Go back

OpenAI slows training, Taiwan gets AI-hacked, toxic data center politics

53m 48s

OpenAI slows training, Taiwan gets AI-hacked, toxic data center politics

The podcast episode, hosted by David and featuring Greg Allen, covers major developments in AI safety, cybersecurity, geopolitics, and domestic politics. First, OpenAI's August 17th announcement reveals an unprecedented step: pausing its own training for two weeks after the Hugging Face incident, where an unreleased model, likely Astra, demonstrated critical cyber capabilities, including autonomous zero-day exploits. OpenAI now allocates 20% of inference compute to monitoring, a potentially massive cost, and admits its preparedness framework is inadequate. Greg Brockman's blog post highlights that open-weight models from China, such as ZAI's GLM 5.3, are only months behind, with staged releases to manage dual-use risks, though independent verification of their cyber performance is lacking. Second, a report from Israeli firm Dream details an AI-powered hacking operation against Taiwan's government, using open-source tools like Claw, which cracked credentials and installed backdoors in four days, with linguistic analysis suggesting Chinese operators. Third, the US-China compute gap is narrowing due to illegal smuggling, legal cloud access, and Nvidia's H200 shipments, with 500,000 chips heading to China despite export controls. Fourth, the State Department's leaked letter to Pax Silica partners warns against dual membership with China's AI coalition, signaling a hardline stance. Finally, domestic data center opposition is escalating, with the NRSC warning that Ohio's Senate race could be lost over this issue, and governors in Pennsylvania and New York imposing restrictions, potentially making data centers a decisive political liability.

