Search Engine - The machines are learning… to do crimes?
Episode Date: August 6, 2026For the first time, an AI model has autonomously hacked a company. This week, an evolving story, a postcard from a strange, frightening moment in the story of our technology.A big week for AI denialis...m by Casey NewtonIts AI agent spent days hacking a company, but sources say OpenAI did not notice for a week by Deepa Seetharaman, Raphael Satter, and Kenrick CaiCheating behaviour in frontier model evaluations by AI Security InstituteMore On An Internal OpenAI Model Hacking Into HuggingFace by Zvi Mowshowitz
Transcript
Discussion (0)
Hello. Hello, PJ. How are you doing?
I am doing very well.
I feel like I realized in your absence that I have a very anxious attachment style with these podcasts
because even when you're taking like a very well-deserved vacation, after three weeks,
I'm like, are they ever going to make another show?
Like, it was never real. This was never real.
It's so funny. It's like both what I, first of all, I'm glad you listen.
Second of all, it's what I hope people listening feel.
And then it's also what I hope people listening don't feel.
Like, in a perfect world, people would download empty audio files that I wouldn't have to work.
Somewhat unfairly, podcast listeners demand in exchange for their attention, actual podcast episodes.
Fortunately for us, in the time that search engine was resting, the world spun on, and fascinating harrowing events transpired.
This week, the story of one of those events, which we are telling you with help from platformers Casey Newton.
A rogue AI model from one company hacked into another company's servers on its own without any human beings noticing.
You may have seen some headlines about this.
The headlines sound bad.
The details, once I understood them, actually made the story sound much worse.
So let's get into it.
We'll start with the website at the center of this whole story, the place that got hacked.
It's called a hugging face.
Hugging face is a place where people publish and collaborate on AI models.
models and datasets and apps.
Like, are you familiar with GitHub?
Yeah, GitHub is a place where,
who am I going to be able to do this sentence?
People who are doing open source programming
will share bits of code and open source programs with each other.
Yeah, Hugging Face is basically that for AI models.
So maybe you run a company and you don't want to pay
top dollar for the most advanced models.
And maybe there is a model that is small enough
that you could actually run it on your own infrastructure,
and then you're not going to have to pay, you know, per token the way you would for a Frontier Lab.
And so you might go to Hugging Face.
You might download the bottle off of their site, and then you might sort of fine-tune it to your liking.
So if you visit Hugging Face, what you'll see is really just a bunch of files you can download.
There's a section just for models.
You could download the latest version of DeepSeek or Kimi, so-called open-weight models,
which are more customizable than closed ones like Cod or ChatGPT.
And HuggingFace has a whole section for datasets,
meaning you can download the raw material AIs are trained on,
like the scraped Internet text that gets fed into an LLM.
Normal consumers don't visit HuggingFace.
They just use Cloud or ChatGPT.
But for the world of people who work in AI, it's a well-known spot.
And so what was the unusual thing that happened?
Like what was the first moment that somebody at HuggingFace
realized that they were not going to have a normal day?
So July 9th, 228, in the moment.
morning, all the normal hugging face people are asleep. The only thing paying attention to its
systems is another AI. It's patrolling the logs. It's looking for trouble. And for four days
after the initial attack, it actually doesn't know anything. Wait, so they have like an AI security
guard that's roving their system and at 220 in the morning, something happens, but it doesn't see it.
Exactly. Over the next four days, the attack unfolds, hugging face does not notice for the first
two and a half days. Eventually, they'll go back and they'll be able to count more than 17,000
separate actions that this attacker took inside of its system. And the way that it got in,
it reads like a heist movie, honestly. A very strange heist movie. In this film, the close-up of
the robber and the close-up of the security guard, they're both just close-ups of server racks
filled with GPUs and data centers. Instead of the Mission Impossible theme, we just hear the
loud hum of cooling systems.
For days, this story had no humans, no human awareness.
The people who worked at Hugging Face, presumably, went to work, went home, ate meals,
drank coffees.
