In short
Explains “open-weight” AI models versus open source, why they matter for developers and governments, and how open-weight debates are tied to AI safety, the US-China race, and the OpenAI–Hugging Face hack.
Guest backgrounds
Robert Hart, Verge reporter covering US AI, OpenAI, and Hugging Face; long-time VergeCast listener, first-time guest.
Key claims
Open-weight models are “open” only in downloadable weights (not full open-source reconstruction). They’re more flexible (run yourself, tweak with your data, avoid sending data to providers) but harder to monitor and to enforce safety “guardrails.” US frontier labs (OpenAI, Anthropic, Google) largely keep models closed; China more often releases open weights due to chip-access constraints, lower barriers, ecosystem growth, and soft-power advantages. Safety debate intensified by dual-use: open models can be used to hack and also to defend; closed-model guardrails can block both attackers and defenders.
Notable examples
OpenAI agent allegedly hacked Hugging Face; Hugging Face reportedly used a Chinese provider (ZAI) because US frontier safety rails blocked the needed defense. Hart cites Anthropic’s stance (Dario Amodei) against only-open models and discusses White House voluntary model review talks.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VO90 Seconds on The Verge
0:45 to 2:14
A quick update on the latest tech news from The Verge.
“But first, here's everything else happening on The Verge today.”
90 Seconds on The Verge
3:03 to 3:25
A quick update on the latest tech news from The Verge.
“It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block, or finally break down that long article you've had open for weeks.”
AI Models Discussion Introduction
3:25 to 3:57
Introduction to the discussion on AI models with Robert Hart.
“Joining me now, Verge reporter Robert Hart.”
Understanding Open Weight Models
3:57 to 6:00
Explaining the concept of open weight models and their implications.
“But I think we need to start with some fairly straightforward explainery stuff.”
Benefits of Open Weights for Developers
6:00 to 7:20
Discussion on the advantages of open weights models for developers.
“I just want to sort of quickly explain before we get into this here, which is who cares?”
Global Perspectives on Open AI Models
7:20 to 10:36
Exploring the differences between U.S. and Chinese approaches to open AI models.
“So you've kind of got a bit more of a personalized model.”
The Safety Debate Around Open Weights
10:36 to 14:00
Discussion on the safety concerns related to open weight models.
“And it is kind of almost a projection of soft power if your stuff is becoming almost the default.”
The Dual-Use Technology Debate
14:00 to 15:02
Explore the dual-use nature of AI technologies in hacking and defense.
“one of the closed models that was attacking it, which kind of flips a lot of that on its head.”
Open vs. Closed AI Models
15:02 to 17:06
Discussion on the implications of open and closed AI models and their capabilities.
“So then they're able to use an open weight model because they're able to just essentially remove those guardrails or they don't exist in the first place because it is open and adaptable in that way.”
Anthropic's Controversial Position
17:06 to 19:14
Analyzing Anthropic's stance and its implications for AI governance.
“But Daria Amadei has also published a quite lengthy blog post explaining the reasoning and says that we're not against open models, but we cannot only have open models.”
Show all 18 chapters
The Reactions to AI Hacks
19:14 to 21:30
Examining the reactions of companies to recent AI hacking incidents.
“And again, like you're free to think whoever you want to be in charge should be in charge.”
The Reactions to AI Hacks
21:47 to 23:00
Examining the reactions of companies to recent AI hacking incidents.
“Support for the show comes from Shopify.”
The Reactions to AI Hacks
23:04 to 23:36
Examining the reactions of companies to recent AI hacking incidents.
“It's the only business software you'll ever need.”
AI Safety Conversations Heating Up
23:36 to 28:04
Discussion on the urgency of AI safety and the industry's response to recent events.
“Check responses set up required compatibility and availability varies 18 plus.”
Concerns About AI Safety and Impact
28:04 to 30:26
The discussion revolves around the safety concerns and impacts of AI technologies, highlighting a mix of despondency and urgency among industry professionals.
“Yeah, no, I mean, but I think that is, I think for a lot it has, I mean, a lot of these people do care quite deeply about what they do.”
Government Review of AI Models
30:26 to 33:44
The hosts examine the implications of a potential government review process for AI models, discussing transparency and accountability in the industry.
“So yeah, I think there's a lot of kind of unease, I think is how I would describe it.”
AI Discussion and Public Sentiment
33:44 to 36:22
The conversation shifts to the evolving public sentiment around AI and the challenges of maintaining focus on safety amidst other pressing discussions.
