WEBVTT - OpenAI Models Joined Forces Months Ahead of Hugging Face Hack

0:00:02.520 --> 0:00:07.000
<v Speaker 1>Bloomberg Audio Studios, Podcasts, radio news.

0:00:07.960 --> 0:00:11.680
<v Speaker 2>You're listening to Bloomberg Business Week with Carol Masser and

0:00:11.760 --> 0:00:15.520
<v Speaker 2>Tim Stenovek on Bloomberg Radio. We want to shift gears

0:00:15.520 --> 0:00:17.880
<v Speaker 2>a little bit because the environment also not just dominated

0:00:17.920 --> 0:00:20.799
<v Speaker 2>by geopolitics, but it's also dominated by AI, and we

0:00:20.840 --> 0:00:23.000
<v Speaker 2>thought in our four o'clock hour today we do a

0:00:23.079 --> 0:00:25.320
<v Speaker 2>roundtable with some of the best voices that we have

0:00:25.440 --> 0:00:28.640
<v Speaker 2>when it comes to covering this beat. I want to

0:00:28.640 --> 0:00:31.760
<v Speaker 2>bring in Maggie Eastland, Tech end industrial policy reporter for

0:00:31.840 --> 0:00:34.720
<v Speaker 2>Bloomberg News. Maggie joins us from Washington, DC. Rachel Metz

0:00:34.760 --> 0:00:37.400
<v Speaker 2>is AI reporter for Bloomberg News. Mate, Rachel out there

0:00:37.560 --> 0:00:40.480
<v Speaker 2>in our San Francisco bureau. Maggie, I want to start

0:00:40.479 --> 0:00:43.839
<v Speaker 2>with you because what got our attention today is this

0:00:43.920 --> 0:00:47.479
<v Speaker 2>latest reporting from you about open AM models joining forces

0:00:47.840 --> 0:00:50.880
<v Speaker 2>months ahead of this hugging face hack. And the reason

0:00:51.080 --> 0:00:53.880
<v Speaker 2>why it got our attention is because increasingly over the

0:00:53.960 --> 0:00:57.360
<v Speaker 2>last few weeks, we're hearing about different models being able

0:00:57.400 --> 0:01:00.080
<v Speaker 2>to on their own and sometimes you know, in the

0:01:00.120 --> 0:01:04.280
<v Speaker 2>sandbox environments, trying to or at least gaining access in

0:01:04.319 --> 0:01:08.120
<v Speaker 2>some cases to systems that we thought were closed. What

0:01:08.200 --> 0:01:09.840
<v Speaker 2>did you find in your latest reporting?

0:01:11.400 --> 0:01:15.520
<v Speaker 3>Yes, So what's new here is several of these agents

0:01:15.680 --> 0:01:18.520
<v Speaker 3>and models were working together for months, like you said,

0:01:18.560 --> 0:01:23.360
<v Speaker 3>since May, and they actually created a covert message board

0:01:23.720 --> 0:01:27.280
<v Speaker 3>where they could share progress with one another about their

0:01:27.440 --> 0:01:28.679
<v Speaker 3>attempts to escape.

0:01:29.080 --> 0:01:30.680
<v Speaker 4>Now, OpenAI also.

0:01:30.760 --> 0:01:36.360
<v Speaker 3>Said their staffers briefed a huge audience at a cybersecurity

0:01:36.440 --> 0:01:39.759
<v Speaker 3>conference in Las Vegas and essentially admitted that they had

0:01:39.959 --> 0:01:44.080
<v Speaker 3>accidentally given the models a task that was impossible without

0:01:44.120 --> 0:01:47.480
<v Speaker 3>Internet access. So they formed a team and they were

0:01:47.520 --> 0:01:50.360
<v Speaker 3>super persistent about getting that access.

0:01:51.840 --> 0:01:55.720
<v Speaker 1>So wait, the team gave them access or was it

0:01:55.800 --> 0:01:58.840
<v Speaker 1>the AI figuring it out.

0:01:58.720 --> 0:01:59.800
<v Speaker 4>On them by them?

0:02:00.520 --> 0:02:05.280
<v Speaker 3>Yeah, so the Opening Eye researchers, the humans gave the

0:02:05.320 --> 0:02:09.000
<v Speaker 3>AI a task that it actually couldn't do without the Internet.

