[00:02.480 --> 00:03.240] Evening everyone. [00:03.540 --> 00:05.160] Good to be here again, I HOPE. [00:05.640 --> 00:15.280] So, in case you come away from this talk thinking I'm very anti-AI and I'm very against machine learning and artificial intelligence, don't. [00:15.500 --> 00:19.560] As mentioned, if you go to my LinkedIn profile, you can download that book for free from NVIDIA. [00:19.740 --> 00:23.860] It's got some actual good use cases for AI, especially for defensive cybersecurity. [00:24.420 --> 00:30.840] There's lots of really great opportunities for using machine learning and AI and large language models. [00:32.040 --> 00:36.440] But that doesn't make a very interesting talk, so we're going to be looking at the bad side of stuff. [00:37.620 --> 00:47.800] Before I get any further, one thing I will mention about myself, obviously from the accent, I'm English, I have a German name, I live in Italy, and I have Latvian citizenship. [00:48.220 --> 00:56.700] So I'm a bit of a mutt, but I'd like you to remember those bizarre data points as we go through the talk, because they're going to come a bit more relevant towards the end. [00:58.080 --> 01:12.400] So, first of all, one of the big problems with AI, and one of the big problems with the tech industry is that second only really to politics, the tech industry is one of the largest concentration of liars and thieves and grifters. [01:12.960 --> 01:14.640] And we've seen this repeatedly. [01:15.160 --> 01:23.280] Whenever there's a new technology that comes out, everyone slaps that label on their shonky 20 year old product and says, yeah, antivirus infused with AI. [01:23.280 --> 01:29.660] We have anti-malware software that uses the blockchain, right? [01:29.760 --> 01:34.480] They jump all over it like rats on a... fleas on a rat. [01:35.300 --> 01:42.800] And it's a problem because if we want to talk about the dangers of a new technology, this kind of muddies the water. [01:42.800 --> 01:47.520] We can't really have a meaningful conversation about the pros and cons of a technology. [01:47.520 --> 01:54.020] If everyone is saying, oh, yeah, my thousand dollar phone has AI in it because it can use your picture to do a Google search. [01:56.920 --> 02:02.180] So, one of the things that we need to do, first of all, is look at what do we mean by AI? [02:02.720 --> 02:07.100] And what is the current crop of AI solutions actually doing? [02:07.860 --> 02:09.240] And for that, we're going to go back. [02:09.420 --> 02:10.260] We're going to go back. [02:10.580 --> 02:12.080] Obviously, I've got lots of grey hair. [02:12.080 --> 02:15.660] We're going to go back before even my early days of getting involved in computing. [02:16.160 --> 02:17.800] All the way back to the Second World War. [02:18.240 --> 02:21.120] We're going to talk about this chap, Alan Turing. [02:22.500 --> 02:25.140] He was... he was fairly clever. [02:25.520 --> 02:29.900] He came up with one of the first designs for the programmable digital computer. [02:30.500 --> 02:42.280] And specifically a digital computer, because back in the 30s and the 40s, a computer was some bloke with an abacus who could use it very, very quickly, and add and subtract stuff very, very quickly. [02:42.460 --> 02:45.880] That was the pre-war vision of what a computer was. [02:46.460 --> 02:48.400] Turing came up with the idea of a digital computer. [02:48.680 --> 02:54.060] And obviously, it helped massively with the stuff that he's most famous for, which is cracking codes in the Second World War. [02:54.640 --> 03:02.280] But some of his real breakthroughs in the area was talking about a programmable digital computer. [03:02.280 --> 03:11.700] Rather than building a single-use computer that can be used to crack codes, create a digital computer that can be programmed to carry out many, many functions. [03:12.480 --> 03:19.080] And so, in many ways, his ideas were the precursor of the laptops and the mobile phones and all the other smart devices that we've got today. [03:20.860 --> 03:23.940] He then developed the idea of what he called a Turing machine. [03:24.060 --> 03:36.000] If I can develop a digital programmable computer that can be programmed to carry out a task, it can be programmed to carry out the tasks of another computer, and maybe one that's not programmable. [03:36.800 --> 03:38.420] And some of you will recognize this. [03:38.680 --> 03:44.320] We deal with it every day, especially if you're involved in arcade machines or game console hacking, right? [03:44.380 --> 03:47.940] This idea of emulators, of virtual machines, of containers. [03:48.160 --> 03:50.200] We use it every single day. [03:50.200 --> 03:58.280] And most modern phones these days will have some sort of containerization in them to split work profiles from personal profiles. [03:58.880 --> 04:03.320] And this was an idea that Turing came up during the war when he was developing his code-breaking machines. [04:03.920 --> 04:05.960] And then he took it a step further. [04:05.960 --> 04:16.900] And he said, well, if we can develop a machine that can be programmed to emulate another machine, why can't we develop a machine that can be programmed to emulate people? [04:18.600 --> 04:24.760] Now, there's lots of arguments to be said, OK, there are some very, very simple people, like politicians. [04:25.160 --> 04:26.740] It's very, very easy to emulate. [04:26.740 --> 04:28.140] You just stand up and you lie. [04:28.660 --> 04:29.420] Easy job. [04:29.600 --> 04:30.400] Anyone can do that. [04:30.500 --> 04:32.320] I've got a pocket calculator that can do that. [04:33.260 --> 04:46.240] Turing was taking it a step further and saying, well, actually, if we think and if we take in input and we process it and then we generate output, that should be able to be encapsulated inside a programmable computer. [04:47.420 --> 04:56.760] And he went a step further and he said, OK, if we do that, surely then this machine intelligence is going to be indistinguishable from a real person. [04:57.080 --> 04:58.200] Obviously not a politician. [04:58.200 --> 05:02.120] I'm talking about a normal thinking person who's capable of original thought. [05:02.800 --> 05:05.120] So he developed this idea of a Turing test. [05:05.300 --> 05:15.900] And the Turing test is essentially a bunch of people who sit down and they ask a series of questions designed to suss out, am I talking to a very, very clever machine? [05:15.900 --> 05:18.860] Or am I talking to a very, very stupid politician? [05:19.580 --> 05:24.540] And the Turing test remains kind of the gold standard about how do we define artificial intelligence? [05:24.920 --> 05:29.300] And it's essentially something that can pass the Turing test and that can pass off as human. [05:29.680 --> 05:31.920] A lot like Boris Johnson if you're in the UK. [05:34.280 --> 05:40.880] Now, if we look at current AI solutions, they can pretend to be humans. [05:40.980 --> 05:46.540] They can emulate human speech, but none of them are capable of actually passing the Turing test. [05:46.700 --> 05:48.960] They're not actual artificial intelligences. [05:49.460 --> 05:59.280] And marketing people have come up with a whole bunch of largely inaccurate labels to call them generative AI, large language models, blah, blah, blah, blah, blah, blah, blah, blah, blah. [06:00.120 --> 06:09.620] There have been lots of really great talks at HOPE so far, and there are some more tomorrow as well, that dig into the technical aspects of how the most common ones, large language models, actually work. [06:10.020 --> 06:16.140] And they look into the nitty-gritty of the technology and the underlying technical functions and how you program them and how you grow them. [06:16.980 --> 06:17.940] Really great talks. [06:18.380 --> 06:18.980] Very, very technical. [06:19.600 --> 06:21.420] This is not one of those talks. [06:22.140 --> 06:29.160] I'm going to explain how LLMs, how generative AI works, via the medium of game shows. [06:30.320 --> 06:31.840] Some of you may recognize this. [06:32.000 --> 06:34.280] This is Family Feud, I think you call it over here. [06:34.500 --> 06:36.940] In the UK, we call it Family Fortunes. [06:37.380 --> 06:42.980] And there's a whole bunch of social discourse that can be explored about why those are two very, very different names. [06:42.980 --> 06:50.600] But this is fundamentally how AI, as is sold to us today, works. [06:50.840 --> 06:52.320] We have a pool of data. [06:52.600 --> 06:55.640] It's gathered from data subjects who are members of the public. [06:55.900 --> 07:02.620] We have a prompt, and then people have to guess the statistically most likely answer to that prompt. [07:03.140 --> 07:07.200] Whoever invented this was an absolute genius and deserves the Nobel Peace Prize, right? [07:07.600 --> 07:09.320] Statistics as entertainment. [07:09.340 --> 07:10.880] Who would have thought that? [07:10.880 --> 07:19.060] And if anyone's ever studied economics at university, you're probably as gobsmacked as I am that this actually took off. [07:19.260 --> 07:22.160] And then it's screened across multiple countries as well. [07:22.380 --> 07:23.540] Absolutely genius idea. [07:25.880 --> 07:31.140] Fundamentally, AI, as we think about it, is an authoritative statistics engine. [07:31.140 --> 07:36.140] And it works in exactly the same way as Family Fortunes, Family Feuds does. [07:37.100 --> 07:45.700] It generates output based on statistical analysis of the model that has been given and the data that it has access to. [07:47.300 --> 07:55.600] And this is an important distinction because large language models, generative AI, don't give out the most accurate answer. [07:55.940 --> 08:05.060] They give out what is statistically the most likely answer based on the data that they have and the model that they've been trained on. [08:05.060 --> 08:07.780] And those are two very, very different things. [08:08.440 --> 08:16.800] Yes, if you go to ChatGPT-4 and you ask a bunch of questions, it will probably come back with something that makes sense and sounds plausible. [08:17.440 --> 08:21.360] Because it has a huge amount of data analyzed off the back of that. [08:22.160 --> 08:32.940] If you try and get a large language model to give you output for something it's not been trained for, that it has insufficient data for, it's going to spew out a bunch of garbage. [08:33.160 --> 08:35.040] It's going to be unintelligible nonsense. [08:39.190 --> 08:55.850] I call this an authoritative statistics engine because all of the chat bots especially, but most of the large language models, most of the AI tools that we use today, are programmed in such a way that they give out their output in a way that we believe them. [08:57.130 --> 09:05.950] And from a very young age, we are conditioned to respect authority figures, listen to your teachers, listen to your parents, go to the police if you're lost, right? [09:06.010 --> 09:06.710] All this sort of stuff. [09:07.910 --> 09:11.510] I'm fairly certain no one stills trust politicians anymore. [09:11.990 --> 09:13.790] No, no, didn't think so. [09:16.110 --> 09:22.590] We are more likely to believe someone or something if it speaks in an authoritative way. [09:23.010 --> 09:24.050] You're doing it here now. [09:24.290 --> 09:25.190] You're listening to me. [09:25.590 --> 09:32.530] I'm here pretending that I know what I'm talking about and I'm speaking very confidently about it and you're all sitting there going, yeah, yeah, Tom knows his stuff. [09:32.710 --> 09:33.290] This is great. [09:33.450 --> 09:34.270] What an awesome talk. [09:35.310 --> 09:35.930] Hands up. [09:35.930 --> 09:41.790] Who has heard a politician in the last two months confidently talk nonsense about a subject they know nothing about? [09:42.890 --> 09:44.170] Yeah, most of you. [09:44.390 --> 09:46.210] Of course, it's election year, right? [09:46.210 --> 09:47.530] They're all coming out of the woodwork. [09:47.770 --> 09:49.410] Just had general elections in the UK. [09:49.810 --> 09:50.910] There's European elections. [09:51.230 --> 09:55.610] You can't throw a stone without hitting a politician who's spouting off about something they know nothing about. [09:55.990 --> 09:57.450] But people listen to them. [09:57.630 --> 10:00.670] And they listen to them because they speak in an authoritative way. [10:00.850 --> 10:04.370] They have mastered the art of appearing cleverer than they are. [10:04.370 --> 10:08.090] And this is fundamentally built into all large language models. [10:08.230 --> 10:11.950] This is fundamentally built into AI solutions. [10:12.290 --> 10:24.290] If you ask ChatGPT a question, it turns and says, well, I kind of think that the sky is blue and the grass is green, but there's only a 60% probability based on my data, right? [10:24.310 --> 10:25.070] You think it was rubbish. [10:25.630 --> 10:31.850] But if it confidently says, yes, I know that the sky is red and the grass is brown, people will believe that. [10:32.090 --> 10:35.510] Because it is delivered to them in a confident, authoritative way. [10:36.350 --> 10:43.830] And we're going to get back onto why there are some issues with this authoritative presentation of data later on as well. [10:44.830 --> 10:47.470] Now, lots of people have been talking about the dangers of AI. [10:49.670 --> 10:52.070] And this is stuff that we've all heard before. [10:52.230 --> 10:53.530] We've heard it before as technologists. [10:53.730 --> 10:54.630] We've heard it before as hackers. [10:54.950 --> 10:56.630] We've heard it before as security people. [10:57.350 --> 10:59.250] AI is a neutral technology. [10:59.250 --> 11:00.950] It is a dual use tool. [11:01.490 --> 11:04.690] Yes, it's absolutely fantastic for phishing attacks. [11:04.870 --> 11:05.590] I love it. [11:05.730 --> 11:06.130] It's brilliant. [11:06.830 --> 11:09.090] Yes, it's also good for learning a new language. [11:09.090 --> 11:10.190] I live in Italy. [11:10.350 --> 11:11.250] Italian is difficult. [11:11.910 --> 11:13.250] AI is helping me an awful lot. [11:13.430 --> 11:13.910] It's great. [11:14.590 --> 11:15.790] But we've seen this before. [11:15.910 --> 11:23.270] And we can go all the way back to the 80s when Alec Muffet created crack for UNIX systems to crack passwords. [11:23.590 --> 11:26.970] The outrage, the hysteria in the press was massive then. [11:27.150 --> 11:29.270] We've seen it when Back Orifice was launched. [11:29.510 --> 11:31.390] We've seen it when Satan was launched. [11:31.790 --> 11:34.650] We're still hearing about encryption even now today. [11:34.650 --> 11:39.930] In 60 years time when we're all back here for another HOPE and we're just head in jars like in Futurama. [11:40.130 --> 11:44.610] We're still going to be moaning about governments banging on about how encryption is dangerous and it should be outboard. [11:45.130 --> 11:46.890] These are all dual use technologies. [11:47.170 --> 11:48.570] They have pros and they have cons. [11:49.110 --> 11:53.270] But fundamentally that's because at their core they are neutral technologies. [11:53.830 --> 11:55.590] And AI is another manifestation of that. [11:55.710 --> 11:58.050] It has good uses and it has bad uses. [11:59.110 --> 12:01.270] Like I said, talk about the good uses of AI. [12:01.790 --> 12:02.510] Crappy talk. [12:02.750 --> 12:04.410] Let's talk about the bad uses of AI. [12:04.410 --> 12:05.890] Let's look at the real danger a bit. [12:07.630 --> 12:09.950] Kind of breaks down to three main areas. [12:10.170 --> 12:13.470] So we've got the companies and the people behind AI solutions. [12:14.570 --> 12:21.110] We've got the issues around data and accuracy and the opacity of the data and the models. [12:21.390 --> 12:25.290] And we've got issues around data theft and privacy breaches. [12:27.050 --> 12:36.310] AI, as it is built today, poses zero chance of some sort of Skynet Terminator style HAL 9000 uprising. [12:37.070 --> 12:48.010] It is exponentially more difficult to create an AI that can emulate a pet than it is to generate an AI that can pretend that it's talking like a human being. [12:49.290 --> 12:50.810] And some of you will be looking down this list. [12:51.010 --> 12:53.730] Some of you have been to some other great talks this weekend. [12:53.970 --> 12:57.470] And you'll be looking there and saying, wait, how come you're not talking about misinformation? [12:58.290 --> 13:00.310] That's like the big headline grabber at the moment. [13:00.690 --> 13:02.350] AI is going to impact our elections. [13:03.230 --> 13:09.590] The problem is that using AI for misinformation is a symptom. [13:10.150 --> 13:11.610] AI is not the cause. [13:12.130 --> 13:15.110] Misinformation has been around for as long as there's been conflict. [13:15.610 --> 13:23.870] If you go all the way back, if you believe this sort of stuff to Cain and Abel, I'm fairly certain that Cain would have turned around and gone, I didn't kill my brother. [13:24.050 --> 13:25.290] It was fake news. [13:26.290 --> 13:29.790] This has been endemic throughout history. [13:30.450 --> 13:34.130] And also, when we look at misinformation, we don't have to go that far back either. [13:34.330 --> 13:37.550] We can go back to when the Internet started to be generally available. [13:37.890 --> 13:45.910] The hysterics in the press at the time about how the Internet was going to undermine social fabric, how it was going to mislead people, it was going to break the democratic process. [13:46.470 --> 13:48.610] Before that, we had the same arguments with TV. [13:48.970 --> 13:57.790] When politicians first started appearing on TV, when TV started to get popular, again, a social outcry about this is going to give politicians an unfair advantage. [13:57.790 --> 14:11.230] A politician who can speak eloquently on TV is going to get more votes than the politician who comes across as a buffoon, which is the same argument we had when radio became available in households, which is the same argument we had when newspapers started to be printed, when the printing press came out. [14:14.050 --> 14:25.850] One of the very, very early arguments of the Catholic Church against the printing press was that the plebs would be able to get their own copies of the Bible, and then they'd be able to see that the priests have been talking nonsense at them. [14:26.030 --> 14:31.570] The priests have been talking about stuff that wasn't in the Bible, and that would undermine the fabric of the church and therefore society. [14:31.910 --> 14:33.270] It's bad technology. [14:33.930 --> 14:35.690] Misinformation has been around for ages. [14:36.910 --> 14:38.470] AI aids misinformation. [14:39.130 --> 14:40.610] It helps misinformation. [14:41.570 --> 14:44.610] But is misinformation bad necessarily? [14:45.050 --> 14:49.670] If a government is using misinformation to push propaganda, yeah, okay, that's bad. [14:49.850 --> 14:55.330] But we can use the same tool to push misinformation to undermine government propaganda. [14:55.570 --> 14:56.470] And people do. [14:56.750 --> 15:02.170] And there have been social uprisings that have been enabled by things like social media, social networking. [15:02.170 --> 15:11.350] If you think back to the Arab Spring uprisings, social media played a huge part in that, which is surprising to me because I think all social media is a total cancer. [15:11.670 --> 15:13.130] It's a blight on humanity. [15:13.410 --> 15:16.070] And yet here it is affecting positive social change. [15:16.810 --> 15:21.490] So, I don't think misinformation is a uniquely AI problem. [15:21.830 --> 15:22.770] AI is a tool. [15:23.010 --> 15:24.390] It can be used in misinformation. [15:24.770 --> 15:26.570] That's kind of handy for lots of people. [15:26.770 --> 15:28.210] But it's not a real danger. [15:29.750 --> 15:30.810] Thank you, Terminator. [15:33.010 --> 15:36.970] So, let's dig into some of the calls of that first one. [15:37.150 --> 15:38.910] So, the companies and the people behind AI. [15:39.330 --> 15:41.630] Now, I'm going to pick on Sam Altman. [15:41.990 --> 15:43.650] I'm going to pick on him for a number of reasons. [15:44.010 --> 15:45.810] He's a hateful human being. [15:46.070 --> 15:48.830] He is the poster child of terrible tech bros. [15:49.010 --> 15:57.210] And also, the stuff that he has done with OpenAI is a perfect example of the dangers of large tech companies and the amount of data they hold. [15:58.730 --> 16:01.590] Well, Sam Altman was going on his very, very public. [16:01.770 --> 16:02.990] Oh, woe is me. [16:03.250 --> 16:04.730] AI is going to destroy humanity. [16:04.730 --> 16:06.130] It's the new Skynet. [16:06.350 --> 16:07.770] Why won't government step up? [16:08.070 --> 16:11.810] By the scenes, he was going to those government legislators and saying, you know what? [16:12.730 --> 16:15.670] AI isn't a problem as long as you trust us tech bros. [16:15.870 --> 16:17.010] It's all those hobbyists. [16:17.090 --> 16:19.210] It's all those upstarts who use AI for bad. [16:19.390 --> 16:24.250] But we've been entrusted with safeguarding the technology that underpowers Western civilization. [16:24.250 --> 16:25.570] You can trust us. [16:25.570 --> 16:31.590] So he was publicly saying AI is bad, while behind the scenes lobbying politicians and saying, AI is good. [16:31.750 --> 16:35.950] If you are going to enact legislation, do it to protect us because we know best. [16:36.970 --> 16:40.070] Other large tech companies joined in because, hey, why not? [16:40.190 --> 16:42.590] Why should OpenAI get the slice of the pie? [16:42.950 --> 16:47.310] Google, Meta, Amazon, Microsoft, they all piled in with that. [16:47.950 --> 17:04.130] The end result was that the public hysteria about AI drove interest in AI, which pushed OpenAI's valuation through the roof, which enabled Sam Altman to execute a boardroom coup and to make a, frankly, shit tonne of money off the back of that. [17:05.170 --> 17:12.270] It also then meant that legislators enacted laws around AI that erected barriers for competition. [17:12.930 --> 17:22.070] And I'm going to specifically call out the EU, big fan, like the DSA, like GDPR, their most recent AI Act, total bag of spanners. [17:22.410 --> 17:23.770] Utterly, utterly useless. [17:23.770 --> 17:28.650] All it does is create a barrier for entry against tech company competitors. [17:29.350 --> 17:31.870] And we'll get into ways that we can fix that a bit later on. [17:35.640 --> 17:50.420] I'm just going to point up here as well to that newspaper article about Sam Altman's personal net wealth, because not only did he manipulate the media and manipulate government to secure a stranglehold on new technology, he then went off to all the [17:50.420 --> 17:54.940] other companies where he sat on the board and had influence and got them to make deals with OpenAI. [17:55.800 --> 17:57.520] Who uses Reddit? [17:58.700 --> 17:59.360] Still. [18:00.200 --> 18:01.080] A few people. [18:02.000 --> 18:03.520] Someone at the back, excellent. [18:04.380 --> 18:10.180] Reddit's recent IPO served no purpose apart from making some venture capitalists money. [18:10.540 --> 18:13.000] Reddit is