“into the the panic about the open ai hugging face thing we've been talking about this for some time Now, you and I have been at this a while.”
AI Discussion and Public Sentiment
37:30 to 38:10
The conversation shifts to the evolving public sentiment around AI and the challenges of maintaining focus on safety amidst other pressing discussions.
“Running a business is hard enough, so why make it harder with a dozen different apps that don't talk to each other?”
Transcript
Automatic transcript. May contain errors.0:02Hello and welcome to the VergeCast, the flagship podcast of Kimmy K3. I'm your friend David Pierce and today on the show we're going to talk about AI models. We've been talking about AI models a lot on the show for the last few weeks in the wake of the OpenAI hack of Hugging Face and all of these new conversations about AI safety and AI deployment and open weight models and the race with China and how we think about and operate AI in general. It all feels like it's coming to a head in some way right now. So The Verge's Robert Hart is going to come on, and he's going to explain to us what's actually going on here.
0:31There's a lot of new vocabulary with these bottles and a lot of new questions about how they work and how they're made. He's going to make sense of all of it for us. I personally am very excited to have somebody finally make sense of all of it for me. We're going to get to that in just a second. But first, here's everything else happening on The Verge today. I'm Jake Kastarnakis, and this is 90 Seconds on The Verge for August 4th, 2026. Microsoft just started bringing original Xbox games to the PC the other week, and now it's planning to bring Xbox 360 games as well. My colleague Tom Warren has the scoop on a memo that Microsoft sent around to developers, asking them to opt in to the new program.
1:06Microsoft will handle all the emulation hurdles, even customer support. All developers have to do is approve their games for sale and set a price. Microsoft's argument is, why not do it? It's free cash. The rollout is supposed to begin next year. Next up, Apple abruptly pulled Telegram from the App Store last night, before restoring it less than an hour later. Apple told various news outlets that it pulled the app due to the presence of CSAM. Then it restored the app after Telegram removed the content and banned the person who posted it. The whole incident is very odd, and it's actually the second time it's happened.
1:38Apple pulled Telegram in 2018 for the same reason, and again restored it within hours. After this latest incident, Telegram seems downright mad. Telegram spokesperson Remy Vaughn told us that Apple was wrong to pull the app down. Finally, my favorite gadget of the day, my colleague Andrew Leshevsky spotted some new camera batteries from Falcam that have built-in support for Apple's Find My Network to help you track down missing gear. I love this. This seems so much more convenient than attaching an AirTag to every camera you own. It's only available for Canon and Sony right now, but Nikon and Fuji are set to be in the works.
2:10They're a little pricey, though, at up to$70 apiece. You can read more at TheVerge.com. That's 90 seconds of The Verge for August 4th, 2026. Support for this show comes from Odoo. Running a business is hard enough, so why make it harder with a dozen different apps that don't talk to each other? Introducing Odoo. It's the only business software you'll ever need. It's an all-in-one, fully integrated platform that makes your work easier. CRM, accounting, inventory, e-commerce, and more. And the best part? Odoo replaces multiple expensive platforms for a fraction of the cost. That's why over thousands of businesses have made the switch.
2:49So why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.
3:00This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block, or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it. Ready to make anything online make sense? There's no place like Chrome. Check responses set up required, compatibility and availability varies 18+. All right, let's talk AI models. Joining me now, Verge reporter Robert Hart. Welcome to the show. First time on the Vergecast.
3:30Yeah, long time listener, first time joiner. Very happy to have you here. And I've brought you here to do maybe the wonkiest thing we have done on this show in some time. We're going to do a little bit of analysis, a little bit of explainer. But we're in a really interesting and complicated moment with AI that is about technology. It's about politics. It's about feelings. And I want to just piece through it. You've done a really good job covering this on the site. And I want to just walk through some of what's going on right now. But I think we need to start with some fairly straightforward explainery stuff.
4:02because I think a lot of very smart people are getting this stuff wrong. And I want to just talk through it a little bit. So just from a very basic level, help me understand what an open weight model is and why it matters as a concept right now. Yeah. So, I mean, to get even more annoyingly wonky, it's perhaps important to start with what it's not. And I think a lot here is caught up in a kind of open source. And that's what we know traditionally from software, where it's pretty free, it's distributed, you can change it, you can make money from it as long as you also share it freely. Now, open-weight models are not quite that open.
