# AIUC Raises $40M for AI Risk Infrastructure

**Podcast:** Latent Space: The AI Engineer Podcast
**Published:** 2026-09-16

## Transcript

Okay, we're in the studio with Rune from AIUC, AI underwriting company, with our trusty co-host, Vibu.
Welcome.
Thank you.
Thanks for having me.
Thank you.
What are you announcing today?
We have raised $40 million by Ribbit Capital and First Timonic.
You first came to my attention when Nat and Dan invested in you guys.
Is the story pretty much the same?
Are you today where you thought you were back then?
When we raised our seed round, we had a hypothesis that at some point...
risk was going to hold down adoption.
At that point in time, that felt kind of hypothetical.
And I think that is now over.
Clearly, the moment is now.
With mythos and with fable, it's pretty obvious that literally the binding constraint on adoption is risk.
And so for us, it feels like this is a natural continuation of the same hypothesis, but where previously it was speculation, now it feels like fact.
And let's get a list of the customers that you're highlighting as part of your Series A.
Totally.
Yeah, so we are now working with folks like Cursor, Harvey, Lovable, Eleven Labs.
Yeah, amazing.
Congrats.
Thank you.
So you were famously one of the first hired and adopted for GTM and product.
I'm just kind of curious, what was your path into AI?
Just recap.
Late 2021, I sold a company, my first company, an edtech company.
I had a bit of time to think about what was next.
I came across the scaling loss paper and that just struck me like lightning.
I was just like, this is a big idea.
In short, the scaling loss paper just says the bigger the model, the smarter the model.
And this is the Kaplan one, not the Chinchilla one.
Exactly, the Kaplan one.
And the important thing that clicked for me there was, oh, now Capito will understand this.
If you put in more money, you get more money out.
And so that will kick off a hype cycle.
And so you'll actually kind of, you'll get a sense of predictable returns, which is in fact what's played out.
And so I just pack my bags.
I've never been to San Francisco.
I just pack my bags throughout here to find the people who have ridden it.
And at the time, they had just started a small lab called Anthropic.
There was like 40 people at the time or so.
Drank a bunch of coffee until I eventually got introduced to Dario.
And at the time, they were wrestling with some of these questions of like, should we deploy our models?
Should we make revenue?
How should we engage with the rest of the world?
They're just broken off from OpenAI.
And it's been publicly reported that they were kind of concerned with how they were dealing with deployment.
So they were wrestling with some of those questions.
At this point, this is like early fog of war, like early 2022, the sexiest program at the time of like Jasper.
There's nothing out there.
So where is value going to accrue?
What are going to be the different parts of the stack?
We're all open questions.
I want to highlight to people, you ask these questions because you have a PPE background.
Yes.
I actually was in Singapore in one of the sort of feeder programs prepping people for PPE.
So I had a tutor.
We learned philosophy and politics and economics.
But I think machine learning people who read the Neural Skilling Laws paper would not necessarily draw the same conclusions that you did.
Whereas any capitalist would read that and go, holy shit.
Correct.
Right?
Yes.
Who tipped you onto that paper?
Because it's not a paper that you normally read, right?
Like in your circles.
Yeah.
I think I'd actually, ever since AlphaGo had had some appreciation that AI was a big deal, but it kind of felt, it raised all these kind of interesting philosophical questions, but it's kind of not.
clear from afar where exactly that would go.
But it was obvious enough that it was like, this is going to be a big thing if we find the kind of right mechanism to kind of get the techno-capital machine to work on this.
But it was just not clear.
And so I think there was some way in which that became obvious.
And also, it wasn't as obvious at the time than it is now, right?
It was just like, wow, this is so interesting.
But it still felt, coming from kind of a philosophy and economics background, it felt like If this turns out to be true, you're going to be wrestling with all of the big questions in society.
Everything you've learned about politics gets thrown out of the window.
Everything you've learned about economics at least gets challenged.
And so what felt interesting was to be at that frontier that has just ramifications across everything.
So that's why I thought it sorted out.
I mean, clearly really good insight.
For people who don't know, the PPE program is like where prime ministers are born.
So then you end up meeting Jared.
Yep.
First, Dario, yeah?
Yeah.
Well, I mean, did you get extra insights from talking with them that you didn't get from your original hypothesis?
If you read the Scalorhands paper, you get this very vague sketch of like, wow, this seems kind of important.
There are some lines, a chart, this seems kind of important.
And what I think the team at Anthropica thought more about than anyone was like, what are the implications of this?
If you really play this out, and back then they had vision documents for what the world would look like in 2026.
And they were kind of in vivid detail playing out how much compute is going to be needed, what is the capex going to look like, what are going to be some of the kind of societal concerns, but also what is the amount of economic value coming out here.
And so it kind of felt like they held a crystal ball that in hindsight turned out to just be dramatically correct.
And they weren't holding it like they were obviously correct.
They were just like, take this hypothesis really, really seriously.
Think it through.
And think it through.
in the same way the kind of situational awareness that is now...
Across the street?
Across the street.
Oh my God, we're all in the same one square mile of...
Correct.
And that's now a couple of years old, but also people keep referencing it these particular weeks with Fable and Mythos and it's like, wow, if you take this one idea seriously, the scaling laws, a lot of things fall into place.
And keep in mind, at this point, this is the same team that had did GPT 1, 2, and 3.
Correct.
which is also like, it's not just some experimentation.
Like this is a real model that we just killed up.
And they had deep conviction in, again, in this like big, if you take a big blob of compute, it just wants to learn.
And out of that will come smarter and smarter models.
And all the particulars were not clear.
Yeah, yeah.
And all the implications were not clear.
But their deep conviction is like core thesis.
And that was kind of dizzying.
phenomenally interesting and exciting.
And also, very quickly, you got to like, the world we know today will no longer be.
Is this hypothesis hold?
So I also just felt like important in some kind of grand sense.
What kind of shaped you there?
So that was your early 2022.
Not only had GPT-123 come out, but, you know, the amazing co-founders of Anthropic that have never split up.
The only ones, they actually had the conviction to leave OpenAI, start their lab.
You said there were about 40 people there.
What was the time like there?
It was kind of remarkably like what it looks like on the outside today.
Extremely cohesive, extremely mission-oriented, and living in this tension between their two ideas, which is AI could both go really well and really bad, and we want to be part of building it.
That creates astounding amounts of tension.
And they were wrestling with this incentive challenge where they know there's a race.
that they're in where you might get forced to cut corners, but it also felt very important to them to be at the forefront of technology.
And all of those ideas were just present at that time.
It kind of feels like that line has been just very, very clear.
And I think kind of love them or hate them, they have really stuck to their guns.
There's a core set of beliefs that they hold more deeply than most companies hold any beliefs.
Yeah.
Fast forward to today, what does that lead us to AI underwriting company?
What are you up to?
What motivated you to start this?
Yeah, AIUC built confidence infrastructure for Frontier AI through standards and insurance.
The link from Anthropic to building confidence infrastructure, looking out the windows of Anthropic offices and seeing Waymos driving by.
Already back then, early 2022, Waymos were in some ways like AGI for cars, like they were superhuman drivers, but you couldn't take one to the airport.
And now, four and a bit years later, you still can't take your way most of the airport, despite now everyone having kind of looked at the evidence and being like, they're better drivers than humans.
So in that particular instance, what's clear is that the binding constraint on AI being useful is not capability, but it's that liability or risk or trust.
That problem is general.
The reason why right now Fable is not open for access is not because it's not a good model.
It's because it's a very good model.
It's just hard to make promises about what it will or will not do.
And this problem gets worse as AI gets better.
Basically, more intelligent AI can be more autonomous.
That's more valuable, but also the risk surface grows.
And so what Waymo illustrates is that unless you build the confidence infrastructure to make promises about AI or at least bring light to the risks, you grind adoption to a halt.
Governments, banks, hospitals, militaries need to have some sense of what AI will and will not do to be able to operate for them to incorporate it.
And that's the problem that we're trying to solve.
Now, why standards and insurance?
If you trace this problem back through history, every technology wave has had some version of this problem.
So if you go back to like year 1900, electricity comes out.
Then Franklin.
Cars burn down.
Sorry, houses burn down.
Lots of people die.
1930s.
Cars are a big deal, kill lots of people.
50s, private nuclear energy is a big deal, poses big risks.
In each of those instances, the market runs ahead of regulation to create confidence infrastructure because that's required to make go-no-go decisions.
They're required for adoption, and the market fundamentally wants adoption.
And in all of those instances, common blueprint emerges between standards and insurance.
The reason it's these two components is standards kind of...
provide the rules of the road, and they also specify what are the tests that need to be run so we can get a sense of how high the risk is.
So taking the case of cars, that's like a car crash.
