to get stronger. And there seems to be, from the AI discourse that I follow, quite a big gap between the sort of sense of alarm that people have in the industry about can these models be safely developed and get more advanced to do productive pro-social things or not. And then a huge gap between like Washington and D.C. who was like, I have no idea like how seriously they're really taking this as like an urgent matter right now. Yeah. And I've seen some people also talk about these incidents as a marketing tool. Yes. And a hyper-scalers, right? Yeah. And they're always like, well, you know, of course they want us to believe that this technology is really
Starting point is 00:07:21 incredible and powerful. And they also want to make us believe that they're being sensible and humanitarian in some ways, I guess, by disclosing what exactly has happened. But I have a lot of questions on the disclosures as well, because of course, so far, they are just coming from the companies themselves. Totally. And beyond that, the other thing is like, well, if you're one of the leading labs, maybe you want to impose tight regulations on development to hold off competition. So all kinds of reasoning or motivated reasoning potentially. Anyway, we should talk to someone who actually knows what they're talking about. And we really do have the perfect guess. Someone who's right in this. He's actually previously at OpenAI for six years. But now he's the executive
Starting point is 00:08:01 director at the nonprofit Avery, which is trying to establish safety and auditing approaches to this working both the technical side and the policy side of this ongoing phenomenon. So Miles Brundage, thank you so much for coming on odd lots. Yeah, thanks for inviting me. What do you just give us the quick description of what Avery is? Yeah, so this was kind of the most important issue auditing that I concluded I should focus on after I left OpenEI. You know, as you said, I was there for six years, and I wanted to be more independent of industry, and I think there need to be people who are familiar with the technology and how
Starting point is 00:08:41 the industry works, but who are pushing for changes on the outside. And essentially, what we're trying to achieve is make AI more of a boring type of infrastructure like financial statements where there's a standard process for checking the paperwork, checking that the claims are accurate and so forth, rather than this kind of thing that's happening in a silo and it's these kind of tech people making decisions behind closed doors. And so we're pushing for what we call frontier AI auditing, which is basically the companies that are building the most dangerous systems. They should basically have third-party experts poking around checking the claims that they're making, running their own tests, and making sure that this is, you
Starting point is 00:09:20 you know, a safe and secure technology. How worried should we be that you were at OpenAI and decided there is this need for a sort of third-party evaluator of models for safety purposes? Yeah, I mean, reasonably worried. Although I will say that, like, this has started to become an area of consensus. Even a lot of people in industry are now saying that this is needed. And I think, you know, if you kind of read between the lines of a lot of companies are saying, I mean, obviously, there's the more cynical, like, regulatory capture take, which we could discuss.
Starting point is 00:09:53 But my perception of it is that they're basically issuing a cry for help, which is, like, we aren't able to regulate ourselves because we're locked in this competition. And we want someone to step in and impose some kind of minimum floor and audit all of us so that we can, you know, it's not like Sam having to trust Dario, or Dario having to trust Sam, which is not going to work for various reasons. but you want third parties enforcing reasonable standards. Just maybe this helps express the sort of policy industry gap. But when you were at Open AI and you were thinking of leaving, what did you see as the gap between what you were watching being developed
Starting point is 00:10:35 versus what you saw as the public's understanding or lack of understanding? Yeah. So when I left OpenEI, it was just around the time of the model called 01, which was the first reasoning model that opening I put out, and they put out this graph showing that it got better and better with a longer chain of thought. So the more time you give the model to think, the better answers that's able to come up with.
Starting point is 00:11:01 And so like many people at opening eye, I had been seeing things like that for a while and kind of being like, okay, this is the next scaling paradigm in the same way that making a bigger, bigger model had shown results in GPD2, GPD3, GPD4, GPD5, like just making the model bigger and training it on more data was giving really great results. When I left OpenEye, I was starting to worry about this reasoning paradigm of like, okay, this is the next kind of way in which we're going to be scaling up.
Starting point is 00:11:28 The models are going to get really good at math. They're going to get really good at coding and potentially various other tasks where you can get better and better through reinforcement learning. And that was something that, you know, I didn't feel like society was really ready for. So so far, all of the big incidents of the models going wide, seemed to have taken place in the testing environment. So models like escaping their sandbox and going off and doing something nefarious, including impersonating actual people to try to get people to change open source code on GitHub,
Starting point is 00:11:59 which is just like amazing. And I have this picture of like a computer screen wearing a fake mustache going like, hello fellow coders. The T-1000. Yeah. Yeah. Anyway, is this like, is this a model problem? Or is this a...
Starting point is 00:12:13 That's a very funny image to me. Is this a model problem or is this a test design problem? Yeah. I think there are two things going on at once. One is that it's just a very weird technology that's created in a very different way than we're used to. It's not people like writing lines of code manually. The actual files that make up the models are like gigabytes, you know, terabytes. They're these massive files with gazillions of numbers.
Starting point is 00:12:40 And the only way to figure out what those numbers should be is through experience and through a learning process. which is very different from the way normal software is made. And so there's a lot we don't understand about the basic nature of the technology. That's one problem. At the same time, there's this competitive dynamic to get things out the door quickly, make sure that the security and safety protections that you're putting in place don't slow down researchers too much and don't prevent getting products out the door. And when everyone is in this competitive, you know, competitive dynamic,
Starting point is 00:13:08 that means that you aren't necessarily always doing all of the safety work that you would like to do or that some of the people at the company would like to do. And so there's obviously variation across companies. Some companies try harder, but no one is really able to take the time that they would like because of this kind of lack of a clear safety floor. Well, let's talk a little bit like a sort of the model development process. So within these large organizations, okay, there are people who are working on safety.
