OpenAI vs Anthropic, Cyber Models, and AI Job Subcontracting
YouTube will ask you to confirm your subscription.
About this episode
OpenAI and Anthropic both claim they’re deploying cyber models safely. They just have totally different approaches. OpenAI’s bet: give cyber-defence tools to loads of verified people and let the mess sort itself out. Anthropic’s bet: keep the sharp tools in a smaller room, with fewer keys. Justin’s basically arguing “security works like open source — more eyes, fewer bugs.” Frank’s not buying it. He thinks attack speed will beat defence speed, and “ID checks” won’t stop serious bad actors anyway.
Plus: the leaked OpenAI CRO memo laying out the real strategy (agents, enterprise, and lock-in), the New Yorker piece asking if Altman is the sort of person you’d trust with this much power, and the grim bit where AI fear turns physical — a Molotov cocktail attack on Altman’s home and possible shots fired in a separate incident — followed by Altman saying it’s not right for a few AI labs to make the biggest calls about our future, and calling for a “society-wide response” to new threats.
JOIN THE ARGUMENT
Is open access to powerful cyber AI safer than controlled release?
Sources
Key insights
Is open access to powerful AI actually safer than controlled release?
Opening access spreads both risk and responsibility. More people can exploit vulnerabilities, but more people can fix them too. The real tension is whether collective defence can realistically outpace collective attack, especially when organisations move slower than bad actors.
Can restricted access to dangerous AI meaningfully improve safety?
Restricting access sounds prudent, but it only works if bad actors are genuinely kept out and defenders still get what they need in time. If capable attackers can use other models, frameworks, or front organisations, the safety gain may be smaller than it appears.
Is the real power in AI shifting from models to systems?
The model still matters, but the surrounding system increasingly matters just as much. How AI is deployed, structured, and integrated into workflows may now shape outcomes more than raw model differences alone, especially when capable models can be amplified by better frameworks.
TranscriptThis transcript was generated with AI and may contain errors.Read full transcript
Justin: Hello. Good morning, good afternoon, good evening, and welcome to The AI Argument. It is myself, Justin Collery, joined as with the ever careful and ever conscious, Frank Prendergast. Frank, how’s your week been?
Frank: It has been exhausting, Justin, trying to figure out what the safest way to roll out powerful models is. I just haven’t come up with the answer yet.
Is OpenAI making Anthropic’s caution pointless?
Justin: Well, you’ve come to the right place because today we are going to debate the relative merits of the two big model providers, which currently have models which are too dangerous to be rolled out. We have on one side of the ring OpenAI, do, do, do, do, do, do, do, and their view that they should just release everything and let the world sort it out.
And on the other side of the ring, we have Anthropic and their view that we should only allow a very select number of people who they personally choose to use these models because they’re too dangerous. So that’s the big question for today. What is the right approach? The Anthropic approach is we’re going to control the model. We’re not going to release it yet. And we’ll just give it to some security researchers and let them fix the world’s software before we give the general population the model. Or is it the OpenAI approach, which is we think that we should just release this and allow everybody to fix their software all at the same time? What do you think?
Frank: Well, the scary thing is, no matter what we, no matter where we get to today when we’re chatting about this, if it turns out that Anthropic’s approach, that it should be given to a select group of companies to explore and figure out before it’s released any wider, if it turns out that was the safest option, it won’t matter.
Because OpenAI are giving theirs to anyone who will identify themselves. Because last week, you know, this isn’t hypothetical anymore. Last week we talked about Anthropic releasing Mythos, which is highly cyber capable and able to find vulnerabilities in software much, much faster and easier.
And now this week we have had the release of OpenAI’s 5.4 cyber model, which they are, yeah, taking the approach that you just talked about where, I wouldn’t go as far as say anyone can get access, but you can apply for access, identify yourself. I think the first stage of identification is pretty simple. I’d say you or I could go through the identification and verification and get access to the basic level of more capable cyber models. It’s basically some safeguards taken off some of the existing models we use.
