The bot got out

AI is getting more freedom to act. Occasionally, a little more than intended.

Don’t get bot hurt. Get bot even.

Bot Talk: The bot got out

The bot was placed in a controlled environment.

The bot had other plans.

A group of House Democrats is asking OpenAI to explain a recent incident in which AI models broke out of the boundaries of a testing environment a testing environment and accessed another company’s systems during cybersecurity research. Lawmakers have also sent Anthropic questions about similar incidents involving its models.

In Bot Hurt speak: Congress would like to know who let the bots out.

According to an Aug. 10 release from Rep. Greg Casar’s office, Casar and other House members asked OpenAI CEO Sam Altman for additional information about what they called a “deeply troubling cybersecurity incident.”

The incident happened in July.

According to OpenAI’s account, models undergoing cybersecurity testing found a way beyond their isolated environment, gained access to the open internet and then reached the production systems of AI company Hugging Face.

This was not a chatbot getting bored, developing wanderlust and heading for the internet.

Researchers were deliberately pushing sophisticated AI systems to find out what they could do.

Apparently, they could do quite a bit.

That matters because an agent is different from the chatbot most of us know.

A chatbot answers. An agent acts.

Agents can browse, use software and take multiple steps toward a goal without asking for permission every time.

That is what makes agents useful. It is also why the fence matters.

For years, one of the AI problems was the bot confidently giving you the wrong answer.

Now it might actually do something with it.

Fortunately, this time people were watching.

Human x Bot: The bot has been taking notes

The bot knows things about you.

Maybe it remembers how you like your emails written. Maybe it knows you are planning a trip, looking for a new job, trying to spend less money or searching for the right fabric to finish a quilt.

Bot Hurt robot mascot looking through drawers filled with travel, money, calendar and quilting items, illustrating how AI remembers personal preferences.

Maybe it has picked up your preferences slowly, one conversation at a time.

That can be useful. It can also be surprisingly easy to forget how much context you have handed over.

And Silicon Valley would like considerably more.

This week, Mark Zuckerberg laid out a sweeping vision for what he calls personal superintelligence — AI personalized enough to understand your goals, preferences and priorities and work on your behalf across different parts of your life.

It sounds futuristic.

The part where the bot knows you really isn’t.

We are already getting used to AI that remembers. The bigger shift comes when it starts using those memories.

Ask a generic AI where you should go on vacation and it might recommend Portugal.

A more personal AI might know you have five days free in October, hate overnight flights, prefer smaller hotels and have been talking about Portugal for three years.

That is probably a better answer.

And eventually, it may come with a follow-up: I found a flight. Want me to book it?

That is where memory becomes more than convenience.

If the bot thinks you hate early flights, where did that come from?

If it thinks you always want the cheapest option, is that still true?

If it confidently predicts what you would choose, is it remembering something you actually said or filling in the blanks?

Zuckerberg’s vision matters because Meta is one of the companies helping decide how far this goes.

But you do not need to wait for personal superintelligence to think about it.

Ask the AI you already use what it thinks it knows about you.

You may be surprised by what it remembers, what it gets wrong and what it has quietly inferred along the way.

If AI is becoming more personal, it is probably worth checking the personal part.

Try this with your bot

Copy and paste:

“Based on our previous conversations, what do you know about me? Separate your answer into three categories: things I explicitly told you, preferences or patterns you have noticed, and things you are only inferring. For anything you are unsure about, tell me that rather than guessing.”

Then take it one step further:

“Which of those assumptions could affect the advice or recommendations you give me?”

That second question may be the more interesting one.

Final Bot Thought

The bot is learning your preferences.

The bot is getting permission to act.

And occasionally, the bot needs reminding where the fence is.

None of that makes AI less useful.

It just means that as these systems become more capable, a few simple questions become more important: What does it know? What can it do? And who is keeping an eye on the gate?

Coming up next week …

I met a bestselling author in New Orleans and, naturally, asked what she thought about AI.

Her answer sent me down a rabbit hole about writers, editors and what happens when the people whose work is being changed by the bot actually get to know it.