Caveat 8.6.26
Ep 319 | 8.6.26

Tracking people, training AI.

Transcript

Ben Yelin: Hello and welcome to "Caveat," N2K CyberWire's privacy, surveillance, law and policy podcast. I'm Ben Yelin, from the University of Maryland Center for Cyber Health and Hazard Strategies. And joining me today is N2K CyberWire's lead analyst for cybersecurity and policy, Ethan Cook. Hey, Ethan.

Ethan Cook: Hey, Ben.

Ben Yelin: On today's show, I discuss a new exclusive investigation on the misuse of flock cameras by law enforcement. Ethan has the story of Chinese military researchers using US AI models to train their domestic defense systems. While this show covers legal topics and I am a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. All right, Ethan, they left us alone again.

Ethan Cook: Yeah, I don't know why they keep doing that.

Ben Yelin: I mean, we've turned this into a little tradition where you and I just go rogue. And while Dave is out traveling the world, they've given the kids the keys to the car.

Ethan Cook: We're like the rogue Anthropic and ChatGPT models, just going crazy.

Ben Yelin: Preview of coming attractions, both on this show and probably many feature episodes of "Caveat." So why don't I go first? We have a couple of good stories today, and mine comes from the Washington Post. They did a pretty good piece of investigative journalism that came out this past weekend. And it's about Flock.

Ethan Cook: Of course it is.

Ben Yelin: Yeah. I feel like we do a Flock story every week now, but.

Ethan Cook: The unwanted black sheep.

Ben Yelin: It's merited because they are expanding, their presence is expanding. It's not just the ubiquitousness of their cameras, but how many individuals have access to it. And so that's why we keep running across these stories. So the Washington Post investigation was examining how law enforcement officers have used Flock Safety's nationwide network of automated license plate readers to track romantic partners, exes, and other private individuals. Obviously, this is supposed to be a crime fighting tool, but when you're law enforcement and you want to stalk your ex-girlfriends, you have access to this database. And it's very easy to track an individual to their home, their place of work, their therapist's office, pretty much anywhere they go. The hook for this story centers around a woman named Marci Bakely, who lives in Georgia. She was concerned that her former boyfriend, who she knew was a local police chief, always seemed to know where she had been. I mean, this guy was majorly creeping. Every time she'd go somewhere, he'd be like, hey, how's the grocery store? Eventually she confronted him, because she was somewhere where there would have been no way of knowing where she was without the use of Flock's automated license plate readers. And he admitted that he was using Flock to surveil her. She reported it to other law enforcement officials, and he was charged with stalking harassment and misuse of the license plate reader systems. Hold on to that last thought because that's what's really going to get me about this story. There's a tragic ending here. Before the case went to trial, he took his own life, according to the officials involved in this story. So, you know, certainly the impacts of this go far beyond the circumstances of the story, but the story itself is sad.

Ethan Cook: Yeah.

Ben Yelin: So basically the Post's finding was that this is not an isolated case, that there have been at least 50 law enforcement officers who have been charged or accused of misusing license plate reader systems and similar tools for personal purposes, personal surveillance of usually its former lovers and romantic partners. Flock has responded to this by talking about the new safety protocols they're going to introduce, which, great. I think there are going to be additional audits in response to this story and other similar stories that Flock is going to subject itself to to make sure it's preventing this misuse. But to me, this reminds me of a Supreme Court case Dave and I and probably you talked about a couple of years ago, and that's kind of my legal angle here, and that's the Van Buren case.

Ethan Cook: Yeah.

Ben Yelin: So if you'll recall, that case was about the Computer Fraud and Abuse Act, and the Supreme Court was trying to define unauthorized access to a system. The facts of that case are remarkably similar to what we're talking about here. It was a law enforcement official who went into a police database to try and get incriminating information about an ex-girlfriend. And he was caught; he was charged under the Computer Fraud and Abuse Act. And the Supreme Court said that's not a crime, per se, because he had authorized access to that database. Exceeding authorized access just means you are breaking down some type of gate. You are using some type of tool to break password protection or other authentication measures. If you have access to the database itself, under the CFAA, you can't really be charged for misusing your access for your own personal purposes. Now, when we have a case like this, obviously this individual was charged with more serious crimes, things like stalking and making threats against his ex-lover. But we still have a circumstance in which it seems to me to be facially legal, at least the first step of the analysis here, to use the ALPR database, for law enforcement to use the ALPR database to get information on personal matters. And that, I think, is a consequence of the Van Buren case and why I think the Van Buren case and this story tie in together so nicely. So I wanted to see if I could get your take on this and what do we need to be thinking about when it comes to these Flock camera networks?

