Pt. 1: Is The Golden Age Of AI Already Over
I wasn't planning on this being a series, but this stuff is moving fast.
So we just found out we're getting Anthropic's Fable 5 back: https://www.anthropic.com/news/redeploying-fable-5. Plan users will have somewhat limited access to it for a week, after which it will only be available via usage credits, i.e. regular API per-token based billing. Not sure exactly how expensive that will be, but it will certainly be somewhat more expensive than other models.
It's not the price that concerns me though, it's the last section of Anthropic's news article there. "Partnering with the US government on frontier AI security". Scroll down that news article and read the whole section please. I'm not going to copy a bunch of it here, and it's not very long.
The four main points:
- The US government will be provided with early access to new models for evaluation and testing. The government can selectively block access to models based on their evaluations.
- Any jailbreaks or patterns of misuse detected by Anthropic will be immediately reported to the US government. It's not clear who decides precisely what constitutes a pattern of misuse.
- Anthropic will be increasing the resources it contributes to joint research with the US government regarding AI security.
- Anthropic will be working with the US government to establish a "common industry bar" of security and evaluation policies and practices for all frontier model providers.
This is all in response to Executive Order 14409 which is worth a read as well, though the whole big-picture issue here has been bubbling up for some time now.
As I pointed out in Pt 1, the US government now stands between its citizens and their access to artificial intelligence. Given point one of the four points above, the government can now decide which models we will be allowed to use, and which ones we will be prohibited from using. They can choose to allow certain entities to use more advanced models while denying those models to others. This is all being done with the stated purpose of improving national cybersecurity.
Is AI Itself A Cybersecurity Threat?
Before you start Googling up links to articles about how AI hacked this or that (and sending me those links before you've even read the whole article yourself, damn it annoys me when people do that) let's just talk high-level for a minute.
AI is quite good at finding vulnerabilities in code that humans have missed, code that may be in production use somewhere. AI is also good at automating tasks related to locating and exploiting those vulnerabilities. There is evidence that the rate of security incidents has increased in the last couple years, and that this increase is at least in part due to attackers incorporating AI technology into their processes.
There have also been security incidents linked to developers incorporating AI into their systems without first understanding the security implications of doing so. Sometimes, these statistics are lumped together with statistics relating to the exploitation of traditional vulnerabilities in computer code. I do not think these should be combined, as they are fundamentally different issues, with fundamentally different solutions.
In any case, there are two important points I want to make here.
First, though the rate of cybersecurity incidents might be increasing, the fundamental concepts behind these security threats, and the well-established methods for dealing with them, have not changed at all since the advent of LLM-based AI. Let me say the same thing again, only in bold. AI does not introduce any fundamental changes to cybersecurity.
Second, and this is really important to understand, thus worth spending extra pixels on more bold text: The same AI that is good at finding and exploiting vulnerabilities is equally good and addressing them. AI-based security defenses can meet the threat of AI security attacks head on. It can find vulnerabilities in code before that code is deployed. It can monitor systems with efficiency that other technologies couldn't hope to achieve. It can deploy patches, detect breaches, intercept phishing, and it can do all these things with astounding speed and proficiency. In other words, thanks to AI, the ability to defend against security threats is ramping up at precisely the same rate AI is advancing those threats. This is assuming the defenders have access to the same level of AI as the attackers, which, with these new government regulations in place, is not guaranteed.
So why do we need government regulation involved in any of this? I'm not convinced it's necessary or even desirable.
Is It Really About Security In The First Place?
Just one direct quote from the news article:
Our hope is that this collaboration, along with our proposed consensus industry framework, will serve as the basis for systematic rules for the whole industry—and even offer the beginnings of a template for effective global coordination on the risks and benefits of AI.
That one sentence packs a big punch beyond the initial stated scope of the article. They're not just talking about security threats anymore, they're talking about "risks and benefits" of AI on a global scale, across all disciplines. That includes economic and political risks and benefits. Given the nearly inconceivable amount of money already invested in AI, and the potential power the technology represents, these risks and benefits dwarf the cybersecurity angle alone.
Also, if these new government rules were all about security, then why don't they address the availability of LLM providers outside of the US? Bad actors are prevented from using US-based providers for their nefarious deeds, but they can just change one URL and one API token in their scripts and start using a foreign LLM, without any of these rules or restrictions in place. The people who put these new rules together must be aware of this. But the fact that they don't mention any plans for addressing it as they are announcing these US-based restrictions is somewhat telling. They only hint at a "hope" that there will someday be "global coordination" on the subject. But why roll forward with limitations on US providers without also addressing foreign providers? Because as it stands, these rules do nothing to actually improve the cybersecurity situation. They just establish a channel of control over as much of the AI industry as the US government can reach.
My Contentious Commentary
For the reasons stated above, I do not believe that these US government regulations have anything to do with cybersecurity. All of this commotion is just one play in a much larger game, the game that ultimately determines who controls the AI that controls everything else. These sorts of games usually take years or even decades to play out. But AI is advancing at an astounding rate, so this game is progressing at warp speed.
At the moment, the only other player in the game is China. More may enter, but the US and China will always be the big two. And as it stands today, anyone in the world can choose between US or Chinese providers to power whatever it is they want to do with AI.
So back to Anthropic's stated hope for global coordination. What incentive can the US offer China to cooperate with these new US-established AI regulations? That's a really tough nut to crack, and there's probably not one single, simple answer to this question. China is not likely to agree to anything that puts their providers at a competitive disadvantage. So establishing a true alliance on this front would have to involve some major give-and-take negotiations.
Another possibility is that the US will ban the use of foreign LLMs inside the US. They've already done something similar with certain categories of computer hardware. But enforcing a ban on digital communication is an awfully difficult thing to do, from a technology perspective. In the past, the US has dealt with these sorts of difficulties by simply attaching outsized punishments to breaking these sorts of laws. I really hope it doesn't come to this.
Banning foreign AI wouldn't even address the issue, since anyone in the rest of the world could still use that AI to stage a cyberattack against the US. So if the US does attempt to ban foreign AI within the US, we will know for certain that none of this has anything to do with cybersecurity. But if they don't address the issue of foreign LLMs somehow, then these new regulations can't be about cybersecurity either.
But I'm already pretty convinced of that. It's about money, power, and control. It's always about money, power and control.