Searchable transcript of AI Security Costs Rise: Cost of a Data Breach Report & Claude Opus 5 — IBM Technology (37:37). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:01 Putting together an AI attack is becoming increasingly cheaper, more cost effective and thus more profitable. All that and more on today's Mixture of Experts. I'm Tim Hwang and welcome to Mixture of Experts. Each week, Emily brings together some of the leading minds in artificial intelligence to banter through the ever packed week's news. On this week's episode, we've got Kush Varshney, IBM fellow Nathalie Baracaldo, senior research scientist, the master inventor, and Mihai Criveti, distinguished engineer.
00:32 Chief architect, watsonx Orchestrate. Welcome to you all. And Natalie, welcome back to the show. I know it's been a minute. We're going to cover four big stories today. We're going to talk a little bit about Claude Opus 5. We'll talk a little bit about this interesting story by David Zacks on what AI might look like. And finally, there's a bunch of chatter online about Midjourney acquiring CoStar.
00:51 But first I want to start because it is the annual release of the IBM Cost of a Data Breach report. There's a bunch to go into here. But, Natalie, one of the reasons we're having you on the show is basically that, you're well positioned to talk about it. What caught your eye on this year's report? Well, a couple of things that the report was really, really interested in covered the entire cybersecurity space for those of you that are not familiar.
01:18 So they analyzed from ransomware, a little bit of, all the types of attacks that happen when you don't have your data encrypted, but your address really, really special is that it was dominated by AI. So I think this, was the very first report where every single section had mention in some form or another AI. What is really interesting is that people are starting really to utilize AI for threat hunting.
01:52 But there's not a lot of investment in the side of prevention. And that is, I think, very, very interesting. They also, survey everybody to see if they are planning to increase the amount of money they are going to spend in the future to prevent the vulnerabilities. And it turns out that prior to those new models that are basically frontier, are helping find vulnerabilities.
02:19 People had, read of less, intention to invest in cybersecurity. And now with these huge, huge news and these increasing capability, what you are really seeing is an increase on, the investment intention. And so hopefully it would not only go to threat hunting, but also to prevention, because at the end of the day, that's the root. There's a lot of Yeah, that's a good sign.
02:46 I mean, I think, it's, it's it takes a while to catch up. It seems like. So the, the increase that I, that we saw was from 64% to 85% investments. So that substantial amount of money that people are, thinking on increasing their investments. Another interesting thing, and this is because I have been working so much in AI safety and security, is that when they evaluate AI vulnerabilities, we have, the following very top two data release.
03:19 One is inversion where model inversion. For those of you that are not really, kind of, familiar with that, it's, the fact when a model or an attacker tries to use a model to get to the training data. And so this was around 6 to $7 million incidents in. And that's a lot of money. When I was starting to working AI privacy and we were kind of, thinking about this threat, it seemed like a super far away situation.
03:54 And now we're seeing $6 million figure to one of these attacks. The second type of attack that we saw was prompt injection. And, that was $4.89. And basically, what it does is, prompt injection is people manipulate or adversaries manipulate the prompts to tweak the model. And because these models are really stochastic, they tend to kind of change their answer and do nefarious things, especially when we have multi-agent.
04:28 So those that I guess, where where some of the highlights, did anything does anything like that I mentioned ring a bell or seems interesting. Yeah. No, I think it's all really, really interesting. I mean, I think one of the questions that I had is, you know, I think it's not just AI is dominating, you know, the attack surface here, but it also kind of feels like the nature of the security threats that AI is presenting is itself changing as well.
04:56 You know, I think just a little bit there's a lot of discussion about, you know, this sort of a vulnerability that got discovered. You know, it seems like almost the discourse is moving from, well, AI, you know, it just does the same old attacks but better like faster, to like, actually creating novel classes, a problem that we need to deal with. Is that where you see things going?
05:15 I see it as an economic problem. It's an economic challenge. I think AI is creating an asymmetric cost structure where putting together an AI attack is becoming increasingly cheaper, more cost effective, and thus more profitable. Attackers don't need to have the best hackers, they just need to have a model without the right guardrails in place, and they only need to succeed once, while defenders need to hire the best practitioners more practitioners, and they need to use the best models with no guardrails.