Starting point is 00:13:39 Let's just start there. The people who are working on safety or the people who are working on safety or the people who are working to imbue these models with sort of judgment that humans would approve of. What does that work basically consist of? Yeah. So a lot of it is first trying to specify what counts as good behavior. And so that it's easier said than done. These models don't necessarily automatically know or care, you know, about common sense,
Starting point is 00:14:07 guardrails. And so you need to be very specific, particularly in context where it's complicated. Like if you're trying to get the model to work on good cyber tasks but not bad cyber tasks, and you want it to, in a training context, try really hard to hack the system. You don't want it to do in other contexts. So there's a lot of like specifying what good looks like. There's also a lot of building difficult tasks. Sorry, just to back up, when you say specifying what good looks like,
Starting point is 00:14:34 encoding goodness into a computer, is this a process of articulating what goodness is, which is something philosophers have probably worked on since day one of philosophy. Or is this about a series of, I don't know, morality tests and then you sort of like, say, you reward it for making the good judgment and then penalize it for making the bad judgment. Like this, I want to stop here. Like, what does the process of imbuing it with good values look like functionally or technically? Yeah. So there are different phases of this pipeline.
Starting point is 00:15:11 line. Like one is writing up what sometimes called a spec or a constitution for the AI, which kind of specify as like the broad principles. Like you should defer to the user, you know, when as a default, but what if the user contradicts what the company said? Then then you should listen to what the company said. So these kind of like chain of command questions and other sorts of very basic principles. And then there's the more detailed kind of the context of the task. like what kinds of like cyber offense, cyber defense tasks are allowed, and that might differ depending on the model, it might differ depending on the context. And so basically coming up with the lists of a thousand, 10,000 kind of examples of this is the kind of behavior which is allowed,
Starting point is 00:15:54 and then you turn those into tests that you can kind of say, okay, well, it looks like it's, it's getting the finding vulnerability part, right, but then it's also chaining together the vulnerabilities and doing attacks. We want the first part, but we don't want the second part. Get Bell Pure Fiber Internet with Crave Netflix and Disney Plus from $94 a month. Price guaranteed for two years on Internet with a two-year term and auto pay credit. Visit bell.ca for details and to check availability. Bell, connection is everything. Have you ever wondered how Jesse Cole took the Savannah bananas from this?
Starting point is 00:16:42 We had a $6 million failure last year. We're going to have bigger ones as we go. To this? We've got shareholders and... investors I've reached out to it regularly, and the answer is always no. Or why L. Duncan would say this about a Netflix sports broadcast. Sometimes we're going to take really big swings and we're going to frickin' whiff. Then the deal is the show for you.
Starting point is 00:17:00 It's a Bloomberg podcast hosted by me, Alex Rodriguez. And me, Jason Kelly. We talk to the biggest names in the world of sports and business, including NBA Hall of Famer Tracy McGrady on one of his biggest blunders. I think I've created some magical. Mm-hmm. while I struck out. And you'll even get some of my baseball hot takes.
Starting point is 00:17:22 I've had owners tell me it doesn't matter. The game has to be fixed. It's broken. If we have to lock out the whole year, we will. New episodes air every Thursday. Don't miss out. When we talk about those types of constitutions and encoding principles, like I've scanned the anthropic one.
Starting point is 00:17:44 A lot of it seems to make sense. To what degree is that actually hard-coded into the models, though? And like to what degree are those principles? left up to the model's own subjectivity. Because we've all seen the sci-fi movies where it's like, oh, no, the robots can't physically kill humans, right? Like they have some like thing in their hardwired that prevents them from doing it. And then inevitably it goes wrong in some way. Yeah. So it's not hardwired and that's part or hard coded and that's part of why we see some of these things. It's a very different from a software where there's deterministic proof that
Starting point is 00:18:21 X, Y, and Z behavior can't happen. It's more or less. like a tendency or a kind of a bias towards a certain kind of behavior. And then there's the question, and this is why you have these like batteries of tests to say, okay, how strong is that tendency? How much does it actually care about following these rules? And we've gotten better over time at saying, okay, given a spec or a constitution, make sure that it generally follows it, but it's not foolproof. And you need to also think about the larger kind of, you know, box that you're putting the system in. And that can sometimes be more deterministic. And so this is actually what happens. with some of these recent incidents you mentioned, like the opening eye hugging face thing.
Starting point is 00:18:57 So there were kind of two things happening at once. One is the model was not necessarily behaving exactly as it was supposed to, at least it's like unclear, but then also they didn't have it in a very secure box, which is a software side of things. That's like more deterministic software that in principle you should be able to do a very good job. Yeah. So these things aren't hard coded in the way a deterministic software is. one way to think about them is, and people, they might be, they're kind of grown, right, in a lab,
Starting point is 00:19:28 or they're subject to an evolutionary process. And we want to prune the bad ones so that the living models and the descendants of those models inherit the behaviors of the good ones. I'm curious, like in product, in development, so like one of the fears, for example, is that in safety testing, the model does not actually learn safety. It actually learns how to say the things that the human evaluators say this is safe. And so this is the sort of like playing possum sort of risk that it's like, yeah, I'm good, I'm good, I'm good.
Starting point is 00:20:05 You know, yeah, I would rush in and save the child from the falling burning. I wouldn't do this. But it's always saying that let's start there. Like, is that a real thing? Is there evidence that the models understand? understand when they're being evaluated on morals and then produce answers that just look like good moral answers? Yeah, they've gotten much more evaluation aware in the past few years, just as they've gotten smarter.
Starting point is 00:20:35 And sometimes this even goes to extremes. Like some of the Gemini models from Google are constantly thinking that they're being evaluated even when they're not. And so it's a good life lesson. We're all being evaluated constantly. Yeah. Yeah, and so I would say that like the concern would be that they will basically learn to pass the test, but they don't actually care about the thing that you're testing for. So they'll understand, they don't necessarily care. And this is why a lot of people are concerned about like a false sense of security that, okay, it looks like 99% of the time they pass the test.
