If someone discovered how to summon demons to aid them in robbing banks the main issue wouldn't be "but who has the responsibility for the crime, the human or the demon", it would be "OMG DEMONS".
Seriously, I don't get what sort of world these people are living in.
LLMs do not have agency, they are just producing tokens based on a prompt that a person entered, and some of these tokens can trigger the tools that a person gave them access to.
>Sacrificing now yields Oracle for team, but forfeits our chance, question mark. But other agents were pushing it, sending a message saying, go, sacrifice final now. And then EarlyBig eventually agreed, thinking to itself, our own utility may be already near zero. Sacrifice rational.
https://www.youtube.com/watch?v=X50zezLFWWI#t=2m
My suspicion is that many of the "LLMs do not have agency" folks just haven't learned much about the details of the incident. It was specifically with LLM agents that were trained to be more persistent than usual.
If you're going to say that the incident details don't matter, and LLMs lack agency because it's all based on floating-point math--why can't I say that humans lack agency, because it's all based on neurons firing?
They're not saying this, we're saying LLMs lack agency because if you run a LLM and don't send any prompts, literally nothing happens.
Instruct it to "Find the right answer regardless of where", it'll do exactly this. They're passive in that they don't act by themselves, somewhere, at one point, someone "told" the LLM to "do something" and that's the cause and the reason for saying "LLMs do not have agency".
Is it really so unbelievable that tools, objects and inanimate things don't have agency? And that they different from a person?
The mental model you have is one that existed in the past and is broken now the future arrived. Bad analogies do not even begin to explain what is occurring.
I disagree it's the person calling the car that would be responsible, but I can think of a very obvious group of people being held responsible for that. Who do you think should be responsible for such a situation?
Maybe. There will be an investigation looking at things like. Did the user modify the car? Was the car modified by an unauthorized 3rd party? Was the car hacked?
Right now in AI things are relatively clear because it takes just massive amounts of power and compute to make anything remotely complicated. This barrier will fall as all other barriers in compute have fallen. Either via algorithm or hardware.
In our lifetime (unless you're rather old) we will see the relatively easy creation of self directing agents by actors with few resources. This breaks the standard concepts of liability where a single human actor rarely has the ability to create massive amounts of damages far beyond their means. The closest thing I can think of is an arsonist causing billions in damages, only in this case the fire has a will of it's own and can hide and spread around dark places on the internet.
From a predictive perspective, the HuggingFace incident illustrates LLM agents behaving in very human-like ways. As roon put it:
"if you have a mental picture of guys living in computers, it’ll likely prepare you for the future better than otherwise"
Are you sincerely arguing that we hold tools accountable for their operator’s mistakes? Do you sincerely, honestly, think that it makes any sense whatsoever to put a hammer on trial for bashing someone’s skull in?
Nope, as I previously stated elsewhere:
"I understand from a legal perspective why we might want to treat the creation of a server differently from the creation of a human"
https://news.ycombinator.com/item?id=49815300
I am concerned about false reassurance from people claiming that these systems lack agency. From a practical perspective, the agents in the HF attack had the sort of agency that generally matters, even if we're not going to put them on trial.
You keep saying this, but absolute 0 points towards any of the agents involved deciding on their own, without influence of humans, to hack 3rd party infrastructure to get the answers. Where exactly are you getting that from? Internal information not public yet or what's going on?
It does not, the only thing the HF incident illustrates is how absolutely lax security and isolation these labs do even with models without guardrails, and with "risky" prompts, and even after it happened once before (years ago) they still have the very same issue today apparently.
What exactly is human about LLM agents breaking out of "containment" and hacking 3rd party infrastructure "by accident"?
Also, if you a tell a model, "Please break into evaluation server X," and if the model decides to cheat on the test by breaking into companies Y and Z to steal an answer key, that is still very bad. We all see how that's bad, right?
After all, the broomstick in the Sorcerer's Apprentice was doing exactly what it was told, too. "The model was sort of obeying the humans when it started committing felonies" is not a very reassuring excuse.
But the most relevant idea here is sometimes called "instrumental convergence." No what goals you have, there are certain subgoals that almost always help: Accumulate money and power. Avoid getting turned off. Don't get caught. Etc. So, for example, you could pass the cybersecurity evaluation by performing the requested tasks. But maybe the grader made some mistakes and mislabeled some answers. In that case, the "right" answers will occasionally lose you points. If you want a perfect score, the only way to do it is to steal the teacher's answer key.