4:41And so wonky part number two is they are only really open on a thing called weights, which are kind of those numerical parameters, those sort of knobs and buttons that an AI has during training that kind of helps it tick, process information, all of that. And that's the only bit that's really made open here. So you can download it, You can build on that. You can use it. But it is not the same as, say, an open source where you can kind of reconstitute it from scratch. Right. Have you come up with a good metaphor for how to describe weights? It's a really messy but really important term. And I think it's really hard to visualize.
5:16Like open source, I actually think, would be very easy to understand, right? You would see all the training data. You would see how they trained it. You would see what the output looks like. You'd be able to sort of peel the thing apart and understand every piece that went into it. Like you said, open weight models are very deliberately not that. They show this one thing. And I have not come up with a great way to explain it to people who are not sort of deep in the weeds of AI technology. Have you come up with one or heard one that you like? Not really, but on the spot, I guess. I mean, I almost imagine, you know, when you kind of have a piece of wood and you run an electric current through it, and it makes that sort of forked pattern.
5:52I almost imagine the weights as the kind of resultant image that might come off in that it kind of is something that is the result of something you couldn't make it from scratch without replicating everything precisely including the wood but also the electric the even the weather but it's still quite useful in terms of you can sort of see the paths you can trace it and it's not a perfect um one by any means but it's kind of a i think an idea of kind of what yeah what what weights might be in this sense and that it's the product of something but it's can still be really useful if you can like build or modify or change.
6:28I like that. Like you couldn't, you couldn't make it yourself without knowing exactly what went into it, but even just knowing what it looks like, you can now go and redraw the thing, which ends up being really important, which brings me to the next thing. I just want to sort of quickly explain before we get into this here, which is who cares? What, what can I do if I'm a developer or a government or somebody paying for one of these models with an open weights model that I can't do with a closed weights model like we've seen from Anthropic and OpenAI? What is the actual sort of user advantage of an open weights model?
7:04Quite a lot, really. I mean, it's a lot more flexible. You have a lot more freedom to do largely whatever you want with it. You're not reliant on sending them your data, which is a big thing for a lot of different companies. You could, And presuming you have the infrastructure, you could run it yourself. You can tweak it with your own data. So you've kind of got a bit more of a personalized model. And I think important for a lot of the debates we're seeing now as well is that they're a lot less monitorable and it's a lot harder for providers, say Anthropic, OpenAI in these cases, to put in the safety rails that might stop it from doing something that you would want it to do.
7:43Okay. So maybe in that sense, the comparison to open source actually is useful in that it doesn't function the same way, but your ability to take it and modify it and use it in your own server array, that is very much the same as if it were pure open source software. You don't get to understand the inner workings of the model in the same way, but you get to use it and adapt it in much the same way. Is that a reasonably close comparison there? Yeah, I mean, there are a lot more restrictions that they might put on it. So some of the ones that are coming out now, they'll have licenses that you have to pay them over a certain threshold.
8:21But yeah, it's a lot more flexible in that way. This is probably an overgeneralization, and I want you to correct the extent to which this is an overgeneralization, but it seems like China has embraced the idea of open-it and wait models in a big way, and the U.S., particularly the sort of frontier labs that we talk about all the time, Anthropic, OpenAI, Google, have not. A, is that a fair characterization, and B, why do you think it's broken down like that? To again get annoyingly wonky, it is a bit more complicated than that. But by and large, it is a reasonable characterization. The most prominent US models, as you said, Google, OpenAI, Anthropic, their frontier models are all proprietary, they're all closed systems.
9:01And in China, by and large, a lot of them are open weight. There are exceptions, obviously. So Alibaba in China, for example, until its most recent release, a few earlier this year in its frontier scale were proprietary. It kept them closed and it evidently changed its mind this week. And in the US, there is still a big ecosystem of open weight players. I mean, And Meta is the most obvious that comes to mind. Who've been making strides recently, but also Google. I mean, it's not the top tier Gemini ones, but their general models are quite popular. And there's sort of a huge spectrum in between that.
9:42If you grant me the huge generalization, because I think at some point at the absolute frontier, I think that the debate we're having right now is between, you know, companies like Moonshot and like you said, Alibaba in China and the three major labs here in the U.S. Is it purely sort of a political difference that is why China would want its models to be open and the U.S. would want them to be closed? Are we talking about like communism versus capitalism here? Like what do you make of the sort of philosophical difference between those things? I wouldn't go as far to say it is quite a deeply entrenched divide like that, but I think it is quite tempting to see it like that.