05:48 And we've even seen this recently in the, I would say, incident between OpenAI and Hugging Face when there was an attack on their infrastructure, they couldn't use a frontier model from the established vendors they had to go to. I think it was Qwen or something like that, because they didn't have guardrails to help them patch their infrastructure. So while attackers only need to have one model which doesn't have guardrails that they can use in an effective way, defenders are stuck behind, you know, corporate
06:22 approved spending cost and guardrails and models which keep degrading you because they think you are the attacker. So to me, it almost seems like tokenomics and guardrails are affecting defenders more than they are attackers. Kush, this report in some ways is making me a little bit nervous. You know, I think like, and Nathalie, like last year, it was a little bit like, well, we weren't investing in security.
06:50 And now it seems like we are investing more and more in security. But the question is almost like to me has Mihai's point like, can we invest faster in this? If you had to predict, I guess for a cost of a data breach, 2027, you know, do you think those costs are going to be going up over time, or what is the kind of overstay to play, you think, in terms of where this is all going?
07:07 Yeah, I think, you have posed it very well in terms of the economics of it. So, I think the investment on the defender side, needs to keep increasing, but also in a particular way, which is that, the open, open weight model sort of way and I think this week's collapse, that was last week's news, right? That, OpenAI Hugging Face sort of thing. And this week it's all been about the open weight versus closed weight.
07:37 And, everyone's kind of using the same evidence, and some people are saying, oh, this is evidence that, yes, we should do more open weight models. And then there's these other people saying this is what happened. No, it's about closed too. So. Exactly. Right. So like when it's all about I mean the same exact incidents or I mean whatever, and both sides are taking this as proof that we need to go this way or that way.
08:03 I think it stops being a technical sort of problem. It's really a business problem. What's the business model? How are things going to play out economically as Mihai? I so. Yeah. And I think the Hugging Face example, if we can just sit on it for a moment, is really strange in some ways. Because it gets me how the way you put it was. Well, you know, if you're going to pull this off, you don't need hackers anymore.
08:24 You just need a good enough model. I mean, the Hugging Face example, it almost suggests that you may not even be an attacker intentionally. And you might create, you know, all of this unintentional hacking activity, I guess Mihai. What do you think is this, is that really, like an edge case? We're not going to see, like, you know, sort of people running cyber evals causing, you know, AI sort out of the lab and attack people.
08:45 You know, it almost feels like there's going to be traditional malicious actors that are motivated by, say, money, right? Economics of it. And then I wonder if there's going to be a whole class of attack, which is just like unintentional agents running around. I don't know. Natalie. What do you think? Yeah. So there are two aspects to it. The first part is there are always going to be adversaries.
09:06 We know these for sure. Just the report that we were discussing, 55% of the, incidents reported were from attackers, malicious actors. Now, it's an interesting aspect of using AI and using these large language models is that they are subject to what we called regular hacking. And that's exactly what happened in Hugging Face. So in in their situation, OpenAI was trying to basically run a testbed of, of things.
09:39 And then the model decided it really, really, really needed to complete that test. And so, Hugging Face seems to have the key answers. Let's just go and get them regular hacking. It did get the answers, but not the way the evaluators were intending. And so if you think about our normal agents and our everyday operations, they are given things that are or tasks that are really beneficial.
10:06 But there is always a chance to have something that goes wrong just because the models are stochastic. And now to me, what this highlights is the necessity. I don't see in that report that we're discussing the necessity to just cover the gaps that companies have would actually reduce the amount of successful incidents. Once we have agents, because, for example, if people have encrypted data, the agent is less likely, even if it's under a reward.
10:38 Hacking situation, to get that data out and exfiltrate the data. For example, if, we don't have like the basic, identity management. And so forth, we are not going to be able to cover that sort of use case or right now it's kind of a use case, like because we we need to treat these agents as a first class citizen right now. And I think, surrounding them with, guardrails not only from the machine learning perspective, but having identity management proper access control and so forth.
11:09 Encryption at rest and, it's going to be incredibly important to really reduce the number of incidents. Well, we'll definitely check in on the cost of a data breach 2027. Maybe we'll go around and do a quick vote. I mean, I guess, if you had to guess for 2027, if the cost of a data breach is going to be higher or lower. I'm kind of curious about what you what you think, I guess.