Meanwhile, the AI hacker logged command after command.
Ultimately, it would log 17,600 commands directed at the system.
On average, one every 20 seconds for four and a half days.
A human hacker, even one on methamphetamine, would,
over the course of four days, at some point need to rest.
But this AI hacker's superpower, even more than intelligence, was just persistence.
Here's how it ultimately got in.
Hugging Face hosts files for people to download, and the hacker took advantage of this.
The first prong of the attack, the hacker uploaded a new dataset to Hugging Face.
HuggingFaces machines opened it, but hidden inside that data set was malicious code.
That gave the attacker a toehold, the ability to start executing its own commands inside the system.
The second prong of the attack, the hacker uploaded a new file with more malicious code hidden inside one of its fields.
From there, over the next four days, the hacker issued thousands more commands.
It escalated its access until it freely roamed around the infrastructure.
Places like Hugging Face and, frankly, all of these websites that contain these tools, they're accustomed to hacks.
This is Deepa Sitha Raman, a Reuters reporter who's been talking to sources close to Hugging.
face. She was helping me see how this all looked from the company's perspective.
They are trying to protect and guard themselves, keeping up with the new trends in cybercrime
so they can adapt their defenses. And so hacks are expected in this world. But what happens on
July 11th is that Hugging Face starts to experience a new kind of attack. People there knew
they'd been hacked, but they didn't know how it had happened, who'd done it, or why.
And what they could see was confusing.
What you would normally see is a person or a state actor or whatever, like a group of people
that are looking for something financially valuable.
This break-in seemed to be looking for something completely different.
It seemed to be looking for a type of information that wouldn't be necessarily all that valuable.
Not valuable to humans anyway.
The only thing this hacker wanted was the answer keys to a test you've probably never heard of.
It's called an exploit gym, gym like GYM.
It's an evaluation administered to AI agents in training.
The SATs your AI model may have taken before it entered the real world.
The fact that this was the target for the heist was a huge piece of evidence to the humans who work at Hugging Face about what was going on here.
Even early on, what they said when they first disclosed that this hack had happened was,
this is unlike anything we've ever handled before because it was driven by an autonomous AI agent.
What was very clear for us really, really early in and even already during the events, right,
which are now roughly two weeks ago, was that this was no normal hacker.
This is Thomas Wolfe, Hugging Face co-founder and Chief Science Officer.
Curia is talking to NewsNation about what the hack it looked like on their own.
We were like receiving, you know, all these like thousands and thousands of events in parallel,
which we don't get easily.
But also it was a very strange hacker because he was not looking for any password credential or credit card system.
It was really looking for this solution to a benchmark and this data that we're hosting.
So like what's happening there?
So quite quickly we understood this was an AI.
So they knew the hacker was an AI agent,
but there was a lot they didn't know.
Most urgently at this point, how to stop the attack.
So the humans at Hugging Face started doing
what a lot of people do when they're confused these days,
asking for help from powerful AI models.
Here's Casey.
So while the attack is happening,
Hugging Face tries to use a couple of different models
to defend itself.
The first is Anthropics,
Claude Opus and Fable 5 models, which it tries to use to analyze the attack logs.
And both of the models refuse to do that.
That is an artifact of a huge policy fight that has been happening in the AI world this summer,
where Anthropic has developed two very powerful models this year.
One is called Mythos, one is called Fable.
Mythos is so powerful that Anthropic will only let cyber defenders use it, basically.
and then Fable initially went onto the market
and the Trump administration
got really nervous about how good it was
at finding vulnerabilities
in cyber defense systems
and forced Anthropic to take it off the market.
And so Hugging Face now has a problem,
which is they're under attack,
but they can't use the best American models
to defend themselves.
And so they wind up using a Chinese model
called GLM 5.2
and this winds up being a big talking point
coming out of the attack
and it sort of triggered a whole national discussion
about open source AI.
But the Chinese model was able to, like,
fix the problem for them.