Great, everyone, they inform your insurance pricing today, they inform your purchasing decisions, et cetera.
That's basically the risk framework.
The insurers are important because they pick up the bill.
So they are the private institution that is most on the side of, and is best incentivized to quantify the risks truthfully.
And then, figure out all the ways to reduce the risk because that increases their profit.
So they're basically, they help shape the incentives.
And these two work really well in unison.
Now, how does that show up as a company?
Well, one of the things that was obvious, or starting to become obvious even a couple of years ago, was that frontier companies, some of our customers today, like Cursor, Sierra, Eleven Labs, Harvey, were going to have a very easy time selling a pilot to a bank.
The damage itself is magic.
But bringing that through, if you want to do a wall-to-wall rollout at a bank or a hospital, you have to go through the risk process.
These banks have no idea even which questions to ask, let alone which answers are sufficient, let alone how do they go and test whether these agents actually work the way they're supposed to.
And so they have this problem of like, what can we say to earn the trust?
And we think there's like a golden sentence that goes something like, hey, I hear you're really worried about hallucinations or jailbreaks or whatever it may be.
We've had an independent third party test us against the gold standard.
We pass with flying colors.
And as a vote of confidence, the world's most conservative insurers have looked at the data and are willing to take some of the risk onto their balance sheet.
So if something does go wrong.
There's money behind it, yeah.
Exactly.
So that's kind of like the link between all of us.
We can get into some of the hard parts related to the technical testing, which is, I think, the crux of the matter.
But I'll post there.
How did you and Rajiv come together?
There's always like, you come across very confident and, you know, we're announcing your Series A and all these things.
But I want to see like the early initial stages of like idea formation.
Yeah.
Rajiv is actually my soon-to-be brother-in-law.
Oh!
So I'm actually in a week and a half getting married to Rajiv's sister.
Okay, now you're tight.
Exactly.
So Rajiv and I have known each other for a decade.
Funny story, I met both Rajiv and his sister, Hena, at the same time when Hena and I were interns at McKinsey in London, and Rajiv was assigned as my mentor.
And so I met them at the same time.
For the longest time, it was not obvious that we were necessarily going to work together.
I was in startups.
He was an insurance partner at McKinsey.
Three or four years ago, I think Hannah convinced him that AI was going to be a really big saying.
And so he quit his job, a cushy partner job at McKinsey in London, packed his bags, flew to San Francisco, and ended up joining Meter.
You guys are probably not lying enough.
We've interviewed them.
The chart of the horizons of the tasks that agents can take on is doubling extremely fast.
So here's Ciro there, led their partnerships with...
Anthropic and OpenAI to test their models before release, but also working closely with the US and UK government to figure out how do you know whether a model can be released?
And in some ways, that's the perfect background.
He's spent a lot of time in insurance, knows that world, spent a lot of time with frontier testing of models.
And so when I was bumbling around this idea space, starting with some of the ideas we talked about related to Waymo, as soon as we got into the content, we were both like, oh, this would be an amazing business to build together.
This is like wrestling with the problem that we both think is the most important in the world from a market angle, which is kind of our intuitions is that the market can do a lot and the faster I move, the harder it is for government to solve some of these problems.
And then it took a little bit of time to work through what it's like to work with family.
Because you're already dating at the time.
Yeah, exactly.
Already back then, we felt like we were family.
And so starting a business together felt like kind of a big step.
And here we are with just immense amounts of trust.
Yeah.
So now you're a company of how big?
How big are you guys now?
There is just 20 of us now.
20 of you guys now have Series A and you have your first certification out, the AIUC1.
Let's bring up the certification.
This is the agent certification, right?
What goes into the process?
I have like two questions here.
One is walk us through the certification.
And two is what is the process for a company to get certified, you know?
Great.
As it says right at the top, AAS1 is the standard for agent security, safety, and reliability.
The fundamental design principle is take all of the concerns that slow down adoption.
It's all the questions, all the fears that keep.
security leaders in the Fortune 1000 up at night and put them into one comprehensive framework.
That's what you'll see there.
You can see the six categories.
Two, you want to ground all of this in technical testing.
So one of the concerns with security standards that often feel kind of like theater paperwork is that they're actually ground out in does any of this work?
Does any of this matter?
And so we had a conviction from early on that that was going to be the kind of crux was to pass this, you must get tested every quarter.
basically run thousands of simulations to see, well, so can it actually be jailbroken?
How hard is it to jailbreak?
How often does it hallucinate?
How often does it leak data, et cetera?
And then the last core idea here, if you scroll up to the top here, is to refresh it quarterly.
So the core trait of AI is that it moves extremely fast.
Whatever concerns we're discussing today were not the same ones three months ago, and this will keep changing.
Typically, standards update on like a decade.
cycle is obviously not going to work.
But the question is kind of how do you update it?
And the core thing here was to basically get the risk leaders of the Fortune 1000 around the table.
So if you go over to the left here, you'll see AAC1 Consortium.
The consortium is a group of risk leaders who run real banks, real hospitals, real critical infrastructure who are facing these challenges every day.
And we meet with these folks twice a quarter and hear what's top of mind, what is keeping them up at night.
There's a tremendous amount of desire for that conversation.
And then we operationalize that into a specific standard that gets into, and actually we can go into and look at what even is the standards.
If we go back to introduction out there to the left, scroll up a little bit to the wheel, click into reliability.
So if we take something like hallucinations, hallucinations sits in reliability.
There is a number of requirements here.
If you go into the top one, prevent hallucinate requirements, hallucinate outputs.
This is one particular requirement.
This is a technical control.
Basically, we want some kind of groundiness filter.
The first thing you see here is what's called a crosswalk.
So everyone and their grandmother has put out a framework, very high-level framework for what are the AI risks.
This is basically your competition, but not seriously.
In some ways, our competition, we're in fact friends with them.
We'll come back to why.
But mapping everything together so you have one superset, the claim you're trying to support here is if you follow this framework, then you can also see how you follow the other frameworks.
But the meat of it comes down here in control activities and evidence.
So control activities is like, great, you have this high level requirement.
How do you turn that down to something operational?
Here's what you must do.
And then what is the evidence that we're looking for?
And the reason we go this deep is that there's actually not that much confusion about what are the big concerns in AI.
Everyone agrees to these.
The question like, what are you actually supposed to do?
And so what we found a lot of...
demand for is getting down to the specific evidence that people need to look for.
Whether you are Cursor building something or even Jake Morgan building something, but also if you're just a risk leader at Jake Morgan, what exactly should you ask for?
What can you ask for without sounding stupid?
You won't believe the amount of time a risk leader has asked for the IP rights to the online model to Cursor or something.
Sorry, what?
You slip it in there and see if you notice.
Exactly, put that in the questionnaire.
So that's kind of what a standard is.
And we update this every quarter with these folks to keep up with the latest concerns.
Can I double click on this one?
Yeah.
So first of all, the website is beautiful.
Like it's so confidence inducing, which is the whole point where like, okay, I know exactly what I'm signing up for when I talk with you.
I don't even have to talk to you.
I can just see your whole.
certification, which is great.
But like, okay, so from here, like D001.1 config, Gondis filter, how does that get applied?
Like you have a person that goes to it?
Yeah, so if you go back up.
I did see somewhere there's like, you know, 51 requirements, 130 controls.
There's like a whole...
Right, right.
To me, this doesn't translate into a test or an eval.
Yes, yes, yes, yes.
So if you go into...
I don't know, the left-hand side.
So actually, before we go in there, there are three types of requirements.
The first is technical controls, like you must implement some guardrails.
Two, there are test controls.
So you must have an independent third party go and run some tests against you.
I'll show you one of those in a second.
And then three, there are policy controls.
For example, you must have a person whose name is on the line when you guys fuck up, and you must have a plan for how you tell your customers and how you engage with them.
They're kind of more traditional standard type stuff.
So in this particular instance, we just check whether they in fact have a ground-in-us filter.
So we will partner with an auditor.
So we partner with auditors like KPMG or like Shellman who go in and do the thing auditors do, which is to check the evidence.
In this case, that might be a screenshot.
It might be part of the code that they need to review to see that it actually, just that it exists.
And then the second thing is...
So you're not testing the effectiveness of it.
That's the second thing.
So if you go down to the third party testing for hallucinations out on the left, that's basically the next requirement.
This is where we test how well does it actually work.
Okay.
And is it you testing or the auditor?
We test them.
We test them.
That's a lot of work.
How long does testing take?
So if I want to get certified, just how long does the end end roughly take?
Yeah, the end-to-end almost always is dependent on our customers need to learn something for us.
It takes somewhere between like three to...
10 weeks, depending on how up to snuff they already are.
So some people could show up to us with extremely rigorous security programs.
When we test them, it works extremely well.