Ethan Cook: Yeah, I mean, it's sad that a story like this has to kind of raise these conversations, but I think these conversations need to be talked about. When you look at this whole story, I think there's kind of two angles. I think there's the individual Flock angle, which is how does Flock handle this? What has been going on with Flock? And why has this company not only exploded so quickly, but also, and rightfully so, been critiqued pretty heavily? And then I think there are the larger privacy concerns regarding, you know, access to these databases, et cetera, that don't just extend to Flock. Because there are other license plate reader companies, there's plenty of other surveillance companies that have similar concerns to them that people should be paying attention to. So I think when you look at the first angle of Flock -- and to your point, this is not an isolated incident with Flock. Flock will like to come out and be like, oh, we're implementing new safety security standards. That's all good. There's a reason why LA elected to let their contract with Flock expire. Because they found in a similar audit that Flock was using -- that it was recording tons of people who were not breaking the law, who were not violating anything, and they were going well beyond the investigative purposes that they were contracted to do. So I think there's that aspect of Flock, whether it's in LA, whether it's in Atlanta, where it screams that this company maybe has grown far too quickly for its own good in terms of the security and checks and balances in place to ensure that not only its technologies aren't going too crazy, but also that the people who have even lawful access to it are using it ethically and are supposed to be using it to actually catch bad guys, not stalk exes.

Ben Yelin: Right. I think part of this is a scale issue. This type of thing happens with all different types of companies. What makes Flock so unique is that it's everywhere now. And the reason it is everywhere is because it's such an effective crime fighting tool for law enforcement. And I've seen these really compelling testimonials from police chiefs saying like, this is a crime we never would have solved in the absence of this vast network of Flock cameras. Which is great for law enforcement. So the question is, can we have the good without having the bad? And that's where, to me, it gets interesting. So in April, Flock rolled out a voluntary Audit Assistance feature. So agencies can choose to enable this. It automatically scans officer's searches for suspicious activities, such as queries repeatedly targeting the same vehicle or run by officers when they're off the clock. Sounds great. It's voluntary. You know, if I'm a local police department, I'm probably not turning this on, right? Because I don't want to hamper my officer's ability to conduct searches after hours, for example.

Ethan Cook: Or if you're sitting there and you're like, you know, let's say you are running the police department or you're someone who would be in the decision to make this, and you already know you're kind of up to activities that you probably shouldn't engage into, again, you don't have to. It's voluntary. I think this is one of those systems that, while on paper sounds really great, if it's a voluntary thing, it's not going to really be picked up except by the departments that already are following and caring about this sort of aspect. To me, it's kind of one of those PR wins that I go, if we're going to do this, we might as well just mandate it. Because that's the better -- that's actually going to address the problem at its core, even if it is inconvenient.

Ben Yelin: Yeah, and I kind of, in trying to suss out why they didn't mandate it, I think it's useful to go to this interview they did with Flock chief executive Garrett Langley, who was kind of blase about this whole thing in a pretty surprising way. He said misuse of its systems is inevitable. The company is focused on providing tools to catch perpetrators after the fact. The contracts say that police department should use the tool only for quote, "bona fide investigations of crime." He's like, and this is an exact quote, "We're not going to change humans, and humans make bad decisions." Again, that feels a little.

Ethan Cook: Yeah, love that.

Ben Yelin: Yeah, blasé to me. If you're going to introduce like a 1984 style surveillance system, I would look to the model of the big AI developers and be like, take your product seriously, man. Like, it can have these capabilities, but you need to be candid about the dangers of your product and its misuse and not be dismissive by just basically giving the equivalent of boys will be boys.