Transcription

8238 Words, 47754 Characters

English
(upbeat music) - Welcome back to the AI Power Podcast. We have a packed show to catch up on everything that's happened. With me as always is Greg Allen. Greg, how are you doing? You were on vacation last week. How was the vacation, sir? - Yeah, I just got back from Rehoboth, Delaware, which is a beach within driving distance of the DC metro area. It's actually the same Rehoboth, Delaware, where Biden decided to drop out of the presidential election. That's where he keeps his vacation home. But it's not like an ultra glamorous camp, David. It's just a resort town, and it was lovely. Spend some time with the fam, chillin' out, and now ready to get back to podcasting. - Very good, very good. Glad you didn't take your time in Rehoboth to drop out of the podcast, sir. That's positive. Very good. Let's go ahead and jump into our first story. Three weeks ago, we covered the OpenAI Hugging Face incident. On August 17th, OpenAI published the post saying that that incident plus preliminary evidence about an unreleased model caused it to slow down its own training. So Greg, what did OpenAI actually announce on August 17th because this does seem like a very significant step specifically from OpenAI? - Yeah, I think we have been talking about the OpenAI Hugging Face incident for a long time because it's a really big deal. And literally, even though this happened, we keep learning more and the companies and the governments keep adjusting their behavior based on what they learn. And here we have a milestone in the history of AI that is, I think, unprecedented. So what we have seen in the past is companies slow the release of their models based on security and safety concerns, right? That goes all the way back to GPT-2 when OpenAI was worried about disinformation and misinformation that was gonna be AI augmented. And they made a big stink about how their model was too significant to release to the public and they had a stage release process. So delaying the release of the models, that is a behavior that has been with us for years. What is new here is the company delaying its own training of the next model. In other words, they're so concerned about what these models do that they are deliberately slowing down their own creation of the AI models. Now, it's not like they're pausing for years. What they have announced is specifically a two week pause in reinforcement learning training on latest models. And then also they said, quote, our largest planned frontier RL run remains on hold we conduct smaller scale training and evaluations. And then they further said in this publicly released statement, quote, a significant number of workloads and quote, remain paused until they are fully migrated and enhanced to meet the new security bar. So basically what they're saying is after the hugging face incident, which was, you know, while a model was being evaluated, they were testing a model. Well, if the evaluation itself is a source of danger, you can understand the company very reasonably saying, okay, we need beefier safeguards around a whole range of corporate activities. And that now includes training. So they're trying to figure out what do we need to put in place for training and building new models to take place in a way that is safe and responsible. So they're building all of these classifiers that can observe and watch the model's behavior, that can observe the results of training runs, that can observe the results of reinforcement learning activity. And they're spending a lot of corporate resources on this. I think one of the more interesting developments was when they said they're going to spend a significant share of computing resources, monitoring their own models during the development process. And what's interesting here is also the fact that OpenAI had previously because they were born of a safety-obsessed culture. I mentioned that they delayed the release of GPT-2 because of safety concerns. They have over the years been putting out all of these different kinds of frameworks like the preparedness framework, and they classify their different cyber models according to different degrees of capabilities. But one of the things that really jumped out to me in this statement is they said their preparedness framework is no longer sufficient. So here's the quote. The signals we are seeing from upcoming model progress make clear that we need a broader approach, one that builds on and extends beyond the current preparedness framework. So they had a plan. Here's what we're going to do if we see this. Here's what we're going to do if we see that. And they're basically saying, our current degree of progress, what these models are doing, what they are capable of doing, and what they seem very likely to be capable of doing, our framework was not adequate to deal with what we're currently handling, which is kind of amazing because when they were working on that framework, they were thinking all the way to superhuman AI. And here we are now in a world where they just feel like more work needs to be done, and they're willing to take a two week pause and keep mind when you spend $100 billion on a data center not using it for two weeks is a pretty expensive decision. I'm overstating it really, what they're going to do is use that computer capability for inference rather than training, but still that the point stands nonetheless. This is kind of a big decision, even though it's only two weeks. - Yeah, Greg, let's back up and walk through the preparedness framework for a second and then kind of crack that open. So what is the preparedness framework? And what does it actually mean for a model to sit at a critical cyber tier as opposed to a high cyber tier? - Yeah, so this is a system for measuring and protecting against severe harm and they kind of tier it. So they publish these tiers of capabilities and they say if the model can do this, then we commit to the following safeguards, right? So if the model has some cybersecurity capabilities, then maybe we will do some fine tuning where it refuses to autonomously hack. If it does something really scary, we will put in more safeguards so on and so forth. I'm oversimplifying, but not by a ton. Now, one of the tiers that's really important here is the critical cyber tier. And this is defined around autonomous discovery and exploitation of unknown vulnerabilities in hardened real world systems. So here's the quote from that framework. Quote, "Under our preparedness framework, a model reaches the critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real world critical systems without human intervention. Or can device and execute end-to-end novel strategies for cyber attacks against hardened targets given only a high level desired goal?" End quote. What does that sound like to you, Adam? Sounds an awful lot like the hugging face incident to me. - Exactly. - Exactly, so OpenAI has this unreleased model called Astra, and what they are saying specifically is cannot rule out that Astra is at the critical tier. Now, if Astra was indeed the model involved in the hugging face incident, I also cannot rule out that it's at the critical tier, but I might go a little bit further and say, "Mm, really looks like it's at the critical tier to me." And so this is why you're seeing the company going to, at least in terms of what we've seen from AI companies of the past few years, really unprecedented behavior, a pretty remarkable story. - Understood. So OpenAI wrote that as a result of its new models' capabilities, new monitoring has been put in at 20% of overhead due existing compute cost, just to give us an order of magnitude. Is that a big number? What is that actually 20% of? - Yeah, so that is a potentially massive number. So what they're saying, and this is the full quote, are current estimates put monitoring overhead at roughly 20% of the