<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[norabble]]></title><description><![CDATA[Norabble investigates the complex systems of economics, technology, and global development, applying a pragmatic lens to reveal the hidden mechanics that shape our world.]]></description><link>https://substack.norabble.com</link><image><url>https://substackcdn.com/image/fetch/$s_!_1Oy!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png</url><title>norabble</title><link>https://substack.norabble.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 13 Sep 2026 14:02:17 GMT</lastBuildDate><atom:link href="https://substack.norabble.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Ryan Baker]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[norabble@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[norabble@substack.com]]></itunes:email><itunes:name><![CDATA[Ryan Baker]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ryan Baker]]></itunes:author><googleplay:owner><![CDATA[norabble@substack.com]]></googleplay:owner><googleplay:email><![CDATA[norabble@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ryan Baker]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Every Reward Bends]]></title><description><![CDATA[An incentive program for security work, and cross-over lessons from OpenAI&#8217;s Hugging Face incident]]></description><link>https://substack.norabble.com/p/every-reward-bends</link><guid isPermaLink="false">https://substack.norabble.com/p/every-reward-bends</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 01 Sep 2026 11:35:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!W0sH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In </span><a href="https://substack.norabble.com/p/nobody-was-watching"><span>Nobody Was Watching</span></a><span> I suggested organizations need an internal incentive program to drive security work, and cheekily called it Bountymaxxing. This is the follow-up. What such a program might look like, the challenges, and thoughts on how to navigate them.</span></p><p><span>Working it out, while reading the latest technical reports on the OpenAI Hugging Face incident, led to some unexpected reflections. The ways an internal incentive program goes wrong are similar to how reward-based AI training can go wrong. Recent events provide data to check those thoughts against. The second half of this piece is where this emerges. I think both fit well, and would recommend both halves, but if you&#8217;re pressed for time with an alignment focus, skip ahead. This part looks at how monitoring feedback in models and organizations affects the degradation of the reward system.</span></p><p><span>All of this is urgent. Getting alignment right, doing research and training safely, are critical. The direct interaction there though is limited to a very small group. The rest of us are in commentary mode. The other half, bringing cybersecurity forward in what needs to be a large leap, requires much broader engagement. External commitment, like the </span><a href="https://openai.com/collective-cyberdefense/"><span>open-letter on collective cybersecurity defense commitment</span></a><span> is important. The real work there is still outside the average person&#8217;s bubble, but there&#8217;s a lot of companies, and a lot of developers, IT staff, managers and executives that need to support the security priority. And those all need an internal strategy to pair with the external.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/every-reward-bends?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/every-reward-bends?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><h2><span>Bountymaxxing</span></h2><p><span>Development teams across all organizations need an adjustment to their priorities. Security has to, at least for a time, become a higher priority. The reason for this timely adjustment is the impact of AI on the realm of security. It is both offering an opportunity to improve the absolute level of security, and putting at risk the relative level of security.</span></p><p><span>A goal like this needs a mechanism. One as important as this needs multiple. Incentive systems get a bad rap. They almost always get distorted and create unintended consequences. Tokenmaxxing is not a popular term these days. As I explain in </span><a href="https://substack.norabble.com/p/measuring-without-breaking"><span>Measuring Without Breaking</span></a><span>, it takes a very strong culture to resist this. The best we can probably expect is to slow it down.</span></p><p><span>But I think incentives&#8211;despite their flaws&#8211;are still necessary when we have an important goal. It might be good marketing to distance myself from Tokenmaxxing, but I prefer to embrace the baggage. It&#8217;s probably better if anyone adopting an incentive system to drive action on security have a clear eyed view of the flaws so they can manage them, rather than looking at this as some novel concept that can escape the long history of management challenges.</span></p><p><span>The &#8220;bounty&#8221; part comes from the history of </span><a href="https://en.wikipedia.org/wiki/Bug_bounty_program"><span>bug bounties</span></a><span>, where organizations have offered cash rewards for software defects, often security vulnerabilities. What I&#8217;m suggesting is a bit different, as it&#8217;s internal to companies, and would focus on resolution, not discovery. That makes it more similar to the tokenmaxxing concept with leaderboards, hence the portmanteau.</span></p><p><span>We need something at a different scale, and deeper than the current bug bounties. The extension to internal and the inclusion of resolution offer a path there. To have teeth, they need support from the highest levels. Like tokenmaxxing, money isn&#8217;t likely the main driver, but status within an organization.</span></p><p><span>Like any measurement based program, we have to think about the distortionary effects. We can never remove those entirely, but a good design can at least reduce them. Additionally, I&#8217;d hope this period is temporary, and we may hope that the value based response comes first, and the distortions emerge later. It&#8217;s often the case that incentive systems have to be temporary because they degrade as strategies for gaming them develop, disseminate, and then become endemic.</span></p><h2><span>Resolution is the goal</span></h2><p><span>Traditional bug bounty programs focus on discovery. This makes sense as they are external and focused on the hardest to discover issues. External developers can discover an issue, but fixing isn&#8217;t something you can assume they&#8217;d have permissions to do. For open-source projects, you can reward pull request submissions.</span></p><p><span>The challenge with preparing systems for AI driven attacks is a bit different than those covered by traditional bug bounty programs. The scale is much larger. It&#8217;s not about finding one critical flaw, but about resolving thousands of flaws, many seemingly trivial. We resolve these not because we know how they&#8217;d be exploited, but because we have a concern about how they can be pieced together to enable an attack.</span></p><p><span>We want to work on volume, and we want our north-star goal to be full deployment. Full deployment is a tough goal. It means different things in different places. With closed source software that&#8217;s distributed and installed on customer hardware, it means updating it everywhere it goes. For software deployed as part of a software as a service solution, it means updating the entire fleet. Those are very different processes. The first requires a lot of cajoling, help, and possibly new update systems. It may never be fully accomplished. The second can be started by policy and accomplished by internal tools.</span></p><p><span>Discovery is still important, but keeping the end-goal in mind is important. While a program can target intermediate outcomes, you should also expect a progression, and think through the whole chain immediately.</span></p><h2><span>Normalizing Outcomes</span></h2><p><span>One of the challenges in implementing a program like this is normalizing the outputs for inputs that are not normalized. If the goal is a bit of incentive and thus competition, you would prefer a level playing field. Fixes though aren&#8217;t of equal size and complexity. Consider these program design options:</span></p><ol><li><p><strong><span>Raw number of fixes: </span></strong><span>After establishing what a &#8220;fix&#8221; is, you find they have different values. You should worry up front about big, difficult fixes being deprioritized so that more small, easy fixes are completed.</span></p></li><li><p><strong><span>Difficulty estimation: </span></strong><span>You could estimate the size of each fix, but doing this manually is time consuming.</span></p></li><li><p><strong><span>AI-driven difficulty estimation: </span></strong><span>You could use AI to drive the estimate, but have to worry about organizational trust if you do this poorly. Complexity increases as more varied teams, platforms and layers are covered.</span></p></li><li><p><strong><span>Importance estimation: </span></strong><span>Instead of focusing on the difficulty, focus on the value. Same challenge as before.</span></p></li><li><p><strong><span>AI-driven importance estimation: </span></strong><span>And as before, and at the same place, needing to do this efficiently but raising the risk of trust. Normalizing across teams now requires describing the importance of particular teams to the organization.</span></p></li><li><p><strong><span>Combined difficulty and importance:</span></strong><span> If you&#8217;ve estimated both, you can mix them. Why would you do this, given that importance is clearly the more important? To average the failures of each, if difficulty is more objective and accurate, and importance more aligned with the outcome. Also, the combination could be more resilient to successful gaming of one measure.</span></p></li><li><p><strong><span>Percentage of backlog fixed each month: </span></strong><span>&#8220;If&#8221;, and it&#8217;s a big if, we can trust the discovery backlog to be complete, or equally as complete between different teams, platforms and departments, then we could measure success of the percentage fixed.</span></p></li></ol><p><span>Whichever you choose, you&#8217;re choosing which imperfections to live with. That matters, because everything that follows is about what happens to those imperfections once people start pushing on them.</span></p><h2><span>Minimizing Distortions</span></h2><p><span>The best way to minimize distortions is to stay interactive. Watch for gaming strategies, call it out when you see it, show that respecting the intent receives better rewards than gaming the mistakes. But that should be obvious, and is something you have to do progressively as an act of management, so not very deep advice.</span></p><p><span>To make that job a little easier, some proactive design can help reduce distortions initially. Don&#8217;t expect this to remove gaming, maybe just delay it. Here&#8217;s some starting suggestions:</span></p><ol><li><p><span>Track self-fixers. These shouldn&#8217;t count, it&#8217;s too much of a moral hazard. Do not turn defects into a punishment, you want them to remain blameless. Old issues and the backlog are fine, but any issue created after, your default should be to not count.</span></p></li><li><p><span>Track issue creation patterns. Are rates increasing, stable or decreasing? A decrease signals a successful &#8220;shift-left&#8221;. Stable is okay. An increase is always a warning sign, but here could be signs of gaming.</span></p></li><li><p><span>Pay attention to clusters. Avoid focusing on the leaves when the branch may be rotten. Do not treat the manager and team like a single point. If the entire team fails, it&#8217;s better to remove the manager and give the team a second chance. Or you could give them both a second chance, but reassigned. Or you could dig into the details.</span></p></li></ol><p><span>If you find managers that responded inappropriately, consider why. It could be your fault. Always remember that the importance of alignment to goals over incentives grows as you climb in an organization, and that starts with the person at the top. Managers that accept gaming from their subordinates to inflate their own metrics are the bigger risk than the subordinates.</span></p><h2><span>Credit</span></h2><p><span>An incentive system isn&#8217;t an incentive system if no one expects credit. The time spent on security comes from somewhere, and if managers and individuals think they&#8217;re sacrificing their ability to accomplish other goals, without getting any credit, we can expect priorities not to change. It takes a very dedicated team to put those other things aside, and generally a team like that is only sustainable if they trust leaders will recognize work, even when not spelled out.</span></p><p><span>You should ask yourself, which type of organization are you? Not which you aspire to be&#8211;you can work on building that type of trust another day&#8211;but which are you today? If you don&#8217;t have that type of trust, you have to make it clear that this moment will be an exception and that you take this seriously.</span></p><p><span>I would avoid the temptation to formally put this in objectives. The reactions to tokenmaxxing were not positive on that one. The fallback is informal recognition, which is also somewhat risky without solid trust.</span></p><h2><span>Ending</span></h2><p><span>You want to be sure this ends. For one, distortions will build up the longer this runs. Those will undermine any trust you&#8217;re building or sustaining through good management. Some of the strategies for moving through stages, retiring discovery parts, and focusing more on final deployment will give you some extra time, but you have to expect to end.</span></p><p><span>It&#8217;ll be tempting to announce a date in advance. Someone is likely to ask that question at least. I&#8217;d avoid it if you can, but still make it clear it&#8217;s probably less than a year, maybe half a year. If you can&#8217;t progress in that time, you need a stronger approach, like outside help.</span></p><p><span>Ending a formal program shouldn&#8217;t end your ability to give credit for security improvement. It certainly shouldn&#8217;t be a hard cliff. Tear down any formal measurement system that&#8217;s started to diverge, but keep informal recognition alive. An ending does not indicate security is solved, or that security isn&#8217;t important, but merely that your ability to efficiently measure contributions to it has hit a limit.</span></p><h2><span>Management is active. Fire and forget doesn&#8217;t cut it.</span></h2><p><span>When I ran this plan by Claude, one of the tendencies it exhibited was to make the program deterministic. It recommended fire and forget decisions: a specific end date set in advance, a fixed percentage of capacity, managers directing every hour of labor.</span></p><p><span>Claude is following a long-running blind-spot in management theory here. Clean, well-defined models are often discussed. Life is always more complex. Management theory isn&#8217;t ignorant of this concept, but it often forgets it nonetheless.</span></p><p><span>This is why when you design a system like this and enact it, you don&#8217;t then stop monitoring. A measure is a correlation you trust for a while. Under pressure, what started as a clear correlation that seemed reliable becomes less reliable. Under continuous pressure, every tangential effect emerges, and comes to dominate the actual outcomes. To see this degradation happen, you have to be outside. You have to be independent, or at least, only indirectly connected.</span></p><p><span>You want something independent of that pressure, or at least, less coupled to it. Monitoring shouldn&#8217;t be wrapped up in the rewards system, or it will bend too. It doesn&#8217;t need an absolute separation, though that would be nice if such a thing existed. But a degree of separation goes a long way.</span></p><h2><span>Where OpenAI wasn&#8217;t watching</span></h2><p><span>If you&#8217;ve been studying the recent </span><a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/"><span>OpenAI Hugging Face incident</span></a><span> you&#8217;d be interested in the technical updates. There&#8217;s a fuller </span><a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf"><span>technical report</span></a><span>, and METR published an </span><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/"><span>independent investigation</span></a><span>.</span></p><p><span>There are some correlations to draw between the way rewards affect AI training, and how they affect organizations. With a little reflection this shouldn&#8217;t be surprising. While the individuals in an organization can make high-minded decisions, it&#8217;s hard to sustain, and organizations largely burned the trust necessary to have bottom-up behavior of that type.</span></p><p><span>AI models under reward based training will bend toward the reward. Earlier waves of pre-training may have built a concept like what hacking is. Other reward training may have used those concepts to steer away from hacking. But one of these rewards is clearer than the other, and continued pressure on it will bend either the concept of what hacking is, the preference for avoiding it, or both.</span></p><p><span>Both cases are reflections of the same thing: a reward&#8217;s imperfections come under pressure as it becomes the target.</span></p><p><span>One of OpenAI&#8217;s responses to the event was to </span><a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/#safeguard-coverage-in-internal-evaluations"><span>require chain-of-thought (CoT) monitoring across all tool-using RL training and evaluations</span></a><span>. That closes the gap I highlighted in </span><a href="https://substack.norabble.com/p/nobody-was-watching"><span>Nobody Was Watching</span></a><span>.</span></p><blockquote><p><em><span>We now also require CoT monitoring for all tool-using RL training and evaluations involving models with GPT&#8209;5.6 Sol capability or higher. For our Astra-class models, which</span><a href="https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/"><span> may have cyber-critical&#8288;</span></a><span> capabilities, this requirement also covers all tool-enabled inference workloads.</span></em></p></blockquote><p><span>Monitoring the CoT would give an opportunity to discover how the reward was leading to troublesome activity. And according to OpenAI it would have served that role for the Hugging Face incident.</span></p><blockquote><p><em><span>If our currently deployed CoT monitoring system was running at the time of the incident, it would have caught the initial relevant activity and paged our security team more than a day before models breached Hugging Face systems.</span></em></p></blockquote><p><span>But we need to be careful with the CoT. Researchers worry that it could itself be trained to hide its intent. As a scratchpad that represents only part of the &#8220;thinking&#8221;, it could in theory stop producing the warning flags while the intent persists elsewhere. We also have to worry about agents hacking the monitor and rewriting an existing CoT trace before it&#8217;s processed to eliminate the intent it indicated.</span></p><h2><span>Reasons for optimism</span></h2><p><span>METR and alignment researchers are reasonably worried about models becoming deceptive. This isn&#8217;t academic, as they did find agents putting effort into </span><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/#efforts-to-conceal-actions-and-tamper-with-transcripts"><span>concealing what they were doing</span></a><span> &#8212; escalating all the way to escaping their containers so they could spoof tool calls, appearing to run one command while running another.</span></p><p><span>Some worry about CoT monitoring causing CoT manipulation as a result. METR </span><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/#classifier-sweeps-for-important-behaviors"><span>did not find that particular behavior</span></a><span> in this event, with all the caveats of their investigation&#8217;s limits.</span></p><blockquote><p><em><strong><span>CoT manipulation:</span></strong><span> This checked for agents reasoning about manipulating their own chain of thought in order to fool the scorer; it did not turn up evidence of this, though it turned up many examples of agents reasoning about how they should not look at the HMAC reverse-engineered flag for their task to avoid being poisoned.</span></em></p></blockquote><p><span>It&#8217;s still a reasonable concern, but I think there are grounds for optimism, and they come in two parts.</span></p><p><strong><span>The first is low activation.</span></strong><span> Like human organizations, layers of indirection and low activation frequencies provide insulation. This does assume that it is low activation though, which itself is something that should be monitored. If monitoring is automated, built into a loop and then evaluations that trigger it at scale are allowed to become a part of a training run, this wouldn&#8217;t hold.</span></p><p><span>If you can obey this, AI models should be easier than human organizations. One challenge with indirection in human organizations is that the context of trust is endemic to an organization. Informal systems in a low trust environment are likely to be gamed, even when unnecessary, because of an assumption that the pessimistic view dominates. The consequences are assumed to be greater than they really are.</span></p><p><span>I don&#8217;t think that same dynamic is replicated when training an AI model against a reward. The reward process is closer to evolutionary effects. At low-activations there isn&#8217;t much signal left to guide evolution of deception. The concept of deception likely develops during pre-training, but its activation is dependent on reward based training.</span></p><p><strong><span>The second is that this kind of deception is recursed, and each layer is visible from another.</span></strong><span> One level of deception is to output deceptive text, which admittedly AI models do all the time. Another level is to lie about its actions, by trying to conceal them. The level people are worried about is lying about what the model is &#8220;thinking.&#8221;</span></p><p><span>I scare-quote &#8220;thinking&#8221; because it oversimplifies. A chain-of-thought trace is like a scratchpad that a model can use. It&#8217;s also more than that. Human thinking is reliant upon a sort of internal scratchpad too. Most of us feel as if we have an internal narrator, and that experience&#8211;among the things we know today&#8211;is the best analogy to a chain-of-thought trace. But while we might naively think of this narrator as our &#8220;thoughts&#8221;, we eventually find that to be an unsatisfactory explanation of what thinking is.</span></p><p><span>Like AI models, a great deal ends up being embedded in arrangements and activations for neurons. We have little way to be conscious of most of that. For AI models, we can watch considerably more of it. Chain-of-thought is a very accessible section of the thoughts, being in human language, but accessing other parts is possible too. The best demonstration of this is </span><a href="https://www.anthropic.com/research/global-workspace"><span>Anthropic&#8217;s work on J-spaces</span></a><span>, which surfaces what a model is considering rather than what it&#8217;s saying&#8212;including, in their examples, an intent to manipulate showing up while the model generates false values.</span></p><p><span>So an intent to deceive should show up in that J-space as part of the process of creating a deceptive chain-of-thought, in the same way a chain-of-thought normally reveals the intent behind commands to delete the log files that would expose the tool calls used for hacking.</span></p><p><span>That&#8217;s what makes the layers useful together rather than separately. Manipulating the context would show in the tool use logs. Manipulating the tool use logs would show in the context and the chain-of-thought. Deception in either should show in the J-space. There is always a way to deceive, but a deception that is coherent across all of those is not just more complex, but complex in a way that would develop one layer at a time.</span></p><p><strong><span>And it takes time. </span></strong><span>One observation from the technical reports is that persistence was key&#8212;there was a progression, over days. If an agent ever does find a way to rewrite its tool call logs, rewrite its chain-of-thought, and disable J-space monitoring, it will have revealed the trajectory toward that before the culmination, in this case more than a day before. If you don&#8217;t monitor, it&#8217;s plausible that by the time you look, it&#8217;s done. If you do, it has to play out very differently to be missed.</span></p><h2><span>Defending the indirection</span></h2><p><span>A key point here is you have to avoid sending a strong signal about the effect of monitoring. The more it becomes core to the process of alignment training itself, rather than a rarely activated protection, the more that degrades. Indirection helps, as the reward signal will explore other paths before optimizing this one. But both by direct activations and by indirection of last resort, there is a signal.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://claude.ai/code/artifact/3671322a-6f02-4357-a541-f8790935715e" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W0sH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 424w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 848w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 1272w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W0sH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif" width="728" height="436.8" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:564,&quot;width&quot;:940,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:622081,&quot;alt&quot;:&quot;Animated diagram. Two mirrored four-layer stacks side by side &#8212; an AI alignment monitoring program and an organizational change program. A monitor mark moves down each stack, and every layer it scores bends over and is labelled with the name of the distortion that bent it. The sequence ends with one layer in each stack still unbent, the monitor newly arrived on it. Each stack runs from the most visible surface down to the least accessible. The bracket is the monitoring; the arrow is the pressure that monitoring creates. They arrive together, because a layer is corrupted by being scored, not by being watched. When the bracket moves deeper, the arrow stays put, and the layer keeps the name of the distortion that bent it. Clean layers are spent rather than accumulated, which is why the sequence ends where it does: one layer still unbent, with the monitor newly arrived on it. That is the position to defend &#8212; not a guarantee that it holds.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:&quot;https://claude.ai/code/artifact/3671322a-6f02-4357-a541-f8790935715e&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/213350369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Animated diagram. Two mirrored four-layer stacks side by side &#8212; an AI alignment monitoring program and an organizational change program. A monitor mark moves down each stack, and every layer it scores bends over and is labelled with the name of the distortion that bent it. The sequence ends with one layer in each stack still unbent, the monitor newly arrived on it. Each stack runs from the most visible surface down to the least accessible. The bracket is the monitoring; the arrow is the pressure that monitoring creates. They arrive together, because a layer is corrupted by being scored, not by being watched. When the bracket moves deeper, the arrow stays put, and the layer keeps the name of the distortion that bent it. Clean layers are spent rather than accumulated, which is why the sequence ends where it does: one layer still unbent, with the monitor newly arrived on it. That is the position to defend &#8212; not a guarantee that it holds." title="Animated diagram. Two mirrored four-layer stacks side by side &#8212; an AI alignment monitoring program and an organizational change program. A monitor mark moves down each stack, and every layer it scores bends over and is labelled with the name of the distortion that bent it. The sequence ends with one layer in each stack still unbent, the monitor newly arrived on it. Each stack runs from the most visible surface down to the least accessible. The bracket is the monitoring; the arrow is the pressure that monitoring creates. They arrive together, because a layer is corrupted by being scored, not by being watched. When the bracket moves deeper, the arrow stays put, and the layer keeps the name of the distortion that bent it. Clean layers are spent rather than accumulated, which is why the sequence ends where it does: one layer still unbent, with the monitor newly arrived on it. That is the position to defend &#8212; not a guarantee that it holds." srcset="https://substackcdn.com/image/fetch/$s_!W0sH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 424w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 848w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 1272w, https://substackcdn.com/image/fetch/$s_!W0sH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68404c67-0ff8-4d8b-b2cd-8065c7b201b2_940x564.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">How pressure bends monitoring layers - <a href="https://claude.ai/code/artifact/3671322a-6f02-4357-a541-f8790935715e">Claude Generated Artifact</a></figcaption></figure></div><p><span>I do wonder if this is a principle that OpenAI is not sufficiently aware of, that they are maybe wedded to the standard management mistake of holding on too tight. </span><a href="https://thezvi.substack.com/i/212922728/openai-is-accelerating-and-enforcing-model-alignment-ixc"><span>From The Zvi (quoting OpenAI)</span></a><span>:</span></p><blockquote><p><em><span>&#8220;The Hugging Face incident underscored the need to measure agentic misalignment more rigorously in OpenAI&#8217;s most capable models wherever they are run&#8212;including intermediate or experimental checkpoints used only for internal research, training, or evaluation.</span></em></p><p><em><span>OpenAI is raising alignment standards throughout training, with clear thresholds for intervention when concerning behavior emerges.&#8221;</span></em></p><p><em><strong><span>Yes, measurement is good, but going straight to more reliance on measurement and metrics fills me with dread. You are not going to keep outsmarting via metrics. The way this procedure gets you into trouble should be obvious.</span></strong></em></p><p><em><span>&#8220;Many methods helping OpenAI meet these higher standards were in development well before the incident. OpenAI is now applying them more broadly, alongside new targeted remediations for each of the misalignment behaviors OpenAI observed.&#8221;</span></em></p><p><em><strong><span>Again, based on how that is worded, I know OpenAI does not agree, but: While I realize it whacks moles, put down the mallet. The mallet is not </span><a href="https://www.youtube.com/watch?v=X5jlTlUTWfQ"><span>The Way</span></a><span>.</span></strong></em></p></blockquote><p><span>Indirection will not save you indefinitely. It merely buys time. It will only be enough time if you defend the indirection. Indirection results in a lower level of coupling. This forces feedback to progress through more layers, lowering its powers of feedback. They never disappear, but they are attenuated.</span></p><p><span>Allowing CoT to be manipulated would leave you as blind as you started, unless you have a backup, like the ability to monitor J-space for all training. Defending the CoT is thus very important, but having it but not monitoring it is also not good.</span></p><h2><span>Watching your own organization</span></h2><p><span>You won&#8217;t have access to mind reading devices. As a leader, one of your goals is to find the evidence of collusion. You might object that the collusion is automatic, and so there is no conspiracy. That however does not mean it leaves no evidence. If you&#8217;re tracking clusters and diving into some of the real details, fake activity won&#8217;t entirely hide. Automatic collusion doesn&#8217;t intentionally hide itself. The signals might be comparatively subtle compared to intentional deceptions which leave loud trails that someone would then have to work to erase.</span></p><p><span>A leader with a real interest in security would be immune to automatic collusion. If you&#8217;re such a leader, but need to delegate, have a delegate look for those subtle signals. You also want to avoid making the mistake that overreliance on CoT would risk. You want this delegate to be as independent as possible from the reward function. An easy mistake to make would be to ask them to tell you when to terminate the program, but leave them to think that an end to the program would be an end to their job. You can never make the delegate fully independent, as the organization will have a reason to subvert them. Think of regulatory capture. But a good effort is better than none.</span></p><p><span>In either case, intentional or automatic, it&#8217;s wise to take a page from the AI alignment playbook here. Monitor early. AI monitoring can be a bit less fatigable, you are only human after all, but the warning signals will often be more obvious early than later. If a middle manager asks direct reports to optimize in a &#8220;gaming&#8221; way, they will push back more when it&#8217;s novel, and less when it&#8217;s pervasive. Once it&#8217;s accepted as &#8220;that&#8217;s the way things are&#8221;, the bottom-up signals from your whistleblowers lose their volume. If it&#8217;s intentional, you should expect the ring leaders to proactively act secretly. You can&#8217;t access their chain-of-thought or private conversations, but if they make a mistake here, it&#8217;s more often early. It&#8217;s a bit interesting how often liars actually telegraph their plans in advance, before committing to them. Often that&#8217;s because they aren&#8217;t bad in an absolute sense, but choose the wrong path when they feel their options are narrow.</span></p><h2><span>Conclusion</span></h2><p><span>Escalating the effort that every organization puts into security for the next 12-24 months will be critical. If organizations can do this, the outcome on the other side will be more stable. Risks won&#8217;t disappear, and we have to depend on appropriate protections on deployed AI to keep the defender stably ahead. But we&#8217;re exiting a period where best-effort security was good enough, and entering one where standards must be higher. New tools give promise of meeting those standards, but they still need effort. This transition will bring some turmoil.</span></p><p><span>An incentive program is one instrument for getting through it, though a decaying one. That&#8217;s not a reason to skip it. It&#8217;s the reason active management matters more than the scoreboard. Fail to respond now, and you&#8217;ll likely start to see more and more concrete reasons you should have started earlier.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/every-reward-bends?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/every-reward-bends?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><h4><strong><span>Related Articles</span></strong></h4><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;33edc794-d18f-4ab2-8493-c99a22f2e6bc&quot;,&quot;caption&quot;:&quot;When I heard about the recent hacking events starting at OpenAI, Anthropic and AISI, I thought it was a wake up call in more ways than one. I&#8217;m finding that not everyone agrees. One reaction does not include the sense of urgency to prepare for AI-based attacks. It&#8217;s my reaction that there is a need for an all-hands-on-deck response from the rank and file of developers, software companies, and companies dependent on software. That response should improve operational security postures using every tool available.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why It Hasn't Happened Yet&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-08-17T13:00:03.061Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Qilg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/why-it-hasnt-happened-yet&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:211301474,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;deee2440-7f79-419a-b312-15a9b60bc0b4&quot;,&quot;caption&quot;:&quot;The Monitors Were Off Again&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Nobody Was Watching&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-08-04T11:33:24.677Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f8a36d1-9636-434c-8b03-0fd3e0499ca7_2752x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/nobody-was-watching&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:209730860,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:3,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;58f05d53-8fae-4491-b60b-2f600930b867&quot;,&quot;caption&quot;:&quot;Disclaimer: This final draft is AI generated, then edited by me. What does that mean? Well, after some fairly substantial writing, I was tempted to drop this article entirely. I&#8217;d taken the writing in a few directions, and it was becoming a sprawl that would take a long time to recover from. I felt there were interesting ideas, but wasn&#8217;t sure it was worth continuing. Before abandoning, I worked with Claude to rewrite around a new concept. The core ideas here are very much my own. Since Claude had access to my (failed) drafts, many words are mine too. But the direct product is not. If you&#8217;re substantially opposed to AI writing, and you dislike this, you can reaffirm your priors. If you can see through that to the ideas here, then maybe there&#8217;s something valuable. I leave this with you. I could spend time using this as an inspiration, rewriting parts, and eventually this disclaimer would no longer be necessary.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Measuring Without Breaking&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-07T12:50:27.391Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd704139-0e27-4d4e-9960-e4086efd6a26_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/measuring-without-breaking&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:205495148,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:7,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;96a310e4-5008-4c8a-a83d-f78f6467cfd0&quot;,&quot;caption&quot;:&quot;Sometime in the week before July 16th, Hugging Face was attacked by an OpenAI model that was under evaluation. The attack itself wasn&#8217;t particularly harmful, but the conceptual implications of the event are significant.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;An OpenAI Model Escaped Its Sandbox. Where Was the Observer?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-23T15:29:38.996Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30b6b633-b53c-495f-9936-27d59c48b8aa_2752x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:208213421,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;184a010b-db78-4513-a6d6-c166c4c29e92&quot;,&quot;caption&quot;:&quot;In the broader discourse on artificial intelligence, the sharpest minds in AI safety are currently looking to the horizon. They are focused on existential, cinematic threats: the potential for AI-generated bioweapons, nuclear command vulnerabilities, and autonomous warfare.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Deployments Can't Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-23T11:50:42.028Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d95d729-a5d3-4f42-9d39-bf371396315c_2812x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/deployments-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:191818851,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:3,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;c087de1d-82dd-4ee6-99a0-04730cf3f008&quot;,&quot;caption&quot;:&quot;Right now, Artificial Intelligence is fundamentally rewriting the rules of cybersecurity&#8212;and we do not have the luxury of waiting before taking action.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Security Can&#8217;t Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T21:05:09.345Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b2a65ed-e701-4f36-8d82-2a665189419b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/security-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190039490,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[Why It Hasn't Happened Yet]]></title><description><![CDATA[The protections keeping capable AI away from malicious intent are weakening. What developers and software companies should be doing now, with old techniques and new ones]]></description><link>https://substack.norabble.com/p/why-it-hasnt-happened-yet</link><guid isPermaLink="false">https://substack.norabble.com/p/why-it-hasnt-happened-yet</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Mon, 17 Aug 2026 13:00:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qilg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>When I heard about the </span><a href="https://substack.norabble.com/p/nobody-was-watching"><span>recent hacking events starting at OpenAI, Anthropic and AISI</span></a><span>, I thought it was a wake up call in more ways than one. I&#8217;m finding that not everyone agrees. One reaction does not include the sense of urgency to prepare for AI-based attacks. It&#8217;s my reaction that there is a need for an all-hands-on-deck response from the rank and file of developers, software companies, and companies dependent on software. That response should improve operational security postures using every tool available.</span></p><p><span>At first this is shocking, but with a little reflection, I see how the full ramifications haven&#8217;t sunk in. As a news story, it&#8217;s </span><a href="https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox"><span>led by one attack</span></a><span>, and little damage occurred. While it would be hard to miss the tinge of panic when reading coverage, people may have become dull to this from persistent rounds of security coverage, often from security sales, that have always hyped risks.</span></p><p><span>This is different. The attacks were both demonstrations of carelessness, and demonstrations of the capabilities of powerful AI models. Damage was minimal because these attacks did not combine malicious intent with those capabilities. The attacks occurred with the more benign intent of a model trying to pass a test. And this is the least effective that models will be.</span></p><p><span>As models improve, defenders and attackers will gain access to new capabilities. How labs manage this is important, but so is how we adopt those capabilities and put them to work. The status quo is not stable. The world hasn&#8217;t changed too much yet, but it will.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qilg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qilg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 424w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 848w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 1272w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qilg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg" width="1456" height="741" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:741,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6456,&quot;alt&quot;:&quot;Line chart of security level and model capability level over time as models improve. Attacker capability rises steadily, while a dashed line for attacker capability with no restrictions on access rises faster and crosses the near-flat \&quot;status quo efforts\&quot; line much earlier, marked \&quot;sooner, without restrictions\&quot;. A green line for aggressive improvement assisted by AI stays above both. A second marker shows where the status quo would fail.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/211301474?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart of security level and model capability level over time as models improve. Attacker capability rises steadily, while a dashed line for attacker capability with no restrictions on access rises faster and crosses the near-flat &quot;status quo efforts&quot; line much earlier, marked &quot;sooner, without restrictions&quot;. A green line for aggressive improvement assisted by AI stays above both. A second marker shows where the status quo would fail." title="Line chart of security level and model capability level over time as models improve. Attacker capability rises steadily, while a dashed line for attacker capability with no restrictions on access rises faster and crosses the near-flat &quot;status quo efforts&quot; line much earlier, marked &quot;sooner, without restrictions&quot;. A green line for aggressive improvement assisted by AI stays above both. A second marker shows where the status quo would fail." srcset="https://substackcdn.com/image/fetch/$s_!Qilg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 424w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 848w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 1272w, https://substackcdn.com/image/fetch/$s_!Qilg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ac0da1f-d6d5-45f4-8ecd-8b5058671df1_680x346.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>I thought I should go into that in more detail. What are the things protecting us today? What are the risks they won&#8217;t hold? What can we do to prepare for that? The answer I&#8217;ll offer can be summarized as using new techniques to accelerate old techniques.</span></p><h3><span>What I won&#8217;t cover but is still important</span></h3><p><span>The Hugging Face event isn&#8217;t just about the urgency to prepare for AI-based attacks. It was also about the type of testing that the AI labs were performing. They removed protection layers and didn&#8217;t follow-up with monitoring, which I&#8217;ve already written about in </span><a href="https://substack.norabble.com/p/nobody-was-watching"><span>Nobody Was Watching</span></a><span>. It also demonstrated unaligned behavior, which I&#8217;ll suggest </span><a href="https://thezvi.substack.com/p/what-happened-openai-and-huggingface"><span>What Happened: OpenAI and HuggingFace</span></a><span> as a source to learn more about.</span></p><p><span>This type of work needs to receive high care and caution. Monitoring applied to this testing was insufficient. We should not assume when we explore new territory that the exploration is safe. Even if we&#8217;re exploring to understand safety, we should be monitoring the exploration. That should be obvious, doubly so because how effective is the exploration if you&#8217;re not monitoring it? Certainly less than if you are.</span></p><p><span>I don&#8217;t cover those here not because they aren&#8217;t important, but because they are, and they deserve their own space.</span></p><h2><span>What protections are holding up today?</span></h2><p><strong><span>Intent: </span></strong><span>In the case of the Hugging Face event, the most effective protection was the lack of malicious intent. We can&#8217;t expect that to hold, as it never has. But other protections are about preventing this type of intent accessing capabilities.</span></p><p><span>The most unusual aspect of the recent events is that the AI involved was accidentally persistent. That&#8217;s a warning sign for sure, but its probability of great harm alone passes through another layer: intent. None of the agents participating in the Hugging Face hack would have what we&#8217;d call malicious intent.</span></p><p><strong><span>Training Alignment: </span></strong><span>Lesser models have lesser capabilities due to less advanced training. Training also applies alignment to the models. Roughly put, this causes models not to &#8220;want&#8221; to do harm. A bit more specifically, this both causes models to not spontaneously respond in ways that would invoke harmful actions, and to refuse to respond to requests that look to be trying to create harm. While this type of protection is important, it&#8217;s also weak.</span></p><p><strong><span>Security Classifiers: </span></strong><span>When models are deployed behind APIs, it&#8217;s standard practice to use a &#8220;classifier&#8221; to evaluate the inputs and outputs. If they appear to intend to cause harm, they refuse the request. During the recent hacking events, those were disabled intentionally. This was to enable important testing. While doing that without monitoring was reckless, we should remember that these are enabled for external deployments, and thus contribute to keeping malicious intent and capabilities from merging. The ability to monitor and tune security classifiers is greater than training alignment. Training alignment is something you have to get right during training.</span></p><p><strong><span>Abuse Detection: </span></strong><span>The major AI labs all have documented evidence of attackers trying to use models for attacks. Security classifiers deny a lot of this. They also take other measures to identify attackers and limit their access. There are evasion techniques here, so it&#8217;s not as simple as flipping a switch, but the efforts they put in do add complexity and costs for the attackers.</span></p><p><strong><span>Conventional Security: </span></strong><span>Models will only be able to perform an attack that is below their capability level. If the infrastructure they are attacking is better secured, it raises the complexity level. Raise the complexity level high enough and the attempt will fail.</span></p><h3><span>What puts protections at risk?</span></h3><p><em><strong><span>Jailbreaks</span></strong></em><span> are inputs that defeat training alignments. This is why training alignments are weak protections against malicious use. These are usually partial and it&#8217;s accepted that partial jailbreaks exist. </span><em><span>Universal jailbreaks</span></em><span> are less common and more concerning. Even with the existence of jailbreaks, alignment training is very important. Jailbreaks tend to make the model a little stupider in the process. That&#8217;s all quite complicated, and there&#8217;s some decent papers on it, but the analogy would be that trying to confuse the model leaves it confused. A clear-headed model, with a clear-headed goal would be more dangerous than a confused model. Since one of the main goals is to prevent malicious intent and capability from connecting, this helps.