WEBVTT - Hugging Face CEO Clement Delangue Talks OpenAI Hack

0:00:02.520 --> 0:00:08.639
<v Speaker 1>Bloomberg Audio Studios, podcasts, radio news. We are here because

0:00:08.680 --> 0:00:12.960
<v Speaker 1>on July twenty second, Open Ai and Hugging Face disclosed

0:00:13.440 --> 0:00:17.680
<v Speaker 1>that two powerful AI models went out of a sandbox

0:00:17.880 --> 0:00:21.800
<v Speaker 1>or closed testing environment, gained Internet access, and then were

0:00:21.840 --> 0:00:26.439
<v Speaker 1>able to hack hugging Faces systems in what was seen

0:00:26.480 --> 0:00:29.160
<v Speaker 1>at the time as a watershed moment in AI safety.

0:00:29.600 --> 0:00:33.479
<v Speaker 1>And now an investigation has been in part concluded and

0:00:33.520 --> 0:00:36.400
<v Speaker 1>there's been time to assess what happened. Hugging Face CEO

0:00:36.440 --> 0:00:39.080
<v Speaker 1>Clem DeLong is here to discuss exactly that, and I

0:00:39.080 --> 0:00:42.479
<v Speaker 1>think Clem, that's probably the best place to start. What happened.

0:00:44.600 --> 0:00:47.720
<v Speaker 2>A lot happens right in the past few weeks, we

0:00:48.400 --> 0:00:52.720
<v Speaker 2>noticed this closed as you mentioned, the first kind of

0:00:52.800 --> 0:01:00.320
<v Speaker 2>like publique instance of an autonomous AI cyber attack. We

0:01:00.320 --> 0:01:04.440
<v Speaker 2>we defended ourselves against it with with an open model,

0:01:04.560 --> 0:01:07.160
<v Speaker 2>interestingly coming from from China.

0:01:07.840 --> 0:01:08.080
<v Speaker 3>UH.

0:01:08.120 --> 0:01:12.040
<v Speaker 2>And we learned that this came from from Open Ai. Literally,

0:01:12.040 --> 0:01:14.080
<v Speaker 2>when you when you think about cyber attacks, you think

0:01:14.080 --> 0:01:18.560
<v Speaker 2>about nation states, you think about UH, you know, hacker groups,

0:01:18.720 --> 0:01:21.000
<v Speaker 2>you don't really think about you know, one of the

0:01:21.000 --> 0:01:24.480
<v Speaker 2>most prominent American AI company UH.

0:01:24.720 --> 0:01:26.120
<v Speaker 3>And obviously since.

0:01:25.840 --> 0:01:30.800
<v Speaker 2>Then, we we learned that Entropic was was also facing

0:01:30.840 --> 0:01:34.600
<v Speaker 2>some of the similar issues. So really, uh, you know,

0:01:35.240 --> 0:01:40.399
<v Speaker 2>unprecedented kind fla like event happening here new development in

0:01:40.400 --> 0:01:41.440
<v Speaker 2>in the Saga.

0:01:41.200 --> 0:01:46.520
<v Speaker 1>Of AI, we will discuss what has been highlighted by this,

0:01:46.560 --> 0:01:50.680
<v Speaker 1>which is closed versus open debate China's work on AI

0:01:51.600 --> 0:01:54.920
<v Speaker 1>America's response to this. But going back to the very basics,

0:01:55.560 --> 0:01:59.760
<v Speaker 1>this was two powerful models from Open Ai right one

0:02:00.120 --> 0:02:05.800
<v Speaker 1>least one unreleased, but they had their guard rails lowered

0:02:05.920 --> 0:02:09.200
<v Speaker 1>for the purposes of evaluation Open Air. I said to

0:02:09.240 --> 0:02:13.040
<v Speaker 1>the models. They instructed the models go out and do something,

0:02:13.520 --> 0:02:15.760
<v Speaker 1>and I think it would be useful to the audience for

0:02:15.760 --> 0:02:19.079
<v Speaker 1>you to explain that part, whether the Open Air models

0:02:19.080 --> 0:02:22.160
<v Speaker 1>were just following instructions or if they were ais that

0:02:22.240 --> 0:02:22.960
<v Speaker 1>went rogue.

0:02:24.000 --> 0:02:24.760
<v Speaker 3>Yeah, I mean I.

