Why Aren’t Modernist Bridges Awful?

The public dislikes modern architecture but, generally speaking, they do not dislike modern bridges. Lists of the most awesome, most stunning, most beautiful bridges in the world will mention classics like London’s Tower Bridge, the Brooklyn Bridge, or the Rakotzbrücke but alongside them they will picture the Kubitschek Bridge in Brazil (Shutterstock).
The Rio-Antirrio Bridge in Greece:
Rio-Antirrio Bridgeor the Moses “Bridge” in the Netherlands.
Moses Bridge
Whether you like these bridges or not, I don’t see in the literature an idea that modern bridges are all ugly or that modern bridge building has failed or fallen behind the great bridges of the past in the way that there is such a critique for modern architecture in general.

Why is this? I have a theory, which is that bridge designers come from engineering schools rather than schools of architecture. It is possible, of course, that there is something in the nature of bridges that prunes the design space in a way that attracts beauty–maybe we like catenaries, arches, cables in tension and beauty is just a byproduct of the engineering.

It is possible, however, to produce ugly bridges so it’s not just an engineering constraint. Moreover, one small but telling piece of evidence in favor of my theory is that most of the bridges chosen by Wallpaper magazine, an architecture magazine specifically, are in fact ugly (and with no overlap in the bridges from my first category of “popular” beautiful bridges). Here are a few, judge for yourself:

The fact that modern bridges are often beautiful, especially when they come from engineers, is consistent with Samuel Hughes’s argument that ugly has been a choice, not a constraint.

Regulated Markets Are Slow to Handle Change

Gowrisankaran, Langer and Reguant have an excellent paper, Energy Transitions in Regulated Markets (WP), in the latest AER.

The basic idea is that regulation designed to prevent utilities from building useless power plants can induce them to keep obsolete power plants. Some background. We regulated electric utilities under the theory that they were natural monopolies and therefore we would do better by pushing their prices down. What’s a reasonable price? Hard to say, so regulated utilities were allowed to recoup their operating costs plus a fair return on their “rate base”—their capital stock. Makes sense, but once profits depended on the size of the capital stock, utilities had an incentive to build too much—the classic Averch–Johnson effect. Regulators responded with “prudence” requirements and the rule that capital must be “used and useful.” In a stable world, that rule is a check, albeit an imperfect check, on so-called gold-plating.

But now consider what happens in a time of technological change, such as a rapid decrease in the cost of generating electricity with natural gas (driven by fracking and improvements in combined-cycle natural-gas (CCNG) technology). In a free market, large decreases in costs would cause firms to abandon coal and move to natural gas—some would do this to make profits, others to avoid losses. In short, the market forces sunk investments to be abandoned when not profitable.

But there is another possibility under regulation. Tell the regulator that your plants are still viable. Well, telling is cheap talk so you keep burning coal to prove that the plant remains useful. If you can keep your base operating that’s better than abandoning it and to signal how valuable your coal plant still is, it may even be worth while to burn coal when the cost exceeds the price of electricity! The authors have some nice data on exactly this point.

Figure 3 takes a little work to understand, but the pattern is clear. Each point represents a state. In panel A, the vertical axis shows how much less likely a coal plant is to run when the cost of coal exceeds the price of electricity. Obviously, a strongly negative coefficient is the economically sensible response: when burning coal is more expensive than buying electricity, the plant should burn less.

The red points represent restructured states and the green points regulated states. In restructured states coal burning falls when prices fall, just as expected. Coal burning in regulated states responds much less. (I.e., the red points generally lie below the green points.) Indeed, the six states with the largest reductions in coal operation are all restructured states.

One objection to this analysis might be that utilities in general are just slow to respond to prices, so on the horizontal axis the authors plot how well utilities respond to a higher price of gas. Note that these coefficients are all negative and there is no obvious difference between regulated and restructured states. In both types of states, utilities respond well to the price of gas, but only in restructured states do utilities respond strongly to the price of coal. (Why coal and not gas? Because the used-and-useful standard binds on capital whose usefulness is in doubt—which, once gas got cheap, meant coal. In other words, the utilities have to defend coal to the regulators, not gas.)

Panel B on the right shows a slightly different way of presenting the same data. The vertical axis is again how much less likely a coal plant is to run when its cost exceeds the electricity price. The horizontal axis is the fraction of generation owned by electric utilities. Regulated states tend to be vertically integrated, while restructured states opened electricity generation to competition, so utility ownership and regulatory status are closely correlated. Regulated states generally have utility ownership above 60%, while all the restructured states but one are below 30%. The best-fit line slopes upward: in other words, the more generation a state’s utilities own, the less coal dispatch responds to price. A different perspective on the same story.

