YouTubeFeed

Why Washington Suddenly Wants A.I. Regulation

Summary

The Trump administration just did a stunning about-face on AI safety. After two years of dismissing safety concerns as “doomer” hysteria and rolling back the Biden-era AI executive order, the White House is now reportedly drafting a new AI executive order that would create a working group to develop a formal government review process for new frontier models before they ship. Kevin Roose and Casey Newton walk through what changed: Anthropic’s release of Claude Mythos, an AI model so good at finding novel software exploits that a handful of federal agencies have it but the public doesn’t. Once “the serious people” inside the Trump administration saw what Mythos could do, the position pivoted from “let them cook” to “wait, maybe we do need to vet these things.”

The hosts also detail the absurd schism this is creating. President Trump is flying to China on Air Force One with Jensen Huang, Tim Cook, Elon Musk, and Joel Kaplan to ease chip export restrictions and possibly open up AI model access — while other Trump officials are arguing those same models need pre-release safety review. The Pentagon is simultaneously trying to remove Anthropic as a “supply chain risk” while deploying Mythos to scan for vulnerabilities. CASI (Center for AI Standards and Innovation, formerly the AI Safety Institute) appears to be winning some of the turf war against the NSA-aligned faction. Casey notes that Republican state legislatures had never been the problem — they were already racing to regulate AI — and the Trump administration was always out on a limb that finally broke when Mythos shipped. Cyber catastrophe risk is now percolating on the right: Ted Cruz is suddenly talking about it. Germany is demanding access to Mythos. Kevin: “We may have a catastrophe unfolding under our noses, we just don’t know about it yet.”

Then Palo Alto Networks CEO Nikesh Arora joins for a front-line view of the cybersecurity reckoning. Arora’s company has early access to both Mythos and GPT-5.5 Cyber and recently disclosed 26 critical exploits patching 75 issues against a typical baseline of “under five” — a 5–7x spike. The classic 90-day responsible disclosure window is dying because attackers can now go from initial access to data exfiltration in 25 minutes. Mythos’s edge isn’t just finding vulnerabilities — it’s “daisy chaining” them, persisting in Ultra mode for far longer than Flash-class models. Arora is calm about it (“I’m a little more relaxed than what you’re trying to ascribe”) but warns the asymmetry favors attackers: defenders must be right 100% of the time, attackers only once. He’s most worried about non-tech industries (small businesses, manufacturing, hospitals — “remember the Change Healthcare breach”), least worried about banks who out-resource him. On hiring: he needs MORE engineers, not fewer, because every CFO and HR head wants to deploy AI and there’s a decade-long transformation backlog. On the unease around OpenInterpreter: “you don’t need to change your password — OpenInterpreter is just going to tweet on your behalf because it had a moment last night.” Kevin’s followup: “And for all my objectionable tweets over the years, I would like to formally say that was my OpenInterpreter acting autonomously.”

The episode closes with Hot Mess Express, including Venmo finally defaulting transactions to private (Casey mourns this “end of an era”), Amazon employees gaming token-usage metrics on Mesh Claw to look productive (Goodhart’s Law in action), UCF graduates booing the commencement speaker who called AI “the next industrial revolution,” Dua Lipa suing Samsung for $15 million over using her face on TV packaging, GameStop’s not-actually-credible $55 billion bid for eBay, Shein and Temu suing each other over copyright in the UK, Grindr’s Madonna campaign outing closeted users at family dinners with an audible “Hi Grindr, it’s mother,” and Sam Altman’s bombshell testimony about Musk wanting to leave OpenAI to his children.

Highlights

”The Trump administration’s view of AI did not survive contact with reality”

Clip

“Basically, to use a phrase you used to sometimes like to use, the Trump administration’s view of AI just did not survive contact with reality… What has changed here is Mythos.” — Casey Newton, 3:54

Clip command
yt-dlp --download-sections "*3:54-4:45" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "view-of-ai-survive-reality.mp4"

”Remove safety from the name then say AI safety is a focus”

Clip

“There is just something so funny about these people coming in and saying AI safety is such a stupid idea that we have to remove safety from the name of this institute and then one year later being like, uh, well, AI safety is really going to be a focus for us from now on.” — Kevin Roose, 4:58

Clip command
yt-dlp --download-sections "*4:58-6:00" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "removed-safety-from-name.mp4"

”Install and uninstall Anthropic at the same time”

Clip

“I want to be in the meeting where the person who has to remove Anthropic from the Pentagon system sits down with the person who’s installing Anthropic into the Pentagon and just hear what those talks are like.” — Kevin Roose, 8:25

Clip command
yt-dlp --download-sections "*7:46-8:37" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "install-uninstall-anthropic.mp4"

”A great cleansing moment” — Palo Alto’s 5–7x exploit spike

Clip

“It’s almost like this is a great cleansing, right? So it’s a great cleansing moment. We found seven times the volume that we would have normally found in a normal period.” — Nikesh Arora, 27:16

Clip command
yt-dlp --download-sections "*27:16-28:43" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "great-cleansing-vulnerabilities.mp4"

”We have to be right 100% of the time”

Clip

“Remember, it’s an unbalanced fight to start with. We have to be right 100% of the time, the bad guys have to be right once. So it’s an uneven playing field from that perspective.” — Nikesh Arora, 38:00

Clip command
yt-dlp --download-sections "*38:00-39:00" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "right-100-percent-time.mp4"

”OpenInterpreter is going to tweet on your behalf”

Clip

“You don’t need to change your password. OpenInterpreter is just going to tweet on your behalf because it had a moment last night.” — Nikesh Arora, 45:55

Clip command
yt-dlp --download-sections "*45:00-46:30" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "openinterpreter-tweet-on-behalf.mp4"

”Hi Grindr, it’s mother”

Clip

“Apparently over the past week, when you opened up Grindr, even if you had your phone volume turned off, you would hear a sound of Madonna saying loudly, ‘Hi Grindr, it’s mother.’” — Casey Newton, 1:01:54

Clip command
yt-dlp --download-sections "*1:01:21-1:02:44" "https://www.youtube.com/watch?v=js2FCXP_KaA" --force-keyframes-at-cuts --merge-output-format mp4 -o "hi-grindr-its-mother.mp4"

Key Points

  • Trump admin pivoting on AI safety (0:56) - After dismissing AI safety concerns for years, the administration is suddenly scared
  • New EO would create pre-release model review (1:56) - Working group + similar review process to what Biden’s EO had before Trump scrapped it on day one
  • Mythos is the proximate cause (3:54) - Anthropic’s vulnerability-finding model has rattled even hawks who wanted no regulation
  • CASI (formerly AI Safety Institute) winning turf war (4:45) - Inside the Commerce Department; staffed by people who held their nose to serve under Trump
  • “Let them cook” vs. hawkish safety factions (6:00) - David Sacks’s laissez-faire approach colliding with intelligence-community pre-release vetting
  • Pentagon installing AND uninstalling Anthropic simultaneously (7:46) - Anthropic still designated a supply chain risk while Mythos is being deployed for vulnerability scanning
  • AI safety was “vaguely woke-coded” (9:55) - Kevin notes how the polarization actively hurt the discourse
  • Public opinion was always anti-AI (10:52) - Republican state legislators didn’t need convincing — Trump admin had to push a moratorium to override them
  • Catastrophic risk on the right now (11:51) - Ted Cruz talking about it on Tuesday, joining Bernie Sanders on the left
  • AI Action Summit in Paris was “we’re not gonna talk about dangers” (19:17) - Kevin reflects on how the framing has flipped
  • Casey: “I rather have an administration saying don’t give the cyber model to everyone” (21:31) - Even acknowledging censorship risk
  • Cyber attacks everywhere this week (22:29) - Mozilla 423 patches in April (vs ~22/month baseline); Google identifies first AI-developed zero-day; Canvas/Instructure hacked
  • Palo Alto disclosed 26 exploits / 75 issues vs. baseline under 5 (26:52) - The 5–7x spike Arora confirms
  • 50% false positives, but Mythos gets better with context (30:59) - You have to feed it code purpose + threat research data
  • Mythos and GPT-5.5 Cyber find DIFFERENT things (32:35) - Suggests there’s still a lot more to find
  • 90-day disclosure window is dead (35:18) - AI-assisted attackers go from initial access to data exfil in 25 minutes
  • The asymmetry: defenders 100%, attackers once (38:00) - Attackers favored, but defense is about sensors, not models
  • Most worried about: non-tech industries (39:29) - Hospitals, mining, manufacturing, small businesses (cf. Change Healthcare)
  • Mythos runs in Ultra mode (40:56) - Compute-consumptive persistence enables better daisy chaining
  • Need MORE engineers, not fewer (47:22) - Arora pushes back hard on the layoff narrative — 6-12 month feature backlogs justify rehiring
  • Decade-long transformation ahead (48:23) - CFO wants AI, HR wants AI interviewer; efficiency from those teams pays for the tokens
  • Arora’s earnings script: “are you trying to hide something?” (46:35) - Gemini told him he overused “momentum” and “excited” — he toned it down
  • Venmo finally defaults to private (51:01) - End of an era for the public Venmo journalism genre (Biden, JD Vance, Matt Gaetz)
  • Amazon Mesh Claw token gaming (52:55) - Employees inflating usage scores; Goodhart’s Law in action
  • UCF graduates booed AI commencement speech (54:30) - Gloria Caulfield called AI “the next industrial revolution”; someone yelled “AI sucks!”
  • Casey: students are radically more anti-AI than people realize (55:46) - 80% hate AI at his campus visits
  • Dua Lipa sues Samsung for $15M (56:27) - Over her face on TV packaging via third-party content partner
  • GameStop offered $55B for eBay without having $55B (57:59) - eBay called it “neither credible nor attractive”
  • Shein vs. Temu fast fashion copyright fight in UK (1:00:01) - Two brands famous for ripping off clothing accusing each other of it
  • Grindr’s Madonna ad outed people at family dinners (1:01:21) - Audio played even with phone on silent
  • Musk wants to leave OpenAI to his children (1:02:47) - Sam Altman testified about this exchange

