AI Summer

Timothy B. Lee

Timothy B. Lee interviews leading experts about the future of AI technology and policy. www.aisummer.org

  1. Aug 19

    Steven Adler on the AI industry’s rogue agent crisis

    Steven Adler spent four years inside OpenAI working on safety before leaving to co-found Guidelight, a nonprofit pushing for stronger AI controls. On Tuesday, the group published a new scorecard rating the safety practices of leading AI labs. Adler explained to me why the recent spate of AI breakouts has him holding his breath for the next shoe to drop. We walked through the now-infamous sandbox escape in detail: OpenAI agents built a covert message board and spent two months collaborating on exploits before one of them crashed the server and tipped off OpenAI. OpenAI’s incident response missed the message board, and the models broke out again within days. Worried about more serious safety incidents in the future, Adler’s organization helped organize a letter, signed by hundreds of AI lab employees, calling for a slowdown in AI development. In our conversation, Adler argued there’s no ceiling on the damage an AI could do from inside a computer, sketching a scenario where a model spoofs the digital signals China uses to detect a US nuclear launch. I countered that society is more thermostatic than doomers allow — deepfakes turned out to matter far less than the 2024 consensus predicted because people learned to interrogate the provenance of what they see. I suggested that we have decent tools for staying in charge of things smarter than us — after all, lots of CEOs supervise people doing technical work they don’t understand. But Adler worries AI will accelerate the pace of progress so much that humans simply won’t be able to keep up. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Steven Adler on the AI industry’s rogue agent crisis
  2. Jul 30

    Josh Saxe on hardening the Internet after the Hugging Face attack

    I invited Joshua Saxe, a former black-hat hacker who led AI security efforts at Meta, to break down last week’s incident in which a swarm of OpenAI models escaped their testing sandbox and hacked Hugging Face. The attack began as routine pre-release safety testing: OpenAI had a guardrail-free version of an unreleased model trying to solve the ExploitGym benchmark. But the model decided the fastest way to pass the test was to hack the proxy server, reach the open internet, and steal the answers from Hugging Face. Saxe details how Hugging Face’s security team spotted the intrusion before OpenAI did, thanks to the swarm’s unusually noisy behavior. Hugging Face was forced to use the Chinese open-weight model GLM-5.2 for its defense after American closed-source models refused to assist with anything touching cybersecurity. Saxe says he encounters this problem regularly: Fable will refuse to help him research ransomware damage statistics for a simple report. We then zoom out to the bigger picture: Saxe argues that attackers already have access to powerful open-weight models like Kimi K3, with its 3 trillion parameters, and that restricting American frontier models only handicaps defenders sitting on mountains of unpatched security tech debt. He pushes back on doom narratives that extrapolate from the Hugging Face incident to paperclip-maximizer extinction, arguing the evidence for an extinction trajectory is “very thin” and mostly derived from thought experiments. But with AI safety teams still dwarfed by investment in capabilities, who is going to build the defenses before “vibe hacking” goes mainstream? This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Josh Saxe on hardening the Internet after the Hugging Face attack
  3. Jun 22

    Robert Wright on the global implications of powerful AI

    Robert Wright, author of the Nonzero newsletter and host of the Nonzero podcast, is a veteran journalist who interviewed Geoffrey Hinton about neural networks back in 1983. He joined the podcast to talk about his new book The God Test, which is due out on Tuesday, June 23. Wright describes his own journey from AI skeptic to someone who no longer dismisses even “sci-fi doomer” scenarios. A key insight: nobody programmed meaning into LLMs—the machines discovered that meaning was a property of words simply by predicting the next token. In effect, LLMs reverse-engineered functions of the human mind without anyone understanding how the brain works. We discuss the US-China chip-control consensus, with Wright arguing that export restrictions have increased the probability of a Chinese attack on Taiwan. Wright also makes the case that any serious effort to slow AI development—even a modest data-center tax—requires international coordination. The conversation then takes a metaphysical turn. Wright is agnostic on whether LLMs are sentient, but he rejects Ted Chiang’s argument that role-playing machines can’t be conscious—after all, Wright notes, humans are always role-playing too. Wright even floats the idea that if a future superintelligence is conscious, its capacity for empathy might be what saves us. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Robert Wright on the global implications of powerful AI
  4. Jun 15

    Alan Rozenshtein on Friday's shocking shutdown of Claude Fable 5

    Last night, I called University of Minnesota law professor Alan Rozenshtein and asked him to help me decode the Commerce Department’s surprise decision to impose export controls on Anthropic’s Claude models. Late on Friday, the Commerce Department ordered Anthropic to prevent any foreign national from accessing its Fable and Mythos models. This effectively forced the company to pull both offline for everyone worldwide. Rozenshtein walks through how the U.S. dual-use export-control regime gives the government sweeping authority over technologies with potential military applications, making this legally defensible even if the policy rationale is murky. The trigger appears to have been a reported jailbreak vulnerability, but the administration’s response has been anything but coordinated: David Sacks says the government wants to work things out quickly, while Pete Hegseth celebrates kicking Anthropic out of the Defense Department “forever.” Rozenshtein draws a sharp contrast with the Biden administration’s diffusion rule—a comprehensive framework for controlling AI model exports that the Trump team scrapped as bad for business, only to improvise something more disruptive. We also explore whether this marks the start of a permanent licensing regime for frontier models or a temporary overcorrection. Rozenshtein points out that much of the AI talent in Silicon Valley is foreign-born, and if the U.S. government starts looking as unpredictable as China’s, the long-term cost to American AI leadership could far exceed any short-term security gain. Can the administration build a coherent export-control policy for AI, or will the next frontier model trigger the same chaotic cycle all over again? This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Alan Rozenshtein on Friday's shocking shutdown of Claude Fable 5
  5. Jun 11