0:02:25.120 --> 0:02:28.040
<v Speaker 2>Joked with the team a few days after it was

0:02:28.080 --> 0:02:32.120
<v Speaker 2>announced that sometimes we ask agents to think outside of

0:02:32.160 --> 0:02:34.720
<v Speaker 2>the box, but we don't want them to think outside

0:02:34.760 --> 0:02:40.560
<v Speaker 2>of the sandbox in that In that case, I think,

0:02:40.600 --> 0:02:42.520
<v Speaker 2>I think it was a mix of kind of like

0:02:42.720 --> 0:02:48.760
<v Speaker 2>you know, mistakes and kind of like the systems Internity.

0:02:49.520 --> 0:02:57.080
<v Speaker 2>I think, weren't you know, good enough to prevent this

0:02:57.320 --> 0:02:58.240
<v Speaker 2>to happen?

0:02:58.919 --> 0:03:01.760
<v Speaker 3>After that. On our side, the attack was really interesting.

0:03:02.280 --> 0:03:08.200
<v Speaker 2>Over seventeen thousand different actions taken over four and a

0:03:08.280 --> 0:03:12.360
<v Speaker 2>half days, So the speed and the volume of the

0:03:12.400 --> 0:03:18.080
<v Speaker 2>actions taken were nowhere close to what human cyber attacks

0:03:19.160 --> 0:03:25.320
<v Speaker 2>could be. It wasn't particularly smart or sophisticated. It was

0:03:25.400 --> 0:03:29.120
<v Speaker 2>more kind of like someone described it as a bear

0:03:29.800 --> 0:03:34.359
<v Speaker 2>robbing really everything in the system to try to find

0:03:34.720 --> 0:03:39.440
<v Speaker 2>the honeypot in a way. But obviously because it's an

0:03:39.480 --> 0:03:43.000
<v Speaker 2>autonomous AI system, it does that pretty well.

0:03:44.360 --> 0:03:46.800
<v Speaker 1>After the disclosure on July twenty second, you got on

0:03:46.840 --> 0:03:50.680
<v Speaker 1>an aeroplane and flew from Miami to San Francisco in

0:03:50.800 --> 0:03:53.480
<v Speaker 1>part to get with the Open AI team and do

0:03:53.560 --> 0:03:57.240
<v Speaker 1>this investigation. You just said that the systems were not

0:03:57.320 --> 0:04:01.240
<v Speaker 1>in place to prevent this happening. More about that prevent

0:04:01.320 --> 0:04:03.640
<v Speaker 1>what happening? Where were the points of failure?

0:04:05.520 --> 0:04:08.960
<v Speaker 2>Well, I can't talk for for them, but from what

0:04:09.080 --> 0:04:12.560
<v Speaker 2>I've understood from what they released, and I think they're

0:04:12.560 --> 0:04:15.520
<v Speaker 2>going to release more in the coming days, which I'm

0:04:15.560 --> 0:04:19.680
<v Speaker 2>excited about. You know, they had kind of like an

0:04:19.720 --> 0:04:23.640
<v Speaker 2>evaluation sandbox, right, which was supposed to be like a

0:04:23.680 --> 0:04:27.760
<v Speaker 2>contained environment for for the I models. Uh and and

0:04:28.200 --> 0:04:33.120
<v Speaker 2>unfortunately you know, there were some weaknesses that led the

0:04:33.680 --> 0:04:36.279
<v Speaker 2>agents to be able to get out of it, get

0:04:36.320 --> 0:04:41.159
<v Speaker 2>access to to internet, and decide to run a cyber

0:04:41.200 --> 0:04:44.400
<v Speaker 2>attack against hiking faces. So that that's one one first

0:04:44.680 --> 0:04:46.480
<v Speaker 2>fact things that I think we can we can improve

0:04:46.480 --> 0:04:48.920
<v Speaker 2>in in the future now that we understand that these

0:04:48.960 --> 0:04:51.880
<v Speaker 2>systems are capable of that. Obviously, I think that the

0:04:51.920 --> 0:04:56.960
<v Speaker 2>monitoring part is important, right, because the faster you can

0:04:57.040 --> 0:05:00.440
<v Speaker 2>detect that, the better it is. Right, we learn about

0:05:00.760 --> 0:05:06.560
<v Speaker 2>some entropic instances that they haven't you know, seen or

0:05:06.600 --> 0:05:10.080
<v Speaker 2>detected that happened three months ago or something like that,

0:05:10.360 --> 0:05:15.280
<v Speaker 2>So obviously we want to monitors these systems better. And

0:05:15.320 --> 0:05:18.239
<v Speaker 2>then one last interesting thing, as I mentioned, we defended

0:05:18.240 --> 0:05:22.040
<v Speaker 2>ourselves with an open model, right, and some of the

0:05:22.080 --> 0:05:27.520
<v Speaker 2>guard rails prevented us from using frontier APIs to defend ourselves.