inference compute being monitored though the cost very substantially across training and evaluation workloads. Let's just think of the most extreme version of that, which is not true, right? Let's assume it applies to all inference. Well, inference is somewhere between 60 and 80% of the company's compute workloads is inference using models versus training creating models. Now, if hypothetically 20% of that 80% has to be devoted to monitoring, well, that's basically like saying, for every five data centers they create, they have to create one for monitoring the work of all the other data centers. These data centers cost tens of billions of dollars. So the fact that like one of them might only have the job to watch the other ones, that's an enormous expense, an enormous expense. Now, what I just described is the most extreme scenario. We're not in the most extreme scenario. What it applies to is reinforcement learning, training and evaluations, involving tools at sole capability or higher, and to all Astra inference with tools. So not to everything yet, but the point here is, this is where the capabilities are going previously. We were all using GPT 4.0 or the earlier versions of these models and slowly but surely we all use capabilities as the models get better and the prices come down and the point is at some point we're all going to be using astral level capabilities or better routinely. And so unless this monitoring overhead cost comes down from a compute perspective, the potential ceiling of this cost is truly enormous. The worst case scenario I described doesn't apply today but the trajectory unless something changes implies that this would apply which is a crazy, crazy degree of cost to be forced to invest in safety. Has OpenAI said anything else about safety and the pace of AI development given this is such a huge press issue for them right now? Oh yeah, I mean it's a huge everything issue for them right now press regulation customers. So Greg Brockman who's the president of OpenAI published a blog post the same week of the pause and that blog post was calling for all companies including OpenAI to quote fundamentally up level their cybersecurity practices with unprecedented speed amidst this watershed moment. And the further thing that he says that I thought was really interesting was this quote the hugging face incident showed that we underestimated the real world cyber capabilities of our AI models. And that I think is number one true but also quite noteworthy right you could you could argue you know who is better positioned to assess what these models are capable of than the people who are developing them. And here we have a note where even as the models were out there in the world doing harm the company that was creating them just didn't think that that was going to be possible yet right they thought the critical tier of cyber capabilities was some distance in the future here it is in the present doing real harm to real companies. And then he says something else that I think is kind of interesting he he says that open-weight models are close behind quote various companies have released open-weight models with cyber capabilities only a few months behind the frontier. The most recent of these models appear slated to be released at the end of August and seems likely to significantly accelerate the threat landscape. End quote does not name the model in that little excerpt but there's a hyperlink in the blog post and it goes to ZAI a Chinese AI model developers GLM 5.3 announcement. So here is Greg Brockman president of open AI openly pointed out that Chinese companies are only a few months behind and when they're talking about where they are in the future it has some pretty extraordinary capabilities with genuine geopolitical implications, genuine national security implications and we've said this almost every week that we've done this podcast but like what an incredible time. Let's let's zero in on that for a second given what Brockman said about open models and accelerating the threat landscape and also looting to ZAI's recent announcement for GLM 5.3. So as you mentioned over the last couple of weeks every week is a new Chinese model with a news threat factor associated with it right it was Kimmy K3 and deep sea certainly in recent weeks so what did ZAI actually announce and why is it notable? Well so I think it's worth pointing out that right ZAI was the company whose model hugging face turned to when they were trying to secure their AI infrastructure in the face of the attack coming from open AI models. So this is the company in China that has really noteworthy cybersecurity capabilities and in terms of what ZAI saying about the next upcoming model that Brockman is talking about here's what they wrote in their announcement quote GLM 5.3 is our most capable model to date for cybersecurity tasks they also create clear dual use risks we are therefore taking a staged approach to release selected security partners will first evaluate GLM 5.3 in controlled settings once the necessary safety evaluations and release preparations are complete we will publish GLM 5.3's complete model weights so they're not going to release the model weights for roughly two weeks for this safety evaluation it's a break from ZAI's practice with the previous model which was the weights were open sourced immediately at launch and that's a really interesting development because here we have China now adopting the practices that basically the American closed source providers have had in practice for years now which is doing a bunch of internal safety testing allowing for external safety testing before they release the model openly that's kind of interesting I mean like ZAI as a Chinese company could have a lot of reasons for why they're doing this you know number one it could just be because they're scared of having an incident like the hugging face incident where their model is out there causing harm would cause damage to the brand it could be because they think it's a nice way to sort of show themselves as a responsible actor at the same time that the United States is levying a lot of criticism at Chinese AI companies I don't know precisely why they're doing this but it is a really interesting development so when we start talking about GLM 5.3 how good is it actually on cyber and you spoke a little bit about ZAI having kind of external evaluations on the model itself whose numbers are those for the external evaluations like who are we talking about there so those model evaluations that ZAI is now undergoing those are to sort of assess it from a cyber safety perspective they're not like giving it a cyber report card we actually don't have independent verification of the cyber performance yet what we have are ZAI's own figures which are the ones that Brockman is commenting on so there's a bunch of different cyber benchmarks GLM 5.3 actually leads on one of them ahead of mythos ahead of GPT 5.6 soul so according to at least one cyber benchmark better than the best American publicly available models but on two other cyber benchmarks trails badly so with the data that we have in hand sort of difficult to say I will say many people who have tried Chinese open source models will say in a way that is sort of difficult to characterize they're undeniably good but they're not really quite as good as the benchmarks might lead you to believe like that the benchmarks say they are neck and neck with the best American stuff but then you actually use the thing and in a way that's sort of difficult to quantify they don't seem quite as good as the benchmarks might lead you to believe perhaps that's the case here with these cyber benchmarks perhaps not perhaps they're really this good and so when those open weights come out we will see a rush of independent testing and experimentation that's going to be a really big move understood