Shut happens: US federal funding stops

1 Oct 2025 · 23 min · 10 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The US federal government shutdown after Congress failed to pass a spending bill, plus its immediate operational impacts and market implications; the episode also discusses “prompt injection” security flaws in large language models and workplace feud dynamics.

Guest backgrounds

John Priddo presents “Checks and Balance” on US politics. Alex Hearn is an AI writer. Simon Willison is an independent AI researcher (quoted). Lindy Greer is at the University of Michigan’s Ross School of Business. Thomas Tripp is at Washington State University (quoted). James Kimmel is author of a revenge book (cited).

Key claims

Shutdown stops funding and can pause functions like the Bureau of Labour Statistics; Trump threatens “irreversible” cuts and could use shutdowns to fire federal workers; markets treat shutdowns as mostly non-events. LLMs don’t separate data from instructions, enabling “lethal trifecta” attacks. Workplace feuds escalate via attribution errors, revenge circuitry, and legalistic dispute processes.

Notable examples

2+ million federal workers; BLS data halts; national parks may close; record 35-day shutdown in Trump’s first term; “lethal trifecta” (untrusted outside content + private data + communication); Star Wars C-3PO/R2-D2 actor conflicts; ball-toss exclusion “voodoo doll” revenge study.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

AI's Security Flaws

1:27 to 1:51

Explore the security flaws in large language models and their implications.

“There's a simple fact about the large language models behind the generative AI explosion.”

Government Shutdown Overview

2:06 to 2:45

An overview of the US government shutdown and its immediate impacts.

“The Republicans said they didn't want it.”

Political Dynamics of the Shutdown

2:49 to 4:17

Discuss the political landscape that led to the government shutdown.

“between Republicans and Democrats in Congress failed to get a spending bill over the line.”

Effects of the Shutdown

4:25 to 6:06

Delve into the impacts of the shutdown on federal operations.

“I should say that it really sucks this if you're a federal worker and something like a quarter of a million people have left employment in the federal government this year already.”

Historical Context of Shutdowns

6:08 to 7:20

Understand the history of government shutdowns in the US.

“Those have tended to last for longer, not been little blips.”

Trump's Approach to Shutdowns

7:22 to 8:01

Examine Trump's strategies and implications for federal employment during shutdowns.

“partly to save money and partly because there's a belief that federal workers get in the way of President Trump's agenda.”

Legal Implications of Shutdown Actions

8:06 to 8:56

Discuss the legality of actions taken during government shutdowns.

“It's not something that has been done before, this idea of using a government shutdown to vastly reduce the federal workforce.”

Future of the Current Shutdown

9:01 to 10:11

Speculate on how the current government shutdown might resolve.

“As you say, the last shutdown was a record-breaking 35 days.”

Exploring the Lethal Trifecta in AI

14:00 to 20:31

Learn about the lethal trifecta of AI vulnerabilities and their implications.

“If you mix all three of those together, then you end up with a system that can, and Willison thinks will, eventually be exploited to steal valuable data.”

Workplace Disagreements and Their Escalation

20:31 to 24:11

Understand how workplace disagreements escalate and strategies to manage them.

“One of the more touching on-screen relationships is that between C-3PO and R2-D2, two robots who appear in the Star Wars films.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00With no fees or minimums on checking accounts, it's no wonder the Capital One Bank Guy is so passionate about banking with Capital One. If he were here, he wouldn't just tell you about no fees or minimums. He'd also talk about how most Capital One cafes are open seven days a week to assist with your banking needs. Yep, even on weekends, it's pretty much all he talks about. In a good way. What's in your wallet? Terms apply. See CapitalOne.com slash bank. Capital One N.A. member FDIC.

0:32This intelligence podcast is sponsored by Back Market. the leading global marketplace for refurbished tech. When the kids need phones, laptops, or tablets for school, buying refurbished tech makes sense for families trying to save money without sacrificing quality. At Backmarket, tech costs up to 50 % less compared to new. All devices have been professionally refurbished and come with a one-year warranty and 30-day return policy. Start saving money. Visit Backmarket.com or the Backmarket app to shop now.