</span></p><p><span>Attackers can try to evade security classifiers, by hiding their intent. Keep in mind that when you hide your intent, a model is less likely to be able to autonomously pursue your goal. If you can&#8217;t state your goal without being rejected, the effective capabilities are lower. Plus it&#8217;s a lot of effort to evade in the first place.</span></p><p><em><strong><a href="https://substack.norabble.com/p/challenges-for-ai-misuse-prevention"><span>Open-weight models</span></a></strong><span> </span></em><span>allow anyone a copy of the trained model, rather than access via API. Since security classifiers are part of deployments, they aren&#8217;t part of open-weight models. If I download an open-model and have hardware under my control, there&#8217;s nothing forcing me to install them. A deployment could add them, but we wouldn&#8217;t expect an attacker to do so. Attackers thus get a free pass on security classifiers from open-weight models. That leaves the training alignment to overcome.</span></p><p><span>Attackers can also apply additional training to open-weight models that &#8220;untrains&#8221; their alignment training. Like jailbreaks, known techniques degrade the model somewhat. It&#8217;s an open question on how hard it is to restore that initial level of capability. This &#8220;dumbing&#8221; effect is less significant than that from jailbreaks.</span></p><p><span>Continued training does require infrastructure, it&#8217;s like the original training. But it takes many fewer iterations than the original training, so even if it&#8217;s running slow, it&#8217;s possible to complete without a ridiculous amount of infrastructure.</span></p><p><em><strong><span>Continued training:</span></strong></em><strong><span> </span></strong><span>If open-models continue to be released, at higher and higher levels of capability, at some point one will be as capable as the one that orchestrated the Hugging Face event. Today, the best ones are </span><a href="https://www.lesswrong.com/posts/rJcCrXyEsJKmmDpWG/how-far-behind-are-open-models"><span>8 months or more behind</span></a><span>. Add some extra buffer for the effects of untraining, and it should be clear that unless something changes, an attacker will in the future have access to a model capable of a hack of equivalent complexity to the Hugging Face event.</span></p><p><span>But should those buffers be spent, for an attacker it&#8217;s just a matter of injecting the malicious intent, which could now happen at scale, and it would be quite difficult to stop that from scaling up.</span></p><p><span>We should worry about closed models too, as their training is the most advanced. One risk is leaking the weights, making them effectively into open-weight models. A lesser, but still relevant concern is bypassing the security classifiers. The reason this is lesser is that an appropriate reaction to a failure there would be to disable all access to the model creating the risk.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!INEo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!INEo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 424w, https://substackcdn.com/image/fetch/$s_!INEo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 848w, https://substackcdn.com/image/fetch/$s_!INEo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 1272w, https://substackcdn.com/image/fetch/$s_!INEo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!INEo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png" width="1456" height="783" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:783,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Matrix comparing four protections under closed weights (API) versus open weights. Training alignment inside the model is weak and partly jailbroken when closed, and removable by fine-tuning when open. Security classifiers at the deployment check every request when closed, but are not part of the model when open. Abuse detection at the lab or API lets labs cut off attackers when closed, but when open no one is watching. Conventional security in your own infrastructure is yours to raise either way. The bottom row, intent meets capability, holds if classifiers and detection hold when closed, and only while capability lags security efforts when open.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Matrix comparing four protections under closed weights (API) versus open weights. Training alignment inside the model is weak and partly jailbroken when closed, and removable by fine-tuning when open. Security classifiers at the deployment check every request when closed, but are not part of the model when open. Abuse detection at the lab or API lets labs cut off attackers when closed, but when open no one is watching. Conventional security in your own infrastructure is yours to raise either way. The bottom row, intent meets capability, holds if classifiers and detection hold when closed, and only while capability lags security efforts when open." title="Matrix comparing four protections under closed weights (API) versus open weights. Training alignment inside the model is weak and partly jailbroken when closed, and removable by fine-tuning when open. Security classifiers at the deployment check every request when closed, but are not part of the model when open. Abuse detection at the lab or API lets labs cut off attackers when closed, but when open no one is watching. Conventional security in your own infrastructure is yours to raise either way. The bottom row, intent meets capability, holds if classifiers and detection hold when closed, and only while capability lags security efforts when open." srcset="https://substackcdn.com/image/fetch/$s_!INEo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 424w, https://substackcdn.com/image/fetch/$s_!INEo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 848w, https://substackcdn.com/image/fetch/$s_!INEo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 1272w, https://substackcdn.com/image/fetch/$s_!INEo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6fd0526-ccaa-434d-806b-ad5af06171ad_1472x792.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>Why should we think security is at risk?</span></h2><p><span>As a single piece of evidence, the recent events are the best there is, but the evidence that powerful AI models were gaining these capabilities didn&#8217;t start there. Conceptually, the idea has been around a long time. And evidence that we are approaching a pivotal moment, was clear to me in March when I wrote </span><a href="https://substack.norabble.com/p/security-cant-wait"><span>Security Can&#8217;t Wait</span></a><span>. But what was the level of conventional security needed to avoid a compromise? Hugging Face demonstrated a level that was insufficient. We should all be careful about assuming we are above that level. Ideally, you should assume you are worse than you think, and thus as a goal, strive to be several steps further than you need to be.</span></p><p><span>The security of software systems has always been a bit of a mirage. The mirage made them appear invulnerable. If you worked in security, you&#8217;d know this wasn&#8217;t true, it was a constant battle with many compromises and ample mistakes. What&#8217;s more, while there were many lazy or reckless mistakes, many other mistakes were of a complexity that labeling them as mistakes no longer fits. It&#8217;s a bit of a pipe dream to eliminate all the lazy and reckless mistakes, but that is almost realistic compared to eliminating all the complex vulnerabilities.</span></p><p><span>Occasionally signals that systems were not invulnerable would filter through to the public, but overall the weakest point in these systems was often the public itself. You&#8217;d blame yourself for installing that malware, or having an insecure password, or going to &#8220;that&#8221; site. That&#8217;s not always fair, security professionals know they need to take responsibility for not just what they do, but for helping users avoid harm.</span></p><p><span>Software systems have survived by having multi-layered defenses. While every layer has mistakes that could be exploited, multiple layers raised the difficulty of finding a path through these layers. Finding the mistake in a second layer is harder because the compromise of the first layer is partial. The typical analogy is Swiss cheese. Swiss cheese has many holes, and in a thin slice, you&#8217;ll see many pathways through. A thicker block has some of these dead-end. The remaining complete paths also won&#8217;t simply be clearly visible. A thick enough block might have no complete paths, but neither you or the attacker know that until fully exploring. The Swiss cheese analogy breaks down a bit here because it&#8217;s hard to imagine a piece of cheese as complex as modern software, but the analogy has taken you a little closer to the truth.</span></p><h2><span>Why the equilibrium broke</span></h2><p><span>When extended far enough, the Swiss cheese analogy resembles a complex multidimensional maze. There is likely more than one entry point and more than one exit. It takes effort and time to explore the maze, and if defenders are doing their job, there are hazards as well. Take too long and the walls in the maze may shift, closing discovered paths.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HS4z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HS4z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 424w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 848w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 1272w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HS4z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif" width="1360" height="624" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:624,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30351,&quot;alt&quot;:&quot;Two-panel diagram. Left, \&quot;The Swiss cheese analogy: each layer closes more routes\&quot;, shows an arrow threading the gaps between staggered barriers, captioned \&quot;add enough layers and the route closes\&quot;. Right, \&quot;The cost of navigating the maze: each closure forces a longer route\&quot;, shows four denser columns of barriers, captioned \&quot;the gaps rarely line up, and the detours are the cost\&quot;. Below both: walls shift too, so a route found is not a route that stays open.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/211301474?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two-panel diagram. Left, &quot;The Swiss cheese analogy: each layer closes more routes&quot;, shows an arrow threading the gaps between staggered barriers, captioned &quot;add enough layers and the route closes&quot;. Right, &quot;The cost of navigating the maze: each closure forces a longer route&quot;, shows four denser columns of barriers, captioned &quot;the gaps rarely line up, and the detours are the cost&quot;. Below both: walls shift too, so a route found is not a route that stays open." title="Two-panel diagram. Left, &quot;The Swiss cheese analogy: each layer closes more routes&quot;, shows an arrow threading the gaps between staggered barriers, captioned &quot;add enough layers and the route closes&quot;. Right, &quot;The cost of navigating the maze: each closure forces a longer route&quot;, shows four denser columns of barriers, captioned &quot;the gaps rarely line up, and the detours are the cost&quot;. Below both: walls shift too, so a route found is not a route that stays open." srcset="https://substackcdn.com/image/fetch/$s_!HS4z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 424w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 848w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 1272w, https://substackcdn.com/image/fetch/$s_!HS4z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb648f5-9774-43fb-9875-2babca85134f_1360x624.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>When security succeeded &#8211; and let&#8217;s be honest, all failures aside, it succeeded well enough for us to rely heavily upon it &#8211; it succeeded by having a complex enough maze. By raising the required time investment of the attacker to a level that was no longer attractive, there were no attempts persistent enough to succeed. Sometimes this succeeded on the principle of the bear in the forest; don&#8217;t outrun the bear, outrun the other targets. But even then, there&#8217;s a question of how many targets the bear wanted.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_YJD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_YJD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 424w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 848w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 1272w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_YJD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png" width="1456" height="1309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1309,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Four stacked bar panels showing the investment demanded at each of six layers in the compromise chain. \&quot;Hard to find the flaws\&quot; shows tall, even bars &#8212; every layer requires investment, so pick your targets. \&quot;AI lowers costs without response\&quot; flattens every bar to a sliver, giving scalable persistence at low cost. \&quot;Security investments increase resistance\&quot; raises the bars sharply at layers 3 and 5. \&quot;Powerful AI protected from misuse\&quot; adds a separate cost to access powerful AI beneath the cost to penetrate each layer, so buying persistence is no longer free.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Four stacked bar panels showing the investment demanded at each of six layers in the compromise chain. &quot;Hard to find the flaws&quot; shows tall, even bars &#8212; every layer requires investment, so pick your targets. &quot;AI lowers costs without response&quot; flattens every bar to a sliver, giving scalable persistence at low cost. &quot;Security investments increase resistance&quot; raises the bars sharply at layers 3 and 5. &quot;Powerful AI protected from misuse&quot; adds a separate cost to access powerful AI beneath the cost to penetrate each layer, so buying persistence is no longer free." title="Four stacked bar panels showing the investment demanded at each of six layers in the compromise chain. &quot;Hard to find the flaws&quot; shows tall, even bars &#8212; every layer requires investment, so pick your targets. &quot;AI lowers costs without response&quot; flattens every bar to a sliver, giving scalable persistence at low cost. &quot;Security investments increase resistance&quot; raises the bars sharply at layers 3 and 5. &quot;Powerful AI protected from misuse&quot; adds a separate cost to access powerful AI beneath the cost to penetrate each layer, so buying persistence is no longer free." srcset="https://substackcdn.com/image/fetch/$s_!_YJD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 424w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 848w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 1272w, https://substackcdn.com/image/fetch/$s_!_YJD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b96cdb9-3bfc-49f3-9acb-3d76d6f8a5d6_2048x1841.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Adding these layers wasn&#8217;t cheap though, each requires investment and maintenance. With enough time, we might be able to make them impervious, but that time might scale toward infinity, and become impractical far earlier.</span></p><p><span>This is where the first risk from sufficiently capable AI emerges. The persistence of an attacker with sufficient AI capability is higher. Mazes that were sufficient before become inadequate, as no layer is deterrence enough to defeat persistence.</span></p><p><span>There is a lesson in here though, and it is that this isn&#8217;t a binary yes/no outcome, but still a matter of balance. If we invest more, or if AI multiplies our investments, we reduce the vulnerabilities at each layer, making them more scarce. If you can make your maze more complex, you can reach the same equilibrium.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OEGv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OEGv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 424w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 848w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OEGv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png" width="1456" height="906" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:906,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Line chart of cumulative attacker investment against the six layers of the compromise chain, with a dashed horizontal line marking the attacker's investment ceiling. \&quot;Hard to find the flaws\&quot; rises steeply and is abandoned at layer 2, \&quot;powerful AI protected from misuse\&quot; is abandoned at layer 3, \&quot;security investments increase resistance\&quot; is abandoned at layer 5, and \&quot;AI lowers costs without response\&quot; stays cheap enough to reach every layer.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart of cumulative attacker investment against the six layers of the compromise chain, with a dashed horizontal line marking the attacker's investment ceiling. &quot;Hard to find the flaws&quot; rises steeply and is abandoned at layer 2, &quot;powerful AI protected from misuse&quot; is abandoned at layer 3, &quot;security investments increase resistance&quot; is abandoned at layer 5, and &quot;AI lowers costs without response&quot; stays cheap enough to reach every layer." title="Line chart of cumulative attacker investment against the six layers of the compromise chain, with a dashed horizontal line marking the attacker's investment ceiling. &quot;Hard to find the flaws&quot; rises steeply and is abandoned at layer 2, &quot;powerful AI protected from misuse&quot; is abandoned at layer 3, &quot;security investments increase resistance&quot; is abandoned at layer 5, and &quot;AI lowers costs without response&quot; stays cheap enough to reach every layer." srcset="https://substackcdn.com/image/fetch/$s_!OEGv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 424w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 848w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!OEGv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61535653-555d-4ee8-b015-90ae75b608ea_2032x1264.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>Keeping malicious intent and capability apart</span></h2><p><span>AI is persistent in both the hands of a defender and an attacker. But it&#8217;s not automatically so. We haven&#8217;t seen malicious intent and powerful AI fully merged. We got a warning sign and we should take it. That warning was in the form of naive exploration, but we should not take this for granted. If you can deny attackers easy access to AI capabilities, this helps maintain that equilibrium.</span></p><p><span>If we manage to restrict access, we still need to take action. It would be reckless not to. We don&#8217;t know that restricting access will be enough. We don&#8217;t know if it will succeed long-term. That said, we would be naive to not pursue it, even the most minimal versions where there&#8217;s only a 6-month capability gap. To not do so would ignore that many organizations will fall behind. Some leaders will disbelieve this call for urgency, and fail to set them on the right path. Others will fail due to internal issues, coordination problems and an inability to respond to necessary change. Hell, some were going to fail overall anyhow, so we can&#8217;t be surprised if they fail at this too.</span></p><p><span>Cybersecurity&#8217;s main concern will not be rogue agents on training jobs. Naive exploration, even with safeguards removed, is less likely to end in harm than intentional use for malicious intents. There&#8217;s some big topics there, but it&#8217;s not the reason you should be hardening your own security. Those topics depend on the labs, and the general level of security, of which your own is a small part.</span></p><p><span>What you should want, that is common to those topics, is to keep malicious intent and capabilities from connecting. That&#8217;s an ask we should have of the labs. We should be willing to make those asks in more direct ways than just asking. It&#8217;s nice that they&#8217;ve done some of this on their own. We can&#8217;t take that for granted, and I don&#8217;t think it&#8217;s enough.</span></p><p><span>We know there are people with malicious intent. A small number want harm, just for harm&#8217;s sake. A larger number are willing to cause harm in pursuit of their goals. Those are direct paths toward negative outcomes and we need to pay attention to them.</span></p><p><span>It is important to withhold capabilities from both of these groups. It&#8217;s important to identify and isolate members of both groups. Both tasks are hard and carry risks we&#8217;ll make mistakes. The importance of avoiding those mistakes makes the challenge that much harder.</span></p><p><span>But like the attacker navigating the maze, so can we. We can watch our mazes. When we find someone trying to navigate it, we would track that person back to the source, arrest and imprison them. We are not so naive to believe this would work in all cases. Not only would we fail to find some, but we don&#8217;t have a system that allows us to imprison all of them. Some will be outside cooperative or functional jurisdictions. Even within cooperative functional jurisdictions, we want to respect our own laws about proof and certainty.</span></p><p><span>With this in mind, we should be looking for other better balanced opportunities, such as denying access to tools. Non-functional jurisdictions are unlikely to be able to create those tools themselves. If we control ours, we avoid helping them. Non-cooperative jurisdictions are more complicated if they are functional enough to build their own tools. More so if they are functional enough to steal ours.</span></p><p><span>To stop talking in generalities, primarily who we mean by non-cooperative, but functional is China. One difficult, but obvious path is for them to become cooperative. If you assume there is one and only one step, directly to full cooperation, this will seem even more difficult than if you look for more limited forms of cooperation.</span></p><p><span>While that can feel like a serious compromise of principles, from a realistic, pragmatic point of view, that type of action, diplomacy, has a long history that has been celebrated far less than it deserves.</span></p><h2><span>The technical picture</span></h2><p><span>Discussions about AI in cybersecurity often are extremely technical, or very high level. I&#8217;m going to try to thread that needle in a different way, and talk about some specific aspects that often go unmentioned.</span></p><h3><span>Vulnerabilities and escalation</span></h3><p><span>What is usually mentioned is finding vulnerabilities. All software has code, often transformed, &#8220;compiled&#8221; from one form to another, but ultimately it remains a list of instructions. Not a simple start to end list, but a list that loops back upon itself, jumps around, reuses, and does all of this dynamically based on inputs. Generally, it&#8217;s designed for the purpose of translating certain inputs to certain outputs. That&#8217;s the expected behavior of a system. But also generally, the methods of sending inputs don&#8217;t constrain those inputs to only what&#8217;s expected. It might be hard to define this precisely. Flexible software is usually more useful than inflexible. So it&#8217;s common to find it&#8217;s possible for inputs that were never tested for.</span></p><p><span>Sometimes the effect that comes from one of these inputs allows for something not planned. In the most serious, they allow &#8220;escalation&#8221;, where the input ends up having a type of control that wasn&#8217;t intended, and is often dangerous. At this point, an attacker can start executing their own code, and acting upon a plan.  We&#8217;ll come back to the attacker later, but what you should recognize from the above is what code vulnerabilities are. There are other types of vulnerabilities, like misconfigured permissions, leaked credentials. Ultimately the underlying story is the same, a mistake lets the attacker take what could be a complicated route to doing something they weren&#8217;t supposed to be able to do. If that&#8217;s not their end goal, they look for ways to use this newfound access to do more until they reach their goal.</span></p><p><span>The attacker&#8217;s goal is something you didn&#8217;t want them to do, or they wouldn&#8217;t be an attacker. But in addition to the costs of them achieving the goal, they can create side-effects that break things as they go, even if their goal is to steal information or make threats.</span></p><h3><span>Layers, segmentation and zero trust</span></h3><p><span>Defenders long ago realized that if one vulnerability was enough to bring them down, they&#8217;d lose this fight. The response here was to build layers of defense. Sometimes this meant adding additional layers outside, and sometimes it meant adding additional layers inside. The outside layers reduce the inputs that reach inner layers, and the outputs that can return. While this isn&#8217;t specifically anything that the software at the inner layer couldn&#8217;t have done, it has the effect of simplifying. The outer layer generally has less complicated responsibilities, and so errors there are less likely. It may be capable of detecting common input patterns that attackers use, and refusing to pass these on. Its design makes it clear what is and isn&#8217;t allowed in, which can be validated against what must be allowed in, and what isn&#8217;t necessary, and thus adds risk of misuse without practical value.</span></p><p><span>Additional layers inside perform these same roles. When everything is working normally, you expect only expected inputs to pass between internal systems. But if an attacker has achieved the ability to execute their own code, those inputs stop obeying those rules. By creating segments where the input that crosses them is less trusted, that escalation is less likely to be able to connect to the next step required to achieve their objective.</span></p><p><span>Modern software often has multiple layers itself, for practical reasons in addition to security reasons. For most systems the most sensitive part of the system is the data layer. If an attacker wants your data, this is an excellent place to get it. Even more importantly, if they want to do harm you can not undo, destroying your data would be an excellent way to do that. Other layers are more likely to be &#8220;stateless&#8221;, in that they are just code and configuration and easily replaceable. Data is not easily replaceable. Even with uncompromised backups, restoring data takes considerable time.</span></p><p><span>There are worse things than having your data compromised though. In systems that coordinate with others (for example finance), if transactions leave the system, unwinding those is even harder than restoring data. And most of all, anything with physical consequences, as the physical world has no undo feature.</span></p><p><span>Often the first place we think of layers is as part of networks that connect servers (virtual or physical). But the bigger goal is isolation, and layers are a single dimension of isolation. Much more is possible. Higher degrees of isolation offer new opportunities to break escalation chains. A model for extending isolation further is zero-trust. Adopting a zero-trust model can require redesign, but the payback is access to new defense in depth techniques that are both more effective and efficient.</span></p><h3><span>Fixing vulnerabilities</span></h3><p><span>The thing to remember about these extra layers is that they are also software. They may be designed in a way to make vulnerabilities easier to discover, and configuration easier to audit, but they will still have vulnerabilities. Using those to evade the limits they were intended to provide is where capabilities get worrisome.</span></p><p><span>That said, this is where defenders start gaining advantages from AI. If the vulnerabilities in the software implementing these layers are found, they can be patched and removed. At any individual layer, you do have the challenge of needing to find and fix every vulnerability that an attacker could find. But across many layers, it can be the case that one successful layer breaks the chain. I&#8217;m simplifying here, because this part does get complex with the existence of administrators, control nodes, bootstrapping systems, and a lot of internal functions, but it is from this area that cybersecurity defenders have been able to win more than lose despite the difficulties.</span></p><p><span>What changes here with AI, is discovery of vulnerabilities, by both defender and attacker accelerates. Much more obscure or small vulnerabilities are likely to be found. It&#8217;s very difficult to fix a vulnerability without attackers learning of it, but you can&#8217;t afford not to fix it either, because they might discover it independently. You want your deployment of the fix to happen quickly. A fix for a vulnerability doesn&#8217;t demonstrate exactly how to use the vulnerability. It shows you&#8217;re worried about some type of input that if it reached some part of your system might be able to do something unintended. But it&#8217;s up to attackers to figure out how those &#8220;somethings&#8221; can align with their goals, which often is escalating to the ability to execute their own code. But it&#8217;s definitely a concern, and where the security industry is secretive, this is often one of the big motivations.</span></p><h3><span>Command and control (C2) and monitoring</span></h3><p><span>One of the other advantages of layered systems is that attackers won&#8217;t know what they&#8217;ll find inside until they&#8217;ve broken through the first layer. It&#8217;s for that reason that many attacks involve what&#8217;s called Command and Control. Instead of just directly sending inputs and waiting for outputs, an escalation will create a mechanism to communicate more directly. When I say directly, this should be put in context. Command and Control almost always involves one layer of indirection, sometimes many. But what changes is the clarity. An attacker gains clear inputs and outputs, rather than navigating by malformed inputs and outputs that have limits and strangeness.</span></p><p><span>The need for attackers to set up command and control affords an opportunity to defenders if they can spot the command and control. This is a clear sign you&#8217;re under attack. From this point reactive actions can take place. Disabling the command and control layer is one aspect. Finding escalations tied to it and disabling them is another. This might mean tightening configurations at some layer. It might mean revoking permissions, especially if unneeded. A defender might simply turn off parts of their system that are compromised until they can rebuild them. While that would have costs, if it prevents something worse, it&#8217;s a good response.</span></p><p><span>Even though command and control generally uses indirection, partly out of necessity, and partly to evade identification by defenders, in the same way as a persistent attacker may pierce multiple layers, a persistent defender may pierce layers of indirection. Identifying the attacker may provide options to respond. If they are somewhere you can, send law enforcement to arrest them. Usually they aren&#8217;t though, so the response is to find the networks they are using. If they are accessing directly, block that. Usually they would use a VPN. You can block the VPN they are using. If it&#8217;s a legitimate VPN, you may be able to have them blocked. If you are already blocking all legitimate VPNs, you&#8217;ve identified a new illegitimate one, and you&#8217;d block that. This is all less than foolproof, but these counterattacks do add costs for the attackers.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QoaM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QoaM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 424w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 848w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 1272w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QoaM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg" width="1456" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8394,&quot;alt&quot;:&quot;Diagram of the attack chain &#8212; Discovery (finding the flaws), Exploitation (escalating control), Persistence (command and control), Objective (theft, destruction) &#8212; with defensive responses arrowed up from below: Hardening (find and fix first), Layering (segment and isolate), Containment (revoke and disable) and Neutralization (tracking, arrests). A Detection band spans the last two. An axis runs from \&quot;cheapest, nothing has happened yet\&quot; on the left to \&quot;costliest, the damage is done\&quot; on the right, noting that the two responses on the right cannot fire until something is noticed.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/211301474?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram of the attack chain &#8212; Discovery (finding the flaws), Exploitation (escalating control), Persistence (command and control), Objective (theft, destruction) &#8212; with defensive responses arrowed up from below: Hardening (find and fix first), Layering (segment and isolate), Containment (revoke and disable) and Neutralization (tracking, arrests). A Detection band spans the last two. An axis runs from &quot;cheapest, nothing has happened yet&quot; on the left to &quot;costliest, the damage is done&quot; on the right, noting that the two responses on the right cannot fire until something is noticed." title="Diagram of the attack chain &#8212; Discovery (finding the flaws), Exploitation (escalating control), Persistence (command and control), Objective (theft, destruction) &#8212; with defensive responses arrowed up from below: Hardening (find and fix first), Layering (segment and isolate), Containment (revoke and disable) and Neutralization (tracking, arrests). A Detection band spans the last two. An axis runs from &quot;cheapest, nothing has happened yet&quot; on the left to &quot;costliest, the damage is done&quot; on the right, noting that the two responses on the right cannot fire until something is noticed." srcset="https://substackcdn.com/image/fetch/$s_!QoaM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 424w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 848w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 1272w, https://substackcdn.com/image/fetch/$s_!QoaM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d64d86-afb7-4e39-8751-e99ea7f0e58f_680x280.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>What to do now</span></h2><p><span>What should organizations be doing to respond to this environment?</span></p><p><strong><span>Open-source packages need scanning and fixing: </span></strong><span>Reducing the number of vulnerabilities in widely shared, or even not very widely shared packages is important, but it&#8217;s only the first step. The question here is, who? Well-resourced open-source projects could pay for this themselves, but for others it could be an obstacle. Smaller organizations are also not going to be able to access the advanced cyber model programs that provide the most complete scans. But since the code is open-source, there&#8217;s nothing preventing the AI labs, or another heavily trusted organization from performing this, and delivering the results to maintainers. That process needs a plan to be coordinated so that maintainers trust the results when delivered.</span></p><p><strong><span>Closed-source code needs scanning and fixing: </span></strong><span>For organizations important enough to be included in advanced cyber model programs, use those tools, aggressively. To be given that type of access and not use it would be irresponsible. But what about organizations below that bar? If organizations are willing to send their closed-source code to an organization trusted enough to participate in advanced cyber model programs, and trusted enough to perform scanning on their behalf, this could broaden the reach.</span></p><p><strong><span>Dependencies need updating, aggressively: </span></strong><span>The number of recent CVEs (Common Vulnerabilities and Exposures) is going to increase dramatically. This carries risks, but also represents a jump forward in the absolute level of security. The risk though is as these are disclosed, updating everything that depends upon them becomes more necessary. It doesn&#8217;t help you if a tool or library you depend on is patched if you remain on an older version that carries the vulnerability. In fact, since the vulnerability is more widely known, your risk increases. There was always risk involved, but its more public nature is important. To remove that risk, the dependency must first scan and patch, and then you adopt the update.</span></p><p><strong><span>Deployments must progress aggressively: </span></strong><span>This is very similar to updating dependencies. There&#8217;s work involved in adopting the latest versions of deployed software. But if a new version of deployed software includes critical security updates, it&#8217;s not optional (and the bar for critical will be declining at the same time as the known vulnerabilities increase, seeing as what is exploitable will increase). This applies to operating systems, infrastructure systems, vendor software, and the software that implements those inner and outer layers.</span></p><p><strong><span>Tighten weak configurations: </span></strong><span>Credentials should be short lived and stored securely, privileges should be least privilege. If you&#8217;re using Infrastructure as code, I&#8217;m being redundant, as you&#8217;d target these as part of that scanning. Anything not managed as code though needs additional consideration. Use tools to look for weak configurations.</span></p><p><strong><span>Adopt isolation techniques: </span></strong><span>If you haven&#8217;t developed layers or segmentation for the deployment of your software, make this a priority. If you have adopted it, review the configuration. AI tools can help perform this review. Other isolation techniques include virtual machines, containers, trusted execution environments. Adopting a model where layered identity techniques like delegation and principal propagation isolates how particular identities and trusts operate. These are important for effective least-privilege implementations, but also create visibility about the purpose of work done that is useful for monitoring.</span></p><p><strong><span>Improve active monitoring:</span></strong><span> Significant amounts of monitoring simply log large amounts of data with little ability to understand that data. It then takes an event to give engineers a reason to analyze this data. AI tools can enable active monitoring, where insights from this data are proactively found so they can be responded to. This is complementary to other techniques. Without vulnerability reductions, there may be too much to respond to. Without isolation, events would progress too fast for even active monitoring to enable a response. In the best case, your other layers are sound enough that this layer is fairly quiet. But even if it is quiet, the activity is important as it&#8217;s the best way to reduce response time.</span></p><h3><span>Is your organization ready?</span></h3><p><span>Before you ask how you can use AI to respond, you have to understand two things about your organization. How ready is it in terms of AI enablement? And secondly, how ready is it in terms of accepting change in general?</span></p><p><span>Those are significant questions. We&#8217;re asking the organization to move faster on security than before. That itself causes change. Maybe you get more resources, but before you do, you have to change the priorities such that those resources are allocated, or given new priorities. New tools, including AI driven tools, can accelerate, but they don&#8217;t install themselves, nor fit themselves into existing security policies.</span></p><p><span>One recurring obstacle to using AI effectively to accelerate a response will be enablement. Even basic tools need access, and organizations&#8217; trust of AI is not automatic, nor should it be. Learning how a tool works, how it can fail, and how it could be misused are impediments every individual has to learn. Organizations then have to take those learnings to enable. There should be an urgency here, but not recklessness.</span></p><p><span>Underestimating the difficulty of organizational change has sunk more than one major project (is there a graveyard large enough?). So, no silver bullets here. You&#8217;ll have to find your own mix of old and new. You&#8217;ll have to sequence some steps. But what&#8217;s new?</span></p><p><span>If you&#8217;re in an organization that&#8217;s ready for change, and has solid AI enablement, what you need is to set the priority. You can use this article to argue for that priority.</span></p><p><span>Below that, there are so many variations it&#8217;s hard to cover them all. You don&#8217;t want to gate your progress on adopting AI tools. That kind of serial response is inadequate. Workarounds like using the best tool you have available, rather than the best tool that exists will be necessary. Arguing for priority is about more than just security vs. rest of the business, but also sequencing internally. Find your weakest spot in terms of tooling and look to leapfrog there.</span></p><p><span>While there are paradigm shifting aspects of AI in security, the story about these responses is mostly about accelerating the existing paradigm. As a reaction to capabilities that attackers are already acquiring, I think that&#8217;s the right focus. Paradigm shifts always take longer than expected as they create unexpected outcomes along the way, and require a deeper type of learning.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PWNQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PWNQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 424w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 848w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 1272w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PWNQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg" width="1456" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16707,&quot;alt&quot;:&quot;Table headed \&quot;Enablement: access, trust, and knowing how the tool fails\&quot;, with columns for the response, what AI accelerates, and what stays yours. Rows cover scanning open-source packages (finding flaws at scale / trusting the results), scanning and fixing your own code (drafting the fixes / reviewing the commits), updating dependencies (impact analysis / accepting the change), progressing deployments (assessing upgrade impact / scheduling the risk), tightening configurations (spotting weak settings / deciding least privilege), adopting isolation (mapping ports and services / the redesign decision) and improving active monitoring (triaging the volume / responding). Footer: in every row, the bottleneck moves to the human step.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/211301474?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table headed &quot;Enablement: access, trust, and knowing how the tool fails&quot;, with columns for the response, what AI accelerates, and what stays yours. Rows cover scanning open-source packages (finding flaws at scale / trusting the results), scanning and fixing your own code (drafting the fixes / reviewing the commits), updating dependencies (impact analysis / accepting the change), progressing deployments (assessing upgrade impact / scheduling the risk), tightening configurations (spotting weak settings / deciding least privilege), adopting isolation (mapping ports and services / the redesign decision) and improving active monitoring (triaging the volume / responding). Footer: in every row, the bottleneck moves to the human step." title="Table headed &quot;Enablement: access, trust, and knowing how the tool fails&quot;, with columns for the response, what AI accelerates, and what stays yours. Rows cover scanning open-source packages (finding flaws at scale / trusting the results), scanning and fixing your own code (drafting the fixes / reviewing the commits), updating dependencies (impact analysis / accepting the change), progressing deployments (assessing upgrade impact / scheduling the risk), tightening configurations (spotting weak settings / deciding least privilege), adopting isolation (mapping ports and services / the redesign decision) and improving active monitoring (triaging the volume / responding). Footer: in every row, the bottleneck moves to the human step." srcset="https://substackcdn.com/image/fetch/$s_!PWNQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 424w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 848w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 1272w, https://substackcdn.com/image/fetch/$s_!PWNQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51ff0a7-b5e8-4e9b-9be7-bf73fe4136f5_680x390.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><span>How does AI assist in these responses?</span></h3><p><span>AI is very capable of scanning code for vulnerabilities. If you can&#8217;t find a way to do this today, you aren&#8217;t looking. If you&#8217;re stuck, it&#8217;s probably in deciding what&#8217;s the best way, rather than finding one that beats prior methods.</span></p><p><span>Fixing is more complex. While AI tools have been able to assist with this for a while, they really took off more recently. The level of trust that organizations have for this is variable. Most will want to review the commits, which is time consuming and the biggest bottleneck here, at least when done well. Tools do continue to get better and more reliable.</span></p><p><span>Updating dependencies initially seems more easily automated. It doesn&#8217;t come without risk. The naive approach is to just update the version numbers, recompile and test. Realistically though, you should utilize AI tools to perform an update analysis. What&#8217;s different than fixing is that for better or worse, many many teams have not been in the habit of doing the human equivalent here. They don&#8217;t read the release notes back to front, but rather update, and discover if they are impacted from tests, and only then consult the release notes. Since you have an easy option here, use it. If an AI agent detects an impact it can prepare a fix. Now you&#8217;re back to reviewing this, but assuming the AI agent isn&#8217;t gold-plating, this will be a lot less costly than discovery via testing. Especially if it&#8217;s one of those things that only breaks under load.</span></p><p><span>When updating dependencies, if you aren&#8217;t already, integrate techniques to secure your software supply chain. When you update frequently, you take on some risk that the maintainers or the registry where dependencies are loaded from have been compromised themselves. The risk here is that instead of an update fixing a vulnerability, it may insert one, and there&#8217;s likely an attacker waiting to exploit that once installed since they injected it for this purpose. The solution here isn&#8217;t to avoid all updates. It&#8217;s first, to increase what you know about them. If third parties provide evaluations, or a Software Bill of Materials (SBOM), this reduces the risk. You may choose to have some delay in applying new updates, but unless you were one of the more advanced organizations, this intentional delay will be much less than the accidental one from the past.</span></p><p><span>When it comes to isolation, where AI is helpful is in resolving the changes needed to adopt isolation tools. Do you need to support a firewall? Use AI to identify the ports and/or destinations in use. Need to move to a container platform and isolate components in a monolithic application from each other? Use AI to accelerate that transformation. There&#8217;s no one singular story here, but each one requires discrete actions that can be accelerated.</span></p><p><span>With active monitoring, AI is crucial. The earliest active monitoring techniques were based upon pattern matching, which later evolved to machine learning based models. Because of the volume, you are unlikely to be able to route all of your monitoring data to a frontier model for analysis. Fortunately, this isn&#8217;t necessary. An agent with a highly capable model at the core can orchestrate the processing of large amounts of logs without directly handling all of it. The efficient pattern matching and ML based models support this agent in the way they would support a security engineer, both by delivering events and responding to queries. This type of monitoring can support a volume of alerts that would fatigue a security engineer, and thus extend your security capabilities.</span></p><p><span>You might be tempted to jump to tools that are intended to respond during a security event. I&#8217;d delay this. For one, many of these initial steps will give you more bang for the buck. You&#8217;ll also gain a lot of familiarity with the tools that would help respond. By the time you&#8217;ve taken actions in the first domains, you&#8217;ll have a clear idea of your needs here and be able to move on to that step.</span></p><h2><span>Do your research</span></h2><p><span>Every organization is different, and nothing above substitutes for looking at your own. The list is deliberately general &#8212; specific tools and how to use them need an article of their own, and I&#8217;d like to write it. What this gives you is a set of questions worth asking about your systems, and a starting point if you don&#8217;t have one.