That is the direct empirical evidence. The authors then construct a more ambitious structural model. In theory, regulation could produce either too much or too little investment in the new technology; their estimates imply too much. Much, too much. Not only do regulated utilities retain too much coal, they also build too much gas capacity. In short, they accumulate both too much old capital and too much new capital. Averch–Johnson on steroids.

The bottom line is that regulation under dynamic conditions is much more difficult than under static conditions. My view is that it may not even be worth the candle.

Impedimenta Developerum!

NME: Harry Potter fans have succeeded in moving a construction project that would have originally gone through the “grave” of the character Dobby.

The 125-mile Greenlink power connector, which costs £430million, is intended to link power between the UK’s National Grid and Ireland, running between County Wexford and Freshwater West in Pembrokeshire.

However, the latter site is known to Potter fans as the site of house elf Dobby’s grave in the film Harry Potter And The Deathly Hallows, and contains a pile of stones with the words “here lies Dobby” that many flock to…

All I can say is that Voldemort would never have put up with this shit.

JFK’s AI Voice

From Kennedy’s 1961 inaugural:

  • “Ask not what your country can do for you—ask what you can do for your country.”
  • “Let us never negotiate out of fear. But let us never fear to negotiate.”
  • “United, there is little we cannot do… Divided, there is little we can do.”
  • “If a free society cannot help the many who are poor, it cannot save the few who are rich.

and from the 1962 moon speech at Rice University;

  • We choose to do these things not because they are easy but because they are hard.

and from Lyndon Johnson’s inaugural speech:

  • John Kennedy’s death commands what his life conveyed—that America must move forward.
  • On the 20th day of January, in 1961, John F. Kennedy told his countrymen that our national work would not be finished ‘in the first thousand days, nor in the life of this administration, nor even perhaps in our lifetime on this planet.’ But, he said, ‘let us begin.’ Today, in this moment of new resolve, I would say to all my fellow Americans, let us continue.

Sound familiar?

Were John F. Kennedy’s speeches written by an AI? Probably not. But were AI’s trained on the speech writer Ted Sorensen? It would appear so. Or to be more accurate, AIs have absorbed the Sorensen toolkit: symmetry, parallelism, antithesis, repetition, and the neatly turned reversal.

Sorensen is considered a great stylist, and these are iconic lines. The problem with AI voice is not the techniques themselves. It is the overuse of them—their deployment to describe a trip to 7-Eleven with the same rhetorical flourishes once used to send men to the moon.

I suspect that will be an easy problem to fix, so don’t expect AI voice to continue.

Hat tip: murgh

Pressure

Who would have thought that someone could make a gripping movie about predicting the weather? Nevertheless, Pressure delivers. To be sure, it’s predicting the weather for D-Day. Excellent cast. Hews very close to the truth. The two camps really did divide on theory versus past prediction and the weather was as portrayed. After the war, John F. Kennedy asked Eisenhower what gave the Allies the decisive advantage during the D-Day invasion, Eisenhower replied, “We had better meteorologists than the Germans.”

I agree with Tyler’s earlier review: A truly excellent movie, one of the best of the year.  Specifically, it concerns the meteorological forecasts (!) leading up to the D-Day invasion.  Thematically, it is about the differences between Americans and Brits, how bureaucracy operates, the nature of leadership, and the proper role of science in government.  It is like an old-style Hollywood movie.  Most of the action takes place in only a few rooms, and with superb dialogue and performances.  Although you all know how D-Day turns out, the movie still generates suspense on some of the major plot points.

AI and Marginal Revolutions in Wastewater Treatment

An interesting paper from French economists, including recent Nobelist Philippe Aghion, looks at the savings from a predictive machine-learning model applied to wastewater treatment:

This paper studies the environmental effects of a specialised AI aeration-control system deployed across French wastewater treatment plants operated by a global leader in water supply services. Exploiting quasi-experimental variation in both the timing of adoption and outages, we estimate the causal impact of AI on electricity use, carbon emissions, and energy expenditures. We find that full-time AI control reduces plants’ electricity consumption and carbon emissions by 5.4% and 6% respectively, and energy expenditures by 8.2%, resulting in negative abatement costs, while also improving water effluent quality. The additional electricity demand generated by AI models represents less than 1% of these savings. Beyond these effects, AI-equipped plants prove more resilient to high operational stress during extreme meteorological events and chemical pollutant peaks. They also improve load management by reallocating electricity consumption from peak to off-peak hours. Finally, we use the DICE model to assess the aggregate implications of our findings
in three diffusion scenarios. We find substantial global welfare gains from the CO2 reductions associated with this industrial AI use case.

