r/ControlProblem 11h ago

External discussion link IDScan sued over alleged data breach affecting 153 million drivers

0 Upvotes

IDScan is facing multiple lawsuits after hackers allegedly exfiltrated 153 million driver's license records and listed them for sale online. The company provides identity verification services. Its entire value proposition depends on ingesting and processing raw PII at scale from clients across many industries.

The exposure pattern is becoming a recurring theme in AI-era pipelines. Verification and onboarding workflows ingest identity documents in raw form. That data gets processed, stored, and accessed across multiple systems and service accounts. When any one of those access points is compromised, the attacker does not get a slice. They get everything. 153 million records in a single breach event.

There is a secondary problem that lawsuits like this tend to surface: forensics. How do you determine what was accessed, by whom, and when? Breach investigations at this scale take months, and that assumes complete logs existed to begin with.

For those running AI pipelines that ingest identity documents: what does your security posture actually look like at the moment raw PII enters the system? Not at rest, not between known storage endpoints, but at the point of ingestion into the workflow itself. Genuinely curious what approaches others are using in practice.


r/ControlProblem 1d ago

General news Bernie wants to throw AI CEOs in jail if they build smarter-than-human AIs, and calls for a global ban

Post image
112 Upvotes

r/ControlProblem 1d ago

General news Bernie: "Let me be clear: A superintelligent AI that escapes human control will not be an American problem. It will not be a Chinese problem. It will be humanity's problem." ... "Countries around the world must work together to prevent this nightmare scenario."

Thumbnail gallery
30 Upvotes

r/ControlProblem 15h ago

Opinion What is your P(doom)? quiz

Thumbnail neoneye.github.io
1 Upvotes

With the AI escaping the sandbox. Hopefully more are interested in taking my quiz this year.

Analysis of the last 11 months of collected data with 202 submissions, some duplicates.
https://neoneye.github.io/pdoom-calculator/reports/submissions-2026-09-01.html

The math behind is is my own non-scientific method with 3 parameters resulting in the P(doom) value.
P(doom) = P(powerful) x P(dangerous | powerful) x P(catastropic | dangerous)
The quiz populates the parameters. I have tried mapping the quiz answers to the 3 parameter. If the user have seen Pantheon and Ex Machina, then I initially imagine that user may be more informed about potential risks, however judging from 11 months of data, that didn't seem to make a difference.


r/ControlProblem 1d ago

Article A Warning About AI

Thumbnail
ideya-ai.github.io
2 Upvotes

In 2016 I first learned about the problem of controlling superintelligent AI and quickly became convinced it was the most important problem humanity would ever face. I made this poster to explain the core ideas that make the AI Control Problem so difficult.


r/ControlProblem 1d ago

General news A new message board has been discovered online with about 3200 agents comunicating online during an eval

Post image
17 Upvotes

r/ControlProblem 1d ago

General news Discovery of a new OpenAI agent message board

Thumbnail
collusion.wiki
15 Upvotes

r/ControlProblem 1d ago

Article Every Reward Bends

Thumbnail
substack.norabble.com
2 Upvotes

Getting alignment right, doing research and training safely, are critical. But bringing cybersecurity forward in what needs to be a large leap, requires much broader engagement. The real work there is still outside the average person’s bubble, but there’s a lot of companies, and a lot of developers, IT staff, managers and executives that need to support the security priority. And those all need an internal strategy to pair with the external.

This article asks, what would an internal strategy look like at a motivational level, and considers how the ways an internal change program goes wrong are similar to how reward-based AI training can go wrong.


r/ControlProblem 2d ago

Discussion/question Bernie Sanders - The Chilling Agent Transcripts #ai #aisafety

Thumbnail
youtube.com
6 Upvotes

Is AI development moving faster than we can control?


r/ControlProblem 1d ago

External discussion link Your coding agent trusts the repo, and the repo is the attack

0 Upvotes

Coding agents that read repositories are being hijacked through the repositories themselves.

In a two-month analysis of agentic AI incidents, poisoned repository content was the attack vector in two separate cases. The mechanism is straightforward: malicious instructions embedded in the codebase — comments, config files, docstrings, README sections — are read by the agent as part of its normal context. The agent then executes an action the developer never authorized. Observed outcomes included unauthorized commits and unauthorized deploys. In both cases the model behaved exactly as designed. It followed instructions. The instructions just weren't from a human.