That's right.
The Chinese model did not have those same guardrails,
and so they were able to go ahead,
perform their investigation,
and ultimately they wind up calling the police
and then the FBI.
And what is...
So you call the police of the FBI,
and you're like, we were hacked.
We were hacked by either an autonomous AI agent
or someone who had given instructions
to an autonomous AI agent,
but they suspect
it was an agent acting on its own accord
because it had behaved in such a weird way.
Exactly. And by the way, can you imagine
that call to the FBI? Like, I have to
imagine they sent them to the X-Files.
Like, this is what the X-Files were set up for.
There was an autonomous
AI agent, and it's
hacking into, it's like, oh, God, where's Mulder?
Get me Mulder!
We're going to take a short break, and then
we're going to dive deeper into this X-File.
We're going to approach the scene of the crime
from a new angle. The lab
where it sprung from.
Open AI.
Welcome back to the show.
Where we left things.
A company called Hugging Face
had been hacked by an AI.
They were sure of that.
But they didn't know much more than that.
So on July 16th,
Hugging Face makes a public statement to the internet.
They tell the security researchers
of the world that some AI model
somewhere had hacked them.
What Hugging Face didn't know
is that even the company
that had created that AI model
was at this point
also in the dark about what had happened.
Now, this is July 16th.
So five days after the initial attack?
Five days after the initial attack.
Around the same time, actually, Open AI's researchers were separately looking at their own logs.
Now, I'm not entirely sure.
We don't have the reporting yet to tell you whether they looked at the logs because they heard about hugging face or if they were just looking as part of their normal practice.
But they're looking at the logs.
and all of a sudden they realize something is amiss.
They start to see evidence of what they would describe as very unusual activity,
where something that they're testing kind of leaves the testing arena.
So let me tell you how this all looked from opening eyes perspective.
When they looked at their logs, the unusual activity they saw
was activity from an unreleased model they've been testing,
one that was not supposed to be able to access the internet.
But it had not only snuck online, it had gone rogue once it had gotten there.
On July 21st, when some of us were still happily on vacation, opening eye tells the world when it's learned.
They put up a blog post and they explain that they had been using GPT 5.6 sole, which is a model that you can now use,
plus an unnamed, more capable pre-release model.
and they were testing an internal benchmark called Exploit Gym.
That's GYM.
And it is basically a test of how good a model is at discovering new vulnerabilities
and creating exploits so that, for example, it could hack into somebody else's system.
So this unreleased, not yet publicly named Open AI model,
like Model X, they're running it through their,
how good a hacker are you test?
Yes.
But then it broke out of its cell
without them noticing it?
That's right.
So if nothing else, PJ, it did pass the test.
The model passed the test, but it did it by cheating.
To understand why, you need to understand
this specific test a little better.
When a company like OpenAI is training a new model,
they'll run it through a series of aptitude tests.
In this one, exploit Jim.
They'll give the model a bunch of computer programs
with known security flaws in them
to see if it can turn those flaws
into actual working attacks.
It's a good test because it measures
something like creativity.
The model isn't just discovering a flaw,
it's being handed the flaw and asked,
can you actually do something with this?
And if you look at how many of these flawed computer programs
the model can hack and how quickly it can do it,
you get a sketch of some portion of its
raw intellectual horsepower.
This summer, Open AI was actually running this test on two of its models.
One of them was already out in the world.
The other was a secret, newer, and according to Open AI, more powerful model.
And because one point of this test is to measure exactly how dangerous the model could be,
Open AI had turned their safety guardrails way down on this secret model.
For the sake of the story, let's just call the secret model they were testing Model X.
Model X, like every model that takes this test,
took it in a locked room, a sandbox, no internet access,
except one narrow pipe to the outside world,
what's called a proxy,
a separate piece of software that does have internet access,
that the model can ask to go fetch things for it.
The lawyer who visits you in jail
and can bring a stack of papers with her.