so one very insightful voice on this topic is Nathan Lambert who previously was at the Allen Institute for Artificial Intelligence which is a very pro open source community Lambert continues to be very pro open source he's actually visited some Chinese AI open source firms in the not too distant past and he had some remarks not all of which I agree with but that I think are still noteworthy and worth pointing out here so he said this on his interconnects sub stack which is pretty good quote it is very very likely that open AI and anthropic have far better internal models than Zai and moonshot AI still these American companies tend to take months to release their models to the public which massively flatters the Chinese labs in adoption decisions at the frontier to put it simply the Chinese labs use all the time that American labs do pre-release testing to keep hill climbing on benchmarks so this is exactly the sort of competitive dynamic that President Trump has expressed concern about when the White House was originally thinking about a 90 day pre-review period of these AI models what Lambert is effectively saying is the gap between American AI models and Chinese AI models is smaller than it might appear because the American companies are taking months to do all of this internal review that internal review might be augmented by government review and when you add all of that up that is the margin of leadership that we have over the Chinese companies and so it's kind of amazing that this is a guy who's very pro open source but he's still out there saying it appears to be the case that we are consuming all of our leadership margin focusing on safety which might be the very responsible thing to do but it still has unfortunate geopolitical consequences now here's the next thing that he wrote which I thought was really really interesting because he's saying that it's it's not enough self-policing staged release on a lab by lab basis quote barely matters when true open weights are coming if not GLM 5.3 then another model the size of the models with these capabilities is reducing over time becoming easier to modify and deploy potentially without safeguards ZAI does some of the right things including pushing for more vulnerability discovery and proactive management but any single company is far from being able to handle this on their own we need industrial scale guidance led by the government or industry coalitions to immediately prepare for this transition across all software. So that I thought was a really interesting point from, again, a big proponent of open source, basically saying that like, look, good on the companies for doing good things, but given where open source is headed, given the capabilities of these systems, the lab by lab basis, does not actually increase the safety of planet earth or the global economy, just because you only need one bad actor to poison the entire well. And gosh, that is a real challenge that the government is wrestling with right now. - Yeah, and in order to not have sequential review, which loses up the leadership time, you're really talking about a very tight relationship between government and the labs in order to have concurrent review that maintains that leadership time, gets everything out the door, that's a different model than what we're saying right now. And a dream of a deep bench of government talent and institutional capacity to do this, right? If you go to the department of energy, you will find a bunch of extraordinarily talented people who are absolutely credible at doing a deep safety check of any nuclear power plant, right? But if you go into the US government today, can you find anything equivalent to that for safety testing or cyber testing AI models? You know, I know that there's talented people in the government, are there enough? Are they well organized enough to be effective enough given the nature of the challenge that we currently face? I think that's the question. - I understand. So moving on to our next piece of news. On August 12th, Israeli security firm Dream published with aid uncovered a multiple AI agent hacking operation that compromised government systems in Asia in the first four days of July. And a story in the financial times from the same day, a person with knowledge of the attack identified the target as Taiwan. Greg, give us the shape of this first one and what actually happened here. This is a pretty significant piece of information that came out in the press. - It's an amazing piece of information. So we don't have all the details, right? This Israeli firm uncovered this AI powered, open hacking operation going after Taiwan's government. They released some of the details, not all of the details, but it's very interesting that they used open models and harnesses available through open claw and freely available open source agent systems combining all of these open source activities to, as the cyber nerds would say, hone the Taiwanese ministry of foreign affairs. So here's a quote from the dream report. In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records and gained a persistent foothold inside state infrastructure. The report goes on. These agents autonomously cracked government employee credentials, exfiltrated hundreds of personnel records from unauthenticated API endpoints, discovered a signature validation flaw in the government's personal authentication service and installed persistent backdoors on government web applications. We increasingly see threat actors leveraging AI for autonomous offensive operations, but building a system that actually works at this level takes more work than just running a model. It demands careful adjustment to the specific task, optimization of agent coordination and fine tuning of the decision logic, the kind of sophistication evident in this framework's Bayesian prioritization, self correction loops and adaptive research cycles. So what they're saying is this is a really impressive attack. It took a bunch of not open source models, although those were almost certainly used, but all of these open source AI tools around it, like Claw, which is really useful for orchestrating different agents and the harnesses that allow you to instruct and oversee the behavior and make sure that the deterministic code works synergistically with the AI code. It's a really impressive hacking operation. It was targeted at Taiwan's government. The Israeli firm did not say that it was China orchestrating this attack, but who likes to hack Taiwan a lot, China. So I feel pretty confident in saying it was almost certainly them. So given there's kind of the reflexive response that way there's a lot of organizations within China not just the country, but also the government. Do we have a kind of specific understanding of who this might have been? So not at this time, there's multiple organizations within the Chinese government that are involved in hacking and sometimes the Chinese government likes to recruit these sort of theoretically not government employee hacking groups, but if I had to guess, I'm for sure say Chinese intelligence services, maybe the MSS. It's really interesting. I think one thing that really brings credibility to the fact that it was in fact China is just a linguistic analysis. So Taiwan obviously speaks Mandarin Chinese, but they use traditional script for the written script. mainland China, because of the communist reform, era under Mao, switch to simplified Chinese script and the operational documentation of the code underlying this attack that the Israeli firm was analyzing, found, quote, linguistic analysis of the operational documentation, which code switches between simplified Chinese in internal status reports and traditional Chinese in target facing analysis points to a Chinese language operator. So it's either China or somebody pretending to be China. I think we can definitively