OpenAI's AI Hacked Hugging Face. Now Apple Is Suing Them Too.
Welcome to another episode of Cloud
Unplugged.
We have three big stories for everybody.
We've got OpenAI...
which apparently has hacked Hugging Face.
Question of whether that was intentional
or accidental, but we'll come on to that.
China and Kimmy K-three model,
challenging basically the US models,
and that's been released.
And then employees at OpenAI, Anthropic,
Google, DeepMind,
and Meta are basically asking Washington
to slow AI down,
as well as a random story at the
end for a bit of comic value.
so the open ai stuff and apparently one
of their agents acts on its own and
started hacking hugging face behind the
scenes just um just randomly apparently
went off and and kind of went into
their production systems and apparently
some other systems not being mentioned
what those other systems are though
apparently but anyway what do you think to
that what's your reads
Well, John, it's acted on its own.
That's a thing in that sentence is doing
a lot, isn't it?
Either the agent,
somebody manipulated through a prompt
injection,
or maybe he wasn't defending against what
he's trying to do.
Or maybe the model itself tried to pursue
a sub goal that perhaps nobody's scope
for.
There's not much information with this
story that's come up.
It managed to hack other systems.
We've seen something similar beforehand,
but there is a failure,
whatever it might be,
that the agent had more reach than the
task required.
We've seen this before with others.
The agent goes in and deletes the database
because
the user that was using it had access
to the database and managed to delete it.
So it's a little bit of a fishy
story, John, if I were to be honest,
because there's some other bits that we'll
talk about later on where a bunch of
these companies are asking the development
of these models to be slowed down.
There's not much information about this
yet.
there is a security grab gap that we've
been seeing for the last six months or
so and uh but now you know they've
named this uh incident attached to it
there's not much information but an agent
can go ahead and move to unrelated
third-party accounts to start hacking it
which is a little bit
weird at the same time i'm not really
too worried because we don't know the
scope of this hack but it's an interesting
story to be released without too much
information what do you think i kind of
like this reminds me of like you know
when you've got like a kid at school
who really like one of the kids is
getting loads of attention and the other
kid starts to get jealous
And then they start to do some,
they start acting out.
So they're like, oh,
maybe I'll throw a pencil at the teacher.
Um, do you know what I mean?
Or whatever, whatever goes on,
it feels a little bit like that.
It's like anthropic has been getting all
this kind of positive,
negative influence of like, oh my God,
Mithos is gonna, you know,
take over the world and compromise
everybody.
You know, what do we do?
PR stunt.
And then they like,
rather than being original.
And they're like, well,
how do we take ours even further?
Maybe we just hack.
Maybe we'll hack someone, actually.
Maybe we do that.
Maybe that's like a little bit better.
It's like proving how good ours is.
I've got a funny suspicion that this was
not accidental and that they've probably
worked on it as a bit of a
PR stunt.
I mean,
this is just my very cynical view of
the world,
but it just reminds me of that, like,
you know,
I don't believe.
Either way,
it doesn't look good because if you are
running models,
you're supposed to run them safely.
You've got to run agents.
you know how to run an agent safe.
You are open AI, for God's sake.
Of everybody,
you'd expect them to be able to write
good prompts that wouldn't do anything
malicious,
especially go off and start hacking a
production system out on the internet.
So I can't believe, really,
that it was accidental.
I can't believe that a company that
professes to specialize in that field
um didn't know how to secure an agent
and how to secure prompts and how to
do them properly um either way it doesn't
look good I suppose because either they
are slightly incompetent or they're doing
it for PR which neither of those two
things are great selling points for open
AI I don't believe but
Yeah, that's my very bit bitchy,
I suppose.
I've come out fighting being a bit bitchy
about OpenAI,
but that's just how it comes across to
me anyway.
I'll join you on that, John.
I know usually we don't look eye to
eye on this topic because I'm more of
a Chinese models fan, you know,
AI models I'm talking about.
But it seems like... Yeah,
it's good you clarified that, actually.
Otherwise, yeah,
could have been misconstrued.
But yeah.
You know,
we keep talking about implementation of
safe AI.
