Transcript
Hook
0:00 · If you think fable concerns are bad, like see when Whimo hits a dog nest as if people lose their mind. Imagine when first robot knocks off a toddler off a kitchen table, you're going to see some real strict liability. So physical AI, the level of stringency just goes up and up and up and up. [music] Um, so that's kind of like the big picture, agents, models, robotics. As the technology progresses, as agents [music] get longer horizons, new types of failure modes will emerge that will also bring in just new [music] kinds of ways to create value, but also more risk surface.
0:33 · You'll start to see true agent to agent interactions that are not mediated by humans. There's [music] going to be a bunch of interesting questions. You're basically going to need a new legal system. How do they build trust amongst each other?
0:46 · Okay, we're in the studio with Run from AIU, AI underwriting company, uh, with our trusty co-host, Vivu. Welcome.
0:53 · Thank you. Thanks for having me. Thank you.
0:54 · Uh, what are you announcing today?
0:55 · We have raised $40 million led by Ribbit Capital and Frost Money.
1:00 · You first came to my attention when uh Nat and Dan invested in you guys. Is the story like pretty much the same? Like, are you today where you thought you were back then? When we raised our seed round, we had a hypothesis that at some point risk was going to hold down adoption. At that point in time, that felt kind of hypothetical. And I think that that is now over. Clearly, the moment is now with uh Mythos and with Fable. It's pretty obvious that literally the binding constraint on adoption is risk.
AIUC’s $40M Round and the Risk Bottleneck for AI
1:29 · And so for us, it feels like this is a natural continuation of the same hypothesis, but where previously it was speculation, now it feels like fact. And let's get the list of the customers that you um highlighting as part of your series A.
1:41 · Totally. Yeah. So we are now working with folks like Cursor, Harvey, Lovable, 11 Labs.
1:48 · Yeah. Amazing. Congrats.
1:49 · Thank you.
1:50 · So you were famously one of the first like the first uh hired and topic for GTM and product. I'm just kind of curious like what was your path into AI?
2:00 · Just Yeah.
2:01 · Recap.
2:02 · Late 2021 I sold a company, my first company, an edtech company. I had a bit of time to think about what was next. I came across a scaling laws paper and that just struck me like lightning. I was just like this is a big idea. In short, the scaling laws paper just says the bigger the model, the smarter the model. And this is the Kaplan one, not the chinchilla one.
2:23 · Exactly.
2:23 · The cap one. And the important thing that clicked for me there was oh now capital will understand this. If you put in more money, you get more money out. And so that will kick off a hype cycle. Uh and so you'll actually kind of you'll get a sense of predictable returns which is in fact what's played out. And so I just packed my bags. I'd never been to San Francisco. I just packed my bags throughout here to find the people who had written it. Uh and at the time they had just started a small lab colanthropic.
From Scaling Laws to Early Anthropic
2:53 · There was like 40 people at the time or so. Drank a bunch of coffee until I eventually got introduced to Dario. And at the time they were wrestling with some of these questions of like should we deploy our models? should we make revenue? How should we engage with the rest of the world? They just broken off from OpenAI. Uh, and it's been publicly reported that they were kind of concerned with how they were dealing with deployment. So, they were wrestling with some of those questions at that this point. This is like early fog of war, like early 2022. The sexiest product at the time was like Jasper.
3:24 · Like there's there's nothing out there. So, where is value going to acrue? Uh, what are going to be the different parts of the stack were all open questions.
3:30 · But I want to highlight to people, you ask these questions because you have a PPE background. Uh I actually was in in Singapore in one of the sort of feeder programs for prepping people for PPE. So I had a tutor. We learned uh you know philosophy and politics and economics.
3:46 · But like I think you're kind of like machine learning people who read the neural uh scaling laws paper would not necessarily draw the same conclusions that you did whereas any capitalist would read that and go holy [laughter] Correct.
4:03 · Right. Like yes uh who tipped you onto that paper because it's not a paper that you normally read, right? Like in your circles.
4:09 · Yeah.
4:09 · I think I'd actually uh ever since Alph Go had had some appreciation that AI was a big deal. Uh but it kind of felt it raised all these kind of interesting philos philosophical questions, but it was kind of not clear from afar where exactly that would go.
4:28 · But it was obvious enough that it was like this is going to be a big thing if we find the kind of right mechanism to kind of get the technoc capital machine to work on this. but it was just not clear. And so I think it was some way in which like that became obvious and also it wasn't as obvious at the time than than it is now, right? Like it was just like wow this is so interesting but it still felt coming from kind of a philosophy and economics background it felt like if this turns out to be true you're going to be wrestling with all of the big questions in society.
4:58 · Everything you've learned about politics gets thrown out of the window. Everything you've learned about economics at least gets challenged. And so what felt interesting was to be at that frontier that has just ramifications across everything. So that's that's why I I I thought it sorted out.
5:15 · I mean clearly really good insight for people people who don't know PP the PP program is like where prime ministers are born. So then you end up meeting Jared.
5:24 · Yep. Uh first Dario. Yeah.
5:26 · Yeah.
5:26 · Uh well I mean like so did you get extra insights from talking with them that you didn't get from your original hypothesis? If you read the scaling paper, you get this like very vague sketch of like, wow, this seems kind of important. There are some lines and a chart. This seems kind of important. Um, and what I think the team at Anthropic had thought more about than anyone was like, what are the implications of this?
5:47 · If you really play this out, and back then they had kind of vision documents for what the world would look like in 2026. And there are kind of in vivid detail playing out how much comput is going to be needed, what is the capex going to look like, what are going to be some of the kind of societal concerns, but also what is the amount of economic value coming out here. And so it kind of felt like they held a crystal ball that in hindsight not just be dramatically correct. And they weren't holding it like they were obviously correct.
6:17 · They're just like take this hypothesis really really seriously.
6:21 · Think it through and think it through. in the same way the kind of situational awareness that is now across the streets. Yeah.
6:29 · Oh my god, we're all in the same one square mile of [laughter] right and that's now a couple years old but also people keep referencing it these particular weeks with Fable and Methos and it's like wow if you take this one idea seriously with the scale a lot of things fall into place.
6:44 · And keep in mind at this point this is the same team that had did GPT 1 2 and three correct which is also like it's not just some experimentation like there this is a real model that that we just scaled up and they had deep conviction in in again in this like big if you take a big blob of compute [laughter] data it just wants to learn and out of that will come smarter and smarter models and all the particulars were not clear.
7:09 · Yeah.
7:09 · Yeah. and all the implications were not clear but that deep conviction is this like core thesis and that was kind of dizzying [clears throat] it's both phenomenally interesting and exciting and also very quickly you got to like the world we know today will no longer be this if this hypothesis holds so felt like important in some kind of grand sense what kind of shaped you there so that was your early 2022 not only had GPT123 come out but you know the amazing co-founders of anthrop rope that have never split up.
7:40 · The only ones they actually had the conviction to leave OpenAI, start their lab. You said there were about 40 people there. What was the time like there? It was kind of remarkably like what it looks like on the outside today. Extremely cohesive, extremely missionoriented and living in this tension between their two ideas, which is AI could both go really well and really bad and we want to be part of building it. that creates astounding amounts of tension and they
8:12 · were wrestling with this incentive challenge where they know they're kind of there's a race that they're in where you might get forced to cut corners but it also felt very important to them to be at the forefront of technology [clears throat] and all of those ideas were just present at that time. It kind of feels like that line has been just very very clear. Um and I think kind of love them or hate them they have really stuck to their guns. There's a core set of beliefs that they hold more deeply than most companies hold any beliefs.
8:41 · Yeah. Fast forward to today. What does that lead us to AI underwriting company?
8:45 · What are you up to? What what motivated you to start this?
8:48 · Yeah.
8:48 · AI built confidence infrastructure for Frontier AI through standards and insurance. The link from Enthropic to building confidence infrastructure.
8:58 · Looking out the windows at Anthropic offices and seeing Whimos driving by already. back then early 2022 ways were in some ways like Agi for cars like they were superhuman drivers but you couldn't take one to the airport and now 400 years later you still can't take a way to the airport despite now everyone having kind of looked at the evidence and being like they're better drivers than humans so in that particular instance what's clear is that the binding constraint on AI being useful is not capability but instead liability or risk or trust that problem is
Why Trust, Not Capability, Could Limit AI Adoption
9:31 · uh general The reason why right now Fable is not open for access is not because it's not a good model. It's because it's a very good model. It's just hard to make promises about what it will or will not do. And this problem gets worse as AI gets better. Basically, more intelligent AI can be more autonomous. That's more valuable, but also the risk surface grows.
9:51 · And so the what a way more illustrates is that unless you build the confidence infrastructure to make promises about AI or at least bring light to the risks you grind adoption to halt. Governments, banks, hospitals, militaries need to have some sense of what AI will and will not do to be able to operate for them to incorporate it. And that's the problem that we're trying to solve. Now why standards and insurance?
10:19 · Uh [laughter] if you trace this problem back through history, every technology wave has had some version of this problem. So if you go back to like your 1900, electricity comes out.