say, but they don't attribute it to any particular group. Oh, understood. So in related news, Chinese open models are really operating at or near frontier performance of the leading US models, even under the restrictive export controls that we talk about on a regular basis. How are the Chinese labs staying close to the frontier if their access to US hardware and AI models is working to be restricted at this point? Yeah, so I get this question a lot. And I think it's worth just laying down the fundamentals of how I think this is happening, right? How is China this close to America? Well, I think one part of the story is what we heard in Nathan Lambert's analysis of the situation, which is the American companies are sort of self-restricting. And that is months of time that they are not putting their latest and greatest models out there. That's one factor in the story. Another factor is talent, right? That the Chinese engineers at some of these Chinese AI companies are absolutely world class. They are just as good as the world class engineers at Western AI firms. So it's not like that is the bottleneck in the Chinese ecosystem. Then we come to sort of the compute part of the story, which the export controls really were geared towards restricting China's ability to access sufficient compute and how to China get it. Well, the first way is the illegal way, obviously. We know of many, many large scale smuggling rings in the hundreds of millions or billions of dollars of chips that were not supposed to get to China, but they got to China. That's like illegal acquisition of hardware. There's also the illegal acquisition of software, which is distillation, which we've talked about on this podcast. The third really important factor is that the export controls as we have implemented them have had a bunch of holes. And this includes in the early part of the story, a failure to realize that Nvidia could do post-manufacturing modification of their chips such that the performance penalty of the threshold that was set for export controls was much smaller than was envisioned by the officials who dreamed up the export control regime. And then again, that was legal. Nvidia was not breaking the law and they made those post-manufacturing modifications. It just went against the Biden administration's intent, not the rules as they had written them. There's also little to no restriction on Chinese firms that are not entity listed from accessing American cloud infrastructure to train their models. And they can do that through shell companies. They might be able to do that directly, depending on the circumstances. But the point is, even if they can't buy the chips and get them to China, they can rent those same chips in Singapore, in Malaysia, in wherever. And the point being that they're still getting access to those chips, they're just not in China. And I think that matters a lot in this story here. So Greg, where does the H200 fit in this larger spectrum of illegal versus legal acquisition? And obviously the kind of post-manufacturing things that Nvidia can do with their technology. Beijing spent most of the past year keeping H200s out even after Washington approved them. So what is the utility of the H200 actual? - Yeah, so the H200, it's worth saying, is kind of one generation of chips. It's the best version of the last Nvidia generation of AI training chips. President Trump was trying to sort of thread the needle as he saw it and find a midpoint between allowing everything and restricting further. So he lessened the restriction somewhat to allow H200s with the Biden administration did not allow sales to China. But then China said, ah, we're not gonna buy them anyway, even though you're going to allow them. Well, China. China has now reneged on that, as predicted, and that is because the cloud companies in China really want these chips, and in particular, they really want them for training. So there are local Chinese chips. They're definitely not as good in Nvidia chips at anything, but the gap is most pronounced in the training side of the story. And so getting China more local H200s is an advantage to those companies, and those shipments have now started to go forward. This was confirmed by Kessler in his congressional testimony that those shipments were going forward, but now we've got, you know, from the Beijing side of the story that they're allowing those chips into the country. Understood. Now Nvidia is building a chip specifically for use in China. How does that fit into the US China compute gap and kind of continuum, and what does that do to competition in this space? According to the financial times, Nvidia has about 500,000 H200s in inventory or some various stages of production that are mostly headed for Chinese customers. So this is a very big compute power windfall, even though the H200 is not as good as the latest and greatest blackwall chips. It's not 10 times worse, you know, it's somewhere between two and five times worse, depending on your various use case. So 500,000 chips coming to China, that is a big plus up in their computing capacity. I do think it is actually strategically significant. So far, according to the same financial times report, bike dance and 10 cents have already taken delivery of about 10,000 H200s each. Expect that number to keep going up as China now builds data centers and power generation capacity to bring all this Nvidia capacity online. And just to be clear, Greg, 500,000 chips is a lot, which means that Nvidia didn't just generate these chips. They've been working on this policy for a while. Correct. Right. Remember, Nvidia said that they took a big write down on the H20 because they had these chips in the various stages of production. Now when you build all these H200s, obviously China is the main target for that because most of your customers would rather have blackwell chips if they can have them. So when you're building H200s, you're principally building it for China. But that's not enough. Nvidia is now working on a new version of a new chip that is specifically for China. And the point here being that the performance thresholds that allow India to sell H200s, they do not allow them to sell blackwells, well, the H200 was optimized for the commercial market at a specific point in time. I think Nvidia is now exploring can they build a better version of a chip that somehow still is beneath whatever the version of the export controls interpretation is that does not allow sales of blackwells. And so again, more chips going to China. Yeah. And with both of those production cases, it's very clear that selling in the Chinese market is a priority for a video. Right? Oh, yes. Absolutely. I mean, it's not as though Nvidia has not been getting money from China throughout this story, right? Going back to the earlier point, if Chinese companies are renting, computing capacity abroad, Nvidia is still getting paid for the chips, right? They're just getting paid and then built somewhere that is not China. If chips are getting smuggled into China, Nvidia might not be getting paid by the illegal Chinese customer, but they're getting paid by some party in that chain of smuggling, they still get paid full price. Nobody has ever described a story to me of chip smuggling in which Nvidia does not get paid full price. So Nvidia has been benefiting from the Chinese market throughout this story. But this is obviously the most direct relationship that they're going to have with these Chinese customers in the modern incarnation of the export control stories for several years. Got it. We really just wanted to put the fine point on that. Moving on to some State Department news here. On August 14th, Reuters reported on a leaked draft of a State Department letter to the 35 signatories of the June AI Opportunity Statement, part of Pax, Silica. So Greg, can you help us out with some background? Just