Tag Archives: Clement Delangue

Rerun anyone?

As I wrote an article propping questions there. I see earlier today, the BBC is giving us ‘Warning shot or publicity stunt – how worried should we be about the OpenAI hack?’ (at https://www.bbc.com/news/articles/cd9w22n9e4go) as such, I had some initial questions in my article: ‘Is it real or is it media?’ (at https://lawlordtobe.com/2026/07/24/is-it-real-or-is-it-media/) where I posted the idea ““The ChatGPT-maker said its agent – an AI system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.” Which is fine, but that is still programmer controlled. So as I see it “after finding weaknesses, was able to escape the test limits” it didn’t escape it merely found a weakness as its ML systems were taught to find out and went elsewhere. It reminded my of the 90s hacking setting where towards ‘password’ a clever hacker gave “1=1” invoking the ‘True’ setting. Then we get “OpenAI said the incident was “unprecedented”, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was “mind-blowing that all of this happened autonomously”.”” And now we see “Hugging Face said the hack was different from anything it had handled before because it was done at superhuman speed by an AI with little or no human guidance.” It is the “little” addition to the sentence that is validating my setting of “that is still programmer controlled”, because as I see it, “little guidance” might merely be human ‘adjusting’. And when we see “Hugging Face researchers guessed the mysterious attackers had used one of the big AI models but they had no idea who or where the criminals were.” So, the issues is even bigger, it could have been Organized Crime setting the parameters of a sandbox, I know it sounds outlandish, but there is either a massive shortage in structure and security of DML (Deeper Machine Learning) settings (so it could either be ML or DL) but the setting that this is out there whilst there is no oversight is something that most of the media is painting over with innuendo and whether this is given by some is not in question, also irrelevant. And we see this when we get to “The Scooby-Doo-style reveal was made even more bizarre – and worrying – because OpenAI said its bot did the whole thing on its own, without permission. The firm said it all went down during a test of its tech’s hacking skills.

Two new versions of ChatGPT, designed to be master hackers, broke out of a supposedly secure test environment and gained access to the internet.” We see “broke out of a supposedly secure test environment” implies that it was not secure and the testing facility (the sandbox) is lacking security and oversight. And the statement “OpenAI said its bot did the whole thing on its own” implies that the bot was not monitored or ‘left alone in limbo’ but we all know that any computer is  never idle, it is always doing something and whilst it depends on human interactions it is fine. With autonomous systems it is a different matter and OpenAI should have known that. They are supposed whole lot better than I would ever be and I reckon that the larger issue is what did OpenAI know ad what are they hiding, because as I see it, they are hiding something. I am not sure what and it might be innocent in most cases but as I see it, hiding something is fear for some illumination. That has for themes nearly always been the case.

Then the BBC hits a note that I was playing all along a for the most I hinted to that in the previous article (listed above) but the BBC is giving us “Was it truly a stark warning about the future of AI? Or was it a publicity stunt by OpenAI to show off how powerful their models are? It’s the kind of scare marketing AI companies have been accused of for years and, since the much discussed launch of Anthropic’s Mythos model, cyber-security prowess has been a focal point. One of the top comments on OpenAI boss Sam Altman’s X post about the incident summarises this skepticism: “If y’all can’t understand that this was written to purely brag about the model then I don’t know what to tell you.”” And the ‘statement’ “If y’all can’t understand that this was written to purely brag about the model then I don’t know what to tell you” summarizes it nicely. We also get “The OpenAI and Hugging Face incident is a real-world example of a broader issue we’ve been highlighting for months,” said Dor Sarig from Pillar Security. “Sandboxes alone are not a sufficient security boundary for agentic AI.” And I tend to agree with that. Any Agentic system requires different security requirements. Whether it is Fake AI, True AI or simple ML AI. An agentic system does not work according to ‘human’ settings. I tend to go back to the original chess computers from the 80s. They will try any movement that is possible until they get the right result whilst replaying every chess match that was programmed into its memory. And the chess computer is relatively simple. Hacking into a system has all kind of places to pass. I gave the window example in my previous article. But the setting of software is that they are set to libraries that give abilities to a program. You see, a program gets linked to <stdio.h>, <stdlib.h> and <string.h>, but merely these three open up options in I/O operations, copy operations that are not part of the program, but they are in that system and it can run by all of them in mere seconds, optionally finding alternative options. Even this is not AI, a programmer had to program it in and regardless whether an agentic system does it autonomously, it only does it because it was handed that training and these instructions, and the agentic system started to combine options and learnings and it learned (using my previous examples) that it can leave a location via a window, it does not require to use a door. Which makes me remember an MSDOS program that turned the speaker into a device. So giving it the instruction:

And then wait from a distance, whist I added this to the autoexec.bat of a friend and watch him go nuts why his PC is singing the tune of Monty Python. It wasn’t me, someone programmed the setting of a speaker to become a SPKR: drive. So when an agentic program gets creative it might take routes no programmer could anticipate, not even when he/she programmed it. Because the reality of the setting is that no sandbox suffices to any agentic program. As I see it, it requires a sandbox in a sandbox and when the agentic program gets out of the inner sandbox the arms of the outer sandbox go off and as I see it, because it was unmentioned, that setting seemingly does not exist.  So whilst I understand the position given by “Cyber security Professor Alan Woodward from Surrey University told reporters OpenAI had “egg on it’s face”, and Katie Moussouris from Luta Security went further, suggesting the AI industry is failing to control its dangerous inventions.” I kinda disagree and it comes from the plain setting that AI does not yet exist. And all this is the consequence of ‘experts’ covering each other by making claims that all this is AI, whilst it is mere ML/DL (I call it DML) and it comes from a programmer. And even as they are covering each other, and clapping each other on the back. They know that the wrong settings are in place, but they are in too deep and it will hinder whatever comes next. There is one upside, you see, the AI Kill Switch Act might be in place before True AI comes to town and that could be the one great good thing.

I get the doubt thrown my way and I get that a lot of people have no idea, even though they gave all their IP and data to ChatGPT. I never used it and until there is a real AI, I will never use it to grow ideas. So whilst IBM (decently recent) gave us “Key concerns include autonomous system risks, data privacy violations, algorithmic bias, widespread misinformation, and intellectual property challenges” which is something I gave several times in the past and it all comes from a programmer, and as soon as they get connected to some sort of organized criminal enterprise the fence is broken open and all that IP will go anywhere and everywhere. That is the larger setting and no one is examining the ML/DL libraries that these players are making and as such when these class actions are placed beyond the settlements that they can afford, the ‘sudden’ revelation comes out and that is the moment these programmers can’t remember anything. And whilst the setting comes to point that the dollar sign no longer validates the setting of “Tech companies argue that training AI on public data falls under legal “fair use,” while creators argue it is unauthorized commercial exploitation” we will get a whole new ballgame and whilst this all plays out, the tech companies are creating new libraries with these agentic knowledge basis making a secure sandbox even more difficult. Optionally it might even contain three sandboxes in a nested structure, but that is merely my view on the matter and I might be incorrect in that assessment. 

So whilst we are facing rerun after rerun and optionally faked settings of Google vs OpenAI, both against Anthropic and all against each other when xAI enters the fold. And all that time the are still figuring out both a Trinary system (I see that as an essential setting for True AI) and how that is voiced into data systems, because they will have ramifications. Which is why I see that Oracle and Snowflake have the largest chances in that respect. I am certain that this is a race that Microsoft is unable to get into and I have no idea where Google is there. I am decently certain that IBM figured this out before I did and optionally they have this ‘under control’ through what was LISP and is now optionally coming to systems in some point in the future. Because as I see it, the setting of a trinary driven system with what I tend to call an Epsilon processor would require a LISP driven setting where the optional inclusion and exclusion would run simultaneously and this requires some form of LISP setting (a personal speculation) and all this would come with IBM shallow circuits. And all this gives IBM the largest head start, even Google might not be able to compete and I reckon that IBM might have talked to someone like Oracle on these settings. I have no idea where IBM is in databases, because in the end any true AI system is depending on the data it has. The question becomes in the meantime, how to transform binary (fake) AI into trinity true AI. The setting will become the discussion among data experts in the next few years and it hold bearing to all this, because it also impacts on how sandboxes are designed and monitored. 