One annoyance: The authors frame the paper as a contrast to worries about AI’s energy use and environmental impact. But those objections are almost entirely innumerate and pretextual and casting the paper as a rebuttal lends them more credibility than they deserve.

One note: Don’t misread the “less than 1%” line as being in the same units as the 5.4%, 6%, and 8.2% figures above it — it isn’t a comparable percentage-point offset. It means the AI system’s own electricity draw is a rounding error next to the savings it generates.

More generally, the effect of AI will be through many, many improvements of this nature.

The Binmen of Birmingham

I was on the British CapX Podcast talking about the Equality Act, riffing off my two posts Equality Act 2010 and The Apples and Oranges Tribunal. One thing I discussed in the podcast which I haven’t blogged on is the amazing Birmingham dustbin dispute.

In 2010 an employment tribunal ruled that Birmingham City Council had discriminated against thousands of female workers — cooks, cleaners, care assistants, caretakers — who were denied bonuses paid to the mostly male binmen, gardeners, and gravediggers. Why were the binmen given bonuses? Well, refuse collection is filthy, heavy, outdoor work and not many people want to be gravediggers. Thus, these jobs command a premium for exactly the reason Adam Smith gave in 1776compensating differentials. Or was it sexism? Well, note first that there is nothing stopping women from becoming “binpersons” and indeed there are female binpersons and they earn the same bonuses as their male counterparts (just as with the Next case). Moreover, we can test the sexism versus compensating differentials theory. Let’s see what happened.

Here’s the problem, which contributed to Birmingham going bankrupt in 2023. The council employs roughly 400 binmen and something like 6,000 women in comparable graded roles. Every extra pound paid to a binman therefore implied about fifteen pounds owed to the cooks and cleaners. The council simply didn’t have the money to pay everyone binman wages so they cut the binmen’s wages. But the market wage for collecting rubbish is what it is, so when Birmingham finally deleted the premium in January 2025, the binmen went on strike — and they are still on strike, nearly eighteen months later. The rubbish piled up, 17,000 tonnes of it, and the city declared a major incident.

Here’s the most amazing part. The council hired an outside contractor to take over its rubbish collection and it now pays roughly triple its pre-strike outsourcing bill–more than it was paying its own employees. So much for sexism. Apparently the premium wasn’t a favor to men; it was the price of the job. If you want your rubbish picked up and your graves dug, you must pay the market wage. This was pure regulatory arbitrage, of course. Because the new binmen were contractors they legally had a different employer than the Council’s female caregivers and the Act’s comparator rules stop at the employer’s nexus.

The government mandarins, of course, want to close the “loophole” adding yet another bureaucratic requirement to push the equal pay madness up the supply chain. The rubbish piles up.

Dominant Assurance Contract aka Refund Bonus Explainer

I created the dominant assurance contract aka the refund bonus mechanism in 1998–it’s a mechanism capable of producing some types of public goods privately–in recent years working with Tim Cason and Robertas Zubrickas I’ve put refund bonuses to the test in lab experiments and they work! I’ve written an accessible Refund Bonus Explainer that covers this body of work. Here’s one bit:

The dike is a public good. Once it stands, it protects everyone nearby, and a neighbor who contributed nothing cannot easily be excluded. That property is what makes it hard to finance.

Paul Samuelson defined public goods in 1954, and he was pessimistic about them. Each person does better by understating what the good is worth to him, so it is, in Samuelson’s words, “in the selfish interest of each person to give false signals, to pretend to have less interest in a given collective consumption activity than he really has.” From this he concluded that “no decentralized pricing system can serve to determine optimally these levels of collective consumption.” Public goods, on this view, are what governments are for. Refund bonuses challenge that conclusion.

Read the whole thing and here is my Rent Control Explainer.