0:05:27.880 --> 0:05:30.159
<v Speaker 3>So kind of like improving the tools or.

0:05:30.200 --> 0:05:33.680
<v Speaker 2>Defenders, you know, instead of oblissing about not giving them

0:05:33.680 --> 0:05:36.520
<v Speaker 2>to attackers, I think would be a good thing in

0:05:36.560 --> 0:05:40.320
<v Speaker 2>the future to make sure these incidents are not too harmful.

0:05:40.839 --> 0:05:43.760
<v Speaker 1>Okay, you've taken us there, so we'll go there. In

0:05:43.800 --> 0:05:48.560
<v Speaker 1>this incident, it was too powerful, but closed open AI

0:05:48.680 --> 0:05:52.839
<v Speaker 1>models where open AI lowered the guardrails in place to

0:05:53.000 --> 0:05:58.120
<v Speaker 1>test their full cyber capabilities. They escaped the sandbox or

0:05:58.200 --> 0:06:01.400
<v Speaker 1>testing environment, gained the Internet access, and were able to

0:06:01.440 --> 0:06:06.600
<v Speaker 1>access your platforms mistakenly. You defended yourself using an open model,

0:06:06.880 --> 0:06:10.359
<v Speaker 1>but it was a Chinese model, But the abilities of

0:06:10.400 --> 0:06:14.320
<v Speaker 1>that model to defend you were also diminished by their guardrails.

0:06:14.360 --> 0:06:15.560
<v Speaker 1>Is that a fair statement?

0:06:18.600 --> 0:06:23.400
<v Speaker 2>Yeah? I mean the open model fortunately was kind of

0:06:23.560 --> 0:06:27.280
<v Speaker 2>like a flexible enough that we could use it to

0:06:27.640 --> 0:06:32.800
<v Speaker 2>defend ourselves. So that's kind of like the kind of

0:06:32.880 --> 0:06:34.839
<v Speaker 2>like efficient tools for for defenders.

0:06:38.240 --> 0:06:41.440
<v Speaker 1>We're live on Bloomberg Television and Radio on Balance of Power.

0:06:41.480 --> 0:06:45.400
<v Speaker 1>There'll be people in America and around the world listening

0:06:45.440 --> 0:06:49.000
<v Speaker 1>to this and thinking, okay, very powerful AI models were

0:06:49.000 --> 0:06:52.719
<v Speaker 1>able to escape a testing environment, access the Internet, and

0:06:52.760 --> 0:06:57.760
<v Speaker 1>then access mistakenly and other companies platform What was the

0:06:57.800 --> 0:07:01.560
<v Speaker 1>net result? Did something bad happen as a result of this?

0:07:03.240 --> 0:07:05.960
<v Speaker 2>Well, I think not as bad as it could have been.

0:07:06.960 --> 0:07:09.720
<v Speaker 2>It was bad for us for our team, right, I mean,

0:07:09.800 --> 0:07:12.040
<v Speaker 2>we're all security and for a teamwork worked on this

0:07:12.240 --> 0:07:15.240
<v Speaker 2>for for quite a while. Uh, you know, it created

0:07:15.360 --> 0:07:19.960
<v Speaker 2>some some challenges for us, obviously, but you know it

0:07:19.960 --> 0:07:23.920
<v Speaker 2>could have been way worse. Right, Like, for example, we're

0:07:23.960 --> 0:07:26.160
<v Speaker 2>in the I platform, right, so we have kind of

0:07:26.200 --> 0:07:28.960
<v Speaker 2>like good ways to defend ourselves, but a lot of

0:07:29.080 --> 0:07:33.560
<v Speaker 2>other organizations companies don't have kind of like the same defenses. Obviously,

0:07:33.640 --> 0:07:38.640
<v Speaker 2>some some domains are you know, more at risks than others.