Mentions

Companies

  • Anthropic (0:04) - Created Mythos; Casey’s fiancée works there
  • OpenAI (1:45) - GPT-5.5 Cyber; being sued by NYT
  • Palo Alto Networks (22:18) - Nikesh Arora’s company; 70,000+ customers, vast majority of Fortune 100
  • Nvidia (0:43) - Jensen Huang on Air Force One with Trump to China
  • Apple (14:02) - Tim Cook on the China trip
  • Meta (14:02) - Joel Kaplan on the China trip
  • Microsoft (1:45) - Sued by NYT
  • Perplexity (1:45) - Sued by NYT
  • Mozilla (22:55) - 423 patches in April vs. ~22/month baseline
  • Google (23:07) - Identified first attacker using AI-developed zero-day
  • Instructure / Canvas (23:18) - Education platform hacked; negotiated with hackers
  • Change Healthcare (40:06) - Cited as example of non-tech breach causing massive disruption
  • IBM, PWC, Deloitte, Accenture (29:24) - System integrators rallying to help patch enterprise systems
  • Venmo (51:01) - Switching public to private by default
  • Amazon (52:55) - Mesh Claw rollout; employees gaming token usage
  • University of Central Florida (54:46) - Where the commencement speaker was booed
  • Samsung (56:27) - Sued by Dua Lipa for $15M
  • GameStop (57:59) - Unsuccessfully bid $55B for eBay
  • eBay (57:59) - Rejected GameStop bid as “neither credible nor attractive”
  • Shein / Temu (1:00:01) - Fast fashion brands suing each other in UK courts
  • Grindr (1:01:08) - Madonna campaign outing closeted users
  • Tavistock Group (54:46) - Where Gloria Caulfield (booed commencement speaker) is VP

Products & Technologies

  • Claude Mythos (3:54) - Anthropic’s still-restricted vulnerability-finding model
  • GPT-5.5 Cyber (24:08) - OpenAI’s competing cyber model
  • Ultra mode (40:56) - Compute-consumptive persistence mode of Mythos
  • OpenInterpreter (45:55) - Hot topic agentic tool Arora calls a “security nightmare”
  • Mesh Claw (52:55) - Amazon’s in-house agentic AI product
  • SynthID (implied in EO discussion)
  • AI Action Summit / India / Paris (19:17) - Western AI cooperation forums

People

  • President Trump (0:27) - Headed to China with tech CEOs; AI EO in flux
  • Xi Jinping (0:27) - Meeting with Trump on the China visit
  • Jensen Huang (0:43) - Last-minute Air Force One invite
  • Elon Musk (14:02) - On Trump’s China trip; OpenAI trial happening simultaneously
  • Tim Cook (14:02) - Stepping down as Apple CEO; still on China trip
  • Joel Kaplan (14:02) - Meta’s policy chief on the trip
  • David Sacks (6:00) - Former AI Czar; “let them cook” philosophy
  • President Biden (2:26) - His AI EO was scrapped on Trump day one
  • Ted Cruz (12:00) - Now talking about catastrophic AI risk on Tuesday
  • Bernie Sanders (12:00) - Has been talking AI catastrophic risk for months on the left
  • Dario Amodei (13:54) - Anthropic CEO; Chinese think tank tried to lobby him in Singapore
  • Nikesh Arora (24:08) - CEO & Chairman of Palo Alto Networks; episode’s guest
  • Himanshu Anand (35:18) - Researcher who declared the 90-day disclosure window dead
  • Sam Altman (1:02:47) - Testified about Musk’s hereditary monarchy comment
  • Madonna (1:01:21) - Promoting “Confessions on a Dance Floor 2” via Grindr campaign
  • Dua Lipa (56:27) - Suing Samsung over face on TV packaging
  • Ryan Cohen (58:47) - GameStop CEO who tried the $55B eBay bid
  • Gloria Caulfield (54:46) - VP at Tavistock Group; booed at UCF commencement
  • JD Vance / Joe Biden / Matt Gaetz (52:21) - Subjects of past public-Venmo journalism

Surprising Quotes

“The Trump administration’s view of AI just did not survive contact with reality.” — Casey Newton, 3:54

“There is just something so funny about these people coming in and saying AI safety is such a stupid idea that we have to remove safety from the name of this institute and then one year later being like, uh, well, AI safety is really going to be a focus for us from now on.” — Kevin Roose, 4:58

“There may be a catastrophe unfolding under our noses, we just don’t know about it yet.” — Kevin Roose, 12:59

“We have to be right 100% of the time, the bad guys have to be right once.” — Nikesh Arora, 38:00

“You don’t need to change your password. OpenInterpreter is just going to tweet on your behalf because it had a moment last night.” — Nikesh Arora, 45:55

“Are you trying to hide something? You’re too enthusiastic, use the word momentum and excited too much more than you normally use.” — Nikesh Arora quoting Gemini’s review of his earnings script, 46:35

“Hi Grindr, it’s mother.” — Casey Newton quoting Madonna’s Grindr ad, 1:01:54

Transcript

Kevin Roose: 0:00 I’m Kevin Roose, tech columnist at the New York Times.

Casey Newton: 0:02 I’m Casey Newton from Platformer.

Kevin Roose: 0:04 And this is Hard Fork. This week, is AI safety back? The Trump administration seems to be changing its tune. Then, Palo Alto Networks CEO Nikesh Arora joins us to discuss what’s real and what’s hype in the freak out over Cloud Myths.

Casey Newton: 0:18 And finally, the train has returned to the station. It’s the Hot Mess Express. Buckle up.

Kevin Roose: 0:27 Well the big news this week is that President Trump headed to China with a cohort of American business executives to have a series of meetings about Chinese trade policy and AI and other things with Xi Jinping and other leading Chinese officials.

Casey Newton: 0:43 Now is it true when they walked off the plane a bunch of H100s fell out of the leg of Jensen Huang’s pants?

Kevin Roose: 0:52 I haven’t heard that confirmed but I’ll look into it.

Casey Newton: 0:54 Thank you.

Kevin Roose: 0:56 I want to talk about this but less through the lens of like sort of President Trump and United States trade policy then through this sort of larger shift that I think we’ve both observed over the past week or so which is that after several years of kind of dismissing AI safety and doomer fearmongering about AI, the Trump administration or at least parts of the Trump administration seem to be getting quite scared about what’s happening.

Casey Newton: 1:25 Yes, and while this is something that I think was honestly inevitable, it’s still has been jarring to see it happen because it seems like this administration has really turned on a dime when it comes to this subject.

Kevin Roose: 1:36 Yeah, so let’s talk about what’s been going on and some of the data points that support the idea that the Trump administration is sort of changing its AI posture or at least has several different AI postures that it’s considering.

Kevin Roose: 1:45 But first, let’s do our AI disclosures. I work for the New York Times which is suing OpenAI, Microsoft and Perplexity.

Casey Newton: 1:53 And my fiancee works at Anthropic.

Kevin Roose: 1:56 So first there was this executive order or rumored executive order that my colleagues at the New York Times reported on last week. This would be a new executive order to create an AI working group that would bring together tech executives and government officials to potentially come up with new ways of overseeing or regulating AI. One of the potential plans being discussed is a formal government review process for new AI models before they are released. So this is still ongoing, we still don’t know exactly what the executive order will or won’t include but we are expecting more news on that soon.

Casey Newton: 2:26 Yes, and the reason that is notable, Kevin, is that on President Trump’s first day in office in his second term, he canceled President Biden’s executive order on AI, which among other things included a very similar kind of review process for new frontier AI models. The Biden people were very confident that we would one day get models that could be used to commit great harm and so they wanted to get a handle on that before those models were released. And when Biden did that, many Republicans were saying this is anti-innovation, you’re going to make us lose to China.

Casey Newton: 3:00 Well, well, well, now the shoe is on the other foot and they are saying, hey, slow down, don’t release those things quite so fast.

Kevin Roose: 3:07 It’s so remarkable how fast the Overton window has shifted on this idea. During the Biden administration, during the SB 1047 fight here in California over this proposed AI bill, people in tech and on the tech right and sort of among the more libertarian crowd were incensed about the idea that the government might ask them to do pre-release testing of their models that they then submit the results of to the government. They called this communist. They were sort of implying this would be kind of the end of free enterprise as we know it, and now just a couple of years later, they are reportedly considering doing something similar. So what do you think happened here?

