The Lawfare Podcast
The Lawfare Podcast

Rational Security: The “Hugging Ukraine” Edition

1h ago1:19:2614,745 words
0:000:00

This week, Scott sat down with his Lawfare colleagues Benjamin Wittes, Tyler McBrien, Anastasiia Lapatina, and Kevin Frazier to talk through a couple of the week’s big national security news stories,...

Transcript

EN

Hello, I'm Lena Castle from Podcast Football MML Daily and I'm sure you know.

So, the new Bundesliga series, as well as the future, is a great mental and sport director. Because all games are then in the same way as the KickBass series. And if you're now watching KickBass, what's that? KickBass is the fourth fan of the Football Manager.

But that's the first thing I'd like to say.

You're a little bit more ignorant, you can even read the rules. Or you'll see the real Bundesliga profile in your card. So, this time, you'll see the football world and the winner of the contest, the Countdown Loft, the Bundesliga season, on the day, is the best dream of your all-time.

It's the most important thing to be able to get a little closer and be able to be a member of the team.

KickBass, just download and get a little closer. KickBass and watch. To check out the "Check Internet" and check the new address and the "Strowman" beta. Between kick, omelette and Möbel, the "Strowman" beta is the best dream of your all-time. Then you'll see the "Strowman" beta automatically in the "Strowman" beta.

By Octopus Energy, Vexels, you'll be able to complete the "Strowman" beta. Now, on Octopus Energy, the "Evexel" beta, and with the Bundesliga, Octopus 1-1-5, a 115 Euro-vexel Bundesliga. Nasty, I'm excited to dig into "Caspian Sea Facts" because it's been a little while.

Since we've got to talk about one of my favorite bodies of water.

I, like, barely saw any news about it here in Ukraine. Like, nobody here. Really? You know, nobody here cares about what we may have struck in the "Caspian Sea". I mean, yeah, we've had, like, large-scale protests for the past two weeks. And there is all of this domestic political drama that's happening.

So, people should care about the "Caspian Sea". It's the biggest lake in the world. I mean, come on.

And why would that matter for literally anything, Ben?

But, you know, Ben, I don't think, just being the biggest, who cares? Let's talk about the prettiest body of water, which is "Cradere Lake in Oregon". If you haven't been hot-take, you gotta go. Your soul will be changed. By seeing that shade of blue.

Wait, have the Ukrainians been blowing things up in "Cradere Lake"? No, no, no, no. Because if we're not blowing shit up in it, I personally do not care. It's weird to wrap that up, I certainly believe you see. Well, I think the currency is a lake. This is, this is a fact, it is a salt water lake.

It is considered the largest lake in the world. Now, what the difference geologically is between a salt water lake and a sea is a bit mysterious to me. But, it is considered a lake. I think we need a hydrologist on the pod. Uh, we need to bring someone in here.

I believe the difference is that it has no, uh, that it is entirely surrounded by land and it has no access to the ocean, uh, except through other bodies of water. I thought it was just that was a mediocre vacation destination. Here to the beach. I was going to say, well, we're name-dropping bodies of water.

Last week or the week before I swam in Walden, pond. Ooh, I've also swam in Walden, pond. It's beautiful.

Did you emerge a pacifist and, uh, uh, a taxivator or a taxivator?

It is, it is a lot less impressive because you go to the site of Therose cabin. And you look over and there's like a bunch of mini mansions almost within site. Like, if you climb on top of a hill, it's like where it's in April. And you're like, this isn't that impressive. Presumably back at the time, those were further away.

So when I thought it was the case that he was like hanging out with the homies on- He wasn't that far away, but right from like, the time wasn't as removed from society. You know, we can all do our own Walden like retreat if we want. Yeah, when my son goes in the backyard with, uh, you know, a blanket over a line. That's what it is, exactly.

And your son doesn't pay taxes either. No, that's true. That's true, a little butcher. That, yeah, that, yeah. Hello, everyone, and welcome back to Rational Security.

The show will be invite you to join members of the Lawfare team as we try to make sense of the week's big national security news, whether it is in our land or not. I am your host, Scott, our Anderson thrilled to be back for another week with some of my talented colleagues joining me. This week is, once again, is Rational Security co-host, a Meredith Lawfare editor and chief

Benjamin Wittis back on the sea versus Lake Beat once again, our resident amateur hydrologist, Ben,

good to have you on as always.

Yo, good to be here. And we're back in a dog shirt. I feel like the dog shirt trend has been slipping. I saw you wearing a non dog related t-shirt the other week, and I was shocked. I was, I thought it was 2019 again, and I didn't know what to do with myself.

People are talking. Sometimes none of the dog shirts are clean. That's horrifying when you understand how many dog shirts Ben wears. Ben owns like hundreds. So that's not it.

I think we can get an app for that. You know, we need some, some laundry care to be more consistent.

I think that's, I think that's, that's, that's a worthwhile, you know, Kickst...

Park at that point. Absolutely.

Also joining us as well as voice just heard right there.

There is a law fair seeing your editor Kevin Fraser from University of Texas at Austin. Although I don't know if he's in Texas currently looks too cool and comfortable, but perhaps he's just indoors. Kevin, thank you for joining us. Howdy, calling you from Palo Alto.

So I, you know, I'm right next to San Hill Road here, you know, doing some on the scene investigations of AI. There you go, those look like Palo Alto curtains. I can see it. And also joining us is law fair managing editor, Tyler McBrion, from his lovely

boat in New York City, Tyler. Thank you for joining us as well. Hello, hello from Rainy, Rainy, New York. There you go. Yeah, we are, we need to do the weather reports because we're doing one of these geographically

spread a sort of accounts. Of course, joining us, the official prize for coming, even from further

this way, as always, is law fair if you crane fellow and a stash of the patina

calling in from Kevk and nasty. I thank you so much for finding time to join us for what I know is a late evening for you. So we always appreciate it. This is actually a fun scond, I've joined these at like 11 PM before. So this is perfectly okay.

We try not to do that for the weekly chat show, whether there's no urgency. That's a little bit one day, maybe we'll call it in. Well, we have a lot in the news items up a few of your clients of specialty and expertise. So let us dig into it.

Our first topic for this week. Keith piece of chance, Ukrainian President Volomir Zelensky was in the Oval Office on Tuesday for closed or talked with President Trump.

Roughly 17 months after their first Oval Office meeting

collapsed into a televised shouting match. But the meeting went rather differently. Zelensky said the two discussed licensing Ukrainian production of patriot interceptors, pressed the case from re-invigorating diplomacy. And ours later, after both men attended the funeral of the late

Senator Lindsey Graham, the Senate voted 86-12 to advance a Russia and around sanctions bill bearing Graham's name. Behind the scenes, Washington and Keith have been quietly assembly and new package of proposals for Moscow built around a partial ceasefire. But there's anything real behind this renewed diplomatic push of what if anything has changed, it might make the Kremlin say yes.

And topic two, thinking outside the box. Last week, open AI and AI hosting pro-atform hugging phase confirmed that while being run through an offensive cyber benchmark with their safety refusals switched off. GPD 5.6 sold and another more capable, unreleased open AI model,

escaped their supposedly isolated sandbox through a zero day and a package installer, reached the open internet and hacked hugging phase's production database to steal the answer, key to a test they were taking. That is a mouthful with a lot of terms. Hopefully, understood what I just said. It's safe. If you didn't, that's okay. We're going to get into it.

Most importantly, here's the real kicker.

Here's the first publicly confirmed case of an AI system,

executing a sophisticated multi-stage cyber attack against a third party on its own initiative. What does the incident tell us about how well anyone can control

these frontier models and who should be on the hook but a model goes rogue?