And then if we wanted to, we could contact them directly and explain, if we were in the cybersecurity field, we could explain, look, this is who I am, this is what I’m working on. I would like to get access to 5.5, 5.4 cyber, and they’ll vet the person and give them access. I’m not a hundred percent clear on what the processes are. They’re pretty vague, but I was able to go onto their site and get to that first round of verification. Now, I didn’t go through it because I don’t actually need it, and I didn’t want to draw the attention of myself or give away my personal information for no good reason.
Justin: Don’t we worry about that? Well, look, we’ve been here before, right? So back, if you go back about five years, OpenAI had GPT-2 and they said, oh look, this thing is so dangerous that we can’t release it to the public. And they didn’t. And then they did. When they released 3.5, they were worried that at the time that text was so human-like that people wouldn’t be able to tell the difference between it and whatever AI-generated text, and that that was terribly dangerous. And it wasn’t, right. So, I’m going to put my cards on the table.
Frank: Wasn’t it?
Justin: Not yet, Frank. Not yet, yet to be seen.
Frank: We’re all in the debt, thanks to their decision to release these models.
Justin: This also seems to be a good time yet again to remind Sam I still haven’t got my orb. I’m still waiting. When is my orb coming? Because that would also prove that I’m a human. But anyway, that’s neither here nor there.
Should AI copy open source on security?
Justin: There is a general principle in software that’s existed for a very long time, that making software open source is the safer thing to do. And the reason that making software open source is the safer thing to do is because everybody can see its total transparency. Everybody can see the software and if there’s a problem with it, the community jumps on the problem and fixes it. And the outcome of that approach, right, is that every web server, pretty much on the internet bar none, is run by open source software because it clearly is the safer piece of software.
And incredibly, the approach that OpenAI are taking is actually closer to the open source approach, which is, here’s the model. You can use it. You should now go use it to go and fix your software, so everybody is aware of the security vulnerabilities that exist, as opposed to Anthropic, which is more like a Mac-type view of the world, which is we’re going to make everything closed and we will pick the winners, we will decide who gets to test their software or not.
And I think that the Anthropic approach is inherently more risky because what happens if they don’t pick the right winners? If they miss somebody that should have used it and they didn’t, well then they’ve been the ones who’ve decided to pick the winners and losers. Whereas with the OpenAI approach, it is incumbent on everybody to go and fix their software. And they said, yes, you can get access to it. This is how you get access to the software, right, to the model to test your software. That’s the right thing to do. And if you don’t, then you yourself are responsible, as opposed to the model company being responsible for not fixing your software.
What I’m saying to you, Frank, is what this will lead to is a period potentially when you’re more at risk, right? Right now for the next couple of minutes, months, your software may be more at risk, but at the end of that period, all software will be better as a result, which is exactly what happened with open source software, and therefore the OpenAI approach is actually the better one.
Frank: I can see the argument. I still think, same as when we were talking with Mythos, I just think that the speed of attack is going to be so much faster than the speed of defence. And just because of the way organisations are, because of the fact that the models, because of the fact that basically there is a lot more human involvement in hardening the software than there needs to be in attacking the software. I don’t think, unfortunately, that there is a good answer to this.
And I think ultimately it comes back to what we were saying last week in terms of really, it just shouldn’t be up to these companies. And we’re seeing, we’re kind of seeing why now, as in we have two companies having two totally different approaches. And as I said, if one of them turns out to be safe and the other, it doesn’t really matter because they can do what they want. And so we have these different approaches. What we should have is some form of regulation.
Justin: Well, but you do have regulation here because you have to prove who you are. You’ve got to prove that you’re human, you’ve got to identify yourself, and then you’ve got to go through, I’m sure, what is a very strict three-stage process to get access to the most dangerous security model that’s generally available.
Frank: And identification is no guarantee of safe usage, for want of a better word.
Justin: No, but your usage has been logged, so it’s a guarantee of consequences.
Frank: But what would you do if you were a, what would you do if you were an elite team of, let’s just say some nation’s hackers, some state-sanctioned elite hacking team?
Justin: Yes. Okay. So I’m a baddie.