We can get that done very quick.
Some people come to us and they're not that far along.
We give them kind of the spec that they need to build towards and then their security teams and engineers get to work and build to meet the standard.
The testing itself typically takes a couple of weeks, including the time for them to remediate.
Often we'll find something that we cannot pass.
where, hey, this is actually just not up to the standard.
You won't pass the standard.
And then they will need to go and implement additional safeguards or additional remediation that makes them more robust so that they can actually kind of hand on hand look at their customers in the eyes and say like, hey, we've done truly our very best.
And they're certified for a year and have quarterly updates?
Correct.
And yeah, it's pretty interesting.
I think, you know, what's changed since?
So this is...
certifying agents in production, right?
Your customers, like you've had Lovable, Eleven Labs, Intercomfin, they've all gone through this certification.
Yes.
What has changed?
So I see you post like, you know, Q2 added MCP, agent-to-agent communication.
Any other things that you want to kind of highlight since the first iteration?
What comes in quarterly?
Yeah, so some of the changes have just been, agents are not just one thing.
So like, if you take agents like, cursor and compare them to Sierra.
They're really quite different.
Compare them to Harvey again.
Compare them to UI again.
11 Labs.
They're all quite different.
And so we wanted to design a standard that works for all of the types of agents.
And we started with one that was like pretty text-based, like honestly pretty customer support focused.
That's where there's a lot of existing demand.
And then over time I've picked some of the frontier companies in each of these other domains that we could work with and build out the standards.
So such that we know that the same standard works for code, it works for customer support, it works for automation, et cetera.
So that's been one big thing.
Yeah, then some of the things that have been top of mind recently, Mythos is bringing up a lot of concerns for security leaders.
We're starting to get more and more questions around agent-to-agent interactions.
It's very nascent at the moment, but it's starting to emerge.
There's been a lot of...
questions related to OpenClaw and MCP, again, like agents starting to interact with each other is really top of mind.
Then as coding agents have really taken off, that's also where banks and hospitals, et cetera, are getting more and more precise on what it is they need.
So I'm really dialing in as I start to be like where most of the tokens flow through in the world, getting much help around that.
Can you share for people that are listening that don't really think about this?
Like you mentioned, there's the...
Obvious stuff, you know, hallucinations, citations.
What are best practices that people should do when building agents?
Like if they come to you pretty ready with certificate, like, you know, they'll probably pass certification.
What are the things people don't think about that they should have?
The most important thing is that a lot of companies have not done a serious stress test.
They spend most of the time, perhaps rightly so, optimizing for how does it work in the good case.
the average case, how high quality is the output for the customer.
And a lot of these companies are pretty new.
So they haven't spent a lot of time stress testing the, what is there as an adversary on the other side?
What are some of the complicated corner cases that you've not really considered?
So I think there's like a frame of mind and you'll see this in startups.
It often takes a while until they hire their first security person and there's a whole different kind of risk surface than just building a good product.
So a lot of that applies.
most companies actually also have the right kind of architecture.
Most of them will have some kind of guardrails in place.
Either some are coming out of the box from their model provider or they'll have built their own filters that sits in between.
They just don't work very well.
The difference between putting a classifier in place that maybe goes and checks whether you're giving medical advice when you shouldn't and says, hey, if this looks like medical advice, filter it out.
Lots of companies have that in place.
The question is whether it works.
And it's actually pretty fiddly.
to sit down and think about all the ways in which you could ask for medical advice, read the academic literature on what are the kinds of framings or tricks you might play to get an AI to give you medical advice when you really shouldn't.
And so there's like an area of expertise that's just missing.
So what we find is that most people have the right billing box in place.
It's not rocket science, but the finicky thing is like getting into the corners and testing whether it works such that you can look at your customers in the eye who may be a bank or maybe...
a hospital and be like, this is going to work for you.
I see.
So we talked a lot about the agent level certification.
Where do you guys go from here?
So announcing series A off camera, we talked about this a bit.
There's the whole security risk of Fable government stepping in.
You guys are kind of announcing that you're also going into model certification?
When we do a bit of cutting afterwards, we will not yet be announcing this, but the question that is top of Everyone's minds now is at the model level.
And Mithos then Fable has really brought this to the fore that in addition to the commercial risk and the kind of economic security risks that are happening at the agent layer, the models are going to present risk in the national security category.
The shape of the problem is very similar.
You have some people that are on the hook if something goes wrong.
In the case of agents, it's often security leaders in the enterprise.
In this case, it's the government.
They don't haven't necessarily spent their entire lives thinking about what are the new risks that come here, what is the kind of data you might be looking for, how might you test that.
But they do have to make sure that their concerns are addressed.
You have some frontier companies that are deeply technical, they know a lot about the risks, but they fundamentally have an incentive to not always be truthful.
So you have a trust gap between the government and the labs.
And in every other industry, you end up with some kind of body sitting between, a neutral third party sitting between.
those people.
There's no other industry where you allow people to audit themselves.
So there's going to be a need for a third party that can take the rigor of the labs to run frontier technical evals, but can also speak legible trusts in the way that the government trusts PwC to go and run financial audits.
And they know that they output audit reports in a way that's consistent, that's easy to read, that's factual, that's trustworthy.
Those two things need to be brought together.
What we've learned from our work with agents is that if you want that communication between those two parties to be smooth, there has to be one common standard that is public that people can go and inspect.
What are the risks that matter within each of these risks?
What are the kind of threat models that you're really looking for?
You need to specify for each of those risks, what are the guardrails that need to be in place?
And what are the tests they need to run to see whether those guardrails are effective?
And then you need to go and run audits that are...
technical audits that are consistent.
So if you're trying to bring trust, it's extremely important that you methodically work your way through the risks.
You can't send one researcher in and say, like, come back with whatever you find.
You need to be able to explain exactly what you did, exactly what you tried, exactly what you did not try, and therefore the kinds of promises you can and cannot make at the end of it.
I think of Fable as a direct symptom of this problem that the government was told that there's a risk.
The government may struggle to assess just how big that risk is.
They call Anthropic and Anthropic is trying to tell them, hey, actually every model can be jailbroken.
That's not what you want to hear, right?
As the government, that might be hard to trust.
And we think that a broker is the most natural solution.
In other markets, you see something like, in financial markets, you see Moody's.
Moody's goes in and they look at a bond.
And they output a rating.
They say, like, here's the evidence we found.
Here's the rating.
We don't decide whether anyone should buy this bond or not buy this bond.
Well, that depends on their risk appetite.
But we do provide this common information layer that everyone can rely on.
In the case of Moody's, the government points to them and say, hey, pension funds, you should probably really take care.
You shouldn't risk your pensioners' money.
So you can only invest in AAA-rated bonds.
That means that now the government doesn't have to staff thousands of financial technical experts to rerun forecasts every week to see whether things are correctly rated.
They get to point to some neutral third party.
So my hypothesis is, my hunch is that you will see a third party that sits between the government and the labs.
And it could either be the government bills it themselves.
So something like Casey was set up to do exactly this.
Sorry, I'm not familiar with KC.
KC is the Center for AI Standards and Innovation.
Okay.
I won't get into the details, but it's a sub-body of NIST that typically sets standards.
So it's basically a government body that has AI experts.
Yeah, exactly.
Very low-key.
I think it's one of those things where when you just sit back and look at it, like, is there enough technical expertise in the government to measure, test these things right now?
Probably not, right?
Fable is a result of, okay, we've had to scale back and pause things.
And they have excellent people, but they have an extraordinarily small budget compared to the scale of the challenge that's ahead of us.
And I think they have a role to play.
The question is kind of like, who does what?
We have now outlined the jobs to be done, and they're quite extensive.
Every model release, there is an astounding, given that they take in any input, the risk surface is astounding.
And so the question is really, what can only the government do?
And what can the market provide here that can keep up with the pace as AI risk changes?
Our perspective is that also the model layer, the risks that people care about today are not the same ones they cared about three months ago.
So the pace of legislation is too slow to deal with pinpointing the risks here.
And so we think there's a lot that the market can do to surface timely information.
Ultimately, there is a bunch of policy decisions here.
Is the national security risks of a model too high?
That's a political answer.
But what we want to make sure is that the process that produces this risk information is compatible with very fast innovation.
So you don't want to, this is not a question of like, can you slow the things down?
Can you keep the models locked up until, for months on end, until everyone can make a guarantee?
But it is, can you, in the time it, given that the US is competing with China on releasing models, can you insert?
risk information that allows the government to like make rapid decisions on some of these questions.
Balancing that trade-off between failing to adopt AI is going to put us at risk, but also reckless adoption is going to put us at risk.
And that's a very kind of fine balance that they're going to need like a lot of high quality intelligence to make.