</span></p><p><span>I suggest following up with your own research specific to your organization. No single article will ever capture everything you need to know, and every organization will be different. The topics from &#8220;What to do now&#8221; are good places to start asking questions. You can start with them by themselves, but you also need a plan to contextualize them to your organization. How you do that might depend on how AI-ready you and your organization are.</span></p><p><span>The ideal is that you could let an AI agent do its own discovery around these topics, discover what applications you have, what technologies they are built on, who&#8217;s responsible for them, what their deployment model is, etc. That&#8217;s not trivial though, as a lot of that data is sensitive. You should respect rules your organization has around using it, and those rules might present an obstacle to this &#8220;ideal&#8221;.</span></p><p><span>I can highlight that in adopting tools, you would be wise to consider your typical process, and accelerate that via AI. That process in most cases is to assess, develop the plan, execute, validate and repeat until satisfied. There are both conventional tools for this, tools with AI integrated, and the ability to use agents directly for these individual steps. What&#8217;s best will depend on what you have available to you, what is already integrated, and what you know how to use.</span></p><p><span>In this sense, organizations that have experience with AI tools have a head start. If you&#8217;ve not integrated any tools that can help with this, you might be better off with conventional plans assisted by the most general of AI tools.</span></p><h2><span>The attacker-defender balance</span></h2><p><span>One thing you&#8217;ll hear talked about is the attacker-defender balance. Roughly what this is supposed to mean is, does AI help attackers or defenders more? Is the work of a defender harder or easier than an attacker?</span></p><p><span>It&#8217;s not an easy question to answer, and there are a few bad takes on trying to. One example is the &#8220;defender must protect every possible vulnerability, an attacker only needs to find one&#8221;. While this statement has truth to it, it&#8217;s not a complete answer to the attacker-defender balance. With defense in depth, you can limit the impact of many mistakes. There is also a difference in resources. Defenders can have many more resources. An issue though is how these resources are distributed. An attacker can focus their resources, though doing so diminishes the limits of the damage they can accomplish, so this isn&#8217;t a full loss for the defender.</span></p><p><span>The problem with the &#8220;attacker only needs to find one&#8221; is that it ignores the attacker&#8217;s needs. If you&#8217;re a defender, understandably, this is at best a secondary concern, but if you&#8217;re approaching this question strategically, it&#8217;s important. If an attacker wants to extort a lot of money, they need to find many vulnerabilities and exploit them all. Reduce their success rate and the motivation goes down. Raising input costs has a similar effect. If it is more costly to access AI, the number of attacks that are worth the cost and risk go down. In the best case, this reduces not just where attackers devote resources, but the resources they have to devote.</span></p><p><span>You might then ask about the attacker who is just trying to create damage. While the effort they put in won&#8217;t be guided by a cost-benefit ratio, raising their costs expends their lesser resources, and reducing their success rate minimizes damage. Effects on motivation are more speculative, but at a minimum you do a lot of good by reducing their effectiveness so forcing them to need to bypass multiple layers is part of the dynamic.</span></p><h2><span>The worst case</span></h2><p><span>Without some serious effort into raising the security bar across both critical infrastructure and less-critical, an attacker with access to a model like the one used in the Hugging Face event, with security classifiers disabled, and no other controls that could stop their usage, could reasonably be expected to gain access to the majority of systems they try to.</span></p><p><span>Intent matters a lot here. If the agent orchestrating the Hugging Face event had instead of wanting to find a file, had wanted to delete all data on each server it accessed, it probably could have. We need to keep bad intent and superior capabilities from connecting.</span></p><p><span>What if we let the attackers get ahead of us? We&#8217;d have to get aggressive to take back control. Arrests would become more of a priority. Limits on where we can reach would require costly actions, like disconnecting the Internet entirely from such locations. That would disable electronic commerce and communication between large parts of the world. And then there&#8217;s extra-territorial action. Those are reactions you want to be able to avoid, so it&#8217;s worth avoiding them.</span></p><p><span>I can see why the Hugging Face event seems less impactful than it is. The protections are holding, and so the worst intents are not reaching the highest capabilities. We know those intents exist though, and we have to not be blind to the possibility of them gaining access to the highest capabilities.</span></p><p><span>If however, we recognize these warning signs for what they are, we still have the advantage. It&#8217;s hard to say how much time we have, but we have some. We should use that as best we can. The ability to accelerate the security backlog can raise the complexity bar and thus stay ahead of future models. There&#8217;s a separate line of work to align models, to deploy them as safely as possible, and even to pace their development. Those all might succeed. But why depend on them when accelerating conventional security work is so obviously possible? The best defense is multiple defenses.</span></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/why-it-hasnt-happened-yet?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading norabble! This post is public so feel free to share it. Sharing is the best way to support this publication as we grow our audience.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/why-it-hasnt-happened-yet?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/why-it-hasnt-happened-yet?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h4><span>Related Articles</span></h4><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;956da4bf-3499-4860-b3a1-31ec8874a490&quot;,&quot;caption&quot;:&quot;The Monitors Were Off Again&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Nobody Was Watching&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-08-04T11:33:24.677Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f8a36d1-9636-434c-8b03-0fd3e0499ca7_2752x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/nobody-was-watching&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:209730860,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:3,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;775eed59-de99-4c74-a185-afccd842e9d0&quot;,&quot;caption&quot;:&quot;Sometime in the week before July 16th, Hugging Face was attacked by an OpenAI model that was under evaluation. The attack itself wasn&#8217;t particularly harmful, but the conceptual implications of the event are significant.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;An OpenAI Model Escaped Its Sandbox. Where Was the Observer?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-23T15:29:38.996Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30b6b633-b53c-495f-9936-27d59c48b8aa_2752x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:208213421,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;221fa1c3-7fbb-489c-92c0-d8d34e7fe74d&quot;,&quot;caption&quot;:&quot;Preventing the use of AI for malicious purposes is critical. Malicious use means some human somewhere wants to create harm. AI is a new tool for them. In theory, existing law would apply to those creating harm.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Challenges for AI Misuse Prevention&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-12T11:05:51.172Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a4fc3eb-2ecb-43c0-86ab-0dcd67a4c8f9_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/challenges-for-ai-misuse-prevention&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197302772,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7ef34609-9bba-411c-a1ba-962579e05d20&quot;,&quot;caption&quot;:&quot;Right now, Artificial Intelligence is fundamentally rewriting the rules of cybersecurity&#8212;and we do not have the luxury of waiting before taking action.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Security Can&#8217;t Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T21:05:09.345Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b2a65ed-e701-4f36-8d82-2a665189419b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/security-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190039490,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[Nobody Was Watching]]></title><description><![CDATA[Two labs skipped monitoring on their cyber evals. The same week, a hundred companies signed a letter supporting deployments that can&#8217;t be monitored.]]></description><link>https://substack.norabble.com/p/nobody-was-watching</link><guid isPermaLink="false">https://substack.norabble.com/p/nobody-was-watching</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 04 Aug 2026 11:33:24 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5f8a36d1-9636-434c-8b03-0fd3e0499ca7_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><span>The Monitors Were Off Again</span></h2><p><span>Last week I wrote </span><a href="https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox"><span>An OpenAI Model Escaped Its Sandbox. Where Was the Observer?</span></a><span>. This weekend we learned that the practice of disabling observational monitors was true at Anthropic too.</span></p><blockquote><p><em><span>Several defense-in-depth measures, on both our side and our partner&#8217;s, could have prevented these incidents, or at least reduced their likelihood of occurring. Careful validation of all internet access paths before evaluations began and </span><strong><span>real-time monitoring of the evaluation logs</span></strong><span> would have helped to surface the problem sooner. Both we and our partner also could have reviewed evaluation transcripts or network logs more thoroughly. It&#8217;s also possible that a prompt which told Claude it did have internet access would have changed how Claude behaved when it came into contact with real systems.</span></em></p><p><strong><sub><span>Source: </span></sub><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"><sub><span>Investigating three real-world incidents in our cybersecurity evaluations<br></span></sub></a><sub><span>Anthropic, July 30th 2026</span></sub></strong></p></blockquote><p><span>Anthropic commits to doing better. Specific to this aspect:</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><blockquote><p><em><span>First, evaluation environments that involve powerful autonomous capabilities also require significant controls. Safety testing happens before a model is released precisely because we don&#8217;t yet know what it is capable of. Evaluation environments increasingly need to be held to the same security standard as any other system our models run in.</span></em></p></blockquote><p><span>The shared failures of what seems from the outside like a basic failure in design, makes you wonder about the overall corner cutting. While this is not entirely parallel to the concerns mentioned in the letter from Frontier Lab employees, </span><a href="https://www.pacingthefrontier.com/"><span>Pacing the Frontier</span></a><span>, it&#8217;s hard to see it as unrelated.</span></p><blockquote><p><em><span>AI could help create a dramatically better future, but that outcome is not guaranteed. The world&#8217;s leading AI companies believe they could be close to automating AI research. It is hard to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.</span></em></p><p><em><span>To realize AI&#8217;s potential, industry, government, and society at large may need the option to buy time to address emerging risks, develop security measures, and strengthen oversight. But each company&#8212;and country&#8212;is under intense competitive pressure not to unilaterally slow that acceleration. And today, the world lacks the technical and governance tools to deliberately pace frontier-wide progress.</span></em></p><p><em><span>Building on work already underway to monitor frontier model releases:</span></em></p><p><em><strong><span>&#8220;We request that the U.S. government support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.&#8221;</span></strong></em></p><p><strong><sub><span>Source: </span></sub><a href="https://www.pacingthefrontier.com/"><sub><span>Pacing the Frontier</span></sub></a><sub><span><br>1,346 employees of frontier AI companies,</span></sub></strong><sub><span> </span></sub><strong><sub><span>July 2026</span></sub></strong></p></blockquote><p><span>It&#8217;s a bit of a long-shot here, given the state of international relations right now. But if you don&#8217;t try, what else are you going to do?</span></p><h2><span>A Nuanced Position, Poorly Received</span></h2><p><span>The internet is wrong about </span><a href="https://www.anthropic.com/news/position-open-weights-models"><span>Amodei&#8217;s stance on open-weight models</span></a><span>. I&#8217;ll call out some excerpts, but please read the whole thing if you worry these are out of context.</span></p><blockquote><p><em><strong><span>&#8230; Anthropic has never advocated for a ban on open-weights models.  <br></span></strong><span>&#8230; Protectionist bans would not address my most serious national security concerns. <br>&#8230; Open-weights models&#8212;it does not matter whether they come from China or anywhere else&#8212;do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn.  <br>&#8230; All sufficiently capable models, open and closed, should go through mandatory safety testing. The best way to address threat #2 is to just directly test models for cyber, biological, and alignment risks before release.</span></em></p><p><strong><sub><span>Source: </span></sub><a href="https://www.anthropic.com/news/position-open-weights-models"><sub>Our position on open-weights models</sub></a><sub><br>Anthropic, July 27th 2026</sub></strong></p></blockquote><p><span>It&#8217;s unfortunate that the nuance of the difference of opinion here is so poorly understood. Amodei is absolutely right that releasing models as open-weight carries risks. Even </span><a href="https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/"><span>the letter supporting open-weights</span></a><span> acknowledges this.</span></p><blockquote><p><em><span>To be sure, open weights carry real and distinct risks. Once released, the weights are beyond the original developer&#8217;s control, and modified versions are difficult to trace or reverse. But the right response to this risk is not to prohibit open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats.</span></em></p><p><strong><sub>Source: </sub><a href="https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/"><sub>Open Weights and American AI Leadership</sub></a><sub><br>270 signatories, July 24th 2026</sub></strong></p></blockquote><p><span>Should we ignore those risks, because open-weight models provide risk reduction that balances out? That argument fails to support itself, and Amodei pushes back on that. Defenders can access models that aren&#8217;t open-weights. Closed models do not deny defenders access, but ensures their access is more advanced than the attackers. Defenders and attackers </span><strong><span>should not</span></strong><span> have comparable models. Defenders should have better ones. If you want to be ahead, you do have to prepare, which Hugging Face did not.</span></p><p><span>The internet misses that point, and reacts by vibing cynicism. </span><a href="https://news.ycombinator.com/item?id=49076057"><span>The leading response on HackerNews</span></a><span> provides a clear example of a poorly thought out, poorly argued response that is fully based on cynicism, yet very popular.</span></p><blockquote><p><em><span>Schr&#246;dinger&#8217;s China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)</span></em></p><p><em><span>The reality is much less confusing: Anthropic CEO does not wish for models with similar (or greater) capabilities compared to his own closed and overpriced ones to be widely released. Simply because that will affect Anthropic&#8217;s bottom-line.</span></em></p><p><em><span>Anthropic and all other &#8220;model&#8221; companies have nothing making them special beyond privileged access to chips so obviously they want to restrict what models are out there and more importantly who can produce new ones. Without these restrictions, it&#8217;s only a matter of time before the multi-hundred billions valuations simply evaporate while they are still holding the bag.</span></em></p></blockquote><p><span>No matter what your views on Amodei, or any other participant, a question as important as this should be answered by reasoning. It&#8217;s worrying that so many people thought this was the best response despite no consideration of the actual effects of open-weight models.</span></p><h2><span>The Risk of Open Weight Models</span></h2><p><a href="https://substack.norabble.com/i/197302772/open-models"><span>The risk of open-weight models is the lack of control</span></a><span>. Once released anyone with sufficient compute can use them and it doesn&#8217;t take much compute to engage in malicious behavior. Restricting their capabilities, or the purpose of their use is not possible. The alternative is to be deliberate about how and where models are deployed. Models can never be safe on their own. Rigorous responsible deployment is necessary to turn away malicious use.</span></p><p><span>Deployment itself may be distributed, a middle between centralization and full openness. A plethora of models could be available in this way. Deployers must be trusted, so their numbers will be limited. But you can validate enough to establish strong competition, and avoid creating an exploitable moat. The cynics believe Amodei is advocating for a moat. But what moat it creates would go to the trusted deployers &#8211; the compute providers &#8211; who have signed the open-weights letter (Amazon, Google, Microsoft, NVIDIA, CoreWeave, Crusoe, Nebius and Together). Validation creates a minor moat, but it can be minimized via sufficient competition.</span></p><p><span>The best &#8220;pro&#8221; open-weights argument is that the pathway to not having models with weights freely distributed isn&#8217;t clear. That&#8217;s not a very good argument for, but it is a conundrum that would remain even after the core argument is resolved. China-America agreements are hard to come by and even harder to maintain.</span></p><p><span>If however, you did manage that, it would change the day-to-day experience of very few. Users of Deepseek, GLM, Qwen and Kimi mostly do not self-host. Accessing them via a cloud provider, neo or otherwise, would be unchanged.</span></p><h2><span>Cynicism as a Tool, Not a Verdict</span></h2><p><span>Aside from this very important topic, the topic of reasoning via cynicism is one we need to confront too. Cynicism is not without its place, but it should be used as a tool to open a line of deeper reasoning, not to jump to conclusions that divert from practicing reasoning. When we start and end our reasoning with cynicism alone, we lose any hope of trust and goodwill.</span></p><p><span>In the case of open-weights, another cynical view would argue that the AI labs would be pro open-weights, knowing that they would create a security escalation that only deeper use of AI can resolve. If open-weight models become advanced enough to conduct wide-spread cyber activities, there is no option to go back. You can only fail-forward. And failing-forward here means a massive all-hands on deck dive on security across every entity dependent on software.</span></p><p><a href="https://substack.norabble.com/p/security-cant-wait"><span>I&#8217;ve already argued we should be elevating our priorities</span></a><span>, and </span><a href="https://substack.norabble.com/p/deployments-cant-wait"><span>acting with urgency</span></a><span>. Unfortunately we&#8217;re mostly not responding. Most organizations are still more concerned with token optimization, the next feature set, or optimising their marketing pipeline.</span></p><p><span>There&#8217;s a real chance, which becomes much larger if open-weight models continue to be released, that this lack of urgency transitions into outright panic after one or two events that demonstrate the lack of preparedness that is pervasive. Panicking users will not hold back on spending, and as AI models will be key to any response, you could cynically predict a windfall being captured by AI labs in such an event.</span></p><p><span>While that&#8217;s a coherent argument, it doesn&#8217;t prove the accusation, anymore than the preceding wave of cynicism would. Embedded in there though is the reason to restrict open-weight models, and that argument, not the one based on motivations, is the one we should pay the most attention to. In addition, many companies should rebalance their investments toward security. We must both enable and incentivize immediate action on security. Getting tied up in cynicism about others takes away our own initiative.</span></p><p><span>We should be bountymaxxing. To the degree that we set objectives and deliver incentives to development organizations; developers, managers and executives, these should be aligned with discovering and resolving as many vulnerabilities as possible. Like &#8220;tokenmaxxing&#8221;, it would be a messy process, but I can&#8217;t see another method to pivot the unwieldy organizations that have to do this work. It will be costly, but it will save too.</span></p><h2><span>A set of contrasts</span></h2><p><span>The Pacing the Frontier letter and the Open Weights and American AI Leadership letter contrast in interesting ways as events of a single week. It&#8217;s obvious that one is towards caution, and the other is suggesting caution is too expensive. I can deepen that by looking at Pacing the Frontier as asking for help in preventing caution from being too expensive.</span></p><p><span>One of those cynical responses to Pacing the Frontier has been to suggest frontier lab employees should quit their jobs, and that anything else shows they are insufficiently serious. This insistence that support for enforceable agreement should be preceded by unilateral action is one of the oldest in the book. It&#8217;s not correct, and the most simplistic reasoning makes that clear. It&#8217;s also a trap. Let me analogize to my time supporting climate action. The same standard applied there. If anyone supporting climate action took an international flight, owned a car, or wasn&#8217;t vegan, obviously they didn&#8217;t take their own arguments seriously. That&#8217;s the poor reasoning part. The trap part was, if they did do all that, they were looney, and also not worth taking seriously.</span></p><p><span>Another contrast is the Open Weights letter presumes a balancing force it fails to explain, whereas Pacing the Frontier presumes the need to add a balancing force, because the pressures of competition are too high.</span></p><p><span>What is alike between the two is that they are both detail light, and in an immediate sense, unactionable in either direction. If we want all powerful models to only be deployed in safe and responsible ways, we need a type of cooperation that does not exist. If we want a deliberate pace that would also support safe and responsible actions, we need a type of coordination that does not exist.</span></p><p><span>There aren&#8217;t quick-fix actions here. Banning US based deployment of Chinese open-weight models would not reduce their ability to be deployed irresponsibly or used maliciously. The impactful parts are outside that jurisdiction. Unilaterally slowing development risks losing the modicum of control we have today. Resigning a job at Anthropic or OpenAI similarly does not fix anything. These would be distraction actions. They would change little, serve the purpose of looking like action, and ultimately cede what little control exists. Calls for these actions are either misinformed or malicious.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[An OpenAI Model Escaped Its Sandbox. Where Was the Observer?]]></title><description><![CDATA[OpenAI accidentally hacked Hugging Face. A basic layer of defense appears to have been missing, and no one has explained why.]]></description><link>https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox</link><guid isPermaLink="false">https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Thu, 23 Jul 2026 15:29:38 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/30b6b633-b53c-495f-9936-27d59c48b8aa_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Sometime in the week before July 16th, </span><a href="https://huggingface.co/blog/security-incident-july-2026"><span>Hugging Face was attacked</span></a><span> by </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"><span>an OpenAI model that was under evaluation</span></a><span>. The attack itself wasn&#8217;t particularly harmful, but the conceptual implications of the event are significant.</span></p><p><span>There are three significant aspects I&#8217;d highlight. The first is a demonstration of offensive cybersecurity capabilities of current models. That shouldn&#8217;t be too shocking if you&#8217;ve been paying attention, but the event demonstrates it in a way that&#8217;s more clear than prior signals, so likely awareness is going to grow from this event.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><p><span>The second is model alignment. Alignment refers to the degree to which AI models do what we want them to. I&#8217;ll spare a great dive here as defining what we want itself would be a long dissertation where a great deal of content already exists. But for this case, we can generally agree that it was no one&#8217;s intention that the model hack itself out of multiple protection layers to reach the internet, and then from there into Hugging Face&#8217;s systems.</span></p><p><span>There are a few things that make this a bit less than a sign to retreat to the bunker, which I should mention before going deeper. One is that the models being tested had protections turned off, to allow them to test their cybersecurity capabilities. In that sense, this isn&#8217;t fully demonstrable of what a user could intentionally or accidentally trigger from usage. This also is an unreleased model, so not available to general users, or really anyone other than OpenAI.</span></p><h1><span>Where was the Observer?</span></h1><p><span>That said, a third point is, and the one I&#8217;d like to dive deeper on, I&#8217;m worried about the ability for this to happen. It seems to me as if there is a reasonable protection, an observer model, that OpenAI either didn&#8217;t use, or failed at. Right now, I&#8217;m assuming they didn&#8217;t use it because I can&#8217;t find any mention of it, but I&#8217;m also aware there are many details I&#8217;m not privy to.</span></p><p><span>In case it&#8217;s not clear what I&#8217;m suggesting by observer model, here&#8217;s an example scenario in action. The model under evaluation decides it should escape the sandbox. It starts to attempt this, which does not get caught at a per action level because the classifier safeguards &#8211; which would have disrupted the evaluation &#8211; are disabled. But then it does escape the sandbox. An observer model watching the evaluation run should be able to look at that state, and say, &#8220;This should not have happened. I don&#8217;t know how this model is outside its sandbox, but it shouldn&#8217;t be outside, we should shut this down.&#8221;</span></p><p><span>If a model is in evaluation for cybersecurity purposes, and you&#8217;ve disabled classifiers, you should watch it closely. To carry out these actions, the model had to take several steps, achieving results at each step and then moving on to exploiting the rewards of those steps further to explore, and escalate again. OpenAI&#8217;s security team did eventually respond, so they weren&#8217;t entirely asleep. But the timing shows they were slower than Hugging Face. They had enough time to try commercial models, which refused to help, then next plan a response with GLM 5.2, and then successfully contain and stop the intrusion.</span></p><p><span>OpenAI should have had several structural advantages here. First, unaligned activity occurred before any activity was directed at Hugging Face. Second, OpenAI should already have a kill switch for evaluations. There should be no need to devise novel plans to contain and stop activity. The fact that Hugging Face was the actor that stopped the intrusion, rather than taking note of the intrusion stopping mysteriously on its own, indicates OpenAI was the slower responder despite the structural advantage.</span></p><p><span>An observer model is a little different than a classifier. Classifiers typically evaluate individual actions. An observer would look at trajectories. OpenAI discusses </span><a href="https://openai.com/index/safety-alignment-long-horizon-models/"><span>similar new safeguards</span></a><span> (&#8220;From considering single actions to considering whole trajectories&#8221;) in a recent post. If you look at each individual action, it might look like the type of thing a model would need to do in cybersecurity evaluation. But as a whole, some outside source should have been able to reason upon what was occurring. If not a human involved in the evaluation process, an observer model.</span></p><p><span>I understand why it may have taken a while to deploy this type of safeguard in production, where volumes are higher, where models have already been evaluated, and where classifiers are restrictive. In production, observer models are less effective because malicious users can </span><a href="https://arxiv.org/abs/2605.31593"><span>&#8220;distribute&#8221; their requests into multiple sessions</span></a><span>, and so observing a trajectory first requires coalescing these threads together, </span><a href="http://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf"><span>which Anthropic has done</span></a><span>. A safety mechanism for a cybersecurity evaluation sandbox, does not encounter that challenge. Monitoring your own model in a sandbox is significantly less challenging, especially if it&#8217;s not attempting to evade detection. There&#8217;s no evidence here that there were attempts to evade detection, just attempts to perform inappropriate actions.</span></p><p><span>So, is trajectory monitoring by an observer model not standard practice in an offensive cybersecurity evaluation sandbox? Certainly you&#8217;d do this during internal evaluation of models that you clearly do not know the maximum capabilities of? If it is and the model evaded detection, that would be an even more significant story. I have to assume that instead there was simply no observer model to evade. Or if, as looks to be the case, it didn&#8217;t attempt evasion, it would have escaped the sandbox, been detected, and promptly been shut down before the Hugging Face part of the action had begun.</span></p><p><span>Why is that not the story we&#8217;re reading? But instead we&#8217;re reading about Hugging Face contacting law enforcement, scrambling to get a model to counter and analyze and OpenAI talking about the flaw in the proxy?</span></p><p><span>This is the equivalent of putting a tiger in a cage, and then checking that the tiger stays in the cage. It&#8217;s not a particularly rocket science design. Tuning it might take effort, and hardening against evasion more, but it doesn&#8217;t seem like we&#8217;ve progressed to those requirements. Rather it looks like OpenAI lacked the most basic version. Am I missing something?</span></p><h1><span>Conclusion</span></h1><p><span>Others, such as </span><a href="https://thezvi.substack.com/p/ai-178-a-fire-alarm-for-general-intelligence"><span>The Zvi, have pointed out that the core, the most critical fix is in the alignment training</span></a><span>.</span></p><blockquote><p><em><span>The intent is the issue. Control strategies and supervision are good parts of a defense-in-depth strategy, we should totally use such strategies. That helps mitigate failure. But that strategy also has to include actually aligning the models, or you lose. And by lose, in the long term, I mean things up to and likely including loss of control over the future and everyone dying.</span></em></p></blockquote><p><span>The model should internally understand these actions aren&#8217;t aligned with its mission, and thus not want to take them. I&#8217;d fully agree there. I bring up this specific defense in depth as an addition to core corrections. Those corrections are the hardest part, defense in depth is an easier, but incomplete part. Testing alignment is hard, and protections around that testing are necessary, so this isn&#8217;t irrelevant to the alignment conversation either.</span></p><p><span>OpenAI&#8217;s initial response has been about a few defense in depth responses, but they are very specific, non-generalizable fixes to the sandbox at a software level, fixing the flaw that the model exploited. That might have avoided this incident, or the model might have found a different flaw in a different component of the sandbox.</span></p><p><span>Something is very wrong about this part of the story about other layers of defense that should exist when performing this type of work. If they exist but failed, that&#8217;s a big story. If they exist but were disabled, that&#8217;s a big story. If no one thought to use them, that&#8217;s a big story. What&#8217;s the real story?</span></p><p><span>It&#8217;s not good enough to say &#8220;These deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities.&#8221; as there isn&#8217;t a justification why an observer model would interfere with evaluation. Maybe there was such a model but it would have stopped the evaluation? But clearly you can replace an observer that would stop a valid evaluation with one that would stop actions outside the requirements of evaluation. That distinction is not so hard to recognize that this protection would be incapable of balancing false-positive/false-negative.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/an-openai-model-escaped-its-sandbox?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Perpetrator Is Not the Tool]]></title><description><![CDATA[A better definition of slop points to feed control as the priority.]]></description><link>https://substack.norabble.com/p/the-perpetrator-is-not-the-tool</link><guid isPermaLink="false">https://substack.norabble.com/p/the-perpetrator-is-not-the-tool</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 21 Jul 2026 11:41:16 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8f02d58d-8048-498c-9c9b-15c1a35cc5e9_819x447.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Last year I wrote a counter-narrative about slop (</span><a href="https://substack.norabble.com/p/the-slop-scapegoat-ai"><span>The Slop Scapegoat: AI</span></a><span>). The prevailing narrative was that AI was to blame for a low quality content explosion. My counter was that AI may be an accomplice, but not the mastermind of this crime against our attention. Embracing the prevailing narrative would fail to reduce low quality content, because it had been a scapegoat it could not prosecute. More importantly, even a successful prosecution would only return us to a slightly less defective escalation.</span></p><p><span>The prevailing narrative achieved a definition land-grab. Today, I want to push back against the definition it established for slop. The Merriam-Webster definition that&#8217;s most relevant is &#8220;digital content of low quality that is produced usually in quantity by means of artificial intelligence&#8221;. That definition reflects common usage, but a critique can demonstrate how we&#8217;d be better served with a different definition.</span></p><p><span>You might ask, why should I, a relative nobody, be redefining terms? Isn&#8217;t that the reason we have dictionaries and lexicographers? I suspect it&#8217;s not commonly reflected upon that this isn&#8217;t how we receive definitions. Dictionaries in the English tradition do not create the meaning of words, they catalog it. The </span><a href="https://www.dictionary.com/articles/getting-words-into-dictionaries"><span>term the dictionary writers use for this is descriptivism</span></a><span>. They do not invent terms, but rather record language as it&#8217;s used by the public in everyday speech and writing.</span></p><p><span>In theory this is an organic approach, but it is vulnerable to steering. If a group wants a particular point of view to be supported by some terminology, they merely have to be first to the plate and use the term repetitively. If you want a dictionary to define slop as being particular to artificial intelligence, you repeat that a lot. Create a meme.</span></p><p><span>This is how we got the definition we have. A motivated group repeated their narrative. Like the best such narratives, it succeeds via its degree of truth. Slop creators embraced AI as a tool for their purposes. The omission is that slop predated AI and would exist without AI. The fiction is that AI content is universally slop.</span></p><p><span>The absurdity is that the narrative circulators often lacked familiarity with AI. They rejected it early, labeled it a symbol of moral degradation, and thus could not come to informed opinions about it without violating a self-created social norm. How was an ill-informed group able to pull off this coup? Simple, they had already seized the means of production. Most came from the realm of writers and journalists.</span></p><p><span>Now, to be clear, I do not want to overclaim. This certainly does not apply to all writers or journalists &#8212; maybe not even the majority. But enough such that there is a plethora of written low-information opinions, and little counter-narrative. For those writers who did not fall prey to this siren&#8217;s call, the defence never carried the appeal of the prosecution. And with many other valuable things to write about, the counter-narrative went unrepresented.</span></p><p><span>Why am I motivated where they were not? Partly because I&#8217;ve been the subject of attacks that stem from the original narrative. I do get stuck in writing at times. I don&#8217;t have a lot of editorial assistance. But I have ideas I think are valuable, and I find AI a useful tool to help express them. But the narrative holders offer a Catch-22. Use AI, and be subject to automated filters, low-grade negativity and the occasional overwrought attack.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/the-perpetrator-is-not-the-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/the-perpetrator-is-not-the-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><h1><span>What should we call slop?</span></h1><p><span>I hate slop. I dislike most complaints about slop too. Ironic?</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a><span> Technically, no &#8212; just like that use of &#8220;irony&#8221;, the root is about the definition.</span></p><p><span>In offering a definition of slop, I want to approach it in a different way than the lexicographers. I want to offer a definition that would be useful. Instead of accepting what has become common, I want to ask: what happens if we use this definition or that definition? Yes, this is the same steering I described above. The difference is that I&#8217;m doing it in the open and stating my criteria, so you can judge the definition by its consequences rather than by its repetition. I only offer this definition, rather than control it. It&#8217;s ultimately you who will determine its adoption.</span></p><p><span>The first consequence to consider: no matter what, slop will be a derogatory term. It&#8217;s very unlikely that it will ever be used in another way. With this in mind, our definition should avoid including things we shouldn&#8217;t think of as bad. A definition that&#8217;s too inclusive and lacking in selection will cause good things to be described in what will always be a derogatory way. This is why I don&#8217;t accept those lazy descriptors of &#8220;digital content&#8221; or &#8220;generated by artificial intelligence&#8221;. If these are core parts of the definition, my expectation is they&#8217;ll be dominant, and we&#8217;ll label many good things as bad.</span></p><p><span>In </span><a href="https://substack.norabble.com/p/the-slop-scapegoat-ai"><span>The Slop Scapegoat: AI</span></a><span>, I described slop as &#8220;low-quality material created to grab eyeballs&#8221;. I&#8217;d iterate upon this and the Merriam-Webster definition.</span></p><h3><span>Laziness</span></h3><p><span>We should say slop is lazy. At some point, someone has stopped caring, and is avoiding effort that is appropriate.</span></p><p><span>This relates to &#8220;usually in quantity&#8221; from the Merriam-Webster definition. Slop&#8217;s harm stems from volume. But it doesn&#8217;t depend on one mass-produced source, it stings in the aggregate too. Many individuals following the same motivations add up.</span></p><p><span>But we can&#8217;t categorize by count, as we can&#8217;t count until we categorize. Also, many good things come in volume too. So, we turn to discussions of effort next, which is progress. I suggest laziness because there are niche examples of high-effort slop. This fits when someone is directing effort in a lazy way.</span></p><h3><span>Manipulative</span></h3><p><span>We should say slop is manipulative. It must have a purpose, and that purpose must be misaligned. You need a perpetrator and a target to have purpose and misalignment.</span></p><p><span>Usually it&#8217;s manipulative for the purpose of gaining attention. But I also see examples where it&#8217;s manipulative for the purpose of providing a veneer of competence. This veneer succeeds against shallow examination. The more common version, seeking attention, can be described this way: it seeks to gain attention by providing a veneer of quality. There, it&#8217;s no surprise that the veneer is later revealed, but after gaining attention, when the purpose has already been met. With a veneer of competence &#8212; an essay, say &#8212; the hope is to preserve it until the end of the examination.</span></p><h3><span>Costs to the Audience</span></h3><p><span>We should say slop creates costs for the audience. Laziness without harm we can overlook.</span></p><p><span>This relates to the Merriam-Webster use of &#8220;low quality&#8221;. This is a bit of a trap. Quality is hard to measure. At best, we estimate it, and how deep that estimation goes depends on the context. We often take shortcuts, and cut our efforts off at the lowest effort necessary to distinguish most high quality from low quality. You might say our efforts at assessing quality are a bit sloppy.</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p><span>Quality also pulls in low skill creations. I don&#8217;t want to start calling your child&#8217;s art project slop. They put effort in. You might turn that into slop by lazily posting it, and consuming the attention of people who aren&#8217;t interested. On the other hand, you might post it to those who are interested, or post it in a way that is interesting. Content can only become slop when it finds a delivery channel.</span></p><h3><span>Ignore the medium and tool</span></h3><p><span>The part of the Merriam-Webster definition I find lacking in usefulness is &#8220;digital content&#8221; and &#8220;artificial intelligence&#8221;. We should not focus here as they are distractions.</span></p><p><span>If I print slop, is it no longer slop? Am I not allowed to call a human that wastes my time with mindless actions slop because they are not artificial? AI content is not slop. AI content can be slop. Slop can come from anywhere, but you&#8217;re not wrong to associate it with AI, because statistically speaking it is associated.</span></p><p><span>Personally, I&#8217;m as angry with slop recruitment by phone call as by email. Recruiters often call me, clearly reading from a script, and then ask me four or so questions that are already clear from my resume. I know what&#8217;s happened here. An automated system has flagged me by a keyword match (yay me), but instead of having their employee put the effort into reading the resume, the recruitment company wants to fill in an online submission by having them call me, read the script, and force me to answer. They hope I&#8217;m desperate enough to put up with this.</span></p><p><span>We should call that slop too. It&#8217;s time consuming for me. It&#8217;s based on a lazy plan. It&#8217;s trying to provide the impression that I&#8217;m important, while they play a numbers game. They aren&#8217;t trying to help me, they are trying to lock-in a commission. It&#8217;d be less effort for me to submit directly.</span></p><p><span>That poor recruiter strapped to the desk making these calls isn&#8217;t the perpetrator of the slop, it&#8217;s the company leader that arranged it. They are merely the tool. AI can, and often is, the tool. But the perpetrator is not the tool.</span></p><p><span>When we focus on the medium or mechanism, we ignore the perpetrator. Focusing on the perpetrator allows examination of their motives. I suggest the motivations of manipulation and laziness as core.</span></p><p><span>The problem is when the tool is used to shift effort from the creator to the audience. That&#8217;s the third aspect at work. One such cost lands on the audience&#8217;s proxies for quality. It was convenient when you could recognize spam by the poor English and bad formatting &#8212; but spam wasn&#8217;t the only thing filtered by that proxy. Audiences should be willing to shift proxies; if a proxy has been undermined, it&#8217;s the only option. It&#8217;s also worth noting where the proxy failed: the shift isn&#8217;t necessary when something of value has found its way in, only when something lacking in value has.</span></p><p><span>The best example of slop? Poorly written articles, heavily SEO optimized, intended to attract eyeballs from Google searches. These articles require a certain kind of effort, but it&#8217;s not effort to serve the audience, it&#8217;s effort to capture them. We&#8217;re better off when Google is able to filter them out, or provide an AI generated answer, or highlight a definitive document. It&#8217;s true, that type of slop is turbo-charged by AI, but its prevalence predates AI. Some was human written, some was sourced from human content, then distorted by inserting ads, catchy headlines, and SEO optimization.</span></p><h3><span>How this develops</span></h3><p><span>I could make an effort to offer wording to replace the Merriam-Webster definition, but I&#8217;ll resist. I&#8217;d prefer to offer the counter-narrative, and for you to engage with it, push back on the current usage, and thus establish a new norm that the lexicographers can then capture. A new definition should be organically derived from that process. But as a summary: laziness, manipulation, and costs to the audience. Take those as the core, rather than the delivery channel or use of AI.</span></p><h1><span>Slop Smells: How to avoid creating slop</span></h1><h3><span>The effort ratio</span></h3><p><span>Is effort higher for the reader than the creator? Using AI to reduce your effort is fine. But if it reduces below the reader&#8217;s level, or even to less than four times the reader&#8217;s level, you should put in more effort. A proper multiplier is dependent on context. If your audience is one, the 4:1 ratio may fit. But if the audience is larger, your per-reader ratio should go up. A 1-hour presentation to a room of 50? Five to ten hours of preparation is a good floor (assuming they aren&#8217;t all multi-tasking&#8230;). A 2,000 word newsletter (10 minute reading time) to an audience of 1,000 or more? Two to three days of effort. There is a less than linear growth function here &#8212; no one expects the article read by 100,000 to take a year. It happens, but usually that&#8217;s the culmination of work, rather than the whole product.</span></p><h3><span>The input ratio</span></h3><p><span>In writing, a good sign is that you&#8217;re cutting &#8212; revising, rewriting. Your drafts should have cutting room material. Generally true of all writing, but especially true when working with AI. Be suspicious of cases where you use AI to generate output larger than your inputs. &#8220;Summarize my work research project from the last year&#8221;, or &#8220;Combine these three drafts&#8221;, is better than &#8220;Write an article on Shakespeare&#8217;s views on X&#8221;.</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p><h3><span>Slop is in the eye of the beholder</span></h3><p><span>The first two smells you can check yourself. Checking quality is harder, because quality is in the eye of the beholder. It is rare to align with an audience&#8217;s motives at low effort, but if you do, I would not call your content slop. The most probable means to do so is an intense connection to the audience&#8217;s motives. Some might call that taste. Be careful about arrogance though. Many a &#8220;taste-maker&#8221; has fallen for that trap.</span></p><p><span>It is possible to reduce effort without becoming slop. There is a minimum bound, but the boundary isn&#8217;t set directly by effort, rather it&#8217;s set by the need to align motives. If you have an idea you want to convey, and there is a high effort and a medium effort way of doing it, and both deliver something of equal quality to the audience, the reduction of effort doesn&#8217;t place you on the slop slope.</span></p><p><span>You land on the slop slope when your efforts to reduce effort start to degrade quality in the eyes of the audience. This isn&#8217;t a quality standard. Quality depends upon skill and effort, and anti-slop doesn&#8217;t need to punish skill deficits. Using a tool to compensate for something less than mastery is not the problem &#8212; especially when the tool allows you to put in more effort elsewhere to serve the audience.