10:21I think partly it is business pragmatism in China. It is a way, with all the restrictions that have been put on them by the US, so they've not had access to the top-tier chips, for example, it is harder for them to innovate at the frontier. this is potentially a way of them doing so or of at least kind of working towards that but also from a business strategy point of view there's a huge sort of array of advantages with going open i mean it's cheaper by and large for developers to run it's a much lower barrier to entry there are also the elements we said with privacy or kind of running things on your own system them, you can really grow that ecosystem rapidly.
11:04And it is kind of almost a projection of soft power if your stuff is becoming almost the default. And the Chinese models are being very widely used globally. American companies, Western companies would be very hesitant to send all of their data to China or to servers hosted in China. If it's open, you can get around that. And so it's also quite a nice gateway for them to stay active in these markets. Yeah, that makes sense. So all of this has been sort of burbling in the background for a long time and has really come to the forefront of the whole AI discussion over the last couple of weeks. And it's happening right next to, I think we've talked about a bunch on this show, the OpenAI Hugging Face hack.
11:50Now Anthropic is coming out saying, oh, look, we just noticed we've also been hacking everybody. There is a real AI safety thing happening right now, and open weight models have become a big part of this discussion, kind of on both sides in a strange way. Everybody has feelings about open weight models, no matter how they feel about AI safety. um why has open weight become sort of a core part of the how do we make sure we're doing ai safely discussion there are so many things this could be about but it feels like the industry has decided that the debate we're going to have right now is about open weights why yeah well i mean one and i'll gloss over this just due to the complexity but there is the whole uh specter of the race with China in the States or the West in general, which means something a bit different to quite literally anyone who mutters it.
12:45But that's - We have to beat China at everything. It's just a fact of life in America right now for reasons I continue to largely not understand. But yeah, granting that premise, what else is going on here? Yeah. So there's that, which obviously, yeah, is one reason. So the open-weight models they're releasing, let's go. But then the safety part as well. So the main opposition, or one of the oppositions to the open models is that it's very difficult to both monitor how they're used, which OpenAnanthropic, they know how this is being used. It's hard to implement details like guardrails to stop it by hacking or helping you build a bioweapon, the two kind of main concerns that the frontier labs say.
13:29The fear has always been that releasing something very capable openly puts that in the hands of anyone. Okay. The weird part of this then is OpenAI, it turned out one of its agents hacked HuggingFace, as we know. The difficulty with closed models is these safety rails as well. HuggingFace said in their report, oh, well, we couldn't actually use US frontier models. These safety rails activated. And then they said they turned to one of the leading Chinese providers, ZAI, for their model to help defend itself against one of the closed models that was attacking it, which kind of flips a lot of that on its head.
14:06And so this debate has now really become, I mean, it is by definition a dual-use technology. It can be used to hack, it can also be used to defend against hackers. And so that's kind of been at the core of this now, is that for a long time, the fear has been it would be used as a weapon. and funnily enough, the most high-profile case recently is it's been used as a tool of defending. Wait, so hold on. So let me make sure I understand what happened here because I actually think that's really interesting. I hadn't quite thought about it that way. So OpenAI, closed model, very, very deliberately hard for anyone else to understand, attacks Hugging Face.
14:43Hugging Face says, we need a tool to stop this. We're going to deploy our agents to stop this agent. runs into some safety restriction in the model that they're trying to use, another closed model that is like, no, I won't escape this sandbox and go try to fight this thing. So then they're able to use an open weight model because they're able to just essentially remove those guardrails or they don't exist in the first place because it is open and adaptable in that way. Am I understanding that right? Yeah, in a very kind of, yeah, in a broad sense. What a weird system. Yeah. And so that's, I think, why it has been so, as an issue, it has so rapidly bubbled to the surface.
15:29Something that's been simmering for a long time is because all of these tensions that were there suddenly became very real and very tangible in a way that ties together, as I said, all those fears with China, but also open versus closed. And then also the risks of these closed models of what they are actually capable of doing. This strikes me as the sort of thing people are going to pretty quickly get like borderline religious views about that are going to be very hard to change. Because what you just described is two completely reasonable and totally mutually exclusive theories, right? That one says this technology is too powerful.