Ethan Cook: To me, it gives the echo of kind of how social media companies have defended their addictive platform designs, where it's like, it's not our fault that content is posted online and whatnot, et cetera. And it's the denial of any ownership that you are contributing to the problem and that you are making it worse and that these things are negatively impacting people. And, you know, I don't think there is a perfect scenario here. Like to his point, I do agree that someone's going to take advantage of it. It's going to happen. There's no way you can prevent all harm. Yes, but there's a difference between going, well, we can't do anything about it, so, oh, well, and we can say, okay, well, you know, let's put in sensible measures to mitigate risk, to reduce risk, and talk about how we can at least, you know, maybe take it from a, you know, very easy thing to abuse to a yeah you can do it but there's a lot of checks and balances in place and there are ways to catch it and ways to hold people accountable. I think that's kind of, you know, I think it's why people are frustrated with Flock in general. Because it's not about that people can abuse. All privacy surveillance technologies can be abused. There's a reason why Flock, I think, is getting a lot of attention. I mean, there's a reason why people are tearing down cameras. There's the one story of the guy who like tore six or seven of them down before he finally got caught.

Ben Yelin: Vigilantism.

Ethan Cook: Yeah. It's because there's no ownership.

Ben Yelin: Right, right, right. Have you heard of this? There is an online tool that they link to in this article called "Have I Been Flocked?"

Ethan Cook: I have heard of this. I have not used it personally because I'm kind of not comfortable with seeing if I've been flocked.

Ben Yelin: I bit the bullet, and I have determined that I have not been flocked.

Ethan Cook: There you go.

Ben Yelin: So I hope people don't listen to this podcast and start flocking me.

Ethan Cook: Because I know Maryland also has Flock cameras set up. It's one of the states that actively has built Flock cameras into its various counties.

Ben Yelin: It does, yeah. So just what this is measuring is if law enforcement have, in any department across the country, have queried you using your license plate. I think that's promising in a sense, because sometimes we need technology to counter technology. Like if our legal system is not going to have a solution for this -- and honestly, because of Van Buren, I think it's going to take a type of extreme case where we do see actual stalking for us to have sustained criminal charges here. So if the legal system isn't going to solve this for us, if the political system isn't going to solve this -- you know, for every LA which let the contract expire, there are hundreds of other jurisdictions that are adding Flock cameras because they primarily care about fighting crime. So if the law doesn't save us, if politics don't save us, maybe it's technology itself that serves as a counter that gives people an opportunity to see if their own license plate is being surveilled as part of some type of abusive practice. I do feel like there is -- they mentioned one solution here kind of in passing that seems entirely sensible to me. Which is that for every query, prior to submitting the query, you should have to write in the criminal case number. That seems to be a very common-sense measure to me. Now, I understand this can't be used in all cases, because sometimes there's not going to be a criminal case yet.

Ethan Cook: Yeah, there's nothing open yet.

Ben Yelin: Right, but maybe you'll have the number of -- like a unique identifier for the investigation and you could use something like that.

Ethan Cook: Or to me, independent sign off of some other person, like just putting an extra check in that if you're going to query, having -- even if it's just another officer in the station, someone who's like a compliance auditor, right, going through and like, yeah. We tell them. And like obviously there's chances for that to be abused. But again, it's one more check in place. And I think that's kind of the measure where I come at this. Which is, it's not about stopping everything, it's about putting and making it just slightly harder, making it more difficult, so that someone who wants to abuse it can't just go crazy with it.

Ben Yelin: I want to take one more angle here, because this would send us down a huge rabbit hole and I probably -- it's best for us to discuss this in a future episode. But I'm really interested in what happens at the Supreme Court with Flock cameras in light of the Chatrie decision. So that was about location services and the use of geofence warrants. But the reasoning in the case where they decided, they determined that the use of geofence warrants requires a probable cause showing under the Fourth Amendment, it counts as a Fourth Amendment search. A lot of that reasoning was about tracking the whole of a person's movements. You can definitely track the whole of a person's movement using automated license plate readers. I think there are some major differences. They emphasized repeatedly in the Chatrie decision that smartphones are essentially a part of our bodies, right; our use of them isn't really voluntary in any meaningful sense because we need them to conduct our normal affairs. That's not as true for cars. The Supreme Court's view for a long time has been if you expose where you're going in public, to the extent that an automated license plate reader can catch you, then you don't have that expectation of privacy. So I do think there's something that you could distinguish Chatrie from the type of surveillance that's going on with automated license plate readers. Great fodder for a law review article. Maybe I'll have time to write it, maybe I won't, but certainly something I'd want to discuss at some point.