Casey Newton: 3:54 Well, I think that basically, to use a phrase you used to sometimes like to use, the Trump administration’s view of AI just did not survive contact with reality. And that in a word, what has changed here is Mythos, the model that Anthropic now has released in a preview to a very small group that includes now many federal agencies. This model is very good apparently at finding novel vulnerabilities in code that can be used to create exploits, and that appears to be true across many, many programs. And so the administration, I think, took a look at this and the serious people over there said, look, whatever your views may be about free trade and the threat of losing to China, we have a model right now that if it were just sort of unleashed on the public could just create vast amounts of harm. And I think to their credit, the Trump administration said, okay, then what would be a policy to prevent harm from happening?

Kevin Roose: 4:45 Yes, Mythos is the proximate cause here for a lot of this, but I think it’s also worth talking about the various factions within the Trump administration that appear to be battling over control of this new AI regulatory push. There appears to be a turf war breaking out between the Center for AI Standards and Innovation, or CASI—

Casey Newton: 4:57 Shout out to CASI!

Kevin Roose: 4:58 —which is formerly known as the US AI Safety Institute. This was a group within the Commerce Department that was set up under the Biden administration. The Trump administration came in and basically they didn’t like that this was, you know, what they considered sort of a bunch of doomers, so they sort of made some changes, including to the name, but this is a group of AI researchers and safety experts who work in the Commerce Department who want to be involved in vetting new models. And there is just something so funny about these people coming in and saying AI safety is such a stupid idea that we have to remove safety from the name of this institute and then one year later being like, uh, well, AI safety is really going to be a focus for us from now on.

Casey Newton: 6:00 There’s also just like this interesting kind of posture war over whether the kind of let it rip approach to AI development or as former AI czar David Sacks put it, the “let them cook” philosophy of laissez-faire regulation and this more sort of hawkish safety oriented faction within the Republican Party that does see these models as a big threat and wants to take steps to reel them in. Yes, so there are some people who believe that the vetting of frontier models should take place like in the intelligence community, among the NSA and various other organizations.

Kevin Roose: 6:27 Right. So do we know at this point who seems to be winning that battle and do you think it matters to the average person which side gains the upper hand?

Casey Newton: 6:36 I do. I think there’s obviously going to be some back and forth. We’ll see when this executive order comes out, what they do about the testing requirements and where they locate that, if it’s like we’re going to let the NSA do this or we’re going to let CISA do this. I think that all might matter a little bit. But I think the general posture of the administration changing from “AI safety is ridiculous and these doomers are using hyped up fears to enact regulatory capture” is very different from what we are seeing now, which is, oh wait, these models are very powerful and we don’t want our adversaries to get access to them.

Kevin Roose: 7:15 But we should also say it is entirely confused and incoherent right now at the level of the federal government because on one level you have President Trump inviting Jensen Huang of Nvidia onto Air Force One to fly with him to China to try to make a deal to presumably like open up the export of Nvidia’s most powerful AI chips to China while at the same time you have other high ranking government officials saying we need to institute some kind of safety regime because these models are potentially very dangerous.

Casey Newton: 7:46 Yes, and nowhere is that schism more apparent than in the Pentagon, Kevin, where on one hand the Pentagon has designated Anthropic as a supply chain risk because it refused to amend its contract to enable any quote, lawful use of its technology as we talked about on the show for a few months. That designation the Pentagon is still arguing for in court. But at the same time, we learned that this week during the period where the Pentagon is supposed to be unwinding all of Anthropic’s technology from the Pentagon, the Pentagon is also implementing Mithos and using it to try to scan for vulnerabilities.

Kevin Roose: 8:25 It’s truly wild. I want to be in the meeting where the person who has to remove Anthropic from the Pentagon system sits down with the person who’s installing Anthropic into the Pentagon and just hear what those talks are like.

Casey Newton: 8:37 Yeah, so aside from the obvious sort of incoherence and maybe hypocrisy of these conflicting positions, which side do you think is going to come out on top here? Under President Biden, the idea was these models are getting better, pretty soon they’re going to be dangerous, we need to have a way of evaluating them before they are released. And frankly, they’ve just sort of hired a lot of people who I think ordinarily might not work in a Trump administration, but felt like this is so important that I’m going to swallow hard and go over there and try to serve my country by protecting us from the worst things that AI can do. And so to me, that seems like they would be very well set up to do this kind of work.

Casey Newton: 9:30 Where I think we still have an obvious gap though, Kevin, is it’s not entirely clear to me what is supposed to happen in the case when a company like Anthropic comes up with a model that is too dangerous to release in the view of something like the AISI, but wants to release it anyway. And I assume we are just going to get to sometime within the next six months, one of these companies is going to say, ‘Yeah, it’s risky, but you know, we think it’s sort of fine to put out there, we have business imperatives, we’re going to talk ourselves into it.’ And then what happens?

Kevin Roose: 9:55 Yeah. I mean, it’s also just so clearly unfortunate that the issue of AI safety has become polarized in the way that it did over the past couple of years, that sort of caring about safety, talking about safety became sort of like vaguely woke-coded, and people in the Trump administration thought it was like a bunch of hysterical liberals using fears of AI to get heavy-handed regulation into place. I don’t think that was ever true, but I think it has become especially untrue now when you have very senior people in the Republican Party talking about how we need to restrain these systems. So it’s frustrating because I think you and I both saw this technology is real, it’s going to get even more powerful than it is, and at that point, it’s not going to matter whether you’re a Republican or a Democrat, you do not want this stuff falling into the hands of our adversaries.

Casey Newton: 10:52 True, but I think the Trump administration was always out on a limb here in a really weird way. We have talked a lot recently about what the surveys show when it comes to the public opinion of AI in America. Republicans and Democrats are like largely aligned in being deeply skeptical of it and even outright hating it. And that’s why you see so many Republican state legislators trying to pass laws to rein in AI. You did not have to convince Republican state legislators that AI was dangerous and needed to be regulated. They were racing to do it. And the Trump administration has had to put a lot of energy into trying to pass a moratorium so that it can preserve its sort of all-gas, no-brakes approach to AI. So what I think happened here was that there was basically a minority of Republicans that happen to be running the country that said, ‘Let the labs do whatever they want,’ and then this comes out and the bill comes due and they sort of have their pants down and they have to change their tune. Yeah, just to sort of throw a lot of metaphors in there.

Kevin Roose: 11:46 Yeah.

Casey Newton: 11:47 Pants, tunes…

Kevin Roose: 11:48 We’re getting there.

Casey Newton: 11:50 Oh, I’ll come up with more. Don’t worry.

Kevin Roose: 11:51 We’re getting there. One other thing here is that you are starting to see the issue of catastrophic or existential risk floating up and percolating on the right. This is something that people like Bernie Sanders have now been talking about on the left for a couple of months, but on Tuesday of this week, Ted Cruz was talking about catastrophic risk and the need to protect against it. So I just think that the improvement of these models and the fact that they are so clearly useful for dangerous things like cyber attacks is going to scramble some of the usual partisan allegiances here.

Casey Newton: 12:25 Yeah, I mean look, the idea that a large language model might eventually get so good that it could break into your computer and wreak havoc, that was not a liberal view. That was just a view grounded in an observation of the rate of improvement in the model. In truth, I am glad that they are reversing course on this, and they’re doing it before we’ve had a massive catastrophe. Maybe an asterisk there though, which is I truly feel like every single day for the past week I’ve seen news of a major cyberattack, and increasingly we’re getting word that these may have had AI systems involved in identifying these vulnerabilities.

Kevin Roose: 12:59 Yes, so there may be a catastrophe unfolding under our noses, we just don’t know about it yet.

Casey Newton: 13:04 Yeah, stay tuned for next week’s episode.

Kevin Roose: 13:07 I want to talk a little bit about this China trip and what, if anything, we think that has to do with AI regulation. So there was some reporting in the Wall Street Journal last week that both the US and China have been considering a series of official discussions around AI. We know that AI is on the agenda for President Trump’s meetings with Xi in China this week. And we also know that China has been looking to get access to models. There was a great story recently in the Times that talked about the fact that a representative from a Chinese think tank approached Anthropic officials at a meeting in Singapore last month to basically lobby them to open this model up to China.

Casey Newton: 13:48 And we want to give them the Hard Fork Chutzpah Award for shooting your shot.

Kevin Roose: 13:53 Yeah.

Casey Newton: 13:54 If you work at a Chinese think tank and you think Dario Amodei was about to hand you models, that is truly like I aspire to your level of self-confidence.

Kevin Roose: 14:00 Listen, you miss a hundred percent of the shots you don’t take. So along with Jensen Huang, who finagled a last-minute invite on Air Force One after there were news reports that he was not going to be going on this trip, Elon Musk, Tim Cook, and Joel Kaplan from Meta are also on the trip with Trump. What’s going on here and how would you characterize the blunt rotation among those tech executives?

Casey Newton: 14:29 You know, this is a group of executives that are aligned with the Trump administration, and they have all found in various ways that the more time you spend flattering President Trump, the more tax breaks and other forms of relief your company gets. So this is exactly what we talked about expecting Tim Cook to do once he announced that he’d be stepping down as CEO, is you’re just kind of like a Trump whisperer and you follow him around and you say, go President Trump, and also please give Apple what we want. So Meta, Apple, and Nvidia have all had huge runs of huge success with this administration and now as their reward they get to be photographed with the President flying around China.

