My incredibly complicated relationship with "AI"

So, if it wasn't clear, I work in Cybersecurity. Shocker I know. I'll give you some time to digest that fact as we continue on. 

In the last... three years or so there has been the ever increasing drumbeats of AI and discussion on the ethics surrounding AI. Is AI, as the folks over at Y-Combinator / Hacker News so graciously put it 

[Generative AI is] not really a mechsuit; inasmuch as it is, it's more like an Evangelion: it's got bits of people's souls floating around in there; it only works well with a high synch rate with the user, which is difficult to achieve consistently; and sometimes it pops off and does its own thing anyway.

Or is it the future by which we all must live breathe and learn. If you're working for any kind of security agency at this very moment I assure you that your CISO / CIO and the rest of the C-Suite are asking you how to protect from the magic of AI, how to properly contain this beast.  At the same time I'm a furry who get a near impossible amount of furry artwork (I don't have kids, so you know, you've gotta invest in something). And there the very concept of Generative AI is so horrifically toxic that if there is even a hint that you may have used it as part of your process you are effectively blackballed by the community. 

So how do I live in one world where it's expected I know all the intricacies of a where you need to know about MCP, RAG, Harness, the various models available, setting up Terraform for for IAC, having proper guard rails, DLP, Monitoring, logging, etc. Understanding the difference between a cloud hosted LLM solution, a locally hosted LLM solution and building your very own model. While at the same time understanding the underlying fundamentals of these systems are entirely based on stolen works or the very fact that much of it's training data could have been horrific and gross abuses of everything we hold to be moral. 

The fact that the AI industry as a whole is a giant ticking time bomb of debt and market collateral that  everyone is keenly aware will fail at some point in the very near future like the .com bubble or housing collapse but probably many times worse as the Magnificent 7 are literally propping up the entire global economy. All at the same time that AI is contributing to global warming, taxing electrical grids. How to live in a bubble with all this information and still try to see value in it all. 

AI Platform Engineering Reference Architecture(stolen from: https://re-cinq.com/blog/ai-platform-reference-arch)

And this is where it gets hard for me, because I do see value in Large Language Models (LLMs). I think you'd be hard pressed to find anyone who thought that Machine Learning (ML) was useless, but you might get a fair bit of pushback at the notion that LLM's might be useful but... much like ML is great at finding abnormalities in data, LLM's are absolutely great at finding abnormalities in natural or pseudo natural languages. What better way to stop phishing emails than to have an LLM ingest it all on a regular basis, parse it, and use training data to determine which emails are likely phishing and which are legitimate to a much higher degree of percision than previous Machine Learning models. 

What better than an LLM to take gigabytes of security log ingest and alerts, cross compare against analyst notes and tap into MCP servers to access live real time data to do an initial triage to help sort and escalate the various different types of alerts to the surface that might indicate there's more going on. Basically being able to take Risk Rating capabilities from alerting to a much higher level. Because you can feed the LLM which systems are worth more to you than others and as part of it's initial triage evaluation it can just sort of take that into account. Areas like what adobe was doing 10 years ago with being able to use existing data from within the image to give a best guess at an area that might have been damaged. 

And so it becomes difficult to look at the blanket "Yes" or "No" on AI and say that I fall into one side or another. On one hand I have watched the immeasurable damage it's doing in fields like Voice Acting, Graphic Design, Writing, and Digital art taking away revenue from very real individuals using the very work they created as the base. I have to consider the immense environmental impact and economic damage that hyper focusing the worlds resources into such a thing might have, but knowing that for DNA sequencing, and other forms of Medical ML it can literally save lives by helping to detect abnormalities in X-rays, MRI's, test results and more to help shape proper medical treatment that may have been missed otherwise. 

There is value in having a machine that can do what is basically a glorified version of your phones autocomplete on massive sets of data or analysis and very real harm in the exact same set of tooling. And so I find myself at this odd crossroads. Would AI be ethical if LLM's used for Art and Writing properly tracked their training data and properly awarded royalties to the various groups and individuals who provided that training data? Is it just a matter of compensation and copyright?  Or do the environmental, economic matters start to change that perspective? 

Holodecks in Star Trek Adventures - 

Or does none of this matter at all because you are talking about the dangers of allowing a machine to replace the work of a human. And not to sound overly like a luddite but do we lose part of ourselves if we allow a machine to replace us in areas like story writing or art. I mean we look at Star Trek's holodecks, that's literally an LLM combining art and writing and putting into a holographic form. When it creates Captain Picards favorite Dixon Hill novel generating holographic people based on descriptions and data provided to it, is it not basically just an LLM on steroids? Was that ethical [Well apparently not all of it]?  It starts nosing into that black mirror territory of if it looks and feels enough like what an individual wants is it harmful for the person to believe it's human. 

10 Horrific Fates Suffered By Black Mirror Characters – Page 6 

It makes it a strange place to stand when there is very much, very clearly, a want and a desire for this sort of technology, but no clear method for doing it the 'right' way. At some point, the LLMs or whatever future 'AI' is going to have to learn from us, and that means taking other peoples data to do it. How do you properly compensate them? How do you make sure they aren't lost to time? Or on the flip side. How do you do HR for an Agentic personality that is frequently misbehaving or under-performing? Do you just build it from scratch? What about Privileged Identity management for agentic workflows? How do I make sure the 'AI' that I've asked to do backups hasn't gone off the rails and accidentally deleted years worth of data? Do I make an AI check things out in a PIM solution and cite a ticket for the work it's doing or do I make the human who spun it up do that? When it fails who is responsible? When the AI Customer Support Agent gives the improper instructions is that upon the company or the creator of the AI?

Unfortunately Pandora's box has been opened, and there is no way to close it again. Folks are going to use AI for incredibly dumb things, making memes on Facebook, etc. and I'm not really sure if I have it in me to be angry with them for doing it. Save a narrow subsection of the population there aren't a lot of folks who fully understand the implications and ethical concerns raised by LLM's. So you'll forgive me if I don't yell at Grandma for sending me a meme that she had Gemini generate using Minions. The value of that anger just isn't there. 

All this, I guess to say to my tech and furry art friends alike. This situation is not so black and white, and blanket condemnation or celebration of LLM's, ML, and the like don't come without some wide areas of gray. Is it a crime if your junior developers are asking LLM's questions that functionally just acts like a slightly more fine tuned version of google searching Stack Overflow? I don't know... I don't think it's as clear cut as we'd like it to be. If some code focused solution could dig through code and basically act as the Hyper Fuzzer 9000 is that such a bad thing? Would there be outrage over LLM's if so much hadn't been stolen

I guess to say is the problem the technology? Or is the problem the hosting infrastructure and training data? I fear for me this is a far grayer answer than I think most folks would like.  

 

Comments

Popular Posts