11:28 Kush, do you want to make a prediction first? I think the cost of doing the breach will be lower, but the costs incurred by having the breach will be higher. A nuanced and good answer, Mihai. I guess you agree as well. I agree with that. Yeah. And Natalie as well. Yes. All right. I don't think there's another option. Yeah, exactly. Well, your predictions are locked.
11:49 Well, we'll check in next year and see where everybody's at. Well, great. I'm going to pull into our next topic of the day. After all of the, stress and drama and conversation about Opus 5, Claude Opus 5 is out. And, in some ways, I feel like this might be the bigger story is kind of my prediction is, you know, it turns out that Opus is a really expensive model to use.
12:21 And so in some ways, it may turn out that the release of Sonnet is, is a much bigger deal. And so I guess maybe, I mean, I'll turn it to you. Anything new that you're seeing in this release? Is this more of the same? You know, this is the always the question is kind of like, are we just having another model release? You know, are the benchmarks just state of the art?
12:40 Again, curious about what you point our listeners to? I think I'm on the record on Mixture of Experts saying almost every single time, I love Claude Code and I love Opus as my model. I've kind of shifted from that opinion between Opus, 4.7 and 4.8. I didn't like them as much as I like the model from OpenAI, especially as those harnesses evolved. I think with Opus, I've seen a return to the glory days of Anthropic.
13:08 Opus is an amazing model. I love it. It's extremely effective at what it does. It follows instructions very well. The only time it doesn't do what they want is when it finds a bug. It tries to fix it. Then goes, oh, you've been downgraded to Opus. I believe you're trying to hack something. It's like, no, no, no, that's a bug you found. You're trying to fix it.
13:31 So the guardrails did get in the way. But that was a great model. I did find an interesting bug when I was using Opus, which was that it was telling you the cost of inference. Even on a max subscription. So within two hours, that number shot up to about $5,000 for me. And I was like, okay, I might have that, are you guys going to tell me what's going on here?
13:55 Right? Turns out it was a bug. But it kind of scared me because I boiled it down to about 100 bucks a question. What is your question on this large codebase? So it was a very effective model. It was a great model, but an expensive model with Opus 5. I think the intent was to give you similar capabilities, but at a much lower cost. I haven't seen it.
14:18 So in my experience, Opus 5 performs worse than 4.8. For me, it's ignoring my instructions. It's ignoring my agents, and it's contradicting itself. And if I ask it five times in a row. Go fix this issue is going to try to fix it. It says it's fixed. I say go fix it is going to find five more bugs, five more bugs, five more bugs. I didn't have the same experience that I'm getting out of Opus.
14:45 So I think while the model might be okay, the harness, the prompt Claude Code itself hasn't yet caught up. Or maybe the prompting techniques haven't yet caught up to be able to use Opus 5 just as effectively as I was using 4.8, or as people are using Opus. So right now I'm still spending the vast majority of my tokens on that weekly allowance of, of Opus.
15:12 Yeah. The kind of, adjustments I think that people are going to make are pretty interesting here, particularly just because, like Opus is so, so intense in terms of usage and cost. There's a couple of ways you can go, but maybe Kush. First, we can kind of maybe touch on like Mihai's point about sort of the security aspects of this, I have a couple friends who work in biosecurity and they're like, I can't use any Anthropic product for anything, because even if you mentioned, like, what is DNA?
15:36 And sometimes you'll get freaked out and shut you down, you know, I wonder, I guess maybe you could. The question just to turn into a question is whether or not you think Anthropic will be able to kind of sustain those types of restrictions for long on their products? Because it feels like the pressure to use it for completely non-threatening, innocuous cases is so great that, like, eventually they're going to have to let up a little bit on their security classifiers.
15:58 But I don't know how you think about that. Yeah, I think it's actually more of a system level thing. So Mihai was just mentioning this, right. There's the harness around it and the model and both have to work in concert with each other. And, many of the, these sort of guardrail things are getting triggered at the harness level. So it's, the model, but also the harness together.
16:15 And. Yeah, I think both can be updated. I think understanding the user and their intent, is something that needs to happen a bit more and maybe that doesn't happen at the model level, but, at the wrapper around the model. So I think we'll, we'll see things. I mean, eventually, things have to be more like, personalized to you to to your needs. And I think we'll we'll get there in some fashion.