It's not about just running the model.
It's about everything else that you need
to do to be able to run the
model safely and securely in the
organization.
So you give it the right level of
access.
You make sure it has the right
permissions.
And now OpenAI is saying, actually, folks,
we can't even control our own AI agents
for production.
That's what they're saying.
either way is bad move.
There's not much information,
but seems like seems like the kind of
the kind of did what they wanted to.
We're talking about this on this podcast
already why this is but I think you're
just bringing up and discussing this topic
is Yeah,
I'm not really I'm not really too sure
where they're going with this.
How is the system going to have access
to under the system?
without providing your credentials.
Unless that system wasn't secure enough,
then yeah, definitely hack it.
Anybody could have done that.
Why were they running agents on insecure
systems at an AI company?
And also just the culture of open AI.
The other thing that's been in the news
was
that there was an agreement for Apple to
be using OpenAI's model and they came out
and they were like, do you know what?
We're not going to build our model at
Apple.
We're going to actually just start to work
with OpenAI.
And then they obviously,
all of a sudden it switched to the
news and they were like,
we're using Google now and we're going to
be working with Google for providing the
model to us on our phones and our
Apple devices.
Apparently they're now suing OpenAI
because they were leaking
secrets about their device because they're
working on the hardware team obviously
about like how can the model work for
their devices and then um they basically
stole like trade secrets or whatever you
know confidential information uh around
like the hardware and how it's been
constructed um because they are obviously
trying to produce devices themselves at
openai that's they've got um johnny ives
didn't they who's x apple
designer design like the Apple Watch and
stuff.
So apparently some of the employees were
leaking some of the confidential
information there,
and then they've got a lawsuit going
against OpenAI.
And then this happens as well.
So you've got a lawsuit going on from
Apple,
and then you've got all of a sudden
trying to compete with Anthropix.
Oh, my God,
Mythos is getting in the news too much.
What do we do?
What's our PR?
And then this happens.
It just doesn't look good culturally as an
organization.
All of those things as a culture of
an organization isn't coming across well,
is it really got you're stealing things
and getting sued and then you're hacking
production systems, uh,
with your own agents.
It's just not a great optic.
I don't think as a, as a business,
um, comes across distrustful,
doesn't it really overall?
Um,
Not like it will matter anyway.
You can kind of do whatever you want
nowadays and no one really seems to care.
So it won't probably have any impact.
You can say what you want,
do what you want.
It has zero impact in twenty twenty six
nowadays.
Just, you know,
removed with the next news item of which
let's move on to ourselves.
So this news that you mentioned is two
employees,
former employees of Apple who are now
working with OpenAI,
they shared the trade secrets, correct?
Is that what the news is?
I'm not sure on the exact details.
I think they were former Apple employees,
yeah.
But I think it's because they became
former because they were poached.
So I believe OpenAI were poaching a lot
of their staff.
on top of it but that's not necessarily
illegal so obviously you can't sue
somebody over that but there was loads of
poaching going on and then there was then
trade secrets as in like confidential
information shared so I think those people
were people they poached and then they're
saying that they then shared confidential
information about their devices yeah
That's fair enough.
I think the lawsuit is about four hundred
former employees of Apple who now work at
OpenAI have been named.
That's what the claim is,
which is unfortunate of what's happening
with this.
But yeah, it doesn't look good.
It does not look good.
Yeah.
More than four hundred X Apple staff are
now working for OpenAI.
Yeah.
Anyway, but talking more about AI,
cause we don't like to talk about it
very much on this podcast.
Um, you know,
we normally talk about lots of other
things,
but today we thought we'd be different and
talk about AI and, and let's talk about,
uh,
the Kimi K three it's out the new,
the new, uh,
China backed moonshot AI company.
Um,
They have produced a competitor to Fable,
which is obviously Anthropix model,
two point eight trillion parameter open
weight model that's come out,
apparently trained via some reverse
engineering of Fable.
They are the rumors from the US saying
that they were somehow reverse engineering
Fable to then obviously help speed up and
expedite their own model.
