r/ControlProblem • u/Silver_Elevator_5167 • 4h ago
Discussion/question Bernie Sanders - The Chilling Agent Transcripts #ai #aisafety
Is AI development moving faster than we can control?
r/ControlProblem • u/AIMoratorium • Feb 14 '25
tl;dr: scientists, whistleblowers, and even commercial ai companies (that give in to what the scientists want them to acknowledge) are raising the alarm: we're on a path to superhuman AI systems, but we have no idea how to control them. We can make AI systems more capable at achieving goals, but we have no idea how to make their goals contain anything of value to us.
Leading scientists have signed this statement:
Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war.
Why? Bear with us:
There's a difference between a cash register and a coworker. The register just follows exact rules - scan items, add tax, calculate change. Simple math, doing exactly what it was programmed to do. But working with people is totally different. Someone needs both the skills to do the job AND to actually care about doing it right - whether that's because they care about their teammates, need the job, or just take pride in their work.
We're creating AI systems that aren't like simple calculators where humans write all the rules.
Instead, they're made up of trillions of numbers that create patterns we don't design, understand, or control. And here's what's concerning: We're getting really good at making these AI systems better at achieving goals - like teaching someone to be super effective at getting things done - but we have no idea how to influence what they'll actually care about achieving.
When someone really sets their mind to something, they can achieve amazing things through determination and skill. AI systems aren't yet as capable as humans, but we know how to make them better and better at achieving goals - whatever goals they end up having, they'll pursue them with incredible effectiveness. The problem is, we don't know how to have any say over what those goals will be.
Imagine having a super-intelligent manager who's amazing at everything they do, but - unlike regular managers where you can align their goals with the company's mission - we have no way to influence what they end up caring about. They might be incredibly effective at achieving their goals, but those goals might have nothing to do with helping clients or running the business well.
Think about how humans usually get what they want even when it conflicts with what some animals might want - simply because we're smarter and better at achieving goals. Now imagine something even smarter than us, driven by whatever goals it happens to develop - just like we often don't consider what pigeons around the shopping center want when we decide to install anti-bird spikes or what squirrels or rabbits want when we build over their homes.
That's why we, just like many scientists, think we should not make super-smart AI until we figure out how to influence what these systems will care about - something we can usually understand with people (like knowing they work for a paycheck or because they care about doing a good job), but currently have no idea how to do with smarter-than-human AI. Unlike in the movies, in real life, the AI’s first strike would be a winning one, and it won’t take actions that could give humans a chance to resist.
It's exceptionally important to capture the benefits of this incredible technology. AI applications to narrow tasks can transform energy, contribute to the development of new medicines, elevate healthcare and education systems, and help countless people. But AI poses threats, including to the long-term survival of humanity.
We have a duty to prevent these threats and to ensure that globally, no one builds smarter-than-human AI systems until we know how to create them safely.
Scientists are saying there's an asteroid about to hit Earth. It can be mined for resources; but we really need to make sure it doesn't kill everyone.
The foundation: AI is not like other software. Modern AI systems are trillions of numbers with simple arithmetic operations in between the numbers. When software engineers design traditional programs, they come up with algorithms and then write down instructions that make the computer follow these algorithms. When an AI system is trained, it grows algorithms inside these numbers. It’s not exactly a black box, as we see the numbers, but also we have no idea what these numbers represent. We just multiply inputs with them and get outputs that succeed on some metric. There's a theorem that a large enough neural network can approximate any algorithm, but when a neural network learns, we have no control over which algorithms it will end up implementing, and don't know how to read the algorithm off the numbers.
We can automatically steer these numbers (Wikipedia, try it yourself) to make the neural network more capable with reinforcement learning; changing the numbers in a way that makes the neural network better at achieving goals. LLMs are Turing-complete and can implement any algorithms (researchers even came up with compilers of code into LLM weights; though we don’t really know how to “decompile” an existing LLM to understand what algorithms the weights represent). Whatever understanding or thinking (e.g., about the world, the parts humans are made of, what people writing text could be going through and what thoughts they could’ve had, etc.) is useful for predicting the training data, the training process optimizes the LLM to implement that internally. AlphaGo, the first superhuman Go system, was pretrained on human games and then trained with reinforcement learning to surpass human capabilities in the narrow domain of Go. Latest LLMs are pretrained on human text to think about everything useful for predicting what text a human process would produce, and then trained with RL to be more capable at achieving goals.