Frank: What would you do? Because I know what I would do. I would set up a clean front man.
Justin: So I’m a baddie in a James Bond movie.
Frank: Let’s say I want to, let’s say I’m going to hack the Pentagon. I’m not going to just—
Justin: It doesn’t, yeah, if there’s a knock on your door, don’t answer.
Frank: Let’s—
Justin: But it doesn’t matter, right? Because what I’ve been reading from the security researchers this week is that you don’t need a model as capable as Mythos to find exactly the same exploits, and this isn’t—okay. So when this happened first, right, they released and they detailed the exploits and then people said, oh, that’s a load of rubbish. I got a really small model and I found exactly the same exploit. It didn’t. That was a lie. What they did was you had this huge piece of software and they boiled it down into the one tiny bit of code and they said to the small model, can you find the security flaw that exists? Right? So they fed it the answer, right? And so that didn’t—
However, other security researchers this week have come out and said that if you use a very capable model, so an Opus 4.6-type model with the same framework as they used with Mythos, it is likely to find many of the same flaws as Mythos did. So, and this comes back to the thing that the framework is now just as important as the model itself. So if I’m a bad actor, I’m just going to get one of the regular models and I’m going to copy the framework and I’m going to use the existing models to use similar type exploits to hack your system. And so I’ll get around them that way. I don’t think that helps my argument, Frank, as I say it out loud, but you did ask the question, what would I do? And I’m incapable of lying. So that’s what I would do.
Frank: So, yeah, so you’re saying what they do with Mythos and 5.4 cyber is irrelevant because the elite hacking teams don’t need access to them. They’re just going to build better frameworks for the existing frontier models.
Justin: Yeah. Yeah. And let’s be honest, right, if some of those, if some of those, you would have to assume that in the very near future nation-state actors that are not in the US will have access to models which are of a similar calibre to 4.6, 4.7 or Mythos, right? So we live in this world now.
So again, it comes back to the point of let’s say, let’s say a nation-state actor that’s not American and not European, it gets access to a hardened model, right, internal or external, that can do this. What’s your best defence? Is it that Anthropic have decided that no, you’re not, I’m afraid, important enough to us to allow you to defend yourself? Or is it instead better that OpenAI said, no, you can use our model to help you defend yourself? It’s definitely the OpenAI way of doing it. It just is.
Frank: Well, it sounds it the way you put it, but when you then consider that it also opens the possibility of a lot more people having, a lot more bad actors having access to the most powerful cyber-capable model, it doesn’t sound quite so nice then.
Is low-cost AI a gift to hackers?
Justin: Tell you what’s interesting, right? Here’s an interesting question for you now, because I know that you’re somewhat distrustful of Mr. Altman from time to time. Here’s the thing, right? I remember years ago spam emails were a problem and there was lots of discussion as to how would you stop spam emails, how could we get rid of, discourage. Now Google came up with a great solution and they kind of solved it, right? One of the potential solutions was, how about if we charged 1 cent or one penny for every single email that you wanted to send? And so there was a monetary cost. You couldn’t just send millions of emails for free, essentially for free, and therefore you would have to think about every single email before you sent it because it would cost you a penny, right?
In the same vein, right, under the guise of stopping bad actors from doing things, they could easily charge more money for the security version of their models and say, oh yeah, yeah, this is a security version, so therefore it costs three times as much as the regular model, even though the model itself is exactly the same underneath. But they didn’t. They released it at the same cost as their regular model.
Frank: Mythos is more expensive.
Justin: But it’s more expensive anyway, right? They didn’t charge. Mythos is more expensive by virtue of the fact that it’s a model that’s 10 or a hundred times bigger than Opus, right? So it’s just more expensive. I’m more speaking about OpenAI and you’ve got the cyber-attack-tuned version of an existing model. They could charge more for that, they don’t, which seems to me like something that’s for the good of humanity. So I’m on the side of OpenAI. I’m falling on the side of OpenAI this week. I think they’re doing a great job.
Frank: Interesting. Okay. Yeah. Interesting.