The Endangered Species Act Reduces Housing

Max Tabarrok’s paper on the Endangered Species Act and housing (WP) has just been published in the Journal of Public Economics! It’s a clever paper: Max observed that the moment an animal is put on the endangered species list, developers face enhanced compliance costs and liability risk. But what’s important for an empirical economist is that this increased regulation isn’t national–it binds just where the species lives. Thus, the ESA creates many natural experiments, places where it binds and nearby places where it doesn’t and the list changes over time–there were 82 listings in 1970 and nearly 1500 today–and there are even some de-listings which reduce regulation.

Here, for example, is a picture of the habitat (red) and control areas (blue) for when the Northern Long Eared Bat was put on the endangered species list.

 

The bottom left panel measures annual housing permits per 1000 1980 pop in treatment (red) versus control (blue) areas. The bottom right is the event study coefficients. After the bat was put on the endangered species list, the number of new housing permits declined in areas where bats might live relative to control areas.

Here is what happened when the Peregrine falcon was delisted. Before the delisting, housing permits were lower in regions (red) where the falcon had habitat compared to controls areas but after the delisting the treatment areas caught up to the control areas.

Overall:

…this paper provides evidence that an additional endangered species listing reduces annual housing permit flows by 0.5 permits per thousand 1980 residents, about 10% of the average place’s permit flow. Accounting for spillovers and diminishing costs, my estimates suggest the aggregate effect of the ESA has been to reduce the national housing stock by…roughly 6.3 million missing units over 1980–2024, about 4% of the 2025 housing stock.

Now, you might say, ok this shows the ESA has costs. What about the benefits of the ESA? It’s hard to measure the benefits, of course, or even know if the ESA is effective. But Max shows using satellite data that there are quite a few places where the ESA binds on infill development.

…at the intensive margin of housing production, new developments are often replacing existing buildings or are filling in space in a highly developed area that could not host endangered species even if no new construction took place. On the intensive margin, the tradeoff with species protection does not bind, and may even be positive sum as it substitutes for less dense greenfield development. Therefore, whether and how much the ESA constrains development on the extensive vs intensive margin is relevant to the tradeoffs we face between housing production and species protection, and thus is relevant to the aggregate welfare effects of the law.

In this section I extend the main empirical specification of the paper to satellite data on land use from the National Land Cover Database (NLCD) (Multi-Resolution Land Characteristics Consortium, 2025) and to heterogeneity within the Building Permits Survey to assess where the effects of the Endangered Species Act are accruing.

The NLCD is a set of satellite images of the United States compiled and pre-classified by the U.S. Geological Survey. They classify 30-square-meter pixels into one of fifteen land use groups, including four levels of development, three types of forest, and two types of wetland. The NLCD has annual files going back to 1985. I overlap these pixels with the map of permit-issuing places in the BPS using constant 2024 borders, and track the changes to pixels within each place over time. The hazard rate of extensive margin or greenfield development is measured by the flow of non-developed pixels (e.g., forests or wetlands) into any of the four levels of developed land use, divided by the total area of greenfield land use.

He concludes:

The most urbanized 15% of places are responsible for 90% of total permit flows, while the highest-value endangered species habitat is well outside these developed areas. The Endangered Species Act seems to restrict infill development in these dense areas as much as it restricts greenfield development in exurban sprawl (Table 9, Table 10, Table 11). Relaxing the legal mechanism of the Endangered Species Act in already developed areas may increase permit flows in dense, energy- and land-efficient cities in California and on the East Coast at the expense of sprawling suburbs in the Sun Belt, increasing both housing supply and endangered species habitat.

The Trump administration is trying to limit the ESA, multiple lawsuits have already been filed. Max’s paper is thus timely and it points to a fix that might satisfy housing proponents and environmentalists: relax the ESA’s bite on infill and redevelopment in already-built-up areas, where the housing-versus-habitat tradeoff barely binds, rather than across the board.

Addendum: Obviously, I am pleased as punch to see this paper in print. Max began writing the paper before graduate school–he has only just finished his first year. He was fortunate to have had lots of great advice along the way, most notably from a superb pre-doc he did at Dartmouth under the auspices of Heidi Williams.

The Apples and Oranges Tribunal

Suppose that apples sell for more than oranges and Parliament in it’s wisdom decides that, at last, apples and oranges must be compared. Not by shoppers — shoppers are biased, they merely reveal what they are willing to pay — but by a tribunal, which will determine whether apples and oranges are of truly equal value and thus must sell at the same price.

What would the tribunal need to know?

