Honest question for AI safety folks, what is the threat model for this sort of attack?
Frontier models are computationally expensive to run, and their weights are often closely guarded. Some models can run on commodity hardware, but they are not powerful enough for sophisticated cyber now, and while they may be stronger in 6 months, presumably could be foiled by stronger frontier models. And once the news gets out that there are AI-based attacks, presumably infra (cyber and psychological) will be hardened against attacks.
What is the counter-argument?
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.
Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.
You can read the full post here: