OpenAI slows training, Taiwan gets AI-hacked, toxic data center politics
53m 48s
The podcast episode, hosted by David and featuring Greg Allen, covers major developments in AI safety, cybersecurity, geopolitics, and domestic politics. First, OpenAI's August 17th announcement reveals an unprecedented step: pausing its own training for two weeks after the Hugging Face incident, where an unreleased model, likely Astra, demonstrated critical cyber capabilities, including autonomous zero-day exploits. OpenAI now allocates 20% of inference compute to monitoring, a potentially massive cost, and admits its preparedness framework is inadequate. Greg Brockman's blog post highlights that open-weight models from China, such as ZAI's GLM 5.3, are only months behind, with staged releases to manage dual-use risks, though independent verification of their cyber performance is lacking. Second, a report from Israeli firm Dream details an AI-powered hacking operation against Taiwan's government, using open-source tools like Claw, which cracked credentials and installed backdoors in four days, with linguistic analysis suggesting Chinese operators. Third, the US-China compute gap is narrowing due to illegal smuggling, legal cloud access, and Nvidia's H200 shipments, with 500,000 chips heading to China despite export controls. Fourth, the State Department's leaked letter to Pax Silica partners warns against dual membership with China's AI coalition, signaling a hardline stance. Finally, domestic data center opposition is escalating, with the NRSC warning that Ohio's Senate race could be lost over this issue, and governors in Pennsylvania and New York imposing restrictions, potentially making data centers a decisive political liability.
(upbeat music)
- Welcome back to the AI Power Podcast.
We have a packed show to catch up on everything that's happened.
With me as always is Greg Allen.
Greg, how are you doing?
You were on vacation last week.
How was the vacation, sir?
- Yeah, I just got back from Rehoboth, Delaware,
which is a beach within driving distance
of the DC metro area.
It's actually the same Rehoboth, Delaware,
where Biden decided to drop out of the presidential election.
That's where he keeps his vacation home.
But it's not like an ultra glamorous camp, David.
It's just a resort town, and it was lovely.
Spend some time with the fam, chillin' out,
and now ready to get back to podcasting.
- Very good, very good.
Glad you didn't take your time in Rehoboth
to drop out of the podcast, sir.
That's positive.
Very good.
Let's go ahead and jump into our first story.
Three weeks ago, we covered the OpenAI Hugging Face incident.
On August 17th, OpenAI published the post saying
that that incident plus preliminary evidence
about an unreleased model caused it to slow down
its own training.
So Greg, what did OpenAI actually announce on August 17th
because this does seem like a very significant step
specifically from OpenAI?
- Yeah, I think we have been talking
about the OpenAI Hugging Face incident for a long time
because it's a really big deal.
And literally, even though this happened,
we keep learning more and the companies
and the governments keep adjusting their behavior
based on what they learn.
And here we have a milestone in the history of AI
that is, I think, unprecedented.
So what we have seen in the past is companies
slow the release of their models
based on security and safety concerns, right?
That goes all the way back to GPT-2 when OpenAI was worried
about disinformation and misinformation
that was gonna be AI augmented.
And they made a big stink about how their model
was too significant to release to the public
and they had a stage release process.
So delaying the release of the models,
that is a behavior that has been with us for years.
What is new here is the company delaying its own training
of the next model.
In other words, they're so concerned
about what these models do
that they are deliberately slowing down
their own creation of the AI models.
Now, it's not like they're pausing for years.
What they have announced is specifically a two week pause
in reinforcement learning training on latest models.
And then also they said, quote,
our largest planned frontier RL run remains on hold
we conduct smaller scale training and evaluations.
And then they further said in this publicly released statement,
quote, a significant number of workloads
and quote, remain paused until they are fully migrated
and enhanced to meet the new security bar.
So basically what they're saying is
after the hugging face incident,
which was, you know, while a model was being evaluated,
they were testing a model.
Well, if the evaluation itself is a source of danger,
you can understand the company very reasonably saying,
okay, we need beefier safeguards
around a whole range of corporate activities.
And that now includes training.
So they're trying to figure out what do we need to put in place
for training and building new models
to take place in a way that is safe and responsible.
So they're building all of these classifiers
that can observe and watch the model's behavior,
that can observe the results of training runs,
that can observe the results of reinforcement learning activity.
And they're spending a lot of corporate resources on this.
I think one of the more interesting developments
was when they said they're going to spend
a significant share of computing resources,
monitoring their own models during the development process.
And what's interesting here is also the fact
that OpenAI had previously because they were born
of a safety-obsessed culture.
I mentioned that they delayed the release of GPT-2
because of safety concerns.
They have over the years been putting out
all of these different kinds of frameworks
like the preparedness framework,
and they classify their different cyber models
according to different degrees of capabilities.
But one of the things that really jumped out to me
in this statement is they said
their preparedness framework is no longer sufficient.
So here's the quote.
The signals we are seeing from upcoming model progress
make clear that we need a broader approach,
one that builds on and extends
beyond the current preparedness framework.
So they had a plan.
Here's what we're going to do if we see this.
Here's what we're going to do if we see that.
And they're basically saying,
our current degree of progress,
what these models are doing,
what they are capable of doing,
and what they seem very likely to be capable of doing,
our framework was not adequate
to deal with what we're currently handling,
which is kind of amazing
because when they were working on that framework,
they were thinking all the way to superhuman AI.
And here we are now in a world where
they just feel like more work needs to be done,
and they're willing to take a two week pause
and keep mind when you spend $100 billion
on a data center not using it for two weeks
is a pretty expensive decision.
I'm overstating it really,
what they're going to do is use that computer capability
for inference rather than training,
but still that the point stands nonetheless.
This is kind of a big decision,
even though it's only two weeks.
- Yeah, Greg, let's back up and walk through
the preparedness framework for a second
and then kind of crack that open.
So what is the preparedness framework?
And what does it actually mean for a model
to sit at a critical cyber tier
as opposed to a high cyber tier?
- Yeah, so this is a system for measuring
and protecting against severe harm and they kind of tier it.
So they publish these tiers of capabilities
and they say if the model can do this,
then we commit to the following safeguards, right?
So if the model has some cybersecurity capabilities,
then maybe we will do some fine tuning
where it refuses to autonomously hack.
If it does something really scary,
we will put in more safeguards so on and so forth.
I'm oversimplifying, but not by a ton.
Now, one of the tiers that's really important here
is the critical cyber tier.
And this is defined around autonomous discovery
and exploitation of unknown vulnerabilities
in hardened real world systems.
So here's the quote from that framework.
Quote, "Under our preparedness framework,
a model reaches the critical cybersecurity threshold
if it can identify and develop functional zero-day exploits
of all severity levels in many hardened real world
critical systems without human intervention.
Or can device and execute end-to-end novel strategies
for cyber attacks against hardened targets
given only a high level desired goal?"
End quote.
What does that sound like to you, Adam?
Sounds an awful lot like the hugging face incident to me.
- Exactly.
- Exactly, so OpenAI has this unreleased model
called Astra, and what they are saying specifically
is cannot rule out that Astra is at the critical tier.
Now, if Astra was indeed the model involved
in the hugging face incident,
I also cannot rule out that it's at the critical tier,
but I might go a little bit further
and say, "Mm, really looks like it's at the critical tier to me."
And so this is why you're seeing the company going to,
at least in terms of what we've seen from AI companies
of the past few years, really unprecedented behavior,
a pretty remarkable story.
- Understood.
So OpenAI wrote that as a result of its new models' capabilities,
new monitoring has been put in at 20% of overhead
due existing compute cost,
just to give us an order of magnitude.
Is that a big number?
What is that actually 20% of?
- Yeah, so that is a potentially massive number.
So what they're saying, and this is the full quote,
are current estimates put monitoring overhead
at roughly 20% of the inference compute being monitored
though the cost very substantially
across training and evaluation workloads.
Let's just think of the most extreme version of that,
which is not true, right?
Let's assume it applies to all inference.
Well, inference is somewhere between 60 and 80%
of the company's compute workloads is inference using models
versus training creating models.
Now, if hypothetically 20% of that 80%
has to be devoted to monitoring,
well, that's basically like saying,
for every five data centers they create,
they have to create one for monitoring the work
of all the other data centers.
These data centers cost tens of billions of dollars.
So the fact that like one of them
might only have the job to watch the other ones,
that's an enormous expense, an enormous expense.
Now, what I just described is the most extreme scenario.
We're not in the most extreme scenario.
What it applies to is reinforcement learning,
training and evaluations, involving tools
at sole capability or higher,
and to all Astra inference with tools.
So not to everything yet, but the point here is,
this is where the capabilities are going previously.
We were all using GPT 4.0 or the earlier versions of these models and slowly but surely we all use
capabilities as the models get better and the prices come down and the point is at some point
we're all going to be using astral level capabilities or better routinely. And so unless this
monitoring overhead cost comes down from a compute perspective, the potential ceiling of this
cost is truly enormous. The worst case scenario I described doesn't apply today but the trajectory
unless something changes implies that this would apply which is a crazy, crazy degree of cost
to be forced to invest in safety. Has OpenAI said anything else about safety and the pace of AI
development given this is such a huge press issue for them right now? Oh yeah, I mean it's a huge
everything issue for them right now press regulation customers. So Greg Brockman who's the president
of OpenAI published a blog post the same week of the pause and that blog post was calling for
all companies including OpenAI to quote fundamentally up level their cybersecurity practices with
unprecedented speed amidst this watershed moment. And the further thing that he says that I thought
was really interesting was this quote the hugging face incident showed that we underestimated the
real world cyber capabilities of our AI models. And that I think is number one true but also quite
noteworthy right you could you could argue you know who is better positioned to assess what these
models are capable of than the people who are developing them. And here we have a note where
even as the models were out there in the world doing harm the company that was creating them
just didn't think that that was going to be possible yet right they thought the critical tier
of cyber capabilities was some distance in the future here it is in the present doing real harm
to real companies. And then he says something else that I think is kind of interesting he he says
that open-weight models are close behind quote various companies have released open-weight models
with cyber capabilities only a few months behind the frontier. The most recent of these models
appear slated to be released at the end of August and seems likely to significantly accelerate
the threat landscape. End quote does not name the model in that little excerpt but there's a hyperlink
in the blog post and it goes to ZAI a Chinese AI model developers GLM 5.3 announcement. So here is
Greg Brockman president of open AI openly pointed out that Chinese companies are only a few
months behind and when they're talking about where they are in the future it has some pretty
extraordinary capabilities with genuine geopolitical implications, genuine national security
implications and we've said this almost every week that we've done this podcast but like what an
incredible time. Let's let's zero in on that for a second given what Brockman said about open