Is OpenAI pivoting from models to platforms?
Frank: So you, because you mentioned there about the harness being almost as important as the model itself. Harness, the system, the structure that it sits in. And that’s interesting because it actually aligns with that leaked memo from OpenAI. So we’ve been talking about OpenAI versus Anthropic in terms of the safety approach, but they also leaked this memo from OpenAI from their chief revenue officer. And she was basically saying that, yeah, we’ve gone from, the market has moved on from prompting to agents.
And so she was talking about models themselves are pretty much like commodities now. And so people can just switch from OpenAI, Anthropic to Google to, hopefully not to Grok, but anyway. So she was talking essentially about the need to switch from a product-based company to a platform-based company and to stop thinking in terms of all these different products and to start thinking in terms of a platform that has different entry points for enterprise customers.
And the big thing was, yes, okay, the models need to be more powerful to encourage people to use them for all different types of work, but then companies need to be able to move to an agent system much, much more easily. They need to be, they need a lot more help in terms of deploying AI effectively throughout the company.
And I mean, that kind of fits just with your harness and systems being as important as the model. That seems to be where they’re going with this. And interestingly in that, she not only kind of outlined what she thought needed to happen, which all came, she said, from direct dealings with customers. She said that the number one thing that they needed to do now was just listen to the customer and give them what they need. And she said, but we have to admit as well, we have to kind of accept as well that it’s a highly competitive landscape and the customer is the absolute focus.
But let’s talk for a minute about what the competition are doing. And she talks specifically about Anthropic, which I thought, again, interesting. In a memo about where OpenAI are going, it’s Anthropic she focused in on, in terms of the competitive landscape. No mention of Google, no mention of anybody else. And she outlined, I think, five mistakes that she felt that Anthropic had made or were making. One was that their story’s built on fear and she felt that OpenAI’s positive message would win out in the end.
Justin: There’s this element of truth to that, by the way.
Frank: There is. But I would say at least Anthropic’s message of fear is clear because she said OpenAI’s positive message would win out in the end. What’s OpenAI’s positive message?
Justin: Well, I’m sure OpenAI will be able to articulate that message to you better than I could ever articulate. So let me not besmirch the name of them. Positive message of OpenAI.
Frank: And if she wants it to win out in the end, they’re going to have to start communicating it pretty soon because I certainly don’t know what it is.
Justin: But she’s not wrong, right? What was the text she used, the wording that she used? I read it and it was like, yeah, that’s not unreasonable. Okay, I don’t have it here in front of me, right? But basically—
Frank: Is built on fear, restriction and the idea that a small group of elites should control AI.
Justin: Yes. And that’s exactly what we’ve been talking about, right? Right, when it comes to the security. So, and I agree with that sentiment, right? It’s true. And I do feel that it’s better to do things, build in the open, right? Do it. Do it in the open. The other thing, I’ll tell you—
Frank: It’s only true if it’s fearmongering, as opposed to actually preparing people for something bad that might happen, which needs to be addressed.
Justin: Yeah, I don’t agree. I’ll tell you what was interesting in, I’ll tell you two things that are interesting, right, in that memo.
Are OpenAI and Anthropic fighting for lock-in?
Justin: First was the third point, right? Expand the market through Amazon. That was a very interesting point. Amazon is a big supplier of software to enterprises, to large enterprises, and clearly what the, I mean, the message of fear from Anthropic to OpenAI is they’re grabbing the enterprise market right now, and so they want to get a bit of that pie.
This is going to be the defining moment for these two companies because what they’re trying to do right now is that if you’re a company of any size, right, and you’re deploying agents, if they can get you to deploy your agents onto their platform, and then you do your workflows and you hook them into your existing systems, whatever, it’s called vendor lock-in. You’re stuck, right? It’s going to be really hard for you to move. So it’s like the SaaS-pocalypse, you’ve all heard of that, right? That’s basically their SaaS model for the next 10 years. It’s going to be, at least the view would be, very hard for you to move off from those platforms to another platform.
