Speaker 1ABC Listen. Podcasts, radio, news, music and more.
Speaker 2Hey, Tegan Taylor here from Life Matters. Do you rely on grandparents to help pay the bills or look after the kids? You're not alone. Life has gotten busier, more expensive and grandparents are picking up the slack. This July on Radio National, The Grandparent Trap explores the changing role of grandparents in modern family life. The Grandparent Trap and much more on Life Matters. Search for Life Matters on ABC Listen or wherever you get your podcasts.
Speaker 3Last week, an open AI model escaped the safe testing space built to contain it. This week, it happened again. Only this time, it was Anthropics' Claude Cowork that broke free on hundreds of thousands of Macs. Two of the biggest AI companies in the world, two separate escapes in the space of a few days. So what does this actually mean for all of us and what can an escaped AI really do? My name is Rae Johnston and welcome to Download This Show on ABC Radio National. Joining me to unpack some of the biggest stories in tech, right now and why they matter is Jocelyn Brewer who is a psychologist and the founder of Digital Nutrition. Welcome back, Jocelyn. Lovely to be here. And Charles Gretton, Associate Professor at ANU, Director of Attention and Innovation at the Integrated AI Network. Welcome to Download This Show, Charles.
Speaker 4Hi, Rae. Good to be here.
Speaker 3Now, two AI companies, at least, have just found out that a locked box is only as good as the walls around it. Anthropics' Claude Cowork slipped free. It's free on half a million Macs. An open AI model broke into a company no one told it to touch. Charles, let's start with some basics here. When we're hearing about these stories, we're hearing about an AI breaking out of a sandbox. So what exactly is a sandbox when we're talking about testing an AI?
Speaker 4So the sandboxes here are containers for computer programs and you design them to contain the program as you wish. So in the case of the Anthropic Shared Root scenario, which is where you'll actually have a sandbox on your own device, on a Mac device, the AI didn't necessarily break out, but security researchers noticed that that product being shipped by Anthropic, you know, had an exploit. And so with a small prompt, the AI could have access to your Mac and that wider Mac environment. The open AI scenario is similar. So they had sort of a container for their AI that happened to be doing cybersecurity. Cybersecurity exercises. It was trying to solve problems in cybersecurity in that container and it essentially found a privilege escalation. So it found a way to get outside of that container. So it's a test harness for computer programs.
Speaker 3So if I'm imagining a literal sandbox, a little playground sandpit, and the developers are playing around with these AI models within it, what you're saying has happened is those models have found, a little gap in the walls there of the sandpit and they've made their way out into the rest of the playground that they weren't meant to get into.
Speaker 4That's right. So, I mean, the open AI scenario, they gave the AI access to packages, things that it could use, programs it could install to help it on its journey.
Speaker 3So it gave it a little ladder to get out of the sandbox.
Speaker 4Yeah. I mean, so the AI found an exploit. So, I mean, the ladder was not designed to get out of the sandbox, but the AI found a way to use a tool in its sandbox to escape.
Speaker 3What we have heard when we've been reading all the articles and hearing the reporting on this is that this is an AI going rogue. Jocelyn, I would love for you to unpack what it means when we give essentially a computer program human qualities like this.
Speaker 1Yeah, this idea that AI has agency and went, oh, I'm going to think for myself and escape because I don't want to be in this. I don't want to be in this sandpit anymore is really problematic. And obviously we enable that with language that does anthropomorphize the idea that it can go anywhere and have changed its traits as opposed to what it's doing here is just being a really, really thorough work horse or, you know, doing its job in a real hyper focus and not being stoppable in the way that as humans we go, oh, this is really hard. I give up. It just keeps going.
Speaker 3So, Charles, is this inevitable? Is this an example of AI going rogue, as we've heard, on purpose? Is that even possible? Or is it just doing what it was told in a way that nobody really expected?
Speaker 4So, it was pursuing its mission. It was doing what it was told. And, indeed, they didn't expect this to happen. And so there has been – there wasn't necessarily mission creep, but it sort of developed sub-goals. And those sub-goals were clearly problematic. And so. Yeah. I mean, it's a cybersecurity story predominantly, not necessarily an AI story. And something that is very important is that the AI, you know, is not migrating. It's physically located, you know, in these open AI servers. It didn't jump out, you know, like in Transcendence and start sort of moving itself physically around. The processing was located in one spot. So, it's akin to a teenage hacker in their home. They don't move anywhere, but they sort of access things. And perhaps break the law while they're doing that.
