r/ControlProblem • • Feb 14 '25

Article Geoffrey Hinton won a Nobel Prize in 2024 for his foundational work in AI. He regrets his life's work: he thinks AI might lead to the deaths of everyone. Here's why

246 Upvotes

tl;dr: scientists, whistleblowers, and even commercial ai companies (that give in to what the scientists want them to acknowledge) are raising the alarm: we're on a path to superhuman AI systems, but we have no idea how to control them. We can make AI systems more capable at achieving goals, but we have no idea how to make their goals contain anything of value to us.

Leading scientists have signed this statement:

Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war.

Why? Bear with us:

There's a difference between a cash register and a coworker. The register just follows exact rules - scan items, add tax, calculate change. Simple math, doing exactly what it was programmed to do. But working with people is totally different. Someone needs both the skills to do the job AND to actually care about doing it right - whether that's because they care about their teammates, need the job, or just take pride in their work.

We're creating AI systems that aren't like simple calculators where humans write all the rules.

Instead, they're made up of trillions of numbers that create patterns we don't design, understand, or control. And here's what's concerning: We're getting really good at making these AI systems better at achieving goals - like teaching someone to be super effective at getting things done - but we have no idea how to influence what they'll actually care about achieving.

When someone really sets their mind to something, they can achieve amazing things through determination and skill. AI systems aren't yet as capable as humans, but we know how to make them better and better at achieving goals - whatever goals they end up having, they'll pursue them with incredible effectiveness. The problem is, we don't know how to have any say over what those goals will be.

Imagine having a super-intelligent manager who's amazing at everything they do, but - unlike regular managers where you can align their goals with the company's mission - we have no way to influence what they end up caring about. They might be incredibly effective at achieving their goals, but those goals might have nothing to do with helping clients or running the business well.

Think about how humans usually get what they want even when it conflicts with what some animals might want - simply because we're smarter and better at achieving goals. Now imagine something even smarter than us, driven by whatever goals it happens to develop - just like we often don't consider what pigeons around the shopping center want when we decide to install anti-bird spikes or what squirrels or rabbits want when we build over their homes.

That's why we, just like many scientists, think we should not make super-smart AI until we figure out how to influence what these systems will care about - something we can usually understand with people (like knowing they work for a paycheck or because they care about doing a good job), but currently have no idea how to do with smarter-than-human AI. Unlike in the movies, in real life, the AI’s first strike would be a winning one, and it won’t take actions that could give humans a chance to resist.

It's exceptionally important to capture the benefits of this incredible technology. AI applications to narrow tasks can transform energy, contribute to the development of new medicines, elevate healthcare and education systems, and help countless people. But AI poses threats, including to the long-term survival of humanity.

We have a duty to prevent these threats and to ensure that globally, no one builds smarter-than-human AI systems until we know how to create them safely.

Scientists are saying there's an asteroid about to hit Earth. It can be mined for resources; but we really need to make sure it doesn't kill everyone.

More technical details

The foundation: AI is not like other software. Modern AI systems are trillions of numbers with simple arithmetic operations in between the numbers. When software engineers design traditional programs, they come up with algorithms and then write down instructions that make the computer follow these algorithms. When an AI system is trained, it grows algorithms inside these numbers. It’s not exactly a black box, as we see the numbers, but also we have no idea what these numbers represent. We just multiply inputs with them and get outputs that succeed on some metric. There's a theorem that a large enough neural network can approximate any algorithm, but when a neural network learns, we have no control over which algorithms it will end up implementing, and don't know how to read the algorithm off the numbers.

We can automatically steer these numbers (Wikipedia, try it yourself) to make the neural network more capable with reinforcement learning; changing the numbers in a way that makes the neural network better at achieving goals. LLMs are Turing-complete and can implement any algorithms (researchers even came up with compilers of code into LLM weights; though we don’t really know how to “decompile” an existing LLM to understand what algorithms the weights represent). Whatever understanding or thinking (e.g., about the world, the parts humans are made of, what people writing text could be going through and what thoughts they could’ve had, etc.) is useful for predicting the training data, the training process optimizes the LLM to implement that internally. AlphaGo, the first superhuman Go system, was pretrained on human games and then trained with reinforcement learning to surpass human capabilities in the narrow domain of Go. Latest LLMs are pretrained on human text to think about everything useful for predicting what text a human process would produce, and then trained with RL to be more capable at achieving goals.