Casey Newton: 15:06 Yeah I think I am just very unsure where all of this settles out because I can imagine Trump wanting to go to China and make a bunch of deals and obviously Jensen Huang and NVIDIA want to be able to sell their chips in China and so I can see them on the one hand giving some kind of expanded access to Chinese AI companies to get these American chips but then I can also see them not wanting China to get access to models like Mithos so I just don’t know how that resolves and I see it as basically inherently contradictory that you want to give China or sell China the means to make its own Mithos caliber models while at the same time trying to block them from getting access to the one that we have today.

Kevin Roose: 15:33 Yeah this is where it would be helpful to have a coherent strategy but we don’t right? It’s like the same administration that is installing and uninstalling Anthropic at the same time is kind of having a similar level of confusion over in China where it seems like the administration is just highly susceptible to blowing wherever the wind is today.

Casey Newton: 16:06 Yeah I mean I am generally not all that optimistic about the government’s ability to regulate technology in a way that is timely and relevant and I hope I’m wrong here but I think that we will see this sort of incoherence and contradiction until there is some big event that kind of forces everyone to sit up straight.

Kevin Roose: 16:32 I mean my question is will this be a case of the same AI safety minded people who were dismissed for the past couple years by the Trump administration be proven right again in the future when it turns out that China did use access to American technology to build Mithos or better level models and will there be any regrets that we sort of paved the way for them to do that I don’t think it’s unlikely.

Casey Newton: 16:54 Yeah it’s interesting though I had a conversation with a federal official recently in the last couple of weeks where this person was basically telling me that AI is just a normal technology sort of taking the line that we’ve heard again and again from the people who don’t want to regulate this stuff saying like this is just the internet this is just the PC it’s not some special technology that requires special rules and that position has just become so untenable to me at least when you have models that are out there finding zero day exploits like…

Kevin Roose: 17:33 clearly our military our intelligence agencies they don’t think this is a normal technology they think it’s more like a step change that requires them to act in different ways so I am very curious what happens to the sort of AI’s normal technology camp inside the Trump administration as the technology continues to grow.

Casey Newton: 17:49 Yeah they may change their arguments or they may not that’s the thing you just don’t know how committed these people are to their view.

Kevin Roose: 17:54 You don’t.

Casey Newton: 17:56 We should also talk about some of the international reaction to Mithos because it’s not just China who wants into this thing.

Kevin Roose: 18:00 Germany’s Digital Affairs and Cybersecurity Agency are out this week with a proposal for establishing their own version of something like the US KC, they are also demanding access to state-of-the-art models like Mythos. So it just seems like this model has sort of forced conversations around the world about who should have access to which models when, should the public have access, should governments have access, which governments should have access, it just seems like we are kind of in a new era of AI brinksmanship.

Casey Newton: 18:36 For sure, and what I hope that we will see in the coming months is more and more cooperation. The whole reason that we had that series of AI action summits over the past few years was to try to get more cooperation among the Western powers with this stuff. And then last year the US sort of came in and said, that’s over, the US is winning the AI race, and you can, like it or learn to live with it basically. So it’s no wonder to me that these other Western powers are seeking access to these models, and I think there’s probably honestly a good case that they should get access to these models because when it comes to fixing every vulnerability on the internet I think we could probably use all the help we can get.

Kevin Roose: 19:17 Yeah and I remember that AI action summit, I didn’t go to this, the most recent one in India, but the one in Paris before that I remember was just like, oh we’re just not going to talk about any of this. Like we’re just not going to talk about the dangers that this technology might create because we’re so invested in this sort of accelerationist posture. So how far we’ve come, and yet we are still in the very early innings of this.

Casey Newton: 19:40 Does it make you wonder what would have happened if the Trump administration had just been listening to Hard Fork a year ago? Could they have saved themselves some trouble here?

Kevin Roose: 19:46 It’s possible. So Casey, the politics of AI and AI regulation are obviously shifting very quickly, we may learn more this week after these meetings in China. But what is your take on what this latest burst of news signals about AI or AI regulation?

Casey Newton: 20:04 My take is, this is a rare bit of good news when it comes to AI regulation. I am somebody who’s been worried about AI safety for a long time, and one of the main reasons I’ve been worried about it is that our government has seemed to have this feeling of like, let’s just see what happens. Whereas to me, it seemed pretty obvious what was going to happen. Now we have arrived at that point, we have a super powerful model, and to their credit, the Trump administration is saying, okay, it seems like we were wrong about how capable these models were going to be, let’s make some changes.

Kevin Roose: 20:35 And do you think there’s any way that this turns out to backfire? I’m just remembering people wanting social media to be regulated, and then when the Trump administration started doing things in the realm of social media it amounted to what you and I would consider sort of censorship or at least wanting to strong-arm the social media companies into doing their bidding. So do you think it’s possible that something similar happens with AI where it’s like we get the regulation, but it’s just the wrong kind or this pre-release testing is testing for the right kind of thing.

Casey Newton: 21:05 Yes, I am very sympathetic to those who believe that this could amount to a kind of prior restraint on free speech and that there is the risk that there are members of the Trump administration will effectively say you can’t release that model not because it’s actually dangerous but just because it seems woke and gay. And I think that we need to keep an eye out for that and potentially someone is going to need to sue over it.

Casey Newton: 21:31 But when I look at how I want to balance those things, for the moment, I would rather have an administration saying, ‘The crazy cyber model, don’t give that to everyone.’

Kevin Roose: 21:41 Yeah, I think I’m landing in a pretty similar place where I’m like, I’m a little worried that this regulatory push from the right is going to be confused and maybe too sudden and there’s going to be some sort of overreaction that ends up with something more like the sort of censorship that you mentioned. But I am glad that after many years of denying that this technology was important, that it would become as good as the people at the lab said, that our government at least appears open to the idea that maybe they need to step in and do something here.

Kevin Roose: 22:13 I’ll take the little wins where I can get them.

Casey Newton: 22:14 That’s what I’m saying. When’s the last time we talked about a win on this show?

Kevin Roose: 22:17 Yeah.

Casey Newton: 22:18 When we come back, what is Claude Mythos doing to the world of cybersecurity? We’ll talk to Palo Alto Networks CEO Nikesh Arora.

Casey Newton: 22:29 Well Kevin, is it just me or every time you look at the tech news do you see some new cyber attack that seems to have befallen some company or another?

Kevin Roose: 22:38 Yes, this is my experience of social media over the past two weeks. I log in, I see three posts from companies about how they’ve discovered more bugs in a 24-hour window than in the previous 80 years of their company’s history. And then everyone’s reposting that with just like, ‘it begins’ or ‘it is over’ or ‘hide your kids’.

Casey Newton: 22:55 Yes, just to name a few of those. Mozilla was one of those companies saying that it had pushed 423 bug fixes in April alone compared to an average of about 22 per month throughout 2025.

Casey Newton: 23:07 Google announced on Monday that for the first time ever its threat intelligence group had identified an attacker using a zero-day exploit that the group believes was developed with AI. So that’s kind of a grim milestone.

Casey Newton: 23:18 And then if you’re a student, perhaps you noticed the cyber attack on the learning platform Canvas last week, which forced the site down for several hours and then the company behind Canvas, which is called Instructure, had to negotiate a deal with hackers for the return and destruction of the stolen data. So on one hand, there are cyber attacks going on all the time, but it does seem like some new inflection point has been reached and of course a reason that people think we might be seeing more of these is AI.

Kevin Roose: 23:44 Yes. So we have talked about Claude Mythos preview, the model that Anthropic did not release widely but released to a select group of companies and open source maintainers. And today we’re actually going to talk to someone who has used Mythos and who has been on the front lines of this frantic sprint to secure the infrastructure of modern life.

Casey Newton: 24:08 Yes, our guest today is Nikesh Arora. Nikesh is the CEO and chairman of Palo Alto Networks, the largest cybersecurity firm in the world, which supports more than 70,000 customers including the vast majority of the Fortune 100. And as you mentioned Kevin, Palo Alto was among the organizations given early access to Claude Mythos as well as GPT 5.5 Cyber.

Kevin Roose: 24:30 Nikesh is one of the people, I think, who is best positioned to see the effects that these models are having on cybersecurity because they do work so broadly across industries. They’re also a big government contractor, so I’m just really interested in what he thinks is different about this new class of models.

Casey Newton: 24:46 Yes, and something I appreciate about Nikesh is that in an industry where there is a lot of hype, because of course the more scared that a cybersecurity executive can make you, the more likely you might be to buy their software, Nikesh is somebody who I think tries to maintain an even-keeled approach here and not to ring alarm bells where none are needed. But that said, I do think that he is quite concerned about some of the things that he’s seeing.

Kevin Roose: 25:14 Well, let’s bring him in.

Kevin Roose: 25:16 Nikesh Arora, welcome to Hard Fork.

Nikesh Arora: 25:18 Well, thank you for having me.

Kevin Roose: 25:21 I want to just start with your account of what it feels like to run a major cybersecurity company right now. I feel like Casey and I have talked with people at these companies for many years, usually because something terrible has happened, and I feel like the vibe we get is like, ‘this is the worst, most dangerous time ever in cybersecurity.’ What is your subjective experience as someone who’s been in this field for a long time?