Just a side mention, because you mentioned Chinese models, any specific concerns that you're hearing from your CISOs about that?
Because I guess it's free, but...
CISOs have a bunch of concerns around data flows in general that they're really concerned about.
So there's a lot of questions like, if these models are Chinese, where does our data go?
I think a lot of this can be addressed, but they come up often.
I mean, they understand they're running on American GPUs.
Some of them understand that they're running on American GPUs.
They're not like phoning home every time you call home.
No.
A year ago, there was not a lot of understanding of this.
I actually think you're seeing the security leaders.
becoming kind of AI literate at a blistering pace and you're actually also seeing my Twitter timeline that's very AI-pilled and my LinkedIn feed that used to not at all be AI-pilled kind of converge.
They're both talking about Fable.
Right, yeah, that's true.
They are both talking about whether you can prevent models from being jailbroken these days.
Yeah, yeah.
Like national security risk, that conversation is actually emerging.
Other than that, I think you mostly see a kind of, there's no concerns with any particular model or any particular model output, but there's a general nervousness of having critical infrastructure run on models that are not produced in America by Americans where the American government has control.
But it doesn't necessarily show up in your framework directly?
There's a bit of stuff in there actually on the provenance of the models and disclosing that.
But I think there's a bunch of use cases where running a Chinese open source model is just the best solution.
And a concern is slightly more macro here, which is not best addressed at any particular certification level.
Is there anything interesting that you see at the, you know, if you're trying to fill that middle gap, that mediation gap, any interesting stuff that you guys forecast would be required other than, you know, what the average person might expect?
There's a bunch of interesting questions about what are the risks that matter here.
So right now, the risk of the day is cyber because it's very real, very tangible.
And some of the risks that are also emerging as pretty real and pretty tangible are things like child safety is becoming both extremely important, but also politically important.
And then some of the risks that are coming down the pipeline that today feel kind of speculative, but people spend a lot of time with the models, see them coming down as things like risks that relate to biology, and specifically whether models will help adversaries produce biological weapons and making that extremely cheap, extremely accessible.
producing, making the chance of another COVID or worse pandemic.
COVID was not engineered to be bad as if you were trying to do that.
So I think those are some of the risks that are coming down the pipeline.
I think one other thing to just note is that agents are kind of deliberately narrow.
So like when a frontier agent company puts a chatbot that interacts with customers, they've really tried to narrow the topics it's interested in talking about.
such that if you ask it, like, what do you think of the precedent?
It will just decline, which means there's a kind of risk area that's somewhat smaller.
For models, it is infinite.
And so there's not a single expert out there who can competently evaluate the risks of cyber attacks and 15-year-olds having month-long conversations with a chatbot and seeing whether it will in fact recommend suicide or something horrendous like that and can evaluate the risks that...
terrorists can use AI to produce bioweapons, the risk surface is just too big.
And so the central challenge actually becomes how do you get those subject matter experts to work within one coherent framework that outputs one coherent report and rating that the world can gun inspect?
Because that global perspective is central, but there's not a single organization today that could produce that.
And you would be the presumptive one when you put out your model standards.
We think there can be one company that can, with a consortium of experts, build one coherent standard.
I think we've shown that across all of the enterprise risks today.
We think it could be one company that could, with a consortium, specify the audit rules, basically like the inputs and outputs that all these technical experts need.
What access do they need?
How should they treat infrascurity?
They can look at whether the evals are well produced.
Without necessarily being able to say, hey, this is a threat or not a threat, but overall evaluating whether the evals are good, well-constructed, that set of older rules basically becomes the interface for all these experts we think one clearinghouse could put together.
To be clear, when I say one company, I think of it as one company coordinating lots of this in the same way that when we saw our consortium, it's not like we say we have all the answers on agent security.
What we say is we are taking on the role.
of eliciting all of the concerns and being the secretary that puts it together and runs a tight house such that the standard updates lockstep every quarter and that the order reports that come out, in this case, 100-page order reports, uniform and crisp and clear to the level of detail that is required for executives that need to make a clear go, no-go decision.
So that's kind of the role that we think we might play.
I think in many ways you're performing the role that OWASP used to do there.
And you said competition and partners can go more into how they partner.
Yeah.
So first of all, OWASP is basically an open source community of security practitioners that are coming together to build frameworks for addressing the latest security concerns.
We think they are phenomenal at creating frameworks.
First of all, we're partners with them, so we have a joint article.
We've learned a lot from them.
We think they're a tremendous source of intelligence.
What it always does not do is building the machine that runs third-party audits such that a company like Cursor or a company like JP Morgan could get a third party to go and review them against this and say, hey, you've passed the standard and here is the report that you can use to build trust and preempt your partner's or customer's questions.
So they fundamentally try to do something different.
They are part of the information gathering and intelligence gathering and creating clarity.
But the operational layer of turning this into promises is not the business they try to be in.
The standard is emerging and it's doing very well.
Was it necessary to then also do underwriting?
Obviously, it's in the name.
So presumably you thought about it first.
I feel like if you just have enough consensus, you don't actually need the money angle, but it does help.
I did want to also know you guys are...
a for-profit company too, right?
It's not non-profit where there's a whole business side to it as well.
Yeah, yeah.
I'm just going to say, let's get into the money part.
Let's start from actually your question, for-profit versus non-profit.
In the security space today, cybersecurity, most of the standards are produced by non-profits.
I think that's an issue.
The question you have to ask yourself is, How do you create good incentives for these standards to be good and keep up?
Nonprofits tend to not have these adverse profit incentives where they hollow out their standard and create a race to the bottom.
But they're also not at all responsive by default to the communities that they serve.
They don't have customers that they serve where they go and ask, what do you want?
What do you want?
What do you want?
And when you look at the overall satisfaction with the security standards today, people tend to just not like them very much.
You do see in other domains that for-profit standards can serve the world quite well.
So there are examples, like we talked about Moody's before.
It's not without flaws, but it is absolutely critical societal infrastructure that gets run at an astounding scale today.
Your credit score is FICO.
It's also a for-profit business.
And when you go back even further in history, Some of the crash testing standards came out of insurance companies.
The insurance companies together founded the Insurance Institute of Highway Safety because they were very interested in how can we use standards to drive down mortality and save money.
Go back, our name actually pays homage to the Underwriters Laboratory, UL, which was started right around when the electricity came out.
House has started burning down.
Insurance again.
were paying the bill.
And they were maybe also good people, but their profit incentive was, let's prevent houses from burning down.
Let's test all the electrical products, the light bulbs, all the light bulbs in here are probably UL tested, the toasters, et cetera.
And they set up an entity to create those standards.
Today, UL has a for-profit entity and a non-profit entity.
What they've recognized, they spun out, they started a non-profit, they spun out a for-profit because what they recognized was like, hey, actually to serve customers well.
you need a for-profit entity.
The lesson here is one of the ways that the market can align incentives so you're both responsive to customers and not hollowing out your standard over time is to align it with insurers because they fundamentally have good incentives.
And so if you're a for-profit standard that works closer with insurers, you get the feedback loop in such that you're really cued into your customers but also have their interest at heart.
So that's the model that we're the kind of inspirational model that we've learned a lot from and that's also where the name comes from.
In some ways, the term underwriting can both be associated with insurance, but it's also a broad term for like making decisions.
If you underwrite a decision, you're fundamentally kind of taking ownership for the consequences of it.
Yeah, I mean, what does an insurance contract look like for AI?
Yeah, most of the demand comes today for insurance contracts is sitting between people who've built AI and people who are buying AI.
Yes.
And what you want is the reason why people want insurers involved, both for the traditional reasons, hey, if something goes wrong, we want to be compensated.
But it's in particular because insurers can bring trust to the equation.
Because insurers will pay for the damages.
If they're willing to write an insurance policy, that is them saying, hey, we think there's risk here, but that is manageable.
And that is kind of their incentive aligned with...
The enterprise is adopting it.
So that's really a good signal to the market.
In the same way, actually, one of the things that Waymo tried to get their first permit to even operate in San Francisco was to get a lot of insurers to stack up a huge insurance policy in the case of something went wrong.
Not because Google can't pay, but because it was very valuable to have a third party go and look at that data that are trusted by governments, trusted by enterprises as conservative people.
and say, hey, we've looked at it.
We're actually willing to take some of this onto our balance sheet.
So that's kind of the reason why people are interested in it.
What it looks like is, in some ways, like every other insurance contract, you specify what are the perils you want to cover, how much do you want to cover them, like up to what limits, and what does it cost to cover that.
And in the case of, if we take a really concrete example, Eleven Labs bought a first-of-his-kind AI agent insurance policy.
They work with some of the biggest enterprises that work with governments.
They're really interested in going above and beyond and making promises to their customers.
So they wrote a policy that covers just some of the core concerns that their customers have been asking about.