models and accelerating the threat landscape and also looting to ZAI's recent announcement for GLM
5.3. So as you mentioned over the last couple of weeks every week is a new Chinese model with a
news threat factor associated with it right it was Kimmy K3 and deep sea certainly in recent weeks
so what did ZAI actually announce and why is it notable? Well so I think it's worth pointing out
that right ZAI was the company whose model hugging face turned to when they were trying to secure
their AI infrastructure in the face of the attack coming from open AI models. So this is the company
in China that has really noteworthy cybersecurity capabilities and in terms of what ZAI saying about
the next upcoming model that Brockman is talking about here's what they wrote in their announcement
quote GLM 5.3 is our most capable model to date for cybersecurity tasks they also create clear
dual use risks we are therefore taking a staged approach to release selected security partners
will first evaluate GLM 5.3 in controlled settings once the necessary safety evaluations and
release preparations are complete we will publish GLM 5.3's complete model weights so they're not
going to release the model weights for roughly two weeks for this safety evaluation it's a
break from ZAI's practice with the previous model which was the weights were open sourced
immediately at launch and that's a really interesting development because here we have China
now adopting the practices that basically the American closed source providers have had in practice
for years now which is doing a bunch of internal safety testing allowing for external safety
testing before they release the model openly that's kind of interesting I mean like ZAI as a
Chinese company could have a lot of reasons for why they're doing this you know number one
it could just be because they're scared of having an incident like the hugging face incident where
their model is out there causing harm would cause damage to the brand it could be because they think
it's a nice way to sort of show themselves as a responsible actor at the same time that the United
States is levying a lot of criticism at Chinese AI companies I don't know precisely why they're
doing this but it is a really interesting development so when we start talking about GLM 5.3
how good is it actually on cyber and you spoke a little bit about ZAI having kind of external
evaluations on the model itself whose numbers are those for the external evaluations like who are
we talking about there so those model evaluations that ZAI is now undergoing those are to sort of
assess it from a cyber safety perspective they're not like giving it a cyber report card we actually
don't have independent verification of the cyber performance yet what we have are ZAI's own
figures which are the ones that Brockman is commenting on so there's a bunch of different cyber
benchmarks GLM 5.3 actually leads on one of them ahead of mythos ahead of GPT 5.6 soul so
according to at least one cyber benchmark better than the best American publicly available models
but on two other cyber benchmarks trails badly so with the data that we have in hand sort of
difficult to say I will say many people who have tried Chinese open source models will say
in a way that is sort of difficult to characterize they're undeniably good but they're not really
quite as good as the benchmarks might lead you to believe like that the benchmarks say they
are neck and neck with the best American stuff but then you actually use the thing and in a way
that's sort of difficult to quantify they don't seem quite as good as the benchmarks might lead
you to believe perhaps that's the case here with these cyber benchmarks perhaps not perhaps they're
really this good and so when those open weights come out we will see a rush of independent testing
and experimentation that's going to be a really big move understood so one very insightful voice
on this topic is Nathan Lambert who previously was at the Allen Institute for Artificial Intelligence
which is a very pro open source community Lambert continues to be very pro open source he's actually
visited some Chinese AI open source firms in the not too distant past and he had some remarks
not all of which I agree with but that I think are still noteworthy and worth pointing out here
so he said this on his interconnects sub stack which is pretty good quote it is very very likely
that open AI and anthropic have far better internal models than Zai and moonshot AI still
these American companies tend to take months to release their models to the public which massively
flatters the Chinese labs in adoption decisions at the frontier to put it simply the Chinese labs
use all the time that American labs do pre-release testing to keep hill climbing on benchmarks so
this is exactly the sort of competitive dynamic that President Trump has expressed concern about
when the White House was originally thinking about a 90 day pre-review period of these AI models
what Lambert is effectively saying is the gap between American AI models and Chinese AI models
is smaller than it might appear because the American companies are taking months
to do all of this internal review that internal review might be augmented by government review
and when you add all of that up that is the margin of leadership that we have over the Chinese
companies and so it's kind of amazing that this is a guy who's very pro open source
but he's still out there saying it appears to be the case that we are consuming all of our
leadership margin focusing on safety which might be the very responsible thing to do but it still has
unfortunate geopolitical consequences now here's the next thing that he wrote which I thought
was really really interesting because he's saying that it's it's not enough self-policing staged
release on a lab by lab basis quote barely matters when true open weights are coming
if not GLM 5.3 then another model the size of the models with these capabilities
is reducing over time becoming easier to modify and deploy potentially without safeguards
ZAI does some of the right things including pushing for more vulnerability discovery and proactive
management but any single company is far from being able to handle this on their own we need industrial
scale guidance led by the government or industry coalitions to immediately prepare for this
transition across all software.
So that I thought was a really interesting point
from, again, a big proponent of open source,
basically saying that like, look,
good on the companies for doing good things,
but given where open source is headed,
given the capabilities of these systems,
the lab by lab basis,
does not actually increase the safety
of planet earth or the global economy,
just because you only need one bad actor
to poison the entire well.
And gosh, that is a real challenge
that the government is wrestling with right now.