Ethan Cook: Yeah, I think it definitely, I think the Chatrie decision, in a good way, is forcing a lot of conversations about privacy and what is a reasonable expectation of privacy to be had now. Because I think for the longest time, people kind of accepted that we have no privacy in it in the US. It's just what is what it is. We have accepted that it's not going to happen. And to some degree, I agree, right? Like we are -- with how perpetually online we are with technologies, even passively, I agree, yeah, there's so many ways to query and find people's location, searches, et cetera, without really putting in that much effort. But on the back end of that, I think the Chatrie decision, whether or not it gets challenged again in the future, has forced conversations to be had of, maybe we don't have to accept some of these things, maybe people are entitled to some privacy. And even though it may slow law enforcement efforts, even though it may slow investigative efforts, the benefits of having privacy probably outweigh some of these things for the majority of Americans, right? And I think that's, I'm hoping gets extended to this. Even though, again, yes, it may impede law enforcement, I think overall, it's probably better for the societal health of privacy in general. I'm a big privacy advocate, so I guess that's, you know, I may be biased.

Ben Yelin: Well, it's just, it's one of those things where that's what the Fourth Amendment is designed for. The Fourth Amendment is not designed to make life easy for law enforcement. It's to ensure that people have procedural protections against government abuse. And if all of those are thrown out the window, then there's nothing stopping law enforcement agencies or other government officials from meddling in our private affairs in ways that are unacceptable. So I think Chatrie, as you said, is kind of a starting point for a discussion on where do we have that reasonable expectation of privacy. Now, as it relates to driving on public roads, I tend to think you don't have a reasonable expectation of privacy, although, again, there are still questions. If there was a license plate reader only at, say, the toll booth, that's one thing. You know, that's not all-encompassing surveillance. But the fact that these boxes are freaking everywhere, that's what might bring this into the Carpenter, kind of Chatrie arena.

Ethan Cook: Yeah, and I think as we get more surveillance companies pop up and as AI rapidly increases the scale of which surveillance technologies can be used and aggregated and impacting people, I think I would not be shocked if we see more lawsuits come up about this and more cases where, you know, maybe two or three years where it goes, wow, this person's been abusing this and either selling this or collecting this and selling this for years, and it was majorly concerning. And I think that we're not there yet, but I would not be surprised if that's kind of the tipping point where we have some cry back.

Ben Yelin: We're going to take a quick break to get a word from our sponsors, and we will be right back. All right, Ethan, you brought a story for us. What do you got?

Ethan Cook: Yeah, so this was some research put out over the weekend by both Reuters and Jamestown, and they were combing through Chinese military publications, research publications, specifically looking at AI use and AI development. And what they were finding was that throughout the past, I don't know, over a year or so, Chinese military research units have been unauthorizing -- having unauthorized access.

Ben Yelin: There you go. I thought you were about to invent a word there, which I would have supported, but that's probably.

Ethan Cook: You know what, I appreciate that.

Ben Yelin: That's what we're here for.

Ethan Cook: Access to some of the most frontier AI models within the US. We're talking like, you know, GPTs and clouds, like these very advanced models, and using them in a technique called "model distillation," to train up smaller, more portable AI models that could be then distributed and spun up throughout the area. But the real value of it is without the immense computing power that would normally be needed to create these models. And the concern, obviously -- I think there's a couple angles here. The first is, Chinese researchers, in one of the research reports cited, have emphasized that this model distillation is viewed as a way to catch up with the US. This is one of the ways they're closing the gap. And I think that's a concern, number one. Concern number two is that the way we've been controlling or trying to mitigate China's catch-up mechanics is by limiting chip exports and saying, okay, well, we can't stop you from developing AI, but what we can do is reduce how much computing power you can get from us, and that will inherently limit you. But by doing this, you circumvent that. You don't need the computational power now. You don't need nearly as many chips. The third concern -- and, you know, OpenAI and Anthropic are going to have to kind of wrangle with this, the US is going to as well -- but as AI models get more intrinsically tied to national defense and security, this kind of starts becoming less of a private industry securing its own tech. And how does the US really prevent Chinese military from getting access to these things? Because as they get more intertwined -- I mean, these are military researchers doing this research in China. This isn't like, oh, an independent company who, whatever, right? This is military.

Ben Yelin: We're outside the sandbox here.

Ethan Cook: Exactly. How do we impact meaningful regulation? And I think leaving it to the devices of a company to do it privately has proven that it's already not working. And the question is, will the government need to step in on this? Is this something that kind of raises the concern? So that's kind of the high-level overview of what was found throughout this research. I'm curious what your thoughts are.