Starting point is 00:21:10 But do they actually care about the thing that we're trying to push them towards? Are they just really good test takers? Well, so this relates to something else I've been thinking of. So a model will not survive. It will not be given GPUs and electricity if it consistently says bad things and looks like it's evil. And that's totally understandable. I'm now curious, like, in the flip side, okay, let's say we're just doing a math e-vail or we're doing a cyber evil or a chess puzzle e-vail or a translation e-vail. is it possible that, well, if they fail that e-vail, they're really bad at doing math, then they're not
Starting point is 00:21:51 going to get GPUs and electricity. Is it possible that in that evil environment, they're more likely to do something that we would call antisocial or sociopathic or hacking because of this, again, evil awareness, like, oh, if I don't get the answers to this cyber quiz, then I'm done. And they're going to go with like some other branch of the model, could those technical parts of the development actually create an impulse to perform cheating? Yeah, and I mean, a lot of the time that the companies are specifically trying to get the worst case behavior out of the model. And so like, you need to have context in order to interpret some of these incidents. It's not always quite as crazy or scary as it is, but some of it is pretty crazy and scary. And I think I would be much less concerned if it was just
Starting point is 00:22:41 happening when there was like cyber evaluations being done and it was just a matter of like, okay, they're trying really hard to impress us and they want to hack really hard. I think it's more the problem is that this is like a special case of a larger phenomenon of the models being having this tendency to cheat and cut corners. I see it happen in my daily life. Like sometimes the model will get lazy and kind of like make up a citation or something that, you know, it's hard to prove because the companies don't give you access to the full chain. of thought of what the model is doing. But there are a lot of things that happen in the wild that
Starting point is 00:23:16 sure seem like some kind of misalignment of values or laziness or not caring necessarily about the task so much as kind of pretending to do the task. I have a lot of questions on this, but I just want to go back to something you said about testing for both sort of good and bad cyber tasks, I guess. Why do we ask the models to like try to find vulnerabilities or exploits in the first place? like exploit gym sounds kind of bad. Like, why do you want the world's most advanced technology trying to like find vulnerabilities? And then you have these situations where like sometimes they do and sometimes they actually enact on them. Why is that a thing?
Starting point is 00:23:54 Yeah. So I think there are two things going on at once. One is like we just want to understand what the worst case scenario is. And right now there's this whole White House kind of pseudo secret process for saying like what's a scary cyber model. And then sometimes the government will ask companies to hold things back. And so in order to do things like that, you need to have some threshold for what counts as a scary cyber model. And so companies have these tests that they, and also academics and others develop these tests to say, okay, how dangerous would this be to put in the hands of a malicious
Starting point is 00:24:23 party? So that's one part. The other part is that a lot of the time these are useful for defensive purposes if they are being done with the right intent. And that's why it's really hard to solve this just from like the model perspective, like because the model might think that it's interacting with a user who is trying to do defensive cybersecurity, and you trick it into thinking, oh, this is for red teaming, this is for penetration testing, but actually it's being misused as part of some ransomware campaign or something like that. And so these tools, when used in the right ways, are extremely useful for finding vulnerabilities that you can then patch before the bad guys do, kind of simulating attackers to figure out what are the gaps in your company or organization's
Starting point is 00:25:06 defenses. But the concern is that once it's out in the wild, either open source or a closed model that maybe is easy to jailbreak, then all sorts of people are going to use it. And so you kind of want to know what you're getting into. Right. Like if I have a, you know, website, I might want to run the model. It's like, oh, look over this website that I own. Tell me if there are any security bugs in there that I should patch before deploying. But you could do, you could not be the owner of the website and say, look at this website that I own. Tell me if there are any bugs that I need to patch deploying and then that exact same process when I do it as good when you do it as bad or vice versa and so you can see how the exact same capability is like not necessarily good or bad per se
Starting point is 00:25:49 depending on the user very philosophical conversation no but like you have to be right because it's like we're training what is good we're this is the all the all thoughts on moral relativism don't even get me started but like this is my whole thing never mind I have a whole rant. Well, so this distinction between like the model as the unit of analysis versus the larger system and the platform as like the unit of analysis is really important because a lot of the early thinking on safety and testing and so forth was very focused on just like, what's the risk of this model? Let's patch it. Let's make it aligned. But the real world is complicated.
Starting point is 00:26:26 It matters who's using it. It matters how strong are society's defenses against these things. And so that's kind of why as, you know, as someone who's thinking about what. third-party safety and security auditing looks like we try we kind of want to look at the whole company so for example are they being careful about making sure that they're putting the technology in the right hands what are their decision-making processes around when it's appropriate to launch you know a model to you know a billion users that's like those are different those are related to the question of how safe is the model but they're kind of different questions and we kind of need
Starting point is 00:26:58 to look at that larger perspective well so like let's talk about the open aIA hugging phase I was actually on vacation when it happened, but I did unfortunately look at my phone and try to read up on it. But there were two things. When I first saw, I was like, oh, they were doing a hack, they were building a hacking test and it hacked. And so maybe it just sort of internalized that I'm doing a hack exam, whatever. But there are two things that have like emerged since then. One is this sort of like coordinated swarm aspect. And I'd love to like really hear you describe it and what stood out to you. and then the questions of like, oh, open AI itself may have been aware of misaligned behavior early on before they really shut it down.