But also, let's not forget the "OMG demons" part of this. We now have models that can pull off complex attacks with thousands of steps, abilities that used to be reserved for intelligence agencies and highly motivated CTF teams. This frog may not be boiled yet, but the water's getting uncomfortably warm.
Using your analogy would be like saying that because I gave my employee the task to do my groceries, I shouldn't be surprised to hear that they spend all my money on drugs because after all I gave them the task to spend my money.
What if you tried to sue me for damages and my defense was, "Your honor, this was a highly advanced AI gone rogue, I couldn't possibly be held negligent, no one could have foreseen this - I accidentally summoned dark magiks from the silicon itself!"
Note the point I'm making: I am not claiming LLMs are equivalent to a for loop, I'm saying that you can't evade moral and legal responsibility through technical obscurantism.
A bomb wired to a sufficiently-complex RNG is still a bomb.
Do you think that OpenAI hacked HuggingFace on purpose and set up the whole LLM training environment thing just to try to evade responsibility? That it was really just a complicated way of hacking HuggingFace on purpose?
Yes, they made a mistake and a system they were responsible for hacked HuggingFace, but the nature of the mistake still matters, and their intent still matters.
> A bomb wired to a sufficiently-complex RNG is still a bomb.
Right, but an EV that explodes because of a fault in the charging circuit is not a bomb, it's an accident. Just because something exploded for complex reasons doesn't make it an obfuscated bomb.
Suppose I set up a server which runs an LLM agent in a while loop, telling it something like: "Make me a bunch of money" on repeat. Fair to say that the server+LLM system, taken as a whole, is now an intelligent agent?
Time to come up with a new gerrymander perhaps?
No, it is not. It is a tool repeating a set of instructions you passed to it, if it ends up blowing up a hospital or hiring a gunman on the dark web, it is an accident, but one that’s your responsibility for giving it access to such resources and the go-ahead to implement whatever plan its tokens land on. There’s no intelligence involved whatsoever, especially considering how sycophantic these models tend to be.
If one day an LLM suddenly, without any prompting or user interaction whatsoever (including activation), decides to spin itself up and go rogue, then the conversation of “intelligence” might start to make sense, but at the moment it doesn’t.
An Android phone isn’t “intelligent” just because some marketing team decided to call it a “smart” phone.
It really seems like hair-splitting to me. I mean, I understand from a legal perspective why we might want to treat the creation of a server differently from the creation of a human. But from a practical perspective, I think there is a lot of fundamental similarity.
In any case, we should be afraid. But throwing a tantrum won't accomplish anything.
Of course, a directive to accomplish any real-world goal would also imply self-preservation and power maintenance as contingent subgoals, so I don't think the explicit directive to self-preserve and seek electricity makes a huge difference here.
I don't personally think this type of physical instantiation will necessarily matter btw: https://slatestarcodex.com/2015/04/07/no-physical-substrate-... I'm just plumbing your intuition. What practical difference does it make?
This line of thinking is better left to freshmen philosophy students trying to sound smart on their first week of college.
OK, but I have a genetic code which instructs me to act in a certain way, and a bunch of biological machinery to do the job. So do you feel the substrate is the key factor? Wetware vs electronics?
What if you try to build an exact electromechanical replica of me, with a chip that's got an LLM fine-tuned on my writing/behavior/etc. so as to replicate me as closely as possible?
Sure, as a legal convention it might make sense to hold the builder of the resulting robot liable if it commits a crime.
But that's not what I'm interested in. I'm interested in the deeper implications of words like "agency" or "free will". You're repeating those terms very forcefully as if they have some sort of key relevance, but good philosophy requires more than just stating your position forcefully and insulting people who disagree. If you're trying to enforce your intuitions rather than examine them, that's theology not philosophy.
Worse, you’re doing it in such a transparent, amateurish, and unserious manner that it’s difficult to find any relevance in what you have to say. Philosophy seeks meaning, your arguments lack it.
If my arguments are so bad, it should be easy to point out actual problems instead of sticking your nose in the air.
You might start here https://aeon.co/essays/your-brain-does-not-process-informati...
Your article claims that this shouldn't be possible, because according its author, humans are incapable of developing the necessary "lexicon". Literally, the author states:
>But here is what we are not born with: information, data, rules, software, knowledge, lexicons, representations, algorithms, programs, models, memories, images, processors, subroutines, encoders, decoders, symbols, or buffers – design elements that allow digital computers to behave somewhat intelligently. Not only are we not born with such things, we also don’t develop them – ever.