16:46 Yeah. I was thinking, one of the main focus I have currently is actually policy driven approaches for AI. And your question Tim seems very related to that in that your friend probably has a legitimate use case where the policy. As far as I know, I yeah, I. Will believe that for the time being. Yeah. Sorry. Go ahead. Exactly. Yeah. And so the idea of having a very, tailored policy means that now we have use cases that may require slightly different alignment.
17:25 And so I think as we progress in the usage of this model, we are going to head to a point where every legitimate application should have their own policy of what's acceptable and unacceptable, basically. And because we answer and more or less tailored to that particular, policy that you define, in which case talking about DNA is, okay, we are just working on this.
17:51 This is our company that does this XYZ. So we should have a policy that is tailored to that. And so I think it's it goes back to those, do we have open source models that potentially would allow you to use really, really your own policy if you're deployed correctly? That would be, a much more flexible approach than having a generic policy for everybody.
18:18 I think that to me personally boils down to that. Yeah. And also, I think, tying it to the project itself, like I started a project with Claude with Opus. Opus worked on it for, you know, half of my token, limit at some point to discover some bugs. You tried to fix the bugs and hit the guardrails. Oh, looks like you're trying to hack yourself. I'm going to downgrade you to Opus like first the logic in that.
18:44 Shouldn't it be aware that this was a project that I've built locally? It's trying to do penetration testing against the project itself, to harden it or to improve its security posture. And it keeps downgrading me back to Opus. And now I've got anxiety. If I ask you to go fix the security issue, will it downgrade further? Would they lock me out of my, Anthropic account?
19:11 What's going to happen? Right. And I think it's that level of maybe identifying permitted use cases for projects that have been started or are running locally, that there is clearly no, you know, malicious intent, need to be made available to defenders because otherwise we're going to have hundreds of thousands of software projects that were written with AI that have never been security hardened, because you're not allowed to use the powerful models while the attackers are still going to use, you know, other models
19:42 without those guardrails to generate attacks. Yeah. No, there was, just reaction to what Natalie and Mihai just said. Right. So I think there's the policy itself, which can be customized, but it's also the threshold at which things could trigger. Right. So, just by setting thresholds appropriately, you can go into more of a precautionary sort of mode, more of a dauntless sort of mode.
20:06 And, I think even just that little bit of control can, can make a huge difference. So, you can have more hallucinations by the nature of setting thresholds properly or not. And, kind of trigger things, not trigger them. So it doesn't even have to be very complicated. It can just be like in the harness, like one little ability to have one slider. So yeah.
20:29 Yeah. Kush, the question I had for you is a little bit broader, you know, on this kind of paradigm where, you know, I wonder whether or not the days of you being able to explicitly select your model is only going to be like a temporary thing, because I feel like, safety aside, right, obviously. And topics of, well, of safety. That's right. We're not going to give you the fancy model, but I can imagine a future where you know, a frontier model company basically says, well, we just want to save costs for you.
20:56 We want to use you wouldn't want the product to be as efficient for you as possible. So in a kind of nontransparent way, we're going to switch the models depending on what you think the problem is. You know, on one hand, I think the argument as well that is more efficient, that's actually the better way of doing it. On the other hand, you know, someone who loves that little slider and can like be like, we're going to ultra code mode or whatever.
21:16 It feels like they're taking a little bit of kind of my agency away in doing that. And so just wanted to ask you, as someone who kind of thinks about the ethics of these technologies, you know, if you think one is one paradigm is going to win over the other. Yeah. I mean, I've never driven a stick shift car, and I'm happy with that feel of that. So, yeah, sometimes, like for most users, it's perfectly fine to, to have that hidden away and, yeah, there's going to be power users that do want that, that have strict
21:43 control. I mean, if you're, but that race car driver or whatever sort of thing, but, yeah, I think for the general public, it's the right thing to do is to, to kind of capture that into some automatic orchestrator sort of thing. So, yeah, that's where we're we are at it. And it's not just the cost to the user, it's the cost to the planet, and it's still cost to, to the provider.
22:10 I mean, in all respects, it's good to try to get that right balance. It's a great response. I have to bring up that stick shift example. It's a really good one. Mihai, it looks like you might have one final comment. On this one. How do you know that's not already happening? You just don't know about it. Like, you know. Now you're making me. Maybe they are.