essentially an online forum. [18:13.260 --> 18:14.660] It's a dead business model. [18:14.760 --> 18:15.920] You can't make money from that. [18:16.040 --> 18:22.000] And the last refuge of scoundrel VCs is to say, oh yeah, we'll make money from advertising. [18:24.660 --> 18:29.080] Reddit went one step further, because they had this chap called Sam Altman on the board. [18:29.700 --> 18:34.360] Clearly, it must have been a different Sam Altman, because this would have been a gross conflict of interest. [18:34.680 --> 18:38.340] But this shadow Sam Altman went to the Reddit board and said, you know what? [18:39.100 --> 18:40.020] Advertising's old hat. [18:40.300 --> 18:42.280] You've got this huge pile of data. [18:42.500 --> 18:45.000] That would be a great data set for an AI company. [18:45.420 --> 18:49.280] It happens to be, I know, a really, really good one. [18:50.440 --> 18:51.320] Reddit had their IPO. [18:51.620 --> 18:53.220] They rewrote their terms of service. [18:53.400 --> 19:01.140] They snuck in a bunch of stuff that basically said, all of your content, including all of your previous content, we're going to hive off to AI companies. [19:01.500 --> 19:04.480] And you can tell us not to, but it's too late, because we've already done it. [19:04.800 --> 19:08.340] They signed a deal with Google, and a few weeks later they signed a deal with OpenAI. [19:08.820 --> 19:21.840] And that's just one of the many backroom deals that Sam Altman has done for personal enrichment, but also to harvest data to power his main cash cow, OpenAI. [19:23.780 --> 19:30.400] Speaking of data, the second big danger from AI is data inaccuracy and data opacity. [19:30.800 --> 19:36.640] If you're here for the talk that was immediately before this one, there's some great stuff talking about GDPR. [19:37.800 --> 19:45.900] GDPR gives EU citizens copycat cats of GDPR that have popped up globally as well, give people similar sort of rights. [19:46.080 --> 19:49.400] It gives you the right for data that's incorrect to be fixed. [19:49.720 --> 19:52.740] It gives you the right to view what data is held about you. [19:53.420 --> 19:55.840] And it gives you the right for that data to be deleted. [19:57.300 --> 20:09.660] The problem with the large data sets that are required to train AI, and the large data sets that are required to get AI to do what it does, is that no one wants to talk about where that data came from. [20:10.240 --> 20:12.520] And they don't want to talk about it because they've stolen it. [20:13.720 --> 20:20.540] I haven't given my consent for my data to be sucked into OpenAI, or to Google, or to Facebook, or any of those other training systems. [20:22.400 --> 20:26.200] They are also not talking about how are their models trained. [20:26.660 --> 20:33.440] And these two combined means that any large language model, any generative AI has a huge amount of opacity. [20:33.740 --> 20:48.060] It is impossible for an outsider to understand how it does what it does, which means if it spits out incorrect data, I have a legal right for that data to be corrected, but the AI companies can't actually do it. [20:48.720 --> 20:51.740] There's also the problem that this introduces bias. [20:52.700 --> 20:57.440] Depending on the data set that is created, we will get bias appearing with it. [20:57.900 --> 21:03.820] Now, my hands-down, my favourite AI tool ever, was Microsoft's Tay Tweets. [21:04.100 --> 21:11.700] A fantastic social experiment on how people on the Internet can fuck over big tech in a matter of days. [21:12.020 --> 21:18.520] It went live, some idiot at Microsoft said, wouldn't it be good if we plugged an AI, just plugged it straight into Twitter? [21:19.000 --> 21:21.600] Possibly the most toxic cesspool on the Internet. [21:21.960 --> 21:30.800] And we'll just have that raw, unfiltered data come in and train our AI, and it will then turn into some sort of all-knowledgeable Gaia that will guide humanity. [21:30.800 --> 21:38.360] What actually happened was that within two days, Tay Tweets became a misogynist, racist Nazi. [21:38.360 --> 21:41.800] And it wasn't shy about telling people about that. [21:42.040 --> 21:51.620] This is perhaps my most favourite tweet ever in the history of mankind, and it's from Tay Tweets, and it's an absolute banger. [21:51.660 --> 21:52.600] It's fantastic. [21:52.600 --> 21:57.860] It sums up the problem with data opacity and data going in. [21:58.920 --> 22:11.280] And equally, we had issues with Google's most recent AI attempt with its image generator, where it didn't matter what prompt you did, it always gave an output that didn't match up with it. [22:12.200 --> 22:14.040] And this is a fun example. [22:14.160 --> 22:15.160] Show me vanilla ice cream. [22:15.320 --> 22:16.620] Okay, it showed me chocolate ice cream. [22:16.620 --> 22:17.200] Why? [22:17.380 --> 22:25.680] Because there was an inbuilt bias within the Google team to address what they perceived, quite rightly, as data bias against minorities. [22:26.460 --> 22:27.060] Great, okay. [22:27.160 --> 22:33.740] But if you build that into your model, and you don't think through the problem, you ask it to draw a picture of a white car, and it's going to draw a black car. [22:34.160 --> 22:40.580] If people are relying on that output, foolishly, if people are trusting that output, you're going to get incorrect data out. [22:41.080 --> 22:50.860] Now, that's not to say that meddling with models and training models so that they adjust for racial bias and societal bias is the wrong thing to do. [22:51.000 --> 22:51.300] It's not. [22:51.420 --> 22:52.520] We should be addressing that. [22:54.380 --> 22:57.640] But it should be addressed at the fundamental levels of the model. [22:57.780 --> 23:00.580] And it should be addressed with the data that we feed into it. [23:00.860 --> 23:09.100] If we feed it in, the raw Twitter feed, Twitter is rife with sexism and racism and polarized political ideals. [23:09.320 --> 23:13.900] It's never going to have any sort of valuable, meaningful output coming in. [23:14.540 --> 23:25.540] And because we don't know how these models are trained, and because we don't know the data that's used for them, apart from take tweets, it means that we can never trust the output. [23:27.100 --> 23:31.680] There are people out there who are relying on GitHub Copilot, for example, to generate code for them. [23:33.360 --> 23:48.040] Foreign hostile nation states, and for me as a European, that includes the U.S, have been happily cloning GitHub repositories, injecting malicious code, and then using click farms to make it look like those repositories are very, very active. [23:48.340 --> 23:52.580] Which means that Copilot then says, this is the most active repository. [23:52.580 --> 23:55.340] I will give this an artificially high weighting. [23:55.720 --> 24:06.720] Sucks in the malicious code, and then spits it out to an unsuspecting developer, who then pastes it into production, and lo and behold, we get a load of organizations pwned and no one knows why, because they've not checked the code. [24:07.580 --> 24:09.260] This is a fundamental problem. [24:09.480 --> 24:20.300] And some data scientists, I'm not going to tie them all with the same brush, have called this hallucinations, which fits in very nicely with the narrative that we're dealing with an artificial intelligence. [24:20.920 --> 24:25.200] The problem is the phrase hallucinations to describe this is bollocks. [24:25.480 --> 24:26.940] It's not hallucination. [24:27.120 --> 24:28.300] The machine is not dreaming. [24:28.480 --> 24:30.140] We haven't entered some Philip K. [24:30.360 --> 24:34.840] Dick novel, where we're going to have Blade Runners running around after