Start with land. Orange groves sit on Florida real estate with one set of alternative uses; apple orchards occupy Washington hillsides with another. The opportunity cost of an orange includes the housing development, the solar farm, the tourist attraction not built on that grove. How is the tribunal to value what was never built? Perhaps you answer: look at land prices. Brilliant suggestion, I reply. Keep going.

Next, capital. Orchards take years to mature, so today’s fruit embodies investments made under yesterday’s expectations about today, financed at interest rates the tribunal must somehow incorporate. Then storage: apples keep, oranges rot, so an apple and an orange in April are different goods than the “same” fruits in October. Add transportation, refrigeration, frost, pests, crop insurance, the option to divert fruit into juice, cider, marmalade, or pie, substitution with every other item in the produce aisle, and the shifting preferences of millions of consumers, each of whom knows things about his own breakfast that he could not articulate to a tribunal. It all matters.

To determine the “just” price of apples and oranges, the tribunal would need the entire general-equilibrium system.

Market prices are necessary to compare alternative uses of resources, as Mises taught us in 1920. In 1945, Hayek added the knowledge problem: the relevant knowledge is dispersed, local, tacit, and fleeting. Free markets are the only institution that aggregates that knowledge, articulates it in prices and gives people a reason to listen and respond. A price is a signal wrapped up in an incentive. Apples and oranges can be compared but only by the incomparably complex operations of the price system. There is a reason we call it the super-market.

Britain is now running this experiment in the labor market–Is a retail worker equal to a warehouse worker? A canteen worker equal to a coal miner? A dinner lady equal to a gravedigger?

Under the Equality Act’s “equal value” provisions, tribunals compare jobs by scoring their intrinsic properties — effort, skill, responsibility, working conditions — the labor theory of value applied to labor. How is it going? The Tesco litigation began in 2018; the tribunal’s fact-finding hearing ran 36 days, its judgments run to more than 900 pages resting on some 19,000 pages of training manuals, and the independent experts have yet to begin the report that will actually say whether a shelf-stacker’s job equals a warehouse worker’s. Eight years, and the calculation has not started. Apples and oranges, adjudicated but not, as Orwell or Marx or Stafford Beer might have imagined, by a industrial bureaucracy or by an all-knowing artificial intelligence but by lawyers and commissions and tribunals. The worst of all worlds.

And having discovered that the tribunal cannot price two jobs in a decade, the government now proposes to add race and disability comparisons and an enforcement unit to publish official guidance on which reasons for a wage difference are permissible. A bureau of allowable scarcities.

Moreover, let us say that one day the tribunal reaches its conclusion and finds the truly just apple to orange price. At last, nirvana. The next day the public learns that vitamin C really does combat cancer–the demand for orange juice skyrockets. To encourage more orange juice production we need a higher price but wait…nothing about oranges or apples or the labor required to produce them has changed. We need to attract more labor to the orange juice industry but the effort, skill, responsibility and working conditions of orange juice workers has not changed. How can we justly pay them more than their apple juice brethren? Blank out.

The market compares apples and oranges every day. It is the only institution that can. But there is a deeper error here than computation. Suppose the tribunal succeeded. Suppose that after another decade it delivered the true and final score, shelf-stacker versus warehouseman. What would it have found? Not justice. A wage is not a grade on your character or a measure of your worth as a human being. A wage is a price — a report on how scarce your skills are relative to the desires of people you will never meet. Nurses are not morally less worthy than plumbers should they earn less than plumbers or vice-versa, and no one thinks otherwise except the tribunals.

Hayek nailed it in The Mirage of Social Justice: justice is about conduct — how one person treats another. An employer who defrauds his workers, an employee who steals from the till, a product sold under false pretenses — condemn them, take them to court. But the pattern of prices that emerges from millions of voluntary trades is nobody’s conduct. No one chose it, no one designed it, no one can be guilty of it. The constellation of prices is, in Ferguson’s phrase, the result of human action but not of human design. Demanding that prices be just is a category error, like suing the weather. Prices don’t grade our merit; they guide our actions. Ask them to do the first and they can no longer do the second.

Judge Anthony Kennedy said it well in the Ninth Circuit ruling that (mostly) killed comparable worth in the US: “neither law nor logic deems the free market system a suspect enterprise.”

Talk Therapy is Speech

IJ: On Wednesday, the United States District Court for the District of Columbia struck down a D.C. law that barred therapists from other jurisdictions from doing online teletherapy visits with clients in D.C. The decision comes nearly six years after Virginia-based counselor Elizabeth Brokamp teamed up with the Institute for Justice (IJ) to file a lawsuit arguing the law violated the First Amendment.