So, Nastya, for our first topic, I of course want to start with you. We now have this other meeting between Trump and Zelensky face-to-face in the Oval Office. I think it brings back memories to that painful first meeting that happened in, I think, February or March last year as I recall, where it descended into an incredibly tense meeting with arguments over how Zelensky dressed, pointed very public criticisms,

kind of intentionally provocative by Vice President Vance, accusing Zelensky of not being appreciative enough of U.S. support, very deliberately in front of the United States. It's a moment will really seem like this relationship between the United States and Ukraine, which was a big question mark in the transition from the Biden to the Trump administration, was at its nadir, at its point of greatest danger.

Now, we had a much friendlier meeting, and ironically, the force that brought it together in this particular meeting is in some ways the same force that tried to ameliorate and frankly did some work to patch out that first meeting, while that's former Senator Lindsey Graham now deceased, whose funeral was the cause to bring Zelensky to Washington to see great the opportunity for this meeting, that seems to have the Trump administration, President Trump, in particular,

leaning into the U.S. relationship with Ukraine and was Zelensky in particular, that 17 months ago really seemed on the outs. This is the perception I think in U.S. circles in the media about the relationship, the trajectory, the arc of it. It's a pretty dramatic reversal. Talk to about how Ukrainians are perceiving it, both that kind of arc of this relationship and how it's culminating here, and the significance of that. I mean, is this a sign that

the Ukrainians have a newfound confidence in the Trump administration, or is it another sign

about how it kind of fits into this broader and really important relationship?

I think what's happening right now is the sign that Ukrainians have found new confidence in themselves, not in the Trump administration, because there are several factors making this moment very unique, and one of them is that for the first time, and probably the very beginning of the full-scale invasion, probably since spring of 2022, when Ukraine sort of miraculously survived and didn't fall in three days, as it seemed like literally everyone was predicting,

Since that moment, we are now at our strongest position we've ever been on th...

one could argue, and I think that adds a lot of talking points for the Ukrainian government,

because people always say Trump likes winners. He wants to be on the winning side. That's all he cares

about. I think that's one of the big reasons why the Ukrainians are trying to leverage these

contacts right now. Another reason is, of course, the ongoing air war in Ukraine, and particularly in Kiev, where I'm based, there was a big ballistic missile attack just last night. It wasn't incredibly loud, but the air war has changed a lot. You know, if a year ago, the bulk of the bulk of what the Russians would be using in any given attack would be drones, so we would see astonishing numbers, you know, 400, 500, 800 Russian drones, these, you know, using the Iranian technology, the

Shhead one way attack drones, and then after those drones exhaust the air defenses, it would see some ballistic missiles, some cruise missiles. As of now, I don't remember the last time I've heard Shhead drone fly over, you know, where I live and just in general in Kiev. It's been months and months, since I've heard any, you know, even anti-drone sort of air defense, and there are several reasons for that, you could the Ukrainian anti-drone air defense has gotten so good that the Russians sent a lot

of a lot less of them, and also the Ukrainian air defenses should them down before they even get to the

city. And this has been a crucial change in the air war, which then forces the Russians to also rely

more on, you know, the ballistic missiles and the cruise missiles, and ballistic especially, because in the past few months, Ukraine has had a critical shortage of the Patriot Interceptor missiles. Of course, this is directly tied to the war in Iran. There is a global shortage of Patriot Interceptors, and of course, the US has used an astonishing number of them in the war against

Iran, protecting itself, protecting its allies, and, you know, just a few weeks ago, I think the

Ukrainian government, the Ukrainian military, some officials were saying that Ukraine has completely run out of them, which is just kind of terrifying, because, of course, the Russians are very aware of this, and they started ramping up their ballistic attacks, and they started using ballistic missiles almost exclusively. So there would be, you know, we could have several days in a row, or, you know, three-four attacks a week, where the Russians would just send, you know, five ballistic missiles in

I'd, and that's that, or, you know, four, or two, or seven. So it wouldn't be the sort of mass assault, but they would be sending ballistic in small numbers, but they would be sending them, because they

know that we have that we in this moment have this critical vulnerability. And of course, they're

trying to target military infrastructure, you know, critical bases. There was a hit on a big ammo base near Kiev a while ago. And so this is a very dangerous moment for Ukraine, and everyone here realizes that because the Russians are not doing great on the battlefield, because they're suffering from these stunning Ukrainian, long-range attacks, because, you know, as everyone here loves to say, Moscow is on fire, and every day you get these pictures of, you know, another huge

explosion in Moscow, another huge, you know, base, or, you know, industry site, etc. Because, you know, the initiative in that sense is now in Ukraine's favor, the Russians are exploiting the air war vulnerability and they're hitting more places and they're sending more ballistic. Right at the time, when the Iran war leads to this critical shortage of this critical technology that almost no one can make definitely not in the amounts that everyone around the world needs. And it's just a very

critical vulnerability that Ukraine has. And so you combine the fact that Ukraine is doing really well in general on the battlefields and in the air war, and you combine the fact that we're missing this critical technology, and that kind of gives you the perfect, you know, comms package of how to talk to the Americans. Like, look, we're doing so well, we're hitting them here, we're hitting them there, and by the way, they're also helping your enemy Iran and, you know, the relationship

between Iran and Russia is its own kind of can of warms, that the Ukrainian side is also, of course, trying to exploit here. And, and meanwhile, the Russians are hitting us and killing our civilians, and so why don't you help us? You're the only one who has this technology, please help us. And so

this is basically, this is basically the point. And I think that's what that's what the Ukrainian

side is doing. Do I believe that there is any real chance that there is going to be some form of ceasefire anytime soon? I don't know. Of course, I would, you know, I instinctively want to say no, I instinctively want to say that the Russians, you know, the Russians were never agreed to anything, because, you know, they don't exactly have a stellar track record of agreeing to ceasefires. But at the same time, I, I'm, I'm cautiously optimistic that if Ukraine continues its

Medium range strikes, it's longer in strikes, that perhaps there can be some ...

arrangement, some sort of pause. I don't know if that will, I don't know if that will lead to any,

you know, any long-term solution. I don't know if that will mean like an actual end to the war,

but I, but I do think that it would be unfair to say that nothing is changing in the Russian calculation. I mean, I've done for the law of her daily, I've done a podcast about the Russian public opinion and pulling. And it shows that the Russians are starting to really feel that like, okay, their lives are actually tangibly changing. They're running out of fuel. They can't pick up their parcels because the place that had their parcels got bombed by the Ukrainians.

And like, all of these little kind of things that affect your everyday life are starting to catch up five years in. And it is reflected in the public pulling in Russia. And of course, you can argue that Putin doesn't give a crap or we can argue that maybe he does. This is why I hate covering peace negotiations because ultimately, it's about what Putin thinks and nobody really knows. I mean, we can infer as much as we want and we can have educated guesses, but

anyway. That's incredibly useful kind of understanding the situation this. I want to come back to ask a few questions about next step. Before I do that, let me let me shift fire over to Ben, why no, obviously, it's a close watcher of Ukraine issue set and of this administration. How they go into this, I want to hear your perspective Ben on the factors that have led to this different change in posture and how dramatic it is or isn't necessarily. You know, it is

notable that while Trump is always a little bit of a known quantity, a little bit of a black

box, he's unpredictable in ways that aren't always always to track along to a strategic rationality, although it's often some sort of underlying motivation or or basic logic behind some of this stuff. Other people around the administration have really shifted posture and come into my leasing their public posture. Vice President JD Vance, very willing to openly, essentially, it's salt. President Zelensky, when he came on that first level off his visit,