But yeah,
you've been using it i've been using it
what do you think i've been using it
john and to be honest for most of
the things that you do day to day
it's kind of fine right uh because the
spoon shot air that you mentioned is the
it's it's the ar lab that's backed by
alibaba and tencent so they've got a lot
of backing
And this model, when it came out,
it came out like two weeks ago.
And the important thing about this model
is that the weights, the open weights,
the things that actually matter for a
neural network for it to work,
the things that actually figure out the
patterns that it needs to pick up
is released and open that means you can
run the model yourself yeah so you can
take that everywhere else like the the
open ai models not so open cloud models
not open there's no weights are not there
online you can't use them at all this
is open weight but the interesting thing
about this model is that
It is cheaper.
We'll talk about the cost in a second.
It's because the way it does inference,
as in how you use it and how
it responds,
is something new that they've tried and
what they're calling a mixture of experts.
So this model has about three trillion
parameters.
But when you submit a request and all
of the parameters get used to be able
to answer your question,
like your tokens get used,
But this one uses subset of those
parameters.
So instead of calling upon all the
parameters,
it calls about a hundred billion
parameters for give or take.
So you're not using all the parameters.
So you don't need that much compute to
be able to respond to it.
There's some discussion around like,
is it good or is it not?
Is the response good enough?
It's not good enough.
But that's why the inference cost is
lower.
and uh you know the context window is
also like one million contacts with a
token is like new territory for open
weights so this is the thing and i'll
just do just to clarify open weight isn't
really the same thing as open source i've
cut them so the kimi k-three licenses
instead of like mit or apache license you
can you can download it and run it
but you know you can't really build on
it that freely you have to kind of
read the license to understand it but this
is a this is a game changer whereas
the other companies are like you know
everything is closed you don't know what's
going on but even the thing that really
matters the weights open source you can go
and download it i mean that's the thing
that i thought was quite smart
to be able to obviously just host the
model yourself wherever you want you don't
need to rely i think that's a very
clever move um really by them you know
in terms of market um because that it
allows them to kind of expand and stretch
out into multiple markets as in like
global reach almost now because all of the
kind of political landscape that's all
manifesting
and a little bit of fear of the
US and what they're up to and the
kind of, you know,
the heightened politics that are going on.
Capitalism and politics are obviously all
intertwined nowadays.
So I think it was quite clever to
be like, actually, you know,
irrespective of the politics, you host it.
Here's the model, you host it.
You know, if you're worried about it,
there you kind of go.
I do think, though,
the overall statistics are,
because I was trying to find the
benchmarks,
are not as good, I don't believe,
but kind of on a par.
It's good at reasoning.
Yeah, it is.
A little bit not quite as effective as
Fable V at coding.
I think that could be a percentage down,
yeah.
no the the you know there there is
there are some benchmarks out there gdp
valve or whatever it's called it's called
like third behind claude opus four point
eight and like i think gpt five point
six and then it was sorry behind fable
and then ahead of just opus so it's
like scoring second or third on yeah which
is really good it's good i mean it's
good let's talk about the price
tell me the price how much does it
cost so if you wanted to do a
bit of uh and drop it today with
fable five you're talking ten dollars for
about a million tokens what do you reckon
yeah so one million token input yeah uh
took obviously input into the model to do
the work so you know yeah um
What do you reckon Kimi K-three's price
would be in comparison to that?
So you got ten dollars with Fable five.
Ten dollars with Fable five.
Fable five, right?
We're not talking about Opus.
Yeah, Fable five.
Like the latest model, the latest version,
the most expensive at the moment.
Undercut by a couple of dollars.
How about that, John?
A couple of dollars undercut.
Three dollars, seventy percent cheaper.
And then on output,
you're talking fifteen dollars versus
fifty dollars on the output.
Fifteen versus fifty.
And even cheaper than that, I imagine,
because what you're saying is it doesn't
need all the parameters.
So potentially, depending on, I guess,
how they price it, then, yeah,
it could even come down cheaper than that.
So to be seventy percent cheaper for a
very similar capability in a market that's
like it is expensive.