22:28 Yeah. It's true. Downgrading your model to a different model. Maybe the performance changes. Maybe models are composite models behind the scenes. As long as models are hidden behind the proprietary API, you really have no idea what's going on. Yeah. I mean, you're making me a little bit paranoid as we move to the next topic. So the next story I want to cover, was a really nice blog post that came out from David Zacks on the IBM blog entitled What Does AI Look Like?
23:00 And, this is actually a really fun piece, because it's all about kind of trying to explain what's going on when AI does what AI does. And I actually wanted to kind of put this in a little bit of a historical perspective. You know, I remember the day when, you know, when asked by a reporter or something like, how does AI work? You'd be like, no one really knows is like a mysterious thing.
23:21 And then eventually I think the story became like, oh, well, it's like pattern matching or it's like, you know, token prediction. It's just the next word. You know, that's that's kind of how. But even then I think, you know, both of these approaches were a little bad, right? Like the black box approach. People were like, I don't even know what to make of that.
23:35 It's like, how does it no one knows how it works. On the other hand, you know, just mere token prediction probably gave people too much of, kind of pessimistic sort of view of the technology because it turns out that token prediction really could do quite a lot. And obviously, you know, the technology is pretty far from just token prediction nowadays.
23:56 You know, I guess I want to start I'm curious, Natalie, what you thought of the blog post, but also, I mean, I think when you get questions from families and friends being like, so what's actually going on? Like when an LLM is there, I'm chatting with a chatbot. I'm curious about how you explain it like what's what's the kind of easy to understand layman's terms, because I feel like everybody's come up with their own story.
24:16 Yeah. So I actually do have one slide where I have, the example of it's raining cats then. And then the LLM predicts something like lamps. That's not correct. So you kind of have to iterate. And we have an optimization process until like, it's raining cats and salt. Not really, not really. Not that until basically all the parameters and the optimization on it trains to cats and dogs and then like the LLM gets this prize and that's how it learns.
24:52 Now imagine the amount of data that we actually are feeding into these systems. It's basically like training them in superpowers with all the data sets that we have out there curated, because, a lot of people think is just data from the internet randomly, but there's a lot of curation process that goes before we actually train these models. So to me, it's like we are training our models and these LLMs are just finding patterns.
25:22 So before even they were called LLMs, we were trying to understand each of the components and how they were learning. There's a lot of things related to mechanistic interpretability, that, which probably can tell us a lot about, but basically we have been poking these little, models that are no longer that little and finding patterns in things like activations and try to modify the activations, and I think is just as the models grow bigger and bigger, it becomes a little bit more difficult to use some of these,
25:56 techniques because the parameters are just too large. So to me, there's no really magic behind. And it has never felt like, we don't fully understand. We kind of have certain senses, like some, some sense of what's happening. And so parts lighten up more than others, just because those were the patterns that were learned based on all the documents. So, I'm amazed.
26:25 The other day I was thinking about this, like ten years back, I had this paper on activations tuning for, very tiny data sets and then some up to today, folks are still doing activations tuning to, for example, prevent sycophantic behavior. Very different models. The thing is still is working. So I don't fully believe it's black box. And that's also part of the reason it's very beneficial to have your model there and be able to inspect it as the inference is taking place.
27:01 So that's super long answer. That's great. Yeah. No, no, I mean I feel like everybody's kind of got their own way, like to kind of stick go through all the steps. Kush, I know you were actually you were interviewed for this article. And so, yeah, same question in some ways, like kind of how do you think about explaining some of this stuff? But, it sounds like you, you work with them quite a bit on like how to kind of very, you know, give a kind of user friendly explanation.
27:25 Yeah, I know David, has done a really good job in this article and, yeah, I think the ambition, I wouldn't call it a blog post. I mean, it truly is, so a masterpiece in a way. And, yeah, I think the ambition that David had was, to look just like, Carl Sagan did Cosmos and stuff, like, appeal to my parents generation, to my kids generation and to my generation in the sense that it's, kind of.
27:51 Yeah. I mean, really describing what the inner workings are in a way that, people can relate to. And, yeah, I mean, he uses spreadsheets, dictionaries. I mean, all these sort of things that, we've interacted with to, to make this concept clear and growing things, I mean, all of that sort of stuff. And, the thing that I like is that. Yeah, I mean, it's like, very relatable.