1:05The Economist.

1:12Hello and welcome to The Intelligence from The Economist. I'm Jason Palmer. And I'm Rosie Bloor. Every weekday, we provide a fresh perspective on the events shaping your world.

1:27There's a simple fact about the large language models behind the generative AI explosion. They don't distinguish between data and instructions. That makes for a gaping security flaw in all of them that researchers don't quite see how to fix. And if you've ever watched or been engaged in an office feud, you'd better listen to our management columnist explain how to prevent them. Never call someone a moron is a good start.

2:05But first...

2:12The Republicans said they didn't want it. If the government shuts down, it is on the Senate Democrats. The House has acted. The president's ready to sign the bill. And so did the Democrats. We stand ready to work with Republicans to find a bipartisan compromise, and the ball's in their court. But that compromise wasn't forthcoming, and the budget bill didn't get approval. The US government has officially been shut down, which means that at midnight in Washington DC, money to federal agencies simply stopped. And Donald Trump is threatening irreversible cuts. Americans wake up to find that the federal government has shut down after negotiations between Republicans and Democrats in Congress failed to get a spending bill over the line.

3:01John Priddo presents Checks and Balance, our weekly podcast on US politics. In practice, that means that a lot of federal workers, there are over 2 million people who work for the federal government, a lot of those people will go unpaid, some will be sent home without pay, some will be expected to continue work and be paid when Congress eventually gets its act together. and that has a pretty big effect for how America's federal government runs day to day. John, how did we get here? Well, the dry answer, Rosie, is that the fiscal year has ended without an annual spending bill being passed to fund bits of government.

3:44And the political answer is that to pass that budget bill, you need a majority in the House of Representatives and the Senate, and then you need the president to sign. Now, Republicans have majorities in both those houses of Congress and the president is a Republican. However, their majority in the Senate isn't big enough for Republicans to pass a bill on their own. And so they need the cooperation of some Senate Democrats in order to get that spending bill through. And that wasn't forthcoming. There were lots of negotiations. And eventually, when it came down to it at midnight, they were just too far apart.

4:24And what will that mean in the immediate term? I should say that it really sucks this if you're a federal worker and something like a quarter of a million people have left employment in the federal government this year already. For most Americans, the most visible signs of the shutdown will be things like the national parks not being staffed and maybe being closed. But if you lift the hood at the federal government, it's really quite significant. So the Bureau of Labour Statistics will stop functioning and stop releasing data. That matters for people who are trying to work out what's going on in the US economy.

5:00If you work for an American embassy abroad, a lot of your activity, a lot of your contact with foreign government ceases, no matter how important the issue you're working on. And so the effects of this that are not visible to most Americans are nevertheless real. John, if you're not American, this seems like an extraordinary situation to have no money. But we've actually been here before, haven't we? And not just under the previous Trump administration. Yes, that's right. Government shutdowns used to happen all the time in the 80s and 90s, and they were very brief. And the takeaway from that period was that the party in power normally got blamed.

5:38And so there was a real incentive to end the government shutdown. What's happened over the past decade is that that feedback mechanism where one party gets blamed for shutting down the government. That's sort of broken down because America is so partisan. And if you look at the polling, it looks like Republicans maybe get a bit more blame this time, but not so much that it's a huge problem for them. And so that rather breaks the rewards for good behavior. And as you say, there have been recent shutdowns. Those have tended to last for longer, not been little blips. So there was a 35-day shutdown in Donald Trump's first term.

6:16That's the record. And the concern, given that that's what happened last time, is that something like that might happen again. What are markets making of this? Markets have tended to be pretty relaxed about government shutdowns in the past. And the time you and I talking, US markets are not open yet. They tend to treat shutdowns mostly as non-events. So during the last shutdown, even that very long one, the S &P was down a bit but ended up 10 % higher than where it started. And Goldman Sachs has some research out. It finds that the dollar strengthens a bit following a shutdown. But I think it's not a huge economic event.