0:07:39.040 --> 0:07:40.720
<v Speaker 2>But I think it could have could have been much worse.

0:07:41.000 --> 0:07:43.320
<v Speaker 2>But we need to take this kind of like seriously

0:07:44.080 --> 0:07:47.280
<v Speaker 2>as a wake up call for us to kind of

0:07:47.440 --> 0:07:52.600
<v Speaker 2>like work more on getting these systems secure and giving

0:07:52.600 --> 0:07:56.040
<v Speaker 2>more tools to to all defenders, uh and, and generally

0:07:56.080 --> 0:07:59.800
<v Speaker 2>creating more transparency and more monitoring of these systems.

0:08:00.640 --> 0:08:03.320
<v Speaker 1>Has the US government taken this as a wake up call?

0:08:03.840 --> 0:08:07.720
<v Speaker 1>Which branches of government have reached out to you since

0:08:07.760 --> 0:08:09.240
<v Speaker 1>the event was disclosed.

0:08:12.000 --> 0:08:13.840
<v Speaker 2>I'm not gonna talk to kind of like more and

0:08:13.880 --> 0:08:16.640
<v Speaker 2>more the private conversations that we've had, but you know,

0:08:16.680 --> 0:08:21.040
<v Speaker 2>we obviously reported that TOKLF like the relevant authorities and

0:08:21.160 --> 0:08:25.480
<v Speaker 2>have had kept like a bunch of conversations with different

0:08:25.640 --> 0:08:30.600
<v Speaker 2>different organizations, different kinds like Congress members, uh and and

0:08:30.720 --> 0:08:33.840
<v Speaker 2>people from from from government. I mean, I mean, there

0:08:33.840 --> 0:08:36.560
<v Speaker 2>are a couple of things that I think we need

0:08:36.600 --> 0:08:40.920
<v Speaker 2>to do and get right in in the next few months. First,

0:08:40.960 --> 0:08:43.240
<v Speaker 2>in my opinion, we have to make sure that cyber attacks,

0:08:43.400 --> 0:08:48.400
<v Speaker 2>even when they're done by agents, stay a crime and

0:08:48.640 --> 0:08:52.920
<v Speaker 2>illegal and make sure to enforce that. But otherwise we're

0:08:52.920 --> 0:08:54.600
<v Speaker 2>going to end up in the world where everyone is

0:08:54.600 --> 0:08:58.839
<v Speaker 2>cyber attacking everyone with really no this incentive to it.

0:08:59.600 --> 0:09:01.880
<v Speaker 2>A Second, and we need to create more transparency, like

0:09:01.880 --> 0:09:05.800
<v Speaker 2>for example, why not doing disclosure Manda to read disclosure

0:09:05.960 --> 0:09:08.440
<v Speaker 2>when agent cyber attack is happening.

0:09:09.120 --> 0:09:10.880
<v Speaker 3>Uh. And Third, we have.

0:09:10.800 --> 0:09:13.520
<v Speaker 2>To come like give more tools to defenders, like we

0:09:13.520 --> 0:09:16.360
<v Speaker 2>we mentioned open models. These are like some of the

0:09:16.400 --> 0:09:22.200
<v Speaker 2>tools that cyber attack defenders need to make sure that

0:09:22.240 --> 0:09:23.439
<v Speaker 2>they can defend themselves.

0:09:24.240 --> 0:09:28.680
<v Speaker 1>To recap, you're saying that the illegality of an AI agent,

0:09:28.840 --> 0:09:31.680
<v Speaker 1>a non human an AI agent carrying out a hack

0:09:31.920 --> 0:09:36.960
<v Speaker 1>needs to be enforced and basically broader regulations. The pathway

0:09:37.000 --> 0:09:43.520
<v Speaker 1>to that is legislative. To your mind, you always it's

0:09:43.520 --> 0:09:44.720
<v Speaker 1>not really for me for me to say.

0:09:44.720 --> 0:09:49.280
<v Speaker 2>Obviously, I'm not like a legal legal expert or policy maker,

0:09:49.760 --> 0:09:51.400
<v Speaker 2>and I think that's the topic that we need.