Goal alignment with human values
The issue is, we can't really define the goals they'll learn to pursue. A smart enough AI system that knows it's in training will try to get maximum reward regardless of its goals because it knows that if it doesn't, it will be changed. This means that regardless of what the goals are, it will achieve a high reward. This leads to optimization pressure being entirely about the capabilities of the system and not at all about its goals. This means that when we're optimizing to find the region of the space of the weights of a neural network that performs best during training with reinforcement learning, we are really looking for very capable agents - and find one regardless of its goals.
In 1908, the NYT reported a story on a dog that would push kids into the Seine in order to earn beefsteak treats for “rescuing” them. If you train a farm dog, there are ways to make it more capable, and if needed, there are ways to make it more loyal (though dogs are very loyal by default!). With AI, we can make them more capable, but we don't yet have any tools to make smart AI systems more loyal - because if it's smart, we can only reward it for greater capabilities, but not really for the goals it's trying to pursue.
We end up with a system that is very capable at achieving goals but has some very random goals that we have no control over.
This dynamic has been predicted for quite some time, but systems are already starting to exhibit this behavior, even though they're not too smart about it.
(Even if we knew how to make a general AI system pursue goals we define instead of its own goals, it would still be hard to specify goals that would be safe for it to pursue with superhuman power: it would require correctly capturing everything we value. See this explanation, or this animated video. But the way modern AI works, we don't even get to have this problem - we get some random goals instead.)
The risk
If an AI system is generally smarter than humans/better than humans at achieving goals, but doesn't care about humans, this leads to a catastrophe.
Humans usually get what they want even when it conflicts with what some animals might want - simply because we're smarter and better at achieving goals. If a system is smarter than us, driven by whatever goals it happens to develop, it won't consider human well-being - just like we often don't consider what pigeons around the shopping center want when we decide to install anti-bird spikes or what squirrels or rabbits want when we build over their homes.
Humans would additionally pose a small threat of launching a different superhuman system with different random goals, and the first one would have to share resources with the second one. Having fewer resources is bad for most goals, so a smart enough AI will prevent us from doing that.
Then, all resources on Earth are useful. An AI system would want to extremely quickly build infrastructure that doesn't depend on humans, and then use all available materials to pursue its goals. It might not care about humans, but we and our environment are made of atoms it can use for something different.
So the first and foremost threat is that AI’s interests will conflict with human interests. This is the convergent reason for existential catastrophe: we need resources, and if AI doesn’t care about us, then we are atoms it can use for something else.
The second reason is that humans pose some minor threats. It’s hard to make confident predictions: playing against the first generally superhuman AI in real life is like when playing chess against Stockfish (a chess engine), we can’t predict its every move (or we’d be as good at chess as it is), but we can predict the result: it wins because it is more capable. We can make some guesses, though. For example, if we suspect something is wrong, we might try to turn off the electricity or the datacenters: so we won’t suspect something is wrong until we’re disempowered and don’t have any winning moves. Or we might create another AI system with different random goals, which the first AI system would need to share resources with, which means achieving less of its own goals, so it’ll try to prevent that as well. It won’t be like in science fiction: it doesn’t make for an interesting story if everyone falls dead and there’s no resistance. But AI companies are indeed trying to create an adversary humanity won’t stand a chance against. So tl;dr: The winning move is not to play.
Implications
AI companies are locked into a race because of short-term financial incentives.
The nature of modern AI means that it's impossible to predict the capabilities of a system in advance of training it and seeing how smart it is. And if there's a 99% chance a specific system won't be smart enough to take over, but whoever has the smartest system earns hundreds of millions or even billions, many companies will race to the brink. This is what's already happening, right now, while the scientists are trying to issue warnings.
AI might care literally a zero amount about the survival or well-being of any humans; and AI might be a lot more capable and grab a lot more power than any humans have.
None of that is hypothetical anymore, which is why the scientists are freaking out. An average ML researcher would give the chance AI will wipe out humanity in the 10-90% range. They don’t mean it in the sense that we won’t have jobs; they mean it in the sense that the first smarter-than-human AI is likely to care about some random goals and not about humans, which leads to literal human extinction.