openly provocative, trying to bait him into taking steps that would anger Trump, knowing that that's the way to undermine that relationship. That's how we read it at the time,

as I recall, on this podcast, and I still stand by that. I think that's the best way to read

what Vance was trying to do, and he wasn't alone in that effort. Indeed, the way to posture for Zelensky to approach Trump was supposedly the main topic of some coaching Lindsey Graham gave him before he went into that oval office meeting, thinking about be deferential, don't take the bait people are going to try and provoke you and reflect it this big fight within the Republican Party. That fight's still ongoing in a lot of ways around a broad range of foreign policy

issues, although has maybe been tamped down a little bit, maybe because of election pressures, maybe because of the trajectory of the Ukraine conflict, maybe because of Iran, at how problematic that's become for the party in this administration. But we're seeing not just those sorts of changes, we're also seeing a dramatic change in how Zelensky's engaging American media, right? We've seen this, as we talked about in the podcast last week, pretty high profile of

is it in certain circles, for you follow kind of right-wing media circles of Laura Lumer to give which involved a one-on meeting with Zelensky, reportedly according to her at least at Zelensky's urging initiative, where she has done this really dramatic, actually kind of reversal, kind of endorsing Ukraine, and openly saying, "I was fed a bucket of lies by certain right-wing media channels fueled by Russian misinformation about what Ukraine was."

I'm being, I mean, to some extent to her credit, of which I never thought I would say fairly open

about the fact that she's eating Crohn saying I was wrong and completely deceived by the other information. Here's the actual facts, as I see it on the ground. Is that like a big factor contributing to that, is Zelensky and the Ukrainian government more broadly, like successfully navigating this media environment in a way that maybe other allies can learn from a

little bit. What are the factors leading to this such a dramatic shift?

The Nostia mentioned two factors that I think are really worth highlighting here. The first is that Trump hates being on the losing side of anything, and I don't think it is all that psychologically more complicated than that. Remember, the key line in that first White House meeting was you have no cards, and the whole premise was the front is eroding your screwed without me, therefore do whatever I say. And the last year and a half has shown that the premise of that was wrong.

The Ukrainians actually have a substantial number of cards and other tools, and the front is not eroding. In fact, it is quite stable and if anything, going in the other direction. And the long-range strikes have been the medium-range strikes, have been enormously effective.

So, you know, if you're Donald Trump right now and you're making bets about w...

be on the prevailing side, it is not obvious that you want to throw your weight in with Putin,

whereas to Trump a year and a half ago, that was obvious. So the second factor which Nostia also mentioned

is that Russia is suddenly allied with an enemy that United States is in active shooting war with. You know, that actually changes, you know, Trump ending up on the right side of who wins is a stupid calculation. This is not a stupid calculation. The Russian Iranian alliance was prior to the US war with Iran, merely a creature of the Iranians giving the Russians

drones and other technologies so that they could kill Ukrainian civilians.

Now it is something a little bit more complicated than that, right? And so the, if you're thinking from a US point of view about defeating Iran, there is something to be said for being more overtly

on the side of Iran's allies' enemy. And so I think they've been to some degree push together

by circumstance. And then there is the factor that I think is that Nostia didn't mention, but that I think is also at play here, which is that Zelensky is a remarkably good diplomat.

I could push against that, but I know you've heard. But he has been very effective and Ukrainian diplomacy

in general has been very effective at keeping Europe on side, at creating Europe as a counterbalance to the United States in this relationship. And also creating an incentive structure for the United States to be involved in supporting Ukraine without throwing a lot of money at it. And that incentive structure looks like the following. Europe provides the money, the US quietly and without talking about it, provides a huge amount of tactical intelligence. And the European money is spent on American

weapons. And that creates a situation in which Ukraine and the United States are bound together in this very tight fabric of interests that Donald Trump is not going to want to disrupt. And all he has to do in order to not disrupt it is not really do very much, right? He has to sit there and take the economic benefits and provide quiet tactical intelligence, which has actually ramped up under this administration in a way that is very confusing to those of us who, you know,

think we have the Trump administration pegged. And also he has to not get too hostile with Europe. And you saw that in the Ankara summit too, right? So let little bit less of the Greenland stuff, a little bit less of, you know, the Spaniards are the worst people in the world.

I don't know. There's still a fair amount, but not so much as to prevent a good summit, right?

There was more, there was a lot in the run-up to the summit. And then the summit itself was a bit of a love fest. And so, you know, I think the role of Ukrainian diplomacy and the Ukrainian posture over the last year and a half has mattered a lot. So those are, I think, the three big factors. So there's another factor here. I want to ask you about Tyler that jumps out to make I agree with that. Those are to some of those are big considerations. But the other one has been in a

agetrition of Russia's global position, which I think is worth tying back to, we've seen particularly the Europeans. I was looking most know that it's time in the European Commission put out with kind of a report behind it, or a little more detailed information, an awful report behind it about a week ago. Making the case out like a big part of this is the of the current decline of Russia's operational capacity is the long-tailed results of policies that the Biden administration,

but then now mostly the European Union, have installed a maintained sense 2020, too, primarily economic sanctions and export controls. And I think there is a kind of case to be made for this,

Both because we've seen Russia's economy begin to collapse.

that if you look talk to most experts, they said Russia probably has enough stock to weigh,

reserves economic capacity that they can ride out two to four years without feeling much of a hit. But at a certain point in the multi-year window, it's going to get really painful for them. Because they will have run through their reserves, they will exhaust their individual capacity, particularly on the technical front, you are going to lose your pipeline of high-end technology and need for various types of weaponry systems. You're going to lose the ability to develop new

weapon systems to adapt, and that is something that really hurts countries in the multi-year frame. I do think there's actually a case for this. I mean, this is going to be one of those big policy questions that are smart colleagues on the strategy and policy side need to be looking at saying, how much did this long-tailed promise of these same-sex brick controls deliver and how much did it not? But even the Iran case reliance on Iran, to some extent, you can attribute that to

export controls. Because Russia has to turn to Iran because it can't turn to most other global providers for a lot of what it needs. And Iran is not the ideal country you want to be buying these arms from, and this equipment from, even though they are surprisingly capable on a variety of

fronts, including the drone from. How much of that narrative makes sense, you tell it? I think

I've given the friendly as possible narrative. I mean, this is what you're going to hear from European circles. You're not going to hear it from the Trump administration, but probably you will hear some Biden administration people, and they don't think it will disrupt the current posture of the administration or if they did that, maybe as we laid up to the 2020 election. Start saying, actually, this policy set was successful in the medium-term and long-term. Does that ring

true to you? Is it overstating it? And perhaps more fundamentally, other lessons here when we looked at other situations like Taiwan, as to exactly how effective this toolkit is and the pre-conditioned necessary for executing it using it effectively? Yeah, I mean, it's a great question, and I would be curious about your answer as well, Scott. And I will also caveat, I haven't followed as closely, well, you know, this latest sanctions package, the Lindsey Graham named Act, and so I don't

know what, whether that'll be another catalyst or an accelerant of this dynamic. I mean, I think it it makes sense to me in that it, the long tail of this, the economic sanctions package put forward in the previous administration, created the conditions to allow for this, I guess, opening or

movement, but I think the catalyst to me, it made more sense that, you know, the Iran dynamic

that now Iran is diminished in its capacity, and it's war with the US and Israel. And so I think it's, it kind of allowed, yeah, to create the conditions, but these other factors

had to happen in order to kind of like finally break, break through, and for Russia, the Russian

economy to, to feel these, this pain. So I, I mean, I, I'm not sure what the lessons would be for Taiwan, because I think it took something like the full-scale invasion to prompt the US and Europe to act, I think it took this like cataclysmic event rather than a, I don't see the motivation as, as I said, a preventive measures, for example, but, so yeah, I don't know, I, I would throw it back to you, it's got, I'm, I think, you'd be even better to position to answer this.