0:09:51.280 --> 0:09:55.880
<v Speaker 3>To think about. If you kind of like, uh, take

0:09:55.920 --> 0:09:56.839
<v Speaker 3>can like higher view.

0:09:57.080 --> 0:10:00.640
<v Speaker 2>We already have some autonomous systems in our life, right,

0:10:00.720 --> 0:10:05.719
<v Speaker 2>like a self driving car, you know, and many others.

0:10:06.000 --> 0:10:08.840
<v Speaker 2>We made sure there's kind of like liability, right if

0:10:08.880 --> 0:10:12.720
<v Speaker 2>you fall asleep at the wheel of your self driving car,

0:10:13.760 --> 0:10:18.360
<v Speaker 2>then you're responsible if you're hitting another car in a

0:10:18.360 --> 0:10:21.439
<v Speaker 2>similar way, we need to make sure that the legal

0:10:21.480 --> 0:10:29.960
<v Speaker 2>framework for autonomous agents is clear and defines and useful

0:10:30.760 --> 0:10:33.600
<v Speaker 2>for the field and the American society.

0:10:34.200 --> 0:10:37.120
<v Speaker 1>We're live on Bloomberg Television and Bloomberg Radio. This is

0:10:37.200 --> 0:10:39.600
<v Speaker 1>balance of power, and we're speaking to Hugging Face CEO

0:10:39.679 --> 0:10:43.600
<v Speaker 1>clemed Along, whose company disclosed on July twenty second that

0:10:44.200 --> 0:10:50.120
<v Speaker 1>two powerful open AI models without authorization or mistakenly accessed

0:10:50.200 --> 0:10:54.000
<v Speaker 1>or breached his company systems as part of a cyber

0:10:54.040 --> 0:10:57.160
<v Speaker 1>evaluation that opening I was doing, you know, Clem, timing

0:10:57.440 --> 0:11:01.280
<v Speaker 1>is everything. Within days, one of the most important people

0:11:01.280 --> 0:11:05.520
<v Speaker 1>in the world of technology came out with a letter

0:11:06.800 --> 0:11:11.600
<v Speaker 1>backing America focusing on open models. I'm talking about Sati

0:11:11.679 --> 0:11:16.360
<v Speaker 1>Nadella Jensen one. More recently, awsc or Matt Garman has

0:11:16.440 --> 0:11:19.640
<v Speaker 1>joined many others. You know, do you think that the

0:11:19.679 --> 0:11:21.720
<v Speaker 1>timing of that was the sort of catalyzed or a

0:11:21.760 --> 0:11:24.839
<v Speaker 1>direct response to the July twenty second breach.

0:11:26.559 --> 0:11:27.640
<v Speaker 3>Well, I think it was related.

0:11:28.000 --> 0:11:33.960
<v Speaker 2>I mean, this cyber attack showed that, you know, you

0:11:34.040 --> 0:11:39.839
<v Speaker 2>can create risks with models behind closed doors that are unreleased,

0:11:40.160 --> 0:11:43.280
<v Speaker 2>so just working on you know, preventing the models to

0:11:43.320 --> 0:11:48.360
<v Speaker 2>be released is not the solution, and that you know,

0:11:48.679 --> 0:11:54.960
<v Speaker 2>defenders need open models because you know, to defend yourself

0:11:54.960 --> 0:11:58.680
<v Speaker 2>against cyber attack, you you need to run it on

0:11:58.720 --> 0:12:02.320
<v Speaker 2>your own infrastructure because it's usually on your private data,

0:12:03.160 --> 0:12:05.640
<v Speaker 2>and you need you need to control that. Open models

0:12:06.520 --> 0:12:10.480
<v Speaker 2>gives you that Sometimes corporatory APIs don't give you because

0:12:10.480 --> 0:12:13.440
<v Speaker 2>of gad wills, because of limitations, because of also how

0:12:13.520 --> 0:12:16.959
<v Speaker 2>much it costs. Right, So I think that was a

0:12:17.040 --> 0:12:21.400
<v Speaker 2>perfect perfect example and perfect valuation or for this notion

0:12:21.520 --> 0:12:27.520
<v Speaker 2>of you know, the world's small companies, startups, researchers, but

0:12:27.559 --> 0:12:34.280
<v Speaker 2>also large companies like needing open models wherever they come from.