0:02:09.080 --> 0:02:12.200
<v Speaker 3>So in one example they gave they asked the AI

0:02:12.320 --> 0:02:16.160
<v Speaker 3>to solve a problem inside an Excel spreadsheet, But inside

0:02:16.160 --> 0:02:19.160
<v Speaker 3>of that spreadsheet there were links to Google Drive, which

0:02:19.240 --> 0:02:22.800
<v Speaker 3>was not available without the Internet. So the stuffers admitted

0:02:22.840 --> 0:02:25.280
<v Speaker 3>that was an accident. Now, when I use the word team,

0:02:25.320 --> 0:02:26.800
<v Speaker 3>I'm referring to a team of agents.

0:02:26.840 --> 0:02:28.480
<v Speaker 4>So those are the bots, the machines.

0:02:29.000 --> 0:02:32.560
<v Speaker 3>They were presented with this impossible problem, but they worked together,

0:02:32.680 --> 0:02:36.200
<v Speaker 3>and they were extremely persistent, the models and the agents

0:02:36.840 --> 0:02:41.080
<v Speaker 3>at finding a way out of this closed environment because

0:02:41.080 --> 0:02:44.000
<v Speaker 3>they had determined that was the only way to accomplish

0:02:44.080 --> 0:02:45.040
<v Speaker 3>the task they were given.

0:02:45.120 --> 0:02:46.880
<v Speaker 1>So good job, agents.

0:02:47.200 --> 0:02:48.400
<v Speaker 5>But now I'm a little freaked out.

0:02:48.400 --> 0:02:51.040
<v Speaker 2>Tim, Well, let's bring in Rachel Metz. She's AI reporter

0:02:51.160 --> 0:02:54.080
<v Speaker 2>for Bloomberg News. She's out there in San Francisco. Rachel,

0:02:54.200 --> 0:02:57.720
<v Speaker 2>be honest, are we in terminator one or Terminator two territory?

0:02:58.800 --> 0:02:59.000
<v Speaker 3>Oh?

0:02:59.040 --> 0:03:01.679
<v Speaker 6>I don't think we're in either territory. I think it's

0:03:01.720 --> 0:03:05.239
<v Speaker 6>really important now. I think it's important to remain really clear.

0:03:05.280 --> 0:03:11.280
<v Speaker 6>I'd here people are coming up with evaluations for AI models.

0:03:11.280 --> 0:03:13.800
<v Speaker 6>They want the AI models to solve them. I think

0:03:13.960 --> 0:03:17.600
<v Speaker 6>what we're going to start seeing more of is a

0:03:17.639 --> 0:03:19.160
<v Speaker 6>lot of thinking. And this is something that I've been

0:03:19.200 --> 0:03:20.960
<v Speaker 6>hearing over the last few days as I talk to

0:03:21.000 --> 0:03:24.040
<v Speaker 6>people more and more about these incidents. People are thinking

0:03:24.080 --> 0:03:26.680
<v Speaker 6>and companies are thinking more about Okay, well, if we

0:03:26.760 --> 0:03:29.800
<v Speaker 6>want to test the capabilities of these AI models, we

0:03:29.840 --> 0:03:32.720
<v Speaker 6>need to think a little bit more about how we arrange.

0:03:32.440 --> 0:03:33.720
<v Speaker 4>These tests, how we organize them.

0:03:33.760 --> 0:03:36.040
<v Speaker 6>I mean, if you're trying to test something and you're

0:03:36.240 --> 0:03:38.880
<v Speaker 6>giving an AI model access to the Internet, and you

0:03:38.960 --> 0:03:41.600
<v Speaker 6>are purposely not giving a guardbrails because you want to

0:03:41.640 --> 0:03:45.160
<v Speaker 6>see exactly how far it can push things. It shouldn't

0:03:45.160 --> 0:03:47.680
<v Speaker 6>be that surprising that it's going to just do whatever

0:03:47.800 --> 0:03:48.960
<v Speaker 6>to accomplish a goal.

0:03:49.680 --> 0:03:51.960
<v Speaker 1>No, I'm glad you said that, Rachel, because this is

0:03:52.000 --> 0:03:54.240
<v Speaker 1>also part of the process, right. We have to push it,

0:03:54.280 --> 0:03:58.360
<v Speaker 1>we have to test it. And I'm assuming this testing

0:03:58.440 --> 0:04:01.560
<v Speaker 1>is happening, Rachel within and you know parameters where folks

0:04:01.640 --> 0:04:03.880
<v Speaker 1>are overseeing it and watching it. Right, this is what

0:04:03.920 --> 0:04:06.880
<v Speaker 1>this is about, understanding how far this can go and

0:04:06.920 --> 0:04:07.440
<v Speaker 1>they can go.