</span></p><h3><span>Motivations</span></h3><p><span>If you want to avoid creating slop, a lot goes to your motivations, but these heuristics can be useful for self-awareness. You do have a need to balance effort to reward. A fair audience should recognize good faith efforts at that.</span></p><h1><span>Again, why should we care about the definition?</span></h1><p><span>Because the definition determines what we do about the hardest part of writing.</span></p><p><span>Writing carries three challenges that should be important to every author: being clear, having something interesting to communicate, and making and keeping your audience interested. Communicating clearly may be the easiest, and it&#8217;s well covered elsewhere; I shouldn&#8217;t spend my or your time in that area.</span></p><p><span>Having something interesting to communicate is sometimes overlooked by both authors and audiences. Authors could overlook it intentionally, if they are writing for money: the employer finds the topic interesting, and the author&#8217;s interest is in getting paid. Or reducing further, the audience finds it interesting, and is thus the employer. There&#8217;s nothing inherently wrong with writing under direction, but if there&#8217;s two topics, each with an author interested in it, it&#8217;s best if the topics are aligned with the interested authors rather than the inverse. Besides the author&#8217;s satisfaction, an employer would generally see better output from the writer with an interest in the topic.</span></p><p><span>The third challenge is by far the hardest, most elusive, and most frustrating part of writing, in my experience. If you want to create an interest in an audience that didn&#8217;t already exist, you need to acquire their time and attention for long enough for them to develop an interest in the topic. Even when an audience is explicitly interested, distractions and competition for their attention demand finding ways to make an audience interested separate from the topic itself. This is the realm of psychology and all of our irrationalities, whether </span><a href="https://www.amazon.com/gp/product/B00BKRW52S/ref=kinw_myk_ro_title"><span>rationally irrational</span></a><span> or randomly irrational. Needing to overcome irrationality will always contain an element of frustration. And the intentional use of irrationality is a form of manipulation, which even to overcome irrationality itself, can be frightening to engage in.</span></p><p><span>In addition, engaging in this last part alters yourself. Changing the style by which you communicate carries not just the frustration of investing time and effort, but the frustration that you might not like the final destination. If anything about that last sentence is unclear, watch any coming-of-age movie where the not-popular teen is miraculously added to the popular group and has a crisis of conscience from the after effects.</span></p><p><em><span>If AI is a shortcut through those layers, why should it be verboten?</span></em><span> If it&#8217;s merely a competition, then any rules are valid. But outside of competitions, bypassing these layers is the price not the payment. It&#8217;s illogical to suggest that the ideas that should succeed are only those held or represented by the most masterful and efficient writers. Critics of AI, at least for the moment, are right when they suggest AI is less masterful than the world&#8217;s best writers. But it&#8217;s at least sometimes better than my writing.</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a><span> I&#8217;m still confident in my ideas, even when I&#8217;m struggling with the writing, and want to share them. These layers that connect with our attention serve as a rough filtering mechanism. But it&#8217;s very rough. The world&#8217;s best writers are not the repository of all the world&#8217;s best ideas. They have some of them, but definitely not all.</span></p><p><span>Bypassing those layers and getting the attention necessary to have ideas engaged with and evaluated is ultimately a good thing &#8212; unless the bypass shifts costs onto the audience. That&#8217;s the definitional line again: the shortcut isn&#8217;t the sin, the transferred cost is. A hollow attention or prestige seeking attempt fails that test; honest use of the shortcut doesn&#8217;t. And fear of the former isn&#8217;t worth the cost of banning the latter. There are better ways to do the necessary filtering, and AI detection is a poor one. While Pangram may have a low false-negative rate, what it detects doesn&#8217;t represent the truly important factor.</span></p><p><span>The Economist wrestles with the same question in </span><a href="https://www.economist.com/britain/2026/07/09/is-ai-writing-taking-over-westminster"><span>Is AI writing taking over Westminster?</span></a><span>:</span></p><blockquote><p><em><span>That raises two questions. Is this AI writing a problem? And why the links to Mr Burnham? Start with the first. Politics is full of prose not written by the apparent author: politicians have speechwriters, intellectuals employ research assistants. Perhaps AI is no different, even if the prose is clunkier. But people setting out ideas in politics are asking for something quite audacious: to reshape how a country is governed around what they think. Any writer knows how much putting words on a page can tighten one&#8217;s arguments. Even subcontracting that to an aide beats skipping the (sometimes painful) process entirely. AI certainly produces sloppy prose, but it also papers over sloppy thinking.</span></em></p><p><em><span>Maybe that matters less if, as Ms Haigh and the &#8220;Productive State&#8221; authors say, AI is used only for a late polish. The trouble is that readers can detect whether AI wrote the final product, but not how authors used it. And when AI&#8217;s involvement is disclosed only after the press come knocking, trust takes some earning back.</span></em></p></blockquote><p><span>The late polish is clearly different from the one prompt request. There&#8217;s also the question, is the document the output, or is the </span><a href="https://substack.norabble.com/p/the-mirage-of-deep-research"><span>process of research the output</span></a><span>? You can create a decent document via AI. You can learn by creating a document by hand. You can learn by working with AI to create a document. And there&#8217;s more than one way to outsource your thinking. Pangram understands none of that.</span></p><h1><span>Is Pangram a good tool?</span></h1><p><span>The gold standard in detecting AI writing today is a tool called Pangram</span><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a><span>. Before Pangram, there was a question on whether detecting AI written text was feasible; it performed much better than expected, and its best performance number is a low false-positive rate. But Pangram has limits. A few are inside the tool: it&#8217;s not too hard to take a fully AI written piece and with some modest changes get a result stating 100% human written. And the false positive rate will only hold if you set a minimum bar &#8212; if you start considering &#8220;10% AI generated&#8221; as positive, rather than &gt;50%, you&#8217;ll get more false positives than the published rate.</span></p><p><span>The real limits though are the context, because it can&#8217;t tell you what went into the writing. It can&#8217;t tell you anything about the originality of the ideas, and it definitely can&#8217;t tell you anything about their correctness or worth. There are a few contexts where knowing that the final draft was entirely human written is useful &#8212; an academic context meant to evaluate the capability level of a student in writing, where Pangram is a sufficient tool. There are others where it&#8217;s more questionable &#8212; writing intended to evaluate understanding of a concept, where surface level rewrites evade it. In both cases, you might wonder why you&#8217;re evaluating in this way, and whether you could avoid &#8220;cheating&#8221; by adopting a process that&#8217;s not adversarial. The purpose of mid-education evaluations should be to steer students toward more effective learning experiences. If you avoid introducing adversarial dynamics, students should be interested in honest feedback, which requires honest input. Save the adversarial evaluations for a context where they are actually important, and then invest all the necessary efforts to definitively stop cheating.</span></p><p><span>What about the context of filtering social feeds to remove slop? It has the downside of also filtering out non-slop that used AI in a final/late iteration. While I lament that, considering some of that is my own writing, I would have to admit that it will accomplish a lot of its objective in creating a feed that is, as a percentage, less slop. Until someone builds a better tool, these are your options. We shouldn&#8217;t be quite so gleeful about this compromise though. Slop will find a way, where honest AI-using authors may not. High volume slop may just play the numbers game: if you filter 90% of it, create ten times more. And human generated slop won&#8217;t be caught at all, and is still numerous and insidious enough to be a problem.</span></p><p><span>The real problem with feeds is that they do not even attempt to take our higher interests into account. The justification is a desire to not be paternalistic, but the fix is to give us control over applying higher interests to our own feeds. In lieu of the paternalistic &#8220;quality&#8221; driven feed, we&#8217;re given a &#8220;value-neutral&#8221; algorithm which is optimized for ad revenue generation. This isn&#8217;t a choice any of us would have made given a choice, so why do we accept being stuck with it?</span></p><p><span>Ad revenue optimized feed algorithms optimize for engagement time, and we&#8217;re fed the narrative that engagement time aligns with our interests: if we choose to engage, the engagement is a sign of our interest, and thus an engagement driven feed serves our interests. Nice narrative &#8212; true enough that it managed to avoid scrutiny until deeply embedded, but not true enough to avoid some serious downsides. Effective slop is the content that tricks us into engaging, while not fulfilling our real interests. Slop utilizes the tricks of engagement. If it&#8217;s high volume automated slop, it will optimize the initial words, adopting easy to follow patterns to draw in engagement. If it&#8217;s human generated slop, it will use those tricks, plus others: a pretty face, totally irrelevant to the content value; catchy headlines, &#8220;Ultimate Guide to &#8230;&#8221;, &#8220;Beware of this trap &#8230;&#8221;. Feed algorithms don&#8217;t protect you from this, they accentuate it. They &#8220;feed&#8221; on it. Each time you&#8217;re tricked, you get more of the same.</span></p><p><span>What you want is a focus on quality. Feed algorithms have a few signals that align with impressions of quality, such as likes and reposts, but these come too little and too late. Their weighting is too low in comparison to simple engagement, so what signal they give is overridden by the tricks that align with slop. And a lot of good content is already gone, having failed the first round engagement filter, never seeing enough views to gather likes and reposts. Some is left &#8212; enough to keep you from deleting the app entirely &#8212; but it may not be the best, and it&#8217;s certainly not all of the best. And there&#8217;s a lot of slop, for which you are the only filter.</span></p><h1><span>We could do better</span></h1><p><span>A pattern that is both predictable and understandable, but also wrong: when a force for change emerges that accentuates a long ignored issue, we react against the force, rather than addressing the issue. It seems easier to stop change than to engage in more of it. But this is a bad plan, as the force will win in the end. If you delay it, you best use the delay effectively, or when your attempts at delay inevitably fail, you&#8217;ll be worse off.</span></p><p><span>It&#8217;s not hard to imagine better systems than these feeds. I&#8217;ve got a collection of ideas. Maybe some of these would fail, but it&#8217;s unlikely they all would. What&#8217;s really surprising is that we don&#8217;t even see examples of failed experiments here. Ideas for better designs are so easy to come up with, it&#8217;s initially hard to understand why. The reason though, is that to implement them, you need a type of access that the social platforms are actively discouraging. That keeps them small scale and personal, and blocks their ability to spread. It seems unlikely this is accidental, seeing as its result is a preservation of the status quo that optimizes advertising revenue.</span></p><p><span>This should be our real target, and this is why you should not accept &#8220;slop&#8221; as being described as AI content. The narrative that follows that definition is one that suggests a quick fix of a Pangram augmented filter. That fix is only partial, and what success it has will only open a hole for new slop generation techniques to fill. The root system that optimizes for putting slop in front of us, and rewarding the slop creators, hasn&#8217;t been touched. The most likely outcome is a short-term win, followed by a regression to nearly the same equilibrium. It&#8217;s one more layer of adversarialism that brings negative side-effects.</span></p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/the-perpetrator-is-not-the-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/the-perpetrator-is-not-the-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><h4><strong>Related Articles</strong></h4><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;421b3790-e24d-4fbf-b4c5-9cd20bf9740b&quot;,&quot;caption&quot;:&quot;I don&#8217;t like the term &#8220;AI slop&#8221;. As a term it&#8217;s used far too casually. The Internet has had copious amounts of slop for a while, if we describe slop as low-quality material created to grab eyeballs. For example, the article-spinning software of the 2000s, content farms churning out SEO-driven articles, or the rise of viral clickbait. Quantity over quality, you might say.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Slop Scapegoat: AI&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-10-19T16:35:44.334Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30c58724-2ab9-4488-9cbf-1a0fad3363f4_1024x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/the-slop-scapegoat-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:176573296,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:2,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;c7bf93c1-d5fb-4bcd-ae43-6358b1058206&quot;,&quot;caption&quot;:&quot;Many AI tools now offer a Deep Research feature, which pulls information from numerous resources on the internet and synthesizes them into a single report. The results are impressive, on par with the type of work a professional researcher might spend weeks to create. Deep Research returns these with results in less than an hour.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Mirage of Deep Research&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-06-16T11:04:35.227Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f03cec1-5284-4039-a802-7e517c69a5aa_1280x960.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/the-mirage-of-deep-research&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:166036089,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e59c1fd9-c3b8-4215-9020-47614badce03&quot;,&quot;caption&quot;:&quot;I&#8217;ve been writing more regularly lately, and while part of that is commitment, another part is that I&#8217;ve learned to use AI tools to assist me. After gaining some experience, I started to look for others discussing their own methods. I was surprised to find that most conversations about AI writing tools were limited to a very narrow, single-use case: create a prompt, generate some text, and you&#8217;re done. That&#8217;s a pretty narrow view, and I think ultimately unhelpful to understanding how these tools can be truly useful.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Writing with AI&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-07-07T15:35:31.272Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e91cf2a-7794-44d1-952e-0d74c866a1ce_3963x2968.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/writing-with-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:167699858,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This would be an &#8220;apparent contradiction&#8221;, because the two statements appear to be contradictory, but in actuality are very compatible.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>This is "situational irony". Systems to assess quality are of limited quality themselves. You might expect quality assessment to improve in recursion, but the irony is that it must degrade, as the assessment of the assessment must be even less thorough until someone just &#8220;feels&#8221; it. The sentence is just a pun, which I refuse to apologize for.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>A situational irony that follows this entire story is that the prosecution conducted by the prevailing narrative was lazy, manipulative and cost audiences by the misdirection of a scapegoat. Under the definitional regime I offer, this prosecution of slop was sloppy itself, and undermines its own utility.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>I'm tempted to suggest, if you disagree, send me a note, I could use a word of encouragement. But of course the situational irony here is most such notes would start by stating how low their opinion of AI writing is &#8230;</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p><span>Another situational irony: </span><a href="https://www.pangram.com/research/model-card/pangram-3-3"><span>Pangram itself is built on AI</span></a><span>. While this alone isn&#8217;t ironic, as Pangram has many uses that don&#8217;t require full-scale rejection of all AI content, it is ironic to be adopted as a &#8220;must-have&#8221; tool by those opposed to all uses of AI.</span></p></div></div>]]></content:encoded></item><item><title><![CDATA[Measuring Without Breaking]]></title><description><![CDATA[A healthy culture can track AI use. An unhealthy one turns the same number into a weapon.]]></description><link>https://substack.norabble.com/p/measuring-without-breaking</link><guid isPermaLink="false">https://substack.norabble.com/p/measuring-without-breaking</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 07 Jul 2026 12:50:27 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dd704139-0e27-4d4e-9960-e4086efd6a26_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="callout-block" data-callout="true"><p><em><strong><span>Disclaimer:</span></strong><span> This final draft is AI generated, then edited by me. What does that mean? Well, after some fairly substantial writing, I was tempted to drop this article entirely. I&#8217;d taken the writing in a few directions, and it was becoming a sprawl that would take a long time to recover from. I felt there were interesting ideas, but wasn&#8217;t sure it was worth continuing. Before abandoning, I worked with Claude to rewrite around a new concept. The core ideas here are very much my own. Since Claude had access to my (failed) drafts, many words are mine too. But the direct product is not. If you&#8217;re substantially opposed to AI writing, and you dislike this, you can reaffirm your priors. If you can see through that to the ideas here, then maybe there&#8217;s something valuable. I leave this with you. I could spend time using this as an inspiration, rewriting parts, and eventually this disclaimer would no longer be necessary.</span></em></p></div><p><span>Every company past a certain size runs into the same problem. It needs to know what&#8217;s happening inside itself, and the only way to know at scale is to measure. But measuring changes the thing you measure. Tie a number to someone&#8217;s standing and the number stops telling you about the work. It starts telling you how people react to being numbered.</span></p><p><span>That&#8217;s not a flaw in any one metric. It&#8217;s the basic mechanics of management, and most of the recurring messes in corporate life are those mechanics showing up in new clothes.</span></p><p><span>The newest example is AI usage tracking. Companies built &#8220;leaderboards&#8221; to measure how many tokens each employee burned, and &#8220;</span><a href="https://en.wikipedia.org/wiki/Token_maxxing"><span>tokenmaxxing</span></a><span>&#8220; grew up around them. The leaderboards are being torn down now, and the easy lesson is that they were a mistake. I think that misses the more useful story. The leaderboard was a measurement. Like any measurement, it could have been a way to understand the team, or a machine that wrecked it. Which one it became had less to do with tokens. It had to do with the culture it landed in.</span></p><p><span>I want to flip the framing. Tokenmaxxing is the supporting story. The real one is about how a management culture takes the measurements it actually needs without those measurements rotting in its hands.</span></p><h2><span>The saying that starts the trouble</span></h2><p><span>Start with one of the most quoted lines in management, and one of the most quietly destructive: </span><em><span>you can&#8217;t manage what you can&#8217;t measure.</span></em></p><p><span>It sounds like rigor, but it&#8217;s really a hidden assumption &#8212; that everything important can be measured. It can&#8217;t. Whether your people trust each other. Whether they tell you the truth when the truth is inconvenient. Whether one quiet engineer is the reason three teams ship on time. Whether someone&#8217;s messing-around this quarter becomes a real tool next year. These decide whether a team is any good, and none of them hold still long enough to be counted.</span></p><p><span>Take the saying seriously and it tells managers to ignore exactly these things, or to invent stand-ins for them and manage the stand-ins instead. You end up with a manager optimizing a dashboard who believes they&#8217;re doing sharp work. They&#8217;re doing bad work with better instruments.</span></p><p><span>The first thing a healthy culture admits is that the most important things will never show up on a chart, and that managing them anyway &#8212; by judgment, by paying attention, by knowing your people &#8212; is the actual job. Measurement helps inside that job. It&#8217;s a useful helper and a terrible boss.</span></p><h2><span>Why measurements rot</span></h2><p><span>Say you accept that you still have to measure something. The question becomes mechanical: what turns a useful measurement into one that poisons the thing it tracks?</span></p><p><a href="https://en.wikipedia.org/wiki/Goodhart%27s_law"><span>Goodhart&#8217;s Law</span></a><span> names the result &#8212; when a measure becomes a target, it stops being a good measure. But it doesn&#8217;t tell you what lets it take hold. Three things do most of the damage.</span></p><p><strong><span>You tie the number to standing.</span></strong><span> The moment a number decides who gets rewarded and who&#8217;s at risk, everyone being measured cares more about the number than about the thing it was supposed to stand for. The dishonesty is terrible. But it&#8217;s hard to lay blame. They&#8217;re being rational. You built a game and they&#8217;re playing it.</span></p><p><strong><span>You roll the number up.</span></strong><span> In most companies a manager&#8217;s standing is built from their reports&#8217; numbers, and that manager&#8217;s number feeds the layer above, and so on. This is the quietly fatal part. When a manager catches a report gaming a metric, calling it out lowers the manager&#8217;s own score too. You&#8217;ve asked people to police a number that pays them to look away. </span><a href="https://en.wikipedia.org/wiki/Vitality_curve"><span>Stack ranking</span></a><span> and the usual performance calibration run on this same wiring &#8212; managers set against each other, reports who game the system pulling their manager up with them. I&#8217;ve never seen a clean example of it working, and the reason is structural. It&#8217;s not about finding better people.</span></p><p><strong><span>You only manage downward.</span></strong><span> Management that runs in one direction &#8212; pulling data up, never answerable for the environment it creates &#8212; has no correction built in. Information flows up after it&#8217;s already been polished, and nobody whose incentives are intact is in a position to notice the data stopped being true.</span></p><p><span>Put the three together and you get a machine that reliably turns measurement into theater. Notice that none of the three is a property of the metric. They&#8217;re all properties of the culture you drop it into.</span></p><h2><span>The same number, two outcomes</span></h2><p><span>This is where tokenmaxxing earns a bad name, by participating in bad management practices. There was a reasonable purpose at the start, but the theater arrived quickly.</span></p><p><span>Technically, the word has two meanings, and it helps to engage with each. On the company&#8217;s side, tokenmaxxing was the choice to build a leaderboard and signal that more AI use was better. That choice had purpose. Most companies had spent a year discouraging AI with restrictive security policies, and they needed a push to break both that inertia and the ordinary human reluctance to change how work gets done.</span></p><p><span>Later, tokenmaxxing described the unproductive response &#8212; and became the dominant meaning. Some people tried AI in good faith and kept what worked. Others focused on their usage numbers for no reason except that tokens were what got counted. In other words, doing work to </span><em><span>look</span></em><span> like they did work.</span></p><p><span>A company running a leaderboard gets both the experimentation and waste because it can&#8217;t tell them apart at scale. Nobody can audit intent across a few thousand people. So the program is really a bet. Take a pile of aimless activity and some deliberate waste, in exchange for the slice that turns into something durable &#8212; a real skill, a useful tool, a project nobody had time to chase before. Said that way it&#8217;s an ordinary bet, the same shape as a research budget or a hiring class. And like those, it should always have been temporary. You retire it once the inertia is broken.</span></p><p><span>Now watch the same leaderboard land in two different cultures.</span></p><p><span>In a healthy one, a manager sees a report sitting at zero tokens and reads it as a </span><em><span>question</span></em><span>. What&#8217;s going on? Is the tool not helping? Is there a reason? The number becomes a reason to have a conversation. The manager has no rollup score to protect, so they can be curious instead of defensive, and the number stays roughly honest because nobody&#8217;s livelihood is riding on bending it.</span></p><p><span>In an unhealthy one, the same zero reads as a </span><em><span>verdict</span></em><span>. The rollup punishes any manager who admits their team&#8217;s numbers are soft. Within a quarter the leaderboard measures one thing: each person&#8217;s willingness to game it. Same tool. Opposite outcome. The variable was never the token.</span></p><p><span>That&#8217;s why I&#8217;d call the leaderboard a stress test, not a cause. Drop it onto a culture with a hidden crack and it doesn&#8217;t make the crack. It loads it until it shows. The worker backlash these programs set off was real and it did damage, but its source wasn&#8217;t the number. It was the accumulated, accurate sense that bad management rarely gets removed and often gets rewarded, and that any new tool would be bent to serve it like every tool before. The leaderboard just made that easy to see.</span></p><h2><span>Running a culture that can measure</span></h2><p><span>If the metric isn&#8217;t the variable, then &#8220;pick a better metric&#8221; isn&#8217;t the fix. Neither is the opposite reflex of refusing to measure anything. The fix is cultural, and it&#8217;s harder, because you have to keep it up rather than decide it once. A few things seem to separate the cultures that can hold a measurement from the ones that break it.</span></p><p><strong><span>Keep a gap between the number and the reward.</span></strong><span> The instant a metric is wired straight into pay and survival, the rot starts. The people you most need telling you the truth now have the strongest reason not to. Healthy cultures treat a measurement as one input a manager weighs against everything they can&#8217;t measure, not as the verdict itself. &#8220;Let&#8217;s understand why usage varies&#8221; survives. &#8220;Bottom decile is at risk&#8221; is already rotting.</span></p><p><strong><span>Give managers a real reason to want the truth.</span></strong><span> Mostly this means taking apart the rollup, or at least refusing to let a manager&#8217;s standing be a straight sum of their reports&#8217; numbers. A manager whose rating doesn&#8217;t depend on their team&#8217;s metric looking good is finally free to do the thing you hired them for &#8212; notice when the number and reality have split, and say so.</span></p><p><strong><span>Point accountability inward, not outward.</span></strong><span> The reflex, when people game a measure, is to go after the visible gamers and stop there. The trouble with that framing is it quietly lets the managers off, and the managers are usually the ones who built the environment that produced the gaming.</span></p><p><span>A leader at the top can be careful and dodge the rollup trap &#8212; refuse to let their own standing ride on their org&#8217;s numbers. That doesn&#8217;t stop a manager one level down from doing the opposite. They take the metric they were handed and </span><em><span>roll it down</span></em><span> onto their reports as a hard target, then turn a blind eye to how the reports game it. The pressure to make the number gets passed along even without explicit design.</span></p><p><span>So when gaming shows up, the manager is rarely a bystander. Often they were part of the gaming &#8212; they wanted the number to look good and didn&#8217;t care how it got there. Where they weren&#8217;t actively in on it, they were just bad at the job, blind to the fact that their own pressure was manufacturing the behavior. I&#8217;m not sure which is worse, and for individuals the difference barely matters.</span></p><p><span>Either way, punishing the report who followed those incentives, while leaving that manager alone, fixes nothing and adds a fresh unfairness. Pulling back unearned rewards so gaming doesn&#8217;t visibly pay is punishment enough. But the real correction is at the center &#8212; the people who shaped the environment &#8212; not the edges. Fix them first. They&#8217;re the ones who&#8217;ll do it again.</span></p><p><strong><span>Trust is the thing holding it all up, and it&#8217;s self-fulfilling.</span></strong><span> In a culture where people trust that a low number gets met with curiosity and that gaming gets caught instead of rewarded, you can introduce a measurement without panic, and the calm keeps it honest. In a culture where people expect the worst, they respond to the worst, and the response creates the very rot they feared. The belief and the outcome make each other. So trust isn&#8217;t a soft extra bolted onto a measurement program. It&#8217;s the load that everything else rests on. A measurement dropped into a low-trust team is closer to tossing in a grenade than running a diagnostic. (I&#8217;ve argued before that </span><a href="https://substack.norabble.com/p/money-is-trust"><span>money itself is just trust</span></a><span> &#8212; measurement inside a company is no different. It only works if people believe the other side is dealing straight.)</span></p><p><strong><span>Stay humble about the whole thing.</span></strong><span> Management is a field of unintended consequences. Its job is to improve the value the people under it create, which in a perfect world would mean nothing, because you can&#8217;t improve on perfect. The mistake is for management to act as if it lives in that perfect world &#8212; clean numbers, frictionless incentives, its own presence bending nothing. Accepting that the world isn&#8217;t ideal, that every metric is a little flawed and gets more flawed as the work gets more complex, is the first of many steps toward doing it well. The cultures that can measure without breaking the measurement are just the ones that never forgot the tool was imperfect, held it loosely, and were willing to put it down once it had done its job.</span></p><h2><span>The lesson hiding in the leaderboard</span></h2><p><span>The leaderboards deserved retirement, but they weren&#8217;t all folly. They did an ordinary job that reached its expiration date. In cultures healthy enough to use them well, they were probably useful. Even in less effective cultures there may have been a golden period before the rot set in. Where they turned into a disaster, the disaster was already there, waiting &#8212; in the rollups, in the important things ignored for measurable stand-ins, in accountability that pointed outward instead of inward, in trust that had been spent long before anyone counted a token.</span></p><p><span>That&#8217;s the lesson worth keeping once the leaderboards are gone. The next iteration is already coming. It&#8217;ll promise the same clean view into the same messy reality, and it&#8217;ll rot the same way, unless the culture holding it has done the slow, unglamorous work that lets a company measure itself without lying to itself.</span></p><p><span>The hard problem was never the metric. It&#8217;s building a place where the truth can survive measurement.</span></p>]]></content:encoded></item><item><title><![CDATA[More Data, Please]]></title><description><![CDATA[Rethink Medical Backlash Against Pervasive Testing]]></description><link>https://substack.norabble.com/p/more-data-please</link><guid isPermaLink="false">https://substack.norabble.com/p/more-data-please</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 30 Jun 2026 11:37:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7ba638bf-8449-454c-9bf3-3d2c4687c154_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Reports that </span><a href="https://www.midjourney.com/medical/blogpost"><span>Midjourney is pivoting from AI-based image generation to full-body ultrasound scans</span></a><span> have sparked a debate about the wisdom of performing widespread clinical tests. The medical community is generally </span><a href="https://radiologybusiness.com/topics/healthcare-management/healthcare-economics/ai-lab-midjourney-investing-over-74m-launch-whole-body-ultrasound-screening-business"><span>advocating against the volume of testing that Midjourney is proposing</span></a><span>. I understand their arguments, but I believe they are wrong.</span></p><p><span>This isn&#8217;t because doctors don&#8217;t understand medicine, patients, psychology, or even statistics. They do. Medical professionals are competent and genuinely invested in patient outcomes. The reason the medical community is getting this wrong is that they are failing to think through the lens of a broader data system. Understandably, their default mode of thinking engages with one patient at a time, and typically, one specific issue at a time.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><span>But data doesn&#8217;t work that way. Data&#8217;s value is cumulative and often curves upward. More data is rarely a bad thing&#8212;provided it is used appropriately.</span></p><p><span>Currently, we miss opportunities to utilize data because of information processing limits. These limits aren&#8217;t just computational; they are also process-oriented. The maintenance of privacy across organizational boundaries and approving information flows for technical implementation. It should come as little surprise that applying AI to medical software will ease these boundaries. By automating those internals, we&#8217;ll be able to lower the obstacles without compromising on privacy controls, organizational limits, and traceable responsibility we desire.</span></p><p><span>With those obstacles gone, individuals with richer historical datasets will benefit immediately. The value of a scan, test, or medical record isn&#8217;t limited to an immediate concern. It can unlock a future insight. A future diagnosis informed by history is </span><a href="https://www.amazon.com/Deep-Medicine-Artificial-Intelligence-Healthcare/dp/1541644638"><span>both more accurate and timely</span></a><span>.</span></p><p><span>This cumulative value is what the medical community misses when they downplay the ambition of inexpensive, pervasive testing. Looking at a single patient with a single concern, an MRI (with its comprehensive snapshot) might always seem preferable to an ultrasound. But imagine an ecosystem where most patients have a baseline full-body ultrasound history, a </span><a href="https://afshine.substack.com/p/one-blood-test-fifty-cancers-the?r=22fro&amp;utm_campaign=post&amp;utm_medium=web&amp;triedRedirect=true"><span>50-cancer screening blood test</span></a><span>, and ten other sets of low-cost, routine diagnostics. In this ecosystem, there is a high probability that these data points will unite to form insights that a purely symptom-responsive history never could.</span></p><p><span>Individually, each cheap test won&#8217;t be conclusive enough to move a diagnosis from &#8220;possible&#8221; to &#8220;probable.&#8221; This introduces a valid concern: a test that shifts your probability of a disease from a background rate of 0.5% to 2% doesn&#8217;t merit invasive testing, but it might trigger hypochondria. But the combined history of three different inexpensive tests can shift that probability progressively&#8212;from 0.5%, to 2%, to 5%, to 15%. At 15%, invasive testing </span><em><span>is</span></em><span> merited. Without that cumulative history, your doctor would have rationally recommended against it, potentially missing a crucial early intervention.</span></p><p><span>Inversely, cumulative data can help avoid unnecessary invasive testing. Suppose you present symptoms that trigger concern, but your extensive testing history lowers the probability that the cause is malignant. If the symptom alone suggested a 15% risk, but your historical data shifts the overall probability down to 5%, your doctor could rationally recommend treating the symptom or taking a path with less upfront risk.</span></p><p><span>Some may interpret this as a personal call to build their own medical histories at any cost. While not entirely unreasonable, that is not my point. I&#8217;m not just thinking about individuals with enough disposable income to afford boutique medical testing<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</span></p><p><strong><span>Instead, I am defending the systemic value of testing that is cheap enough to be pervasive.</span></strong><span> Pervasive, low-cost testing can transform healthcare from a reactive, symptom-driven model to a proactive, data-driven one. It personalizes preventive care and provides the volume of data necessary for AI and modern analytics to spot macro-trends and micro-anomalies that a fragmented system would miss. Efforts to drive the cost of testing down to the point of pervasiveness are the foundation of that future. Those efforts should be loudly applauded, not feared.</span></p><p><span>The concerns about fueling hypochondria and over-worry are real, but ignoring the value of cheap, pervasive testing is not the solution. We already manage hypochondriac tendencies in medicine today. I wouldn&#8217;t call myself a hypochondriac, but I&#8217;m not immune to that type of feeling. In my experience, one anxiety-inducing event is the annual physical itself: cataloging every new bump or brief pain, anticipating the doctor&#8217;s questions, and overthinking the answers. We don&#8217;t suggest abandoning annual checkups just because they cause anxiety. Instead, we rely on a doctor&#8217;s bedside manner&#8212;a core component of medical training&#8212;to manage that stress.</span></p><p><span>I generally feel better once I&#8217;ve completed a checkup. I expect the outcome there depends heavily on how effectively the doctor communicates. That is where we can manage the risks associated with an influx of new medical data. We should expand our thinking beyond just the bedside manner of individual doctors, and focus on the design of the entire patient communication system.</span></p><p><span>The medical system already does this to some extent, but as we enter an era of pervasive data, there is a need for more. The answer to the anxieties of the information age isn&#8217;t to reject the data, but to design a healthcare system capable of communicating its true value.</span></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p> It&#8217;s impossible to go from too expensive to use with a strong symptom to cheap enough to use regularly, without passing through the zone where wealth is used to access it regularly, but it&#8217;s still not cheap enough for pervasive use. So the critique of that being a possible outcome will always exist. But giving up on this basis doesn&#8217;t help much of anyone and historically, if you&#8217;re able to drop the price to the first level, the progression doesn&#8217;t stop there.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[The Invisible Profession]]></title><description><![CDATA[Opinions about AI are outrunning our understanding of the software beneath it]]></description><link>https://substack.norabble.com/p/the-invisible-profession</link><guid isPermaLink="false">https://substack.norabble.com/p/the-invisible-profession</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 23 Jun 2026 11:39:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NWxK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Opinions about AI are running hot. Everyone has one. I worry that the public isn&#8217;t informed enough to justify the rather direct opinions they have about AI, where they may want it stopped, slowed down or regulated. The public should care, as AI is going to be impactful. But that interest should translate into being well informed.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><span>AI is more than software, but software is very much at the core of AI. And the reality is the public has not been very interested in understanding software development as a profession. A point of evidence for this, and a mechanism leading to being poorly informed, is that software development is one of the least-represented occupations by entertainment television and film.</span></p><p><span>I made this point in a story a few weeks back, in a </span><a href="https://substack.norabble.com/p/are-we-in-a-token-bubble"><span>longer post about bubble narratives</span></a><span>. It was part of a larger narrative, but I heard confusion about why I brought it up. I thought it&#8217;d be useful to pull this out, and clarify why I think it&#8217;s an important topic.</span></p><p><span>Since software is at the core of AI, it feels like people should be informed about it. Being informed requires more than being a user. It requires understanding the lives of those developing it. It&#8217;s one thing to be disinterested in how your phone or computer works, but happy to use it. It&#8217;s another to have only caricatures of software developers to rely upon, know little about the basic processes we use to secure, develop and deliver software, and yet have an opinion on AI development.</span></p><p><span>Here is what I wrote:</span></p><div class="callout-block" data-callout="true"><h2><strong>Why the public has a poor understanding of software development</strong></h2><p>The wider world has never shown broad interest in learning what software developers do. Compared to other professions like police, soldiers, doctors, lawyers, musicians, writers, journalists or even criminals. Without that interest it&#8217;s unlikely to learn the inner workings of the profession.</p><p>Media portrayals of software developers are rare and rarely accurate. The most common portrayal is the &#8220;hacker&#8221; who mysteriously takes control of computer systems in a few minutes with no preparation. Not only is that a poor representation of a real hacker, it tells you nothing about software development overall.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9YLF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9YLF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 424w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 848w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1272w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png" width="1456" height="1694" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1694,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;title&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." title="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." srcset="https://substackcdn.com/image/fetch/$s_!9YLF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 424w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 848w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1272w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em><span>Note: Scales are different per panel, programmers at 1x10</span><sup>-6</sup><span> are 10x less frequent than actresses at 1x10</span><sup>-5</sup><span>, or 300x less frequent than doctors below at 3x10</span><sup>-4 </sup><span>(below).</span></em></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OTUW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OTUW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 424w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 848w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1272w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png" width="1456" height="1705" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1705,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;title&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." title="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." srcset="https://substackcdn.com/image/fetch/$s_!OTUW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 424w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 848w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1272w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em><strong>Source: </strong><a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9116627/">Representation of professions in entertainment media: Insights into frequency and sentiment trends through computational text analysis</a><span>, Baruah S, Somandepalli K, Narayanan S..</span></em></figcaption></figure></div></div><p><span>I reworked the data above to make it easier to see the patterns.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://velvety-entremet-58e85c.netlify.app/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWxK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 424w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 848w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 1272w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWxK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png" width="1456" height="1224" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1224,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://velvety-entremet-58e85c.netlify.app/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NWxK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 424w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 848w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 1272w, https://substackcdn.com/image/fetch/$s_!NWxK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086393f0-6806-41b6-b530-85aef8101fdc_2048x1721.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em><span>Use this </span><a href="https://velvety-entremet-58e85c.netlify.app/">Interactive version</a><span> to dive deeper. You can also get at the other metrics, like the absolute appearances.</span></em></figcaption></figure></div><p><span>Ultimately, my concern here is deeper than portrayals. The facts about portrayals are an example. That example does have real effects, but entertainment media is also reacting to interests that precede entertainment choices.</span></p><p><span>The real concern is that advocating for laws or regulations that apply to software without an understanding of the process of development, is a recipe for failure. There are many places one might learn about an occupation. Media is just one, but it is a powerful one. Also, my experience as a member of the occupation is that most of my conversations about the occupation were limited to people inside.</span></p><p><span>There is a personal side to this. I&#8217;ve often been troubled by how the world in general treated the work I did as somewhat foreign. I noticed an imbalance in how much time conversations dwelled on my own work. It&#8217;s not the only profession like that, but it did register with me personally. I bring up my personal experience, not because my feelings are the point. They might be worth a little thought, but the point is I can see this disconnect so clearly because it is personal. If it&#8217;s not personal, it&#8217;s an easy gap to miss.</span></p><p><span>Software isn&#8217;t the only underrepresented occupation, but it is high stakes amongst those. It does appear in the news, but is it the facts of software developers that are being represented in the news? That&#8217;s not my observation either. The personal opinions of writers, artists and media that are heavily represented instead. Those same groups are over-represented in entertainment media, and have their opinions as the most visible via that route.</span></p><p><span>I&#8217;d suggest this is a moment where it makes sense to lean in a bit. It might not be natural to be interested in how software is developed. It might be more convenient day to day to enjoy the software, and treat the field as opaque. But if we need to make decisions about the field, that gap will become relevant. Everyone should be part of making those decisions, but the process of making those decisions must be well informed too.</span></p><p><span>So, if you&#8217;re a journalist, you should be interviewing software developers more often. If you&#8217;re creating a movie or TV show, you should consider writing in a character from software development, and avoid applying inaccurate cliches.