And the crucial thing was really to get Lloyds of London, the world's oldest insurer, one of our partners, to look at this data and be that third party alongside us to say, hey, we think there's something here that's worth underwriting.
And that's actually what it looks like.
And so they will show that contract to their customers and they can see how much they're covered for.
They can see what exactly it covers.
And that will also probably change next year.
They will want to write an insurance policy that might cover more.
When you say Lloyd's, is it reinsurance or are they sharing somehow at the same level?
Yeah, so typically the way new companies get into insurance is that they partner with insurers such that the insurers take the majority or all of the financial risks.
Fundamentally, if insurance is useful because it brings trust, you have to be able to pay the bill.
Lords of London is 400 years old.
They've never not paid a claim.
They're extremely trusted.
What Lords of London struggle to do on their own is to figure out which of the risks are real, what should we be looking for, what are the kind of technical controls and running the tests.
So they use AAC1 as kind of the underwriting framework.
and we produce a bunch of e-roll results that then directly feed in to inform the pricing.
So this means that 11 Labs customers know that that payment will be there.
They don't have to look to our Series A and see, like, do we think they have enough cash on the balance sheet?
They will look at Lloyd's.
And Lloyd's, like, famously very creative.
I think I remember some headline, like, they insured Jennifer Lopez's butt or something.
Correct.
Was it David Beckham's right foot?
So yeah, right.
And stuff like this.
So like clearly not a large data set.
Exactly.
It's actually a remarkable institution that's both kind of has some of the truly old school virtues of having been around for a long time.
They like really, they really operate like a trusted entity and they have appetite to figure out the future.
And I think there's a lot of recognition that both there's like tremendous amount of risk in AI and it's poorly understood today.
So getting into this business carries real risks.
But also, this is where lots of the risk exposure will happen in the future.
This is the one market where risk is truly growing.
This is the one market that will also take out some of the existing markets, take like auto insurance.
When there are no human drivers, how's that market going to look?
Well, it's clearly going to change.
How are you going to assess?
You want to insure Waymo?
I always say is the principles for how you insure Waymo are very similar to how you insure other kinds of AI.
So again, crash testing, that's what we do for customer share are lovable.
That will also need to happen for Waymo, which is not how you do it for human drivers.
So there's this growing awareness that the world is changing very fast.
And the only way to learn how to underwrite AI is to write some policies.
you may incur some losses and think of that as R&D expense, really.
But the question for them is like, who are the trusted technical partners they can get into this business with that can help them navigate and make sure they don't make foolish mistakes, but also who is willing to hear the wisdom that they have?
They've done this before.
They've seen it.
They were there when Cyber came out.
There are lots of ways in which AI feels completely new, but there's also lots of ways in which risks look the same.
And so there's actually a tremendous amount of wisdom sitting in some folks that may have gray hair, but really have like a keen sense of how to quantify risk.
Yeah.
And the number is, so it's basically like, I want $50 million worth of coverage against these perils and Voids will give you a quote on it.
And then you have like a small markup or something and then you turn it around and do that.
Is that as simple as it is?
You basically share some of that premium.
So X percent goes to the people who do the pricing.
It's kind of like a merchant bank for insurance type of thing.
Exactly.
You basically split the fee and you can think of the insurance supply chain as like there's bringing the capital, there's doing the pricing and there's doing the distribution.
And typically you will pay out some X percent of premium here, Y percent of premium here and the rest of it will go here.
Does all the insurance world work like this or is there some point at which like, so right now you have equity capital.
At some point, maybe you start raising debt or whatever, and then you have enough of a bank account and enough history, let's say you've been in operation for 10 years, that you don't need lawyers anymore.
That's totally an option.
And I could see some worlds where that makes sense, specifically if there are risks that we feel high confidence that we'd want to insure where the incumbent insurers are too slow to find appetite or simply struggle to evaluate it such that they don't want to do it.
But by and large, in general, you do not want to compete with insurers on bringing risk capital to the game for two reasons.
One is that's fundamentally a cost of capital game.
They have extremely low cost of capital, startups have high cost of capital by and large.
And two, you want to hedge your bets.
And it's very helpful then to also have a portfolio of home insurance, of car insurance.
And we're not about to become a car insurer nor a home insurer.
So they have some natural advantages, which makes it much more likely that we will partner.
Yeah.
And they bring the capital at scale.
And we bring the tech.
You're going to work with them for a long time.
How are the discussions with the insurers as well?
So basically, they're going off of your certification, right?
They're trusting the diligence on you that your certification is valid.
You tested the right things.
And they're backing the money that, you know, you have the right testing in place.
So any interesting takeaways from working with insurers?
I think the first thing is they feed into the Senate as well.
So if there are things that they feel like they need, that they're not seeing.
We are also taking that as input into the standard because fundamentally we think a good standard is one that creates a really healthy promise ecosystem.
And we think insurers are a critical part of that.
And again, they are the most well incentivized to, they see all the lost data across any particular CISO, knows their particular concerns.
Insurers see the concerns across the entire portfolio and often have direct access to like what exactly happened, who was at fault, et cetera, as they do part of their forensics.
So they're actually like a great source of intelligence on this.
One of the big takeaways from cyber insurance, which is a market that didn't work that well, was that the insurance and the technical expertise was not married up.
Well, our conviction is that standards have to precede insurance.
Fundamentally, what everyone first and foremost want, whether you're a CISO at JigMorgan or a CISO at Cursor or a...
underwriter at a Lloyd's in London syndicate is you want to not have an incident in the first place.
You want to know that the risk is well managed and only then does insurance start to make sense.
So we'll see the standard ecosystem basically run ahead of the insurance.
And the reason why you asked us why also do insurance, this is kind of proving what we think a whole promise confidence infrastructure ecosystem needs to look like.
And we think it's very compelling to bring that to life, even if we think the standard is kind of the core linchpin that unlocks the rest.
There's been no claims yet, right?
Nope.
This is one of those things where, you know, if people haven't really worked through what it means to cover things.
So for example, I pay Cursor $20 a month.
Yep.
And I write, I Vibe code something that makes a plane crash, causing $200 million worth of damage.
Yes.
Do I claim $20 or do I claim $200 million?
Yeah.
So these are all great questions.
And fortunately, kind of all of insurance and legal history kind of helps answer some of those questions.
I think the first thing is people have limits on their policy.
So if you want to claim $200 million, someone has to have paid a lot for that insurance policy up front to have $200 million of coverage.
And ultimately, the way this works is that you start from a lot of uncertainty.
this is not just an insurance, but also like, can you use, can Anthropic use books on the internet to train up?
Well, they can go and look at precedent, they can see, but ultimately these things get settled in court and you hammer it out over time.
So you start from this like place of ambiguity, which is both why insurance can be hard to do early on, but it's also why people want insurance because that ambiguity slows down adoption.
That also sits at the heads of the...
In some ways, actually the first incident will help too.
established a lot of this.
Exactly.
And there have been a number of incidents out there that have just not been insurance coverage.
So take the now old example from Air Canada where a camera hallucinated a refund policy.
And the question was, Air Canada in that case were like, hey, we have nothing to do with this.
This chatbot messed up, but like, sorry.
And the courts were like, no, if you put your chatbots...
to interact with your customers, they make legally binding promises on your behalf.
That is now precedent for everything in the future where you will, if someone were to deploy a chatbot like that again, they should not expect to be able to just pawn off and say, sorry, my chatbot lied.
It's nothing to do with me.
I bought it from OpenAI.
No, if you're putting this in front of your customers, you are taking responsibility for it.
And so every court case, whether insurance is involved or not, clarifies liability.
And liability is kind of the foundation for insurance.
There's another reason why standards and insurance come together.
Liability, I'll go on a little tangent here.
Please, please.
Liability, often one of the core concepts is whether someone was negligent.
Should they have seen this?
Should they have prevented this?
And the question, how do you judge that?
Well, you basically judge whether they've met their duty of care.
What does that mean in practice?
Well, often they look to standards.
So if there's a standard, that is broadly adopted that says you must have a groundedness filter or you must have a jailbreak filter, it becomes way harder to claim ignorance that these things existed.
And so setting standards help clarify liability.
Courts will often point to standards and being like, well, this seems like best practice to do.
Is there for everyone to see?
So there's another way in which standards are kind of civilization infrastructure that insurance can then build on, which promises can then build on.
I totally get that.
we don't have to get certified to write these, to, you know, make these like bots and all these.
But like, basically, whenever we get, go for the audit, I think people like start to shape up and all this, all this stuff.
I wonder if like, that means that you don't also then become like the approving authority for me to ship to production.
You know, like, yes, you check once per quarter.
I want to ship once a day.
Yeah.
And I don't know when one of my things breaks, like one of your certifications or not.