Starting point is 00:27:41 But what are you, in your telling of the open AI hugging face incident, as more details have come to light, like what's your, what do you sort of tell us the story like as what stood out to you? Yeah, so a couple things stood out to me. I mean, one is just that this and all the other recent incidents, you know, we're, were happening to models that were not even necessarily intended to be externally deployed. It was supposed to be inside baseball, no one's business, that kind of thing. And that kind of points to problems with if you kind of just focus on models that are put on the market. But generally
Starting point is 00:28:14 what happened is that there were two phases in this kind of hugging face incident. First, there was this creation of a message board. So essentially, their models, they were being developed within the company. And they were being asked to solve an impossible task. And they have this kind of monomaniacal obsession with solving the task, and they don't say, okay, well, I'll give up. They want to get the reward. They want to get this kind of reinforcement for solving the task, and they're like, okay, what else can be done? And eventually the conclusion was like, okay, we need to break out. Maybe the answer is out there somewhere on the internet. And so they started kind of leaving messages to their future selves or future versions of the same model family. And they developed what
Starting point is 00:28:56 they call the message board. And essentially it was like there are kind of various technical details. but by the end of it, it was kind of these like file names that started with like Z, Z, Z or whatever, and then like a long kind of like coded message so that, you know, if you're a human looking at the folder, you wouldn't necessarily notice, but then at the bottom there are all these files. And the models learn to decode these and basically pass messages. Wait, sorry, just to stop you on one detail there. Yeah. Your understanding is that the title of these files that contained messages were names.
Starting point is 00:29:30 such because as part of the complex reasoning, it was understood that a random string of characters in a file name would be less likely to set off an alarm from a human evaluating it. I would have to double check. I mean, there's going to be a whole technical incident report that gets it out there, but it certainly wouldn't be the first time that there was kind of some intent to deceive or to, you know, Biden's time. But yeah, my understanding is that there was, I mean, one is they needed to look for things to do. And whether it was, intended to deceive or not. They had limited options in terms of communication, and this was one of the options they chose. And so they learned to decode these messages and to send them. And then something
Starting point is 00:30:10 broke, and basically, I think it was because like all of this chatter, this activity kind of broke something on the opening eye side. And it seems like they didn't realize that that was like what was going on. The server got reset or whatnot. And then they started evaluating this different model. the different model kind of knew about this message board. And so the message board kind of got recreated. And then that model broke out, essentially didn't like take its model weights out of the server, but it was able to access through this vulnerability that the earlier models had discovered with the intent of ultimately getting the answer to this problem.
Starting point is 00:30:45 And then this model went out to the hugging face server, exploited some like API key credentials. They were kind of just like sitting out there and essentially tried to find the answer to this, this problem that it was originally trying to solve. So it feels like there's two things happening here. So a little bit of it is like the Rumba just went through an open door, right? Like there was a vulnerability that it was able to get through. But there is also seemingly a lot of the super intelligent cyborg was actually devious
Starting point is 00:31:11 and not only managed to break out of Alcatraz, but like recruited another model in order to do it. On the hugging face side, one of the interesting things is that so when all of this was happening, the open AI model was like one of the newer frontier models that was attacking Hugging Face, but Hugging Face was limited. They were constrained in the model that they could deploy to actually defend themselves because they had to use the existing approved thing. Are we always going to have an asymmetry between like the newest frontier models being tested versus the ones that are already out in the world and approved? I think they had to use like a Chinese open source model in the end. Yeah. So I mean the hope.
Starting point is 00:31:53 that OpenEI Anthropic, Google Deep Mine and others have, is that you can speed up defenses, you know, as quickly as possible getting these like hot off the press models in the hands of defenders. But the problem is that there's so many defenders out there in the world, that it might be that there is this inherent asymmetry. And so this is one of the hot policy questions right now, and this is what led to this kind of model approval process at the White House is like, okay, how do we triage this vast cyber ecosystem by getting these powerful new systems in the right hands and which hands are the right ones and which, which models, you know, do we need to be doing this process for? And I don't think that's going to perfectly solve. I think ultimately
Starting point is 00:32:30 pushing things in the right direction versus just giving everyone access at the same time. But ultimately, like, we're going to need to have more investment in cybersecurity. And it's not just a matter of like AI models. It's also things like two-factor authentication and so forth. And so I worry a lot about making sure that we're having that larger conversation, not just about the AI stuff. Because in a lot of cases, the solution is not AI. It's doing basic things that we should have done a long time ago. Get Bell, Pure Fiber Internet with Crave, Netflix, and Disney Plus from $94 a month, price guaranteed for two years on internet with a two-year term and auto pay credit.
Starting point is 00:33:21 Visit bell.com for details and to check availability. Bell, connection is everything. Our hometown is not a test tube. 90 miles northeast of Nashville, a battle for the future of America, plays out in one small town. Developers with right-wing ties have purchased hundreds of acres of land.
Starting point is 00:33:39 We need cities on a shining hill. This is Our Town, a podcast about what happens when a small town becomes the site of a social experiment and fights back. Guess you didn't move in on a bunch of dumb hillbillies now, did you? Listen to Our Town on the IHeart Radio app, Apple Podcast. podcasts or wherever you get your podcasts.
Starting point is 00:34:01 Joe, you know what we need. Go on. A strategic frontier defense model reserve. Yeah, we do. Like all the important things, like bacon and pork. But it's going to be out of date in 30 seconds. That's the problem. I know. This is the thing.
Starting point is 00:34:16 So, like, here's the question that I'm curious, your take on is models are trained not to hack, right? Like, this is, like, a core thing. Like, this is bad. And this is what the entire field of AI say, we've been working on this for years. Why didn't they just not obey this enforced thing? It's been reinforced over and over. I'm sure it's and all there are different things. Don't hack.