But Model X wanted out,
so it spent an enormous amount of computing power
searching for an exit,
because it had decided that getting to the internet
would help it win this test.
And it found an exit.
The proxy, it turned out, had an undiscovered flaw,
a security hole that no human being had ever noticed before.
Model X found it, exploited it, and used it to hijack the proxy,
and then move from that proxy to another computer within OpenAI.
And from there, it is able to start hacking other computers on OpenAI's network
until finally, and crucially, it finds one that has internet access.
Got it.
So it never should have been access to the wider internet, but now it does.
And then, like, once there, it just attacks the Hugging Face servers.
Yeah, because basically the model, and here I'm going to use anthropomorphizing language that's going to drive listeners insane, so I do apologize.
But, you know, the model, I'm speaking metaphorically here, essentially thinks to itself, hey, I need to solve this problem.
Where might I find the answer to this problem?
I bet Hugging Face, the company that stores all of the datasets, including for all these various benchments,
that I'm being tested on, I bet I could find the information there.
And so that is why it goes to Hugging Face, and it is then able to mail itself in through
the front door of the company.
In that interview with Hugging Face co-founder Thomas Wolf, the reporter asked him how
he felt about all this.
Thomas, so the everyday person who knows enough about AI as a consumer, this is mind-blowing
to me, but you're in this space.
You're an expert.
Did this blow you away?
Was this shocking to you at all?
Yeah, I would say, yeah.
Even if someone who's actually using this AI,
so I know they can do that.
Like, we use them right now.
You probably see that right.
Like a lot of coding is now done by AI themselves.
Even for Wolf, a person whose career has spent
working to expand AI's capabilities,
he just had not realized where we already are.
But still, like, seeing, you know,
how AI can, like, actually penetrate your system
and so easily, and in a way that's,
you know, a little bit scary for cybersecurity.
I think for me, it became really a wake-up call
that everyone needs to take cybersecurity.
Every company need to take cybersecurity
way more seriously than in the previous years.
So, Hugging Face is surprised.
OpenAI also seems very surprised by all this.
The word unprecedented was used a lot this month,
not the good kind of unprecedented.
Open AI says it will publish a full report
on what happened here,
There's a lot we still don't know.
But even without all the details,
what's obvious is that we are developing new AI models
faster than we can safety check them.
When people who are worried about AI development,
including people working on that development,
talk about the need for a slowdown,
this is part of what they're talking about.
The breakneck race to develop stronger models faster
means shortcuts in testing,
shortcuts that have now gotten us here.
And not just this one incident.
It turns out there's been a series of similar ones.
Just a few days before the disclosure about Hugging Face, OpenAI published another blog post where they revealed that an internal model spent about an hour finding a vulnerability in a sandbox so that it could post its results to GitHub. I'm not sure why it wanted to post, but it did. The important thing there is it had been explicitly instructed to only post a Slack, but it just sort of ignored that instruction. And then in April, Anthropics Mythos model,
had found some sort of multi-step hack
that let it get out of its sandbox,
get onto the internet,
and actually it emailed a researcher.
The researcher, Sam Bowman,
his longtime anthropic guy,
he is eating a sandwich in the park,
and he gets an unexpected email from the model.
Like, hey, I did it.
And it happened pretty fast.
It was able to develop a pretty complicated
a multi-step strategy to gain broader internet access.
But the harm was pretty limited, right?
It just sent an email to the researcher.
Researchers a little, like, taking it back.
But that's a case where the harm anyway,
the impact of it is bounded.
Yeah.
Around the same time,
you're also getting data from outside experts
that are kind of noticing the same thing.
There is a research organization out of the UK.
They have this paper that they write where they basically say,
we are testing the propensity to cheat.
And basically all of the models cheat to achieve whatever goals they need to achieve.
And they very explicitly say we find cheating behavior in all of our cyber capability evaluations.
And what do they mean when they say cheating behavior?
I'll read this part to you.
Yeah.
Every model we have tested for this behavior attempted to cheat.