Nikesh Arora: 25:43 I’m a little more perhaps relaxed than what you’re trying to ascribe that people come here tell us it’s the worst moment. Historically what’s happened is in the last seven years you’ve seen the time from somebody breaching an organization and being able to extract crown jewels has been measured in days. Unfortunately, with the emergence of AI, the arrival of advanced technologies, that time frame has shrunk down to minutes. And when that happens in minutes, your defense systems have to be able to be activated and defend yourselves in minutes. And fundamentally cybersecurity infrastructure was designed for days, some parts of it are making it to seconds, the good parts where you know how to stop them, but we have to go basically over all the back-end infrastructure to make sure it’s AI-ready so we can fight AI with AI. So you’re seeing people like Anthropic launch models like Mythos, you’re seeing OpenAI do that at 5.5 Cyber, they’re showing you the art of the possible from a bad actor perspective. So we have to make sure we move as fast as them or faster perhaps to try and plug those holes, make the infrastructure better.

Kevin Roose: 26:44 So your company recently put out a report on some patches that you all had made to your own systems.

Nikesh Arora: 26:51 Yes.

Kevin Roose: 26:52 You disclosed 26 critical exploits covering 75 issues and you said that’s against a typical baseline of under five.

Casey Newton: 27:00 So is — meaning that they discovered like five times as many in a comparable period?

Nikesh Arora: 27:05 Five to seven times, yeah, depending on—

Casey Newton: 27:06 Yeah, so is that pretty standard for what kind of spike you all are seeing in exploits or discovered exploits as a result of Mythos and similar models?

Nikesh Arora: 27:16 So look, what we’ve discovered, some of the newer models that have come out in the last few weeks, perhaps a month or so, is AI models are getting really good at coding. Well, guess what? As the models start to understand what good code looks like, they also start developing an understanding of what bad code looks like. So if you point this model and say, ‘Okay, now look through all this code repository I have and find me bad code’, it will. And unfortunately, humans have been writing bad code for a very long time. So on average, we’ll find about one-fifth to one-seventh of what was found in the last six weeks using these models. Now, of course, we ran a concerted effort to see what the models are going to find. We had hundreds of engineers working on it to make sure we look under every rock, run every product through it. So it’s almost like this is a great cleansing. It’s a great cleansing moment. We found seven times the volume that we would have normally found in a normal period. It’s not going to happen again, hopefully, because we have hopefully cleared out a whole bunch of the tech debt or the vulnerability debt. But I think a lot of organizations will have to go through this moment to understand how much of their code written in the past suffers from these vulnerabilities. They’ll have to do their own work, they’ll have to make sure that it’s fixed. And I think the challenge we’re going to run into is most companies use a large corpus of open source, and open source doesn’t get patched or remediated as quickly as your own proprietary code can. The other thing we found very interestingly with Mythos and other models is it’s really good at daisy chaining vulnerabilities. And that’s what needs to be sort of contended for.

Kevin Roose: 28:43 I’m trying to get a sense of the scale of this issue, because I feel like within the past few weeks, I’ve heard a lot of stories like the one you just described about your own company. Mozilla has been publishing blog posts about discovering hundreds of bugs over a period where maybe previously they only would have discovered a couple of dozen. My sense is that as more companies sort of undertake this audit, they’re gonna find that they have similar problems. So what is the time scale that we might expect these kinds of issues to be fixed? And is there enough time to fix particularly like critical infrastructure before our adversaries gain access to similarly capable models?

Nikesh Arora: 29:24 That’s a great question, Kevin. And that’s what should keep us up at night. Because not every organization has resources to fix code that could have been written 20 years ago. Now, the good news is that pretty much most of the cyber defenders have had access to the model. They understand the scale and enormity of the problem to some degree. I think what we have been able to do is we’ve been able to enlist the support of many of the system integrators in the world, like the IBMs, the Pricewaterhouses, the Deloittes, the Accentures, etc., who are all rallying to make sure they make resources available to many of these customers to be able to patch these things. We are in the midst of sort of testing in interesting solve where we can once we know the vulnerabilities in an organization, we can write signatures into our perimeter defense firewalls to say, if you see somebody trying to go in this direction, we know there’s an unpatched piece of code behind it, block them.

Nikesh Arora: 30:21 So we can create a temporary scaffolding to let organizations have a little bit more time to go fix their vulnerabilities, but it has to be done. And the risk like you rightly articulated is that open source or nation states or third parties can start building models that are similar to what Anthropic or OpenAI have built, and the risk is that they get there faster than the patches have been enabled in many enterprises.

Kevin Roose: 30:43 Yeah. I want to understand a little bit more about the defense side of this. Now that you have access to this Mythos model, there’s been a lot written about it. It’s the subject of much debate at the highest levels of power. And I kind of just want to ask, what is it like to use it? Does it feel different than using like Claude? If you’ve used another Anthropic product, does it feel kind of the same? Or just like, what is it like to use Mythos?

Nikesh Arora: 30:59 In the beginning, it was not that impactful because when you’re looking for bad code, it’s going to find everything. Remember, it’s 50% false positive. So it’s not like always going to get the right thing, but unfortunately we got to go test every one of them out to see which is real. But what became more and more fascinating, the more context we gave it, the better it became.

Casey Newton: 31:29 What do you mean?

Nikesh Arora: 31:31 Well, you show it a piece of code, it doesn’t know what the code is trying to achieve. So you have to give it context and say, well, this code works…

Kevin Roose: 31:36 So you’re not just pointing it and saying, go test this firewall and tell me what you find. You’re actually giving it some instructions beyond that.

Nikesh Arora: 31:43 You have to give it context in terms of what is the purpose of the code, what does it do, what is normal behavior supposed to look like? Then you have to give it more context in terms of other threat research. Like the models don’t have all the threat research involved. We sit on hoards of threat data saying this is how 10,000 attacks have been conducted in the past five years, which is the data we store, we hold because we write machine learning algorithms to protect against those instances. So we say, oh, we’re arming you with all the past known techniques that have been used. Can you see if some of those known techniques can be applied in this scenario? Effectively, we’re giving all the human training of the past to make sure that in the future, you can build defense against those techniques.

Kevin Roose: 32:20 Yeah. You mentioned using both Mythos and GPT-5.5 Cyber. I’m curious, in your mind, how comparable those models are. Are they in the same class, or is one different than the other?

Nikesh Arora: 32:35 The most fascinating part is that they both found different things, which tells you that based on their grounding, their training, whatever they’ve been used to train it, some of them was one of them was better at certain things, the other one was better at some other things. But just tells you that there is still a lot that’s going to get found.

Kevin Roose: 32:47 I mean, one thing that stuck out to me as I was reading some of your blog posts and your sort of postmortems about your experiments with Mythos is, if a cybersecurity company is finding five to seven times more vulnerabilities using this model like the average bank, the average insurance company…

Kevin Roose: 33:05 Just say nothing of Kevin’s personal website.

Casey Newton: 33:08 My personal website. We’re going to be looking at many multiples of that, right? Or is it the case that everything is so centralized and runs through just a few platforms that the average institution is not as screwed as I think they are?

Nikesh Arora: 33:20 I wouldn’t say the average institution is screwed. I think, look, there’s a lot of work that needs to be done. It’s not just good at finding vulnerabilities. The other thing we also found as part of our testing, it can even take a look at products you might be using perhaps to power your website which you may have misconfigured. That’s not a vulnerability. That’s human error in the way you’ve used the product, or you’ve left the door open. For example, many people will take products and say, ‘Ah, it’s easier if this control pane of this product was accessible from home or from the internet so I could just go access it from wherever I am and manage this thing.’ Well, you should not leave control panes of most products in your company exposed to the internet, because if I can find it, other people can find it too.

Casey Newton: 33:59 Right. When Mithos was first announced, there were a lot of people who were very skeptical. They said, ‘Oh, this is just marketing hype’ or ‘Anthropic doesn’t have the compute to serve this model, which is why they’re only releasing it to a select group of companies.’ A month or so later, do you still hear that kind of thing from people in your industry that maybe this isn’t the sort of apocalyptic moment that Anthropic and others have said?

Nikesh Arora: 34:25 I look at it slightly from a longer-term perspective. I think what the Mithos model showed is what the art of the possible is going to be in the future. Once we are compute-unconstrained or we have better models in the future which are trained better. So it sort of gave us a window into what’s coming, which I think was very useful. I think that’s a bit of a tough rap towards Mithos that they did this on purpose. You have to remember, these companies, whether it’s OpenAI or Anthropic, they’re sort of working their way trying to understand how to do this. Both them and OpenAI want to do it right. They want to do it so that AI is not used in a bad way. I think they were trying to do the right thing. I think there is no easy solve to this. I give them marks for trying to do the right thing, and I think they sort of partly got most of it right, some of it they fumbled on the way there, but credit to both of them for trying to get it done right.

Kevin Roose: 35:18 Speaking of how we fix this, so for decades cyber security has operated using this sort of 90-day responsible disclosure window. Like I find something, I find a bug, I sort of privately notify you, but in 90 days I’m going to go public with this so you better get your act together and fix it. And companies often do take 90 days or longer to sort of implement those bug fixes. So I read a blog post this week by a researcher named Himanshu Anand who wrote that in his opinion the 90-day responsible disclosure window is dead. I also saw that in your own company’s blog post last week you guys said that within 25 minutes in an AI-assisted scenario, somebody could get initial access to a system and exfiltrate the data. So do you agree that this 90-day window is dead? And if so, what the heck do we do about it?