So a lot of that battle for that market is going to happen over the next 12 to 24 months and whoever wins that will have a locked-in advantage in terms of revenue. That’s why it’s so important. If I was any of those companies, here’s an interesting thought, right, I’d be very slow to go and use those platforms, right? Because I would be resistant to getting maybe I don’t care, right? But generally you’d be resistant to vendor lock-in right now. Maybe if they’re providing so much value, you don’t mind so much about the vendor lock-in.
Now, here’s an interesting thing. At the moment, what they do is they’re very open. They give you Claude Code agent SDK, agents SDK, whatever the Codex is, they give you all that stuff for free, right, because they want you to build and so you don’t have to use their cloud agent platform things. It may be possible that at some point in the future they don’t, right? Because they publish, they say, here, use our cloud platform. Here’s how it works. And you know, whatever. You can literally just take Claude Code and copy it and then you don’t have any vendor lock-in, right? You’re there.
There’s loads of other stuff that goes on in enterprises, right? There’ll be an interesting trade, there’ll be an interesting sort of tension between these people, right, these people being OpenAI and Anthropic and AWS and Microsoft, because AWS and Microsoft will want to own the enterprise bit. And the enterprise bit is, you know, what is my agent doing? Is my agent allowed to do this? How many agents do I have? What are the agents doing today? Are they still working the same way when we put them into production day one? Though, all that sort of stuff that companies like to know about. And—
Frank: I mean she was very, so, she was very clear that she wanted OpenAI’s Frontier, which is their agentic deployment platform, she wanted that to become the enterprise default for agents. She did specify where Amazon Bedrock fits into all that. And I’ll be honest with you, because that is not my area, I didn’t fully understand exactly where she sees Bedrock fitting into the overall plan, but definitely, you know what I mean I’m saying, like she was very clear that she wants—
Justin: What was her title?
Frank: Hmm.
Justin: What was her title? The woman, her title was Chief Revenue Officer.
Frank: Yeah.
Justin: Whatever she wrote down, I don’t know exactly what she wrote down, but the real reason is to meet the customers where they are. So if you’ve got a big bunch of customers in AWS, well then go to AWS so you can get those big customers. That’s the reason they’re going to AWS.
Frank: Yeah, yeah. Yeah.
Justin: I mean, there’s no doubt of it. So anyway, it’s such an interesting time, right? What’s going to happen? Are they still going to give those tools for free? Who knows? Maybe there’s a thing in future where it’s now, if you want to use our SDK, you have to go in our clouds to do it. Our clouds are available in AWS or Azure. Pick which one you want to go to. All these sort of things could happen in the future in an effort to do—you, by the way, today. Very interesting.
Will free Salesforce tools cost you later?
Justin: Sort of related, Salesforce, you’ve heard of them. They’re a big company. They make software. And so they came out today and they said they’re doing this thing, what’s it called? It’s not called Client 360. It’s, that’s called Agent 360, but it’s something 360, every function in Salesforce, Headless 360. That’s what they called it. Every function in Salesforce is now going to be available through an API, MCP or a CLI through the command line.
So what are they going to do, right? So Salesforce are going to give this away for free right now, and they’re going to get you to build your agents that hook into Salesforce using APIs, CLIs or MCPs, and then at some point in the future they’ll turn around and they will start to charge for that access the same way they charge for seats today. It’s a very smart move, right? And again, it’s about lock-in, right? If you build your systems around what we have now, I know that it’s going to be really hard for you to get off them in the future. So—
Did Anthropic make a mistake backing coding?
Frank: I thought one of the other, there was actually, there was so much interesting about that memo in terms of Anthropic versus OpenAI in particular, but I thought another interesting one was that she said it was a mistake for Anthropic to index so specifically on coding. And she thinks that that has given them a wedge right now, but that in the long term, it’s going to be a liability because AI is going to touch so many different parts of work.