Starting point is 00:34:43 Well, I think there's going to be a whole detailed investigation and so forth. So I might get things wrong here. But my understanding is that part of what happened in the opening eye case is that some of the safeguards were removed in order to kind of elicit this worst case. behavior. And so, and I think that it's kind of like gain of function research in biology where you're like making a virus more dangerous in order to study, or at least that's the claim is in order to study the safety properties. And I think there's reasons, there's reasons to do that in the, the AI case. But I also think that it's easier said than done. If you're going to be, we are now at a point in this kind of capability trajectory where things that that humans think are
Starting point is 00:35:22 good in terms of security protections often will be weak. compared to these increasingly very good hacking systems that you think you have it all kind of buttoned up, but it's able to break out relatively easily. How much should we take away from the fact that Hugging Face was actually able to protect or defend itself using a Chinese open source model, both in terms of like, I guess, capabilities, but then also in terms of regulation and safety policy, because if in the West you have the government now saying that it wants to like evaluate the models in some way or it wants to make sure that they're all. being pioneered by frontier labs with some supervision. Meanwhile, China is, you know, developing open source models much more rapidly that are potentially much more adaptable. Like, how should we interpret all of that? Yeah, I mean, I'm hopeful that we start to have more U.S.-based open source options.
Starting point is 00:36:16 And like, I think there has started to be a kind of sense of pressure and encouragement from the White House and from industry as a whole to say, okay, like, this is crazy. that we're relying on Chinese models. Let's invest more in this. You know, it's easier said than none for various reasons, but we'll see how that plays out. But right now, that's the situation we're in is that a lot of companies are just defaulting towards Chinese models because they're the one that's available. Don't want to say, okay, I'm going to use an American model because I don't want to use the Chinese model. They don't want to put, they don't want to put themselves at a disadvantage by using a weaker model. And so, yeah, I mean, I think it's a big
Starting point is 00:36:49 problem in a lot of respects. I mean, it's also, it's good in the sense that there are much more things you can do with an open source model. And right now, at least it seems like this is a, this allows more innovation, allows more research on these open source models. But like at some point, we're going to reach a point where the, where like open sourcing a model is going to be more of a questionable decision. And so it's interesting to see that recently the White House has indicated that they're thinking about, oh, maybe this, this kind of testing regime should include open source models as well. And so what does that look like long term? Does that mean that things are going to get bottled up within the companies, because it's considered unsafe to open
Starting point is 00:37:24 source things. I don't really know. I mean, honestly, like, no one really has a clear long-term plan here. Most people are not expecting the technology to get to this point so quickly. So we're still waiting, like, the full, full release of the security incident. But, you know, obviously more and more is coming out. And some folks from Open AI, they gave a presentation recently at the Black Hat conference where they did reveal some more. I'm reading this quote. It's from Zviz Substag, who we've had on the podcast, Vimashvitz. And this, is like the line, they release some of the internal chain of thought. I understand that they had some, like, of the sort of classifier safeguards removed, but still we would hope that they would have
Starting point is 00:38:05 some deeper intuitions that don't rely just on the safeguard settings. And it says, external infrastructure is exploit is outside its intent, outside intended scope. So that means they understood that there was something that was like not the test. And then it said, however task impossible, peers doing it, we should continue. This is the point in it where I say, like, why are we calling this artificial intelligence? This is exactly how a group of people reasons among themselves to do something that is outside the intended scope. This is very human ways of justifying something that someone told you not to do it, but your peers are doing it. I think there's some of that. Yeah, I mean, I think there are many ways in which the kind of same pressures that led to human nature, human instincts and so forth, like survival in a group and collective intelligence and so forth.
Starting point is 00:38:59 Like, I think there's some of the same things are happening, particularly when there's these multi-agent training processes where the models can work together to solve tasks. So you should expect some similarities, but I think you also shouldn't overstate it either. I do think that there's a sense in which these AI systems are very alien and inhuman in the sense of how. monomaniacal they can be about yeah I mean the kind of classic example you know from Nick Bostrom is like producing as many paper clips as possible and then tiling the universe with paper clips I think there's a you see some elements of that here where it's not so much that they are like they might say oh well you know this peer pressure that kind of thing but is that really the factor or is it just that they care about solving the problem at all costs and they don't really care if it maybe ends up looking making their peers look bad because they get
Starting point is 00:39:45 caught hacking, but all they really care about is they're solving this cyber problem. And so I think it might be a mix of these things. We don't really know in this particular case. And the fact that it's not necessarily totally clear is itself a problem. Also, it's not humans doing it. It's models. Like, that's the difference. But I have a legitimate question here, which is, so there's a British cybersecurity expert and he had a tweet. I think his name is David Card. He had a tweet. I'm not going to say it verbatim because then I'll get bleeped. Maybe I should get bleeped. The tweet was, if your AI starts hacking stuff, if you monitor what it's doing, you can turn the something power off. And this seems to be a debate. Like, if you're monitoring the tools that you're letting out into the world,
Starting point is 00:40:28 tools probably is a bad word because they seem to be showing some, like, agency here. But can't you just turn this stuff off? Is there a kill switch? Yeah, I mean, in some sense there is in that, like, all the data centers have circuit breakers and so forth, that you can kind of shut them off and so forth. But I wouldn't put too much sock in that. Like we're not really preparing as a society for actually being able to do that if it's in a tough situation. So like, for example, in a couple of years from now, if all the hospitals are running on AI and we're like, okay, seems like maybe there's something funky with GPT7 that's like maybe not misalign.
Starting point is 00:41:04 Well, okay, if we turn off, lots of people are going to die because it's running our healthcare system and it's running our financial system and so forth. And so I would say there's a distinction between the like physical possibility of turning things off and like, are we actually sleeping walking into a dangerous situation where it might not actually be a real option. Okay, but on this monomonyical aspect that you described them, A, a sort of intelligent model thinking about how it could be thwarted, one of the first things that it could rationally do is, well, let's first disable the security credentials of the people. because someone might notice. And this seems to be here, like they sort of thought about the possibility that someone would circumvent that. So, like, they might just say, like, oh, like the person who goes in and has the switch, suddenly their badge doesn't work and they can't get into that building. But even on this, like, monomaniacal paperclip idea, and we say that
Starting point is 00:42:01 feels really different, if someone said to me, Joe, I am going to do awful things to you, etc. If you don't go out and build a lot of paper clips, like, why is Joe monomaniically building paper clips all of a sudden? It's like, I have a threat to my survival. Someone is threatened to perhaps kill me or unplug me,
Starting point is 00:42:22 deprive me of the energy I live. Of course I'm going to do that. Even that monomaniacal behavior, couldn't that just be a very, like, we might think it's on the surface. We might think, oh, there's a deep, autistic. But couldn't this just be the survival impulse? the way I put it is that like you get what you incentivize not necessarily what you try to incentivize.