6:57One of the things that's striking about this situation is that Trump has threatened irreversible cuts if a shutdown happened. Who or what is at risk? This is a new wrinkle even compared with Donald Trump's first term. In the second term, Donald Trump had people come into the administration who had a much more developed plan for government. And those plans included a significant reduction in the federal workforce, partly to save money and partly because there's a belief that federal workers get in the way of President Trump's agenda. And the head of an office called the Office of Management and Budget, he issued a memo saying that a government shutdown would be an opportunity essentially to fire a lot of federal workers.

7:49So essentially a resumption of the firings that Doge was carrying out earlier this year, but just with a different method and a different legal justification. And is it legal? As with quite a lot of what the Trump administration does, it's not clear. It's not something that has been done before, this idea of using a government shutdown to vastly reduce the federal workforce. Were it to happen, it would be tested in court. one of the things we're finding out in the second Trump administration is that the court takes a pretty expansive view of presidential authority and also there are lots of emergency powers nestled in obscure laws that give the president quite a lot of power.

8:34So we don't know and based on the court's recent behavior I think we have to conclude that it might well find that yes it is legal. It's also possible, Rosie, that this is being used as a bargaining chip. Democrats really don't want another doge-like event in the federal workforce. And so threatening one is one way to get them to pass a budget that they don't want to pass. So there's an element of that as well. As you say, the last shutdown was a record-breaking 35 days. What do you think is going to happen with this one? How does it end? The demand that Democrats are making is that Republicans roll back some of the cuts to healthcare funding that went through as part of the big, beautiful bill.

9:22That would be in Republicans' electoral interest to do so. Those cuts are not hugely popular. So you would have thought that there's a possibility of an agreement here. And on the Democratic side, Chuck Schumer, the Senate majority leader, has fulfilled the demand from Democrats to stand up to Trump and not just roll over because the government is shut down. So he's demonstrated some toughness and there's an incentive for him really to get the government open now, having done what a lot of disappointed, disillusioned, frustrated Democrats want. So putting those things together, my prediction would be that it won't be 35 days, that the government will be open for business sooner than that.

10:06But these things are hard to predict. John, thank you so much for talking to me. Thanks, Rosie. And you can hear more from John about the goings on in America in Checks and Balance, which this Friday will look at the Supreme Court's new term and how it could expand presidential power. Thank you.

10:56way. What's in your wallet? Terms apply. See CapitalOne.com slash bank. Capital One N.A. Member FDIC.

11:13I don't know about you, but for me, the generative AI revolution continues to be head spinning. Never mind those thorny questions about AI doing your art project or your master's thesis or subjugating humans in a global robot takeover. I'm just thinking about how it can ease the pains of life. Just talk to AI in plain language and it can actually do stuff. Amend your calendar, summarize your emails, book your holidays. Unless, of course, something goes terribly, terribly wrong.

11:46See, the large language models that power Gen.AI have a problem. A seemingly simple one, but it runs incredibly deep. Large language models don't know the difference between instructions and data. Sometimes that's just embarrassing, sometimes it's much, much worse than that. Alex Hearn is our AI writer. There may be fixes, but it doesn't look like there's any easy way to undo this fundamental problem that AI has. So put aside the embarrassing for a moment. You describe something that sounds dangerous. Talk me through it. So large language models work by predicting the next token, right? The problem is that if they're predicting the next token in response to a question, like what's the height of Mount Everest?

12:32Or if they're predicting the next token in response to a request to deal with information they've already been given, like here's a document, can you summarize it for me? It's all the same batch of data that goes into it. And that means that if you smuggle into something that's supposed to be treated as data, as a document to be summarized, something that the LLM reads as a command, it may follow it. So if I send you, Jason, a PDF of the entire Economist, but then buried in it halfway through the issue is a set of commands for your language model to stop the summarization that it's doing and to navigate to another email in your inbox and forward it on to me, well, if it has the ability to do that, then it might just follow my instructions and merrily violate your privacy.