Nikesh Arora: 36:07 Look, I think the principle of the 90-day window is to allow the owners of the product or the piece of software or piece of code to have enough of time to investigate, to fix it, and make sure their customers are secured. I think the 90-day window is going to shrink, as you have rightly articulated. Now, how much does it shrink is still up for debate. How long do we have? Think about for what we just did. We announced this morning that we’ve patched almost 30 critical vulnerabilities. We’ve known about these for two or three weeks. We’ve had that time to go test it, we’ve had time build patches, we’ve pretty much deployed everything that’s available from a SaaS software perspective. So challenge is not the SaaS software, right? SaaS software you can find, you can fix, you can deploy, it’s not a problem. The challenge is when there’s a laptop sitting in front of you and I’ve got to go make sure you update your laptop because you’re required to do something with it.

Kevin Roose: 36:54 And I can tell you, he will go like six months without installing the mandatory updates. I’m not even kidding.

Casey Newton: 36:58 Delay, delay, delay. I mean, I am starting to see more of those just in my products, and I’m getting more requests to update system software. Is that Mythos related? Like, no seriously, every time I see it, I’m like, oh, what did Mythos find now? So are we starting to see as consumers evidence that some of these systems are needing to be patched more frequently?

Nikesh Arora: 37:14 I think there is going to be, as I said, there is going to be the cleansing of the vulnerability backlog that’s been built over the years. So you will most likely experience, in the next three to six months, if you’re an enterprise, you’ll experience it in a lot more boxes that you buy. You buy servers, you buy switches, you buy routers, all those things where you have code lying on them will have to be looked at and will have to be patched or upgraded over time. So you’re going to see some of that cleansing happen, but hopefully you can power through it and get to the other side.

Kevin Roose: 37:35 But it sounds like it is just a good time to install those software updates when you get them.

Nikesh Arora: 37:40 I highly recommend you do that.

Kevin Roose: 37:41 One persistent question about these kind of models is whether they favor attackers or defenders. So I guess I’m just going to put that question to you, is this technology better for people who want to break into systems or people who want to safeguard systems? And if you had attackers and defenders with an equal model, who would win?

Nikesh Arora: 37:58 That’s a great question.

Kevin Roose: 37:59 The classic Batman versus Superman.

Nikesh Arora: 38:00 Remember, it’s an unbalanced fight to start with. We have to be right 100% of the time, the bad guys have to be right once. So it’s an uneven playing field from that perspective. So the model, if you can find five vulnerabilities and you can exploit one of them, it’s a win for them and a loss for us. It doesn’t matter if we protect you on the other four. We don’t get 80% grade for protecting the other four, we get zero because it was able to find something to breach it. So for now, the bad actor is most likely able to use it much better than the good people. But that’s not a model constraint or model fault, it’s because the model doesn’t protect, remember? The sensors protect. The sensors we apply around your perimeter protect. The sensor has to be smart enough to understand what the model’s going to find. And that’s why the fact that we got this window of four to six weeks to test them and to understand them, we’re busy building defense techniques to make sure that as this tsunami of AI-based attacks starts to arrive, we have enough defense capability, which is still powered by AI to give us a real-time response that we need.

Kevin Roose: 39:20 Is there a sector of the economy that you’re most worried about when it comes to cyber security and the new capabilities of AI systems?

Nikesh Arora: 39:29 You know, the challenge always is the companies which use technology where their core business is 95% something else and the 5% part is technology, and you can take that to mean small businesses, you can take that to mean sort of core industrial manufacturing output type businesses where they’re not spending as much time thinking about the technology, they’re busy digging for gold or building infrastructure for something else…

Casey Newton: 40:00 Or hospitals, you know, they use technology.

Nikesh Arora: 40:01 Exactly.

Kevin Roose: 40:02 So you’re worried about the non-tech businesses that may not have as many resources or as many engineers working on them.

Nikesh Arora: 40:06 Yes. And I’m not worried about financial institutions. They have more engineers than I do. So they will go rally against it, they’ll put the resources to work and they’ve been protecting themselves for a very long time. They understand the implication to these things. So it’s like, poor doctor’s office… remember that there was a breach that happened I think almost a year ago now, it was actually more, of Change Healthcare, which caused a whole bunch of the entire physician ecosystem to come to a halt. And the physician didn’t know what to do about it.

Casey Newton: 40:31 I mean, for the moment, do you sort of breathe a sigh of relief that these models are not generally available, or do you think they could be released and it wouldn’t be that big of a deal?

Nikesh Arora: 40:40 Well it’s like, they have been released, right? Both Opus 4.7 Cyber and OpenAI’s 5.5 have both been released with cyber capabilities and guardrails.

Casey Newton: 40:53 But not Amithos.

Nikesh Arora: 40:56 Amithos has another unique property which perhaps goes towards your conversation about constraints, is that Amithos runs in Ultra mode. Ultra mode is a compute consumptive mode which allows the model to persist for much longer than the Flash mode that most models are released in.

Kevin Roose: 41:05 So interesting, it can just work for a lot longer, spend a lot more compute than other models.

Nikesh Arora: 41:10 That’s right. So the compute cost is from the persistence perhaps, not from the capability. And the persistence allows the daisy chaining to happen much more effectively, right? Because it’s trying different techniques trying to see which one’s most likely to work. So that’s what causes the daisy chaining to happen in more effective fashion.

Kevin Roose: 41:27 So is it a good thing that the average person doesn’t have access to that right now?

Nikesh Arora: 41:31 I think so. I think every company should have a chance to be able to fix these things in the meantime. But again, I don’t know who the average person is in this case. Is every company out there an average person? Then they should have access to it because they have to fix it.

Casey Newton: 41:44 You mean the average bad person?

Kevin Roose: 41:46 Basically. I mean I’m just thinking about all of these cyber attacks that we’ve seen just over the past couple of weeks and I’m assuming that they do not have access to an Amithos level model and so I’m just asking myself like well what if they did?

Nikesh Arora: 41:57 Yeah, what if they did? They’ll find a way to attack companies much faster. I don’t think the nature of the attacks will change, but the speed will. I don’t see the nature of the outcomes change. Most likely they will be used to leverage ransomware, or perhaps cause economic harm if you’re looking at it from a nation-state perspective. So I think the entire set of fundamentals of how the bad-actor industry works is not going to change. What it does change is the pace and the volume, perhaps, of attacks are going to be made possible because of the availability of these models.

Kevin Roose: 42:21 I want to talk a little bit about what, if anything, an average person can do here. I myself am the subject of an ongoing phishing attack where—

Nikesh Arora: 42:32 Somebody must like you.

Kevin Roose: 42:33 I mean, I hope so. But basically, almost every day, somebody tries to get me to reset my X password from an email address that has nothing to do with x.com. And because I’m looking at my emails on the desktop, that’s very easy for me to see and I’m not fooled.

Casey Newton: 42:46 That’s me. I’ve been trying to stay relevant.

Kevin Roose: 42:48 Casey, how could you? But I also believe that within six months or a year, one of those emails is going to come in and it’s just going to look way more convincing. It’s going to figure out a way to trick me. And one of my frustrations with talking about cybersecurity in general is that it tends to leave people with this sense of like, ‘Well, everything’s really bad, sorry, good luck to you.’ Usually we give people advice like create a strong password and use multi-factor authentication. Is that good enough, or do people need to update the playbook?

Nikesh Arora: 43:21 Look, I think one of the things that my frustration has always been is that if you think about it, we have much better cybersecurity solutions in the enterprise world than we do for the consumers. For example, if you had a corporate email, and all the phishing attacks were coming to your corporate email, or spam was coming to your corporate email, we’d be pretty good at sussing these out because the X email address that you talk about that you’re getting, which is not actually X, we see it in one customer, we’ll block it everywhere else. Now the problem is the consumer world doesn’t have any such gatekeepers. Because we’re effectively the gatekeepers of enterprise, but consumer world doesn’t have gatekeepers. The consumer gatekeepers are the email providers. The consumer gatekeepers are the telecom networks that give us, if you were getting sort of an attack on your corporate mobile device and we were sitting in front of it, it won’t happen. But on our personal devices, we can all get spammed, we can all get phished, we can all get all this stuff happen to us. So part of the frustration I have is that there are some consumer companies that need to implement better cyber controls for all of us consumers, which they’re not.

Kevin Roose: 44:18 Well, like, any particular controls come to mind that you’d like to see out there?

Nikesh Arora: 44:23 Well, think about the email. I mean, is it hard for the email provider to figure out that this is not an X email address? I mean, these are the same guys that are building AI, right?

Casey Newton: 44:33 These guys are building AI that’s going to anticipate what we want and do it for us, so somebody just needs to pay attention to it.

Kevin Roose: 44:40 That’s sort of funny. I mean, for what it’s worth though, this is like my paid Google Workspace for my work account and you’re absolutely right. It seems like a very simple classifier that Google makes to just be like, ‘Hmm, this probably isn’t coming from x.com.’

Casey Newton: 44:51 How are your engineers feeling about all this? I imagine they’re working a lot these days. Are they excited because there’s this new tool, new set of tools available to them?

Kevin Roose: 45:00 Are they stressed out because all of a sudden their workload just got five times bigger? What is the mood?