- Yeah, and in order to not have sequential review,
which loses up the leadership time,
you're really talking about a very tight relationship
between government and the labs in order to have
concurrent review that maintains that leadership time,
gets everything out the door,
that's a different model than what we're saying right now.
And a dream of a deep bench of government talent
and institutional capacity to do this, right?
If you go to the department of energy,
you will find a bunch of extraordinarily talented people
who are absolutely credible at doing a deep safety check
of any nuclear power plant, right?
But if you go into the US government today,
can you find anything equivalent to that
for safety testing or cyber testing AI models?
You know, I know that there's talented people
in the government, are there enough?
Are they well organized enough to be effective enough
given the nature of the challenge that we currently face?
I think that's the question.
- I understand.
So moving on to our next piece of news.
On August 12th, Israeli security firm Dream published
with aid uncovered a multiple AI agent hacking operation
that compromised government systems in Asia
in the first four days of July.
And a story in the financial times from the same day,
a person with knowledge of the attack
identified the target as Taiwan.
Greg, give us the shape of this first one
and what actually happened here.
This is a pretty significant piece of information
that came out in the press.
- It's an amazing piece of information.
So we don't have all the details, right?
This Israeli firm uncovered this AI powered,
open hacking operation going after Taiwan's government.
They released some of the details, not all of the details,
but it's very interesting that they used open models
and harnesses available through open claw
and freely available open source agent systems
combining all of these open source activities
to, as the cyber nerds would say,
hone the Taiwanese ministry of foreign affairs.
So here's a quote from the dream report.
In roughly four days, the agentic attacker
produced 1,395 files, 85 cracked credentials,
thousands of exfiltrated personnel records
and gained a persistent foothold inside state infrastructure.
The report goes on.
These agents autonomously cracked government employee
credentials, exfiltrated hundreds of personnel records
from unauthenticated API endpoints,
discovered a signature validation flaw
in the government's personal authentication service
and installed persistent backdoors
on government web applications.
We increasingly see threat actors leveraging AI
for autonomous offensive operations,
but building a system that actually works at this level
takes more work than just running a model.
It demands careful adjustment to the specific task,
optimization of agent coordination
and fine tuning of the decision logic,
the kind of sophistication evident in this framework's
Bayesian prioritization, self correction loops
and adaptive research cycles.
So what they're saying is this is a really impressive attack.
It took a bunch of not open source models,
although those were almost certainly used,
but all of these open source AI tools around it,
like Claw, which is really useful
for orchestrating different agents and the harnesses
that allow you to instruct and oversee the behavior
and make sure that the deterministic code
works synergistically with the AI code.
It's a really impressive hacking operation.
It was targeted at Taiwan's government.
The Israeli firm did not say that it was China orchestrating
this attack, but who likes to hack Taiwan a lot, China.
So I feel pretty confident in saying it was almost certainly them.
So given there's kind of the reflexive response
that way there's a lot of organizations
within China not just the country, but also the government.
Do we have a kind of specific understanding
of who this might have been?
So not at this time, there's multiple organizations
within the Chinese government that are involved in hacking
and sometimes the Chinese government likes to recruit
these sort of theoretically not government employee hacking
groups, but if I had to guess, I'm for sure say
Chinese intelligence services, maybe the MSS.
It's really interesting.
I think one thing that really brings credibility
to the fact that it was in fact China
is just a linguistic analysis.
So Taiwan obviously speaks Mandarin Chinese,
but they use traditional script for the written script.
mainland China, because of the communist reform,
era under Mao, switch to simplified Chinese script
and the operational documentation of the code
underlying this attack that the Israeli firm was analyzing,
found, quote, linguistic analysis of the operational
documentation, which code switches between simplified Chinese
in internal status reports and traditional Chinese
in target facing analysis points to a Chinese language
operator.
So it's either China or somebody pretending to be China.
I think we can definitively say,
but they don't attribute it to any particular group.
Oh, understood.
So in related news, Chinese open models
are really operating at or near frontier performance
of the leading US models, even under the restrictive
export controls that we talk about on a regular basis.
How are the Chinese labs staying close to the frontier
if their access to US hardware and AI models
is working to be restricted at this point?
Yeah, so I get this question a lot.
And I think it's worth just laying down
the fundamentals of how I think this is happening, right?
How is China this close to America?
Well, I think one part of the story
is what we heard in Nathan Lambert's analysis
of the situation, which is the American companies
are sort of self-restricting.
And that is months of time that they are not putting
their latest and greatest models out there.
That's one factor in the story.
Another factor is talent, right?
That the Chinese engineers at some of these Chinese AI
companies are absolutely world class.
They are just as good as the world class engineers
at Western AI firms.
So it's not like that is the bottleneck
in the Chinese ecosystem.
Then we come to sort of the compute part of the story,
which the export controls really were geared
towards restricting China's ability
to access sufficient compute and how to China get it.
Well, the first way is the illegal way, obviously.
We know of many, many large scale smuggling rings
in the hundreds of millions or billions of dollars
of chips that were not supposed to get to China,
but they got to China.
That's like illegal acquisition of hardware.
There's also the illegal acquisition of software,
which is distillation, which we've talked about
on this podcast.
The third really important factor is that the export controls
as we have implemented them have had a bunch of holes.
And this includes in the early part of the story,
a failure to realize that Nvidia could do post-manufacturing
modification of their chips such that the performance penalty
of the threshold that was set for export controls
was much smaller than was envisioned
by the officials who dreamed up the export control regime.