And it it important because as I see it, trinary data takes a fifth of the space whilst gaining 4 times the speed of processing. And that is the setting these data farms will have to content with. As such there is plenty of evolution coming, but in this the stages of security becomes essential and whilst you consider rate quote from Katie Moussouris from Luta Security giving us “the AI industry is failing to control its dangerous inventions” and we are nowhere near the setting of true AI and that is where sandboxes require a nasty upgrade and soon, because soon enough, the kill switch might all there is between our data and whomever has access to data farms. And with security failing like we see now, we might not have that much time left and that is where I saw the need for security, because there is every chance that some AI ‘dealers’ already know that their fortune is set towards who has the most data and there is a need that we need to keep our data safe, but others might not want to do anything about it. Naming names is highly speculative because we aren’t shown the real issues and these people don’t want the real issues to come out because when the game is up, these people are playing for all the marbles in the world and there can only be one winner. That is how I see it and I might be wrong, but at present I feel that I am more right than even I think I should be. 

Have a great day today, I am now a mere 80 minutes away from Sunday.

1 Comment

Filed under Finance, IT, Law, Media, Science

Is it real or is it media?

That is the setting, because in my mind when an AI goes rogue I see the gaming example of Shodan (System Shock, 1994) and even then, it was all set in motion by a simple programmer who wanted a nice shiny bauble (a military grade neural interface) so when the BBC (at https://www.bbc.com/news/articles/c3ek3gvdnj3o) gives us ‘OpenAI says its AI went rogue and launched ‘unprecedented’ cyber-attack’, in my mind I merely see Sam Altman, hoping for some limelight and that tends to have media settings. So lets take a look. And don’t forget all AI is fake AI, as such it is started by programmers, that is the underlying truth in all this. It starts nice, with “OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test.” You see, ‘Going Rogue’ means stop following orders, rules, or normal expectations and start acting independently. It describes a person, group, or system that breaks away from a team or authority figure to pursue their own unpredictable course. As such the programming in that setting implies that the instruction to follow its own course was taking shape. Optional it was some military implementation. As I see it, it never “Lost control of them during a security test”, but I’m willing to go with “It had poorly created boundaries and connections” and it got out of its ML loop, driven by DL making it a DML issue. In all this, ML is Machine Learning, DL is Deeper Learning and DML is Deeper Machine Learning (which is a amalgamation of DL and ML) then we get “The ChatGPT-maker said its agent – an AI system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.” Which is fine, but that is still programmer controlled. So as I see it “after finding weaknesses, was able to escape the test limits” it didn’t escape it merely found a weakness as its ML systems were taught to find out and went elsewhere. It reminded my of the 90s hacking setting where towards ‘password’ a clever hacker gave “1=1” invoking the ‘True’ setting. Then we get “OpenAI said the incident was “unprecedented”, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was “mind-blowing that all of this happened autonomously”.” And the skeptic in me is considering that Clement Delangue was in on it all along. So as we see that Agentic AI’s are also not real AI’s, but it has a complicated setting of libraries and a connected knowhow of what its data gives it, it cannot look into unknown settings as it does not have connected data, but a simple input like “check all channels” will make it check all the channels it can find, even the ones the programmer did not consider. It is not clever, it merely found what a programmer never considered as such it never escaped, the programmer forgot that you can also exit a building through window, not merely a door. Then we get something interesting. “Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4’s Today programme that the security tests are supposed to be within “secure environments”, called sandboxes, where you can “see what the models are capable of”.” As well as ““In this case, it looks like OpenAI didn’t make a secure enough sandbox,” she added. Instead, the agents created their own cyber-attack against the sandbox itself, finding a vulnerability which allowed them to escape the restrictions.” That sounds logical, but the underlying setting is “the agents created their own cyber-attack” which is what the programmer wanted, it merely wanted it to stay in the sandbox, and that is where the programmer fell short and when the media starts comprehending that the programmer is still the activator and we see this impact, we can understand that OpenAI is merely responsible, there is no going rogue, there is merely what programmers allowed for to happen, but “going rogue” is sexy and gets digital dollars clanking and there is the rub, was this real or is this all media instigated?