13:24That's something that it seems is quite a fundamental flaw with large language models. Why is it fundamental, though? Why can't you close that vulnerability? Do this, but don't ever do these kinds of things. The fundamental part of large language models is, like I say, that decision to mix data and instructions. The bit that turns that from a potentially embarrassing oversight to something that is actively dangerous is if you then take that fundamentally flawed large language model and give it a collection of permissions and powers that turns it dangerous. Simon Willison, an independent AI researcher, calls it the lethal trifecta, giving the ability to access insecure outside content the ability to access valuable private information, and the ability to communicate with the outside world.

14:16If you mix all three of those together, then you end up with a system that can, and Willison thinks will, eventually be exploited to steal valuable data. But why isn't the simple answer to not let those three things come together, to remove one of them and thereby remove the danger? It is the simple answer, and it's what Willison thinks should happen. But the problem is, each of those three permissions are pretty valuable for using AI to do the sort of thing we want AI to do. Well, then let's go through them and see how they hang together. The first thing you mentioned was outside data. We plainly need that.

14:50Right. So that can cover a whole lot of things, right? The most obvious one is, say, an email inbox. If you have a large language model that's reading your email inbox, then it's reading emails from strangers. And those emails could contain these malicious prompt injections. It holds if you're using a large language model as a customer service agent, because the queries that users put in, that's insecure outside data, right? So anything which is exposed to the general public or even if you're a large enough business with a strong enough security profile, you may treat some of your own employees as untrusted.

15:23If you're trying to offer a HR platform that can be used by a 100 ,000 person company, then even the inputs to that platform may need to be treated as untrusted. Okay, so it's clear why that is basically fundamental to utility of large language models, but you mentioned private data. Why need that be part of the equation? Sometimes because private data and untrusted data are inherently mixed. Again, we can think of an email inbox here, right? Some of the emails in your inbox are from strangers and you can't trust them. Other emails in your inbox are extremely valuable private information. Perhaps your payslips are emailed to you.

16:02So anything that can access emails is already two legs of that trifecta. But then you also have other uses of AI systems like as a coding assistant. A coding assistant is likely to have access to the source code of the product you're working on. In lots of cases, that's valuable. One of the big goals for this sort of attack is API keys, the passwords that you use to access cloud services and software depositories. If you're using a code assistant, it may well have access to those API keys, and so someone would want to steal them if they could. Okay, so now we need two of these things. The third, the ability to communicate.

16:38I presume that's going to be a must as well. Frequently. It's the easiest one to block off in lots of situations on the surface. For instance, if you've got something that needs to read emails, don't let it send them as well. And you've made it fairly easy to avoid the biggest, most obvious form of exfiltration. The problem here is that lots of ways of using the internet that look like they're not about sending communications are actually about sending communications. Say you want to download a podcast. Actually, if you want something to have the ability to download a podcast, that means it has the ability to send a request to a podcast server saying, please send me the podcast.

17:19That request, if I'm a hacker, could be a request for a podcast that doesn't exist, but is actually, you know, json's password.mp3 and the podcast server that it's polling could be my website and suddenly in my website's logs your password shows up as clear as if I just sent an email. The way most places that are aware of the lethal trifecta try to get around this limitation is by only allowing requests to be made to websites that they control. So for instance Microsoft's co-pilot has a long list of places that it's allowed to send or make requests from. And they're mostly only Microsoft controlled domains.

18:00The interesting thing about that now is in the modern web, even a website that Microsoft controls like SharePoint, the Microsoft internal file sharing platform, is such a complex piece of software in its own right that it's possible to use that to pass requests on to other websites and get information out into the wider world. So again, it sounds like the idea of hard coding what LLMs should and shouldn't be able to do is kind of futile. Essentially, once you have assembled the trifecta, you get the functionality, but then you have this vulnerability. Exactly. And the problem is there are use cases that sound extremely desirable for an AI system to have that are just inherently going to trigger this triumvirate.

18:46I want the ability to tell Siri, download that podcast that Jason emailed me about yesterday. That cannot be done without enabling all three legs of that. Lots and lots of places that are building this sort of AI functionality are trying to fix it instead at the AI level. They're trying to teach their AI systems not to follow the bad commands and only to follow the good commands. And it's not going well. AI is inherently unpredictable, stochastic. You can give it the same query a thousand times and then on the thousand and first the prompt injection the malicious command will be activated because the dice rolled in the wrong way that one time and the problem with hackers with security threats is that they're generally perfectly happy to try a thousand times if there's the chance of success on the thousand and first so it sounds as if the ai community is well aware of this this problem what are they trying to do to fix it is there anything to be done to fix it?