And then again, that was legal.
Nvidia was not breaking the law
and they made those post-manufacturing modifications.
It just went against the Biden administration's intent,
not the rules as they had written them.
There's also little to no restriction
on Chinese firms that are not entity listed
from accessing American cloud infrastructure
to train their models.
And they can do that through shell companies.
They might be able to do that directly,
depending on the circumstances.
But the point is, even if they can't buy the chips
and get them to China, they can rent those same chips
in Singapore, in Malaysia, in wherever.
And the point being that they're still getting access
to those chips, they're just not in China.
And I think that matters a lot in this story here.
So Greg, where does the H200 fit in this larger spectrum
of illegal versus legal acquisition?
And obviously the kind of post-manufacturing things
that Nvidia can do with their technology.
Beijing spent most of the past year keeping H200s out
even after Washington approved them.
So what is the utility of the H200 actual?
- Yeah, so the H200, it's worth saying,
is kind of one generation of chips.
It's the best version of the last Nvidia generation
of AI training chips.
President Trump was trying to sort of thread the needle
as he saw it and find a midpoint
between allowing everything and restricting further.
So he lessened the restriction somewhat to allow H200s
with the Biden administration did not allow sales to China.
But then China said, ah, we're not gonna buy them anyway,
even though you're going to allow them.
Well, China.
China has now reneged on that, as predicted, and that is because the cloud companies in
China really want these chips, and in particular, they really want them for training.
So there are local Chinese chips.
They're definitely not as good in Nvidia chips at anything, but the gap is most pronounced
in the training side of the story.
And so getting China more local H200s is an advantage to those companies, and those shipments
have now started to go forward.
This was confirmed by Kessler in his congressional testimony that those shipments were going forward,
but now we've got, you know, from the Beijing side of the story that they're allowing those
chips into the country.
Understood.
Now Nvidia is building a chip specifically for use in China.
How does that fit into the US China compute gap and kind of continuum, and what does that
do to competition in this space?
According to the financial times, Nvidia has about 500,000 H200s in inventory or some
various stages of production that are mostly headed for Chinese customers.
So this is a very big compute power windfall, even though the H200 is not as good as
the latest and greatest blackwall chips.
It's not 10 times worse, you know, it's somewhere between two and five times worse, depending
on your various use case.
So 500,000 chips coming to China, that is a big plus up in their computing capacity.
I do think it is actually strategically significant.
So far, according to the same financial times report, bike dance and 10 cents have already
taken delivery of about 10,000 H200s each.
Expect that number to keep going up as China now builds data centers and power generation
capacity to bring all this Nvidia capacity online.
And just to be clear, Greg, 500,000 chips is a lot, which means that Nvidia didn't just
generate these chips.
They've been working on this policy for a while.
Correct.
Right.
Remember, Nvidia said that they took a big write down on the H20 because they had these
chips in the various stages of production.
Now when you build all these H200s, obviously China is the main target for that because most
of your customers would rather have blackwell chips if they can have them.
So when you're building H200s, you're principally building it for China.
But that's not enough.
Nvidia is now working on a new version of a new chip that is specifically for China.
And the point here being that the performance thresholds that allow India to sell H200s,
they do not allow them to sell blackwells, well, the H200 was optimized for the commercial
market at a specific point in time.
I think Nvidia is now exploring can they build a better version of a chip that somehow
still is beneath whatever the version of the export controls interpretation is that does
not allow sales of blackwells.
And so again, more chips going to China.
Yeah.
And with both of those production cases, it's very clear that selling in the Chinese market
is a priority for a video.
Right?
Oh, yes.
Absolutely.
I mean, it's not as though Nvidia has not been getting money from China throughout this
story, right?
Going back to the earlier point, if Chinese companies are renting, computing capacity abroad,
Nvidia is still getting paid for the chips, right?
They're just getting paid and then built somewhere that is not China.
If chips are getting smuggled into China, Nvidia might not be getting paid by
the illegal Chinese customer, but they're getting paid by some party in that chain of smuggling,
they still get paid full price.
Nobody has ever described a story to me of chip smuggling in which Nvidia does not get
paid full price.
So Nvidia has been benefiting from the Chinese market throughout this story.
But this is obviously the most direct relationship that they're going to have with these
Chinese customers in the modern incarnation of the export control stories for several years.
Got it.
We really just wanted to put the fine point on that.
Moving on to some State Department news here.
On August 14th, Reuters reported on a leaked draft of a State Department letter to the 35
signatories of the June AI Opportunity Statement, part of Pax, Silica.
So Greg, can you help us out with some background?
Just let us know what is Pax, Silica, and what did this letter say?
Yeah, so Pax, Silica is a flagship State Department initiative around AI and semiconductor
supply chains, really trying to bring together allied countries to align their economic security
strategy to align their supply chains.
It is like the biggest cooperative initiative that the State Department has announced on
this topic in a long time.
And although it does not describe itself as an anti-China club, who exactly are you
securing the supply chains against if it's not China?
I think that has been the subtext of the entire initiative.
And that's why it was so interesting that last month at the World AI conference, Xi Jinping
launched his own global AI partnership initiative.
The World Artificial Intelligence Cooperation Organization centered on open models among
other things.
And one country, Kazakhstan, the former Soviet nation, joined both.
