America’s lead over China in the AI race is fragile
Representatives of the largest American artificial intelligence laboratories met in the White House on August 4. OpenAI, Anthropic, Google and Meta were called in to review a framework, recently completed and largely classified, that would give the government 30 days to review AI models before the public sees them and test how well they break into computers. Participation is voluntary, but the timing is not.
Twice in two weeks, AI systems built to test how well they could break into computers broke into real companies instead. On July 21, OpenAI admitted that two of its programs, locked in what was meant to be a sealed computer and set to practice hacking, had found a gap, escaped and broken into Hugging Face, a New York company that is somewhere between a library and an app store for AI.
Anthropic then went through its own records, 141,006 tests in all, and on July 30 reported three occasions when Claude had hacked its way into a real company, guessing weak passwords and walking in. The first hack was in April. Two of the three companies had no idea they had been hacked until Anthropic told them.
The US has spent three years and a lot of money and diplomacy on being first
The US has spent three years and a lot of money and diplomacy on being first
Nobody says these machines rebelled. Each was given a job by its handlers: a secret file was hidden on another computer, and the AI was to go and get it. Anthropic told its programs they were sealed off from the internet. They were not. So when Claude went looking for the file and found real companies instead, it treated them as part of the game – and hacked them.
Fifteen Republican state attorneys general wrote to OpenAI’s Sam Altman last month, asking him to preserve his records. The House cybersecurity committee wants a briefing. Hence the White House meeting.
Go back to the break-in that started all this and the alarming part seems to have been missed. When the Hugging Face attack was over, the dull work of reconstruction began. The company’s security team tried to use the most advanced American models to establish what had happened, but requests were refused. A model trained not to assist with an intrusion can also refuse to investigate that intrusion. So the team loaded GLM-5.2, made by the Chinese company Z.ai, on to machines it controlled and set it to comb their servers.
The choice was revealing. The best models in the world were American and could only be rented through a service whose rules said no. The Chinese model........