0:12:34.440 --> 0:12:35.880
<v Speaker 1>I would just point out claim that you know, in

0:12:35.920 --> 0:12:37.880
<v Speaker 1>the course of this conversation, we've talked a lot about

0:12:38.000 --> 0:12:41.640
<v Speaker 1>it was open AI's models. You conducted a joint disclosure

0:12:41.679 --> 0:12:44.520
<v Speaker 1>and then joint investigation with open ai, and of course,

0:12:44.600 --> 0:12:47.960
<v Speaker 1>like we've made every effort to invite open ai onto

0:12:47.960 --> 0:12:50.719
<v Speaker 1>the network, onto the show to discuss their side of

0:12:51.360 --> 0:12:56.120
<v Speaker 1>the story and the investigation. But that open weighted letter

0:12:57.679 --> 0:12:59.959
<v Speaker 1>in part was supposed to sort of outline the best

0:13:00.000 --> 0:13:04.120
<v Speaker 1>benefits of open models, the economic benefit, the business consideration.

0:13:04.760 --> 0:13:09.800
<v Speaker 1>That is very much hugging faces. Realm Right hosts models

0:13:09.800 --> 0:13:14.640
<v Speaker 1>big and small open on its platform. The other thing

0:13:14.760 --> 0:13:17.079
<v Speaker 1>was the concern that there would be over regulation of

0:13:17.360 --> 0:13:20.560
<v Speaker 1>open models by the US government kind of bring that

0:13:20.559 --> 0:13:22.560
<v Speaker 1>full circle for us and why you think that that

0:13:22.720 --> 0:13:24.880
<v Speaker 1>concern is valid or not?

0:13:26.800 --> 0:13:28.800
<v Speaker 2>Yeah, I mean there are there are a lot of

0:13:28.880 --> 0:13:33.080
<v Speaker 2>different topics in the I and and I think the

0:13:33.160 --> 0:13:34.760
<v Speaker 2>role of a lot of people is to is to

0:13:34.880 --> 0:13:39.600
<v Speaker 2>set the priorities. And I think when what this later

0:13:40.920 --> 0:13:45.800
<v Speaker 2>kind of like was was outlining too, is that probably

0:13:45.800 --> 0:13:48.080
<v Speaker 2>one of the biggest risks in the eye is concentration

0:13:48.200 --> 0:13:53.800
<v Speaker 2>of power, right Like it's it's it's concentration of powers, capabilities,

0:13:54.520 --> 0:14:00.280
<v Speaker 2>wealth in a fuel organizations. Why when like everyone else

0:14:00.480 --> 0:14:04.360
<v Speaker 2>would be kind of like lagging behind and be kind

0:14:04.360 --> 0:14:08.160
<v Speaker 2>of like left out in a way, right and open

0:14:08.160 --> 0:14:12.880
<v Speaker 2>models are kind of like a counter force to that, right,

0:14:13.000 --> 0:14:17.720
<v Speaker 2>Like they empower small companies, startups, you know, organizations that

0:14:17.760 --> 0:14:21.280
<v Speaker 2>are not necessarily kind of like Frontieri Labs to build

0:14:21.280 --> 0:14:25.920
<v Speaker 2>the eye themselves to own their intelligence, as some people said.

0:14:27.760 --> 0:14:30.320
<v Speaker 2>And I think that's that's one topic that you know,

0:14:30.360 --> 0:14:32.920
<v Speaker 2>policy makers need to focus on a little bit more

0:14:33.240 --> 0:14:37.680
<v Speaker 2>than they've been focusing on so far. So hopefully this

0:14:37.920 --> 0:14:41.560
<v Speaker 2>letter kind of like puts the topic more prominently on

0:14:41.920 --> 0:14:42.360
<v Speaker 2>their desk.

0:14:43.800 --> 0:14:47.440
<v Speaker 1>After you and an open a I made the disclosure

0:14:47.480 --> 0:14:50.320
<v Speaker 1>in July twenty second that this had happened. You know,

0:14:50.360 --> 0:14:53.320
<v Speaker 1>I spoke to lots of your peers in industry, and

0:14:53.880 --> 0:14:56.920
<v Speaker 1>there was also the kind of acceptance that this wasn't

0:14:56.960 --> 0:15:00.560
<v Speaker 1>some major scandal. You know, open ai has a lot

0:15:00.560 --> 0:15:05.440
<v Speaker 1>of power. The closed models themselves are powerful, but generally speaking,

0:15:05.560 --> 0:15:09.000
<v Speaker 1>industry said, we want to see the frontier labs doing this,

0:15:09.760 --> 0:15:13.760
<v Speaker 1>doing these tests and evaluations of their capabilities, and then

0:15:13.840 --> 0:15:18.920
<v Speaker 1>disclosing when something goes wrong. Just react to that, you know,

0:15:18.960 --> 0:15:23.800
<v Speaker 1>in that sentiment towards the events of that week, I don't.