these things, shooting them up because they're dreaming. [24:35.360 --> 24:36.400] It's a bug. [24:36.600 --> 24:37.780] It's a data issue. [24:37.920 --> 24:40.500] And it's one of the oldest issues that we've got in technology. [24:40.980 --> 24:42.860] Garbage in, garbage out. [24:43.180 --> 24:48.160] If you don't know how the model is trained and you feed it the wrong data, it's going to spit out gibberish. [24:48.160 --> 24:55.020] If you don't know what data you've got and you can't audit that data, you can't rely on the output. [24:56.080 --> 25:03.420] And that brings me to the last sort of major problem with this, which is fundamentally data theft. [25:03.420 --> 25:11.020] We've already... all of us here should be quite familiar with the ideas about large tech companies stealing our data. [25:11.720 --> 25:23.640] Constantly mining everything that we do and using that data initially for behavioral analytics to sell us more shit, and then later on for adverts to try and click us, to get us to click to buy more shit. [25:24.140 --> 25:26.060] And now that's being fed into AIs. [25:26.060 --> 25:29.120] It's being used as a data pool to drive into this. [25:29.860 --> 25:33.440] And the problem is that that data isn't theirs. [25:34.540 --> 25:36.080] It's not theirs under copyright. [25:36.620 --> 25:39.060] It's not theirs under the laws of GDPR. [25:39.380 --> 25:43.300] It's not theirs under the laws of various privacy legislation that's in place globally. [25:43.300 --> 25:56.700] And in many cases, it's not there because like with Reddit, they've retroactively changed the acceptable use policy and data that you thought was yours and was part of a community has been sold off wholesale without your knowledge and without your ability to stop it. [25:59.100 --> 26:04.540] Large tech companies have decades of experience doing this and they've got very, very good at it. [26:04.680 --> 26:12.340] And this is one of the main reasons why AI companies refuse to talk about how they've trained their models or what data sets they're using. [26:13.340 --> 26:16.300] They're essentially pleading the fifth, as you guys say over here. [26:16.600 --> 26:23.300] They're holding their hands up and saying, well, if we told you how it worked, the first thing you'd say is, wow, you've broken the law to do this. [26:23.620 --> 26:24.620] Where are my lawyers? [26:25.180 --> 26:26.800] So they're keeping shtum about it. [26:26.940 --> 26:28.100] No one wants to talk about it. [26:29.440 --> 26:37.800] There has been some rumors that Google have been talking about, oh, we're gonna sell AI solutions into the U.S. military to help them with intelligence. [26:39.100 --> 26:41.140] Okay, great, they're a business, they're doing that. [26:41.500 --> 26:50.700] One of the side effects is if you start to submit legal queries to Google saying we want to understand how your AI works, they're gonna hide behind that nice big impenetrable shield. [26:52.200 --> 26:54.580] This is a danger to our nation. [26:54.880 --> 26:59.260] This is critical national infrastructure and you can't question us because we've done deals with the government. [26:59.520 --> 27:01.220] You're just gonna have to shut up and use it. [27:03.220 --> 27:06.620] As I mentioned, AI can't meet GDPR legal requirements. [27:07.180 --> 27:09.560] I've not given consent for my data to go in. [27:09.980 --> 27:12.680] It can't even tell me what of my data that it has. [27:12.820 --> 27:13.980] And it can't delete it. [27:16.360 --> 27:26.560] When ChatGPT, I think it was 4, was released, the Italian Information Commissioner immediately turned around and banned it from use in the country because they correctly identified the fact that it was illegal. [27:27.100 --> 27:28.480] And I did some lobbying. [27:29.160 --> 27:32.420] They made some namby-pamby statements about, oh, yeah. [27:32.780 --> 27:39.600] If any of you have watched South Park Bigger Longer Uncut, Sam Altman basically did a Saddam Hussein and was like, I can change, I can change. [27:40.140 --> 27:42.760] The Italians sucked it up, but they've been keeping an eye on it. [27:45.100 --> 28:00.920] Some of you may know the name Max Schrems, an Austrian activist who properly stuck it to Facebook multiple times about their data theft and got the EU to levy some fairly hefty fines against Facebook and struck down some inadequate data sharing rules with the U.S. [28:02.480 --> 28:05.180] He started a group in Europe called NYOB. [28:06.560 --> 28:10.060] None of your business, it stands for, which is quite apropos. [28:10.800 --> 28:16.420] They've sent a bunch of requests into OpenAI, basically saying, you've given some inaccurate data. [28:17.480 --> 28:20.120] Legally, I'm allowed to ask you to fix that. [28:20.280 --> 28:20.540] Do it. [28:21.140 --> 28:23.960] Oh, by the way, I'm going to give you a subject access request. [28:23.960 --> 28:27.160] I'm legally allowed to ask you to give me a copy of the data you've held. [28:29.280 --> 28:32.140] OpenAI have formally turned around and gone, eh. [28:34.120 --> 28:35.180] We can't do that. [28:35.200 --> 28:36.800] That's not how AI works. [28:36.980 --> 28:38.020] You're just an activist. [28:38.020 --> 28:40.660] Don't worry your pretty little head about this technology stuff. [28:40.860 --> 28:41.420] We're the best. [28:42.340 --> 28:45.420] Now, NYOB aren't going to take any of that shit, thankfully. [28:45.680 --> 28:56.400] And they've started enforcement action through the Austrian Information Commissioner, who are currently investigating OpenAI for widespread flagrant breaches of EU law. [28:57.040 --> 29:07.940] And this is great because it starts to open that can of worms so that other countries, other areas of the world, California's got a fairly decent privacy law. [29:08.240 --> 29:10.020] Hopefully they'll be following suit as well. [29:11.840 --> 29:17.400] So, if that's all the bad stuff with AI, I don't want to leave you all with a sour taste in your mouth. [29:17.600 --> 29:18.920] What can we do about it? [29:20.600 --> 29:23.860] Now, I'm going to talk, first of all, about data poisoning. [29:24.160 --> 29:31.640] And I'm going to have a very specific example of here, I personally have suffered food poisoning attacks from a fast food company. [29:32.680 --> 29:34.770] You can now get data poisoning attacks. [29:35.440 --> 29:37.280] Any of you see that that popped up? [29:38.060 --> 29:39.320] Let's cycle through again. [29:39.620 --> 29:45.700] Keep an eye on the top right, top left even, of this fairly terrible McDonald's advert. [29:47.340 --> 29:48.000] There. [29:49.660 --> 29:56.680] Some of you may be familiar with the idea of subliminal advertising, which was very early on in film and TV. [29:56.940 --> 30:04.100] People worried about, in between the frames of pictures, people would insert things like, buy Amazon stock. [30:04.560 --> 30:06.940] Give your data to Mark Zuckerberg. [30:07.700 --> 30:09.340] So they enacted laws about it. [30:10.020 --> 30:23.220] One of the interesting things about AI, here we go again, especially when it's in things like autonomous vehicles, is that it is analyzing data far faster than human eye. [30:24.160 --> 30:37.720] So things like subliminal advertising, where we splice in malicious data into an audio or a video stream, is wildly effective against AI. [30:38.560 --> 30:55.380] And this particular one, there's a link there, there's a paper where they have explored using animated advertising boards, animated billboards, and inserting things like speed limit signs or traffic signs for a split second in an animated advert. [30:56.500 --> 31:01.580] Which, and this is a technical term, causes autonomous vehicles to shit