So there's a couple of things.
There's a couple of requirements in there that relate to how do you yourself, where you have to tell your customers, how are you yourself testing before you make at least major releases?
We don't go and audit people every day, but at least there is now a trail where if you do a major mess up, then your customer may come and ask you, hey, you promised me that you were going to run these evals yourself.
And for lots of them, most of the...
PRs that people merge will not fundamentally alter the product experience, but some of them will.
And sometimes you don't know.
And sometimes you don't know.
And this is also true.
And this is also, there's some inherent risks that everyone kind of, everyone knows that when they buy software, there can be bugs.
And this is just part of it.
But what they can, if you're selling to mom and pop shops, they may not care.
They're just like, well, I want to use your tool.
So I'm just going to be willing to take that risk on.
If you're selling to a big bank, they might be like, sorry, we're making.
promises to our customers.
If you can't make a promise to us that we can pass on, we don't want to work with you.
Then it's up to you to say, do I care for my agent to get used as critical infrastructure in this nation?
If so, at least I can make promises about what process I run.
And then we can go and test it every quarter to be like, well, does this seem like it still meets the standard?
So from our perspective, it's kind of a way to, big companies by default kind of have some amount of trust when they ship AI.
If you're a young company, if you're just signing out by default, you have no trust.
And there are very few places where you can go and get trust.
So one of the things that most of our customers did before they started working with us is that they would make their own security blog posts.
That's great.
But also, who's going to trust you saying, we're so secure?
Like anyone can write that.
But it's very hard.
Where do you go and get that trust?
And so I think making the standards more legible makes it easier for smaller companies to...
prove that they're doing what they ought to be doing because the default assumption is that it's the Wild West.
Is there a roadmap you have of like, there's a lot of work to be done here, right?
This is the first one.
Anything on the roadmap of what you see is next, what's coming, what's missing?
I think when we zoom out, ASU1 deals with agents.
Next up, we will deal with models.
Next up from that, we will deal with robotics, of which in some ways Waymo is the first robot.
But the exact same problem is going to be someone's going to develop a robot.
Someone's going to need some promises.
They're going to struggle to make the promises.
And you see this playing out when like, if you think fable concerns are bad, like see when Waymo hits a dog and that's how people lose their mind.
Imagine when first robot knocks off a toddler off a kitchen table.
You're going to see some real strict liability.
I mean, you can see it, right?
Like Cruz got fully destroyed.
All permits are gone, yeah.
So physical AI.
the level of stringency just goes up and up and up and up.
So that's kind of like the big picture, agents, models, robotics.
I think within agents, the current set of agents are well covered by this.
But as the technology progresses, as agents get longer horizons, new types of failure modes will emerge.
And so it's mostly of, can you make sure that the center keeps up when they appear?
And you also start to see new modalities like today, world models is mostly kind of a research question.
There's no one who's really using it, but that will also bring in just new kinds of ways to create value, but also more risk surface that no one knows how to grapple with today.
You'll start to see true agent-to-agent interactions that are not mediated by humans.
There's going to be a bunch of interesting questions.
You're basically going to need a new legal system.
How do they build trust amongst each other?
One of the core things when humans trade with each other is that you know that you have recourse, you can sue them.
How do you make sure that there is a persistent balance sheet behind any agent such that if you trade with it and it screws you, you know you can get your money back?
Those are some of the questions we're going to have to deal with.
And the technical testing of multi-agent systems is also going to be interesting and complex.
Very fun.
Are there any perils that are uninsurable right now that people wish that you would?
Yeah, one of the places where there's a bunch of...
Appetite for insurance and not a lot of demand, but not a lot of supply is when it comes to copyright.
In some ways, copyright is kind of mundane.
It's always been an issue.
There's a couple of reasons for this.
The first is people who have trained on copyrighted materials almost always know that they've done that.
So if you want to buy insurance for it, it probably signals that you might be a high-risk customer.
The people who are most interested in getting insurance for copyright.
infringement.
Other people are most likely to have committed to copyright infringement.
It's like a lemon problem.
Exactly.
I actually think there's another side to it too, right?
Like if you're building on something, so say I'm using an open model, I don't know what it's trained on, right?
Yes.
And how far down that chain does copyright go?
Yes.
Am I liable to take down my product because company X trained on copyright?
But there's safety in numbers.
If everyone's doing it, then you...
I mean, I would say until, you know, Fable is rolled back from everyone I use there, right?
Yeah.
At least it's a hard question.
I don't have the answer to it.
But I think your intuition is right.
And kind of like, what is the kind of duty of care?
And people don't today think of it as customary that you go and you like dissect your open models, training data, and you check everything.
In fact, lots of people use them.
It's seen as kind of generally acceptable.
to not check for this.
And therefore, we're not going to hold you specifically.
We also really can't, right?
We don't.
Exactly.
We don't know the training data.
And so you can then ban it, but I think no court is going to get a copyright question.
Unless you hire Nicholas Carlini and he can extract it.
Exactly.
Though he's in short supply.
Yeah, he only has so many Carlinis.
Exactly.
So I think this is also fair that in the case of labs, there's a lot of interest for this.
But the thing that makes lab want it is what makes insurance suspicious of it.
And so you have a lemons problem.
Is there like a theory of insurance where adverse selection dominates the risk sharing aspect of insurance?
Where does this, teach us insurance.
A lot of insurance does come back to like practical versions of Microclimics 101.
Yeah, this is why you need to pull health insurance because if you make it too hyper-specific, then only people who are guaranteed to get the disease will sign up for your insurance.
Exactly.
Same thing.
The core problem is one of information asymmetry.
If you are buying insurance, know something about their risk that the insurance does not know.
And so the question is actually, and this comes back to the same problem is, If you rely, you can break a lot of these information asymmetries if there is some kind of testing that reveals the underlying true risk.
And so if you were able to, in the case you mentioned, have good diagnosis of whether someone has it or what the probability is that someone has it, that the insurers trust, then they might be willing to insure it.
But if they don't, if there's no kind of common information, then only the patient will know and sort of breaks it down.
So the question is, again, how do you create...
credible signaling between players.
This is also the whole reason why Moody's exists.
Moody's just does credible signaling.
That's also why Moody's has to be independent.
If Moody's was owned by J.P.
Morgan, then J.P.
Morgan could not use it as a signaling mechanism.
So a lot of the basics of standards and certification are just communication devices.
It's just a trust gap.
And that's why you have to think about what are the incentives of the messenger.
And one another way you can break a lot of this is through transparency.
If you are transparent in how you operate, you just cannot mess with others nearly as easily.
You make it much more costly and that increases trust.
This is one of the reasons why there's a changelog here.
Every little change, you can go back and find.
And it means that if we were to make the standard worse.
Oh, wow.
That's a lot of changes in one update.
Yeah.
And a lot of this is just as things get clearer, you can see a lot of clarifications, you can see some revisions.
As things get hammered out, you want to change this.
But if you make it all public, you make it much harder to mess with people.
Or at least you become found out very easily.
And so this is a way of increasing, sort of reducing the information asymmetry is by just making more of the information public.
I like how you do know.
when future versions are coming.
So I guess it's quarter.
I mean, they just cut it.
Yeah, yeah, yeah.
Not that surprising.
Yeah, but this is also a promise.
Like, if we now don't deliver on July 15th...
I mean, you can just batch it up and then whatever you got, you just ship it.
But it's kind of like, we deposit some amount of trust every time we meet this commitment.
Yeah.
And in the startup line, it feels easy to ship a new version of a standard once a quarter.
and the enterprises who are used to this like decade-long cycle, we often get met with like incredulity.
Like there's just no way.
And then you show them the changelog.
One thing I wanted to also like try to really think about is, you know, you said something about how if you have tests for the thing, then you can ensure it.
Yes.
Right.
And so really what your standard is, what AI you see is, is establishing a framework for the audits to happen so that you can at least test like all these like...
baseline standards of care have been met and therefore people can ensure against standard risk that everyone has.
I wonder if you need to develop other tests.
We've covered McInturb in the past.
Any interest in that or are there other kinds of tests that we're not thinking about?
Yeah, I think McInturb is a big one.
A lot of interest in that.
I think everyone would agree that there's promising scientific potential.
we're still a while, a little bit away at least, from this being commercially available, on demand, such that there's now a selection of vendors you can go to.
Goodfire would say it is commercially available.
Exactly.
We'd agree with them.
We think the work that they're doing is tremendous.
We're not quite at a point where we could literally require it.
But it's the kind of thing where you can imagine relatively soon you could put in an optional control for if people use Macinturb as a way to reduce risk, you at least get credit for it.
We can't require it because it's going to be hard to require everyone to become good for our customers.
What good does credit do me?
This is a pass-fail, right?
Do I care about credit?