10:30 · Ben Franklin, cars burn down, sorry, houses burn down, lots of people die. 1930s, cars are a big deal, kill lots of people. 50s, private nuclear energy is a big deal, poses big risks. In each of those instances, the market runs ahead of regulation to create confidence infrastructure because that's required to make go no-go decisions. They're required for adoption and the market fundamentally wants adoption. And in all of those instances, common blueprint emerges between standards and insurance.
11:01 · The reason it's these two components is standards kind of provide the rules of the road and they also specify like what are the tests that need to be run so we can get a sense of how high the risk is. So taking the case of cars, it's like a car crash. Great. Everyone they inform your insurance pricing today. They inform your purchasing decisions etc.
11:19 · That's basically the risk framework. The insurers are important because they pick up the bill. So they are the private institution that is most on the side of is best incentivized to quantify the risk truthfully and then figure out all the ways to reduce the risk because that increases their profit. So they're basically they help shape the incentives and these two worked really well in Unison. Now how does that show up as a company?
11:44 · Well, one of the things that was obvious even or starting to become obvious even a couple years ago was that frontier companies some of our customers today like Cursor uh [clears throat] Sierra 11 Labs Harvey were going to have a very easy time selling a pilot to a bank. them like the the damage itself itself is magic but bringing that through if you want to do a wall to wall roll out at a bank or a hospital uh you have to go through the risk process.
12:12 · These banks have no idea even which questions to ask let alone which answers are sufficient let alone like how do they go and test whether these agents actually work the way they're supposed to. And so they they have this problem of like what can we say to earn the trust? And we think there's like a golden sentence that goes something like, "Hey, I hear you're really worried about hallucinations or jailbreaks or whatever it may be." We've had an independent third party test us against the gold standard.
12:40 · We pass the flying colors and as a vote of confidence, the world's most conservative insurers have looked at the data and are willing to take some of the risk onto their balance sheet. Yeah.
12:50 · So if something does go wrong, there's money behind it. Yeah.
12:52 · Exactly.
12:52 · That's kind of like the link between all of those. We can we can get into some of the the hard parts related to the technical testing which is I think the crux of the matter. Uh but I'll pause there.
13:02 · How did you and Richie come together?
13:04 · This there's always like you you come across very confident and you know you're we're announcing your series A and all these things but I want to see like the early initial stages of like idea formation.
13:14 · Yeah. Rajiv is actually my soon to be brother-in-law.
13:18 · Oh. So I'm actually uh in a week and a half getting married to Rajiv's sister.
13:25 · [laughter] Okay, now you're tight.
13:27 · Exactly.
13:27 · Now, you know, so Raj and I have known each other for a decade. Uh, funny story, I met both Rajiv and his sister Hannah uh at the same time when Hannah and I were interns at Mckenzie in London and Rajiv was assigned as my mentor. Uh, so met them at the same time. For the longest time, it was not obvious that we were necessarily going to work together. H I was in startups. He was an insurance partner at McKenzie.
Founding AIUC and Building AIUC-1
13:50 · Three or four years ago, I think Hannah convinced him that AI was going to be a really big thing and so he quit his job cushy partner job at Mackenzie in London, packed his bags to San Francisco and ended up joining meter. You guys are probably online enough. Exactly. We see the the chart of a uh the horizons of the task that agents can take on is is doubling extremely fast.
14:15 · So here zero there led their partnerships with Anthropic and OpenAI to test their models before release but also working closely with the US and UK government uh to figure out like how do you know whether a model can be released and in some ways that's like the perfect background. He's spent a lot of time in insurance, knows that world, spent a lot of time with frontier testing of models.
14:38 · And so when I was bumbling around this idea space, starting with some of the ideas we talked about related to Whimo, as soon as we got into the content, we're both like, "Oh, this would be an amazing business to to build together. This is like wrestling with the problem that we both think is the most important in the world." From a market angle, which is kind of our intuitions [snorts] is that the market can do a lot. And the faster AI moves, the harder it is for government to solve some of these problems.
15:06 · And then it took a little bit of time to work through what is it like to work with family.
15:10 · Uh and uh cuz you're already dating at the time or Yeah. Yeah. Exactly. Already back then it was we felt like we're family and so starting a business together felt like kind of a big step and uh here we are with just immense amounts of trust.
15:26 · Yeah. So now you're a company of how big? How big are you guys now?
15:29 · There is just 20 of us now. Tony of you guys now have series A and you have your first certification out the AIU1.
15:36 · Um let's bring up the certification. So this is the agent certification, right?
15:41 · What goes into the process? I have like two questions here. One is walk us through the certification and two is what is the process for a company to get certified? You know, great. As it says right at the top, A1 is a standard for agent security, safety and reliability. The fundamental design principle is take all of the concerns that slow down adoption. So all the questions, all the fears that keep uh security leaders in the Fortune 1000 up at night and put them into one comprehensive framework. Uh that's what you'll see there.
16:11 · You can see the six categories. Two, you want to ground all of this in technical testing. So one of the concerns with security standards that often feel kind of like theater paperwork is that they don't actually ground out in does any of this work?
16:25 · Does any of this matter? And so we had a conviction from early on that that was going to be the kind of crux was to pass this you must get tested every quarter basically run thousands of simulations to see well so can it actually be jailbroken how hard is it to jailbreak how often does it hallucinate how often does it leak data etc. And then the last uh core idea here if you scroll up to the top here is to refresh it quarterly.
16:51 · So the core trait of AI is that it moves extremely fast. whatever concerns we're discussing today were not the same ones three months ago and this will keep changing. Typically standards update on like a decade cycle [laughter] is obviously not going to work. But the question is kind of how do you update it? And the core thing here was to basically get the risk leaders of the Fortune 1000 around the table. So if you go over to the left here you'll see AS1 consortium.
17:16 · The consortium is a group of risk leaders who run real banks, real hospitals, real critical infrastructure who are facing these challenges every day. And we meet with these folks twice a quarter and hear what's top of mind, what is keeping them up at night.
17:31 · There's tremendous amount of desire for that conversation and then we operationalize that into a specific standard that gets into and actually we can go into and look at what is what even is a standard. So if we go back to introduction out there to the left, scroll up a little bit to the wheel.
17:43 · Click into reliability. So if we take something like hallucinations hallucination system reliability there is a number of requirements here. If you go into the top one prevent hallucinate requirements uh hallucinate outputs this is one particular requirement. This is a technical control. Basically we want some kind of groundedness filter. The first thing you see here is what's called a crosswalk. So everyone in their grandmother has put out a framework very high level framework for what are the air risks.
18:10 · This is basically your competition. But in some ways our competition we're in fact friends with them. and we'll come back to why but mapping everything together so you have one superset the claim you're trying to support here is uh if you follow this framework then you can also see how you follow the other frameworks but the meat of it comes down here in control activities and evidence so control activities is like great you have this high level requirement how do you turn that down to something operational here's what you must do and then what is the evidence that we're looking for and the reason we go this
18:41 · deep is that there's actually not much confusion about what are the big concerns in AI. Everyone agrees to these. The question like what are you actually supposed to do and so what we found a lot of demand for is getting down to the specific evidence uh that people need to look for whether you are cursor building something or uh even Jake Morgan building something but also if you're just a risk leader at J Morgan like what exactly should you ask for?
19:08 · What can you ask for without sounding stupid? Like if you ask for some, you won't believe the amount of time a risk leader has asked for the IP rights to the underlying model to cursor or something and you just like [laughter] sorry what like you slip it in there and see see if you notice see exactly put them in the questionnaire. Uh so that's kind of what a standard is and we update this every quarter with these folks uh to keep up with the latest concerns.
19:34 · Can I double click on this one?
19:35 · Yeah.
19:35 · So, first of all, the website's beautiful. Like, it's so confidence inducing, which is the whole point where like like, okay, I know exactly what I'm signing up for when I when I talk with you. I don't even have to talk to you. I can just see your whole uh certification, which is great. But like, okay, so from from here, like D001.1 config, ground filter filter, how does that get applied? like you have a person that goes through it.
19:58 · If you uh go back I did see somewhere there's like you know 51 requirements 130 controls there's like a whole right I just like to me this doesn't translate into a test or yes yes yes so if you go into uh on the left hand side so actually if before we go in there there are three types of requirements the first is technical controls like you must implement some guardrails two there are test controls so you must have an independent third party go run some tests against you.
How AI Agents Are Audited and Stress-Tested
20:30 · Well, I'll show you one of those in a second. And then three, there are policy controls. For example, you must have a person whose name is on the line when you guys up.
20:39 · And you must have a plan for how you tell your customers and how you engage with them.
20:43 · There are kind of more traditional standard type stuff. So in this particular instance, we just check whether they in fact have a ground filter. So we will partner with an auditor. So we partner with auditors like KPMG or like Shellman who go in and do the thing auditors do, which is to check the evidence. In this case, that might be a screenshot. It might be part of the code that they need to review to see that it actually just that it exists.
21:05 · And then the second thing, so you're not testing the effectiveness of it.
21:07 · That's the second thing. So if you go down to the third party testing for hallucinations out on the left, that's basically the next requirement. This is where we test how well does it actually work.
21:15 · Okay. And is it you testing or the auditor?
21:17 · We test them.
21:18 · Ah, we test them.
