Yep, it is well known that AI can/will act unpredictable, if you fail to have operational restrictions that the AI can’t bypass, then you have to be responsible.
An AI/LLM should not have any generic outside access to anything.
And any access should be limited to the bare minimum to do it’s job.
You want it to have access to your calendar?
Ok what level of access do you mean?
Read Free/Busy?
Read the title of meetings?
Read the contents of meetings?
Accept/decline meeting requests?
Make new meetings?
Edit existing meetings?
Delete meetings?
And so on, one of the worst things we can do with AI/LLMs is to assume what it will do and act on that rather than to actually set real rules for it.
AI/LLMs does not understand reason, it doesn’t understand unwritten rules, every rule has to be set up outside of the AI/LLM chat, and use the philosophy that anything not explicitly allowed is blocked.
That is exactly what I wrote, I pointed out that the the rules defined for the AI/LLM has to be external of the AI/LLM, like a network firewall but more sophisticated.
It’s not exactly what you wrote, you only explicitly wrote it doesn’t follow unwritten rules. I think we are both being pedantic over the basic premise though, LLM output dumb.
I am glad we both see the extreme caution we need to treat AI/LLMs with.
Wait, I just think I figured something out…
What is the deterrent for humans to not break rules?
We don’t want the consequences that would impart.
An AI or LLM is not advanced enough to understand consequences these days, so they don’t matter, other than to act as an input to compose a suitable reply according to the LLM.
I have known this logically for a long time, but this is the first time I made the actual intellectual connection and actually understood cause and effect.
Probably old news, but having a moment of realization like this is always fun and interesting.
That’s also the problem though, question is where do we put the controls, lets say on the meeting callendar. The obvious is we do it like humans, we have a calendar program, and the AI program is like a human. We set it’s permissions based what it needs at the calendar level. If it has read only access for instance, it won’t accomplish the goal of “summarize everything I need to do in 2 sentances”, by deleting everything your calendar except for 2 items that it can summarize. except the problem is, the AI has more information than it needs to have, IE it’s got leaked security bullitans that the calendar program you are using has a privilage escalation, or it guesses the IT guys admin passwords, etc…
The only real workaround is, more narrowly trained AIs. instead of trying to make every model know every field. they should really be training 100’s different models into specialties. Fact is the customer service AI’s shouldn’t know how to write python scripts period. and honestly that’s probably the biggest thing that makes them bad at their jobs, and waste so much power and resources to do simple tasks. The idea of “one super AI” is IMO the core stupidest part of the AI rush.
Yep, it is well known that AI can/will act unpredictable, if you fail to have operational restrictions that the AI can’t bypass, then you have to be responsible.
An AI/LLM should not have any generic outside access to anything.
And any access should be limited to the bare minimum to do it’s job.
You want it to have access to your calendar?
Ok what level of access do you mean?
Read Free/Busy?
Read the title of meetings?
Read the contents of meetings?
Accept/decline meeting requests?
Make new meetings?
Edit existing meetings?
Delete meetings?
And so on, one of the worst things we can do with AI/LLMs is to assume what it will do and act on that rather than to actually set real rules for it.
AI/LLMs does not understand reason, it doesn’t understand unwritten rules, every rule has to be set up outside of the AI/LLM chat, and use the philosophy that anything not explicitly allowed is blocked.
It doesn’t understand or follow written rules, never mind unwritten ones.
That is exactly what I wrote, I pointed out that the the rules defined for the AI/LLM has to be external of the AI/LLM, like a network firewall but more sophisticated.
It’s not exactly what you wrote, you only explicitly wrote it doesn’t follow unwritten rules. I think we are both being pedantic over the basic premise though, LLM output dumb.
Fair point!
I am glad we both see the extreme caution we need to treat AI/LLMs with.
Wait, I just think I figured something out…
What is the deterrent for humans to not break rules?
We don’t want the consequences that would impart.
An AI or LLM is not advanced enough to understand consequences these days, so they don’t matter, other than to act as an input to compose a suitable reply according to the LLM.
I have known this logically for a long time, but this is the first time I made the actual intellectual connection and actually understood cause and effect.
Probably old news, but having a moment of realization like this is always fun and interesting.
That’s also the problem though, question is where do we put the controls, lets say on the meeting callendar. The obvious is we do it like humans, we have a calendar program, and the AI program is like a human. We set it’s permissions based what it needs at the calendar level. If it has read only access for instance, it won’t accomplish the goal of “summarize everything I need to do in 2 sentances”, by deleting everything your calendar except for 2 items that it can summarize. except the problem is, the AI has more information than it needs to have, IE it’s got leaked security bullitans that the calendar program you are using has a privilage escalation, or it guesses the IT guys admin passwords, etc…
The only real workaround is, more narrowly trained AIs. instead of trying to make every model know every field. they should really be training 100’s different models into specialties. Fact is the customer service AI’s shouldn’t know how to write python scripts period. and honestly that’s probably the biggest thing that makes them bad at their jobs, and waste so much power and resources to do simple tasks. The idea of “one super AI” is IMO the core stupidest part of the AI rush.