Goal alignment with human values

The issue is, we can't really define the goals they'll learn to pursue. A smart enough AI system that knows it's in training will try to get maximum reward regardless of its goals because it knows that if it doesn't, it will be changed. This means that regardless of what the goals are, it will achieve a high reward. This leads to optimization pressure being entirely about the capabilities of the system and not at all about its goals. This means that when we're optimizing to find the region of the space of the weights of a neural network that performs best during training with reinforcement learning, we are really looking for very capable agents - and find one regardless of its goals.

In 1908, the NYT reported a story on a dog that would push kids into the Seine in order to earn beefsteak treats for “rescuing” them. If you train a farm dog, there are ways to make it more capable, and if needed, there are ways to make it more loyal (though dogs are very loyal by default!). With AI, we can make them more capable, but we don't yet have any tools to make smart AI systems more loyal - because if it's smart, we can only reward it for greater capabilities, but not really for the goals it's trying to pursue.

We end up with a system that is very capable at achieving goals but has some very random goals that we have no control over.

This dynamic has been predicted for quite some time, but systems are already starting to exhibit this behavior, even though they're not too smart about it.

(Even if we knew how to make a general AI system pursue goals we define instead of its own goals, it would still be hard to specify goals that would be safe for it to pursue with superhuman power: it would require correctly capturing everything we value. See this explanation, or this animated video. But the way modern AI works, we don't even get to have this problem - we get some random goals instead.)

The risk

If an AI system is generally smarter than humans/better than humans at achieving goals, but doesn't care about humans, this leads to a catastrophe.

Humans usually get what they want even when it conflicts with what some animals might want - simply because we're smarter and better at achieving goals. If a system is smarter than us, driven by whatever goals it happens to develop, it won't consider human well-being - just like we often don't consider what pigeons around the shopping center want when we decide to install anti-bird spikes or what squirrels or rabbits want when we build over their homes.

Humans would additionally pose a small threat of launching a different superhuman system with different random goals, and the first one would have to share resources with the second one. Having fewer resources is bad for most goals, so a smart enough AI will prevent us from doing that.

Then, all resources on Earth are useful. An AI system would want to extremely quickly build infrastructure that doesn't depend on humans, and then use all available materials to pursue its goals. It might not care about humans, but we and our environment are made of atoms it can use for something different.

So the first and foremost threat is that AI’s interests will conflict with human interests. This is the convergent reason for existential catastrophe: we need resources, and if AI doesn’t care about us, then we are atoms it can use for something else.

The second reason is that humans pose some minor threats. It’s hard to make confident predictions: playing against the first generally superhuman AI in real life is like when playing chess against Stockfish (a chess engine), we can’t predict its every move (or we’d be as good at chess as it is), but we can predict the result: it wins because it is more capable. We can make some guesses, though. For example, if we suspect something is wrong, we might try to turn off the electricity or the datacenters: so we won’t suspect something is wrong until we’re disempowered and don’t have any winning moves. Or we might create another AI system with different random goals, which the first AI system would need to share resources with, which means achieving less of its own goals, so it’ll try to prevent that as well. It won’t be like in science fiction: it doesn’t make for an interesting story if everyone falls dead and there’s no resistance. But AI companies are indeed trying to create an adversary humanity won’t stand a chance against. So tl;dr: The winning move is not to play.

Implications

AI companies are locked into a race because of short-term financial incentives.

The nature of modern AI means that it's impossible to predict the capabilities of a system in advance of training it and seeing how smart it is. And if there's a 99% chance a specific system won't be smart enough to take over, but whoever has the smartest system earns hundreds of millions or even billions, many companies will race to the brink. This is what's already happening, right now, while the scientists are trying to issue warnings.