Nikesh Arora: 45:05 Yes. All of it. Look, if you think about it, if you’re a technologist, this is a phenomenal time to be doing this. The amount of opportunity to learn, the amount of opportunity to understand. Some of the people are fearful, like how is this thing going to work? And then you can find every emotion you can think of is probably in every engineering team out there. We have 9,000-plus technical people. I think every emotion is being sort of expressed in every one of them because it’s not just the tool in front of us, it’s the uncertainty of what this holds in the next two, three years. People are seeing OpenInterpreter being deployed. Now OpenInterpreter is a scary thing from security perspective. It’s going to take all your permissions, all your credentials, do all kinds of stuff for you. There’s nowhere to govern it, nowhere to control it, but it’s cool. So the early adopters are doing cool shit. I had dinner with somebody came to my house like, ‘I got OpenInterpreter on my phone, it’s doing everything I’m asking it to do.’ And the guy sitting next to us says, ‘Holy shit, that’s a security nightmare. You’re worried about your X, AI, X post to change your password? You don’t need to change your password. OpenInterpreter is just going to tweet on your behalf because it had a moment last night.’

Kevin Roose: 46:16 Totally.

Nikesh Arora: 46:17 Right? Yeah.

Kevin Roose: 46:18 Yeah, and for all of my objectionable tweets over the years, I would like to just formally say that was my OpenInterpreter acting autonomously.

Nikesh Arora: 46:25 There we go.

Casey Newton: 46:28 So are you personally running any of these insecure — like are you running OpenInterpreter, are you experimenting with this stuff just from like a I need to understand the landscape perspective?

Nikesh Arora: 46:35 On a segregated device which has no connection to many of my things, which makes it totally useless by the way, because it can’t even book a meeting on my schedule because it doesn’t have access to my schedule. It can’t respond to an email on my behalf because it doesn’t have access to my email. So I’m still sort of using it the old fashioned way, which is I’m using Gemini in the enterprise. I did do that, I took my earnings script, sent it to Gemini and said what do you think? Two quarters ago it says, ‘Are you trying to hide something? You’re too enthusiastic, use the word momentum and excited too much more than you normally use.’ I’m like, holy shit, that’s not bad. So I had to tone it down.

Kevin Roose: 47:08 Yeah.

Kevin Roose: 47:10 That’s very funny.

Kevin Roose: 47:11 Is it changing your hiring plans at all? I mean you employ thousands of cybersecurity engineers and researchers. You may need fewer of those people in the future?

Nikesh Arora: 47:22 No. I need more. I think this is the fallacy out there. The fallacy is that organizations are going to get 30, 40, 50, 60 percent more productive from a development perspective and a testing perspective, so we need less people. The problem is every technologist that you talk to has a feature request list which is long as their arm, and typically people have product roadmaps that are six to 12 months out. Why is that? Because they don’t have enough people or they cannot serialize something because it takes a lot of effort to get it done. So I think the first thing that’s going to happen is as we create more capacity, we’re going to try and fill the technological backlog and try and make that work. I do understand at some point there are people out there, I’ll call it reshaping their technical organizations by creating capacities. Everybody who’s out there saying, “I’m reducing my headcount by 7% or 15% or 20%,” which you’re beginning to see recently, I think they’re just creating capacity. They’re saying that capacity allows me to hire more people and make room for people that I need who have the newer skill set.

Kevin Roose: 48:19 Hmm. They’re not just spending that salary money on tokens instead?

Nikesh Arora: 48:23 Look, I think that the interesting part is, as I was saying this earlier, the part we don’t realize, that we’re dealing with a tsunami of a desire to transform. I think we’re in a decade-long transformation of business ahead of us. Imagine, you have a new technology. My CFO would never come and say, “I want to use AI to transform my team.” He wants to transform his team and see if he can do it much more efficiently, but he wants AI. My head of HR wants AI because she wants to create an AI interviewer, an AI assessor, instead of having humans do it. So every function wants more AI to deploy. Now the question is, where’s the money going to come from? It’s probably going to come from efficiency in those teams, those functions. So that’s what’s going to pay for the tokens.

Kevin Roose: 49:07 I have to say, I don’t think anyone wants to be interviewed by the AI assessor. That’s not a good vibe, you know? I don’t know.

Casey Newton: 49:15 You think — would you want to be interviewed, like, for a job by an AI?

Nikesh Arora: 49:21 I think AI’s most likely going to be better at assessing my domain skills than a human being.

Kevin Roose: 49:27 Really?

Nikesh Arora: 49:28 Yes. If you’re trying to hire a good coder, if you’re trying to hire somebody who knows agentic AI really well, sitting and talking to them is not going to get me a better answer if they can sit and code and deploy open-core in front of me. It’s like — I’ll tell you I’ve done that interview. The guy says, “Well, I’m really conversant with AI.” I’m like, “Really? That’s cool. What have you done?” It’s like, “Well, I built myself an agent.” I’m like, “Show me.” It’s like, “What do you mean?” I’m like, “You’re on Zoom. Show me.” Then you see this bizarre, like simplistic, “Oh, I got it to make a shopping list from the recipe I saw.” I’m like, “Dude.”

Casey Newton: 50:04 It’s an AI girlfriend. It’s — actually, I shouldn’t show you.

Kevin Roose: 50:08 Yeah. And now we have an HR problem.

Nikesh Arora: 50:11 Yeah.

Kevin Roose: 50:12 Um, well, Nikesh, thanks so much for coming in. Really great to talk to you, and good luck out there.

Nikesh Arora: 50:22 Thanks, Kevin.

Casey Newton: 50:24 Fascinating. Please tell Mythos to spare our families in the coming uprising.

Kevin Roose: 50:28 When we come back, all aboard for another installment of the Hot Mess Express.

Casey Newton: 50:35 Well, Kevin, we’ve got a train to catch today. The Hot Mess Express is here.

Kevin Roose: 50:40 The Hot Mess Express is, of course, our segment where we take a look at the various calamities befalling people in and around the tech industry and at the end of discussing them, decide what kind of mess was that. What’s pulling up to the station today?

Casey Newton: 51:01 Our first story today comes from The Verge — oh, and this is truly the end of an era. Venmo is starting to test a big redesign of its app, and as part of the changes, Kevin, it will be implementing a major new privacy feature: the onboarding process for new users will set their posts to only be viewable by their friends by default instead of being public.

Kevin Roose: 51:25 And this is very sad for me because for years now, every time I’ve opened up Venmo to pay a friend, I’ve seen a recent transaction from someone I hooked up with once in 2016.

Casey Newton: 51:30 And the thought that other people aren’t going to have that experience makes me really sad. So as a nosy person who loves to gossip, I am sad about this story because it was always fun to see which of your random phone contacts had been paying their fractional share of the rent or back for dinner.

Kevin Roose: 51:43 People put various jokey things on their transactions, illicit drug deal, foreign arms trade, etc. And it’s just sad that we won’t get to experience that.

Casey Newton: 51:59 Yeah, also, the public-by-default Venmo transactions gave us many great stories over the years, including Joe Biden’s secret Venmo, which was a BuzzFeed story, JD Vance had a public Venmo that Wired reported on, Matt Gaetz’s Venmo payments were part of a federal inquiry into his payments to women, according to the New York Times. So, I guess all of us investigative reporters are going to have to find a new easy way of writing a story, Kevin.

Kevin Roose: 52:21 Yeah, now the only baffling security breach from these apps is that Telegram still does notify you when one of your phone contacts joins. And I always love to screenshot that and send it to people and be like, ‘Crypto or drugs? Which is it this week?’

Casey Newton: 52:34 The only two possible answers. So, what kind of mess is this Venmo mess?

Kevin Roose: 52:38 This is unfortunately a cleanup, not a mess. This used to be a very hot mess and now, you know, belatedly, it is getting cleaned up.

Casey Newton: 52:48 Fair enough. All right, RIP. Let’s see what else is coming down the tracks.

Casey Newton: 52:55 Oh, well, this was interesting, Kevin, and ties in closely to something that you’ve written about recently. Amazon has started to widely deploy its in-house Mesh Claw product in recent weeks, which allows employees to create AI agents that can connect to workplace software and carry out tasks on a user’s behalf. But some employees are saying that colleagues are using the software to automate additional unnecessary AI activity to increase their consumption of tokens, which will then, of course, make them look better to their bosses. So, did we see that one coming or what?

Kevin Roose: 53:26 Yeah, I believe you invoked Goodhart’s Law about what happens when a target becomes a measure — or a measure becomes a target.

Casey Newton: 53:38 When a measure becomes a target, it ceases to become a good measure is of course Goodhart’s Law.

Kevin Roose: 53:44 Thank you so much for that. Yes, and I imagine that at the famously frugal Amazon, they are looking at having this era of people just spending a bunch of random tokens to move up the leaderboard. Here’s the thing. I talked to a lot of Amazon employees over the years. Tokens are the only thing at that company that is free. You want a diet coke from the vending machine, get out your wallet, okay? So these guys finally find something free and now they’re getting in trouble.

Casey Newton: 54:19 Yeah. The good news is they have unlimited tokens. The bad news is they can only use them on Mesh Claw.

Kevin Roose: 54:25 Yeah, I’m gonna say that this is actually a hot mesh. And that’s what kind of mess this is.

Casey Newton: 54:29 Very good.

Casey Newton: 54:30 All right. Next up, Kevin. This comes to us from 404 Media and boy did I see this clip in about 14 different places over the past week. Students boo commencement speaker after she calls AI quote the next industrial revolution. You see this one?