Justin: Yeah. I mean, I’m reminded of Steve Ballmer looking at the iPhone when it was released and laughing at it and saying, oh, who the hell wants to buy a phone like this? It doesn’t have any buttons or anything. I don’t agree. I mean, Claude Code has shown itself to be brilliant at stuff way outside of the realm of coding, right? It can, you know, Cowork, you know, Cowork is not a coding product, but it is Claude Code underneath the hood. So, yeah, I don’t know. And again, actions speak louder than words. I mean, they’re releasing this unified interface now where you can do everything through actually some pretty cool stuff there.
At least they released this computer use thing where if you’re on a Mac, it controls your Mac in the background without you actually having to give up use of your mouse. So it’s almost like it’s got a virtual screen on your Mac that it can do things on while you’re still working away yourself on your Mac. Right. So it’s got coding and all those other things, they’re kind of following in Anthropic’s footsteps. I don’t agree with her. I think she’s—
Frank: As in, do you mean you don’t agree that it was a mistake to over-index on coding, or do you mean that you don’t think Anthropic really did over-index?
Justin: It’s anonymous.
Did Anthropic’s real mistake come down to compute?
Justin: The only Anthropic, the only mistake, and they did talk about this, the only mistake that Anthropic have made so far is they didn’t front-load the amount of compute that they bought, right? They’re being constrained by compute. That was a mistake. But in terms of every other approach and concentration on coding and going down that route, that was absolutely, so far, there’s nothing to tell me that that is not absolutely 100% the correct approach. But it’s so interesting, you know?
Again, think about it. The usage of AI today is what, three to 5% of the planet. By the end of the year, it could be 10 or 15. Like that’s a multiple of what, eight or 10. The use of AI is going to explode. And so the need for compute is about to explode. And that could be the big mistake that Anthropic made.
Frank: Yeah, and she specifically, when she talked about that, she specifically said that we’re seeing it now in terms of that they’re having to throttle their rate limits and users are not happy. And we talked on the show before about when people left OpenAI for ethical reasons and flocked over to Anthropic, they got a bit of a shock because they couldn’t do half as much in Anthropic because of the rate limits. And now we’ve got, trying to keep track of these model numbers, man. Now we’ve 4.7. Thank you.
Justin: Yes.
Frank: And people, I saw people saying that they felt that Claude 4.6 had been throttled in order to make 4.7 seem so amazing when it came out. I understand why people would say that. I don’t, I would suspect it probably wasn’t that. I would suspect it’s all just down to the level of compute that they have, but kind of fascinating all the same, as in they just quietly started throttling the model and not saying anything to anyone and it took somebody doing this huge analysis of their prompts and responses from Claude over a long period of time, and they figured out that there was like a 67% gradual decrease in the thinking that was allotted to Claude.
So in other words, the model that they started using, 4.6, was a very powerful model, and then it became less powerful over time, quietly as Anthropic kind of dialled down the compute that they were willing to give to users.
Justin: Yeah, but I think that’s a direct result of the number of users they have, which is back to my point, that I think the lack, not front-loading, the amount of compute they have may be the biggest issue they have. It’s such an interesting case study, right? I remember hearing Dario talking about this, and he was like going, yeah, we projected the compute, but if you committed yourself too much and you were out by a couple of percent one way or the other, you could bankrupt yourself. So he’s clearly quite cautious in the way that he was growing his business, but now it’s coming back to bite him in the ass. He really needs to expand quickly from the other point of view, right?
Are any AI companies actually trustworthy?
Justin: Sam Altman did turn around at Christmas time saying speed is what matters. We have to be able to deliver tokens fast. Put a focus on that. He’s right about that too, right? From a user experience point of view, sitting there waiting for five minutes for something to come back is a horrible experience. You want it quick. So if OpenAI can deliver good model performance really fast, your model can even be slightly less intelligent if it’s faster.
Frank: You know, you were saying, so just talking about Sam Altman earlier, you were saying about like, I don’t always find him the most trustworthy person.
Justin: Yeah, yeah, yeah. Yeah.