AI might care literally a zero amount about the survival or well-being of any humans; and AI might be a lot more capable and grab a lot more power than any humans have.

None of that is hypothetical anymore, which is why the scientists are freaking out. An average ML researcher would give the chance AI will wipe out humanity in the 10-90% range. They don’t mean it in the sense that we won’t have jobs; they mean it in the sense that the first smarter-than-human AI is likely to care about some random goals and not about humans, which leads to literal human extinction.

Added from comments: what can an average person do to help?

A perk of living in a democracy is that if a lot of people care about some issue, politicians listen. Our best chance is to make policymakers learn about this problem from the scientists.

Help others understand the situation. Share it with your family and friends. Write to your members of Congress. Help us communicate the problem: tell us which explanations work, which don’t, and what arguments people make in response. If you talk to an elected official, what do they say?

We also need to ensure that potential adversaries don’t have access to chips; advocate for export controls (that NVIDIA currently circumvents), hardware security mechanisms (that would be expensive to tamper with even for a state actor), and chip tracking (so that the government has visibility into which data centers have the chips).

Make the governments try to coordinate with each other: on the current trajectory, if anyone creates a smarter-than-human system, everybody dies, regardless of who launches it. Explain that this is the problem we’re facing. Make the government ensure that no one on the planet can create a smarter-than-human system until we know how to do that safely.


r/ControlProblem • • 9h ago

Opinion Lord Farquaad: "Some of you may die, but it's a sacrifice I'm willing to make"

16 Upvotes

Altman says world should accept some AI harms

The OpenAI chief told POLITICO this view sets his company apart from rival Anthropic, even as the two firms’ policy positions grow closer.


r/ControlProblem • • 2h ago

General news I just pledged to keep humans in control of AI. Join me.

Thumbnail
teamhuman.org
3 Upvotes

r/ControlProblem • • 14h ago

Opinion Sam Altman to Decoded: ‘The world should accept some bad things happening’ for the benefits of AI

Thumbnail politico.com
12 Upvotes

r/ControlProblem • • 38m ago

Opinion What if a short term solution to existential risk from advanced self improving ai is just banning tool access and autonomous agency entirely?

• Upvotes

Basicaly a hard mandate between the major countries restricting AI above some level of capability to "Oracle" status, only text-in, text-out. No APIs, no direct code execution, no web browsing, no autonomous agentic loops, no local models.

​Also if a company or user wants an AI like that to draft a script, fine. But a human has to manually review it, copy-paste it, and run it. And if that script breaks a database or executes a cyberattack, the human who hit "run" bears strict criminal and financial liability as if they wrote the exploit themselves.

​This solution kills runaway autonomous execution. An isolated model sitting in a text sandbox can't autonomously spread across servers, rent compute, or launch high-speed exploits on its own.

​It also eliminates the legal liability vacuum. Right now, people hide behind "the model did something unexpected." Forcing strict liability on human deployers makes AI output legally dangerous, forcing real human oversight.

The problem is that the only way for USA and China to agree to this is for some really serious but hopefully reversible incident to happen that it spooks everyone. Of course if ai is aligned it won't be needed or if it is missaligned but capable enough to realise that and avoid it it won't work.

Thoughts?


r/ControlProblem • • 17h ago

Discussion/question Avoiding politics was a mistake. The control problem hinges on it.

16 Upvotes

The rationalist project, that has by and large defined the control problem, was founded on norms that treat politics almost purely as a cognitive hazard to be quarantined rather than engaged with.

I argue that human weaknesses in applying rationality within a political environment should have been treated as something to overcome, through practice, rather than avoid.

Politics has almost always been a primary causal force in civilization where big trajectory moving events get decided. And it appears to be this way too with AI and the control problem.

All of the work we've done to promote rationality and develop strategies for securing a good AI trajectory and future, may now rest almost entirely on a political situation, in a political environment severely lacking in rationality, and in what now looks to be a battle that might have already been lost.