28:18 And then the other thing that I kind of wanted to point out is that, it's interesting that he goes and like, tries to make things, like, less magical in a sense by appealing to this, like, ordered, structured sort of, way of looking at things. But in fact, the technology itself is not that, the emergent behavior of it, the complexity of it goes beyond that, the structure of those, kind of the spreadsheets inside is high as it is, so it's kind of like balancing what we're comfortable with to say.
28:53 Yes, it's, something we know and we can control and we can do well. But there's also like the the wildness to it that, is true, but it's like, kind of not in the, the way it's put together. So it's like all sorts of balances that he puts in. Yeah. One of the things I love is basically like kind of the explanation of like imagine like lots and lots of spreadsheets, you know, in some ways it's like this great way of sort of like making it as kind of near down to earth as possible.
29:24 Yeah. Maybe a final question for you on this is, you know, after all this explanation, you know, do you think sort of future generations will sort of say, like actually, you know, neural nets are not that mysterious. Like, we will kind of, like, ultimately crack a lot of these interpretability problems. We really, really understand the emergent, you know, parts of this.
29:42 And so, you know, at the end of the day, you know, this is just technology we're still figuring out, but we will eventually crack it. Or do you think like there actually is some complexity here that is just like will be persistently weird and difficult. I think the whole history of computing is basically the history of abstraction. And if you look at the way we used to program computers, you know, binary and assembly language and then, you know, higher level languages with compilers, things like C, for example, and
30:06 then interpreter languages like Python and Java. And then we have frameworks and libraries on top. And even when it comes to managing servers you'd, you know, SSH into a machine and type the right commands one by one and script things. And now you describe the environment and end state you want in a declarative language like, you know, HCL, like Terraform.
30:26 So everything is building upon abstraction, upon abstraction, upon abstraction. You don't need to understand the layer below to be very effective at what you do above. So I think new generations of software developers are just going to use, you know, higher level abstractions, you know, language description architectures as opposed to code to describe what they're trying to achieve, the intent, the outcome, as opposed to the steps in how to perform that work.
30:55 So I think from the perspective will be fine. There will still be a number of individuals that need to understand the complexity of individual bits and bobs and parts to optimize them. But now with the AI that is becoming increasingly more and more outsourced to the point where you're going to have AI writing AI, not sure if that's a good thing, as we are outsourcing a lot of our thinking.
31:18 But I think in terms of newer generations, I don't have a concern. Right? They will just adopt this new level of abstraction where they describe the goal they want to achieve, as opposed to the steps that need to be taken. Well, I highly recommend it. So it's on the IBM blog. It's called What Does AI Look Like by David Zacks? And, yeah, Kush is right.
31:38 I mean, I'm sort of underselling it by calling it a blog post. It's just actually like it's almost quite literary in its quality. So I highly recommend everybody here. Check it out. Well, great. I think final story today I want to end on is just a little kind of fun thing. The past my social media feed, Midjourney, most known for its kind of AI art and sort of generation, generated art apps, announced this very interesting acquisition where they acquired an app called CoStar, which is, not really an AI app so much as
32:11 an astrology app. And that, in fact, the sort of CEO of that company is now going to serve as the chief design officer at Midjourney. This comes on the back of Midjourney. Also talking about the fact that they were, you know, working on a full body scanner, like a kind of an MRI style device. So there's lots of strange kind of odd things going on at Midjourney.
32:33 And. I guess Natalie. I'll start with you is, if you were the CEO of Midjourney, why? Why buy an astrology app. If they have a good user base? It's a head start. Then you have, I, I guess that's my only thing. The other thing is, if you read the blog post of the hired person, she goes ahead and, talks about the great relationship. And I feel strongly that when working with people you like, it's very important.
33:00 Because it makes things easier if you're aligned on what things you think are important and so forth. So I think there's a component of, there may be a good user base. I had not heard about that type of app before, but some people may be using it and, it may have, a very interesting, appealing, I don't know if anyone here has tried that app before. Anyone.