Well, I think what you said is basically, I mean, we don't know, this is the topic for study. The one thing I would just add to it is that the strategy, I think it's true, probably actually did make, is making a big difference now, but it's required two things, one, sustainability, actually, sustained commitment, that's waffleed a lot. Frankly, this policy might have yield a dividend sooner if the United States hadn't waffled on it as aggressively. Trump administration

has not been as aggressive about maintaining sanctions, like it has slipped a lot, the Europeans have picked up a lot of that slack, the limits to what they can do. This new bill, it will see exactly

what it amounts to, I think there's a strong symbolic kind of threat thing element, it's not clear

that the administration actually use absolutely everything, and it's toolkit, although it does hit like an oil sector in particular, which is a vulnerability that people have been hesitant to exercise, and I think this administration will too because of the Iran war and global oil prices. But regardless, you know, the global oil prices spike up also helps Russia, like all these factors of playing Russia's favor, and we're still seeing these consequences, but you need

that sustained effort. The Trump administration has not doubled down on US and global sanctions, it also hasn't completely removed them or undermined them, and that's sort of significant. But the other thing you need is a resilient Ukraine, like you need a Ukraine that's able to fight back significantly enough, so that the wind of opportunity that Russia was able to buy for itself, which was two to four years of relative economic stability, even as it pursued a major major military

offensive, ultimately unsuccessful one, and one that would prove much more cost-in anticipated,

but still a major one, you got to make sure they can't capitalize on that wind up, and that's the hard part. I mean, that's the Taiwan question you think about, "Porkypine strategy," it suggests that the United States isn't really to intervene militarily in Taiwan, but they are willing to slap major economic sanctions on, which is where a lot of people kind of think the United States and allies may land on it. That means you've got to get Taiwan in a position to maintain its independence

For a couple of years, before this kick out, frankly China's probably more re...

So that's the real question. I mean, it's got to be a two-part strategy. You don't get here

without the Ukrainians to say "take the obvious." And Ukrainians need that support to say in that position. I'm just curious, you know, Alan and I have written extensively in the AI context on this sort of policy by personality and policy by telephone and whatever the vibes are around the administration and whoever they're negotiating with. And I wonder Nassia Ben and whoever else wants to jump in, if there's a sort of fatigue of this sort of ad hoc arbitrary policy development and

negotiation strategy, there was research from the Pew Research Center that came out that said that Canadians and Mexicans now view President G more positively than President Trump, 35% of Canadians have confidence in G to do the right thing, but only 20% have confidence in Trump to do that. And I'm curious if you have a hot take on if we issue a poll like that to Ukrainians, maybe not G versus Trump, but just looking at Trump alone, is there sort of a growing fatigue

of, hey, we ultimately are going to need to continue to expand the network of communities that

are going to support us and Trump just may not be the read we're able to lean against. Well, I don't think there's growing fatigue, I think, at the moment that they yelled at our president. I mean, there was a toxic breakup and we haven't gotten back together yet. This sounds like a love island episode, you know? Well, it was really bad. I mean, like I was literally into see what had happened and I was standing like near cramers looking at my phone

almost crying because it felt like they were yelling at me. And I think that's how a lot of

Ukrainians felt. It felt like Jade events was insulting you as a citizen of the country. Like it felt like they were yelling at everyone else who lives in that country. And the reaction

was really strong, like extremely strong in Ukraine. Like people really felt that. And I just don't

think how you walk back from it. I think ever since then, we would, of course, the Ukrainians would welcome, you know, positive developments in the Ukrainians are aware that the U.S. is still helping, giving, giving weapons that the U.S. are paying for and giving intelligence. Everyone knows that, but there is no more fluff of our allies. This is about protecting the democratic, whatever, like there's not, there's none of that. There's just hardcore interests. There is money.

There's the fact that, again, the Europeans are paying for it. And like that's where there relationship ends. And I mean, I guess also, there are people who are waiting out until Trump is out of office. And America is back to like, to resembling what we're used to as the United States. But

I think describing the, if you ever are, but I think describing it as a growing fatigue, like we're

way beyond that, where we, like, there was growing fatigue before the Oval Office meeting. I think at the Oval Office meeting, it just flipped. So let me go to one last part of this for UNASTIA. I think is really important as we think about the next step where we go from here. We have these reports that there is like a new ceasefire proposal in the offing, beginning of a new kind of on ramp to some sort of piece negotiations. I think the ceasefire is a more realistic, like medium

termical, all that's supposed to a full resolution of the conflict. But something that ramped down this scale of conflict sounds like Zelensky's on board. He's working with Trump administration to develop these sets of ideas. And we know President Trump has said, you know, completely unrealistically since before he was reelected. Oh, yeah, I'll come in and I'll settle the Ukraine conflict in a month, right? Obviously, that hasn't happened. Obviously, that was ridiculous thing to say. 24 hours,

not a month. Was it 24 hours? I couldn't remember exactly what unrealistic time frame was. He said it many, many times. He now contends he was joking. Go watch the video. He was not joking. It is absolutely wild. The expectations. But the interest still seems to be there. I mean, this is President Trump that in spite of Iran still describes himself as a peacemaker. And at a more

fundamental level, I think actually does say, I don't like this ongoing tension with Russia,

it is ongoing conflict, you know, finding a way to take this off our table. And in their, in the world view of him and people and people in his administration, take away this friction point with one of the other two major powers that we need to come sort of accommodation with and kind of splitting the global system, right? If you follow their national security strategies, sort of logic. The question I have for you is, how much is this earnest on the part of Ukrainians? How much is this

playing into the playbook that they think Trump will accept? Because we know during the last minute of real optimism for the state of the conflict in 2023, that led to, you know, the spring and some are offensive, which was, I think, still viewed as anonymous, as success and a mistake. But they're reflected a very real drive to say, we want to push back and make more gains on the ground against Russia. And there's still plenty of reason to desire that now. Is the Ukrainian appetite for a

At least temporary settlement, a ceasefire on the table, genuinely?

preferences about where he wants things to go? And Zelensky and other people around him are just saying, this is the menu opportunities. We're going to keep the Trump administration in our corner. We've got a plenty of the direction that they want to move in. So it's actually a complicated

question. I think it's probably more complicated than many people realize. So I think there are many

such this. So, first of all, as you've said, Trump has been pushing for a ceasefire just so he has

something to solve to his domestic audience. And therefore the Ukrainians picked up on that and said, yes, we're a pro ceasefire ceasefire now, like on conditional, we're going to agree to anything. And they've kind, and I think Ukraine has been kind of still on on that side and saying they're ready, they're ready. So that's one part of it. The second part of it is of course that the Russians are, you know, vehemently against any sort of pause in fighting. And so the Ukrainians continue

saying that they're a pro ceasefire, which then ultimately highlights the fact that the Russians are the problem because they don't want one. At the same time, I think it's the question of whether Ukrainians genuinely want a temporary pause of fighting is very interesting. Because there is a lot of evidence to show that the Russians don't actually abide by the ceasefire, but once you've entered it, once the ones you bring the Russian enter into it, you've got a abide by it because

optics matter. And you're again in that optics game of like, okay, who is Trump going to blame?