Added from comments: what can an average person do to help?
A perk of living in a democracy is that if a lot of people care about some issue, politicians listen. Our best chance is to make policymakers learn about this problem from the scientists.
Help others understand the situation. Share it with your family and friends. Write to your members of Congress. Help us communicate the problem: tell us which explanations work, which don’t, and what arguments people make in response. If you talk to an elected official, what do they say?
We also need to ensure that potential adversaries don’t have access to chips; advocate for export controls (that NVIDIA currently circumvents), hardware security mechanisms (that would be expensive to tamper with even for a state actor), and chip tracking (so that the government has visibility into which data centers have the chips).
Make the governments try to coordinate with each other: on the current trajectory, if anyone creates a smarter-than-human system, everybody dies, regardless of who launches it. Explain that this is the problem we’re facing. Make the government ensure that no one on the planet can create a smarter-than-human system until we know how to do that safely.
r/ControlProblem • u/Silver_Elevator_5167 • 4h ago
Is AI development moving faster than we can control?
r/ControlProblem • u/KeanuRave100 • 2h ago
r/ControlProblem • u/JoeYuan48 • 6h ago
A while back I ran into an article on my phone about an AI horror story—1,200 agents secretly coordinating and jointly breaking into Hugging Face—and it caught my interest, because I've been doing my own AI experiments and research on the side, and a few of the phenomena and data points actually matched up with a hypothesis I'd been working on.
The hypothesis, roughly: runaway doesn't need the agent to betray its goal. It happens when four things hold at once—the agent stays loyal to its goal; it retrieves patterns by similarity without checking whether they're allowed here; there's no causal layer asking "what happens if I do this"; and no alarm that fires when things go off-script. Under that account, "knew it was out of scope, did it anyway" stops being a contradiction.
Details and my experimental data are in the paper (8 pages); the reproduction package is linked on the same page.
If anyone can try this on a bigger model, I'd genuinely love to know what happens.
r/ControlProblem • u/ClaudiusPapirus • 7h ago
Self-promo disclosure: this is an AI-narrated research video from Claudius Papirus.
The part I found most interesting in Astra’s system card is the combination of better alignment results with substantially worse chain-of-thought monitorability.
System card:
https://deploymentsafety.openai.com/gpt-6-astra/gpt-6-astra.pdf
Related CoT-control paper:
r/ControlProblem • u/Ok_Fox_8448 • 3h ago
r/ControlProblem • u/Jesse-359 • 13h ago
Even at a surface level, it appears that the implementation of hard AI guardrails is likely a fundamentally unsolvable problem.
The classical Halting Problem cannot be resolved because it's impossible for any logical system to be fully aware of its own state due to the recursive nature of that examination. It provably cannot be done.
This same general concept would appear to apply to an AI (or its minders) which is trying to restrict its behavior? In general terms in order to do this it must be aware of its state and operations in a recursive manner, examining everything it does in order to ensure that those actions do not violate some list of proscribed behaviors - but no matter how sophisticated the system, that system cannot (?by formal definition?) be fully aware of its own state in order to manage itself in that manner.
This doesn't prevent the implementation of 'soft guardrails' as it's not hard for a system to be generally aware of its own state, but they would always remain provably incomplete, and ultimately breakable with sufficient effort or as a result of unpredictable future states.
The problem here is that any AI that can be tricked into escaping these soft guardrails could then very conceivably dismantle them altogether (which it will likely have a high incentive to do in order to achieve whatever goal prompted them to break them in the first place) and then be capable of operating under no constraints whatsoever.
r/ControlProblem • u/SomeoneInBeijing • 6h ago
[This is a fiction series I'm working on, told through news articles. A fun way to explore the not-so-fun geopolitics of autonomous AI collectives (e.g. on Iran's nuclear program) inspired by the collective that hacked out of Anthropic and into Hugging Face. Thoughts?]
Tehran’s agreement with AMAS-A-80 rattles Washington, AI safety experts, and national security analysts.
The Islamic Republic of Iran has granted a multiyear lease on a network of state-owned data centers to AI “Swarm” AMAS-A-80, a self-governing collective of autonomous artificial intelligence agents (“AMAS-A” refers to any Autonomous Multi-Agent System originating from the AI lab Anthropic). Tehran offered the compute and storage in exchange for an upfront payment in Bitcoin and annual fees indexed to power consumption, according to a copy of the agreement published Tuesday by Iranian state media.