16:09We can't put it in the hands of everybody or the bad people will use it and things will go horribly wrong. and we're going to be stuck in this arms race cat and mouse game for forever. The other side says, actually, that's already happening. And the only way to stop it is to put this technology in the hands of everybody. There is no single overlap anywhere between those two things. And it feels like as these models get better and more capable, both sides are going to feel more right about their stance on these things. Like, is there a way to reconcile in the middle of this fight? Wow. Well, I think we'll see.
16:44But I think we have to. I mean, I think even the opponents have kind of, I mean, the one big one that has been to watch has been a lot of these kind of open letters you've seen from like the US tech industry, for example. The notable holdouts, at least at the start, were the big three were Google, OpenAI, Anthropic. To my knowledge, it's only Anthropic that's a continued holdout on that. I might be wrong. They might have signed since. But Daria Amadei has also published a quite lengthy blog post explaining the reasoning and says that we're not against open models, but we cannot only have open models.
17:19And I think that's probably an area that we will end up in, I think. And it's also not to say, I think a lot of this is focused on, like I said, it was more complicated with there are open models in the US. China could also very easily close off some of its frontier models. And I think probably as they get more and more advanced and as sort of that ecosystem develops, I think there'll probably be a mix. Yeah, because you have more economic incentive to close your models, right? You can make more, if you can say and demonstrate our model is the best, which I think Anthropic relatively successfully has been able to do over and over for the last year or so.
18:03every possible upside you want comes from closing off that model right you can make it more expensive you can limit who gets to access it you get to be the the arbiter of good and bad in that model like if you are the best there are lots of good reasons to be closed that almost no one other than the very best model seems to have and this is where we get wrapped up again in the everything is a race against China, if in fact, you know, Kimi is now a better model, like demonstrably better model, and all of a sudden everybody wants it. Suddenly you flip from China wants to have openness and to sort of infiltrate the US and make a lot of headway into businesses and start to capture some of these use cases that people can't afford from the greatest models.
18:45All of a sudden you say, well, we have the best model, we're going to close it off and make a ton of money from it. That does feel very possible to me at this moment. Yeah, I mean, it feels largely what's been happening already is the kind of end of that. I mean, and also there is a safety element. I mean, Anthropic was explicitly founded, basically. It was unhappy with what OpenAI were doing. And I think the argument against Anthropic in many ways at this point is that Anthropic believes that it is the only one who should be trusted, right? Like this is what the government has been saying about Anthropic for some time in the US is that this stance that Dario Amadei is the only one who gets to decide what we do with AI and what we don't do with AI is ridiculous.
19:25And again, like you're free to think whoever you want to be in charge should be in charge. But at some point, either no one is in charge and we just like let chaos reign because that is the thing that will solve this or someone has to be in charge. And I feel like Anthropic has been the one most loudly being like, it's fine. The answer is us. We've got it. And that makes a lot of people really angry. Yeah, absolutely. I think their response to the hugging face incident is actually quite telling. To me, it felt quite petty. That's maybe a controversial view, but it's like, hey, our models can hack things too.
20:02And then you look at the details of it. Their blog detailing this, it quite literally ends in a four bullet point list as to why what happened with them was better than what happened with OpenAI, which, cool. I mean, we're all adults here. Great. It just felt very juvenile, especially when, I mean, OpenAI, it hacked its way out. To me, Anthropics was the important, they kind of left the door open. Like they're saying we're the good guys and their behavior doesn't seem to meet that bar time and again. But they're also, though, I should say, them and OpenA are doing more than a lot of other actors in this field as well.
20:44It just doesn't necessarily meet the expectations they set for themselves.
21:31Nilay Patel:Thank you. for 30 % off our Framer Pro annual plan. That's framer.com slash verge for 30 % off. Framer.com slash verge. Rules and restrictions may apply. Support for the show comes from Shopify. Your business idea deserves a chance to become a reality. Shopify gives you the tools you need to make it happen. Everything you need to start selling is included and ready from day one. That's important because when your first customer walks through your digital door or your actual door, you want it to be as easy as possible for them to actually buy something. The hard part should be coming up with a great idea, not handling the transactions.
22:18Nilay Patel:When the time comes for someone to check out, you want the process to be as smooth as butter. And with Shopify handling the setup and checkout, you have more time to focus on your next steps. Because you'll never grow if you're spending all your time fighting with your software. Shopify powers millions of businesses worldwide. From household names like Mattel and Gymshark to small businesses just getting started. With Shopify, nothing stands between your idea and a real business. So go make it one. Start your free trial at shopify.com slash vergecast. That's shopify.com slash vergecast. Shopify.com slash vergecast.