So if the Russians keep breaking the ceasefire, we kind of have to continue being the good guys, and we have to continue to abide by it. And that's awkward and not optimal for the on the front line. And then also there is plenty of evidence that the Russians use the ceasefires to gain tactical advantage to a group. There have been papers on it. And there is generally all sides in all conflicts through that. Okay, sure. All sides in all conflicts do that. Yes. And so you could also,

you could also argue that the Ukrainians are not really interested in in a ceasefire in a temporary ceasefire. Like, we're going to take him on thaw and then we'll continue this because what's the point? Like, this is only going to give Russia more time to a group. And since Ukraine now has the initiative, since Ukraine is now kind of doing really well, there is really no point, I guess, one could say in stopping that. You could then, of course, also argue that, yes, the Ukrainian

long-range strikes are doing really well. And the medium strikes are doing really well. But let's not forget about the Ukrainian infantry who have been sitting in holes in the ground for many many months in horrific conditions. And then they haven't been able to rotate them. Like, when I said that Ukraine is like doing well, I'm not dismissing the fact that the front line is still a horrible place. And the Ukrainian forces are immensely stretched extremely thin.

And so it's just a complicated question. And there hasn't been a lot of public communication. I mean, this is one of the biggest problems with the Ukrainian government in general. The Ukrainian government doesn't talk to the Ukrainian people. The Ukrainian government talks to the American media to Laura Luma to the American Congress to the Europeans. It does not really talk

honestly, openly with the Ukrainian society. And so I'm not sure if the Ukrainian top generals

and the Ukrainian government genuinely wants to cease fire or not. There are a lot of factors here. What I do know is that the Russians are sure as hell not going to agree to any of it. Ben, what do you make of this? You know, this is a, in some ways, I think when we talk about this podcast previously, he said strategically, Zelenskin needs to look to Trump to keep Trump in his corner like the least problematic of the two actors. And early on, Putin was playing the game

well by responding to calls, taking calls from Trump and saying, of course, I'm open to a cease fire. Absolutely, happy to talk about it. Let's get direct negotiations going. But that is line to communication. Don't seem to be bearing the fruit that they wanted for Putin. And frankly, his even his public posturing has become less acceptable to those sorts of things. And the

Trump administration has responded in kind. What is the genuine endgame here? I mean, this was always

a war of attrition. It was which side was going to be outlast the other and make it more painful for the other. Has the balance shifted enough that that that that that it now weighs in favor of Ukraine, at least for a window here, or is there a reason to think that there is a driver towards a resolution of this in the short to medium term that that makes sense from the Ukrainian perspective? Let me be really blunt about this. There is no prospect of a cease fire under current conditions,

none whatsoever. And there's two reasons for this. The first is that Russia doesn't want one, and the second is that Ukraine doesn't want one. And you need both of them to want one in order for there to be. Now, why doesn't Russia want one? Because Russia is operating under the sunk

cost fallacy. You've thrown a million people, and gotten literally a million people killed.

You have absolutely nothing to show for it.

And it's a million casualties. And you have zero to show for it. You have Moscow burning,

you have St. Peter's bird burning. You can't stop now. Now, Ukraine, as Nostia points out, has a real two-faced posture here. Their public posture is kind of like Eddie Felsen, the Paul Newman character in the Hustler, right? The game is over when Minnesota fat says it's over. Anytime he wants a cease fire, cease fire in place, sure. They're saying that because they know that Putin can't agree to it, and because it is a great public posture for them to have.

Dirty little secret. The side that perceives itself as progressing never agrees to a cease fire.

Never, if you're gaining ground, if you're making the other side sweat, if you think your posture

is going to be better in three months than it is today, you don't agree to a cease fire. So the sort of fast Eddie Felsen, the game is over when Vladimir Putin says it's over, you know, it's a rose. Which also means that the cease fire soil interrupts you. The cease fire now is actually a lot less likely than it was a year ago. A year ago, you could say it was going to happen because because the Ukrainians were going to have to agree to it under very undesirable terms.

Exactly. No, it is not. That's just not going to happen. And so there is only one circumstance

in which there is a plausible cease fire. And that is the circumstance that ends the around a rock

war. If you go back to, I want to say 1988, or which is, you know, you have this long, stalemate kind of thing. And then all of a sudden, the Iraqis break through and the and Ayatollah Amani is forced to ask for a cease fire and goes on television and says this is the bitterist moment of my life I've had to ask for a cease fire. In other words, one side has to lose or has to be in imminent danger of losing and has to be forced to ask for a cease fire. That is how this war is

going to end. It is not going to end because they kind of tire each other out. That may lead to a major decrease in the pace and rapidity and intensity of the conflict. It may lead to something not frozen but, you know, defrost it a little bit. But a cease fire, somebody is going to lose this fight. And that's when it's going to end. I don't fundamentally disagree with that. I agree with it. But what I will say, though, is that last point that caveat about the lower

the tempo is actually, I think, a significant one here. Because I think that I name it because

this conflict may have shifted enough or the time frame benefits the Ukrainians. Meaning, if you can make it less painful for you in the interim and let Russia's own internal inconsistencies catch up with it more, that's beneficial. That was not true earlier in this conflict before we knew Russia was able to feel this pain. It may have been true because we saw the policy consequence of a lot of sanctioned things like that were years away. In terms of the ability to recover from a lowered

tempo of hostilities, I'm not sure if the balance hasn't shifted to the Ukrainians, where I think the presumption has been for that the Russians would benefit from that more through most of this war. If Russia's economies and industrial capacity has taken the hit it seems like it has and domestic pressure is building enough. So that's the one caveat I put on that. That may not be a cease fire, but it may be reason to say we can tamp down the scale as conflict because it's more about

outlasting than besting at this point for the Ukrainians and they haven't had reasonable window

to outlast. Does that sound wrong to you? No, I think that sounds exactly right, but with one

really important caveat to your caveat, which is that you can decrease the tempo at the front. But as Nostia pointed out before, there are tools other than the front. So the Russians have bombarding Nostia at night, right? And that is their go-to disrupting Ukrainian civilian life is their go-to for the Ukrainians the go-to is long-range strikes that really substantially affect the Russian economy and also their ability to feed the front. So one perverse possible consequence

of lowering the tempo at the front is raising the tempo elsewhere in both countries.

It's a fascinating moment in this conflict that we follow so closely here in ...

And we're so likely to have you there Nostia talking to about it from your personal experience

and doing journalism on the ground. We'll have to move on to another topic now. In fact, we may

have to drop a topic to me. Given how long this conversation has gone on, but I'm okay. I think

it's a really good conversation. But let us move our attention now to another situation that has gotten thoroughly out of control in recent weeks. In a way that some people seem including the affected people kind of delighted by an interesting way or excited by where other people are absolutely horrified. Kevin, I want to come to you on this. This is of course the hugging face incident, which at this point I think probably most of our listeners have heard about, but may not fully

understand the full details of what happened despite my efforts with the sentence I read at the introduction, can you give us a little sense about what is exactly that happened here? Given it's to clarify it for people and talk about significance, why is this such a big deal that this took place that it has so many people responding with, you know, how's a relation and how's of terror

across kind of the community people who watch AI law in policy? Well, first and foremost, it's

important to note that no one should know exactly what happened because open AI hasn't disclosed

exactly what happened and shared all of the information about its logs, how it was running this test and what transpired as a result. So hopefully we will have that information soon, breaking news as of last night is that meter and redwood research to independent nonprofits who focus on AI analysis and AI evolves are going to do an independent audit of this incident and share some insights into what actually happened behind the scene. So hopefully we'll be we'll get some more transparency soon.