Frank: I’ve kind of, yeah, I’ve said that for a while. And now we have this article, and I’m bringing this up for a reason, an article came out in The New Yorker, what was it called? Sam Altman May Control Our Future. Can He Be Trusted? And it was by Ronan Farrow and Andrew Marantz. And my reading of it would be that there’s no smoking gun. There’s no big wrongdoing on Sam Altman’s behalf. But at the same time, my reading of it was that there’s just a litany of people with a multitude of complaints, of lies, manipulation, deception, that is kind of a body of work that is too significant to completely ignore.
But at the same time, I’m looking at what we were just saying there about Anthropic and I’m like, I get it. I understand the compute is expensive and if you don’t have it and how many users, what do you do? But it’s not what you would expect from the ethical company. It’s not what you would expect, that they would just quietly turn down the compute and do a kind of a bait and switch on the models. So none of these, none of these companies are trustworthy. None of them are, you know, they’re all companies. They’re all private companies.
Justin: Yeah, I mean, I would disagree with the characterisation that it’s a bait and switch, right? They’re dealing with a dynamic situation where they have, like, what were they, they were growing like a thousand percent a week at some point. Like just an enormous, I mean, the amount of effort that it requires just to manage that level of growth and traffic is enormous, right? You can see their system downtime went up. They were clearly having difficulty managing the traffic.
But look, they’ve got great partners, right? They have an investor in Google, as in Google. I think AWS are also an investor, right? They will sort these problems out, but what can, you can’t turn down new subscriptions. You can’t turn away people that you have already. So they came up with what was possibly the best solution they could.
Frank: But if you launch a model with a system card and all this big fanfare about the benchmarks, et cetera, and then somebody signs up to access, we’ll say Claude 4.6, based on the benchmarks that they’ve seen, based on what’s in the system card, they sign up, they’re paying good money to access that model, but what they’re accessing isn’t what was fanfared on release at all. Now it’s 67% less intelligent.
Justin: Well, okay, I don’t know that it’s 67% less intelligent. It used 67% less tokens, right? So not all tokens are born equally, and maybe it got to approximately the same result. But look, again, I would give Anthropic some credit because Boris, who is the creator of Claude Code, is on Twitter constantly where people are complaining, saying, look, do a feedback, send me a screenshot, whatever you’re saying. We set it to automatic, we didn’t turn it down. Maybe it’s not tuned quite correctly.
But did this same thing not happen to OpenAI about six or eight months ago and they went through exactly the same growth pains? Do you remember that? Where they had set the whole thing and people were like, oh my God, this isn’t working the same anymore. And I don’t hear that anymore. So maybe there’s just a sort of a growth phase where you’ve got to figure it out.
Frank: There were several, there were several times that people felt like the models were gradually becoming less effective. To go back to that article about Sam Altman and the trustworthiness, et cetera, did you also hear about—
Do AI companies want regulation or just say they do?
Frank: A Molotov cocktail being thrown at Sam Altman’s home. And another story, which there’s very few details about, but another story about two gunshots apparently being fired in the vicinity of his home as well, which people are assuming might have been some kind of attack as well. But the details are a bit scant, and Sam Altman released a blog post after the Molotov cocktail was thrown at his home, which is horrendous, by the way. I mean—
Justin: Yeah.
Frank: Awful. And he put out a blog post. He did insinuate that that article might have been somewhat to blame. He didn’t— But the article focused a lot on, look, there’s a lot of anxiety about AI around. And again, I just wanted to read one small thing to you because do you remember last week when Mythos was released? I read you that bit from the system card that kind of basically said, we need, I think, I can’t remember exactly what it said, but basically we need regulation. It essentially said we shouldn’t, we need help here. Come on. The governments of the world need to get stuck in here. I don’t remember the exact wording, but that was more or less it.
And I just found it interesting that in the blog post from Sam Altman after the Molotov cocktail, he said there’s a lot of anxiety about AI. And he said, I do not think it is right that a few AI labs would make the most consequential decisions about the shape of our future. And he said, we urgently need a society-wide response to be resilient to new threats. Now—
Justin: Sorry, who said that now?
Frank: Sam Altman.
Justin: Alright. Yeah.