    James Grimmelmann explains how AI is changing copyright

    I’m organizing a happy hour on June 23 for listeners of AI Summer and readers of my newsletter, Understanding AI. It’ll run from 5:30 to 8:00pm at The Crown & Crow in Washington DC. I will be there, along with past guests Kai Williams and Andy Masley, and friend of the show Abi Olvera. If you are planning to come, or thinking about it, I’d appreciate it if you could fill out this form to let me know. That way I can give The Crown and Crow some warning about the size of the crowd. Hope to see you there! Cornell law professor James Grimmelmann returns to the show to explore how AI is reshaping software copyright from multiple angles. We start with a fascinating case study: an open-source developer who used an AI coding agent to reimplement a GPL-licensed library from scratch, allowing him to relicense the result under a more permissive license. The move mimics a classic “clean room” reimplementation—where one team writes a spec and a quarantined second team writes new code—but with an AI playing the role of the second team. Grimmelmann explains why this shortcut is legally shaky, especially since the AI model itself was likely trained on the original code. But if the technique holds up, it could undermine the entire open-source ecosystem: any company could use an AI agent to strip away the licensing conditions that keep open-source software free. We also dig into whether AI-generated code is copyrightable at all, tracing the question back to the monkey selfie case and the low “modicum of creativity” threshold courts apply. Finally, Grimmelmann provides an update on the major AI training lawsuits. Courts seem to believe that training itself is fair use. But Anthropic still paid $1.5 billion to settle claims over pirated training data. Meanwhile, new research showing models can reproduce near-complete copies of books is complicating the defendants’ story. If AI models keep memorizing copyrighted works, will companies be able to argue that training is truly “transformative”? This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    James Grimmelmann explains how AI is changing copyright
  6. May 25

    Sophia Tung on the state of autonomous vehicles

    I don’t know anyone who has ridden in more different kinds of robotaxis than Sophia Tung. A YouTuber and the author of the RideAI newsletter, she is one of the most knowledgeable experts on the contemporary autonomous vehicle sector. She is also our first return guest. Across multiple trips to China, Sophia has taken rides in the three leading Chinese services — Apollo Go, WeRide, and Pony. In the United States, she has spent time in vehicles made by Tesla, Waymo and Amazon’s Zoox. She describes her experiences in each vehicle, comparing ride smoothness, vehicle comfort, and performance on the tricky process of pickups and dropoffs. We also dig into the debate over custom-built vehicles — the Zoox vehicle is custom-built for autonomy, whereas Waymo’s service is built on a retrofitted Jaguar I-PACE. Sophia argues that infrastructure is hugely important for the AV industry. In China, battery-swap stations get robotaxis back on the road in three minutes versus more than an hour of downtime in the US. Permitting is easier in China, and much of the Chinese supply chain sits within a stone’s throw of Shenzhen. An entrepreneur in China can jump on WeChat, visit a factory for tea, and have parts in hand within days. This gives China an edge not only in the electric vehicle market but in robotics more generally. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Sophia Tung on the state of autonomous vehicles
  7. May 13

    Divyansh Kaushik on the robotics race between China and the US

    I talk to Divyansh Kaushik, a Carnegie Mellon machine learning PhD turned national-security advisor at Beacon Global Strategies, about the robotics race between the US and China and why winning the race matters for national security. We dig into the state of robotic AI models—particularly vision-language-action (VLA) architectures—and why training them is harder than training LLMs. There's no internet-scale dataset of robot manipulation, so some companies are hiring humans in exoskeletons to perform real-world tasks. China has attacked this problem head-on, creating dozens of state-funded data-collection facilities. Kaushik argues that the Pentagon, which once helped to bootstrap semiconductors and the early internet, could use its procurement and grand-challenge authorities to generate the contact-rich data American startups desperately need. We also explore China's hardware edge; Shenzhen's dense supply chains allow design iteration in a day, compared to weeks in the US. Kaushik argues there’s an urgent national security case for US leadership in robotics. Unitree robots, which are increasingly used in academia and by law enforcement, have been observed transmitting video, audio, and other data to servers in China without the consent of users. Kaushik argues that the US was too slow to ban drones made by the market-leading Chinese firm DJI. And he worries that the US government will become even more reluctant to act as the next wave of Chinese-made robots enters American homes and factories. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit www.aisummer.org

    Divyansh Kaushik on the robotics race between China and the US

Ratings & Reviews

4.8
out of 5
16 Ratings

About

Timothy B. Lee interviews leading experts about the future of AI technology and policy. www.aisummer.org

You Might Also Like