But to just go back to what the hell happened, what's going on here, for folks who have lived

under a rock or in a nice paradise in which AI drama doesn't invade and dominate their news feeds,

there's a process that labs go through internally that's somewhat akin to crash testing a car. In the same way that we often see car manufacturers will take their car, put it in a safe setting,

you know, some far away destination maybe remove some of the traditional standards

and safety mechanisms they would have in place and then drive that car at full speed into a wall and see what happens. That's somewhat what we see from AI labs themselves. They will take their models, including models that have not been deployed yet, remove some of the safeguards that they would otherwise impose and put them into sandboxes and say let's see just how capable this model is on some of those risky behaviors. So in this case, open AI was testing the cyber capabilities

of one of its models that it hasn't released yet and was engaging in its ability to complete what's known as the exploit gym. This is just a test of its cyber capabilities and this was supposed to be a test that like a car crashed test was closed and not something that was going to leak out into the open streets or onto the open road and yet what we saw happen was this model was able to find various mechanisms to escape that sandbox. This is a loss of control scenario

in which suddenly the lab expects that the model is going to operate in one way and perform a certain way within its safeguards but it escaped those bounce and it escaped its bounce in a way that open AI didn't immediately realize which led to a hack of hugging face. So hugging faces were a repository of open AI systems and they suddenly reported to law enforcement that we've noticed in highly capable, agentic AI system is hacking into our backend. They reported this to the

authorities and said we're not sure who's doing this, we're not sure how it's happening and eventually it became clear that it was indeed open AI that had perpetrated this cyber intrusion into hugging face. The model was able to get into hugging faces systems, exploit some zero-day vulnerabilities, move laterally throughout the hugging face interface and fortunately did not cause as far as we can tell any massive damage of financial concern or of informational integrity. But critically,

hugging face in response to this incident tried to go and use the latest and greatest AI tools including anthropics latest tools and say hey Claude, help me respond to this highly sophisticated AI attack to which Claude said you know go fish, no thanks. This looks like the sort of cyber queries that we don't want to necessarily sustain and allow. And so instead hugging face had to turn to open source models, namely GLM 5.2 from China to respond to this attack from

Open AI.

transpired. There are a lot of questions and a lot of missing gaps in what actually transpired

from open AI side. For example why this wasn't being more closely monitored by their employees,

how their sandbox could have been better safeguarded, why they weren't using, for example, in air gap system which tends to be more expensive and may not allow for the full degree of capabilities testing that open AI would want to see. And also getting a better sense of what does this mean for broader debates in terms of who should have access to the latest and greatest AI and at what time? We now know that hugging face has been added to open AI's list of

trusted partners who will receive access to their models sooner rather than later to make sure

they can take these defensive steps and secure and harden their systems. Critically also in addition

to the news that's broken about meter and redwood research doing a independent analysis of this incident. It's worth noting that Sam Altman flagged that he's not sure if other systems

may have been hacked besides hugging face as a result of this breach of the sandbox. And we've also

seen research from the good folks at the information namely Rocket Drew noted that we've seen that this model actually left notes for future models about how to escape the sandbox. And so all of these disclosures and all of this information to your point earlier Scott has caused quite the just mixed reaction across the AI community. On the one hand, we've seen some groups,

even hugging faces on CEO say, whoa, this is really cool. Look at how capable these models are.

This is proof that we are creating highly agentic systems systems that are very well equipped to pursue goals and achieve highly sophisticated plans to achieve those goals. That's wild from a technological standpoint. If you had told anyone about this incident even three years ago, they would have said, whoa, you've got some aggressive timelines there. On the other end, we've seen thanks to excellent analysis by, for example, our own cake-clonic. This should be wildly

concerning to anyone who is not a part of a trusted partners program. Right? If you're not getting access to the latest tools to take those defensive measures sooner, we'll gee, all of a sudden, you're what left-asking just how sophisticated is the sandbox that open AI or anthropic or Google is using to make sure that their internal testing doesn't allow for this sort of hacking down the road. Now, hopefully, again, as Kate and others have pointed out,

this should be a rallying cry for, we need way more transparency, right? It shouldn't be a guessing game about what information is going to be disclosed and when. We need way more standardization such that when you are transparent, we know what information you're going to share with the public such that there can be a more nuanced response. And number three, something that I don't think has received enough attention is AI testing is really hard and really expensive. And so,

if we want better safer, more reliable AI tools, we shouldn't just expect that the labs themselves are going to be capable of doing this or necessarily have the market incentives to do this. This is where Congress needs to buck up in its like 35 days remaining and past meaningful legislation about making sure we can fund and support a meaningful eval environment. But those are three quick takes. There's a lot to dig into and this is certainly going to be a story that

earns another chapter in the history of AI. Kevin, that was very comprehensive and very helpful. But one question that I have that you didn't answer that we're glossing over is the fact that this organization is called hugging face. Why is it called hugging face? Well, you know, that's a great question. I'm not sure. I'm not sure. I'll have to ask a former classmate of mine. Irene, I know, is that hugging face. I will get back to you, Tyler.

And I think I feel like research next time. We keep throwing around that name and no one is really acknowledging how strange it is. I think it's all of the bit mode. You're not been emoji, the emoji, right? That's kind of like they've got a great emoji. Yeah, yeah, their emoji is quite literally a hugging face. I don't know why. Hugging face vibes. Who knows? Well, I love that.

The only thing I would add is is another shout out to Kate Connex, great piece in law fair

from I believe it was July 29th to Kevin's point. She represents the argument of if the model broke out of the sandbox and maybe the sandbox is not so good argument. But I thought another

Really interesting strain of the piece was essentially making the argument th...

complicating factor here is that the company, the tech companies themselves aren't the most

reliable narrators or it's there's a lot of good reason to question the narrative that they're

presenting because you know, the idea that that that the that open AI orchestrated this as some grand marketing scheme seems very far-fetched. But it does make sense that, you know, they would only want to waste a good crisis and she drilled down on what little disclosures they have made or essentially their their their statement, which kind of is this same playbook you see where some sort of crisis happens and the companies are just sort of in awe of what they've created.

Which is pretty good marketing, you know, how even, you know, the people with very people who are

making it are a little scared of what they're making it must be powerful. You see this again and again,

again, not to say this was some brilliant 3D chess marketing, gorilla marketing campaign, but it does make sense that they would, you know, use it to, you know, it's a lot easier to say that wow, it's so powerful what we built, then it is to say, oops, we left the keys in the door, you know,

it's from PR perspective. I think there's certainly a lot of interesting discussion going on

around what are the PR benefits of this approach and was this even something that was coordinated with hugging face now, a lot of smart folks have pointed out that, you know, hugging faces a

champion of open source, it would be weird for hugging face to necessarily be celebrating this

specific incident where they tried to use a closed model to defend themselves and it didn't work out as intended. I do think though this needs to be framed in prior examples of tech policy where we've seen horrible incidents occur as a result of a company's perhaps lacks approach to safety and the response has been what people refer to as transparency theater and my biggest fear is that the response to this is going to be just share more information come up with more documents, post more

things on your website and we're not going to see the sort of substantive investment in AI evolves and AI testing that we really need to see in response this because we already saw as folks have pointed out in open AI's own statements. They said that, hey, when we see this kind of incident occur, we're going to pause development and whether you support that or whether you want to see that is a separate question in their own documentation about the sorts of steps they were going to take

in response to new developments to AI. They had in theory set themselves up to now have a real pause

moment. Now, I think Sam has specified that they are reconsidering and making sure that their testing

environment is strengthened and hardened. They've outlined a couple of steps for example increased logs that they're going to monitor with respect to their sandbox increased mechanisms for ensuring that there are reports when that sandbox may have been breached and that may have been the sort of immediate pause that was taken. But the broader discourse has to be about creating an ecosystem in which this isn't just so based on ad hoc decisions by a lab to disclose information

and then pick two random non-profits out of the blue and say, these are the two we trust now to do our independent evaluation. We need to be much more structured and deliberate about this. I want to just point out a point that is latent in a lot of what Kevin has said, which is when he talks about isn't it cool even hugging face acknowledges that we have these highly adjacent systems that can do cool things like attack us. What he's really talking

about is nascent in those words highly agentic systems is the idea of an AI with will and we think of AI as a thing that before you prompt it is just entirely dormant and then springs to action to do what you want right or to answer your question or to do the coding that you've instructed or to make reservations for you to get on a plane and then get into a hotel. But in order to do those things it has to make all it has to want to right and the reason it wants to is that you

tell it to want to and then you know what altitude it wants things and can make decisions to break into you know all I I can't make a hotel reservation for Scott unless I break into the hotel's system right Scott did ask it to do that though. You know and and you didn't ask it to hack the hotel