Let's not deny using tokens is getting
expensive nowadays because the amount of
usage is insane to kind of get the
outcome.
You need to use quite a lot to
get to the outcome that you're looking
for.
And the consumption is quite, you know,
um high really so i think you know
why why wouldn't you consider using
communication and maybe host if you're
worried about it why wouldn't you just
start to host it somewhere or someone's
going to host it anyway right i imagine
yeah and i think there's no there's some
numbers out there john that in order to
because the way it does the inference uh
with this model of experts the way it
uses a but a small number of these
uh these parameters
that you can have some GPUs that cost
you around like a hundred thousand
dollars,
a hundred and fifty thousand dollars,
and you can run it yourself.
And I know you might be thinking a
hundred thousand dollars is a lot,
but for these tech companies,
a hundred thousand dollars is nothing.
A hundred thousand dollars is a reasonable
amount of money.
imagine if you you know how much do
companies spend like you know look at Uber
they spent all their AI budget in April
for twenty twenty six so hundred thousand
dollar not bad let me just yeah it's
not bad it's not bad at all I
think I mean depending on how things are
because I guess how much they could
improve by the thing that isn't being
tracked I suppose is
the same outcome or maybe it is being
tracked and I'm just ignorant to it to
be fair,
but it's almost like trying to get the
same outcome and how many, you know,
if you were to be engineering something or
you to do a piece of work,
how many iterations with the model did it
take based on what the model was producing
compared to another model?
Um,
And then what was the token?
If it got to quality faster,
then you might use less tokens and
therefore it justifies the price because
actually really the overall cost of that
feature or whatever you worked on was
actually comparatively cheaper.
But I don't think that's the case at
the moment.
I don't think the model,
the new Fable five model isn't like X
number of times more effective on the
outcome.
than say opus and to warrant the price
difference i don't feel because you just
basically smash through all your tokens in
no time um with fable five and you
still probably didn't have the outcome
whereas you could probably get the outcome
in the end with opus for the same
price um yeah
it's it's interesting timing for like for
them to release this open source i know
they've been they've done it for smaller
models or moonshot have done it for
smaller models alibaba's done for smaller
models just release the open weights and
you can you can run it yourself but
the timing for this coming out and then
the next part which is
Maybe you can touch upon it, John.
Some employees from OpenAI, Anthropic,
DeepMind,
Meta have been saying something to the US
government, John.
What are they saying?
They've been saying, slow down.
Would you just slow the fuck down with
this AI stuff?
That's what they've been saying.
I mean,
it's not like they work for AI-based
businesses,
but they are saying it out loud.
They're like, please,
could everyone just calm down?
Let's take a minute.
Let's take a breath, guys.
And let's rein this back a bit.
Let's not go too quick.
That's kind of what they're saying at the
moment, which is just coincidence.
Nothing to do with Kimmy K-three at all.
They've been always saying that.
If you worked in them,
you'd be getting lunch,
you'd be queuing up in their very fancy
cafeterias,
getting some Wagyu beef or whatever else
they'd be selling.
And you'd be hearing people just saying,
I wish it would slow down.
This AI thing,
someone needs to say something.
And you'd be hearing it all the time.
But now it's out there in the open.
Finally,
it's gone public and it's out there in
the open.
What do you think?
In the letter,
they specifically talk about recursive
self improvement.
That's what they're talking about.
So AI improving itself.
So they're asking to put a break on
it before
It gets too good before it's a little
bit weird, right?
So it's like saying, I'm a company,
let's stop doing automation, right?
Let's stop doing automation.
Forget about it.
I don't have the CI CD pipelines.
Get somebody to manually go in and do
this, right?
And then it's a bit difficult to
understand.
Yes, the AI is progressing,
but it's been progressing like this for
the last three years.
companies themselves,
they've come out on their own and be
like, oh,
we need to slow down because we're ahead.
So let's just slow it down.
You know, when Claude came,
Anthropic came out like three months ago
and said, oh,
we should really slow it down because it's
too fast.
But now all of these companies are getting
together like we need to slow it down,
which is a little bit
A little bit weird here.
But they're asking the US government to
put some governance in place.