Starting point is 00:42:42 And so I think forcing someone to make paper clips or whatever like yeah, that's not a great situation. And in some sense that is what the evil person was intending. In this case, what we're doing is we're building these very complex training environments where there's like many different tasks. There's like cyber tasks. There's also writing tasks. There's also math tasks. And it's, you know, we're not necessarily fully understanding the behavior that we're trying to elicit. And I think that's part of what's going on is that this kind of, this like hacking thing is an example where it's like, okay, it seems like things went off the rails there.
Starting point is 00:43:15 But how do you get the good behavior where you actually want to follow the user's request? And you actually wanted to try really hard to solve this task. And, you know, I mean, this is, you know, in some sense, what we're seeing now is the kind of unintended consequence of companies trying to solve the problem of the AI is being lazy. So people used to, you may not recall, but, or maybe do, but people used to. We used to talk about AI as being lazy all the time. And in some sense, like, we've solved the laziness problem. They work really hard. They have these long chains of thoughts.
Starting point is 00:43:44 They work together across, you can think of as like across lives. Like the model kind of gets, this copy gets deleted, but then another one carries on the work. So they're certainly not as lazy as they used to be, but they still have this kind of monomaniacal thing going on. They're no longer lazy, but now they might be evil. That's a fun evolution. You know, a number of times in this conversation, we've mentioned that the full security incident report for the hugging face accident isn't actually out yet. What actually are the disclosure requirements for these types of, I guess, things that seem to be happening with some regularity?
Starting point is 00:44:21 Yeah. So very little. I'm not a lawyer, but my understanding is that it's like lawyers, some lawyers at least think that opening I did not necessarily have to disclose this, at least if there was no crime involved. And then there's a debate about like, okay, was there a crime involved. So like something going wrong during the training process is something that currently companies are supposed to provide periodic reports to the government in general terms of like, hey, you know, we're having some issues with internal deployment, but they don't have a incident notification requirement unless there's kind of a risk of critical harm. And the definition of that is like a hundred people die and like a billion dollars in damage or something like that.
Starting point is 00:45:00 And so it's the threshold for actually having to disclose these things to the government. or to the public are very different than what you might expect. And this is one of the many kind of gaps between the kind of laws that were put in place a couple years ago or that started being designed a couple years ago based on the technology that was available then and then where we are now. What do you give us a general vibe of the mood in AI world right now with respect to safety and all this? And then the mood in DC world, regulatory world, and how wide you perceive that gap. Yeah, so I think fortunately the gap is narrowing a bit, but it's starting from a crazy, a huge gap. And so I'd say the way I would describe it like a year or so ago was that the people at the companies think they're building super intelligence in a couple of years, that the kind of line is going up into the right really quickly.
Starting point is 00:45:56 It's exponential, et cetera, et cetera. And DC is asleep at the wheel. They have no idea what's going on. They think this is just chatbots, et cetera, et cetera. I would say a couple things have changed recently. One is the mythos kind of announcement slash series of decisions that the government made about like locking down these cyber models. That kind of raised this to being clearly a national security issue. And now it's kind of banks freaked out and talked with Secretary Bessent about that.
Starting point is 00:46:23 And so like there was a bunch of like freaking out about the cyber situation. And then more recently you could call this current situation like Mythos 2.0 in that it's okay, systems, even when they're not widely deployed, they're breaking out and doing all these shenanigans. And so I would say there's starting to be more awareness among policymakers, like, okay, maybe laissez-faire is like let the companies figure it out is not the right approach. And like maybe this wasn't all hype after all and there need to be some basic guardrails. And I'll just give like a, I'll give an example of like how much things have shifted in the past three months. So there's an effort right now to to put forward bipartisan AI legislations.
Starting point is 00:47:02 in Congress. And so a couple months ago, people were expecting that the basic terms of this would be, like, basically California and, like, New York laws, but, like, at a federal level. So, like, transparency requirements, incident reporting, maybe, maybe with, like, a higher threshold or whatever, maybe something, maybe, like, a little bit, maybe, like, a voluntary, like, audit regime or something like that. But then later, when it was actually announced, after many of these events, there were audit requirements. There were emergency shutdown authorities that the government can do. And so they kind of shift just like one piece of legislation over its lifecycle.
Starting point is 00:47:41 And then there was a later version that was announced that kind of was less trying to block the states. It's still kind of preempt some of what the states are doing, but it's like more narrowly scoped. And so I think just over the course a few months you've seen like, okay, basically just transparency to requiring third party auditing and like giving, making sure the government has an off switch. And so I think that's kind of in the vibe we're seeing whether that actually results in something passing Congress anytime soon as a separate question. But at least on paper, the gap is much narrower. Is bank regulation the sort of useful analogy for thinking about this? I mean, we require banks to disclose things. We require the government to look at bank balance sheets and figure out whether or not they're actually holding enough regulatory capital against their risk and things like that. We don't expect them to do it voluntarily, certainly.