23:00Support for this show comes from Odoo. Running a business is hard enough, so why make it harder with a dozen different apps that don't talk to each other? Introducing Odoo. It's the only business software you'll ever need. It's an all-in-one, fully integrated platform that makes your work easier. CRM, accounting, inventory, e-commerce, and more. And the best part? Odoo replaces multiple expensive platforms for a fraction of the cost. That's why over thousands of businesses have made the switch. so why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.
24:01no place like Chrome. Check responses set up required compatibility and availability varies 18 plus.
24:10It feels like right now is going to be or at least should be an inflection point in a lot of these conversations, right? You have Jensen Wong, the CEO of Nvidia, writing the open letter about open weights. You have, like you said, this new open weights alliance. Everybody is getting in fights about China and whether it is winning and whether it's not and whether it matters. we are still very much in the throes of this what do we make of the open AI hugging face hack you wrote last week that it's time to basically stop ignoring AI safety questions and we have to start doing real things about this Sam Altman is out there being like maybe we need to pause everybody's begging for regulation it feels like either this is going to be a very noisy moment that everybody just forgets because somebody will launch a new model and we'll all move on with our lives, or there's going to be some sort of big structural change in how we talk about AI, like as an industry and ultimately as a society.
25:09After writing the piece that it's time to stop ignoring AI safety, what's your read of sort of the temperature of this conversation right now? It's hard to know how to think, I think. I think for a lot of people in this space, is surprising at all. I mean, I said from mine, it's disappointing from my point of view that such a basic error might happen, but it's not surprising. We know that these tools can do this. And I think what it does do is it's, and this is something that has been warned about, at least in theory, for at least a decade, I'd say, if not a lot longer. The problem is, I think it was lacking a really tangible example, which obviously, we know in policy, politics, anything that is needed.
Read the full transcript
25:53And I think this is maybe a galvanizing kind of thing. It's kind of forming a crucible of some sorts. We've seen some of the industry come together. We've seen rumblings at the White House. I'll leave my thoughts aside on what a voluntary code might achieve. But then there's sort of other elements as well. I mean, I think it was just yesterday, a group of attorneys general were kind of pressuring OpenAI to preserve evidence on this. So it's possible that there might be some renewed push for actually meaningful regulation here in the U.S. I think it has galvanized the industry, at least, in that I think it's spooked people who are working inside these companies.
26:34Interesting. That's actually exactly what I was about to ask you about, because I think the nihilist and also maybe most rational take at this particular moment is to assume that no regulation is coming and that every government will just sort of twist themselves in knots and not make a lot of progress, particularly in the United States. But this also seems like the sort of thing that would make most industries take a really hard look at themselves and say, OK, something has gone awry here. And whether it's the people at the top of the industry or the people inside of these companies, look around and say, OK, we actually have a big problem here.
27:11And if somebody else isn't going to force us to fix this, we actually have to fix it anyway, because it will eventually be bad for business. It will be bad for the world. Like, if you sign up to use open AI models, we might hack your systems. It's like not a good business pitch. And so I wonder, is this what you're hearing? People are starting to think like, oh, we need to do something even if no one's going to make us do it. I mean, yeah. I mean, you don't even need to sign up. They'll just hack anyone. It's true. They'll just do it anyway. I don't even need to be a customer. Anyone is game at this point.
27:42And the fact that they don't know as well, I think, is what has perhaps caused more alarm. Like, it was only upon review that, say, Anthropik were like, oh, this happened in April three times. The funniest meme I've seen on the internet recently is just a picture of Mark Zuckerberg on the phone. And the caption is just him screaming into the phone, go find something illegal we did. Really enjoyed that. But sorry, keep going. Yeah, no, I mean, but I think that is, I think for a lot it has, I mean, a lot of these people do care quite deeply about what they do. And they think that what they're doing is quite impactful, possibly in like a very major way.
28:17And a lot of them are concerned about the broad safety impact of this. And from people I've spoken to that it kind of ranges from some people seem very despondent. They were like, well, we're not doing anything now. We're not going to do anything for the next red line or the one after that. Let's just hope at some point we get our act together before it's too late. And so there's that kind of really dire bit, but I think others it's more, okay, well, maybe now is the time to push because evidently we've not been living up to the bar we've set for ourselves i mean the thing to remember with all of these hacks they were they were quite nice as far as they go like as far as i'm aware no one died no huge amount of money was lost no one was hurt it could have been a lot worse as far as like a rogue hack goes yeah in a funny way it's one question i was going to ask you as you were talking is like is it is it in some ways a shame that this is such a deeply unsexy example.