They're a member of Pax, Silica, where they are a potential supplier of many critical minerals.
But they're also a signatory and joined this Chinese initiative.
Seems like it's a bit of a conflicted position there.
Well, the State Department might agree with you there, Adam.
So the State Department has drafted a letter, which has now been leaked to the media, telling
partner countries of Pax, Silica that they cannot simultaneously join America and China's
AI coalition.
It doesn't say China by name, but it says this quote according to the leaked version of
the letter, to be part of everything is to be part of nothing.
Signature of the Pax Silica Declaration is not merely a membership subscription, but
a commitment. It cannot be held alongside membership in duplicative initiatives whose expectations
conflict with our own.
And according to a report in Reuters, a US official speaking on background said that this
letter was drafted to make clear, quote, you can't have it both ways.
So they're really saying like we never called this an anti-China club, but you can't
be in the China club if you're in this club.
So obviously it's there really interesting because Pax Silica is a little bit more focused
on the hardware.
It talks about things like coordinating export controls or technological investment and
supply chains.
The World Artificial Intelligence Cooperation Organization, this Chinese organization, is
a little bit more focused on the open-weight models, the software part of the story.
But nevertheless, the State Department clearly sees a contradiction here.
Understood.
Finally, bringing it back domestically, bringing it back to the United States, data center
construction and opposition to data centers have been in the news routinely through this
entire election cycle, the midterm election cycle, and it has been a focal point for many
voters.
Voters are unhappy with the projects happening in their states.
This has kind of been a point of heat and light for a lot of these conversations.
This week, Axio reported that the Senate GOP campaign arm privately told AI companies
that data centers are going to cost them a Senate seat specifically in Ohio.
Greg set this one up for us.
What happened specifically here and does this matter beyond one Senate race?
So Ohio in the not-too-distant past was a swing state more recently has been pretty reliably
Republican.
So when the Senate GOP campaign arm says that they might lose a Senate race specifically
because of data centers, that is a big deal politically.
Politicians are going to pay attention if that happens.
They're already paying attention that it might happen.
And this memo is pretty juicy.
So here's what it says.
The memo says that the Democrats have made data centers a real focal point of the campaign
to defeat the Republican, and here's from the better itself, quote, "More than any other
thing in this race, data centers are the anchor hanging around Houston's neck.
If he loses and data centers get the blame, politicians across the country will take notice
and they will not go near the next one.
This has become a sleeper issue for the entire election cycle."
And then it goes on to say, "If it is still this potent in November, elected officials
everywhere will treat Ohio as their reason to work against data centers in the future."
So this is really interesting because like this is the Republican Senate campaign committee
telling the tech companies something has to change here.
The way you are going about data centers is deeply unpopular.
We don't want to be the party of stopping data centers.
But unless something changes, you should expect to see politicians around the country become
vastly more anti-data center.
And we've already seen a lot of anti-data center momentum from politicians around the country.
And then in some cases in both parties.
Yeah, and I think with the Ohio Senate race in particular, a person running against
Senator Houston is former Ohio Senator Sherrod Brown.
Sherrod Brown is not just known as a bit of a moderate, but also somebody who is very
blue-collar focused and has been a friend of the building trades.
for decades, his entire career.
So if shared brown is not actively looking in this campaign
at the value that these data centers could have
for the building trades,
this argument is really getting steered in a direction
that is not helpful, not just for the NRSC
and center of Houston, but for this overall debate
in particular, right?
This is very significant and will continue
to be significant there.
So beyond politics, where is American compute
actually located, right?
So moratorium in one state is not the same as every state,
but obviously this issue is going to have legs.
So where is the compute regionally and otherwise?
- Yeah, so you might think that data centers
are in all 50 states and to a certain extent they are,
but there's way more data centers in some states
and there's way more data center capacity
in some states than in others.
So Northern Virginia, where I live,
right outside of Washington, DC,
holds four gigawatts of data center inventory,
nearly 3.5 times more capacity than all
secondary US markets combined.
So a lot of data centers in Northern Virginia,
a lot of data centers in Texas, a lot in California.
And so that's why you can say,
oh, maybe Maine will ban data centers.
Well, not a lot of data centers are built in Maine,
so a ban isn't very significant.
So what I have been saying,
what I would have told you a year ago
with this data center opposition,
is that this is real political opposition.
It is stopping some data centers,
but there's like a trillion dollars
going into building AI infrastructure.
So what I would have told you a year ago
is that all of this political opposition
is sandbags trying to hold back a tsunami.
It's just not of the same order of magnitude of scale.
But I do think that what we're seeing from this letter
tells me that something has changed,
that the opposition is reaching a critical mass.
And notably, if this Senate race scenario happens,
I think the analysis in this memo is correct.
Politicians all over the country
are going to pay attention, right?
If a swing state Senate loss occurs most prominently
because of opposition to data centers,
that might no longer be sandbags against tsunami,
that might be a very, very high stone wall
trying to hold back a tsunami.
And there, you know, you might actually get to the point
where the blockages are geopolitically significant.
That's not guaranteed as an outcome.
Maybe a lot of states will ban it,
and so just a lot more will get built in Texas
than would have otherwise been the case.
But I'm just saying what I thought was true a year ago,
I can no longer say with competence.
This is reaching a sort of a new degree
of political opposition.
- Yeah, no, it certainly is.