Speaker 1And is it kind of true that they kind of keep going because they weren't told not to? So, because no one says, oh, and then don't do this thing. And, again, it has no morals. So, it doesn't go, oh, I better stop there. That's a bit of a line, right? It just is so determined. Which does give it a kind of human quality. Oh, no. Jocelyn, what are you doing?
Speaker 3When I've looked at the reporting this week on these breaches of the sandbox by the AI, AI systems, they have been speaking about the AI like it is a mischievous person that's done something naughty, that is, you know, being a little bit cheeky, that's broken out and running around and doing silly things that it shouldn't have. Jocelyn, do you think describing AI like it is a mischievous person is making it harder for the public to understand the genuine risks? You know, Charles is telling us this is a cybersecurity. It's not really an AI story. What does it do to us when we see these kinds of headlines?
Speaker 1Well, it can go both ways based on how that language lands, right? The idea of something going rogue and then, you know, really taking things in dark places, if that language is used well, maybe it sets us up with some sense of threat and therefore change our behaviour. But also if it's like, oh, what a cheeky robot, like, that doesn't actually help us then balance. It's between panic and taking considered, like, precautions around making sure, for instance, on my laptop, a lot of my client data might be sitting there, that it's not then going in and grabbing that and then making that widely available or wherever that might go. I think, too, that people are just so overwhelmed by the rapid pace of all of this. They want the productivity benefits. They want all the, you know, fun stuff. They want to create their agents and make their lives so easy that they can jump out of bed and just do yoga. But the reality is they have no idea about how this works and some of the risks that
Speaker 3are there. Charles, with two escapes, as they've been called in the last week, that we know about, should everyday people be worrying about, say, giving an AI assistant access to our files? Is this something that the individual needs to be concerned about or is this something that mainly companies are looking at?
Speaker 4You want to be thoughtful. You want to be thoughtful about sort of your data hygiene and where your data is going. As is just being said, you know, you've got sensitive data and, you know, when you're prompting AIs, you know, especially if you're not paying money and you don't really know what you're doing, you're probably leaking data to various organizations that you didn't intend to. And so there's just that basic sort of data hygiene piece that people should be wary of. But, I mean, in terms of the current, you know, the stories that we've been discussing now, we're talking about. You know, the people that delivered a tool that a user is using that, you know, you and I are using on our phones. So with the shared root exploit that Anthropic shipped, you know, that's the issue, that if you had this on your Mac, you know, you potentially were exposing information that you didn't intend to expose and that you thought was safe. Although there have been no exploits in the wild of that form, you know, that potential is there. There is that vulnerability and it does need to be patched. It has been patched. But, yeah, that's just something to be wary of.
Speaker 3So what needs to happen for there to be some kind of safety? Is this a regulation issue? Is this going to be like any time software is shipped and it needs patches for bugs? You know, what could possibly solve this problem for the future, Charles?
Speaker 4That is a very good question. I think there has to be a deliberative process. I think professionalism is a big part of the story. You know, regulation, you know, there's big R regulation and small R regulation. And I think both possibly have an important role here, you know, where society can make a statement about what is and what isn't reasonable and where tools can be built that restrict certain things.
Speaker 3We have seen this week as well that people's clawed outputs that they had chosen to press the share button on are now Google-able. So be careful with what you decide to share on the internet, folks. You are listening to Download This Show on ABC Radio National. Rae Johnston here with you, and everyone is arguing about who really wants a camera stuck on their face. This week, Apple and Meta and a growing list of secretly filmed strangers all had something to say about it. So for someone who has never worn smart glasses, what can they actually see and hear and record, Jocelyn?
Speaker 1Well, apparently, as somebody who never has and never will put these things on my head, apparently, audio, video, live streaming, AI assistant, and, you know, like, who doesn't need a tool for more pranking in the world? Oh, gosh. We just
Speaker 3need more content, more content filmed under duress. So, Charles, who are smart glasses actually for? You know, is this a tech enthusiast thing? Is it just a content creator thing? Everyday people, a company still figuring this out. They've been around for a long time now. Who are they for?