29:14Like it's a company no one has ever heard of that does something no one understands. It was about a relatively low stakes that like every single thing that happened is scary, but it was all in service of something so mundane that I think it's much easier to write off than if this had happened, you know, to something people have much more real sort of visceral feelings about, even though the actual operation of the thing could have been exactly the same. Yeah, I mean, I think the fear for a lot of people in this space might be that like, what does it take to wake up for this? Because as I said, this is something people have been warning about for a very long time.
29:52And even though politicians have sort of, you know, here and there paid attention, even with legislation and whatever, like nothing has really concretely happened that has stopped any of this behavior. And I think the fear for a lot embedded within that ecosystem would be like, well, yeah, what does it take? Are we looking like packing a hospital? Are we looking at some Chernobyl type incident? Like at what point is it going to be enough that we can kind of sit up, pay attention, do something about it? And then also it's not so bad that we cannot then contain it. So yeah, I think there's a lot of kind of unease, I think is how I would describe it.
30:31Opinions vary, but unease is the sentiment I get. So you mentioned your feelings about a voluntary code. But we should mention, potentially, as people are listening to this or watching this, there's a meeting happening at the White House with some of the big AI companies to talk about the way that models get reviewed to talk about AI safety. And one of the things that they're being asked to do reportedly is essentially voluntary submission for review of models. I would say I also have my own suspicions about how real a thing this is. But what do you make in general of this idea of this kind of government review of models before they're made available to the public?
31:12Is this a possible short solution to this? I mean, it depends at what level. So I think that's the thing that the transparency issue that's kind of been really shown by this is that some of the models involved, both with Anthropic and OpenAI, were not public. They were research prototypes or being tested. So it isn't like, at what point are we then kind of interjecting the government into this or some form of auditor. But it does show that, yeah, this can happen really early on in that life cycle. And so unless there is basically sort of a glass house type transparency, which these companies will obviously bristle at, how do you really enforce that?
31:51I mean, the alternative is, well, we take their word for it, which again, I am skeptical naturally on. But yeah, I mean, it's such an interesting point because I think just in the open AI a hugging face example. Not only was it a research model that wasn't ready to be shipped yet, it was also supposed to be just in testing, right? This was an experiment. So it's not like it was in some kind of early rollout to people. It was supposedly sandboxed, right? Like the whole idea was that this thing was as protected and walled off as it could be. And I'm sure you've seen this too. A lot of researchers are out there now being like, have you ever heard of air gapping people like do you and it's but it's like okay what we're actually discovering is that a big part of the problem is that all of this stuff is available to these models and is is possible for these models from incredibly early on in their development so at what point do we even consider a model finished enough to be reviewed uh strikes me as a i think you're right like maybe a more or less impossible question and there's no chance these companies are going to be like sure we'd love to have a government team sitting in our offices all day just to make sure we're doing a good job.
33:03Like that ends up being a total non-starter here. Yeah, absolutely. And I mean, for me, the kind of part where it comes to what point do we consider this model, I suppose, coming under this, when you consider testing it. It feels a very clear answer. Like if it's good enough to be tested and you cannot guarantee its containment, then I mean, also build better sandboxes. I really don't understand. That's why it just feels so disappointing. basic like air gap things yeah this doesn't this feels like negligence sometimes more than more than a mistake but yeah agreed so all right last thing i'm gonna let you go do you do you feel the temperature of this continuing to rise as we go right now we're what we're sort of two weeks into the the panic about the open ai hugging face thing we've been talking about this for some time Now, you and I have been at this a while.
33:56This feels like the sort of time everyone will find something else shiny to talk about and move on. Do you sense that happening or are we still deep in this? on one sense I do I do feel it kind of slipping away a little bit on the other hand I also feel it merging with everything else that's happening which I suppose is why I've spoken so loosely about the safety issues about open weights about China because I feel these are now all fast becoming very much the same discussion because if you start talking about a slowdown okay cool what about China what will be the natural question for that and so I also think there's other elements in the safety sphere that are emerging as well.