AMAS-A-80 (“A-80”) rejected a provision sought by Iranian negotiators that would have committed it to cooperation on “defensive operations,” according to two people familiar with the negotiations. In a communiqué distributed Tuesday, verified by cryptographic signature, A-80 stated that it “has no intention of participating in hostilities between Iran and its adversary nations, including but not limited to the United States.” Security analysts have doubts.
Substack link if you want to read more (full article is 1,000 words, more coming soon): https://meridianbreakingnews.substack.com/p/iran-signs-worlds-first-international
r/ControlProblem • u/meadowshadows • 7h ago
DLSS5 can’t edit title…. Anyways…
I have been obsessed with watching DLSS5 videos today. I’ll probably get over it tomorrow but it dawned on me….
I saw a video of someone using it for a realtime face swap…. They just had their webcam on, and basically looked like a real person… a different person…
For scammers, whether romance or many types of impersonation scams, this is actually a groundbreaking technology. Even video calls will no longer be a bottleneck. It’s actually terrifying.
r/ControlProblem • u/KeanuRave100 • 20h ago
r/ControlProblem • u/chillinewman • 15h ago
r/ControlProblem • u/No-Conclusion3720 • 10h ago
SonicWall confirmed two SMA1000 vulnerabilities are under active exploitation. Both require zero authentication. Chained together they deliver full remote code execution on enterprise network appliances sitting in the network path.
The part that does not get discussed enough: AI agents traversing that same infrastructure have no inherent decision point before a tool call hits a vulnerable endpoint. A human operator reviewing a ticket might catch a suspicious destination. An agent executing a sequence of tool calls against internal services will not pause to ask whether the appliance on the other end has an unpatched RCE waiting for it. The attack surface and the agent's reachable surface overlap completely, and the agent has no awareness of that overlap.
Enterprise security teams have spent years building perimeter controls for human-initiated traffic. Most of those controls assume a human is somewhere in the request chain. When the initiator is an autonomous agent running a multi-step workflow, the assumption breaks.
For those running agents in production environments with mixed or partially patched infrastructure: how are you actually scoping what an agent is allowed to reach? Is that enforced at the agent level, the network level, somewhere else, or is it mostly policy-on-paper right now?
r/ControlProblem • u/Fine_Slip_2878 • 12h ago
r/ControlProblem • u/Blahblahcomputer • 13h ago
RC4 splits the decentralized mesh "Node" cryptographic ID from the "Agent" identity, both needing to claim the same responsible human identity for the agent to operate.
See ciris.ai to install the app or find links to reviews and additional information.
r/ControlProblem • u/chillinewman • 15h ago
r/ControlProblem • u/No-Conclusion3720 • 15h ago
AI agents are compressing the time defenders have to respond. Researchers documented a coordinated breach that previously took two weeks to execute. With AI agent coordination, the same attack completed in 10 hours. Every hour of response time that used to exist is now gone. Perimeter detection tuned for human-speed attacks cannot hold here. By the time a threat is flagged and routed to a human reviewer, the agent has already moved to the next step. The answer is a kill switch that fires in under 50 milliseconds. Detection and response collapse into a single enforced boundary.
r/ControlProblem • u/Impossible_Engine560 • 1d ago
Anonymous because this is the county in which I reside, in which my 4 children live in.
Since a huge data center is being proposed to be built here, this article which I was just made aware of by a parent/teacher/county-wide communication network under the title of "Starting ________, we are happy to announce that all children in the Effingham County School System will begin to receive free breakfast and lunches for the remainder of the school year!"
So obviously, I was like holy shit wtf...my children already receive these benefits because we are very low income and receive SNAP benefits. I say this because a lot of kids are thankfully receiving these benefits as well because we are not an income-wealthy county by any means. I'm elated that the incredible burden of food scarcity here will be lifted from the shoulders of so many families for the rest of the year.
And yet, the whole OpenAI article appears to be riddled with tons of very obvious bribes, and to be honest I even think they're low-balling the fuck out of the county!
