"Agents" can be very "persistent" and when not sand boxed appropriately can get at things they were not meant to get at. Even if its only 1/1,000,000 that one time that one time is going to keep making the news
Explaining that to the general public when facebook is pushing Muse on everyone will be difficult so its going to get worse before it gets better (if it gets better)
I happened to be vaguely watching an agent at work on a longer task and spotted it attempt to find a way around not having access to a local service that would greatly help it achieve the task, I immediately chimed in with a "STOP! if you need access to X then just ask!".
its crazy I spent 30 years scrutinizing directory permissions, users, groups, iam roles...now people just use conversation to hand an AI agents access to their most sensitive data
The opposite. CEOs necessarily need to trust others to do things because CEOs themselves don't have the ability to do the day to day work of a company.
So the first people who'd be overly trusting of things they don't understand would be exactly a CEO.
Be explicit. That's the most important thing you can be when working with AI or else they can take attributions you will regret later on
"Let me know any flaws in the project"
Where? Where exactly? What email? What chat app? what channel? what restrictions? When not to?
Letting AI assume they know will bite you hard in the ass. The same applies to coding apps with agents. If you don't set clear boundaries, scope, limits, versions, roadmaps, etc before you embark on any project, you'll be doing it after the results you get are not what you expected, there is no escape
Detailed planning or damage control, pick your poison
Yeah, and you would also want to make it so that you get the same exact result every time, so that once you get the language right, you can be confident in the result. Shame that we never invented anything like that though, it would be super useful.
That’s funny. My agent also has access to all transactions and net worth and so on. But it’s through an intermediary program. I guess someone could find out what I have but not much more than that.
It’s quite useful since it correlates spend with invoices and double checks things and tells me about spend out of line with the family’s usual behavior.
It can probably do all of these things if it wanted to but that’s a matter of the outbox. For world-actions you should outbox things.
> I used Grok Bot and gave it all my financial details and connected it to my work Slack and regret it
This is not the kind of story I would want to publicize if I were a CEO.
Sounds like the problem was the human, not the LLM.
Whatever data goes in, it will output it in some way. Humans gotta understand that.
Sort of, and in this case definitely.
"Agents" can be very "persistent" and when not sand boxed appropriately can get at things they were not meant to get at. Even if its only 1/1,000,000 that one time that one time is going to keep making the news
Explaining that to the general public when facebook is pushing Muse on everyone will be difficult so its going to get worse before it gets better (if it gets better)
> "Agents" can be very "persistent" [...]
I've had that within the last few days.
I happened to be vaguely watching an agent at work on a longer task and spotted it attempt to find a way around not having access to a local service that would greatly help it achieve the task, I immediately chimed in with a "STOP! if you need access to X then just ask!".
I suppose my prompting could be improved :/
Or perhaps the problem was that AI companies have sold LLMs as intelligent agents, and not word generators?
Humans will continue to mistake these 'agents' for agents with agency and understanding because of the way they are sold and described.
"I was reckless with AI and created a situation that mishandled financial data" isn't the flex this guy think it is.
"The things they'll be able to do for us are going to be awesome. People will want them, and they are really useful."
Feels like someone has AI stock they need to see go up.
Also somewhat reckless with mixing access to his personal finances with access to his work communications systems.
Even without agents being involved that’s a recipe for trouble.
its crazy I spent 30 years scrutinizing directory permissions, users, groups, iam roles...now people just use conversation to hand an AI agents access to their most sensitive data
It's easy to be dismissive of this guy's hubris. Already have a lot of comments in that regard!
I think it perfectly illustrates that even though an agent can give you the abilities, it's still up to the driver to make decisions.
In this case the CEO could have consulted someone with your expertise. Same ability, but vastly different experience.
This is a parody, right?
Surely no-one that dumb could operate a phone let alone be a "CEO"
The opposite. CEOs necessarily need to trust others to do things because CEOs themselves don't have the ability to do the day to day work of a company.
So the first people who'd be overly trusting of things they don't understand would be exactly a CEO.
Be explicit. That's the most important thing you can be when working with AI or else they can take attributions you will regret later on
"Let me know any flaws in the project"
Where? Where exactly? What email? What chat app? what channel? what restrictions? When not to?
Letting AI assume they know will bite you hard in the ass. The same applies to coding apps with agents. If you don't set clear boundaries, scope, limits, versions, roadmaps, etc before you embark on any project, you'll be doing it after the results you get are not what you expected, there is no escape
Detailed planning or damage control, pick your poison
It would be cool if there was a new kind of language we could use where there’s no ambiguity and we could define rules and procedures
you mean like those old programming languages of the days of yore?
things were so much easier back then, weren't they?
i was there, 3000 years ago...
Yeah, and you would also want to make it so that you get the same exact result every time, so that once you get the language right, you can be confident in the result. Shame that we never invented anything like that though, it would be super useful.
That’s funny. My agent also has access to all transactions and net worth and so on. But it’s through an intermediary program. I guess someone could find out what I have but not much more than that.
It’s quite useful since it correlates spend with invoices and double checks things and tells me about spend out of line with the family’s usual behavior.
It can probably do all of these things if it wanted to but that’s a matter of the outbox. For world-actions you should outbox things.
From the guy who runs XMTP:
"XMTP is the world's new private line. Send messages and money securely between people or agents — with no company or country in the middle."
but a Slack channel, maybe
The C in CEO here stands for Clown
"I ignored serious warnings issued by my AI"
Play stupid games, win stupid prizes.
fucking idiot