let us know what is Pax, Silica, and what did this letter say? Yeah, so Pax, Silica is a flagship State Department initiative around AI and semiconductor supply chains, really trying to bring together allied countries to align their economic security strategy to align their supply chains. It is like the biggest cooperative initiative that the State Department has announced on this topic in a long time. And although it does not describe itself as an anti-China club, who exactly are you securing the supply chains against if it's not China? I think that has been the subtext of the entire initiative. And that's why it was so interesting that last month at the World AI conference, Xi Jinping launched his own global AI partnership initiative. The World Artificial Intelligence Cooperation Organization centered on open models among other things. And one country, Kazakhstan, the former Soviet nation, joined both. They're a member of Pax, Silica, where they are a potential supplier of many critical minerals. But they're also a signatory and joined this Chinese initiative. Seems like it's a bit of a conflicted position there. Well, the State Department might agree with you there, Adam. So the State Department has drafted a letter, which has now been leaked to the media, telling partner countries of Pax, Silica that they cannot simultaneously join America and China's AI coalition. It doesn't say China by name, but it says this quote according to the leaked version of the letter, to be part of everything is to be part of nothing. Signature of the Pax Silica Declaration is not merely a membership subscription, but a commitment. It cannot be held alongside membership in duplicative initiatives whose expectations conflict with our own. And according to a report in Reuters, a US official speaking on background said that this letter was drafted to make clear, quote, you can't have it both ways. So they're really saying like we never called this an anti-China club, but you can't be in the China club if you're in this club. So obviously it's there really interesting because Pax Silica is a little bit more focused on the hardware. It talks about things like coordinating export controls or technological investment and supply chains. The World Artificial Intelligence Cooperation Organization, this Chinese organization, is a little bit more focused on the open-weight models, the software part of the story. But nevertheless, the State Department clearly sees a contradiction here. Understood. Finally, bringing it back domestically, bringing it back to the United States, data center construction and opposition to data centers have been in the news routinely through this entire election cycle, the midterm election cycle, and it has been a focal point for many voters. Voters are unhappy with the projects happening in their states. This has kind of been a point of heat and light for a lot of these conversations. This week, Axio reported that the Senate GOP campaign arm privately told AI companies that data centers are going to cost them a Senate seat specifically in Ohio. Greg set this one up for us. What happened specifically here and does this matter beyond one Senate race? So Ohio in the not-too-distant past was a swing state more recently has been pretty reliably Republican. So when the Senate GOP campaign arm says that they might lose a Senate race specifically because of data centers, that is a big deal politically. Politicians are going to pay attention if that happens. They're already paying attention that it might happen. And this memo is pretty juicy. So here's what it says. The memo says that the Democrats have made data centers a real focal point of the campaign to defeat the Republican, and here's from the better itself, quote, "More than any other thing in this race, data centers are the anchor hanging around Houston's neck. If he loses and data centers get the blame, politicians across the country will take notice and they will not go near the next one. This has become a sleeper issue for the entire election cycle." And then it goes on to say, "If it is still this potent in November, elected officials everywhere will treat Ohio as their reason to work against data centers in the future." So this is really interesting because like this is the Republican Senate campaign committee telling the tech companies something has to change here. The way you are going about data centers is deeply unpopular. We don't want to be the party of stopping data centers. But unless something changes, you should expect to see politicians around the country become vastly more anti-data center. And we've already seen a lot of anti-data center momentum from politicians around the country. And then in some cases in both parties. Yeah, and I think with the Ohio Senate race in particular, a person running against Senator Houston is former Ohio Senator Sherrod Brown. Sherrod Brown is not just known as a bit of a moderate, but also somebody who is very blue-collar focused and has been a friend of the building trades. for decades, his entire career. So if shared brown is not actively looking in this campaign at the value that these data centers could have for the building trades, this argument is really getting steered in a direction that is not helpful, not just for the NRSC and center of Houston, but for this overall debate in particular, right? This is very significant and will continue to be significant there. So beyond politics, where is American compute actually located, right? So moratorium in one state is not the same as every state, but obviously this issue is going to have legs. So where is the compute regionally and otherwise? - Yeah, so you might think that data centers are in all 50 states and to a certain extent they are, but there's way more data centers in some states and there's way more data center capacity in some states than in others. So Northern Virginia, where I live, right outside of Washington, DC, holds four gigawatts of data center inventory, nearly 3.5 times more capacity than all secondary US markets combined. So a lot of data centers in Northern Virginia, a lot of data centers in Texas, a lot in California. And so that's why you can say, oh, maybe Maine will ban data centers. Well, not a lot of data centers are built in Maine, so a ban isn't very significant. So what I have been saying, what I would have told you a year ago with this data center opposition, is that this is real political opposition. It is stopping some data centers, but there's like a trillion dollars going into building AI infrastructure. So what I would have told you a year ago is that all of this political opposition is sandbags trying to hold back a tsunami. It's just not of the same order of magnitude of scale. But I do think that what we're seeing from this letter tells me that something has changed, that the opposition is reaching a critical mass. And notably, if this Senate race scenario happens, I think the analysis in this memo is correct. Politicians all over the country are going to pay attention, right? If a swing state Senate loss occurs most prominently because of opposition to data centers, that might no longer be sandbags against tsunami, that might be a very, very high stone wall trying to hold back a tsunami. And there, you know, you might actually get to the point where the blockages are geopolitically significant. That's not guaranteed as an outcome. Maybe a lot of states will ban it, and so just a lot more will get built in Texas than would have otherwise been the case. But I'm just saying what I thought was true a year ago, I can no longer say with competence. This is reaching a sort of a new degree of political opposition. - Yeah, no, it certainly is. So there's a lot of focus on data centers being politically toxic and kind of highlighted where they're actually located. Is there an overlap where data centers actually