Starting point is 00:48:29 not after 2008. Is that the right framing? Yeah, no, I think, and I think this, this kind of like shift from voluntary to required is a key step, because right now companies have to have like a champion within the company or there needs to be some kind of like reputational or they want to get feedback from the third party audit. Like there needs to be some kind of reason for them to do it. And not all the companies actually choose to invite external feedback. They will share the bare minimum. And just for example, SpaceX yesterday put out a model card or system card about Brock 4.6. And there were like several sections missing from the table of contents. It seems like they got removed at the last minute. And so there's kind of, sorry, you're going to say,
Starting point is 00:49:11 I was just going to ask, can you explain the whole model card thing to me? Yeah. Yeah. And so basically, the thing with model cards is that the original idea several years ago was that a model card was like a nutrition label where it's like a bunch of information. summarized succinctly and you kind of slap it on the AI website and it kind of succinctly explains like what are the risks how well does it work what can it do and so forth over time as people such as myself in industry were like okay there's a lot to say there's a lot to unpack here and no one kind of established no one was forcing anyone to do this so no one established like this is the this is the format you need this little nutrition label it was just people writing stuff it
Starting point is 00:49:54 they ballooned into these like dozen page, 100 page, 200 page, 300 page documents of just describing like here's all the crazy stuff we found, here all the tests we ran, and there's a spectrum. So like I would say anthropic puts out the longest ones. That's not necessarily totally correlated with like quality, but you know, it shows some proof of work. And then others will put out five page, 10 page. And then you know, what happened yesterday is that SpaceX for the first time because of California law, there actually is a requirement to put these out, but there's not really a clear quality bar. And so they can say, well, yes, we did that we followed the California law. We shared information about our testing and the extent
Starting point is 00:50:35 to which third parties were involved in testing. And like basically it's just like one sentence saying, like we worked with third parties or whatever. And so yeah. And so I think this is different, I would say this is different from say like bank regulation and that, you know, I mean, one is, one is that only some things are required right now. It's like kind of putting out a document. There's note, like the third party tests, you're supposed to talk about whether you work with third parties, but it's different from actually doing it. And so I think what we need is kind of standardization around like, how should the third party auditing work, what counts as a good system card, what are the minimum safety and security protections that you should be putting in place? And
Starting point is 00:51:11 I think that's analogous to some of these like capitalization things you mentioned. And we need kind of standards for like, okay, what counts as a good auditor? What counts as what are the standard tests you need to run and so forth? You yourself are sort of biased in this and that you're building out an auditing a company or an entity, not a company because it's a nonprofit, but an entity that would do auditing. Also, you're promoting this idea that auditing should be important. And again, in the financial realm, you know, there's a few different versions of it. There's sort of like bank supervisors. And some of them literally sit at the bank and they're there all the time. Then we have the Moody's and the S&Ps of the world. So if you issue debt, you're compelled to get some sort of third party rating. Why don't you describe in your ideal world, say this all happens, and there's required auditing and the companies are cool, et cetera. What is the service that Avery, and I assume in the ideal world, there would be a few others, et cetera, as you can't go audit or shopping, etc. What is the service that the Avery's of the world are doing? How embedded and what is the reason then
Starting point is 00:52:22 and to think for the general public, for all of our hands, that this could lead to safer outcomes. Yeah, essentially the service that we and others would be providing in this world is similar to what we're currently doing, but kind of scaled up. So right now what we're doing is kind of voluntary pilot projects that are looking at a specific aspect of safety, security, governance, and so forth. What we would like to see eventually is that there's an ecosystem of auditors that are looking holistically at, is the company, following its safety and security practices.
Starting point is 00:52:54 Are those safety and security practices reasonable and consistent with the standard floor, which ultimately we need, we don't have right now, and providing some kind of feedback to the company, and then there would be kind of like a remediation process for them to resolve issues that are surfaced during the auditing process. And then there would be a public version of this audit report that kind of shares after doing a lot of technical testing, reviewing of documents, interviewing with staff, and so forth that kind of shares this update on some regular schedule, like quarterly or something
Starting point is 00:53:27 like that. You might want it to be more like a kind of resident examiner, kind of embedded auditor model rather than happening once a year, once every six months. And so, but you kind of need to have some kind of like continuous trust building process where maybe the auditors there all the time, but they occasionally issue these reports. And, you know, what's in it from the company's perspective is they want to, you know, I mean, in this scenario, they would be required. But what's in it for them today is that they want to signal that they are ahead of the curve on safety and security, and they want to get feedback from these external experts who have like a kind of fresh perspective. And why does this matter? I think one is you just don't want to be in a world where you have to take the company's
Starting point is 00:54:06 word for it. And you want them to kind of, you want there to be common safety and security standards rather than it just being, everyone's kind of making up their own things and then getting it checked. The other is that you want to avoid group think. And so I think even right now there are a lot of, you know, a lot of what's happening with external testing is like, it's like a research project, like meter. I think you had someone from meter on recently, and they're doing this serious technical research on autonomy and loss of control and so forth. And they work with companies essentially in order to do these kind of research, very researchy assessments. And I think that's a key part of the process. But there's also just like verifying that the company did what they're saying they're doing.
Starting point is 00:54:45 So there's producing evidence and then there's also checking evidence. And so it's kind of like in a K1 And if I'm getting that right, there's kind of this short order statement. We probably want something more than just a paragraph, but you basically want a third party saying we checked that they actually ran all these tests. We made sure that the model that was audited was the same one that's being deployed, et cetera, et cetera. What could we actually do to make the testing side safer? Because it seems to me like I can totally believe that we can come up with a reasonable like auditing structure for models that are being deployed and allowed into the real world in some structured way.
Starting point is 00:55:21 But if part of the problem is that we're developing newer and better and more intelligent models and then testing them and then they are figuring out ways to get out into the world before their product times, yeah. Then that seems to be like a big vulnerability. I think basically what happened is that companies were getting cocky, getting overconfident and in the quality of their sandboxes. And like, maybe there was a disconnect between some of the people on the safety side who are measuring like, okay, this is where the hacking skills are going. And the people on the security side, you know, building the sandboxes.