33:25 I downloaded and tried it, actually, I think this. Is. Like. Yeah. And I was like, actually. I was like, there is an AI application here. You know, I feel like in some ways people, for astrology, they want they want the story. Right. And so, you know, the idea of AI as a storyteller in that space is is potentially pretty interesting. I guess Mihai, I'll turn to you because, I don't know if you'll make it into the edit, but I saw you give a big shrug when I was introducing this story.
33:49 Are you are you baffled, or do you feel like there's some 4D dimensional chess going on here? I think it's a brilliant move. I mean, I can't think of a better user base when it comes to not objecting to hallucinations, not objecting, to content, which is inaccurate. So from that perspective, I think it's a brilliant move. All joking aside, I'm sure there's a business reason for it.
34:13 Right? And I'm sure that the AI can help generate very creative fictional stories and, that kind of things. But, that's the only thing I'll say. Yeah. Great. Kush, the final word is to you. Sure. Yeah. I mean, when I first saw it, on our roster of, stories, I was like, is this, jumped the shark moment or Pets.com moment or whatever, but, yeah, it was.
34:39 I was like, actually digging in. I think there is a business case, and, this is my, understanding my version of it. So, astrology app gets you into a kind of a ritual. It's a rhythm. Like you're checking every morning. You're making it part of your your daily life. And, I think that's what, AI doesn't have yet in most cases. Right. So when you go to, one of these, chatbots or coding agents, it's something that you're doing actively, separately from your own sort of life.
35:13 And so I think the plan maybe is to, kind of make AI more of this extended mind sort of thing. So it's like with you all the time, it's, frictionless and so forth. And I think that's where, where they must be heading. And this collaborator of mine, Mariano Sigman to finish, he talks about system zero as like the thing that AI will do for us, and it'll become like, just us with that extension.
35:44 And, I think the design, all of that gets us there. And the risk is, though. I mean, like, when it's too much of an extended mind, you, I mean, you can kind of colonize our minds, that sort of thing. But, maybe that's what what their goal is. This is a much more optimistic view on this story than I had really assumed. But that's what you come here, for at a Mixture of Experts, is the unexpected take.
36:11 And that's all the time that we have for today. So. Kush. Mihai. Natalie. Thanks for joining us on the show. Great to have you, as always, Natalie. Hopefully we'll have you soon. And thanks to all you listeners. If you enjoyed what you heard, you can get us on Apple Podcasts, Spotify and podcast platforms everywhere, and we'll see you all next week on Mixture of Experts.
36:39 So this is a bittersweet episode of Mixture of Experts, because our long time producer Alex will be moving teams here at IBM. And so, Alex, we just want to thank you. And we've had a couple people record a goodbye message to you. We'll miss you a lot. And best of luck. Good luck with the new role. I'm looking forward to seeing how you get on with that.
36:58 And thanks again. Thank you for the amazing work producing Mixture of Experts, great work and all the best in your next role. Happy birthday. Alex! Oh it is not a happy birthday. Oh you're leaving. Bye and thanks for having me on. Mixture of Experts. Bye bye. Can't wait to see where your vibes and your work bring you next. Super excited for you for your next move.
37:20 We're all going to miss you at Mixture of Experts. Go do amazing things. Congratulations, Alex. Thank you for everything and good luck. Best wishes on your next adventure. See you soon and so long for now. Thank you so much and best luck. Best of luck in your next role.
Use an astrology app's daily engagement and user base to deliver AI-generated fictional stories and personalized experiences.
A model in which AI becomes part of a user's daily routine through a personalized, frictionless product rather than an occasional chatbot interaction.
Attackers don't need to have the best hackers, they just need to have a model without the right guardrails in place, and they only need to succeed once.
We need to treat these agents as a first class citizen right now.
The cost of doing the breach will be lower, but the costs incurred by having the breach will be higher.
IBM fellow and contributor to the discussion of AI security, model policies, and AI explanations.
00:24Senior research scientist and contributor to the discussion of AI safety, security, and the Cost of a Data Breach report.
00:26Publisher of the annual Cost of a Data Breach report and the IBM blog article What Does AI Look Like?
00:54Involved in the infrastructure incident with Hugging Face and referenced as an established frontier-model vendor.
05:31Organization whose infrastructure was involved in an incident discussed as an example of AI-related hacking activity.
05:31AI company associated with Claude and discussed in relation to Opus models and restrictive security classifiers.
13:08