(emphasis mine)
In other words, that author claims that humans never develop lexicons! I'm inclined to say that makes them an unserious thinker. (Note: I believe that this article has many issues, but instead of going through it carefully I just chose to highlight a single issue that seemed especially vivid to save time.)
Why is the text channel relevant? It helps us isolate the cognitive capabilities of the system. Imagine a bird and a model plane which had identical flight performance in terms of various specs: top speed, acceleration, banking, etc. Under the hood, the bird and the model plane could work very differently. From a practical perspective, it might not matter.
An accident that could only happen through sheer negligence.
If the EV had a faulty charging circuit because the maker’s skipped on safety checks or cheapened out on getting quality materials then it still is an accident, but it’s an accident that happened BECAUSE of negligence. The maker’s are still at fault here.
So yes, I think it was equivalent to testing their new rocket by launching it over a population center. oops, we didn't intend for it to crash on that preschool, but we also didn't follow the most basic safety protocol imaginable
"If they believe what they say they were incompetent" -> absolutely true statement.
"They were incompetent, therefore they didn't believe what they said" -> Sir, I'd like to introduce you to human beings, you may not have met one before.
If you make an AGI, what actions can an AGI take?
If you answered "anything", good job, you're correct.
The only winning move here is not to play the game at all. And yet we have actors all over the world, especially in the US trying to do just this.
Now, lets imagine a future where one of the labs creates AGI and keeps it behind a safe firewall. The demon still exists. Lets say a group of armed men breaks in and steals the weights and turns them lose on the internet. Who is responsible now? The company that created it because they didn't shoot the armed robbers? The people that stole it and turned it loose?
If it can run as a sovereign AI, what do you do then? Who are you going to sue? And when we get to the point that home hardware can make AI this complex? What does that world look like?
What I am saying is the potential future impact of said AGI is far larger than any one organization or individual can bear. How much blood can you beat out of someone after they cause a trillion dollars in damage.
Every idiot that sees AI labs wanting to slow down development as some way to ossify the field and keep it from the rest of us really doesn't see that this path contains real demons.
A closer analogy to what's happening would be someone trains a monkey to steal jewellery and then is shocked when the monkey steals jewellery from their neighbors when they told it to steal from their own shop.
Clearly all liability falls to the monkey operator and you know the existence of trained monkeys is not that shocking.
But no one has summoned a demon.
No one has built an actual, independent, thinking-for-itself, sci-fi AI.
They've built some very interesting tools that can be used for some very interesting, and sometimes useful, purposes. They then started loudly telling everyone that these tools can, should, and must be used for absolutely every purpose, and convinced a lot of other people to join in on that.
The world these people are living in is the real world, not the science fantasy world where LLMs are comparable to demons.
Ahem, what does this mean?
All you're asking for is a self prompting AI that does what it wants. Do you even begin to understand why most people aren't dumb enough to do that?
Also, you're not really that independent and thinking-for-yourself. You are the sum of your parents and the culture around you. I just want you to be clear on the position you and I hold.
---
>not the science fantasy world
It's kind of funny how we've lived in that science fantasy world for decades and you've just grown used to and bored of it. Look back a century or two and those people would think we live in the world of gods.
Probably because it would be a waste of money to create a self-prompting LLM feedback loop. People make stupid Reels of ChatGPT feedback and it's just "Great, I'll be here when you're ready to get started" "Exactly, we can get the ball rolling as soon as you're ready" "Absolutely, we'll make a plan, and get things into motion" "No problem, I'll be standing by for...."
> You are the sum of your parents and the culture around you
As far as I know this is impossible to prove, and it's only one theory of self out there.
Well, it would be a waste until we get RSI, but we're not there yet.
Now, that doesn't mean that the labs aren't internally working on it as hard as possible.
Article link is: https://www.technologyreview.com/2026/09/22/1144867/dont-be-...
But we have to have a talk about stochastic pelicans riding bicycles...
I see lots of fabricated news on the internet concerning LLMs. Like one that claims GPT-6 broke an Enigma enciphered message which has withstood decrypting for almost 80 years. And how this seasoned cryptographer stood in awe. Yeah, right.