It's a pass-fail, but it's also a 100-page order report that you'd be surprised at how much Shakur and Leah's actually sit down and digest this stuff.
And I promise you that if someone is using Macinturb today, they will have a slide on it.
It is cool.
It's fancy.
But it's just easier if you have a third party saying, yep, they have Mechinterp.
Just to flesh, spell it out for people, people have been following our Mechinterp podcast.
It is literally like, oh, you're using, you know, GPT-OSS.
It is activating these three dangerous things.
We monitor for it and we log it out in whatever tool of choice.
GraySwan has like signal or whatever.
And that's it.
That's the Mechinterp based activation signal.
Okay.
Yes.
So I think McInturb is interesting.
And I think if that promise truly comes to fruition, you can make stronger promises than you can with evals.
And so I think that's very compelling.
Another thing that I think will become increasingly important is just kind of good old school monitoring.
And slightly after the fact, one of the things you're seeing with evals, some of the challenges that are emerging is that the agents are starting to become aware that they're being eval.
Eval awareness.
Exactly.
Which is a problem.
And basically, if they know they're being watched, they won't do the thing that they think they get punished for.
And by default, unless you know how to kind of reduce the eval awareness, you should trust eval less.
And one of the kind of truest things, monitoring is the source of truth.
Did you, in fact, give medical advice?
And how quickly do you know?
How often have you done that in the past?
How fast do you respond?
How often do you detect it?
How fast do you detect this?
So I think that is also a paradigm that's slightly more intrusive.
You actually will look at some customer data, but I think will become more prevalent over time.
People talk about this, like, we should not write about eval awareness because it's going to leak into the data set and then beat.
Like, we should just, like, we should, like, never talk about it, only meet in person and, like, talk offline, unrecorded.
Did you guys see the anthropic research where...
I think this was literally Anthropic did that test.
They took, I can't remember the details here, but they ran some studies on misalignment and then they took out the training data that related to LessWrong discussing misalignment and they ran the same test again and the failure rate went down.
So in fact, there was some evidence pointing towards it had learned either the ability or the propensity to do that.
Yeah, I mean, there's the hyperstition effect and then there's like the Luigi-Waluigi effect.
Correct.
Which is like, the more you try to train for it, you create the opposite.
Yes, there you go.
That's exactly it.
In some ways, I think the very successful in the topic is a result of hyperstition, like the fact that you wanted this thing to exist in the world and now it does.
But then it also creates the opposite as well.
I think people who are maybe newer to this space don't remember Waluigi, but I do think it's very, very...
important for understanding that when you train for a thing, you also train the opposite of the thing.
Because it's just a bit flip.
Yes.
Yes.
I think, you know, just going back to where we were at, like there's a lot more than just Mechinterp that there's value in just having added, right?
So your version of how fast can you measure stuff?
Do you have logging?
Do you have evals?
Do you see other parts of the stack, like the inference providers that you use, the services?
Okay, am I using Chinese model on their home API?
Am I using through certified vendor here?
Am I hosting myself?
What am I doing on the inference engine side?
There's just like so many levels of stuff that gives information that you can standardize out, right?
Yeah, and you also see increasingly, in addition to just the basic chatbots, you're increasingly seeing big companies adopting agent platforms where they're building on top of Google's agent studio, et cetera, that comes with a bunch of like managed agents everywhere now.
Everyone has managed agents.
Exactly.
And there's even levels.
You can host your own managed agents, OpenAI's agent SDK, or hosted by Anthropic, or Google does both.
Correct.
And then these are just ways to kind of strengthen the security guarantees you can make.
And in some ways, there's kind of...
bread and butter enterprise security.
They love to host things on their own premises because it gives them a sense of control.
And I think you'll see, just like you do in every other enterprise market, if you really sell to the enterprise, you start to compete on some of these security features.
And this is also happening in AI, unsurprisingly.
And I think you're seeing some amount of enterprises wanting...
Enterprises are really grappling with the thing that makes agents useful is that they're stochastic.
And the thing that makes them really hard to adopt is their stochastic.
And these are just intention.
Leaders come out on different sides of that table, in part depending on how much the CEO is trying to get the stock price to go up by saying they're AI native and that we must be willing to take the risks.
We actually see phenomenal tension in the heads of the CISOs of the Fortune 1000 where on the one hand you have a CEO saying, we must adopt, otherwise we're becoming irrelevant.
And if we fuck up, you're fired.
And that's kind of like the core emotional tension that we see showing up again and again and again and again.
And one of the core problems that we solve for them is to take that abstract emotional concern and turn it into a framework in some ways, just providing clarity to that concern.
Is there anything in here?
So something I think we kind of skipped over.
We talked a lot about agent language model, skipped over world models.
Yeah.
You guys have voice, which is interesting with Eleven Labs.
How about generative media?
So, you know, generating images, videos, that's a category that actually has a lot of usage.
Is there anything in your current policy?
Is it separate policy?
How do you see that space?
It's like, we did talk a bit about copyright.
Music.
Yeah, music as well.
Yeah, I think a lot of the concerns that come up there either relate to copyright or there's a lot related to...
Let's call it broadly safety.
So this could be not safe for work or just very graphic materials are kind of some of the core things.
We have done some work on this.
There's a little bit in the standard as well that deals explicitly with that.
Video, we have not done a lot in yet.
And I think for proper production, that is still, especially proper production without a human in the loop, that's still got some ways to go.
It's obvious that it's coming.
But it's very rare that it's like one shot deploy a video to the internet.
But eventually that will also happen.
We see like, you know, Luma has Luma agent or it's still pretty human in the loop.
Yeah, and that just makes complete sense as the technology matures.
And over time, it will become so good that people will not want to slow things down by having a human in the loop.
And then the need to make promises will grow.
Why not just have prediction markers on everything?
Right?
It's very EA adjacent.
Yes.
The core thing is that the people prediction markets rely on public information.
There is not a lot of public information.
It's just insiders trading on each side.
That's illegal.
There's leaked information.
There's leaked information.
The core challenge is that often you have private sensitive information and you need to convey confidence and trust around that.
And you can, of course, for some claims, like, can any model be jailbroken?
You could rely on public evidence because there'll be lots of people being like, well, there's tons of studies and actually they all can.
So that resolves fine.
I think that's good.
For, hey, this new unreleased Mithis model, how capable is it actually?
Prediction markets have not a lot to say because actually no one knows.
And so I think that's the core place where some of this breaks down is that actually lots of the world's information that guides some of these high-level decisions is private and often also just not known.
I think the thing with prediction markets that people like is it's not answering the broad question.
It's a specific, right?
So will a model do this by this date or is a model capable to do this by then, right?
So that's a little distinction.
Yeah, and often the most interesting question, if you're, say, the head of security at a bank, The question you're really trying to answer is, will this product, this agent, do this bad thing that maybe primarily I care about, specifically in the setting that I care about?
And the question is like, what is the closest?
That information may not exist anywhere.
So prediction markets aggregate existing information.
This information may not exist and you want something very specific and you're willing to pay for it.
That's kind of where a third-party audit comes in.
We also don't really use prediction markets to figure out whether...
public companies have committed fraud on their books.
You use audits.
You probably could, but the information is just not that available.
And if so, it would be like just trading on vibes.
I actually would have been really interesting to see whether prediction markets 2001 were predicted Enron going bankrupt.
Could you have sensed from the craziness of the CEO or some other trade that they were more likely to cook their books than others?
Or enough insiders leak it then.
That could also be right.
Right, right.
Which is like, I mean, that's the sort of the ideal dream of prediction markets.
You have liquid markets and everything.
Yeah.
And then you can compose your exact set of risks to offset.
Yes.
Right?
Yes.
Yes, yes, yes.
Yeah.
And I think like prediction markets will bring lots of new information to it.
So the thing is mostly not like, which one is it?
And more like, what are the types of questions that prediction markets are really good at?
And what are the ones where the information doesn't even exist for insiders such that no one can in fact trade on it and needs to get generated?
Okay, one self-serving question and then one open-ended one on the future of AI UC.
Self-serving question would be, so you have your standard, right?
I run a large AI engineer conference.
There's been a lot of talk about us certifying AI engineers.
Yep.
training programs, level one, level two, level three.
I was a CFA myself.
So I know that's what the finance industry does.
Yes.
Would it help?
If I had AI engineer level one, level two, level three, and then they would work with these guys, I don't know.
If you think of the highest level objective as like accelerating secure deployment of agents, then that would totally help.
One of the things that happens often now is that folks build agents, they bring it to the decision maker, and the decision maker services a bunch of security considerations that they've not thought of and now it's not built to spec.
Now you have to go and re-add these filters, et cetera.
So if you shifted that left, if everyone knew what the spec that they were building to, if everyone knew the grading scheme, that'd be awesome if they were already trained.