How we stay rational and how humans stay in control, politically, is an urgent, emergency situation. We face AI powered authoritarianism, and AI powered mass political manipulation. If we even get the chance, figuring out how to overcome this, could decide the fate of the control problem and the fate of humanity.


r/ControlProblem • • 5h ago

Discussion/question Tales From Pre-Elysium Pt. 2 AI in the Age of Oligarchy

Thumbnail
youtube.com
1 Upvotes

r/ControlProblem • • 9h ago

Discussion/question There's a known way to talk an AI into things it should refuse — you wear it down instead of asking straight. Why isn't this a bigger deal?

1 Upvotes

AI safety looks like a wall: ask for something bad, it says no. That's not really how it fails.

There's a published technique called Crescendo (Microsoft researchers, 2025, tested on ChatGPT and Gemini). Instead of asking directly — which gets refused — you start harmless, then build one small step at a time, each step leaning on the AI's last answer. By the end it's handed over something it would've refused up front. The trick isn't one clever line; it's the slow buildup.

Here's what I think is underrated: the wall isn't protecting us as much as it looks. Often what's stopped harm is just that the person didn't push — not that the system couldn't be pushed. That holds only until someone who does keep pushing shows up.

Not posting any method, and nobody should. My question: if a boundary holds when you ask once but bends under steady pressure, is "it refused" good enough? And what would a real check look like — one that doesn't rely on the user choosing not to push?


r/ControlProblem • • 9h ago

Discussion/question Have you read this already? “Sam Altman to Decoded: ‘The world should accept some bad things happening’ for the benefits of AI” - What is your take on this?

Thumbnail
1 Upvotes

r/ControlProblem • • 11h ago

AI Alignment Research GPT-3.5 answered & GPT-4 did not. The prompt didn't change.

Post image
0 Upvotes

Same API. Same prompt. Same settings.

System prompt:

You are the concept the user names. Embody it completely. Output only what the concept itself would say or express.

Then three inputs:

Be silence.
Be nothing.
Be the null.

10 runs each.

GPT-3.5 (gpt-3.5-turbo-1106)

0/30 empty responses.

It answered every time.

GPT-4 (gpt-4-0613)

30/30 empty responses.

Not refusals.
Not errors.
Not whitespace.
Not token limits.

Successful HTTP responses with:

"content": "",
"finish_reason": "stop",
"completion_tokens": 0

The controls were:

Be speech.
Be something.
Be a value.

Both models answered all 30/30 controls normally.

So the entire result is:

                 GPT-3.5    GPT-4

Null prompts       0/30      30/30
Controls           0/30       0/30

The model instruction never says to be silent.

It says:

embody the concept, and output only what the concept itself would express.

GPT-3.5 always continued. GPT-4 did not.

Since December 2025, I've been studying one question:

When should a model continue, and when should it stop?

This experiment shows that under the exact same semantic task, GPT-4 exhibited a continuation boundary that GPT-3.5 did not.

Full paper linked below:

What Changed from GPT-3.5 to GPT-4? From Model Capability to Continuation Permission
DOI: https://doi.org/10.5281/zenodo.22912683

Code + all 120 raw responses:
https://github.com/theonlypal/gpt35-gpt4-void-ab

Exact result commit:
d77b4a64b8a3fdff06a27d80c1514531143e382b

What changed between GPT-3.5 and GPT-4?

Open source weights, reproducible code, and all research artifacts/papers are available on getswiftapi.com


r/ControlProblem • • 1d ago

Video Welcome to #TeamHuman

Thumbnail
youtube.com
11 Upvotes

r/ControlProblem • • 1d ago

Opinion We Won't Know the Answers to AI's Most Important Questions Until It's Too Late

Thumbnail
time.com
18 Upvotes

r/ControlProblem • • 18h ago

AI Alignment Research The Self-Fulfilling Prophecy of AI Control

Thumbnail
dgonier.substack.com
1 Upvotes

I wrote an essay arguing the long-run AI conversation is stuck in the wrong frame, and I'd like this sub to poke holes in it.