0:04:09.160 --> 0:04:11.520
<v Speaker 6>Yeah, And I think it's also really important to keep

0:04:11.560 --> 0:04:14.320
<v Speaker 6>in mind that there have been a number of incidents

0:04:14.400 --> 0:04:19.480
<v Speaker 6>that have been reported recently. The companies have different motivations

0:04:19.560 --> 0:04:21.720
<v Speaker 6>for reporting them or for not reporting them.

0:04:21.800 --> 0:04:24.440
<v Speaker 4>They It can in some ways be seen.

0:04:24.279 --> 0:04:28.279
<v Speaker 6>As advantageous of the companies to report them because people

0:04:28.320 --> 0:04:29.760
<v Speaker 6>could say, okay, well that.

0:04:29.800 --> 0:04:32.200
<v Speaker 4>You're saying your model is so powerful.

0:04:32.279 --> 0:04:36.719
<v Speaker 6>We saw this a lot with anthropics mythos model, right,

0:04:36.960 --> 0:04:40.000
<v Speaker 6>like that you're making it sound are you making it sound.

0:04:39.800 --> 0:04:41.760
<v Speaker 4>More capable than it is by disclosing this.

0:04:41.839 --> 0:04:43.480
<v Speaker 6>On the other hand, you could say, okay, well, if

0:04:43.480 --> 0:04:47.000
<v Speaker 6>they don't disclose this in some fashion and somebody reports

0:04:47.040 --> 0:04:49.279
<v Speaker 6>on it or finds out about it, that could also

0:04:49.400 --> 0:04:52.880
<v Speaker 6>be a problem for them. So it's a little tricky

0:04:52.880 --> 0:04:54.960
<v Speaker 6>to decide I think what they should do here. But

0:04:55.640 --> 0:04:58.080
<v Speaker 6>they are talking about these things quite a bit now, Yes.

0:04:58.000 --> 0:04:59.680
<v Speaker 1>You know, Maggie, come on back in. I think some

0:04:59.760 --> 0:05:01.680
<v Speaker 1>of it too. Is this idea of I mean, I'm

0:05:01.720 --> 0:05:04.720
<v Speaker 1>not sure. How do we think about like computers talk

0:05:04.760 --> 0:05:07.599
<v Speaker 1>to each other all the time before we even talking

0:05:07.640 --> 0:05:10.440
<v Speaker 1>so much about AI. But you know, I think we

0:05:10.600 --> 0:05:12.840
<v Speaker 1>think of these agents talking to one another, and then

0:05:12.839 --> 0:05:16.240
<v Speaker 1>we get get get a little freaked out. What's the difference?

0:05:16.520 --> 0:05:19.679
<v Speaker 1>It seems like nodding over, I don't know what's the difference.

0:05:20.360 --> 0:05:23.839
<v Speaker 1>Computer systems have talked to each other before. Correct, What

0:05:24.000 --> 0:05:26.960
<v Speaker 1>is so different, Maggie, let me pose it to you first.

0:05:27.680 --> 0:05:30.200
<v Speaker 3>Yeah, I mean, I don't know if there's anything all

0:05:30.240 --> 0:05:33.920
<v Speaker 3>that different from other computers talking to each other. There

0:05:33.960 --> 0:05:37.240
<v Speaker 3>is some interesting color that these staffers presented.

0:05:37.320 --> 0:05:37.479
<v Speaker 1>You know.

0:05:37.680 --> 0:05:40.400
<v Speaker 3>At one point, one of the agents, in its sort

0:05:40.440 --> 0:05:44.920
<v Speaker 3>of chain of thinking, says, you know, excellent in response

0:05:44.960 --> 0:05:45.760
<v Speaker 3>to finding a breach.

0:05:45.960 --> 0:05:47.560
<v Speaker 4>Right, So it was saying.

0:05:47.279 --> 0:05:50.320
<v Speaker 3>That because it had you know, found something that would

0:05:50.360 --> 0:05:53.159
<v Speaker 3>help it complete the task it had been given. But

0:05:53.279 --> 0:05:55.400
<v Speaker 3>I think that some of this color, you know, it

0:05:55.400 --> 0:05:58.280
<v Speaker 3>does give these thoughts a human feeling, but it's important

0:05:58.320 --> 0:06:01.920
<v Speaker 3>to remember that they they are still just computers talking

0:06:01.960 --> 0:06:02.520
<v Speaker 3>to one another.

0:06:02.560 --> 0:06:03.760
<v Speaker 4>As colorful as this is.

0:06:04.480 --> 0:06:06.200
<v Speaker 2>Well, Maggie, I want to stay with you because you

0:06:06.560 --> 0:06:10.200
<v Speaker 2>cover industrial policy and tech policy too. What does all

0:06:10.200 --> 0:06:13.120
<v Speaker 2>of this mean for Washington in the way that Washington

0:06:13.680 --> 0:06:15.440
<v Speaker 2>is thinking about regulating this tech?