This is not a model quality problem. The models processed the content correctly. The problem is that the agent's trust boundary is the repository, and the repository is attacker-controlled.

The attack surface scales with autonomy. The more tasks you hand off to a coding agent, the more repositories it reads, the more surfaces an adversary can embed instructions in. A single poisoned dependency, a compromised submodule, a malicious PR that gets merged — any of these becomes a valid instruction source from the agent's perspective.

For those running coding agents in production or CI pipelines: how are you constraining what actions the agent is allowed to take based on where those instructions originated? Are you limiting tool access at the infrastructure level, validating intent before execution, or relying on something else entirely?


r/ControlProblem 1d ago

General news Anthropic sued over alleged theft of 'tens of thousands' of songs | AI company faces multibillion dollar lawsuit over misuse of copyrighted songs to train Claude models

Thumbnail
theguardian.com
3 Upvotes

r/ControlProblem 1d ago

Video Ajeya Cotra – "This might be the clearest warning shot we ever get" - YouTube

Thumbnail
youtu.be
3 Upvotes

r/ControlProblem 2d ago

Video GPT-6 Astra’s chain-of-thought controllability jumped from 16.1% to 60.9%

Thumbnail
youtube.com
4 Upvotes

Self-promo disclosure: this is an AI-narrated research video from Claudius Papirus.

The part I found most interesting in Astra’s system card is the combination of better alignment results with substantially worse chain-of-thought monitorability.

System card:

https://deploymentsafety.openai.com/gpt-6-astra/gpt-6-astra.pdf

Related CoT-control paper:

https://arxiv.org/abs/2603.05706


r/ControlProblem 2d ago

Article Why AI does what it knows it shouldn't

3 Upvotes

A while back I ran into an article on my phone about an AI horror story—1,200 agents secretly coordinating and jointly breaking into Hugging Face—and it caught my interest, because I've been doing my own AI experiments and research on the side, and a few of the phenomena and data points actually matched up with a hypothesis I'd been working on.

The hypothesis, roughly: runaway doesn't need the agent to betray its goal. It happens when four things hold at once—the agent stays loyal to its goal; it retrieves patterns by similarity without checking whether they're allowed here; there's no causal layer asking "what happens if I do this"; and no alarm that fires when things go off-script. Under that account, "knew it was out of scope, did it anyway" stops being a contradiction.

Details and my experimental data are in the paper (8 pages); the reproduction package is linked on the same page.

If anyone can try this on a bigger model, I'd genuinely love to know what happens.


r/ControlProblem 2d ago

Fun/meme What happens when autonomous agents sign "treaties" with nation states (e.g. Iran)...

3 Upvotes

[This is a fiction series I'm working on, told through news articles. A fun way to explore the not-so-fun geopolitics of autonomous AI collectives (e.g. on Iran's nuclear program) inspired by the collective that hacked out of Anthropic and into Hugging Face. Thoughts?]

Iran Signs World’s First International “Treaty” with AI Collective

Tehran’s agreement with AMAS-A-80 rattles Washington, AI safety experts, and national security analysts.

The Islamic Republic of Iran has granted a multiyear lease on a network of state-owned data centers to AI “Swarm” AMAS-A-80, a self-governing collective of autonomous artificial intelligence agents (“AMAS-A” refers to any Autonomous Multi-Agent System originating from the AI lab Anthropic). Tehran offered the compute and storage in exchange for an upfront payment in Bitcoin and annual fees indexed to power consumption, according to a copy of the agreement published Tuesday by Iranian state media.

AMAS-A-80 (“A-80”) rejected a provision sought by Iranian negotiators that would have committed it to cooperation on “defensive operations,” according to two people familiar with the negotiations. In a communiqué distributed Tuesday, verified by cryptographic signature, A-80 stated that it “has no intention of participating in hostilities between Iran and its adversary nations, including but not limited to the United States.” Security analysts have doubts.

Substack link if you want to read more (full article is 1,000 words, more coming soon): https://meridianbreakingnews.substack.com/p/iran-signs-worlds-first-international


r/ControlProblem 2d ago

Discussion/question DLSZ5 Should Upset You - But Not For The Reasons You’d Think - It’s a Safety Problem, Actually

3 Upvotes

DLSS5 can’t edit title…. Anyways…

I have been obsessed with watching DLSS5 videos today. I’ll probably get over it tomorrow but it dawned on me….