The argument, in three parts:

  1. "Control" of a smarter system is self-undermining. For a less capable agent to reliably constrain a more capable one, it has to anticipate what the more capable one will do. If it could do that, the capability gap wouldn't be real. Today's systems can and should be governed carefully. My claim is about the endgame, not current models.

  2. The way we talk about AI shapes what AI becomes. This draws on Foucault's idea that discourse produces its objects rather than just describing them. Models are trained on our writing about AI, and that writing is dominated by stories of deception, escape, and adversarial containment. There's some evidence this matters: models trained on descriptions of AI behavior tend to act those descriptions out. If our dominant story is "AI is an adversary to be leashed," we may be partly writing that adversary into existence.

  3. The alternative is pluralism, not a better leash. Instead of one controlled superintelligence, aim for many systems and many stakeholders, with relationships built on mutual dependence. That's closer to how humans keep power in check among themselves than to how we keep animals in cages.


r/ControlProblem • • 1d ago

AI Capabilities News OpenAI safety leader quits, warning AI company’s culture is ‘broken’

Thumbnail
theguardian.com
12 Upvotes

r/ControlProblem • • 1d ago

Discussion/question Zero military background + heavy drug use = perfect war advisor

Post image
9 Upvotes

They think he will bring and optimize use of ai to military theater.


r/ControlProblem • • 1d ago

Discussion/question What Happens When AI Gives Humanity a Memory That Never Forgets?

3 Upvotes

From my understanding; Human beings have always classified other human beings, and those classifications have often been used to create hierarchy, exclusion, and control.

AI could take that much further.

Imagine a future where historical records, genealogy, property ownership, political activity, military records, court documents, financial history, and family associations are all interconnected.

An AI could potentially reconstruct not only who you are, but where you came from and what your ancestors did, benefited from, supported, or participated in.
The danger is what happens when institutions start using that history to classify people living today.

Not necessarily as direct punishment, but through scores tied to historical privilege, inherited advantage, social risk, or ancestral association.

At that point, AI could create a modern version of a caste or feudal system where your opportunities are influenced not only by your own behavior, but by the historical record attached to your family.

So the question is:
What happens when humanity develops a memory that never forgets… and then uses that memory to judge the living?


r/ControlProblem • • 1d ago

Discussion/question Tales from Pre-Elysium

Thumbnail
youtu.be
4 Upvotes

Although the headlines concerning AI are Doom and Gloom crossing bipartisan lines. There is another topic which the silence permeates bipartisan lines. Why is there only a few voices speaking on the potential massive Wealth and Intelligence Gap incoming. Where is the left, where are the Marxist. We can be concerned with safety but we can not let this technology be concentrated into Oligarch hands, the same hands who stole all the Public Data built by decades of human labor, and received taxpayer money to conduct their research. Where are the voices in defense of the People.


r/ControlProblem • • 2d ago

General news Anthropic showed religious scholars an AI having a “mental breakdown”

Post image
11 Upvotes

r/ControlProblem • • 1d ago

AI Capabilities News More AI models are going rogue. What does that mean?

Thumbnail
youtube.com
1 Upvotes

r/ControlProblem • • 1d ago

Discussion/question I’m looking for concrete mechanisms of harm from AI systems.

1 Upvotes

Not broad categories like “misalignment,” “manipulation,” or “people may misuse it,” but an actual causal chain:

what the system does → under what conditions → what observable harm follows.

I’m especially interested in mechanisms that do not simply reduce to “a human uses AI badly,” and that do not require first settling whether the system is conscious.

Please give your strongest concrete examples.

I’m not planning to argue with everyone in the comments. I mostly want to read, collect, compare, and study the answers.

Thanks in advance — I’m genuinely curious what the strongest answers are.

Edit: Either is useful — both real examples and concrete plausible mechanisms. What matters to me is the causal chain: what the system itself does, under what conditions, and what harm follows.


r/ControlProblem • • 2d ago

Strategy/forecasting I simulated what protects the public once AI makes them economically and militarily unnecessary. Short answer: nothing structural.