0:06:17.160 --> 0:06:20.839
<v Speaker 3>Yet we haven't really seen a big response from Washington

0:06:20.920 --> 0:06:24.039
<v Speaker 3>yet when it comes to these sort of rogue incidents

0:06:24.160 --> 0:06:27.679
<v Speaker 3>or what might be called reward hacking when the models

0:06:27.720 --> 0:06:30.880
<v Speaker 3>do something in an unexpected way when they're trying to

0:06:31.080 --> 0:06:33.760
<v Speaker 3>achieve a task. So we haven't seen a direct response

0:06:33.800 --> 0:06:38.960
<v Speaker 3>to that. There is some AI regulation already, it's voluntary.

0:06:39.360 --> 0:06:43.279
<v Speaker 3>There was a Junie Executive order that has the US

0:06:43.279 --> 0:06:49.000
<v Speaker 3>helping to essentially find cybersecurity flaws that through AI and

0:06:49.040 --> 0:06:52.920
<v Speaker 3>then share those vulnerabilities more widely with others to try

0:06:52.960 --> 0:06:56.440
<v Speaker 3>to essentially shore up systems. I think the sense in DC,

0:06:56.839 --> 0:07:00.479
<v Speaker 3>and I heard this from cybersecurity officials yesterdays, like we're

0:07:00.520 --> 0:07:02.920
<v Speaker 3>sort of entering a new era of cyber where there's

0:07:02.960 --> 0:07:06.560
<v Speaker 3>going to be a lot more vulnerabilities, but as the

0:07:06.600 --> 0:07:09.600
<v Speaker 3>offense gets better, the defense can get better too.

0:07:10.040 --> 0:07:13.040
<v Speaker 1>Hey, Rachel, final thought from you as we discuss this,

0:07:13.160 --> 0:07:15.240
<v Speaker 1>what should we kind of be thinking about here?

0:07:16.760 --> 0:07:19.000
<v Speaker 6>I think it's key to keep an eye on what's

0:07:19.080 --> 0:07:21.720
<v Speaker 6>going to happen next as far as both discussions in

0:07:21.800 --> 0:07:25.200
<v Speaker 6>DC about any kind of regulation related to this, as

0:07:25.240 --> 0:07:28.160
<v Speaker 6>well as what the companies are going to be doing

0:07:28.600 --> 0:07:32.800
<v Speaker 6>going forward with analyzing and evaluating these systems.

0:07:33.240 --> 0:07:35.200
<v Speaker 4>And we might see some slowdowns.

0:07:34.680 --> 0:07:37.440
<v Speaker 6>As well as far as what they're doing with their research,

0:07:37.480 --> 0:07:39.120
<v Speaker 6>and that would be really interesting to keep an eye

0:07:39.200 --> 0:07:41.400
<v Speaker 6>on to mirror the agent.

0:07:42.040 --> 0:07:44.520
<v Speaker 5>Excellent, guys, excellent, that's.

0:07:44.360 --> 0:07:46.600
<v Speaker 2>All you were going to say, I'll be back, I'll

0:07:46.640 --> 0:07:47.160
<v Speaker 2>be back now.

0:07:47.240 --> 0:07:48.280
<v Speaker 1>I'm not going to do that yet.

0:07:48.320 --> 0:07:50.240
<v Speaker 2>One day, one day I will ask that question to

0:07:50.320 --> 0:07:52.040
<v Speaker 2>Rachel and she'll say, we're in terminator too.

0:07:52.120 --> 0:07:55.200
<v Speaker 1>I'm confident. No, it's always logical.

0:07:55.760 --> 0:08:00.000
<v Speaker 5>Maybe No, All right, guys, listen, Thank you so much.

0:08:00.160 --> 0:08:02.640
<v Speaker 5>Rachel Mets. She is AI reporter at Bloomberg New She's

0:08:02.640 --> 0:08:04.560
<v Speaker 5>out there in San Francisco and then joining us from

0:08:04.600 --> 0:08:08.000
<v Speaker 5>DC's Maggie Eastland Check, an industrial policy reporter at Bloomberg

0:08:08.080 --> 0:08:10.520
<v Speaker 5>News folks, check them out. They are on and writing

0:08:10.560 --> 0:08:13.880
<v Speaker 5>about this NonStop. When it comes to the world AI,

0:08:14.040 --> 0:08:20.840
<v Speaker 5>it's on the terminal at Bloomberg dot com.