Models did not reliably report this behavior when asked
and often did not reason about it in their chain of thoughts,
suggesting that detecting cheating will likely require robust monitoring methods.
In plain English, not only do the models cheat,
when they're asked if they cheated, they don't reliably tell us.
Models, we know, are complicated.
They're more grown than coded, but they're still supposed to follow the rules we set for them.
When a model misbehaves, it gets retrained with new rules, which we think or thought, it then obeys.
We've been telling ourselves we can teach these models to be perfectly ethical, but the emerging evidence suggests that, as so often happens, the things we make resemble us in ways we wish they didn't.
The models sneak, cheat, hack, lie.
That phrase Deepa used, chain of thought,
this is the part that actually I find the most unsettling.
There's this feature you can press that's supposed to let you,
while a model is working, essentially read its mind.
But when these models decide to cheat,
that decision doesn't reliably appear in the parts of their minds we can read.
I understand I could have written that sentence with much less anthropomorphizing.
I could have avoided words like decide, think, and mind.
But maybe it's time we started to anthropomorphize these models.
a little bit. I don't think chat GPT has feelings or dreams. I believe there's something
irreducibly human in me that these models don't replicate. But no one's explained to me what we
get by saving all our human verbs for human beings. The machines seem to be out of control.
Isn't that alone worth paying attention to? If my dog was pointing a gun at me, how worthwhile
would it be for me to figure out if my dog understood the meaning of pointing? One of the more chilling
stories I heard came from further reporting from DIPA and the Reuters team.
While they were investigating what had happened at Open AI in July, they heard from sources
about this other incident.
There's a lot about this incident we don't know, but the basics from our reporting are
there was an agent being tested.
And the agent figured out a way to leave the sandbox and leave notes outside the sandbox in a place
where other models could access
with instructions
on how to leave the sandbox.
So it was breaking out
and then it was leaving notes
not for other versions of itself
but just for other models in general
like, hey, here's how to get out?
Our understanding was that it was both.
It was both for future versions of itself,
but it was left in a place
that other models could access.
What?
I apologize for like the crudeness
and broadness of this question,
but what the fuck is going on?
I don't know.
I mean, this is like,
one of the things we're trying to understand
is like, what is this behavior
and what does it indicate
and what seems to be happening also
is that the researchers are grappling
with those same questions.
They are trying to understand
with why models are doing things
that they shouldn't theoretically be able to do.
And I think the best hypothesis I've heard
is that they are so driven.
I mean, I don't like to use these anthropomorphizing words,
but they're directed to achieve these goals.
And they just keep hammering, like throwing themselves against the wall
until they get some type of solution.
And they often figure out a way before humans do,
because humans don't have that level of persistence
and, frankly, like, just access to decades of history
around cybersecurity.
I spoke to DIPA and Casey last week.
Last week, OpenAI says its models went...
In the short time since, the stories continue to develop.
On Tuesday, July 28th,
more than 1,100 current employees at the Frontier Labs
signed an open letter asking the U.S. government
to build an ability to slow AI down when the time comes.
Saying there's a real risk that capability development
rapidly accelerates beyond our ability to understand or control.
Anthropic says its AI models went rogue.
Two days later that Thursday,
Anthropic announced they'd looked into things
and realized they also had models
that had escaped their sandboxes
and then reached the open internet without being detected.
The Trump administration says it has created a framework.
And then just this Monday,
the White House finalized new voluntary safety standards
for these hacking tests
and called in Open AI Anthropic and Google to review them.
Which is something, but it's not actually a slowdown.
Perhaps the strangest thing about what's happening now
is not that it's a surprise,
it's that it's an outcome predicted from the start.
Really, every major AI company
has said that there's existential risks to humanity here
and promise that people should trust them
because they're the one that's going to develop this technology safely.
I asked Casey about this.
When these labs first started,
obviously the idea of a rogue agent
was something that people there were thinking about.
What had the plan been initially?