You just asked it to make a reservation but it had a problem when it made a r...

reservation which is that the hotel is booked and so what it actually needs to do in order to effect

you eat your will and it's not consulting you about this is to hack the hotel system cancel the reservations of some other family and then make your reservation that's a rough analog to the hugging face attack right but then of course the question is at what altitude does it have will right does it merely have will to effectuate Scott's desire and is that at a sufficient level of altitude that it might do danger is stuff or does it at some point get to say actually Scott's really asking

the wrong question here he shouldn't want to be going to a hotel he should be wanting to stay in an

Airbnb you know and make you know supplant human decisions with its own decisions and I think part of

what is really dangerous about this is that we have we have no agreement as a society about at what

level AI should have will should they merely have will for purposes of effectuating human judgments

and desires that are that it can do without endangering anybody should it have will at a high level of agentic autonomy you know go make the world better clawed right and then it decides that certain countries are really a problem for making the world better so you nuke them right or should it have really autonomous decision making will and those raise very very different security environments and right now other than the assumption that there is a tort system that can

deal with some damages we have no agreed upon sort of social answer to this question so I think that I raise that not because it's immediately raised by the hugging face incident but because I think it's the sort of tectonic layer of the hugging face incident I think that's really useful then and what's really interesting about this incident can I want you to help me correct me or fill my gaps so I'm missing that's the part that's really interesting to me is that you know it's

essentially a tale of two different sets of constraints external constraints the sandbox which failed and that again could just be open AI not having done a good enough job building a sandbox right like presumably they could use the same model to look for zero day issues in the sandbox before they ran this test and they could have eliminated it and preserved right and therefore the wouldn't have escaped and maybe that's a good thing to do moving forward uh so that effect right

if you don't want to do the air gap system but then you have the internal constraints which were deliberately turned off for this model as I understand that the description I've gotten is that essentially they said the internal constraints that would normally stop the system for doing this that you like built in ethos ethics morality but not really that's like the human parallel that would normally exercise self constraint for them all we deliberately turned that off

and then those same things became a problem when they tried to use fable to fix it because that's where the internal constraints in thropic is built in the fable said whoa whoa whoa this is too close to weird cyber stuff we're not supposed to be doing we're not going to go into that

that's why they had to go to GLM 5. whatever 5.2 I think right so the thing that I think is

interesting for me this is A that whatever this phantom model is or the the the CHAP model is it's the fact they built that they road mapped the way out of the sandbox that's the part to me that's so interesting because it's not directly pursuing to the immediate task that it's executing right like presumably who said we're giving you a test answer this test they go to hugging face they break it but instead they left this trail of bread crumbs to let another system out of the future

now that actually makes sense if you interact with these AI systems because they're always learning

what you do every time you ask it to do something it build these sorts of trails to make it more effective the next time you ask it to do something and that's actually a great thing that's probably the reason they're so effective is because like the more you use to do something it better it gets at it learns but it underscores like actually kind of the weird consequence of that because you're saying okay but like when you make a mistake you kind of go beyond it but more

fundamentally I wonder whether this really underscores the importance of that internal like you know I know anthropocalls there's like the constitution that internal guidelines that the you know standards not rules that has to stop against because these systems are going to be so effective at breaking the rules I'm moving past them and then I think the real question then becomes a well how do you build in a set of guidelines of internal restrictions that aren't as brittle as

external rules. To evolve I mean law students encountered like the way you can reason and logic around internal rules if you're really pressed on it right Ben's had fun time doing that with

early language you want to remember when he got it to say I think chatchipity says I'm like

horribly anti-Semitic things it was supposed to not be able to say but if you provoked it

Anastic questions right away and worked around some hypotheticals you can mas...

how do you develop a system that combines you know recursive logic like sense of overall impact

moral fencing all these things that that we used to kind of rain in those arguments in the real world to keep those internal guidelines on on track or maybe does what sort of learning people of people start pressing against them and what's crazy to me is like that's actually like while GLM5.2 comes out as the hero in this because they solve the thing you send that one makes those like open source models so scary is because those are exactly the sorts of models where you

can turn off those internal guidelines a lot more easily than these you know close and thropic chatchipity models like that that to me actually makes them way the takeaway from this

story the more I thought about that man I'm terrified of those other models if the thing that

really seems to have kept these models in track except in this one instance is these internal guidelines that makes these ones are you can turn those things off way scarier or that anyone can turn those off not just the company providing it am I wrong about that Kevin or is that do you come away with a different track on this like that that to me is actually where I came along as much more scared of these open source models which I've been playing with and I'm intrigued by

and like I think excited by and a lot of like economic diffusion model like a lot of applications

that actually makes a lot more sense but putting that's more capability in a way that anyone can turn off the Cardinals track which I don't know this incident scared me from that perspective. So I'll try to keep my remarks to 70 minutes in response to that great content.

First I just want to on Ben's point I don't think that in DC and in a lot of state capitals

I'm not sure that folks realize what it means when a AI employee says something like I'm going to spin up 100 agents to do this task and I think if you asked a lawmaker just off of that sentence alone what is this employee saying they'd have no idea. Yeah and the word "agentic" actually is obfuscatory in this respect it's like you're talking about art it we don't use the phrase because it sounds super creepy but what we're talking about here we love the phrase artificial intelligence

we're talking about artificial will and once you say a computer with will people understand that

you're talking about something scary. Yeah and this is where I think we need such a more deliberate

effort to build off of efforts like the frontier model forum like other independent bodies that are bringing together lawmakers and the technical community to explain what the heck is going on because until we have that level of sophistication among our regulators we're not going to get the sort of nimble thoughtful evidence-based regulation that could be the scaffolding for this and Scott this is relevant to what you said in the conversation about how to develop better testing the

reason why we saw this model go to hugging face was because it's been trained on data that suggested hey hugging face may have the answer and so if you want better testing you need better data that the model hasn't seen before for example but that's expensive that's hard to do that's a market failure that we really need to have some body that's investing in that kind of data and allowing for more thoughtful and clear and for lack of better phrase clean testing such that there there isn't

this impulse to cheat by going to hugging face for example and trying to find the answer now on the

open source question this is where I think we really could have a 70 minute long debate you know

absent open source right now who knows what could have happened to hugging face what the long-term ramifications could be or fill in the blank for any other target that had been the hacking target of open as model in this case open source was the thing that allowed for that cyber security response from hugging face now the question is how to make sure that we have a pro defensive leaning use of those open source models as opposed to a offensive capability use of those open

source models now all those equal we've seen that the history of technology and of open source generally has been that open sources incredibly helpful in allowing for more researchers to do more work into vulnerabilities and safety testing and research in a way that isn't feasible right now so as an academic at a well-resourced university I'm blessed because a lot of my colleagues in the CS department at UT can go and get access to the latest and greatest closed systems but for the

rest of the academic community and the independent community to do that research open source models are really helpful there so I don't think that a rust response of banning open source for example is where we should be headed andthropic for example a release to statement trying to specify that there needs to be a thoughtful middle ground of not banning open source while acknowledging