“This decision is a victory for anyone who speaks for a living,” said IJ Deputy Director of Litigation Robert McNamara. “Elizabeth’s victory here confirms that the First Amendment protects useful speech, including counseling, and that licensing boards can’t censor speech simply because someone doesn’t have their permission to talk.”

Congrats to the IJ! Now, we need to get rid of all the other bans on patients hiring physicians from other states. As I wrote last year:

During the pandemic, many restrictions on telemedicine were lifted, making it far easier for physicians to treat patients across state lines. That window has largely closed. Today, unless a doctor is separately licensed in a patient’s state—or the states have a formal agreement—remote care is often illegal. So if you live in Virginia and want a second opinion from a Mayo Clinic physician in Florida, you may have to fly to Florida, unless that Florida physician happens to hold a Virginia license.

The standard framing says this is a problem of physician licensing. That leads directly to calls for interstate compacts or federalizing medical licensure. Mutual recognition is good. Driver’s licenses are issued by states but are valid in every state. No one complains that Florida’s regime endangers Virginians. But mutual recognition or federal licensing is not the only solution nor the only way to think about this issue.

The real issue isn’t who licenses doctors. It’s that patients are forbidden from choosing a licensed doctor in another state. We can keep state-level licensing, but free the patient. Let any American consult any physician licensed in any state. That’s competitive federalism—no compacts, no federal agency, just patient choice.

Hat tip: Joel Selanikio.

An OpenAI Model Escaped Its Sandbox and Hacked Hugging Face

AI has just had what I considered to be the first truly concerning security breach. The facts, as we know them so far, are wild. On July 16, Hugging Face, a vast repository housing over a million open-source AI models and data, announced in a blog post:

Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.

The timeline here is important so keep in mind that the attack was detected probably around Monday July 13 or Tuesday July 14. Note further:

A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.

So this means the breach started earlier, perhaps Sat July 11 or even a bit earlier. The attack was not just one thing but multi-pronged including decoys:

To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events. This allowed us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed.

Hugging Face tried to respond but they were initially held back by the fact that the most advanced models at their disposal treated defense as attack and refused to work with Hugging Face. HF thus had to turn to open models–specifically GLM 5.2, a Chinese open-weight model run on their own infrastructure. Note the irony: HF had to use a Chinese model to defend themselves because the American models refused to help. The irony gets deeper.

At the time, I assumed this was a state based attack–maybe China or Russia testing out defenses. Indeed, HF “reported this incident to law enforcement agencies.”

But yesterday (Tuesday July 21), we learned who the real attackers were. The attackers were OpenAI models–GPT-5.6 Sol and an even more capable pre-release model. OpenAI had taken some off the guardrails off the models but they felt safe because they were testing the models in a highly secured sandbox.

The models, however, broke out of the sandbox exploiting a never before seen fault. They then gained access to the internet and from there broke into Hugging Face–all in an effort to steal the answers to the very test they had been asked to solve.

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.

Now go back to the timeline. As I read it, the models had escaped the sandbox by around Sat. July 11, possibly earlier, and were detected by Hugging Face on Monday July 13 or Tuesday July 14. HF alerted legal authorities around that time–so Hugging Face clearly had no idea who was attacking them. OpenAI says its security team discovered the anomalous activity internally but has not said when. Attribution was not disclosed until Tuesday July 21, so it may well be that the models were loose for about a week before OpenAI realized that they were the ones attacking Hugging Face. And whatever OpenAI knew and when, nobody warned Hugging Face while the attack was underway–they were left to fight off a frontier lab’s models on their own.

This is a very serious breach.

Addendum: People have been wondering why I signed the We Must Act Now statement. This is why.

I am optimistic about the economic impacts of AI, but I also have no doubt that this is a very powerful technology–an Alien Intelligence–quite unlike any we have dealt with before. This incident was, in fact, error-correcting–the attack was detected, contained, and disclosed. But note who paid for OpenAI’s experiment: Hugging Face. When a lab’s test imposes costs on third parties, that is a classic externality, and taking externalities seriously is not dirigisme, it’s law and economics. And that’s the easy case. What do we do when a Chinese model breaks out of its less secure lab? Hmmm…

I remain optimistic. Learning by doing is how I want us to proceed but we should not kid ourselves: this is a global issue and we must build with safety in mind.