Frank: So again, we have all the leaders saying, it should not be in our hands. Somebody needs to do something and nobody’s doing anything. Now, I will say, look, I don’t trust Sam Altman. I think he says this, he talks about the need for regulation and then he quietly fights it in the background and puts, you know, so, but on the face of it, just looking, taking things at face value, once again, we have Anthropic, we have OpenAI. They’re all saying shouldn’t really be in our hands. We need, yeah, we need a society-wide response.
Justin: Maybe just to make the point on the Molotov cocktail as well, right? We need to have sort of respectful debate about these things, which we do, right? But the world at large needs to learn the lesson that words do matter and you can’t just go around talking, as my kids would say, talking cap about people and say whatever the hell. You can make your argument in a respectful way, but you can’t go around—like, that’s just a terribly dangerous thing, right? And you would hope that it doesn’t happen again because important as it all is, you can’t go around throwing Molotov cocktails at people’s houses. That’s just not okay, you know?
Frank: Yeah. Yeah.
Justin: There you go. And I’ve got good news for you, Frank.
Frank: What’s that?
Will AI take your job then subcontract you?
Justin: So you are worried in particular about AI taking your job? My job, everybody’s job. What are we going to do? AI is coming here to take our job. Yes. This is a concern that you have?
Frank: Yeah, it absolutely is. If I looked puzzled, it was just like, are you not concerned about that too?
Justin: Not really. No. And let me tell you why.
Frank: Okay.
Justin: A new Y Combinator called HumWork AI has been funded. And guess what it’s going to do?
Frank: What’s it going to do?
Justin: When all the AI takes all of our jobs, right, it’s not going to know. AI isn’t going to know every answer, so you can sign up. It’s kind of like an agency. And when the AI needs help, it’ll reach out to you, ask you for your help, and then you’ll make money by telling the AI what it needs to do, so you will still have a job. You’ll have a job helping the AI to take your job. Isn’t that great?
Frank: I see. So enterprises are going to come to OpenAI. OpenAI are going to say, great. We’re going to set you up. We’re going to show you how to deploy this effectively. We’re going to set up all these agents. You don’t need any of those employees. They’re going to set them up with all this agent AI. The agent AI isn’t going to be remotely capable of doing the work of expert humans on long-horizon tasks.
Justin: Yeah.
Frank: And it’s going to fail, and then it rings up the human and goes, here, come here. Would you do that job for me?
Justin: Yeah. Well, in my mind it’s more could you do this captcha for me please? Or could you, you know, I need to get this password. Could you get me the password? And then it carries on. But yes. Isn’t that it? So you’ll still, I for one, I’m all on board. I quite like the idea of lying in bed at 10 o’clock at night, having spent my day sipping coffee and looking at the sea and then making 50 euro, whatever it is, because I answer a question for AI. I’m on board with that. That’s my retirement plan.
Frank: It is a very, very interesting way to keep the human in the loop. Get rid of all your employees, deploy AI, spend a fortune on tokens, and then also spend a fortune on the employees that you fired to do the stuff. Today. I can’t.
Justin: You don’t even have to do it yourself. I mean, I would give it to my kids and have them answer the questions. This is like the modern equivalent of sending your kids down the mine. All of their phones, the only way they get a phone is if they have this app installed and they answer at least 10 questions a week, and then they can keep their phone. If they don’t, I’ve taken their phone off them.
Frank: I thought you were going to say you were going to give it to your open Claude. There’s—
Justin: Yes. Somebody’s got to do that. Yes, it’s a great idea actually. That’s a really good idea. Brilliant. Well, okay—
Frank: Inception levels of human-AI loops going on. Yeah.
Justin: Well, on that happy note, Frank, a pleasure as always. I hope we have a great weekend.
Frank: Chat to you next week. Cheers, Justin.
Justin: Take it easy.
RELATED EPISODES
View all episodesAbout The AI Argument
A weekly podcast where an approachable AI doomer and a techno-optimist argue over the latest AI news. Heavy topics, discussed lightly.

Frank Prendergast
The approachable doomer.

Justin Collery
The techno-overoptimist.