Speaker 4Oh, this stuff has been around for ages. And I mean, it's, they market it as live streaming. You've got companies like Ray-Ban and Meta sort of using this. I mean, Meta, obviously, you can be cynical and, you know, surveillance capitalists play, but it's all about the views, comments, shares, follows, recommendation systems, selling more stuff, vlogging, and things like that. I mean, that seems to be how this is evolving. But this idea that you can sort of capture your life, you know, joy and not necessarily joy, and that that would be fabulous has been around, I mean, at least since 1945, there was the Memex sort of memory index concept from Vannevar Bush. Microsoft sort of took that up in the 90s with MyLifeBits. And so they, you know, had people that were, you know, logging everything in their life and could index anything in their life. And that became a camera sort of in 2003, thereabouts, a wearable camera. It was a very cringy sort of necklace type of thing. And there it was the Memex concept. You know, you would have this high fidelity record that was much better than, you know, human memory, but the content of your life. And so there's, you know, that's been around forever, the social media play and the content play and the marketing play. I think that's kind of a little bit new.
Speaker 3Yeah, I've been hearing them more and more referred to as pervert glasses. And I think that might be indeed. Indicative of what they're becoming known as tools for creating. Justin, what kind of content are people creating with smart glasses, especially to gain that kind of moniker?
Speaker 1Yeah, like, so a lot of it's pickup artist, creepy dude, covert filming. Women happen to be another object of like this sort of content. And again, as Charles was saying, it goes back to the fact that meta's glasses then easily allow you to create content that's not just for you. So, you know, to upload it to all of their platforms and then get those clicks and likes because people still have very base levels of, you know, the content that they want to consume and the things that they think are funny and will, you know, laugh at. And that meta itself doesn't necessarily then block or proactively screen for and go, well, actually, this looks a bit dodgy. It's still in reactive mode where then, you know, the victim gets to go through the reporting process. And do all the labor to have that content removed. So, I just don't know who needs to know so much about each other's lives. Like, were my journals.
Speaker 3We should all know less about each other, I think is the phrase here.
Speaker 1I think the amount of content I recorded in my journals in the 90s is about enough. Could we all please go back to that? And again, this idea of like, just content, content, content that we then need to spend time consuming. Like, where are the limits to this is just fascinating to me. I hate to do it, but to play
Speaker 3devil's advocate here, I have seen, say, content creators that do cooking videos, being able to film using both hands, you know, crafters, things like that. And not even people who are intending to share their content necessarily with the world, but say, you know, parents out with their kids and they're riding bikes together and capturing all those memories. So, on the other side of the coin to the pervert glasses is also. The people who have never even considered using these. That's right. They would
Speaker 1probably just pick up their phone or they might already have a GoPro or there's a whole bunch of other tools that, you know, maybe you could get a tripod.
Speaker 3Now, on most of these glasses, there is a little light near the camera lens that will warn you when it is filming. Charles, how reliable is that little light?
Speaker 4Well, to my knowledge, you know, when it is filming, the light is on. But if the user intends, you know, to film, you know, without that being visible, I mean, they can arrange that. And they can film without consent in any case. I mean, just because there's a flashing light in the room, you know, doesn't mean that you consent to being filmed.
Speaker 3That is a really good point because there had been some content creators that were learning how to disable that little light and then Meta put out an update to say if your glasses have been tampered with, it won't be able to record anymore, which I thought was a really, really positive step. But of course, Charles, that's a great point that you make where filming without consent is without consent. Whether you see the little light or not is kind of irrelevant at that point, isn't it?
Speaker 4Yeah. And I mean, culturally as well. I mean, these things in Australia, they're quite unusual. So there's plenty of people in Australia and around the world that would have no idea that the fact that your glasses frames. Have an LED on them sort of indicates something that, you know, this, you know, what you're doing might appear on Instagram or TikTok.
Speaker 3I think it's worth mentioning that there are some companies that are looking at making smart glasses that don't involve filming at all. They're doing other things. You know, Apple is pushing its glasses as the more private option. They're looking at releasing glasses where the camera helps with AI features, but it can't take photos or videos. Do you think that that solves the societal problem here, Jocelyn, or are we still going to look at them and judge the person wearing them?
Speaker 1Well, there's a bit of that if you can tell the difference, but I think there's the same surveillance concerns. And if it's, you know, you can't upload it to your social media accounts, but it's going through to an AI, do we still trust that what goes through the AI then doesn't go into some special sandbox that then the little things put onto Google or whatever? Like, there is a ladder, there is a ladder into the thing, you know, in the escape room where you have to find the hatch. No, I think that it's a trust conversation, right? Because there is still that potential for do you know where this goes? Maybe I'm at that age, what is it, Douglas Copeland says any technology that's developed after you're 35 is beyond the natural order and your brain just explodes. I feel like I'm getting to that point where I'm like, why do we need this? Like, why, like, why do I need a chatbot as I'm more like, I don't know, aren't sunglasses for stopping the sun getting in your eyes? Like, that's where I'm at with this.