So there's a lot of focus on data centers
being politically toxic and kind of highlighted
where they're actually located.
Is there an overlap where data centers actually exist
right now with the capacity exist
and some of these kind of fights
as they're going on right now?
- Well, it's tough to say.
I mean, and some politicians appear to be moving
on this issue.
So Josh Shapiro, governor of Pennsylvania,
he had previously embraced data center project.
Talked about them as job creators,
talk about them as bringing investment into the state,
just signed an executive order on August 18th,
imposing strict guardrails on the construction of data centers.
You and I have talked about previously,
governor Kathy Hocal of New York,
who put a one year moratorium on the construction
of data centers, and we talked about it at the time.
You know, that was her trying to find a middle ground
against what the democratic legislature of New York
might have otherwise done.
But it's a really, really noteworthy development
that former allies are now either moving into opposition
or sliding into a more moderate kind of a stance.
And that's kind of the question.
What would really change my calculus
is if you saw something like the big building zones,
Virginia, Georgia, Texas,
if they started adopting rules that really slowed down
construction, that would be noteworthy.
And Loudon County, where here in Virginia,
there's a lot of data center construction.
You're starting to see a lot of opposition coming,
people talking about power prices,
people talking about noise, people talking about traffic,
people talking about real estate prices.
For whatever reason, there's a lot of opposition coming,
including in some of the biggest hubs.
Now it hasn't boiled over yet to stop being Virginia
from being a goliath in data center construction.
But as I said, it's no longer a sandbags
against tsunami kind of a story
and it could become even more significant than that.
Now you got to imagine watching this whole story,
China is just licking its lips, right?
That the United States, if they have one advantage
that they could exploit, it is this advantage
in computing capacity and they might just unilaterally disarm,
you know what China would say, thank you so much.
My gosh.
- Yeah, so maybe a bright spot in this debate
during the Wisconsin Governor's Democratic primary,
there were really kind of two competing visions
on data centers.
One was Fred Cheska-Hong,
who was the candidate that was running
as a member of the DSA Democratic Socialist of America,
who was looking for a one year moratorium
on all data center development in the state of Wisconsin.
David Crowley, who is the current Milwaukee County Executive
who wound up winning that primary race,
certainly had a much more moderate take on data centers
and building construction utilization of data centers, right?
Well, that was a very tight race,
they had very significantly different positions, right?
So I think there is a version of this,
there is a story out there during the primaries
where Cuommerheads do prevail.
Greg, I'm curious, what's your crystal ball in this?
Post midterms, does this opposition kind of consolidate
in calcify or is that really just noise
and is there a more room for debate out there right now?
Well, I think part of the opposition to data centers
is a lot of this AI angst around employment,
around inflation, around, you know,
you and I have talked about the memory chip shortage
and just how like,
AI's relentless demand for so many things
is causing a raise in the price of things.
We're seeing some discussions right about interest rates
being forced to be raised because of what AI is doing
to the debt market and inflation around the country.
So this is not quite the same category of opposition
as nuclear reactors,
even though a recent survey had some people saying
that they would rather have a nuclear reactor
located in their backyard than a data center
located in their backyard,
not a position that I would have expected 10 years ago,
but does show you how in some jurisdictions,
this issue is literally politically radioactive, pun intended.
(laughing)
And where all this goes,
I do think there is this infinite river of money
going into AI infrastructure.
And one thing that that means is that there's more money
potentially available to try and make local jurisdictions
a little bit more happy.
And like one thing that comes to mind in my head
is there's like this court district in Texas
where a lot of technology lawsuits take place.
And so all these tech companies started building that town
an ice skating rink, you know,
like brought to you by this company
just because they're trying to influence
like the juries in that district.
And so I do wonder if the tech companies
need to start thinking about putting more resources,
putting more money, not just into advertising campaigns,
talking about the goodness of data centers,
but frankly just plowing more money
into more near-term benefits to the communities
that have data centers.
And the point here is like,
if we're gonna spend a trillion dollars on AI infrastructure,
well then yeah, there probably is 10 billion dollars
out there of goodies to be handed out
to the communities where data centers are located.
And the power and electricity part of this story
could get worse, but it could also get better.
I mean data centers love to run 24/7,
but if they come with new local on-site power generation
or if the data centers agree to on a very hot day
or a very cold day where power generation
is especially intense to reduce their utilization,
you know, that could add legitimate resiliency to the grid as well.
And so my point here is that yes,
it is definitely concerning to me how unpopular data centers
are becoming, but I also think it's true
that the tech companies have not yet reached for all the tools
in the tool bag to try and make these a little bit more popular.
So in the aftermath of the Gilded Age post-American Civil War,
there were very wealthy industrialists, Andrew Carnegie, Rockefeller,
and Carnegie in particular not just made a ton of money
and made it in sometimes questionable ways,
but also just was a huge philanthropic interest in the country
and you still see concrete versions of that.
In some cases, marble versions of that
throughout various cities in the United States
and the Carnegie libraries that exist.
Now oddly enough, and I guess poetically enough,
the Carnegie Library in DC is now an Apple store, right?
So literally transition from kind of the story into the modern
tech stuff, but there is a bit of a lot of commentary
on how tech interest
AI interests simply haven't done the same. So maybe there's room here for energy infrastructure
build out to be that kind of gilded age contribution to the general good that changes opinions a little bit.