themselves. [31:02.680 --> 31:08.360] They'll be driving along, we'll be sitting there going, oh, there's an advert for a salmonella inducing burger. [31:08.540 --> 31:09.240] Lovely, ooh. [31:10.140 --> 31:12.040] The autonomous vehicle will be driving along going, oh! [31:12.720 --> 31:15.720] It says it's a 90 kilometer an hour speed limit, and I'm doing 120. [31:16.020 --> 31:16.940] Slow on the brakes. [31:18.840 --> 31:20.600] It's a hugely interesting paper. [31:21.220 --> 31:22.660] I encourage you all to read it. [31:23.900 --> 31:29.940] It's been published by the ACM, so it's not like it's an academic paper, we have to pay our sale VA three grand to go and read it, right? [31:30.000 --> 31:31.440] It's free on the web, you can go and look at it. [31:31.840 --> 31:33.040] Very, very interesting research. [31:33.040 --> 31:42.420] And they talk about this problem about poisoning data feeds that come into autonomous vehicles, large language models and things like that. [31:44.140 --> 31:46.560] But, we can take it a step further. [31:49.240 --> 31:53.240] Poisoning the well becomes a hugely effective tactic. [31:53.240 --> 32:01.540] Now, I'm a bit of an arse, I'm a troublemaker, I'm a huge fan of direct action, and that's got me into a lot of trouble over the years. [32:01.700 --> 32:03.400] So, I'm a huge fan of poisoning the well. [32:03.980 --> 32:11.000] There are tools out there you can get, which you plug into your social media profiles, and they will overwrite everything with gibberish. [32:11.460 --> 32:17.460] And those are hugely successful for feeding crap data into companies that are stealing your data. [32:19.240 --> 32:25.860] You can get them that will overwrite your Reddit history, you can get them that will overwrite your Twitter history, you can even get them that will overwrite your Facebook history. [32:26.520 --> 32:30.380] Plug them into the API, you give them your credentials, who cares, right? [32:30.500 --> 32:31.880] It's scorched earth policy. [32:32.100 --> 32:37.140] I'm abandoning Reddit, pulling that ejection lever, and I'm going to create a huge mess on the way out. [32:38.060 --> 32:44.940] These are very, very useful tools for punishing companies for breaking the law and stealing our data. [32:48.080 --> 32:52.480] Other things that we can do is that we can expose the botnets. [32:53.260 --> 33:10.500] And there are a lot of posts that you see, especially now it's election year, where you'll see people on Twitter deliberately asking specific questions and using prompt injection attacks to get the AI-powered bots to spaz out and start vomiting out key phrases. [33:11.280 --> 33:18.020] And then you'll see pictures of people where they say, look, here's a thousand accounts that said exactly the same thing and responded in exactly the same way. [33:18.160 --> 33:23.660] This is a botnet that is being powered by this specific AI, expose it, shut it down. [33:25.620 --> 33:31.580] Kind of less effective now than it used to be on Twitter because, let's be honest, Elon Musk doesn't give a shit. [33:31.940 --> 33:40.900] If there's a thousand bots, then that's a thousand people generating comments that will make people outraged and they will respond and then you can point to the usage stacks and say, look, I haven't killed Twitter. [33:41.060 --> 33:42.100] People are still arguing on it. [33:42.200 --> 33:42.740] Aren't I great? [33:45.480 --> 33:47.320] There have been some talks this weekend. [33:47.520 --> 33:54.180] There will be some more talks as well about prompt injection attacks, prompt jailbreaks. [33:54.820 --> 33:57.700] And an AI sitting there saying, give me input. [33:58.160 --> 34:00.740] Now, that can be in the web interface for ChatGPT. [34:00.740 --> 34:02.860] It can be a bot interacting in. [34:03.060 --> 34:11.060] It could be what you think is a request from someone to chat with you on WhatsApp. [34:11.440 --> 34:15.480] I've had a bunch come in for me last week from Signal that were very obviously bots. [34:15.680 --> 34:18.480] And I used prompt injection attacks to expose those. [34:18.980 --> 34:20.460] There's a bunch of different ways. [34:21.140 --> 34:22.940] Like I say, there's some good talks on this. [34:23.160 --> 34:35.760] There's lots of information out there about the different levels of prompt injection attacks and prompt jailbreaks and how you can use those to not only expose a bot, but also to get it to spit out stuff that's contrary to the constraints that have been imposed on it. [34:39.260 --> 34:41.620] We can support activists. [34:42.160 --> 34:44.700] The EFF are here, as always, doing a great job. [34:45.680 --> 34:47.500] NYOB are doing a great job in Europe. [34:49.240 --> 34:52.380] We have a good arsenal of legal tools. [34:53.300 --> 34:56.880] Again, in the previous talk, they were talking about the Digital Services Act in the EU. [34:56.880 --> 35:06.000] That imposes a lot of legal constraints on very large service providers to manage the data that they hold. [35:06.980 --> 35:12.520] It's kind of crappy because it's the first generation of that legislation and they're still sussing it out. [35:12.660 --> 35:14.640] But it's a movement in the right direction. [35:16.640 --> 35:28.460] And one of the benefits of legislation that's created in the EU is that we managed to get 27 different countries who are at each other's throats and don't even speak a common language to agree on something. [35:29.140 --> 35:33.480] So getting a 28th country that's not in the EU to agree, that's kind of easy. [35:33.480 --> 35:42.640] So there is a groundswell and impetus and inertia of EU legislation that means it can be used to affect and enhance legislation globally. [35:42.820 --> 35:44.200] And we've seen that with GDPR. [35:44.340 --> 35:45.760] And that's another tool in our arsenal. [35:46.400 --> 35:50.920] As I mentioned, NYOB are using GDPR to launch investigation to OpenAI. [35:51.320 --> 35:55.380] Other people are using GDPR to launch similar enforcement actions. [35:55.380 --> 35:58.280] I believe there's one currently underway in Italy against Meta. [35:58.520 --> 36:03.340] There's one underway in Germany against Microsoft. [36:03.820 --> 36:05.480] And I think there's two in Google. [36:05.800 --> 36:11.200] But at any point in time, there's like half a dozen legal actions against Google in the EU because they're such a shit company. [36:11.500 --> 36:25.440] So what we can also do is use activism, use privacy respecting groups to try and expose the models, try and expose the data set that's been created. [36:26.120 --> 36:31.080] There is currently a lawsuit that's trundling through the law courts here in New York. [36:32.380 --> 36:36.620] The New York Times, shockingly enough, are not known for very accurate reporting. [36:37.100 --> 36:42.980] They're taking AI companies to court because they're saying, hey, look, we're the ones who publish lies, not you. [36:43.060 --> 36:45.500] And you've stolen our lies and you've used it to feed your AI model. [36:45.600 --> 36:46.340] And that's outrageous. [36:46.340 --> 36:47.480] So we're going to sue you. [36:48.320 --> 36:49.940] A bunch of authors have jumped in as well. [36:50.180 --> 36:50.620] Why not? [36:50.680 --> 36:51.740] It's a class action lawsuit. [36:51.880 --> 36:52.480] Let's go for it. [36:52.720 --> 36:59.800] So there's legal action kicking off all over the place to hold these companies to account, to define where they got their data from. [37:00.260 --> 37:06.900] And that's important because when we know, as I mentioned, where we know where they got the data from, we know the inherent bias in the models. [37:06.900 --> 37:09.020] We know the inherent bias in their outputs. [37:09.320 --> 