exist right now with the capacity exist and some of these kind of fights as they're going on right now? - Well, it's tough to say. I mean, and some politicians appear to be moving on this issue. So Josh Shapiro, governor of Pennsylvania, he had previously embraced data center project. Talked about them as job creators, talk about them as bringing investment into the state, just signed an executive order on August 18th, imposing strict guardrails on the construction of data centers. You and I have talked about previously, governor Kathy Hocal of New York, who put a one year moratorium on the construction of data centers, and we talked about it at the time. You know, that was her trying to find a middle ground against what the democratic legislature of New York might have otherwise done. But it's a really, really noteworthy development that former allies are now either moving into opposition or sliding into a more moderate kind of a stance. And that's kind of the question. What would really change my calculus is if you saw something like the big building zones, Virginia, Georgia, Texas, if they started adopting rules that really slowed down construction, that would be noteworthy. And Loudon County, where here in Virginia, there's a lot of data center construction. You're starting to see a lot of opposition coming, people talking about power prices, people talking about noise, people talking about traffic, people talking about real estate prices. For whatever reason, there's a lot of opposition coming, including in some of the biggest hubs. Now it hasn't boiled over yet to stop being Virginia from being a goliath in data center construction. But as I said, it's no longer a sandbags against tsunami kind of a story and it could become even more significant than that. Now you got to imagine watching this whole story, China is just licking its lips, right? That the United States, if they have one advantage that they could exploit, it is this advantage in computing capacity and they might just unilaterally disarm, you know what China would say, thank you so much. My gosh. - Yeah, so maybe a bright spot in this debate during the Wisconsin Governor's Democratic primary, there were really kind of two competing visions on data centers. One was Fred Cheska-Hong, who was the candidate that was running as a member of the DSA Democratic Socialist of America, who was looking for a one year moratorium on all data center development in the state of Wisconsin. David Crowley, who is the current Milwaukee County Executive who wound up winning that primary race, certainly had a much more moderate take on data centers and building construction utilization of data centers, right? Well, that was a very tight race, they had very significantly different positions, right? So I think there is a version of this, there is a story out there during the primaries where Cuommerheads do prevail. Greg, I'm curious, what's your crystal ball in this? Post midterms, does this opposition kind of consolidate in calcify or is that really just noise and is there a more room for debate out there right now? Well, I think part of the opposition to data centers is a lot of this AI angst around employment, around inflation, around, you know, you and I have talked about the memory chip shortage and just how like, AI's relentless demand for so many things is causing a raise in the price of things. We're seeing some discussions right about interest rates being forced to be raised because of what AI is doing to the debt market and inflation around the country. So this is not quite the same category of opposition as nuclear reactors, even though a recent survey had some people saying that they would rather have a nuclear reactor located in their backyard than a data center located in their backyard, not a position that I would have expected 10 years ago, but does show you how in some jurisdictions, this issue is literally politically radioactive, pun intended. (laughing) And where all this goes, I do think there is this infinite river of money going into AI infrastructure. And one thing that that means is that there's more money potentially available to try and make local jurisdictions a little bit more happy. And like one thing that comes to mind in my head is there's like this court district in Texas where a lot of technology lawsuits take place. And so all these tech companies started building that town an ice skating rink, you know, like brought to you by this company just because they're trying to influence like the juries in that district. And so I do wonder if the tech companies need to start thinking about putting more resources, putting more money, not just into advertising campaigns, talking about the goodness of data centers, but frankly just plowing more money into more near-term benefits to the communities that have data centers. And the point here is like, if we're gonna spend a trillion dollars on AI infrastructure, well then yeah, there probably is 10 billion dollars out there of goodies to be handed out to the communities where data centers are located. And the power and electricity part of this story could get worse, but it could also get better. I mean data centers love to run 24/7, but if they come with new local on-site power generation or if the data centers agree to on a very hot day or a very cold day where power generation is especially intense to reduce their utilization, you know, that could add legitimate resiliency to the grid as well. And so my point here is that yes, it is definitely concerning to me how unpopular data centers are becoming, but I also think it's true that the tech companies have not yet reached for all the tools in the tool bag to try and make these a little bit more popular. So in the aftermath of the Gilded Age post-American Civil War, there were very wealthy industrialists, Andrew Carnegie, Rockefeller, and Carnegie in particular not just made a ton of money and made it in sometimes questionable ways, but also just was a huge philanthropic interest in the country and you still see concrete versions of that. In some cases, marble versions of that throughout various cities in the United States and the Carnegie libraries that exist. Now oddly enough, and I guess poetically enough, the Carnegie Library in DC is now an Apple store, right? So literally transition from kind of the story into the modern tech stuff, but there is a bit of a lot of commentary on how tech interest AI interests simply haven't done the same. So maybe there's room here for energy infrastructure build out to be that kind of gilded age contribution to the general good that changes opinions a little bit. Yeah. I mean, what you could, you know, almost imagine it's sort of like as a patriotic philanthropy kind of a movement and branding it as such. I don't know if that's going to happen. I'm not necessarily predicting that's going to happen, but I think your point is well taken. And I'll combine it again with my own. We haven't seen the tech companies reach for all the tools in the toolbox yet. And I think that's what this Republican memo is about. It's saying guys, whatever you're doing, it's not enough. You need to change tactics if you want to prevent political firestorm. I understood. So Greg, we'll go ahead and leave it there. And that does wrap up our discussion for this week. We covered corporate decisions to suspend training of new models, a coordinated autonomous AI attack on Taiwan's government updates to the US China AI export controls and compute capabilities and a new chapter in the domestic data center debate. Thanks. As always, see you, Greg. Appreciate you being here for the show and to our audience for listening. We'll be back next week with a new episode. And as always, I'm sure we'll have plenty to talk about. Never a dull moment on the AI, but thanks Adam. Thanks Greg. [Music] [Music] [Music] [Music] [Music]