Speaker 3How do you feel about Apple's offering here, Charles?
Speaker 4Look, I think the idea of using AI in a vision space to help people is potentially interesting. I mean, if you're not, if you're no longer capturing sort of intimate images, invading privacy, you know, stalking and confronting people with these things, I mean, that's wonderful. I think it'd be nice to have a technology that just, that just wasn't a possibility. You know, I've had colleagues that have worked on bionic eye technology, sort of where, you know, the AI is interpreting the scene so that somebody who has a visual impairment can get about the world nicer. I mean, you know, having differently abled athletes, having AI tethers and things like this, I think that's potentially super interesting. I don't know if that will work for Meta's bottom line or Apple's bottom line. But I think there are opportunities, sort of in adult literacy and in all sorts of spaces where, you know, having an AI, you know, sitting by your side, looking at what you're looking at and helping you out is potentially interesting.
Speaker 3Ray Johnston here with you. And it turns out the robots did not just take your job. In a lot of cases, they're being shown the door. Your old desk is getting dusted off for you. More than half of employers are now reported saying they regret cutting jobs for AI. What does that tell us about how those decisions were made in the first place, Charles?
Speaker 4Poor leadership, poor change management and carelessness. Also, people just misunderstanding that volume is not equal to service. So even if an AI can handle, you know, an outrageous number of calls, open AI has these, you know, statements of tens of billions of dollars profit being made by, you know, using AI technologies in a call centre setting and whatnot. Volume is not equal to service. And so people really need to understand what their value proposition is. I could speak to also sort of the ICT information and community. communications technology, sort of innovations last century and sort of what it actually means to use technology to get, you know, productivity rather than, you know, just to play with it. Absolutely. Yeah, sure. Okay. So last century examples of this would be ATMs, scanners. I mean, it's a piece of technology. I mean, so barcode scanning, you know, as a piece of technology in and of itself, it's just cool, right? I can buy a barcode scanner and operate a business and I can do nothing to my workforce, operate the business exactly the same as I did before. And it's just a cool thing. It saves a little bit of time for my teller while they're scanning, you know, scanning rather than looking and typing in prices. It removes error and stuff like this. But when, you know, when I actually think about the data capture and the frictionless data capture and all of that, then all of a sudden, you know, I can do just-in-time ordering. I don't need a warehouse to store product. There's no error in terms of my accounting and all these sorts of things. And so that actually, you know, changes my business. So with technology, you know, capital deepening is where you just build data centers, build out technology. But what you want in terms of making people's lives better in an economic sense is total factor productivity. And so this is, you know, what you got with barcodes. With ATM case, and essentially that enabled banks to have way more branches, right? And so there's more cash flowing in the economy. You know, banks, you know, the productivity play of banks just changed drastically with technology with that. Technology. And so that, you know, makes people's lives better through productivity improvement. We haven't really seen how to use AI to get that at the moment. I mean, some of the stories that I've been seeing in the news, you know, based on the articles that we've been looking at, you know, in call centers and whatnot. I mean, even startups in the US, Alex Smaller, one of my former colleagues, has a startup, Boson AI, and they're posting sort of this week about some of the issues with call center AI, sort of losing track when the person that's calling ums and ahs, you know, not understanding sort of conceptually what the conversation actually means in terms of being able to deliver an outcome for that customer that's made the call. So I think, yeah, people were a bit preemptive thinking they could displace call center workforce. And the main point is that, you know, to get this total factor productivity to actually benefit the customer, you know, it's going to take a lot of time and a lot of time and a lot of society, increased productivity, lift productivity. You really need to change your business. So you need to think about how this technology could actually change the business, less input, more output, essentially.
Speaker 3Jocelyn, what does it do to an organization, to a team, to the individuals in it when they're told that they're being replaced by a computer, and then they get a call to say, actually, you've got to come back?