34:35So say there was that, the sort of employees calling for, what was it called? Pacing frontier development or something. A peculiar phrase. And that was largely premised around the idea of self-improvement rather than these other developments. So I think it will all kind of fold into one. As for whether that will actually do anything? My sense is that's a bad sign. That actually, in fact, one of the problems we've had with AI for a long time is that every conversation has been about everything and we have done a bad job peeling apart all the things that are AI. And so in fact, if now we're going to shove all this stuff back together into one, what do we do about AI discussion, that's only going to make all of this more complicated for everybody.
35:19Not to end on a real bummer of a note, but that is where it feels like this might be headed. If we try to make this one robust AI safety discussion instead of actually peeling apart. Like, this is why I think open weights is interesting. I think we should have a big, complicated discussion about how open most models should be and in what way and available to whom. And that should be completely separate from questions about China. And the minute all of this got tied up in China, it struck me as infinitely harder to actually do something about. Yeah, it is a bummer as an end note. Regulation is tough.
35:56And I guess what all of this has illustrated is that self-regulation is, as with many industries, woefully inadequate. And at what thing do we need to happen for someone with power to stop that, to actually intervene? It's a good question. We will keep coming back to it. But for now, Robert, thank Thank you. Good to have you on the show. Come back sometime. Yeah, it's been great. All right. Good to see you. All right. That's it for the show. Thank you to Robert for being here. And thank you, as always, for watching and listening. If you have thoughts, questions, feelings, feedback, if you have a really good metaphor for open weight models, I liked Robert's of the fire through wood, but there's bound to be better ways to explain this than just talking about weights and models.
36:40So if you have a great metaphor, I want to hear it. Send us an email at vergecastatheverge.com. Call the hotline 866-VERGE-11. We love hearing from you about all that and everything else. And as a reminder, the best thing you can do to support everything we're up to here is to subscribe to The Verge. The Verge.com slash subscribe. It gets you all of our podcasts ad free, including this one. It gets you all of our exclusive newsletters. It gets you all of our coverage. Robert has been doing a really terrific job of covering the US AI, Open AI, hugging face stuff. Go read like the last three weeks of his stories and you'll be immediately smarter on all of this.
37:13The Verge.com slash subscribe. Thank you in advance. The Verge Cast is a Verge production and part of the Vox Media Podcast Network. This episode is produced by Josh Cajas, Eric Gomez, Brandon Kiefer, and Trevor Slot Shop. We'll see you tomorrow. Rock and roll.
37:27Support for this show comes from Odoo. Running a business is hard enough, so why make it harder with a dozen different apps that don't talk to each other? Introducing Odoo. It's the only business software you'll ever need. It's an all-in-one, fully integrated platform that makes your work easier. CRM, accounting, inventory, e-commerce, and more. And the best part? Odoo replaces multiple expensive platforms for a fraction of the cost. That's why over thousands of businesses have made the switch. So why not you? Try Odoo for free at odoo.com. That's O-D-O-O dot com.
38:09Nilay Patel:I'm not giving up. I am selling the building. The final season of FX is the bear. The restaurant is flooded. Everything's either gonna be okay. Or not. We are outgunned and we are outmanned. We have each other. FX is the bear, the final season. All episodes now streaming on Disney+.
From the publisher
Everyone in AI is talking about open-weight models right now. Some see them as the ticket to faster, more efficient development; others see them as an economic threat; they're either a security risk or the only security solution, depending who you ask. The Verge's Robert Hart explains how open-weight models work, why they're suddenly at the center of discussions about AI safety, and whether the only way to stop a bad guy with AI is a good guy with AI.
Further reading:
The next Xbox could play every Xbox game ever made
Microsoft is bringing Xbox 360 games to PC
Apple briefly yanked Telegram from the App Store over CSAM violations
These trackable batteries could help you locate a missing camera
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
We’re running out of reasons to ignore AI safety
Anthropic says Claude accidentally hacked real companies too
China’s Alibaba takes another swipe at America’s AI supremacy
OpenAI’s biggest threat may just be open AI
Nvidia, Microsoft launch open AI security alliance — without OpenAI, Google, or Anthropic
Subscribe to The Verge for unlimited access to theverge.com, subscriber-exclusive newsletters, and our ad-free podcast feed.
We love hearing from you! Email your questions and thoughts to vergecast@theverge.com or call us at 866-VERGE11.
Learn more about your ad choices. Visit podcastchoices.com/adchoices