37:12.280] And we can also then suss out, how did you train the model? [37:12.360 --> 37:15.280] If you use this data to train the model, these are the problems with it. [37:15.280 --> 37:16.600] This is what we can do with it. [37:18.060 --> 37:22.760] And finally, the last thing I want to wrap up with, possibly the most important one, education. [37:24.160 --> 37:38.020] One of the problems that we've got with the AI Act in the EU is that policymakers and lobbyists and politicians saw all of this media coverage for AI and stood around going, shit, we have no idea what this means. [37:38.740 --> 37:40.080] Is it how 9000? [37:40.220 --> 37:41.700] Is Google going to create Skynet? [37:42.400 --> 37:51.520] And then the usual tech companies came up and said, ah, we know all about this because we're the idiots who created it in the first place. [37:51.520 --> 37:54.100] So let us tell you what's right to go into the law. [37:54.820 --> 38:04.460] And yeah, I'm harsh on politicians, but I have a lot of goodwill towards policymakers because they have a difficult job. [38:04.720 --> 38:14.300] They have to advise stupid politicians who just care about being reelected about stuff that is going to stay on the law books for 5, 10, 15, 20 years. [38:14.860 --> 38:16.100] They don't know where to turn. [38:16.220 --> 38:17.900] They don't know where to get expertise from. [38:18.700 --> 38:19.860] We are those experts. [38:21.740 --> 38:31.820] Reaching out to policymakers, going to policy seminars, conferences around legal policy, reaching out to organizations like EFF who are very strong in the policy space. [38:32.020 --> 38:33.760] In the EU, we've got EDRI. [38:34.120 --> 38:42.020] We've got a bunch of other organizations that lobby on behalf of technology, giving them support and education and say, look, this is how this stuff actually works. [38:42.400 --> 38:43.600] Don't believe the hype. [38:43.800 --> 38:45.380] Don't be the only voice in the room. [38:46.100 --> 38:47.560] We can educate these people. [38:47.720 --> 38:52.260] And that will then manifest itself in a slightly better level of law. [38:53.420 --> 38:56.100] Now, it doesn't mean that the legal framework is going to be perfect. [38:56.300 --> 38:56.700] It never is. [38:56.760 --> 38:57.660] It needs to be refined. [38:57.660 --> 38:59.020] People need to be sued. [38:59.420 --> 39:05.220] We need a couple of tech companies to be punished publicly before we can then get some case law and we can refine it further. [39:05.520 --> 39:06.460] But it's a start. [39:06.580 --> 39:07.320] It's a good direction. [39:08.440 --> 39:09.780] And also everyday people. [39:10.420 --> 39:12.880] I was talking to someone last week who was going, you know what? [39:13.540 --> 39:14.560] CoPilot's the shit. [39:14.680 --> 39:15.620] It's awesome. [39:15.940 --> 39:24.900] I had no idea how to program in this language and I plugged into CoPilot and it generated all this code and I pushed it to production that afternoon and it's all been fantastic. [39:25.740 --> 39:27.840] I could see someone down there just going, oh God. [39:29.040 --> 39:30.020] Oh God, no. [39:31.560 --> 39:32.000] Yeah. [39:33.420 --> 39:35.140] Those people need our help. [39:35.140 --> 39:39.040] Those people, yeah, it's a crappy job market out there, right? [39:39.180 --> 39:42.820] People are doing what they're told because they want to keep their jobs because they've got bills to pay. [39:43.160 --> 39:49.900] And if CoPilot or a similar tool gives them an easy way out, gives them a quick answer, they're going to take it, why wouldn't they? [39:50.320 --> 39:53.220] I am possibly the laziest man on the face of the planet. [39:53.400 --> 39:56.560] And if I could trust AI, hell yeah, I'd get it to do my job. [39:57.360 --> 39:57.800] Absolutely. [39:57.800 --> 39:58.580] Who wouldn't? [39:59.280 --> 40:01.540] We need to help these people understand the dangers of that. [40:01.540 --> 40:12.340] We have more than enough examples and evidence of incorrect output, of introducing malicious code, of introducing backdoors, of poisoned supply chains. [40:12.680 --> 40:16.760] All of this stuff has manifested itself at that sharp tip of the spear with AI. [40:17.140 --> 40:27.420] It is bringing all of that malicious crap together and serving it up on a platter to developers and to DevOps people and saying, here's a solution, just cut and paste this in. [40:28.480 --> 40:45.960] There have been some very well-publicized research that was posted on Twitter, despite me slagging it off, where people have been saying, okay, they got ChatGPT to write code that didn't link in a library, but when you plugged it into your IDE and [40:45.960 --> 40:58.020] you did code complete features of your IDE, it linked to a known malicious library because that was the best fit according to the IDE and according to Copilot or ChatGPT. [40:58.300 --> 41:00.700] So you don't even need to include malicious code. [41:00.920 --> 41:06.240] You can hint at malicious code and it will then link it for you and prove your downfall. [41:07.380 --> 41:10.760] All of this is hugely important for us to share with people around us. [41:11.000 --> 41:18.540] And not in the, don't be a fucking idiot and do that sort of way, but to do it in a, hey, did you realise this is how it works? [41:18.640 --> 41:19.700] Because most people don't. [41:19.840 --> 41:29.140] Most people are still buying into the very public idea about how all of this stuff is just automation and it takes away the drudge work. [41:29.720 --> 41:34.720] And yeah, don't pay any attention to all those artists who've been putting out of business behind the curtain. [41:34.720 --> 41:35.660] They kind of don't matter. [41:35.900 --> 41:39.080] Look, here's a pretty picture of a kitten riding a unicorn and it's AI generated. [41:40.200 --> 41:45.680] We're in a unique position to help people understand that and to help people push back against its use. [41:45.880 --> 41:49.980] And as I said right at the very beginning, AI has some good uses. [41:50.400 --> 41:58.740] There are some use cases where large data problems, which are well understood with well-trained models, are a perfect fit for this sort of stuff. [41:59.140 --> 42:11.820] If anyone works in a security operations centre as an analyst and spends their day dealing with false positives, an AI-based solution trained on that data, plugged into your SIEM, is perfect. [42:12.100 --> 42:13.640] It cuts down those false positives. [42:13.800 --> 42:20.200] It gives you a probability of this being an incident rather than just a, here's a critical alert, go and look at it. [42:20.440 --> 42:21.880] There are some good use cases. [42:22.260 --> 42:26.100] But we need to educate people around us to understand this is good use. [42:26.560 --> 42:28.320] This is an iffy use. [42:28.560 --> 42:29.840] This is an absolute dog shit. [42:30.120 --> 42:30.940] Terrible use case. [42:31.100 --> 42:31.640] Don't ever do it. [42:31.740 --> 42:32.920] Stop, stop, stop, stop, stop, stop. [42:33.640 --> 42:34.780] Before you push to production. [42:36.900 --> 42:38.660] Thank you all very, very much for listening to me. [42:38.740 --> 42:39.140] Rambo on. [42:39.880 --> 42:40.640] Any questions? [42:44.380 --> 42:44.600] Hello. [42:44.920 --> 42:45.940] Thank you very much. [42:46.080 --> 42:47.360] This is really, really interesting. [42:47.600 --> 42:50.840] And great to hear from a CIS perspective as well. [42:51.720 --> 43:11.200] As someone who is currently working on projects, I'm trying to shepherd my organization towards like a slightly permissive and exploratory attitude towards AI, but also keeping in mind our privacy, our intellectual property, and