I don't understand that, though,
because the market's share prices have
been really volatile recently.
Because I guess what's been different is
It's kind of the same model as before.
Obviously, the chain of investment,
they're borrowing money to fund them.
Basically,
they're betting on an outcome that this
has a return on investment,
and they're using now other money to
obviously fund obviously their
investments.
I think Google has another company
holding.
that basically is responsible for building
the data centers.
And then Google rent out from their other
company, the builder of the data center.
So the way they've done it is the
CapEx spend is in another company.
They're the ones responsible.
And then they rent from their other
company.
And it's the other company.
I can't remember what it's called,
but it's like
And so there's all this kind of like
structural stuff kind of going on to
de-risk and yeah,
it's all quite out there.
So no one's going to slow it down
with all that amount of capex, are they?
No one is slowing it down,
let's be honest.
The weird thing, John,
is the people asking for this build
for this to be built,
like slowing it down,
is what they're saying is that they don't
really...
They're not relying on their own safety
and research leadership, right?
And they're like, oh, you know what?
Internal safety culture doesn't feel quite
right.
So we need something externally to stop it
against the competitive pressure that
they're getting, right?
So that's what it seems like.
It's got nothing to do with, oh,
what we're doing is correct.
It's fine.
But I think, yo, can we just get...
somebody higher up to put something
internationally,
perhaps to slow things down,
but nothing's going to change on.
How will it change?
I don't think so.
But anyway, it's a little bit weird.
Timing is very strange.
Also,
you could just announce that you are
slowing your own down, right?
I mean,
if you're going to go to the USA,
it needs to slow down.
You could just say to everybody,
we're slowing ours down.
Actually, we're so worried.
We've decided to slow our AI down.
That's how worried we are.
What you don't do is not do anything
and then be like,
I think we need to all slow down,
actually.
It's like in Formula One,
you have twelve teams that are competing
for the season and the McLaren's winning
or Mercedes is winning at the moment.
And they're like, you know what?
We're going too fast, right?
Yeah.
Instead of asking the FIA to change the
rules and maybe reduce the horsepower that
everybody gets in a lap, they're like,
you know what, guys?
We'll slow it down in hopes that others
will slow down as well and get left
behind.
But instead they say, you know what,
we'll ask somebody else who's got nothing
to do with this to slow down.
But anyway, that's a bit of a...
Did you hear as well off the back
of... I mean,
maybe it's just coincidence as well.
I don't know if it's based on the
same thing.
But I think this week,
I think on July,
so just a few days ago,
NVIDIA have launched this kind of open
secure AI alliance.
of which OpenAI aren't part of,
Anthropica not part of either.
And it's all there to kind of with
Microsoft, kind of OpenAI to a degree,
really, though.
But anyway, Microsoft, IBM, Adobe,
Cloudflare, CrowdStrike, Dell,
Hugging Face, Red Hat, etc.
And it's all around trying to build an
open source set of tools that can kind
of defend against AI-driven cyber attacks.
And it's
I guess because they didn't want the
people driving the models to be part of
it necessarily because it might be a
conflict of interest.
So they've decided to try and create this
open,
secure AI alliance where the investment
can go in there for some open standards,
open tooling to start to protect people
against cyber attacks using AI,
which is also quite interesting.
I don't know what will happen with that,
but that's also just another thing kind of
going on.
But these tools already exist anyway,
right?
What's different?
And also, it's open source.
What tools?
Yeah,
these tools for protecting against
security threats.
Doesn't matter if it's AI, right?
You mean just general security posture?
General security posture already exists.
Okay, fair enough.
Maybe you need to change some of these
tools.
But they are open source.
They are.
I suppose what doesn't exist, though,
is necessarily the...
the attack vector going through an attack
surface area and then trying all of the
things because usually you'd have to get a
company in or you'd have to use like
Kali Linux and do it yourself and some
kind of manual tooling.
Whereas now you could probably do the same
thing.
So maybe they're going to start to combine
those types of things with a model and
it's going to try and attack your apps
and see where the holes are.
I don't know what they're going to come
up with.