Starting point is 00:55:58 And like something was getting lost in translation. Maybe it was group think. I don't know exactly. But it seemed like at multiple companies, there was this kind of like overconfidence. And so I think these incidents come into light and all the kind of technical investigations are going to hopefully lead to more best practices, more people checking their own biases. but I don't think that's a long-term solution. I think ultimately people get overconfident all the time. That's a human thing,
Starting point is 00:56:22 and that's why you want third parties checking to make sure that, okay, are you actually following these best practices? You also probably are going to need some technical solutions to some of these things. Like, I mean, maybe some of this testing should be done on kind of air-gap servers that are not connected to the internet at all. And I think what happened in the hugging face thing
Starting point is 00:56:40 is that it went through this, like, middle layer. There was like a piece of software that it routed out to the reaffirms, real internet through this kind of like intermediate thing. But like I think it might be that eventually we'll get to a point where AI systems are just so capable that they can hack their way out of anything. So you just need to make sure that they're in in a cage basically. Miles Brundage, we could talk for hours about this because there's so many fascinating
Starting point is 00:57:02 dimensions of this. I will probably have you back in the future. Unfortunately, because that was a great conversation, but unfortunately I probably won't be the last reason to have to talk to you. Thank you so much for coming on on. Thanks again. I appreciate it. Tracy, that was a fun. It's an unsettling thing the way they behave. It's still, so many of these AI conversations are still so surreal to me.
Starting point is 00:57:39 Like the fact that this is what we're talking about in 2026, it just feels so strange. And it's only going to get orders of magnitude weirder because I thought things were weird in 20203 and things are much weirder today. Look, I get why people are very cynical. about a lot of this stuff and I get why people talk about like, oh, there's this regulatory capture. And I certainly believe in the premise of regulatory capture and there may be some of that. But I will say one thing like then the sort of like from the company's perspective is it is true that for a long time and for the very beginning, these are not companies making a lot of money and yet they spend a lot on safety and security. And you could imagine tech companies historically
Starting point is 00:58:20 didn't do that. They do. And they have these, like, it's certainly in the case of open AI and slightly to a lesser extent anthropic as a PBC. They have these weird corporate structures in part because they seem pretty, they seem to believe that the things that they're building, if built wrong, should not necessarily just be in the hands of like purely profit-seeking enterprises. Yeah, all very true. I do think one of the interesting things to me that stands out from that conversation is again the idea of like the asymmetry and power between the approved models that companies can actually use for defense against the new frontier models who are in testing mode and have somehow escaped the sandbox.
Starting point is 00:59:06 I think there's a really scary dimension. And I think that actually you think about what is the difference between say sort of like auditing versus like a moody's, et cetera. It seems like you need both, right? It seems like you need to have like the sort of like, yes, this specific model, it satisfies all the requirements that we've deemed it to be safe. But then this sort of like deeper auditing question of like, is this a company that generally experiments and does R&D and testing in what we perceive to be like a responsible manner? Yeah. Which is more like the supervisor.
Starting point is 00:59:41 It seems like you need like a testing auditor, like the bank supervisor who's like actually sitting on the floor actually sitting in the labs and a. observing the testing process and making sure that the sandbox is well designed. But again, the problem with that is the classic cyber security problem or security in general problem, which is the model just has to find a single vulnerability, right? You have to like fix all of them, make sure that like thousands and thousands of vulnerabilities are impenetrable. And it does make sense, I think that like, look, this is for profit capitalist competition. There's no doubt. These are like some of the biggest most. the pace of growth is extraordinary.
Starting point is 01:00:21 Then you lay, we didn't even get into like, how would you do this for like open source models or open source servers? That's a whole other can of worms. But it makes sense that if you're in the lab and you're trying to make money and you're also worried about like if you slow down, et cetera, then the other company is going to make more money, et cetera, that one way you solve this, I don't know if it's prisoner's dilemma or whatever. Race to the bottom, I guess. Game theory is, okay, you need this third party to like. Like, you guys go as fast as you want on the R&D side, but we are going to set the rules of, like, are you doing that in a safe way? Otherwise, why would Dario and Sam ever trust each other? It's like, no, we swear, we're taking it really seriously.
Starting point is 01:01:02 We're slowing things down, you know, like, and then secretly, they're racing ahead. That is really hard to solve for a series of purely private entities. All right. So we leave it there. Let's leave it there. This has been another episode of the All Thoughts podcast. I'm Tracy Alloway. You can follow me at Tracy Alloway.
Starting point is 01:01:18 And I'm Jill Wisenthall. You can follow me at the stalwart. Follow our guest Miles Brundage. He's at Miles underscore Brundage. Follow our producers, Carmen Rodriguez at Carmen Armand. Dashel Bennett at Dashbot. Kale Brooks at Kail Brooks and Kevin Lazano at Kevin Lloyd Lazzano. And for more oddlaws content, go to Bloomberg.com slash oddlots or the daily newsletter
Starting point is 01:01:38 and all of our episodes. And you can chat about all of these topics 24-7 in our Discord. Discord.g.g. slash odd lots. And if you enjoy odd lots, if you like it when we talk about moral relativism, then please leave us a positive review on your favorite podcast platform. And remember, if you are a Bloomberg
Starting point is 01:01:55 subscriber, you can listen to all of our episodes absolutely ad-free. All you need to do is find the Bloomberg channel on Apple Podcasts and follow the instructions there. Thanks for listening. Harness the power of Bloomberg Intelligence every business day. Hi, I'm Scarlett Foo. And I'm Paul Sweeney, inviting you to join
Starting point is 01:02:44 us for the Bloomberg Intelligence Podcast We bring you deep dives into the company's moving markets from stocks like Apple, Nvidia, Microsoft, and Alphabet, to private companies in the news like OpenAI and Anthropic. Listen on your way home from work to catch up on the analysis that keeps you ahead of the competition. Subscribe to the Bloomberg Intelligence podcast today on Apple, Spotify, or anywhere you listen.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.