fundamentally our safety. [43:12.060 --> 43:17.780] How do you explain that, or how do you do a compelling case to executives in dollars? [43:19.160 --> 43:20.600] In dollars, a good one. [43:20.820 --> 43:32.360] So my favorite is always to waive the GDPR boogeyman, which is easy for me because I'm in the EU and I work for an EU country, but GDPR reaches out beyond the EU. [43:32.660 --> 43:34.840] And GDPR is very strict, right? [43:35.020 --> 43:45.480] It's worst case, I think it's up to a 20 million euro fine or 4% of global turnover, which is the scary bit. [43:47.260 --> 43:54.120] Personally, I've had great success sitting down with executives and saying, yeah, you can do this, but I've told you that it's bad. [43:54.280 --> 44:02.940] So if you do it, you're knowingly breaking the law, which means an information commissioner is going to absolutely nail you to the wall for the maximum they can go for, as an example for others. [44:03.380 --> 44:04.680] So that's a good way of doing it. [44:04.680 --> 44:10.920] Another way of looking at it is getting them to think about corporate liability. [44:12.840 --> 44:19.120] And SolarWinds was a very, very good supply chain hack that happened last few years. [44:20.520 --> 44:25.800] There's lots of very well publicised data about how much it costs people to fix that. [44:26.820 --> 44:41.400] If you're in a business where you are generating code, and that code is being used in products or used by other people, you are going to be legally liable for the damages caused by that if you generate malicious code or if you generate code with [44:41.400 --> 44:45.500] backdoors in it, and it turns out that you just cut and paste that from the output of an AI. [44:47.260 --> 44:52.860] Another good area to look at is that whole area about IP, intellectual property. [44:53.000 --> 44:57.740] What is the data that's going into that AI, and what is it you're expecting to get out of it? [44:57.860 --> 45:06.220] If your company's IP, your business's IP is going into that AI, there is a dollar amount associated with that IP. [45:06.220 --> 45:10.940] And executives will know what it is because it's almost always got an insurance policy around it. [45:11.400 --> 45:13.360] And it also has value to the shareholders. [45:13.820 --> 45:22.060] And the market cap of the company or the amount of investment they've raised through the funding rounds will give a dollar amount on the value of that IP. [45:23.000 --> 45:37.580] And that then, you know, if I have a fledgling business and I've had $2 million of investment, and that investment is around the IP that makes that business valuable, and I go and stick that IP into OpenAI, it's completely opaque. [45:37.860 --> 45:40.480] No one has any idea what OpenAI do with that IP. [45:40.800 --> 45:41.940] Do they delete it? [45:42.160 --> 45:43.140] Does it get copied? [45:43.280 --> 45:44.140] Does it get reused? [45:44.320 --> 45:45.720] Does it resurface elsewhere? [45:46.120 --> 45:58.700] And the current lawsuit that's going on in New York, authors have said that they have seen, word for word, verbatim, their copyrighted work being spat out of ChatGPT, with the right prompts. [45:59.460 --> 46:04.660] So it's clear that data goes in, doesn't get deleted, and it gets shared out to third parties as well. [46:05.120 --> 46:14.620] If your business has a valuation, an investment round, if it has a level of market cap, that's based on your business's IP, and it's based on the revenue your business makes from that IP. [46:14.620 --> 46:22.440] So there's a very good dollar amount to slap onto that, and make people think twice about the data they put in, or the type of AI solution they use. [46:22.820 --> 46:33.640] There are some AI solutions where you can have a dedicated instance, where they claim that it doesn't share data with anywhere else, and it just uses the data you put into it. [46:34.000 --> 46:34.840] Do you trust them? [46:35.240 --> 46:40.600] Well, one of the companies saying that is OpenAI, and Sam Altman deserves a Nobel Prize for bullshit and lying. [46:40.600 --> 46:45.680] So I wouldn't trust them as far as I could throw them, and I would like to throw Sam Altman. [46:45.760 --> 46:46.180] It would be good. [46:46.560 --> 46:50.500] I reckon I could get him about halfway up there easily. [46:52.500 --> 46:53.440] Any other questions? [46:57.870 --> 46:58.350] Yes. [46:58.610 --> 47:07.230] What would actually convince you that AI is alive, has consciousness, it's a silicon-based life form, we're a carbon-based life form. [47:07.490 --> 47:13.030] And because of the complexity of the LLMs, it has developed a consciousness spontaneously. [47:15.330 --> 47:19.210] What convinced me, AI was actually conscious, passing the Turing test. [47:19.670 --> 47:20.210] That's it? [47:20.450 --> 47:21.130] That's it. [47:21.350 --> 47:21.550] Yeah. [47:21.550 --> 47:26.750] Now, in the 60s, there was a chatbot created called Eliza. [47:26.870 --> 47:27.010] Yeah. [47:28.190 --> 47:32.430] That was put up against ChatGPT two years ago, I think. [47:33.050 --> 47:42.550] And Eliza managed to convince more people in the Turing test that it was conscious than ChatGPT3 did. [47:42.550 --> 47:51.570] So it's a 60-year-old chatbot, is more effective at convincing people than the most recent but one iteration. [47:52.150 --> 47:59.610] Now, neither of those convinced more than, I believe it was 35% of the people interviewing them, that they were actual conscious entities. [48:00.090 --> 48:02.330] So there's still a long, long way to go. [48:02.770 --> 48:09.030] The Turing test remains, I think, one of the best ways of judging is something sentient or not. [48:13.180 --> 48:16.940] I was just gonna say, I think GPT-5 blows away the Turing test. [48:17.820 --> 48:19.320] Well, it'll be interesting... [48:19.320 --> 48:19.760] That's a rumor. [48:20.240 --> 48:21.500] It'll be interesting to see. [48:21.740 --> 48:30.380] So, one of the interesting things about the Turing test is that the questions are designed to probe for thought, as opposed to mimicry. [48:31.160 --> 48:39.300] Now, I used Eliza on BBC Micro in the 80s, I hacked into the code, and I got it to emulate Margaret Thatcher, who was then Prime Minister of the UK. [48:39.300 --> 48:42.400] And my version of Eliza was fucking brilliant. [48:43.220 --> 48:48.620] Whenever you asked it, it turned and said, invest in the stock market, buy a file of facts, become a yuppie. [48:48.880 --> 48:49.780] It was brilliant. [48:50.980 --> 48:55.680] Now, that mimicked Margaret Thatcher perfectly, which was hugely successful. [48:55.980 --> 49:04.280] And we've spoken about LLMs and AIs being very good at mimicking stuff, but they are functionally still parrots. [49:04.280 --> 49:09.000] They are trained to mimic human speech and mimic human responses. [49:09.540 --> 49:13.320] Can you get a parrot to the point where you could be convinced it was a human? [49:13.320 --> 49:15.980] For some things, maybe, yeah. [49:16.560 --> 49:19.980] And ChatGPT and other LLMs are kind of getting there. [49:20.160 --> 49:25.340] But the thrust of the questions in the Turing test is less about, can you mimic human responses? [49:25.900 --> 49:27.960] Can you demonstrate original thought? [49:27.960 --> 49:40.100] And that, for me, is kind of the really critical thing in the value in the Turing test, is that pushing these models to demonstrate original thought rather than just mimicry or spitting out what they've been trained to be told. [49:43.960 --> 49:46.560] Guys, please put your hands together for Tom Krantz. [49:46.840 --> 49:47.860] What a lot to think about. [49:48.300 --> 49:48.820] Great talk. [49:49.120 --> 49:49.880] Thank you so much.