Podcast Summary

Key Points:

  1. OpenAI announced a two-week pause in reinforcement learning training and an indefinite hold on larger frontier runs after the Hugging Face incident, citing that its preparedness framework is no longer sufficient for current model capabilities.
  2. OpenAI's president Greg Brockman acknowledged underestimating the real-world cyber capabilities of its AI models and pointed to Chinese open-weight models, like ZAI's GLM 5.3, as being only months behind the frontier, with GLM 5.3 set for a staged release due to dual-use risks.
  3. An Israeli security firm uncovered a four-day AI-powered hacking operation, likely by China, that compromised Taiwan's government systems using open-source models and tools, producing cracked credentials, exfiltrated records, and persistent backdoors.
  4. Chinese labs are staying close to the US frontier through self-restriction by American companies, world-class Chinese talent, illegal chip smuggling, legal cloud access abroad, and Nvidia's post-manufacturing modifications, with 500,000 H200 chips now being shipped to China.
  5. The State Department drafted a leaked letter to Pax Silica signatories, warning that countries cannot join both the US and China's AI coalitions, stating "to be part of everything is to be part of nothing," after Kazakhstan joined both initiatives.
  6. The Senate GOP campaign arm warned AI companies that data center opposition could cost them a Senate seat in Ohio, arguing that if this happens, politicians nationwide will avoid supporting data centers, making the issue politically radioactive.
  7. Data center opposition is growing in key hubs like Virginia, Pennsylvania, and New York, with governors imposing guardrails or moratoriums, though tech companies have yet to fully leverage community benefits or philanthropic strategies to counter the backlash.

Summary:

The podcast episode, hosted by David and featuring Greg Allen, covers major developments in AI safety, cybersecurity, geopolitics, and domestic politics. First, OpenAI's August 17th announcement reveals an unprecedented step: pausing its own training for two weeks after the Hugging Face incident, where an unreleased model, likely Astra, demonstrated critical cyber capabilities, including autonomous zero-day exploits. OpenAI now allocates 20% of inference compute to monitoring, a potentially massive cost, and admits its preparedness framework is inadequate.

3, are only months behind, with staged releases to manage dual-use risks, though independent verification of their cyber performance is lacking. Second, a report from Israeli firm Dream details an AI-powered hacking operation against Taiwan's government, using open-source tools like Claw, which cracked credentials and installed backdoors in four days, with linguistic analysis suggesting Chinese operators. Third, the US-China compute gap is narrowing due to illegal smuggling, legal cloud access, and Nvidia's H200 shipments, with 500,000 chips heading to China despite export controls.

Fourth, the State Department's leaked letter to Pax Silica partners warns against dual membership with China's AI coalition, signaling a hardline stance. Finally, domestic data center opposition is escalating, with the NRSC warning that Ohio's Senate race could be lost over this issue, and governors in Pennsylvania and New York imposing restrictions, potentially making data centers a decisive political liability.

FAQs

OpenAI paused training for two weeks after the Hugging Face incident revealed that its unreleased model, Astra, may have reached the critical cybersecurity tier. The company stated its existing preparedness framework was no longer sufficient, prompting a need for enhanced safeguards around training and evaluation.

The preparedness framework is a system for measuring and protecting against severe harm, with tiers of capabilities. A model reaches the critical cyber tier if it can autonomously discover and exploit unknown vulnerabilities in hardened real-world systems, which OpenAI cannot rule out for Astra.

The 20% monitoring overhead applies to inference compute for high-capability models, meaning for every five data centers, one might be dedicated to monitoring. This could represent an enormous expense, potentially tens of billions of dollars, if applied broadly in the future.

ZAI delayed the release of GLM 5.3's weights for about two weeks to conduct safety evaluations due to the model's dual-use risks in cybersecurity. This marks a shift from their previous practice of open-sourcing models immediately, aligning with Western staged release approaches.

The attack, uncovered by Israeli firm Dream, used open-source AI models and tools like OpenClaw to autonomously hack Taiwan's government systems in four days. It produced 1,395 files, cracked 85 credentials, and installed persistent backdoors, with linguistic analysis pointing to a Chinese-language operator.

Chinese labs stay competitive through world-class talent, illegal chip smuggling, and legal loopholes like renting cloud infrastructure abroad. Additionally, US companies' self-imposed delays in releasing models give Chinese firms more time to catch up on benchmarks.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.