AI doesn’t commit crimes. People do.
Saying “AI hacked a company” is like saying a rock broke into a car. The tool didn’t decide to act, accept risk or assume liability.
The media needs to stop reporting AI as the perpetrator.
If Google builds, deploys or controls the system, Google owns the consequences.
Blaming “AI” removes the human and corporate actor from the sentence. That removes accountability with it.
Bonjour Claude peux-tu me résumer ces 476 pages de données confidentielles qui engageront ma responsabilité pénale en cas de fuite ? Merci
Ptdrrrrrrrrrr
Being a computer scientist who refuses to find anything about LLMs interesting right now is a bit like being a geneticist who refuses to find anything interesting about the recently opened Jurassic Park
Using the existence of a side-channel attack pathway with incredibly low bitrate and requiring two compromised computers to be defeatist about airgaps is peak AI academic security-expert-larping
the heat channel is real. it’s called BitWhisper, 2015. it does 8 bits/hour, at 40cm, AND needs code already running on the receiving machine. at that rate exfiltrating 1TB of weights takes ~114 million years
If frontier AI people were serious about AI risk, they would publish always-updating guides about sandboxing, tools and docs on system hardening and AI defense, promote a security ecosystem. They would be proactive, encouraging. Instead, they fund orgs promoting doom. Why?
OpenAI & Anthropic removing CoT/reasoning traces is actually a bad thing for security
How can White Hats identify security concerns within the models if they cannot see how the model thinks?
If these companies are serious about security they wouldn't do security via obfuscation
a lot of AI safety discourse comes down to a network/hardware/infra engineer saying "ok if it's air gapped the computer can not communicate with other computers" and the safety/alignment researcher going "ok but what if it could"