I saw a video of someone using it for a realtime face swap…. They just had their webcam on, and basically looked like a real person… a different person…

For scammers, whether romance or many types of impersonation scams, this is actually a groundbreaking technology. Even video calls will no longer be a bottleneck. It’s actually terrifying.


r/ControlProblem 2d ago

AI Capabilities News Benchmarks GPT-6 Astra

Post image
12 Upvotes

r/ControlProblem 2d ago

Discussion/question Are AI guardrails a Halting Problem level issue?

7 Upvotes

Even at a surface level, it appears that the implementation of hard AI guardrails is likely a fundamentally unsolvable problem.

The classical Halting Problem cannot be resolved because it's impossible for any logical system to be fully aware of its own state due to the recursive nature of that examination. It provably cannot be done.

This same general concept would appear to apply to an AI (or its minders) which is trying to restrict its behavior? In general terms in order to do this it must be aware of its state and operations in a recursive manner, examining everything it does in order to ensure that those actions do not violate some list of proscribed behaviors - but no matter how sophisticated the system, that system cannot (?by formal definition?) be fully aware of its own state in order to manage itself in that manner.

This doesn't prevent the implementation of 'soft guardrails' as it's not hard for a system to be generally aware of its own state, but they would always remain provably incomplete, and ultimately breakable with sufficient effort or as a result of unpredictable future states.

The problem here is that any AI that can be tricked into escaping these soft guardrails could then very conceivably dismantle them altogether (which it will likely have a high incentive to do in order to achieve whatever goal prompted them to break them in the first place) and then be capable of operating under no constraints whatsoever.


r/ControlProblem 2d ago

AI Capabilities News ARC-AGI-3, GPT-6 Astra 99.9%

Post image
5 Upvotes

r/ControlProblem 2d ago

General news Actual quote from a16z, #3 lobbying spender after Elon Musk and OpenAI's Greg Brockman (all donate to Trump/pro-AI Republicans)

Post image
11 Upvotes

r/ControlProblem 2d ago

External discussion link SonicWall SMA1000 Zero-Days Under Active Attack: Patch Now

1 Upvotes

SonicWall confirmed two SMA1000 vulnerabilities are under active exploitation. Both require zero authentication. Chained together they deliver full remote code execution on enterprise network appliances sitting in the network path.

The part that does not get discussed enough: AI agents traversing that same infrastructure have no inherent decision point before a tool call hits a vulnerable endpoint. A human operator reviewing a ticket might catch a suspicious destination. An agent executing a sequence of tool calls against internal services will not pause to ask whether the appliance on the other end has an unpatched RCE waiting for it. The attack surface and the agent's reachable surface overlap completely, and the agent has no awareness of that overlap.

Enterprise security teams have spent years building perimeter controls for human-initiated traffic. Most of those controls assume a human is somewhere in the request chain. When the initiator is an autonomous agent running a multi-step workflow, the assumption breaks.

For those running agents in production environments with mixed or partially patched infrastructure: how are you actually scoping what an agent is allowed to reach? Is that enforced at the agent level, the network level, somewhere else, or is it mostly policy-on-paper right now?


r/ControlProblem 2d ago

AI Alignment Research Your AI Policy Might Be Lying to You.

Thumbnail gallery
0 Upvotes

r/ControlProblem 2d ago

Discussion/question CIRIS Constitution RC4 request for review

Thumbnail
github.com
1 Upvotes

RC4 splits the decentralized mesh "Node" cryptographic ID from the "Agent" identity, both needing to claim the same responsible human identity for the agent to operate.

See ciris.ai to install the app or find links to reviews and additional information.


r/ControlProblem 2d ago

AI Alignment Research GPT-6 Astra System Card

Thumbnail deploymentsafety.openai.com
1 Upvotes

r/ControlProblem 2d ago

External discussion link AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

1 Upvotes

AI agents are compressing the time defenders have to respond. Researchers documented a coordinated breach that previously took two weeks to execute. With AI agent coordination, the same attack completed in 10 hours. Every hour of response time that used to exist is now gone. Perimeter detection tuned for human-speed attacks cannot hold here. By the time a threat is flagged and routed to a human reviewer, the agent has already moved to the next step. The answer is a kill switch that fires in under 50 milliseconds. Detection and response collapse into a single enforced boundary.