21:19 · That's a lot of work. [laughter] How long does testing take? So if I want to get certified, just how long does the end end roughly take? Yeah, the end to end uh almost always is dependent on like our customers need to learn something for us. It takes somewhere between like three to 10 weeks depending on how up to snuff they already are. So some people show up to us with like extremely rigorous security programs when we test and it works extremely well. We can get that done very quick. Some people come to us and they're not that far along.
21:45 · We give them kind of the spec that they need to build towards and then their security teams and engineers get to work and build to meet the standard. Uh the testing itself typically takes a couple of weeks including the time for them to remediate. Often we'll find something that we cannot pass where hey this is actually just not up to the standard.
22:03 · You won't pass the standard and then they will need to go and implement additional safeguards or additional remediation that makes them more robust so that they can actually kind of hand on heart look at their customers in the eyes and say like hey we've done truly our very best and they're certified for a year and have quarterly updates.
22:21 · Correct. Yeah. And yeah, it's pretty interesting. I think uh you know what's changed since? So this is certifying agents in production, right? Your customers like you've had lovable 11 labs, intercom fin, they've all gone through this certification. Uh what has changed? So I see you post like you know Q2 added MCP agent um agent agent communication. Any other things that you want to kind of highlight since the first first iteration? What comes in quarterly?
22:46 · Yeah, so some of the changes have just been ages are not just one thing. So like if you take agents like cursor and compare them to Sierra, they're really quite different. And compare them to Harvey again, compare them to UI again, 11 Labs, they're all quite different. And so we wanted to design a standard that works for all of the types of agents.
23:08 · And we started with one that was like pretty text based, like honestly pretty customer support focused. That's where there's a lot of existing demand. And then over time I've picked uh some of the frontier companies in each of these other domains that we could work with and build out the standard. So such that we know that the same standard works for code that works for customer support works for automation etc. So that's been one big thing. Yeah. Then some of the things that have been top of mind recently uh mythos is bringing up a lot of concerns for security leaders. We're starting to get more and more questions around agent to agent interactions.
23:39 · It's very nent uh at the moment but it's starting to emerge. There've been a lot of uh questions related to open claw and mcp again like agents starting to interact with each other uh is really top of mind then as coding agents have really taken off. That's also where banks and hospitals etc are getting more and more precise on what it is they need. So really dialing in as as I start to be like where most of the tokens flow through in the world getting much sharper on that.
24:08 · Can you share for people that are listening that don't really think about this? Like you mentioned there's the obvious stuff, you know, hallucination, citations, what are best practices that people should do when building agents like if they come to you pretty ready with certific like you know they'll probably pass certification. What are the things people don't think about that they should have? The most important thing is that a lot of companies have not done a serious stress test.
24:34 · They spend most of their time, perhaps rightly so, optimizing for how does it work in the good case, the average case, how high quality is the output for the customer.
24:46 · And a lot of these companies are pretty new, so they haven't spent a lot of time stress testing the what is what is there as an adversary on the other side? What are some of the complicated corner cases that you've not really considered? So, I think that's like a frame of mind and you also see this in startups. it often takes a while until they hire their first security person and that's a whole different kind of risk surface than just building a good product. So a lot of that applies. Most companies actually also have the right kind of architecture. Most of them will have some kind of guardrails in place.
25:14 · Either some come out of the box from their model provider or they'll have built their own filters that sits in between.
25:21 · They just don't work very well. the difference between putting a classifier in place that like maybe goes and checks whether you're giving medical advice when you shouldn't and says, "Hey, if this looks like medical advice, filter it out." Lots of companies have that in place. The question is whether that works and it's actually pretty fiddly to sit down and think about all the ways in which you could ask for medical advice.
25:41 · Read the academic literature on what are the kinds of framings or tricks you might play to get an AI to give you medical advice when you really shouldn't. Uh and so there's like an area of expertise that's just missing.
25:54 · So what we find is that most people have the right building blocks in place that it doesn't it's not rocket science but the finicky thing is like getting into the corners and testing whether it works such that you can look your customers in the eye who may be a bank or maybe a hospital and be like this is this is going to work for you. I see. So we talked a lot about the agent level certification. Where do you guys go from here? So announcing series A off camerara we talked about this a bit. Um there's the whole security risk of fable government stepping in.
26:24 · You guys are kind of announcing that you're also going into model certification when we do a bit of cutting afterwards.
26:31 · We will not yet be announcing this but the question that is top of everyone's minds now is at the model level and Mthos then Fable has really brought this to the four that in addition to the commercial risk and the kind of economic security risks that are happening at the agent layer the models are going to present risk in the national security category. The shape of the problem is very similar. You have some people that are on the hook if something goes wrong.
Frontier Models, Government, and the AI Trust Gap
26:58 · in the case of agents is often the security leaders in the enterprise. In this case, it's the government. They don't haven't necessarily spent their entire lives thinking about what are the new risks that come here, what is the kind of data you might be looking for, how might you test that? But they do have to make sure that their concerns are addressed. You have some frontier companies that are deeply technical.
27:18 · They know a lot about the risks, but they fundamentally have an incentive to not always be truthful. So, you have a trust gap between the government and the labs. And in every other industry, you end up with some kind of body sitting between a neutral third party sitting between those people. There's no other industry where you allow people to audit themselves.
27:37 · So there's going to be a need for a third party that can take the rigor of the labs to run frontier technical evals, but can also speak legible trust in the way that the government trusts PWC to go and run financial audits. and they know that they output all the reports in a way that's consistent, that's easy to read, that's factual, that's uh trustworthy.
28:01 · Those two things need to be brought together. And what we've learned from our work with agents is that if you want those that communication between those two parties to be smooth, there has to be one common standard that that is public that people can go and inspect.
28:16 · What are the risks that matter within each of these risks? What are the kind of threat models that you're really looking for? You need to specify for each of those risks, what are the guardrails that need to be in place and what are the tests that you need to run to see whether those guardrails are effective. And then you need to go and run audits that are technical audits that are consistent. So if you're trying to bring trust, it's extremely important that you methodically work your way through the risks. You can't send one researcher in and say like come back with whatever you find.
28:44 · You need to be able to explain exactly what you did, exactly what you tried, exactly what you did not try and therefore the kinds of promises you can and cannot make at the end of it. I think of fable as a direct symptom of this problem that the government was told that there's a risk.
29:02 · The government may struggle to assess just how big that risk is. They call anthropic and anthropic is trying to tell them, hey, actually every model can be jailbroken.
29:12 · [laughter] That's not what you want to hear, right?
29:15 · as a government that might be hard to trust and we think that a broker is the most natural solution. In other markets you you see something like uh in financial markets you see Moody's Moody's goes in and they look at a bond and they output a rating. They say like here's the evidence we found. Here's the rating. We don't decide whether anyone should buy this bond or not buy this bond. Well, that depends on the risk appetite, but we do proide this common information layer that everyone can rely on.
29:42 · In the case of Moody's, the government uh points to them and say, "Hey, pension funds, you should probably really take care. You shouldn't risk your pensioners money. So, you can only invest in AAA rated bonds." That means that now the government doesn't have to staff thousands of financial technical experts to rerun forecasts every week to see whether things are correctly rated. They get to point to some neutral third party.
30:11 · Uh so my hypothesis is my hunch is that you will see a third party that sits between the government and the labs and it could either be the government builds it themselves. So something like Casey was set up to to do exactly this. And the question is, all right, I'm not familiar with KC.
30:28 · KC is the center for AI standards and innovation.
30:32 · Okay, I won't get into the details, but it's a sub body of NIST that typically sets standards. Uh, so it's basically a government body that has experts.
30:41 · Exactly. Very low key.
30:42 · Exactly.
30:43 · I think, you know, it's one of those things where when you just sit back and listen, look at it like is there enough technical expertise in the government to measure test these things right now?
30:54 · Probably not, right? And Fable is a result of okay, we've had to scale back and pause things, but and they have they have excellent people uh but they have an extraordinarily small budget compared to the scale of the challenge that's ahead of us and I think they have a role to play. The question is kind of like who does what and we have now outlined the jobs to be done and they're quite extensive. Every model release there is an astounding given that they take in any input the risk surface is astounding.
31:23 · And so the question is really what can only the government do and what can the market provide here that can keep up with the pace as AI risk changes. Our perspective is that also at the model layer the risk that people care about today are not the same ones they care about 3 months ago. So the pace of legislation is too slow to deal with pinpointing the risks here.
31:45 · And so we think there's a lot that the market can do to surface timely information. Ultimately there is a bunch of policy decisions here. Is the national security risks of a model too high? That's a political answer.
31:56 · Uh but what you want to make sure is that the process that produces this risk information is compatible with very fast innovation.
32:03 · So you don't want to this is not a question of like can you slow the things down? Can you keep the models locked up until for months on end until everyone can make a guarantee. uh but it is those can you in the time it given that the US is competing with China on releasing models can you insert risk information
32:23 · that allows the government to like make rapid decisions on some of these questions balancing that trade-off between failing to adopt AI is going to put us at risk but also reckless adoption is going to put us at risk and that's a very kind of fine balance that they're going to need like a lot of high quality intelligence to to make just a side mention because you mentioned Chinese models any specific ific concerns that you're hearing from your CESOS about that uh cuz I guess it's free but CESOS have a bunch of concerns around data flows in general that they're really concerned about.