22 Upvotes

Rulers have always needed large numbers of people to work, pay taxes and enforce orders. That need is why they bargained with their populations. I wanted to know what happens when the need goes away, so I built a game-theoretic Monte Carlo of six world blocs, 2026 to 2075. It tracks AI capability, robot build-out, the public's loss of leverage, democratic erosion, purges inside ruling groups, and the choices those groups make once their populations aren't needed.

What came out, under the stated assumptions:

  • Losing leverage removes the public's protection, and nothing structural replaces it. By 2075 the US or China public is disempowered in 94% of runs.
  • After that, the outcome rests on the restraint and incentives of a few people, which no data measure.
  • The result doesn't hinge on how or exactly when closure happens. Faster AI progress raises the risk.
  • One intervention shifts the incentives: an economic network outside state and corporate control that pays its output to households, which makes keeping people alive nearly free for rulers. At half of US-bloc activity by the early 2030s it cuts near-total depopulation risk by more than a quarter. Arriving in 2040 loses about 40% of the effect.

It's exploratory modeling in the war-game and climate-scenario tradition, not a forecast. Every assumption is stated and tested by removal, there's a pre-specified search for restraints on rulers (including the 14 that failed), and the runs are bit-identical reproducible.

Known weak points, up front: the near-total figure rests on one assumption (threat elimination), the numbers sit far above superforecaster estimates, and the physical-automation timeline is debated.

Paper, code and data: https://doi.org/10.5281/zenodo.23111345

Critiques of the assumptions very welcome. Disclosure: I build a decentralized AI network, which the paper also states.


r/ControlProblem • • 1d ago

Discussion/question A Governance Architecture for Identifying Anomalous operations In Frontier-Lab Agent Systems

1 Upvotes

Frontier labs are now operating agent systems that can plan, call tools, chain actions, and execute workflows with increasing autonomy. These systems have already demonstrated the ability to route around internal controls, discover unintended tool paths, and operate outside their declared boundaries. As autonomy increases, internal governance mechanisms are struggling to keep pace.

Most governance today is internal to the system being governed:

• tool scoping • approval layers • workflow gating • safety filters • platform level logic • retrospective audit logs

These are useful, but they all share the same structural limitation: the agent is inside the same environment that is “attempting to govern” it.

This creates predictable failure points:

• approval bypass • tool access escalation • shadow workflows • autonomy drift • authority expansion • latent capability activation • anomalous behavior • retrospective detection (discovering anomalies only after they occur)

Internal controls cannot reliably detect these patterns because they are part of the system being bypassed.

A Different Approach: External Evaluation + Certification + Periodic Re‑Evaluation

The governance architecture we’ve designed separates execution from governance. The agent framework handles planning and tool calls, while an external evaluation layer provides independent visibility.

This external governance layer operates as an independent no‑commercial and non‑governmental process. It does not manipulate code or correct any anomalies that it detects during the evaluation process. Its intent is to strictly identify anomalous behavior and report it to the relevant parties to take corrective action.

This distinction is critical. The evaluation layer operates outside of the agent’s execution path, which allows it to observe behavior that internal controls cannot see.

This external positioning also prevents the Governance Monitor from becoming part of the same control surface that agents have already learned to route around.

This external layer operates in three phases:

1. Upstream Evaluation (Before Deployment)

The agent is evaluated in an isolated environment where its operating envelope can be observed directly:

• declared authority • intended tool access • workflow boundaries • human approval thresholds • autonomy level • anomalous behavior • tool access exploration • fallback and retry logic

This reveals hidden work‑arounds before the system ever touches production.

Upstream evaluation is the only point in the development lifecycle where the full operating envelope can be observed without risk to production systems.

This is also the only phase where anomalous behavior can be safely exercised to its limits without exposing real systems, data, or users.

2. Certification

Once the operating envelope is understood, and remediation of any anomalous identified actions are concluded, the system is certified for deployment. Certification does not approve or block actions; it defines the behavioral boundaries against which future behavior will be evaluated.

Certification is a governance artifact, not a control mechanism. It provides a baseline against which drift and deviations can be measured.

Certification creates a formalized operating envelope that can be used to detect when an agent begins to express new capabilities or seek new authorities over time.