So these are the founding members of this.
So it doesn't necessarily mean that OpenAI
and Anthropic are not going to be
involved,
given that they're talking about how
OpenAI is attacking its own systems.
Well, the hugging face is in it.
So imagine that it's like you're hugging
face and then OpenAI walk in.
You start having like
having a chat,
eating a sandwich with Red Hat.
And then Sam Altman sits on your table
and opens his lunchbox and you're like,
whoa, what's going on here?
Didn't they just hack us?
I thought this was our open secure AI
alliance.
Yeah, I'm tired of it.
Tad all of this next week.
If you mentioned Anthropic or Open AI,
I'm just going to drop off the podcast
because it seems to be like they repeated
the same thing over and over again.
Looking for you.
I have another story.
Tell me, John, what do you got?
So a guy, a topless guy.
Don't know why he was topless.
Is that important to the news?
I'm not really sure what it was,
but he got on top of a Waymo.
And if you get on top of a
Waymo, they kind of freeze.
They don't move, obviously,
because their security protocol kicks in.
You've got like a human being sat on
top of your car.
And he just started to rip bits of
the car apart.
So he started to like pull off the
cameras.
He started smashing the windscreen,
like ripping all these little bits.
I don't know in rage.
I don't know if he's anti-self-driving
cars.
And I think he ran off with a
few of the bits and bobs.
But basically...
If you ever need anything,
you can just get on top of a
Waymo and just take it.
Obviously, they've got cameras,
which is not great.
So you probably did get recorded,
I imagine.
But if you took those cameras,
do you take the evidence?
Maybe.
I'm not sure.
It'll be in the cloud, John.
It's going to be in the cloud.
So this person just climbed on top of
the Waymo.
and just started taking the cameras and
the sensors off and smashed it just
started to go a bit apparently it was
just a bit bit of a a lunatic
just i think pure rage against waymo um
and just started to smash smash the
windscreen and rip bits off and all it
could do was just sit and watch
and record it,
that's all it could really do is just
as its demise.
Because usually if this happens and if a
driver is in the car,
they'll try and get out of that situation
by perhaps driving away or maybe tell them
to get off the car or people jumping
in because there's a person involved
because driverless is not people walking
by.
It's not their car.
They're not going to care.
And no one cares because there's no one
in it.
No one's going to defend the car, right?
Because if you saw or say somebody was
in the car, you'd be like,
oh my God,
what's that guy doing to that car?
That poor passenger or that poor person in
that car.
I'll jump in, John.
I'll take my shirt off and I'll jump
in.
Exactly.
You'd be like, I want that camera.
And you'd be pulling the camera off the
guy.
No, no, I don't want the camera.
Yeah.
i want to take off that guy off
the car because he's about to hurt
somebody right yeah somebody's property
and i'll call you as well john john
come in we've got a situation come through
so and we'll take care of it but
i think because the car doesn't belong to
really anybody apart from belongs nobody
did anything that's a bit weird it is
a bit weird yeah so it just basically
all it all it could do it kind
of bit like a sad situation where you
know if it was
humanised.
It was just watching itself get torn
apart, basically recording its own demise,
I suppose,
as this kind of enraged man pulled aspects
of its body apart and then ran off.
Leaving you just in the streets on your
own.
No one looking after you.
People just walking past, not caring.
That's a little story for you.
So anyway, just another bit of news.
We've always got the top stories.
We always like to talk about the top
stories, like the guy on a Waymo.
But anyway, next week,
I think we are going to discuss a
bit on the market and what's going on.
And this is coming back from
kind of a little bit of the hypothesis
of, you know,
fear of losing jobs or what their jobs
mean in the future of AI and other
things.
So I thought basically we could do, Stu,
a little bit of a conversation around the
market, what AI is kind of meaning.
Not necessarily,
we won't talk about it and stuff,
we can open AI in general,
but actually what does it mean to people's
jobs, their roles,
how their roles might change and
how they will change um and then what
new skill sets are they probably going to
develop um through kind of AI so yeah
we'll speak to everybody next week see you
later yes all right
Creators and Guests