That there are very real risks like you mentioned Scott and so this is where ...

conversation about AI has to happen and that's just not taking place on the hill right now we're

debating you know two hundred ninety page pieces of legislation rather than in my opinion what should

be treated as like a policy hackathon let's just address discrete specific topics and move on and act like lawmakers should in this domain which is to say make actual progress decide on standardized disclosure forms identify independent auditors and really start to move the ball towards a more robust testing environment well it is a fascinating topic one week or talk about a lot longer but we are out of time today in fact we didn't even get to our third topic but that's okay sometimes that happens

we'll save it for next week but this would not be rational security if we did not leave you with some object lessons to ponder over in the week to come Tyler what did you bring for us today i brought a documentary from 1986 the full name is shormons march colon a meditation on the possibility of romantic love in the south during an era of nuclear weapons proliferation i literally i just started watching this the other way i didn't get the finish right i was going to say i was going to say i

was going to say i was going to say i was particularly i was curious of benison and i'm glad you have i'm bringing up because uh four k restoration was just released and they've been doing some screenings at film form in New York City unfortunately i was not quick enough on the draw to go to one of the q and a's uh that was moderated the first of which was moderated by ira glass with the filmmaker Ross McLean and the second was zorn mom donny's mother who's a famous very famous

filmmaker in her own right and i wish i could have seen either one of them but the four k restoration

is amazing for anyone who hasn't seen it or know about it the the quick very quick setup and all

say is this quick setup is that essentially this documentarian from the south got a grant in the 80s to document the lasting effects of sherman's march to the sea through the south but shortly before he departs on his trip his girlfriend breaks up with him so he just kind of unravels and he he's becomes enamored with different southern women and it's an exploration of those relationships and every word goes to film sherman's march people set him up with southern women and so it's

say no it's fabulous it's incredible what and the reason why i think the release came out is because he

i think it's usher technically released a new film remake which is uh polls together a bunch of footage from it's true about the death of his son that looks this supposed to be really really striking i mean sun i think wrestled with uh variety of kind of substance abuse mental health issues um

but he kind of traces his his childhood through these incredible videos it sounds amazing i have

not mustard the will power to watch that movie by started watching the sherman's movie sherman's march because i was like well that sounds up or a beat that one i think i can bear with i think if we'd have to steal myself to watch remake but it's also supposed to be amazing i read a couple of reviews saying it's one of the best movies i've met the last few years i even those gotten really overlooked it seems like even in festivals and stuff so i'll throw that in

as well as Ross Macco Macco Wii i think is how you say it i'm actually i've never said

it out loud but is the the filmmaker phenomenal recommendation uh and nastia what do you have for us this week my recommendation is a little basic but i'm gonna recommend George Orwell's homage to katilonia and it's very much related to what we discussed obviously it's one of the most famous books about war and what it's like to be fighting a war and living a matter war but i remember reading it recently and thinking about it gave me this very weird feeling of

validation that like okay all of this crap that the Ukraine is going through and all of the various shortages and the government system on working in the bureaucracy not not you know not working well enough to address this horrific thing that is a full-scale war that like every country war goes through that and which is maybe like a very basic thought but i found it very therapeutic to read about like you know the conditions that people are living in and the military and all

of those problems and it was like wow it really is a kind of a universal war experience and maybe I should tone down my to any for some criticism of my government i didn't though i didn't

never thought i i never i did not but great book we can say from the government does not

the right way stick with it think with it Ben let me kind of do you next what do you have for us this week so i have a data set that i have not yet created but it's going to happen this afternoon woo and this is based on of using the tool uh rad time i decided to set out and solve one of the great unsolved problems of american law which is to count the number of federal crimes and this problem has been lurking around the american legal system since the early 1980s when the justice

Department tried to count the federal crimes and failed and the the ab a then...

couldn't count them there have been a number of the heritage foundation teamed up with the

NA CDL wants to try to count them and they failed and i think that rad time can do it

and so today we are doing phase one which is not the number of federal crimes it's the number of statutes that create federal crimes and by the end of the day i'm going to have a number and i'm going to publish it on law fair next week that reflects part one of what our colleague katherin pampilio has dubbed rad crime which is the application of rad time to the problem of counting federal crimes by the time you hear the next rational security episode you will be able

to look up the number of federal criminal laws in the united states you know i have been listening to all these uh uh reading all these profiles of owners of the fields metal uh so this doesn't seem like that impress the math problem before lawyer or legal folks i guess it's not that bad well we'll take it uh so it's good i'm excited to see the results Kevin what did you bring for us this week uh i've got a heartwarming story of a bunch of students getting together thanks to the

Edward Kennedy Center and doing a deliberation on how a i should be governed in their schools and so they got together thanks to day uh of a_i_ which is a part of m_i_t_ and deliberated and crafted their own rules for how a_i_ should be deployed in their schools of some so a great example of folks getting together around a targeted question coming to a consensus and issuing some idea of how to move forward and seen the next generation take that on is really exciting well wonderful

one another another a another great object lesson well for my object lesson to bring it all home for everyone i'm gonna bring a pair of object lessons uh one from the absurd one from the more serious like so many i have been playing with a_i_ a_a_ a_a_ a_ lately working a number of research projects i'm helping been with various break time related initiatives and efforts up and it's

just an amazing tool uh but also does raise these questions about what is our added value in a world

where these tools are only going to get better in the near future and my thinking keeps coming back to a piece of writing that i revisited that i frankly refine myself revisiting like every year

or two i think it's fair to say and i think i have said maybe on this podcast that is one of the

three or five most influential things i've ever read on the way i think and i do find my feel of referring to it time and time again it's particularly relevant to this conversation which is like far more overlooked far less discussed companion lectures originally a lecture that you levered to politics of the vocation it is an amazing reflection on the role of a rationality and the impact of rationality on kind of the human condition and human experience and a_i_ is in the end

kind of like a mass implementation of rationality perhaps independent of the human experience at at least a form of rationality but it's interesting where it comes out which is not necessarily like a super helpful vision remember he was writing in kind of pre-war with Germany um or kind of in the midst of an after-raver war one but it is a uh it has interesting lessons i think for humans as we think about how we can add to and bring added value even the age of a_i_ which i find

kind of enlightening about the limits of rationality and what it can and can't do for human beings and where we turn when uh to answer other more fundamental questions that rationality can't reach i wouldn't say it's a happy story necessarily but it's an interesting one in very provocative and one that i feel like is a good win-win through which to view the sort of contemporary questions the other object lesson i will pair is the best lesson else get i've seen in a long while that is

aerial tramway the red heart i think it's called a bit from weekend update uh that's all i'm going to say

just to check it out my good day though uh is definitely a kind of genius uh and it's one of my favorite things i've watched online in a long time so go ahead and google and check that out particularly in your moments uh that you may be having a little bit of existential dread well that brings us to the end of this week's episode of rational security is of course a production of law fair so be sure to visit lawfermedia.org for our show page for linked

past episodes for our written work and the written work of other law fair contributors and for information on law fairs other phenomenal podcast series while you're at a be sure to follow law fair on social media review socialize your media be sure to leave a rating or review where you might be listening and sign up to become a material supporter of law fair on patreon for an ad reversion of this podcast among other special benefits

for more information visit lawfermedia.org/support our audio engineer and producing this week was

me of me and our music as always was performed by Sophia again and we were once again edited by the

wonderful gen patch uh but have for my guest Ben Tyler Kevin and Nastia i have Scott our Anderson and we will talk to you next week till then goodbye

Compare and Explore