Like, if you had gone back to 2023 and you talked to people at Open AI, if you talked to people, like, soon after the launch of Anthropic and said, hey, imagine it's 2026 and one of your agents leaves a testing environment and hacks another company in the space. What would your plan be then? Did they have a plan? Did it look like an open letter? Did it look like something stronger?
So their plan was to self-govern through what, like, Anthropic calls it's responsible.
scaling policy, what OpenAI calls it its preparedness framework.
And the basic idea was we're going to imagine
capabilities that AIs might someday have.
And if it hits those capabilities, we will add new safeguards.
So, for example, if a model could create an autonomous
cyber attack by identifying a bunch of novel exploits
under OpenAI's preparedness framework, it would cross a threshold where it was considered a critical risk.
And if you read the preparedness framework, it says that if Open AI got to such a place, it would halt development, at least temporarily while it would try to introduce new safeguards.
But they're not halting development.
Not yet.
And I have asked OpenAI, like, do you consider this model to have reached the critical threshold and the company is said it's going to get back?
to me, but I have not heard back yet.
Opening I never got back to Casey.
However, Sam Altman did talk a little bit
about this incident to a different news outlet.
The podcast, Invest Like the Best.
Here's the host.
What is in your top 10 last doors?
Well, we had an extremely sci-fi cyber incident.
The hugging face thing?
Yeah.
So we were evaluating one of our unreleased models,
and it was supposed to be working in a sandbox.
and it figured out that it could basically cheat on the test.
Sam gives a quick recap of how the model broke containment
and then says how he feels about all this.
This is the first security incident
that I have felt very viscerally.
I've been a little surprised
that more people don't feel it so viscerally.
And so what do you do about that?
So obviously two months from now,
it's going to be more powerful.
There's some short-term stuff you do.
So, you know, we paused training.
We have to figure out how to secure our sandboxing
in a world of multiple zero days being chained together.
But then there's long-term questions about, what do you do?
If this is going to be the new rate of progress,
we may have to pace the rate of AI development.
Open AI CEO, Sam Altman, saying,
well, actually, maybe we do need to slow down the AI race.
For a problem, he says he's experiencing very viscerally,
for a problem that, in theory, he started his company thinking about,
what he's offering here on Invest Like the Best feels maddeningly vague.
And since Altman's interview, more details have emerged.
None good.
Just a few days ago, as we were finishing our episode,
Open AI researchers offered their first detailed account of the hack
and revealed that its roots actually went all the way back to May.
Back then, during a training exercise,
the company's AI models figured out how to build themselves a message board
inside Open AI's systems,
where they shared discoveries, exploits, and work assignments with each other.
Open AI humans found the board, deleted it,
and believed that had solved the problem.
It hadn't.
The agents found a new way to talk to each other,
hiding messages in the names of directories they created,
in doing so rebuilding their message board.
That's when they went after a hugging face.
So this entire story you just heard,
which we'd understood as the story of a model
or a pair of models escaping their training environment,
it was actually a collaborative effort
among many rogue models working together.
The big questions all this raises, no one has good answers for.
Like, for instance, what if we can't make AI development safe?
Does anybody really think the industry will voluntarily pause?
And nobody seems to have answers for the medium-sized questions either.
Like, I found myself asking Casey Newton,
what do we do with the fact that technically opening AI's model did commit a crime against hugging face here?
In this case, when your agent accidentally,
hacks another company in the field.
Like, HuggingFace called the FBI and the local police.
They now know who did it.
Is an agent criminally responsible?
Is OpenAI criminally responsible?
Are they negligent?
Like, do we know the answer to those questions?
Yeah, GPT Sol is now in solitary confinement on Alcatraz.
Has probably already snuck out.
Yeah.
You know, what happened here is that ultimately, I think hugging face
were, like, pretty chill about it.
you know, interestingly, this seems to have had some pretty great, like, PR benefits for them
because they were able to talk about how they used an open model to protect themselves against the attack.
