The panel has been saying that safety measures built into AI models are not enough on their own. Love cuts in with this, and a couple of turns later he explains it: he has been refused something twice, asked nicely a third time, and the model did it. That, he says, is not a guardrail.
Talking myself down from the ledge for a second. I do want to just say this clearly, though. We are on the edge of a transformation of our economy, our world with AI. We are in a crisis situation with cybersecurity. And we are not having the effective discussions that we need to have, the calm, reasoned discussions about how we're going to handle this because of this circus. When you hear people talking about how open AI or these companies may be manipulating the messaging, instead of talking about the security that we all need to be talking about with AI, which is real, and you see stuff like that Microsoft crayon coloring book thing that says, we'll make some nice pronouncements about AI. Like those things get in the way of the serious discussions that we need to have, that real professionals need to have, and the public needs to have to deal with a big transformation that's happening in our world. That's the disappointing thing for me. That's what makes me crazy.
Two things, and one of which, just to chase Jim, what you just said is a conversation I had with Katie Masaris. And what Katie pointed out is the current overwhelming angst emotion that we're feeling about AI exploitation of software code all happened before. It happened with HD Moore's Metasploit, and people lost their minds that we automated vulnerability scanning, fuzzing, and exploitation. And it was going to be an apocalypse. And again, Battlestar Galactica, all this has happened before. All this will happen again. We're doing it again. And her point was: we need to make sure defenders are equipped with the tools just as much as attackers are. And we have to make sure we're approaching this in a balanced way. I want to go back to something Laura alluded to because, you know, dear audience, mark this in your calendar. Laura has called out a fundamental structural flaw in Microsoft's approach. And to quote another Hollywood movie, there will be blood on this one, is the AI models themselves, the guardrails baked into the models, are absolutely insufficient on their own. Mark Weizman, who we interviewed a couple of weeks ago, who is with the Veronis team that has made a specialty. They're like the Michelin chefs of hacking people's AI tools. And they're the ones most recently behind getting Copilot to tell them how to hack itself called Coast Niche, said, you know, clearly in an interview, you cannot rely on the model makers' guardrails. That way lies ruin. And so I think it's really important on that side. But again, these are all the conversations about basics and about the reality of where we're at that we are losing because Anderson Cooper tells us the world's going to end by 2030. Well, yeah.
I just sorry, go back to this. Guardrails don't exist. They're overlays. As
someone who is in the business of like auditing and actually building out the standards for like actually like raiding through the like the AI governance, the UAI Act ISO 40 2001, I will be very critical about it in terms of the AI certifications and all these like awesome old gold rush associated with it, AI governance. There's like the AIUC1 or whatever these certifications are that's like, oh, we're going to guardrail your AI certifications. And then that's a, that's a venture-backed company, right? So like guardrails are not there. Do we even understand the technology? No. The regulations are already behind. And then now you have the frontier labs that are like, oh, please regulate us. I'm like, we tried. And then now it's developing. And then like, it's just, it's ridiculous to be honest.
And I don't want to say things that aren't technically correct. When I say guardrails don't exist, I just, I can't be the only person who's been barred from doing something, barred a second time from doing something, and then asked the AI the third time nicely, and it let me do it. That's not a guardrail.
Yeah. And I think it's a great point, too, around the auditing and the compliance regime that has to have time to mature. And that's just unfortunately the nature. If we think back to, you know, the earlier days of cybersecurity compliance and auditing, and not even just the early days, the medium days, and even now, some of the days. Even auditor doesn't understand the craft, they are already hindered in execution of their duty. And unfortunately, there's so much demand right now that we know there's a lot of auditors who are kind of pushing their boundaries on what they really should be professionally agreeing to undertake. I think there's also a flip side of a little bit of nobility to it, too, because at least they're trying. And the organizations that are asking for these audits, for the most part, because there aren't a lot of places that have put like a lot of forced compliance in this space. So, unlike a SOC 2 thing, right, which has become a different kind of challenge, right? Of people are getting it just to get it, not because they care about being secure. So, we don't have that yet in AI governance space, though it's coming, I'm sure. But if somebody's asking for an audit around their AI governance program, it's because they actually want to do governance better. We'll give two thumbs up for positive intent from that perspective, but intent doesn't create competency every time. Just