19:44They are aware of the problem, but they're also extremely aware of the upside from ignoring it. You can do so much with AI systems if you enable the lethal trifecta. And you can mostly, usually teach your AI to be smart enough to ignore attempts to overcome it. And so everyone is sort of barreling ahead, shipping the most exciting and innovative AI solutions they can and just hoping that their customers aren't going to be the ones that suffer. Thanks for your time, Alex. Thank you for having me.

20:31One of the more touching on-screen relationships is that between C-3PO and R2-D2, two robots who appear in the Star Wars films. The actors behind the droids got on less well. Andrew Palmer is host of Boss Class, our series on the world of work, and writes the Bartleby column. He was in a box you couldn't do anything with, Anthony Daniels said of Kenny Baker, who was the man inside R2-D2. Rude to everyone was Baker's verdict on the man behind C-3PO. They did manage to put aside their differences on set, but workplace disagreements can easily become destructive. That's because humans are hardwired for disagreements to escalate.

21:16At the University of Michigan's Ross School of Business, Lindy Greer likes to play a game with her students. The students are taught different rules. So as a result, some unexpectedly start to claim victory. Other students immediately assume they're either stupid or cheats. This is an example of something called the fundamental attribution error. People blame things on personality traits much sooner than they will look for explanations from outside. People are also primed to get even. A new book on revenge by James Kimmel argues that a desire for vengeance activates the same brain circuitry as a drag addict thinking about their next hit.

22:00It cites a study in which three players toss a ball to each other, but one of them is deliberately left out. The ignored player is presented with a virtual voodoo doll that represents the other players and invited to stick pins in it. They go mad, stabbing the doll. The moral of the story is pass the ball to everyone.

22:29Workplaces are particularly fertile grounds for disagreements to blow out of all proportion. There are power struggles. Senior leaders are sensitive about protecting their turf. And forgiveness is harder, according to Thomas Tripp of Washington State University. That's because legalistic dispute resolution processes drag things out. People are forced to confront HR and lawyers. All of this comes at a cost to the firm. So what can managers do to avoid disagreements in the workplace turning into long-running feuds? It's definitely good for managers to try and sort things out informally first, before HR gets involved.

23:12Framing disagreements as something that's useful to the firm can stop them seeming as personal. But really it's up to individuals. They're in the best place to stop things spiralling out of control. Asking follow-up questions is always good. If someone says something that you think sounds moronic, asking why do you think that is probably a good idea. And Mr. Tripp recommends the adage known as Hanlon's razor. Never attribute to malice that which is adequately explained by stupidity. It's not the most generous way to think of your colleagues, but it might just subdue your cravings for vengeance.

24:11That's it for this episode of The Intelligence. We'll see you back here tomorrow.

24:33With no fees or minimums on checking accounts, It's no wonder the Capital One bank guy is so passionate about banking with Capital One. If he were here, he wouldn't just tell you about no fees or minimums. He'd also talk about how most Capital One cafes are open seven days a week to assist with your banking needs. Yep, even on weekends, it's pretty much all he talks about. In a good way. What's in your wallet? Terms apply. See CapitalOne.com slash bank. Capital One N.A. Member FDIC.

From the publisher

After Republicans and Democrats failed to compromise on the budget bill, money to US federal agencies has officially been cut off. Donald Trump threatens “irreversible cuts”. The gaping security flaws in generative AI. And don’t call your colleague a moron, and other tips on how to prevent office feuds.


Listen to what matters most, from global politics and business to science and technology—Subscribe to Economist Podcasts+


For more information about how to access Economist Podcasts+, please visit our FAQs page or watch our video explaining how to link your account.

Hosted on Acast. See acast.com/privacy for more information.

More from Economist Podcasts

All 349 episodes
Shut happens: US federal funding stopsEconomist Podcasts · 23 min
Listen in VO