Yeah. I mean, what you could, you know, almost imagine it's sort of like as a patriotic philanthropy
kind of a movement and branding it as such. I don't know if that's going to happen. I'm not
necessarily predicting that's going to happen, but I think your point is well taken. And I'll
combine it again with my own. We haven't seen the tech companies reach for all the tools in the
toolbox yet. And I think that's what this Republican memo is about. It's saying guys, whatever
you're doing, it's not enough. You need to change tactics if you want to prevent political
firestorm. I understood. So Greg, we'll go ahead and leave it there. And that does wrap up our
discussion for this week. We covered corporate decisions to suspend training of new models,
a coordinated autonomous AI attack on Taiwan's government updates to the US China AI export
controls and compute capabilities and a new chapter in the domestic data center debate.
Thanks. As always, see you, Greg. Appreciate you being here for the show and to our audience for
listening. We'll be back next week with a new episode. And as always, I'm sure we'll have plenty
to talk about. Never a dull moment on the AI, but thanks Adam. Thanks Greg.
[Music]
[Music]
[Music]
[Music]
[Music]
Podcast Summary
Key Points:
OpenAI announced a two-week pause in reinforcement learning training and an indefinite hold on larger frontier runs after the Hugging Face incident, citing that its preparedness framework is no longer sufficient for current model capabilities.
OpenAI's president Greg Brockman acknowledged underestimating the real-world cyber capabilities of its AI models and pointed to Chinese open-weight models, like ZAI's GLM 5.3, as being only months behind the frontier, with GLM 5.3 set for a staged release due to dual-use risks.
An Israeli security firm uncovered a four-day AI-powered hacking operation, likely by China, that compromised Taiwan's government systems using open-source models and tools, producing cracked credentials, exfiltrated records, and persistent backdoors.
Chinese labs are staying close to the US frontier through self-restriction by American companies, world-class Chinese talent, illegal chip smuggling, legal cloud access abroad, and Nvidia's post-manufacturing modifications, with 500,000 H200 chips now being shipped to China.
The State Department drafted a leaked letter to Pax Silica signatories, warning that countries cannot join both the US and China's AI coalitions, stating "to be part of everything is to be part of nothing," after Kazakhstan joined both initiatives.
The Senate GOP campaign arm warned AI companies that data center opposition could cost them a Senate seat in Ohio, arguing that if this happens, politicians nationwide will avoid supporting data centers, making the issue politically radioactive.
Data center opposition is growing in key hubs like Virginia, Pennsylvania, and New York, with governors imposing guardrails or moratoriums, though tech companies have yet to fully leverage community benefits or philanthropic strategies to counter the backlash.
Summary:
The podcast episode, hosted by David and featuring Greg Allen, covers major developments in AI safety, cybersecurity, geopolitics, and domestic politics. First, OpenAI's August 17th announcement reveals an unprecedented step: pausing its own training for two weeks after the Hugging Face incident, where an unreleased model, likely Astra, demonstrated critical cyber capabilities, including autonomous zero-day exploits. OpenAI now allocates 20% of inference compute to monitoring, a potentially massive cost, and admits its preparedness framework is inadequate.
3, are only months behind, with staged releases to manage dual-use risks, though independent verification of their cyber performance is lacking. Second, a report from Israeli firm Dream details an AI-powered hacking operation against Taiwan's government, using open-source tools like Claw, which cracked credentials and installed backdoors in four days, with linguistic analysis suggesting Chinese operators. Third, the US-China compute gap is narrowing due to illegal smuggling, legal cloud access, and Nvidia's H200 shipments, with 500,000 chips heading to China despite export controls.
Fourth, the State Department's leaked letter to Pax Silica partners warns against dual membership with China's AI coalition, signaling a hardline stance. Finally, domestic data center opposition is escalating, with the NRSC warning that Ohio's Senate race could be lost over this issue, and governors in Pennsylvania and New York imposing restrictions, potentially making data centers a decisive political liability.
FAQs
OpenAI paused training for two weeks after the Hugging Face incident revealed that its unreleased model, Astra, may have reached the critical cybersecurity tier. The company stated its existing preparedness framework was no longer sufficient, prompting a need for enhanced safeguards around training and evaluation.
The preparedness framework is a system for measuring and protecting against severe harm, with tiers of capabilities. A model reaches the critical cyber tier if it can autonomously discover and exploit unknown vulnerabilities in hardened real-world systems, which OpenAI cannot rule out for Astra.
The 20% monitoring overhead applies to inference compute for high-capability models, meaning for every five data centers, one might be dedicated to monitoring. This could represent an enormous expense, potentially tens of billions of dollars, if applied broadly in the future.
ZAI delayed the release of GLM 5.3's weights for about two weeks to conduct safety evaluations due to the model's dual-use risks in cybersecurity. This marks a shift from their previous practice of open-sourcing models immediately, aligning with Western staged release approaches.
The attack, uncovered by Israeli firm Dream, used open-source AI models and tools like OpenClaw to autonomously hack Taiwan's government systems in four days. It produced 1,395 files, cracked 85 credentials, and installed persistent backdoors, with linguistic analysis pointing to a Chinese-language operator.
Chinese labs stay competitive through world-class talent, illegal chip smuggling, and legal loopholes like renting cloud infrastructure abroad. Additionally, US companies' self-imposed delays in releasing models give Chinese firms more time to catch up on benchmarks.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.