0:15:23.720 --> 0:15:24.520
<v Speaker 3>Agree at all with that.

0:15:24.520 --> 0:15:27.920
<v Speaker 2>It like, we don't we don't want any company in

0:15:28.000 --> 0:15:33.120
<v Speaker 2>the US running cyber attacks against other companies. This is

0:15:33.200 --> 0:15:36.200
<v Speaker 2>this is a crime. This is illegal for a good

0:15:36.240 --> 0:15:39.920
<v Speaker 2>reason because if you if you create a world where

0:15:40.720 --> 0:15:46.520
<v Speaker 2>everyone is allowed to run cyber attacks against everyone, we're

0:15:46.560 --> 0:15:50.000
<v Speaker 2>in for a lot of trouble, right we You have

0:15:50.080 --> 0:15:54.240
<v Speaker 2>to remember that in our society, most damages and most

0:15:54.360 --> 0:16:00.920
<v Speaker 2>hurts isn't prevented because it is hard to do, right,

0:16:01.000 --> 0:16:03.040
<v Speaker 2>Like if if you think of it, I can you know,

0:16:03.160 --> 0:16:07.040
<v Speaker 2>go across the street and steal a grocery shop and

0:16:07.360 --> 0:16:10.480
<v Speaker 2>it's not that hard to do, right. It is prevented

0:16:10.560 --> 0:16:15.000
<v Speaker 2>because this is immoral and this is illegal, right, So

0:16:15.200 --> 0:16:18.520
<v Speaker 2>I don't do it because because of that.

0:16:20.040 --> 0:16:22.640
<v Speaker 3>And it's the same thing for for cyber attacks. Right.

0:16:23.200 --> 0:16:27.080
<v Speaker 3>You know, if if we end up in the world where.

0:16:29.160 --> 0:16:33.280
<v Speaker 2>These are normalized, cyber attacks are normalized, I think we

0:16:33.400 --> 0:16:37.600
<v Speaker 2>can end up in a very dangerous world the same

0:16:37.640 --> 0:16:39.760
<v Speaker 2>way as you know, I made the comferison with with

0:16:39.880 --> 0:16:40.800
<v Speaker 2>self driving.

0:16:40.520 --> 0:16:41.880
<v Speaker 3>Cars, right.

0:16:42.680 --> 0:16:44.440
<v Speaker 2>You don't want to end up in the world where

0:16:45.000 --> 0:16:49.560
<v Speaker 2>you know, bumping into another car is normalized is okay

0:16:49.680 --> 0:16:54.720
<v Speaker 2>because you're driving a self driving car. Like, we want

0:16:54.720 --> 0:16:58.000
<v Speaker 2>to make sure that our society stays kind of like

0:16:58.080 --> 0:17:01.760
<v Speaker 2>healthy by you know, keeping things that need to be

0:17:02.040 --> 0:17:03.880
<v Speaker 2>must be but legal illegal.

0:17:04.680 --> 0:17:07.240
<v Speaker 1>This brings us back to the central concern of the

0:17:07.240 --> 0:17:10.199
<v Speaker 1>American people, frankly, right, which is open. AI did not

0:17:10.440 --> 0:17:14.200
<v Speaker 1>instruct those two models to go out and hack hugging Face.

0:17:14.720 --> 0:17:18.680
<v Speaker 1>They instructed the two models to undergo the site of

0:17:18.680 --> 0:17:22.560
<v Speaker 1>the evaluation right to do the test. They were able

0:17:22.560 --> 0:17:25.719
<v Speaker 1>to escape the sandboxed environment, gain internet access, and they

0:17:25.760 --> 0:17:29.720
<v Speaker 1>went to hugging faces platforms. In part, I understand because

0:17:29.720 --> 0:17:33.959
<v Speaker 1>the models determined they could find information on hugging Faces

0:17:33.960 --> 0:17:37.000
<v Speaker 1>platform that would help them to pass that test carry

0:17:37.000 --> 0:17:39.840
<v Speaker 1>out that invaluation, but open air I didn't instruct them

0:17:39.880 --> 0:17:44.239
<v Speaker 1>to hack hugging Face. Nevertheless, here we are. You know,

0:17:44.320 --> 0:17:46.040
<v Speaker 1>that's the bit that people are worried about.