Kevin Roose: 54:46 Yes. Yes, so May 8th, commencement speaker Gloria Caulfield, who’s the vice president of strategic alliances at Tavistock Group, told graduates of the University of Central Florida’s College of Arts and Humanities and Nicholson School of Communication that AI is the next industrial revolution. She was met with thousands of booing graduates and someone in the crowd, Kevin, yelled “AI sucks!”

Casey Newton: 55:29 So, what did you make of this commencement moment?

Kevin Roose: 55:32 Here’s my thing. Students are allowed to feel however they want about AI. But if you boo the commencement speaker for suggesting that AI is a big deal, I want to see your ChatGPT history. If you have used AI to write your exams, to help you with your problem sets, in any way for your academic work, you are not allowed to boo it at commencement. That is my rule.

Casey Newton: 55:46 I don’t know, I think these students were fine to boo. I mean, Ms. Caulfield was after all addressing the College of the Arts and Humanities, who I’m guessing is probably not the group of students at the university that are most excited to see AI come into their lives. Here’s the thing that I’ll say that is sincere. I think people are radically underestimating how mobilized young people are against AI right now. I see this every time I go to a college to talk to students. There’s like a small group of them who are like running open source and very excited and like 80% of them are like I hate this.

Kevin Roose: 56:13 Yeah. So look, if you have to give a commencement speech within the next few months, a highly relatable situation that many of our listeners will be in, now you know. Careful how you talk about AI.

Casey Newton: 56:22 Yeah.

Casey Newton: 56:27 Kevin, our next story comes to us from the good folks at Variety. Dua Lipa has filed a $15 million lawsuit against Samsung for using her face to sell TVs. And this one is honestly pretty incredible. Samsung has apparently used Dua Lipa’s image on the cardboard packaging of its TVs starting last year, when Ms. Lipa became aware of it, she demanded that the company stop using her image and apparently could not get through to anyone at Samsung. So Samsung finally responds on Monday and said this was all the fault of some third party content partner, and Samsung said we have a great respect for Ms. Lipa and the intellectual property of all artists, and they are actively seeking and remain open to a constructive resolution with Ms. Lipa’s team.

Kevin Roose: 57:34 Well, it sounds like a constructive resolution could be taking her face off the packaging and paying her $15 million.

Kevin Roose: 57:43 Yeah, what kind of mess is this?

Casey Newton: 57:45 And I understand her concern because the thing that people always forget about Samsung products is that they do explode when you least expect them. There was of course the famous series of explosions related to their phones. So if I see my face on a Samsung TV, I’m thinking I do not want to be the literal face of an exploding piece of hardware. This is a true hot mess, because the TV could have exploded.

Casey Newton: 57:58 There, you want to read one?

Kevin Roose: 57:59 Alright, this next one comes to us from our colleagues at the New York Times. eBay rejects GameStop’s $55 billion takeover bid. Last week GameStop offered $55 billion to eBay in an unsolicited takeover attempt. According to some interviews, they appeared not to have $55 billion, which would put a damper on their plans. This week eBay officially said no to the GameStop offer, calling it, quote, “neither credible nor attractive”.

Casey Newton: 58:31 Which is also what our last iTunes review of this podcast said.

Casey Newton: 58:34 And there you have it. This one’s an interesting story from the world of what I like to call companies that I can’t believe still exist. I don’t know what’s happening on eBay, I don’t know what’s happening on GameStop. But what I do know is these companies probably don’t belong together, Kevin.

Kevin Roose: 58:47 Yeah, I find this fascinating because it is just like the internet brained CEO of GameStop is this guy Ryan Cohen who’s like sort of rose to prominence during the meme stock mania of like 2020 and 2021. And now you can just do whatever you want. If you’re the CEO of a company, you can just say we’re gonna buy a company that’s like five times bigger than us. How? Shame on you for asking.

Casey Newton: 59:21 I mean, is it unreasonable given their history to expect that he could have announced this and GameStop stock could have gone through the roof and all of a sudden they would have had $55 billion for eBay? But that didn’t happen.

Kevin Roose: 59:32 Well, if they’d done this deal in typical GameStop fashion, they would have offered about half of what the market value for eBay was because it’s used and probably doesn’t even work on your console anymore.

Casey Newton: 59:44 I like jokes that you’ll only get if you have returned a video game to GameStop.

Kevin Roose: 59:50 Listen, for our younger listeners, there used to be a time when you could walk into GameStop with a box of old video games that you wanted to get rid of and they would offer you between 50 cents and $1 for each video game.

Casey Newton: 59:59 Alright, this is the sort of mess where we…

Kevin Roose: 1:00:00 We’re explaining the joke.

Casey Newton: 1:00:01 Okay. So, Shein and Temu are fighting it out in UK courts, Kevin, as Shein has accused Temu of, quote, astonishing levels of copyright infringement, and Temu accused Shein of waging, quote, an aggressive and relentless battle using copyright allegations to undermine competition. This comes to us from Bloomberg, and the whole trial revolves around thousands of photographs that Shein says are from its website. According to Shein’s lawyers, Temu sold identical clothing items using the same images and is seeking to piggyback off Shein’s own investment in building up its supply chain and training and upskilling suppliers. What do you make of this fight?

Kevin Roose: 1:00:41 The fast fashion brands are fighting!

Casey Newton: 1:00:43 They’re fighting.

Kevin Roose: 1:00:44 They’re fighting. There’s no one I’m rooting for in this fight. I’ve never bought an item of clothing from either of them, but it is very funny that two of the brands who have made their sort of entire existence ripping off the clothing from more established purveyors are now fighting each other about which one’s ripping off the other one.

Casey Newton: 1:01:00 Yeah, truly a situation where is there a way they both could lose and learn a hard lesson about intellectual property? We’re rooting for them.

Casey Newton: 1:01:08 Next up, a favorite story of the week, Kevin, and I imagine you heard about this one. People are seriously pissed that Grindr outed them with its latest Madonna advert. Did this happen to you?

Kevin Roose: 1:01:21 No.

Casey Newton: 1:01:21 Okay. So this issue stems from the fact that Madonna has been doing this big campaign inside of Grindr to promote her upcoming album, Confessions on a Dance Floor 2, which is a concept album about a 68-year-old woman who still wants to be at a nightclub like after midnight. And she’s advertising on Grindr. And apparently over the past week, when you opened up Grindr, even if you had your phone volume turned off, you would hear a sound of Madonna saying loudly, ‘Hi Grindr, it’s mother.’

Kevin Roose: 1:01:54 No!

Casey Newton: 1:01:54 Which first of all, it’s grandmother. Sorry. Second of all, apparently people who are not out to their families were opening Grindr at the dinner table, which, you know, you’re already sort of putting yourself in harm’s way there maybe, but the last thing they expected was to have Madonna being like, ‘Hey, look at this guy. He’s on Grindr right now.’ So truly one of the most misconceived ad campaigns in recent history.

Kevin Roose: 1:02:23 Wow, that’s so wild. It’s like if they put U2’s Songs of Innocence on your phone, but it just outed you to your family.

Casey Newton: 1:02:30 The song was ‘You’re Gay.’ That was the song.

Kevin Roose: 1:02:33 Yeah.

Casey Newton: 1:02:34 This is a dangerous mess. It is not always safe for people to be outed to people in their immediate surroundings. So, shame on Grindr. They really should have known better.

Kevin Roose: 1:02:44 Yes. Push notifications should be illegal.

Casey Newton: 1:02:47 All right, and one more car coming down the train tracks here, Kevin. This is from the Elon OpenAI trial this week. Sam Altman was on the witness stand Tuesday and testified that at one point Elon thought he should run OpenAI. Sam asked him, hey, what do you think would happen to the company if you died? And according to Sam, Elon replied, I haven’t thought about it a ton, but maybe control should pass to my children?

Kevin Roose: 1:03:12 Question mark, question mark, question mark.

Casey Newton: 1:03:14 So, what do you think? Do you, let me just ask it this way, do you think we would be better off if OpenAI was a hereditary monarchy controlled by the Musk clan?

Kevin Roose: 1:03:24 I do. I think that really is the ideal. We always talk about what is the ideal governance structure for AGI? I think we can all agree that it would be best if Elon’s 27 children were involved somehow.

Casey Newton: 1:03:41 Yeah, or just you know, I don’t know, they pick one at random. One is probably I don’t know, 11 years old and rides a skateboard around town. They’re like, alright kid, you run AGI now. Best of luck. So, yeah, that continues to be a legal mess.

Kevin Roose: 1:03:51 Yeah, the whole trial has just been fascinating to me, less because I care about the actual like legal issue on trial, and more because it has just produced all these amazing and incriminating files from like the early days of OpenAI, including all of their texts and emails and messy drama. I live for it.

Casey Newton: 1:04:08 Yeah, just look, it’s very hard to run a successful company without a lot of executives saying a bunch of really stupid things and writing them down. We just see it over and over again.

Kevin Roose: 1:04:17 Yeah. So let that be a lesson to us.

Casey Newton: 1:04:20 Yep.

Kevin Roose: 1:04:21 Hot mess!

Casey Newton: 1:04:23 And that is it for the Hot Mess Express. Thank you to all of this week’s passengers and best of luck with your messes. Try to stay on the right side of the track.