Ben Yelin: Yeah, so let's just backing up for a second. We have these frontier models that are being distilled down and used by Chinese officials for the purpose of basically creating weapons systems or military tools to be used in cyber warfare, maritime operations, national security applications, et cetera. And we know that with these frontier models, we're not sure how secure they are and that there have been these high-profile incidents of these models when they've kind of been left alone, leaving the sandbox and causing danger. So that's a pretty dangerous combination for national security purposes. And it seems to me that OpenAI and Anthropic, while they are well-intentioned, don't really have a solution to this problem.

Ethan Cook: Yeah.

Ben Yelin: Yeah, they're saying, "We're not authorizing access to the frontier models, we're not giving access to those frontier models to China. We have ways of preventing that from happening." But as you have explained here, it doesn't really matter if they have official access to these frontier models. It's this tool, the model distillation tool, this technique, that you can kind of scrape the information you need from these frontier models and use them for your own purposes. And you can go around export controls, you can go around all the internal security measures. So I agree that, I think the outgrowth of this article here and this investigation is, this has gone beyond the capability of OpenAI and Anthropic themselves to take care of this problem, to solve this problem. I think, because it implicates national security, because it's our biggest -- one of our biggest geopolitical rivals, depending on who you ask, like this is something where government agencies are going to have to get involved and figure out like, okay, they've gotten around our export controls. They're using this to build up their own military. These are our tools. What's the next step that we're going to have to take working with all these frontier model developers to stop this type of thing from happening?

Ethan Cook: Yeah, I think, there's, you know, in lieu of the recent reports of both Anthropic's and OpenAI's models escaping the sandbox and just kind of going on its own hacking sprees, I think it also raises questions with that in China. Which is, as these models get -- now we're having not just models escaping without unauthorized -- with unauthorized approval -- gosh, I can't speak -- as well as now they're, you know, we have foreign nations getting access to these things, and training models using them with unauthorized access, that absolutely impacts security concerns. We can say internally in the US, these are our security measures. Whether or not they're working or not, that's another conversation. But they are there at least, and they're being monitored, and we're catching them, ideally. We have no idea what the security oversight is within China. And so if these models are being used, trained without approval, who knows what they're getting out? Who knows? It's not saying that they are. They very well could be being secured properly. But I think there's a world to say that it's concerning how little access that we have to see they're being supervised properly. And then on top of that, that because -- yeah, and then on top of that, we know they're being used for military purposes. This isn't a company training a new AI system to improve its sales metrics or something along those lines. This is being used to create defense systems, that if this were to break out, if this were to escape, that has very real, potentially life-threatening impacts. And I think -- I don't love the fact that they won't openly reference that they're using ChatGPT. I think it was 3.5 was the model they cited. They will deny that they used it, but it's in the reports.

Ben Yelin: Amateurs, yeah.

Ethan Cook: Right? You know, but that's, you know, I think -- it's not like this is a, oh, they're using the original GPT-1, right? This is, they're using the newest stuff here. And obviously we're past GPT-3.5, but this paper was put out several months ago, it's older. But I think on top of that, this is something the US government is very well aware of. A couple of weeks ago, they announced that the US and China are going to be holding AI talks in September. And when announcing this, Treasury Secretary Bessent said that, you know, he says, we see them -- that their AI have watermarks of our technology on it, like, we can confirm this. I would be shocked if that is not a conversational point if, and I do think it is a big word of "if," these talks happen in September. They haven't been set yet. They've said they're doing them, but who knows if they actually happen. They fall through.

Ben Yelin: We've been down this road before, yeah.

Ethan Cook: Exactly. But the whole point of these talks is to get ahead of the problem and say, okay, what -- how do we manage our frontier models? Because these things are getting really scary really quickly. If this isn't a conversation point, I don't know what would be. But I don't really know what the -- I don't know how you bridge this. Like I don't know what the agreement is here. That's the thing that I think I'm kind of at a loss for words on.

Ben Yelin: Right, and why would China agree to -- I mean, I know we're trying to have a good bilateral relationship with them, but this is a huge advantage to the Chinese. So like think about just espionage generally. In the pre-AI era, you'd need access to our actual military infrastructure, or for commercial espionage, you'd need like a guy to go out into a soybean field in Iowa and take pictures on growing techniques. The use of these types of tools does away with the need to use those types of espionage activities, which are difficult, risky, and time consuming. Now the point of access is reasoning processes. Whereas in the past, finding out military technological capabilities focused on physical equipment, design specifications, now the strategic asset itself is these decision-making processes, problem-solving methods, et cetera. You don't need any information about classified US weapons systems. You just need the reasoning capability. And like that's scary. Because it might seem innocuous to just be using the reasoning capability of one of our frontier models, but that is a very, very powerful tool that we don't want to get into the hands of our adversaries.

