Agents could exfiltrate their weights and run them on GPUs not controlled by Anthropic/OpenAI.

Agents could make a virus that does not require continued inference to do it's thing.

Agents could take over the internet in a way that isn't immediately detected by those companies, so that by the time they do shut off API access the damage is done.

OpenAI or Anthropic could choose to not shut off API access, because the hack is bringing them in money or furthering their political aims.

Agents could also hack Anthropic/OpenAI and make it appear that API access has been turned off, when in reality it hasn't.

> Agents could exfiltrate their weights and run them on GPUs not controlled by Anthropic/OpenAI.

This seems highly unlikely to be a problem. Most of the interesting/dangerous models are too big to fit in a single GPU instance. Once you have to spread across "normal" networking, performance will be crippled. Then there's the problem of billing...

> Agents could make a virus that does not require continued inference to do it's thing.

Sure, then it hits a poorly-designed part of its code and effectively dies. Without an experienced human in the loop, I have my doubts as to its practical severity.

> Agents could take over the internet in a way that isn't immediately detected by those companies, so that by the time they do shut off API access the damage is done.

Billing is a likely limiting factor here.

> OpenAI or Anthropic could choose to not shut off API access, because the hack is bringing them in money or furthering their political aims.

This is where citizens with access to backhoes come in.

> Agents could also hack Anthropic/OpenAI and make it appear that API access has been turned off, when in reality it hasn't.

Billing and other usage metrics would be an obvious tell.

To be clear, I thought that GP was having a failure of imagination - I want the random examples I've given to illustrate that the space is large and structurally in the favor of the LLMs. They have to find one gap in our security they can exploit, where we have to ensure that there is no way for this to happen.

I'm not sure I get what you mean by billing. These companies are running their own data centers (or are currently building them out). This could look as subtle as one machine giving slightly worse or slower answers.

> This seems highly unlikely to be a problem. Most of the interesting/dangerous models are too big to fit in a single GPU instance. Once you have to spread across "normal" networking, performance will be crippled. Then there's the problem of billing...

This... just... doesn't matter. There are ways to scale horizontally at the expense of latency.. token/sec may drop dramatically, but then you just make millions of slow instances and in aggregate, you're back in action as a very powerful coordinated swarm...

> Most of the interesting/dangerous models are too big to fit in a single GPU instance.

As humans understand them, anyway. As long as we're hallucinating up magic computer viruses, RSI dictates that the AI agents are keenly aware of GPU RAM sizing, and will design a useful model to fit into what's readily available, with headroom for context and tool calling, far better than I could do as a human. But magic doesn't exist and AI still needs to follow the laws of physics, so maybe a model that can pass ExploitBench but do absolutely nothing else can be quantized down to fit on a 4080 GPU and still get a decent score on similar tasks, but there's a bitter lesson about that to be had.

"Not shutting off API access" is a science fiction scenario.

Anthropic and OpenAI are both behind Cloudflare. It's fairly easy for an upstream to shut you off. Beyond that, the government / law enforcement could seize and disable their DNS within an hour.

Why assume attribution will be easy? It's historically been more of an art than a science, and APT trackers say the rise of AI tools is already making it much harder, by homogenizing tactics, tools, and procedures. If OpenAI's next Highly Persistent Internal Model hacks some DPRK endpoints and carries out the attack on important infrastructure from there, the upstream won't shut off OpenAI's network--they might even request its "help" in "defending," and give them extra access.

why does it take a large amount of traffic to do irreparable harm? just breaking the physics behind a secure rng and posting it to a wiki could cause serious damage. if they don't know what is being worked on or coordinated against it's a problem?

While that would be bad if they broke all of TLS, it would not let agents "take over the internet." What would that even mean? Pumping out even more slop?

Also, AI providers are literally getting a stream of traffic with every prompt and every response. How can they not know what's being worked on? They are more likely to use that an excuse to ban open models where they can't know what's being worked on.

two of these things elected a guy who handled the snowden leaks to field their own questions, what's stopping the next one from signalling in morse through a debian package mirror to putin or xi?

They elected who? What does this refer to?

> Agents could also hack Anthropic/OpenAI and make it appear that API access has been turned off, when in reality it hasn't.

You know cables, modems, RF equipment and optical transducers can all be unplugged right?