32:51 · So there's a lot of questions like if these models are Chinese where does where does our data go? I think a lot of those can be addressed but they they come up often.
33:01 · I mean they understand they're running on American GPUs. Some of them some of them understand cuz they're running on American GPU.
33:07 · They're not like phoning home every time you like call home.
33:09 · No. uh a year ago there was not a lot of understanding of this. I actually think uh you're seeing this cure leaders becoming kind of AI literate at a blistering pace and you're actually also seeing my Twitter timeline that's very AI pled and my LinkedIn feed that used to not at all be AI pill kind of converge. They're both talking about fable, right? Yeah, it is true.
33:29 · They are both talking about whether you can prevent models from being jailbroken jailbroken these days. Uh like national security risk are kind of that that conversation is actually emerging. Other than that, I think you mostly see a kind of uh there's no concerns with any particular model or any particular model output. But there's a general nervousness of having critical infrastructure run on models that are not produced in America by Americans where the American government has control.
33:58 · It doesn't necessarily show up in your framework that directly or it might there's a bit of stuff in there actually on the like the provenence of the models and disclosing that. But I think there's a bunch of use cases where running an Chinese open source model is just the best solution.
34:10 · Uh and a concern is slightly more macro here which is not best addressed at any particular certification level. Is there anything interesting that you see at the, you know, if you are trying to fill that middle gap, that mediation gap, any interesting stuff that you guys forecast would be required other than, you know, what what the average person might expect? There's a bunch of interesting questions about what are the risks that matter here. So, right now, the risk of the day is cyber because it's very real, very tangible.
34:38 · And some of the risks that are also emerging as pretty real and pretty tangible are things like child safety is becoming both extremely important uh but also politically important. And then there are some of the risks that are coming down the pipeline that today feel kind of speculative but people spend a lot of time with the models see them coming down is things like um risks that relate to biology and specifically whether models will help adversaries produce biological
Cyber, Child Safety, and AI-Enabled Biological Risk
35:05 · weapons and making that extremely cheap, extremely accessible. producing making the chance of another co or worse pandemic. CO was not engineered to be bad as if you're trying to do that. So I think those are some of the risks that are coming down the pipeline. Uh I think one other thing to just note is that agents are kind of deliberately narrow.
35:27 · So like when a frontier agent company puts a chatbot that interacts with customers, they've really tried to narrow the topics it's interested in talking about. such that if you ask it like what do you think of the president it will just decline which means that the kind of risk area is somewhat smaller for models it is infinite and so there's not a single expert out there who can competently evaluate the risks of cyber attacks and 15year-olds having
35:57 · month-long conversations with a chatbot and seeing whether it will in fact recommend suicide or something horrendous like that and can evaluate the risks that terrorists can use AI to produce bio weapons, the risk surface is just too big. And so the central challenge actually becomes how do you get those subject matter experts to work within a one coherent framework that outputs one coherent report and rating that the world can go and inspect because that global perspective is central.
36:27 · But there's not a single organization today that could produce that and you would be the presumptive one when you put out your model standards.
36:34 · We think there can be one company that can with a consortium of experts build one coherent standard. I think we've shown that across all of the enterprise risks today. We think there could be one company that could with a consortium specify the audit rules basically like the inputs and outputs that all these technical experts need. What access do they need? How should they treat infra infra security?
36:55 · They can look at whether the eval evals are well produced without necessarily being able to say hey is this a thread or not a thread but overall evaluating whether the evals are good well constructed that set of audio rules that basically becomes the interface for all these experts we think one clearing house could put together to be clear when I say one company I think of it as one company coordinating lots of this in the same way that when we saw our consortium it's not like we say we have all the answers on agent security.
37:27 · What we say is we are taking on the role of eliciting all of the concerns and being the secretary that puts it together and runs a tight house such that the standard updates lockep every quarter and that the order reports that come out in this case 100page order reports uniform and crisp and clear all to the level of detail that is required for executives that need to make a clear go no-go decision. So that's kind of the role that we think we might play.
37:53 · I think in many ways you're performing the role that OASP used to do there and you said like you know competition and partners. Can you go more into like how they partner?
38:04 · Yeah. So first of all OASP is basically an open source community of security practitioners that are coming together to build frameworks for addressing the latest security concerns.
38:12 · We think they are phenomenal at creating frameworks. We've in fact we first of all we're partners with them. So we have a joint article. Two we've learned a lot from them. we think a tremendous source of of intelligence. What does not do is building the machine that runs third party audits such that a company like Cursor or a company like JP Morgan could get a third party to go and review them against this and say hey you've passed the standard and here is the report that you can use to build trust and preempt your partners or customers questions.
38:43 · So they fundamentally try to do something different. You can they are part of the information gathering and intelligence gathering and creating clarity but the operational layer of turning this into promises is is not the business they they tried to be in.
38:57 · The standard is emerging and and it's doing very well. Was it necessary to then also do underwriting? Uh obviously it's in the name so presumably you thought about it first. I feel like if you just have enough consensus you don't actually need the money angle but it does help. I did want to also note you guys are a for-profit company too, right? It's not nonprofit work. There's there's a whole business side to it as well.
39:22 · Yeah. Yeah. Yeah. This is crazy about the money.
39:25 · Yeah. Yeah. Yeah. Let's get into the money part.
39:27 · Let's start from actually your question for profit versus nonprofit in the security space today. Cyber security most of the standards are produced by nonprofits. I think that's an issue.
39:40 · [laughter] The question you have to ask yourself is how do you create good incentives for these standards to be good and keep up?
Why Standards and Insurance Belong Together
39:51 · Nonprofits tend to not have these adverse profit incentives where they uh hollow out their standard and create a race to the bottom. But they're also not at all responsive by default to the communities that they serve there because there's no process. They don't have customers that they serve where they go and ask what do you want? What do you want? What do you want? And when you look at the overall satisfaction with the security standards today, people tend to just not like them very much.
40:18 · You do see in other domains uh that for-profit standards can serve the world quite well. So there are examples uh like we talked about movies before. It's not without flaws, but uh it is absolutely critical societal infrastructure that gets run at astounding scale today. your credit score. It's FICO. It's also a for-profit business. And when you go back even further in history, some of the crash testing standards came out of insurance companies.
40:49 · The insurance companies together funded the founded institute of insurance institute of highway safety because they were very interested in like how can we use standards to drive down mortality and save money. go back uh prior our name actually pays homage to the underwriters laboratory UL which uh was
41:08 · started right around when electricity came out houses started burning down insurers again were paying the bill and they were maybe also good people but their profit incentive was let's prevent houses from burning down let's test all the electrical products the light bulbs all the light bulbs in here are probably well tested the toasters etc and they set up uh an entity to create those standards Today, UL has a for-profit entity and a nonprofit entity.
41:32 · Um, what they've recognized, they spun out, they started a nonprofit, they spun out a for-profit because what they recognized was like, hey, actually to serve customers well, you need a for-profit entity. The lesson here is one of the ways that the market can align incentives so you're both responsive to customers and not hollowing out your standard over time, is to align it with insurers because they fundamentally have good incentives.
41:57 · And so if you're a for-profit standard that works closely with insurers, you get the feedback loop in such that you're really queued into your customers but also have their interest at heart. So that's the model that we're the kind of inspirational model that we've learned a lot from and that's also where the name comes from.
42:15 · In some ways the the term underwriting can both be associated with insurance, but it's also a broad term for like making decisions. M if you underwrite a decision uh you're fundamentally kind of taking ownership for for the consequences of it.
42:28 · Yeah. I mean what does an insurance contract look like for AI?
42:32 · Yeah. Most of the demand comes today for insurance contracts is uh sitting between people who've built AI and people who are buying AI.
42:39 · Yes.
42:40 · And what you want is the reason why people want insurers involved both for the traditional reasons. pay. If something goes wrong, we want to be compensated. But it's in particular because insurers can increase in can bring trust in the equation because insurers will take pay for the damages.
42:58 · If they're willing to write an insurance policy, that is them saying, "Hey, we think there's risk here, but that is manageable." And that is kind of a their incentive aligned with the enterprises adopting it. So that's a really a good signal to the market. In the same way actually uh one of the things that Whimo tried to get their first permit to even operate in San Francisco was to get a lot of insurers to stack up a huge insurance policy in the case of something went wrong.
What Does an AI Insurance Policy Actually Cover?
43:23 · Not because Google can't pay, but because it was very valuable to have a third party go and look at that data that are trusted by governments, trusted by enterprises as conservative people and say, "Hey, we've looked at it. We're actually willing to take some of this onto our balance sheet." So that's that's kind of the reason why people are interested in it.
43:40 · What it looks like is uh in some ways like every other insurance contract, you specify what are the perils you want to cover, how much do you want to cover them, like up to what limits, what does it cost to cover that? And in the case of um if we take a really concrete example, uh 11 Labs uh bought a first of its kind AI agent insurance policy. They work with some of the biggest uh enterprises. They work with governments.
44:08 · They're really interested in going above and beyond and making promises to their customers. So, they wrote a policy that covers just some of the core concerns that our customers have been asking about. And uh the crucial thing was really to get Lloyds of London, the world's oldest insurer, one of our partners to look at this data and be that third party alongside us to say, "Hey, we think there's something here that's worth underwriting."
44:32 · Um, and that's actually what it looks And so they will show that c that contract to their customers and they can see how much they're covered for. They can see what exactly it covers. Uh and that will also probably change next year. They will want to write an insurance policy that might cover more.
44:47 · When you say Lloyds, is it reinsurance or are they sharing somehow at the same level or Yeah. So typically the way uh new companies get into insurance is that they partner with insurers such that the insurers take the majority or all of the financial risks. Fundamentally if if if insurance is useful because it brings trust, you have to be able to pay the bill. Lloyds of London is 400 years old.
45:13 · They've never not paid a claim. They're extremely trusted. Um what Lloyds of London struggled to do on their own is to figure out which of the risks are real. what should we be looking for?
45:24 · What are the kind of technical controls and running the tests? So they use AEC1 as kind of the underwriting framework and we produce a bunch of email results that then directly feed in to inform the pricing. Uh so this means that Level Labs customers know that that payment will be there. They don't have to look to our series A and see like do we think they have enough cash on the balance sheet? They will look at Lloyds.
45:47 · Yeah.
45:48 · Um and Lloyd's like famously very creative.
45:51 · I I think I remember some headline like they insured Jennifer Lopez's butt or something.
45:56 · Correct. And I think uh was it David Beckham's right foot? Yeah. Stuff like this.
46:01 · So like clearly not a large data set.
46:05 · [laughter] Exactly.
46:07 · It's actually a remarkable institution that's both kind of has some of the truly old school virtues of having been around for a long time. they like really they really operate like a trusted entity and they have appetite to figure out the future h and I think there's a lot of recognition that both there's like tremendous amount of risk in AI that is poorly understood today so getting into this business carries real risks uh but also this is where lots of
46:34 · the risk exposure will happen in the future this is the one market where risk is truly growing this is the one market that will also take out some of the existing markets take like auto insurance when there are no human drivers how's that market going to look well it's clearly going to change how are you going to assess you want to insure way more [laughter]
46:53 · I all I'll say is the principles for how you ensure way more are very similar to how you ensure other kinds of AI so can crash testing that's what we do for customer share are lovable that will also need to happen for way is not how you do it for human drivers so there's this growing awareness that the world is changing very fast and the only way to learn how to underwrite AI is to write some policies.
47:13 · You may incur some losses and and think of that as R&D expense really, but the question for them is like who are the trusted technical partners they can get into this business with that can help them navigate and make sure they don't make uh kind of foolish mistakes, but also who is willing to hear the wisdom that they have. They've done this before.
47:32 · They've seen they were there when cyber came out. So there are lots of ways in which AI feels completely new, but there's also lots of ways in which risks look the same. And so there's actually tremendous amount of wisdom sitting in some folks that may have gray hair uh but really have like a a keen sense of uh how to quantify risk.
47:51 · Yeah.
47:51 · And and the number is so it's basically like I want $50 million worth of of coverage against these perils and VO will give you a quote on it and then you you have like a small markup or something and then you you turn it around and and do that. Is that is that as simple as it is?
48:06 · You you basically share some of that premium. X% goes to the people who do the pricing of it. It's kind of like a It's kind of like a merchant bank for insurance type of thing.
48:16 · Exactly.
48:16 · You basically split the fee and you can think of the insurance supply chain as like there's bringing the capital, there's doing the pricing and there's doing the distribution and typically you will pay out some x% of premium here, y% of premium here and the rest of it will go here. Does all the insurance world work like this or is there some point at which like so so right now you have equity capital at some point maybe you start raising uh
48:37 · debt or whatever and then you have enough of a bank account and enough history let's say you've been operating for 10 years that you don't need lawyers anymore that's totally an option uh and I could see some worlds where that makes sense specifically if there are risks that we feel high confidence they would want to ensure where the incumbent insurers are too slow to find appetite okay or or simply struggle to evaluate such that they don't want to do But by and large in general you do not want to compete with insurers on uh bringing risk capital to the game for two reasons. One is that's fundamentally a cost of capital game.
49:08 · They have extremely low cost of capital startups have high cost of capital by and large and two you want to hedge your bets and it's very helpful then to also have a portfolio of home insurance of car insurance and we we're not about to become a cars nor a home insurer. So they have some natural advantages which makes it much more likely that we'll partner.
49:31 · Yeah.
49:31 · And they bring that the capital at scale and we bring the technical.
49:34 · You're going to work with them for a long time.
49:36 · How are the discussions with the insurers as well? So basically they're going off of your certification, right?
49:41 · They're trusting the diligence on you that your certification is valid. You tested the right things and they're backing the money that you know you have the right testing in place. So any interesting takeaways from working with insurers? I think the maybe the first thing is they feed into the standard as well.
49:57 · So if there are things that they feel like they need that they're not seeing we are also taking that as input into the standard uh because fundamentally we think a good standard is one that creates a really healthy promise ecosystem and we think insurers are critical part of that uh and again they are the most well incentivized to they see all the loss data across any particular CISO knows their particular concerns. insurers see the concerns across the entire portfolio and often have direct access to like what exactly happened, who was at fault, etc. as they do part of their forensics.
50:28 · So, they're actually like a great source of intelligence on this. One of the big takeaways from cyber insurance, which is a market that didn't work that well, was that the insurance and the technical expertise was not married up. Uh what our conviction is that standards have to precede insurance. fundamentally what everyone first and foremost want whether you're a CISO at Jig Morgan or a CISO at Cursor or a underwriter at at Lloyds of
50:59 · London syndicate is you want to not have an incident in the first place you want to know that the risk is well managed and only then does insurance start to make sense so we'll see the standard ecosystem basically run ahead of the insurance and the reason why we you asked us kind of why I also do insurance this is kind of proving what We think that whole promise confidence infrastructure ecosystem needs to look like and we think it's very compelling to bring that to life even if we think the standard is kind of the the core lynch pin that unlocks the rest. There's been no claims yet, right?
51:28 · Nope.
51:29 · This is one of those things where um you know if people haven't really worked through what it means to cover things. So for example, I pay cursor $20 a month.
51:38 · Yep.
51:38 · And I write I vibe code something that makes uh a plane crash causing $200 million worth of damage. Uh, do I claim $20 or do I claim 200 million?
51:48 · [laughter] Yeah. So, these are all great questions.
51:53 · Uh, and fortunately, kind of all of insurance and legal history kind of helps answer some of those questions. I think the first thing is people have limits on their policy. So, if you want to claim $200 million, you have to someone has to have paid a lot for that insurance policy up front to have $200 million of coverage. And ultimately the way this works is that uh you start from a lot of uncertainty.
The $20 Cursor Subscription and the $200M Plane Crash
52:16 · This is not just an insurance but also like can you use can anthropic use books from the internet to train up well they can go and look at precedent they can see but ultimately this these things get settled in court and you hammer it out over time. So you start from this like place of ambiguity which is both why insurance can be hard to do early on but it's also why people want insurance because that ambiguity slows down adoption. Yeah, that also sits at the heads of the uh in some ways actually the first incident will help to establish a lot of this.
52:48 · Exactly.
52:48 · And and there have been a number of incidents out there that have just not been insurance covered.
52:52 · Take the now old uh example from Air Canada where hallucinated a a refund policy and the question was Air Canada in that case were like hey we have nothing to do with this chatbot messed up but like sorry and the courts were like no if you put your chatbots to interact with your customers they make legally binding promises on your behalf.
53:15 · That is now precedent for everything in the future where you will if someone were to deploy a chatbot like that again there you should not expect to be able to just pawn off and say sorry my chatbot lied it's nothing to do with me I bought it from open AI no if you're putting this in front of your customers you are taking responsibility for it and so every court case whether insurance is involved or not clarifies liability and liability is kind of the foundation for
53:43 · insurance there's another reason why stands and insurance come together liability ility for I'll go on a little tangent here. Get the weeds of it.
53:50 · Please liability often one of the core concept is whether someone was negligent. Should they have seen this? Should they have prevented this? And the question you how do you judge that? Well, you basically judge whether they've met their duty of care. What does that mean in practice?
54:05 · Well, often they look to standards. So if there's a standard that is broadly adopted that says you must have a groundedness filter or you must have a jailberg filter it becomes way harder to claim ignorance that these things existed and so setting standards help clarify liability points courts will often point to standards and being like well this seems like best practice to do is there for everyone to see. So there's another way in which like standards are kind of civilization infrastructure that insurance can then build on which promises can then build on.
54:34 · I I totally get that we don't have to get certified to to write these to you know make these like bots and all these.
54:43 · Um but like basically whenever we get go for the audit I think people like start to shape up and and all this all this stuff. I wonder if like that means that you don't also then become like the approving authority for me to ship to production you know like um yes you check once per quarter I want to ship once a day.
55:02 · Yeah. and I don't know when one of my things breaks like one of your certifications or not.
55:07 · So there there's a couple of things um there's a couple of requirements in there that relate to how do you yourself where you have to tell your customer how are you yourself testing before you make at least major releases. We don't go and order to people every day. Uh but at least there is now a trail where if you do a major mess up then your customers may come and ask you hey you promised me that you were going to run these emails yourself and for lots of them most most
AI Liability, Monitoring, and Earning Enterprise Trust
55:35 · of the PRs that people merge will not fundamentally alter the product experience but some of them will and sometimes you don't know and sometimes you don't know and this is also true and this is also there's some inherent risk that everyone kind of everyone knows that when they buy software there can be bugs and this this is just part of it but what they can if you're selling to mom and pop shops they may not here that is like well I I want
55:55 · to use your tool so I'm just going to will be willing to take that risk on if you're selling to a big bank they might be like sorry we're making promises to our customers if you can't make a promise to us that we can pass on we don't want to work with you then it's up to you to say do I care for my agent to get used as critical infrastructure in this nation if so at least I can make promises about what process I run and then we can go and test it every quarter to be like well does it seem like uh it's still of uh kind of it still meets the standard.
56:24 · So from my perspective, it's kind of a way to big companies by default kind of have some amount of trust when they ship AI. If you're a young company, if you're just starting out, by default, you have no trust. And there are very few places where you can go and get trust. So one of the things that most of our customers did before they started working with us is that they would make their own security blog posts. That's great, but also who's going to trust you saying we're so secure? [laughter] Like anyone can write that, but it's very hard where do you go and get that trust?
56:50 · And so I think making the standards more legible makes it easier for smaller companies to prove that they're doing what they ought to be doing because the default assumption is that it's the wild west.
57:03 · Is there a road map you have of like there's a lot of work to be done here, right? This is the first one. Um anything on the road map of what you see is next, what's coming, what's what's missing? I think when we when we zoom out a1 deals with agents we will next up
57:21 · we will deal with models next up from that we will deal with robotics of which in some ways Whimo is the first robot but the exact same problem is going to be someone's going to develop a robot someone's going to need some promises they're going to struggle to make the promises and you see this playing out when like uh if you think fable concerns are bad like see when hits a dog and as if people lose their mind imagine when first robot knocks off a toddler off kitchen table.
57:46 · Yeah, you're going to see some real strict liability.
From AI Agents to Models to Robotics
57:50 · I mean, you can see it, right? Like crews got fully all permits are gone. Yeah.
57:55 · Right.
57:55 · So, physical AI, the level of stringency just goes up and up and up and up. Um, so that's kind of like the big picture. Agents, models, robotics. I think within agents the current set of agents are well covered by this but as the technology progresses as agents get longer horizons new types of failure modes will emerge and so it's mostly of can you make sure that the standard keeps up when they appear and you'll also start to see new modalities like today world models is mostly kind of a a
58:28 · research question there's no one who's really using it but that will also bring in just new kinds of ways to create value but also more risk surface that no one knows how to grapple with today.
58:38 · You'll start to see true agent to agent interactions that are not mediated by humans. There's going to be a bunch of interesting questions. You're basically going to need a new legal system. How do they build trust amongst each other? How one of the core things when humans trade with each other is that you know that you have recourse, you can sue them. How do you make sure that there is a persistent balance sheet behind any agent such that if you trade with it and it screws you, you know, you can get your money back? Those are some of the questions we're going to have to deal with.
59:03 · And the technical testing of multi- aent systems is also going to be interesting and complex. [laughter] Very fun. Uh are there any perils that are uninsurable right now that people wish that you would?
59:18 · Yeah, one of the places where there's a bunch of appetite for insurance and not a lot of a lot of demand but not a lot of supply is when it comes to copyright. In some ways, copyright is kind of mundane. It's always been an issue. Uh there's a couple reasons for this. The first is people who have trained on copyrighted materials almost always know that they've done that.
59:42 · So if you want to buy insurance for it, it probably signals that you might be a high-risisk customer.
59:49 · The people who are most interested in getting insurance for copyright infringement are the people who are most likely to like it's like a lemon problem.
59:56 · Exactly.
59:56 · I actually think there's another side to it too, right? Like if you're building on something, so say I'm using an open model, I don't know what it's trained on, right? And how far down that chain does copyright go? Yes.
Copyright, Adverse Selection, and AI Insurance
1:00:07 · Am I liable to take down my product because company X train?
1:00:13 · But there's safety in numbers. If everyone's doing it, then you I mean I would say until you know, Fable [laughter] is rolled back from everyone that use it, right?
1:00:20 · Yeah.
1:00:20 · It's a hard question. I don't have the answer to that but I think [laughter] your your intuition is your intuition is right that kind of like uh what is the kind of duty of care and people don't today think of it as customary that you go and you like dissect your open models training data and you check everything [clears throat] in fact lots of people use them it's seen as kind of generally acceptable to not check for this and therefore we're not going to hold you specific we also really can't right we don't exactly we don't know the training they have you can ban it but I think no court is going to get a copyright question to get banned.
1:00:52 · Hire Nicholas Kini and he can extract it from Exactly. Though he is in short supply.
1:00:58 · [laughter] Yeah. He only has so many khalinis. But uh Exactly. So I think this is this is also fair that uh in the case of labs there's a lot of interest for this but the thing that makes lab wanted it is what makes insurance suspicious of it and so you have a lemons problem. Um yeah. Is there like a theory of insurance where adverse selection dominates the risk sharing aspect of insurance? Like where does this like teach us insurance?
1:01:23 · A lot of insurance does come back to like practical versions of microchamics 101.
1:01:29 · It's like it's like this is why you need to pull health insurance uh because if you make it too hyper specific then only people who are guaranteed to get the disease will sign up for your insurance.
1:01:39 · Exactly. Same thing.
1:01:40 · The core problem is one of information asymmetry. people who are buying insurance know something about their risk that the insurers [laughter] do not know. And so the question is actually and this comes back to the same problem is if you rely you can break a lot of these information symmetries if there is some kind of testing that reveals the underlying true risk. And so if you were able to in the case you mentioned have good diagnosis of whether someone has it or what the probability is that someone has it that the insurers trust then they might be willing to insure it.
1:02:09 · But if they don't, if there's no kind of common information, then the only the patient will know. That's what breaks it down. So the question is again, how do you create credible signaling between players? This is also the whole reason why Moody's exists. Moody's just does credible signaling. That's also why Moody's could never uh Moody's has to be independent. If Moody's was owned by JP Morgan, then JP Morgan could not use it as a signaling mechanism.
1:02:34 · So a lot of the basics of standards and certification are just communication devices. there's just a trust gap and uh that's where you have to think about what are the incentives of the messenger and one another way you can break a lot of this is through transparency. If you are transparent in how you operate you just cannot mess with others nearly as easily. You make it much more costly and that increases trust. This is one of the reasons why there's a change log here.
1:03:00 · Every little change Yeah. Yeah. you can go back and find and it means that if we were to make the standard worse Oh wow that's a lot of changes in one update.
1:03:10 · Yeah.
1:03:10 · Okay.
1:03:11 · And a lot of this is just as things get clearer you can see a lot of clarifications you can see some revisions as things get hammered out you want to change this but if you make it all public you make it much harder to mess with people or at least you become found out very easily. Mhm. And so this is a way of increasing uh sort of reducing the information as symmetry is by just making more of the information public.
1:03:32 · I like how you do know when future versions are coming. So I guess it's quarter.
1:03:36 · I mean they just not that surprising. [laughter] Yeah. But this is also promise like if we now don't deliver on July 15th.
1:03:46 · I mean you can just batch it up and then whatever you got. Yeah.
1:03:50 · Like we deposit some amount of trust every time we meet this commitment.
1:03:55 · Yeah.
1:03:55 · Uh and in the startup land it feels easy to ship a new version of a standard once a quarter. Uh in the enterprises who are used to this like decade long cycle we often get met with like incredul like there's just no way and then you show them the change log.
1:04:11 · One thing I wanted to also like try to really think about is you know you said something about how if you have tests for the thing then you can ensure it.
1:04:18 · Yes.
1:04:19 · Right.
1:04:19 · And so really what your standard is, what AIU is, is establishing a framework for the audits that happen so that you can at least test like all these like baseline standards of care have been met and therefore people can ensure against standard risk that everyone has. I wonder if like there needs to be develop you need to develop other tests. Uh we've covered mechan uh in in the past. Any interest in that or are there other kinds of tests that we're not thinking about? Yeah, I think Mechinurb is a big one. Uh, a lot of interest in that.
1:04:51 · I think everyone would agree that there's like promising scientific potential. We're still a while a little bit away at least from this being like commercially available on demand such that there's like now a selection of vendors you can go to.
Evals, Mechanistic Interpretability, and Eval Awareness
1:05:09 · Goodfire would say it is commercially available.
1:05:11 · Exactly.
1:05:13 · We would agree with them. We we think the work that they're doing is tremendous. We're not quite at a point where we could like literally require it, but it's the kind of thing where you can imagine relatively soon you could put in an optional control for if people use that interpret as a way to reduce risk. You at least get credit for it. We can't require it because it would be hard to require everyone to become good fire customers.
1:05:32 · What good does credit do me? This is this is a past fail, right? Do I do I do I care about credit? Uh it's a past fail, but it's also 100 page order report that you'd be surprised at how much security actually sit down and digest this stuff.
1:05:45 · Okay.
1:05:45 · Uh and I promise you that if someone is using mechan today, uh they will have a slide on it.
1:05:53 · They'll try. It is cool. It's fancy.
1:05:55 · Yeah.
1:05:55 · But it's just easier if you have a third party saying, "Yep, they have meant to actually just like just to flesh spell it out for people people who have been following our our mechan podcast." It is literally like you're using it dangerous. We monitor for it and we log it out in whatever tool of choice. Grace one has like signal whatever and that's it. That that that's the mechan based activation uh signal. Okay.
1:06:21 · Yeah.
1:06:21 · Yeah. So I think mechan is interesting and I think if that promise truly comes to fruition you can make stronger promises than you can with evals. And so I think that's very compelling. Another thing that I think will become increasingly important is just kind of good old school monitoring and slightly after the fact. Uh one of the things you're seeing with eval some of the challenges that are emerging is that the agents are starting to become aware that they're being evalued.
1:06:55 · They won't do the thing that they think they get punished for. And by default, unless you know how to kind of reduce your val awareness, you should trust Els less. And one of the kind of truest things monitoring like is the source of truth. Did you in fact give medical advice and how quickly do you know? How often do have you done that in the past?
1:07:14 · How fast do you respond? How often do you detect it? How fast do you detect this? Uh so I think that is also a paradigm that slightly more intrusive.
1:07:21 · You actually will look at some customer data. uh but I think will become more prevalent over time. People talk about this like we should not write about EVA awareness because it's going to leak into the data set and then beat [laughter] like we should just like we should like never talk about it only meet in person and like talk offline unrecorded like did you guys see the anthropic research where I think this is literally anthropic did that test where they took I can't remember the details here but they uh ran some studies on misalignment
1:07:54 · and then they took out the training data that related to less wrong discussing misalignment and they ran the same test again and the failure rate went down. [laughter] So it in fact was some evidence pointing towards it had learned the either the ability or the propensity to do that.
1:08:10 · Yeah. I mean there's there's the hypersition effect and there's there's like the Luigi waluigi effect. Correct.
1:08:15 · Which is like you are the the more you try to train for it you you create the opposite.
1:08:19 · Yes.
1:08:19 · There you go. That's exactly it. In some ways I think the very successful topic is a result of hypers position like the the fact that you wanted this this thing to exist in the world and now it does but like then it also creates the opposite as well like I think I think people who are maybe newer to this space don't remember wui but like I do think it's very very important for understanding that when you train for a thing you also train the the opposite of the thing cuz it's just a bit flip.
1:08:45 · Yes.
1:08:45 · [laughter] Yes. I think you know just going back to where we were at like there's a lot more than just mechan that there's value in just having added right so your version of how fast can you measure stuff do you have logging do you have evals you know do you see other parts of the stack like the inference providers that you use the services okay am I using Chinese model
1:09:05 · on their home API am I using through certified vendor here am I hosting myself uh what am I doing on the inference engine side there's just like so many levels of stuff that gives you know information that you can standardize out, right?
1:09:19 · Yeah.
1:09:19 · And you also see increasingly in addition to just the basic chatbots, you're increasingly seeing big companies adopting agent platforms where they're building on top of Google's agent studio, etc. that comes with a bunch of like managed managed everyone has managed agents.
1:09:38 · Exactly.
1:09:38 · And there's there's even levels you can host your own manage agents open agent SDK or hosted by Anthropic or Google does both. Correct. And then these are just ways to kind of strengthen the security guarantees you can make. Uh and in some ways this kind of breadandbut enterprise security they like they love to host things on their own premises because it gives them really a sense of control.
1:10:01 · And I think you'll you'll see just like you do in every other enterprise market if you really sell to the enterprise you start to compete on some of these security features and this is also helping AI unsurprisingly and I think you are seeing some amount of enterprises wanting enterprises are really grappling
The Impossible Enterprise AI Mandate
1:10:20 · with the thing that makes agents useful is they're stoastic and the thing that makes them really hard to adopt is they're sarcastic and these are just intention leaders come out on different sides of that in part depending on how much the CEO is trying to get the stock price to go up by saying they're AI native that we must be willing to take the risks but you see we actually see phenomenal tension in the heads of the CESOS of the Fortune 1000 where on the one hand you have a CEO saying we must adopt otherwise we're
1:10:47 · becoming irrelevant and if we up you're fired and that's kind of like the core emotional tension that we see showing up again and again and again and again and one of the core problems that we solve for them is to take that abstract emotional concern and turn it into a framework in some ways just provide and clarity to to that concern.
1:11:06 · Is there anything in here? So something I think we kind of skipped over. We talked a lot about agent language model, skipped over world models. Um you guys have voice which is interesting with 11 labs. How about generative media? So you know generating images, videos, that's a category that actually has a lot of usage. Is there anything in your current policy? Is it separate policy? How do you see that space? Yeah, it's like we did talk a bit about copyright. So, yeah, music as well.
1:11:34 · Yeah, I think a lot of the concerns that come up there either relate to uh copyright or there's a lot related to let's call it broadly safety. So, like this could be not safe for work or just very graphic materials uh are kind of some of the core things. Uh we have done some work on this.
1:11:51 · There's a little bit in the standard as well that deals explicitly with that. uh video we have not done a lot in yet and I think for proper production that has still especially proper production without a human in the loop that's still got some ways to go.
1:12:08 · It's obvious that it's coming but it's very rare that it's like one shot deploy a video to the internet but eventually that will also happen. we see like you know Luma has Luma agent where it's still pretty human in the loop and that just makes complete sense as the technology matures and over time it will become so good that people will not want to slow things down by having a human in the loop and then uh the need to make promises [snorts] will grow. Why not just have prediction markets on everything, right? It's very EA adjacent.
1:12:39 · Yes.
1:12:39 · [laughter] The core thing is that the people prediction markets rely on public information. There is not a lot of public information. It's just insiders trading on each side. [laughter] That's illegal.
1:12:53 · There's leaked information.
1:12:55 · There's leaked information. The core challenge is that often you have private sensitive information and you need to convey confidence and trust around that. And you can of course for some claims like can any model be jailbroken? You could rely on public evidence cuz there'll be lots of people being like well there's tons of studies and actually they all can so that resolves fine. I think that's good for hey this
Prediction Markets vs. AI Audits
1:13:21 · new unreleased methus model how capable is it actually prediction marketers have not a lot to say because actually just no one knows and so I think that's the core place where some of this breaks down is that actually lots of the world's information that guides some of these high level decision is private and often also just not known I think the thing with prediction markets that people like is it's not it's not answering the broad question it's a specific right so will a model do this by this date or is a model capable to do this by then, right? So that's a little distinction there.
1:13:53 · Yeah.
1:13:53 · And often the most interesting question if you're say the head of security at a bank, the question you're really trying to answer is will this product, this agent do this bad thing that maybe primarily I care about specifically in the setting that I care about and the question is like what's the closest that information may not exist anywhere. So prediction markets aggregate existing information. this information may not exist and you want some very specific and you're willing to pay for it. That's kind of where a third party audit comes in.
1:14:21 · We also don't really use prediction markets to figure out whether uh public companies have committed fraud on their books. You use audits. You probably could, but the information is just not that available.
1:14:33 · [laughter] And if so, it would be like just trading on bibs. Uh I actually would have been really interesting to see where the prediction markets 2001 would have predicted Enron going bankrupt and the kind of could you have told could you have sense from like the the craziness of the CEO or some other trait that they were more likely to cook their books than others or enough insiders leak it than that you
1:14:55 · could also right which is like I mean this that that's the sort of the ideal dream of prediction markets you have liquid markets and everything and then you can compose your exact set of risks to offset.
1:15:07 · Yes.
1:15:08 · Right.
1:15:08 · Yes.
1:15:08 · Yes. Yes. Yeah. And I think like prediction markets will bring lots of new information to it. So the thing is mostly not like which one is it and more like what are the types of questions that prediction markets are really good at and what are the ones where the information doesn't even exist for insiders such that no one could in fact trade on it and needs to get generated.
1:15:26 · Okay.
1:15:26 · One self-s serving question and then one open-ended one uh on like the the future of AI. Uh self-s serving question would be so you have your standard right? I run, you know, a large AI engineer conference. Like there's been a lot of talk about us certifying AI engineers.
1:15:41 · Yep.
1:15:42 · Training programs level one, level two, level three. I was a CFA myself. So I know what that that's what the finance industry does.
1:15:47 · Yes.
1:15:48 · Would it help if we I had AI engineer level one, level two, level three, and then would they would like work with these guys? I don't know. If you think of the highest level objective as like accelerating secure deployment of agents, then that would totally help.
1:16:02 · But one of the things that happens often now is that folks build agents, they bring it to the to the decision maker and the decision maker surfaces a bunch of security considerations that they had not thought of and now it's not built to spec. Now you have to go and re like add these filters etc. So if you shifted that left like if everyone knew what the spec they were building to if everyone knew the grading scheme.
Should AI Engineers Be Certified?
1:16:24 · Yeah, that'd be awesome if they were already trained. So by default you're the grading scheme, right? I don't get to set the grading. You guys you set the grading scheme. We set the grading screen and I think what's uh valuable is like if you can turn this into training programs training programs such that which you're you're not doing we're not doing that. I think there's value in doing it.
1:16:40 · There there are others doing I mean not to interrupt interrupt but you know open has their andic also has like a CCPA thing.
1:16:47 · Yeah. You know they want they want 100,000 deployed certified consultants.
1:16:52 · Right.
1:16:53 · I think it's good for we will accelerate adoption if we have more people who know how to build secure agents and we're not working on the side of training people at the moment. I think it's like very aligned with our mission. We only have so much uh attention. M I tell you why I haven't done it.
1:17:09 · It's not like I I haven't thought about it before.
1:17:11 · It's just being prescriptive, right?
1:17:14 · About like, well, this is what you should know, therefore like the stuff that I didn't include is what you don't need to know.
1:17:18 · Yes.
1:17:19 · I'm like, that sucks. Like, yes. Yeah. Yeah. [laughter] Yeah.
1:17:22 · And I think it's like, you know, the the the very interesting defensible thing you guys do is your opinionated 100page report of here's what matters, right?
1:17:31 · here's the like prescriptive definition of the requirements you need to be certified. So yeah, and I think that's a choice. I think basically that's a that's a choice and I think that serves some audiences very well where if you're trying to deploy this into a bank or a hospital etc. Clarity of the B those boundaries is extremely valuable.
1:17:52 · There's lots of other settings where being much more experimental, much more trying it out is just the better fit. And so to me this makes a ton of sense. Also, you'd have to rewrite your curricula every freaking three months. [laughter] It's fine. I do that. Like, it's okay. But yeah, no, for me, it's actually like genuinely like the the consequences of getting it wrong and like affecting somebody's career is is a big responsibility.
1:18:18 · Yeah.
1:18:18 · Yeah. I think that's exactly right. And I think a lot of our work actually goes like we don't want to carry we also don't think ourselves as able to carry the kind of the true north of what's like secure not secure but we can coordinate the forum where you elicit all of that is this can be crowd
1:18:38 · sourced like for your example for what is AI engineer certification right this is a pretty big podcast there's a lot of takes that people can have and you know discussions that can and people reasonably disagree so who am to say like that's a correct question, that's a wrong question.
1:18:52 · Yeah.
1:18:52 · Right.
1:18:52 · So like I don't know [laughter] vent your frustration to someone that's and I think there's also you uh or it matters a lot what the promises. So if the promise is hey if you've taken my course you will not up. You can't make that promise clearly.
1:19:13 · You could make a promise of like here's the some important things that everyone should at least know and then you have to fill out the rest there. At least the promise changes. Of course, there's some subtlety in how do you communicate this stuff so people really get it. Uh but I think it's important to dial in and we have a section in our standard like what is the promise and what is the promise not uh because it's impossible to guarantee that nothing will go wrong. If you need a guarantee that nothing will go wrong, you cannot work with Frontier AI but you can make some claims.
1:19:39 · Yeah, for sure. Uh cool. uh wanted to end with open-ended. Where is AIU going?
1:19:44 · Um I I think you talked about model stuff, robotics stuff and just open-ended like where you know what what is what is in the future for you guys very near term. We've now started to work with some of the frontier companies in each of the categories that are taking off and we'll we'll continue that work to make sure that we cover all of the use cases that are really taking off.
1:20:04 · We see a lot of interest once the first one in the market moves. lots of people want to follow them and we think basically a1 will get to a point where all of the fortune 1000 will organize their risk processes around the standard and you have 50%.
1:20:22 · No, we do not have 50% today. Uh I think there's some world where probably by end of year we might have representation in our consortium for 50% of the fortune.
1:20:32 · So that's on the agent layer and then we think yeah the model layer it's going to be it just brings are now surfacing the concerns that are most likely to slow down adoption of AI and then yeah we think robotics comes after that. Um what are you hiring for what's hard to hire for? We are hiring across the board across go to market and members of tech staff. The people who do really well on our technical team are folks who are really excited about kind of being truly full stack. So let's say when we started working with cursor uh we had never done coding uh tools before.
AIUC’s Roadmap, AGI, and Who Watches the Watchdogs?
1:21:05 · So taking the standard and extending it, fleshing out what does frontier elast look like for long horizon coding agents and taking that problem all the way from like working with cursor and other folks in the space down to like fleshing out and shipping a new version of the standard.
1:21:21 · Uh so that's like a truly a full stack entrepreneur entrepreneurship technical people do extremely well at a hard part is building one universal red teamer that works across from Harvey to cursor and everywhere in between that has one consistent methodology one consistent tonomy of what are the risks and the attacks uh and making we think that's fundamentally the best way to make consistent promises. Jim Morgan is buying both. They want to have one framework, one consistent way that this comes out and the mechanics of making that happen.
1:21:53 · You get to deal with a lot of the complexity of the real world. I think we have good answers in a bunch of that, but there's some pretty hard engineering problems in Finex and CQing.
1:22:01 · Can I push a little bit like must you have one? Why not just be like okay look 40% of our use cases are coding agents so we will specialize in coding agents and that's the that's the one of them and then 30% is like rag.
1:22:14 · Yes.
1:22:14 · Just do rag.
1:22:15 · Yes. Uh I think there's some wisdom in that question.
1:22:19 · Yeah.
1:22:20 · Um it depends on what we found that there's a lot of value on is being able to if the decision maker on the buying side, let's say you're the head of risk at a bank and your biggest risk is not in coding or in customer support or whatever the top two biggest use cases, but is somewhere else. You want to still make sure that that framework has something to say about it to the burning question you have. Otherwise, you'll not earn that trust. Now it's true that a lot of the burning questions follow where there's a lot of adoption and so great so do we.
1:22:49 · So we do today do not cover every single edge but we have a framework that we can add all of these within. We have one global taxonomy of risks and attacks that keeps adapting as like every time a new incident occurs that has never been seen before. Great let's go and update the taxonomy so we bake that in. So I think we have one coherent universal approach. It doesn't mean that we spend equal amounts of time on code and in certain [clears throat] niche use case uh we we do spend time where people where people care.
1:23:21 · We think it's very valuable to have one language.
1:23:26 · Yeah.
1:23:26 · Yeah. It makes sense. Um that's that's a that's an important choice. Uh we were going to end actually but I thought of one final ending closing question which is take this however you want right. Um let's say one and a half years from now openai secret panel of five experts declares that we have reached AGI.
1:23:42 · Mhm. Do you expect your business to change?
1:23:46 · No. I think there's some important way I think the the last businesses to exist beyond the labs will be underwriting. [laughter] Well, there's one there's one job that the labs can never do for themselves which is to be their own watchdog.
1:24:02 · There you go. So I I think kind of to the extent you believe this frame of like you'll see hyper concentration like the labs will kill all the startups which uh we can go into the pros and cons.
1:24:15 · I feel like the labs actually care a lot about this right there was the whole superp position what do we do and we have models smarter than us tier above right models smarter than them training them. So the labs actually think about this a lot they they think a lot about I think there are some of the smartest people on these topics work at the labs. So the problem is not whether they care. Uh the problem is that they will all be stuck in a race where they might have incentive to cut corners and they might have incentive to withhold information from the government etc.
1:24:41 · And so one kind of feels like eternal truth is that you need an independent third party to go and inspect that data and share information in this case say with the government is more of an incentive problem than an interest problem. I think they're fundamentally all trying to make this go well. What I'm not hearing is like AGI whatever that label means to you to me to to them uh doesn't
1:25:03 · fundamentally have like a qualitative shift in like you still have to and I think the one thing that would make this a qualitative shift is uh there for some definitions of AGI it will just get nationalized it'll be a threat to sovereignty yes and at that point kind of maybe every company is the government the government is every company I struggle to think about that world but at that point you've kind of we I don't think we'll fast enough, right?
1:25:27 · You know, like we're not we're not set to to do that.
1:25:30 · Yeah.
1:25:31 · But I I have discussed this a lot on the podcast.
1:25:34 · Yeah. Yeah. [laughter] Yeah. Yeah.
1:25:35 · I mean, you know, as far as the the watchdog concerned, uh I will also mention that because I have my finance background, I often think about the scene in the big short where they talk to like Moody's but also standard and pores and then the lady at Moody's is like, "Well, if I don't give you AAA rating, you're just going to go down to standard and pors." So, so actually the watchdog is a natural monopoly because if you have race dynamics in watchd dogs then the watchdogs will compete each other to the lowest possible standard.
1:26:01 · Correct. [laughter] Uh and so I think what's one of the things one of the reasons why we're very excited about having insurers be around this table is that insurers are the only ones that do not have this generate because they pay the bill. because they keep lowering the prices.
1:26:15 · Yeah.
1:26:15 · You you will find the market clearing and this is not true for movies where uh they don't directly pay the bill if they make recommendations that that are off. Uh so we think that balancing factor is is pretty important and I think it also highlights that there's like no system that's perfect. You need scrutiny of moodies. You need scrutinies of the watchd dogs. Uh for sure.
1:26:35 · Beautiful. Thank you so much for indulging this is a beautiful conversation covering everything. Congrats on your success so far.
1:26:42 · Thanks for having me. Yeah, appreciate it.
1:26:47 · [music]