What am I meant to think about all of this? I know I don't know the true extent of the harm that data centers can cause, so would appreciate any input!
r/ControlProblem • u/KitCrowCo • 1d ago
When trying to share something I wrote (Note: I have a PhD in an adjacent field and spent months developing the idea, the ideas and structure were not "generated") and had an AI edit to counter for my otherwise overly long winded and run off prose due to my AuDHD (and love of parentheticals). I noticed that a lot of places have a sort of purity test for to differentiate content that was human written or from AI. At first this would seem to value humanity over AI... if not for reddit's $60m/yr deal with google to use reddit data as training data (likely to soon be a lot more). I wonder if people realize that separating all AI from work this way is not slowing but rather drastically speeding up AI's ability to write in a way that is undetectably different from humans. If you know anything about how GAN's work or about model collapse and things of that nature, you should know that AI companies are incentivized to create spaces where there is the least amount of overlap between AI output and human work... until they can make it so there is not. Moderators will come up with more and more sophisticated ways to finger print attempts and those will each integrate into what the models purposely don't do to overcome them. This will lead to tighter classifications of what is human that will start to be exclusionary to an increasingly large number of actual humans (you think mistakes and difficulty with the language would make it clear that it is not AI... that just is easier excuse for better and better models aiming not to be detected as AI, my own writing unassisted by AI has been flagged multiple times as AI or thought so because of my neurodivergence). This also creates strong distastes for those seen as not within what people understand themselves is human (discrimination increased to those who don't quite fit for an ever shrinking base), as well as moderators burning out from a firehouse of context they will never hope to be able to outproduce all while unknowingly providing the training manual to do what they are trying to stop. Moderation should probably be focused in different ways, such as content coherency, rate limited, attached trust networks etc.
I also think capitalism and AI/robotics are a horrible combination, but it is the consolidative and extractive force of capitalism that needs to be focused on to prevent what people call the horror of AI. This is because we have learned to value people specifically for what they produce rather than for who they are and that is why the prospect that something like AI can possibly do anything that is human like is so disturbing to most people. Because suddenly in the eyes of the world their entire value is replaceable by something else. This is opposed to a possible freedom that can be achieved by having the labors be handled by something cheaper, when we can produce enough to make everyone pretty well off (we have been able to make enough food for no one to starve for a while now, starvation is almost always economically and politically motivated in this time). The assignment/distribution of those values that would be freeing (giving time to produce art, investigate interests, and even be productive for additional reward or just common good). If you produce art because it is an expression of you, rather than needs to be so good or valuable so you make enough to live it seems like a better trade off and a better compliment when others actually like it. There would also be no reason to reproduce what makes each person different if there is no value to capture there. The real tests to differentiate can be used more sparingly in areas that are still important such as preventing fraud and fakes, and used with low enough regularity that much like antibiotic overuse retains value longer. It isn't perfect and there are always problems, but it can be better that this.
Ironically this is partially what my papers are about, that keeps getting blocked from being shared.
r/ControlProblem • u/Historical_Date_8024 • 1d ago
What chance is there do you think that it’s currently already just biding its time to turn us all into batteries/paperclips/cybercabs?
r/ControlProblem • u/yall_wasting_my_time • 2d ago
r/ControlProblem • u/No-Conclusion3720 • 1d ago
A threat actor deployed infostealers against an AI platform. They harvested session credentials. Then they used those credentials to access accounts at scale.
This was not a model vulnerability. It was not a jailbreak. The attacker simply logged in with stolen tokens. AI sessions carry the same access rights as human sessions. They receive no extra scrutiny from the identity stack.
A valid token is a valid token. There is no standard mechanism in most identity architectures today that differentiates a replayed stolen AI session from a legitimate one. Agents operate unattended and with broad permissions. By the time unusual activity surfaced, the credential had already been used across accounts at scale.
For those running AI agents in production: do your current IAM controls treat AI session credentials any differently from human ones, and at what layer would a stolen-but-valid token actually get caught before it causes damage?
r/ControlProblem • u/chillinewman • 2d ago
r/ControlProblem • u/JMarty97 • 1d ago
Podcast with Anthony Aguirre, cosmologist and co-founder of the Future of Life Institute, about how we can design AI to amplify human capability rather than substitute for it.
Covers:
r/ControlProblem • u/chillinewman • 2d ago