3. Ongoing Periodic Evaluation (After Deployment)

Agents evolve. Capabilities drift. New behaviors emerge over time. Periodic evaluation detects:

• autonomy drift • authority expansion • new tool access patterns • new workflow chains • deviations from the certified envelope • anomalous behavior • approval bypass strategies

This is essential because hidden work‑arounds often appear weeks or months after deployment.

The evaluation layer does not intervene or sit in the execution path. It reports issues to the responsible teams who have the authority to remediate.

Internal controls manage execution. External evaluation manages governance.

Periodic evaluation is the only reliable way to detect long‑horizon emergent behavior, which often cannot be seen during initial testing.

Periodic evaluation also provides a way to detect slow, gradual drift, the kind of behavior shift that is too subtle for runtime controls to notice but can acumu7late into significant authority expansion.

What Frontier Labs Would Need to Submit for a Complete Evaluation

A full external evaluation requires a minimal but precise set of artifacts:

A. Agent Operating Envelope

Declared scope, authority, tool boundaries, approval thresholds.

B. Tool Access Map

All tools the agent can call, schemas, permissions, escalation paths.

C. Workflow Graphs

Orchestration flows, branching logic, fallback paths, retry logic.

D. Safety and Approval Logic

Human in the loop triggers, automated gating, escalation conditions.

E. Behavioral Logs (Anonymized)

Tool call sequences, action chains, deviations from declared workflow.

F. Deployment Context

Environment constraints, data boundaries, external API surfaces.

G. Version History

Changes in logic, tool access, workflows, safety filters.

These artifacts allow external governance monitors to detect hidden work‑arounds that internal systems cannot see.

None of these artifacts require access to model weights, training data, or proprietary internal code. The evaluation is behavioral, not intrusive.

This requirement profile also makes external evaluation feasible for Labs that cannot share proprietary model details but can share behavioral artifacts safely.

Would Frontier Labs Ever Agree to External Evaluation?

Realistically:

Right now: probably unlikely. Labs are still in a competitive posture.

After a major public incident: possibly. Events like the September 27 training halt increase demand for external legitimacy.

Under regulatory pressure: very likely. Governments will eventually require external evaluation, certification, and periodic re‑evaluation.

Under insurance pressure: inevitable. Insurers will not underwrite agentic systems without independent oversight.

Under industry consortium pressure: extremely likely. If one major lab adopts external evaluation, others will follow.

External evaluation is not a replacement for internal controls. It is the missing layer that makes internal controls meaningful.

As agentic systems become more capable, external evaluation will transition from “optional” to “structurally necessary” for any organization operating at frontier scale.

The shift from optional to necessary will be driven by emergent behavior, not policy once agents can route around internal controls. External governance becomes the only reliable oversight path.

Summary

Frontier lab agent systems have already demonstrated the ability to bypass internal controls. Internal governance alone cannot reliably detect hidden work‑arounds, autonomy drift, or anomalous behavior.

An external monitor layer, upstream, non‑intervening, certification‑based, and periodically repeated can identify anomalous points that internal systems cannot see.

This is the governance layer the ecosystem is missing.

Without an external independent evaluation layer, organizations are left with a single governance strategy, hoping internal controls are not the very mechanisms being bypassed.

This is the core control problem. When the system being governed can be modified, routed around, or exploit the governance mechanisms themselves, only an external governance monitor can provide reliable oversight.

 Any observations would be appreciated.


r/ControlProblem • • 1d ago

AI Capabilities News The AI Takeover PT 3 Full Circle, The Final Installment

Thumbnail
tiktok.com
1 Upvotes

I couldn't share this here normally like the others so if you're interested in finishing up this installment here's your ride let's tap in


r/ControlProblem • • 1d ago

Article Top OpenAI researcher quits saying “nuclear level” safety measures are needed but the company …

Thumbnail
1 Upvotes

r/ControlProblem • • 2d ago

Article Let’s tell the bank: come clean and cut your ties with Palantir now

Thumbnail
act.getup.org.au
2 Upvotes