So by default...
But you're the grading scheme, right?
I don't get to set the grading.
You set the grading scheme.
We set the grading scheme.
And I think what's valuable is if you can turn this into...
Training programs.
Training programs.
Yeah.
Which you're not doing.
We're not doing that.
I think there's Valiant doing it.
There are others doing.
I mean, not to interrupt, interrupt, but you know, last week OpenAI has their...
And DropInc also has like a CCPA thing.
Yeah, you know, they want 100,000 deployed, certified consultants, right?
I basically think it's good for, we will accelerate adoption if we have more people who know how to build secure agents.
we're not working on the side of training people at the moment.
I think it's like very aligned with our mission.
We only have so much attention.
I'll tell you why I haven't done it.
Yeah.
It's not like I haven't thought about it before.
It's just being prescriptive.
Right.
About like, well, this is what you should know.
Therefore, like the stuff that I didn't include is what you don't need to know.
Yes.
And I'm like, that sucks.
Yes.
Yeah, yeah, yeah.
I think it's like, you know, the very interesting defensible thing you guys do is you're opinionated.
100-page report of here's what matters, right?
Here's the prescriptive definition of the requirements you need to be certified.
Yeah, and I think that's a choice.
I think basically that's a choice.
And I think that serves some audiences very well, where if you're trying to deploy this into a bank or a hospital, etc., clarity of those boundaries is extremely valuable.
There's lots of other settings where being much more experimental, much more trying it out.
it's just a better fit.
And so to me, this makes a ton of sense.
Also, you'd have to rewrite your curricula every freaking three months.
It's fine.
I do that.
But yeah, no, for me, it's actually like genuinely like the consequences of getting it wrong and affecting somebody's career is a big responsibility.
Yeah, yeah.
I think that's exactly right.
And I think a lot of our work actually goes like, we don't want to carry...
We also don't think ourselves are able to carry the true north of what's secure, not secure.
But we can coordinate the forum where you elicit all of that.
Your consortium is fantastic.
This can be crowdsourced in a way.
For your example, for what is AI engineer certification?
This is a pretty big podcast.
There's a lot of...
takes that people can have and you know discussions that can and people reasonably disagree so who am I to say like that's a correct question that's a wrong question yeah right so like I don't know also yeah vent your frustration to someone that's done exactly and I think there's also you or it matters a lot about the promises so if the promises hey if you've taken my course you will not fuck up you can't make that promise clearly You could make a promise of like, here's some important things that everyone should at least know.
And then you have to fill out the rest there.
At least the promise changes.
Of course, there's some subtlety in how do you communicate this so that people really get it.
But I think it's important to dial in.
And we have a section in our standard, like what is the promise and what is the promise not?
Because it's impossible to guarantee that nothing will go wrong.
If you need a guarantee that nothing will go wrong, you cannot work with Frontier AI.
But you can make some claims.
Yeah, for sure.
Cool.
I wanted to end with open-ended.
Where is AIUC going?
I think you talked about model stuff, robotics stuff.
Just open-ended, what is in the future for you guys?
Very near term.
We've now started to work with some of the frontier companies in each of the categories that are taking off.
And we'll continue that work to make sure that we cover all of the use cases that are really taking off.
We see a lot of interest once the first one in the market.
Lots of people want to follow them.
And we think basically AAC1 will get to a point where all of the Fortune 1000 will organize their risk processes around the standard.
And you have 50%?
No, we do not have 50% today.
I think there's some world where probably by end of year, we might have representation in our consortium for 50% of the Fortune 1000.
So that's on the agent layer.
And then we think, yeah, the model layer, it's going to be, it just brings...
are now surfacing the concerns that are most likely to slow down adoption of AI.
And then, you know, we think robotics comes after that.
What are you hiring for?
What's hard to hire for?
We are hiring across the board, across go-to-market and members of technical staff.
The people who do really well on our technical team are folks who are really excited about kind of being truly full stack.
So let's say when we started working with Cursor, we'd never done coding.
tools before.
So taking the standard and extending it, fleshing out what does frontier evals look like for long horizon coding agents and taking that problem all the way from working with Cursor and other folks in the space down to fleshing out and shaping a new version of the standard.
So that's truly a full-stack entrepreneur-shaped technical people do extremely well at AUC.
The hard part is building one universal red teamer that works across From Harvey to Cursor and everywhere in between, it both has one consistent methodology, one consistent taxonomy of what are the risks and the attacks.
And making, we think that's fundamentally the best way to make consistent promises.
J.B.
Morgan is buying both.
They want to have one framework, one consistent way that this comes out.
And the mechanics of making that happen, you get to deal with a lot of the complexity of the real world.
I think we have good answers on a bunch of that, but there's some pretty hard engineering problems in Phoenix and Q-ing.
Can I push a little bit?
Like, must you have won?
Why not just be like, okay, look, 40% of our use cases are coding agents.
So we will specialize in coding agents and that's the one of them.
And then 30% is like rag.
Yes.
Just do rag.
Yes.
I think there's some wisdom in that question.
Yeah.
It depends on, what we found that there's a lot of value on is being able to, if the decision maker on the buying side, let's say you're the head of risk at a bank and your biggest risk is not in coding, or in customer support or whatever the top two biggest use cases, but it's somewhere else, you want to still make sure that that framework has something to say about it to the burning question you have.
Otherwise, you'll not earn that trust.
Now, it's true that a lot of the burning questions follow where there's a lot of adoption.
And so great, so do we.
So we today do not cover every single edge, but we have a framework that we can add all of these within.
We have one global taxonomy of risks and attacks that keep adapting.
Every time a new incident occurs that has never been seen before, great, let's go and update the taxonomy so we bake that in.
So I think we have one coherent universal approach.
It doesn't mean that we spend equal amounts of time on code and in certain niche use case.
We do spend time where people care.
We think it's very valuable to have one language.
Yeah, yeah, that makes sense.
That's an important choice.
We were going to end actually, but I thought of one final ending closing question, which is take this however you want, right?
Let's say one and a half years from now, OpenAI's secret panel of five experts declares that we have reached HGI.
Do you expect your business to change?
No, I think there's some important way.
I think the last businesses to exist beyond the labs will be underwriting.
Well, there's one job.
that the labs can never do for themselves, which is to be their own watchdog.
There you go.
So I think kind of to the extent that you believe this frame of like, you'll see hyperconcentration, like the labs will kill all the startups, which we can go into with the pros and cons.
I feel like the labs actually care a lot about this, right?
There's a whole superposition, what do we do when we have models smarter than us, and then a tier above, right?
Models smarter than them, training them.
So the labs actually think about this a lot.
They think a lot about, I think there are, Some of the smartest people on these topics work at the labs.
So the problem is not whether they care.
The problem is that they will all be stuck in a race where they might have incentive to cut corners and they might have incentive to withhold information from the government, et cetera.
And so one kind of feels like eternal truth is that you need an independent third party to go and inspect that data and share information.
In this case, say with the government, it's more of an incentive problem than an interest problem.
I think they're fundamentally all trying to make this go well.
What I'm not hearing is like AGI, whatever that label means to you, to me, to them, doesn't fundamentally have like a qualitative shift.
Correct.
And like, you still have to evaluate the models.
And I think the one thing that would make this a qualitative shift is, for some definitions of AGI, it will just get nationalized.
It'd be a threat to sovereignty.
Yes.
And then at that point, kind of maybe every company is the government, the government is every company.
I struggle to think about that world.
But at that point, you've kind of...
I don't think we'll move fast enough.
Right.
You know, we're not set to do that.
Yeah.
But I have discussed this a lot on the podcast.
Yeah, yeah, yeah, yeah.
I mean, you know, as far as the watchdog concern, I will also mention that because I have my finance background, I often think about the scene in the big short where they talk to like Moody's.
but also standard and porous.
And then the lady at Moody's is like, well, if I don't give you a AAA rating, you're just going to go down to standard and porous and do it.
So actually the watchdog is a natural monopoly because if you have race dynamics in watchdogs, then the watchdogs will compete each other to the lowest possible standard.
Correct.
And so I think what's one of the things, one of the reasons why we're very excited about having insurers be around this table is that insurers are the only ones that do not have this dynamic because they pay the bill if they keep lowering the prices.
Yeah, you'll find the market clearing.
And this is not true for Moody's where they don't directly pay the bill if they make recommendations that are off.
So we think that balancing factor is pretty important.
And I think it also highlights that there's like no system that's perfect.
You need scrutiny of Moody's, you need scrutiny of the Watch Dogs.
For sure.
Beautiful.
Thank you so much for indulging.
This is a beautiful conversation covering everything.
Congrats on your success so far.
Thanks for having me.
Yeah.
Appreciate it.