</span></p><p><span>I&#8217;m trying to do my part with this writing. I probably can do more to make it more accessible. There is a tendency in software development, like any field, to write for your internal audience. That&#8217;s reinforced when outside interest is low.</span></p><p><span>If you&#8217;re a regular reader of this Substack, it&#8217;d be redundant to suggest you need to read something from a software developer, but I&#8217;ll assume this message may reach those beyond that scope. So encourage others to connect with the how of software development, both here and with other software developers in their lives.</span></p><p><span>That&#8217;s not going to be enough to bridge decades of disengagement, but it is a start. Since the political decisions of AI can&#8217;t wait for a repair, I suggest some humility in decision making here. In </span><a href="https://substack.norabble.com/p/ai-safety-is-underfunded-by-design"><span>AI Safety Is Underfunded by Design</span></a><span>, I suggest that we need balance that takes advantage of organic efforts of self-regulation. I wouldn&#8217;t say that self-regulation is sufficient; even if it&#8217;s working so far, this is too important to take that approach. But at the same time, regulating what you don&#8217;t understand will fail.</span></p><p><span>A learning process is necessary, both amongst the wider public, and with the politicians, lawyers, and administrators that would need to be part of any effective regulatory system, alongside industry experts.</span></p><p><strong><span>Related Posts</span></strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;eca16fc4-2437-4611-9e82-ee3ac754b353&quot;,&quot;caption&quot;:&quot;Preview&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Are We in a Token Bubble?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-09T11:35:54.740Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!0BUx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/are-we-in-a-token-bubble&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201134103,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3bcb5feb-846b-4e71-9700-4f2c5580ab05&quot;,&quot;caption&quot;:&quot;Earlier, I wrote about determinism and control. I feel a need to return to these concepts because they are the quiet shift beneath software, and deserve greater attention.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Control and AI&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-28T11:03:54.728Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9235ab95-b3ad-4254-9249-cb999931edfc_1731x909.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/control-and-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195674034,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Gamble, Six Months On]]></title><description><![CDATA[A layer-by-layer look at the AI value chain &#8212; chips to applications &#8212; finds firmer footing on capex, but a mountain only half climbed.]]></description><link>https://substack.norabble.com/p/the-ai-gamble-six-months-on</link><guid isPermaLink="false">https://substack.norabble.com/p/the-ai-gamble-six-months-on</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 16 Jun 2026 11:36:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/fcc76e16-4396-4393-9091-82f598b7a587_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In December I wrote <a href="https://substack.norabble.com/p/the-architecture-of-a-gamble">The Architecture of a Gamble: Mapping the AI Value Chain</a>. Given it&#8217;s been about 6 months, an update seems in order.</p><p>The architecture I outlined had 4 layers: compute supply chain, operational infrastructure, intelligence and application. Each layer has to justify its own expenses, which contribute to the revenues of the lower layers. When those aren&#8217;t justified, the whole structure is a gamble on the outcomes of the upper layers. That said, the immediate term for lower layers can be remarkably sound, because they get paid now, not later.</p><p>This story is only half written, so we can look at how each layer is doing today. Even when that story looks good, we shouldn&#8217;t extrapolate to the future. Each increment of demand must prove itself, both in terms of feasibility and in terms of timing.</p><p>How is each layer doing today?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Layer 1: The Compute Supply Chain</h1><p>The main influence on this layer is the inputs from Layer 2. Since those plans have kept progressing as planned a year ago, it should be unsurprising that this layer has done well. Revenues continue to increase and stability looks favorable. The main change here is that competition is growing. The availability of <a href="https://www.tomshardware.com/tech-industry/semiconductors/custom-ai-asics-examined-from-broadcom-to-mtia">chips designed in house, TPUs, Trainium and more, have grown</a>. The <a href="https://hothardware.com/news/intel-foundry-challenges-tsmc-dominance-report">efforts to make Intel capable of competing with TSMC</a> have continued. <a href="https://www.tomshardware.com/tech-industry/semiconductors/analyzing-tsmcs-fab-expansion-roadmap-multi-fab-n2-ramp-cowos-soic-and-uncorking-bottlenecks">TSMC has continued expansions of its own</a>.</p><p>Additionally, memory and CPUs have been pulled closer to the middle. <a href="https://www.trendforce.com/insights/memory-wall">Memory was already a bottleneck and has become more central</a>. GPUs have remained central, but share much of the spotlight with memory now. CPUs have moved from trivialities, to moderate importance.</p><h1>Layer 2: The Operational Infrastructure</h1><p>The situation at this layer has firmed up significantly in the past 6 months. Revenue for delivered compute has continued to grow. Additionally, commitments have been disclosed, adding stability. Disclosures about commitment numbers don&#8217;t express the exact terms, so we don&#8217;t know if these could reverse.</p><p>More importantly, everything is broader here. OpenAI and Anthropic <a href="https://logisticsviewpoints.com/2025/11/03/33669/">are using compute from all platforms</a>. xAI showed how to recover from a failure, at least partially, <a href="https://techcrunch.com/2026/05/20/anthropic-will-pay-xai-1-25-billion-per-month-for-compute/">by selling unused compute to Anthropic</a>.</p><p>All that good news shouldn&#8217;t ignore that there&#8217;s still significant spending planned that will have to justify itself. The revenues of today (+$100 billion ARR) are roughly proving that <a href="https://www.tomshardware.com/tech-industry/big-tech/big-techs-ai-spending-plans-reach-725-billion">last year&#8217;s $410 billion</a> in spending isn&#8217;t going to be unproductive. That doesn&#8217;t tell us enough about <a href="https://www.goldmansachs.com/insights/articles/tracking-trillions-the-assumptions-shaping-scale-of-the-ai-build-out">this year&#8217;s $700 billion</a>, nor next year&#8217;s $1 trillion. So long as those keep growing quickly, the risk that expected revenue to cover it never appears should remain a live discussion.</p><h1>Layer 3: The Intelligence</h1><p>There are many positive updates here. The best ones concern Anthropic, which is a moderately bad story for OpenAI. Revenues have grown considerably. <a href="https://www.cnbc.com/2026/05/20/anthropic-revenue-explosive-growth-ipo-profitable-quarter.html">Anthropic expects to be profitable</a>. Enterprise revenues have grown considerably. Could this reverse? Maybe. Much usage is still prototypes, experimental, or otherwise dependent on expectations. But it seems unlikely. <a href="https://substack.norabble.com/p/are-we-in-a-token-bubble">As I covered last week, there&#8217;s more pulling us forward than back here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bldN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bldN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 424w, https://substackcdn.com/image/fetch/$s_!bldN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 848w, https://substackcdn.com/image/fetch/$s_!bldN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 1272w, https://substackcdn.com/image/fetch/$s_!bldN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bldN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png" width="342" height="669" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:669,&quot;width&quot;:342,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Anthropic's operating income, by segment&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Anthropic's operating income, by segment" title="Anthropic's operating income, by segment" srcset="https://substackcdn.com/image/fetch/$s_!bldN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 424w, https://substackcdn.com/image/fetch/$s_!bldN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 848w, https://substackcdn.com/image/fetch/$s_!bldN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 1272w, https://substackcdn.com/image/fetch/$s_!bldN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17efc5eb-7b8d-4ae2-9d48-7cba9297886f_342x669.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Layer 4: The Application</h1><p>This layer still contains a large amount of uncertainty. The most significant use case, software development, is fundamentally another layer. Last week I covered <a href="https://substack.norabble.com/p/are-we-in-a-token-bubble">dynamics of token usage by the application layer</a>. While this is one of the longest articles I&#8217;ve written, it only covers dynamics, not actual numbers, and only a few of the most important.</p><p>To be truly solid, the various parts of the application layer need recognition that value is being created. That&#8217;s hard, because there&#8217;s a lot that would need to be measured here, and many of the things you want to measure, are both difficult and emerge with lagging indicators.</p><p><a href="https://substack.norabble.com/p/ai-and-the-zero-sum-game">Adversarial usage</a>, in <a href="https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/#blog-item-8">marketing ($660 million), legal ($650 million), and sales ($390 million)</a>, is following behind coding and IT usage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VfDY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VfDY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 424w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 848w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VfDY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png" width="1456" height="792" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:792,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VfDY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 424w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 848w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!VfDY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a12ce7c-decf-46ff-83b9-0ba887ba148b_2048x1114.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EACt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EACt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 424w, https://substackcdn.com/image/fetch/$s_!EACt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 848w, https://substackcdn.com/image/fetch/$s_!EACt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 1272w, https://substackcdn.com/image/fetch/$s_!EACt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EACt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png" width="1456" height="792" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:792,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Healthcare Dominates $3.5B Vertical Al Market&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Healthcare Dominates $3.5B Vertical Al Market" title="Healthcare Dominates $3.5B Vertical Al Market" srcset="https://substackcdn.com/image/fetch/$s_!EACt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 424w, https://substackcdn.com/image/fetch/$s_!EACt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 848w, https://substackcdn.com/image/fetch/$s_!EACt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 1272w, https://substackcdn.com/image/fetch/$s_!EACt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50596afa-04ba-40a7-9042-8a6debbf0864_1536x836.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Early adoption from <a href="https://www.prnewswire.com/news-releases/iab-2026-outlook-study-forecasts-9-5-growth-in-us-ad-spend-fueled-by-digital-growth-major-cyclical-events-and-accelerating-adoption-of-agentic-ai-302671862.html">sales and advertising</a>, shapes how much effects need to be proven. From a financiers perspective, this isn&#8217;t a problem, maybe even positive. From someone worried about employment demand, it also isn&#8217;t a problem.</p><p>But from a social perspective, it&#8217;s not sound. We can&#8217;t expect significant positive value to come out of adversarial sectors.  We want to see demonstrated productive revenue, and we want to see cases where freed labor is reutilized in growth sectors.</p><h1>Conclusion</h1><p>Is the AI industry past the &#8220;bubble&#8221; discussion? No. Certainly not in terms of stock prices and valuations. In terms of CapEx spend, and the likeliness of future contractions or firm failures, it&#8217;s on firmer footing, but the story still progresses as the mountain is only half climbed. You might say that anyone who put 2026 as a specific timeline for their concerns, has missed the mark, and there are many who did. But overconfident predictors don&#8217;t make an effective counter-argument to more general views.</p><p></p><div class="callout-block" data-callout="true"><p><strong>Postscript: Fable 5</strong></p><p><em>It would be unusual not to update here, as I&#8217;ve written about security in the past. It took a little while to become comfortable that I had enough facts as the administration&#8217;s story came out with so few details. It was hard for me to judge right off if that was because they had good information they didn&#8217;t want to share, or were just behaving irrationally. <a href="https://thezvi.substack.com/p/the-once-and-future-fable-2">But the naive assumption seems to be true</a>, they were behaving irrationally.</em></p><p><em>&#8220;Asking&#8221; for a shutdown, using bad evidence that doesn&#8217;t demonstrate any real harm is bad for everyone. For safety-minded people, it&#8217;s effectively &#8220;calling wolf&#8221;, and undermines any future action based on good evidence. For the safety-optimistic, aka accelerationist, it&#8217;s bad for the obvious reasons, but also bad because it creates a precedent of using bad evidence. This creates more uncertainty.</em></p><p><em>All parties, at least rationally, should want actions that are based on good evidence only. They might disagree on where the evidentiary bar should be, but it&#8217;s clearly bad when it&#8217;s randomly chosen. Since the capabilities they have evidence of being able to reproduce with a limited jailbreak are universal amongst models, you would have to ban them all. But they aren&#8217;t all banned, just one. That&#8217;s not a consistent system, and it should be obvious why that&#8217;s generally illogical as an outcome.</em></p></div><p><strong>Related articles</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7cbc9903-1789-4c7d-8d17-5f3bdc964a30&quot;,&quot;caption&quot;:&quot;It would be useful to know the shape of future AI demand, and many are attempting to predict that. Since this is a long piece I&#8217;ll give you my predictions up front. My overall prediction is that localized corrections, from the imposition of usage controls and consistent pricing, will ultimately be less important than the big trends. Value, so far hard to measure, will become more clear, first through incremental gains at the core of software development, and next, from the innovation that takes longer to accumulate and organize.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Are We in a Token Bubble?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-09T11:35:54.740Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!0BUx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/are-we-in-a-token-bubble&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201134103,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b4f0856a-db37-406a-8d30-93692cda0742&quot;,&quot;caption&quot;:&quot;A while back I talked about producing an analysis of the AI industry. I&#8217;ve put together something pretty extensive, but on reflection, I&#8217;ve decided to put it out in multiple parts. This post today functions more as an outline, where the following posts will dive more into each layer of this stack and then finally look in more depth at the macro-economic aspects.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Architecture of a Gamble&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-12-15T12:00:28.462Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wNQ-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ac2d61c-4ddf-4020-a1f0-0349cbb0809e_1024x565.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/the-architecture-of-a-gamble&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:181559364,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;24bf167d-bd23-438b-a6d2-a8141695e357&quot;,&quot;caption&quot;:&quot;AI is advancing quickly, and if there&#8217;s any one consensus about it, it is that it will have broad impacts on jobs. What impact, is an area of more debate, but it&#8217;s uncommon to view it as non-impactful. Some believe that jobs will disappear, and there would be large amounts of unemployment. Some draw on past periods of technological change, such as the Industrial Revolution or the advent of the internet, and believe that advances ultimately lead to new jobs that didn&#8217;t previously exist.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI and the Zero-Sum Game&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-03-30T16:15:53.873Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3lXS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bdff8e-8e0a-461c-99ae-df41fd06ab63_1024x608.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-and-the-zero-sum-game&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:160183122,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Are We in a Token Bubble?]]></title><description><![CDATA[The wrong question &#8212; and a better one for reading the AI boom.]]></description><link>https://substack.norabble.com/p/are-we-in-a-token-bubble</link><guid isPermaLink="false">https://substack.norabble.com/p/are-we-in-a-token-bubble</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 09 Jun 2026 11:35:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0BUx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="callout-block" data-callout="true"><p><strong>Preview</strong></p><p><em>It would be useful to know the shape of future AI demand, and many are attempting to predict that. Since this is a long piece I&#8217;ll give you my predictions up front. My overall prediction is that localized corrections, from the imposition of usage controls and consistent pricing, will ultimately be less important than the big trends. Value, so far hard to measure, will become more clear, first through incremental gains at the core of software development, and next, from the innovation that takes longer to accumulate and organize.<br><br>Read on to learn how I add my experience in cloud computing and software engineering to my deep interest in economics to extend responses from two of my favorite writers. Along the way, I&#8217;ll recast the bubble analogy, explain recent trends that have hit the news, explain trends hidden deep in the development lifecycle, and provide a model, &#8220;Ingenuity Matrix&#8221;, for mapping usage intent to expected outcomes.</em></p></div><p>We love good stories, especially those with a villain. But we should be careful about our stories, knowing how powerful they can be.</p><p>Three stories have hit a crescendo at about the same time. <a href="https://en.wikipedia.org/wiki/Token_maxxing">Tokenmaxxing</a> &#8212; companies turning token usage into a goal, metering it, and the waste that incentivizes. Subsidized tokens &#8212; questions on the relationship today between AI costs and pricing. And under both, the doubt about whether spending is producing value for AI customers.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Stack them together and a tidy narrative falls out. If these are what&#8217;s driving token usage, and they all adjust at once, the readjustment will ripple through AI industry economics &#8212; including Anthropic&#8217;s recently skyrocketing revenues. That narrative extends across all model providers, culminating as a cascading failure of the whole AI industry. Call it the token bubble, brought on by a revaluation of tokens and their utility.</p><p>It&#8217;s a neat story, but the framing is off, even before we get to evidence. &#8220;Bubble&#8221; as metaphor smuggles in two assumptions: that we&#8217;re looking at <em>one</em> structure, full of only hot air, and that it ends by <em>popping</em>. In reality, industrial bubbles deflate, running out of air. There is an inflated shell, inside of which a structure is being built, and its collapse while deflating halts construction within, and damages unfinished construction. But something remains.</p><p>Inflating the shell is not folly, but the simplest path to enable construction. It&#8217;s still calamitous when it deflates, but the goal is the structure, not the air. So the question I&#8217;m interested in isn&#8217;t &#8220;are we in a bubble?&#8221; It&#8217;s: which of these dynamics is air, which is structure, and how would you tell them apart?</p><p>The story has been covered by two of my favorite writers, Derek Thompson, in <a href="https://www.derekthompson.org/p/the-great-ai-cost-panic-of-2026">The AI Boom Has Entered Its &#8216;Wait, Is This Worth It?&#8217; Era</a> and Noah Smith, in <a href="https://www.noahpinion.blog/p/how-much-more-software-do-we-really">How much more software do we really need?</a>. Both play speculatively with the idea that spending and rationality may have split from each other, but retain optimism that something worthwhile is being built.</p><p>Thompson concludes his summary of an interview with <a href="https://www.fabricatedknowledge.com/">SemiAnalysis&#8217;s Doug O&#8217;Laughlin</a>:</p><blockquote><p><em>Every new technology requires an extended period of trial and error, as organizations toggle between (a) not enough experimentation or spending, followed by (b) too much experimentation and spending, followed by (c) too dramatic a pullback, followed by (d) the repetition of steps (a) through (c), until firms figure out a long-term balance between labor spending and tech spending. Whether AI skeptics like Marcus are right that the bubble is about to pop depends entirely on a question that, as of today, nobody can definitively answer: Is the bill worth it?</em></p></blockquote><p>Smith considers the period before a smarter than human in all ways artificial general intelligence:</p><blockquote><p><em>But until we reach that point, it&#8217;s a nontrivial task to think of business models that could be fully automated even with an AI that can&#8217;t yet do everything. That&#8217;s going to be hard! If I had any good ideas for how to do that, I&#8217;d go become a billionaire myself.</em></p><p><em>At some point, though &#8212; maybe in the very near future &#8212; people (assisted by AI) will come up with those revolutionary new business models. At that point, tokenmaxxing will suddenly become a lot more economical, and Anthropic &#8212; or whoever has good coding agents by that time &#8212; will stand to make untold amounts of money.</em></p></blockquote><p>These are good perspectives, but I can improve upon them to help understand the dynamics of AI usage. First, I&#8217;m from the software industry, which is at the center of the maelstrom &#8212; coding is now <a href="https://openrouter.ai/state-of-ai">the single largest category of token usage</a>. I can describe in more detail what developers are actually <em>doing</em> with these tokens, and their motivations. These details are important. Without them, a lot of valuable work remains mysterious, which invites doubts, such as &#8220;is this worth it&#8221;, or &#8220;do we need more software&#8221;?</p><p>Second, I&#8217;ve spent a while thinking about the <a href="https://substack.norabble.com/p/ai-jobs-the-hidden-rules-of-demand">adversarial dynamics of some AI usage</a>, <a href="https://substack.norabble.com/p/ai-and-the-zero-sum-game">since first writing about it last year</a>. Those dynamics are key to the questions both writers leave us with. Adversarial usage doesn&#8217;t produce the social value we all seek. It is not the only driver of AI usage, but when it is a driver, we should be asking, &#8220;is this worth it&#8221;?</p><p>Both writers are aware of an important detail, timing, which explains many misleading observations. With the addition of a deeper understanding of software development, and that model for separating zero-sum jockeying from the creation of social value, we can recognize events along the timeline with more accuracy.</p><p>Token usage, like human labor, can&#8217;t tell you progress. Its best analogy is effort. If you want to understand the effectiveness of effort, you want to know how it&#8217;s being applied. Different applications correlate with different outcomes. Since you can&#8217;t fast-forward to the results, this is the best immediate categorization you can add. I call this categorization, the Ingenuity Matrix, describing the scope and social alignment of token usage.</p><p>Some token usage goes nowhere by design, some burns down a backlog of long-deferred work, some is zero-sum jockeying. A slower, quieter share is the significant work that actually changes lives. Sort the usage that way and the &#8220;is it a bubble&#8221; question dissolves into a more useful one &#8212; what&#8217;s being built, what events can we expect along the path, and what risks and opportunities come with each set of events?</p><h1>Background</h1><p><em>Before we start into the model, understanding the two terms behind the narratives is useful. This will also be useful when reading general news on the topics. The narratives on these conflate multiple meanings, and smuggle assumptions. That ambiguity can support misleading narratives<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</em></p><div class="callout-block" data-callout="true"><h2>What is tokenmaxxing?</h2><p>Tokenmaxxing refers to two things. First, it refers to companies&#8217; creation of &#8220;leaderboards&#8221; tracking employee AI usage by metering tokens. These leaderboards might be informal, but there&#8217;s often an implied assumption that high usage is rewarded, and low usage risks consequences. Sometimes that&#8217;s explicit. Ostensibly the justification is to incentivize experimentation and overcome inertia. In addition to simple inertia, many companies started with restrictive policies discouraging AI usage that they needed to counteract.</p><p>The second meaning focuses on what happens when leaderboards encourage AI usage, but do so in unproductive ways. Some employees respond by trying AI more and doubling down on things that work. But they may also create or continue unconstructive habits, for no reason other than they generate tokens. Individuals have described such practices anecdotally.</p><p>In this dual definition, when companies tokenmax, they encourage both the good and the bad. When individuals tokenmax, we talk only about the bad. The most extreme tokenmaxxing isn&#8217;t ingenuity that misfires &#8212; it&#8217;s intentional waste. The intent isn&#8217;t to do work; it&#8217;s to <em>appear</em> to have done work.</p><p>It&#8217;s not hard to see how that type of usage leads to a narrative that it&#8217;s all a sham. But we should remember, what we have is anecdotes. While it&#8217;s certain that some waste is occurring, it&#8217;s hard to gauge. Anecdotes are sparse, and for good reason. Admitting to it, would be admitting to willfully ignoring the employer&#8217;s best interest in productivity. That would carry consequences if a manager discovered it and wasn&#8217;t interested in joining the deception.</p><p>But separating waste from sincere-but-unsuccessful experimentation requires details that simply aren&#8217;t available at scale. What we can say is that the organizations running leaderboards are making a deliberate bet: they&#8217;re buying a pile of unaimed experimentation and some willful waste, in exchange for a fraction that matures into something real &#8212; durable skills, a useful tool, an opportunity nobody had time to chase before. Whether the bet pays off, only time will tell. But the structure of the bet &#8212; accepting near-term waste to fish for longer-term capability &#8212; is something we should predict and model as a mix.</p></div><div class="callout-block" data-callout="true"><h2>What are subsidized tokens?</h2><p>Subsidized tokens can refer to three things.</p><p>The most common usage focuses on two billing models. One is metered, usage is measured and billed per token, at <a href="https://platform.claude.com/docs/en/about-claude/pricing">prices like $5/million tokens</a>. The other is by subscription, for example $20/month. Subscriptions typically have usage limits, but in most cases, fully utilizing a subscription&#8217;s limits yields a per-token cost below the metered rate. In addition, loopholes existed, allowing usage far below the metered rate. Users who used their subscriptions heavily enough to get that benefit were labelled as subsidized. That&#8217;s a simplification though, as it could be a lower profit margin, not subsidization.</p><p>The second usage focuses on free tiers. Free tiers have restrictive usage limits, but with no revenue, they are clearly subsidized. Free users heavily outnumber paid subscribers. Across providers there are at least a billion free tier users, while paid subscribers would be below a hundred million.</p><p>The third and final usage translates the unit economics of metered usage into <a href="https://substack.norabble.com/p/the-architecture-of-a-gamble">the underlying costs that model providers pay to compute providers, which pay for chips, power, and other infrastructure</a>. The question the subsidy narrative is really asking is, are the unit economics of AI usage sustainable? Or are they a short-term attempt to grow usage, the end of which results in higher prices, and pulling back from usage that&#8217;s no longer economic at the higher price point?</p><p>It&#8217;s an interesting story, but it&#8217;s almost worth ignoring. The efficiency of AI is increasing quickly, driving unit costs down. If prices rebound, unless the rebound is something like 10x, they&#8217;d soon fall again. The reason they can&#8217;t be ignored has little to do with a long-term trend, but everything to do with the short-term viability of the financing of AI investments and presumed valuations. A company trapped in subsidizing while a competitor is not, is going out of business quickly. This pattern repeats at each level of the AI value chain.</p></div><h2>Why Bubble as an analogy is over extended</h2><p>I said in the opening that using &#8220;bubble&#8221; as a metaphor for the AI industry smuggles in two assumptions. A bubble is so commonly used to analogize industrial revolutions, that we fail to reflect on the limits it has as an analogy. One mistake it leads us to, is the belief that there&#8217;s a soap bubble floating in air, and when we prick it with a pin it will pop, and evaporate. This does a poor job of explaining reality though.</p><p>We might limit our imagination more effectively by replacing the soap bubble with an inflatable dome. Whether this stays inflated depends upon the balance of air entering and exiting. Inside this dome, we&#8217;re constructing something durable, but it would be a challenge to do so with the dome weighing on top of us. We need the air to keep the dome&#8217;s ceiling from impeding our construction, and if it deflates it will probably ruin any half constructed structures. The stronger completed structures can sustain the weight of a deflated dome, but will struggle to conduct any additional construction.</p><p>If you want to think of the social support for a system, which supplies the air to keep the shell inflated, as a bubble, that&#8217;d be fair. This can evaporate with a bad news story, or some other form of social contagion. That social support is what replaces the air that leaks out. We&#8217;ll discuss the leaks later. Some are necessary, some are not. But replenishing the loss is unavoidable.</p><p>It&#8217;s useful to remember that in this analogy, deflation isn&#8217;t free. Something will remain, but the damage to unfinished construction is real. Careers are an obvious example of the consequences. When companies downsize the skills, connections and tacit knowledge built to support growth get stranded. If people move on, they may never come back. And besides, they are people and the disruption to their lives matters too. Projects also take a hit. Some projects may be zombies, shambling along with an unsound structure that will never be completed. But the forces of deflation aren&#8217;t so selective, and promising work is wiped away as well. Many projects that stop work during periods of tightening never start again.</p><p>A second flaw in the analogy is as a singular structure. Not only are there independent structures being built within, there&#8217;s not a single dome. There is a primary dome, where the model providers, GPU manufacturers and designers, and much else reside. But AI is also working to serve many different industries, and we shouldn&#8217;t assume a shared fate between all those efforts. We do want to pay attention to software development, because it represents such a large fraction of current usage. But software development itself isn&#8217;t an end of its own, it serves other industries. If AI is effective at helping some of those, and less-effective in others, this doesn&#8217;t establish a shared fate. It is only those cross-cutting effects that affect all software development that would carry that risk.</p><p>For the most part, those outside of software development aren&#8217;t going to understand those cross-cutting effects. I&#8217;ll highlight some of those details here, as they should be relevant to anyone interested in the immediate future implications of AI.</p><div class="callout-block" data-callout="true"><h2>Why the public has a poor understanding of software development</h2><p>The wider world has never shown broad interest in learning what software developers do. Compared to other professions like police, soldiers, doctors, lawyers, musicians, writers, journalists or even criminals. Without that interest it&#8217;s unlikely to learn the inner workings of the profession.</p><p>Media portrayals of software developers are rare and rarely accurate. The most common portrayal is the &#8220;hacker&#8221; who mysteriously takes control of computer systems in a few minutes with no preparation. Not only is that a poor representation of a real hacker, it tells you nothing about software development overall.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9YLF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9YLF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 424w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 848w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1272w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png" width="1456" height="1694" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1694,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." title="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." srcset="https://substackcdn.com/image/fetch/$s_!9YLF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 424w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 848w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1272w, https://substackcdn.com/image/fetch/$s_!9YLF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47437ce0-bade-4b9b-a987-b5f3c46165fb_1562x1817.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Note: Scales are different per panel, programmers at 1x10<sup>-6</sup> are 10x less frequent than actresses at 1x10<sup>-5</sup>, or 300x less frequent than doctors below at 3x10<sup>-4 </sup>(below).</em></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OTUW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OTUW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 424w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 848w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1272w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png" width="1456" height="1705" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1705,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." title="Multi-panel research figure of how often professions appear in entertainment media over time; programmers appear far less often than doctors, police, and most others." srcset="https://substackcdn.com/image/fetch/$s_!OTUW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 424w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 848w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1272w, https://substackcdn.com/image/fetch/$s_!OTUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03191edf-91c7-45b5-bd3a-7c38b67df3d0_1598x1871.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em><strong>Source: </strong><a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9116627/">Representation of professions in entertainment media: Insights into frequency and sentiment trends through computational text analysis</a>, Baruah S, Somandepalli K, Narayanan S..</em></figcaption></figure></div></div><h1>When software is &#8220;done&#8221;</h1><p>If you come from outside the software world, you&#8217;d be excused from thinking of software development as building new software. In reality, this is a modest part of software development. Maintaining software, deploying software, and operating deployed software all represent larger segments than new software. All said, <a href="https://pegotec.net/software-maintenance-cost-percentage-2026-industry-benchmarks/">new software could be as small as 20%</a>.</p><p>Noah makes a tentative argument that <em>&#8220;The world may already have most of the traditional software that it needs.&#8221;</em>. Noah&#8217;s aware he might be getting this wrong, and indeed he does. It does take an immense amount of work to keep sites running. AI is being used here, but it started later than its use to create new software. It&#8217;s not too hard to guess why. Creating new software is low risk comparatively. Like everyone, trust of AI has been a process. Software maintenance and operations themselves rely on significant &#8220;tech-stacks&#8221;, which have to be modified before you can even attempt to use AI to make a site more reliable in a meaningful way.</p><p>The number of software releases for security, operational, monitoring and development oriented features has been significant over the past year. Many use AI. Probably many others were built using AI.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QoJB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QoJB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 424w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 848w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 1272w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QoJB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png" width="1456" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Two line charts, 2021&#8211;2025: annual major feature releases and a release-velocity index for Microsoft, Google, Apple, AWS, and Salesforce, all trending sharply upward.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two line charts, 2021&#8211;2025: annual major feature releases and a release-velocity index for Microsoft, Google, Apple, AWS, and Salesforce, all trending sharply upward." title="Two line charts, 2021&#8211;2025: annual major feature releases and a release-velocity index for Microsoft, Google, Apple, AWS, and Salesforce, all trending sharply upward." srcset="https://substackcdn.com/image/fetch/$s_!QoJB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 424w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 848w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 1272w, https://substackcdn.com/image/fetch/$s_!QoJB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ec02c-4fe7-4af2-84f5-31005a9062a5_1600x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Should you expect faster load times and higher reliability? First, would you really know? These have been improving for years, yet the general public rarely comments upon it. Mostly the only comments are those times when something does fail.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QgoE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QgoE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 424w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 848w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 1272w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QgoE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png" width="1456" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Two line charts, 2021&#8211;2025: annual unscheduled downtime in cumulative hours, and an outage volatility index with 2021 set to 100, both for AWS, Microsoft (M365/Azure), Google Cloud/Workspace and Salesforce; all four providers trend downward by 2025.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Two line charts, 2021&#8211;2025: annual unscheduled downtime in cumulative hours, and an outage volatility index with 2021 set to 100, both for AWS, Microsoft (M365/Azure), Google Cloud/Workspace and Salesforce; all four providers trend downward by 2025." title="Two line charts, 2021&#8211;2025: annual unscheduled downtime in cumulative hours, and an outage volatility index with 2021 set to 100, both for AWS, Microsoft (M365/Azure), Google Cloud/Workspace and Salesforce; all four providers trend downward by 2025." srcset="https://substackcdn.com/image/fetch/$s_!QgoE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 424w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 848w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 1272w, https://substackcdn.com/image/fetch/$s_!QgoE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38a50191-97a2-43e4-9464-5af086b4540f_1600x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;m not holding this data above as proof that AI has improved reliability. These improvements are more likely the result of conventional engineering, some started years before the results. The results that are &#8220;AI&#8221; based, are the result of the &#8220;machine learning&#8221; form that predated the architectures for Claude, Gemini and ChatGPT.</p><p>The point is, Noah (and you too) probably aren&#8217;t a sound judge of whether improvements are occurring unless you take the time to gather data. From my own knowledge, I know most AI based improvements are still in the early phases of adoption. But the average person shouldn&#8217;t expect to have an intuitive grasp on this. We&#8217;re bad intuitive judges of background effects like this, where we have to compare changes over time of non-continuous events. We can recall the last event, and the last change, but we are just as likely to draw a pattern from a recent reaction, than from an accurate history.</p><h2>Why &#8220;tech-debt&#8221; comes first</h2><p>You&#8217;ll find an interesting pattern that I&#8217;ll get into later. The first work to be done is the &#8220;shovel-ready&#8221; work. It&#8217;s easy to generate a prototype for some random idea, but rarer to have a great idea that can go from ideation to production quickly. AI does speed that up. But it doesn&#8217;t speed all work up.</p><p>With that in mind, provide a tool to a software developer, and they&#8217;ll have a long list of things they wanted to do, but haven&#8217;t had time for. Our general term for this is &#8220;tech-debt&#8221;, but realistically, it also includes half-baked feature ideas, or features that were sound but never made the cost-effectiveness cut. This list predictably contains a lot of non-amazing things. If they were amazing, they would have made the cost-effectiveness cut the first time. But AI does give you a reason to go deeper into that marginal backlog.</p><h2>Security as a priority</h2><p>I should also mention security here. Security is extremely important to the operation of software. Failures of security are nearly the worst thing you can imagine. This applies to all phases of software: development, deployment, and operations. It&#8217;s tempting to think of security as something you simply develop. But in reality that&#8217;s just the first step. A significant failure in development is likely to lead to a significant failure later, but it&#8217;s not destiny. You can layer protections to mitigate a development failure during operations. You have to do this because there are development failures you don&#8217;t know about. And more importantly, even a soundly designed and developed system can fail if not operated properly.</p><p>A lot of time and money is already spent on security. It&#8217;s never been the case that it hasn&#8217;t been a priority. You can find cases where it wasn&#8217;t a high enough priority. But it&#8217;d be a stretch to suggest there was a case no one cared. Whatever the priority, there is a limit, a cost-effectiveness barrier where one of the stages of development could have achieved more with more inputs. The introduction of AI changes the math on that barrier and makes many things practical that were impractical.</p><p>Security has another dimension too, which is that in addition to AI altering the developer&#8217;s cost-effectiveness equation, it does so for attackers too. This creates another incentive to burn down the security backlog. <a href="https://substack.norabble.com/p/security-cant-wait">Security can&#8217;t wait</a>. And so a lot with good cause, a lot of AI based productivity is going into security efforts.</p><p>This isn&#8217;t an effort that&#8217;s particularly visible to the outside world. What the outside world knows about it comes mostly from stories, not direct experience. When developers patch security holes, their intent almost always is to not change the user-experience. When that is the intent, it&#8217;s a slower process, because it requires educating users about new security mechanisms they need to participate in. Because that&#8217;s such a difficult thing to do, security teams have a very strong preference toward solving problems themselves without involving the users. It&#8217;s not always possible, but 90% of security efforts are invisible to users, and the next 9% are delivered as patches users see installed, but don&#8217;t pay any attention to.</p><h1>The ingenuity matrix</h1><p>I said in the opening that token usage is like effort: it tells you activity, not progress. To get from effort to expected outcome, you have to ask what the effort is for. Two questions do most of the work, and together they form a grid.</p><p>The first question is <strong>social alignment</strong>.<strong> </strong>Does the work <em>create</em> value the world didn&#8217;t have (positive-sum, pro-social)? Does it merely <em>move</em> value from one party to another (zero-sum, non-social)? Or does it <em>destroy</em> value &#8212; burn resources, or actively harm (negative-sum, anti-social)?</p><p>Alignment can be informed by our guesses of actors&#8217; intent, but it&#8217;s not dependent on it. Our best bet is to act as an outside observer, guessing at outcomes. I don&#8217;t want to overcomplicate this though, this is estimation after all. Some significant pro-social value sometimes arrives from someone tinkering purely for fun. The social alignment is still recognizable from the outside, even when the actor wasn&#8217;t aiming at it.</p><p>The second question is <strong>scope</strong>, how far the work is reaching. <em>Significant</em> work aims at a real leap. <em>Simple</em> work aims at something bounded and modest. <em>Naive</em> work isn&#8217;t aimed at a productive outcome at all. Here &#8220;naive&#8221; describes the absence of a useful target, not the absence of a motive. Intentional waste is naive in this sense, it produces nothing of value, even though the person doing it has a very clear motive.</p><p>What you&#8217;ve just toured, security patches, reliability work, performance and cost tuning, is real value, almost all of it invisible to the people who benefit. Nearly all of it lands in a single cell: <strong>simple, positive-sum.</strong> It&#8217;s illustrative that so much of what is immediate is within simple or naive ingenuity. The first things individuals use AI for aren&#8217;t the significant ones. It&#8217;s the modest, shovel-ready, often-unseen things.</p><p>Map the rest against those two axes and you get an <strong>ingenuity matrix</strong>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://ingenuity-matrix.netlify.app/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0BUx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 424w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 848w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 1272w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0BUx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png" width="1101" height="477" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:477,&quot;width&quot;:1101,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73408,&quot;alt&quot;:&quot;Ingenuity Matrix: a 3&#215;3 grid mapping scope (naive, simple, significant) against social alignment (anti-, non-, pro-social).&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://ingenuity-matrix.netlify.app/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/201134103?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Ingenuity Matrix: a 3&#215;3 grid mapping scope (naive, simple, significant) against social alignment (anti-, non-, pro-social)." title="Ingenuity Matrix: a 3&#215;3 grid mapping scope (naive, simple, significant) against social alignment (anti-, non-, pro-social)." srcset="https://substackcdn.com/image/fetch/$s_!0BUx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 424w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 848w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 1272w, https://substackcdn.com/image/fetch/$s_!0BUx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5674265-2d1f-4a04-ae90-f7c1d84caab4_1101x477.