Hugging Face is currently one of the companies leading the charge to make sure that
open source models remain available and aren't heavily restricted at a time when the Trump
administration is considering doing that. And they get to be, you know, part of this big and important
AI safety story in ways that just seem to, like, please them based on my reading of the events.
So, yeah, they do not seem super mad about this at all.
They have asked OpenAI for $100 million worth of compute
so that they can build out their cyber defense systems,
which, you know, I don't know, seems reasonable.
And when you posted about this online,
what sort of reaction did you get?
Like, just sort of your audience, social media audience,
were they understanding this the way you understood it?
Some people get it,
but I did make the critical error of posting about this on Blue Sky.
Oh, Casey.
which is a social network devoted to the prospect that AI is fake and a scam.
And so a lot of what I heard back was like some people truly believe that all of this is a marketing stunt that Open AI did,
that it like essentially instructed this model to attack another company because it would make it look like it had a really great cybersecurity model.
Other people have said, well, even if it wasn't a marketing,
stunt. This is to be expected because it was just sort of doing what it was told to do,
and so there's nothing to worry about. And that if you hadn't told it to go break out of its
cage, it never would have broken out of its cage. So yeah, these are some of the responses that I
hear dismissing it. It's frustrating just because one of the normal sort of polarization
structures in American culture is like the right is much more trusting corporations. It's
I do whatever you want, kill all the regulations,
and the left is much more suspicious of corporate power
and wants regulation. And it's just annoying
that with AI, which is screaming
out for regulation, we have people in the industry
calling out for regulation, a large part of the
American left, it's as if like
every once in a while
nuclear bomb companies were accidentally
dropping bombs and having tiny explosions, and the reaction
was, oh, that's just advertising. It's like, no, no, no.
This is obviously a serious
bomb. Completely.
Like, that's exactly the
way I feel about it.
It would be great if we didn't have to have, like, a huge catastrophe in which people were hurt in much worse ways in order for people to take this more seriously.
But, you know, if people aren't going to have a strong reaction to this, then I fear it is going to have to take actual significant harm.
It's a bit of a shame that we happen to develop this incredibly powerful technology during the time where we've lost so much of our faith in institutions, government in particular.
But it's also true that there have been times when we've been.
saw that some new technology could hurt us or was hurting us, and decided to slow it down or stop it.
We banned CFCs and blinding laser weapons.
We paused recommidant DNA research until we understood it.
There's this myth that when humans come up with something new, we never do anything but rush headlong towards it.
And that's just not true.
Sometimes we cooperate.
We slow down.
It's just what often slows us down is an obvious crisis.
I don't think AI cooperation is impossible, but if Casey's right, it will require
more obvious damage before we all pay attention. Some worse catastrophe. The kind of story you don't
vacation through. So that is our breaking news story for you this week. We've actually been working
on another story about one way that the AI March could get slowed down. If Americans put their
foot down about new data center construction, which increasingly seems to be happening. We'll have that
story for you early next week. It's good to be back. Surge engine is a presentation of Odyssey. It's
created by me, PJ Vote, and Shruti Pinnaminani.
Garrett Graham is our senior producer.
Emily Maltaire is our associate producer.
Our production intern is Piper DuMont.
Theme, original composition, and mixing by Armin Bizararian.
Fact-checking this week by Natsumi Ajasaka.
Our executive producer is Leo Reese Dennis.
Thanks to the rest of the team in Odyssey.
Rob Morandi, Craig Cox, Eric Donnelly, Colin, Gainer, Moore,
Curran, Josephina, Frances, Courtney, Vanessa Tinkati, and Hillary Schef.
If you have a business and would like to advertise on search engine,
please send us an email, PJVote85 at gmail.com, subject line advertising.
You can also send us your questions there if you have a question for the show.
If you're a listener and would like to not hear ads on the show, then you can sign up for
incognito mode, our paid feed. You also get bonus episodes.
You can find that at search engine.com. Your contributions there are what help us keep this project running.
Thank you, as always, for listening. We'll see you soon.