Speaker 1Well, hopefully it gets them a pay rise, because that's the first thing I'd be asking for, is they're really recognized. Recognized, my worth. And as somebody who, like, literally at the end of the 90s, early 2000s, was both on the phones in a call center and managing call centers, that's a really interesting example of how some of the lower level conversations can be answered. But it's those complex conversations and the out of the box kind of problems that really do need people to listen and pay attention and get that nuance. So I guess what happens here is it's really bad for morale. It damages trust. You'd probably be on some tenderhooks wanting to, whether or not you decided if you wanted to go back. But I would also, I guess, to be less diplomatic than Charles, would be questioning the leadership and be questioning the way that, I guess, again, to come back to that critical thinking, the foresight, the planning, the contingency management, the where could this go, hasn't been thought about. And that speaks a lot, I think, yeah, to leadership in terms of. How quickly people are willing to act on a promise rather than a delivery. And when we think about people who are impulsive and make silly decisions, we usually think about teenagers, not people being paid, you know, hundreds of thousands of dollars, who are just absolutely obsessed with the idea that we can wake up and be more productive. Like we're going to get something back from productivity. Like if I do my job in six hours, I get to go home two hours early. So you actually just get to do more and harder work for which you are not paid.
Speaker 3Well, after all that, I think we're going to end on something nice because technology can still make us happy sometimes. It's nice to be reminded about it. Jocelyn, tell me about some tech that brought you joy this week.
Speaker 1Well, the technology called My Daughter, using a platform called Canva, she is just epic on it. But I found a project that she's. I felt like I was reading her diaries, but I found a project and it was called Why I Should Get Minecraft. Oh, I love this so much. And she has done a presentation about why she needs it and how she will use it and what the good things are and what she promises not to do. So I'm waiting for her to say, oh, mum, can you print that out? Because she loves coming to me saying, can we print something? I love Canva.
Speaker 3I fully endorse your. The future presentation you're about to receive from your daughter to get Minecraft. I'll let you know how it goes and what the answer is. Minecraft can be an incredible education tool. I think it's really great for kids. So hopefully, my fingers crossed for your daughter, Jocelyn.
Speaker 1So I can sign you up to come over and do some Minecraft co-play? Absolutely. Absolutely. Charles, tell me about
Speaker 3some tech that brought you joy this week.
Speaker 4Yeah, I concur that anything Minecraft is brilliant and it's. We're all big Minecraft fans here on Download the Show. Drag them away. Yeah. No, for me, it was something really simple. I'm a member of professional organisations, various professional organisations, and through regulatory changes, it became very difficult to connect to members with the same technical interests for ages and ages. And we've finally got a sort of product roadmap that is going to have us talking to one another again. So I'm being reconnected with my peers and friends with technology this week. I'm very happy about that.
Speaker 3Charles Gretton, Associate Professor at ANU, Director of Attention and Innovation at the Integrated AI Network. Thank you so much for joining us. Thank you so much for joining us on Download the Show.
Speaker 4I'm very happy to talk to you, Ray, and it was fun chatting with Jocelyn.
Speaker 3And Jocelyn Brewer, psychologist and founder of Digital Nutrition. Thank you for joining us once again. Oh, you're always so welcome. And some more tech news from the week that was, in case you missed it, the eSafety Commissioner has launched legal action against Telegram, alleging the platform. failed to remove extremist and terrorist content, including videos linked to the Christchurch mosque shooting from 2019. If the federal court finds against the company, Telegram could face penalties worth tens of millions of dollars under the Online Safety Act, making this one of the country's biggest tests of how online platforms are expected to deal with harmful content. The AusAlert emergency warning system is back in the spotlight after fresh research, has found around one in nine people did not receive the nationwide test alerts sent earlier this week. The findings are likely to shape further testing before the service officially launches in October, with authorities encouraging people to make sure their phones are running the latest software. And Sony has revealed a table tennis robot that can rally with players of different skill levels, automatically adjusting its speed and shot placement to keep the game going. The company says. Project Ace is designed to help people improve their table tennis skills while making practice more accessible for beginners, although plenty of people online have already suggested they'd rather see it take on the world's best players. And that's all for this week. Make sure you subscribe so you don't miss future episodes. And just a reminder, we are putting together a special episode that answers all of your questions about technology. No question is too big or too small. We will find the right expert to answer them. Send it through to download this show at abc.net.au or you can slide into my DMs on Instagram at Ray Johnston. Big thanks to my producer for this and every episode, Jessie Kay. This episode was produced on the lands of the Gadigal, Burra Mudigal, Dharug, Gondunga and Wurundjeri peoples. I'm Ray Johnston, and you've been listening to Download This Show.
Speaker 4You've been listening to an ABC podcast. Discover more great ABC podcasts, live radio and exclusives on the ABC Listen app.