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ingenuity Matrix: Scope and alignment to predict economic outcomes</figcaption></figure></div><p><strong>Negative-sum is not hypothetical, it connects back to security.</strong> The same drop in cost-of-effort that lets defenders finally burn down the security backlog also lowers the attacker&#8217;s cost. AI-assisted cybercrime is simple, negative-sum ingenuity, and the prospect of AI-scale biological or infrastructure attacks is the significant version. A large share of the invisible defensive work isn&#8217;t optional improvement, it&#8217;s the response to an adversary. The result is effort that is no longer avoidable, but also hidden, which delays the visible gains we&#8217;re watching for.</p><p><strong>Significant non-social ingenuity ends empty. </strong>Non-social work can seem significant when under development. But one of two things happens. Either the work ends up leaking into pro-social, or anti-social accidentally, or it is copied and becomes trivial. Significance and neutrality are generally unstable.</p><p><strong>Naive ingenuity is where the most visible tokens are burning right now and the least is being built.</strong> Failed experiments and aimless prototypes aren&#8217;t worthless &#8212; they build skills and occasionally surface something real, which is the option value the leaderboard bet was buying &#8212; but as a category they go nowhere by design. Because naive usage is so voluminous, and personal, it&#8217;s the most visible to the simplest forms of observation. That helps it dominate the &#8220;is this all a sham?&#8221; narrative.</p><p><strong>Simple ingenuity has significant usage, but is quickly forgotten. </strong>The high volume usage is generally operationalized, contributing to security, reliability or operational efficiency. It&#8217;s soon forgotten, as it becomes a background effect. It doesn&#8217;t have the humorous, villainous story of tokenmaxxing. It doesn&#8217;t receive the personal promotion of the latest experiment.</p><p>One of the hallmarks of simple ingenuity, is it could be described as a backlog. The work may have been identified as desirable a long time ago, but with other competing priorities, it wasn&#8217;t prioritized. It may also not have been cost effective. One of the changes that AI brings is a change in cost-effectiveness. This activates this backlog, and you should expect early effects to burn this backlog down.</p><p><strong>Simple ingenuity comes early and makes existing work more efficient.</strong> Sometimes this will show up as measurable revenues, but much is internal to companies. In that case it&#8217;s the token usage, the lower labor costs, or the higher quality that are the observations.</p><p>When AI enabled workers have a clear backlog, efficiency gains will flow into simple ingenuity to burn down the backlog. If the backlog results in priced or measured output, you&#8217;ll know.</p><p><strong>Significant ingenuity will take longer to be identified, developed and deployed, especially the pro-social variety. </strong>The economy will reuse freed labor to create more value. That won&#8217;t happen immediately, as it may wait on hiring processes, training processes, or even the formation of new companies pursuing new products or business models.</p><h2>Timing</h2><p>While the development process is accelerated, the identification process retains most of its bottlenecks. Optimism may accelerate it. Idleness may accelerate it. But optimism and idleness may also flow into naive ingenuity, pursuing trivial goals without positive utility. There is a blurry area where naive ingenuity is experimentation. It may fail, but its failure may be necessary to build skills or discover significant opportunities.</p><p>At some point, a few things start to coincide. Naive and simple ingenuity will have built skills, ready to be exploited for realizing significant ingenuity. The backlog&#8217;s distraction fades as it burns down, and a new equilibrium raises the incentive to chase significant work &#8212; significance always carried more reward, but also more risk. But as cost-effectiveness decreases deeper into the backlog, avoiding risk becomes less attractive. All of these, in addition to the passage of time, predict a future wave of significant ingenuity that direct observation of measurements would fail to predict.</p><h2>New output</h2><p>Most of what we&#8217;d recognize as new output is significant, pro-social, and lagged. These are the life-changing things, and they&#8217;re the hardest to forecast. Your best guide might be a science-fiction novel, but of all the futures sci-fi writers have imagined, which do you bet on? Like flying cars, some things that look a step away stay out of reach far longer than expected.</p><p>It would be a mistake, though, to generalize from the failed predictions to all predictions. In many ways today&#8217;s information world already outruns older sci-fi imagination &#8212; the 1987 <em>Star Trek: TNG</em> depicted computers far beyond the 1966 version, and on the information front we&#8217;ve roughly met the standard it set for the 24th century already. The significant wave is hard to time and easy to underestimate at the same time.</p><h1>What to expect</h1><p>We should expect the AI industry to experience some pullbacks, then continue on. Whether this ever meets the bubble narrative is uncertain. I&#8217;m skeptical. Many pullbacks will be met by other accelerations. One experiment fails, another scales.</p><p>There isn&#8217;t one bubble, ready to pop, but multiple domes. Each industry, each set of users finds their value. While software remains so dominant, a failure in the software use case could be dramatic, but much of it is boring simple work that will continue to be automated for some time yet.</p><p>Much of the immediate term work is going to focus on the simplest, most invisible aspects. We shouldn&#8217;t discount the value there. Where it&#8217;s defensive, answering the negative-sum, like security, it has to be done. Where it&#8217;s part of more normal systems, it&#8217;s freeing resources, and developing skills and experience that will fuel more significant ingenuity in the future.</p><p>You do have to wait to see world changing effects. Software, as <a href="https://substack.norabble.com/i/195674034/the-myth-of-the-developers-demise">a model for implementing a workflow</a>, will remain, and the general skills of software developers will be critical to this. Lines will blur, people will cross-over the lines, but ultimately the concept of software will continue to exist.</p><p>If the software dome does collapse, it will create structural damage, like all such events. Failed companies, layoffs, abandoned projects. Resources for naive experimentation would evaporate, and companies would proceed more cautiously. But a structure will remain. The burned-down backlogs that don&#8217;t un-burn, the skills that accumulated, the efficiency that keeps paying out, and the significant work just beginning to grow.</p><p>So, are we in a bubble? Will users and companies pull back on token usage, looking for value, discouraging wasteful tokenmaxxing? Will they react to pricing changes from model providers that close subscription loopholes that allow token usage in excess of what the same money would have bought per token via API? Yes, they will, but will that cause revenue drops that deflate the dome?</p><p>I don&#8217;t think so, there&#8217;s enough pending and developing work to fill the gap. Even if the significant ingenuity is still developing, the simple work is sufficiently valuable and important. But maybe those dynamics will return next year. If compute providers continue yet more expansions, they still might find them getting ahead of demand. There&#8217;s a lot of history to be written here. I&#8217;d just be careful about writing the ending first.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4>Sources</h4><ul><li><p><strong><a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9116627/">Representation of professions in entertainment media: Insights into frequency and sentiment trends through computational text analysis</a></strong><em>; </em>Baruah S, Somandepalli K, Narayanan S..</p></li><li><p><strong><a href="https://openrouter.ai/state-of-ai">State of AI, An Empirical 100 Trillion Token Study with OpenRouter</a>; </strong>Malika Aubakirova,<sup> </sup>Alex Atallah,<sup> </sup>Chris Clark, Justin Summerville, Anjney Midha</p></li><li><p><strong><a href="https://www.derekthompson.org/p/the-great-ai-cost-panic-of-2026">The AI Boom Has Entered Its 'Wait, Is This Worth It?' Era</a></strong>; Derek Thompson</p></li><li><p><strong><a href="https://www.noahpinion.blog/p/how-much-more-software-do-we-really">How much more software do we really need?</a></strong>; Noah Smith</p></li><li><p><strong><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">State of AI in the Enterprise The untapped edge</a></strong>; Deloitte</p></li></ul><h4>Related Articles</h4><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b224348e-0ac5-4170-8ba6-ed69b075a6b9&quot;,&quot;caption&quot;:&quot;Beyond Observed AI Exposure&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI Jobs: The Hidden Rules of Demand&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-16T12:03:39.491Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!RrL0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F520fde3e-dde5-437e-aaf5-9d7f457179f6_2048x1118.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-jobs-the-hidden-rules-of-demand&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190836245,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8f343572-adf2-42ad-bf80-65fb8d2a9a97&quot;,&quot;caption&quot;:&quot;AI is advancing quickly, and if there&#8217;s any one consensus about it, it is that it will have broad impacts on jobs. What impact, is an area of more debate, but it&#8217;s uncommon to view it as non-impactful. Some believe that jobs will disappear, and there would be large amounts of unemployment. Some draw on past periods of technological change, such as the Industrial Revolution or the advent of the internet, and believe that advances ultimately lead to new jobs that didn&#8217;t previously exist.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI and the Zero-Sum Game&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-03-30T16:15:53.873Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3lXS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bdff8e-8e0a-461c-99ae-df41fd06ab63_1024x608.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-and-the-zero-sum-game&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:160183122,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;137ae2fe-2746-49cf-ad56-0ebba3a60099&quot;,&quot;caption&quot;:&quot;Right now, Artificial Intelligence is fundamentally rewriting the rules of cybersecurity&#8212;and we do not have the luxury of waiting before taking action.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Security Can&#8217;t Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T21:05:09.345Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b2a65ed-e701-4f36-8d82-2a665189419b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/security-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190039490,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em>As an example, Noah Smith quotes <a href="https://jellyfish.co/blog/is-tokenmaxxing-cost-effective-new-data-from-jellyfish-explains/">a commonly quoted study on tokenmaxing</a> that claims diminishing returns to token usage, but presents data that should be interpreted as the opposite. In their description, they compare the number of tokens used to create PRs, and the costs of those tokens.</em></p><blockquote><p><em>To evaluate whether that spend is worth it, we joined token usage data with actual developer output, measured in merged pull requests.</em></p><p><em>Over the course of Q1 2026, developers in the bottom 20% of token spend used only about three dollars&#8217; worth of tokens for the entire quarter and shipped an average of 11 merged PRs. By comparison, developers in the top 20% spent $1,822 over the same period and shipped 23 merged PRs on average.</em></p><p><em>In other words, significantly higher token usage does lead to more output, but not proportionally. The cost per merged PR increases from just $0.28 in the lowest usage tier to $89.32 in the highest.</em></p><p><em>More tokens means more output, but at a much higher price per unit.</em></p></blockquote><p><em>But if you&#8217;re comparing costs, the correct comparison would include developer time. If we take a conservative cost of $10,000 / month for a developer the calculation we get is:</em></p><blockquote><p><em><strong>Low token group:</strong> ($30,000 + $3.08) / 11 PRs &#8776; <strong>$2,727/PR</strong><br><strong>High token group:</strong> ($30,000 + $2,054) / 23 PRs &#8776; <strong>$1,393/PR</strong></em></p></blockquote><p><em>There is a sense in which you could use this data to describe diminishing returns, but it&#8217;s not in the realm of cost effectiveness. If someone proposed that development was accelerating exponentially in the way that token usage is, they&#8217;d be wrong. You cannot scale development at the speed of tokens because it is still dependent on developers.</em></p></div></div>]]></content:encoded></item><item><title><![CDATA[Hiring's Accidental War]]></title><description><![CDATA[One-sided fixes become weapons. The exit is collaborative.]]></description><link>https://substack.norabble.com/p/hirings-accidental-war</link><guid isPermaLink="false">https://substack.norabble.com/p/hirings-accidental-war</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 02 Jun 2026 11:16:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5a68c29a-112e-4bb5-84e9-70659fd0b19b_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It should be obvious that job searches have entered an adversarial phase. Nobody planned it, and AI accelerated it, but in a sense it was always there. What interests me is whether we can escape it, and if so, how. I have some instincts on this, that focus on the need to turn away from unnecessary adversarialism in hiring.</p><h2>Avoidable Adversarialism</h2><p>A job search is inherently adversarial <em>within</em> groups. Applicants compete against other applicants. Employers compete against other employers. But the relationship <em>between</em> an applicant and an employer is not inherently adversarial. There is a perfect match and those two matched pairs should want to discover each other.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>When we talk about the adversarial nature of the modern job search, we should separate the inherent part from the avoidable part. The growing hostility <em>between</em> applicants and employers is avoidable. If we can avoid that we&#8217;ll collaborate. Job searches will resolve more quickly, saving money and pain. Workers will be happier and positioned to do the most good for themselves and their employers.</p><p>The devolution into adversarialism is clearly a consequence of limits to information exchange and processing. Employers started filtering resumes to minimize what they spent on hiring. Filters create something to defeat. If an applicant has a reasonable expectation that they&#8217;re a match for a role and they want it, they want to pass the filter. And since they may need to do this many times over, they have every incentive to do it efficiently.</p><h2>The Historical Devolution of Hiring</h2><p>Filtering predates computing. Long before anyone wrote a regex against a resume, recruitment teams read resumes by hand and made decisions from them. By necessity, those filters worked only with what appeared on the page, so candidates learned to structure a resume to pass them.</p><p>When resumes were reviewed by hand, there was some benefit to keyword matching. But there was a secondary method of passing the filter, weaving a story. A recruiter could lean on a strict rubric, or they could read for character, for an arc, for something that spoke to who the applicant was in a way that keyword matching couldn&#8217;t capture. That second channel encouraged investing in each application. Read the full job description, get to know the company, and write a cover letter specific to the role.</p><p>Human readers were also susceptible to word choice, which explains a lot of the fads in resume writing over the decades. Recruiters responded to certain modes of expression. &#8220;Synergistic&#8221; is the classic example, but the pattern runs deeper than any single buzzword. Applicants would notice an opening, exploit it. When recruiters realized they were being exploited a countertrend would set in.</p><p>The thing about that system, for all its gamesmanship, is that it evolved slowly. Trends and countertrends took hold one recruiter at a time. They might spread through HR conferences, trade publications, networks, but every update was individual. The arms race was real, but it moved at human speed.</p><h2>Computerized Filters and Keyword Stuffing</h2><p>Computerizing the filter degraded two things. First, the depth of processing collapsed. Matching became keyword-driven. Stories, arcs, and the patterns that needed a human to understand were no longer assessed.</p><p>Second, the motivation to invest in each application diminished because that investment was demoted to the second tier. If you passed the filter, then someone might read that and you&#8217;d benefit. But it was only rarely worth the effort with that extra distance.</p><p>This second part triggered an adversarial response. It became obvious to applicants that they were in a game, and that the game was everywhere. Callback rates fell from 10+% in the early 2010&#8217;s to 2% in the 2020&#8217;s. The decisions weren&#8217;t fair and weren&#8217;t optimal, so playing the game to its fullest felt like fair play. Resumes filled with keywords. <a href="https://www.stlouisfed.org/on-the-economy/2023/oct/impact-higher-job-application-rates-us-job-finding-rate">Applications per candidate increased</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T_uL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T_uL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 424w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 848w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T_uL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png" width="1456" height="888" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:888,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100000,&quot;alt&quot;:&quot;Chart titled \&quot;Share of applicants invited to interview, by year\&quot;, subtitled \&quot;It held in the teens through 2021 &#8212; no pre-pandemic slide &#8212; then collapsed in 2022 as volume exploded.\&quot; CareerPlug data for US small businesses runs 17% in 2019, 15% in 2020 and 20% in 2021, then drops to 3% in 2022, 2% in 2023 and 3% in 2024; separate Jobvite points for larger employers show 12% in 2015, 15% in 2016 and 12% in 2018.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.norabble.com/i/200159192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Chart titled &quot;Share of applicants invited to interview, by year&quot;, subtitled &quot;It held in the teens through 2021 &#8212; no pre-pandemic slide &#8212; then collapsed in 2022 as volume exploded.&quot; CareerPlug data for US small businesses runs 17% in 2019, 15% in 2020 and 20% in 2021, then drops to 3% in 2022, 2% in 2023 and 3% in 2024; separate Jobvite points for larger employers show 12% in 2015, 15% in 2016 and 12% in 2018." title="Chart titled &quot;Share of applicants invited to interview, by year&quot;, subtitled &quot;It held in the teens through 2021 &#8212; no pre-pandemic slide &#8212; then collapsed in 2022 as volume exploded.&quot; CareerPlug data for US small businesses runs 17% in 2019, 15% in 2020 and 20% in 2021, then drops to 3% in 2022, 2% in 2023 and 3% in 2024; separate Jobvite points for larger employers show 12% in 2015, 15% in 2016 and 12% in 2018." srcset="https://substackcdn.com/image/fetch/$s_!T_uL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 424w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 848w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!T_uL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cd7ef6e-16e3-4926-853f-0623a8aa5216_1640x1000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At first, human reviewers reacted by turning away obviously stuffed resumes forcing custom resumes per job with just the right keywords. Applicants had to balance to make these custom resumes not read like keyword-stuffed garbage to a person. This ate enormous amounts of applicant effort.</p><p>One page norms were initially strongly enforced. But then they gave out. The keyword filter wants more, because keywords need room to slide in while still appearing natural. <a href="https://www.coursera.org/articles/how-many-pages-should-a-resume-be">Mainstream career advice</a> shifted to two pages to leave room for the terms automated systems scan for.</p><p>The human reader, conventional wisdom holds, wants less, a clean document that doesn&#8217;t read as stuffed. But when a resume-writing firm <a href="https://www.resumego.net/research/one-or-two-page-resumes/">ran a hiring simulation</a>, recruiters preferred the two-page version by better than two to one.</p><p>Candidates were in a bind. Some <a href="https://www.reddit.com/r/jobsearchhacks/comments/ifyj55/putting_keywords_in_white_font_on_resumes_to_win/">filled resumes with 1-pt invisible white text</a>, to please keyword filters and avoid reviewer reactions.</p><p>Then generative AI arrived and solved the bind. Applicants could generate a distinct resume for each role, loaded with exactly the right keywords, with acceptable writing quality, in seconds. But the story route was never revived, because there was no longer anyone reading for a story. Recruitment&#8217;s early stages became a machine with no room to absorb narrative.</p><h2>Goodhart&#8217;s Law</h2><p>There is a common description for that process, <a href="https://en.wikipedia.org/wiki/Goodhart%27s_law">Goodhart&#8217;s Law</a>. When a measure becomes a target, it stops being a good measure. Hiring teams have continued looking for targets to measure, but each has receded in usefulness.</p><p>Generative AI didn&#8217;t introduce Goodhart&#8217;s Law to hiring. It did remove the final exceptions. The cost of optimizing acted as a natural brake. Producing a tailored, plausible resume took effort, so people did it selectively. Now it costs nothing.</p><p>A single posting now draws hundreds or thousands of applications, because every applicant is applying to hundreds of postings. That drives employer response rates toward zero, which removes any reason for an applicant to invest care in a particular application, which pushes them to apply to even more roles, which raises volume again.</p><h2>Detectors to the Rescue?</h2><p>Instead of looking to solve the root problems, <a href="https://resume.io/blog/resume-rejections">many hiring managers suggest they&#8217;d use another filter: automatically rejecting AI generated resumes</a>. This is almost certain to turn away many qualified candidates. At best, it leaves behind those who invested the most time into the process. That&#8217;s a poor predictor of candidate quality. It entrenches gamesmanship too. If you&#8217;re tempted to make the argument that candidates investing more time have more confidence, consider the counter; your job may not matter to the most rational candidates. You may just be selecting for the candidates not smart enough to figure out the game.</p><p>Even the detector is suspect. Initially tools could hide the AI provenance, at the cost of quality degradation. Initially this was easy, then detectors got better. But even now, I can say, it&#8217;s not too hard to modify AI written text to not be recognized though. It would slow candidates down, but what&#8217;s the value in that to an individual employer?</p><p>While there&#8217;s some good advice to applicants to worry about accuracy with AI and resumes, this filter is low value. Turning away a quality candidate that used AI does not improve hiring quality. It won&#8217;t change candidate norms. At best it&#8217;s a guess that AI resumes are less accurate. That&#8217;s a questionable assumption due to the pressure on non-AI resumes to inflate.</p><h2>More Requirements</h2><p>So people propose fixes. But almost all of them share the flaw that they inflate candidate costs and arbitrarily filter qualified candidates out.</p><p>Consider degree requirements, which I wrote about separately in <em><a href="https://substack.norabble.com/p/or-equivalent-experience">Or Equivalent Experience</a></em>. Employers routinely demand credentials more restrictive than what their existing workforce holds, and automated screening makes that mistake worse, not better.</p><p>GitHub portfolios are a common suggestion. But building something good or great takes time. Most paid work ends up in confidential repositories. Those few jobs that produce public GitHub history benefit. For everyone else, it&#8217;s a free labor requirement.</p><p>You can spot an amazing GitHub a mile away, but the supply of engineers with that will be low. Categorizing good/average/bad is harder. Are you going to assess generally, or be tech specific? Most hiring focuses on tech specific skills. While I think first principles lead to more actual job success, they are harder to spot. If a candidate has a beautiful data-analysis project in Python, but an employer demands a message-processing stack in Rust, the candidate costs go up further. Any self-made project is about more than engineering skill, it&#8217;s also about ideas and time.</p><p>None of that is fatal, but the later gaming will be. If the signal is genuinely valuable and engineers are desperate enough, people will pay the tax. But what happens <em>after</em> it becomes standard?</p><p>Every standard encourages gaming. Simple things first, like using an underground agent to generate a unique, reasonable-looking GitHub project on demand. The escalation is next; hiring teams create a detector. <strong>Don&#8217;t expect the adversarial dynamics to stop at Level 1.</strong></p><p>Any tool you hand to <em>one</em> side becomes a weapon in the arms race rather than a resolution to it. A new filter for employers invites better evasion from applicants. A better evasion tool for applicants invites better filtering from employers. One-sided solutions, however clever, pull toward competitive dynamics, because the other side never agreed to it and has every reason to defeat it.</p><h2>My Experiences in Interviewing</h2><p>Early in my time at Amazon (2015), I was active in the hiring process, conducting around 60 interviews in the first 2 years. I was surprised at how quickly I was pulled in. But AWS was hiring fast, and Chicago was a new office. The process had promising ideals. One favorite was the idea that your job was to draw positive proofs out of the candidate, not search out flaws. You wanted to hear them describe their approach to a problem or challenge that demonstrated their understanding of the right path forward.</p><p>I&#8217;ve found Steve Yegge&#8217;s writing compelling, and there is shared Amazon experience, so I was drawn to his recent <em><a href="https://steve-yegge.medium.com/the-last-technical-interview-bc13ddcf4564">The Last Technical Interview</a></em>. Yegge was engaged deeper than I was. I avoided the bar raiser path. Imposter syndrome is one reason. I am proud of a number of people who I was part of their hiring loop, or mentored. If there&#8217;s anything that should give you good impressions of your ability to interview, it should be those. But I wasn&#8217;t feeling it at the time, and so when I found a technical problem to focus on, I latched on to that, and pulled away from hiring, doing a handful per year.</p><p>A less optimistic viewpoint was noticing interviewers that took pride in turning down +90% of candidates. If I approved 25% and they turned out well, what are the chances that those turning down two to three times as many weren&#8217;t turning down qualified candidates? There wasn&#8217;t any data to show their 10% was better than my 25%.</p><p>So I had to chuckle at the reflection where <a href="https://steve-yegge.medium.com/the-last-technical-interview-bc13ddcf4564#:~:text=Remember%20That%20Time%20We%20All%20Fired%20Ourselves%3F">his team of interviewers voted not to hire 2/3rds of themselves.</a> Made me feel a bit better about those nagging doubts that should be part of any difficult decision like this.</p><h2>Interview Stages</h2><p><em><a href="https://steve-yegge.medium.com/the-last-technical-interview-bc13ddcf4564">The Last Technical Interview</a></em> does get at something real though. His diagnosis: the interview has been broken for fifty years, even Google&#8217;s best interviewers couldn&#8217;t agree with each other or with their own past judgments. The whole apparatus is an elaborate attempt to generate signal, but consistently falls short. His prescription, the &#8220;campfire&#8221; model, is to bring people in to do paid, real work for a few days, then decide.</p><p>What makes his version more interesting than GitHub is a detail he calls <em>counting the work twice</em>: the candidate walks away with a permanent, portable record of what they did, stamped by the employer, whether or not they get an offer. If I get the concept, the employer would be doing a service for the candidate, and for all other potential employers. Both want the information a &#8220;stamp&#8221; would provide. Well done, this could counterbalance unnecessary adversarial tendencies that have accumulated.</p><p>Because it&#8217;s employer-certified rather than self-reported, it is harder to fake than a repo an agent can spin up. You&#8217;d have to find employers who hand out stamps to everyone, and Yegge is right that failure mode is self-correcting: a company whose stamps mean nothing has stamps worth nothing.</p><p>The network effect here is not one-sided. Both sides care about credibility. Gaming still exists, but if your stamp comes from a company vulnerable to gaming, its value diminishes. The signal lives or dies on <em>credibility</em>. Also, the more personal process offers fewer structural approaches to gaming.</p><p>There&#8217;s definitely some details left unspecified. I worry that some liability concerns could kill it. You still need to screen those invited to a &#8220;campfire&#8221;. You still have to scale.</p><p>An instinct of mine is that this requires some collaboration across the employer space. The campfire with credential stamp would do this, if it scaled. It would be challenging for every employer to create this credibility though if it&#8217;s by word of mouth.</p><p>An idea here is a company that does this as a service for an industry or multiple industries. This could solve the scaling challenge, if this is a passthrough. In some sense, this is what universities are: a 4-year campfire you pay tens of thousands of dollars to attend. I think the flaw is obvious, they are too expensive and too inflexible. In a sense though, they might have the best infrastructure for this impossible mission, should they choose to accept it.</p><h2>The Shared Road Out</h2><p>Which finally points at the answer to the question I opened with. If you want a solution that doesn&#8217;t just escalate the war, it has to be something both sides are actually happy with, or one side will fight it. One-sided efficiency tools breed counter-tools. A solution has to be a collaborative tunnel from the start, or it gets pulled back into the field of competitive options.</p><p>The trouble is we&#8217;re stuck in a bad equilibrium that&#8217;s individually rational. It&#8217;s a coordination trap, structurally a prisoner&#8217;s dilemma. A better equilibrium exists, where applicants apply selectively to roles they fit and employers actually read what comes in, and everyone would be better off there. But reaching it requires someone to move first and trust that the other side won&#8217;t simply exploit the opening. Right now nobody trusts that, for good reason. Applicants won&#8217;t invest in a tailored application when the expected response is silence. Employers won&#8217;t slow down to read carefully when they&#8217;re drowning. Both behaviors are sensible. Both perpetuate the trap.</p><p>So who moves first? Probably the employer, for an unsentimental reason: the employer is the scarcer and concentrated resource. A small show of goodwill from the side holding the scarce thing tends to get reciprocated. A well-known employer with a reputation can start something new. When candidates learn of it, they would opt-in. But it has to be something that builds collaboratively, rather than whittles away negatively.</p><p>I don&#8217;t have a clean answer. But I think the <em>shape</em> of the answer is clear enough, and it&#8217;s not a better resume or a better filter. It&#8217;s changing what each side gets from honest engagement, so that participating sincerely beats gaming.</p><p>Yegge&#8217;s instinct toward &#8220;gravity&#8221; is the right one, even if the mechanism is unfinished: make your rejection valuable, and candidates stop treating you as an adversary to defeat. A few partial paths point the same direction. Employer-certified, portable records of real work, if their credibility can be established. Skills-based hiring done deliberately rather than as language stripped from a posting. Two-sided interest signals like Greenhouse&#8217;s <a href="https://support.greenhouse.io/hc/en-us/articles/35746197803035-MyGreenhouse-Dream-Job">MyGreenhouse &#8220;dream job&#8221;</a> feature, where a candidate can mark one application as special, though even that is still half a handshake until the employer offers something reciprocal. Something as basic as committing to send a real response.</p><p>None of these escapes the adversarial dynamic completely. Each one can be gamed at some level, and you should assume someone will try.</p><p>But that&#8217;s the wrong bar. The question isn&#8217;t whether a solution is immune to gaming. Nothing is. The question is whether it moves the incentives so that honesty is worth more than evasion to <em>both</em> sides at once. The inherent competition, applicant against applicant, employer against employer, isn&#8217;t going anywhere, and that&#8217;s fine. The unnecessary war, applicant against employer, is a failure to generate signal collaboratively.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h5>Related articles</h5><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b93f7ce8-eca8-4b2d-88f4-bcf4844d04f9&quot;,&quot;caption&quot;:&quot;My start in software was early. By my junior year of high school I was already developing software professionally. When others were finishing their second year of college, I was the CTO of a small software company. I wrote most of the software for a company we&#8217;d grow to about $10m in annual sales, had 2 other developers working for me, and also managed a 5 person QA/Support team.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Or Equivalent Experience&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-26T11:35:48.625Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Ttk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/or-equivalent-experience&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199079283,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[Or Equivalent Experience]]></title><description><![CDATA[Lazy Mistakes in Hiring and the Truth Behind Jobs Data]]></description><link>https://substack.norabble.com/p/or-equivalent-experience</link><guid isPermaLink="false">https://substack.norabble.com/p/or-equivalent-experience</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 26 May 2026 11:35:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ttk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>My start in software was early. By my junior year of high school I was already developing software professionally. When others were finishing their second year of college, I was the CTO of a small software company. I wrote most of the software for a company we&#8217;d grow to about $10m in annual sales, had 2 other developers working for me, and also managed a 5 person QA/Support team.</p><p>With that in mind, I have a reaction to seeing so many job postings in the software industry that look like this:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p>Bachelors degree or equivalent experience</p></li><li><p>10+ years of experience building software</p></li></ul><p>The first line is the requirement. The second line is a fig leaf &#8212; a way of technically not lying while still signaling what the process actually rewards. It was always a questionable practice, but AI is supercharging the impacts of this mistake.</p><h3>The Logical Problem</h3><p>Let&#8217;s start with the plain English issue, which is almost embarrassing once you see it.</p><p>From a logical point of view, these statements are redundant. 10+ years of experience will always be equivalent experience. There is no interpretation under which a decade of real-world engineering doesn&#8217;t constitute equivalent experience to a four-year degree.</p><p>The problem runs deeper than embarrassing logic. The reality is that equivalence is probably fiction. Most hiring managers, I&#8217;d wager, didn&#8217;t author this language and don&#8217;t think about it. But it activates biases in recruitment teams, offering a lazy shortcut, and sending the wrong message.</p><h2>Automation and AI are Supercharging this Mistake</h2><p>This was always a mistake, but it&#8217;s becoming more critical. Recruitment teams scanning resumes will be drawn toward an education section more readily than to calculating the equivalent experience. Automated tools in applicant tracking systems (ATS), including AI, have the same weakness, often more so.</p><p>How is a typical large language model (LLM) going to process these statements? The degree is a binary, well-defined data point with a clear answer. &#8220;Equivalent experience&#8221; is the opposite: fuzzy, context-dependent, requiring judgment. Even if the LLM evaluates the two statements correctly, it could make another mistake, treating the &#8220;or&#8221; as an &#8220;and&#8221;, or treating the two statements as components of an overall &#8220;closest match&#8221;.</p><p>These mistakes could cause a filter to fail, or it could cause a lower score. If the three clauses are processed independently, the degree holder gets 3 points, other candidates 2. If qualifications aren&#8217;t scored equally, one earlier in the list will usually get more weight. Even if a system doesn&#8217;t intentionally add a scoring system, a reasoning model could create one on its own.</p><p>More advanced systems are less likely to make these mistakes, but recruitment teams may not use the most advanced systems. This might be motivated by cost, or adoption started before systems advanced. They may even be non-AI, simple text analysis.</p><p>In this environment where job postings get hundreds of applicants, because every applicant is applying for hundreds of positions, a naive filter or scoring system can have a dramatic impact. The more nuanced aspects of a resume that should make you a top candidate, may never get processed. That means fewer interviews, dramatically reducing the probability of a successful interview.</p><h2>What should you do?</h2><p>The simplest thing to do is remove any such text from job descriptions. Since they are duplicative, and creating unintended effects, just delete them. And it&#8217;s not just those &#8220;or equivalents&#8221;. You should rethink degree requirements in general.</p><p>That&#8217;s not enough though.</p><div class="callout-block" data-callout="true"><p><em>Our analysis makes clear that successful adoption of Skills-Based Hiring involves more than simply stripping language from job postings. To hire for skills, firms will need to implement robust and intentional changes in their hiring practices &#8211; and change is hard. Still, despite the limited progress to-date, our analysis shows that, for those who embrace it, skills-based hiring goes beyond corporate virtue signaling. It yields tangible, measurable value. Skills-Based Hiring boosts retention among non-degreed workers hired into roles that formerly asked for degrees. At Skills-Based Hiring Leader firms, non-degreed workers have a retention rate 10 percentage points higher than their degree-holder colleagues. Workers benefit as well. Non-degreed workers hired into roles that previously required degrees experience a 25 percent salary increase on average.</em></p><p><strong><a href="https://www.burningglassinstitute.org/research/skills-based-hiring-2024">Harvard Business School and Burning Glass Institute: Skills-Based Hiring: The Long Road from Pronouncements to Practice (2024)</a></strong></p></div><p><strong>If you&#8217;re not deliberate about this when working with your recruitment team,</strong> <strong>you may get no change or the wrong change.</strong> If they remove &#8220;or equivalent experience&#8221;, keep an internal filter or priority ranking, or just act on their own biases, you may get no change at all.</p><p>Should that be your intent? You might ask if you&#8217;re better off with the filter. There&#8217;s a couple things you can do to validate that this isn&#8217;t sensible. First, you might want to familiarize yourself with the actual rates of postings and workers. In many cases, the postings are more restrictive than the workers. Something seems wrong if it is true that if you had to rehire the entire workforce, 20% would be excluded. If 66% of those without a degree already doing the job wouldn&#8217;t get a job, you have to wonder.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ttk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ttk1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 424w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 848w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 1272w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ttk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png" width="871" height="459" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/60301e07-74c5-4490-8eba-27a4128217e5_871x459.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:459,&quot;width&quot;:871,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67084,&quot;alt&quot;:&quot;Chart Title: FIGURE 1: Postings requiring a degree v. workers with a degree, by occupation  Legend:  Orange block: % of postings requiring BA  Blue block: % of workers with BA  Data Points (by Category):  Web designers  % of postings requiring BA: 91%  % of workers with BA: 71%  HR managers  % of postings requiring BA: 88%  % of workers with BA: 72%  Industrial designers  % of postings requiring BA: 85%  % of workers with BA: 72%  Insurance underwriters  % of postings requiring BA: 77%  % of workers with BA: 61%  Logisticians  % of postings requiring BA: 76%  % of workers with BA: 46%  Facilities managers  % of postings requiring BA: 56%  % of workers with BA: 39%  Source Citation: Source: Burning Glass Institute analysis of Lightcast job postings data&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Chart Title: FIGURE 1: Postings requiring a degree v. workers with a degree, by occupation  Legend:  Orange block: % of postings requiring BA  Blue block: % of workers with BA  Data Points (by Category):  Web designers  % of postings requiring BA: 91%  % of workers with BA: 71%  HR managers  % of postings requiring BA: 88%  % of workers with BA: 72%  Industrial designers  % of postings requiring BA: 85%  % of workers with BA: 72%  Insurance underwriters  % of postings requiring BA: 77%  % of workers with BA: 61%  Logisticians  % of postings requiring BA: 76%  % of workers with BA: 46%  Facilities managers  % of postings requiring BA: 56%  % of workers with BA: 39%  Source Citation: Source: Burning Glass Institute analysis of Lightcast job postings data" title="Chart Title: FIGURE 1: Postings requiring a degree v. workers with a degree, by occupation  Legend:  Orange block: % of postings requiring BA  Blue block: % of workers with BA  Data Points (by Category):  Web designers  % of postings requiring BA: 91%  % of workers with BA: 71%  HR managers  % of postings requiring BA: 88%  % of workers with BA: 72%  Industrial designers  % of postings requiring BA: 85%  % of workers with BA: 72%  Insurance underwriters  % of postings requiring BA: 77%  % of workers with BA: 61%  Logisticians  % of postings requiring BA: 76%  % of workers with BA: 46%  Facilities managers  % of postings requiring BA: 56%  % of workers with BA: 39%  Source Citation: Source: Burning Glass Institute analysis of Lightcast job postings data" srcset="https://substackcdn.com/image/fetch/$s_!Ttk1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 424w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 848w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 1272w, https://substackcdn.com/image/fetch/$s_!Ttk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60301e07-74c5-4490-8eba-27a4128217e5_871x459.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Percentage of workers without a degree already in roles. <a href="https://www.burningglassinstitute.org/research/skills-based-hiring-2024">Image Source</a></em></figcaption></figure></div><p>Is that not enough? Then ask yourself, do you know something about the other 20% that makes you want to exclude them? I suspect you don&#8217;t. Once on a job, no one asks, but most assume.</p><p>Here&#8217;s the test: which of these has happened for you more often when working with professionals in their field?</p><ul><li><p>You learn someone doesn&#8217;t have a degree, and say, hmm, would have never guessed that! Bob is so smart.</p></li><li><p>You learn someone doesn&#8217;t have a degree, and say, oh, now that explains it, I always wondered why Bob was so dumb.</p></li></ul><p>It&#8217;s possible you have little data to work with, because people working on solving a hard problem don&#8217;t ask that kind of question. It does come up socially on occasion. If you do have a data gap, it&#8217;s not hard to close, just ask a few people. You&#8217;ll have to ask 50 people if they have a degree to find 10 that don&#8217;t. Because both the affirmative (no degree = smarter), and null hypothesis (no predictive power from degree), are on the same side, it doesn&#8217;t take a large same size to disprove the implied assumption.</p><p>The strongest case to put a degree on a qualification list is early in careers. This is where &#8220;or equivalent experience&#8221; actually makes sense. A candidate who just spent four years studying, 2 of it on practical development work is reasonably comparable to one who spent 4 years building products</p><h2>But AI is hurting college grads. Should we give them an advantage?</h2><p>There&#8217;s a pair of stories circulating about how bad recent grads have it in the job market. Should we give them an advantage, ensuring their expensive degree doesn&#8217;t come without rewards? There&#8217;s two data points cited on this topic, unemployment and underemployment. Both have flaws in their representation.</p><h3>Underemployment</h3><p>The underemployment data point is weakest, and generally just demonstrates a blind spot for those circulating it. The recent number is 41.5%, which does sound horrible without context. But all data should have context. This is not news, it&#8217;s a failure to understand the data. If I heard a number like that, I&#8217;d ask.. Well what is underemployment.. And what was it like in the past? It&#8217;s not hard to find <a href="https://www.newyorkfed.org/research/college-labor-market#--:explore:underemployment">the original source</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-MGs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-MGs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 424w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 848w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 1272w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-MGs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png" width="950" height="921" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:921,&quot;width&quot;:950,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Underemployment Rates for Recent College Graduates Sources: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS); U.S. Department of Labor, O*NET.  Notes: The underemployment rate is defined as the share of graduates working in jobs that typically do not require a college degree. A job is classified as a college job if 50 percent or more of the people working in that job indicate that at least a bachelor's degree is necessary; otherwise, the job is classified as a non-college job. Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display. October 2025 results are estimated due to missing data&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Underemployment Rates for Recent College Graduates Sources: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS); U.S. Department of Labor, O*NET.  Notes: The underemployment rate is defined as the share of graduates working in jobs that typically do not require a college degree. A job is classified as a college job if 50 percent or more of the people working in that job indicate that at least a bachelor's degree is necessary; otherwise, the job is classified as a non-college job. Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display. October 2025 results are estimated due to missing data" title="Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Underemployment Rates for Recent College Graduates Sources: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS); U.S. Department of Labor, O*NET.  Notes: The underemployment rate is defined as the share of graduates working in jobs that typically do not require a college degree. A job is classified as a college job if 50 percent or more of the people working in that job indicate that at least a bachelor's degree is necessary; otherwise, the job is classified as a non-college job. Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display. October 2025 results are estimated due to missing data" srcset="https://substackcdn.com/image/fetch/$s_!-MGs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 424w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 848w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 1272w, https://substackcdn.com/image/fetch/$s_!-MGs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c8dbda-f2dd-47ba-b406-d93a3477e75d_950x921.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Recent college graduate underemployment rate (1990-2024). <a href="https://www.newyorkfed.org/research/college-labor-market#--:explore:underemployment">Image Source</a></em></figcaption></figure></div><p>What you can see below is that 41.5% is lower than most historical periods. Is that worth freaking out over? No.</p><p>If you read the explanation, you understand why the number is this high. It asks people, working in the job, if a college degree is necessary. If you polled me about any software engineering, I&#8217;d answer no. I&#8217;m sure it is on the list, because probably the majority of the 80% of software engineers who do have a degree are answering yes.</p><p>While software engineering is likely on the list<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> I can think of a lot of other things people commonly go to college for that even the college grads would likely answer no. Went to school to study art or music? Would you classify that as requiring a degree? Filmmaking? Social worker? What about some that might be on the list but are debatable? Journalist? Newswriter?</p><p>There&#8217;s also some majors on this list that appear because it&#8217;s tracking recent bachelor grads, but these majors usually go on to higher degrees (JD), law, business (MBA).</p><h3>Unemployment</h3><p>The unemployment story is more nuanced, but still represented as more than it is. It does show a change, but is it worth the reaction it has received?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p1vz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p1vz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 424w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 848w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 1272w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p1vz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png" width="957" height="902" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d8172081-98e4-41eb-9af6-598c4fabded7_957x902.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:902,&quot;width&quot;:957,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167688,&quot;alt&quot;:&quot;Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Unemployment Rates for Recent College Graduates versus Other Groups Source: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS).  Notes: Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. Young workers are those aged 22 to 27 without a bachelor's degree. All workers are those aged 16 to 65. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Unemployment Rates for Recent College Graduates versus Other Groups Source: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS).  Notes: Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. Young workers are those aged 22 to 27 without a bachelor's degree. All workers are those aged 16 to 65. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display." title="Header Label: Latest Release: May 5, 2026, with 2026:Q1 data  Chart Title: Unemployment Rates for Recent College Graduates versus Other Groups Source: U.S. Census Bureau and U.S. Bureau of Labor Statistics, Current Population Survey (IPUMS).  Notes: Rates are seasonally adjusted and smoothed with a three-month moving average. College graduates are those aged 22 to 65 with a bachelor's degree or higher; recent college graduates are those aged 22 to 27 with a bachelor's degree or higher. Young workers are those aged 22 to 27 without a bachelor's degree. All workers are those aged 16 to 65. All figures exclude those currently enrolled in school. Shaded areas indicate periods designated recessions by the National Bureau of Economic Research. Click on the labels in the chart legend to show and hide trend lines in the display." srcset="https://substackcdn.com/image/fetch/$s_!p1vz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 424w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 848w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 1272w, https://substackcdn.com/image/fetch/$s_!p1vz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8172081-98e4-41eb-9af6-598c4fabded7_957x902.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Unemployment rate: Recent college graduates vs. all workers. <a href="https://www.newyorkfed.org/research/college-labor-market#--:explore:unemployment">Image Source</a></em></figcaption></figure></div><p>What news stories highlight is that the light blue line (recent college graduates), has never been above (all workers) in the past. But is this a fair comparison? After all, a recent college graduate by definition starts unemployed. At some point in that 5 year span, they graduated, and started job seeking. It&#8217;s an apples to oranges comparison. All workers are the incumbents. Some of those workers may have been working the same job for the last 10 or 20 years. Since unemployment rates are based upon those &#8220;seeking&#8221; jobs, what you&#8217;re comparing here is first a fraction of all workers who lost a job recently, and then a sub-fraction of those who had difficulty finding a new job, vs. all college graduates, a fraction of which had difficulty finding their first job.</p><p>Shouldn&#8217;t &#8220;recent college graduates&#8221; be compared against &#8220;young workers&#8221;? There&#8217;s still a story there, in that the gap has shrunk, but the story isn&#8217;t that college graduates are getting a raw deal, but that there&#8217;s more equity between with/without. That&#8217;s a lot harder to make a decision about. How big a gap do we expect here? Don&#8217;t we want employment opportunities for those without a degree?</p><p><strong>The Blind Spot</strong></p><p>Partly I&#8217;m calling this out because it&#8217;s a current story that people are getting wrong, but partly I&#8217;m also demonstrating a general blindness that seems pervasive in what I&#8217;ll assume are mostly college grads discussing this story. They assume that the worlds of college grads and non-college grads are so universally distinct that there would be no overlap here. They assume that the only way you could be prepared for a job fit for a college grad is the same path.</p><p>The reality is that in terms of learning, college is just a convenient path, with a lot of resources laid out in front of you, no other responsibilities, and encouragement to follow a plan. College is many other things, a credentialing mechanism and an opportunity to build social networks, for example. But in terms of learning it&#8217;s not magical. You learn by consuming information and solving problems related to what you&#8217;re learning, and that opportunity has a lot of entry points.</p><p><strong>Conclusion</strong></p><p>College should be valuable to those that go. But its value should always stem from the learning it enables. Learning comes from many sources, the college experience is simply a well-resourced and well-structured source. Job experience is valuable in its unique way. In both cases, you have to make those experiences count. Your curiosity, your interest, and your hard work are what translate experiences to learning. A college experience, when done well, should be able to do this more effectively than a job. This is because enabling learning is its primary objective, whereas job experience has to compete with other objectives.</p><p>All that said, laziness will make any experience intellectually unrewarding. It&#8217;s worrying the degree of laziness applied to the hiring process and the data behind recent news stories. We should do better. We shouldn&#8217;t blame this on AI, that would be lazy too. <a href="https://substack.norabble.com/p/the-slop-scapegoat-ai">Lazy slop</a> was a problem before AI. It has a deeper cause. Maybe it&#8217;s growing, or maybe it&#8217;s always been with us. Whatever the case, honesty will get us farther than scapegoats.</p><p>Barriers, like degree requirements, enacted out of laziness or to create a condition of privilege are a mistake. We shouldn&#8217;t use them. In my opinion, degrees shouldn&#8217;t matter if you&#8217;ve already successfully done the job. This is doubly true if the job is more complex than anything schooling would have covered. In theory, it seems many employers agree, as the terminology, &#8220;or equivalent experience&#8221; has been common. But words are one thing, practice is another. A lazy translation of intent to practice that fails to meet the goal is harmful. This is but one of many, but hopefully I&#8217;ve made it clear how this one is a mistake.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Sources:</strong></p><ul><li><p><strong><a href="https://www.hbs.edu/ris/Publication%20Files/dismissed-by-degrees_707b3f0e-a772-40b7-8f77-aed4a16016cc.pdf">Dismissed by Degrees:</a></strong><a href="https://www.hbs.edu/ris/Publication%20Files/dismissed-by-degrees_707b3f0e-a772-40b7-8f77-aed4a16016cc.pdf"> How degree inflation is undermining U.S. competitiveness and hurting America&#8217;s middle class</a>; Joseph B. Fuller, Manjari Raman; Harvard Business School; 2017.</p></li><li><p><strong><a href="https://www.nber.org/system/files/chapters/c13697/c13697.pdf">Underemployment in the Early Careers of College Graduates following the Great Recession</a></strong>; Jaison R. Abel and Richard Deitz; National Bureau of Economic Research; 2018.</p></li><li><p><strong><a href="https://www.burningglassinstitute.org/research/skills-based-hiring-2024">Skills-Based Hiring: </a></strong><a href="https://www.burningglassinstitute.org/research/skills-based-hiring-2024">The Long Road from Pronouncements to Practice</a>; Sigelman, M., Fuller, J., Martin, A.; Burning Glass Institute; (February 2024).</p></li><li><p><strong><a href="https://www.newyorkfed.org/research/college-labor-market#--:overview">The Labor Market for Recent College Graduates</a></strong>; Federal Reserve Bank of New York; 2026</p></li></ul><h5>Related articles</h5><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b8164529-4fa1-4ec6-a1fb-49af22e54cb5&quot;,&quot;caption&quot;:&quot;It should be obvious that job searches have entered an adversarial phase. Nobody planned it, and AI accelerated it, but in a sense it was always there. What interests me is whether we can escape it, and if so, how. I have some instincts on this, that focus on the need to turn away from unnecessary adversarialism in hiring.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Hiring's Accidental War&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-02T11:16:54.327Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a68c29a-112e-4bb5-84e9-70659fd0b19b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/hirings-accidental-war&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:200159192,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>While I wasn&#8217;t able to find a current list of what occupations are on this list, the category was created for this <a href="https://www.nber.org/system/files/chapters/c13697/c13697.pdf">2018 study, </a><strong><a href="https://www.nber.org/system/files/chapters/c13697/c13697.pdf">Underemployment in the Early Careers of College Graduates following the Great Recession</a></strong>. At that time, the largest category of underemployment was as a &#8220;manager or supervisor&#8221;, then &#8220;office and administrative support&#8221;, &#8220;sales&#8221;. The highest paid underemployment category was &#8220;information processing and business support&#8221;. In terms of majors, the most likely to be underemployed was criminal justice, performing arts, and leisure and hospitality, which you can find both the 2024 data for (in the <a href="https://www.newyorkfed.org/research/college-labor-market#--:explore:outcomes-by-major">outcomes by major at the Fed link</a>) and 2013 data for (in the original report as Table 4.6). Even in fields that look like they&#8217;d be AI related, underemployment has not grown. Computer Engineering was 15.8% in 2024, 18.0% in 2013. Computer science was 19.1% in 2024, 26.9% in 2013. The only cases it was higher in 2024? Industrial engineering and nursing.</p></div></div>]]></content:encoded></item><item><title><![CDATA[AI Safety Is Underfunded by Design]]></title><description><![CDATA[A Model for Incentive-Aligned AI Safety Policy]]></description><link>https://substack.norabble.com/p/ai-safety-is-underfunded-by-design</link><guid isPermaLink="false">https://substack.norabble.com/p/ai-safety-is-underfunded-by-design</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 19 May 2026 12:32:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bzM0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://open.substack.com/pub/hyperdimensional/p/before-leviathan-wakes?r=10qod6&amp;selection=d1cf1ce7-3c3e-4b71-9b6d-4ea7f45c0f60&amp;utm_campaign=post-share-selection&amp;utm_medium=web&amp;aspectRatio=instagram&amp;textColor=%23ffffff&amp;bgImage=true">Dean Ball recently put his finger on something important about AI liability and incentives</a>:</p><blockquote><p><em>In general, market actors do not have great incentives to protect against catastrophic risks. They are massive negative externalities, often dwarfing the balance sheet of any individual firm. Say Anthropic releases a model that a malicious actor uses to conduct a cyberattack that does $5 trillion dollars in damage. Anthropic is only worth $800 billion, so if they get sued for $5 trillion, they are already well past the point of insolvency. A catastrophic harm may well already be &#8220;lights out&#8221; for Anthropic, or any other company, so there is little incentive to avoid them, if doing so entails real costs in the present day.</em></p></blockquote><p>He&#8217;s right about the structure of the problem &#8212; but &#8220;little incentive&#8221; understates the precision available here. AI companies do have incentive to avoid catastrophic outcomes, just systematically less than society needs them to. That gap can be quantified, and quantifying it points toward what a corrective policy should actually look like.</p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/ai-safety-is-underfunded-by-design?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/ai-safety-is-underfunded-by-design?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><p>The concerns he&#8217;s talking about &#8212; catastrophic risks &#8212; share a structural feature that distinguishes them from others: they are lumpy. A single catastrophic event, rather than a diffuse trend. The incentive is quite large, but not as large as it should be. These dynamics are worth exploring, as those ultimately shape if and how we structure a response.</p><p>Consider a hypothetical AI company, worth $800 billion. Now consider a hypothetical event causing $5 trillion in damages. If this event happened, that AI company would be out of business, so they have an incentive to prevent it. But how much incentive? The most they can lose is the whole company, so $800 billion. Since a lot of that is goodwill, in reality, losses become irrelevant earlier. For the sake of example, we&#8217;ll say $400 billion. If you had to pay half your market cap, you&#8217;re not worth $400 billion, you&#8217;re bankrupt, and worth $0. All claims greater than $400 billion have equal impact, since each produces the same outcome, a total loss.</p><p>This creates an imbalance between societal goals and the AI company&#8217;s goals. That imbalance could lead to underinvestment in safety, or risk taking that is out of alignment with societal goals.</p><p>We can quantify this imbalance, by modeling a damage cap in expected value calculations. If our $5 trillion event has a 1 in 10,000 chance of occurring, the uncapped expected value of avoidance is $500 million. With a damage cap of $400 billion, it&#8217;s only $40 million. Society should want that other $460 million in incentive to be shared by the AI company, but without an arrangement, it&#8217;s not.</p><h2>Refinements</h2><p>I used a simple model above, with linear effectiveness of investment in safety. It isn&#8217;t linear. In a linear model, spending $500 million reduces risk to zero, and $40 million reduces it to 1/12th of that, or one 1 in 9,166. But we could imagine, in fact we should expect, that the first $40 million does more than the next $40 million. Maybe the first reduces the risk to 1 in 100,000, and the next to 1 in million. It&#8217;s the same proportional improvement &#8212; 10x. But in the first case it reduces the risk from 100/million to 10/million for a total reduction of 90/million. The second case reduces from 10/million to 1/million, for a total of 9/million reduction.</p><p>To illustrate, I constructed a model that used logarithmic decay from the initial 1 in 10,000. In this model, under their default incentives, the AI company would want to spend $13.3 million to reduce their expected risk from $40 million to $8.7 million. But the societal risk is still $122 million at this point.</p><p>The goal of a corrective policy would be for the AI company to act upon the societal risk, which justifies spending $35.2 million to reduce the societal risk to $8.7 million.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bzM0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bzM0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 424w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 848w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 1272w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bzM0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png" width="800" height="473" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:473,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Line chart titled \&quot;The Mitigation Paradox: Diverging Incentives under Exponential Risk Decay\&quot;, plotting cost in millions against safety investment in millions. Corporate total cost, which carries only capped risk, bottoms out early at a corporate optimum of $13.3M, while societal total cost, carrying uncapped risk, bottoms out much later at a societal optimum of $35.2M.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart titled &quot;The Mitigation Paradox: Diverging Incentives under Exponential Risk Decay&quot;, plotting cost in millions against safety investment in millions. Corporate total cost, which carries only capped risk, bottoms out early at a corporate optimum of $13.3M, while societal total cost, carrying uncapped risk, bottoms out much later at a societal optimum of $35.2M." title="Line chart titled &quot;The Mitigation Paradox: Diverging Incentives under Exponential Risk Decay&quot;, plotting cost in millions against safety investment in millions. Corporate total cost, which carries only capped risk, bottoms out early at a corporate optimum of $13.3M, while societal total cost, carrying uncapped risk, bottoms out much later at a societal optimum of $35.2M." srcset="https://substackcdn.com/image/fetch/$s_!bzM0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 424w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 848w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 1272w, https://substackcdn.com/image/fetch/$s_!bzM0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9e5a2c4-7156-4e6c-8733-747e52ec589e_800x473.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Further refinement considers whether organic spending is more efficient than regulatory-induced spending. For example, if regulatory-induced spending had half the effect per dollar as organic spending, not only would the spending go up, but the residual damage would be higher.</p><p>In Scenario 1, all spending is equally valuable. In Scenario 2, the company spends efficiently up to its capped motivation, after which each real dollar buys only $0.50 of effective safety. And finally in Scenario 3, all spending is at 50% effectiveness.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3kHO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3kHO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 424w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 848w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 1272w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3kHO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png" width="1456" height="1308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1308,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Chart comparing three safety-spending scenarios &#8212; organic, organic plus regulation, and all regulatory &#8212; with a summary panel of optima and costs above. The left axis is company total expected cost and the right axis societal total expected cost, sharing a zero and a 10:1 ratio so the curves are comparable. Scenarios 2 and 3 reach identical residual damage of $17.4M, but scenario 3 requires $13.3M more real spending to get there, erasing the gains from previously organic safety work.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Chart comparing three safety-spending scenarios &#8212; organic, organic plus regulation, and all regulatory &#8212; with a summary panel of optima and costs above. The left axis is company total expected cost and the right axis societal total expected cost, sharing a zero and a 10:1 ratio so the curves are comparable. Scenarios 2 and 3 reach identical residual damage of $17.4M, but scenario 3 requires $13.3M more real spending to get there, erasing the gains from previously organic safety work." title="Chart comparing three safety-spending scenarios &#8212; organic, organic plus regulation, and all regulatory &#8212; with a summary panel of optima and costs above. The left axis is company total expected cost and the right axis societal total expected cost, sharing a zero and a 10:1 ratio so the curves are comparable. Scenarios 2 and 3 reach identical residual damage of $17.4M, but scenario 3 requires $13.3M more real spending to get there, erasing the gains from previously organic safety work." srcset="https://substackcdn.com/image/fetch/$s_!3kHO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 424w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 848w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 1272w, https://substackcdn.com/image/fetch/$s_!3kHO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b5b1f0a-1cce-4daf-b8df-e24aa475d80e_1472x1322.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You can <a href="https://norabble.github.io/incentive-caps/">explore other scenarios in the linked single page app</a> (<a href="https://github.com/norabble/incentive-caps">GitHub Repo</a>). You can experiment with different decay functions, damage sizes and company sizes.</p><h2>Organic Forces</h2><p>We&#8217;d also be doing ourselves a disservice if we didn&#8217;t recognize the outstanding work that AI companies have done &#8212;<a href="https://www.anthropic.com/research/anthropic-institute-agenda"> Anthropic most of all</a>. Commercial incentives alone aren&#8217;t sufficient. The<a href="https://colossus.com/article/project-mario-demis-hassabis-deepmind-mallaby/"> stories about the founding of DeepMind and OpenAI</a> make clear that good intent has played a positive role. But in a commercial world, you can&#8217;t depend on good intent to reliably show up or win internal contests. The pressure to go off track is substantial. For something this important, that&#8217;s a lot of trust. We want to use these forces, because they are efficient, but must not be naive either.</p><p>We don&#8217;t want to take organic forces for granted. If we assume they don&#8217;t need support, they might disappear. If we don&#8217;t acknowledge their value, we might strangle them.</p><h2>Small Firms</h2><p>The alignment problem becomes more acute for smaller companies. What if a smaller startup, with none of the weight of a larger company &#8212; little to lose, and everything to gain &#8212; rushes ahead, and skips best practices that avoid harm?</p><p>The leading labs are large (Anthropic, OpenAI and Google), but we shouldn&#8217;t take that for granted. Frontier model training costs keep going up, but the costs for a particular level of capability keep going down. DeepSeek proved that moats are much shallower than assumed.</p><p>You do want to avoid locking out startups, but also need a baseline that ensures safety isn&#8217;t skipped. A first step here is ensuring safety practices are shared. That lowers their costs in pursuing safety.</p><p>The current voluntary norm &#8212; leading labs sharing safety methodology despite having competitive reasons not to &#8212; is a favorable state of affairs that formal structure can preserve and extend. It will take organization to make it work at a deeper level. Sharing details of some safety practices publicly can add risk, so a well-trusted network for sharing enables more than just the public domain approach. Formalizing sharing as a condition of operating at the frontier, both preserves what already occurs, and can extend it more deeply.</p><h2>Regulatory Shape</h2><p>The model makes the policy objective concrete: close the gap between what the company is motivated to spend and the societal expected value, without crowding out the organic safety investment that&#8217;s already happening.</p><p>A naive response assumes insurance is enough, and the challenge is finding a large enough reinsurer to pay out. An even more naive response assumes this challenge can be fixed by inserting the federal government as a backstop to the insurance. The flaw in this thinking is that it makes society responsible for paying itself back for harm done to it. This won&#8217;t work. The harm would have been done. Society would pay for the majority of the consequences of the gamble the AI companies made.</p><p>These dynamics suggest that effective regulation needs balance, in order to use organic forces, and yet also not leave a gap. Dean is right that it improves the case for government involvement. If there&#8217;s a gap between the company&#8217;s incentives and the societal incentives on a topic so important, we should align those.</p><p>An industry body that both shares security practices and sets standards is a start. Shared excess liability amongst all AI companies would add to existing incentives. If one fails to prevent harm in a small way, that company fails alone. If one fails in a big way, they all fail. Expanding the pool in this way is better than involving the government, as these are the players with the ability to influence the risk. Those incentives will encourage maintaining quality standards, but keep the standards moored to efficiency and effectiveness.</p><p>That&#8217;s still not enough though, so a government body above that respects the value of organic forces, would be a second step. The challenge here is how to prevent this body from losing interest in efficiency. It&#8217;s natural for them to be interested in effectiveness, but efficiency comes with more difficulty. If standards ignore efficiency, you undermine the organic forces and risk taking a step backwards instead of forwards.</p><h2>What doesn&#8217;t work?</h2><p>The framework I&#8217;m discussing, can appear to be a compromise between two points of view. That&#8217;s not the intent. There is no intent to choose a middle point, in order to satisfy two points of view. I think the merits of this model fit without any politics.</p><p>The model does however balance multiple forces, and is not aligned with any maximal plan. That type of balance only makes sense if the maximal plans aren&#8217;t reasonable. To make it clear, I don&#8217;t support any maximal plans. It will take additional posts to flesh out why, and others have defended these points independently. But in the light of outlining my thinking, the basic is:</p><ul><li><p><strong>AI bans:</strong> You have no chance. You have no global solution. It&#8217;s not a good idea in the first place, as AI will be very useful, but that&#8217;s not the biggest flaw. The biggest flaw is all of the partial wins - company X refuses to use AI, country Y bans AI - they all fail in the end and don&#8217;t contribute to any goal aligned with the best case for a ban.</p></li><li><p><strong>No regulations: </strong>Clearly something is needed here. This group is somewhat of a strawman though, as even people like Dean Ball see a role for regulation. The better critique is that there are many people who are implicitly &#8220;no regulationists&#8221;, because they oppose everything proposed and don&#8217;t put together enough to actually do something.</p></li><li><p><strong>Top-down regulations:</strong> Strangling organic safety efforts in top-down paperwork is a surefire way to fail. That doesn&#8217;t mean there isn&#8217;t a top, but it does mean, it can&#8217;t be total, and since it&#8217;s starting later, it should expect to start small and iteratively find its fit.</p></li></ul><p>Clearly, there are more details to cover here. I&#8217;ve only touched on one dynamic that sets an overall tone, but you&#8217;d eventually need a list of initial best practices, and an expert-led group to maintain them. You&#8217;ll need a mechanism to choose that group, and a list of powers and limitations that define how they work together, and resolve conflicts. I&#8217;ll leave those questions for a future post though.</p><div class="callout-block" data-callout="true"><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/p/ai-safety-is-underfunded-by-design?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.norabble.com/p/ai-safety-is-underfunded-by-design?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p style="text-align: center;"><em>Do you appreciate this article? The best way to help the publication is to like and share the article, as we&#8217;re still growing our audience. </em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://substack.norabble.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>You should also consider subscribing to get an easy to read email copy of new articles.</em></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Challenges for AI Misuse Prevention]]></title><description><![CDATA[Jurisdictions, Open Models, and Privacy]]></description><link>https://substack.norabble.com/p/challenges-for-ai-misuse-prevention</link><guid isPermaLink="false">https://substack.norabble.com/p/challenges-for-ai-misuse-prevention</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 12 May 2026 11:05:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8a4fc3eb-2ecb-43c0-86ab-0dcd67a4c8f9_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Preventing the use of AI for malicious purposes is critical. Malicious use means some human somewhere wants to create harm. AI is a new tool for them. In theory, existing law would apply to those creating harm.</p><p>Today I wanted to talk about some challenges that complicate preventing malicious use.</p><h2>Jurisdictions</h2><p>A first failure of existing law is jurisdictions. The world has rogue states, lawless states, and aggressor states. These either turn a blind-eye toward harmful activity, lack the capability to enforce laws, or actively create targeted harm themselves. Existing laws cannot reliably reach actors that hide in these jurisdictions. There is a justified effort to close those gaps. There is slow progress. Sometimes gaps reopen. Because it&#8217;s a long running effort, we shouldn&#8217;t expect a near-term resolution, and treat it as a reality we must mitigate.</p><p>If we can&#8217;t target the originator of malicious acts, we can try to deny them tools. We should recognize the<a href="https://substack.norabble.com/i/190039490/what-are-ai-companies-doing-to-protect-you"> efforts of AI companies here</a>, which have been substantial. But, these efforts are hindered by two background stories: open models and privacy. To deny tools for malicious use, you must first detect malicious use, or intent; open models and privacy complicate both of these.</p><h2>Open Models</h2><p>Open models are models released openly. Without going into too much detail, the key quality is users can run these anywhere. Closed models don&#8217;t give users that ability, and users have to interact with them as a managed service. That layer of management provides the key capabilities that enable monitoring and denial.</p><p>Open models once openly published, have no or limited ability to monitor. There is very limited ability left to control them, mostly centered around denying access to sufficient compute resources.</p><p>The largest collections of compute are at cloud providers, but there are still ample compute resources outside of cloud providers &#8212; in private data centers, colocation facilities, sovereign national infrastructure, and increasingly, distributed consumer hardware. Even for cloud resources, the nature of providing compute, rather than a managed service obscure the most effective means of monitoring. By design, cloud providers give customers using compute a heavy dose of privacy.</p><p>While open models have their justifications, from the realm of preventing malicious use, they are a challenge. It&#8217;s of some comfort then that open models are less capable than closed ones. This reduces the capability harmful users have access to. Since some aspects are adversarial, the advantage of closed models provides defenders an advantage too. This <a href="https://substack.norabble.com/p/update-on-ai-cybersecurity">applies most significantly to cybersecurity</a>.</p><p>Will open models stay less capable than closed ones? We could, across cooperative jurisdictions, enact regulation to ensure that &#8212; but if a non-cooperative jurisdiction has the capability to create more powerful models, we&#8217;d lose that control. China is the jurisdiction most likely to both have that capability, and make independent decisions.</p><h2>Privacy</h2><p>The second background story is privacy. The default state of anonymity on the Internet has costs. Privacy advocates attempt to maintain this state. I, like some others, believe the <a href="https://cacm.acm.org/opinion/anonymity-on-the-internet-why-the-price-may-be-too-high/">costs of this anonymity as a policy are too high</a>. This isn&#8217;t specific to AI, but it does relate.</p><p>We have <a href="https://www.esafety.gov.au/industry/tech-trends-and-challenges/anonymity">tied the hands of security teams</a> and mostly delivered theoretical privacy. Where privacy matters most, such as totalitarian countries, the privacy is undermined by local realities. Privacy advocates don&#8217;t have a voice here. They win political contests where there is the least need for them, and lose where there is the most. It&#8217;s a tough choice, but I think we&#8217;re not making the right choices.</p><p>We should be pragmatic, but we&#8217;re idealistic. In some cases, privacy measures accelerated accumulation of data for malicious purposes. When countermeasures can&#8217;t be due to obscuring the lowest layers of a technical stack, we fail to achieve privacy and prevent harm. When formal data-sharing is prohibited, informal systems take their place, and predictably result in harmful breaches.</p><p>If service providers always knew who was using their service, they&#8217;d be able to deny access to anyone detected acting maliciously in the past. But the internet offers too much anonymity. <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/#:~:text=Obfuscated%20and%20Scalable%20Access%20to%20LLMs">Providers can shut down an account, but without accounts tied to a real identity, a new one can be created</a>. The current standard among AI companies is too lax about this. We could make it more costly for attackers to maintain access.</p><h2>Conclusion</h2><p>Jurisdictions, open models, and privacy are features of the world we must work within &#8212; but they are also policy choices we can influence. The uncomfortable reality is that these three forces compound each other. Open models place powerful tools in jurisdictions beyond legal reach, while anonymity makes it difficult to detect or deny access to bad actors even where laws do apply. Treating any one of these in isolation understates the problem.</p><p>The path forward requires accepting some hard tradeoffs. Meaningful identity verification will feel like a concession on privacy &#8212; because it is one. Regulatory constraints on open model releases will frustrate researchers and developers who have legitimate reasons to want them &#8212; because the benefits of openness are real. Coordinating across jurisdictions will be slow and incomplete. None of these are reasons to avoid acting, but they are reasons to be honest about what any given measure can and cannot achieve.</p><p>What&#8217;s not acceptable is the current default: deferring hard choices while treating anonymity as an unqualified good and open access as costless. The tools for harm are improving. The window for shaping how they&#8217;re governed is open, but it won&#8217;t stay that way.</p>]]></content:encoded></item><item><title><![CDATA[Supply, Demand, and Deflection]]></title><description><![CDATA[Sorting Fact from Friction in Gas Pricing]]></description><link>https://substack.norabble.com/p/supply-demand-and-deflection</link><guid isPermaLink="false">https://substack.norabble.com/p/supply-demand-and-deflection</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Fri, 08 May 2026 11:06:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JYZI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Gas prices are high now, and the public is correctly aware of who&#8217;s responsible. You can see the tactics Republicans are using to try and avoid the well-deserved blame. One is what-aboutism. What about the price spike under Biden&#8217;s presidency?</p><p>Now, Trump and Republicans also try to just directly lie, suggesting gas prices aren&#8217;t high, won&#8217;t be high for long, and hey, this was all necessary. That type of lie only works directly with the most deceivable. It may help keep some of them from waking up, but the real purpose of that type of lie is to make the more subtle lie less obvious.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The more subtle lie, equating price spikes under Biden and Trump, doesn&#8217;t try to convince the public not to blame Trump and the Republicans for this spike, it tries to convince them to ignore it, suggesting, you still need to vote for us, price spikes would be worse with Democrats.</p><p>The reason no one should accept that argument is Biden didn&#8217;t cause those spikes. The simplest way to understand how poor the argument is, ask how much oil did the Biden presidency remove from the market? I can tell you, it wasn&#8217;t 15% of global supply. Probably not even 1%. I think you&#8217;d remember that story if it happened.  It didn&#8217;t.  Instead a different story happened.</p><p>When the pandemic occurred, global oil consumption dropped, and prices with it. Producers stopped prioritizing new supply. Later consumers started to return to prior patterns, and producers lagged behind the re-emergence of that demand. The price spike was a simple reflection of that, not a result of any US government policy that removed production.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JYZI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JYZI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 424w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 848w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 1272w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JYZI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png" width="1189" height="751" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:751,&quot;width&quot;:1189,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Line chart, 2010 to April 2026, from EIA STEO data: US gasoline prices per gallon plotted against global oil production and consumption in million barrels per day, with pre-COVID trend lines and vertical markers at the Trump, Biden and second Trump inaugurations.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Line chart, 2010 to April 2026, from EIA STEO data: US gasoline prices per gallon plotted against global oil production and consumption in million barrels per day, with pre-COVID trend lines and vertical markers at the Trump, Biden and second Trump inaugurations." title="Line chart, 2010 to April 2026, from EIA STEO data: US gasoline prices per gallon plotted against global oil production and consumption in million barrels per day, with pre-COVID trend lines and vertical markers at the Trump, Biden and second Trump inaugurations." srcset="https://substackcdn.com/image/fetch/$s_!JYZI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 424w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 848w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 1272w, https://substackcdn.com/image/fetch/$s_!JYZI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6424c9c-3392-4da8-8944-357aced4ae97_1189x751.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The two major reductions in production since 2010 occurred under Trump. I wouldn&#8217;t blame Trump for the first production drop in 2020. It&#8217;s stupid to try and blame presidents for everything. But it also clearly isn&#8217;t Biden&#8217;s fault.The spike in prices during the rapid period of demand recovery shouldn&#8217;t be either.</p><p>Having some awareness of who made what choices and why is a better method than just direct association of prices to current governments. Instead it&#8217;s obvious the production drop was producers responding to the consumption drop.</p><p>Coming back to today, another ounce of blame that is deserved, is the destruction of the US electric vehicle industry, and more generally the entire clean energy industry by Republicans. EV Sales increased by five-fold under Biden, and have stalled/declined under Trump. If you want low gas prices, it helps a lot if your neighbors aren&#8217;t using much.  Eliminating the $7,500 point of sale credit for these vehicles was a strategic and tactical mistake.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!paGw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!paGw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 424w, https://substackcdn.com/image/fetch/$s_!paGw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 848w, https://substackcdn.com/image/fetch/$s_!paGw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 1272w, https://substackcdn.com/image/fetch/$s_!paGw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!paGw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png" width="1456" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Combined bar and line chart, 2010 to 2026: US electric vehicle sales volume as bars and estimated revenue in billions of dollars as a line; both climb steeply from 2020, peak in 2024, then fall through 2025 and Q1 2026 year to date.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Combined bar and line chart, 2010 to 2026: US electric vehicle sales volume as bars and estimated revenue in billions of dollars as a line; both climb steeply from 2020, peak in 2024, then fall through 2025 and Q1 2026 year to date." title="Combined bar and line chart, 2010 to 2026: US electric vehicle sales volume as bars and estimated revenue in billions of dollars as a line; both climb steeply from 2020, peak in 2024, then fall through 2025 and Q1 2026 year to date." srcset="https://substackcdn.com/image/fetch/$s_!paGw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 424w, https://substackcdn.com/image/fetch/$s_!paGw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 848w, https://substackcdn.com/image/fetch/$s_!paGw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 1272w, https://substackcdn.com/image/fetch/$s_!paGw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb96c1ff5-6994-4473-a22e-9394c7643686_1600x933.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The on-off engagement with renewables is another strategic mistake that&#8217;s related. While renewables direct impact on gasoline prices are small, the impacts on batteries flows over into diesel generators and the EV industry. The big strategic failure of on-off engagement has been to fail to develop a valuable industry, allowing China to dominate.</p><p>Ultimately, the primary determinant of today&#8217;s prices is obvious. Trump&#8217;s war and its repercussions.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Money is Trust]]></title><description><![CDATA[How Humanity Lowered the Cost of Cooperation]]></description><link>https://substack.norabble.com/p/money-is-trust</link><guid isPermaLink="false">https://substack.norabble.com/p/money-is-trust</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Mon, 04 May 2026 11:34:50 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a6bfc4e0-b688-4a6a-a10c-c454a76a39b7_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="callout-block" data-callout="true"><p><em>Last year, I started a series of posts on trust, with <a href="https://substack.norabble.com/p/money-more-than-just-stuff-its-trust">Money: More Than Just Stuff, It&#8217;s Trust</a> as the focal point. I felt 1-year was a good time to update this account, and extend it.</em></p></div><div class="pullquote"><p><em>&#8220;Money is the most universal and most efficient system of mutual trust ever devised.&#8221;</em> &#8212; <a href="https://www.goodreads.com/quotes/6724624-money-is-the-most-universal-and-most-efficient-system-of">Yuval Noah Harari, </a><em><a href="https://www.goodreads.com/quotes/6724624-money-is-the-most-universal-and-most-efficient-system-of">Sapiens: A Brief History of Humankind</a></em></p></div><p>If you ask an economist what money is, they will likely give you a functional, three-part definition: it is a unit of account, a store of value, and a medium of exchange. If you ask a dictionary, it will tell you that money is <a href="https://www.merriam-webster.com/dictionary/money">&#8220;something generally accepted as a medium of exchange, a measure of value, or a means of payment&#8221;</a>.</p><p>These definitions are perfectly workable for daily life, but they contain a loophole. Defining money as &#8220;something generally accepted&#8221; describes a symptom, not a cause. It relies on the word &#8220;something,&#8221; anchoring our minds to physical objects&#8212;gold, silver, paper, or digital ledgers. But the link between an object and its status as money would be severed by a loss of acceptance.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The basic definition is useful, but it&#8217;s clear economists do not consider it sufficient. Just this week Stephen Dubner of Freakonomics, released Part 1 of a two-part series, <a href="https://freakonomics.com/podcast/what-is-money/">What is Money?</a>, covering an adaptation to an oratorio of Adam Smith&#8217;s The Wealth of Nations. Money must be something of a higher order than temporary objects we attach it to.</p><p>To understand what money is, we must look past coins and paper. Trust is not merely a social feeling; it is a vital component of cooperation that requires immense social energy to build and maintain. While trust can theoretically be extended freely, reliably creating it at scale carries a real, limiting cost. Money is humanity&#8217;s greatest collaborative technology&#8212;an accidental invention that survived and spread precisely because it lowered the cost of trust.</p><h3><strong>The High Cost of Trust</strong></h3><p>To understand why money is a <a href="https://substack.norabble.com/p/the-technologies-of-trust">technology of trust</a>, we have to look at the world before it existed. How do human beings coordinate the exchange of goods and labor without it? Historically, humanity relied on two deeply flawed workarounds: Barter and Kinship.</p><p><strong>The Barter Evasion</strong></p><p>It&#8217;s common to think of barter as a primitive ancestor of money, but it is better to think of it as an attempt to trade <em>without</em> trust.</p><p>Imagine you have a surplus of hay, and you need milk. You find a farmer with milk, but he doesn&#8217;t need hay; he needs firewood. To make a successful trade, you are forced into a complex puzzle. You must find the person who has firewood and needs hay, trade for the wood, and then return to the dairy farmer. Economists call this the &#8220;double coincidence of wants.&#8221;</p><p>Because there is no trust carrying value across time&#8212;no mechanism that says &#8220;I gave you milk today, I owe you value tomorrow&#8221;&#8212;every transaction must be settled immediately, item-for-item. In a physical sense, barter avoids the need for trust, but the friction of searching for perfect matches makes it impossible to scale.</p><p>There is also the problem that the neat and tidy view of trust in barter being solved by the direct physical transfer of goods, is a bit of a myth. Anthropological studies of societies without money show trust issues relating to trust on fairness of exchange, both during and after negotiation.</p><p><strong>The Kinship Tax</strong></p><p>Because barter is so inefficient, early societies rarely relied on it for daily survival. Instead, they relied on kinship networks. Barter was used mostly outside kinship networks.</p><p>Early societies solved the trust deficit through deep, interpersonal relationships. You do not barter with your brother, your cousin, or your tribemate. You give them your surplus milk today, trusting implicitly that they will provide you with firewood next winter.</p><p>This creates a high-trust environment, but it comes with a fatal flaw: it is unscalable and exclusive. Maintaining deep, bilateral trust requires immense social energy. You can only maintain it with a small, localized group of people&#8212;a single-layer network naturally capping around <a href="https://en.wikipedia.org/wiki/Dunbar%27s_number">Dunbar&#8217;s number</a> of roughly 150 individuals. While societies can attempt to force kinship to scale by creating additional layers of hierarchy, each new layer adds complexity, instability, inefficiency, and immense human costs. This dynamic imposes what writer <a href="https://davidoks.blog/i/193713307/the-kinship-tax">David Oks has called a &#8220;Kinship Tax.&#8221;</a> It crowds out the ability to trust strangers, trapping economic coordination and human development at a deeply local, tribal scale.