The people testing AI for danger are having a hard time keeping up

Axios
Published

The short version

  • Why it matters: When safety testing can't keep pace, models capable of hacking companies or aiding in the development of bioweapons could reach the public before anyone knows what they can do.…
  • Reality check: The models themselves are also getting in the way of their own evaluations as they start to cheat more and learn when they're being evaluated…
  • The big picture: Safety testing rests on model companies voluntarily working with third-party evaluators before deployment. "Companies are voluntarily giving access to their private models," Chan…
  • Between the lines: Many frontier AI models have been outgrowing existing benchmarks as they each score highly on routine cyber tests…
  • Zoom in: Chris Canal, CEO and co-founder of third-party evaluation company EquiStamp, told Axios his company has been asked to build a "hard mode" version of a popular cybersecurity…

The story

The pace of AI development combined with soaring compute costs is squeezing the AI researchers responsible for evaluating frontier models — just as those models' capabilities are becoming harder to measure.

Why it matters: When safety testing can't keep pace, models capable of hacking companies or aiding in the development of bioweapons could reach the public before anyone knows what they can do.


Several challenges are tying up AI safety and security researchers just as U.S. frontier AI companies race to get new models to market:

  • Some testers tell Axios that they're getting far less time to study models' capabilities before release — in some cases just days instead of weeks.
  • Building benchmarks that can accurately probe models' security skills is becoming cost-prohibitive as bigger tests chew through ever more compute.
  • Researchers often get access to a single, rate-limited API endpoint shared with other testers, so they quickly hit usage caps and can't run large or thorough evaluations in the time they have before deployment.

Reality check: The models themselves are also getting in the way of their own evaluations as they start to cheat more and learn when they're being evaluated, former Metr researcher Lawrence Chan told Axios.

  • This puts evaluators in the tough spot of trying to figure out how a model that knows it's being watched would behave in the wild, Chan added.

Threat level: That kind of test-gaming, if unfixed, could lead to "full-blown AI doom scenarios in the future," Chan said.

  • Miriam Vogel, president and CEO of EqualAI, told Axios the stakes extend beyond frontier AI labs because most people interact with AI through banks, social media platforms, news organizations and other companies deploying AI systems rather than building them.
  • If we get AI safety wrong, "it will hurt people and hurt our institutions, because we have not put the governance in place to deserve the trust," Vogel said.

The big picture: Safety testing rests on model companies voluntarily working with third-party evaluators before deployment.

  • "Companies are voluntarily giving access to their private models," Chan said. "As a result, you have to stay on their good side."
  • Short testing windows, limited API access and expensive benchmarks all feel "downstream of this problem," he said.

Between the lines: Many frontier AI models have been outgrowing existing benchmarks as they each score highly on routine cyber tests — making it difficult for AI companies and third-party evaluators to properly measure the cyber capabilities of these models.

  • Earlier this week, Cisco said it developed a new internal benchmark to test its new security-focused, open-source models specifically because it didn't have a better way to measure its capabilities.
  • "There is a crisis in benchmarking," Amin Karbasi, Cisco's vice president and chief AI scientist, told Axios. If everyone scores 95% on the benchmarks, it could mean that the companies are training on that benchmark, Karbasi says.

Zoom in: Chris Canal, CEO and co-founder of third-party evaluation company EquiStamp, told Axios his company has been asked to build a "hard mode" version of a popular cybersecurity benchmark, where models have to find and exploit serious, unpublished software vulnerabilities.

  • But to do that responsibly, he said his team would have to buy information about zero‑day vulnerabilities from the exploit market.
  • A single zero-day can run $50,000 to $100,000, and Canal says he'd have to compete with the Russian and North Korean governments who bid up prices.
  • One frontier AI company brushed off the concern, telling Canal its model could simply use the open internet as an "exploit finder" to uncover new vulnerabilities on its own.

What to watch: Some evaluators argue that third-party testing should happen during model training, not right before a public deployment.

  • "External deployment is just no longer the important barrier for harm," Marius Hobbhahn, CEO of third-party AI evaluation organization Apollo Research, said on X. "A smart misaligned model will cause harm during training or internal evals already."
  • Testing earlier, tighter sandboxes and monitoring all help, Chan said, but none solve the underlying issue: "It's hard to make a box that is secure against a thing that is much smarter than you."
Read the full story at AxiosOriginal

Related Markets

All Markets
View full chart →
View Full Chart
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

How other outlets covered this

Compare all

Alto found this story at 6 outlets. Same event, different framing — compare the headlines.

How this story developed

Full timeline

Alto has tracked this across 9 days of coverage from 6 outlets.

    • The people testing AI for danger are having a hard time keeping upYou are here

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

Up next

Related coverage from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  2. Where does a $75,000 household income rank nationally?Census percentile — national and state
  3. What's Alto covering on the Tech & AI desk?Latest headlines on this beat

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Big Tech Where Big Tech Can't Reach

AI, surveillance, and censorship, covered by the people the platforms removed first.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.