Then we get another cry of whatever. With “Neil Lawrence, Professor of machine learning at Cambridge University, called it an “impressive feat”, but cautioned it “falls well within the known capabilities of the current generation” of high-powered AI models. He pointed out that OpenAI is looking to list itself on the stock market, and faces intense pressure from rival firm Anthropic, which has made headlines with its own powerful AI tool, Mythos.” And I am with him on the “OpenAI is looking to list itself on the stock market, and faces intense pressure” and we see the mention of Anthropic, but it is more, OpenAI is allegedly sliding against Gemini (Google) and DeepSeek (China) and I have no idea where the others are. And as I see it the “Intense pressure spots” is what made programmers overlook the limitations that needed to be in place, or perhaps seen as better defined. That is the (as I personally see it) the truth of the matter. 

So when we see ““OpenAI are now playing catch-up, they are trying to demonstrate their own systems’ capabilities in cyber-security.” “It shows us that OpenAI are not capable of safely deploying their own technology,” he added. In its initial disclosure of the hack on 16 July, Hugging Face said it was still assessing whether any customer or partner data was affected and would contact affected parties if necessary.” I can agree with that, because “safely deploying” is programmer territory and I reckon that there will be two minds here, what the customer thinks it is transgressed on (any client wants money) and what the programmer sees as transgressed on (he needs a playable excuse) and that is where it all ends. Because when this comes to blows, it will matter and in all this we see “Meanwhile Travis Lelle, principal security engineer at cyber-security consulting firm Guidepoint Security, said the update marked a “sobering moment in cyber-security”. “This highlights a known asymmetry,” he said. “Offensive agents are unconstrained, while the best defensive tools are locked behind guardrails that cannot understand context.”” Which is interesting as the setting that Travis Lelle gives us is the setting that OpenAI is facing, there is a sandbox setting all whilst the programmer was set towards locks behind guardrails and as I see it, he never explained context to the Agentic AI agent. It makes it Fake AI, because the AI could never see beyond its programming and that made it go nuts beyond the sandbox. It is a slippery slope and it makes a dangerous setting, because what other things did the programmer not think of? Any ML setting can become an expert hacker, because it can do things a million times faster than any keyboard puncher can and agentic settings can merely go nuts on the target, because it will reflect to anything it can push against, like the 80s chess computers it merely goes over everything it has access to, like those chess computers that compute every match it was ever given until the play matches what it needs to and as it goes through 10,000 matches in less than a minute we thought it was clever. And we are making the same mistake again. These systems are fast enough to consider the encyclopedia Brittanica and  consider anything in a few seconds, these systems will act faster than any person clearing its throat. 

So whilst the article ends with “It comes a week after Chinese AI start-up Moonshot unveiled Kimi K3 – a massive new artificial intelligence model it said could rival top US firms.” Which explains the  pressure and we get that, but any system grown to a 1000 times its venture points is not more clever and it remains fake AI, as it merely considers more and it still cannot fathom intelligence that does not hold data, these AI’s are dependent on data, making it (as I stated before) fake AI and until IBM finishes its settings (optionally Google too) True AI cannot come to life and that is the real deal. Some greedy individuals want to call AI the AI, but without the Epsilon processor it will never be, because all this is set to binary fields and that makes the loopholes more and more realistic (and larger), but it is not. As I see it, someone will push one border against the next border and enable players like organized crime to get the entire bucket of data, all the data out there and that is the reality we all face. 

So I have a few questions in all this and it seems like the media is all whistling the same tune and that is more scary that anything else, because are they not willing to look elsewhere, or are they told to look in a specific direction? It is a simple question.

Have a great day

1 Comment

Filed under IT, Media, Science