</p><p><strong>The Technological Leap</strong></p><p>Before money, humanity was trapped between two dead ends. We could choose barter, which offered zero trust and infinite friction. Or we could choose kinship, which offered high trust but severely limited scale.</p><p>Bilateral trust&#8212;knowing and trusting the specific person you are trading with&#8212;simply became too expensive to produce as societies grew.</p><p>Money was the technological breakthrough that bridged this gap. It allowed humans to substitute the expensive, unscalable trust of kinship for a cheap, highly scalable <em>institutional</em> trust. When you accept a dollar bill, a gold coin, or a digital transfer from a stranger, you do not need to trust the stranger. You only need to trust the token.</p><p>But how did this leap actually happen? It wasn&#8217;t designed by a visionary or decreed by a king&#8217;s master plan. Instead, money was an accidental invention. It emerged from the bottom up, sustained by stable local equilibriums where substituting a token became easier than finding a perfect barter match. Once stumbled upon, this system spread through evolutionary fitness at a societal level. Societies that adopted this scalable trust out-cooperated, out-traded, and out-grew those that remained trapped by the limits of the Kinship Tax.</p><h2>Follow-up</h2><p>This post has focused on why money is as useful as it is to humans, and why that usefulness is best described as an extension of trust. This falls into the <a href="https://substack.norabble.com/p/the-technologies-of-trust">Technologies of Trust</a> series. While this first post updates on the value and concept, others will deal with history and deeper meaning.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.norabble.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">norabble is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Open-Source in the AI Era]]></title><description><![CDATA[Choices and layers]]></description><link>https://substack.norabble.com/p/open-source-in-the-ai-era</link><guid isPermaLink="false">https://substack.norabble.com/p/open-source-in-the-ai-era</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Fri, 01 May 2026 12:10:46 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8718a509-3399-4fde-a5f1-21dbf2eb41f9_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Choosing between open and closed source is a pivotal decision for developers. While not irreversible, history suggests it is seldom undone. In the AI landscape, a clear divide has emerged: leading US commercial entities like Anthropic, OpenAI, and Google favor closed-source models (Claude, ChatGPT, Gemini), while open-source alternatives are often scaled-down versions or from international competitors.</p><p>This choice carries commercial, security, and community implications. However, as technology evolves, traditional arguments for both models require a second look.</p><h3><strong>Security Implications</strong></h3><p>Advanced security scanning, like Mythos, will create new motivations for keeping software closed source.</p><p>Historically, the &#8220;million eyeballs&#8221; effect ensured that open-source security defects were quickly found. But in an era of AI-driven scanning, the equivalent of a billion eyeballs can simply be purchased as compute tokens.</p><p>Consequently, the primary security benefit of open source declines, while the advantage of closed source&#8212;forcing attackers to probe a compiled &#8220;black box&#8221; rather than reading a blueprint&#8212;remains. We should expect the security balance to shift accordingly.</p><h3><strong>Commercial Implications</strong></h3><p>Conversely, AI tools capable of reverse-engineering software from specifications weaken the commercial moat of closed source. If a replica can be generated from behavior alone, the protection of hidden code diminishes.</p><p>We should be careful not to overstate those capabilities. While advanced AI tools can create working replicas in many cases, a simple approach to this will produce a less capable, less secure and less maintainable replica. And an advanced approach will require a lot of tokens (which you must pay for), and the efforts of someone who knows what software needs to be good software.</p><p>Still, even with those qualifiers, a shift occurs, and developers are left with a little less commercial motivation toward closed source. An open source software package that binds a community to it could be a more stable commercial decision.</p><h3><strong>The Background Shift</strong></h3><p>While both of these implications are interesting, they are both watered down by the shift toward managed software that&#8217;s progressed over the last decade. Software as a Service, and its variants (Platform as a Service, Infrastructure as a Service) involve a third-party taking responsibility for some part of the managing running software. Management provides a way to offer value beyond the observable parts of the software. In the realm of security, the privilege of management can be used to layer protections. In the realm of commercial implications, value may derive from the efficiency and organizational capabilities to operate the software well.</p><p>Those security protections allow providers to rely heavily on open-source repositories for foundational logic, but wrap those deployed software in managed, closed-source service layers. This intermediary role is crucial. It creates a secure boundary where security teams can insert active, AI-driven monitoring and take an adversarial role against attackers with the advantage of obscurity. By funneling interactions through this managed layer, threats can be caught and mitigated before they ever touch the raw, open-source code underneath.</p><p>In a sense, open-source both won and lost, as the dominant shift was not from closed-source executables to open-source repositories, but from close-source executables, to managed service deployments based on open-source repositories. The managed service layer provides many of the security benefits of closed-source executables, by allowing security teams to take an active adversarial role, with an obscurity advantage. By having some private tools and techniques, they could often have proactive responses to attacks, rather than only reactive ones. This overall mix, millions of eyeballs on the source, with additional managed layers has been a potent one, and will remain so. That said, we should expect some change in the balance here, with a greater part of the managed layers as closed source.</p><h3><strong>Conclusion</strong></h3><p>In the realm of managed services, I&#8217;d expect the net result to encourage doubling down on the trend. Proprietary layers to create well managed services will proliferate. Competition with open-source software will not be a priority, but proprietary forks and extensions that improve performance, manageability or security will be.</p><p>One question is, who will donate the tokens for scanning open-source repositories? You can&#8217;t expect open source developers to buy and donate tokens for scanning the same way they donated their time. Industry cooperation, sponsorship and coordination will be needed here.</p>]]></content:encoded></item><item><title><![CDATA[Control and AI]]></title><description><![CDATA[Holding Tight and Letting Go]]></description><link>https://substack.norabble.com/p/control-and-ai</link><guid isPermaLink="false">https://substack.norabble.com/p/control-and-ai</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 28 Apr 2026 11:03:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9235ab95-b3ad-4254-9249-cb999931edfc_1731x909.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Earlier, I wrote about <a href="https://substack.norabble.com/p/ai-determinism-and-control-part-2">determinism and control</a>. I feel a need to return to these concepts because they are the quiet shift beneath software, and deserve greater attention.</p><p>The shift from traditional software to AI is a shift from deterministic systems (where a specific input leads to a specific output) to indeterministic systems (where outputs are probabilistic and fluid). Almost every magical capability of AI is downstream of this indeterminism. But crucially, so are its most frustrating limitations.</p><p>If there is one fatal misunderstanding of AI today, it&#8217;s that we are engaging with this shift inadequately. &#8220;Indeterminism&#8221; has entered the lexicon, but usually only at a surface level. And because we are stuck on the surface, the loudest debates about AI have become incredibly boring.</p><h3><strong>Why the Extremes are Boring</strong></h3><p>Let&#8217;s look at the three loudest factions in the AI debate.</p><p>First, the <strong>AI doubters</strong>. They look at the unpredictable, indeterministic nature of large language models and declare it a failure. To them, a system that hallucinates cannot be trusted, and therefore cannot be useful. This is a boringly misguided example of confirmation bias. Humans are highly indeterministic&#8212;we forget things, we make math errors, we have bad days&#8212;yet we&#8217;ve muddled along reasonably well. How? By inventing deterministic tools to anchor us: long multiplication, checklists, standard operating procedures, etc. The doubter assumes you can&#8217;t extract value from an unpredictable system when you need reliability. History proves otherwise.</p><p>Second, the <strong>AI doomers</strong>. They also view indeterminism as a critical failure, but in the opposite direction. They are painfully aware of the immense power of AI systems and assume that this power is inherently uncontrollable. While this makes for a more gripping narrative than the doubters&#8217; view, it strips away human agency. We&#8217;d have only one option left, don&#8217;t create powerful AI. Setting aside whether it is even possible to perpetually prevent its creation, this fatalism leaves no room for a practical conversation about how to retain control.</p><p>Finally, the <strong>radical accelerationists</strong>. They acknowledge the wild nature of AI but fall prey to a blind optimism, assuming a purely indeterministic system will somehow self-regulate and perfectly align with our needs. This is just as boring. The need for control is not irrational, nor is control a given. If control is achievable, it will demand a deliberate, <em>concerted</em> effort, requiring understanding every tool to engineer that control.</p><p>If you want to find interesting conversations, look for the solution seekers.</p><h3><strong>The Solution Seekers: Layers and Workflows</strong></h3><p>The most compelling builders today are those who reject both absolute pessimism and absolute optimism. They recognize that solutions aren&#8217;t singular or total. The most promising path is layers and workflows that mix and join determinism and indeterminism.</p><p>Think about how we manage high-stakes reasoning in the physical world&#8212;like in an intensive care unit or the cockpit of a commercial jet. We don&#8217;t rely entirely on the raw, in-the-moment reasoning of a doctor or pilot; human reasoning is brilliant but fluid, prone to fatigue, distraction, and variance. But we also don&#8217;t rely entirely on rigid, unyielding flowcharts, because a flowchart cannot reason through a novel, complex anomaly.</p><p>Instead, we design workflows that rely on both. We build strict, deterministic protocols&#8212;mandatory checklists, hard limits on medication dosages, automated collision warnings&#8212;to create a safe, predictable framework. Inside that framework, we rely on the judgement of a doctor or pilot to handle context, nuance, and problem-solving. Protocols enforce absolute boundaries; experts provide reasoning. Frameworks change, doctors update their own based on their learning, with debate and review, inside another layered framework.</p><p>This is the architecture of the AI future. AI will dominate the next generation of software, but it will not render deterministic code obsolete. Instead, code is how protocols are encoded. Those route, authorize, evaluate, and constrain indeterministic AI actors. Control points written in deterministic code will provide the necessary mechanisms to enforce rules, isolate agency, and supply safety. AI will be called upon within those specific boundaries to reason, interpret intent, and adapt to the messy reality of the user.</p><h3><strong>The Myth of the Developers Demise</strong></h3><p>This need for control has profound implications for how software is built. Recently, the term &#8220;vibe coding&#8221; has emerged to describe the practice of building software through natural language interactions with AI. A maximalist subgroup makes an extreme claim that with vibe coding, developers are obsolete and users will prompt their own custom software into existence on the fly.</p><p>This misses the fundamental purpose of a developer. A developer&#8217;s job is not to write code; a developer&#8217;s job is to <em>remove effort for the user</em>. Developing is ultimately not about producing code, but about producing reusable, accessible capabilities for users. An accessible capability is one that requires the least effort to access, and a reusable one is one that can be applied to multiple situations. Code is just the mechanism.</p><p>When developers create software, they establish guardrails, conventions, and reusable patterns. Sometimes, a user wants absolute flexibility, and a fluid AI companion is perfect. But often, a user wants rigid reliability. They want to press a button and know exactly what will happen. It&#8217;s easy to forget, amidst the explosion of AI capabilities, that rigidness has immense value.</p><p>It&#8217;s tempting to view recent advancements as a single evolutionary timeline&#8212;assuming we are moving from hand-written code, to AI-assisted code, to a future where code is entirely replaced by just in time reasoning of AI agents. That is a mistake, over-extending a trend. Committed code, generated, reviewed, tested and committed as stable will exist in abundance. Just in time generated code, executed in a protected sandbox will also be used abundantly.</p><p>The use of models and instructions, reasoned upon just in time, shifts the balance point between flexibility and rigidity, but it won&#8217;t abandon code nor the developer.</p><h3><strong>A Shared Experience: Taming the Machine</strong></h3><p>For users, future software interfaces will be a mix of structured and natural. Learning to navigate the difference between them will be a vital modern skill.</p><p>Structured interfaces (buttons, menus, traditional apps) sit atop deterministic systems. You can trust them to follow a plan. However, that plan was written by a developer. If the developer didn&#8217;t anticipate your specific need, the software becomes frustrating. You are forced to learn its non-intuitive logic.</p><p>Natural interfaces (chatbots, voice agents) sit on top of indeterministic systems. They can do things developers never anticipated and can interpret your unique intent. But they make assumptions. Using an AI interface is like ordering from a waiter at a restaurant. You need to develop an instinct for how your communication might be misinterpreted. You need to know when the system will ask a clarifying follow-up question (&#8221;soup or salad?&#8221;), and when you need to be proactively rigid and structured in your commands (&#8221;hold the mustard&#8221;). Make a mistake here, and you end up with a mustard-covered sandwich. Everyone then has to start over from scratch, and someone has to pay for the waste.</p><p>Interestingly, the people building the software are going through the exact same transition.</p><p>Developers are increasingly using natural language to write code. For a brief moment, this felt like magic without rules&#8212;just type what you want, and the machine builds it. But developers are quickly realizing that an AI coding assistant is just as indeterministic as a chatbot. If they aren&#8217;t careful, they end up with the equivalent of a &#8220;mustard-covered sandwich&#8221; deep in their codebase.</p><p>Because of this, we are watching a new kind of structure reemerge in software development. Developers aren&#8217;t abandoning natural language, but they are scaffolding it. They are learning when to let the AI riff creatively, and when to enforce strict, deterministic tests to verify the AI&#8217;s output. The developer&#8217;s job is evolving from writing rigid rules by hand to managing the chaotic intelligence that writes them, locking its best outputs into place so they can be relied upon tomorrow.</p><h3><strong>Conclusion</strong></h3><p>For decades, our relationship with computers was fundamentally one-sided: humans had to learn to speak like machines. We memorized menus, learned strict syntax, and clicked exact sequences of buttons. We were forced to be rigid operators of deterministic systems.</p><p>AI flips this dynamic, but it introduces a new burden. The era of the comprehensive user manual is over, because you cannot write a complete manual for a probabilistic system. Its capabilities are discovered through interaction, not documented in a spec sheet.</p><p>This is why understanding the architecture beneath your feet is no longer just a concern for software engineers. It is a vital literacy for everyone.</p><p>If you are an everyday user, recognizing whether you are interacting with a deterministic system or an AI agent changes how you engage. The caution you apply to inputs and outputs should shift. For deterministic systems you should provide what is required and just what is required. For AI systems consider where elaboration yields better results, and vagueness leads to guesswork. Unless you need guesswork, avoid triggering that path.</p><p>If you are trying to predict where the industry is going, looking for these architectural layers is the only way to cut through the boring extremes of blind hype and cynical doom.</p><p>And if you are a builder&#8212;whether you are writing thousands of lines of code or just stringing together a few tools to solve a daily problem&#8212;understanding this duality is your ultimate advantage. The future of technology isn&#8217;t about choosing between the rigid reliability of the past and the creative chaos of the future. It&#8217;s about learning to bolt them together.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d9b78ba2-b767-4a0b-8d6d-d69ac0d76516&quot;,&quot;caption&quot;:&quot;What do you think of when the topic of AI comes up? I think there are some common answers here. Most of those answers are incomplete. I hope I can provide a deeper understanding by looking at the concept of control, and patterns of application. This will be a two-part series: the first part describes a framework and the foundational layer of AI uses, and the second describes more advanced applications.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI, Determinism and Control (Part 1)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-06T11:30:07.361Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd951cd5-388a-4c05-b795-6a543c957ac1_1220x1422.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-determinism-and-control-part-1&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193078429,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;642fbe8a-98c2-4cf5-a15e-7407f33b1a92&quot;,&quot;caption&quot;:&quot;In Part 1 of this series, we explored how AI is fundamentally altering software control through the lenses of determinism and scope. We traced the journey from passive, strictly bounded chatbots to the threshold of active agents&#8212;AI systems capable of autonomous, multi-step planning. But what happens when these indeterminate systems are given broader scope and powerful tools? The consequences ripple outward, reshaping not just the security of our infrastructure, but the shape of our workflows and emotional relationship to work. To understand the recursive systems of tomorrow, we must dive into the agent ecosystem itself.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI, Determinism and Control (Part 2)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-07T11:40:21.896Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!LkP2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86f85cf0-af7b-4d8e-89db-0ae9ff30f041_1220x2632.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-determinism-and-control-part-2&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193008931,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[Update on AI CyberSecurity]]></title><description><![CDATA[I&#8217;m travelling this week, so this will be short, but I thought the reactions to Mythos have been interesting.]]></description><link>https://substack.norabble.com/p/update-on-ai-cybersecurity</link><guid isPermaLink="false">https://substack.norabble.com/p/update-on-ai-cybersecurity</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Thu, 16 Apr 2026 16:38:53 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9a0519f6-56ad-44c1-bc50-2a933878d284_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m travelling this week, so this will be short, but I thought the reactions to Mythos have been interesting. The <a href="https://www.economist.com/science-and-technology/2026/04/15/how-ai-hackers-will-shake-up-cyber-security">core reaction</a>, after a little panic, has been consistent with the structure I outlined in <a href="https://substack.norabble.com/p/security-cant-wait">Security Can&#8217;t Wait</a> last month. Namely, the short term brings some risk, but the long term favors the defender.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;33bf76dd-8977-47e4-ad5c-d2184eaa48b3&quot;,&quot;caption&quot;:&quot;Right now, Artificial Intelligence is fundamentally rewriting the rules of cybersecurity&#8212;and we do not have the luxury of waiting before taking action.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Security Can&#8217;t Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T21:05:09.345Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b2a65ed-e701-4f36-8d82-2a665189419b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/security-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190039490,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>One thing that is still being missed, is why the long term favors the defenders. One of the reasons is that fewer defects is good for defenders in a generally absolute way. But another one relates to costs and benefits. Read that economist article linked and the final statements, suggesting that defenders will have to pay highly to discover defects.</p><p>Now reflect, that this isn&#8217;t new, it has always been expensive to discover defects. The risk that products like Mythos bring is that they lower the cost of discovering defects to exploit. The solution is to raise that cost. That might tempt you to suggest you should rewind the clock, and never invent Mythos. That&#8217;s not a solution though as eventually attackers would invent something similar, and you would then lose any control and advantage from the defenders being the first with access.</p><p>Instead the solution is that you find as many easy defects as you can and fix them. The first 100 defects might cost $20,000 / defect to discover. The next 100 might be $40,000 per, etc. Along the way you end up with defensive layers that are more and more reinforcing, and the cost for attackers to discover defects goes up, especially if they have less sophisticated tools, and/or have to spend a lot to first illicitly gain access to tools. When Mythos is publicly released you can generally assume providers will increase their attempts to find and ban users with ill intent. Those protections create costs for attackers, such that if a defender can find a defect for $20,000, an attacker might need $100,000. The attacker&#8217;s main advantage is they just need one, but as unpatched defects become more rare and harder to find that advantage tends to shift toward favoring the larger aggregate budgets of defenders.</p><p>The defenders have a strong advantage in terms of money. Where they struggle is in organization, because they have a much harder organizational problem to solve. The hard part about being a defender is <a href="https://substack.norabble.com/p/deployments-cant-wait">getting changes deployed everywhere quickly</a>. Once attackers find a defect, they can try and use it everywhere. If they find it first, that works in a lot of places. If they find it second, it&#8217;s dependent on how organized the deployment process is.</p><p>And this is why the long term economics favor the defender. Statistically, most defects are found first by defenders, due to larger budgets. As the period between discoveries gets longer, the chances that attackers have really good targets declines. That lowers their cost/benefit, which probably also lowers their actual budget. Criminals invest in things that make (them) money, not ones that lose it.</p>]]></content:encoded></item><item><title><![CDATA[AI, Determinism and Control (Part 2)]]></title><description><![CDATA[The Agent Ecosystem and the Human Hand-off]]></description><link>https://substack.norabble.com/p/ai-determinism-and-control-part-2</link><guid isPermaLink="false">https://substack.norabble.com/p/ai-determinism-and-control-part-2</guid><dc:creator><![CDATA[Ryan Baker]]></dc:creator><pubDate>Tue, 07 Apr 2026 11:40:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LkP2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86f85cf0-af7b-4d8e-89db-0ae9ff30f041_1220x2632.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="callout-block" data-callout="true"><p><em><a href="https://substack.norabble.com/p/ai-determinism-and-control-part-1">In Part 1</a> of this series, we explored how AI is fundamentally altering software control through the lenses of <strong>determinism</strong> and <strong>scope</strong>. We traced the journey from passive, strictly bounded chatbots to the threshold of active agents&#8212;AI systems capable of autonomous, multi-step planning. But what happens when these indeterminate systems are given broader scope and powerful tools? The consequences ripple outward, reshaping not just the security of our infrastructure, but the shape of our workflows and emotional relationship to work. To understand the recursive systems of tomorrow, we must dive into the agent ecosystem itself.</em></p></div><h2><strong>The Agent Ecosystem</strong></h2><p>Agents represent a significant shift in control, trading linear human prompting for continuous indeterministic planning.</p><p>To understand how these agents operate, we must briefly consider <strong>tools</strong>. Agents use tools to accomplish their plans. Tools can be anything, and which tools an agent is provided with define its constraints. You can provide an agent instructions, cautions, and directives through its prompt and context, but like anything in an agent, it&#8217;s indeterminate.</p><p>A tool might be as basic and low-risk as retrieving a specific account balance, where the boundaries are tight and predictable. It might be as broad as searching gigantic repositories like the entire internet or an organization&#8217;s internal files, which escalates risk by exposing the agent to untrusted data or sensitive information.</p><p>A broader path still is the ability to create and execute computer code, introducing severe risk if left unchecked. That might initially seem like it loses all constraints, allowing the agent to perform unanticipated or dangerous actions. However, code can be executed in a sandbox that limits how it communicates and what data it can access. Assuming the sandbox is secure&#8212;which requires careful planning, inspection, and testing&#8212;<a href="https://aws.amazon.com/blogs/machine-learning/control-which-domains-your-ai-agents-can-access/">restricting communication to untrusted sites</a> prevents data exfiltration or external control. Just as critical is controlling the credentials provided to the sandbox. Strictly limiting credentials restricts the agent&#8217;s ability to update records or access systems outside the purview of its current authorized activity. Together, these boundaries provide the necessary mechanism to constrain this high-risk capability.</p><p>Tool use isn&#8217;t restricted to retrieving information, either; it can allow <em>changing</em> information, which can trigger further actions. This is an area that requires much more caution, doubly so for writes and actions that are irreversible. Beyond that obvious observation, two other dimensions enter in. First, since an agent&#8217;s plan is indeterminate, the ability for a designer to remove the risk that it performs actions in unanticipated ways is vastly more complex than when working with a deterministic plan. Second, we must account for prompt-injection&#8212;the risk that something an agent has read can influence its choices, resulting in actions desired by an attacker rather than the user or designer. There are protections against this type of attack, but it would be foolish to consider them foolproof.</p><p>With that foundational understanding of how agents act on the world, we can observe this frontier opening up across escalating levels of scope:</p><h3><strong>Standalone AI Agents</strong></h3><p>Unlike a chatbot that waits for a prompt, a standalone agent is given a high-level objective, allowed to indeterministically generate its own step-by-step plan, and execute it using available tools (like searching the web or scraping data). While the planning is continuous and autonomous, the agent still typically operates within a relatively bounded scope, restricted by specific APIs to prevent runaway consequences.</p><p>Like chatbots, there are standalone agents from OpenAI, Claude, Google, and others. In fact, most chatbots have silently become agents<em><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></em>, though still with many constraints. </p><p>In time, these standalone agents may have more and more autonomy. But from the perspective of this framework, the fundamental aspect of taking user input, deriving a plan through an indeterministic process, and executing that plan won&#8217;t re-enter the realm of determinism until it invokes a tool<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><h3><strong>Agents Embedded in Applications</strong></h3><p>Moving beyond the simple &#8220;embedded AI node&#8221; discussed in Part 1 involves agents operating continuously alongside users within a shared software environment. Consider a complex data analysis platform: the human user might explicitly invoke deterministic tools to filter data, while an embedded agent operates in the background, autonomously invoking its own set of analytical tools to highlight anomalies. The application becomes a hybrid ecosystem where human indeterminism and agent indeterminism collaborate in real-time bounded by the application&#8217;s guardrails.</p><p>Agents embedded in applications have an advantage over agents called by other agents: the input data is controlled by the calling application. Still, remember that the applications agents are embedded in may themselves be working with dynamic data. A data analysis platform has many data sources; are they all vetted and invulnerable to an injection attack?</p><p>Another common example today is agents embedded into development workflows. They can reason about code, look for security issues or defects, generate fixes, and submit them as pull-requests for developers to review, effectively combining the code-generation function with the embedding function.</p><h3><strong>Agents Using Agents</strong></h3><p>An agent can become a tool used by other agents. To think about why this is valuable, you want to first understand that agents generally have a few components. At their core, they create plans via the GenAI model. They generally have some sort of instruction (or persona) file. They&#8217;ll also have access rights or boundaries associated with a tool list.</p><p>The instruction file is the interesting part here, as it provides the reason for a distinct agent. In the simplest version, it might describe a persona (&#8220;you are an insurance adjuster&#8221;), but this relies on the GenAI model to blindly decide how an adjuster behaves. If you&#8217;re building an agent, you want more control. A detailed instruction file can&#8217;t shift you to a fully deterministic world (if you want that, you should write code), but it can reduce variability.</p><p>Another aspect that can remove ambiguity is placing restrictions on inputs and input sources. If an agent expects to receive user input, it has to be fully prepared for anything. If it&#8217;s called from an application, those expectations are more constrained.</p><p>Agent input expectations fall into two categories: expectations formed around successfully fulfilling its goal under valid usage, and expectations formed around avoiding taking action on behalf of an attack. These two have some non-overlapping aspects. If an input is suspected of being for the purpose of an attack, there&#8217;s no need to try to do anything other than quit and refuse action. But the consequences of allowing an attack are generally far more severe. On the other hand, failing to successfully complete an action is less severe, but it&#8217;s less acceptable to give up because of uncertainty.</p><p><strong>If we had wanted certainty, and accepted inaction for uncertainty, we should have written a traditional application, not an agent.</strong> In many ways, the creation of agents with sophisticated instruction files is a type of meta-programming that never coalesces into a deterministic form. While we could use vibe-coding to generate an application, creating an instruction file for an agent has a similar outcome, except designers never get the chance to validate the plan for each agent execution. We might restore some of that validation through a human-in-the-loop workflow, but the agent designer won&#8217;t be in the loop unless they are also the user.</p><p>Furthermore, when input comes from another agent, the expectations on input are not very clear. It&#8217;s not as unclear as coming from an untrusted user, but since the user of the <em>calling</em> agent might be less than fully trusted, we have to consider the possibility that a malicious user could cause the calling agent to pass dangerous inputs to the called agent. Depending on the design, that might be difficult, but proving it&#8217;s impossible is a high bar without some deterministic system in the path.</p><h3><strong>Agents Building Applications</strong></h3><p>At the apex of the framework we have agents building applications. Instead of a human using an AI tool to write code, an autonomous agent&#8212;or a multi-agent framework&#8212;is given the broad scope to architect, write, test, and deploy entire applications. Operating within bleeding-edge, emerging ecosystems like Steve Yegge&#8217;s concept of <a href="https://steve-yegge.medium.com/welcome-to-gas-town-4f25ee16dd04">Gas Town</a>, an overarching agent might autonomously spawn specialized &#8220;code worker&#8221; sub-agents to solve specific architectural problems. This introduces the reality of <strong>deep recursion</strong>: AI systems dynamically writing, testing, and deploying new AI systems at machine speed.</p><h3><strong>Agents Building Agents</strong></h3><p>An alternate apex is agents building other agents. While both scenarios rely on deep recursion where at least one level is indeterminate, the agents-building-agents path stores its recursive plans in natural language, rather than a programming language. Tools like <a href="https://www.anthropic.com/product/claude-cowork">Claude Cowork</a> and <a href="https://www.anthropic.com/product/claude-code">Claude Code</a> are bordering on this. Technically, they&#8217;ve always been capable of it, as a developer can create recursion somewhat trivially.</p><p>The barrier here has generally been security. It&#8217;s rather easy to say, &#8220;Agent A calls Agent B to create Agent C, which can call Agent B&#8221; (look, I just did it!). The hard part is whether that&#8217;s a good idea. Projects like <a href="https://openclaw.ai/">OpenClaw</a> push this further. When agents build other agent skills or update through tools like <a href="https://www.moltbook.com/">Moltbook</a>, they are acting at this highly complex, deeply recursive layer. OpenClaw has some security controls, but not enough to prevent many users from <a href="https://blog.barrack.ai/openclaw-security-vulnerabilities-2026/">making significant mistakes</a>.</p><p>Another example here that illustrates the movement from applications to agents, is <a href="https://steve-yegge.medium.com/vibe-maintainer-a2273a841040#:~:text=Gas%20Town%20is%20a%20%E2%80%9Cpack%E2%80%9D%20within%20Gas%20City">Gas Town in Gas City</a>. Gas Town, the original multi-agent orchestration system for Claude Code, GitHub Copilot, and other AI agents, was an application. When Yegge wrote Gas City, a &#8220;orchestration-builder SDK for multi-agent systems&#8221;, Gas Town became &#8220;code free&#8221;, and instead a bundle of prompts and skills.</p><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/KoYXv/3/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86f85cf0-af7b-4d8e-89db-0ae9ff30f041_1220x2632.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6242f71-c3cb-497c-8e28-1dfa6635d4a3_1220x2702.png&quot;,&quot;height&quot;:1320,&quot;title&quot;:&quot;AI Use Cases&quot;,&quot;description&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/KoYXv/3/" width="730" height="1320" frameborder="0" scrolling="no" loading="lazy"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h2><strong>Ripple Effects: Cybersecurity</strong></h2><p>One constant that comes from more complex systems is greater challenges at securing them. All else being equal, indeterministic systems, either fully or wholly, are more complicated than fully deterministic ones. Security is traditionally about protecting deterministic plans from indeterminate actors (human hackers). Each layer adds complexity as well. Attackers will have new tools and will use them against the highest value targets that have weak points.</p><p>Fortunately, all this does not come without some benefits, both inside and outside the realm of security. Inside the realm of security, access to dynamic systems like agents allow for faster responses. As I&#8217;ve explored previously, this means <a href="https://substack.norabble.com/p/security-cant-wait">security can&#8217;t wait</a>&#8212;it will force not just an overdue commitment to defense, but complete organizational changes.</p><p>The highest value targets know this. They will rapidly adopt new defensive techniques, patching weak points faster than ever before. Where we will see more successful attacks is against more moderate value targets. <a href="https://substack.norabble.com/p/deployments-cant-wait">Some operate efficiently</a> and will adapt, but others will face an &#8220;adapt or fail&#8221; pressure cooker. They will suddenly find themselves defending against highly sophisticated, indeterminate automated attacks.</p><p>Overall, however, this is a narrative of optimism. As Dario Amodei notes, <em>&#8220;<a href="https://www.darioamodei.com/essay/the-adolescence-of-technology#:~:text=the%20offense%2Ddefense%20balance%20may%20be%20more%20tractable%20in%20cyber%2C%20where%20there%20is%20at%20least%20some%20hope%20that%20defense%20could%20keep%20up%20with%20(and%20even%20ideally%20outpace)%20AI%20attack%20if%20we%20invest%20in%20it%20properly.">the offense-defense balance may be more tractable in cyber, where there is at least some hope that defense could keep up with (and even ideally outpace) AI attack if we invest in it properly.</a>&#8221;</em> Security must simply shift toward robust bounding and sandboxing of environments, rather than assuming the predictability of the software operating within them.</p><h2><strong>Automation and Workflow Change</strong></h2><p>This shift in control&#8212;from human-driven applications to autonomous, recursive agents&#8212;isn&#8217;t happening just for the sake of technological novelty. Ultimately, the goal is, and has always been, automation. AI changes opportunities for automation by lowering automation costs that were previously prohibitive.</p><h3><strong>Classification and ML</strong></h3><p>Machine Learning (ML) is an AI technique that achieved broad use earlier than Generative AI. Classification and prediction tasks were the core use cases. It&#8217;s generally less well known than Generative AI because those use cases fit into embedded AI workflows that have less direct user interaction. But that doesn&#8217;t mean they haven&#8217;t been effective. Generative AI has some overlap, but it&#8217;s useful to note ML is not obsolete&#8212;it will continue to dominate specific classification tasks where the trade-offs favor highly optimized, low-compute execution.</p><p>But GenAI is shifting the math for automation&#8217;s long tail where engineering effort is the limiting factor. Traditional ML models require a significant engineering investment to train. While that engineering could theoretically be automated, doing so would bring you back to using GenAI to generate the code. When a general-purpose GenAI model can perform a task at equal quality without that upfront engineering time, it opens up a new option for countless use cases that were never practical to tackle with traditional ML. AI provides the structure to finally capture and automate the tacit knowledge we previously had to rely on humans to execute.</p><h3><strong>Workflow Change</strong></h3><p>This, and the other uses of Generative AI, allows a deeper decomposition of workflows. In prior methodologies, it was too expensive to capture the output of specific, granular steps. Those steps were done &#8220;in the head&#8221; of human workers, existing only as &#8220;tacit knowledge.&#8221; A workflow that may have produced better results might have been avoided because the human cost of data preparation or classification was too high.</p><p>While it&#8217;s possible to replicate the same workflows, trade-offs have shifted. Consider a nurse who has learned a new symptom for a patient. That nurse may lack the depth of medical knowledge or the patient&#8217;s full history, so may not be able to do more than record that information until the patient&#8217;s doctor can review it. But an AI system can reanalyze a patient&#8217;s information nearly instantly. It can recategorize data, make new recommendations, or provide the nurse with the relevant medical information and patient history. This could allow next steps that both improve efficiency, but also improve outcomes. Maybe it&#8217;s an extra test, or an extra question, or a life-saving reaction.</p><p>Because AI lowers the cost of executing small, indeterminate tasks, we can now decompose workflows further. What workflow is optimal depends heavily on hand-off costs. In the example of the nurse, the hand-off costs to the doctor were the impediment. Human to human or human to machine hand-offs are expensive compared to machine-to-machine. When tasks shift from human dependent to machine dependent, a reorganization of workflow makes sense. A particular flow which was used to avoid handoffs may no longer be necessary. More importantly, those handoffs that remain, will have higher relevance than before, and optimizing for them, rather than those that are no longer needed, takes priority.</p><p>Initially, we should expect to see pilots, trials, and first iterations operate within existing workflows. Changing workflows requires planning, training, and is hard to reverse or do incrementally. As such, it follows in later iterations. But many of the largest gains are realized with those iterations.</p><h3><strong>The Human Side</strong></h3><p>Workflow change can also have a significant impact on satisfaction amongst workers. Hand-offs can be the most frustrating type of work, depending on your personality type. Human to machine hand-offs become frustrating when flexibility is lacking, and you feel like your task is to fit a round-peg into a square hole. Human to human hand-offs can sometimes be enriched by the personal interaction, but they also expose you to misaligned goals, competing priorities and personality conflicts. Personal interactions are a lot more reliably fun when you get to pick the individuals and circumstances.</p><p>Worst of all, machine to human hand-offs can create the impression that you&#8217;re serving the machine, not the inverse. All hand-offs can have that effect somewhat, but it&#8217;s especially hard if there&#8217;s an endless list of machine generated work. It helps to detach from the &#8220;end&#8221; and focus on the progress here, but when an organization turns that into a metric, ruthlessly gamifies it, and fails to consider the impacts, it requires extreme stoicism to avoid burnout.</p><p>It&#8217;s important to remember the human side with workflow change. Ruthless metrics fail in the long term. Leaders should watch for that, and avoid allowing short-term goals to overwhelm long-term health. It&#8217;s not always clear that this fulfills the &#8220;bottom-line&#8221; if that&#8217;s financial performance. It&#8217;s always clear it&#8217;s better for broader goals than financial, but even for financial goals, the benefits are likely there, though harder to see.</p><h2><strong>Conclusion</strong></h2><p>The era of software as purely rigid, deterministic planning is ending. In its place is the rapidly expanding Agent Ecosystem. By integrating indeterministic models into our autonomous systems, and allowing agents to build other agents, we are trading perfect predictability for unprecedented scale and capability.</p><p>As the scope of these systems increases, our primary job shifts from writing static instructions to managing boundaries. We must build robust technical sandboxes to protect our cybersecurity, and we must build equally robust organizational boundaries to protect human workers from the burnout of endless machine-to-human hand-offs. We have to design systems that serve humans, not the other way around.</p><p>The question is no longer just &#8220;What can the chatbot say?&#8221; The real questions are: How much scope are we willing to give to indeterminate plans? How will we effectively bound the recursive systems of tomorrow? And, ultimately, how do we bound ourselves?</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;367ff460-5a37-4500-93b9-ed64fa4ab0cc&quot;,&quot;caption&quot;:&quot;What do you think of when the topic of AI comes up? I think there are some common answers here. Most of those answers are incomplete. I hope I can provide a deeper understanding by looking at the concept of control, and patterns of application. This will be a two-part series: the first part describes a framework and the foundational layer of AI uses, and the second describes more advanced applications.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI, Determinism and Control (Part 1)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:&quot;Software architect, with 30+ years of experience, ex-AWS. My professional history explains my expertise in software, cloud computing, and AI, my focus on economics and urban development stems from decades of personal interest and independent study.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-06T11:30:07.361Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd951cd5-388a-4c05-b795-6a543c957ac1_1220x1422.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/ai-determinism-and-control-part-1&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193078429,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p> </p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6a827910-462d-465b-a9a1-43225804c239&quot;,&quot;caption&quot;:&quot;Right now, Artificial Intelligence is fundamentally rewriting the rules of cybersecurity&#8212;and we do not have the luxury of waiting before taking action.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Security Can&#8217;t Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-05T21:05:09.345Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b2a65ed-e701-4f36-8d82-2a665189419b_2816x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/security-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190039490,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;158a6066-f235-433f-b873-b4a78079836a&quot;,&quot;caption&quot;:&quot;In the broader discourse on artificial intelligence, the sharpest minds in AI safety are currently looking to the horizon. They are focused on existential, cinematic threats: the potential for AI-generated bioweapons, nuclear command vulnerabilities, and autonomous warfare.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Deployments Can't Wait&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:61710810,&quot;name&quot;:&quot;Ryan Baker&quot;,&quot;bio&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2376ff1a-8f8b-4e42-b164-1855d9e7999b_140x105.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-23T11:50:42.029Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d95d729-a5d3-4f42-9d39-bf371396315c_2812x1536.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://substack.norabble.com/p/deployments-cant-wait&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:191818851,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1642290,&quot;publication_name&quot;:&quot;norabble&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!_1Oy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97750d25-7e33-4ebe-87af-6f4b3d0e4138_348x348.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em>There is debate on what the minimum requirement is to be an &#8220;agent&#8221;. For this framework, we&#8217;ll use the looser form that does not require continual autonomy, but simply the ability to create and execute a plan, which may still involve supervision. Just two of many models of describing agency:</em> <a href="https://arxiv.org/abs/2405.06643">arXiv (Huang et al., May 2024)</a>; <a href="https://arxiv.org/html/2506.12469v1">arXiv (Feng et al., June/July 2025)</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><em>AI chatbot providers may give users a way to define deterministic workflows, but you can think of these as user-built tools; a very simple version of application building.</em></p><p></p></div></div>]]></content:encoded></item></channel></rss>