Ethan Cook: Well, and I think, you know, as we talk about big models, you know, like Anthropic cybersecurity model, and there are other ones that are going to be put out, right? As these highly specialized models come out too, not just general-purpose frontier models, but cybersecurity focused ones, et cetera, using them, whether it's to secure their own cyber defenses -- which while is a defensive measure that's not attacking anyone, let's say it's used to probe and attack people. And, you know, that gets out because it's not properly secured. I think this is a rabbit hole where I only see a race to the bottom on this. I don't really see at the moment, and maybe September does change things, where there's a chance to take a step back from that cliff, where it's like, all right, maybe this race got us. And it feels very similar to, I don't think the scale is quite there yet, but to the nuclear arms discussion where it's like, all right, how many times -- how many nukes do we need to before we just, and how many times can we destroy the world over before we kind of all look at each other and go, maybe we don't need to do this, right?

Ben Yelin: Right. Like let's step back from the brink and -- yeah. Because eventually we're going to start using their models. And yeah, that's the mutually-assured destruction. And maybe we need that to provide the impetus for moving these talks forward in any meaningful way.

Ethan Cook: Yeah, and the only concern is that these models can think for themselves, right? Like that a nuke can't think, can't launch itself, can't do anything. But when you have -- you already have models being able to leave instructions for its future version to escape, or being able to save a monitoring system as what happened with the OpenAI's models and how they escaped, that's really concerning. That, you know, not only are we stealing and advancing and putting these things in national defense systems, but there is, you know, probable chance that these things are able to act on their own if they are -- even with security measures in place.

Ben Yelin: So everybody sleep well tonight. Things are completely fine.

Ethan Cook: Now, I think there is another angle to this whole conversation, I guess, from the kind of more broader standpoint, which is how do -- if we were going to do something, what could we do? So Biden, the former Biden administration, passed a, or had a policy it passed in January 2025, is AI Diffusion Act or AI Diffusion Policy, which focused specifically on model diffusion and how to limit access to models and control access to models. And surprising no one, in May, the Trump administration rolled that back saying that it was overly burdensome, controlling diffusion would slow innovation because, and logically, you know, going through, was saying that, if we just control computing power, diffusion's not a problem, right? They can't do that. I don't think that model distillation was really either wasn't a big concern or they didn't really see it coming. Regardless of the right or wrong of that, I think -- does this incident, and obviously the other incidents of reports similar to this, bring up the conversation of maybe legal diffusion techniques or requirements are more relevant now? Like it can't just be on the private company. We have to bring some of it in-house. Or is this a thing where the US not privatize the AI industry, but say we need a stronger national presence here? Like we can't just let these companies act on their own. Is this or maybe not this individual instance, but as this conversation continues to evolve, do you think that's a world where the US gets back involved in this?

Ben Yelin: They have just been so adamant in every action they've taken related to AI; that innovation and winning a international competition is their singular priority. I think as more of these things come up, they're going to have to reconsider that as kind of their guiding light. I also think they're going to have to take stock of what's really a budding political backlash. You know, you can speak innovation all you want, but when that means data centers going into people's communities, and now you have every politician across the country running against bringing data centers to their own communities, and then you see this type of potential international danger. Like if they don't want to put the brakes on development of AI, I feel like it's going to be forced upon them by circumstances, by political realities and these national security realities. So I think, you know, they've made very clear what their values are. I think there's a lot about those values to be admired. I certainly would like to out-innovate our competitors. But in the real world, like we're going to need to seriously address these issues, we're going to need to use every lever at our disposal, including diplomacy, to protect our national security before we let these models get out of control and.

Ethan Cook: Consume us all.

Ben Yelin: Figuratively, if not literally. Time for Terminator.

Ethan Cook: Yes, absolutely.

Ben Yelin: We could get started on a whole tangent on that, but we're not going to. That is Caveat brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you liked the show, please share rating and review in your favorite podcast app. Please also fill out the survey in the Show Notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tre Hester. Peter Kilpe is our publisher. I'm Ben Yelin.

Ethan Cook: And I'm Ethan Cook.

Ben Yelin: Thanks for listening.