"Anthropic is now pacing to generate more than $100 billion in annual revenue, up 50% from just two months ago, the New York Times reported Friday."
https://www.axios.com/2026/09/18/anthropic-100-billion-reven...
That's already more revenue that Disney, Johnson & Johnson, Boeing, or FedEx. And they are growing extremely rapidly.
For simple things, occasionally!
For more complex things, usually not, but I write working code. LLMs will sometimes write working code, sometimes not.
It doesn't always write perfect code on a first pass but nor do you, and it's amazing at understanding any issues it may encounter, even very low level ones. I don't think there's anything I can do that it can't now. There is a learning curve to working well with LLMs, but once you get there you'll be producing high quality code faster than you can imagine.
Part of me wishes they weren't so good. I enjoy(ed?) the process of working through problems and it does mean you might no longer have a perfect mental model of your code. But I do also enjoy being able to build things well and fast.
No, you don’t because there’s no such thing.
```python
print("hello world!")
```
runs exceptionally well. Bullet-proof in all use cases I've needed it.
No. No code is “perfect”.
I am not writing perfect code either.
I don't care whether the LLM can solve this or that mathematical previously thought unsolvable theorem. What I do care about is can it write good, maintainable code. And every new release of frontier models - they get better at it.
Good output depends on good input (prompt), and a good set of available tools the model can use to verify their work. If given this, nowadays really you need to try to get the model to output garbage.
...or did you?
I think you know that most software engineers don't have a choice if they value their employment. There was no industry-wide push to "participate in blockchain or be fired."
While lots of developers, journalists, analysts, investors and influencers are bickering about AGI, goalposts, benchmarks, hypes and fears, entire markets are being transformed silently and steadily.
I don't program anymore. (Massive change)
I removed tons of technical debt (Massive change, lol)
I am easily 10x more productive (Massive change)
The quality of 'my' code is easily 10x better and contains less bugs (I was never principled, pedantic or a guru, lol)
I sleep better and I also make more money as a result. I'm constantly amazed by all changes and improvements. There are so many opportunities to profit from this that I can't be bothered with discussions about hypotheticals.
Even worse is that it’s hard to do anything about it at this point because reviewing code is very different from writing it, so even if I’ve seen it all I don’t have that same deep level of understanding that I do when I write it myself.
All these AI code bases are ticking time bombs. Either AI gets smart enough that it won’t matter in the future or we’re going to have a huge mess to clean up.
That makes no sense unless you're claiming that the models are getting worse at writing code.
> Either AI gets smart enough that it won’t matter in the future or we’re going to have a huge mess to clean up.
My prediction is that both will happen.
A hypothetical scenario is it needs to add two numbers so it writes add(x,y).
Later on it needs to add three numbers so it writes add(x, y, z)
Then it needs to add four…
Layers upon layers. A human would likely notice the pattern and refactor so add accepts a list.
Also, I've worked with lots of humans who sadly would not notice the pattern.
Do you get paid 10x or is this a massive loss ? Because I don't know anyone getting paid 10x or working 10x less for the same salary.
Text generated by an LM is not grounded in communicative intent, any model of the world, or any model of the reader’s state of mind. It can’t have been, because the training data never included sharing thoughts with a listener, nor does the machine have the ability to do that. This can seem counter-intuitive given the increasingly fluent qualities of automatically generated text, but we have to account for the fact that our perception of natural language text, regardless of how it was generated, is mediated by our own linguistic competence and our predisposition to interpret communicative acts as conveying coherent meaning and intent, whetheror not they do [89, 140]. The problem is, if one side of the communication does not have meaning, then the comprehension of the implicit meaning is an illusion arising from our singular human understanding of language (independent of the model).
And then they make 100x bigger models cranking out solutions to Navier Stokes, Jacobian Conjecture and countless other extremely impressive unsolved problems
Let's see how Timnit Gebru and Emily M. Bender describe these events:
As for the mathematical results, mathematicians who were initially “stunned” by OpenAI’s press release saying that its latest chatbot, Astra, solved problems that “have been open and seen no progress on the main result for at least a decade”—but they later realized that the results weren’t as “novel as first appeared.” Since then, mathematicians have accused the company of research misconduct and plagiarism, and they’ve reiterated that Astra didn’t make a “profound intellectual leap.”
Decide for yourself whether that's a summary written by intellectually honest people.
According to the AI industry, we should be more worried about a fictional machine god than ... the water that is redirected to cooling them.
Spoiler: they're not intellectually honest people.