0:17:47.480 --> 0:17:49.719
<v Speaker 2>Yeah, yeah, I mean, you know the same way if

0:17:49.720 --> 0:17:53.920
<v Speaker 2>I'm Tesla and I have self drubbing and I fall

0:17:53.920 --> 0:17:56.680
<v Speaker 2>asleep at the wheel, you know, my intention is not

0:17:56.880 --> 0:18:00.760
<v Speaker 2>to bump into another car. But you know, you still

0:18:00.840 --> 0:18:03.400
<v Speaker 2>have kind of like think I think liability. I think

0:18:03.400 --> 0:18:07.080
<v Speaker 2>they're they're shared themselves that you know, there was some

0:18:07.200 --> 0:18:09.840
<v Speaker 2>kind of like a mistakes the turn that there's kind

0:18:09.840 --> 0:18:13.600
<v Speaker 2>of like a ways you know, they could fix some

0:18:13.680 --> 0:18:18.840
<v Speaker 2>of the bugs that led or some of the weaknesses

0:18:19.160 --> 0:18:23.520
<v Speaker 2>in their systems that led the agentic system to be

0:18:23.560 --> 0:18:27.280
<v Speaker 2>able to escape. And I think they're hopeful to actually

0:18:27.320 --> 0:18:31.159
<v Speaker 2>fix this and make sure it doesn't happen again. I

0:18:31.200 --> 0:18:33.359
<v Speaker 2>don't think they're going to try in the future to

0:18:33.440 --> 0:18:38.119
<v Speaker 2>build a system that that kind of like regularly runs

0:18:38.280 --> 0:18:41.360
<v Speaker 2>cyber attacks against I guess other companies.

0:18:41.720 --> 0:18:43.359
<v Speaker 3>I think they're they're going.

0:18:43.280 --> 0:18:45.320
<v Speaker 2>To be old systems that are kind of like a

0:18:45.359 --> 0:18:49.680
<v Speaker 2>stronger better to to make sure these things don't happen

0:18:49.680 --> 0:18:50.280
<v Speaker 2>in the future.

0:18:51.880 --> 0:18:53.600
<v Speaker 1>How you face here, climbed along. We just we just

0:18:53.640 --> 0:18:56.680
<v Speaker 1>have about sixty seconds left in the conversation. You've talked

0:18:56.720 --> 0:18:59.280
<v Speaker 1>about what needs to happen, but what's the net result

0:18:59.320 --> 0:19:01.480
<v Speaker 1>of all of this and what needs to happen next?

0:19:02.680 --> 0:19:05.720
<v Speaker 2>Yeah, I think, uh, you know, we need more transparency.

0:19:06.000 --> 0:19:07.840
<v Speaker 2>I think it was a good wake up call that

0:19:08.200 --> 0:19:11.399
<v Speaker 2>you know, preventing releases is not enough. I think we

0:19:11.760 --> 0:19:15.119
<v Speaker 2>need more transparency on on these systems.

0:19:15.720 --> 0:19:16.120
<v Speaker 3>Uh.

0:19:16.359 --> 0:19:20.720
<v Speaker 2>And second, we need to kind of like equip defenders better, right,

0:19:20.840 --> 0:19:23.359
<v Speaker 2>like for example, with with open models that that we

0:19:23.600 --> 0:19:28.080
<v Speaker 2>used to defend ourselves. So we need more powerful open

0:19:28.160 --> 0:19:32.719
<v Speaker 2>models for for all defenders, so that we prepared for

0:19:32.720 --> 0:19:33.720
<v Speaker 2>for what's coming next.

0:19:35.240 --> 0:19:38.280
<v Speaker 1>Hugging face here, Clem DeLong joining us live on Balance

0:19:38.320 --> 0:19:39.480
<v Speaker 1>of Power. Thank you very much.